You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过PowerShell部署Azure CIS策略时遇InvalidTemplate错误排查

解决管理组级别部署Azure CIS合规策略时的InvalidTemplate错误

我帮你定位到问题所在了——你在管理组级别部署ARM模板时,误用了仅适用于订阅/资源组范围的subscription().id内置函数,这直接导致了InvalidTemplate错误里提到的'SUBSCRIPTION'元数据无效问题。

问题根源

当你在管理组(/providers/Microsoft.Management/managementGroups/xxx)范围部署资源时,部署上下文并没有关联的默认订阅,所以subscription().id这个函数无法返回有效内容。而你的策略规则里用这个函数来判断角色定义的可分配范围,Azure在解析模板时就会抛出元数据无效的错误。

修复方案

核心是移除策略规则中依赖subscription().id的判断逻辑,或者替换为适配管理组层级的范围检查。下面是修改后的完整ARM模板:

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "effect": {
      "type": "string",
      "metadata": {
        "displayName": "Effect",
        "description": "Enable or disable the execution of the policy"
      },
      "allowedValues": ["Audit", "Disabled"],
      "defaultValue": "Audit"
    }
  },
  "variables": {},
  "resources": [
    {
      "name": "CIS1.23-EnsureNoCustomerOwnerRoles",
      "type": "Microsoft.Authorization/policyDefinitions",
      "apiVersion": "2018-03-01",
      "properties": {
        "policyType": "Custom",
        "displayName": "CIS 1.23 Custom Owner Roles should not exist (Not Scored)",
        "description": "This policy checks that Custom Roles with Owner privileges are removed",
        "mode": "all",
        "metadata": {
          "category": "Identity"
        },
        "parameters": {
          "effect": {
            "type": "String",
            "metadata": {
              "displayName": "Effect",
              "description": "Enable or disable the execution of the policy"
            },
            "allowedValues": ["Audit", "Disabled"],
            "defaultValue": "Audit"
          }
        },
        "policyRule": {
          "if": {
            "allOf": [
              {
                "field": "type",
                "equals": "Microsoft.Authorization/roleDefinitions"
              },
              {
                "field": "Microsoft.Authorization/roleDefinitions/type",
                "equals": "CustomRole"
              },
              {
                "anyOf": [
                  {
                    "not": {
                      "field": "Microsoft.Authorization/roleDefinitions/permissions[*].actions[*]",
                      "notEquals": "*"
                    }
                  },
                  {
                    "not": {
                      "field": "Microsoft.Authorization/roleDefinitions/permissions.actions[*]",
                      "notEquals": "*"
                    }
                  }
                ]
              },
              {
                "anyOf": [
                  {
                    "not": {
                      "field": "Microsoft.Authorization/roleDefinitions/assignableScopes[*]",
                      "in": ["/"]
                    }
                  },
                  {
                    "not": {
                      "field": "Microsoft.Authorization/roleDefinitions/assignableScopes[*]",
                      "like": "/providers/Microsoft.Management/*"
                    }
                  }
                ]
              }
            ]
          },
          "then": {
            "effect": "[parameters('effect')]"
          }
        }
      }
    }
  ]
}

关键修改说明

  • 移除了原模板中[concat(subscription().id,'/')]和[subscription().id]这两个依赖订阅上下文的判断项,因为在管理组级别,这些单个订阅的范围判断没有实际意义,反而会导致模板解析失败。
  • 如果你的业务需求需要排除特定订阅的可分配范围,可以手动指定订阅ID(例如"/subscriptions/your-subscription-id"),但绝对不能使用subscription().id函数——管理组部署上下文没有默认订阅,无法解析这个函数。

内容的提问来源于stack exchange,提问作者user1197981

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 15:23:11