last sync: 2024-Jul-26 18:17:39 UTC

Deploy Diagnostic Settings for Key Vault to Log Analytics workspace

Azure BuiltIn Policy definition

Source Azure Portal
Display name Deploy Diagnostic Settings for Key Vault to Log Analytics workspace
Id bef3f64c-5290-43b7-85b0-9b254eef4c47
Version 3.0.0
Details on versioning
Category Monitoring
Microsoft Learn
Description Deploys the diagnostic settings for Key Vault to stream to a regional Log Analytics workspace when any Key Vault which is missing this diagnostic settings is created or updated.
Mode Indexed
Type BuiltIn
Preview False
Deprecated False
Effect Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
RBAC role(s)
Role Name Role Id
Monitoring Contributor 749f88d5-cbae-40b8-bcfc-e573ddc772fa
Log Analytics Contributor 92aaf0da-9dab-42b6-94a3-d43ce8d16293
Rule aliases THEN-ExistenceCondition (6)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.Insights/diagnosticSettings/logs[*] microsoft.insights diagnosticSettings properties.logs[*] True False
Microsoft.Insights/diagnosticSettings/logs[*].category microsoft.insights diagnosticSettings properties.logs[*].category True False
Microsoft.Insights/diagnosticSettings/logs[*].enabled microsoft.insights diagnosticSettings properties.logs[*].enabled True False
Microsoft.Insights/diagnosticSettings/metrics[*] microsoft.insights diagnosticSettings properties.metrics[*] True False
Microsoft.Insights/diagnosticSettings/metrics[*].enabled microsoft.insights diagnosticSettings properties.metrics[*].enabled True False
Microsoft.Insights/diagnosticSettings/workspaceId microsoft.insights diagnosticSettings properties.workspaceId True False
Rule resource types IF (1)
Microsoft.KeyVault/vaults
Compliance
The following 1 compliance controls are associated with this Policy definition 'Deploy Diagnostic Settings for Key Vault to Log Analytics workspace' (bef3f64c-5290-43b7-85b0-9b254eef4c47)
Control Domain Control Name MetadataId Category Title Owner Requirements Description Info Policy#
RMiT_v1.0 10.66 RMiT_v1.0_10.66 RMiT 10.66 Security of Digital Services Security of Digital Services - 10.66 Shared n/a A financial institution must implement robust technology security controls in providing digital services which assure the following: (a) confidentiality and integrity of customer and counterparty information and transactions; (b) reliability of services delivered via channels and devices with minimum disruption to services; (c) proper authentication of users or devices and authorisation of transactions; (d) sufficient audit trail and monitoring of anomalous transactions; (e) ability to identify and revert to the recovery point prior to incident or service disruption; and (f) strong physical control and logical control measures link 32
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State Type
[Deprecated]: Deploy Diagnostic Settings to Azure Services Deploy-Diagnostics-LogAnalytics Monitoring Deprecated ALZ
[Preview]: Control the use of diagnostic settings for specific resources in a Virtual Enclave 0a9ea1cb-7925-47fc-b0fe-8bb0a8190423 VirtualEnclaves Preview BuiltIn
RMIT Malaysia 97a6d4f1-3bed-4cf4-ac5b-0e444c0408d6 Regulatory Compliance GA BuiltIn
History
Date/Time (UTC ymd) (i) Change type Change detail
2022-08-26 16:33:38 change Major (2.0.0 > 3.0.0)
2021-10-08 15:47:40 change Major (1.0.0 > 2.0.0)
2019-10-29 23:04:36 add bef3f64c-5290-43b7-85b0-9b254eef4c47
JSON compare
compare mode: version left: version right:
JSON
api-version=2021-06-01
EPAC