Azure PolicyAzure Resource ManagerKnown error
RequestDisallowedByPolicy
Azure Policy said no
Azure Policy β deny
What the error looks like
- Error code
- WHO β identity
- WHAT β action
- WHERE β scope
- Policy
- Correlation / trace
{
"error": {
"code": "RequestDisallowedByPolicyCODE",
"target": "stdevdata001",
"message": "Resource 'stdevdata001' was disallowed by policy. Reasons: 'Required tag Environment is missing.'. See error details for policy resource IDs.",
"additionalInfo": [
{
"type": "PolicyViolation",
"info": {
"policyDefinitionDisplayName": "Require-Environment-TagPOLICY",
"policyAssignmentName": "require-env-tagPOLICY",
"policyAssignmentId": "/subscriptions/00000000-1111-4222-8333-444444444444/providers/Microsoft.Authorization/policyAssignments/require-env-tagPOLICY",
"policyDefinitionName": "11111111-2222-4333-8444-555555555555POLICY",
"policyEffect": "DenyPOLICY"
}
}
]
}
}What you told me
βSomething's wrong with the subscription.β
you Β· just now
Let's read it.
RTFE Β· seen
What it actually says
An Azure Policy assignment denied the operation. The error usually names the policy assignment, the definition (or initiative), the resource, and often the property that failed.
Azure outage? No. This is a governance rule working as designed.
The fix
- 01Read additionalInfo β policyDefinitionDisplayName and the 'Reasons' text.
- 02Change the resource to comply (add the tag, change the SKU, region, settingβ¦).
- 03If the resource genuinely can't comply, request a policy exemption from whoever owns the assignment.
az policy assignment show \
--name <policy-assignment-name> \
--scope <scope>Read it faster next time
Search for 'policyDefinitionDisplayName' in the error. That's the rule you broke.