Quantcast
Channel: Azure Security Center – Cloud Administrator in Azure World
Viewing all articles
Browse latest Browse all 17

Azure Policy Policies not evaluated right away

$
0
0
[Azure Policy](https://docs.microsoft.com/en-us/azure/governance/policy/overview?WT.mc_id=AZ-MVP-5000120) has a unique feature compared to other competitors when it comes to evaluating Azure Resources. As Azure Policy is built along Azure Resource Manager (ARM) policies are in effect right away. This means if you have policy that blocks location and you try to deploy to that location a resource you will not be able to. The effect is enforced no matter if you use ARM Template Deployments, Portal, PowerShell, CLI, SDK or just plain old REST API. Of course on existing resources the policies are evaluated once 24 hours but you can of course [trigger on-demand evaluation scan](https://docs.microsoft.com/en-us/azure/governance/policy/how-to/get-compliance-data#evaluation-triggers?WT.mc_id=AZ-MVP-5000120). The time that the scan will run depends on how many resources the policy will need to evaluate. Obviously policies that evaluate many resources (such as policies for tags or locations) will take longer (also dependable on the number of resources for the applied scope).

Viewing all articles
Browse latest Browse all 17

Latest Images

Trending Articles





Latest Images