Sacha Narinx
Sacha Narinx
policy_definition_es_deploy_diagnostics_*.json policies shouldn't have hardcoded existence condition
Closing this as we've deprecated all our diagnostic settings policies and shifted to the PG owned initiative to do the same. Please review https://aka.ms/alz/whatsnew for details.
@brianlo-ms have you reviewed https://github.com/Azure/Enterprise-Scale/wiki/Deploying-ALZ-Platform-DevOps#operating-the-azure-platform-using-azops-infrastructure-as-code-with-github-actions? AzOps is no longer part of this repository, and our recommended approaches for infra-as-code for landing zones is either ALZ Bicep or ALZ Terraform. AzOps...
@brianlo-ms did we answer your question?
@robsissons-contino thanks for raising this issue. This has been a gap since early 2024 when the product group changed the APIs for Defender for API as it transitioned from free...
@AErmie thanks for raising the issue. Those custom roles are from before my time, @jtracey93 do you have any thoughts?
@Greg-Court thanks for raising this issue: All resources will be transitioning to resource specific logging (away from logging to the same core tables) however, this will take time to adopt...
Closing this as we've deprecated all our diagnostic settings policies and shifted to the PG owned initiative to do the same. Please review https://aka.ms/alz/whatsnew for details.
@steph409 you can't change the provider, which is why it is hardcoded, and this is why we've "defaulted" to `DeployIfNotExists`. Are you looking to `Disable` this? (as stated, you can't...
@NucLabs thanks for raising your concern. We are aware of the issues in this space and are transitioning to a more comprehensive solution in the near term. This is a...
There are a new set of policies and initiatives coming soon, 412 policies and 6 initiatives, covering 137 Azure services and a set depending on the log target (Log Analytics,...