Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium
A company uses Azure AD and has implemented a strict naming convention for all Azure resources. They want to ensure that all new resource groups created within a specific subscription (Subscription A) automatically adhere to this naming convention, which requires resource group names to start with 'rg-prod-' for production environments. Any attempt to create a resource group that violates this rule should be blocked. Which Azure feature should you use to enforce this naming convention at the time of creation?
- AAzure Resource Locks
- BAzure Policy
- CAzure Blueprints
- DAzure AD Conditional Access
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Policy
Azure Policy is the correct service for enforcing organizational standards and assessing compliance at scale. You can create a policy definition that uses a 'deny' effect to prevent the creation of resource groups whose names do not match a specified pattern, such as 'rg-prod-*'.
Why the other options are wrong
- A. Azure Resource Locks prevent accidental deletion or modification of resources, but they do not enforce naming conventions during creation.
- C. Azure Blueprints orchestrate the deployment of various resource templates and policies, but Azure Policy is the direct mechanism for enforcing the naming rule itself.
- D. Azure AD Conditional Access manages user access to applications based on conditions, unrelated to resource naming conventions.
Azure Policy for Naming
Azure Policy enables the enforcement of naming conventions for resources during their creation, ensuring compliance with organizational standards.
- Uses 'deny' effect to block non-compliant creations.
- Can apply to resource groups, resources, and locations.
- Assesses compliance and provides reporting.
Memory trick: Policy is the rulebook for your Azure kingdom.