last sync: 2025-May-14 18:52:07 UTC

Deploy Windows Diagnostic Agent to Collect Security Related Events

Community Policy definition

Source Repository Community-Policy GitHub
JSON Community-Policy GitHub
Deploy policy c0684160-102c-4d85-a658-d54f16e05ef7 (1.0.0) to Azure
Display name Deploy Windows Diagnostic Agent to Collect Security Related Events
Id c0684160-102c-4d85-a658-d54f16e05ef7
Version 1.0.0
Details on versioning
Category Monitoring
Microsoft Learn
Description This Policy will Deploy the Windows Diagnostic Agent and collect the following Security events: Audit success, Audit failure; and the following System events: Critical, Error, Warning. Additionaly, to account for VMs provisioned from custom images where the image SKU is blank this Policy is keyed to look for the storageProfile.osDisk.osType property of a VM. This property does not exist at provisioning time, but is populated by the VM agent after provisioining, and so will not trigger an automatic remediati
Mode Indexed
Type Custom Community
Effect Default
DeployIfNotExists
Allowed
DeployIfNotExists, AuditIfNotExists, Disabled
RBAC role(s)
Role Name Role Id
Log Analytics Contributor 92aaf0da-9dab-42b6-94a3-d43ce8d16293
Rule aliases IF (1)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.Compute/virtualMachines/storageProfile.osDisk.osType Microsoft.Compute virtualMachines properties.storageProfile.osDisk.osType True True
THEN-ExistenceCondition (3)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.Compute/virtualMachines/extensions/provisioningState Microsoft.Compute virtualMachines/extensions properties.provisioningState True False
Microsoft.Compute/virtualMachines/extensions/publisher Microsoft.Compute virtualMachines/extensions properties.publisher True False
Microsoft.Compute/virtualMachines/extensions/type Microsoft.Compute virtualMachines/extensions properties.type True False
Rule resource types IF (1)
Microsoft.Compute/virtualMachines
THEN-Deployment (1)
Microsoft.Compute/virtualMachines/extensions
JSON
EPAC
Deploy policy c0684160-102c-4d85-a658-d54f16e05ef7 (1.0.0) to Azure