last sync: 2022-Jan-21 21:53:22 UTC

Community Policy definition

Key vault - Firewall Settings DENY v1

Name Key vault - Firewall Settings DENY v1
Community-Policy GitHub
Id key-vault-firewall-settings-v1
Version 1.0.0
details on versioning
Category Key Vault
Microsoft docs
Description This Azure Policy denies the deployment of an Azure Key Vault when the 'Allow access from' setting is not set to 'Private endpoints and selected networks' or when the Firewall does contain any IP addresses outside of the approved ones.
Mode All
Type Custom Community
Effect Fixed: Deny
Used RBAC Role none
Rule Aliases IF (2)
Alias Namespace ResourceType DefaultPath Modifiable
Microsoft.KeyVault/vaults/networkAcls.defaultAction Microsoft.KeyVault vaults properties.networkAcls.defaultAction true
Microsoft.KeyVault/vaults/networkAcls.ipRules[*].value Microsoft.KeyVault vaults properties.networkAcls.ipRules[*].value true
Rule ResourceTypes IF (1)
Microsoft.KeyVault/vaults
JSON