Policy-usedHide
Records: 10 25 100 200 Use the filters above each column to filter and limit table data. Advanced searches can be performed by using the following operators:
< ,
<= ,
> ,
>= ,
= ,
* ,
! ,
{ ,
} ,
|| ,
&& ,
[empty] ,
[nonempty] ,
rgx: Learn more ? Page 1 2 of 2
Clear Azure Ai Services Cognitive Services Clear GA Clear ALZ BuiltIn
Policy DisplayName
Policy Id
Category
Effect
Roles#
Roles
State
Type
policy in AzUSGov
Azure AI Services resources should have key access disabled (disable local authentication)
71ef260a-8f18-47b7-abcb-62d0673d94dc
Azure Ai Services
Default AuditAllowed Audit, Deny, Disabled
0
GA
BuiltIn
true
Azure AI Services resources should restrict network access
037eea7a-bd0a-46c5-9a66-03aea78705d3
Azure Ai Services
Default AuditAllowed Audit, Deny, Disabled
0
GA
BuiltIn
true
Azure AI Services resources should use Azure Private Link
d6759c02-b87f-42b7-892e-71b3f471d782
Azure Ai Services
Default AuditAllowed Audit, Disabled
0
GA
BuiltIn
true
Cognitive Services accounts should use a managed identity
fe3fd216-4f83-4fc1-8984-2bbec80a3418
Cognitive Services
Default AuditAllowed Audit, Deny, Disabled
0
GA
BuiltIn
unknown
Cognitive Services accounts should use customer owned storage
46aa9b05-0e60-4eae-a88b-1e9d374fa515
Cognitive Services
Default AuditAllowed Audit, Deny, Disabled
0
GA
BuiltIn
unknown
Configure Azure AI Services resources to disable local key access (disable local authentication)
d45520cb-31ca-44ba-8da2-fcf914608544
Azure Ai Services
Default DeployIfNotExistsAllowed DeployIfNotExists, Disabled
3
Cognitive Services Contributor , Cognitive Services OpenAI Contributor , Search Service Contributor
GA
BuiltIn
unknown
Configure Azure AI Services resources to disable local key access (disable local authentication)
55eff01b-f2bd-4c32-9203-db285f709d30
Azure Ai Services
Default DeployIfNotExistsAllowed DeployIfNotExists, Disabled
2
Cognitive Services Contributor , Cognitive Services OpenAI Contributor
GA
BuiltIn
unknown
Configure Cognitive Services accounts to disable local authentication methods
14de9e63-1b31-492e-a5a3-c3f7fd57f555
Cognitive Services
Default ModifyAllowed Modify, Disabled
1
Contributor
GA
BuiltIn
unknown
Diagnostic logs in Azure AI services resources should be enabled
1b4d1c4e-934c-4703-944c-27c82c06bebb
Azure Ai Services
Default AuditIfNotExistsAllowed AuditIfNotExists, Disabled
0
GA
BuiltIn
true
Network ACLs should be restricted for Cognitive Services
Deny-CognitiveServices-NetworkAcls
Cognitive Services
Default DenyAllowed Audit, Deny, Disabled
0
GA
ALZ
Outbound network access should be restricted for Cognitive Services
Deny-CognitiveServices-RestrictOutboundNetworkAccess
Cognitive Services
Default DenyAllowed Audit, Deny, Disabled
0
GA
ALZ
No results
JSON
Copy definition Copy definition 4 EPAC EPAC
{ 7 items policyType: "Custom" , displayName: "Enforce recommended guardrails for Open AI (Cognitive Service)" , description: "This policy initiative is a group of policies that ensures Open AI (Cognitive Service) is compliant per regulated Landing Zones." , metadata: { 4 items version: "1.2.0" , category: "Cognitive Services" , source: "https://github.com/Azure/Enterprise-Scale/" , alzCloudEnvironments: [ 3 items "AzureCloud" , "AzureChinaCloud" , "AzureUSGovernment" ] } , parameters: { 11 items cognitiveServicesOutboundNetworkAccess: { 3 items } , cognitiveServicesNetworkAcls: { 3 items } , cognitiveServicesModifyDisableLocalAuth: { 3 items } , cognitiveServicesDisableLocalAuth: { 3 items } , cognitiveServicesCustomerStorage: { 3 items } , cognitiveServicesManagedIdentity: { 3 items } , azureAiNetworkAccess: { 3 items } , azureAiPrivateLink: { 3 items } , azureAiDisableLocalKey: { 3 items } , azureAiDisableLocalKey2: { 3 items } , azureAiDiagSettings: { 3 items } } , policyDefinitions: [ 11 items { 5 items policyDefinitionId: "/providers/Microsoft.Management/managementGroups/contoso/providers/Microsoft.Authorization/policyDefinitions/Deny-CognitiveServices-RestrictOutboundNetworkAccess" , policyDefinitionReferenceId: "Deny-OpenAi-OutboundNetworkAccess" , definitionVersion: "1.*.*" , groupNames: [] , parameters: { 1 item effect: { 1 item value: "[parameters('cognitiveServicesOutboundNetworkAccess')]" } } } , { 5 items policyDefinitionId: "/providers/Microsoft.Management/managementGroups/contoso/providers/Microsoft.Authorization/policyDefinitions/Deny-CognitiveServices-NetworkAcls" , policyDefinitionReferenceId: "Deny-OpenAi-NetworkAcls" , definitionVersion: "1.*.*" , groupNames: [] , parameters: { 1 item } } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } ] , policyDefinitionGroups: null }