last sync: 2024-Apr-24 17:46:58 UTC

Azure Storage deploy a specific min TLS version requirement and enforce SSL/HTTPS

Azure Landing Zones (ALZ) Policy definition

Source Repository Azure Landing Zones (ALZ) GitHub
JSON Deploy-Storage-sslEnforcement
Display name Azure Storage deploy a specific min TLS version requirement and enforce SSL/HTTPS
Id Deploy-Storage-sslEnforcement
Version 1.2.0
Details on versioning
Category Storage
Description Deploy a specific min TLS version requirement and enforce SSL on Azure Storage. Enables secure server to client by enforce minimal Tls Version to secure the connection between your database server and your client applications helps protect against 'man in the middle' attacks by encrypting the data stream between the server and your application. This configuration enforces that SSL is always enabled for accessing your Azure Storage.
Mode Indexed
Type Custom Azure Landing Zones (ALZ)
Preview False
Deprecated False
Effect Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
RBAC role(s)
Role Name Role Id
Storage Account Contributor 17d1049b-9a84-46fb-8f53-869881c3d3ab
Rule aliases IF (2)
Alias Namespace ResourceType DefaultPath Modifiable
Microsoft.Storage/storageAccounts/minimumTlsVersion Microsoft.Storage storageAccounts properties.minimumTlsVersion true
Microsoft.Storage/storageAccounts/supportsHttpsTrafficOnly Microsoft.Storage storageAccounts properties.supportsHttpsTrafficOnly true
THEN-ExistenceCondition (2)
Alias Namespace ResourceType DefaultPath Modifiable
Microsoft.Storage/storageAccounts/minimumTlsVersion Microsoft.Storage storageAccounts properties.minimumTlsVersion true
Microsoft.Storage/storageAccounts/supportsHttpsTrafficOnly Microsoft.Storage storageAccounts properties.supportsHttpsTrafficOnly true
Rule resource types IF (1)
Microsoft.Storage/storageAccounts
THEN-Deployment (1)
Microsoft.Storage/storageAccounts
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State
Deny or Deploy and append TLS requirements and SSL enforcement on resources without Encryption in transit Enforce-EncryptTransit Encryption GA
History
Date/Time (UTC ymd) (i) Change type Change detail
2023-09-27 17:59:47 change Minor (1.1.0 > 1.2.0)
2022-06-17 17:16:31 change Minor (1.0.0 > 1.1.0)
JSON compare
compare mode: version left: version right:
JSON
EPAC