Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceMedium

A software development company is using Azure DevOps for their CI/CD pipelines. They want to ensure that all deployed Azure resources automatically adhere to internal security standards, such as requiring all storage accounts to enforce HTTPS-only access and all virtual machines to be deployed with specific antivirus extensions. Which Azure governance feature allows them to define and enforce these rules at scale?

  1. AAzure Management Groups
  2. BAzure Resource Locks
  3. CAzure Policy
  4. DAzure Blueprints
Show answer & explanation

Correct answer: C. Azure Policy

Azure Policy enables organizations to create, assign, and manage policies that enforce rules over their Azure resources. It can ensure that resources comply with corporate standards and service level agreements, such as requiring HTTPS-only for storage accounts or specific VM extensions.

Why the other options are wrong

  • A. Azure Management Groups help organize subscriptions for hierarchical policy and access management, but Policy is the direct enforcement tool.
  • B. Azure Resource Locks prevent accidental deletion or modification, not for enforcing configuration standards.
  • D. Azure Blueprints packages policies, ARM templates, and other artifacts for repeatable deployments, but Policy is the enforcement mechanism.

Azure Policy

A service in Azure that helps enforce organizational standards and assess compliance at scale. It defines rules that resources must follow, ensuring they adhere to business requirements.

  • Enforces rules and effects on Azure resources.
  • Can be applied at various scopes (subscription, resource group, management group).
  • Provides compliance reporting.

Memory trick: Policy is the rulebook that resources must follow.

More Describe Azure management and governance questions