Effect of editing custom Azure Policy definition on existing assignments?

Mark Poole (7805) 0 Reputation points
2024-10-14T15:13:09.56+00:00

I am trying to understand how editing a custom Azure policy definition affects existing assignments but can't find any info on this.

Our scenario: We have a custom policy definition for the deployment and configuration of the AMA client on Arc connected machines. The policy was assigned to an RG with Arc connected machines in it. The AMA client was installed and configured, and the machines showed as being compliant with the policy. Unfortunately, the policy definition has a typo in the proxy settings so the machines need updating with the correct value.

I updated the policy definition but clients still reported as being compliant with the policy even though the AMA client reported back the wrong proxy config.

I then tried removing the policy assignments and creating new policy assignments against the updated policy definition. The clients still report back as being compliant with the policy even though the AMA client is still reporting back the wrong proxy config. I have manually triggered a compliance scan to try and rule out the compliance date being stale.

I am expecting the clients to become non-compliant as their AMA config no longer matches the policy definition but this does not seem to be happening. Am I wrong in my expectations?

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
898 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.