Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceHard

A multinational corporation has several Azure subscriptions organized under a top-level management group. They want to ensure that all virtual networks (VNets) deployed across these subscriptions automatically have DDoS Protection Standard enabled. Additionally, they need to prevent users from accidentally deleting critical networking resources like virtual networks and public IP addresses. Which combination of Azure features should be implemented?

  1. AAzure Blueprints for both DDoS Protection and resource deletion prevention.
  2. BAzure AD Conditional Access for resource deletion and Azure Policy for DDoS Protection.
  3. CManual configuration of DDoS Protection and custom RBAC roles for resource deletion.
  4. DAzure Policy with a 'DeployIfNotExists' effect for DDoS Protection and Azure Resource Locks for deletion prevention.
Show answer & explanation

Correct answer: D. Azure Policy with a 'DeployIfNotExists' effect for DDoS Protection and Azure Resource Locks for deletion prevention.

Azure Policy with a 'DeployIfNotExists' effect can automatically enable DDoS Protection Standard for new VNets. Azure Resource Locks (Delete or ReadOnly) prevent accidental deletion of critical resources. Both can be applied at the management group level for broad enforcement.

Why the other options are wrong

  • A. Azure Blueprints can define a set of policies and locks, but the specific mechanism for automatic DDoS enablement for *new* VNets is a 'DeployIfNotExists' policy, and resource deletion prevention is via Resource Locks, which are components *within* a blueprint or directly assigned.
  • B. Conditional Access manages identity access, not resource configuration or deletion prevention. Azure Policy can enforce DDoS Protection but this option misses deletion prevention.
  • C. Manual configuration is inefficient and does not guarantee compliance. Custom RBAC roles control *who* can delete, but Resource Locks prevent *anyone*, even owners, from deleting without removing the lock.

Azure Policy 'DeployIfNotExists' and Azure Resource Locks

DeployIfNotExists (DINE) is an Azure Policy effect that ensures a resource or configuration exists. Azure Resource Locks prevent accidental deletion or modification of resources.

  • DINE automates post-creation resource configuration.
  • Resource Locks provide an additional layer of protection against accidental changes.
  • Both can be assigned at various scopes, including management groups, for wide enforcement.

Memory trick: Policy builds the shield, Locks secure the gate for networks.

More Manage Azure identities and governance questions