通过策略在存储账户级别激活Defender for Cloud失败求助
存储账户级别激活Defender for Cloud的自定义策略问题排查
我参照官方文档编写了自定义策略,意图在存储账户级别激活Defender for Cloud,但该策略无法正常工作,请求排查并使其生效。
原策略定义
{ "properties": { "displayName": "DFC", "policyType": "Custom", "mode": "Indexed", "version": "1.0.0", "parameters": { "Effect": { "type": "String", "metadata": { "displayName": "Policy Effect", "description": "Enable or disable the execution of the policy" }, "allowedValues": [ "Audit", "DeployIfNotExists", "Disabled" ], "defaultValue": "DeployIfNotExists" } }, "policyRule": { "if": { "allOf": [ { "field": "type", "equals": "Microsoft.Storage/storageAccounts" } ] }, "then": { "effect": "[parameters('effect')]", "details": { "type": "Microsoft.Security/DefenderForStorageSettings", "roleDefinitionIds": [ "/providers/Microsoft.Authorization/roleDefinitions/fb1c8493-542b-48eb-b624-b4c8fea62acd" ], "deployment": { "properties": { "mode": "incremental", "template": { "$schema": "http://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "resources": [ { "type": "Microsoft.Security/DefenderForStorageSettings", "apiVersion": "2022-12-01-preview", "name": "[concat(parameters('storageAccountName'), '/current')]", "properties": { "isEnabled": true, "malwareScanning": { "onUpload": { "isEnabled": true, "capGBPerMonth": 5000 } }, "sensitiveDataDiscovery": { "isEnabled": true }, "overrideSubscriptionLevelSettings": true } } ] }, "parameters": { "storageAccountName": { "value": "[field('name')]" } } } } } } }, "versions": [ "1.0.0" ] } } }
问题排查与修复
原策略存在以下关键问题,修复后即可正常工作:
1. 参数引用大小写不匹配
Azure策略对参数名称大小写敏感,原策略中effect参数引用写成[parameters('effect')],但定义的参数名称是Effect,需改为[parameters('Effect')]。
2. DefenderForStorageSettings资源名称格式错误
Microsoft.Security/DefenderForStorageSettings是存储账户的子资源,部署作用域为存储账户时,资源名称固定为current,不需要拼接存储账户名。原策略中的name字段应改为"current"。
3. 缺少存在性检查条件
DeployIfNotExists策略需要添加existenceCondition判断资源是否已满足要求,避免重复部署或误触发。需在details中添加:
"existenceCondition": { "field": "Microsoft.Security/DefenderForStorageSettings/isEnabled", "equals": true }
4. 多余的versions字段
自定义策略的properties中不需要versions数组,该字段为内置策略专属,需删除。
修复后的完整策略
{ "properties": { "displayName": "DFC - Enable Defender for Storage on Storage Accounts", "policyType": "Custom", "mode": "Indexed", "version": "1.0.0", "parameters": { "Effect": { "type": "String", "metadata": { "displayName": "Policy Effect", "description": "Enable or disable the execution of the policy" }, "allowedValues": [ "Audit", "DeployIfNotExists", "Disabled" ], "defaultValue": "DeployIfNotExists" } }, "policyRule": { "if": { "allOf": [ { "field": "type", "equals": "Microsoft.Storage/storageAccounts" } ] }, "then": { "effect": "[parameters('Effect')]", "details": { "type": "Microsoft.Security/DefenderForStorageSettings", "existenceCondition": { "field": "Microsoft.Security/DefenderForStorageSettings/isEnabled", "equals": true }, "roleDefinitionIds": [ "/providers/Microsoft.Authorization/roleDefinitions/fb1c8493-542b-48eb-b624-b4c8fea62acd" ], "deployment": { "properties": { "mode": "incremental", "template": { "$schema": "http://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "resources": [ { "type": "Microsoft.Security/DefenderForStorageSettings", "apiVersion": "2022-12-01-preview", "name": "current", "properties": { "isEnabled": true, "malwareScanning": { "onUpload": { "isEnabled": true, "capGBPerMonth": 5000 } }, "sensitiveDataDiscovery": { "isEnabled": true }, "overrideSubscriptionLevelSettings": true } } ] } } } } } } } }
额外说明
- 修复后的策略会自动为未启用Defender for Storage的存储账户部署配置,已启用的账户不会重复操作。
- 确保分配策略的主体拥有
Security Admin角色(对应roleDefinitionIds中的ID),否则部署会因权限不足失败。
内容的提问来源于stack exchange,提问作者Rousseto
相关产品推荐
相关产品推荐

