From 7e8e025ffab47a3aaa00db85b2d3e819c9f97f55 Mon Sep 17 00:00:00 2001 From: Andi Schabus Date: Tue, 19 Dec 2023 10:32:46 +0100 Subject: [PATCH] Change "evaluationDelay" to "AfterProvisioning" The policy evaluation has been set to run after the provisioning instead of waiting for 10 minutes. For more information, refer to: https://learn.microsoft.com/en-us/azure/governance/policy/concepts/effects#deployifnotexists --- .../deploy-resource-lock-on-rgs-tag-exclusion/azurepolicy.json | 1 + .../azurepolicy.rules.json | 1 + 2 files changed, 2 insertions(+) diff --git a/policyDefinitions/General/deploy-resource-lock-on-rgs-tag-exclusion/azurepolicy.json b/policyDefinitions/General/deploy-resource-lock-on-rgs-tag-exclusion/azurepolicy.json index 92993d61..64b984ff 100644 --- a/policyDefinitions/General/deploy-resource-lock-on-rgs-tag-exclusion/azurepolicy.json +++ b/policyDefinitions/General/deploy-resource-lock-on-rgs-tag-exclusion/azurepolicy.json @@ -59,6 +59,7 @@ "effect": "[parameters('effect')]", "details": { "type": "Microsoft.Authorization/locks", + "evaluationDelay": "AfterProvisioning", "existenceCondition": { "field": "Microsoft.Authorization/locks/level", "equals": "CanNotDelete" diff --git a/policyDefinitions/General/deploy-resource-lock-on-rgs-tag-exclusion/azurepolicy.rules.json b/policyDefinitions/General/deploy-resource-lock-on-rgs-tag-exclusion/azurepolicy.rules.json index 80a63999..c053e5cc 100644 --- a/policyDefinitions/General/deploy-resource-lock-on-rgs-tag-exclusion/azurepolicy.rules.json +++ b/policyDefinitions/General/deploy-resource-lock-on-rgs-tag-exclusion/azurepolicy.rules.json @@ -17,6 +17,7 @@ "effect": "[parameters('effect')]", "details": { "type": "Microsoft.Authorization/locks", + "evaluationDelay": "AfterProvisioning", "existenceCondition": { "field": "Microsoft.Authorization/locks/level", "equals": "CanNotDelete"