Граф коммитов

194 Коммитов

Автор SHA1 Сообщение Дата
Jack Tracey 17d8b3cac9
docs and fixes to firewallPolicies (#890) 2022-02-16 13:36:36 +00:00
Johan Dahlbom 8b429f71c7
Update reference to AzOps bootstrap deploymentScript (#916)
* update uri
2022-02-14 12:24:05 +01:00
Jack Tracey f421fed2c8
fix typo DonNotEnforce (#915) 2022-02-11 17:27:09 +00:00
Jack Tracey c1d545390d
bicep preview launch doc updates (#909) 2022-02-07 18:28:07 +00:00
Jack Tracey 4ed462c7cf
Update Microsoft Defender for Cloud plan for Containers (#876)
* docs

* Portal UXs & orchestration

* policy defs and assignments

* update portal MDFC naming

* portal fairfax MDFC naming

Co-authored-by: Matt White <matt.white@microsoft.com>
2022-01-28 10:29:58 +00:00
withstu e977b6c906
Update deny subnet without NSG & UDR policy (#885)
* Update policies.json

fixes deny subnet without nsg & udr policies when used in ARM deployment: https://github.com/Azure/Enterprise-Scale/issues/407

* policy fixes, version updates, arm escaping and formatting

* update mooncake

* update Fairfax

* Update NSG & UDR in policy table

* update whats new

* update udr policy description

* update udr policy description

* updated descriptions

* updated descriptions

* updated descriptions and version no.

Co-authored-by: Jack Tracey <41163455+jtracey93@users.noreply.github.com>
Co-authored-by: Matt White <matt.white@microsoft.com>
2022-01-27 18:27:37 +00:00
Kristian Nese 6a880386c8
update (#822) 2021-12-09 09:24:59 +01:00
Fai Lai da293ab92b
Mooncake updates (#873)
* removed MS Defender for Cloud built-in policies not available in Mooncake

* ms defender

* updated DIY instructions to deploying ESLZ to Mooncake

* updated whats new

* reworded explanation as to why the policy def/set def deployment may fail and need to rerun

Co-authored-by: Kristian Nese <kristiannese@live.com>
2021-12-08 14:16:39 +01:00
Kristian Nese 21a92f2903
Defender update (#863)
* MS Defender update

* dependency graph

* Naming update

* Naming update for China

* Update eslzArm.json

Adding condition for environment()

* priv DNS condition for public vs gov
2021-12-03 13:06:33 +01:00
Kevin Rowlandson 78bfdc09d0
Add `AuditEvent` to `Deploy-Diagnostics-AA` Policy Definition (#865)
* Add `AuditEvent` to `Deploy-Diagnostics-AA`

* Add 864 to What's New
2021-11-25 11:00:51 +00:00
Federico Guerrini 14f9760db9
Replaced 'Deploy-Default-Udr' policy with 'Deploy-Custom-Route-Table' (#853) 2021-11-11 07:58:29 +01:00
Jack Tracey c69c1817f8
Add parameter for budget name to Deploy-Budget policy (#850)
* whitespace removal, casing fix, new param, docs and gitignore

* missing param usage

* incorrect param

* location updates

Co-authored-by: Kristian Nese <kristiannese@live.com>
2021-11-09 09:24:55 +00:00
Chris King 5093f80a0e
Update README.md (#846)
* Update README.md

wrong parameter in the section to Assign Azure Policy to enforce VM Backup on VMs on the landing zones management group.

* Update README.md

Differentiate between Az Vm Backup policy assignment for identity management group, and landing zone management group in the DIY guidance

Co-authored-by: Kristian Nese <kristian.nese@microsoft.com>
Co-authored-by: Kristian Nese <kristiannese@live.com>
2021-11-05 09:20:18 +00:00
Simona Tarantola a64c9f6780
Update eslz-portal.json (#845)
Adding Azure Arc-enabled servers as per Marketing Arc name guidance
2021-10-28 16:42:01 +01:00
Osterberg afdd5510b8
Fixed missing idempotency in vmBackup assignment (#844)
Co-authored-by: Kristian Nese <kristiannese@live.com>
2021-10-28 11:41:21 +02:00
Kristian Nese 5ba2b46218
ASC built-ins (#835)
* ASC built-ins

* correcting parameter for sql on vm

* updated documentation

* updated china, gov, and readme

* added list for built-in policies
2021-10-22 16:29:27 +02:00
Kristian Nese 417031b1e3
update to policy assignment for Azure Monitor for VMs (#830)
* update to policy assignment for Azure Monitor for VMs

* minor change to text
2021-10-18 13:14:19 +02:00
Kristian Nese 7425c351f8
Fairfax enablement (#820)
* Farfax enablement

* updated folder structure for c and g policies

* added deploy button for Azure gov

* Update Whats-new.md
2021-10-01 19:21:43 +02:00
Fai Lai ef50dc3940
Mooncake deployment (#802)
* reverted missing built-in policies to custom policies

* modified deployment templates so that it works in Azure China regions

* lighter implementation for mooncake deployment

* remove mooncake policy definition and a misedit in DINE-PrivateDNSZonesPolicySetDefinition.json

Co-authored-by: Fai Lai <hoongfai@microsoft.com>
Co-authored-by: Kristian Nese <kristiannese@live.com>
2021-09-21 21:17:27 +02:00
Marvin Buss 84753ec70a
Added AML Policy to Disable Public Network Access (#807)
* Added Stream Analytics Custom Policies

* update to be consistent with eslz

* synch with azure main

* Added AML Policy to Disable Public Network Access

* added whats new
2021-09-16 14:17:31 +02:00
Jack Tracey f92c9c9d58
add depnendsOn to resolve not found errors (#805) 2021-09-14 17:55:49 +01:00
Marvin Buss 6e7364a050
Fix VWAN Portal Requirements (#799)
* Added Stream Analytics Custom Policies

* update to be consistent with eslz

* synch with azure main

* Fixed Portal for VWAN Deployments
2021-09-10 13:50:42 +02:00
Marvin Buss cc85d600ef
Identity subnet size (#800)
* Added Stream Analytics Custom Policies

* update to be consistent with eslz

* synch with azure main

* Update Identity Vnet Size Check
2021-09-10 10:02:27 +02:00
Kristian Nese 04360554bf
Adding policies for Databricks workloads (#778)
* Adding databrics policy def to ESLZ

* removing dupe

* adding ux element for databricks in lz

* pivot to consolidated data policy json

* adding optional policyAssignments for data

* Wiring up the ARM template for data policies

* correcting parameter to nested deployment

* updated description

* fixing typo

* updated casing
2021-09-09 10:43:32 +02:00
Marvin Buss 4a8a6f57dd
Add Option to select Firewall SKU (#793)
* Added Stream Analytics Custom Policies

* update to be consistent with eslz

* synch with azure main

* Added dataPolicies.json

* * updated policy definition for private endpoints
* removed policies from policies.json

* added databricks policies

* removed single policy definition files

* removed initiatives resource

* Add Option to select Firewall SKU

* added docs

* updated label for firewall sku

* updating azure firewall tier tooltip
2021-09-08 17:10:34 +02:00
Marvin Buss a17b01a5db
Simplify Visibility Condition (#794)
* Added Stream Analytics Custom Policies

* update to be consistent with eslz

* synch with azure main

* Simplify Visibility Condition

* updated checks for other locations
2021-09-08 15:56:31 +02:00
Marvin Buss afae0478ec
Added Data Policies File (#786)
* Added Stream Analytics Custom Policies

* update to be consistent with eslz

* synch with azure main

* Added dataPolicies.json

* * updated policy definition for private endpoints
* removed policies from policies.json

* added databricks policies

* removed single policy definition files

* removed initiatives resource
2021-09-08 07:43:15 +02:00
Marvin Buss ed36d26aae
Validation updates (#784)
* Added Stream Analytics Custom Policies

* update to be consistent with eslz

* synch with azure main

* Updated Validation of CIDR

* updated regex to capture missing subnet mask

* Updated AZ fw subnet mask checks
2021-09-06 16:38:33 +02:00
Marvin Buss 9a591a4a8c
Validate VPN/ER Gateway Subnet CIDR Range (#780)
* Added Stream Analytics Custom Policies

* update to be consistent with eslz

* synch with azure main

* Add Validation for VPN/ER Gateway
2021-09-02 14:50:15 +02:00
Marvin Buss 545789b746
Databricks Custom Policies (#757)
* Added Stream Analytics Custom Policies

* update to be consistent with eslz

* Added Custom Databricks Policies

* removed updates

* Update Policy Definition structure

* * Update metadata
* Improve policy description

* * updated folder structure
* Updated Policy file names

* renamed policy file
2021-09-02 09:37:35 +02:00
Johan Dahlbom 02d6b74995
Updates and bugfixes to Deploy-VNET-HubSpoke policyDefinition (#772)
* policy updates

* update whats new
2021-08-31 11:13:46 +02:00
Marvin Buss 12c2d7ada7
Portal Network Validation Improvement (#767)
* Improved Network Range Validation in Portal

* added note to whats new

* update whats new

* added validation to landing zone config
2021-08-27 13:05:53 +02:00
Hansjoerg Scherer 39e0e175ba
Update filter for "disabled" subscription state (#753)
* Update subscription filter

* Update "whats new"
2021-08-25 16:50:54 +02:00
huqianghui 22c594cd6a
Update README.md (#741)
If you do not have authorization to perform action 'Microsoft.Resources/deployments/validate/action', the script deployment error appear.
So follow the link to configure Azure permissions for ARM tenant deployments.
2021-08-19 09:13:17 +01:00
Fai Lai c0012af47b
corrected -subscriptionId parameter for online connected landing zone… (#740)
* corrected -subscriptionId parameter for online connected landing zone subscription to $OnlineLandingZoneSubscriptionId

* updated comment line as well to online management group
2021-08-18 13:40:11 +02:00
Jack Tracey 297e154901
Portal UX - Fix VWAN Address Space & Remove AzFW Subnet For VWAN (#718)
* split-1

* split-2

* split-3

* split-4

* fix azfw vwan

* update params

* update nested template references

* revert eslzArm to current in main

* revert hubspoke-connectivity to main

* revert nvahubspoke-connectivity to main

* revert vwan-connectivity to main apart from address space default value

* remvoe whitespace

* fix for addressSpace DRY'er

Co-authored-by: Kristian Nese <kristiannese@live.com>
2021-08-13 10:31:02 +02:00
Kevin Rowlandson 1b79b700ab
Patch ESLZ ARM (#727)
* Fix naming for lzsManagementGroup variable
Fix value for sqlEncryptionPolicyAssignment variable

* Update name and description

* Replace invalid whitespace character

* Revert Policy Assignment names
2021-08-11 10:42:27 +02:00
Kristian Nese 200203374d
diy guidance 1 (#690)
* diy guidance 1

* Update eslzArm/README.md

Co-authored-by: Jack Tracey <41163455+jtracey93@users.noreply.github.com>

* update

* 2nd update

* Update

* updated DIY

* Added remaining LZ policy assignments

* Updated text

* updated email

* final commit

* Update eslzArm/README.md

Co-authored-by: Jack Tracey <41163455+jtracey93@users.noreply.github.com>

* Update eslzArm/README.md

Co-authored-by: Jack Tracey <41163455+jtracey93@users.noreply.github.com>

* updated variables for lzs

Co-authored-by: Johan Dahlbom <johan@dahlbom.eu>
Co-authored-by: Jack Tracey <41163455+jtracey93@users.noreply.github.com>
2021-08-11 10:00:56 +02:00
Kristian Nese 2792f0060f
renaming ESLZ to ALZ (#701)
* renaming ESLZ to ALZ

* plural

* update
2021-07-22 23:37:18 +02:00
Johan Dahlbom 420b13d734
Removing unnecessary backup file (#699) 2021-07-21 20:17:35 +02:00
Jack Tracey 37d4854291
Fix for Deploy-Diagnostics-LogicAppsWF Not Assigned #691 & Updating NSG, UDR & VNET Peering policies to versions they were before in RIs (#692)
* fix for Deploy-Diagnostics-LogicAppsWF Not Assigned #691

* update vnet peerings to latest defs

* update subnet nsg policy

* remove whitespace

* remove unrequired subnets

* change udr casing
2021-07-19 14:27:31 +01:00
Kristian Nese deee462d0d
condition for azfw when nva is set (#688) 2021-07-15 15:21:06 +02:00
Kristian Nese f7bce808b3
Rename Deny-PublicEndpointsPolicySetDefinition.json to DENY-PublicEndpointsPolicySetDefinition.json (#685)
fixing casing
2021-07-14 13:31:17 +02:00
Kristian Nese e411a859c8
adding ARM modules (#613)
* adding modules

* defined contract

* update #3

* added enforcementMode param

* adding param

* UX and contract changes

* conditional firewall for hub vs vwan

* support for single vs N platform subs

* updated UX for single vs dedicated platform subscriptions

* updating built-in policy

* correcting parameter

* navigating policies for identity

* adding vwan and nva for networking

* removing peering

* adding scaleUnit for vpnGateway and ER for vwan

* fixing parameter

* adding disclaimer for sub selection

* adding private dns zones and moving to built-in policies

* adding policySet for DINE Private DNS Zones

* Added policyset for public paas

* removed custom references

* Update Deny-PublicEndpointsPolicySetDefinition.json

* policy updates

* adding policies and UX enhancements

* removing option for private dns zones when vwan is selected

* adding UX for vnet peering of dedicated ID sub

* adding peering for identity sub

* adding vnet peering for corp lz

* corp lz move and peering

* sequencing corp lz move vs peering

* updated description and displayName

* updating rg location for nw

* adding condition for AzFw as DNS proxy vs not

* adding peering support for identity to vwan hub

* updating displayName

Co-authored-by: Johan Dahlbom <johan@dahlbom.eu>
2021-07-13 20:23:32 +02:00