[AP 4] Effects: What Each One Commits You To

Eleven effects, a fixed order of evaluation, and a delete-protection effect whose cascade behaviour decides whether it protects anything at all.
Identity and data governance: privileged access, reviews, entitlement, lifecycle.

Eleven effects, a fixed order of evaluation, and a delete-protection effect whose cascade behaviour decides whether it protects anything at all.

Assign the security baseline Microsoft maintains, in audit, then read the result by control rather than by resource and separate what you own from what Microsoft owns.

Most of the rules you are about to write already exist. Four policy types, a versioning scheme with real consequences, and a repository that tells you what changed before the portal does.

A definition holds one effect, an initiative holds a parameter surface, and an assignment holds only a reference. Those three facts decide which parts of your governance stay editable and which freeze.

You are already running Azure Policy, because landing zones, Arc and Defender for Cloud all arrive carrying assignments. This is what the engine actually governs, what it costs, and the two ways estates get it wrong.

Which estates stop at role PIM, which need groups, which extend to Azure, and the list of problems you should stop trying to solve with this product. Plus what the rest of the Governance pillar has to pick up.

A quarterly recurring review of who is eligible for Global Administrator, with named reviewers and results that apply themselves. Includes denying a test assignment and proving it actually disappeared.

A just-in-time estate decays back into a standing one within a year, through exceptions that each seemed reasonable. The seven alerts, the reviews that actually remove access, and the two places this costs more than P2.