Skip to content

Commit c5bd723

Browse files
committed
Update governance-rules.md
Added a section for effective rules on scope
1 parent 5e6e933 commit c5bd723

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

articles/defender-for-cloud/governance-rules.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -86,6 +86,9 @@ If there are existing recommendations that match the definition of the governanc
8686
> - Create and apply rules on multiple scopes at once using management scopes cross cloud.
8787
> - Check effective rules on selected scope using the scope filter.
8888
89+
To view the effect rules on specific scope, use the “scope” filter and select a desired scope.
90+
In general, rules on management scopes (Azure management groups, AWS master accents, GCP organizations) take effect before rules on scopes (Azure subscriptions, AWS accounts, or GCP projects). Conflicting rules are applied in priority order.
91+
8992
## Manually assigning owners and due dates for recommendation remediation
9093

9194
For every resource affected by a recommendation, you can assign an owner and a due date so that you know who needs to implement the security changes to improve your security posture and when they're expected to do it by. You can also apply a grace period so that the resources that are given a due date don't impact your secure score unless they become overdue.

0 commit comments

Comments
 (0)