last sync: 2024-Nov-25 18:54:24 UTC

Azure Database for MySQL server deploy a specific min TLS version and enforce SSL.

Azure Landing Zones (ALZ) Policy definition

Source Repository Azure Landing Zones (ALZ) GitHub
JSON Deploy-MySQL-sslEnforcement
Deploy policy Deploy-MySQL-sslEnforcement (1.2.0) to Azure
Display name Azure Database for MySQL server deploy a specific min TLS version and enforce SSL.
Id Deploy-MySQL-sslEnforcement
Version 1.2.0
Details on versioning
Category SQL
Description Deploy a specific min TLS version requirement and enforce SSL on Azure Database for MySQL server. Enforce the Server to client applications using minimum version of Tls to secure the connection between your database server and your client applications helps protect against 'man in the middle' attacks by encrypting the data stream between the server and your application. This configuration enforces that SSL is always enabled for accessing your database server.
Mode Indexed
Type Custom Azure Landing Zones (ALZ)
Preview False
Deprecated False
Effect Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
RBAC role(s)
Role Name Role Id
Contributor b24988ac-6180-42a0-ab88-20f7382dd24c
Rule aliases IF (2)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.DBforMySQL/servers/minimalTlsVersion Microsoft.DBforMySQL servers properties.minimalTlsVersion True False
Microsoft.DBforMySQL/servers/sslEnforcement Microsoft.DBforMySQL servers properties.sslEnforcement True True
THEN-ExistenceCondition (2)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.DBforMySQL/servers/minimalTlsVersion Microsoft.DBforMySQL servers properties.minimalTlsVersion True False
Microsoft.DBforMySQL/servers/sslEnforcement Microsoft.DBforMySQL servers properties.sslEnforcement True True
Rule resource types IF (1)
Microsoft.DBforMySQL/servers
THEN-Deployment (1)
Microsoft.DBforMySQL/servers
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State
[Deprecated]: Deny or Deploy and append TLS requirements and SSL enforcement on resources without Encryption in transit Enforce-EncryptTransit Encryption Deprecated
Deny or Deploy and append TLS requirements and SSL enforcement on resources without Encryption in transit Enforce-EncryptTransit_20240509 Encryption GA
History
Date/Time (UTC ymd) (i) Change type Change detail
2024-10-10 01:17:21 change Minor (1.1.0 > 1.2.0)
2023-09-27 17:59:47 change Minor (1.0.0 > 1.1.0)
JSON compare
compare mode: version left: version right:
JSON
EPAC
Deploy policy Deploy-MySQL-sslEnforcement (1.2.0) to Azure