自定义Azure策略禁用指定标签存储账户的资源级Azure Defender for Storage遇阻
问题分析与修正方案
你的核心需求是对带指定标签的存储账户,在资源级别禁用Azure Defender for Storage,这个需求完全可行。当前策略失效的核心原因是混淆了订阅级(Microsoft.Security/pricings)与资源级(Microsoft.Security/defenderForStorageSettings)的Defender配置对象,同时存在语法和字段路径错误。
错误原因拆解
- 资源类型混淆:资源级别的Defender for Storage配置对应
Microsoft.Security/defenderForStorageSettings,而非订阅级的Microsoft.Security/pricings。 - 字段路径错误:存在条件引用的字段与目标资源类型不匹配,导致策略无法正确识别合规状态。
- 语法错误:第二个策略的JSON格式不完整,缺少必要的逗号分隔符。
- 逻辑反转:第二个策略的存在条件设置为
isEnabled: true,与“禁用Defender”的需求逻辑相反。
修正后的策略示例
1. AuditIfNotExists 策略(仅审计不合规资源)
标记带指定标签但未禁用资源级Defender for Storage的存储账户:
{ "policyRule": { "if": { "allOf": [ { "field": "type", "equals": "Microsoft.Storage/storageAccounts" }, { "field": "tags[dfs-enabled]", "equals": "off" } ] }, "then": { "effect": "auditIfNotExists", "details": { "type": "Microsoft.Security/defenderForStorageSettings", "name": "current", "existenceCondition": { "field": "Microsoft.Security/defenderForStorageSettings/isEnabled", "equals": false } } } } }
2. DeployIfNotExists 策略(自动修复不合规资源)
自动为带指定标签的存储账户禁用资源级Defender for Storage:
{ "policyRule": { "if": { "allOf": [ { "field": "type", "equals": "Microsoft.Storage/storageAccounts" }, { "field": "[concat('tags[', parameters('inclusionTagName'), ']')]", "in": "[parameters('inclusionTagValues')]" } ] }, "then": { "effect": "[parameters('effect')]", "details": { "type": "Microsoft.Security/defenderForStorageSettings", "name": "current", "roleDefinitionIds": [ "/providers/Microsoft.Authorization/roleDefinitions/fb1c8493-542b-48eb-b624-b4c8fea62acd" ], "existenceCondition": { "field": "Microsoft.Security/defenderForStorageSettings/isEnabled", "equals": false }, "deployment": { "properties": { "mode": "incremental", "parameters": { "storageAccountId": { "value": "[field('id')]" } }, "template": { "$schema": "https://schema.management.azure.com/schemas/2015-01-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "parameters": { "storageAccountId": { "type": "string" } }, "resources": [ { "type": "Microsoft.Security/defenderForStorageSettings", "apiVersion": "2022-12-01-preview", "scope": "[parameters('storageAccountId')]", "name": "current", "properties": { "isEnabled": false } } ] } } } } } }, "parameters": { "inclusionTagName": { "type": "string", "metadata": { "displayName": "标签名称", "description": "用于筛选存储账户的标签名称" } }, "inclusionTagValues": { "type": "array", "metadata": { "displayName": "标签值", "description": "符合条件的标签值列表" } }, "effect": { "type": "string", "allowedValues": [ "DeployIfNotExists", "Disabled" ], "defaultValue": "DeployIfNotExists", "metadata": { "displayName": "策略效果", "description": "控制策略执行的行为" } } } }
关键说明
- 资源固定标识:资源级Defender for Storage的配置对象名称固定为
current,类型必须为Microsoft.Security/defenderForStorageSettings。 - 权限要求:DeployIfNotExists策略需使用
Security Admin角色(ID:fb1c8493-542b-48eb-b624-b4c8fea62acd),该角色具备修改资源级Defender配置的权限。 - API版本:使用
2022-12-01-preview或更高版本的API,确保支持资源级Defender配置操作。
内容的提问来源于stack exchange,提问作者Ahmed El Ghilani
相关产品推荐
相关产品推荐

