Permissions
The Enforce Azure Compute Virtual Machines Use Approved AMIs From Trusted Publishers policy pack requires 2 permissions:
microsoft.compute/virtualmachines/deallocate/actionmicrosoft.compute/virtualmachines/delete
The Enforce Azure Compute Virtual Machines Use Approved AMIs From Trusted Publishers policy pack requires 2 permissions:
microsoft.compute/virtualmachines/deallocate/actionmicrosoft.compute/virtualmachines/delete