-
Notifications
You must be signed in to change notification settings - Fork 145
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update securityCenter.bicep module API provider to prevent warnings #560
Conversation
Proposed changes involve adding a default policyAssignment that originates from the policy initiative "Azure Security Benchmark" and is named "ASC Default" - this has been tested and it has shown that the deployment completes successfully and proves to be idempotent in nature; updating as needed to ensure a consistent baseline policy initiative assignment. Slightly new resource type designation but will create the same policy assignment consistently: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
To verify this I deployed the main branch to a subscription with deployASC=true
. Then I deployed this PR branch to another subscription with deployASC=true
. I compared the policy assignments of the two subscriptions and they are almost exactly the same. The difference was an additional policy included in the default initiative, but I'm assuming that's due to using a documented and current API, which is a good thing. Everything about ASC being enabled looks the same as before, except no warnings. 🎆 👍 🎉
Description
removed invalid parameters in securityCenter.bicep


Tested and observed "ASC Default" policies being applied upon initialization of ASC on account.
Also observed the set-hub-sub-security-center deployment completing successfully:
No warnings are occurring and this appears to be behaving as expected.
Issue reference
The issue this PR will close: #485
Checklist
Please make sure you've completed the relevant tasks for this PR out of the following list: