deployIfNotExists自定义策略启用Function App客户端证书配置问题
问题描述
- 待修复的Microsoft Defender for Cloud安全建议:Function apps should have Client Certificates (Incoming client certificates) enabled(Function应用需启用传入客户端证书)
- 操作:直接修改对应内置策略的effect为
deployIfNotExists,分配到测试环境后未按预期运行,分配阶段即触发报错 - 报错截图:

- 原有错误自定义策略代码如下:
{ "properties": { "displayName": "function app should have client certificate", "policyType": "Custom", "mode": "All", "metadata": { "version": "1.0.1", "category": "App Service", "createdBy": "faa7d217-4419-499b-9d86-4cd7112f88ab", "createdOn": "2022-06-08T11:11:39.3281436Z", "updatedBy": "faa7d217-4419-499b-9d86-4cd7112f88ab", "updatedOn": "2022-06-08T11:21:58.3249668Z" }, "parameters": { "effect": { "type": "String", "metadata": { "displayName": "Effect", "description": "Enable or disable the execution of the policy" }, "allowedValues": [ "Audit", "Disabled", "DeployIfNotExists" ], "defaultValue": "DeployIfNotExists" } }, "policyRule": { "if": { "allOf": [ { "field": "type", "equals": "Microsoft.Web/sites" }, { "field": "kind", "like": "functionapp*" }, { "field": "Microsoft.Web/sites/clientCertEnabled", "equals": "false" } ] }, "then": { "effect": "[parameters('effect')]" } } }, "id": "/subscriptions/a98b0a61-c76f-4334-afbc-33f49d7af1f7/providers/Microsoft.Authorization/policyDefinitions/4a8bbbc0-8f82-429b-ac84-527ba4c9fed4", "type": "Microsoft.Authorization/policyDefinitions", "name": "4a8bbbc0-8f82-429b-ac84-527ba4c9fed4", "systemData": { "createdBy": "maheshcg2@outlook.com", "createdByType": "User", "createdAt": "2022-06-08T11:11:39.303033Z", "lastModifiedBy": "maheshcg2@outlook.com", "lastModifiedByType": "User", "lastModifiedAt": "2022-06-08T11:21:58.2882516Z" } }
问题根因
推测完全准确:现有策略仅实现了Audit/Disabled效果所需的资源检测逻辑,完全缺失DeployIfNotExists效果强制要求的合规性判断规则、部署权限声明、修复部署模板配置,Azure Policy引擎无法识别修复逻辑,因此分配时报错。
正确自定义策略配置
补全DeployIfNotExists所需完整规则块后的可用策略代码如下:
{ "properties": { "displayName": "Function apps should enable incoming client certificates", "policyType": "Custom", "mode": "Indexed", "metadata": { "version": "1.0.0", "category": "App Service" }, "parameters": { "effect": { "type": "String", "metadata": { "displayName": "Effect", "description": "Enable or disable policy execution" }, "allowedValues": [ "Audit", "Disabled", "DeployIfNotExists" ], "defaultValue": "DeployIfNotExists" } }, "policyRule": { "if": { "allOf": [ { "field": "type", "equals": "Microsoft.Web/sites" }, { "field": "kind", "like": "functionapp*" } ] }, "then": { "effect": "[parameters('effect')]", "details": { "type": "Microsoft.Web/sites", "name": "[field('name')]", "existenceCondition": { "field": "Microsoft.Web/sites/clientCertEnabled", "equals": true }, "roleDefinitionIds": [ "/providers/Microsoft.Authorization/roleDefinitions/de139f84-1756-47ae-9be6-808fbbe84772" ], "deployment": { "properties": { "mode": "Incremental", "template": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "resources": [ { "type": "Microsoft.Web/sites", "apiVersion": "2022-03-01", "name": "[field('name')]", "location": "[field('location')]", "properties": { "clientCertEnabled": true } } ] } } } } } } } }
使用注意事项
- 策略模式从
All调整为Indexed,适配资源提供者评估逻辑,减少不必要的非资源类型评估 - 分配策略时必须启用系统分配托管标识,平台会自动匹配
roleDefinitionIds中声明的网站参与者权限,需确认账号在目标作用域有角色分配权限,否则托管标识授权失败会导致修复不生效 - 策略生效后对新建Function App会自动开启客户端证书校验,存量不合规资源可在策略合规性面板手动创建修复任务批量整改
- 若需要排除Function App部署槽位,可在
if条件块中新增规则{"field": "kind", "notContains": "slot"}
内容的提问来源于stack exchange,提问作者mprj
相关产品推荐
相关产品推荐

