last sync: 2020-Sep-25 13:37:27 UTC

Azure Policy

[Deprecated]: Access to App Services should be restricted

Policy DisplayName [Deprecated]: Access to App Services should be restricted
Policy Id 1a833ff1-d297-4a0f-9944-888428f8e0ff
Policy Category Security Center
Policy Description Azure security center has discovered that the networking configuration of some of your app services are overly permissive and allow inbound traffic from ranges that are too broad
Policy Mode All
Policy Type BuiltIn
Policy in Preview FALSE
Policy Deprecated True
Policy Effect Default: Disabled
Allowed: (AuditIfNotExists,Disabled)
Roles used none
Policy Changes
Date/Time (UTC ymd) (i) Change Change detail
2020-02-25 11:29:35 change: DisplayName previous DisplayName: [Preview]: Access to App Services should be restricted
Used in Policy Initiative(s) none
Policy Rule
{
  "properties": {
  "displayName": "[Deprecated]: Access to App Services should be restricted",
    "policyType": "BuiltIn",
    "mode": "All",
    "description": "Azure security center has discovered that the networking configuration of some of your app services are overly permissive and allow inbound traffic from ranges that are too broad",
    "metadata": {
      "version": "1.0.0-deprecated",
      "category": "Security Center",
      "deprecated": true
    },
    "parameters": {
      "effect": {
        "type": "String",
        "metadata": {
        "displayName": "[Deprecated]: Effect",
          "description": "Enable or disable the execution of the policy"
        },
        "allowedValues": [
          "AuditIfNotExists",
          "Disabled"
        ],
        "defaultValue": "Disabled"
      }
    },
    "policyRule": {
      "if": {
        "field": "type",
        "equals": "Microsoft.Web/sites"
      },
      "then": {
      "effect": "[parameters('effect')]",
        "details": {
          "type": "Microsoft.Security/complianceResults",
          "name": "restrictAccessToAppServices",
          "existenceCondition": {
            "field": "Microsoft.Security/complianceResults/resourceStatus",
            "in": [
              "OffByPolicy",
              "Healthy"
            ]
          }
        }
      }
    }
  },
  "id": "/providers/Microsoft.Authorization/policyDefinitions/1a833ff1-d297-4a0f-9944-888428f8e0ff",
  "type": "Microsoft.Authorization/policyDefinitions",
  "name": "1a833ff1-d297-4a0f-9944-888428f8e0ff"
}