How to Apply and Verify the LegacyVMNVA Tag for FortiGate on Azure with MANA

송진우 0 Reputation points
2026-08-20T08:44:10.9533333+00:00

Hello,

We are currently running FortiGate in Azure, and due to MANA (Microsoft Azure Network Adapter), we need to apply the LegacyVMNVA tag to the FortiGate resources.

We found the following Microsoft documentation that explains how to apply the required policy:

https://learn.microsoft.com/en-us/azure/virtual-network/accelerated-networking-mana-network-virtual-appliance-opt-out

However, we are having difficulty following the steps described in the documentation.

Could you please guide us through the correct procedure?

Specifically, we would like to clarify the following:

  1. In the Resource / Service Search section, should we search for the policy using "LegacyVMNVA" or the policy ID "e87a87f5-e6dd-4919-be21-abb0a4ea4630", and then assign the policy?
  2. When assigning the policy, is it sufficient to select only the Resource Group where the FortiGate resources are deployed?
  3. How can we verify that the LegacyVMNVA tag has been successfully applied?
  4. Currently, under the Resource Group's Policy section, we see the compliance status as "Non-compliant" and "Not started." Is this expected, or does it indicate that the policy has not been applied correctly?
  5. Is it normal that LegacyVMNVA does not appear in the regular Tags section of the Resource Group or resource?
  6. If the compliance status does not change to compliant, should we manually trigger a policy scan using the following Azure CLI command from Bash?

az policy state trigger-scan --resource-group <resource-group>

Could you please provide us with a step-by-step guide on how to:

  • Assign the LegacyVMNVA policy correctly
  • Apply the LegacyVMNVA tag to the FortiGate resources
  • Verify that the tag has been successfully applied
  • Confirm that the policy is working as expected and the resources are compliant

We would appreciate any guidance on the correct procedure and how to verify the final result.

Thank you.Hello,

We are currently running FortiGate in Azure, and due to MANA (Microsoft Azure Network Adapter), we need to apply the LegacyVMNVA tag to the FortiGate resources.

We found the following Microsoft documentation that explains how to apply the required policy:

https://learn.microsoft.com/en-us/azure/virtual-network/accelerated-networking-mana-network-virtual-appliance-opt-out

However, we are having difficulty following the steps described in the documentation.

Could you please guide us through the correct procedure?

Specifically, we would like to clarify the following:

  1. In the Resource / Service Search section, should we search for the policy using "LegacyVMNVA" or the policy ID "e87a87f5-e6dd-4919-be21-abb0a4ea4630", and then assign the policy?
  2. When assigning the policy, is it sufficient to select only the Resource Group where the FortiGate resources are deployed?
  3. How can we verify that the LegacyVMNVA tag has been successfully applied?
  4. Currently, under the Resource Group's Policy section, we see the compliance status as "Non-compliant" and "Not started." Is this expected, or does it indicate that the policy has not been applied correctly?
  5. Is it normal that LegacyVMNVA does not appear in the regular Tags section of the Resource Group or resource?
  6. If the compliance status does not change to compliant, should we manually trigger a policy scan using the following Azure CLI command from Bash?

az policy state trigger-scan --resource-group <resource-group>

Could you please provide us with a step-by-step guide on how to:

  • Assign the LegacyVMNVA policy correctly
  • Apply the LegacyVMNVA tag to the FortiGate resources
  • Verify that the tag has been successfully applied
  • Confirm that the policy is working as expected and the resources are compliant

We would appreciate any guidance on the correct procedure and how to verify the final result.

Thank you.

Azure Policy
Azure Policy

An Azure service that is used to implement corporate governance and standards at scale for Azure resources.

0 comments No comments

1 answer

Sort by: Most helpful
  1. 송진우 0 Reputation points
    2026-08-20T08:52:02.93+00:00

    It is literally just listing AI-generated explanations of the document, so a more detailed explanation is needed. I also tried reapply it, but the tag was not created under the Tags menu, and the compliance status still remains Non-compliant.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.