Concept and mechanism
Azure Policy evaluates organizational rules over resources and requests, while RBAC handles principal authorization. A person authorized to create resources may have a request denied for choosing a disallowed region. A Policy assignment may include scope, parameters, and exclusions; any exception needs justification and control. Compliance results describe evaluation and do not themselves prove an existing resource was corrected. Effects such as modify and deployIfNotExists may require remediation tasks with suitable identity and permissions to address existing resources.
Guided application
Resource locks protect covered management operations but are not equivalent to data-retention policy. Before applying a lock, also assess legitimate operations that may be affected. Tags help assign ownership and cost when conventions and maintenance exist. A budget with notification creates a management signal; it is not a hard billing cap or automatic authorization to stop production. Define who investigates variance, which information they compare, and which actions they may take. Optimization should consider critical windows, retention, and service commitments.
A storage account with CanNotDelete still needs blob protection. The management lock does not replace appropriate versioning, retention, and data permissions.
Common pitfalls
Using Owner to try to ignore Policy; confusing noncompliance with remediation; treating a financial alert as a cap.
Related topics: Storage, delegation, and recovery · Declarative deployments and virtual machines
Define the risk each control addresses and the evidence demonstrating its effect.
Reference: Azure Policy · AZ-104; skills measured 2026-04-17