← AZ-104: Azure administration in production
02 / 7 · 23 MIN

Governance, protection, and costs

Apply distinct controls to configuration, deletion, and spending.

Concept and mechanism

Azure Policy evaluates organizational rules over resources and requests, while RBAC handles principal authorization. A person authorized to create resources may have a request denied for choosing a disallowed region. A Policy assignment may include scope, parameters, and exclusions; any exception needs justification and control. Compliance results describe evaluation and do not themselves prove an existing resource was corrected. Effects such as modify and deployIfNotExists may require remediation tasks with suitable identity and permissions to address existing resources.

Guided application

Resource locks protect covered management operations but are not equivalent to data-retention policy. Before applying a lock, also assess legitimate operations that may be affected. Tags help assign ownership and cost when conventions and maintenance exist. A budget with notification creates a management signal; it is not a hard billing cap or automatic authorization to stop production. Define who investigates variance, which information they compare, and which actions they may take. Optimization should consider critical windows, retention, and service commitments.

IN PRACTICE

A storage account with CanNotDelete still needs blob protection. The management lock does not replace appropriate versioning, retention, and data permissions.

Common pitfalls

Using Owner to try to ignore Policy; confusing noncompliance with remediation; treating a financial alert as a cap.

Related topics: Storage, delegation, and recovery · Declarative deployments and virtual machines

Take this idea with you

Define the risk each control addresses and the evidence demonstrating its effect.

Create account

Reference: Azure Policy · AZ-104; skills measured 2026-04-17