This command creates a policy definition named LocationDefinition that contains the policy rule specified in C:\LocationPolicy.json.
Example content for the LocationPolicy.json file is provided above.
Three file content formats are supported:
1.
Policy rule only (example above).
2.
Policy properties object.
This format is displayed in the portal when editing a policy definition and may include parameters.
3.
Full policy object.
This format is generated by the Azure Policy export function and may include parameters.
Note: Values provided on the command line (e.g.
parameters, metadata) override corresponding values present in the file.
Example 2: Create a parameterized policy definition using inline parameters
This command creates a policy definition named LocationDefinition that contains the policy rule specified in C:\LocationPolicy.json.
The parameter definition for the policy rule is provided inline.
Example 3: Create a policy definition inline in a management group
This command creates a policy definition named VMPolicyDefinition in management group Dept42.
The command specifies the policy as a string in valid JSON format.
Example 4: Create a policy definition inline with metadata
This command creates a policy definition named VMPolicyDefinition with metadata indicating its category is "Virtual Machine".
The command specifies the policy as a string in valid JSON format.
Example 5: Create a policy definition inline with mode
This command creates a policy definition named TagsPolicyDefinition with mode "Indexed" indicating the policy should be evaluated only for resource types that support tags and location.
Example 6: Create a policy definition inline with version
This command creates a policy definition named VMPolicyDefinition with incremented version 2.0.0.
The command specifies the policy as a string in valid JSON format.
Example 7: Create a policy definition with external evaluation enforcement settings
This command creates a policy definition named InvokePolicy with external evaluation enforcement settings to call the CoinFlip endpoint, which requires the specified role definition.
Parameters
-Confirm
Prompts you for confirmation before running the cmdlet.
The DefaultProfile parameter is not functional.
Use the SubscriptionId parameter when available if executing the cmdlet against a different subscription.
What to do when evaluating an enforcement policy that requires an external evaluation and the token is missing.
Possible values are Audit and Deny and language expressions are supported.
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable,
-InformationAction, -InformationVariable, -OutBuffer, -OutVariable, -PipelineVariable,
-ProgressAction, -Verbose, -WarningAction, and -WarningVariable. For more information, see
about_CommonParameters.
The source for this content can be found on GitHub, where you can also create and review issues and pull requests. For more information, see our contributor guide.