Municipal cloud governance wants to know whether every resource has a required Department tag without immediately blocking deployments. Which Azure Policy theme best fits?
Select an answer to reveal the explanation.
Short Explanation
Audit mode is the flashlight: it shows which resources skipped the Department tag without slamming the door on deployers yet. Deny comes later when the city is ready to enforce. Locks and Entra licenses are different tools.
Full Explanation
Azure Policy can audit compliance—for example reporting resources that lack a required tag—without necessarily denying creation, depending on the effect chosen. That supports a measure-then-enforce governance path for municipal standards. Resource locks, billing substitution, and Entra licensing are not the mechanism for tag-compliance auditing.