Configure Azure Activity logs to stream to specified Storage account from all subscriptions
I want to Configure Azure Activity logs to stream to specified Storage account from all subscriptions, is there any Built In policy available which can be leveraged to send activity logs from all subscription to a pre-defined storage account.
DORA Regulations and Azure CSP (Reseller)
Hi team - we have customers asking us for DORA addendums in their Azure contracts - as they are in our CSP model, that would fall under the MCA framework - what is the guidance from Microsoft on that, has the MCA been updated so that it is fit for…
Configure Azure Activity logs to stream to specified Storage account from all subscriptions
I want to send all Activity logs from all subscriptions (with in my Managment group) to a specific storage account. Do we have any Built in policy which can be enforced at management group and propagated to all subscriptions ?
Use Azure Policy to manage Extensions Allow- and Blocklist on Azure Arc Connected Machines
Is there a way to manage Extensions Allow- and Blocklist for Azure Arc Connected Machines? As mentioned in this KB-Article, it should be possible. But it is not precisely stated, if this works only for Azure VMs, or if this also applies for Arc…
Question about VM update and Policy
Hi everyone, I have been tasked to create a policy that will do a weekly VM update at a certain time but I have been reading more about this and if my understanding is correct, policy is not meant to be used this way. My understanding is I will need to…
Urgent: Account Locked and Verification Issues (TrackingID#2412170040002994)
Dear Azure Support, I am reaching out regarding our account, which has been locked for almost a month. Unfortunately, despite following up on the emails we've received, the responses have not been helpful in resolving the issue. This situation is…
Question regarding the document- https://learn.microsoft.com/en-us/azure/openshift/howto-tag-resources
Team, I'm from the Azure Containers team, and regarding the documentation, there seems to be an issue that needs some opinions. Below are the test lab results I performed. Please see the details below. Thanks, Conclusion The policy definition and…
Is it possible to enforce a Resource Naming Convention using a RegEx from an Azure Policy.
Is it possible to enforce a required resource naming convention using a RegEx from an Azure Policy.
AZT508 - Azure Policy
Hello all :) I have designed the following simple KQL query to monitor for potential misuse of the DeployIfNotExists effect by detecting policy definition updates: AzureActivity | where OperationNameValue ==…
Restrict Savings Plan creation outside specified subscription in Mgmt group via Azure Policy
Using Terraform/Azure Policies, I want to restrict the creation of savings plans only to one of our subscriptions i.e Prod. We have more than 10 subscriptions in the tenant in different management groups. Since Savings Plans don't have a straightforward…
Have few queries related to management group
Hello Team, Have few queries related to management group. For example, I've a parent MG and child MG. Need to create a new MG under child MG and move few subscriptions from child MG to new MG. By doing so, Will there be any latency and data loss? Will…
Azure initiative for ISO 27001:2022
We have to implement ISO 27001:2022 at Azure Switzerlan. Is there an azure initiative for ISO 27001:2022? There is currently one for ISO27001:2013. Does anyone know what should be changed for 27001:2022?
How to resolve Windows servers should be configured to use secure communication protocols
I have got an azure advisor alert concerning windows virtual machines. These are standard VM's and they are reporting the following remediation steps. I have carried out the following to remediate the issue, the Os version is windows 2019. I have carried…
Azure Account Registration Issue – Urgent Assistance Needed
Dear Azure Support Team, I am unable to register an Azure account due to repeated phone number validation errors. I have attempted using my Philippine number as well as several other numbers, but the issue persists. Additionally, one of our accounts is…
Azure Defender for cloud Settings | Security policies
Guideline to create Azure Defender for cloud Settings | Security policies
Azure Policy Tag add tag if missing
I set a new policy for existing resources to add required tag if missing. scenario1: Resource1 have the following tags and value Tag name = Project Value = ProjSSO Tag name = Purpose Value = app login however if the the policy trigger I received an…
Dynamic 'kid' Usage in Azure APIM Validate-JWT Policy
We currently use hardcoded exponent and modulus values within the
Set up notifications for Root Tenant Group assigments
Set up notifications for Root Tenant Group assigments azurerm_role_management_policy I am trying to enable notification(email to slack channel) whenever someone requests for PIM role activiation. The slack channel contains the admins who can approve the…
Can I create an Azure Policy that disables both FTP and FTPS deployment?
I am wondering if there is way to disable both FTP and FTPS web app deployments. I have a policy but it doesnt enforce it unless I manually disable it and then the policy becomes compliant. Can a policy automatically do this for me to make it compliant…
I have enabled the periodic assessment of this VM through azure policy but still periodic assessment is not enabled.
I have enabled the periodic assessment of this VM through azure policy but still periodic assessment is not enabled.