Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium
A company is implementing Microsoft Defender for Cloud for their Azure environment. They need to ensure that all newly provisioned virtual machines are automatically configured with a specific set of security extensions, including a vulnerability assessment solution. The security team wants this to be enforced across all subscriptions and resource groups without manual intervention. Which Azure Policy effect should they use in conjunction with Defender for Cloud recommendations to achieve this?
- AModify
- BDeny
- CDeployIfNotExists
- DAudit
Show answer & explanationAnswer & explanation
Correct answer: C. DeployIfNotExists
The 'DeployIfNotExists' Azure Policy effect is designed to deploy a resource or template if a specified condition is not met. In this scenario, it can be used to automatically deploy required security extensions to new VMs if they are missing, ensuring compliance without manual intervention.
Why the other options are wrong
- A. The 'Modify' effect is used to add, update, or remove properties or tags on a resource during creation or update. While it can modify properties, 'DeployIfNotExists' is more suitable for deploying a *missing* resource or extension.
- B. The 'Deny' effect prevents resource creation or modification if conditions are not met, which would block VM provisioning if extensions are missing, rather than automatically deploying them.
- D. The 'Audit' effect creates a warning or record of non-compliance but does not enforce or deploy anything automatically.
Azure Policy DeployIfNotExists
An Azure Policy effect that automatically deploys a resource or template when the evaluated condition is true (i.e., the resource is missing or non-compliant).
- Used for automatic remediation and configuration.
- Requires a managed identity for deployment.
- Ensures resources are compliant by deploying missing components.
Memory trick: Policies 'effect' change in different 'ways'.