官术网_书友最值得收藏!

  • Learn Azure Administration
  • Kamil Mrzyg?ód
  • 368字
  • 2021-06-11 18:14:28

Getting started with Azure Policy

To get started, we will have to actually create a policy. The process of assigning a policy is quite simple and can be covered by the following steps:

  1. Search for the Subscriptions blade—the easiest way to do so is to use the search field at the top of the Azure portal, as shown in the following screenshot:
Figure 1.7 - Searching for the Subscriptions blade
  1. Select the subscription you are interested in. The last thing you need to do is to click on the Policies blade:
FIgure 1.8 - The Policies blade 
  1. Click on the Assign policy button, which will display a form where you can define how the policy should work:

Figure 1.9 - The Assign policy button
  1. Assign a policy and configure the appropriate fields as follow: set the Scope of your subscription (in my case, it is Pay-As-You-Go) and leave the exclusions empty and the policy definition as Not allowed resource types. Remember that you can select either a built-in or a custom policy (if you have one).
  2. Initially, the compliance state may be displayed as Not registered as in the following screenshot. Wait a few minutes before proceeding:
Figure 1.10 - Created policies view
  1. If this status is diplayed longer than a few minutes, make sure a proper resource provider for the policies is registered. To do so, go to the Resource providers blade and check the status of the provider:
Figure 1.11 - Subscription resource providers
  1. Once the status is displayed as Registered, you can test the results. Try to perform a forbidden action (such as creating a forbidden resource type). If you do so, you will see a result similar to the following:
Figure 1.12 - Validation error

When a policy is enabled and working, it constantly monitors your resources against configured parameters. Depending on its configuration, it may either block deploying particular services or enforce a specific naming convention. An audit policy can report on non-compliant resources and, with enforcement mode enabled, can deny the creation of resources that don't comply with the policy.

Let's now check what a policy validation result may look like.

主站蜘蛛池模板: 新乡市| 兖州市| 施甸县| 曲周县| 开鲁县| 普兰店市| 内乡县| 珠海市| 来凤县| 津市市| 东阿县| 成都市| 松滋市| 长沙县| 南岸区| 东安县| 内黄县| 凤翔县| 韩城市| 乌鲁木齐市| 九寨沟县| 兴山县| 周口市| 左贡县| 巴南区| 汾阳市| 治多县| 禹城市| 墨玉县| 青浦区| 鹤山市| 秦皇岛市| 元氏县| 淳化县| 永嘉县| 江华| 孝昌县| 武乡县| 绵竹市| 剑河县| 永寿县|