Issue - Azure Security Center always shows 0 affected resources for custom initiatives

Charles MURE 1 Reputation point
2021-03-30T09:39:04.467+00:00

Description of the issue.
Custom policies definition inside custom initiative seem to not work as excepted.
We have seen this problem since the 03/22/2021 release of Azure Security Center including the Recommendations page enhancements feature.
Since this date, custom recommendations have disappeared from ASC and they do not trigger workflow automation anymore. Also, ASC always shows zero affected resources for custom policies in the regulatory compliance dashboard.
I haven't found any documentation that mentions this change in behavior. Is it normal ?

To Reproduce
Steps to reproduce the behavior (mostly from the documentation):

  1. Enable Azure Defender plan to enable custom initiative in ASC Regulatory Compliance
  2. Duplicate one built-in policy in order to create a custom policy from a "validated" rule logic.
  3. Create a policy initiative that includes the created policy.
  4. Assign the policy initiative in ASC or add the metadata property with the value {"ASC": "true"} in the initiative assignement.
  5. Create a non-compliant resource affected by your policy.

After more than 24h, in the ASC Regulatory compliance dashboard, ASC still found 0 affected resources for the policy.
82727-asc-custom.png
82687-asc-built-in.png

On the over side, the Azure Policy compliance dashboard indicates that a non-compliant resource indeed exists for this custom initiative.
82716-policy-ok.png

Expected behavior
Non compliant resources for custom initiatives appear in the ASC Regulatory compliance and Recommendation dashboard as custom Security Center recommendations.

Additional context
Documentation linked to this feature: https://learn.microsoft.com/en-us/azure/security-center/custom-security-policies?pivots=azure-portal
On-boarding process followed during deployment: https://github.com/Azure/Azure-Security-Center/blob/onboarding/Onboarding/Modules/3-Policy-Management.md#step-6---assign-custom-policies-optional

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
{count} votes

1 answer

Sort by: Most helpful
  1. VipulSparsh-MSFT 16,236 Reputation points Microsoft Employee
    2021-03-30T13:41:48.183+00:00

    @Charles MURE MS is aware about this and there is an ongoing investigation going on with no public status update as of now.
    If this is a high priority for your org, you are advised to open a case with support and get a private status update from there.

    0 comments No comments