Using Azure Policy and Resource Locks
Pluralsight Hands-On Lab — Identity & Governance
At a Glance
| Platform | Pluralsight |
| Category | Azure Governance |
| Lab Type | Guided + Challenge Mode |
| Environment | Azure Portal, Azure Policy, Resource Locks |
| Completed | 2026 |
Overview
Azure Policy and resource locks are complementary governance controls: Policy enforces compliance rules across resources at scale, while locks prevent accidental deletion or modification of specific critical resources. In this lab, I explored the Azure Policy interface — reviewing compliance, remediation, events, definitions, assignments, and exemptions — then explored the custom policy and initiative definition workflows, and applied both Delete and Read-only resource locks at the individual resource level to protect a production web app and a VM.
What I Did
- Navigated the Azure Policy interface, reviewing the Compliance, Remediation, and Events blades to understand where compliance summaries, remediation tasks, and resource state change events are surfaced
- Explored the Definitions blade listing all available built-in and custom policy definitions, and opened the custom Policy definition and Initiative definition wizards to review their configuration interfaces
- Reviewed the Assignments blade (where policies and initiatives are deployed to scopes) and the Exemptions blade (where specific resource exemptions are managed for regulatory purposes)
- Explored resource lock placement at the subscription level (Resource locks under Subscriptions) and at the resource group level (Locks under Settings) to understand the inheritance hierarchy
- Applied a Delete lock named "ProductionApplication" to the production web app, preventing accidental deletion while allowing modifications
- Applied a Read-only lock named "DoNotModify" to lab-VM, preventing both deletion and configuration changes — the most restrictive lock type available
← Back to Pluralsight Labs