Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceHard

A company is implementing a new Azure subscription for a project. They need to ensure that all virtual machines deployed in this subscription are automatically configured with a specific custom DNS server IP address. Additionally, this configuration should be immutable for all existing and newly deployed VMs. Which combination of Azure governance features should be used?

  1. AAzure Management Groups for scope and Azure AD PIM for access
  2. BAzure Policy for network configuration and Azure Resource Locks
  3. CAzure Blueprints for VM deployment and Azure Policy for enforcement
  4. DAzure Network Watcher for monitoring and Azure Security Center for recommendations
Show answer & explanation

Correct answer: B. Azure Policy for network configuration and Azure Resource Locks

Azure Policy can be used to audit or modify network configurations, such as DNS server settings, for VMs. A 'DeployIfNotExists' policy can automatically apply the custom DNS. Azure Resource Locks (specifically 'CanNotDelete' or 'ReadOnly') can then be applied to prevent changes to these network interfaces or VMs, making the configuration immutable.

Why the other options are wrong

  • A. Management Groups define scope, and PIM manages privileged access, neither directly enforces or immutabilizes VM network configurations.
  • C. Blueprints deploy environments, but Policy directly enforces configurations and locks ensure immutability. Blueprints can include policies, but the core tools for this specific scenario are Policy and Locks.
  • D. Network Watcher and Security Center are for monitoring and recommendations, not for enforcing and immutability of configurations.

Azure Policy + Azure Resource Locks

Combining Azure Policy to enforce desired configurations (like DNS settings) and Azure Resource Locks to prevent their modification, thereby achieving immutable and compliant resource configurations.

  • Azure Policy defines and enforces rules (e.g., 'DeployIfNotExists' for DNS)
  • Resource Locks prevent deletion or read-only modification
  • Ensures configuration compliance and immutability

Memory trick: Policy sets the rules, Locks bolt them down.

More Manage Azure identities and governance questions