Instiq
Chapter 4 · Develop a Security and Compliance Plan·v2.0.0·Updated 6/3/2026·~10 min

What's changed: Deepened AZ-400 Chapter 4 (added comparison tables, scenarios, FAQs, exam traps, deep-dive paragraphs to each section; localized figures to Japanese)

4.3Compliance and Governance

Key points

Understand control and trails—approvals/audit logs, Azure Policy, environment protection (checks), license/compliance management, and separation of duties. Meet regulatory requirements while shipping fast.

In regulated environments, control and trails are essential. Approvals, policy, and audit logs make who-approved/changed-what traceable.

4.3.1Governance mechanisms

Diagram of AZ-400 governance: deployments require approvals (responsible sign-off) and environment checks (branch control / no out-of-business-hours / required templates), Azure Policy enforces organizational guardrails, all operations (approve/change/deploy) recorded in audit logs, separation of duties (builder vs approver) ensures internal control, and dependency license compliance is managed—regulated DevOps.
Compliance and governance
  • Approvals/environment checks: enforce human approval or conditions (branch/time/template) before prod.
  • Azure Policy: enforce organizational guardrails (allowed resources/mandatory encryption).
  • Audit logs: record approvals/changes/deployments for traceability.
  • Separation of duties: separate builders from approvers/deployers for internal control.
Exam point

Common on AZ-400: human gate before prod = approvals, enforce environment conditions = checks (branch/time/template), org guardrails = Azure Policy, operation records = audit logs, builder ≠ approver = separation of duties. Even under regulation, keep automation—balance control and speed with gates/approvals.

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.