Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceHard
A company wants to ensure that all Azure resources deployed within a specific subscription are tagged with 'CostCenter' and 'Environment'. If a resource is deployed without these tags, it should be automatically assigned a default value for 'CostCenter' and 'Environment'. Which Azure Policy effect should be used?
- AModify
- BAppend
- CDeny
- DAudit
Show answer & explanationAnswer & explanation
Correct answer: A. Modify
The 'Modify' effect in Azure Policy is designed to update existing properties or add new ones to resources during creation or update. It can be used to add or update tags if they are missing or have incorrect values, making it suitable for automatically assigning default tag values.
Why the other options are wrong
- B. Append is deprecated and has been replaced by Modify for most scenarios, especially for tags. Modify is more flexible for updating existing properties.
- C. Deny blocks the deployment of non-compliant resources, which is not the goal here (we want to fix, not block).
- D. Audit only reports non-compliance, it does not modify resources.
Azure Policy 'Modify' Effect
An Azure Policy effect that allows you to add, update, or remove properties on a resource during deployment or update. It is commonly used for enforcing tagging standards by automatically adding missing tags or updating existing ones.
- Used to change properties of a resource
- Can add or update tags
- Runs during resource creation or update
- Requires a managed identity for remediation of existing resources
Memory trick: Modify policies act like an editor, fixing missing tags.