Skip to main content

Overview

Azure Policy enforces compliance on Azure resources at the resource provider level. Policies evaluate resource properties during creation, updates, and on a regular compliance cycle, ensuring resources meet organizational standards.

Capabilities

  • Enforce compliance at the Azure subscription or management group level
  • Multiple effects: Deny, Audit, Modify, Append, DeployIfNotExists, AuditIfNotExists, DenyAction, and Disabled
  • Built-in and custom policy definitions
  • Initiative (policy set) grouping for compliance standards

Limitations

Generated Format

  • Language: JSON
  • Structure: Azure Policy definition with policyRule containing if/then conditions
  • Execution: Applied via Azure Portal, CLI, ARM templates, Bicep, Terraform, or REST API

Example Guardrail

Learn more at Azure Policy documentation and policy definition structure.