This article shows how to create Azure Policy Assignments to prevent Azure Administrators or Devepores from creating expensive Virtual Machines. and create some resources types (for example express Route)

We will cover steps using Azure Portal and PowerShell

We will be using the following existing two policies
Allowed virtual machine size SKUs Policy Assignment
Not allowed resource types

Navigate to Policy-Definitions, search for Allowed virtual machine size SKUs definitions. Select Assign form right menu

On the Basic tab leave it as default. By default, this policy will be assigned to the whole subscription

Navigate to the Parameters tab and select all SKUs which you want to be available for your users

After you assign a policy, this is a screen which will be available during VM creation. The end-users will see which VM is blocked and which are allowed.

Setup Policy Assignment using PowerShell

You can use this script to create policy  assignment. Just add your SKUs in $SKUs variable.

$location=”Canada Central”

# Create a Azure Policy Assignment (Allowed virtual machine size SKUs)
# Allow VM creation only for the following SKUs

$PolicyAssignmentName=”Allowed virtual machine size SKUs”
$Policy = Get-AzPolicyDefinition -Builtin | Where-Object {$_.Properties.DisplayName -eq “Allowed virtual machine size SKUs”}
$Parameter = @{“listOfAllowedSKUs”=@($SKUs)}
New-AzPolicyAssignment -Name $PolicyAssignmentName -PolicyDefinition $Policy -Scope “/subscriptions/$SubscriptionId” -PolicyParameterObject $Parameter -Location $location -AssignIdentity

We can use the following commands to check is assignment has been assigned 
$Policy = Get-AzPolicyAssignment -Name “Allowed virtual machine size SKUs”
($Policy).Properties.Parameters.listOfAllowedSKUs | fl


Setup Policy Assignment using Portal

To set up this policy assignment, type Not Allowed Resource Types in search and navigate to the Assign buttons as presented in the following pictures.

On the Basic tab leave it as default. By default, this policy will be assigned to the whole subscription

Navigate to the Parameters tab and select all services which you do not want to be available for your users

Setup Policy Assignment using PowerShell

You can use this script to create policy  assignment. Just add your resources s in $BlockResources variable.

$location=”Canada Central”

# Create an Azure Policy Assignment (Not allowed resource types)
# Dendy creation only for the following resource types

$PolicyAssignmentName=”Not allowed resource types”
$Policy = Get-AzPolicyDefinition -Builtin | Where-Object {$_.Properties.DisplayName -eq “Not allowed resource types”}
$Parameter = @{“listOfResourceTypesNotAllowed”=@($BlockResources)}
New-AzPolicyAssignment -Name $PolicyAssignmentName -PolicyDefinition $Policy -Scope “/subscriptions/$SubscriptionId” -PolicyParameterObject $Parameter -Location $location -AssignIdentity -Verbose

We can use the following commands to check is assignment has been assigned 
$Policy = Get-AzPolicyAssignment -Name “Not allowed resource types”
($Policy).Properties.Parameters.listOfResourceTypesNotAllowed | fl

By Dan Djurasovic

Dan is an Azure Technical Advisor, with over a dozen years of IT experience, specializing in Microsoft Office 365, Exchange Server Azure IaaS and Active Directory..

Related Post

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.