Skip to main content

Azure Policy Initiative

A collection of individual Azure Policy definitions grouped together and assigned as a single unit, used to enforce a broader compliance standard (such as "PCI-DSS baseline") across multiple resources at once.

Azure Policy Initiative

An Initiative bundles related policies — like "require encryption," "deny public storage," and "require tags" — so they're assigned and tracked together instead of one by one.

Why It Matters in Production

Razorpay assigns a custom "PCI Compliance Initiative" across its payments subscription, bundling 12 individual policies, so compliance auditors get a single compliance score instead of checking 12 separate policy states.

Bash
az policy set-definition create --name pci-baseline-initiative \
--definitions @initiative-definitions.json
Tip

Start new policies in "Audit" mode before switching to "Deny" — this shows you what would break without actually blocking deployments.

Frequently Asked Questions

Why use an initiative instead of assigning individual policies one at a time?

Assigning dozens of individual policy definitions separately means tracking compliance against each one independently, with no single score representing whether a broader standard like PCI-DSS or ISO 27001 is met. An initiative bundles related definitions into one assignable unit with one compliance percentage, so auditors and platform teams get a single pass/fail view instead of reconciling twenty separate policy states manually. Microsoft ships built-in initiatives for common regulatory baselines.

What's a common mistake when rolling out a new policy initiative?

Assigning an initiative with 'Deny' effect policies directly to a production management group without first running it in 'Audit' mode. Audit mode reports non-compliant resources without blocking anything, letting you see the blast radius before enforcement. Skipping straight to Deny commonly breaks existing deployment pipelines that were creating resources in a way the policy now prohibits, with the failure surfacing as a cryptic ARM deployment error rather than an obvious policy violation.