You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Policy来宾配置:查找Windows防火墙已停用的虚拟机

检测Windows防火墙已停用的Azure虚拟机

要检测Azure中Windows防火墙已停用的虚拟机,需借助Azure Policy Guest Configuration(用于检查VM内部配置状态),以下是完整的策略实现方案:

核心逻辑说明

Windows防火墙的状态可通过PowerShell命令Get-NetFirewallProfile获取,Guest Configuration会在VM内部执行检测脚本,将结果上报至Azure Policy完成合规性评估。

完整Policy定义

{
  "properties": {
    "displayName": "检测Windows虚拟机的Windows防火墙是否已启用",
    "policyType": "Custom",
    "mode": "Indexed",
    "description": "确保Windows虚拟机上的Windows防火墙(域、专用、公用三个配置文件)处于启用状态",
    "metadata": {
      "version": "1.0.0",
      "category": "Guest Configuration"
    },
    "parameters": {
      "effect": {
        "type": "String",
        "metadata": {
          "displayName": "执行效果",
          "description": "检测到不合规资源时的执行动作"
        },
        "allowedValues": [
          "Audit",
          "Disabled"
        ],
        "defaultValue": "Audit"
      }
    },
    "policyRule": {
      "if": {
        "allOf": [
          {
            "field": "type",
            "equals": "Microsoft.Compute/virtualMachines"
          },
          {
            "field": "Microsoft.Compute/imagePublisher",
            "equals": "MicrosoftWindowsServer"
          },
          {
            "field": "Microsoft.Compute/imageOffer",
            "equals": "WindowsServer"
          }
        ]
      },
      "then": {
        "effect": "[parameters('effect')]",
        "details": {
          "type": "Microsoft.GuestConfiguration/guestConfigurationAssignments",
          "name": "WindowsFirewallEnabled",
          "existenceCondition": {
            "field": "Microsoft.GuestConfiguration/guestConfigurationAssignments/complianceStatus",
            "equals": "Compliant"
          }
        }
      }
    }
  }
}

配套Guest Configuration检测脚本

上述Policy依赖的Guest Configuration配置包,需包含以下PowerShell检测逻辑:

$firewallProfiles = Get-NetFirewallProfile -All
$disabledProfiles = $firewallProfiles | Where-Object { $_.Enabled -eq $false }

if ($disabledProfiles) {
    Write-Output "已检测到停用的Windows防火墙配置文件: $($disabledProfiles.Name -join ', ')"
    exit 1
} else {
    Write-Output "所有Windows防火墙配置文件均已启用"
    exit 0
}

部署注意事项

  • 目标VM需已安装Guest Configuration代理(Windows Server镜像默认预装,缺失可通过Azure VM扩展手动安装)
  • 若需覆盖非Microsoft官方Windows镜像,可调整policyRule中的imagePublisher和imageOffer字段匹配对应镜像信息
  • 默认执行效果为Audit,仅记录不合规资源;如需自动修正,可搭配DeployIfNotExists类型Policy实现防火墙自动启用

内容的提问来源于stack exchange,提问作者Phil

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.21 18:06:17