Build Azure Policy initiative (policy set) configs with parameterized definitions, definition groups, and non-compliance messages.
Output will appear here...Build an Azure Policy initiative (policy set) grouping multiple policyDefinitions under a shared groupName, each with its own effect (Audit, Deny, AuditIfNotExists, DeployIfNotExists, Disabled), plus initiative-level parameters that individual member policies can reference so one initiative assignment can configure many policies' behavior consistently rather than needing separate parameter values per policy. The effect field per policy definition reference is a real operational lever distinct from the policy definition itself: the same underlying policy definition (say, 'require a specific tag') can be assigned with effect Audit for visibility-only reporting or Deny for actual enforcement blocking non-compliant resource creation, and initiatives commonly parameterize effect itself so the same initiative can run in Audit mode in a test environment and Deny mode in production without needing two separate initiatives.
The tool validates that initiativeName, displayName, and at least one complete policy definition reference (with a non-empty policyDefinitionId) are present, then assembles the initiative definition combining parameters and policyDefinitions into the shape Azure Policy's CreatePolicySetDefinition API expects; it can't verify the referenced policyDefinitionId values actually exist or that referenced parameter names in each policy definition reference correspond to genuinely declared initiative parameters, those are only confirmed against the live Azure Policy service.
Never flip a policy from Audit to Deny without first reviewing how many currently non-compliant resources exist under Audit, an abrupt switch to Deny can unexpectedly block routine updates to resources that have been quietly non-compliant for a while, a rollout surprise worth avoiding.
Group related policies under a meaningful groupName from the start, an initiative that grows into dozens of ungrouped policy references becomes hard to reason about as a coherent governance story rather than a flat compliance checklist.
Parameterize effect for initiatives that need different enforcement postures across environments (test versus production), rather than maintaining separate, potentially-drifting initiative definitions for each environment's enforcement level.
Was this tool helpful?
Disclaimer: This tool runs entirely in your browser. No data is sent to our servers. Always verify outputs before using them in production. AWS, Azure, and GCP are trademarks of their respective owners.