Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium

A company wants to ensure that all Azure virtual machines (VMs) deployed in a specific subscription (Subscription-Prod) are configured with a minimum of 8 GB of RAM and are located in the 'East US 2' region. Any VM deployment that does not meet these criteria should be prevented. Which Azure governance feature should be used to enforce these rules?

  1. AAzure Advisor
  2. BAzure Policy
  3. CAzure Resource Locks
  4. DAzure Monitor
Show answer & explanation

Correct answer: B. Azure Policy

Azure Policy is designed for enforcing organizational standards and assessing compliance. You can create policy definitions with 'deny' effects to prevent the creation of VMs that do not meet the specified RAM size or region requirements, ensuring that all deployed VMs adhere to the company's standards.

Why the other options are wrong

  • A. Azure Advisor provides recommendations for optimizing Azure deployments but does not enforce rules or prevent non-compliant deployments.
  • C. Azure Resource Locks prevent accidental deletion or modification of resources but do not enforce configuration standards during creation.
  • D. Azure Monitor collects and analyzes telemetry data but does not enforce resource configuration rules at deployment time.

Azure Policy for VM Configuration

Azure Policy can enforce specific configuration requirements for virtual machines, such as minimum RAM size or allowed deployment regions, by denying non-compliant deployments.

  • Uses 'deny' effect to block non-compliant VMs.
  • Can target various VM properties (SKU, image, location).
  • Ensures standardization and compliance at scale.

Memory trick: Policy is the blueprint police for your VMs.

More Manage Azure identities and governance questions