Instiq
Chapter 5 · Cost and Governance·v2.0.0·Updated 6/3/2026·~14 min

What's changed: Revamped AZ-900 Chapter 5 to the new depth (cost factors/tools/savings, Policy/locks/RBAC/Purview/landing zones)

5.2Governance and Compliance

Key points

Understand enforcing rules and safe operations with Azure Policy, resource locks, and RBAC, plus data governance and compliance via Microsoft Purview and the Service Trust Portal.

Using the cloud in an organization requires governance—enforcing rules, preventing mistakes, granting permissions only to the right people, and staying compliant. Azure supports these with separate mechanisms. They are easy to confuse, so the trick is to organize them by what each one controls.

5.2.1Enforcing rules: Azure Policy

Azure Policy defines and enforces "conditions resources must meet" as rules (e.g., restrict allowed regions, require tags, limit VM sizes). It can deny non-compliant creation, evaluate compliance of existing resources, and even auto-remediate. A policy initiative bundles many policies to apply a whole set of rules (e.g., for a regulatory standard) at once.

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.