Evaluates whether each resource inherits a specified tag from the resource group to which it belongs. Resources that inherit the specified tag are evaluated as Compliant.
Scenarios
Use this rule to verify that resources automatically inherit specified tags from their resource groups, improving resource management efficiency.
Risk level
Default risk level: high.
You can change the risk level based on your business requirements when you apply this rule.
Compliance evaluation logic
- If each resource inherits a specified tag from the resource group to which it belongs, the evaluation result is Compliant.
- If a resource does not inherit a specified tag from the resource group to which it belongs, the evaluation result is Incompliant. For more information about how to remediate an incompliant configuration, see Incompliance remediation.
- This rule does not apply to resources that do not belong to any resource group, or resources added to a resource group that has no tags attached.
Rule details
| Item | Description |
| Rule name | resources-inherit-tags-from-resource-group |
| Rule identifier | resources-inherit-tags-from-resource-group |
| Tag | ResourceGroup and Tag |
| Automatic remediation | Supported |
| Trigger type | Configuration change |
| Supported resource type | Resource types |
| Input parameter | inheritTagKeys
Note Separate multiple values with commas (,). |
Incompliance remediation
Create a custom tag and attach it to a resource. For more information, see Add a custom tag.