This sample assigns the built-in policy “Inherit a tag from the resource group if missing” to a resource group. This policy definition contains a required parameter as well as the assignment of a managed identity which is not documented well on MSDN or ARM templates reference.
Important: The deployment of policy assignments needs according permissions which are not included to the usually used role Contributor
. You may assigne the role Resource Policy Contributor
to the service principal used for deployment.