An Azure policy 'Not allowed resource types' is assigned to RG1 with parameters Microsoft.Network/virtualNetworks and Microsoft.Compute/virtualMachines and policy enforcement enabled. In RG1 you need to create VM2 and connect it to VNET1. What should you do first?
Choose an answer
Tap an option to check your answer.
Correct answer: Remove Microsoft.Compute/virtualMachines from the policy..
Why this is the answer
The policy 'Not allowed resource types' with enforcement enabled prevents the creation of specified resource types. Since Microsoft.Compute/virtualMachines is listed, you cannot create VM2 in RG1. Removing this resource type from the policy's parameters will allow you to create the virtual machine. Creating an Azure Resource Manager template doesn't bypass the policy enforcement. Adding a subnet to VNET1 is a networking configuration step, not a solution for policy enforcement preventing VM creation. Removing Microsoft.Network/virtualNetworks from the policy would allow new virtual networks, but the problem is creating a virtual machine, not a virtual network.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed