last sync: 2021-Aug-04 14:59:26 UTC

Azure Policy definition

Azure Monitor Private Link Scope should use private link

Name Azure Monitor Private Link Scope should use private link
Azure Portal
Id 0fc55270-f8bf-4feb-b7b8-5e7e7eacc6a6
Version 1.0.0
details on versioning
Category Monitoring
Microsoft docs
Description Azure Private Link lets you connect your virtual networks to Azure services without a public IP address at the source or destination. The Private Link platform handles the connectivity between the consumer and services over the Azure backbone network. By mapping private endpoints to Azure Monitor Private Links Scope, you can reduce data leakage risks. Learn more about private links at: https://docs.microsoft.com/azure/azure-monitor/logs/private-link-security.
Mode Indexed
Type BuiltIn
Preview FALSE
Deprecated FALSE
Effect Default: AuditIfNotExists
Allowed: (AuditIfNotExists, Disabled)
Used RBAC Role none
History
Date/Time (UTC ymd) (i) Change type Change detail
2021-07-07 15:26:31 add 0fc55270-f8bf-4feb-b7b8-5e7e7eacc6a6
Used in Initiatives none
JSON
{
  "properties": {
    "displayName": "Azure Monitor Private Link Scope should use private link",
    "policyType": "BuiltIn",
    "mode": "Indexed",
    "description": "Azure Private Link lets you connect your virtual networks to Azure services without a public IP address at the source or destination. The Private Link platform handles the connectivity between the consumer and services over the Azure backbone network. By mapping private endpoints to Azure Monitor Private Links Scope, you can reduce data leakage risks. Learn more about private links at: https://docs.microsoft.com/azure/azure-monitor/logs/private-link-security.",
    "metadata": {
      "version": "1.0.0",
      "category": "Monitoring"
    },
    "parameters": {
      "effect": {
        "type": "String",
        "metadata": {
          "displayName": "Effect",
          "description": "Enable or disable the execution of the policy"
        },
        "allowedValues": [
          "AuditIfNotExists",
          "Disabled"
        ],
        "defaultValue": "AuditIfNotExists"
      }
    },
    "policyRule": {
      "if": {
        "allOf": [
          {
            "field": "type",
            "equals": "Microsoft.Insights/privateLinkScopes"
          },
          {
            "count": {
            "field": "Microsoft.Insights/privateLinkScopes/privateEndpointConnections[*]",
              "where": {
              "field": "Microsoft.Insights/privateLinkScopes/privateEndpointConnections[*].privateLinkServiceConnectionState.status",
                "equals": "Approved"
              }
            },
            "less": 1
          }
        ]
      },
      "then": {
      "effect": "[parameters('effect')]"
      }
    }
  },
  "id": "/providers/Microsoft.Authorization/policyDefinitions/0fc55270-f8bf-4feb-b7b8-5e7e7eacc6a6",
  "type": "Microsoft.Authorization/policyDefinitions",
  "name": "0fc55270-f8bf-4feb-b7b8-5e7e7eacc6a6"
}