Skip to content

Commit 8a6c851

Browse files
authored
Merge pull request #201923 from timwarner-msft/timwarner-mconfig2
Add new Azure Automanage Machine Configuration docset
2 parents ba0633e + bb7cbec commit 8a6c851

File tree

84 files changed

+1499
-1330
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

84 files changed

+1499
-1330
lines changed

.openpublishing.publish.config.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -978,6 +978,7 @@
978978
".openpublishing.redirection.app-service.json",
979979
".openpublishing.redirection.key-vault.json",
980980
".openpublishing.redirection.sql-database.json",
981+
".openpublishing.redirection.machine-configuration.json",
981982
".openpublishing.redirection.security-benchmark.json",
982983
"articles/synapse-analytics/.openpublishing.redirection.synapse-analytics.json",
983984
".openpublishing.redirection.azure-web-pubsub.json",
Lines changed: 69 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,69 @@
1+
{
2+
"redirections": [
3+
{
4+
"source_path_from_root": "/articles/governance/policy/concepts/guest-configuration.md",
5+
"redirect_url": "/azure/governance/machine-configuration/overview",
6+
"redirect_document_id": false
7+
},
8+
{
9+
"source_path_from_root": "/articles/governance/policy/concepts/guest-configuration-policy-effects.md",
10+
"redirect_url": "/azure/governance/machine-configuration/machine-configuration-policy-effects",
11+
"redirect_document_id": false
12+
},
13+
{
14+
"source_path_from_root": "/articles/governance/policy/how-to/guest-configuration-desired-state-configuration-extension-migration.md",
15+
"redirect_url": "/azure/governance/machine-configuration/machine-configuration-dsc-extension-migration",
16+
"redirect_document_id": false
17+
},
18+
{
19+
"source_path_from_root": "/articles/governance/policy/concepts/guest-configuration-custom.md",
20+
"redirect_url": "/azure/governance/machine-configuration/machine-configuration-custom",
21+
"redirect_document_id": false
22+
},
23+
{
24+
"source_path_from_root": "/articles/governance/policy/how-to/guest-configuration-create.md",
25+
"redirect_url": "/azure/governance/machine-configuration/machine-configuration-create",
26+
"redirect_document_id": false
27+
},
28+
{
29+
"source_path_from_root": "/articles/governance/policy/how-to/guest-configuration-create-test.md",
30+
"redirect_url": "/azure/governance/machine-configuration/machine-configuration-create-test",
31+
"redirect_document_id": false
32+
},
33+
{
34+
"source_path_from_root": "/articles/governance/policy/how-to/guest-configuration-create-signing.md",
35+
"redirect_url": "/azure/governance/machine-configuration/machine-configuration-create-signing",
36+
"redirect_document_id": false
37+
},
38+
{
39+
"source_path_from_root": "/articles/governance/policy/how-to/guest-configuration-create-setup.md",
40+
"redirect_url": "/azure/governance/machine-configuration/machine-configuration-create-setup",
41+
"redirect_document_id": false
42+
},
43+
{
44+
"source_path_from_root": "/articles/governance/policy/how-to/guest-configuration-create-publish.md",
45+
"redirect_url": "/azure/governance/machine-configuration/machine-configuration-create-publish",
46+
"redirect_document_id": false
47+
},
48+
{
49+
"source_path_from_root": "/articles/governance/policy/how-to/guest-configuration-create-definition.md",
50+
"redirect_url": "/azure/governance/machine-configuration/machine-configuration-create-definition",
51+
"redirect_document_id": false
52+
},
53+
{
54+
"source_path_from_root": "/articles/governance/policy/how-to/guest-configuration-create-assignment.md",
55+
"redirect_url": "/azure/governance/machine-configuration/machine-configuration-create-assignment",
56+
"redirect_document_id": false
57+
},
58+
{
59+
"source_path_from_root": "/articles/governance/policy/how-to/guest-configuration-azure-automation-migration.md",
60+
"redirect_url": "/azure/governance/machine-configuration/machine-configuration-azure-automation-migration",
61+
"redirect_document_id": false
62+
},
63+
{
64+
"source_path_from_root": "/articles/governance/policy/concepts/guest-configuration-assignments.md",
65+
"redirect_url": "/azure/governance/machine-configuration/machine-configuration-assignments",
66+
"redirect_document_id": false
67+
},
68+
]
69+
}

articles/active-directory-domain-services/manage-group-policy.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ This article shows you how to install the Group Policy Management tools, then ed
2424
If you are interested in server management strategy, including machines in Azure and
2525
[hybrid connected](../azure-arc/servers/overview.md),
2626
consider reading about the
27-
[guest configuration](../governance/policy/concepts/guest-configuration.md)
27+
[guest configuration](../governance/machine-configuration/overview.md)
2828
feature of
2929
[Azure Policy](../governance/policy/overview.md).
3030

articles/automanage/automanage-arc.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ For all of these services, we will auto-onboard, auto-configure, monitor for dri
1818

1919
Automanage supports the following operating systems for Azure Arc-enabled servers
2020

21-
- Windows Server 2012 R2, 2016, 2019, 2022
21+
- Windows Server 2012 R2, 2016, 2019, 2022
2222
- CentOS 7.3+, 8
2323
- RHEL 7.4+, 8
2424
- Ubuntu 16.04, 18.04, 20.04
@@ -32,7 +32,7 @@ Automanage supports the following operating systems for Azure Arc-enabled server
3232
|[Update Management](../automation/update-management/overview.md) |You can use Update Management in Azure Automation to manage operating system updates for your machines. You can quickly assess the status of available updates on all agent machines and manage the process of installing required updates for servers. |Production, Dev/Test |
3333
|[Microsoft Antimalware](../security/fundamentals/antimalware.md) |Microsoft Antimalware for Azure is a free real-time protection that helps identify and remove viruses, spyware, and other malicious software. It generates alerts when known malicious or unwanted software tries to install itself or run on your Azure systems. **Note:** Microsoft Antimalware requires that there be no other antimalware software installed, or it may fail to work. This is also only supported for Windows Server 2016 and above. |Production, Dev/Test |
3434
|[Change Tracking & Inventory](../automation/change-tracking/overview.md) |Change Tracking and Inventory combines change tracking and inventory functions to allow you to track virtual machine and server infrastructure changes. The service supports change tracking across services, daemons software, registry, and files in your environment to help you diagnose unwanted changes and raise alerts. Inventory support allows you to query in-guest resources for visibility into installed applications and other configuration items. |Production, Dev/Test |
35-
|[Azure Guest Configuration](../governance/policy/concepts/guest-configuration.md) | Guest Configuration policy is used to monitor the configuration and report on the compliance of the machine. The Automanage service will install the Azure security baseline using the Guest Configuration extension. For Arc machines, the guest configuration service will install the baseline in audit-only mode. You will be able to see where your VM is out of compliance with the baseline, but noncompliance won't be automatically remediated. |Production, Dev/Test |
35+
|[Azure Guest Configuration](../governance/machine-configuration/overview.md) | Guest Configuration policy is used to monitor the configuration and report on the compliance of the machine. The Automanage service will install the Azure security baseline using the Guest Configuration extension. For Arc machines, the guest configuration service will install the baseline in audit-only mode. You will be able to see where your VM is out of compliance with the baseline, but noncompliance won't be automatically remediated. |Production, Dev/Test |
3636
|[Azure Automation Account](../automation/automation-create-standalone-account.md) |Azure Automation supports management throughout the lifecycle of your infrastructure and applications. |Production, Dev/Test |
3737
|[Log Analytics Workspace](../azure-monitor/logs/log-analytics-overview.md) |Azure Monitor stores log data in a Log Analytics workspace, which is an Azure resource and a container where data is collected, aggregated, and serves as an administrative boundary. |Production, Dev/Test |
3838

articles/automanage/automanage-linux.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ Automanage supports the following Linux distributions and versions:
3737
|[Microsoft Defender for Cloud](../security-center/security-center-introduction.md) |Microsoft Defender for Cloud is a unified infrastructure security management system that strengthens the security posture of your data centers, and provides advanced threat protection across your hybrid workloads in the cloud. Learn [more](../security-center/security-center-introduction.md). Automanage will configure the subscription where your VM resides to the free-tier offering of Microsoft Defender for Cloud (Enhanced security off). If your subscription is already onboarded to Microsoft Defender for Cloud, then Automanage will not reconfigure it. |Production, Dev/Test |
3838
|[Update Management](../automation/update-management/overview.md) |You can use Update Management in Azure Automation to manage operating system updates for your machines. You can quickly assess the status of available updates on all agent machines and manage the process of installing required updates for servers. Learn [more](../automation/update-management/overview.md). |Production, Dev/Test |
3939
|[Change Tracking & Inventory](../automation/change-tracking/overview.md) |Change Tracking and Inventory combines change tracking and inventory functions to allow you to track virtual machine and server infrastructure changes. The service supports change tracking across services, daemons software, registry, and files in your environment to help you diagnose unwanted changes and raise alerts. Inventory support allows you to query in-guest resources for visibility into installed applications and other configuration items. Learn [more](../automation/change-tracking/overview.md). |Production, Dev/Test |
40-
|[Guest configuration](../governance/policy/concepts/guest-configuration.md) | Guest configuration is used to monitor the configuration and report on the compliance of the machine. The Automanage service will install the Azure Linux baseline using the guest configuration extension. For Linux machines, the guest configuration service will install the baseline in audit-only mode. You will be able to see where your VM is out of compliance with the baseline, but noncompliance won't be automatically remediated. Learn [more](../governance/policy/concepts/guest-configuration.md). |Production, Dev/Test |
40+
|[Guest configuration](../governance/machine-configuration/overview.md) | Guest configuration is used to monitor the configuration and report on the compliance of the machine. The Automanage service will install the Azure Linux baseline using the guest configuration extension. For Linux machines, the guest configuration service will install the baseline in audit-only mode. You will be able to see where your VM is out of compliance with the baseline, but noncompliance won't be automatically remediated. Learn [more](../governance/machine-configuration/overview.md). |Production, Dev/Test |
4141
|[Boot Diagnostics](../virtual-machines/boot-diagnostics.md) | Boot diagnostics is a debugging feature for Azure virtual machines (VM) that allows diagnosis of VM boot failures. Boot diagnostics enables a user to observe the state of their VM as it is booting up by collecting serial log information and screenshots. This will only be enabled for machines that are using managed disks. |Production, Dev/Test |
4242
|[Azure Automation Account](../automation/automation-create-standalone-account.md) |Azure Automation supports management throughout the lifecycle of your infrastructure and applications. Learn [more](../automation/automation-intro.md). |Production, Dev/Test |
4343
|[Log Analytics Workspace](../azure-monitor/logs/log-analytics-workspace-overview.md) |Azure Monitor stores log data in a Log Analytics workspace, which is an Azure resource and a container where data is collected, aggregated, and serves as an administrative boundary. Learn [more](../azure-monitor/logs/workspace-design.md). |Production, Dev/Test |

articles/automanage/automanage-windows-server.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ Automanage supports the following Windows versions:
2424
- Windows Server 2019
2525
- Windows Server 2022
2626
- Windows Server 2022 Azure Edition
27-
- Windows 10
27+
- Windows 10
2828

2929
## Participating services
3030

@@ -36,7 +36,7 @@ Automanage supports the following Windows versions:
3636
|[Microsoft Antimalware](../security/fundamentals/antimalware.md) |Microsoft Antimalware for Azure is a free real-time protection that helps identify and remove viruses, spyware, and other malicious software. It generates alerts when known malicious or unwanted software tries to install itself or run on your Azure systems. **Note:** Microsoft Antimalware requires that there be no other antimalware software installed, or it may fail to work. |Production, Dev/Test |
3737
|[Update Management](../automation/update-management/overview.md) |You can use Update Management in Azure Automation to manage operating system updates for your machines. You can quickly assess the status of available updates on all agent machines and manage the process of installing required updates for servers. |Production, Dev/Test |
3838
|[Change Tracking & Inventory](../automation/change-tracking/overview.md) |Change Tracking and Inventory combines change tracking and inventory functions to allow you to track virtual machine and server infrastructure changes. The service supports change tracking across services, daemons software, registry, and files in your environment to help you diagnose unwanted changes and raise alerts. Inventory support allows you to query in-guest resources for visibility into installed applications and other configuration items. |Production, Dev/Test |
39-
|[Guest configuration](../governance/policy/concepts/guest-configuration.md) | Guest configuration policy is used to monitor the configuration and report on the compliance of the machine. The Automanage service will install the [Windows security baselines](/windows/security/threat-protection/windows-security-baselines) using the guest configuration extension. For Windows machines, the guest configuration service will install the baseline in audit-only mode. You will be able to see where your VM is out of compliance with the baseline, but noncompliance won't be automatically remediated. Learn [more](../governance/policy/concepts/guest-configuration.md). To modify the audit mode for Windows machines, use a custom profile to choose your audit mode setting. [Learn more](virtual-machines-custom-profile.md) |Production, Dev/Test |
39+
|[Guest configuration](../governance/machine-configuration/overview.md) | Guest configuration policy is used to monitor the configuration and report on the compliance of the machine. The Automanage service will install the [Windows security baselines](/windows/security/threat-protection/windows-security-baselines) using the guest configuration extension. For Windows machines, the guest configuration service will install the baseline in audit-only mode. You will be able to see where your VM is out of compliance with the baseline, but noncompliance won't be automatically remediated. Learn [more](../governance/machine-configuration/overview.md). To modify the audit mode for Windows machines, use a custom profile to choose your audit mode setting. [Learn more](virtual-machines-custom-profile.md) |Production, Dev/Test |
4040
|[Boot Diagnostics](../virtual-machines/boot-diagnostics.md) | Boot diagnostics is a debugging feature for Azure virtual machines (VM) that allows diagnosis of VM boot failures. Boot diagnostics enables a user to observe the state of their VM as it is booting up by collecting serial log information and screenshots. This will only be enabled for machines that are using managed disks. |Production, Dev/Test |
4141
|[Windows Admin Center](/windows-server/manage/windows-admin-center/azure/manage-vm) | Use Windows Admin Center (preview) in the Azure portal to manage the Windows Server operating system inside an Azure VM. This is only supported for machines using Windows Server 2016 or higher. Automanage configures Windows Admin Center over a Private IP address. If you wish to connect with Windows Admin Center over a Public IP address, please open an inbound port rule for port 6516. Automanage onboards Windows Admin Center for the Dev/Test profile by default. Use the preferences to enable or disable Windows Admin Center for the Production and Dev/Test environments. |Production, Dev/Test |
4242
|[Azure Automation Account](../automation/automation-create-standalone-account.md) |Azure Automation supports management throughout the lifecycle of your infrastructure and applications. |Production, Dev/Test |

articles/automanage/virtual-machines-best-practices.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ For all of these services, we will auto-onboard, auto-configure, monitor for dri
2626
|Microsoft Antimalware |Microsoft Antimalware for Azure is a free real-time protection that helps identify and remove viruses, spyware, and other malicious software. It generates alerts when known malicious or unwanted software tries to install itself or run on your Azure systems. Learn [more](../security/fundamentals/antimalware.md). |Azure VM Best Practices – Production, Azure VM Best Practices – Dev/Test |Yes |
2727
|Update Management |You can use Update Management in Azure Automation to manage operating system updates for your virtual machines. You can quickly assess the status of available updates on all agent machines and manage the process of installing required updates for servers. Learn [more](../automation/update-management/overview.md). |Azure VM Best Practices – Production, Azure VM Best Practices – Dev/Test |No |
2828
|Change Tracking & Inventory |Change Tracking and Inventory combines change tracking and inventory functions to allow you to track virtual machine and server infrastructure changes. The service supports change tracking across services, daemons software, registry, and files in your environment to help you diagnose unwanted changes and raise alerts. Inventory support allows you to query in-guest resources for visibility into installed applications and other configuration items. Learn [more](../automation/change-tracking/overview.md). |Azure VM Best Practices – Production, Azure VM Best Practices – Dev/Test |No |
29-
|Guest configuration | Guest configuration is used to monitor the configuration and report on the compliance of the machine. The Automanage service will install the [Windows security baselines](/windows/security/threat-protection/windows-security-baselines) using the guest configuration extension. Learn [more](../governance/policy/concepts/guest-configuration.md). |Azure VM Best Practices – Production, Azure VM Best Practices – Dev/Test |No |
29+
|Guest configuration | Guest configuration is used to monitor the configuration and report on the compliance of the machine. The Automanage service will install the [Windows security baselines](/windows/security/threat-protection/windows-security-baselines) using the guest configuration extension. Learn [more](../governance/machine-configuration/overview.md). |Azure VM Best Practices – Production, Azure VM Best Practices – Dev/Test |No |
3030
|Azure Automation Account |Azure Automation supports management throughout the lifecycle of your infrastructure and applications. Learn [more](../automation/automation-intro.md). |Azure VM Best Practices – Production, Azure VM Best Practices – Dev/Test |No |
3131
|Log Analytics Workspace |Azure Monitor stores log data in a Log Analytics workspace, which is an Azure resource and a container where data is collected, aggregated, and serves as an administrative boundary. Learn [more](../azure-monitor/logs/log-analytics-workspace-overview.md). |Azure VM Best Practices – Production, Azure VM Best Practices – Dev/Test |No |
3232

0 commit comments

Comments
 (0)