Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium

A company wants to ensure that all Azure virtual machines (VMs) deployed in a specific subscription have a particular tag, 'Owner', populated with the name of the deploying user. If the 'Owner' tag is missing or has an incorrect value, the policy should automatically correct it during deployment. Which Azure Policy effect should the company use?

  1. ADeny
  2. BModify
  3. CAudit
  4. DDeployIfNotExists
Show answer & explanation

Correct answer: B. Modify

The 'Modify' effect in Azure Policy is designed to add or update properties and tags on a resource during creation or update. This allows for automatic correction of the 'Owner' tag without preventing the VM deployment.

Why the other options are wrong

  • A. Deny would prevent the VM from being deployed if the 'Owner' tag is missing or incorrect, which is not the desired behavior.
  • C. Audit would only report non-compliance, not automatically fix the tag.
  • D. DeployIfNotExists is for deploying entirely new resources if they are missing, not for modifying properties of a resource being deployed.

Azure Policy Modify Effect

An Azure Policy effect that automatically adds, updates, or removes properties or tags on a resource during creation or update, ensuring compliance without blocking the deployment.

  • Ideal for enforcing tagging standards and property settings.
  • Can apply default values or enforce specific values.
  • Evaluates before a resource is created or updated.

Memory trick: To fix or add a tag, Modify is the flag.

More Manage Azure identities and governance questions