# Locate a custom policy definition where its intended subscriptions can use it

> Can a policy definition stored in one subscription be assigned to resources in a sibling subscription?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-528-locate-a-custom-policy-definition-where-its-intended-subscriptions-can-use-it/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:23:08+00:00
- Modified: 2026-09-10T02:11:18+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Can a policy definition stored in one subscription be assigned to resources in a sibling subscription?

## Potentially affected

Azure Policy authors choosing the definition location for a custom policy or initiative.

## DSE recommendation

Map intended assignment subscriptions to their hierarchy before selecting the definition's storage location.

## Article

## Source facts

Azure Policy definitions and initiatives are created at either a subscription or management-group location. That location constrains where they can be assigned: a subscription-level definition can serve only resources within that subscription. A management-group definition can serve its descendant management groups and subscriptions. Microsoft directs authors planning assignments across several subscriptions to place the definition at a management group containing all of them. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/governance/policy/concepts/definition-structure-basics).

## Applicability

Use this design check before creating a shared custom definition. Its storage location and a later assignment’s scope are separate choices; begin with the subscriptions that actually need the definition instead of selecting whichever subscription happens to be active in the portal.

## DSE recommendation

Map intended assignment subscriptions to their hierarchy before selecting the definition’s storage location. Ask the governance owner to identify the common containing management group when multiple subscriptions must consume it. Keep intended reuse distinct from broad enforcement: making a definition available to descendants is not an instruction to assign it everywhere. Record the chosen location with the definition owner and expected consumers.

## Verification

Inspect the created definition’s resource identifier and compare its location with the planned hierarchy. During an approved nonproduction rollout, confirm that intended assignment scopes can reference that definition. Investigate an unavailable sibling scope as a placement issue before copying the definition into several independently maintained versions. Revisit the mapping when subscriptions are reorganized, and preserve any unresolved scope mismatch in the deployment review.

## Official references

[Microsoft Learn: Azure Policy definition structure and location](https://learn.microsoft.com/en-us/azure/governance/policy/concepts/definition-structure-basics). Source reviewed September 9, 2026.

## Primary reference

- Name: Details of Azure Policy definition structure basics - Azure Policy | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/governance/policy/concepts/definition-structure-basics
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Locate a custom policy definition where its intended subscriptions can use it,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-528-locate-a-custom-policy-definition-where-its-intended-subscriptions-can-use-it/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
