A Deny-public-IP Azure Policy assignment at the management group must stay in force, but one lock-lab sandbox resource group needs temporary relief. What should the security engineer create?
Select an answer to reveal the explanation.
Short Explanation
Don’t yank the management-group Deny just for one sandbox. Hang a dated policy exemption on that resource group—waiver or mitigated—and leave the big assignment locked on for everyone else.
Full Explanation
Policy exemptions scope relief to a resource, resource group, or other supported scope while the broader assignment remains active. Exemptions are typically category-tagged (for example waiver or mitigated) and can carry an expiration. Deleting the management-group assignment removes enforcement estate-wide. Azure RBAC deny assignments control authorization, not Azure Policy evaluation, and granting Owner does not create a governed exemption.