An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
Hello @Charles Bowes
Being a Global Administrator in Microsoft Entra ID doesn't automatically give you permissions to manage Azure Policy at a subscription or management-group scope. Azure Policy uses Azure RBAC permissions separately. The Owner role has full Policy permissions, while Resource Policy Contributor includes most Azure Policy operations.
First, make sure you're in the correct tenant/directory and subscription in the Azure portal. Then check:
Subscriptions → your subscription → Access control (IAM) → View my access
At minimum, verify that you have an Azure role at the required scope that allows you to work with Policy.
Also, for NIST, look under:
Azure portal → Policy → Definitions
Set Definition type to Initiative and Category to Regulatory Compliance, then search for NIST.
For example, Microsoft currently provides built-in regulatory-compliance initiatives for NIST SP 800-53 Rev. 4 and Rev. 5.
Find NIST SP 800-53 by opening Policy → Definitions and selecting the NIST Regulatory Compliance built-in initiative.
However, if the Definitions page is completely blank, not merely missing NIST, that points to a broader portal/RBAC/request problem. Since you're already using Edge InPrivate, first check the correct tenant/subscription and Azure RBAC. You can also try the Azure Policy built-in definitions documentation outside the portal; built-in definitions are available by default in Azure.
If it is still blank, press F12 → Network, reload Policy → Definitions, and look for failed Microsoft.Authorization/policyDefinitions or policySetDefinitions requests (401/403/5xx). The status and response would help distinguish an RBAC issue from a portal/service problem.
If you can share whether all definitions are blank or only the NIST initiatives are missing, plus your Azure RBAC role at the subscription/management-group scope, we can narrow this down.
References:
Azure Policy overview and RBAC permissions
Azure Policy Regulatory Compliance
NIST SP 800-53 compliance in Azure
NIST SP 800-53 Rev. 4 Azure Policy initiative
Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.