StudyToCert

All certifications / SC-500 / Lessons

Microsoft Certified: Cloud and AI Security Engineer Associate (replaces Azure Security Engineer Associate / AZ-500) SC-500 · Domain 1: Manage identity, access, and governance

Azure Policy: built-in vs custom definitions, initiatives, effects (Deny, Audit, Modify, DeployIfNotExists), remediation tasks, exemptions

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Azure RBAC controls who can act; Azure Policy controls what resources may look like. A policy definition is a rule written in JSON with an if condition (for example, a storage account where supportsHttpsTrafficOnly is false) and a then effect. You assign the definition to a scope (management group, subscription or resource group), optionally excluding child scopes, and Azure evaluates matching resources on create and update and periodically for compliance.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-500 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-500 study plan