Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceHard
A global organization has multiple Azure subscriptions structured under a top-level Management Group. They need to ensure that all virtual machines deployed across these subscriptions are automatically configured with specific diagnostic settings, including sending logs to a central Log Analytics workspace. This configuration should be applied consistently and automatically to any new or existing VM. Which Azure feature should be used?
- AAzure Automation runbooks
- BAzure Policy with a 'DeployIfNotExists' effect
- CAzure Blueprints with custom roles
- DAzure Resource Graph queries
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Policy with a 'DeployIfNotExists' effect
Azure Policy with a 'DeployIfNotExists' (DINE) effect is the ideal solution. It allows you to define a policy that audits for the absence of a specific configuration (like diagnostic settings) and, if missing, automatically deploys the required settings to the resource. This ensures consistent application across all VMs, new or existing, within the defined scope.
Why the other options are wrong
- A. Azure Automation runbooks can configure diagnostics, but they are imperative scripts that need to be scheduled and managed. They don't automatically trigger on new resource creation or continuously enforce settings like Policy.
- C. Azure Blueprints can deploy resources and assign policies, but it's more for initial environment setup. For continuous enforcement and automatic remediation of diagnostic settings on *any* VM, new or existing, Policy with DINE is the direct tool.
- D. Azure Resource Graph queries are for exploring and querying Azure resources, not for enforcing configurations or deploying settings.
Azure Policy DeployIfNotExists (DINE)
The 'DeployIfNotExists' (DINE) effect in Azure Policy audits for the absence of a resource or configuration and, if missing, automatically deploys or remediates the required resource/setting.
- Used for continuous compliance and automatic remediation.
- Requires a managed identity for the policy assignment.
- Ideal for ensuring consistent configurations like diagnostic settings or security baselines.
Memory trick: Policy DINE makes sure no VM is left undiagnosed, automatically.