Securing Access to Azure Resources with Managed Disks

Preventing Creation of Azure Virtual Machines with Unmanaged Disks

Question

You are securing access to the resources in an Azure subscription.

A new company policy states that all the Azure virtual machines in the subscription must use managed disks.

You need to prevent users from creating virtual machines that use unmanaged disks.

What should you use?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

B

The correct answer is B. Azure Policy.

Azure Policy is a service in Azure that allows you to create, assign, and manage policies to enforce compliance with organizational standards and regulations. Azure Policy can be used to define rules that ensure that resources deployed in an Azure subscription comply with specific guidelines or restrictions.

In this case, you need to prevent users from creating virtual machines that use unmanaged disks. To accomplish this, you can create an Azure Policy that specifies the use of managed disks for all virtual machines deployed in the subscription. This policy can be enforced by assigning it to the subscription.

Once the policy is assigned, Azure Policy will evaluate resources in the subscription to ensure they comply with the policy. If a virtual machine is created that uses an unmanaged disk, Azure Policy will prevent the deployment and notify the user that their resource does not comply with the policy.

Azure Monitor is a service that provides monitoring and alerting capabilities for Azure resources. While it can be used to monitor and alert on policy violations, it is not designed to enforce policy compliance.

Azure Security Center is a service that provides security recommendations and threat protection for Azure resources. While it can provide recommendations related to managing disks for virtual machines, it is not designed to enforce policy compliance.

Azure Service Health is a service that provides information about service incidents and planned maintenance for Azure resources. It is not designed to enforce policy compliance.