Brings existing non-compliant resources into line under a Modify or DeployIfNotExists policy assignment, acting through the managed identity of that assignment.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104SC-500SC-200AZ-400ALZ
Each book explains Remediation task in context, with comparison tables and the common traps.
Terms in this definition
- Modify
Policy effect in Azure that can add, replace or remove tags and other properties. Resources that already exist are brought into line by running a remediation task.
- DeployIfNotExists
When a related resource is absent, this Azure Policy effect deploys an ARM template to create it. Resources that already exist are corrected only by a remediation task running as the assignment's managed identity.
- Policy assignment
What makes a policy definition or initiative take effect: it targets a management group, subscription or resource group, supplies parameter values, exclusions, an enforcement mode and non-compliance messages, and starts a compliance scan.
- Managed identity
Identity in Microsoft Entra given to an Azure resource so that no secret has to be stored. It comes in two kinds: user-assigned and system-assigned.
Related terms
- Modify effect
With this policy effect, Azure can add, replace or strip tags and other properties. For resources that already exist, a remediation task makes the change, running under the managed identity of the assignment.
- Start-AzPolicyRemediation
Creates a remediation task for an assignment whose effect is Modify or DeployIfNotExists (Az.PolicyInsights). Pass -ResourceDiscoveryMode ReEvaluateCompliance to rescan before remediating.