Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium

A global company uses Azure Active Directory (Azure AD) and has implemented a strict naming convention for all Azure resources. They want to ensure that all new resource groups created adhere to the pattern 'rg-[department]-[environment]-[projectname]'. If a resource group is created that does not follow this pattern, it should be automatically deleted. Which Azure Policy effect should the company use to achieve this?

  1. ADeployIfNotExists
  2. BModify
  3. CDeny
  4. DAudit
Show answer & explanation

Correct answer: C. Deny

The 'Deny' effect is the only Azure Policy effect that can prevent the creation of non-compliant resources. While it won't 'automatically delete' a resource after creation, it will prevent its successful deployment if it doesn't meet the naming convention, effectively achieving the goal of not having non-compliant resource groups.

Why the other options are wrong

  • A. DeployIfNotExists is for deploying missing resources, not for enforcing naming conventions by preventing creation.
  • B. Modify is used to add or update properties/tags, not to prevent creation based on naming conventions.
  • D. Audit would only report non-compliance, allowing the non-compliant resource group to be created.

Azure Policy Deny Effect

An Azure Policy effect that prevents the creation, update, or deletion of resources that do not meet the defined policy rules.

  • Ensures strict compliance with standards.
  • Blocks non-compliant operations.
  • Can be used for naming conventions, allowed locations, SKU restrictions.

Memory trick: If the name's not right, Deny the light.

More Manage Azure identities and governance questions