Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium
A global company has multiple Azure subscriptions organized under a management group. They want to ensure that all virtual machines (VMs) deployed in a specific subscription, regardless of who deploys them, automatically have a specific custom tag named 'CostCenter' with a default value of 'Unknown' if the tag is not explicitly provided during deployment. What Azure feature should you use?
- AAzure AD Privileged Identity Management (PIM)
- BAzure Blueprints
- CAzure Policy with a 'Modify' effect
- DAzure Resource Locks
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Policy with a 'Modify' effect
Azure Policy with a 'Modify' effect is designed to add or update tags on resources during or after deployment. This allows you to automatically apply a default 'CostCenter' tag with a value of 'Unknown' to VMs if it's missing, ensuring compliance with tagging requirements.
Why the other options are wrong
- A. PIM manages access to privileged roles and does not deal with resource tagging.
- B. Azure Blueprints help define a repeatable set of Azure resources and policies, but a 'Modify' policy effect is the specific mechanism for automatic tag application.
- D. Resource Locks prevent accidental deletion or modification, but do not add or modify tags automatically.
Azure Policy 'Modify' Effect
The 'Modify' effect in Azure Policy is used to add, update, or remove tags, properties, or resource configurations on existing resources or during resource creation, ensuring compliance with organizational standards.
- Automates remediation of non-compliant resources.
- Can add or update tags and other resource properties.
- Runs after resource creation or through a remediation task.
Memory trick: Azure Policy with 'Modify' is like an 'Auto-Stamper' for your resources, ensuring tags are always there.