What is Azure Policy?
Azure Policy is a governance service that enforces organizational standards and compliance requirements in Azure. Policies define rules that are evaluated when resources are created or updated, preventing or reporting violations.
The service enables central definition of policies that are automatically applied to all subscriptions and resource groups.
Core Features
- Policy definitions in JSON for any resource properties
- Initiatives for grouping multiple policies
- Compliance dashboard with real-time assessment
- Remediation tasks for automatic correction of violations
- Policy exemptions for justified exceptions
- Integration with Azure Blueprints for comprehensive governance
Typical Use Cases
Tagging enforcement: Ensuring all resources are created with required tags (CostCenter, Owner, Environment).
Location restrictions: Restricting resource deployment to approved regions for data residency compliance.
Security baseline: Enforcing security settings like TLS 1.2, encryption, or NSG rules across all resources.
Benefits
- Free service for all Azure customers
- Proactive prevention of policy violations
- Automatic correction of existing non-compliant resources
- Audit trail for compliance evidence
Frequently Asked Questions
What does Azure Policy cost?
Azure Policy is free for all Azure customers. There are no additional costs for policy evaluations or remediation tasks.
What is the difference between Deny and Audit?
Deny blocks creating or modifying a non-compliant resource. Audit allows the action but creates a compliance entry for reporting purposes.
Can I create custom policies?
Yes, custom policies can be defined in JSON. You can check any property of an Azure resource. Microsoft also provides over 100 built-in policies as templates.
How do remediation tasks work?
Remediation tasks use Managed Identities to automatically adjust existing non-compliant resources. You can define which properties should be corrected.
Integration with innFactory
As a Microsoft Solutions Partner, innFactory supports you with Azure Policy: governance strategy, policy development, compliance reporting, and remediation.
