Azure Policy
- Enforces organizational standards and assesses compliance at scale.
- Policies can audit, deny, or remediate non-compliant resources.
- Initiative definitions group multiple policies together.
- Policies are inherited through the management group hierarchy.
Resource Protection
- Resource locks prevent accidental deletion or modification.
- Delete lock: allows read and modify, prevents deletion.
- ReadOnly lock: allows read only, prevents modification and deletion.
- Locks are inherited by child resources.
Compliance
- Microsoft Purview provides data governance across your data estate.
- Azure Blueprints packages ARM templates, policies, RBAC, and resource groups.
- Service Trust Portal provides audit reports and compliance documentation.
- Trust Center contains information about Microsoft security, privacy, and compliance.
Practice Governance Questions
Put your knowledge to the test with practice questions.