Several Azure Policy definitions grouped together for assignment as a single unit.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Initiative in context, with comparison tables and the common traps.
Terms in this definition
- Azure Policy
Azure service that audits and enforces how resources are configured, for example their location, SKU or tags, using definitions and assignments. It neither deploys resources nor controls access.
Related terms
- Definition location
Where a policy definition or initiative is saved, either a management group or a subscription. Assignments can only be made beneath that point in the hierarchy, which is why widely used definitions should sit high up.
- Definition version
Lets an initiative or assignment lock to a specific release of a policy definition. If none is chosen, the newest major release is used and minor updates flow in automatically.
- Exemption
Lets you take a particular scope or resource out of an Azure Policy assignment's evaluation, or out of chosen definitions within an initiative, so it reports as Exempt. You label it Waiver or Mitigated and can give it an end date; exclusions hide resources from compliance results, whereas exempted ones still appear.
- Policy assignment
What makes a policy definition or initiative take effect: it targets a management group, subscription or resource group, supplies parameter values, exclusions, an enforcement mode and non-compliance messages, and starts a compliance scan.
- Regulatory compliance standard
Defender for Cloud lets you add built-in frameworks, ISO 27001, CIS, NIST SP 800-53 or AWS Foundational Security Best Practices among them. Each is applied as an assignment of a policy initiative, so Owner or Resource Policy Contributor rights are needed.
- Resource Policy Contributor
Role able to author and assign policy and initiative definitions, which is needed, for instance, to add a standard in Defender for Cloud. Contributor cannot do this because it lacks
policyDefinitions/write.