You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

自定义Azure策略禁用指定标签存储账户的资源级Azure Defender for Storage遇阻

问题分析与修正方案

你的核心需求是对带指定标签的存储账户,在资源级别禁用Azure Defender for Storage,这个需求完全可行。当前策略失效的核心原因是混淆了订阅级(Microsoft.Security/pricings)与资源级(Microsoft.Security/defenderForStorageSettings)的Defender配置对象,同时存在语法和字段路径错误。

错误原因拆解

  • 资源类型混淆:资源级别的Defender for Storage配置对应Microsoft.Security/defenderForStorageSettings,而非订阅级的Microsoft.Security/pricings。
  • 字段路径错误:存在条件引用的字段与目标资源类型不匹配,导致策略无法正确识别合规状态。
  • 语法错误:第二个策略的JSON格式不完整,缺少必要的逗号分隔符。
  • 逻辑反转:第二个策略的存在条件设置为isEnabled: true,与“禁用Defender”的需求逻辑相反。

修正后的策略示例

1. AuditIfNotExists 策略(仅审计不合规资源)

标记带指定标签但未禁用资源级Defender for Storage的存储账户:

{
  "policyRule": {
    "if": {
      "allOf": [
        {
          "field": "type",
          "equals": "Microsoft.Storage/storageAccounts"
        },
        {
          "field": "tags[dfs-enabled]",
          "equals": "off"
        }
      ]
    },
    "then": {
      "effect": "auditIfNotExists",
      "details": {
        "type": "Microsoft.Security/defenderForStorageSettings",
        "name": "current",
        "existenceCondition": {
          "field": "Microsoft.Security/defenderForStorageSettings/isEnabled",
          "equals": false
        }
      }
    }
  }
}

2. DeployIfNotExists 策略(自动修复不合规资源)

自动为带指定标签的存储账户禁用资源级Defender for Storage:

{
  "policyRule": {
    "if": {
      "allOf": [
        {
          "field": "type",
          "equals": "Microsoft.Storage/storageAccounts"
        },
        {
          "field": "[concat('tags[', parameters('inclusionTagName'), ']')]",
          "in": "[parameters('inclusionTagValues')]"
        }
      ]
    },
    "then": {
      "effect": "[parameters('effect')]",
      "details": {
        "type": "Microsoft.Security/defenderForStorageSettings",
        "name": "current",
        "roleDefinitionIds": [
          "/providers/Microsoft.Authorization/roleDefinitions/fb1c8493-542b-48eb-b624-b4c8fea62acd"
        ],
        "existenceCondition": {
          "field": "Microsoft.Security/defenderForStorageSettings/isEnabled",
          "equals": false
        },
        "deployment": {
          "properties": {
            "mode": "incremental",
            "parameters": {
              "storageAccountId": {
                "value": "[field('id')]"
              }
            },
            "template": {
              "$schema": "https://schema.management.azure.com/schemas/2015-01-01/deploymentTemplate.json#",
              "contentVersion": "1.0.0.0",
              "parameters": {
                "storageAccountId": {
                  "type": "string"
                }
              },
              "resources": [
                {
                  "type": "Microsoft.Security/defenderForStorageSettings",
                  "apiVersion": "2022-12-01-preview",
                  "scope": "[parameters('storageAccountId')]",
                  "name": "current",
                  "properties": {
                    "isEnabled": false
                  }
                }
              ]
            }
          }
        }
      }
    }
  },
  "parameters": {
    "inclusionTagName": {
      "type": "string",
      "metadata": {
        "displayName": "标签名称",
        "description": "用于筛选存储账户的标签名称"
      }
    },
    "inclusionTagValues": {
      "type": "array",
      "metadata": {
        "displayName": "标签值",
        "description": "符合条件的标签值列表"
      }
    },
    "effect": {
      "type": "string",
      "allowedValues": [
        "DeployIfNotExists",
        "Disabled"
      ],
      "defaultValue": "DeployIfNotExists",
      "metadata": {
        "displayName": "策略效果",
        "description": "控制策略执行的行为"
      }
    }
  }
}

关键说明

  • 资源固定标识:资源级Defender for Storage的配置对象名称固定为current,类型必须为Microsoft.Security/defenderForStorageSettings。
  • 权限要求:DeployIfNotExists策略需使用Security Admin角色(ID:fb1c8493-542b-48eb-b624-b4c8fea62acd),该角色具备修改资源级Defender配置的权限。
  • API版本:使用2022-12-01-preview或更高版本的API,确保支持资源级Defender配置操作。

内容的提问来源于stack exchange,提问作者Ahmed El Ghilani

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 05:35:11