last sync: 2020-Sep-28 14:58:36 UTC

Azure Policy

Advanced threat protection should be enabled on Azure Container Registry registries

Policy DisplayName Advanced threat protection should be enabled on Azure Container Registry registries
Policy Id c25d9a16-bc35-4e15-a7e5-9db606bf9ed4
Policy Category Security Center
Policy Description Advanced threat protection provides scanning of container registries for security vulnerabilities on each pushed container image and exposes detailed findings per image.
Policy Mode All
Policy Type BuiltIn
Policy in Preview FALSE
Policy Deprecated FALSE
Policy Effect Default: AuditIfNotExists
Allowed: (AuditIfNotExists,Disabled)
Roles used none
Policy Changes
Date/Time (UTC ymd) (i) Change Change detail
2020-07-14 15:28:17 change: DisplayName previous DisplayName: Advanced threat protection should be enabled on Azure Container Registry
2020-06-23 16:03:25 add: Policy c25d9a16-bc35-4e15-a7e5-9db606bf9ed4
Used in Policy Initiative(s)
Initiative DisplayName Initiative Id
Enable Monitoring in Azure Security Center 1f3afdf9-d0c9-4c3d-847f-89da613e70a8
Policy Rule
{
  "properties": {
    "displayName": "Advanced threat protection should be enabled on Azure Container Registry registries",
    "policyType": "BuiltIn",
    "mode": "All",
    "description": "Advanced threat protection provides scanning of container registries for security vulnerabilities on each pushed container image and exposes detailed findings per image.",
    "metadata": {
      "version": "1.0.2",
      "category": "Security Center"
    },
    "parameters": {
      "effect": {
        "type": "String",
        "metadata": {
          "displayName": "Effect",
          "description": "Enable or disable the execution of the policy"
        },
        "allowedValues": [
          "AuditIfNotExists",
          "Disabled"
        ],
        "defaultValue": "AuditIfNotExists"
      }
    },
    "policyRule": {
      "if": {
        "field": "type",
        "equals": "Microsoft.Resources/subscriptions"
      },
      "then": {
      "effect": "[parameters('effect')]",
        "details": {
          "type": "Microsoft.Security/pricings",
          "name": "ContainerRegistry",
          "existenceScope": "subscription",
          "existenceCondition": {
            "field": "Microsoft.Security/pricings/pricingTier",
            "equals": "Standard"
          }
        }
      }
    }
  },
  "id": "/providers/Microsoft.Authorization/policyDefinitions/c25d9a16-bc35-4e15-a7e5-9db606bf9ed4",
  "type": "Microsoft.Authorization/policyDefinitions",
  "name": "c25d9a16-bc35-4e15-a7e5-9db606bf9ed4"
}