How to assign policies by updating ARM template?

%3CLINGO-SUB%20id%3D%22lingo-sub-2028200%22%20slang%3D%22en-US%22%3EHow%20to%20assign%20policies%20by%20updating%20ARM%20template%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2028200%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%3EHello%20all!%20I%20need%20to%20assign%20policies%20to%20my%20subscription%20for%20it%20to%20be%20compliant.%20How%20will%20I%20be%20able%20to%20assign%20the%20policies%20by%20updating%20the%20ARM%20template%20of%20the%20subscription%3F%20Also%2C%20I%20found%20out%20a%20way%20to%20assign%20policies%20through%20azure%20portal%2C%20will%20the%20policies%20assigned%20through%20portal%20will%20be%20also%20included%20in%20the%20ARM%20template%3F%20Where%20can%20I%20find%20and%20edit%20the%20ARM%20template%20for%20my%20subscription%3F%20And%20how%20will%20I%20deploy%20it%3F%20Thank%20you%20in%20advance!%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2028200%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Earm%20template%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20Policy%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2028653%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20assign%20policies%20by%20updating%20ARM%20template%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2028653%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F707596%22%20target%3D%22_blank%22%3E%40UserID707597%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETo%20assign%20policy%20definitions%20or%20initiative%20you%20have%20many%26nbsp%3B%20ways%20like%20%3A%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E-%20Assigning%26nbsp%3B%20through%20the%20portal%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E-%20Assigning%20through%20Azure%20Blueprint%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E-%20Assigning%20through%20Infra%20as%20code%20(Arm%20Templates%20Terraform%20Pulumi...)%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFor%20Infra%20as%20code%20you%20will%20need%20to%20export%20the%20policy%20definition%26nbsp%3B%20and%20customize%20it%20.%26nbsp%3B%3C%2FP%3E%3CP%3EOnce%20you%20have%26nbsp%3B%20done%20that%26nbsp%3B%20you%20deploy%20it%20like%20a%20regular%20resource%20in%20azure%20.%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20are%20not%20familiar%20with%20IaC%20you%20can%20simply%20use%20the%20UI%20and%20deploy%20it%20through%20the%20portal%20or%20Azure%20Blueprint%20(%20Arm%20yemplate%20behind%20the%20scene)%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2028690%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20assign%20policies%20by%20updating%20ARM%20template%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2028690%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F540591%22%20target%3D%22_blank%22%3E%40ibrahimambodji%3C%2FA%3E%26nbsp%3B%20thank%20you%20for%20answering.%20Sorry%20I'm%20not%20yet%20familiar%20with%20this%2C%20but%20how%20do%20I%20export%20and%20deploy%20the%20policy%20definition%3F%20Also%2C%20if%20I%20assign%20the%20policy%20through%20portal%2C%20will%20it%20also%20be%20included%20in%20the%20ARM%20template%20for%20that%20subscription%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2028761%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20assign%20policies%20by%20updating%20ARM%20template%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2028761%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F707596%22%20target%3D%22_blank%22%3E%40UserID707597%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou're%20welcome%20.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETo%20export%20the%20policy%20definition%20you%20need%20to%20go%20to%20the%20Azure%20Policy%20blade%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fportal.azure.com%2F%23blade%2FMicrosoft_Azure_Policy%2FPolicyMenuBlade%2FOverview%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EPolicy%20-%20Microsoft%20Azure%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESelect%20Definitions%20and%20in%20the%20list%20select%20the%20definition%20you%20want%20to%20export%20.%20You%20need%20to%20have%20Github%20account%20to%20be%20able%20to%20do%20that%20.%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20can%20do%20that%20in%20other%20ways%20documented%20below%20%3A%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fgovernance%2Fpolicy%2Fhow-to%2Fexport-resources%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EExport%20Azure%20Policy%20resources%20-%20Azure%20Policy%20%7C%20Microsoft%20Docs%3C%2FA%3E%3C%2FP%3E%3CP%3ENotice%20that%20you%20don't%20need%20to%20do%20that%20if%20there%20is%20no%20changes%20in%20the%20builtin%20policy%20.%20You%20can%20just%20assign%20to%20a%20scope%20directly%20.%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20want%20add%20changes%20you%20can%20simply%20add%20a%20policy%20definition%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fportal.azure.com%2F%23blade%2FMicrosoft_Azure_Policy%2FPolicyMenuBlade%2FDefinitions%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EPolicy%20-%20Microsoft%20Azure%3C%2FA%3E%3C%2FP%3E%3CP%3EEdit%20the%20policy%20rule%20and%20hit%20save%20.%20You%20can%20also%20import%20the%20policy%20rule%20from%20Github%20.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3EThere%20is%20no%20update%20mecanism%20for%20Arm%20templates%20.If%26nbsp%3B%20you%20want%20to%20have%20custom%20definitions%20you%20need%20to%20export%20builtin%20definitions%20add%20changes%20and%20redeploy%20it%20.%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20not%20you%20don't%20need%20to%20export%20anything%20.%20Identify%20the%20definitions%20or%20initiative%20and%20just%20assign%20them%20to%20a%20defined%20scope%20.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2029176%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20assign%20policies%20by%20updating%20ARM%20template%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2029176%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F540591%22%20target%3D%22_blank%22%3E%40ibrahimambodji%3C%2FA%3E%26nbsp%3Bgreat!%20thank%20you%20for%20the%20answers.%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2029241%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20assign%20policies%20by%20updating%20ARM%20template%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2029241%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F707596%22%20target%3D%22_blank%22%3E%40UserID707597%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENo%20problem%20thanks%20.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2029516%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20assign%20policies%20by%20updating%20ARM%20template%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2029516%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F707596%22%20target%3D%22_blank%22%3E%40UserID707597%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20was%20looking%20at%20this%20for%20a%20previous%20job%20and%20found%20this%20info%20very%20helpful%3A%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fazure.microsoft.com%2Fen-us%2Fupdates%2Fexport-and-manage-azure-policy-as-code-with-github%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EExport%20and%20manage%20Azure%20Policy%20as%20code%20with%20GitHub%20%7C%20Azure%20updates%20%7C%20Microsoft%20Azure%3C%2FA%3E%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-governance-and-management%2Fusing-github-for-azure-policy-as-code%2Fba-p%2F1886464%23%3A~%3Atext%3DAzure%2520Policy%2520as%2520code%2520embodies%2520this%2520idea%2520and%2Cdefinitions%2520and%2520assignments%2520using%2520an%2520%2522as%2520code%2522%2520approach.%22%20target%3D%22_blank%22%3EUsing%20GitHub%20for%20Azure%20Policy%20as%20Code%20-%20Microsoft%20Tech%20Community%3C%2FA%3E%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2FAzure%2Fmanage-azure-policy%2Fblob%2Fmain%2Ftutorial%2Fazure-policy-as-code.md%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Emanage-azure-policy%2Fazure-policy-as-code.md%20at%20main%20%C2%B7%20Azure%2Fmanage-azure-policy%20(github.com)%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2031868%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20assign%20policies%20by%20updating%20ARM%20template%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2031868%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F540591%22%20target%3D%22_blank%22%3E%40ibrahimambodji%3C%2FA%3E%26nbsp%3BHi%20again%2C%20is%20it%20possible%20to%20create%20a%20template%20in%20the%20Template%20blade%20in%20Azure%20and%20specify%20all%20the%20needed%20policies%20there%2C%20then%20deploy%20it%20to%20my%20subscription%3F%20Also%2C%20can%20I%20deploy%20many%20ARM%20templates%20into%20one%20subscription%3F%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22UserID707597_1-1609831536022.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F244222i50306FABA111A9E2%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22UserID707597_1-1609831536022.png%22%20alt%3D%22UserID707597_1-1609831536022.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hello all! I need to assign policies to my subscription for it to be compliant. How will I be able to assign the policies by updating the ARM template of the subscription? Also, I found out a way to assign policies through azure portal, will the policies assigned through portal will be also included in the ARM template? Where can I find and edit the ARM template for my subscription? And how will I deploy it? Thank you in advance!

9 Replies

@UserID707597 

 

Hi 

 

To assign policy definitions or initiative you have many  ways like :  

- Assigning  through the portal  

- Assigning through Azure Blueprint  

- Assigning through Infra as code (Arm Templates Terraform Pulumi...) 

 

For Infra as code you will need to export the policy definition  and customize it . 

Once you have  done that  you deploy it like a regular resource in azure . 

If you are not familiar with IaC you can simply use the UI and deploy it through the portal or Azure Blueprint ( Arm yemplate behind the scene) 

Hi @ibrahimambodji  thank you for answering. Sorry I'm not yet familiar with this, but how do I export and deploy the policy definition? Also, if I assign the policy through portal, will it also be included in the ARM template for that subscription?

@UserID707597 

 

You're welcome . 

 

To export the policy definition you need to go to the Azure Policy blade 

Policy - Microsoft Azure

 

Select Definitions and in the list select the definition you want to export . You need to have Github account to be able to do that . 

You can do that in other ways documented below : 

Export Azure Policy resources - Azure Policy | Microsoft Docs

Notice that you don't need to do that if there is no changes in the builtin policy . You can just assign to a scope directly . 

If you want add changes you can simply add a policy definition 

Policy - Microsoft Azure

Edit the policy rule and hit save . You can also import the policy rule from Github .  

There is no update mecanism for Arm templates .If  you want to have custom definitions you need to export builtin definitions add changes and redeploy it . 

If not you don't need to export anything . Identify the definitions or initiative and just assign them to a defined scope . 

@ibrahimambodji great! thank you for the answers. :)

@UserID707597 

 

No problem thanks .

@ibrahimambodji Hi again, is it possible to create a template in the Template blade in Azure and specify all the needed policies there, then deploy it to my subscription? Also, can I deploy many ARM templates into one subscription?

UserID707597_1-1609831536022.png

 

@ibrahimambodji Hi, can you answer the follow-up question for this post? Thank you!

@UserID883312 

 

Hi you can do that regarding the documentation below : 

Quickstart: New policy assignment with templates - Azure Policy | Microsoft Docs

But you will notice that resource group is always necessary and it will be scope .So if you need the subscription as scope you will be blocked .

If you don't want to do it through Github try Azure Blueprint it's more flexible 

Security compliance with Azure Policy and Azure Blueprints | Microsoft Docs

 

You can test this to see if it can fit your need : 

Go to Blueprints Menu 

https://portal.azure.com/#blade/Microsoft_Azure_Policy/BlueprintsMenuBlade/GetStarted 

Click Create 

Select Common Policies  ( You can also start with blank blueprint)

Give a name a description and a location (The management group or subscription where the blueprint is saved)

Click Next:Artifacts

click on ... and remove artifacts you don't want 

click add artifact  and choose Policy assignment as artifact type 

You will see all the iniative definitions and policy definitions 

select and add

click on save draft

In the notifications blade click on saving blueprint definition succeeded 

then publish blueprint  

Give a version and a change notes and hit publish 

Once published you can assign it by giving the necessary parameter values and click assign.