Azure Policy enforces rules about what resources may look like, while role-based access control (RBAC) controls who may act. RBAC answers 'can Ana create a VM?'; Policy answers 'is this VM, in this region, with these tags and this size, allowed to exist?'. Policy applies even to Owners, which is what makes it a governance tool rather than a permission system. Organizations use it to keep data in approved regions, require tags for cost reporting, restrict expensive VM sizes and make sure monitoring or security settings are always present.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.