811 questions with Azure Policy tags

Sort by: Updated
3 answers

Custom Azure policy "Logic apps should use the latest TLS version"

Hello, I need to create a custom policy for Logic Apps. There is already a built-in policy in Azure for App service and Function apps. App service (App Service apps should use the latest TLS version) - Definition ID:…

Azure Logic Apps
Azure Logic Apps
An Azure service that automates the access and use of data across clouds without writing code.
2,921 questions
Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
811 questions
asked 2024-04-18T14:01:57.9766667+00:00
Kym Caris Natividad 20 Reputation points
edited an answer 2024-04-19T14:48:59.5566667+00:00
Prashant Kumar 75 Reputation points Microsoft Employee
2 answers

Applying azure PCI DSS4 regulatory complaince policy for passwords

Hi, I am trying to assign PCI DSS4 Defender for cloud regulatory compliance policy for passwords - Audit Windows machines that allow re-use of the passwords after the specified number of unique passwords- where count is 24 Audit Windows machines that…

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
811 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,226 questions
asked 2024-04-16T20:23:01.5533333+00:00
Ishan Saxena 20 Reputation points
answered 2024-04-18T20:45:02.7166667+00:00
Marcin Policht 15,050 Reputation points MVP
2 answers One of the answers was accepted by the question author.

Azure policy for auditing trial subscriptions

My team is trying to create an audit effect Azure policy to audit any trial subscriptions. The goal of our policy is to show all the trial subscriptions as non-compliant. Below is the JSON template we were able to come up with. We are testing for…

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
811 questions
asked 2024-04-17T15:26:21.7566667+00:00
Sparsh Raj 20 Reputation points
answered 2024-04-18T09:23:32.85+00:00
AnuragSingh-MSFT 20,981 Reputation points
1 answer

I am uanble to upgrade my account because my billing access was changed automatically by Azure

Recently my account was disabled. I would like to find out how to enable it and upgrade it. Its not letting me upgrade.

Azure Cost Management
Azure Cost Management
A Microsoft offering that enables tracking of cloud usage and expenditures for Azure and other cloud providers.
2,172 questions
Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
695 questions
Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
811 questions
asked 2021-02-15T16:56:56.39+00:00
odsbyz 6 Reputation points
commented 2024-04-17T15:48:13.9666667+00:00
Christine 0 Reputation points
1 answer

Setting up Azure Firewall for network perimeter

How can I set up Azure Firewall for better security and at more of the resource group level? I already have a network security group (NSG) set up with IP whitelisting for an exposed endpoint, but I'm not sure how to connect the filtered traffic to the…

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
585 questions
Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
811 questions
asked 2024-04-16T14:10:38.7166667+00:00
Anmol Arora 0 Reputation points
answered 2024-04-17T12:15:41.1166667+00:00
GitaraniSharma-MSFT 48,196 Reputation points Microsoft Employee
0 answers

How to restrict users from deploying the resources in a RG when a specified tag is applied to that RG?

I already know how to deny resource deployment when a specific tag is missing using Azure custom policies. Now, I'm interested in creating a custom policy that prevents users from deploying resources in a resource group if a particular tag exists for…

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
811 questions
asked 2024-04-16T07:53:53.1266667+00:00
Priyanka Varma 60 Reputation points
1 answer

I am working on azure policy where an alert will be generated if a RBAC role is assigned with a blob data action permissions on a storage account. Can anyone please help in correcting the code I have written.

{ "mode": "All", "policyType": "Custom", "displayName": "Audit Creation of RBAC Roles for Storage Accounts", "description": "This policy audits any new or updated RBAC…

Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
2,800 questions
Azure
Azure
A cloud computing platform and infrastructure for building, deploying and managing applications and services through a worldwide network of Microsoft-managed datacenters.
1,032 questions
Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
811 questions
asked 2024-03-25T14:24:12.9833333+00:00
Sahith Thatipalli 40 Reputation points
edited a comment 2024-04-16T03:21:36.9066667+00:00
Sumarigo-MSFT 44,336 Reputation points Microsoft Employee
1 answer

Create VM issue with Not allowed resource types - virtualNetwork

If I apply a new Azure policy to the management group which has been associate to the subscription. There is a configuration for "Not allowed resource types" with virtualNetwork. Could I create the new VM to existing VNet? Because we have…

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
811 questions
asked 2020-12-09T14:25:13.053+00:00
Walker Chong 41 Reputation points
commented 2024-04-14T10:04:52.6+00:00
Tobiloba Ajibade 0 Reputation points
3 answers

Find the resources which are untagged / not having any Tags in a Subscription

How to find all the resources which are Untagged / Not having any tags in a subscription Via PowerShell Script or Policies

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
811 questions
asked 2024-02-14T13:07:26.23+00:00
Dhanalakshmi 20 Reputation points
commented 2024-04-12T20:46:15.0066667+00:00
Rob Logie 0 Reputation points
1 answer One of the answers was accepted by the question author.

How to exempt a particular Service Principal (SPN) / App registration from the denial actions enforced by a Azure custom policy

Hello, I've implemented a deny policy to prevent end users from deploying unauthorized resources. However, this policy is also affecting the automation within the service principal's account. Now, I want to find a way so that it should allow this…

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
811 questions
asked 2024-04-09T05:12:39.05+00:00
Priyanka Varma 60 Reputation points
accepted 2024-04-12T10:19:52.69+00:00
Priyanka Varma 60 Reputation points
6 answers

The template deployment failed because of policy violation.

When I attempt to run through Exercise1 - Create a WordPress website hosted in Auzure, I encounter "The template deployment failed because of policy violation." while creating the WordPress Detailed: Information: "galleryItemId":…

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
811 questions
asked 2021-02-04T16:58:37.947+00:00
SVM 6 Reputation points
answered 2024-04-11T18:12:54.13+00:00
Joka 0 Reputation points
1 answer One of the answers was accepted by the question author.

How can I create a custom Azure policy to prevent/deny manual resource creation in resource groups while allowing automated creation through GitHub Actions or Azure Automation?

How can I create a custom Azure policy to restrict end users from manually creating resources in resource groups and prevent unauthorized peerings with existing VNets, while also allowing the creation of resources through GitHub action automation or…

Azure Automation
Azure Automation
An Azure service that is used to automate, configure, and install updates across hybrid environments.
1,154 questions
Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
811 questions
asked 2024-04-01T05:49:52.1833333+00:00
Priyanka Varma 60 Reputation points
accepted 2024-04-11T03:58:20.34+00:00
Priyanka Varma 60 Reputation points
2 answers

Looking for Kusto query or a azure policy where an alert should be generated when azure blob data action role permissions are assigned on a built in or custom role for a storage account.

{ "mode": "All", "policyType": "Custom", "displayName": "Audit Blob Data Action Role Permissions Assignments", "description": "Audits when roles with Azure Blob data…

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
811 questions
asked 2024-03-26T17:51:42.8933333+00:00
Sahith Thatipalli 40 Reputation points
commented 2024-04-10T07:32:19.22+00:00
AnuragSingh-MSFT 20,981 Reputation points
2 answers One of the answers was accepted by the question author.

Enabling periodic assessment automatically for the VM

After creating the VM, I should see that periodic assesment option to be enabled a when I navigate to update section. how it can be achieved?

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
811 questions
Azure Update Manager
Azure Update Manager
An Azure service to centrally manages updates and compliance at scale.
260 questions
asked 2024-03-30T06:29:25.4+00:00
Varma 1,250 Reputation points
accepted 2024-04-01T07:04:28.0466667+00:00
Varma 1,250 Reputation points
2 answers

How deny policy or rule inherits from Root Tenant to resource level

I am trying to understand how deny policy/rule works in terms of inheritance. If I create a deny policy of - "not able to create resources" at Root Tenant. Under the root tenant I have a management group IT and a Dev subscription under this…

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
811 questions
asked 2024-03-17T20:46:18.96+00:00
Nishith Suthar 0 Reputation points
commented 2024-04-01T06:44:18.4+00:00
SwathiDhanwada-MSFT 18,041 Reputation points
1 answer One of the answers was accepted by the question author.

How to lock the Vnet peerings like we lock the the resources in resource group once after we create them?

To prevent unauthorized peerings to other Vnets after creation, it's essential to lock the peerings to restrict access for other users from creating unnecessary peerings. How to do that? Can anyone help me out with this? Thanks.

Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,219 questions
Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
695 questions
Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
811 questions
asked 2024-03-27T04:26:00.8033333+00:00
Priyanka Varma 60 Reputation points
accepted 2024-04-01T05:52:03.73+00:00
Priyanka Varma 60 Reputation points
0 answers

Azure policy is not working on App services

I have created azure policy for app service that do not assign any public IP and set default TLS 1.3 but still I can be able to create app services with default settings.

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
811 questions
asked 2024-03-27T12:58:15.2366667+00:00
Shivshankar sharma 0 Reputation points
commented 2024-03-27T23:33:33.9+00:00
guilherme rodrigues 240 Reputation points
4 answers One of the answers was accepted by the question author.

Disable trusted launch Azure VM

Hello Everyone, I have an issue with one of my VM's on Azure. This machine was previously created with Trusted Launch enabled on it(Don't know why). Now, I can't backup it up with my default backup policy, only with enhanced one which is…

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,344 questions
Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
811 questions
asked 2022-09-01T12:36:42.213+00:00
Vlad Dodin 21 Reputation points
commented 2024-03-26T13:09:12.57+00:00
Mohammad Wasif Rafique Mandal 35 Reputation points
8 answers

Exempt Azure policy for Users in specific AD group?

Hello, Is it possible to bypass Azure policy for specific AD users or AD groups while creating objects in AKS

Azure Kubernetes Service (AKS)
Azure Kubernetes Service (AKS)
An Azure service that provides serverless Kubernetes, an integrated continuous integration and continuous delivery experience, and enterprise-grade security and governance.
1,912 questions
Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
811 questions
asked 2023-04-28T15:02:45.9833333+00:00
Tanul 1,251 Reputation points
answered 2024-03-22T03:23:02.8966667+00:00
Konstantinos Passadis 17,376 Reputation points MVP
1 answer One of the answers was accepted by the question author.

Why ceating private endpoint in existing key vault blocks the public access from all network as well as selected network fails?

In Key Vault, Customer firewall is set to public and some to selected network with list of IPs. As soon as we create private endpoint, all other previous connection with pubic/selected network fails. But based on below documentation, I would like…

Azure Key Vault
Azure Key Vault
An Azure service that is used to manage and protect cryptographic keys and other secrets used by cloud apps and services.
1,156 questions
Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
695 questions
Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
811 questions
asked 2022-09-26T18:41:02.043+00:00
Dinesh Madhup 46 Reputation points Microsoft Employee
accepted 2024-03-21T00:28:13.5933333+00:00
Dinesh Madhup 46 Reputation points Microsoft Employee