← cd ~/learn
azureblog.co.uk · cheat sheet
Azure Policy effects and assignments
What each policy effect does, the order they run in, and how assignments, exemptions and remediation fit together.
Fits on one A4 page. Checked 9 Oct 2026.
Effects
| Effect | What happens | Typical use |
|---|---|---|
| Audit | Logs non-compliance; the request succeeds | Trial any policy first |
| AuditIfNotExists | Audits when a related resource is missing | Missing diagnostic settings or extensions |
| Deny | Blocks the create or update request | Allowed locations, SKUs, public access |
| DenyAction | Blocks an action such as delete | Protect critical resources from deletion |
| Modify | Adds, updates or removes properties or tags | Inherit tags, turn settings on |
| Append | Adds fields to the request | Older policies; prefer Modify |
| DeployIfNotExists | Deploys a related resource when it's missing | Diagnostic settings, Defender plans, agents |
| Disabled | Turns the policy off | Parameterise effects in initiatives |
| Manual | Compliance is attested by a person | Regulatory controls Azure can't check |
Evaluation order
- Disabled is checked first
- Append and Modify change the request
- Deny can block it
- Audit logs it
- After the resource is created or updated, AuditIfNotExists and DeployIfNotExists check related resources
Assignments
- Scope: management group, subscription, resource group or a single resource. Assign high and inherit.
- Exclusions remove scopes from the assignment.
- Exemptions cover a resource or a whole scope, with a category (Waiver or Mitigated), a reason and an expiry.
- Enforcement mode DoNotEnforce evaluates without blocking or deploying.
- Modify and DeployIfNotExists need a managed identity with the right role.
Timing and remediation
- New assignments take about 5 minutes to apply, then a compliance scan starts. New or changed resources show a result about 15 minutes later.
- Existing resources are evaluated by a compliance scan roughly every 24 hours. Start one with
az policy state trigger-scan. - Modify and DeployIfNotExists only act on new or changed resources. Fix existing ones with a remediation task.
Guide: guardrails every subscription should have. Name your resources consistently with the naming generator.