Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium
A company has a multi-subscription Azure environment managed under a single management group. They want to ensure that all new virtual machines deployed in any subscription within this management group automatically have a specific Azure Monitor Log Analytics workspace configured for diagnostic logging. What is the most efficient way to achieve this consistent configuration across all future deployments?
- AManually configure the Log Analytics workspace for each new VM.
- BUse an Azure Resource Manager (ARM) template for each VM deployment.
- CAssign the 'Log Analytics Contributor' role to all users deploying VMs.
- DCreate an Azure Policy with a 'DeployIfNotExists' effect.
Show answer & explanationAnswer & explanation
Correct answer: D. Create an Azure Policy with a 'DeployIfNotExists' effect.
An Azure Policy with a 'DeployIfNotExists' (DINE) effect can automatically deploy or configure resources, such as linking VMs to a Log Analytics workspace, if they are missing after a resource creation or update. Assigning this at the management group level ensures consistent application across all subscriptions.
Why the other options are wrong
- A. Manual configuration is inefficient and prone to human error, especially in a large multi-subscription environment.
- B. ARM templates define resources at deployment time but don't enforce post-deployment configuration on resources deployed outside the template or ensure consistency across all future deployments without specific processes.
- C. Assigning a role provides permissions but does not automate the configuration of Log Analytics workspaces for new VMs.
Azure Policy 'DeployIfNotExists' (DINE)
An Azure Policy effect that audits for non-compliance and then automatically deploys a specified template as a remediation within the scope of the policy assignment.
- Automates resource deployment or configuration.
- Ensures compliance with desired state after resource creation/update.
- Can be assigned at various scopes (management group, subscription, resource group).
Memory trick: Policy is the robot that makes sure every VM gets its monitoring gear.