Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium
A security administrator is setting up a new Azure subscription for a development team. They need to ensure that all virtual machines provisioned in this subscription automatically have Microsoft Defender for Cloud's endpoint protection enabled. Manual configuration for each VM is not feasible due to the dynamic nature of the environment. Which Azure Policy effect should they use to achieve this?
- AModify
- BAudit
- CDeployIfNotExists
- DDeny
Show answer & explanationAnswer & explanation
Correct answer: C. DeployIfNotExists
The DeployIfNotExists effect in Azure Policy is used to deploy a specific resource or template if a compliant resource (in this case, Defender for Cloud endpoint protection) is not found during evaluation.
Why the other options are wrong
- A. Modify is used to add, update, or remove properties or tags on resources, not to deploy entirely new configurations like endpoint protection.
- B. Audit only reports non-compliance, it does not remediate or deploy resources.
- D. Deny prevents the deployment of non-compliant resources, but doesn't enable protection on existing or newly deployed ones.
Azure Policy DeployIfNotExists
The 'DeployIfNotExists' effect in Azure Policy automatically deploys a specified resource or template when a non-compliant resource is identified, ensuring compliance by adding missing configurations.
- Used for automated remediation.
- Deploys resources or configurations if they are missing.
- Requires a managed identity for deployment actions.
Memory trick: Audit reports, Deny stops, DeployIfNotExists adds, Modify changes.