I have the same problem.
Azure policy did not apply tags to the resources
Hill Alcantara
51
Reputation points
I enforced a policy to my subscription but it failed to tag networking and managed identity resources such as:
microsoft.network/privatednszones
microsoft.network/privatednszones/virtualnetworklinks
microsoft.managedidentity/userassignedidentities - belong to Databricks managed resources
These resources are what's left of the non-compliant resources. Everything was tagged except these. The user assigned identity have Contributor role on the subscription level.
Per checking, all of these resources are taggable.
Azure Private Link
Azure Private Link
An Azure service that provides private connectivity from a virtual network to Azure platform as a service, customer-owned, or Microsoft partner services.
Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.