分配Azure Policy时遇ResourceIdentityRequired错误,缺失什么配置?
问题:分配Azure DeployIfNotExists策略时提示需要托管标识错误
我正尝试分配一篇博客中的Azure Monitor Agent部署策略,执行以下PowerShell命令时触发错误:
New-AzPolicyAssignment -Name $policyNameToAssign -DisplayName $PolicyDisplayName -Scope $Subscription -PolicyDefinition $definition # Enter: DCRResourceID string
错误提示:
New-AzPolicyAssignment: ResourceIdentityRequired : The policy assignment 'PolicyName' request is invalid. Policy assignments must include a 'managed identity' when assigning 'DeployIfNotExists' policy definitions.
请问该策略分配操作中缺失了什么配置?
解决方案
核心缺失项:未指定托管标识(Managed Identity)。
DeployIfNotExists类型的策略需要依赖托管标识获取权限,才能在符合条件的资源上执行部署操作。修正后的命令:
添加-IdentityType SystemAssigned参数启用系统分配的托管标识,同时指定托管标识所在的Azure区域(必填项):New-AzPolicyAssignment -Name $policyNameToAssign -DisplayName $PolicyDisplayName -Scope $Subscription -PolicyDefinition $definition -IdentityType SystemAssigned -Location "EastUS" # 替换为你的目标区域后续注意事项:
策略分配完成后,需要为这个系统托管标识配置足够的权限(比如目标资源组的Contributor角色),确保它能完成Azure Monitor Agent相关资源的部署操作。
内容的提问来源于stack exchange,提问作者RSW
相关产品推荐
相关产品推荐

