Keeping cloud deployments in line with an organisation's rules on technology, security and compliance, helped by Azure Policy, tags and resource locks.
Also called cloud governance.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Governance in context, with comparison tables and the common traps.
Terms in this definition
- Azure Policy
Azure service that audits and enforces how resources are configured, for example their location, SKU or tags, using definitions and assignments. It neither deploys resources nor controls access.
- Image tagging
An Image Analysis feature producing single-word tags, each with a confidence score, for actions, scenery, objects and living things in an image.
- Resource locks
Locks, at ReadOnly or CanNotDelete level, that stop management-plane changes. They place no limits on where resources go or how large they are, and data-plane work such as blob reads and writes carries on regardless.
Related terms
- Accountability principle
Under this responsible AI principle, identifiable people must answer for how an AI system behaves; human oversight, override capability and governance committees support it.
- Azure Governance Visualizer
An open-source script that produces a report on a tenant's governance setup, including management groups, policy and RBAC, and highlights Azure landing zone policies that are out of date or obsolete. The Architecture Center offers an accelerator for running it.
- Azure subscription
Container for Azure resources that also marks the edge of their billing, quotas and scale limits, governance, security and identity. Each one trusts a single Microsoft Entra tenant, and it isn't bound to any region.
- Cloud Center of Excellence
A team drawn from several disciplines (adoption, strategy, governance, platform, automation) that defines standards and guardrails so others can serve themselves in the cloud. When subscriptions are vended, it decides the request logic and approvals.
- Cloud operating model
Who looks after cloud governance, security and operations, and how that work is split. The Cloud Adoption Framework sets out centralised, shared management and decentralised options, which are frequently combined.
- Data engineer
A person who builds and operates data integration, including pipelines that ingest and reshape data, cleansing, governance rules and the stores that hold data for analysis.
- Databricks
Analytics platform built on Apache Spark where data is processed in notebooks; Unity Catalog is the governance model it recommends.
- Defender for Identity
Microsoft Defender service that detects attacks on identities, using sensors on on-premises Active Directory servers plus signals from Microsoft Entra ID and other identity providers; it does no access reviews or identity governance.