Get the App
SLTechnology News&Howtos  ›  Servers  › 

Use Azure Policy to restrict all ASM resources

Shulou Source: shulou.com Published: 2022-06-02 20:46:01 10月04日 Update

Azure policies are an excellent tool for managing standard policies in Azure subscriptions. Can be used to create, assign, and manage policies. These policies will enforce different rules and effects across resources so that these resources comply with corporate standards and service-level agreements. Azure Policy meets this requirement by evaluating whether the resource conforms to the specified policy. For example, you can set a policy to allow only virtual machines of a specific SKU size in the environment. When this strategy is implemented, the compliance of new and existing resources is evaluated. By using the correct policy type, you can ensure the compliance of existing resources.

Let's take a look at how to use a very simple policy definition to restrict all Azure Service Manager (ASM, aka Classic) resources at the subscription level.

Define the JSON file:

{

"if": {

"field": "type"

"like": "Microsoft.Classic*"

}

"then": {

"effect": "Deny"

}

}

Apply policies:

Define policies:

$definition = New-AzureRmPolicyDefinition-Name "restrict-all-asm-resources"-DisplayName "Restrict All ASM Resources"-description "This policy enables you to restrict ALL Azure Service Manager (ASM, aka Classic) resources."-Policy'.\ Restrict-ALL-ASM-Resources.json'-Mode All

Apply policies:

$assignment = New-AzureRMPolicyAssignment-Name 'Restrict All ASM Resources'-PolicyDefinition $definition-Scope "/ subscriptions/$subscriptionId"

After the policy was applied, when I tried to create a classic VNet, I failed the validation:

Tags: Policies resources applications standards compliance levels management subscription evaluation restrictions different excellent company alias size tools effects files environment type Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Apple Microsoft vpn macOS OPPO Reno