Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

"Configure Microsoft Defender for Azure Cosmos DB to be enabled" Built In Policy Does Not Exist In "Deploy Microsoft Defender for Cloud configuration" Initiative #1081

Closed
dburlinson opened this issue Oct 12, 2022 · 7 comments · Fixed by #1100
Assignees
Labels
engineering engineering work enhancement New feature or request policy Status: Fixed

Comments

@dburlinson
Copy link
Contributor

dburlinson commented Oct 12, 2022

I notice that "Configure Microsoft Defender for Azure Cosmos DB to be enabled" built in policy does not exist in the "Deploy Microsoft Defender for Cloud configuration" initiative. It's the only one missing. Shouldn't it be added?

/providers/Microsoft.Authorization/policyDefinitions/82bf5b87-728b-4a74-ba4d-6123845cf542

@ghost ghost added the Needs: Triage 🔍 Needs triaging by the team label Oct 12, 2022
@jtracey93 jtracey93 added enhancement New feature or request policy engineering engineering work Needs: Author Feedback and removed Needs: Triage 🔍 Needs triaging by the team labels Oct 12, 2022
@jtracey93 jtracey93 self-assigned this Oct 12, 2022
@jtracey93
Copy link
Collaborator

Great spot @dburlinson.

We will get that fixed ASAP, or would you like to contribute (we love community contributions🥰)?

Should just be a PR to update this file: https://github.com/Azure/Enterprise-Scale/blob/main/src/resources/Microsoft.Authorization/policySetDefinitions/Deploy-MDFC-Config.json

As it's only supported in Azure Public today as per: https://learn.microsoft.com/en-us/azure/defender-for-cloud/concept-defender-for-cosmos#availability

Let us know either way and we can get it dealt with 👍

@ghost
Copy link

ghost commented Oct 17, 2022

This issue has been automatically marked as stale because it has been marked as requiring author feedback but has not had any activity for 5 days.

@dburlinson
Copy link
Contributor Author

Thanks Jack. Sorry for my slow reply, been a busy few days.

Please leave with me to contribute. Seems simple enough!

@ghost ghost added Needs: Attention 👋 Needs attention from the maintainers and removed Needs: Author Feedback Status: No Recent Activity labels Oct 17, 2022
@jtracey93
Copy link
Collaborator

Hey @dburlinson, no worries at all. Ill assign this to you now. Please let me know if you need any assistance.

I will check back in with you in 1 week to see how you are getting on if I haven't seen a PR by then 👍

Thanks

Jack

@jtracey93 jtracey93 added Needs: Author Feedback and removed Needs: Attention 👋 Needs attention from the maintainers labels Oct 18, 2022
@ghost
Copy link

ghost commented Oct 23, 2022

This issue has been automatically marked as stale because it has been marked as requiring author feedback but has not had any activity for 5 days.

@jtracey93
Copy link
Collaborator

Hey @dburlinson,

any updates on this one or anything we can do to assist?

Let us know

Thanks

Jack

@dburlinson
Copy link
Contributor Author

Hey @jtracey93

PR coming in next day or so

I've modified these files, just need to test and check there's no other files that need updating.

Thanks

Dave

@ghost ghost added Needs: Attention 👋 Needs attention from the maintainers and removed Needs: Author Feedback labels Oct 24, 2022
@jtracey93 jtracey93 removed the Needs: Attention 👋 Needs attention from the maintainers label Oct 25, 2022
jtracey93 added a commit that referenced this issue Nov 1, 2022
* Fixes issue 1081 by enabling defender for cosmos

* Auto-update Portal experience [dburlinson/fa0840c5]

* update assignment

* portal arm template update

* update test params

* update portal

* update whats new

Co-authored-by: David Burlinson <david.burlinson@microsoft.com>
Co-authored-by: github-actions <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jack Tracey <41163455+jtracey93@users.noreply.github.com>
@ghost ghost added the Status: Fixed label Nov 1, 2022
@ghost ghost locked as resolved and limited conversation to collaborators Dec 1, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
engineering engineering work enhancement New feature or request policy Status: Fixed
Projects
None yet
2 participants