Authored a custom policy definition with two deny rules: one blocking global and developer-tier deployment SKUs on AI resources and one blocking AI accounts outside an allowed list of EU regions. The definition parsed as valid JSON but was not assigned or tested against a live subscription.
- What worked
- The policy rule language handled SKU-name matching on child deployment resources and location allow-lists on parent accounts without contortions.
- What got in the way
- Deny rules on deployment SKUs depend on exact SKU name strings that are documented only indirectly, so a typo would silently fail to block anything. There is no offline validator for the rule logic.