Azure Policy fails when everything is Deny on day one and teams discover broken deploys in production. Start with Audit, measure impact, then tighten.
Group policies into initiatives that match your landing zone standards: locations, public endpoints, required tags, encryption, and diagnostic settings.
Exemptions should be time-boxed and owned. Permanent exemptions are just undocumented architecture.
Good policy feels like paved roads—teams stay inside the lines because the path is clear, not because every PR is blocked.
Publish a policy catalog in plain language next to the technical effect.
Test policy changes in a canary Management Group before estate-wide rollout.
Feed policy failures into platform backlog items—not only into developer blame.
Key takeaways
- Start with deny/audit on the few risks that matter; expand with evidence.
- Exemptions must expire and name an owner.
- Pair Policy with Landing Zone templates so compliant paths are the easy paths.
FAQ
Why do teams hate Azure Policy?
Because initiatives are dumped without golden paths. Guardrails without self-service create tickets and shadow IT.
Audit vs deny—when?
Audit to measure and educate; deny when the risk is clear and a compliant alternative exists.