Built-in Deny policy that prevents the resource types you list from being deployed by any route, including ARM templates.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Not allowed resource types in context, with comparison tables and the common traps.
Terms in this definition
- DENY policy
A Beta ABAC policy type that takes a privilege away rather than granting one; at the moment it can only block
MANAGE ACCESS CONTROL. It applies wherever governed tags match and beats every grant, ownership too, though it never restricts metastore admins. - List
Permission on Key Vault secrets allowing a caller to enumerate those in a vault, though their values are not returned.
- ARM
Short for Azure Resource Manager, the control plane Azure uses for deploying and managing resources.