分配用于确保标记符合性的策略Assign policies for tag compliance

使用 Azure Policy 强制实施标记规则和约定。You use Azure Policy to enforce tagging rules and conventions. 通过创建策略,可以避免将没有组织所需标记的资源部署到订阅。By creating a policy, you avoid the scenario of resources being deployed to your subscription that don't have the expected tags for your organization. 不要手动应用标记或搜索不符合的资源,请创建一个策略,用于在部署期间自动应用所需标记。Instead of manually applying tags or searching for resources that aren't compliant, you create a policy that automatically applies the needed tags during deployment. 现在,还可以通过新的 Modify 效果和修正任务将标记应用于现有资源。Tags can also now be applied to existing resources with the new Modify effect and a remediation task. 以下部分展示标记策略示例。The following section shows example policies for tags.

策略Policies

名称Name
(Azure 门户)(Azure portal)
说明Description 效果Effect(s) 版本Version
(GitHub)(GitHub)
将标记添加到资源组Add a tag to resource groups 创建或更新任何缺少此标记的资源组时添加指定的标记和值。Adds the specified tag and value when any resource group missing this tag is created or updated. 可以通过触发修正任务来修正现有资源组。Existing resource groups can be remediated by triggering a remediation task. 如果存在具有不同值的标记,则不会更改该资源组。If the tag exists with a different value it will not be changed. modifymodify 1.0.01.0.0
将标记添加到资源Add a tag to resources 创建或更新任何缺少此标记的资源时添加指定的标记和值。Adds the specified tag and value when any resource missing this tag is created or updated. 可以通过触发修正任务来修正现有资源。Existing resources can be remediated by triggering a remediation task. 如果存在具有不同值的标记,则不会更改该资源组。If the tag exists with a different value it will not be changed. 而不会修改资源组上的标记。Does not modify tags on resource groups. modifymodify 1.0.01.0.0
在资源组中添加或替换标记Add or replace a tag on resource groups 创建或更新任何资源组时添加或替换指定的标记和值。Adds or replaces the specified tag and value when any resource group is created or updated. 可以通过触发修正任务来修正现有资源组。Existing resource groups can be remediated by triggering a remediation task. modifymodify 1.0.01.0.0
在资源中添加或替换标记Add or replace a tag on resources 创建或更新任何资源时添加或替换指定的标记和值。Adds or replaces the specified tag and value when any resource is created or updated. 可以通过触发修正任务来修正现有资源。Existing resources can be remediated by triggering a remediation task. 而不会修改资源组上的标记。Does not modify tags on resource groups. modifymodify 1.0.01.0.0
追加资源组的标记及其值Append a tag and its value from the resource group 创建或更新任何缺少此标记的资源时,从资源组追加指定的标记及其值。Appends the specified tag with its value from the resource group when any resource which is missing this tag is created or updated. 在更改这些资源之前,请不要修改应用此策略之前创建的资源的标记。Does not modify the tags of resources created before this policy was applied until those resources are changed. 新的“modify”效果策略已可供使用,这些策略支持对现有资源中的标记进行修正(请参阅 https://docs.azure.cn/governance/policy/concepts/effects#modify)。New 'modify' effect policies are available that support remediation of tags on existing resources (see https://docs.azure.cn/governance/policy/concepts/effects#modify). appendappend 1.0.01.0.0
将标记及其值追加到资源组Append a tag and its value to resource groups 创建或更新任何缺少此标记的资源组时追加指定的标记和值。Appends the specified tag and value when any resource group which is missing this tag is created or updated. 在更改这些资源组之前,请不要修改应用此策略之前创建的资源组的标记。Does not modify the tags of resource groups created before this policy was applied until those resource groups are changed. 新的“modify”效果策略已可供使用,这些策略支持对现有资源中的标记进行修正(请参阅 https://docs.azure.cn/governance/policy/concepts/effects#modify)。New 'modify' effect policies are available that support remediation of tags on existing resources (see https://docs.azure.cn/governance/policy/concepts/effects#modify). appendappend 1.0.01.0.0
将标记及其值追加到资源Append a tag and its value to resources 创建或更新任何缺少此标记的资源时追加指定的标记和值。Appends the specified tag and value when any resource which is missing this tag is created or updated. 在更改这些资源之前,请不要修改应用此策略之前创建的资源的标记。Does not modify the tags of resources created before this policy was applied until those resources are changed. 不要应用到资源组。Does not apply to resource groups. 新的“modify”效果策略已可供使用,这些策略支持对现有资源中的标记进行修正(请参阅 https://docs.azure.cn/governance/policy/concepts/effects#modify)。New 'modify' effect policies are available that support remediation of tags on existing resources (see https://docs.azure.cn/governance/policy/concepts/effects#modify). appendappend 1.0.11.0.1
从资源组继承标记Inherit a tag from the resource group 创建或更新任何资源时,添加或替换父资源组中指定的标记和值。Adds or replaces the specified tag and value from the parent resource group when any resource is created or updated. 可以通过触发修正任务来修正现有资源。Existing resources can be remediated by triggering a remediation task. modifymodify 1.0.01.0.0
从资源组继承标记(如果缺少此标记)Inherit a tag from the resource group if missing 创建或更新任何缺少此标记的资源时,从父资源组添加指定的标记及其值。Adds the specified tag with its value from the parent resource group when any resource missing this tag is created or updated. 可以通过触发修正任务来修正现有资源。Existing resources can be remediated by triggering a remediation task. 如果存在具有不同值的标记,则不会更改该资源组。If the tag exists with a different value it will not be changed. modifymodify 1.0.01.0.0
从订阅继承标记Inherit a tag from the subscription 创建或更新任何资源时,添加或替换包含订阅中指定的标记和值。Adds or replaces the specified tag and value from the containing subscription when any resource is created or updated. 可以通过触发修正任务来修正现有资源。Existing resources can be remediated by triggering a remediation task. modifymodify 1.0.01.0.0
从订阅继承标记(如果缺少)Inherit a tag from the subscription if missing 创建或更新任何缺少此标记的资源时,从包含订阅添加指定的标记及其值。Adds the specified tag with its value from the containing subscription when any resource missing this tag is created or updated. 可以通过触发修正任务来修正现有资源。Existing resources can be remediated by triggering a remediation task. 如果存在具有不同值的标记,则不会更改该资源组。If the tag exists with a different value it will not be changed. modifymodify 1.0.01.0.0
需要资源组上的标记及其值Require a tag and its value on resource groups 强制要求资源组中存在所需的标记及其值。Enforces a required tag and its value on resource groups. denydeny 1.0.01.0.0
需要资源上的标记及其值Require a tag and its value on resources 强制执行所需的标记及其值。Enforces a required tag and its value. 不要应用到资源组。Does not apply to resource groups. denydeny 1.0.11.0.1
需要资源组上的标记Require a tag on resource groups 强制要求资源组中存在某个标记。Enforces existence of a tag on resource groups. denydeny 1.0.01.0.0
需要资源上的标记Require a tag on resources 强制要求存在某个标记。Enforces existence of a tag. 不要应用到资源组。Does not apply to resource groups. denydeny 1.0.11.0.1

后续步骤Next steps