Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium

A global organization has multiple Azure subscriptions structured under a top-level Management Group. They want to enforce a policy that automatically deploys a specific Azure Monitor Log Analytics workspace to any new resource group created within these subscriptions if one doesn't already exist. Which Azure Policy effect should be used to achieve this?

  1. ADeployIfNotExists
  2. BModify
  3. CDeny
  4. DAuditIfNotExists
Show answer & explanation

Correct answer: A. DeployIfNotExists

The 'DeployIfNotExists' (DINE) effect is perfectly suited for this scenario. It evaluates if a specific resource (the Log Analytics workspace) exists within the scope of a new resource group. If it doesn't, the policy automatically deploys the defined resource.

Why the other options are wrong

  • B. Modify is used to add, update, or remove properties or tags on an existing resource, not to deploy a new, related resource.
  • C. Deny would prevent the creation of the resource group if the Log Analytics workspace is not present, which is not the goal.
  • D. AuditIfNotExists would only report non-compliance if the Log Analytics workspace is missing, it wouldn't deploy it.

Azure Policy DeployIfNotExists (DINE)

An Azure Policy effect that automatically deploys a specified resource or template when a condition is met and the target resource does not exist.

  • Used to ensure foundational resources are always present.
  • Requires a deployment template within the policy definition.
  • Evaluates after a resource (e.g., Resource Group) is created or updated.

Memory trick: If it's not there, DINE will make it appear.

More Manage Azure identities and governance questions