last sync: 2022-Sep-30 16:34:23 UTC

Azure Policy definition

Stream Analytics job should connect to trusted inputs and outputs

Name Stream Analytics job should connect to trusted inputs and outputs
Azure Portal
Id fe8684d6-3c5b-45c0-a08b-fa92653c2e1c
Version 1.1.0
details on versioning
Category Stream Analytics
Microsoft docs
Description Ensure that Stream Analytics jobs do not have arbitrary Input or Output connections that are not defined in the allow-list. This checks that Stream Analytics jobs don't exfiltrate data by connecting to arbitrary sinks outside your organization.
Mode All
Type BuiltIn
Preview FALSE
Deprecated FALSE
Effect Default: Audit
Allowed: (Deny, Disabled, Audit)
Used RBAC Role none
Rule Aliases IF (21)
Alias Namespace ResourceType DefaultPath Modifiable
Microsoft.StreamAnalytics/streamingjobs/functions[*].binding.Microsoft-MachineLearning-WebService.endpoint Microsoft.StreamAnalytics streamingjobs properties.functions[*].properties.properties.binding.properties.endpoint false
Microsoft.StreamAnalytics/streamingjobs/functions[*].type Microsoft.StreamAnalytics streamingjobs properties.functions[*].type false
Microsoft.StreamAnalytics/streamingjobs/inputs/Reference.datasource.Microsoft-Sql-Server-Database.server Microsoft.StreamAnalytics streamingjobs/inputs properties.datasource.properties.server false
Microsoft.StreamAnalytics/streamingjobs/inputs/Reference.datasource.Microsoft-Storage-Blob.storageAccounts[*] Microsoft.StreamAnalytics streamingjobs/inputs properties.datasource.properties.storageAccounts[*] false
Microsoft.StreamAnalytics/streamingjobs/inputs/Reference.datasource.Microsoft-Storage-Blob.storageAccounts[*].accountName Microsoft.StreamAnalytics streamingjobs/inputs properties.datasource.properties.storageAccounts[*].accountName false
Microsoft.StreamAnalytics/streamingjobs/inputs/Reference.datasource.type Microsoft.StreamAnalytics streamingjobs/inputs properties.datasource.type false
Microsoft.StreamAnalytics/streamingjobs/inputs/Stream.datasource.Microsoft-Devices-IotHubs.iotHubNamespace Microsoft.StreamAnalytics streamingjobs/inputs properties.datasource.properties.iotHubNamespace false
Microsoft.StreamAnalytics/streamingjobs/inputs/Stream.datasource.Microsoft-ServiceBus-EventHub.serviceBusNamespace Microsoft.StreamAnalytics streamingjobs/inputs properties.datasource.properties.serviceBusNamespace false
Microsoft.StreamAnalytics/streamingjobs/inputs/Stream.datasource.Microsoft-Storage-Blob.storageAccounts[*] Microsoft.StreamAnalytics streamingjobs/inputs properties.datasource.properties.storageAccounts[*] false
Microsoft.StreamAnalytics/streamingjobs/inputs/Stream.datasource.Microsoft-Storage-Blob.storageAccounts[*].accountName Microsoft.StreamAnalytics streamingjobs/inputs properties.datasource.properties.storageAccounts[*].accountName false
Microsoft.StreamAnalytics/streamingjobs/inputs/Stream.datasource.type Microsoft.StreamAnalytics streamingjobs/inputs properties.datasource.type false
Microsoft.StreamAnalytics/streamingjobs/jobStorageAccount Microsoft.StreamAnalytics streamingjobs properties.jobStorageAccount false
Microsoft.StreamAnalytics/streamingjobs/jobStorageAccount.accountName Microsoft.StreamAnalytics streamingjobs properties.jobStorageAccount.accountName false
Microsoft.StreamAnalytics/streamingjobs/outputs/datasource.Microsoft-AzureFunction.functionAppName Microsoft.StreamAnalytics streamingjobs/outputs properties.datasource.properties.functionAppName false
Microsoft.StreamAnalytics/streamingjobs/outputs/datasource.Microsoft-ServiceBus-EventHub.serviceBusNamespace Microsoft.StreamAnalytics streamingjobs/outputs properties.datasource.properties.serviceBusNamespace false
Microsoft.StreamAnalytics/streamingjobs/outputs/datasource.Microsoft-Sql-Server-Database.server Microsoft.StreamAnalytics streamingjobs/outputs properties.datasource.properties.server false
Microsoft.StreamAnalytics/streamingjobs/outputs/datasource.Microsoft-Storage-Blob.storageAccounts[*] Microsoft.StreamAnalytics streamingjobs/outputs properties.datasource.properties.storageAccounts[*] false
Microsoft.StreamAnalytics/streamingjobs/outputs/datasource.Microsoft-Storage-Blob.storageAccounts[*].accountName Microsoft.StreamAnalytics streamingjobs/outputs properties.datasource.properties.storageAccounts[*].accountName false
Microsoft.StreamAnalytics/streamingjobs/outputs/datasource.Microsoft-Storage-DocumentDB.accountId Microsoft.StreamAnalytics streamingjobs/outputs properties.datasource.properties.accountId false
Microsoft.StreamAnalytics/streamingjobs/outputs/datasource.Microsoft-Storage-Table.accountName Microsoft.StreamAnalytics streamingjobs/outputs properties.datasource.properties.accountName false
Microsoft.StreamAnalytics/streamingjobs/outputs/datasource.type Microsoft.StreamAnalytics streamingjobs/outputs properties.datasource.type false
Rule ResourceTypes IF (2)
Microsoft.Devices/IotHubs
Microsoft.StreamAnalytics/streamingjobs
History
Date/Time (UTC ymd) (i) Change type Change detail
2022-02-18 17:44:00 change Minor (1.0.0 > 1.1.0)
2021-11-12 16:23:07 add fe8684d6-3c5b-45c0-a08b-fa92653c2e1c
Used in Initiatives none
JSON Changes

JSON