通过PowerShell部署Azure CIS策略时遇InvalidTemplate错误排查
解决管理组级别部署Azure CIS合规策略时的InvalidTemplate错误
我帮你定位到问题所在了——你在管理组级别部署ARM模板时,误用了仅适用于订阅/资源组范围的subscription().id内置函数,这直接导致了InvalidTemplate错误里提到的'SUBSCRIPTION'元数据无效问题。
问题根源
当你在管理组(/providers/Microsoft.Management/managementGroups/xxx)范围部署资源时,部署上下文并没有关联的默认订阅,所以subscription().id这个函数无法返回有效内容。而你的策略规则里用这个函数来判断角色定义的可分配范围,Azure在解析模板时就会抛出元数据无效的错误。
修复方案
核心是移除策略规则中依赖subscription().id的判断逻辑,或者替换为适配管理组层级的范围检查。下面是修改后的完整ARM模板:
{ "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "parameters": { "effect": { "type": "string", "metadata": { "displayName": "Effect", "description": "Enable or disable the execution of the policy" }, "allowedValues": ["Audit", "Disabled"], "defaultValue": "Audit" } }, "variables": {}, "resources": [ { "name": "CIS1.23-EnsureNoCustomerOwnerRoles", "type": "Microsoft.Authorization/policyDefinitions", "apiVersion": "2018-03-01", "properties": { "policyType": "Custom", "displayName": "CIS 1.23 Custom Owner Roles should not exist (Not Scored)", "description": "This policy checks that Custom Roles with Owner privileges are removed", "mode": "all", "metadata": { "category": "Identity" }, "parameters": { "effect": { "type": "String", "metadata": { "displayName": "Effect", "description": "Enable or disable the execution of the policy" }, "allowedValues": ["Audit", "Disabled"], "defaultValue": "Audit" } }, "policyRule": { "if": { "allOf": [ { "field": "type", "equals": "Microsoft.Authorization/roleDefinitions" }, { "field": "Microsoft.Authorization/roleDefinitions/type", "equals": "CustomRole" }, { "anyOf": [ { "not": { "field": "Microsoft.Authorization/roleDefinitions/permissions[*].actions[*]", "notEquals": "*" } }, { "not": { "field": "Microsoft.Authorization/roleDefinitions/permissions.actions[*]", "notEquals": "*" } } ] }, { "anyOf": [ { "not": { "field": "Microsoft.Authorization/roleDefinitions/assignableScopes[*]", "in": ["/"] } }, { "not": { "field": "Microsoft.Authorization/roleDefinitions/assignableScopes[*]", "like": "/providers/Microsoft.Management/*" } } ] } ] }, "then": { "effect": "[parameters('effect')]" } } } } ] }
关键修改说明
- 移除了原模板中
[concat(subscription().id,'/')]和[subscription().id]这两个依赖订阅上下文的判断项,因为在管理组级别,这些单个订阅的范围判断没有实际意义,反而会导致模板解析失败。 - 如果你的业务需求需要排除特定订阅的可分配范围,可以手动指定订阅ID(例如
"/subscriptions/your-subscription-id"),但绝对不能使用subscription().id函数——管理组部署上下文没有默认订阅,无法解析这个函数。
内容的提问来源于stack exchange,提问作者user1197981
相关产品推荐
相关产品推荐

