azure-policy-custom-definition
Type: regulative
Decision
A guardrail gap must be closed by a custom Azure Policy definition when no built-in policy can enforce the institutional fact.
Why
Without custom definitions, a resource type can appear to satisfy a guardrail while the Azure Policy assignment cannot enforce the status the knowledge graph names.
Violations
- Resource type listed with a known guardrail gap and no custom definition to close it.
Anchor
no-unapproved-resources
Implements
Files
- platform-management/policy/bicep/customPolicyDefinitions.bicep
- platform-management/policy/parameters/customDefinitions/policyDefinitions.bicepparam
- platform-management/policy/parameters/customDefinitions/*.json
Links
← Back to knowledge graph