Skip to main content

Azure Policy Regulatory Compliance Guide

What this view shows

Open Investigate -> Analyze -> Governance -> Regulatory Compliance, then select one Azure subscription. Spotto shows the regulatory initiatives Azure reports as effective for that subscription, their controls and contributing policies, evaluated resources, existing exemptions, and any evidence-coverage problem that needs attention.

Azure Policy evidence is not certification

This is a partial technical view of Azure Policy assignments and evaluations. It is not a certification, attestation, audit conclusion, legal opinion, or a claim of parity with Microsoft Defender for Cloud. Missing or unavailable evidence is never treated as compliant.

Azure remains the source of truth. Spotto preserves Azure's reported counts and percentages rather than creating a separate audit score.

Why use this view

Use Regulatory Compliance to confirm which Azure Policy standards actually apply to a subscription, separate missing evidence from a clean result, and trace a non-compliant control to the affected resources. You can also record optional standard recommendations and, with separate write access, request a narrowly scoped exemption without losing the Azure assignment context.

Read the evidence states

StateMeaning
CompleteThe required source completed for this scan. Spotto keeps this successful state quiet instead of showing a confirmation banner. A complete empty result is different from unavailable evidence.
PartialSome evidence is usable, but one or more queries, pages, joins, or metadata sources were incomplete.
UnavailableAzure denied or did not expose the required evidence. Do not interpret empty rows as a clean result.
StaleEvidence exists but is older than the current collection window.
Not collectedSpotto has not produced this evidence for the selected subscription yet.

Azure evaluation states remain explicit, including compliant, non-compliant, exempt, error, conflicting, unknown, protected, not started, and not registered. A zero non-compliant count only describes the available evaluated rows; it does not repair missing coverage. See Azure Policy compliance states for Microsoft's state definitions.

Coverage messages appear only when evidence is incomplete, unavailable, out of date, or not collected. If all required sources completed, the page does not add a success message or an evidence-generated timestamp.

The evaluated-resource percentage is displayed only when Azure supplies a meaningful numerator and denominator with usable evaluation coverage. It is Azure Policy evaluated posture, not a certification score.

  • Assigned means an Azure Policy initiative is effective at the subscription, directly or through inheritance.
  • Recommended is customer intent recorded in Spotto at company, cloud-account, or subscription scope. It is guidance, not a mandatory requirement or a failed control.
  • Evaluated means Azure returned compliance evidence for the initiative's controls and resources.

A recommended standard with no effective assignment appears as an optional setup recommendation, not a failed control. Use its Azure definition or documentation link to review the appropriate initiative; assignment happens in Azure, not Spotto. Azure identifies regulatory controls from initiative metadata, as described in Microsoft's regulatory compliance initiative documentation.

Open the collapsed Recommended Standards section and select Manage Standards. The dialog saves one standard preference at a time:

  1. Choose the company, cloud account, or subscription scope.
  2. Select the standard family and, when needed, a preferred Azure definition.
  3. Choose Recommended to show the standard as customer guidance, or Optional to suppress an inherited recommendation at this more-specific scope.
  4. Add an optional note, up to 512 characters, and select Save.

The recommendation shows whether it came from a manual setting or company survey, which scope supplied it, and whether it is explicit or inherited. Subscription settings take precedence over cloud-account settings, which take precedence over company settings. You need Governance management access to change these preferences; read-only users can still view them.

Investigate a control

  1. Select the standard name or its table row to open the initiative's dedicated detail page. Use the page title link to return to Regulatory Compliance.
  2. Review its assignment and effective scopes. An inherited assignment can originate at a management group.
  3. Select Inspect on a control to move to its contributing policies, evaluated resources, matching exemptions, and notes.
  4. Review any evidence-coverage warning before drawing a conclusion. Matching exemptions include the Azure exemption details or justification when Azure provides one, and their expiry is shown as relative time with the exact date available on hover or focus.
  5. Evaluated resource times are shown as relative times, such as 3 hours ago.
  6. Select a resource name to open its Spotto resource details page. Subscription-scope evidence shows the subscription name without a link because it is not an individual Azure resource.
  7. Use the sparkle action labelled Ask Spotto AI for read-only guidance grounded in the selected initiative, control, resource when selected, and non-compliant contributing policies.

When you select a control, Spotto loads its explanatory Azure Policy metadata on demand. About This Control can show Azure's friendly title, description, responsibility, and requirements, while Control Reference keeps the standard identifier visible in a readable form. If Azure supplies an HTTPS reference, Learn More opens that Azure-provided destination in a new tab; the destination may be the standard owner's website rather than Microsoft Learn.

This lookup is independent of the collected compliance evidence. Contributing policies, evaluated resources, exemptions, notes, and actions remain available while control details load or when Azure has no matching metadata. A temporary lookup failure shows Retry only in About This Control; a definitive unavailable result is shown once without implying that the control evaluation failed.

Evaluated Resources shows one row per Azure resource, even when several contributing policies evaluated the same resource. Policies shows how many child-policy evaluations were combined, while Compliant uses the most important state for investigation (for example, one non-compliant evaluation keeps the resource non-compliant). Spotto retains the individual policy references behind the row for AI context and exact exemption requests.

The browser does not send raw resource configuration, exemption justification, ticket content, named approvers, or unrestricted artifacts in general page telemetry.

Collaborate with notes

Open an assigned standard and select a control. In Notes, choose the initiative, selected control, or one of its contributing policies, then add context such as a decision, owner, evidence gap, or next step. Target names are displayed in a readable form, even when Azure returns underscore-separated identifiers. Notes show their author and relative creation time and are stored in Spotto for your team. They do not change the policy assignment, evaluation, exemption, or any other Azure resource.

Select Draft With AI to ask Spotto AI for an editable starting point based on the current initiative, control, and non-compliant contributing-policy evidence. If text is already present, the prompt asks AI to improve that draft. When the matching AI request completes, Spotto places the response in the note field and stops the sending state. AI cannot save the note. Review the result and select Save Note yourself. Governance view access can read notes, while Governance manage access is required to add or delete one. Deleting a note requires confirmation and permanently removes it from Spotto.

Regulatory notes follow the Azure cloud account lifecycle. Deleting an Azure cloud account from Spotto permanently removes the regulatory notes for its subscriptions during account deletion. This cleanup affects Spotto's collaboration records only; it does not delete or modify Azure Policy assignments, evaluations, exemptions, or attestations.

Spotto notes are deliberately separate from two Azure-native concepts:

  • An Azure Policy exemption changes how an assigned policy is evaluated for a bounded scope and is created through the separate Exception workflow.
  • An Azure Policy attestation records formal compliance evidence for a policy that uses the Manual effect. Azure attestations can contain a compliance state, comments, evidence links, owner, assessment date, and expiry. Spotto does not publish notes as attestations in this release. See Azure Policy's Manual effect and attestations.

Keeping ordinary discussion in Spotto avoids accidentally turning an internal comment into formal Azure compliance evidence. A future attestation workflow would need separate Azure permissions, explicit confirmation, and clear applicability to Manual policies.

Decide between remediation and an exemption

Remediate the resource when the control should apply and can be met. Use an exemption only when a reviewed exception is justified:

  • Waiver: the non-compliant state is temporarily accepted.
  • Mitigated: the policy intent is met through another approved method.

Spotto creates exemptions for one or more exact child-policy reference IDs returned by the selected initiative. It does not offer whole-initiative exemptions from a control row. Targets are limited to the selected subscription, a resource group derived from returned resource evidence, or an exact returned resource. These fields follow the Azure Policy exemption structure.

Broader subscription or resource-group exemptions affect more resources. Record a clear owner, risk decision, compensating control where relevant, ticket reference, and an expiry whenever the exception is temporary. Azure preserves an expired exemption resource for record keeping, but no longer honors it.

Create and monitor an exemption

  1. Open a non-compliant control or resource and select Exception. The Create Azure Policy Exemption dialog opens.
  2. Choose the bounded target, Waiver or Mitigated, and enter a display name and justification.
  3. Optionally add a future expiry, ticket reference, requester, and approver.
  4. Select Review Request, then check the exact target, category, child-policy references, expiry, and justification.
  5. Select Request Exemption. After the API accepts the queued request, the dialog closes so you can continue working. Spotto monitors the request in the background; Queued and in progress do not mean Azure has created the exemption.
  6. Spotto shows a notification when Azure reports success or failure. A successful request does not start another subscription scan. The exemption appears in Regulatory Compliance after the next scheduled scan or after you start a scan manually.

Display names are limited to 128 characters and justifications to 512 characters. Ticket, requester, and approver fields each allow 256 characters. Expiry is optional but must be a future date and time.

Draft With Spotto requests an editable AI draft based on the selected control/resource evidence. Review and edit it; AI cannot submit the exemption and human confirmation remains required.

The Exemption Expiry section defaults to a 30-day lookahead and also supports 7, 60, and 90 days. Use Show Full Inventory to inspect active, expired, no-expiry, and unknown-lifecycle exemption records.

Required Azure access

Regulatory evidence remains readable when exemption creation is disabled. Creation requires a separate Spotto manage entitlement and both Azure actions:

  • Microsoft.Authorization/policyExemptions/write at the exemption target.
  • Microsoft.Authorization/policyAssignments/exempt/action at the policy assignment scope.

A subscription-scoped assignment can use the subscription role. An initiative inherited from a management group also needs the assignment action at that management group. See Azure Policy exemption permissions.

Troubleshooting

No regulatory initiatives

Check the assignment coverage state. A complete empty assignment result means Azure returned no effective regulatory initiatives; unavailable or partial coverage means Spotto cannot prove that none exist. Recommended-but-unassigned standards appear separately as optional setup recommendations.

Control details are unavailable

What you're seeing: About This Control says that control details are not available, could not be verified, or it offers Retry.

How to fix: Continue reviewing the contributing-policy and evaluated-resource evidence. If Retry is shown, use it to repeat a temporary metadata lookup. If no retry is offered, Spotto has no verified explanatory details to show for that control; this does not change its evaluation state.

Exemption request returns 403

A Spotto 403 means the signed-in user lacks the product entitlement. It is distinct from Azure rejecting the cloud service principal. Ask a Governance administrator for exemption management access.

Exception is unavailable on a non-compliant row

What you're seeing: The Exception action is present but unavailable.

How to fix: Hover over or focus the action to read the specific reason. You may need Spotto exemption-management access, policyExemptions/write at the target, or policyAssignments/exempt/action at the assignment scope. For an inherited initiative, the latter permission belongs at the originating management group.

A regulatory note cannot be saved or deleted

What you're seeing: Save Note or Delete Note is unavailable, or the API rejects the action.

How to fix: Confirm that your role has Governance manage access. Governance view access can read notes but cannot add or delete them. A failed save keeps the current draft in the note field so you can retry.

Draft With AI does not fill the note field

What you're seeing: The AI request fails, is cancelled, or completes after you move to another subscription or initiative.

How to fix: Return to the intended note target and retry Draft With AI. Suggestions are bound to the company, subscription, initiative, and target that started the request, so a response cannot be inserted into a different customer's note. You can continue writing and saving the note manually.

Exemption fails after queueing

Review the safe terminal message. Confirm the target write action and assignment-scope action are both present. For inherited initiatives, check the exact management-group assignment scope. Wait for Azure RBAC propagation and retry the retained request.

Evidence or capability changed (409)

Spotto refreshes the summary and assignment because the assignment, child-policy references, target evidence, request identity, or known Azure capability changed. Your form values are retained; review the refreshed evidence and confirm a new submission.

Evaluation or exemption is stale

Azure Policy evaluation and exemption discovery are asynchronous. Run the Azure cloud-account sync again, review any coverage warning, and wait for Azure's evaluation cycle. An expired exemption remains visible but is not active.

Optimize Your Azure Environment

Looking to enhance your cloud setup for cost efficiency, performance, reliability, or security?

Talk to a cloud specialist. Email us or schedule a 30-minute consultation and let's optimize your cloud environment together.

Book a Free Consultation