Azure / Enterprise-Scale

The Azure Landing Zones (Enterprise-Scale) architecture provides prescriptive guidance coupled with Azure best practices, and it follows design principles across the critical design areas for organizations to define their Azure architecture
https://aka.ms/alz
MIT License
1.69k stars 963 forks source link

Feature Request - single policies should be added to policy sets #1610

Closed vegazbabz closed 3 months ago

vegazbabz commented 6 months ago

According to Microsoft policy documentation, all single policy definitions should be part of an initiative:

https://learn.microsoft.com/en-us/azure/governance/policy/overview#recommendations-for-managing-policies

Springstone commented 6 months ago

Hi @vegazbabz, we're following up with PG, as this guidance conflicts with other guidance we've been given, and we question the reasoning of the public documentation. Will update when we get an answer.

Springstone commented 3 months ago

@vegazbabz turns out we're not on the incorrect path, and guidance / documentation in not accurate, and PG will be updating accordingly. This particular guidance was meant for internal teams and built-in policies/initiatives, specifically around helping customers minimize the need for assignments (due to the limits).

The guidance doesn't apply to customs, however, we do follow the best practice of grouping policies together as much as possible as long as it makes sense.

Closing this story, as we have an answer - and we're not wrong. (Expect public documentation to be updated over the next month).