What makes a policy definition or initiative take effect: it targets a management group, subscription or resource group, supplies parameter values, exclusions, an enforcement mode and non-compliance messages, and starts a compliance scan.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Policy assignment in context, with comparison tables and the common traps.
Terms in this definition
- Policy definition
A JSON rule expressing a compliance condition as if/then logic with an effect, plus parameters and metadata. Nothing happens until it is assigned, and the category it carries is purely metadata.
- Initiative
Several Azure Policy definitions grouped together for assignment as a single unit.
- Management group
An Azure scope that sits over subscriptions. Policies and role assignments set there flow down to every subscription, resource group and resource it contains.
- subscription
Entitlement bought for a product under VCF 9.0 licensing, carrying a set capacity. Where active ones share the same site, unit and product, their capacity is combined into licences, which are then allocated to vCenters.
- Resource group
Container for Azure resources. Its location holds only metadata and cannot be changed afterwards, and one resource group cannot sit inside another.
- State
A parameter in OAuth that carries custom data through the authorisation flow and back, as with the "Support state parameter" option in APIM.
- VALUES
Returns in DAX the distinct column values, or table rows, still visible after filters are applied, sometimes with an extra blank entry. CALCULATE often takes the result as a table filter.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
Related terms
- Assignment overrides
An optional property on a policy assignment that alters a definition's effect, or the version of a built-in definition, without touching the definition itself. Selectors can narrow where an override applies, and pairing it with resource selectors supports safe, staged rollout.
- Enforcement mode
Decides whether a policy assignment actually applies its effect. Default does; DoNotEnforce only evaluates and reports, without blocking or logging deny events (remediation tasks still run); Enroll applies the effect only to enrolled scopes.
- nonComplianceMessages
Property on a policy assignment containing custom text shown on denial or non-compliance. It holds a default message and, for initiatives, messages aimed at individual policies via
policyDefinitionReferenceId. - Policy exclusions
Scopes listed in
notScopesthat carve parts out of a policy assignment so they are not evaluated. Exclusions can only shrink the assigned scope, never widen it. - Remediation task
Brings existing non-compliant resources into line under a Modify or DeployIfNotExists policy assignment, acting through the managed identity of that assignment.
- Resource selectors
Property on a policy assignment that limits evaluation to particular resource types or locations, such as just VMs located in East US.
- Scope
Where an access or policy assignment takes effect. It can be set on a single resource, a resource group, a subscription or a management group, and settings flow down from higher levels.
- Set-AzPolicyAssignment
PowerShell cmdlet in Az for changing a policy assignment that already exists, such as its identity or display name. Creating a new assignment uses New-AzPolicyAssignment.