Security wants several house rules—HTTPS on storage, no anonymous blobs, and Key Vault firewall—assigned once across the canal estate. Which Azure Policy construct should you use?
Select an answer to reveal the explanation.
Short Explanation
An initiative is the binder: drop HTTPS-on-storage, no-anonymous-blobs, and Key Vault firewall into one set and assign it once. Twenty loose policies drift like twenty sticky notes.
Full Explanation
A policy definition is a single rule; an initiative (policy set) groups multiple definitions for coordinated assignment and compliance tracking. Bundling related storage and Key Vault guardrails into an initiative reduces assignment drift compared with many independent assignments. Defender for Cloud regulatory standards and Secure Score are related posture tools but are not a substitute for choosing initiative versus definition when the task is Azure Policy assignment design.