微信公众号搜"智元新知"关注
微信扫一扫可直接关注哦!

有关 Azure 政策豁免的查询

如何解决有关 Azure 政策豁免的查询

我想通过 ARM 模板为我现有的策略分配部署策略豁免。目标是从给定订阅中免除特定资源组,这样属于该资源组的资源将免于合规性报告。

我指的是 Microsoft Azure 文档(在 ARM JSON 的链接和示例结构下方提供)以了解如何构建 ARM 模板,但我没有找到有关在何处定义豁免范围的信息。

https://docs.microsoft.com/en-us/azure/governance/policy/concepts/exemption-structure

    "id": "/subscriptions/{subId}/resourceGroups/ExemptRG/providers/Microsoft.Authorization/policyExemptions/resourceIsNotApplicable","name": "resourceIsNotApplicable","type": "Microsoft.Authorization/policyExemptions","properties": {
        "displayName": "This resource is scheduled for deletion","description": "This resources is planned to be deleted by end of quarter and has been granted a waiver to the policy.","Metadata": {
            "requestedBy": "Storage team","approvedBy": "IA","approvedOn": "2020-07-26T08:02:32.0000000Z","ticketRef": "4baf214c-8d54-4646-be3f-eb6ec7b9bc4f"
        },"policyAssignmentId": "/subscriptions/{mySubscriptionID}/providers/Microsoft.Authorization/policyAssignments/resourceShouldBeCompliantinit","policyDeFinitionReferenceIds": [
            "requiredTags","allowedLocations"
        ],"exemptionCategory": "waiver","expiresOn": "2020-12-31T23:59:00.0000000Z"
    }
}

解决方法

豁免的范围在创建时的范围内定义。因此,对于上述现有豁免的示例,豁免的范围是 ExampleRG 资源组。

从文档中,Microsoft 指出: 策略豁免是作为资源层次结构上的子对象或授予豁免的单个资源创建的,因此目标不包括在豁免定义中。

版权声明:本文内容由互联网用户自发贡献,该文观点与技术仅代表作者本人。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如发现本站有涉嫌侵权/违法违规的内容, 请发送邮件至 dio@foxmail.com 举报,一经查实,本站将立刻删除。