Soru

Zorluk: OrtaAzure Policy

An administrator assigns an Azure Policy definition to an Azure subscription to enforce resource tagging. The administrator wants to prevent the policy from applying to resources inside a resource group named 'Test-RG'. Is it true that the administrator can exclude 'Test-RG' from the scope of the policy assignment?

Cevap: Cevap

Cevap

It is true that the administrator can exclude the resource group from the scope of the policy assignment.

Adım Adım Çözüm

1
Analyze the default behavior of Azure Policy subscription-level assignments.
By default, a policy assigned to a subscription is inherited by all resource groups and resources within that subscription.
Azure Policy assignments apply hierarchically to all child resources.
2
Determine if Azure Policy supports exceptions within the assignment scope.
Azure Policy supports configuring exclusions at the resource group or individual resource level to bypass the policy assignment.
Exclusions allow administrators to refine governance controls and accommodate exceptions like test environments.

Anahtar Kavram

Azure Policy Assignment Scopes and Exclusions
Bu soruyu puanla