Dynamic 'kid' Usage in Azure APIM Validate-JWT Policy
We currently use hardcoded exponent and modulus values within the
I want to add a policy using Azure policy that ensures that anonymous users cannot login or see my Azure storage. I'm getting an error.
I want to add a policy using Azure policy that ensures that anonymous users cannot login or see my Azure storage. I'm getting an error when using the JSON script that help tells me to use.
Require a tag on secret creation using Azure Policy
Background I want to make an Azure Policy that requires a tag to be created for every newly created secret. What I tried so far I made a new policy by copying the pre-existing Azure Policy Require a tag on resources and changed it to only apply to…
Azure initiative for ISO 27001:2022
We have to implement ISO 27001:2022 at Azure Switzerlan. Is there an azure initiative for ISO 27001:2022? There is currently one for ISO27001:2013. Does anyone know what should be changed for 27001:2022?

Unable to make the policy "An activity log alert should exist for specific administrative operations" compliance
Hello All, We have applied Azure CIS Azure Foundations v2.1.0 Regulatory Compliance on our subscription. Some of the policy among the initiative is not getting compliance, Below is the initiative for the NSG. I have created alert for the NSG creation…
Azure policy to allow tags with certain names (value doesn't matter)
Hi everyone, I have a list of allowed tags, I don't mean the value that the tag contains but only the name of the tag. The purpose of this is that all the tenant's resources only have tags that are included in this list. Because of this I need a policy…
An activity log alert should exist for specific Security operations : Wrong category in the rules sec
Hello Team, I Have assigned policy CIS Microsoft Azure Foundations Benchmark v2.0.0 to my subscription. I have created alerts for the required policy but still it showing non compliance. Upon further researching it seems there is some bug in the Policy…
Assign policy to specific resource in azure
Hi, Can I assign a policy to a specific resource (Ex, Virtual Machine) in azure? or the policy assigns to a resource group that includes the resources.
azure policy to check managedby property of resource group
hi, i m trying to create azure policy to make sure the mangedby property is set when creating resources group using terraform. { "field": "type", "equals": "Microsoft.Resources/resourceGroups/managedBy" } but…

Azure Resource Graph (ARG) Query to List All Failed Policy Deployments
When using Azure Policy, in particular a policy with Deploy If Not Exist (DINE), naturally the policy will try to remediate anything that doesn't align to the policy definition. However, if there is something that prevents the Policy Deployment from…

ISO27001:2013
Hello, I have noticed that my VMs running Linux Ubuntu 24.04 LTS are not compliant with the following policies: 7f89b1eb-583c-429a-8828-af049802c1d9 (Audit diagnostic setting for selected resource types) 32133ab0-ee4b-4b44-98d6-042180979d50 ([Preview]:…
how can i re -enable my disabled azure subscription?
To protect the security and privacy of your account, we perform routine audits of all Azure subscriptions. During one of these audits, we identified suspicious activity in your subscription that violates the Microsoft Acceptable Use Policy. We’ve…
Configure Azure Activity logs to stream to specified Storage account from all subscriptions
I want to Configure Azure Activity logs to stream to specified Storage account from all subscriptions, is there any Built In policy available which can be leveraged to send activity logs from all subscription to a pre-defined storage account.
DORA Regulations and Azure CSP (Reseller)
Hi team - we have customers asking us for DORA addendums in their Azure contracts - as they are in our CSP model, that would fall under the MCA framework - what is the guidance from Microsoft on that, has the MCA been updated so that it is fit for…
Private DNS zone with virtual network link on creation.
We currently have a hub and spoke setup with our Custom DNS on a single Subscription. what we want to do is if new DNS zones are created they get linked to the Custome DNS Vnet. Could this be done by azure policy
I am facing an issue with Azure Policy.
I am trying to enforce a tag on all my VMs. I have created a policy definition with a modify effect that adds the tag env with a value of prod if its missing. The policy assignment is at the subscription level. New VMs are getting tagged correctly, which…
Geo-fencing on complete azure solution
Hi Team, I want my azure subscription and its resource to be only accessible from specific countries like US, India, Canada & Austrailai
Generate Azure Policy compliance report with resource list
I am looking for a way to generate a report for Azure Policy compliance, which contains azure policies under a targeted Initiative, compliance against each azure policy under this initiative, including compliant and non-compliant resource list. At the…
How can I discover all necessary permissions to use a Azure Policy with least privileges
The Problem Hey I working for a project that will implement azure policies to secure the platform. We have to follow the policies of our customer. One of this policies is, to use always the concept of least privileges. If we take a look in the Policy…
How can I limit an application access to view only a subset of the users in Microsoft Graph API, MS Teams endpints?
What are the methods to restrict an application, that is using the Microsoft Graph API to fetch users conversations, access so that it can only view data of Microsoft Teams endpoints for a specific subset of users, ?