Azure Policy: diagnose an expired exemption before disabling the assignment
A production runbook for tying expiry, scope, assignment and compliance together before renewing an Azure Policy exemption or disabling the guardrail.
Read article
Tag
8 articles connected to this technical signal.
A production runbook for tying expiry, scope, assignment and compliance together before renewing an Azure Policy exemption or disabling the guardrail.
Read articleA production runbook for proving that a recreated Azure resource has a new principalId, finding orphaned roles and restoring least privilege without broadening RBAC.
Read articleA production runbook for proving which Terraform writer owns an Azure Blob state lease, stopping competing pipelines, recovering a stale lock and validating state before another apply.
Read articleA production runbook for reconstructing an interrupted Terraform apply on Azure, comparing configuration, state and live resources, then choosing rerun, targeted import, rollback or state repair.
Read articleA production runbook for qualifying a Terraform provider upgrade with a lockfile, baseline plan, canary, operational evidence and an explicit rollback.
Read articleA production runbook for reviewing managed resources, unmanage behavior, deny settings, excluded identities, validation and rollback before updating an Azure Deployment Stack.
Read articleA production runbook for qualifying an Azure Policy deployment deny with assignment, initiative, deny effect, compliance, scoped exemption, validation and rollback.
Read articleA production runbook for qualifying a Terraform, Bicep or ARM plan before apply with drift, CI identity, Azure Policy, destructive changes, validation and rollback.
Read article