When a related resource is absent, this Azure Policy effect deploys an ARM template to create it. Resources that already exist are corrected only by a remediation task running as the assignment's managed identity.
Also called Policy effect.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains DeployIfNotExists in context, with comparison tables and the common traps.
Terms in this definition
- RELATED
Fetches a column value from the lookup table, that is the one side of a many-to-one relationship, for whichever row is being evaluated. It therefore needs to run inside an iterator or a calculated column, where row context exists.
- Azure Policy
Azure service that audits and enforces how resources are configured, for example their location, SKU or tags, using definitions and assignments. It neither deploys resources nor controls access.
- ARM template
JSON file describing Azure infrastructure declaratively. Once deployed it keeps no live connection to the resources, unlike Blueprints, which retires fully on 31 January 2027.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
- Remediation task
Brings existing non-compliant resources into line under a Modify or DeployIfNotExists policy assignment, acting through the managed identity of that assignment.
- Managed identity
Identity in Microsoft Entra given to an Azure resource so that no secret has to be stored. It comes in two kinds: user-assigned and system-assigned.
Related terms
- Azure Monitor Baseline Alerts
A collection of recommended alerts for landing zone components, covering metrics, activity logs and logs, maintained by Microsoft. They are rolled out with Azure Policy using DeployIfNotExists, alongside action groups and alert processing rules.
- existenceCondition
Used by AuditIfNotExists and DeployIfNotExists inside a policy rule's details, this is what the related resource is checked against; a true result means the effect doesn't fire.
- roleDefinitionIds
Array within the details of a Modify or DeployIfNotExists policy definition giving the full IDs of roles the assignment's managed identity requires for remediation. Only the portal grants them automatically.
- Start-AzPolicyRemediation
Creates a remediation task for an assignment whose effect is Modify or DeployIfNotExists (Az.PolicyInsights). Pass -ResourceDiscoveryMode ReEvaluateCompliance to rescan before remediating.