last sync: 2024-Nov-25 18:54:24 UTC

Azure Active Directory should use private link to access Azure services

Azure BuiltIn Policy definition

Source Azure Portal
Display name Azure Active Directory should use private link to access Azure services
Id 2e9411a0-0c5a-44b3-9ddb-ff10a1a2bf28
Version 1.0.0
Details on versioning
Versioning Versions supported for Versioning: 1
1.0.0
Built-in Versioning [Preview]
Category Azure Active Directory
Microsoft Learn
Description Azure Private Link lets you connect your virtual networks to Azure services without a public IP address at the source or destination. The Private Link platform handles the connectivity between the consumer and services over the Azure backbone network. By mapping private endpoints to Azure AD, you can reduce data leakage risks. Learn more at: https://aka.ms/privateLinkforAzureADDocs. It should be only used from isolated VNETs to Azure services, with no access to the Internet or other services (M365).
Mode Indexed
Type BuiltIn
Preview False
Deprecated False
Effect Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
RBAC role(s) none
Rule aliases THEN-ExistenceCondition (1)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
microsoft.aadiam/privateLinkForAzureAD/privateEndpointConnections/privateLinkServiceConnectionState.status microsoft.aadiam privateLinkForAzureAD/privateEndpointConnections properties.privateLinkServiceConnectionState.status True False
Rule resource types IF (1)
Microsoft.aadiam/privateLinkForAzureAD
Compliance Not a Compliance control
Initiatives usage none
History
Date/Time (UTC ymd) (i) Change type Change detail
2022-07-22 16:34:49 add 2e9411a0-0c5a-44b3-9ddb-ff10a1a2bf28
JSON compare n/a
JSON
api-version=2021-06-01
EPAC