You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求开启DataLake Store防火墙的Azure Policy JSON部署代码

Sure thing! Below is a fully functional Azure Policy JSON definition designed to enforce enabling the firewall for Azure Data Lake Store accounts. I’ve built it with flexibility in mind, letting you customize allowed IP ranges and trusted Microsoft services access directly through policy parameters.

Azure Policy to Enforce Enabled Firewall on Azure Data Lake Store Accounts

This policy will deny the creation of Data Lake Store accounts without an enabled firewall (or mark them as non-compliant if you switch to the Audit effect). It includes configurable parameters to tailor the firewall settings to your organization's needs.

Complete Policy JSON

{
  "properties": {
    "displayName": "Enforce Enabled Firewall on Azure Data Lake Store Accounts",
    "policyType": "Custom",
    "mode": "Indexed",
    "description": "Ensures all Azure Data Lake Store accounts have firewall enabled with specified IP ranges and optional trusted Microsoft services access.",
    "parameters": {
      "allowedIpAddresses": {
        "type": "Array",
        "metadata": {
          "displayName": "Allowed IP Address Ranges",
          "description": "List of IP address ranges (in CIDR format) allowed to access the Data Lake Store account."
        }
      },
      "allowTrustedMicrosoftServices": {
        "type": "Boolean",
        "metadata": {
          "displayName": "Allow Trusted Microsoft Services",
          "description": "Set to true to allow trusted Microsoft services to bypass the firewall."
        },
        "defaultValue": true
      }
    },
    "policyRule": {
      "if": {
        "allOf": [
          {
            "field": "type",
            "equals": "Microsoft.DataLakeStore/accounts"
          },
          {
            "anyOf": [
              {
                "field": "Microsoft.DataLakeStore/accounts/firewallState",
                "notEquals": "Enabled"
              },
              {
                "field": "Microsoft.DataLakeStore/accounts/firewallRules[*].value",
                "notIn": "[parameters('allowedIpAddresses')]"
              },
              {
                "field": "Microsoft.DataLakeStore/accounts/trustedIdProviderState",
                "notEquals": "[if(parameters('allowTrustedMicrosoftServices'), 'Enabled', 'Disabled')]"
              }
            ]
          }
        ]
      },
      "then": {
        "effect": "Deny"
      }
    }
  }
}

Key Details & Customization Tips

  • Effect: Currently set to Deny which blocks non-compliant account creation. If you want to audit existing non-compliant resources instead (without blocking new ones), change the effect to Audit.
  • Parameters:
    • allowedIpAddresses: Populate this with your organization's approved IP ranges (e.g., ["192.168.1.0/24", "10.0.0.0/8"]).
    • allowTrustedMicrosoftServices: Toggle this to control if services like Azure Data Factory can access the Data Lake Store without being in the IP allowlist.
  • Policy Logic: The policy checks three critical conditions:
    1. The Data Lake Store account's firewall is enabled.
    2. The configured IP allowlist matches your specified ranges.
    3. Trusted Microsoft services access is set according to your preference.

Deployment Steps

To deploy this policy using Azure CLI:

  1. Save the JSON above to a file named datalake-firewall-policy.json.
  2. Run the following command:
az policy definition create \
  --name "enforce-datalake-store-firewall" \
  --display-name "Enforce Enabled Firewall on Azure Data Lake Store Accounts" \
  --description "Ensures all Azure Data Lake Store accounts have firewall enabled with specified IP ranges and trusted services access" \
  --rules "@datalake-firewall-policy.json" \
  --mode Indexed
  1. Assign the policy to your desired management group, subscription, or resource group using the Azure portal or CLI.

Notes

  • If you need to remediate existing non-compliant accounts (when using the Audit effect), you can create a remediation task through the Azure Policy portal to enable the firewall and apply the correct IP ranges.
  • Always test the policy in a non-production environment first to ensure it doesn't block legitimate workflows.

内容的提问来源于stack exchange,提问作者gachCoder

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 07:35:49