Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium

A company policy requires that all Azure resources deployed into a specific subscription must be tagged with 'Department' and 'CostCenter'. If these tags are missing, the resource creation should be prevented. Which Azure governance feature should be implemented to enforce this policy?

  1. AAzure Blueprints
  2. BManagement Groups
  3. CAzure Resource Locks
  4. DAzure Policy
Show answer & explanation

Correct answer: D. Azure Policy

Azure Policy is the correct service for enforcing organizational standards and assessing compliance. It can define rules that prevent resource creation if specific tags are missing, directly addressing the requirement.

Why the other options are wrong

  • A. Azure Blueprints package and deploy standardized environments, but Azure Policy is the underlying mechanism for enforcing specific rules like mandatory tagging.
  • B. Management Groups provide a way to organize subscriptions into containers for applying governance at scale, but Azure Policy is the tool that defines the actual governance rules.
  • C. Azure Resource Locks prevent accidental deletion or modification of resources, but do not enforce tagging during creation.

Azure Policy

A service in Azure that enables organizations to create, assign, and manage policies to enforce rules and effects over their Azure resources, ensuring compliance with corporate standards and service level agreements.

  • Enforces rules and effects on resources.
  • Can audit, deny, modify, or deploy if not compliant.
  • Supports tag enforcement, resource type restrictions, etc.

Memory trick: Policies are the rules of the Azure land, enforced by the Azure Guard.

More Manage Azure identities and governance questions