Issue while accessing Azure Policy REST API in Power BI - Getting Error: Access to the resource is forbidden
I am trying to access Azure Policy Compliance data from Azure Policy REST API to Power BI. To access the Azure API into Power BI, I have registered an application in Entra ID and generated Client ID and Client Secret. In the App Permission, I have…
Azure Policy Tag add tag if missing
I set a new policy for existing resources to add required tag if missing. scenario1: Resource1 have the following tags and value Tag name = Project Value = ProjSSO Tag name = Purpose Value = app login however if the the policy trigger I received an…
how do I use Azure Policy to enable 'Agentless scanning for machines (preview)' setting for Defender for CSPM
I cant seem to find a policy that enables the 'Agentless scanning for machines (preview)' setting in Defender for Cloud. How do i do it then?
Azure Default Policy preventing us creating or amending resources
Came into work after a weekend, and we noticed that Azure resources (VM's, AVD, Storage accounts etc), would not lets us create or amend settings because of a deny error with the Azure Default Policy (error below) Resource '#########' was disallowed by…
Does the current SQL Database TLS Policy check if nothing is selected?
We recently implemented a built-in Azure Policy, that checks for the minimum TLS Version to be 1.2. -…
Azure Policy & VM JIT - Do not allow Any as source
I am currently trying to prevent users from requesting Azure JIT VM access coming from the Source IP addresses "Any". According to this thread, https://learn.microsoft.com/en-us/answers/questions/846584/azure-vm-jit-do-not-allow-any-as-source ,…
How to create a overview over all VMs and his CIS compliance status?
Is there any way to generate an overview to see the CIS compliance coverage over all virtual maschines? Me problem is, we need to use CIS Images vor VMs but some applications need the possibility to deactivate some of the CIS rules to work correctly. So…
"ResourceNotFound" Error from the existing Azure Policy once the VM was deployed
I am trying to add MDE for all the resources. I know there is an "Endpoint Protection" function on server's service of CWP. But my requirement is that we need to control MDE's deployment by policy. So, I purchased the CWP server's service but…
My Azure Student Suscription suddenly was deactivated
Today I was developing a simple API in Go for learning purposes. I had installed go and set up the server using localhost on port 8080 and when it came to testing my host lost connection to remote and an email arrived explaining that my Azure…
Problem with "exclude" user/target resource in conditional access policy
Hi, I have been trying to restrict 1 user to access only 1 app on Azure Entra ID, so I use the condition access policy under security tab. I have put the conditions as follows: user: userx@microsoft.com Target Resources: Include All cloud apps &…
Configure machines to receive a vulnerability assessment provider azure policy confusion
hi, can anyone please tell me why does the following Azure Policy Configure machines to receive a vulnerability assessment provider https://www.azadvertizer.net/azpolicyadvertizer/13ce0167-8ca6-4048-8e6b-f996402e3c1b.html has two options for the…
Unable to add application access policy: The remote name could not be resolved 'webdir.online.lync.com'
I am unable to add an application access policy to my organization due to the following error: I need an application access policy as my organization would like to use Microsoft Graph API and application access policy is needed for some of the APIs.
Unable to deployment many 3rd party product from Azure Marketplace
Every time I try to deploy a product from the Azure Marketplace. I get an error at the validation step that looks like this: Is there any way to resolve this?
How can i export Azure policy controls output
I am trying to export the output of azure policy controls output into an excel file so that they can be tracked in the form of a report that i can present, if i copy and paste from the portal the formatting is all over the place. I was wondering if…
Problem with subscription creating Azure AD B2C tenant
Hi everyone, i'm trying to separate my app environments so i want to create AD B2C tenants and their resources per environment (develop and production). I've created a Azure AD B2C tenant, but it doesn't have any subscription, so i can't create any…
Bug in built-in activity log alert should exist policies
We use the following built-in policies to ensure activity log alerts are created for certain…
Azure VM JIT - Do not allow Any as source
Hello gents, I'm having some issues with JIT for Azure VMs. We want to use JIT to allow externals (Third-parties or contractors) to access specifics VMs remotely. As we have an huge list of externals (big enterprise, long list of applications…
Azure Policy- Remediating Managed Disks to Disable Public Access+Disable Private Endpoint
Hello Microsoft and Community, There is a built in policy for Managed Disks: Managed disks should disable public network access and there is one remediation/configuration called: Configure managed disks to disable public network access But,on closer…
I am using the azure policy to whitelist the domain for outbound connectivity from Azure Data Factory to other services. But facing issues in connectivity due to throttling applied on policy.
I am using the azure policy (https://learn.microsoft.com/en-us/azure/data-factory/configure-outbound-allow-list-azure-policy) which is applied at resource group level. This policy is working as expected and is only allowing outbound connectivity to the…
How to automate turning off or suspending some Azure services to save money?
What Azure objects can we suspend or turn off outside business hours to save running costs? App Service: The app service implements the message compose experience in the team tab and the messaging endpoint for the bot. Service Bus: The individual…