Azure Policy is a service that helps you enforce organizational standards and assess compliance at scale. Where role-based access control (RBAC) controls who can do something, Azure Policy controls what can be created and how resources must be configured, no matter who is doing it, even an Owner. For example, a policy can allow resources only in certain regions to meet data-residency rules, require a tag on every resource group, allow only specific VM sizes to control cost, or require that storage accounts accept only HTTPS traffic. It is one of the core governance tools on the exam, alongside management groups, locks and tags.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.