You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

deployIfNotExists自定义策略启用Function App客户端证书配置问题

问题描述
  • 待修复的Microsoft Defender for Cloud安全建议:Function apps should have Client Certificates (Incoming client certificates) enabled(Function应用需启用传入客户端证书)
  • 操作:直接修改对应内置策略的effect为deployIfNotExists,分配到测试环境后未按预期运行,分配阶段即触发报错
  • 报错截图:
    策略分配报错截图
  • 原有错误自定义策略代码如下:
{
    "properties": {
      "displayName": "function app should have  client certificate",
      "policyType": "Custom",
      "mode": "All",
      "metadata": {
        "version": "1.0.1",
        "category": "App Service",
        "createdBy": "faa7d217-4419-499b-9d86-4cd7112f88ab",
        "createdOn": "2022-06-08T11:11:39.3281436Z",
        "updatedBy": "faa7d217-4419-499b-9d86-4cd7112f88ab",
        "updatedOn": "2022-06-08T11:21:58.3249668Z"
      },
      "parameters": {
        "effect": {
          "type": "String",
          "metadata": {
            "displayName": "Effect",
            "description": "Enable or disable the execution of the policy"
          },
          "allowedValues": [
            "Audit",
            "Disabled",
            "DeployIfNotExists"
          ],
          "defaultValue": "DeployIfNotExists"
        }
      },
      "policyRule": {
        "if": {
          "allOf": [
            {
              "field": "type",
              "equals": "Microsoft.Web/sites"
            },
            {
              "field": "kind",
              "like": "functionapp*"
            },
            {
              "field": "Microsoft.Web/sites/clientCertEnabled",
              "equals": "false"
            }
          ]
        },
        "then": {
          "effect": "[parameters('effect')]"
        }
      }
    },
    "id": "/subscriptions/a98b0a61-c76f-4334-afbc-33f49d7af1f7/providers/Microsoft.Authorization/policyDefinitions/4a8bbbc0-8f82-429b-ac84-527ba4c9fed4",
    "type": "Microsoft.Authorization/policyDefinitions",
    "name": "4a8bbbc0-8f82-429b-ac84-527ba4c9fed4",
    "systemData": {
      "createdBy": "maheshcg2@outlook.com",
      "createdByType": "User",
      "createdAt": "2022-06-08T11:11:39.303033Z",
      "lastModifiedBy": "maheshcg2@outlook.com",
      "lastModifiedByType": "User",
      "lastModifiedAt": "2022-06-08T11:21:58.2882516Z"
    }
  }
问题根因

推测完全准确:现有策略仅实现了Audit/Disabled效果所需的资源检测逻辑,完全缺失DeployIfNotExists效果强制要求的合规性判断规则、部署权限声明、修复部署模板配置,Azure Policy引擎无法识别修复逻辑,因此分配时报错。

正确自定义策略配置

补全DeployIfNotExists所需完整规则块后的可用策略代码如下:

{
  "properties": {
    "displayName": "Function apps should enable incoming client certificates",
    "policyType": "Custom",
    "mode": "Indexed",
    "metadata": {
      "version": "1.0.0",
      "category": "App Service"
    },
    "parameters": {
      "effect": {
        "type": "String",
        "metadata": {
          "displayName": "Effect",
          "description": "Enable or disable policy execution"
        },
        "allowedValues": [
          "Audit",
          "Disabled",
          "DeployIfNotExists"
        ],
        "defaultValue": "DeployIfNotExists"
      }
    },
    "policyRule": {
      "if": {
        "allOf": [
          {
            "field": "type",
            "equals": "Microsoft.Web/sites"
          },
          {
            "field": "kind",
            "like": "functionapp*"
          }
        ]
      },
      "then": {
        "effect": "[parameters('effect')]",
        "details": {
          "type": "Microsoft.Web/sites",
          "name": "[field('name')]",
          "existenceCondition": {
            "field": "Microsoft.Web/sites/clientCertEnabled",
            "equals": true
          },
          "roleDefinitionIds": [
            "/providers/Microsoft.Authorization/roleDefinitions/de139f84-1756-47ae-9be6-808fbbe84772"
          ],
          "deployment": {
            "properties": {
              "mode": "Incremental",
              "template": {
                "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
                "contentVersion": "1.0.0.0",
                "resources": [
                  {
                    "type": "Microsoft.Web/sites",
                    "apiVersion": "2022-03-01",
                    "name": "[field('name')]",
                    "location": "[field('location')]",
                    "properties": {
                      "clientCertEnabled": true
                    }
                  }
                ]
              }
            }
          }
        }
      }
    }
  }
}
使用注意事项
  • 策略模式从All调整为Indexed,适配资源提供者评估逻辑,减少不必要的非资源类型评估
  • 分配策略时必须启用系统分配托管标识,平台会自动匹配roleDefinitionIds中声明的网站参与者权限,需确认账号在目标作用域有角色分配权限,否则托管标识授权失败会导致修复不生效
  • 策略生效后对新建Function App会自动开启客户端证书校验,存量不合规资源可在策略合规性面板手动创建修复任务批量整改
  • 若需要排除Function App部署槽位,可在if条件块中新增规则{"field": "kind", "notContains": "slot"}

内容的提问来源于stack exchange,提问作者mprj

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.02 02:28:04