How to disable the Azure policy 'Storage account public access should be disallowed'?
When setting the 'Public read access for blob only' Access level for an Azure Container, it reverts back to 'No public access' after a short period. It seems that the Azure policy 'Storage account public access should be disallowed' is responsible for…
Azure Policy
Azure Policy is showing Compliant for Other type of OS as well
Hi Team, We are trying to configure an azure policy "Configure periodic checking for missing system updates on azure virtual machines" for Linux OS type of VMs only by selecting the parameter as below. But when checking the compliance report…
Azure Policy
How can I delete my card from azure portal? I no longer wants to use this account anymore, how can I remove?
I'm unable to delete my payment card from the Azure portal. I deleted the Azure subscription and all, but I'm still not able to delete the card details
Azure Policy
Policy on hosting gambling content
We're looking for documentation(or clarification) on Azure policies in relation to hosting and compliance for gambling/casino apps. From what we've gathered its not strictly forbidden but the documentation is super bare bones.
Azure Policy
Unable to Reactivate Disabled Azure Subscription – No Access to Support Request
My Azure subscription has been disabled due to suspected policy violations, but I believe this was a mistake. I am currently able to log in to the Azure Portal, but I cannot reactivate the subscription or create a support ticket. The portal shows this…
Azure Policy
Azure subscription disabled Microsoft Resource Block Applied[#SIR21265734]
Hi Azure support team, This morning we got an email from Azure with title Microsoft Resource Block Applied[#SIR21265734] alert us the security breach to my account. All permissions is revoked (readonly) which is great. That buy us time to reset users…
Azure Policy
How to Enforce Tagging Standards During Azure Subscription Creation
Issue Statement: There is a need to implement an Azure Policy that prevents the creation of Azure subscriptions if certain required tags are not provided during the creation process. However, it has been observed that Azure Policy does not support…
Azure Policy
The policy assigned to the management group cannot take effect during the create subscription process. Is this the design?
We found that the policies assigned to the management group cannot take effect during the subscription creation process After the subscription is created, we can identify new subscriptions that do not comply through compliance and modify them through…
Azure Policy
Azure Resource Graph (ARG) Query to List All Failed Policy Deployments
When using Azure Policy, in particular a policy with Deploy If Not Exist (DINE), naturally the policy will try to remediate anything that doesn't align to the policy definition. However, if there is something that prevents the Policy Deployment from…
Azure Policy


Dynamic 'kid' Usage in Azure APIM Validate-JWT Policy
We currently use hardcoded exponent and modulus values within the
Azure API Management
Azure Policy
Azure policy to allow tags with certain names (value doesn't matter)
Hi everyone, I have a list of allowed tags, I don't mean the value that the tag contains but only the name of the tag. The purpose of this is that all the tenant's resources only have tags that are included in this list. Because of this I need a policy…
Azure Policy
Urgent: Account Locked and Verification Issues (TrackingID#2412170040002994)
Dear Azure Support, I am reaching out regarding our account, which has been locked for almost a month. Unfortunately, despite following up on the emails we've received, the responses have not been helpful in resolving the issue. This situation is…
Azure Policy
AZT508 - Azure Policy
Hello all :) I have designed the following simple KQL query to monitor for potential misuse of the DeployIfNotExists effect by detecting policy definition updates: AzureActivity | where OperationNameValue ==…
Azure Policy
Problems with Microsoft Defender for Cloud identity recommendations V2
The new set of identity related recommendations when GA on 2023-05-01: https://github.com/MicrosoftDocs/azure-docs/commit/aba0c46fdabe84065951c96a7df75333a0493cac#diff-dbd404e58cedaa40736d88385d006caf82189af9cac95af849538aab5c5b57d8L70-L78 As a result…
Azure Policy
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Despite creating an Activity alert in the Microsoft Defender portal, we are still not receiving any alerts.
Despite creating an Activity alert in the Microsoft Defender portal, we are still not receiving any alerts.
Azure Policy
Microsoft 365 and Office | Install, redeem, activate | For business | Windows
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
I Need help with a policy to Azure Budget
Hello, I would like to request help with a problem I am facing. I am trying to apply a policy that essentially prevents deployments if the subscription's budget exceeds 200. Is there any way to do this with a policy? If not, how can I enforce a cost…
Azure Cost Management
Azure Policy

Availability Sets are not supported in Azure Policy for deploying Azure Monitor Agent.
I have created a Initiative for deploying the Azure Monitor agent on a subscription. The agent is deployed on all the Windows vm's except on the machines in a availability set. The policy I'm using is "Configure Windows virtual machines to run Azure…
Azure Monitor
Azure Policy
Windows for business | Windows Server | User experience | Other
Azure policy does not back up persistent AVD VMs.
We're running into a weird issue. We have two Azure policies, one which adds a tag for any VM, the tag name is "backup" and it sets the value to [true]. Then a second policy is set to backup VMs with a given tag to an existing vault in the…
Azure Backup
Azure Policy
Allow-Access-Control-Origin Error on Web App
Hey everyone. I may be missing something simple, but here's one for you guys! Turning on App Gateway WAF Policy with a custom rule for geo location match. Essentially just to deny any traffic outside of select countries. Without this WAF Policy turned…
Azure Application Gateway
Azure Web Application Firewall
Azure Policy


Azure Policy not working with Def. JIT (- Do not allow Any as source)
I am currently trying to prevent users from requesting Azure JIT VM access coming from the Source IP addresses "Any". According to this thread, https://learn.microsoft.com/en-us/answers/questions/846584/azure-vm-jit-do-not-allow-any-as-source ,…
Azure Policy
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
