Governance
CoreAzure Policy
Compliance evaluation, deny/audit/modify/deploy effects, assignments, and initiatives.
Key points
- Definitions evaluate resource properties and specify effects such as audit or deny.
- Assignments establish scope, exclusions, and parameter values.
- Initiatives group definitions into one compliance and assignment unit.
Best-known use cases
- Prevent deployment outside approved regions.
- Report or remediate missing governance settings.
What candidates often confuse it with
- Policy vs RBAC: enforce resource state vs authorize principals.
- Deny vs audit: block a noncompliant request vs permit and report it.
Key takeaway
Use Azure Policy to evaluate or enforce resource configuration across a chosen management scope.
Related services
- Azure resource locks
- Microsoft Cost Management
- Azure Advisor
Relevant exam tasks
- D1.3.S1 — Implement and manage Azure Policy
- D1.3.S2 — Configure resource locks
- D1.3.S6 — Manage costs by using alerts, budgets, and Azure Advisor recommendations