just published a new demo showing you how to use #AzurePolicy to apply and inherit tags at scale using a combination of custom and builtin policies
https://t.co/Jf0VVpSWH3
My friends at @MicrosoftPress have given me a couple of copies of the eBook for The Definitive Guide to KQL to give away. Retweet or comment below and I will put you in the draw. To give everyone a chance, I will give it 48 hours and then draw two winners. https://t.co/ne19KZTytZ
Enterprise Azure Policy as Code (EPAC) consists of several scripts that can be utilized in a CI/CD-oriented system or a partially automated manner.
Check it out:
https://t.co/KfIgdlR8jv
Credit: Luke Murray
#MicrosoftAzure#EPAC#PolicyAsCode
Love the concept - it fills a gap with policy development and getting that feedback loop QUICKLY
I know this is early early stage - seeing support for test files in .bicep would be great for wider adoption
Nitpick - I'm not a fan of the short name of this 'ape'
2 years. 380 links. 57 PRs. 1000s of visits.
still maintaining this list of awesome #AzurePolicy content until an AI takes over the job for me
https://t.co/8LtzrIjqqv
@EelcoLabordus@autosysops Thanks for sharing.
creating a policy exemption for a resource that needs to be deleted seems kind of odd though?
in terms of lifecycle mgmt should we be cleaning up these exemptions just in case a resource with the same name is created again.. like in IaC managed environments
#AzurePolicy GA announcement 🚨
🆕 DenyAction (effect)
🛑 block request based on actions to the resource
🛑 safeguard critical infrastructure
🛑 block actions at-scale
https://t.co/F42JjEjds1
@ADurrante Certainly appears possible to do with Azure Policy if the requirements are to:
1) install AMA to session hosts
2) add system managed identity session hosts
Both of the above have built-in policies already available so you would probably need to customise them a bit for this use