last sync: 2020-Jul-03 15:47:34 UTC

Azure Policy

Advanced threat protection should be enabled on Virtual Machines

Policy DisplayName Advanced threat protection should be enabled on Virtual Machines
Policy Id 4da35fc9-c9e7-4960-aec9-797fe7d9051d
Policy Category Security Center
Policy Description Advanced threat protection standard tier should be enabled on Virtual Machines. This provides real-time threat protection for virtual machine workloads and generates hardening recommendations as well as alerts about suspicious activities.
Policy Mode All
Policy Type BuiltIn
Policy in Preview FALSE
Policy Deprecated FALSE
Policy Effect Default: AuditIfNotExists
Allowed: (AuditIfNotExists,Disabled)
Roles used none
Policy Changes
Date/Time (UTC ymd) (i) Change Change detail
2020-06-23 16:03:25 add: Policy 4da35fc9-c9e7-4960-aec9-797fe7d9051d
Used in Policy Initiative(s)
Initiative DisplayName Initiative Id
Enable Monitoring in Azure Security Center 1f3afdf9-d0c9-4c3d-847f-89da613e70a8
Policy Rule
{
  "properties": {
    "displayName": "Advanced threat protection should be enabled on Virtual Machines",
    "policyType": "BuiltIn",
    "mode": "All",
    "description": "Advanced threat protection standard tier should be enabled on Virtual Machines. This provides real-time threat protection for virtual machine workloads and generates hardening recommendations as well as alerts about suspicious activities.",
    "metadata": {
      "version": "1.0.1",
      "category": "Security Center"
    },
    "parameters": {
      "effect": {
        "type": "String",
        "metadata": {
          "displayName": "Effect",
          "description": "Enable or disable the execution of the policy"
        },
        "allowedValues": [
          "AuditIfNotExists",
          "Disabled"
        ],
        "defaultValue": "AuditIfNotExists"
      }
    },
    "policyRule": {
      "if": {
        "field": "type",
        "equals": "Microsoft.Resources/subscriptions"
      },
      "then": {
      "effect": "[parameters('effect')]",
        "details": {
          "type": "Microsoft.Security/pricings",
          "name": "VirtualMachines",
          "existenceScope": "subscription",
          "existenceCondition": {
            "field": "Microsoft.Security/pricings/pricingTier",
            "equals": "Standard"
          }
        }
      }
    }
  },
  "id": "/providers/Microsoft.Authorization/policyDefinitions/4da35fc9-c9e7-4960-aec9-797fe7d9051d",
  "type": "Microsoft.Authorization/policyDefinitions",
  "name": "4da35fc9-c9e7-4960-aec9-797fe7d9051d"
}