Skip to content

Details

This session makes the case for "guardrails, not gates": governance that's built into the platform itself rather than bolted on afterward.

We'll start with Azure Policy fundamentals, including policy definitions, initiatives, and effects (Deny, Audit, DeployIfNotExists, Modify), and explore how each effect type is appropriate for different governance scenarios.

From there, we move into practical network security baselines, covering policies that:

  • Deny public IP creation on VMs
  • Enforce mandatory NSG association on subnets
  • Require specific Azure Firewall routing
  • Mandate encryption in transit

The session then zooms out to the Cloud Adoption Framework Landing Zone model, showing how these individual policies are assembled into a coherent governance architecture and applied automatically at subscription vending time. This ensures every new subscription inherits the right guardrails from day one, rather than having security retrofitted later.

We'll also cover:

  • Management group hierarchy design
  • Policy assignment scope
  • Handling policy exemptions for legitimate edge cases without undermining the overall baseline

Related topics

Microsoft Azure
Microsoft
Technology Professionals

Sponsors

Microsoft Reactor YouTube

Microsoft Reactor YouTube

Watch past Microsoft Reactor events on-demand anytime

Microsoft Learn AI Hub

Microsoft Learn AI Hub

Learning hub for all things AI

Microsoft Copilot Hub

Microsoft Copilot Hub

Learning hub for all things Copilot

Microsoft Reactor LinkedIn

Microsoft Reactor LinkedIn

Follow Microsoft Reactor on LinkedIn

You may also like