Skip to content
RTFE_
Error library
Azure PolicyAzure Resource ManagerKnown error

RequestDisallowedByPolicy

Azure Policy said no

Azure Policy β€” deny

What the error looks like

  • Error code
  • WHO β€” identity
  • WHAT β€” action
  • WHERE β€” scope
  • Policy
  • Correlation / trace
{
  "error": {
    "code": "RequestDisallowedByPolicyCODE",
    "target": "stdevdata001",
    "message": "Resource 'stdevdata001' was disallowed by policy. Reasons: 'Required tag Environment is missing.'. See error details for policy resource IDs.",
    "additionalInfo": [
      {
        "type": "PolicyViolation",
        "info": {
          "policyDefinitionDisplayName": "Require-Environment-TagPOLICY",
          "policyAssignmentName": "require-env-tagPOLICY",
          "policyAssignmentId": "/subscriptions/00000000-1111-4222-8333-444444444444/providers/Microsoft.Authorization/policyAssignments/require-env-tagPOLICY",
          "policyDefinitionName": "11111111-2222-4333-8444-555555555555POLICY",
          "policyEffect": "DenyPOLICY"
        }
      }
    ]
  }
}

What you told me

β€œSomething's wrong with the subscription.”

you Β· just now

Let's read it.

RTFE Β· seen

What it actually says

An Azure Policy assignment denied the operation. The error usually names the policy assignment, the definition (or initiative), the resource, and often the property that failed.

Azure outage? No. This is a governance rule working as designed.

The fix

  1. 01Read additionalInfo β†’ policyDefinitionDisplayName and the 'Reasons' text.
  2. 02Change the resource to comply (add the tag, change the SKU, region, setting…).
  3. 03If the resource genuinely can't comply, request a policy exemption from whoever owns the assignment.
Azure CLI β€” inspect the assignment
az policy assignment show \
  --name <policy-assignment-name> \
  --scope <scope>

Read it faster next time

Search for 'policyDefinitionDisplayName' in the error. That's the rule you broke.

Further reading

Open Microsoft Learn

Related errors