Microsoft Certified: Azure Security Engineer AssociateManage security operationsHard

A security administrator needs to ensure that all virtual machines deployed in a specific Azure subscription automatically have Microsoft Defender for Cloud's endpoint protection solution (e.g., Microsoft Defender for Endpoint) enabled. This must be enforced without requiring manual configuration by developers. Which Azure Policy definition effect, when combined with a Defender for Cloud recommendation, is best suited to achieve this continuous enforcement?

  1. AModify
  2. BDeny
  3. CDeployIfNotExists
  4. DAuditIfNotExists
Show answer & explanation

Correct answer: C. DeployIfNotExists

The 'DeployIfNotExists' Azure Policy effect is specifically designed for scenarios where you need to automatically deploy a resource (like a security extension for endpoint protection) if a condition (e.g., a VM is created without it) is met. This ensures continuous enforcement and compliance without manual intervention.

Why the other options are wrong

  • A. Modify is used to add or update properties on existing resources or during creation; while it could potentially configure *existing* settings, DeployIfNotExists is more direct for ensuring a *missing* component is added.
  • B. Deny would prevent the creation of any VM that does not already have the endpoint protection, which is too restrictive for an 'auto-enable' requirement.
  • D. AuditIfNotExists would only report non-compliance if the endpoint protection is missing; it would not automatically enable or deploy it.

Azure Policy DeployIfNotExists

An Azure Policy effect that automatically deploys a resource or template if the absence of that resource or a specific configuration is detected.

  • Used for automated remediation of non-compliant resources.
  • Requires a managed identity to perform deployments.
  • Essential for ensuring continuous compliance and security baselines.

Memory trick: If it's 'not there', the policy 'deploys' it.

More Manage security operations questions