What you need to know
For existence-check policies, Last evaluated resource can point to the related resource defined in the policy rather than the initially selected asset.
Potentially affected
Azure Policy compliance investigations involving auditIfNotExists or deployIfNotExists definitions.
DSE recommendation
Read the definition's related-resource requirements before proposing a change to the selected asset.
Source facts
For auditIfNotExists and deployIfNotExists, compliance details include the definition’s details.type and optional existence-check properties. Last evaluated resource refers to a related resource from that details section.
Viewing current property values requires the read operation for the resource type; secret values are masked. Compliance details explain the present non-compliance reason, not when the responsible change occurred. Microsoft identifies change history as a separate preview experience. Microsoft Learn.
Applicability
Identify the policy assignment, definition revision, selected resource and related resource named in the evaluation. Keep missing evidence caused by read access separate from the policy’s actual failure reason.
DSE recommendation
DSE recommends tracing the existence condition to the precise related object before opening remediation work. Compare expected and observed properties and note whether the required object is missing or does not meet the condition. Avoid changing an unrelated VM or service merely because its name appears on the compliance page. Preserve masked values as masked rather than requesting secrets to complete the review.
Verification
Use an approved representative evaluation to confirm the related-resource identity and reason. After the authorized correction, recheck the same assignment and condition and compare the resource state independently. Record the evaluation time separately from any established change time. If chronology is needed, collect the supported historical evidence without inventing it from the current compliance result.
Official references
Microsoft Learn: Determine causes of non-compliance. Source retrieved September 9, 2026.
Review the official source
Determine causes of non-compliance - Azure Policy | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE