Azure / bicep-registry-modules

Bicep registry modules
MIT License
460 stars 305 forks source link

[AVM Module Issue]: avm/ptn/security/security-center - enable required policies with defender pricing plans #2662

Open jikuja opened 2 months ago

jikuja commented 2 months ago

Check for previous/existing GitHub issues

Issue Type?

Security Bug

Module Name

avm/ptn/security/security-center

(Optional) Module Version

No response

Description

Splitted from https://github.com/Azure/bicep-registry-modules/issues/2007

Missing policy assignments

Defender for Containers

For example Defender for Containers does 4 policy assignments with remediation role assignments if enabled on on Portal, AVM does 0:

image

Defender for Servers:

Policy assignments

image

(Optional) Correlation Id

No response

microsoft-github-policy-service[bot] commented 2 months ago

[!IMPORTANT] The "Needs: Triage :mag:" label must be removed once the triage process is complete!

[!TIP] For additional guidance on how to triage this issue/PR, see the BRM Issue Triage documentation.

avm-team-linter[bot] commented 2 months ago

@jikuja, thanks for submitting this issue for the avm/ptn/security/security-center module!

[!IMPORTANT] A member of the @Azure/avm-ptn-security-securitycenter-module-owners-bicep or @Azure/avm-ptn-security-securitycenter-module-contributors-bicep team will review it soon!

microsoft-github-policy-service[bot] commented 1 month ago

[!WARNING] Tagging the AVM Core Team (@Azure/avm-core-team-technical-bicep) due to a module owner or contributor having not responded to this issue within 3 business days. The AVM Core Team will attempt to contact the module owners/contributors directly.

[!TIP]

  • To prevent further actions to take effect, the "Status: Response Overdue 🚩" label must be removed, once this issue has been responded to.
  • To avoid this rule being (re)triggered, the ""Needs: Triage :mag:" label must be removed as part of the triage process (when the issue is first responded to)!