Policy DisplayName |
Policy Id |
Category |
Version |
Versioning |
Effect |
Roles# |
Roles |
State |
policy in AzUSGov |
Add system-assigned managed identity to enable Guest Configuration assignments on virtual machines with no identities |
3cf2ab00-13f1-4d0c-8971-2ac904541a7e |
Guest Configuration |
4.1.0 |
2x 4.1.0, 4.0.0 |
Fixed modify |
1 |
Contributor |
GA |
true |
Add system-assigned managed identity to enable Guest Configuration assignments on VMs with a user-assigned identity |
497dff13-db2a-4c0f-8603-28fa3b331ab6 |
Guest Configuration |
4.1.0 |
2x 4.1.0, 4.0.0 |
Fixed modify |
1 |
Contributor |
GA |
true |
App Service Environment should have TLS 1.0 and 1.1 disabled |
d6545c6b-dd9d-4265-91e6-0b451e2f1c50 |
App Service |
2.0.1 |
1x 2.0.1 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
unknown |
Azure SQL Database should be running TLS version 1.2 or newer |
32e6bbec-16b6-44c2-be37-c5b672d103cf |
SQL |
2.0.0 |
1x 2.0.0 |
Default Audit Allowed Audit, Disabled, Deny |
0 |
|
GA |
true |
Azure Synapse Analytics dedicated SQL pools should enable encryption |
cfaf0007-99c7-4b01-b36b-4048872ac978 |
Synapse |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
unknown |
Deploy the Linux Guest Configuration extension to enable Guest Configuration assignments on Linux VMs |
331e8ea8-378a-410f-a2e5-ae22f38bb0da |
Guest Configuration |
3.1.0 |
2x 3.1.0, 3.0.0 |
Fixed deployIfNotExists |
1 |
Contributor |
GA |
true |
Deploy the Windows Guest Configuration extension to enable Guest Configuration assignments on Windows VMs |
385f5831-96d4-41db-9a3c-cd3af78aaae6 |
Guest Configuration |
1.2.0 |
1x 1.2.0 |
Fixed deployIfNotExists |
1 |
Contributor |
GA |
true |
Disk encryption should be enabled on Azure Data Explorer |
f4b53539-8df9-40e4-86c6-6b607703bd4e |
Azure Data Explorer |
2.0.0 |
1x 2.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Linux virtual machines should have Azure Monitor Agent installed |
1afdc4b6-581a-45fb-b630-f1e6051e3e7a |
Monitoring |
3.4.0 |
4x 3.4.0, 3.3.0, 3.2.0, 3.1.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
unknown |
SQL Managed Instance should have the minimal TLS version of 1.2 |
a8793640-60f7-487c-b5c3-1d37215905c4 |
SQL |
1.0.1 |
1x 1.0.1 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
Storage accounts should have the specified minimum TLS version |
fe83a0eb-a853-422d-aac2-1bffd182c5d0 |
Storage |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Vulnerability assessment should be enabled on your Synapse workspaces |
0049a6b3-a662-4f3e-8635-39cf44ace45a |
Synapse |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Web Application Firewall (WAF) should use the specified mode for Application Gateway |
12430be1-6cc8-4527-a9a8-e3d38f250096 |
Network |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Windows machines should configure Windows Defender to update protection signatures within one day |
d96163de-dbe0-45ac-b803-0e9ca0f5764e |
Guest Configuration |
1.0.1 |
2x 1.0.1, 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
unknown |
Windows machines should enable Windows Defender Real-time protection |
b3248a42-b1c1-41a4-87bc-8bad3d845589 |
Guest Configuration |
1.0.1 |
2x 1.0.1, 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
unknown |
Windows virtual machines should have Azure Monitor Agent installed |
c02729e5-e5e7-4458-97fa-2b5ad0661f28 |
Monitoring |
3.2.0 |
2x 3.2.0, 3.1.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
unknown |