This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Choose the best response for each of the following questions.
Your organization operates in both the United States and European Union, each with distinct data residency requirements. The US division requires all AI workloads to deploy in US regions, while the EU division requires deployment in EU regions only. Both divisions share the same base security policy requiring managed identities and encryption. How should you structure Microsoft Foundry policies to enforce these requirements?
Create separate base security policies for US and EU divisions, each including both security controls and region restrictions specific to their geography.
Define one organization-wide base security policy with managed identity and encryption requirements, then create business unit policies for US and EU divisions that add region restrictions specific to each geography.
Configure region restrictions in the resource catalog templates rather than policies, allowing developers to select geography-appropriate templates when provisioning.
Your compliance scanner reports that 15 Azure OpenAI endpoints in the production environment have diagnostic logging disabled, violating the base security policy that requires logging to a centralized workspace. The resources were provisioned through Microsoft Foundry three weeks ago with logging enabled. What is the most likely cause of this policy drift, and how should you address it?
Developers manually disabled logging after provisioning to reduce costs; implement autoremediation in the compliance scanner to re-enable logging when drift is detected.
The base security policy wasn't properly configured with enforcement mode; update the policy to 'Deny' rather than 'Audit' to prevent future logging changes.
Azure service updates changed default logging behavior; create an incident ticket for developers to manually restore logging on affected endpoints.
Your development teams complain that approval workflows for experimental AI deployments take 2-3 days, slowing innovation velocity. Current policies routes all Azure OpenAI requests greater than $500 monthly cost to VP approval. Development deployments rarely exceed $1,000 monthly and have separate budget allocation from production. How should you optimize governance policies to enable faster development cycles without compromising production controls?
Increase the autoapproval threshold to $5,000 for all environments so both development and production teams can provision faster.
Remove approval workflows entirely for development environments and rely on budget enforcement policies to prevent overspending.
Create environment-specific policies where development environments autoapprove requests under $2,000 monthly cost while production maintains VP approval for all deployments.
You must answer all questions before checking your work.
Was this page helpful?
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?