-
Notifications
You must be signed in to change notification settings - Fork 1.1k
New Feature: Workload Specific Compliance #1622
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from 154 commits
Commits
Show all changes
155 commits
Select commit
Hold shift + click to select a range
196bdd0
Add FSI specific policies
Springstone a1fdff3
Add Deny-CognitiveServices-RestrictOutboundNetworkAccess policy defin…
Springstone 97db4cb
Add FSI specific policies
Springstone 15610d5
Add FSI specific initiative policy set definition
Springstone ecdae38
Add FSI specific initiative policies for App Services
Springstone be7bc0d
Add aaModifyPublicNetworkAccess parameter to Deny-PublicPaaSEndpoints…
Springstone 4032cb7
Add policy definitions for Cognitive Search and Automation
Springstone a449bff
Update policy definitions for Deny-PublicPaaSEndpoints and Enforce-En…
Springstone 97d4c06
Update policy set definitions for Compute and Container Apps
Springstone 7f35801
Add new policy set definitions for Enforce-Guardrails-CosmosDb, Enfor…
Springstone f2de5cd
Update policy definitions for Event Hub encryption
Springstone 7147bb3
Update Enforce-Encryption-CMK policy set definition version and name
Springstone 64eddf4
Add new policySetDefinitions for KeyVault guardrails
Springstone 50b18c5
Remove metadata and update groupNames in policySetDefinitions
Springstone 6703c5e
Add ESLZ custom initiatives
Springstone ec12be6
Update policy and initiative files
Springstone 6ab4bfb
Add FSI specific policy set definitions for Kubernetes, Machine Learn…
Springstone f321e00
Add policy set definition for Service Bus and update policy set defin…
Springstone 22e017d
Add policy set definitions for SQL and Storage
Springstone aa7da20
Add policy set definition for Enforce-Guardrails-Synapse.json
Springstone dd098a5
Update policy and initiative files
Springstone c7f60e5
Update policy set definitions for ESLZ Arm template and Enforce-Encry…
Springstone 97999e3
Update policy set definitions for Enforce-Encryption-CMK.json, Enforc…
Springstone 90b5f3a
Update policy set definitions for Enforce-Guardrails-CosmosDb.json, E…
Springstone d6bd94f
Update policy set definitions for Enforce-Guardrails-KeyVault-Sup.jso…
Springstone 969a8be
Update ALZ Policies documentation and ESLZ Arm template
Springstone 2791ffa
Update mdfcConfiguration.json description for resource group name
Springstone 0d575d4
Update policy set definitions for ESLZ Arm template and Enforce-Encry…
Springstone 684a4e1
Update policy set definitions for Enforce-Guardrails-ServiceBus.json
Springstone 501f4f9
.
Springstone 27b3a1c
.
Springstone 65d2ec6
.
Springstone 7939b30
.
Springstone 8a53c49
.
Springstone 3b4429b
.
Springstone ce6327c
.
Springstone 1336c28
Update labels and descriptions for regulated industry policy initiatives
Springstone da224a5
Update labels and descriptions for regulated industry policy initiatives
Springstone 1c4aba5
Update regulated industry and regulatory compliance initiatives assig…
Springstone b1edff6
Refactor policy assignments for regulated industry and regulatory com…
Springstone afdcbb1
Add policy assignment for API Management
Springstone 3c0038a
Add support for enabling API Management Policy Initiatives in regulat…
Springstone cd95554
Update multiselect and selectAll properties in eslz-portal.json
Springstone 51aa41f
Update labels and descriptions for regulated industry policy initiatives
Springstone e88ea04
Refactor policy assignments for regulated industry and regulatory com…
Springstone f30e319
.
Springstone e7ff876
Update labels and descriptions for regulated industry policy initiatives
Springstone 6905103
.
Springstone bb97da3
.
Springstone 9385efa
.
Springstone 96deba4
Update labels and descriptions for regulated industry policy initiatives
Springstone bc338da
.
Springstone e96c18e
.
Springstone 7cb943c
Update labels and descriptions for regulated industry policy initiatives
Springstone bf2a03c
Update labels and descriptions for regulated industry policy initiatives
Springstone 8fa209f
Merge branch 'Azure:main' into FSI
Springstone 88b69ab
Update defaultValue for delayCount to 45 in eslzArm.json
Springstone 18ebd31
Merge branch 'FSI' of https://github.com/Springstone/Enterprise-Scale…
Springstone c8b4427
Update labels and descriptions for regulated industry policy initiatives
Springstone 13f4c77
Update labels and descriptions for regulated industry policy initiatives
Springstone 58d3ba0
Update labels and descriptions for workload specific compliance polic…
Springstone 835db96
Update labels and descriptions for regulated industry policy initiatives
Springstone 71e8db4
Update names and scopes for wsAPIM deployments in eslzArm.json
Springstone ac845ab
.
Springstone 99d4e1a
.
Springstone c57d209
Update policy assignment names and variables in ENFORCE-GuardrailsAPI…
Springstone c60db38
Update descriptions for regulated industry policy initiatives
Springstone ff59bea
Update descriptions for regulated industry policy initiatives
Springstone ac234c9
Update policy definition group names in Enforce-Guardrails-ContainerI…
Springstone 5396bc2
Update policy definition group names, descriptions, and labels for re…
Springstone 586ff0a
Update eslz-portal.json to hide "resourceScope" field in Microsoft.Co…
Springstone 2d2e147
Update eslz-portal.json to remove "visible" property for "resourceSco…
Springstone 5ac9198
Fix typo in eventGridPublicNetworkAccess parameter name
Springstone 8548093
Update deployment name in eslzArm.json for wsContainerInstance
Springstone 29a9b00
Add option to enable all workload specific compliance initiatives in …
Springstone 8c02fcc
.
Springstone e0e4982
.
Springstone cb64d20
.
Springstone 034fdf5
.
Springstone 0fc8768
.
Springstone a407eff
.
Springstone e734a95
Add option to enable all workload specific compliance initiatives in …
Springstone df4b232
Update policy assignment names for guardrails in eslzArm/managementGr…
Springstone 7fc9b3f
Add new workload specific compliance initiatives and update existing …
Springstone e876277
Update ALZ Portal accelerator with new "Workload Specific Compliance"…
Springstone 66c6615
Update ALZ Portal accelerator with new "Workload Specific Compliance"…
Springstone 2d12ae2
Update ALZ Portal accelerator with new "Workload Specific Compliance"…
Springstone 02fcb46
Fix ALZ Policies and Initiatives escape character issue and update De…
Springstone 835f1dc
Auto-update Portal experience [Springstone/651f57a7]
github-actions[bot] 71b20af
Adding dependsOn for workload policies to stagger identity creation
Springstone 4d78387
Update ALZ Portal accelerator with new "Workload Specific Compliance"…
Springstone 2c0a47a
Update eslzArm.json to remove wsAPIMDeploymentName from dependencies
Springstone a79cc46
Update policy assignment names for guardrails in eslzArm/managementGr…
Springstone da02a54
Update policy assignment names for guardrails in eslzArm/managementGr…
Springstone 66a8d21
Update Enforce-Encryption-CMK.json with default values set to "Deny"
Springstone 63c8f96
Update ALZ Portal accelerator with tooltip text change in eslz-portal…
Springstone 23eb19d
Update policy definitions for storage account TLS and secure transfer
Springstone 907598d
Update Whats New for custom policy for storage account TLS and secure…
Springstone bff97fa
Fixing policy description length
Springstone 59691d4
Add ddosPlanResourceId to eslzArm.json
Springstone 4e688df
Add ddosPlanResourceId parameter to ENFORCE-GuardrailsNetworkPolicyAs…
Springstone 28efe0f
Update Audit-PublicIpAddresses-UnusedResourcesCostOptimization policy…
Springstone f9c2aca
Auto-update Portal experience [Springstone/651f57a7]
github-actions[bot] cdda534
Update visibility condition for Network and Networking services in es…
Springstone b8a201d
Merge branch 'FSI' of https://github.com/Springstone/Enterprise-Scale…
Springstone 5d5f73f
Merge branch 'policy-refresh-q3fy24' of https://github.com/Azure/Ente…
Springstone 5986775
Auto-update Portal experience [Springstone/79c74f4d]
github-actions[bot] a4e6c3f
Merge branch 'policy-refresh-q3fy24' of https://github.com/Azure/Ente…
Springstone 14d8d20
Auto-update Portal experience [Springstone/e2264bf6]
github-actions[bot] 788ac66
Merge branch 'policy-refresh-q3fy24' of https://github.com/Azure/Ente…
Springstone 1c0bbee
Merge branch 'FSI' of https://github.com/Springstone/Enterprise-Scale…
Springstone 091f87c
Auto-update Portal experience [Springstone/e2264bf6]
github-actions[bot] 2f22f1d
Fixing a merge issue
Springstone 7e2deac
Meh, another merge issue.
Springstone bee9fb7
Update .github/workflows/update-portal.yml
Springstone a643a1a
Update src/resources/Microsoft.Authorization/policyDefinitions/Audit-…
Springstone 66f751a
Auto-update Portal experience [Springstone/e2264bf6]
github-actions[bot] da2c6a8
Update docs/wiki/ALZ-Policies-Extra.md
Springstone b9d6fea
Update src/resources/Microsoft.Authorization/policySetDefinitions/Enf…
Springstone e47bd94
Update src/resources/Microsoft.Authorization/policyDefinitions/Deploy…
Springstone 7a88d92
Auto-update Portal experience [Springstone/e2264bf6]
github-actions[bot] a8da58f
Update src/resources/Microsoft.Authorization/policyDefinitions/Deny-S…
Springstone d195087
feat: Add new generic policy for PaaS resources private endpoint to o…
Springstone 3049425
Merge branch 'FSI' of https://github.com/Springstone/Enterprise-Scale…
Springstone 198d740
Auto-update Portal experience [Springstone/e2264bf6]
github-actions[bot] f708cff
Update docs/wiki/ALZ-Policies-Extra.md
Springstone a4f3f93
Update src/resources/Microsoft.Authorization/policySetDefinitions/Enf…
Springstone 6bf11fd
Update src/resources/Microsoft.Authorization/policyDefinitions/Deny-E…
Springstone 03c1034
Auto-update Portal experience [Springstone/e2264bf6]
github-actions[bot] 5008c64
Update policy set definitions for enforcing guardrails
Springstone 9d4d316
Merge branch 'FSI' of https://github.com/Springstone/Enterprise-Scale…
Springstone 1d907e1
Update docs/wiki/ALZ-Policies-Extra.md
Springstone 4600af3
Update src/resources/Microsoft.Authorization/policyDefinitions/Deny-L…
Springstone 4317ef0
Auto-update Portal experience [Springstone/e2264bf6]
github-actions[bot] 3b92d0f
Update src/resources/Microsoft.Authorization/policyDefinitions/Deny-L…
Springstone f778788
Auto-update Portal experience [Springstone/e2264bf6]
github-actions[bot] e970c1c
Update policy set definitions for enforcing guardrails
Springstone b17189b
Update docs/wiki/ALZ-Policies-Extra.md
Springstone 939ca85
chore: Update ALZ-Policies-FAQ.md with deployment instructions
Springstone b0539aa
Merge branch 'FSI' of https://github.com/Springstone/Enterprise-Scale…
Springstone 650d4cc
chore: Update ALZ-Policies-FAQ.md with deployment instructions
Springstone c9446eb
Update ALZ-Policies-Extra.md to fix typo in policy name
Springstone 8b027fb
Fix typo in ALZ-Policies-Extra.md
Springstone 76925b9
Update ALZ-Policies-Extra.md to fix typo in policy name
Springstone 1eed266
Update policy set definitions for enforcing guardrails
Springstone fd4e3d0
Update policy set definitions for enforcing guardrails
Springstone e602796
Update policy set definitions for enforcing guardrails
Springstone cb43fff
Auto-update Portal experience [Springstone/e2264bf6]
github-actions[bot] 34f58b7
Update policy set definitions for enforcing guardrails
Springstone c182e01
Merge branch 'FSI' of https://github.com/Springstone/Enterprise-Scale…
Springstone 57e77ee
Update policy set definitions to include Enforce-EncryptTransit_20240…
Springstone c10909e
Update policy set definitions to include Enforce-EncryptTransit_20240…
Springstone 579a017
Update policy set definitions to include Enforce-EncryptTransit_20240…
Springstone f23ea29
Update policy set definitions to include Enforce-EncryptTransit_20240…
Springstone d476a25
Update docs/wiki/ALZ-Policies-Extra.md
Springstone File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,57 @@ | ||
| # ALZ Policies - Extra | ||
|
|
||
| This document describes additional ALZ custom policy definitions and initiatives that are not assigned by default in ALZ, but are provided as they may assist some consumers of ALZ in specific scenarios where they can assign these additional policies to help them meet their objectives. We also provide guidance on how to handle certain situations as some of the policies require additional considerations prior to assigning. | ||
|
|
||
| > For the complete list of Azure Landing Zones custom policies, please use [AzAdvertizer](https://www.azadvertizer.net/azpolicyadvertizer_all.html), and change `type` to `ALZ`. | ||
|
|
||
| ## Additional ALZ Custom Policies for consideration | ||
|
|
||
| ALZ provides several additional policies that are not assigned by default but that can be used for specific scenarios should they be required. | ||
|
|
||
| | Policy | Description | Notes | | ||
| |------------|-------------|-------------| | ||
| | Deny-Appgw-without-Waf | Application Gateway should be deployed with WAF enabled | Use to ensure Application Gateways are deployed with Web Application Firewall enabled | | ||
Springstone marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| | Deny-Private-Dns-Zones | Deny the creation of private DNS | For organizations that centralize core networking functions, use this policy to prevent the creation of additional Private DNS Zones under specific scopes | | ||
| | Deny-Subnet-Without-Udr | Subnets should have a User Defined Route | Should you require all network traffic be directed to an appliance for inspection, you can use this policy to ensure UDR is associated with a subnet | | ||
| | Deny-Udr-With-Specific-Nexthop | User Defined Routes with 'Next Hop Type' set to 'Internet' or 'VirtualNetworkGateway' should be denied | Refining `Deny-Subnet-Without-Udr` you can ensure non-compliant UDRs are denied (e.g., bypassing a firewall) | | ||
| | Deny-Vnet-Peering | Deny vNet peering | Use to prevent vNet peering under specific scopes (e.g., Sandbox management group) | | ||
| | Deny-Vnet-Peering-To-Non-Approved-Vnets | Deny vNet peering to non-approved vNets | Use to control vNet peering under specific scopes, like in the Corp management group, only allow peering to the hub vNet. | | ||
| | Deploy-Budget | Deploy a default budget on all subscriptions under the assigned scope | Set a default budget for a specific scope, like setting a $500 budget on all subscriptions in the Sandbox management group | | ||
| | Deploy-Vnet-Hubspoke | Deploy Virtual Network with peering to the hub | Automatically peer a new virtual network with the hub, for example, in the Corp management group | | ||
| | Deploy-Windows-DomainJoin | Deploy Windows Domain Join Extension with Key Vault configuration | Windows Domain Join a virtual machine using domain name and password stored in Key Vault as secrets | | ||
|
|
||
| ## 2. ALZ, Workload Specific Compliance and Regulated Industries | ||
|
|
||
| The Azure Landing Zone is designed to be a flexible and scalable solution that can be used by organizations in a variety of industries. However, organizations in regulated industries (FSI, Healthcare, etc.) may need to take additional steps to ensure compliance with industry-specific regulations. These regulations often commonly have a consistent set of controls to cover, like CMK, locking down public endpoints, TLS version enforcement, logging etc. | ||
|
|
||
| To support the additional control requirements of these industries, we're providing the following additional initiatives that enhance the security and compliance posture of the Azure Landing Zone: | ||
|
|
||
| > **Please Note:** These are meant to help customers across all regulated industries (FSI, Healthcare, etc.) and not be aligned to specific regulatory controls, as there are already policy initiatives available for these via [Azure Policy](https://learn.microsoft.com/azure/azure-resource-manager/management/security-controls-policy) & [Microsoft Defender for Cloud](https://learn.microsoft.com/azure/defender-for-cloud/regulatory-compliance-dashboard) | ||
|
|
||
| | Initiative ID | Name | Description | # of Policies | | ||
| |------------|-------------|-------------|-------------| | ||
| | [Enforce-Guardrails-APIM](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-APIM.html) | Enforce recommended guardrails for API Management | This policy initiative is a group of policies that ensures API Management is compliant per regulated Landing Zones. | 11 | | ||
| | [Enforce-Guardrails-AppServices](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-AppServices.html) | Enforce recommended guardrails for App Service | This policy initiative is a group of policies that ensures App Service is compliant per regulated Landing Zones. | 19 | | ||
| | [Enforce-Guardrails-Automation](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-Automation.html) | Enforce recommended guardrails for Automation Account | This policy initiative is a group of policies that ensures Automation Account is compliant per regulated Landing Zones. | 6 | | ||
| | [Enforce-Guardrails-CognitiveServices](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-CognitiveServices.html) | Enforce recommended guardrails for Cognitive Services | This policy initiative is a group of policies that ensures Cognitive Services is compliant per regulated Landing Zones. | 5 | | ||
| | [Enforce-Guardrails-Compute](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-Compute.html) | Enforce recommended guardrails for Compute | This policy initiative is a group of policies that ensures Compute is compliant per regulated Landing Zones. | 2 | | ||
| | [Enforce-Guardrails-ContainerApps](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-ContainerApps.html) | Enforce recommended guardrails for Container Apps | This policy initiative is a group of policies that ensures Container Apps is compliant per regulated Landing Zones. | 2 | | ||
| | [Enforce-Guardrails-ContainerInstance](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-ContainerInstance.html) | Enforce recommended guardrails for Container Instance | This policy initiative is a group of policies that ensures Container Instance is compliant per regulated Landing Zones. | 1 | | ||
| | [Enforce-Guardrails-ContainerRegistry](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-ContainerRegistry.html) | Enforce recommended guardrails for Container Registry | This policy initiative is a group of policies that ensures Container Registry is compliant per regulated Landing Zones. | 12 | | ||
| | [Enforce-Guardrails-CosmosDb](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-CosmosDb.html) | Enforce recommended guardrails for Cosmos DB | This policy initiative is a group of policies that ensures Cosmos DB is compliant per regulated Landing Zones. | 6 | | ||
| | [Enforce-Guardrails-DataExplorer](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-DataExplorer.html) | Enforce recommended guardrails for Data Explorer | This policy initiative is a group of policies that ensures Data Explorer is compliant per regulated Landing Zones. | 4 | | ||
| | [Enforce-Guardrails-DataFactory](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-DataFactory.html) | Enforce recommended guardrails for Data Factory | This policy initiative is a group of policies that ensures Data Factory is compliant per regulated Landing Zones. | 5 | | ||
| | [Enforce-Guardrails-EventGrid](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-EventGrid.html) | Enforce recommended guardrails for Event Grid | This policy initiative is a group of policies that ensures Event Grid is compliant per regulated Landing Zones. | 8 | | ||
| | [Enforce-Guardrails-EventHub](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-EventHub.html) | Enforce recommended guardrails for Event Hub | This policy initiative is a group of policies that ensures Event Hub is compliant per regulated Landing Zones. | 4 | | ||
| | [Enforce-Guardrails-KeyVault-Sup](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-KeyVault-Sup.html) | Enforce additional recommended guardrails for Key Vault | This policy initiative is a group of policies that ensures Key Vault is compliant per regulated Landing Zones. This includes additional policies to supplement Enforce-Guardrails-KeyVault, which is assigned by default in ALZ. | 2 | | ||
| | [Enforce-Guardrails-Kubernetes](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-Kubernetes.html) | Enforce recommended guardrails for Kubernetes | This policy initiative is a group of policies that ensures Kubernetes is compliant per regulated Landing Zones. | 16 | | ||
| | [Enforce-Guardrails-MachineLearning](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-MachineLearning.html) | Enforce recommended guardrails for Machine Learning | This policy initiative is a group of policies that ensures Machine Learning is compliant per regulated Landing Zones. | 5 | | ||
| | [Enforce-Guardrails-MySQL](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-MySQL.html) | Enforce recommended guardrails for MySQL | This policy initiative is a group of policies that ensures MySQL is compliant per regulated Landing Zones. | 2 | | ||
| | [Enforce-Guardrails-Network](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-Network.html) | Enforce recommended guardrails for Network and Networking services | This policy initiative is a group of policies that ensures Network and Networking services is compliant per regulated Landing Zones. | 22 | | ||
| | [Enforce-Guardrails-OpenAI](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-OpenAI.html) | Enforce recommended guardrails for Open AI (Cognitive Service) | This policy initiative is a group of policies that ensures Open AI (Cognitive Services) is compliant per regulated Landing Zones. | 6 | | ||
| | [Enforce-Guardrails-PostgreSQL](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-PostgreSQL.html) | Enforce recommended guardrails for PostgreSQL | This policy initiative is a group of policies that ensures PostgreSQL is compliant per regulated Landing Zones. | 1 | | ||
| | [Enforce-Guardrails-ServiceBus](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-ServiceBus.html) | Enforce recommended guardrails for Service Bus | This policy initiative is a group of policies that ensures Service Bus is compliant per regulated Landing Zones. | 4 | | ||
| | [Enforce-Guardrails-SQL](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-SQL.html) | Enforce recommended guardrails for SQL and SQL Managed Instance | This policy initiative is a group of policies that ensures SQL and SQL Managed Instance is compliant per regulated Landing Zones. | 5 | | ||
| | [Enforce-Guardrails-Storage](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-Storage.html) | Enforce recommended guardrails for Storage Account | This policy initiative is a group of policies that ensures Storage is compliant per regulated Landing Zones. | 22 | | ||
| | [Enforce-Guardrails-Synapse](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-Synapse.html) | Enforce recommended guardrails for Synapse workspaces | This policy initiative is a group of policies that ensures Synapse is compliant per regulated Landing Zones. | 9 | | ||
| | [Enforce-Guardrails-VirtualDesktop](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-Guardrails-VirtualDesktop.html) | Enforce recommended guardrails for Virtual Desktop | This policy initiative is a group of policies that ensures Virtual Desktop is compliant per regulated Landing Zones. | 2 | | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.