Governance and Compliance

Manage compliance and governance with Azure Policy, Microsoft Purview, and resource locks.

Every organization using the cloud must eventually ask two critical questions: "Can we apply our company's rules and policies to the cloud environment?" and "How do we prevent employees from accidentally deleting important data or violating regulations?" These questions sit at the heart of cloud governance.

AZ-900 frequently tests governance and compliance concepts. This post explains Microsoft Purview, Azure Policy, Resource Locks, Azure Blueprints, and the Service Trust Portal using everyday analogies that make the concepts stick — even if you have never worked in IT before.

 

What Is Governance?

Think about how a school operates. A school has rules: wear your uniform, no phones in class, no food outside the cafeteria. Teachers enforce these rules, and students who break them face warnings or sanctions. Cloud environments need exactly the same kind of structure. When hundreds of employees are working with thousands of cloud resources, operating without rules leads to security incidents, wasted costs, and regulatory violations.

Governance is the overall framework for defining how your organization uses cloud resources, automatically verifying those rules are being followed, and proactively preventing violations before they cause harm. Azure provides several specialized tools to make this possible.

 

Microsoft Purview — Library Librarian and Data Detective

Imagine your company has millions of files, emails, and database records. Among all of that, which records contain customer personal information (PII)? Which ones contain medical records? Which ones have credit card numbers? Automatically finding and classifying all of this is exactly what Microsoft Purview does.

Think of Microsoft Purview as a library librarian combined with a detective. When a new book arrives, the librarian determines whether it is fiction or nonfiction, which section it belongs in, and whether it has restricted access. The librarian can immediately answer questions like "how many books on economics do we have?" or "where are all the Korean-language books?" Purview does the same thing for your organization's data — it automatically scans, classifies, catalogs, and identifies sensitive information across your entire environment.

Microsoft Purview Core Components

| Feature | Description | Analogy | |---------|-------------|---------| | Data Map | Automatically scans all data sources across on-premises, Azure, and multi-cloud and builds a live data map | Library inventory system | | Data Catalog | Lets employees search for data using business terms ("where is our customer order data?") | Subject-based book search | | Data Classification | Automatically detects sensitive data: PII, credit card numbers, medical records, passport numbers | Restricted books list | | Data Lineage | Tracks where data came from, how it was transformed, and where it went | Tracing a book from publisher to distributor to library | | Compliance Management | Dashboard tracking compliance status against GDPR, HIPAA, ISO 27001 | Legal deposit and copyright management |

Why Purview Matters in Practice

Companies doing business in Europe must comply with GDPR (General Data Protection Regulation). Violations can result in fines of up to 4% of annual global revenue or 20 million euros — whichever is higher. To comply, you must know exactly where customer personal data is stored, how long it is retained, and who can access it. Purview automates this discovery process.

There is a saying in security: "You cannot protect what you cannot find." Purview starts by finding everything first.

 

Azure Policy — Automated Rule Enforcer

Back to the school analogy. If a teacher had to personally check all 300 students every day to catch rule violations, it would be impossible. But if the school installed an automatic detection system at the gate — alerting staff and blocking entry when a student without a uniform arrives — enforcement becomes effortless.

Azure Policy works exactly this way. Define a rule once, and Azure automatically applies that rule to all resources, detecting violations or blocking non-compliant actions entirely.

Azure Policy Effect Types

When you define a policy, you specify what happens when a violation is detected — this is called the "Effect."

| Effect | What It Does | Use Case | |--------|-------------|----------| | Deny | Immediately blocks creation or modification of non-compliant resources | "No VMs outside approved regions" | | Audit | Logs violations without blocking anything (warning only) | "Building awareness of current violations" | | DeployIfNotExists | Automatically deploys required settings when a resource is created without them | "Auto-install monitoring agent when VM is created" | | Modify | Automatically modifies specific properties of a resource | "Automatically add an encryption tag to all storage accounts" | | AuditIfNotExists | Audits only when a related resource is missing | "Detect VMs that have no backup configured" |

Real-World Azure Policy Examples

A fictional financial services company might configure policies like these:

Every resource must have "team name," "environment (dev/prod/test)," and "cost center" tags Virtual machines can only be created in Korea Central or Korea South regions Storage accounts must allow HTTPS only with a minimum of TLS 1.2 Databases must have encryption enabled Unusually large VM sizes require special approval before deployment

Policy Initiative (Policy Set)

Applying policies one by one means managing dozens individually. A Policy Initiative groups related policies into a single bundle (called a Set) that can be applied all at once.

For example, applying an "HIPAA Healthcare Data Protection Compliance" initiative activates dozens of healthcare-related policies simultaneously. Azure ships with built-in initiatives for widely used standards: GDPR, ISO 27001, HIPAA, PCI DSS, and CIS Benchmarks.

Compliance Dashboard

After setting up policies, the Azure Portal provides a compliance dashboard giving you a complete overview at a glance. You can see what percentage of resources are compliant, which resources violate which policies, and how long each violation has persisted. One click takes you directly to the offending resource so you can fix it immediately.

 

Resource Locks — Padlocks and Glass Cases

Everyone makes mistakes. Even experienced cloud engineers occasionally click the wrong resource group and accidentally delete a production database. Resource Locks are a safety mechanism that eliminates this type of human error entirely.

Two analogies help clarify the two lock types:

First analogy — Delete lock: Imagine an important sculpture in a park surrounded by a "Do Not Touch" fence. Visitors can see it and photograph it (read and modify are allowed), but no one can remove or destroy it (deletion is blocked).

Second analogy — ReadOnly lock: Think of an artifact inside a museum glass case. Visitors can only look (read is allowed). They cannot touch it (modification is blocked) or take it out (deletion is blocked).

Lock Types Compared in Detail

| Lock Type | Read | Modify | Delete | Best Used When | |-----------|------|--------|--------|---------------| | Delete | Yes | Yes | No | Preventing accidental deletion of production resources | | ReadOnly | Yes | No | No | Audit scenarios, preventing any configuration changes |

Lock Inheritance and Scope

Locks follow Azure's hierarchy and are inherited downward. A lock placed at the subscription level applies to every resource group and resource inside it. A lock placed at the resource group level applies to every resource inside that group.

Critical point: locks take precedence over RBAC permissions. Even a user with the Owner role — the highest permission level in Azure — cannot delete a locked resource without first removing the lock. This is precisely what makes locks so powerful. You must explicitly remove the lock before any deletion can proceed.

Inheritance order: Subscription → Resource Group → Individual Resource

!Delete lock versus ReadOnly lock

Azure Blueprints — Office Interior Design Package

When a company opens a new branch office, it would be wildly inefficient to design the interior from scratch every time. Instead, the company creates a standard office design package — furniture, security systems, network setup — and replicates it for every new location.

Azure Blueprints applies this concept to cloud environments. When setting up a new Azure environment (subscription), Blueprints packages together all necessary policies, RBAC role assignments, resource groups, and ARM templates for one-click deployment.

What Blueprints Can Include

Azure Policy definitions and initiatives RBAC role assignments (who can do what) Resource group creation ARM templates (deploying specific resources)

Example: A financial compliance Blueprint defined once means every new project team automatically gets GDPR compliance policies, security roles, and standard network configuration — instantly, with no manual setup.

 

Service Trust Portal — Security Audit Reading Room

Many organizations, especially in finance and healthcare, must verify that their cloud provider actually complies with security regulations — proven by independent audit reports. The Service Trust Portal is Microsoft's public portal where it shares security, privacy, and compliance information for Azure, Microsoft 365, and Dynamics 365.

What You Can Find in the Service Trust Portal

Independent audit reports (SOC 1, SOC 2, SOC 3) ISO certifications (ISO 27001, ISO 27018, etc.) GDPR compliance documentation Country-specific compliance guides Penetration test reports Security white papers

Service Trust Portal URL: servicetrust.microsoft.com (requires Microsoft account sign-in)

 

Data Sovereignty and Data Residency

Global organizations using the cloud must consider two closely related concepts.

Data Residency refers to which country or regi

Back to blog list