You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure DeployIfNotExists策略无法创建资源组策略分配问题

问题:Azure订阅级DeployIfNotExists策略执行成功但未创建资源组级策略分配

我定义了如下资源白名单策略(直接分配到资源组时可正常工作):

{
  "properties": {
    "displayName": "Deny resource creation if not in whitelist",
    "policyType": "Custom",
    "mode": "Indexed",
    "description": "This policy denies the creation resources which are not allowed in the whitelist.",
    "policyRule": {
      "if": {
        "not": {
          "field": "type",
          "in": [
            "Microsoft.KeyVault/vaults",
            "Microsoft.Storage/storageAccounts"
          ]
        }
      },
      "then": {
        "effect": "Deny"
      }
    }
  },
  "id": "<POLICYDEFINITIONID>",
  "type": "Microsoft.Authorization/policyDefinitions",
  "name": "Deny_resource_creation_if_not_in_whitelist",
}

我还创建了一个订阅级的DeployIfNotExists策略,用于将上述白名单策略部署到名称以rg-*开头的资源组:

{
  "properties": {
    "displayName": "Deploy resource whitelist policy",
    "policyType": "Custom",
    "mode": "All",
    "description": "This policy assigns the resource whitelist policy to resource groups starting with rg-*.",
    "policyRule": {
      "if": {
        "allOf": [
          {
            "equals": "Microsoft.Resources/subscriptions/resourceGroups",
            "field": "type"
          },
          {
            "field": "name",
            "like": "rg-*"
          }
        ]
      },
      "then": {
        "details": {
          "deployment": {
            "properties": {
              "mode": "incremental",
              "template": {
                "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
                "contentVersion": "1.0.0.0",
                "resources": [
                  {
                    "apiVersion": "2022-06-01",
                    "name": "[guid('<POLICYDEFINITIONID>', resourceGroup().name)]",
                    "properties": {
                      "displayName": "Deny resource creation if not in whitelist",
                      "enforcementMode": "Default",
                      "policyDefinitionId": "<POLICYDEFINITIONID>"
                    },
                    "type": "Microsoft.Authorization/policyAssignments"
                  }
                ]
              }
            }
          },
          "evaluationDelay": "AfterProvisioning",
          "roleDefinitionIds": [
            "/providers/Microsoft.Authorization/roleDefinitions/8e3af657-a8ff-443c-a75c-2fe8c4bcb635"
          ],
          "type": "Microsoft.Authorization/policyAssignments"
        },
        "effect": "DeployIfNotExists"
      }
    }
  },
  "id": "",
  "type": "Microsoft.Authorization/policyDefinitions",
  "name": "Deploy_resource_whitelist_policy",
}

当前问题:该订阅级策略已完成评估,且显示DeployIfNotExists事件执行成功,但实际上并未创建策略分配。

补充信息:

  • 已成功从Azure门户手动部署该策略分配的ARM模板
  • 将该ARM模板替换为简单的存储账户模板时,可正常在资源组中创建存储账户

解决方案

1. 指定部署目标资源组

订阅级DeployIfNotExists策略默认会将模板部署到订阅范围,而策略分配需要针对具体资源组。需要在deployment配置中添加resourceGroup参数,明确指向匹配的目标资源组:

"deployment": {
  "properties": {
    "mode": "incremental",
    "resourceGroup": "[field('name')]", // 新增此行,指定部署到当前匹配的资源组
    "template": {
      // 原模板内容保持不变
    }
  }
}

2. 修正策略定义ID引用

确保模板中的<POLICYDEFINITIONID>替换为完整的ARM资源ID,格式为:
/subscriptions/{你的订阅ID}/providers/Microsoft.Authorization/policyDefinitions/Deny_resource_creation_if_not_in_whitelist

3. 优化策略分配名称(可选)

原模板中用guid生成名称可能导致存在性检查异常,可改为固定名称或结合资源组名称的规则:

"name": "[concat('Deny-Whitelist-', resourceGroup().name)]"

4. 添加存在性检查条件(可选)

为了让DeployIfNotExists更精准判断是否需要创建分配,可在details节点下添加existenceCondition:

"existenceCondition": {
  "allOf": [
    {
      "field": "Microsoft.Authorization/policyAssignments/policyDefinitionId",
      "equals": "<POLICYDEFINITIONID>"
    },
    {
      "field": "name",
      "equals": "[concat('Deny-Whitelist-', resourceGroup().name)]"
    }
  ]
}

5. 验证权限配置

虽然使用了8e3af657-a8ff-443c-a75c-2fe8c4bcb635(资源策略参与者角色),仍需确认策略分配的主体拥有在目标资源组创建策略分配的权限,可通过Azure门户的权限检查功能验证。

内容的提问来源于stack exchange,提问作者Chris

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 01:35:23