last sync: 2025-Jul-03 17:22:55 UTC

Windows machines should meet requirements for 'Security Options - Devices'

Azure BuiltIn Policy definition

Source Azure Portal
Display name Windows machines should meet requirements for 'Security Options - Devices'
Id 8794ff4f-1a35-4e18-938f-0b22055067cd
Version 3.0.0
Details on versioning
Versioning Versions supported for Versioning: 1
3.0.0
Built-in Versioning [Preview]
Category Guest Configuration
Microsoft Learn
Description Windows machines should have the specified Group Policy settings in the category 'Security Options - Devices' for undocking without logging on, installing print drivers, and formatting/ejecting media. This policy requires that the Guest Configuration prerequisites have been deployed to the policy assignment scope. For details, visit https://aka.ms/gcpol.
Cloud environments AzureCloud = true
AzureUSGovernment = true
AzureChinaCloud = unknown
Available in AzUSGov The Policy is available in AzureUSGovernment cloud. Version: '2.0.0'
Repository: Azure-Policy 8794ff4f-1a35-4e18-938f-0b22055067cd
Mode Indexed
Type BuiltIn
Preview False
Deprecated False
Effect Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
RBAC role(s) none
Rule aliases IF (7)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.Compute/imageOffer Microsoft.Compute
Microsoft.Compute
Microsoft.Compute
virtualMachines
virtualMachineScaleSets
disks
properties.storageProfile.imageReference.offer
properties.virtualMachineProfile.storageProfile.imageReference.offer
properties.creationData.imageReference.id
True
True
True


False
False
False
Microsoft.Compute/imagePublisher Microsoft.Compute
Microsoft.Compute
Microsoft.Compute
virtualMachines
virtualMachineScaleSets
disks
properties.storageProfile.imageReference.publisher
properties.virtualMachineProfile.storageProfile.imageReference.publisher
properties.creationData.imageReference.id
True
True
True


False
False
False
Microsoft.Compute/imageSKU Microsoft.Compute
Microsoft.Compute
Microsoft.Compute
virtualMachines
virtualMachineScaleSets
disks
properties.storageProfile.imageReference.sku
properties.virtualMachineProfile.storageProfile.imageReference.sku
properties.creationData.imageReference.id
True
True
True


False
False
False
Microsoft.Compute/virtualMachines/osProfile.windowsConfiguration Microsoft.Compute virtualMachines properties.osProfile.windowsConfiguration True True
Microsoft.Compute/virtualMachines/storageProfile.osDisk.osType Microsoft.Compute virtualMachines properties.storageProfile.osDisk.osType True True
Microsoft.ConnectedVMwarevSphere/virtualMachines/osProfile.osType Microsoft.ConnectedVMwarevSphere virtualmachines properties.osProfile.osType True False
Microsoft.HybridCompute/imageOffer Microsoft.HybridCompute machines properties.osName True False
THEN-ExistenceCondition (2)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.GuestConfiguration/guestConfigurationAssignments/complianceStatus Microsoft.GuestConfiguration guestConfigurationAssignments properties.complianceStatus True False
Microsoft.GuestConfiguration/guestConfigurationAssignments/parameterHash Microsoft.GuestConfiguration guestConfigurationAssignments properties.parameterHash True False
Rule resource types IF (3)
Compliance Not a Compliance control
Initiatives usage
Rows: 1-1 / 1
Records:
Use the filters above each column to filter and limit table data. Advanced searches can be performed by using the following operators:
<, <=, >, >=, =, *, !, {, }, ||,&&, [empty], [nonempty], rgx:
Learn more

TableFilter v0.7.3

https://www.tablefilter.com/
©2015-2025 Max Guglielmi
?
Page of 1
Initiative DisplayName Initiative Id Initiative Category State Type polSet in AzUSGov
[Preview]: Windows machines should meet requirements for the Azure compute security baseline be7a78aa-3e10-4153-a5fd-8c6506dbc821 Guest Configuration Preview BuiltIn true
History
Date/Time (UTC ymd) (i) Change type Change detail
2022-01-28 17:51:01 change Major (2.0.0 > 3.0.0)
2020-09-15 14:06:41 change Previous DisplayName: [Preview]: Windows machines should meet requirements for 'Security Options - Devices'
2020-08-20 14:05:01 add 8794ff4f-1a35-4e18-938f-0b22055067cd
JSON compare
compare mode: version left: version right:
2.0.0 → 3.0.0 RENAMED
@@ -4,9 +4,9 @@
4
  "mode": "Indexed",
5
  "description": "Windows machines should have the specified Group Policy settings in the category 'Security Options - Devices' for undocking without logging on, installing print drivers, and formatting/ejecting media. This policy requires that the Guest Configuration prerequisites have been deployed to the policy assignment scope. For details, visit https://aka.ms/gcpol.",
6
  "metadata": {
7
  "category": "Guest Configuration",
8
- "version": "2.0.0",
9
  "requiredProviders": [
10
  "Microsoft.GuestConfiguration"
11
  ],
12
  "guestConfiguration": {
@@ -21,9 +21,10 @@
21
  "IncludeArcMachines": {
22
  "type": "String",
23
  "metadata": {
24
  "displayName": "Include Arc connected servers",
25
- "description": "By selecting this option, you agree to be charged monthly per Arc connected machine."
 
26
  },
27
  "allowedValues": [
28
  "true",
29
  "false"
@@ -105,9 +106,9 @@
105
  "equals": "microsoft-dsvm"
106
  },
107
  {
108
  "field": "Microsoft.Compute/imageOffer",
109
- "equals": "dsvm-windows"
110
  }
111
  ]
112
  },
113
  {
@@ -219,14 +220,34 @@
219
  "value": "[parameters('IncludeArcMachines')]",
220
  "equals": "true"
221
  },
222
  {
 
 
 
 
223
- "field": "type",
224
- "equals": "Microsoft.HybridCompute/machines"
225
- },
226
- {
227
- "field": "Microsoft.HybridCompute/imageOffer",
228
- "like": "windows*"
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
229
  }
230
  ]
231
  }
232
  ]
 
4
  "mode": "Indexed",
5
  "description": "Windows machines should have the specified Group Policy settings in the category 'Security Options - Devices' for undocking without logging on, installing print drivers, and formatting/ejecting media. This policy requires that the Guest Configuration prerequisites have been deployed to the policy assignment scope. For details, visit https://aka.ms/gcpol.",
6
  "metadata": {
7
  "category": "Guest Configuration",
8
+ "version": "3.0.0",
9
  "requiredProviders": [
10
  "Microsoft.GuestConfiguration"
11
  ],
12
  "guestConfiguration": {
 
21
  "IncludeArcMachines": {
22
  "type": "String",
23
  "metadata": {
24
  "displayName": "Include Arc connected servers",
25
+ "description": "By selecting this option, you agree to be charged monthly per Arc connected machine.",
26
+ "portalReview": "true"
27
  },
28
  "allowedValues": [
29
  "true",
30
  "false"
 
106
  "equals": "microsoft-dsvm"
107
  },
108
  {
109
  "field": "Microsoft.Compute/imageOffer",
110
+ "like": "dsvm-win*"
111
  }
112
  ]
113
  },
114
  {
 
220
  "value": "[parameters('IncludeArcMachines')]",
221
  "equals": "true"
222
  },
223
  {
224
+ "anyOf": [
225
+ {
226
+ "allOf": [
227
+ {
228
+ "field": "type",
229
+ "equals": "Microsoft.HybridCompute/machines"
230
+ },
231
+ {
232
+ "field": "Microsoft.HybridCompute/imageOffer",
233
+ "like": "windows*"
234
+ }
235
+ ]
236
+ },
237
+ {
238
+ "allOf": [
239
+ {
240
+ "field": "type",
241
+ "equals": "Microsoft.ConnectedVMwarevSphere/virtualMachines"
242
+ },
243
+ {
244
+ "field": "Microsoft.ConnectedVMwarevSphere/virtualMachines/osProfile.osType",
245
+ "like": "windows*"
246
+ }
247
+ ]
248
+ }
249
+ ]
250
  }
251
  ]
252
  }
253
  ]
JSON
api-version=2021-06-01
EPAC
{7 items}