Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planMedium
A global enterprise is migrating its legacy applications to Azure. They need to ensure that all Azure resources deployed within specific subscriptions are tagged with 'CostCenter' and 'Environment' tags. Furthermore, if these tags are missing or have non-compliant values, the resources should automatically be updated to include the correct tags. Which Azure service should the DevOps team use to implement this tagging strategy?
- AAzure Policy with a DeployIfNotExists effect
- BAzure Resource Health
- CAzure Monitor
- DAzure Security Center
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Policy with a DeployIfNotExists effect
Azure Policy with a DeployIfNotExists effect is specifically designed to audit for non-compliance and then automatically deploy or modify resources to bring them into compliance, such as applying required tags with specific values.
Why the other options are wrong
- B. Azure Resource Health provides information about the health of Azure resources, not for enforcing policy or tagging.
- C. Azure Monitor collects telemetry and provides insights into resource performance and health, but does not enforce resource configuration like tagging.
- D. Azure Security Center (now Defender for Cloud) focuses on security posture management and threat protection, not automatic resource tagging.
Azure Policy DeployIfNotExists
An Azure Policy effect that audits for non-compliant resources and, if non-compliant, deploys a specified ARM template to remediate the resource.
- Audits for missing or non-compliant configurations.
- Automatically deploys or modifies resources to comply.
- Used for enforcing standards like tagging, network settings, etc.
Memory trick: Policy's DeployIfNotExists ensures tags are always there, like a diligent robot.