Azure / Enterprise-Scale

The Azure Landing Zones (Enterprise-Scale) architecture provides prescriptive guidance coupled with Azure best practices, and it follows design principles across the critical design areas for organizations to define their Azure architecture
https://aka.ms/alz
MIT License
1.69k stars 963 forks source link

[AWARENESS] Defender for APIs error #1606

Closed Springstone closed 4 months ago

Springstone commented 6 months ago

Describe the bug

Due to plan changes for the Defender for APIs, the portal accelerator will show an error when trying to enable the Defender for APIs feature, as it now requires a sub plan to be defined. We're busy investigating how to proceed, as this plan seems to have a minimum monthly cost even if not using APIs.

Please let us know if you have run into this issue and it is impacting you.

pkorolo commented 5 months ago

@Springstone at least one CMF engineer had this issue while deploying to end Cx environment. I have instructed to report here as well.

Springstone commented 5 months ago

Update: we have a good relationship with the owning PG and have a way forward in the short term.

We will be enabling sub plan P1 as part of the initial ALZ deployment but will need to remove the policy that configures Defender for APIs at scale - as this policy currently no longer works. PG is working on new policies to support scale configuration of Defender for API targeting Q1 FY25.

Springstone commented 4 months ago

Closing this issue as we have a workaround that is already in the policy-refresh branch and will go live in the coming weeks.