last sync: 2020-Dec-03 15:30:53 UTC

Azure Policy definition

Public network access should be disabled for MySQL flexible servers

Name Public network access should be disabled for MySQL flexible servers
Azure Portal
Id c9299215-ae47-4f50-9c54-8a392f68a052
Version 1.0.0
details on versioning
Category SQL
Microsoft docs
Description Disabling the public network access property improves security by ensuring your Azure Database for MySQL flexible servers can only be accessed from a private endpoint. This configuration strictly disables access from any public address space outside of Azure IP range and denies all logins that match IP or virtual network-based firewall rules.
Mode Indexed
Type BuiltIn
Preview FALSE
Deprecated FALSE
Effect Default: Audit
Allowed: (Audit, Deny, Disabled)
Used RBAC Role none
History
Date/Time (UTC ymd) (i) Change type Change detail
2020-10-20 13:29:33 add c9299215-ae47-4f50-9c54-8a392f68a052
Used in Initiatives none
Json
{
  "properties": {
    "displayName": "Public network access should be disabled for MySQL flexible servers",
    "policyType": "BuiltIn",
    "mode": "Indexed",
    "description": "Disabling the public network access property improves security by ensuring your Azure Database for MySQL flexible servers can only be accessed from a private endpoint. This configuration strictly disables access from any public address space outside of Azure IP range and denies all logins that match IP or virtual network-based firewall rules.",
    "metadata": {
      "version": "1.0.0",
      "category": "SQL"
    },
    "parameters": {
      "effect": {
        "type": "String",
        "metadata": {
          "displayName": "Effect",
          "description": "Enable or disable the execution of the policy"
        },
        "allowedValues": [
          "Audit",
          "Deny",
          "Disabled"
        ],
        "defaultValue": "Audit"
      }
    },
    "policyRule": {
      "if": {
        "allOf": [
          {
            "field": "type",
            "equals": "Microsoft.DBforMySQL/flexibleServers"
          },
          {
            "field": "Microsoft.DBforMySQL/flexibleServers/publicNetworkAccess",
            "notEquals": "Disabled"
          }
        ]
      },
      "then": {
      "effect": "[parameters('effect')]"
      }
    }
  },
  "id": "/providers/Microsoft.Authorization/policyDefinitions/c9299215-ae47-4f50-9c54-8a392f68a052",
  "type": "Microsoft.Authorization/policyDefinitions",
  "name": "c9299215-ae47-4f50-9c54-8a392f68a052"
}