last sync: 2021-Jan-18 16:05:48 UTC

Azure Policy definition

Cognitive Services accounts should enable data encryption

Name Cognitive Services accounts should enable data encryption
Azure Portal
Id 2bdd0062-9d75-436e-89df-487dd8e4b3c7
Version 1.0.0
details on versioning
Category Cognitive Services
Microsoft docs
Description This policy audits any Cognitive Services account not using data encryption. For each Cognitive Services account with storage, should enable data encryption with either customer managed or Microsoft managed key.
Mode Indexed
Type BuiltIn
Preview FALSE
Deprecated FALSE
Effect Default: Audit
Allowed: (Audit, Deny, Disabled)
Used RBAC Role none
History
Date/Time (UTC ymd) (i) Change type Change detail
2020-06-09 16:25:53 add 2bdd0062-9d75-436e-89df-487dd8e4b3c7
Used in Initiatives
Initiative DisplayName Initiative Id Initiative Category State
[Preview]: Azure Security Benchmark v2 bb522ac1-bc39-4957-b194-429bcd3bcb0b Regulatory Compliance Preview
Json
{
  "properties": {
    "displayName": "Cognitive Services accounts should enable data encryption",
    "policyType": "BuiltIn",
    "mode": "Indexed",
    "description": "This policy audits any Cognitive Services account not using data encryption. For each Cognitive Services account with storage, should enable data encryption with either customer managed or Microsoft managed key.",
    "metadata": {
      "version": "1.0.0",
      "category": "Cognitive Services"
    },
    "parameters": {
      "effect": {
        "type": "String",
        "metadata": {
          "displayName": "Effect",
          "description": "The effect determines what happens when the policy rule is evaluated to match"
        },
        "allowedValues": [
          "Audit",
          "Deny",
          "Disabled"
        ],
        "defaultValue": "Audit"
      }
    },
    "policyRule": {
      "if": {
        "allOf": [
          {
            "field": "type",
            "equals": "Microsoft.CognitiveServices/accounts"
          },
          {
            "field": "Microsoft.CognitiveServices/accounts/encryption.keySource",
            "exists": "false"
          }
        ]
      },
      "then": {
      "effect": "[parameters('effect')]"
      }
    }
  },
  "id": "/providers/Microsoft.Authorization/policyDefinitions/2bdd0062-9d75-436e-89df-487dd8e4b3c7",
  "type": "Microsoft.Authorization/policyDefinitions",
  "name": "2bdd0062-9d75-436e-89df-487dd8e4b3c7"
}