Key-value label on compute (for cost tracking) or on a Unity Catalog securable or column, applied with SET TAG or SET TAGS and requiring APPLY TAG. Governed tags restrict allowed keys, values and assigners across the account.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Tag in context, with comparison tables and the common traps.
Terms in this definition
- Route table label
Name for a set of route tables in Virtual WAN hubs, used when choosing where routes propagate; Default, for instance, covers the defaultRouteTable of every hub.
- Unity Catalog
Azure Databricks' governance solution covering both data and AI in one place, with centralised permissions, auditing, data discovery and lineage.
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- Image tagging
An Image Analysis feature producing single-word tags, each with a confidence score, for actions, scenery, objects and living things in an image.
- APPLY
Evaluates a table-valued expression for every row on its left, inside
FROM. Think ofOUTER APPLYas a left outer join andCROSS APPLYas an inner join. - Governed tags
Tags defined at account level and controlled by a tag policy that sets permitted values and who can apply them. Catalogs and schemas pass them down to child objects (columns do not inherit them), and ABAC policies use them as the attributes to match.
- VALUES
Returns in DAX the distinct column values, or table rows, still visible after filters are applied, sometimes with an extra blank entry. CALCULATE often takes the result as a table filter.
Related terms
- acr purge
A container command, currently in preview, that runs as an ACR task either on demand or on a schedule. It removes tags matching a repository and tag regex once they pass a given age, can also clear untagged manifests, and anything it deletes is gone for good.
- Administrative (Activity log category)
Category of Activity log entries covering every create, update, delete and action call made via Resource Manager, for example adding a tag, attaching a disk or creating a resource group.
- Append a tag and its value to resources
Append-effect built-in policy that adds a tag whenever a resource is created or updated, leaving tags users set intact. Resource groups are not covered.
- Authentication context
A Conditional Access tag placed on just one sensitive area or action within an app (a particular SharePoint site, say, or activating a PIM role), so tougher sign-in conditions apply there without covering everything else in the app.
- Auto-generate release notes
An option when creating a GitHub release that lists what changed since the previous release's tag; a
.github/release.ymlfile can tailor the output. - Azure ABAC
Attribute-based conditions added on top of Azure RBAC role assignments, such as granting access only to blobs carrying a certain index tag. Blobs (ADLS Gen2 included) and queues support them; Azure Files and Tables do not.
- Azure Instance Metadata Service
Endpoint at the non-routable address 169.254.169.254, reachable only from within a VM, that returns metadata about the VM and issues managed identity tokens. An outbound NSG rule denying the AzurePlatformIMDS tag cuts off access.
- Budgets
In Cost Management, spending limits you can scope and filter by tag, which raise alerts when actual or forecast spend nears or passes them.