Policy-usedHide
Records: 10 25 100 200 Use the filters above each column to filter and limit table data. Advanced searches can be performed by using the following operators:
< ,
<= ,
> ,
>= ,
= ,
* ,
! ,
{ ,
} ,
|| ,
&& ,
[empty] ,
[nonempty] ,
rgx: Learn more ? Page 1 2 of 2
Clear App Service Clear GA Clear ALZ BuiltIn
Policy DisplayName
Policy Id
Category
Effect
Roles#
Roles
State
Type
policy in AzUSGov
App Service app slots should enable configuration routing to Azure Virtual Network
5747353b-1ca9-42c1-a4dd-b874b894f3d4
App Service
Default AuditAllowed Audit, Deny, Disabled
0
GA
BuiltIn
unknown
App Service app slots should enable outbound non-RFC 1918 traffic to Azure Virtual Network
f5c0bfb3-acea-47b1-b477-b0edcdf6edc1
App Service
Default AuditAllowed Audit, Deny, Disabled
0
GA
BuiltIn
unknown
App Service apps should enable configuration routing to Azure Virtual Network
801543d1-1953-4a90-b8b0-8cf6d41473a5
App Service
Default AuditAllowed Audit, Deny, Disabled
0
GA
BuiltIn
unknown
App Service apps should enable outbound non-RFC 1918 traffic to Azure Virtual Network
a691eacb-474d-47e4-b287-b4813ca44222
App Service
Default AuditAllowed Audit, Deny, Disabled
0
GA
BuiltIn
unknown
App Service apps should use a SKU that supports private link
546fe8d2-368d-4029-a418-6af48a7f61e5
App Service
Default AuditAllowed Audit, Deny, Disabled
0
GA
BuiltIn
unknown
App Service certificates must be stored in Key Vault
Deny-AppService-without-BYOC
App Service
Default AuditAllowed Audit, Deny, Disabled
0
GA
ALZ
App Service Environment should be provisioned with latest versions
eb4d34ab-0929-491c-bbf3-61e13da19f9a
App Service
Default AuditAllowed Audit, Deny, Disabled
0
GA
BuiltIn
true
Configure App Service app slots to disable local authentication for SCM sites
2c034a29-2a5f-4857-b120-f800fe5549ae
App Service
Default DeployIfNotExistsAllowed DeployIfNotExists, Disabled
1
Website Contributor
GA
BuiltIn
true
Configure App Service app slots to disable public network access
c6c3e00e-d414-4ca4-914f-406699bb8eee
App Service
Default ModifyAllowed Modify, Disabled
3
Managed Identity Operator , Network Contributor , Website Contributor
GA
BuiltIn
true
Configure App Service app slots to turn off remote debugging
cca5adfe-626b-4cc6-8522-f5b6ed2391bd
App Service
Default DeployIfNotExistsAllowed DeployIfNotExists, Disabled
1
Website Contributor
GA
BuiltIn
true
Configure App Service apps to disable local authentication for FTP deployments
572e342c-c920-4ef5-be2e-1ed3c6a51dc5
App Service
Default DeployIfNotExistsAllowed DeployIfNotExists, Disabled
1
Website Contributor
GA
BuiltIn
true
Configure App Service apps to disable local authentication for SCM sites
5e97b776-f380-4722-a9a3-e7f0be029e79
App Service
Default DeployIfNotExistsAllowed DeployIfNotExists, Disabled
1
Website Contributor
GA
BuiltIn
true
Configure App Service apps to disable public network access
2374605e-3e0b-492b-9046-229af202562c
App Service
Default ModifyAllowed Modify, Disabled
3
Managed Identity Operator , Network Contributor , Website Contributor
GA
BuiltIn
true
Configure App Service apps to only be accessible over HTTPS
0f98368e-36bc-4716-8ac2-8f8067203b63
App Service
Default ModifyAllowed Modify, Disabled
1
Website Contributor
GA
BuiltIn
true
Configure App Service apps to turn off remote debugging
a5e3fe8f-f6cd-4f1d-bbf6-c749754a724b
App Service
Default DeployIfNotExistsAllowed DeployIfNotExists, Disabled
1
Website Contributor
GA
BuiltIn
unknown
Configure Function app slots to disable public network access
242222f3-4985-4e99-b5ef-086d6a6cb01c
App Service
Default ModifyAllowed Modify, Disabled
3
Managed Identity Operator , Network Contributor , Website Contributor
GA
BuiltIn
true
Configure Function app slots to only be accessible over HTTPS
08cf2974-d178-48a0-b26d-f6b8e555748b
App Service
Default ModifyAllowed Modify, Disabled
1
Website Contributor
GA
BuiltIn
true
Configure Function app slots to turn off remote debugging
70adbb40-e092-42d5-a6f8-71c540a5efdb
App Service
Default DeployIfNotExistsAllowed DeployIfNotExists, Disabled
1
Website Contributor
GA
BuiltIn
true
Configure Function apps to turn off remote debugging
25a5046c-c423-4805-9235-e844ae9ef49b
App Service
Default DeployIfNotExistsAllowed DeployIfNotExists, Disabled
1
Website Contributor
GA
BuiltIn
true
No results
JSON
Copy definition Copy definition 4 EPAC EPAC
{ 7 items policyType: "Custom" , displayName: "Enforce recommended guardrails for App Service" , description: "This policy initiative is a group of policies that ensures App Service is compliant per regulated Landing Zones." , metadata: { 4 items version: "1.1.0" , category: "App Service" , source: "https://github.com/Azure/Enterprise-Scale/" , alzCloudEnvironments: [ 3 items "AzureCloud" , "AzureChinaCloud" , "AzureUSGovernment" ] } , parameters: { 18 items functionAppDebugging: { 3 items } , appServiceDisableLocalAuth: { 3 items } , appServiceSkuPl: { 3 items } , appServiceDisableLocalAuthFtp: { 3 items } , appServiceRouting: { 3 items } , appServiceScmAuth: { 3 items } , appServiceRfc: { 3 items } , appServiceAppsRfc: { 3 items } , appServiceAppsVnetRouting: { 3 items } , appServiceEnvLatestVersion: { 3 items } , appServiceAppSlotsRemoteDebugging: { 3 items } , appServiceAppsRemoteDebugging: { 3 items } , appServiceByoc: { 3 items } , functionAppSlotsModifyHttps: { 3 items } , appServiceAppHttps: { 3 items } , functionAppSlotsModifyPublicNetworkAccess: { 3 items } , appServiceAppsModifyPublicNetworkAccess: { 3 items } , appServiceAppModifyPublicNetworkAccess: { 3 items } } , policyDefinitions: [ 19 items { 5 items policyDefinitionId: "/providers/Microsoft.Management/managementGroups/contoso/providers/Microsoft.Authorization/policyDefinitions/Deny-AppService-without-BYOC" , policyDefinitionReferenceId: "Deny-AppService-Byoc" , definitionVersion: "1.*.*" , groupNames: [] , parameters: { 1 item } } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } ] , policyDefinitionGroups: null }