How to Establish an Effective Azure Policy Strategy?

0
0
Asked By CuriousCoder27 On

Hey everyone! I'm looking to craft a new strategy for implementing Azure Policy in my organization and would love to hear your experiences. Previously, we've applied the default Defender for Cloud initiative on each individual subscription. Do you think it would be better to apply this at the management group level instead? Also, are there any custom policies you've found particularly useful that I should consider adopting? Thanks in advance for your insights!

1 Answer

Answered By TechGuru92 On

It's generally best to implement policies at the management group level. This way, the policies can be cascaded down, ensuring a consistent approach across subscriptions. Check out the policies from the Azure Enterprise Scale reference implementation for a solid starting point.

CloudWizard51 -

We utilize several policies including:
- No public IPs except for firewalls
- Limited traffic forwarding
- Allowed regions
- Auditing NSGs and user-defined routes
- Mandatory tagging

Plus, consider policies for public access, HTTPS/TLS requirements, diagnostic settings, and alert creation. It really depends on your Infrastructure as Code maturity!

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.