
Advanced Azure Policy Techniques #5: Versioning and rollout
Once you have set up your policy estate, I’m afraid the work doesn’t quite stop. While you have (hopefully) a solid set of initiatives, policies and assigments that ensure all components meet your minimum security and compliance baseline, new developments will require your vigilance and adaptations to your policies – driven by new threats, new cloud offerings, or changes to the structure of your cloud resources and services.
If you are using built-in policies, you’re in luck, Microsoft will take care of maintenance and updates, as they are part of Microsoft’s secure by default paradigm. Of course your resources belong to you, so while Microsoft will periodically review and adapt these policies, they are versioned too and applying a new version is up to you, since otherwise changes to the policy definition could cause problems for your resources (e.g. by enforcing TLS 1.3 when your legacy application might only support TLS 1.2).
















