[Feature Request]: Allow Resource level policy exemption
Open
[cat] needs further discussion
blocked
enhancement
- Dominant language
- PowerShell
- Stars
- 737
- Forks
- 436
- Avg merge
- 10d 7h
- Merged PRs (30d)
- 1
Description
### Description
The current policyExemption modules only support exemptions at the MG, Sub, or RG levels. When policyExemptions are deployed to resources, they are treated as extensions. We need this capability to allow the creation of a storage account with public access when we have a policy applied to the Sub or MG that blocks this access.
If implemented, this would need to be added to all resource types as assignments can be created on every resource's level.
Contributor guide
Assessment
This issue has not been assessed yet.