Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceHard
A global consulting firm uses Azure to host various client projects. They need to ensure that all resources deployed for a specific client project adhere to a common set of security configurations, region restrictions, and naming conventions. These standards must be enforced automatically upon resource creation and continuously audited for compliance. Which Azure governance feature should they implement to achieve this?
- AAzure Policy
- BAzure Management Groups
- CAzure Resource Groups
- DAzure Blueprints
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Policy
Azure Policy helps enforce organizational standards and assess compliance at scale. It can enforce rules like permitted locations, allowed resource types, and naming conventions, automatically applying these rules during resource creation and continuously auditing existing resources for compliance.
Why the other options are wrong
- B. Azure Management Groups are used to organize subscriptions hierarchically, applying governance at a broader scope, but Azure Policy is the specific service used to define and enforce the rules themselves.
- C. Azure Resource Groups are logical containers for resources, primarily for organization and lifecycle management, not for enforcing policy rules or continuous compliance auditing.
- D. Azure Blueprints orchestrates the deployment of standardized environments including policies, but Azure Policy itself is the underlying mechanism for enforcing and auditing those rules continuously.
Azure Policy
A service that helps you enforce organizational standards and to assess compliance at scale. It defines rules for your Azure resources to ensure they meet specified requirements.
- Enforces organizational standards
- Assesses compliance at scale
- Supports rules for resource creation and updates
- Continuous compliance auditing
Memory trick: Policy: 'police' for your Azure resources.