The destination resource group must not have any existing App Service resources. App Service resources include: Web Apps App Service plans Uploaded or imported TLS/SSL certificates App Service Environments
Policies are inherited
Can you assign the Azure Policy exclusion at the Tenant Root Group Level? NO :bangbang:
| Level | Policy |
| Tenant | :x: |
| Mgmt group| :white_check_mark: |
| Subscription| :white_check_mark: |
| Resource Group| :white_check_mark: |
| Resource| :x: |
Not allowed resource types (Deny): Prevents a list of resource types from being deployed. - so these resources cannot be modified. :bangbang:
If I try to create a new resource this needs to be compliant. On the existing resources they will be marked as not policiy compliant.
Management groups are containers that help you manage access, policy, and compliance across multiple subscriptions. Create these containers to build an effective and efficient hierarchy that can be used with Azure Policy and Azure Role Based Access Controls.
Tags cannot be applied to Mgmt group!