Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium

A company wants to ensure that all virtual machines (VMs) deployed in a specific Azure subscription are automatically configured with a particular network security group (NSG). This NSG must be applied to every new VM's network interface upon creation. Which Azure Policy effect should be used to achieve this automatic configuration?

  1. AModify
  2. BDeployIfNotExists
  3. CDeny
  4. DAudit
Show answer & explanation

Correct answer: B. DeployIfNotExists

The 'DeployIfNotExists' (DINE) effect in Azure Policy is designed to deploy a resource or template when a condition is met and the target resource does not exist. In this scenario, it can deploy the NSG association if a VM is created without the specified NSG.

Why the other options are wrong

  • A. Modify is used to add, update, or remove properties or tags on a resource during creation or update, but DINE is more suitable for deploying a related resource like an NSG.
  • C. Deny would prevent VM creation if the NSG is not present, not automatically add it.
  • D. Audit would only report non-compliance, not automatically configure the NSG.

Azure Policy DeployIfNotExists (DINE)

An Azure Policy effect that automatically deploys a resource or template if a specified condition is met and the target resource does not exist.

  • Used for ensuring compliance by automatically deploying missing resources.
  • Requires a deployment template within the policy definition.
  • Evaluates after a resource is created or updated.

Memory trick: If it's not there, DINE will make it appear.

More Manage Azure identities and governance questions