Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium

A company has several Azure subscriptions, and they want to ensure consistent naming conventions for all resource groups across these subscriptions. Specifically, all resource groups must start with the prefix 'rg-' followed by the environment name (e.g., 'prod', 'dev', 'test') and then a descriptive name. Any attempt to create a resource group that does not follow this convention should be blocked. Which Azure feature should be implemented?

  1. AAzure Blueprints
  2. BAzure Management Groups with custom naming tags
  3. CAzure Policy with a 'Deny' effect
  4. DAzure Resource Graph queries with alerts
Show answer & explanation

Correct answer: C. Azure Policy with a 'Deny' effect

Azure Policy with a 'Deny' effect is the correct solution. You can create a policy definition that uses a regular expression to enforce the naming convention for resource groups. If a resource group creation request violates this policy, the 'Deny' effect will block the operation, ensuring strict compliance.

Why the other options are wrong

  • A. Azure Blueprints can deploy resources and assign policies, but for *enforcing* a naming convention and *blocking* non-compliant deployments across existing and new resource groups, Azure Policy is the direct and continuous enforcement mechanism.
  • B. Azure Management Groups help organize subscriptions, and while tags can be used for classification, they do not enforce naming conventions or block non-compliant resource creation.
  • D. Azure Resource Graph queries are for exploring and querying existing resources, not for enforcing policies or blocking resource creations.

Azure Policy (Naming Convention Enforcement)

Azure Policy enables the enforcement of organizational standards and assessment of compliance for Azure resources, including defining and blocking resource deployments that do not adhere to specific naming conventions.

  • Uses policy definitions with rules and parameters.
  • The 'Deny' effect blocks non-compliant resource creation/updates.
  • Can use regular expressions for complex naming patterns.
  • Can be assigned at various scopes (management group, subscription, resource group).

Memory trick: Policy is the strict editor that blocks any misnamed resource.

More Manage Azure identities and governance questions