azure-policy-custom-definition
Type: decision
Decision
Every Deny or DeployIfNotExists gap with no built-in policy requires a custom definition.
Why
Without custom policies, Audit-only coverage looks like enforcement but the violation still occurs.
Violations
- Resource type whitelisted with a known Deny gap and no custom definition to close it.
Links
- azure-policy-naming-convention — The naming convention constrains custom definitions to Deny, DeployIfNotExists, or Modify effects — the effect determines the assignment prefix.
← Back to knowledge graph