A JSON rule expressing a compliance condition as if/then logic with an effect, plus parameters and metadata. Nothing happens until it is assigned, and the category it carries is purely metadata.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Policy definition in context, with comparison tables and the common traps.
Terms in this definition
- JSON
Text-based format for structured data. ARM templates and Cosmos DB documents are written in it, and most Azure REST APIs exchange request and response bodies as application/json.
- Metadata
Describes data rather than being the data itself, for instance how a file is laid out or what rows each chunk contains, so tools can read things efficiently.
Related terms
- Definition location
Where a policy definition or initiative is saved, either a management group or a subscription. Assignments can only be made beneath that point in the hierarchy, which is why widely used definitions should sit high up.
- Definition version
Lets an initiative or assignment lock to a specific release of a policy definition. If none is chosen, the newest major release is used and minor updates flow in automatically.
- Get-AzPolicyDefinition
Cmdlet in Az.Resources that fetches a policy definition, for instance using
-Name, so it can be handed toNew-AzPolicyAssignment. - New-AzPolicyAssignment
Cmdlet that applies a policy definition (
-PolicyDefinition) at a chosen scope (-Scope, for example a resource group's ResourceId). To change an assignment that already exists, use Set-AzPolicyAssignment. - New-AzPolicyDefinition
Cmdlet that creates a policy definition without assigning it anywhere; Set-AzPolicyDefinition is used to change one.
- Policy assignment
What makes a policy definition or initiative take effect: it targets a management group, subscription or resource group, supplies parameter values, exclusions, an enforcement mode and non-compliance messages, and starts a compliance scan.
- roleDefinitionIds
Array within the details of a Modify or DeployIfNotExists policy definition giving the full IDs of roles the assignment's managed identity requires for remediation. Only the portal grants them automatically.
- Set-AzPolicyDefinition
PowerShell cmdlet in Az for changing an existing policy definition. Assigning it is a separate step.