Azure Gov does not appear to have the required Azure Firewall logic app connector and possibly a different version of the Virus Total connector. This is likely the cause. You could probably recreate these logic apps using direct API calls if this is critical. The data connector and analytic rules should work. Though the added value of these playbooks may not be worth the effort.
How to install Sentinel Solutions specifically Playbooks and Connectors in Azure Gov
Hello Guys,
I am trying to install Azure Firewall Solution (Playboks and custom connectors) in Azure Gov Cloud.
I have installed the Azure Firewall Solution from Content Hub, The details shows that this solution has Custom Azure Logic Apps Connector and 3 playbooks, but they are not installed with this solution when I search it in Sentinel Automation Playbooks templates and custom connector is also missing in the respective service.
I udnerstand that I can install these playbooks and connectors from github from here:
https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Azure%20Firewall/Playbooks
Clicking on Deploy to Gov opens the ARM template in Azure Gov but validations fails seeming as if it cannot download the json files form the link?
I get this error when I am deploying the custom connector + 3 playbooks all together, we can install each playbook and connector seperately from github links which then passes the validation and starts deploying each playbook seperately but then I get another error.
For example deploy this playbook AzureFirewall-BlockIP-addToIPGroup, form this link: https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Azure%20Firewall/Playbooks/AzureFirewall-BlockIP-addToIPGroup
It starts deploying but then fails with this error:
**{"code":"DeploymentFailed","message":"At least one resource deployment operation failed. Please list deployment operations for details. Please see https://aka.ms/arm-deployment-operations for usage details.","details":[{"code":"ApiNotFound","message":"The API 'AzureFirewallConnector' could not be found."}]}
**
I had somewhat similar errors in Azure Commerical as well but I was finally able to install the entire solution with connector and playbooks from link in this Microsoft Article: https://techcommunity.microsoft.com/t5/azure-network-security-blog/automated-detection-and-response-for-azure-firewall-with-logic/ba-p/2414224 by clicking Deploy to Azure under How to Deploy section.
But the link in this article is only for Azure Commercial, I am not sure what is the difference in this link provided here and the github links, it seems both are the same by looking at the links of ARM templates.
I need to deploy this solution in Azure Gov but I am running into this issue and there seems to be no way around it.
Any direction and help to troubleshoot will be much appreciated.
Thank you.
Azure Logic Apps
Microsoft Security | Microsoft Sentinel
1 answer
Sort by: Most helpful
-
Andrew Blumhardt 10,051 Reputation points Microsoft Employee
2024-03-14T02:18:20.8666667+00:00