Azure Policy Definitions is blank

Charles Bowes 0 Reputation points
2026-09-18T18:21:20.9966667+00:00

I am a Global Admin trying to configure Azure Policy for the built in NIST SP 800 policies but NO Azure policies will appear. I am using Edge in InPrivate mode on a Macbook Pro. What do I need to do so the NIST policies appear?

Azure Policy
Azure Policy

An Azure service that is used to implement corporate governance and standards at scale for Azure resources.

0 comments No comments

2 answers

Sort by: Oldest
  1. Allan Solomon Mejia 10,225 Reputation points
    2026-09-19T18:51:59.2666667+00:00

    Hello @Charles Bowes

    Being a Global Administrator in Microsoft Entra ID doesn't automatically give you permissions to manage Azure Policy at a subscription or management-group scope. Azure Policy uses Azure RBAC permissions separately. The Owner role has full Policy permissions, while Resource Policy Contributor includes most Azure Policy operations.

    First, make sure you're in the correct tenant/directory and subscription in the Azure portal. Then check:

    Subscriptions → your subscription → Access control (IAM) → View my access

    At minimum, verify that you have an Azure role at the required scope that allows you to work with Policy.

    Also, for NIST, look under:

    Azure portal → Policy → Definitions

    Set Definition type to Initiative and Category to Regulatory Compliance, then search for NIST.

    For example, Microsoft currently provides built-in regulatory-compliance initiatives for NIST SP 800-53 Rev. 4 and Rev. 5.

    Find NIST SP 800-53 by opening Policy → Definitions and selecting the NIST Regulatory Compliance built-in initiative.

    However, if the Definitions page is completely blank, not merely missing NIST, that points to a broader portal/RBAC/request problem. Since you're already using Edge InPrivate, first check the correct tenant/subscription and Azure RBAC. You can also try the Azure Policy built-in definitions documentation outside the portal; built-in definitions are available by default in Azure.

    If it is still blank, press F12 → Network, reload Policy → Definitions, and look for failed Microsoft.Authorization/policyDefinitions or policySetDefinitions requests (401/403/5xx). The status and response would help distinguish an RBAC issue from a portal/service problem.

    If you can share whether all definitions are blank or only the NIST initiatives are missing, plus your Azure RBAC role at the subscription/management-group scope, we can narrow this down.

    References:

    Azure Policy overview and RBAC permissions

    Azure Policy Regulatory Compliance

    NIST SP 800-53 compliance in Azure

    NIST SP 800-53 Rev. 4 Azure Policy initiative


    Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.

    Was this answer helpful?


  2. Suchitra Suregaunkar 16,780 Reputation points Microsoft External Staff Moderator
    2026-09-21T04:18:54.5433333+00:00

    Hello @Charles Bowes

    Thank you for posting your query on Microsoft Q&A platform and for the detailed description — this is a common one, and in almost every case it comes down to what the Definitions page is filtered to rather than anything missing from your tenant. The built-in NIST definitions are always present in every Azure tenant; they can't be deleted or disabled, so they are there — they're just not being surfaced by the current view.

    There are two things to check, in this order.

    1. NIST SP 800-53 is an initiative**, not a policy**

    This is the single most common reason the list looks empty. The NIST content ships as a policy set definition (initiative) that groups hundreds of individual policies together, so it will never appear while the page is filtered to "Policy."

    In the Azure portal:

    1. Go to Policy → Authoring → Definitions
    2. Set Definition type = Initiative (or All)
    3. Set Type = Built-in (make sure it isn't set to Custom — that filter alone returns an empty list)
    4. Set Category = Regulatory Compliance
    5. Search for NIST

    You should now see NIST SP 800-53 Rev. 5, Rev. 4, and NIST SP 800-171. The Rev. 5 initiative ID is 179d1daa-458f-4e47-8086-2a68d0d6c38f.

    Also confirm the Scope selector at the top of the Definitions page is pointing at a management group or subscription. If no scope is selected, the page returns nothing regardless of filters.

    2. Global Administrator by itself does not grant access to Azure resources

    Microsoft Entra ID and Azure resources are secured independently — Entra role assignments (including Global Administrator) do not grant access to Azure subscriptions or management groups. Azure Policy reads definitions through Azure Resource Manager, so if your account has no Azure RBAC assignment at the selected scope, the blade will legitimately come back blank.

    To confirm and fix this:

    1. Go to Microsoft Entra ID → Properties
    2. Set Access management for Azure resources to Yes and save — this assigns you User Access Administrator at root scope (/)
    3. Sign out and sign back in
    4. Assign yourself Reader or Resource Policy Contributor on the target management group/subscription
    5. Set the toggle back to No once you're done — this is intended as temporary elevation, not a standing permission

    A quick way to tell these two causes apart is to run this from PowerShell:

    If the NIST initiatives are returned here but the portal is still blank, it's a filter/scope issue (step 1). If nothing is returned, it's a permissions issue (step 2).

    One note on your browser

    Edge InPrivate on macOS applies strict tracking prevention, which can block scripts and cookies the portal relies on and leave blades empty. Please retry in a normal Edge window with cookies allowed for portal.azure.com, *.azure.com, and *.microsoft.com, and with extensions disabled. If it renders correctly there, the InPrivate session was the cause.

    Official documentation

    Could you try the filter change in step 1 first and let me know what you see? If the NIST initiative still doesn't appear after setting Definition type to Initiative and Type to Built-in, please share a screenshot of the Definitions page including the Scope and filter bar, along with the output of the PowerShell command above, and I'll take it from there.

    Hope this helps!

    Thanks,
    Suchitra.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.