Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planMedium

A large enterprise is migrating its legacy applications to Azure. They need to ensure that all Azure resources (e.g., Virtual Machines, Storage Accounts) are automatically tagged with specific metadata, such as 'CostCenter', 'Owner', and 'Environment', upon creation. This tagging is critical for cost management, resource organization, and compliance auditing. Which Azure service should the DevOps team use to enforce this automatic tagging?

  1. AAzure Service Health
  2. BAzure Policy
  3. CAzure Resource Graph
  4. DAzure Management Groups
Show answer & explanation

Correct answer: B. Azure Policy

Azure Policy can be used to enforce tagging standards. Specifically, a policy with the 'Modify' effect can automatically add or update tags on resources during or after their creation, ensuring consistent and compliant tagging across the Azure environment.

Why the other options are wrong

  • A. Azure Service Health provides personalized guidance and support when Azure service issues affect you, not for resource tagging enforcement.
  • C. Azure Resource Graph is for exploring and querying Azure resources, not for enforcing configurations or tagging.
  • D. Azure Management Groups provide hierarchical organization for subscriptions and apply policies, but Azure Policy is the specific service for defining and enforcing the tagging rules themselves.

Azure Policy Tag Enforcement

Using Azure Policy to automatically add, modify, or audit tags on Azure resources to ensure compliance with organizational tagging standards.

  • Policies can use 'Modify' effect to add/update tags.
  • Can enforce mandatory tags or specific tag values.
  • Essential for cost management, resource organization, and compliance.

Memory trick: Policy is the Auto-Stamper for your Azure Resources!

More Develop a security and compliance plan questions