Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium
A global organization has multiple Azure subscriptions structured under a top-level Management Group. They want to enforce a policy that automatically deploys a specific Azure Monitor Log Analytics workspace to any new resource group created within these subscriptions if one doesn't already exist. Which Azure Policy effect should be used to achieve this?
- ADeployIfNotExists
- BModify
- CDeny
- DAuditIfNotExists
Show answer & explanationAnswer & explanation
Correct answer: A. DeployIfNotExists
The 'DeployIfNotExists' (DINE) effect is perfectly suited for this scenario. It evaluates if a specific resource (the Log Analytics workspace) exists within the scope of a new resource group. If it doesn't, the policy automatically deploys the defined resource.
Why the other options are wrong
- B. Modify is used to add, update, or remove properties or tags on an existing resource, not to deploy a new, related resource.
- C. Deny would prevent the creation of the resource group if the Log Analytics workspace is not present, which is not the goal.
- D. AuditIfNotExists would only report non-compliance if the Log Analytics workspace is missing, it wouldn't deploy it.
Azure Policy DeployIfNotExists (DINE)
An Azure Policy effect that automatically deploys a specified resource or template when a condition is met and the target resource does not exist.
- Used to ensure foundational resources are always present.
- Requires a deployment template within the policy definition.
- Evaluates after a resource (e.g., Resource Group) is created or updated.
Memory trick: If it's not there, DINE will make it appear.