Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium
A company wants to ensure that all virtual machines (VMs) deployed in a specific Azure subscription are automatically configured with a particular network security group (NSG). This NSG must be applied to every new VM's network interface upon creation. Which Azure Policy effect should be used to achieve this automatic configuration?
- AModify
- BDeployIfNotExists
- CDeny
- DAudit
Show answer & explanationAnswer & explanation
Correct answer: B. DeployIfNotExists
The 'DeployIfNotExists' (DINE) effect in Azure Policy is designed to deploy a resource or template when a condition is met and the target resource does not exist. In this scenario, it can deploy the NSG association if a VM is created without the specified NSG.
Why the other options are wrong
- A. Modify is used to add, update, or remove properties or tags on a resource during creation or update, but DINE is more suitable for deploying a related resource like an NSG.
- C. Deny would prevent VM creation if the NSG is not present, not automatically add it.
- D. Audit would only report non-compliance, not automatically configure the NSG.
Azure Policy DeployIfNotExists (DINE)
An Azure Policy effect that automatically deploys a resource or template if a specified condition is met and the target resource does not exist.
- Used for ensuring compliance by automatically deploying missing resources.
- Requires a deployment template within the policy definition.
- Evaluates after a resource is created or updated.
Memory trick: If it's not there, DINE will make it appear.