Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planEasy
A multinational corporation needs to ensure that all Azure resources deployed within specific subscriptions are located only in approved geographic regions (e.g., 'East US 2', 'West Europe'). Any attempt to deploy resources outside these approved regions should be prevented. Which Azure service should the DevOps team use to enforce this geographical restriction?
- AAzure Policy with an 'Allowed locations' definition
- BAzure Resource Locks
- CAzure Advisor recommendations
- DAzure Cost Management
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Policy with an 'Allowed locations' definition
Azure Policy with an 'Allowed locations' definition is the precise tool for enforcing geographical constraints on resource deployments. It prevents the creation of resources in unapproved regions.
Why the other options are wrong
- B. Resource Locks prevent deletion or modification of resources but do not restrict their initial deployment location.
- C. Azure Advisor provides recommendations for best practices but does not enforce policies.
- D. Azure Cost Management helps track and optimize spending but does not enforce deployment locations.
Azure Policy Allowed Locations
An Azure Policy definition that restricts the Azure regions where resources can be deployed within a specific scope.
- Prevents deployment outside specified regions.
- Enforces compliance with data residency requirements.
- Applies at management group, subscription, or resource group scope.
Memory trick: Policy sets the geopolitical fence; no resources outside the allowed zones.