How deny policy or rule inherits from Root Tenant to resource level

Nishith Suthar 0 Reputation points
2024-03-17T20:46:18.96+00:00

I am trying to understand how deny policy/rule works in terms of inheritance. If I create a deny policy of - "not able to create resources" at Root Tenant. Under the root tenant I have a management group IT and a Dev subscription under this management group. I have allowed policy of creating resources under management group. Can I in this case create resources under subscription over-riding deny policy at Tenant level ?

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
793 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Silvia Wibowo 2,931 Reputation points Microsoft Employee
    2024-03-18T01:57:52.1466667+00:00

    Hi @Nishith Suthar , I understand that you want to know how Azure Policy is inherited and applied.

    Any assignment of user access or policy on the root management group applies to all resources within the directory. Source: Important facts about root management group.

    Answer to your question: No. If a deny policy applies, the request will be denied, unless you define excluded scopes. Policies are inherited: management structure from higher to lower level, to subscription, to resource group, to resources.

    Please refer to Azure Policy Assignment Structure.

    0 comments No comments

  2. SwathiDhanwada-MSFT 17,401 Reputation points
    2024-03-20T07:15:08.6366667+00:00
    0 comments No comments