Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium

A company has a multi-subscription Azure environment managed under a single management group. They want to ensure that all new virtual machines deployed in any subscription within this management group automatically have a specific Azure Monitor Log Analytics workspace configured for diagnostic logging. What is the most efficient way to achieve this consistent configuration across all future deployments?

  1. AManually configure the Log Analytics workspace for each new VM.
  2. BUse an Azure Resource Manager (ARM) template for each VM deployment.
  3. CAssign the 'Log Analytics Contributor' role to all users deploying VMs.
  4. DCreate an Azure Policy with a 'DeployIfNotExists' effect.
Show answer & explanation

Correct answer: D. Create an Azure Policy with a 'DeployIfNotExists' effect.

An Azure Policy with a 'DeployIfNotExists' (DINE) effect can automatically deploy or configure resources, such as linking VMs to a Log Analytics workspace, if they are missing after a resource creation or update. Assigning this at the management group level ensures consistent application across all subscriptions.

Why the other options are wrong

  • A. Manual configuration is inefficient and prone to human error, especially in a large multi-subscription environment.
  • B. ARM templates define resources at deployment time but don't enforce post-deployment configuration on resources deployed outside the template or ensure consistency across all future deployments without specific processes.
  • C. Assigning a role provides permissions but does not automate the configuration of Log Analytics workspaces for new VMs.

Azure Policy 'DeployIfNotExists' (DINE)

An Azure Policy effect that audits for non-compliance and then automatically deploys a specified template as a remediation within the scope of the policy assignment.

  • Automates resource deployment or configuration.
  • Ensures compliance with desired state after resource creation/update.
  • Can be assigned at various scopes (management group, subscription, resource group).

Memory trick: Policy is the robot that makes sure every VM gets its monitoring gear.

More Manage Azure identities and governance questions