-
Notifications
You must be signed in to change notification settings - Fork 1.1k
Policy Refresh H1FY26 #2105
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
Springstone
wants to merge
8
commits into
main
Choose a base branch
from
policy-refresh-h1fy26
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Policy Refresh H1FY26 #2105
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
jtracey93
requested changes
Dec 15, 2025
Collaborator
jtracey93
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Some comments - also see my ping in teams about some more policies we may want to add.
Also lets merge this PR first and completing the release before we get to moving the wiki in this other PR Azure/Azure-Landing-Zones#165
src/resources/Microsoft.Authorization/policySetDefinitions/Enforce-Guardrails-Kubernetes.json
Outdated
Show resolved
Hide resolved
src/resources/Microsoft.Authorization/policySetDefinitions/Enforce-Guardrails-Kubernetes.json
Outdated
Show resolved
Hide resolved
eslzArm/managementGroupTemplates/policyAssignments/DINE-ASB2PolicyAssignment.json
Show resolved
Hide resolved
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This pull request introduces several updates and improvements to Azure Landing Zones policies and documentation, with a focus on security benchmarking, compliance, and Kubernetes deprecation detection. The most significant changes include the addition of the Microsoft Cloud Security Benchmark v2 initiative, updates to existing policy definitions, and new custom policies to improve compliance and security posture.
Policy and Initiative Updates:
e3ec7e09-768c-4b64-882c-fcada3772047), including ARM template changes to assign this initiative by default at the intermediate root management group scope if Defender for Cloud and Log Analytics are enabled. This allows customers to evaluate and prepare for the transition to the new security benchmark. [1] [2] [3] [4] [5]New and Updated Policy Definitions:
Audit-AKS-kubenetto detect AKS clusters using the deprecated 'kubenet' network plugin, with default effect set to "Audit". This policy is included in the "Enforce-Guardrails-Kubernetes" initiative. [1] [2]Deny-FileServices-InsecureSmbChannelto version 2.0.0, improving compliance checks for storage accounts created with maximum compatibility. [1] [2]Deny-FileServices-InsecureSmbVersionsto version 1.1.0, adding checks for storage accounts withprotocolSettings.smb.versionsset tonullto ensure accurate compliance reporting.Documentation Improvements:
These changes help keep Azure Landing Zones up-to-date with evolving security standards and provide customers with improved tools for compliance and governance.