azureblog.co.uk
← cd ~/learn
azureblog.co.uk · cheat sheet

Azure Policy effects and assignments

What each policy effect does, the order they run in, and how assignments, exemptions and remediation fit together.

Fits on one A4 page. Checked 9 Oct 2026.

Effects

EffectWhat happensTypical use
AuditLogs non-compliance; the request succeedsTrial any policy first
AuditIfNotExistsAudits when a related resource is missingMissing diagnostic settings or extensions
DenyBlocks the create or update requestAllowed locations, SKUs, public access
DenyActionBlocks an action such as deleteProtect critical resources from deletion
ModifyAdds, updates or removes properties or tagsInherit tags, turn settings on
AppendAdds fields to the requestOlder policies; prefer Modify
DeployIfNotExistsDeploys a related resource when it's missingDiagnostic settings, Defender plans, agents
DisabledTurns the policy offParameterise effects in initiatives
ManualCompliance is attested by a personRegulatory controls Azure can't check

Evaluation order

  1. Disabled is checked first
  2. Append and Modify change the request
  3. Deny can block it
  4. Audit logs it
  5. After the resource is created or updated, AuditIfNotExists and DeployIfNotExists check related resources

Assignments

  • Scope: management group, subscription, resource group or a single resource. Assign high and inherit.
  • Exclusions remove scopes from the assignment.
  • Exemptions cover a resource or a whole scope, with a category (Waiver or Mitigated), a reason and an expiry.
  • Enforcement mode DoNotEnforce evaluates without blocking or deploying.
  • Modify and DeployIfNotExists need a managed identity with the right role.

Timing and remediation

  • New assignments take about 5 minutes to apply, then a compliance scan starts. New or changed resources show a result about 15 minutes later.
  • Existing resources are evaluated by a compliance scan roughly every 24 hours. Start one with az policy state trigger-scan.
  • Modify and DeployIfNotExists only act on new or changed resources. Fix existing ones with a remediation task.

Guide: guardrails every subscription should have. Name your resources consistently with the naming generator.