GuideInformationCybersecurityIT

Locate a custom policy definition where its intended subscriptions can use it

Can a policy definition stored in one subscription be assigned to resources in a sibling subscription?

Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.
DSE visual intelligenceCyber defenseGuide · 2 min read
Executive summary

What you need to know

Can a policy definition stored in one subscription be assigned to resources in a sibling subscription?

Potentially affected

Azure Policy authors choosing the definition location for a custom policy or initiative.

DSE recommendation

Map intended assignment subscriptions to their hierarchy before selecting the definition's storage location.

Source facts

Azure Policy definitions and initiatives are created at either a subscription or management-group location. That location constrains where they can be assigned: a subscription-level definition can serve only resources within that subscription. A management-group definition can serve its descendant management groups and subscriptions. Microsoft directs authors planning assignments across several subscriptions to place the definition at a management group containing all of them. Microsoft Learn.

Applicability

Use this design check before creating a shared custom definition. Its storage location and a later assignment’s scope are separate choices; begin with the subscriptions that actually need the definition instead of selecting whichever subscription happens to be active in the portal.

DSE recommendation

Map intended assignment subscriptions to their hierarchy before selecting the definition’s storage location. Ask the governance owner to identify the common containing management group when multiple subscriptions must consume it. Keep intended reuse distinct from broad enforcement: making a definition available to descendants is not an instruction to assign it everywhere. Record the chosen location with the definition owner and expected consumers.

Verification

Inspect the created definition’s resource identifier and compare its location with the planned hierarchy. During an approved nonproduction rollout, confirm that intended assignment scopes can reference that definition. Investigate an unavailable sibling scope as a placement issue before copying the definition into several independently maintained versions. Revisit the mapping when subscriptions are reorganized, and preserve any unresolved scope mismatch in the deployment review.

Official references

Microsoft Learn: Azure Policy definition structure and location. Source reviewed September 9, 2026.

Primary reference

Review the official source

Details of Azure Policy definition structure basics - Azure Policy | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE