The Azure Landing Zones (Enterprise-Scale) architecture provides prescriptive guidance coupled with Azure best practices, and it follows design principles across the critical design areas for organizations to define their Azure architecture
is missing a parameter for effect on policy id 766e621d-ba95-4e43-a6f2-e945db3d7888 (Setup subscriptions to transition to an alternative vulnerability assessment solution)
The default is DeployifNotExists but if we don't use an external assesment provider I want to have a chance to change the value to Disabled
@sweprs thanks for raising the issue. Was just updating this initiative, so have added the parameter you requested. Will be part of the January refresh.
Describe the solution you'd like
The iniative: https://github.com/Azure/Enterprise-Scale/blob/main/src/resources/Microsoft.Authorization/policySetDefinitions/Deploy-MDFC-Config_20240319.json
is missing a parameter for effect on policy id 766e621d-ba95-4e43-a6f2-e945db3d7888 (Setup subscriptions to transition to an alternative vulnerability assessment solution)
The default is DeployifNotExists but if we don't use an external assesment provider I want to have a chance to change the value to Disabled