What Deny, Audit, Append, Modify and DeployIfNotExists do, and when you need a remediation task and managed identity.
From Ultra Transcenders SC-500 by Tony Rough (publishing soon)
The effect in a definition decides what happens when a resource doesn’t comply: block it, report it, change it or deploy something alongside it. Effects that change resources need an identity and a remediation task to fix what already exists. Figure 4.1 shows which effects act at request time and which need a remediation task for existing resources.
| Effect | What it does | Existing resources | Needs managed identity |
|---|---|---|---|
| Deny | Rejects the Resource Manager request, so the resource is never created | Marked noncompliant, not changed | No |
| Audit | Marks a resource noncompliant only if it was allowed to deploy | Reported | No |
| AuditIfNotExists | Checks for a related resource and logs if it’s missing | Reported | No |
| Append | Adds fields to the request at create/update time | Marked noncompliant, not changed | No |
| Modify | Changes properties or tags on the resource itself | Remediation task | Yes |
| DeployIfNotExists | Deploys a template when a related resource (for example a VM extension) is missing on new or updated resources | Marked noncompliant, fixed only by a remediation task | Yes |
roleDefinitionIds. For extensions it needs a role such as Contributor, or the narrower Virtual Machine Contributor. User Access Administrator can’t deploy extensions.Common trap: a database deployed into a resource group that has both a Deny and an Audit assignment is created and then marked noncompliant - the Deny effect blocks the deployment, so no resource exists for Audit to report.
Set-AzContext -Subscription switches to the subscription that holds the assignment.Start-AzPolicyRemediation creates and starts a remediation task. Adding -ResourceDiscoveryMode ReEvaluateCompliance re-scans compliance first.Get-AzPolicyRemediation only reads tasks, Start-AzPolicyComplianceScan only triggers an evaluation, and Set-AzResourceGroup only changes resource group tags.This note is one section of Ultra Transcenders SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Publishing soon on Amazon in Kindle and paperback editions.
About the book · Free SC-500 glossary · All SC-500 study notes
How PIM activation, approval, maximum duration and notifications work, and what each role setting controls.
How a Conditional Access policy is built and how multiple policies combine.
Why control-plane roles can't read secrets, and which Key Vault role or access policy each task needs.
Account keys, account and service SAS, user delegation SAS and Entra RBAC compared by scope and revocability.
Where each Azure SQL data protection feature works and who it protects data from.
How security admin rules are evaluated before NSGs, and when to use Allow, Deny or Always allow.
How JIT locks management ports and opens them on request, with the plan and permissions it needs.