You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过策略在存储账户级别激活Defender for Cloud失败求助

存储账户级别激活Defender for Cloud的自定义策略问题排查

我参照官方文档编写了自定义策略,意图在存储账户级别激活Defender for Cloud,但该策略无法正常工作,请求排查并使其生效。

原策略定义

{
  "properties": {
    "displayName": "DFC",
    "policyType": "Custom",
    "mode": "Indexed",
    "version": "1.0.0",
    "parameters": {
      "Effect": {
        "type": "String",
        "metadata": {
          "displayName": "Policy Effect",
          "description": "Enable or disable the execution of the policy"
        },
        "allowedValues": [
          "Audit",
          "DeployIfNotExists",
          "Disabled"
        ],
        "defaultValue": "DeployIfNotExists"
      }
    },
    "policyRule": {
      "if": {
        "allOf": [
          {
            "field": "type",
            "equals": "Microsoft.Storage/storageAccounts"
          }
        ]
      },
      "then": {
        "effect": "[parameters('effect')]",
        "details": {
          "type": "Microsoft.Security/DefenderForStorageSettings",
          "roleDefinitionIds": [
            "/providers/Microsoft.Authorization/roleDefinitions/fb1c8493-542b-48eb-b624-b4c8fea62acd"
          ],
          "deployment": {
            "properties": {
              "mode": "incremental",
              "template": {
                "$schema": "http://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
                "contentVersion": "1.0.0.0",
                "resources": [
                  {
                    "type": "Microsoft.Security/DefenderForStorageSettings",
                    "apiVersion": "2022-12-01-preview",
                    "name": "[concat(parameters('storageAccountName'), '/current')]",
                    "properties": {
                      "isEnabled": true,
                      "malwareScanning": {
                        "onUpload": {
                          "isEnabled": true,
                          "capGBPerMonth": 5000
                        }
                      },
                      "sensitiveDataDiscovery": {
                        "isEnabled": true
                      },
                      "overrideSubscriptionLevelSettings": true
                    }
                  }
                ]
              },
              "parameters": {
                "storageAccountName": {
                  "value": "[field('name')]"
                }
              }
            }
          }
        }
      }
    },
    "versions": [
      "1.0.0"
    ]
  }
  }
}

问题排查与修复

原策略存在以下关键问题,修复后即可正常工作:

1. 参数引用大小写不匹配

Azure策略对参数名称大小写敏感,原策略中effect参数引用写成[parameters('effect')],但定义的参数名称是Effect,需改为[parameters('Effect')]。

2. DefenderForStorageSettings资源名称格式错误

Microsoft.Security/DefenderForStorageSettings是存储账户的子资源,部署作用域为存储账户时,资源名称固定为current,不需要拼接存储账户名。原策略中的name字段应改为"current"。

3. 缺少存在性检查条件

DeployIfNotExists策略需要添加existenceCondition判断资源是否已满足要求,避免重复部署或误触发。需在details中添加:

"existenceCondition": {
  "field": "Microsoft.Security/DefenderForStorageSettings/isEnabled",
  "equals": true
}

4. 多余的versions字段

自定义策略的properties中不需要versions数组,该字段为内置策略专属,需删除。

修复后的完整策略

{
  "properties": {
    "displayName": "DFC - Enable Defender for Storage on Storage Accounts",
    "policyType": "Custom",
    "mode": "Indexed",
    "version": "1.0.0",
    "parameters": {
      "Effect": {
        "type": "String",
        "metadata": {
          "displayName": "Policy Effect",
          "description": "Enable or disable the execution of the policy"
        },
        "allowedValues": [
          "Audit",
          "DeployIfNotExists",
          "Disabled"
        ],
        "defaultValue": "DeployIfNotExists"
      }
    },
    "policyRule": {
      "if": {
        "allOf": [
          {
            "field": "type",
            "equals": "Microsoft.Storage/storageAccounts"
          }
        ]
      },
      "then": {
        "effect": "[parameters('Effect')]",
        "details": {
          "type": "Microsoft.Security/DefenderForStorageSettings",
          "existenceCondition": {
            "field": "Microsoft.Security/DefenderForStorageSettings/isEnabled",
            "equals": true
          },
          "roleDefinitionIds": [
            "/providers/Microsoft.Authorization/roleDefinitions/fb1c8493-542b-48eb-b624-b4c8fea62acd"
          ],
          "deployment": {
            "properties": {
              "mode": "incremental",
              "template": {
                "$schema": "http://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
                "contentVersion": "1.0.0.0",
                "resources": [
                  {
                    "type": "Microsoft.Security/DefenderForStorageSettings",
                    "apiVersion": "2022-12-01-preview",
                    "name": "current",
                    "properties": {
                      "isEnabled": true,
                      "malwareScanning": {
                        "onUpload": {
                          "isEnabled": true,
                          "capGBPerMonth": 5000
                        }
                      },
                      "sensitiveDataDiscovery": {
                        "isEnabled": true
                      },
                      "overrideSubscriptionLevelSettings": true
                    }
                  }
                ]
              }
            }
          }
        }
      }
    }
  }
}

额外说明

  • 修复后的策略会自动为未启用Defender for Storage的存储账户部署配置,已启用的账户不会重复操作。
  • 确保分配策略的主体拥有Security Admin角色(对应roleDefinitionIds中的ID),否则部署会因权限不足失败。

内容的提问来源于stack exchange,提问作者Rousseto

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 12:10:09