Policy DisplayName |
Policy Id |
Category |
Effect |
Roles# |
Roles |
State |
Enable logging by category group for Apache Spark pools (microsoft.synapse/workspaces/bigdatapools) to Storage |
a6d488fc-3520-4ec8-9cf6-c5e78d677651 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for API Management services (microsoft.apimanagement/service) to Storage |
6f3f5778-f809-4755-9d8f-bd5a5a7add85 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for App Configuration (microsoft.appconfiguration/configurationstores) to Storage |
2e8a8853-917a-4d26-9c3a-c92a7fa031e8 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for App Service Environments (microsoft.web/hostingenvironments) to Storage |
bfc6b185-2af1-4998-a32e-c0144792eeb2 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Attestation providers (microsoft.attestation/attestationproviders) to Storage |
39741c6f-5e8b-4511-bba4-6662d0e0e2ac |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Automation Accounts (microsoft.automation/automationaccounts) to Storage |
07c818eb-df75-4465-9233-6a8667e86670 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for AVS Private clouds (microsoft.avs/privateclouds) to Storage |
50cebe4c-8021-4f07-bcb2-6c80622444a9 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Azure AD Domain Services (microsoft.aad/domainservices) to Storage |
9c79e60b-99f2-49f3-b08c-630d269bddc1 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Azure Cache for Redis (microsoft.cache/redis) to Storage |
d3e11828-02c8-40d2-a518-ad01508bb4d7 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Azure Cosmos DB accounts (microsoft.documentdb/databaseaccounts) to Storage |
0fcf2d91-8951-43be-9505-ab43dee2f580 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Azure Data Explorer Clusters (microsoft.kusto/clusters) to Storage |
2137dd9f-94ac-413f-93a8-d068966308c9 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Azure FarmBeats (microsoft.agfoodplatform/farmbeats) to Storage |
0f708273-cf83-4d29-b31b-ebaf8d0eb8c2 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Azure Load Testing (microsoft.loadtestservice/loadtests) to Storage |
1c5187ed-9863-4961-bb92-c72bc3883e24 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Azure Machine Learning (microsoft.machinelearningservices/workspaces) to Storage |
a8de4d0a-d637-4684-b70e-6df73b74d117 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Azure Managed Grafana (microsoft.dashboard/grafana) to Storage |
a78631da-8506-4113-96f4-2805de193083 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Azure Synapse Analytics (microsoft.synapse/workspaces) to Storage |
96abcdc6-3c5a-4b0f-b031-9a4c1f36c9a6 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Bastions (microsoft.network/bastionhosts) to Storage |
be9259e2-a221-4411-84fd-dd22c6691653 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Batch accounts (microsoft.batch/batchaccounts) to Storage |
40f0d036-d73d-45a9-8c3d-f3f84d227193 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Caches (microsoft.cache/redisenterprise/databases) to Storage |
e76ef589-c7d6-42cf-a61a-13471f6f50cd |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Chaos Experiments (microsoft.chaos/experiments) to Storage |
1cd30d13-d34c-4cb8-8f9d-4692f7d40d97 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Code Signing Accounts (microsoft.codesigning/codesigningaccounts) to Storage |
42e5ad1f-57fd-49a7-b0e4-c7a7ae25ba3d |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Cognitive Services (microsoft.cognitiveservices/accounts) to Storage |
14e81583-c89c-47db-af0d-f9ddddcccd9f |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Container Apps Environments (microsoft.app/managedenvironments) to Storage |
a26c842f-bee7-4a1f-9ae1-a973d3a0075a |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Container registries (microsoft.containerregistry/registries) to Storage |
106cd3bd-50a1-466c-869f-f9c2d310477b |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Dedicated SQL pools (microsoft.synapse/workspaces/sqlpools) to Storage |
f7407db8-e40d-4efd-9fff-c61298e01fd5 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Dev centers (microsoft.devcenter/devcenters) to Storage |
a474a6be-35da-4c8a-ae97-f97d03bbd213 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Event Grid Domains (microsoft.eventgrid/domains) to Storage |
03a087c0-b49f-4440-9ae5-013703eccc8c |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Event Grid Partner Namespaces (microsoft.eventgrid/partnernamespaces) to Storage |
f873a711-0322-4744-8322-7e62950fbec2 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Event Grid Topics (microsoft.eventgrid/topics) to Storage |
fcfe6bfa-dd36-40ef-ab2b-ed46f7d4abdb |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Event Hubs Namespaces (microsoft.eventhub/namespaces) to Storage |
e20f31d7-6b6d-4644-962a-ae513a85ab0b |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Front Door and CDN profiles (microsoft.cdn/profiles) to Storage |
9f4e810a-899e-4e5e-8174-abfcf15739a3 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Front Door and CDN profiles (microsoft.network/frontdoors) to Storage |
d147ba9f-3e17-40b1-9c23-3bca478ba804 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for IoT Hub (microsoft.devices/iothubs) to Storage |
94d707a8-ce27-4851-9ce2-07dfe96a095b |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Key vaults (microsoft.keyvault/vaults) to Storage |
edf35972-ed56-4c2f-a4a1-65f0471ba702 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Live events (microsoft.media/mediaservices/liveevents) to Storage |
17f18067-406f-49b2-84ce-d1eb66c3fc75 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Log Analytics workspaces (microsoft.operationalinsights/workspaces) to Storage |
fe85de62-a656-4b79-9d94-d95c89319bd9 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Managed CCF Apps (microsoft.confidentialledger/managedccfs) to Storage |
0eb11858-8d9f-4525-b9ab-cc5eab07d27a |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Managed HSMs (microsoft.keyvault/managedhsms) to Storage |
5a6186f9-04a4-4320-b6ed-a1c3f2ebbc3b |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Media Services (microsoft.media/mediaservices) to Storage |
0925a080-ab8d-44a1-a39c-61e184b4d8f9 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Microsoft Purview accounts (microsoft.purview/accounts) to Storage |
fc66c506-9397-485e-9451-acc1525f0070 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for microsoft.azuresphere/catalogs to Storage |
9b6f89db-876b-4156-9f9b-f29dcf302ad2 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for microsoft.community/communitytrainings to Storage |
2eb903dd-4881-4284-a31d-4bae3f053946 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for microsoft.dbformysql/flexibleservers to Storage |
95f9d29c-defd-4387-b73b-5cdb4a982bf0 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for microsoft.dbforpostgresql/flexibleservers to Storage |
499b7900-f44e-40ea-b8d3-2f3cf75f2ca4 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for microsoft.documentdb/cassandraclusters to Storage |
0bb5a1fb-b1ad-45fd-880e-a590f2ec8d1c |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for microsoft.documentdb/mongoclusters to Storage |
10e8c93c-658d-47e8-aa6f-ed60f329c060 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for microsoft.machinelearningservices/registries to Storage |
84d8a69f-788a-4025-ba96-f36406cc9ee5 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for microsoft.network/networkmanagers/ipampools to Storage |
28e2d787-b5f4-43cf-8cb7-11b54773d379 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for microsoft.network/p2svpngateways to Storage |
00ec9865-beb6-4cfd-82ed-bd8f50756acd |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for microsoft.networkanalytics/dataproducts to Storage |
aa78af66-1659-40aa-90b0-b35b616adbdc |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for microsoft.notificationhubs/namespaces/notificationhubs to Storage |
ebd6e41f-c33e-4e16-9249-cee4c68e6e8c |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for microsoft.synapse/workspaces/kustopools to Storage |
5a1fa110-16bc-49d0-a045-29a552b67cef |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for microsoft.workloads/sapvirtualinstances to Storage |
5164fdc7-cfcd-4bd8-a3e9-f4be93166cde |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Network Managers (microsoft.network/networkmanagers) to Storage |
82333640-495e-4249-92bb-2a5e2d07b964 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Notification Hub Namespaces (microsoft.notificationhubs/namespaces) to Storage |
0983eb33-77d7-47e5-9fa7-879f8cea012e |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Playwright Testing (microsoft.azureplaywrightservice/accounts) to Storage |
2e3285f9-ae82-4f69-b83f-5b6f1ee69f3a |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Public IP addresses (microsoft.network/publicipaddresses) to Storage |
39aa567d-69c2-4cc0-aaa9-76c6d4006b14 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Public IP Prefixes (microsoft.network/publicipprefixes) to Storage |
a2361fd4-721d-4be2-9910-53be250b99ad |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for SCOPE pools (microsoft.synapse/workspaces/scopepools) to Storage |
9dbcaaa7-0c1b-4861-81c2-d340661b4382 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Search services (microsoft.search/searchservices) to Storage |
480ee186-7504-48ac-b64e-af38673aa2c6 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Service Bus Namespaces (microsoft.servicebus/namespaces) to Storage |
3dd58519-427e-42a4-8ffc-e415a3c716f1 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for SignalR (microsoft.signalrservice/signalr) to Storage |
0e0c742d-5031-4e65-bf96-1bee7cf55740 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for SQL databases (microsoft.sql/servers/databases) to Storage |
8656d368-0643-4374-a63f-ae0ed4da1d9a |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for SQL managed instances (microsoft.sql/managedinstances) to Storage |
40654dcd-0b26-49d6-aeaf-d12d7c1e8c4d |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Streaming Endpoints (microsoft.media/mediaservices/streamingendpoints) to Storage |
f48e8ce0-91bd-4d51-8aba-8990d942f999 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Video Analyzers (microsoft.media/videoanalyzers) to Storage |
f08edf17-5de2-4966-8c62-a50a3f4368ff |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Virtual network gateways (microsoft.network/virtualnetworkgateways) to Storage |
b4a9c220-1d62-4163-a17b-30db7d5b7278 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Volumes (microsoft.netapp/netappaccounts/capacitypools/volumes) to Storage |
20f21bc7-b0b8-4d57-83df-5a8a0912b934 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
Enable logging by category group for Web PubSub Service (microsoft.signalrservice/webpubsub) to Storage |
bf6af3d2-fbd5-458f-8a40-2556cf539b45 |
Monitoring |
Default DeployIfNotExists Allowed DeployIfNotExists, AuditIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |