Loading…
Type: Security clear filter
Wednesday, April 15
 

10:45am PDT

From Code to Compliance: Enforcing Azure Security with Terraform and Azure Policy-as-Code
Wednesday April 15, 2026 10:45am - 11:30am PDT
“Set it and forget it” doesn’t cut it for cloud security—you need proof that controls are consistently enforced. Azure Policy provides that enforcement layer, but managing definitions, initiatives, and assignments by hand quickly becomes a mess.This session shows how to operationalize Azure Policy with Terraform, so your baselines are versioned, reviewable, and consistently applied across subscriptions and management groups. Beyond simply deploying policy, you’ll see how treating policies as code unlocks change control, peer review, and CI/CD approval workflows—making compliance part of your release process instead of an afterthought.We’ll start with a quick primer on Azure Policy for anyone new to its concepts (definitions, initiatives, assignments, exemptions, and remediations), then move into practical patterns and live demos:• Author and organize policy definitions and initiatives• Parameterize assignments per scope, attach non-compliance messages, and configure deployIfNotExists remediations with the right role assignments• Manage exemptions cleanly (temporary, scoped, time-boxed) while avoiding “exemption sprawl”• Integrate policy into CI/CD: pull requests for changes, approval gates for rollout, and drift detection for audits• End-to-end demo: define an initiative, assign it at a management group, exempt a subscription for a pilot, and kick off remediations — all in TerraformBy the end, you’ll know how to evolve your Azure Policy workflows to be repeatable, auditable, and code-driven that fit neatly into modern DevOps practices.
Speakers
avatar for Blake Cherry

Blake Cherry

Principal in Cybersecurity & Enterprise Technology, West Monroe
Blake is a Principal in West Monroe's Technology practice, operating out of Chicago, IL. Known for accelerating the delivery of best practice infrastructure by leveraging infrastructure as code, his expertise lies in Azure, Microsoft 365, and Infrastructure Automation, with a specialized... Read More →
avatar for Danny Stutz

Danny Stutz

Cybersecurity & Enterprise IT Architect, West Monroe
I am passionate about technology, learning new things, and working with computers! I love PowerShell and any automation tools I can use to help streamline my work and personal projects I work on. I specialize in Microsoft 365, Entra ID (Azure AD), AD, AWS, Azure and other cloud platforms... Read More →
Wednesday April 15, 2026 10:45am - 11:30am PDT
Meydenbauer Center - Room 405 11100 NE 6th St, Bellevue, WA 98004, USA
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.