Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Policy Refresh Q4FY23 #1354

Merged
merged 7 commits into from
Jun 20, 2023
Merged

Policy Refresh Q4FY23 #1354

merged 7 commits into from
Jun 20, 2023

Conversation

Springstone
Copy link
Member

@Springstone Springstone commented Jun 19, 2023

Overview/Summary

Policy Refresh for Q4 FY23.

This PR fixes/adds/changes/removes

Policy

  • Fixed default assignment for SQLEncryption (DINE-SQLEncryptionPolicyAssignment) to use the correct policy definition.
  • Added new default assignment for SQLThreatDetection (DINE-SQLThreatPolicyAssignment) to use the previous policy definition from DINE-SQLEncryptionPolicyAssignment.
  • Updated the assignment DINE-LogAnalyticsPolicyAssignment (Deploy-Log-Analytics) to default enforcement mode to "DoNotEnforce". The Log Analytics workspace is deployed directly by the reference implementations, and as a result this policy is no longer required to deploy the Log Analytics workspace. Retaining the assignment for auditing purposes.
  • Added new custom policies for:
  • Updated Deploy-Diagnostics-APIMgmt.json to support resource-specific destination table in the diagnostic setting for API Management.
  • Updated Deploy-Diagnostics-LogAnalytics.json policy initiative with new parameter to support resource-specific destination table in the diagnostic setting for API Management.
  • Deprecated policy Deny-MachineLearning-PublicNetworkAccess.
  • Update initiative Deny-PublicPaaSEndpoints to replace deprecated policy Deny-MachineLearning-PublicNetworkAccess with builtin 438c38d2-3772-465a-a9cc-7a6666a275ce.
  • Deprecated policy Deny-PublicEndpoint-MariaDB.
  • Update initiative Deny-PublicPaaSEndpoints to replace deprecated policy Deny-PublicEndpoint-MariaDB with builtin fdccbe47-f3e3-4213-ad5d-ea459b2fa077 - special note: US Gov/Fairfax still uses the now deprecated policy as the builtin is not yet available.

Tooling

  • Updated Portal Accelerator tooltips to provide more relevance and links to associated policies or initiatives.

Breaking Changes

  1. N/A

Testing Evidence

Please provide any testing evidence to show that your Pull Request works/fixes as described and planned (include screenshots, if appropriate).
image

Testing URLs

Azure Public

Deploy To Azure

As part of this Pull Request I have

  • Checked for duplicate Pull Requests
  • Associated it with relevant issues, for tracking and closure.
  • Ensured my code/branch is up-to-date with the latest changes in the main branch
  • Performed testing and provided evidence.
  • Ensured contribution guidance is followed.
  • Updated relevant and associated documentation.
  • Updated the "What's New?" wiki page (located: /docs/wiki/whats-new.md)

Springstone and others added 6 commits May 30, 2023 14:30
…valent. (#1335)

Co-authored-by: Anthony Watherston <anwather@microsoft.com>
Co-authored-by: Christoffer Holt <chholt93@gmail.com>
Co-authored-by: Holt, Christoffer <christoffer.holt@skatteetaten.no>
Co-authored-by: github-actions <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jack Tracey <41163455+jtracey93@users.noreply.github.com>
Co-authored-by: github-actions <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Sacha Narinx <Springstone@users.noreply.github.com>
Co-authored-by: github-actions <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions <41898282+github-actions[bot]@users.noreply.github.com>
@Springstone Springstone requested a review from a team as a code owner June 19, 2023 13:04
@ghost ghost added the Needs: Triage 🔍 Needs triaging by the team label Jun 19, 2023
@Springstone Springstone temporarily deployed to csu-rw June 19, 2023 13:04 — with GitHub Actions Inactive
@Springstone Springstone added enhancement New feature or request policy and removed Needs: Triage 🔍 Needs triaging by the team labels Jun 19, 2023
@Springstone Springstone requested a review from jtracey93 June 19, 2023 13:39
@Springstone Springstone added this to the policy-refresh-fy23-q4 milestone Jun 19, 2023
@jtracey93 jtracey93 temporarily deployed to csu-rw June 20, 2023 10:49 — with GitHub Actions Inactive
Copy link
Collaborator

@jtracey93 jtracey93 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@jtracey93 jtracey93 merged commit 87842a9 into main Jun 20, 2023
@jtracey93 jtracey93 deleted the policy-refresh-q4fy23 branch January 12, 2024 13:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request policy
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants