last sync: 2021-May-10 15:04:35 UTC

Azure Policy definition

[Preview]: Azure Defender for Resource Manager should be enabled

Name [Preview]: Azure Defender for Resource Manager should be enabled
Azure Portal
Id c3d20c29-b36d-48fe-808b-99a87530ad99
Version 1.0.0-preview
details on versioning
Category Security Center
Microsoft docs
Description Azure Defender for Resource Manager automatically monitors the resource management operations in your organization. Azure Defender detects threats and alerts you about suspicious activity. Learn more about the capabilities of Azure Defender for Resource Manager at https://aka.ms/defender-for-resource-manager . Enabling this Azure Defender plan results in charges. Learn about the pricing details per region on Security Center's pricing page: https://aka.ms/pricing-security-center .
Mode All
Type BuiltIn
Preview True
Deprecated FALSE
Effect Default: AuditIfNotExists
Allowed: (AuditIfNotExists, Disabled)
Used RBAC Role none
History
Date/Time (UTC ymd) (i) Change type Change detail
2021-03-09 14:37:41 add c3d20c29-b36d-48fe-808b-99a87530ad99
Used in Initiatives
Initiative DisplayName Initiative Id Initiative Category State
Azure Security Benchmark 1f3afdf9-d0c9-4c3d-847f-89da613e70a8 Security Center GA
JSON
{
  "properties": {
  "displayName": "[Preview]: Azure Defender for Resource Manager should be enabled",
    "policyType": "BuiltIn",
    "mode": "All",
    "description": "Azure Defender for Resource Manager automatically monitors the resource management operations in your organization. Azure Defender detects threats and alerts you about suspicious activity. Learn more about the capabilities of Azure Defender for Resource Manager at https://aka.ms/defender-for-resource-manager . Enabling this Azure Defender plan results in charges. Learn about the pricing details per region on Security Center's pricing page: https://aka.ms/pricing-security-center .",
    "metadata": {
      "version": "1.0.0-preview",
      "category": "Security Center",
      "preview": true
    },
    "parameters": {
      "effect": {
        "type": "String",
        "metadata": {
        "displayName": "[Preview]: Effect",
          "description": "Enable or disable the execution of the policy"
        },
        "allowedValues": [
          "AuditIfNotExists",
          "Disabled"
        ],
        "defaultValue": "AuditIfNotExists"
      }
    },
    "policyRule": {
      "if": {
        "field": "type",
        "equals": "Microsoft.Resources/subscriptions"
      },
      "then": {
      "effect": "[parameters('effect')]",
        "details": {
          "type": "Microsoft.Security/pricings",
          "name": "Arm",
          "existenceScope": "subscription",
          "existenceCondition": {
            "field": "Microsoft.Security/pricings/pricingTier",
            "equals": "Standard"
          }
        }
      }
    }
  },
  "id": "/providers/Microsoft.Authorization/policyDefinitions/c3d20c29-b36d-48fe-808b-99a87530ad99",
  "type": "Microsoft.Authorization/policyDefinitions",
  "name": "c3d20c29-b36d-48fe-808b-99a87530ad99"
}