Discussion on recent updates and improvements to Azure Policy, including disk encryption for Azure cache for Redis and user managed identities in Azure SQL database auditing. Introduction of Kemly from Azure policy team. Basics of Azure policy including enforcement, compliance reporting, and remediation.
Azure policy consists of enforcement and compliance, compliance reporting, and remediation and automation to control and govern resources at scale.
New features like deny action, safe deployment mechanisms, and versioning enhance the policy experience for enforcing and managing compliance of Azure resources.
Deep dives
Overview of Azure policy
Azure policy allows users to control and govern their resources at scale. It consists of three main pillars: enforcement and compliance, which ensures that standards are enforced; compliance reporting, which evaluates the compliance of resources; and remediation and automation, which allows for automatic remediation of resources. Policy sits at the front door of Azure Resource Manager and monitors requests to ensure compliance. It can modify requests, provide audit reports, and even deny actions like resource deletion. New features, such as deny action and selectors, are being introduced to enhance safe deployment and versioning of policy definitions. Improvements in latency and simplification of the policy experience are also in progress.
Safe deployment and versioning
Safe deployment is a top priority for Azure policy, ensuring that policy definitions and assignments can be deployed and upgraded without breaking changes. Resource selectors enable fine-grained control over where policy assignments apply, allowing for gradual enforcement, and override allows for overriding the effect of a built-in policy definition. Versioning for built-in definitions is being developed to ease tracking and updates. Other enhancements on the roadmap include deprecating policy parameters, rollback support, and improved latency and replication.
The importance of governance and policy
Azure policy emphasizes the vital role of governance in creating and managing Azure environments. It highlights that governance should be a foundational consideration, as policy allows for consistent and controlled management of resources at scale. Policy provides active control, ensuring compliance and governance for existing and future Azure resources.
Key takeaways
Azure policy enables users to enforce, automate, and report on compliance of resources at scale. New features like deny action, safe deployment mechanisms, and versioning are enhancing the policy experience. Governance and policy should be prioritized as foundational elements in creating Azure environments, providing consistent control over resource management.
Michael and Mark talk to Kemley Nieva from the Azure Governance team about some of the recent updates and improvements to Azure Policy. We also cover the latest Azure security news covering Microsoft Security Copilot, Azure Functions, SQL Managed Instance, Azure Backup, Ephemeral OS disks, Azure Cache for Redis, Azure SQL Database, Azure Monitor, API Management, Azure Maps and Storage.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode