Skip to content

Commit 05d3278

Browse files
robgaAzure Policy Bot
andauthored
Built-in Policy Release 74b1e6d3 (#1535)
Co-authored-by: Azure Policy Bot <azgovpolicy@microsoft.com>
1 parent 2e07c27 commit 05d3278

15 files changed

+158
-44
lines changed

built-in-policies/policyDefinitions/App Service/HostingEnvironment_LatestVersions_Audit.json

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,18 +1,19 @@
11
{
22
"properties": {
3-
"displayName": "App Service Environment should be provisioned with latest versions",
3+
"displayName": "[Deprecated]: App Service Environment should be provisioned with latest versions",
44
"policyType": "BuiltIn",
55
"mode": "Indexed",
6-
"description": "Only allow App Service Environment version 2 or version 3 to be provisioned. Older versions of App Service Environment require manual management of Azure resources and have greater scaling limitations.",
6+
"description": "Only allow App Service Environment version 2 or version 3 to be provisioned. This policy is deprecated because App Service Environment v1 and v2 are retired and no longer supported. Learn more about policy definition deprecation at aka.ms/policydefdeprecation.",
77
"metadata": {
8-
"version": "1.0.0",
9-
"category": "App Service"
8+
"version": "1.1.0-deprecated",
9+
"category": "App Service",
10+
"deprecated": true
1011
},
11-
"version": "1.0.0",
12+
"version": "1.1.0",
1213
"parameters": {
1314
"effect": {
1415
"type": "string",
15-
"defaultValue": "Audit",
16+
"defaultValue": "Disabled",
1617
"allowedValues": [
1718
"Audit",
1819
"Deny",
@@ -42,6 +43,7 @@
4243
}
4344
},
4445
"versions": [
46+
"1.1.0",
4547
"1.0.0"
4648
]
4749
},
Lines changed: 56 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,56 @@
1+
{
2+
"properties": {
3+
"displayName": "Durable Task schedulers should not allow open IP allowlists",
4+
"description": "Deny Durable Task schedulers that include 0.0.0.0/0 in their IP allowlist to prevent exposure to the public internet. Remove the open entry so that only trusted networks can reach the scheduler.",
5+
"policyType": "BuiltIn",
6+
"mode": "Indexed",
7+
"metadata": {
8+
"version": "1.0.0",
9+
"category": "Durable Task"
10+
},
11+
"version": "1.0.0",
12+
"parameters": {
13+
"effect": {
14+
"type": "String",
15+
"defaultValue": "Audit",
16+
"allowedValues": [
17+
"Audit",
18+
"Deny",
19+
"Disabled"
20+
],
21+
"metadata": {
22+
"displayName": "Effect",
23+
"description": "Enable or disable the execution of the policy"
24+
}
25+
}
26+
},
27+
"policyRule": {
28+
"if": {
29+
"allOf": [
30+
{
31+
"field": "type",
32+
"equals": "Microsoft.DurableTask/schedulers"
33+
},
34+
{
35+
"count": {
36+
"field": "Microsoft.DurableTask/schedulers/ipAllowlist[*]",
37+
"where": {
38+
"field": "Microsoft.DurableTask/schedulers/ipAllowlist[*]",
39+
"equals": "0.0.0.0/0"
40+
}
41+
},
42+
"greater": 0
43+
}
44+
]
45+
},
46+
"then": {
47+
"effect": "[parameters('effect')]"
48+
}
49+
},
50+
"versions": [
51+
"1.0.0"
52+
]
53+
},
54+
"id": "/providers/Microsoft.Authorization/policyDefinitions/d82527a7-91cd-409f-b96e-049600b16b9e",
55+
"name": "d82527a7-91cd-409f-b96e-049600b16b9e"
56+
}

built-in-policies/policyDefinitions/Monitoring/AzureMonitor_AddSystemIdentity_Prerequisite.json

Lines changed: 12 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,10 +6,10 @@
66
"description": "Configure system-assigned managed identity to virtual machines hosted in Azure that are supported by Azure Monitor and do not have a system-assigned managed identity. A system-assigned managed identity is a prerequisite for all Azure Monitor assignments and must be added to machines before using any Azure Monitor extension. Target virtual machines must be in a supported location.",
77
"metadata": {
88
"category": "Monitoring",
9-
"version": "6.1.0-preview",
9+
"version": "6.2.0-preview",
1010
"preview": true
1111
},
12-
"version": "6.1.0-preview",
12+
"version": "6.2.0-preview",
1313
"parameters": {
1414
"effect": {
1515
"type": "String",
@@ -67,25 +67,34 @@
6767
"centralindia",
6868
"centralus",
6969
"centraluseuap",
70+
"chilecentral",
7071
"eastasia",
7172
"eastus",
7273
"eastus2",
7374
"eastus2euap",
7475
"francecentral",
7576
"germanywestcentral",
77+
"indonesiacentral",
78+
"israelcentral",
79+
"italynorth",
7680
"japaneast",
7781
"japanwest",
7882
"jioindiawest",
7983
"koreacentral",
8084
"koreasouth",
85+
"malaysiawest",
86+
"mexicocentral",
87+
"newzealandnorth",
8188
"northcentralus",
8289
"northeurope",
8390
"norwayeast",
91+
"polandcentral",
8492
"qatarcentral",
8593
"southafricanorth",
8694
"southcentralus",
8795
"southeastasia",
8896
"southindia",
97+
"spaincentral",
8998
"swedencentral",
9099
"switzerlandnorth",
91100
"uaenorth",
@@ -716,6 +725,7 @@
716725
}
717726
},
718727
"versions": [
728+
"6.2.0-PREVIEW",
719729
"6.1.0-PREVIEW",
720730
"6.0.0-PREVIEW"
721731
]

built-in-policies/policyDefinitions/Monitoring/AzureMonitor_Agent_Linux_VMSS_Audit.json

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,10 +5,10 @@
55
"mode": "Indexed",
66
"description": "Linux virtual machine scale sets should be monitored and secured through the deployed Azure Monitor Agent. The Azure Monitor Agent collects telemetry data from the guest OS. This policy will audit virtual machine scale sets with supported OS images in supported regions. Learn more: https://aka.ms/AMAOverview.",
77
"metadata": {
8-
"version": "3.5.0",
8+
"version": "3.6.0",
99
"category": "Monitoring"
1010
},
11-
"version": "3.5.0",
11+
"version": "3.6.0",
1212
"parameters": {
1313
"effect": {
1414
"type": "String",
@@ -64,6 +64,7 @@
6464
"centralindia",
6565
"centralus",
6666
"centraluseuap",
67+
"chilecentral",
6768
"eastasia",
6869
"eastus",
6970
"eastus2",
@@ -72,6 +73,7 @@
7273
"francesouth",
7374
"germanynorth",
7475
"germanywestcentral",
76+
"indonesiacentral",
7577
"israelcentral",
7678
"italynorth",
7779
"japaneast",
@@ -81,7 +83,9 @@
8183
"koreacentral",
8284
"koreasouth",
8385
"malaysiasouth",
86+
"malaysiawest",
8487
"mexicocentral",
88+
"newzealandnorth",
8589
"northcentralus",
8690
"northeurope",
8791
"norwayeast",
@@ -563,6 +567,7 @@
563567
}
564568
},
565569
"versions": [
570+
"3.6.0",
566571
"3.5.0",
567572
"3.4.0",
568573
"3.3.0",

built-in-policies/policyDefinitions/Monitoring/AzureMonitor_Agent_Linux_VMSS_DINE.json

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,10 +5,10 @@
55
"mode": "Indexed",
66
"description": "Automate the deployment of Azure Monitor Agent extension on your Linux virtual machine scale sets for collecting telemetry data from the guest OS. This policy will install the extension if the OS and region are supported and system-assigned managed identity is enabled, and skip install otherwise. Learn more: https://aka.ms/AMAOverview.",
77
"metadata": {
8-
"version": "3.9.0",
8+
"version": "3.10.0",
99
"category": "Monitoring"
1010
},
11-
"version": "3.9.0",
11+
"version": "3.10.0",
1212
"parameters": {
1313
"effect": {
1414
"type": "String",
@@ -68,6 +68,7 @@
6868
"centralindia",
6969
"centralus",
7070
"centraluseuap",
71+
"chilecentral",
7172
"eastasia",
7273
"eastus",
7374
"eastus2",
@@ -76,6 +77,7 @@
7677
"francesouth",
7778
"germanynorth",
7879
"germanywestcentral",
80+
"indonesiacentral",
7981
"israelcentral",
8082
"italynorth",
8183
"japaneast",
@@ -85,7 +87,9 @@
8587
"koreacentral",
8688
"koreasouth",
8789
"malaysiasouth",
90+
"malaysiawest",
8891
"mexicocentral",
92+
"newzealandnorth",
8993
"northcentralus",
9094
"northeurope",
9195
"norwayeast",
@@ -616,6 +620,7 @@
616620
}
617621
},
618622
"versions": [
623+
"3.10.0",
619624
"3.9.0",
620625
"3.8.0",
621626
"3.7.0",

built-in-policies/policyDefinitions/Monitoring/AzureMonitor_Agent_Linux_VMSS_UAI_DINE.json

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,10 +5,10 @@
55
"mode": "Indexed",
66
"description": "Automate the deployment of Azure Monitor Agent extension on your Linux virtual machine scale sets for collecting telemetry data from the guest OS. This policy will install the extension and configure it to use the specified user-assigned managed identity if the OS and region are supported, and skip install otherwise. Learn more: https://aka.ms/AMAOverview.",
77
"metadata": {
8-
"version": "3.10.0",
8+
"version": "3.11.0",
99
"category": "Monitoring"
1010
},
11-
"version": "3.10.0",
11+
"version": "3.11.0",
1212
"parameters": {
1313
"effect": {
1414
"type": "String",
@@ -111,6 +111,7 @@
111111
"centralindia",
112112
"centralus",
113113
"centraluseuap",
114+
"chilecentral",
114115
"eastasia",
115116
"eastus",
116117
"eastus2",
@@ -119,6 +120,7 @@
119120
"francesouth",
120121
"germanynorth",
121122
"germanywestcentral",
123+
"indonesiacentral",
122124
"israelcentral",
123125
"italynorth",
124126
"japaneast",
@@ -128,7 +130,9 @@
128130
"koreacentral",
129131
"koreasouth",
130132
"malaysiasouth",
133+
"malaysiawest",
131134
"mexicocentral",
135+
"newzealandnorth",
132136
"northcentralus",
133137
"northeurope",
134138
"norwayeast",
@@ -684,6 +688,7 @@
684688
}
685689
},
686690
"versions": [
691+
"3.11.0",
687692
"3.10.0",
688693
"3.9.0",
689694
"3.8.0",

built-in-policies/policyDefinitions/Monitoring/AzureMonitor_Agent_Linux_VM_Audit.json

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,10 +5,10 @@
55
"mode": "Indexed",
66
"description": "Linux virtual machines should be monitored and secured through the deployed Azure Monitor Agent. The Azure Monitor Agent collects telemetry data from the guest OS. This policy will audit virtual machines with supported OS images in supported regions. Learn more: https://aka.ms/AMAOverview.",
77
"metadata": {
8-
"version": "3.5.0",
8+
"version": "3.6.0",
99
"category": "Monitoring"
1010
},
11-
"version": "3.5.0",
11+
"version": "3.6.0",
1212
"parameters": {
1313
"effect": {
1414
"type": "String",
@@ -64,6 +64,7 @@
6464
"centralindia",
6565
"centralus",
6666
"centraluseuap",
67+
"chilecentral",
6768
"eastasia",
6869
"eastus",
6970
"eastus2",
@@ -72,6 +73,7 @@
7273
"francesouth",
7374
"germanynorth",
7475
"germanywestcentral",
76+
"indonesiacentral",
7577
"israelcentral",
7678
"italynorth",
7779
"japaneast",
@@ -81,7 +83,9 @@
8183
"koreacentral",
8284
"koreasouth",
8385
"malaysiasouth",
86+
"malaysiawest",
8487
"mexicocentral",
88+
"newzealandnorth",
8589
"northcentralus",
8690
"northeurope",
8791
"norwayeast",
@@ -563,6 +567,7 @@
563567
}
564568
},
565569
"versions": [
570+
"3.6.0",
566571
"3.5.0",
567572
"3.4.0",
568573
"3.3.0",

built-in-policies/policyDefinitions/Monitoring/AzureMonitor_Agent_Linux_VM_DINE.json

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,10 +5,10 @@
55
"mode": "Indexed",
66
"description": "Automate the deployment of Azure Monitor Agent extension on your Linux virtual machines for collecting telemetry data from the guest OS. This policy will install the extension if the OS and region are supported and system-assigned managed identity is enabled, and skip install otherwise. Learn more: https://aka.ms/AMAOverview.",
77
"metadata": {
8-
"version": "3.9.0",
8+
"version": "3.10.0",
99
"category": "Monitoring"
1010
},
11-
"version": "3.9.0",
11+
"version": "3.10.0",
1212
"parameters": {
1313
"effect": {
1414
"type": "String",
@@ -68,6 +68,7 @@
6868
"centralindia",
6969
"centralus",
7070
"centraluseuap",
71+
"chilecentral",
7172
"eastasia",
7273
"eastus",
7374
"eastus2",
@@ -76,6 +77,7 @@
7677
"francesouth",
7778
"germanynorth",
7879
"germanywestcentral",
80+
"indonesiacentral",
7981
"israelcentral",
8082
"italynorth",
8183
"japaneast",
@@ -85,7 +87,9 @@
8587
"koreacentral",
8688
"koreasouth",
8789
"malaysiasouth",
90+
"malaysiawest",
8891
"mexicocentral",
92+
"newzealandnorth",
8993
"northcentralus",
9094
"northeurope",
9195
"norwayeast",
@@ -616,6 +620,7 @@
616620
}
617621
},
618622
"versions": [
623+
"3.10.0",
619624
"3.9.0",
620625
"3.8.0",
621626
"3.7.0",

0 commit comments

Comments
 (0)