求开启DataLake Store防火墙的Azure Policy JSON部署代码
Sure thing! Below is a fully functional Azure Policy JSON definition designed to enforce enabling the firewall for Azure Data Lake Store accounts. I’ve built it with flexibility in mind, letting you customize allowed IP ranges and trusted Microsoft services access directly through policy parameters.
Azure Policy to Enforce Enabled Firewall on Azure Data Lake Store Accounts
This policy will deny the creation of Data Lake Store accounts without an enabled firewall (or mark them as non-compliant if you switch to the Audit effect). It includes configurable parameters to tailor the firewall settings to your organization's needs.
Complete Policy JSON
{ "properties": { "displayName": "Enforce Enabled Firewall on Azure Data Lake Store Accounts", "policyType": "Custom", "mode": "Indexed", "description": "Ensures all Azure Data Lake Store accounts have firewall enabled with specified IP ranges and optional trusted Microsoft services access.", "parameters": { "allowedIpAddresses": { "type": "Array", "metadata": { "displayName": "Allowed IP Address Ranges", "description": "List of IP address ranges (in CIDR format) allowed to access the Data Lake Store account." } }, "allowTrustedMicrosoftServices": { "type": "Boolean", "metadata": { "displayName": "Allow Trusted Microsoft Services", "description": "Set to true to allow trusted Microsoft services to bypass the firewall." }, "defaultValue": true } }, "policyRule": { "if": { "allOf": [ { "field": "type", "equals": "Microsoft.DataLakeStore/accounts" }, { "anyOf": [ { "field": "Microsoft.DataLakeStore/accounts/firewallState", "notEquals": "Enabled" }, { "field": "Microsoft.DataLakeStore/accounts/firewallRules[*].value", "notIn": "[parameters('allowedIpAddresses')]" }, { "field": "Microsoft.DataLakeStore/accounts/trustedIdProviderState", "notEquals": "[if(parameters('allowTrustedMicrosoftServices'), 'Enabled', 'Disabled')]" } ] } ] }, "then": { "effect": "Deny" } } } }
Key Details & Customization Tips
- Effect: Currently set to
Denywhich blocks non-compliant account creation. If you want to audit existing non-compliant resources instead (without blocking new ones), change the effect toAudit. - Parameters:
allowedIpAddresses: Populate this with your organization's approved IP ranges (e.g.,["192.168.1.0/24", "10.0.0.0/8"]).allowTrustedMicrosoftServices: Toggle this to control if services like Azure Data Factory can access the Data Lake Store without being in the IP allowlist.
- Policy Logic: The policy checks three critical conditions:
- The Data Lake Store account's firewall is enabled.
- The configured IP allowlist matches your specified ranges.
- Trusted Microsoft services access is set according to your preference.
Deployment Steps
To deploy this policy using Azure CLI:
- Save the JSON above to a file named
datalake-firewall-policy.json. - Run the following command:
az policy definition create \ --name "enforce-datalake-store-firewall" \ --display-name "Enforce Enabled Firewall on Azure Data Lake Store Accounts" \ --description "Ensures all Azure Data Lake Store accounts have firewall enabled with specified IP ranges and trusted services access" \ --rules "@datalake-firewall-policy.json" \ --mode Indexed
- Assign the policy to your desired management group, subscription, or resource group using the Azure portal or CLI.
Notes
- If you need to remediate existing non-compliant accounts (when using the
Auditeffect), you can create a remediation task through the Azure Policy portal to enable the firewall and apply the correct IP ranges. - Always test the policy in a non-production environment first to ensure it doesn't block legitimate workflows.
内容的提问来源于stack exchange,提问作者gachCoder
相关产品推荐
相关产品推荐

