Effect of editing custom Azure Policy definition on existing assignments?

Mark Poole 20 Reputation points
2024-10-14T15:13:09.56+00:00

I am trying to understand how editing a custom Azure policy definition affects existing assignments but can't find any info on this.

Our scenario: We have a custom policy definition for the deployment and configuration of the AMA client on Arc connected machines. The policy was assigned to an RG with Arc connected machines in it. The AMA client was installed and configured, and the machines showed as being compliant with the policy. Unfortunately, the policy definition has a typo in the proxy settings so the machines need updating with the correct value.

I updated the policy definition but clients still reported as being compliant with the policy even though the AMA client reported back the wrong proxy config.

I then tried removing the policy assignments and creating new policy assignments against the updated policy definition. The clients still report back as being compliant with the policy even though the AMA client is still reporting back the wrong proxy config. I have manually triggered a compliance scan to try and rule out the compliance date being stale.

I am expecting the clients to become non-compliant as their AMA config no longer matches the policy definition but this does not seem to be happening. Am I wrong in my expectations?

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
1,019 questions
{count} votes

Accepted answer
  1. Pranay Reddy Madireddy 6,180 Reputation points Microsoft External Staff Moderator
    2024-11-04T13:25:30.9+00:00

    Hi Mark Poole (7805)
    I'm glad that you were able to resolve your issue and thank you for posting your solution so that others experiencing the same thing can easily reference this! Since the Microsoft Q&A community has a policy that "The question author cannot accept their own answer. They can only accept answers by others ", I'll repost your solution in case you'd like to "Accept " the answer.

    Issue:
    Effect of editing custom Azure Policy definition on existing assignments?

    Solution:
    The only way I managed to get this resolved was to remove the AMA client from the machines and create a new remediation task. The client was then redeployed with the correct settings.

    If you have any other questions or are still running into more issues, please let me know. Thank you again for your time and patience throughout this issue.

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.