Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium

A company has several Azure subscriptions, and they want to ensure that all resources deployed within these subscriptions are tagged with 'CostCenter' and 'Environment'. These tags are crucial for cost management and resource organization. They need a solution that automatically adds these tags if they are missing or updates them if they have incorrect values, without preventing resource deployment. Which Azure Policy effect should they use?

  1. AModify
  2. BDeployIfNotExists
  3. CAudit
  4. DDeny
Show answer & explanation

Correct answer: A. Modify

The 'Modify' effect in Azure Policy is specifically designed to add, update, or remove properties or tags on a resource during creation or update. This allows for automatic tag enforcement without blocking deployments.

Why the other options are wrong

  • B. DeployIfNotExists is for deploying entirely new resources, not for modifying properties or tags of an existing or newly created resource itself.
  • C. Audit would only report non-compliance, not automatically fix the tags.
  • D. Deny would prevent resource creation if tags are missing or incorrect, which is not the desired outcome.

Azure Policy Modify Effect

An Azure Policy effect used to add, update, or remove properties or tags on a resource during creation or update, ensuring compliance without blocking resource deployment.

  • Ideal for enforcing naming conventions, tagging standards, and property settings.
  • Can apply default values or enforce specific values.
  • Evaluates before a resource is created or updated.

Memory trick: To fix or add a tag, Modify is the flag.

More Manage Azure identities and governance questions