FREE STUDY NOTES · SC-500

Azure Policy effects and remediation tasks

What Deny, Audit, Append, Modify and DeployIfNotExists do, and when you need a remediation task and managed identity.

From Ultra Transcenders SC-500 by Tony Rough (publishing soon)

The effect in a definition decides what happens when a resource doesn’t comply: block it, report it, change it or deploy something alongside it. Effects that change resources need an identity and a remediation task to fix what already exists. Figure 4.1 shows which effects act at request time and which need a remediation task for existing resources.

A three-column chart lists the six effects Deny, Append, Audit, AuditIfNotExists, Modify and DeployIfNotExists, and shows what each one does when a resource is requested. It also shows that Deny, Append, Audit and AuditIfNotExists report existing resources as noncompliant without changing them, and Modify and DeployIfNotExists need a remediation task that runs as the policy assignment's managed identity with the roles in roleDefinitionIds.
Figure 4.1: What each Azure Policy effect does to a new or updated resource and to resources that already exist
Effect What it does Existing resources Needs managed identity
Deny Rejects the Resource Manager request, so the resource is never created Marked noncompliant, not changed No
Audit Marks a resource noncompliant only if it was allowed to deploy Reported No
AuditIfNotExists Checks for a related resource and logs if it’s missing Reported No
Append Adds fields to the request at create/update time Marked noncompliant, not changed No
Modify Changes properties or tags on the resource itself Remediation task Yes
DeployIfNotExists Deploys a template when a related resource (for example a VM extension) is missing on new or updated resources Marked noncompliant, fixed only by a remediation task Yes

Deny in practice

Common trap: a database deployed into a resource group that has both a Deny and an Audit assignment is created and then marked noncompliant - the Deny effect blocks the deployment, so no resource exists for Audit to report.

Remediation in PowerShell

Get the whole book

This note is one section of Ultra Transcenders SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Publishing soon on Amazon in Kindle and paperback editions.

About the book · Free SC-500 glossary · All SC-500 study notes

More SC-500 study notes