-
Notifications
You must be signed in to change notification settings - Fork 5
/
ntaassign.bicep
59 lines (54 loc) · 1.32 KB
/
ntaassign.bicep
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
//This bicep deploys the Azure Policy.
//Scope
targetScope = 'managementGroup'
//Variables
var managementgroup = tenant().tenantId
//Parameters
param loganalyticsregion string
param loganalyticsrid string
param azdsumiid string
param policydefinitionid string
param policyassignname string
param policydescription string
param ntastorageid string
param nsgflowlogworkspaceid string
//Resources
//This deploys the Azure Policy Assignment.
resource policyas 'Microsoft.Authorization/policyAssignments@2022-06-01' = {
name: '${policyassignname}'
location: loganalyticsregion
identity: {
type: 'UserAssigned'
userAssignedIdentities: {
'${azdsumiid}': {}
}
}
properties: {
description: policydescription
displayName: '${policyassignname}'
policyDefinitionId: policydefinitionid
parameters: {
workspaceResourceId: {
value: loganalyticsrid
}
nsgRegion: {
value: loganalyticsregion
}
storageId: {
value: ntastorageid
}
workspaceRegion: {
value: loganalyticsregion
}
workspaceId: {
value: nsgflowlogworkspaceid
}
networkWatcherRG: {
value: 'NetworkWatcherRG'
}
networkWatcherName: {
value: 'NetworkWatcher_${loganalyticsregion}'
}
}
}
}