Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudMedium
A company is onboarding a new Azure subscription to Microsoft Defender for Cloud. They have a strict compliance requirement to ensure that all newly created Azure SQL Servers automatically have Microsoft Defender for SQL enabled. They want to implement this using an Azure Policy that will automatically remediate non-compliant resources. Which Azure Policy effect should the security engineer use to fulfill this requirement?
- AAudit
- BDisable
- CDeny
- DDeployIf NotExists
Show answer & explanationAnswer & explanation
Correct answer: D. DeployIf NotExists
The 'DeployIf NotExists' effect in Azure Policy is used to deploy a resource or modify a setting if a specified condition is not met. This is ideal for automatically enabling Defender for SQL on non-compliant SQL Servers.
Why the other options are wrong
- A. Audit only reports non-compliance without taking any action, which doesn't meet the automatic enablement requirement.
- B. Disable temporarily disables a policy definition or assignment, which is not for enforcing compliance.
- C. Deny prevents the creation or modification of non-compliant resources, which is too restrictive for automatic remediation.
Azure Policy 'DeployIf NotExists'
The 'DeployIf NotExists' effect in Azure Policy is used to automatically deploy a resource (e.g., enable a security setting, deploy an extension) or modify an existing resource if a specified condition is not met on the target resource.
- Used for automatic remediation of non-compliant resources.
- Requires a managed identity for deployment/modification actions.
- Commonly used to enforce security baselines or enable Defender features.
Memory trick: If it's not there, deploy it there, to keep compliance in the air.