Azure Policy来宾配置:查找Windows防火墙已停用的虚拟机
检测Windows防火墙已停用的Azure虚拟机
要检测Azure中Windows防火墙已停用的虚拟机,需借助Azure Policy Guest Configuration(用于检查VM内部配置状态),以下是完整的策略实现方案:
核心逻辑说明
Windows防火墙的状态可通过PowerShell命令Get-NetFirewallProfile获取,Guest Configuration会在VM内部执行检测脚本,将结果上报至Azure Policy完成合规性评估。
完整Policy定义
{ "properties": { "displayName": "检测Windows虚拟机的Windows防火墙是否已启用", "policyType": "Custom", "mode": "Indexed", "description": "确保Windows虚拟机上的Windows防火墙(域、专用、公用三个配置文件)处于启用状态", "metadata": { "version": "1.0.0", "category": "Guest Configuration" }, "parameters": { "effect": { "type": "String", "metadata": { "displayName": "执行效果", "description": "检测到不合规资源时的执行动作" }, "allowedValues": [ "Audit", "Disabled" ], "defaultValue": "Audit" } }, "policyRule": { "if": { "allOf": [ { "field": "type", "equals": "Microsoft.Compute/virtualMachines" }, { "field": "Microsoft.Compute/imagePublisher", "equals": "MicrosoftWindowsServer" }, { "field": "Microsoft.Compute/imageOffer", "equals": "WindowsServer" } ] }, "then": { "effect": "[parameters('effect')]", "details": { "type": "Microsoft.GuestConfiguration/guestConfigurationAssignments", "name": "WindowsFirewallEnabled", "existenceCondition": { "field": "Microsoft.GuestConfiguration/guestConfigurationAssignments/complianceStatus", "equals": "Compliant" } } } } } }
配套Guest Configuration检测脚本
上述Policy依赖的Guest Configuration配置包,需包含以下PowerShell检测逻辑:
$firewallProfiles = Get-NetFirewallProfile -All $disabledProfiles = $firewallProfiles | Where-Object { $_.Enabled -eq $false } if ($disabledProfiles) { Write-Output "已检测到停用的Windows防火墙配置文件: $($disabledProfiles.Name -join ', ')" exit 1 } else { Write-Output "所有Windows防火墙配置文件均已启用" exit 0 }
部署注意事项
- 目标VM需已安装Guest Configuration代理(Windows Server镜像默认预装,缺失可通过Azure VM扩展手动安装)
- 若需覆盖非Microsoft官方Windows镜像,可调整
policyRule中的imagePublisher和imageOffer字段匹配对应镜像信息 - 默认执行效果为
Audit,仅记录不合规资源;如需自动修正,可搭配DeployIfNotExists类型Policy实现防火墙自动启用
内容的提问来源于stack exchange,提问作者Phil
相关产品推荐
相关产品推荐

