diff --git a/policyDefinitions/SQL/configure-a-private-dns-zone-id-for-sql-server-sqlserver-groupid/azurepolicy.json b/policyDefinitions/SQL/configure-a-private-dns-zone-id-for-sql-server-sqlserver-groupid/azurepolicy.json new file mode 100644 index 00000000..2ea0dd2e --- /dev/null +++ b/policyDefinitions/SQL/configure-a-private-dns-zone-id-for-sql-server-sqlserver-groupid/azurepolicy.json @@ -0,0 +1,115 @@ +{ + "name": "87b09efd-f716-4a73-a509-c8f831bba93e", + "type": "Microsoft.Authorization/policyDefinitions", + "properties": { + "displayName": "Configure a private DNS Zone ID for Azure SQL Server sqlserver groupID", + "description": "Configure private DNS zone group to override the DNS resolution for a Azure SQL Server sqlserver groupID private endpoint.", + "metadata": { + "version": "1.0.0", + "category": "SQL" + }, + "mode": "Indexed", + "parameters": { + "privateDnsZoneId": { + "type": "String", + "metadata": { + "displayName": "Configure a private DNS Zone ID for Azure SQL Server sqlserver groupID", + "description": "Configure private DNS zone group to override the DNS resolution for a Azure SQL Server sqlserver groupID private endpoint.", + "strongType": "Microsoft.Network/privateDnsZones", + "assignPermissions": true + } + }, + "effect": { + "type": "String", + "metadata": { + "displayName": "Effect", + "description": "DeployIfNotExists, AuditIfNotExists or Disabled the execution of the Policy" + }, + "allowedValues": [ + "DeployIfNotExists", + "AuditIfNotExists", + "Disabled" + ], + "defaultValue": "DeployIfNotExists" + } + }, + "policyRule": { + "if": { + "allOf": [ + { + "field": "type", + "equals": "Microsoft.Network/privateEndpoints" + }, + { + "count": { + "field": "Microsoft.Network/privateEndpoints/privateLinkServiceConnections[*].groupIds[*]", + "where": { + "field": "Microsoft.Network/privateEndpoints/privateLinkServiceConnections[*].groupIds[*]", + "equals": "sqlServer" + } + }, + "greaterOrEquals": 1 + } + ] + }, + "then": { + "effect": "[parameters('effect')]", + "details": { + "type": "Microsoft.Network/privateEndpoints/privateDnsZoneGroups", + "roleDefinitionIds": [ + "/providers/Microsoft.Authorization/roleDefinitions/4d97b98b-1d4f-4787-a291-c67834d212e7" + ], + "deployment": { + "properties": { + "mode": "incremental", + "template": { + "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", + "contentVersion": "1.0.0.0", + "parameters": { + "privateDnsZoneId": { + "type": "string" + }, + "privateEndpointName": { + "type": "string" + }, + "location": { + "type": "string" + } + }, + "resources": [ + { + "name": "[concat(parameters('privateEndpointName'), '/deployedByPolicy')]", + "type": "Microsoft.Network/privateEndpoints/privateDnsZoneGroups", + "apiVersion": "2025-07-01", + "location": "[parameters('location')]", + "properties": { + "privateDnsZoneConfigs": [ + { + "name": "privateDnsZone", + "properties": { + "privateDnsZoneId": "[parameters('privateDnsZoneId')]" + } + } + ] + } + } + ] + }, + "parameters": { + "privateDnsZoneId": { + "value": "[parameters('privateDnsZoneId')]" + }, + "privateEndpointName": { + "value": "[field('name')]" + }, + "location": { + "value": "[field('location')]" + } + } + } + } + } + } + } + } +} diff --git a/policyDefinitions/SQL/configure-a-private-dns-zone-id-for-sql-server-sqlserver-groupid/azurepolicy.parameters.json b/policyDefinitions/SQL/configure-a-private-dns-zone-id-for-sql-server-sqlserver-groupid/azurepolicy.parameters.json new file mode 100644 index 00000000..2a810212 --- /dev/null +++ b/policyDefinitions/SQL/configure-a-private-dns-zone-id-for-sql-server-sqlserver-groupid/azurepolicy.parameters.json @@ -0,0 +1,24 @@ +{ + "privateDnsZoneId": { + "type": "String", + "metadata": { + "displayName": "Configure a private DNS Zone ID for Azure SQL Server sqlserver groupID", + "description": "Configure private DNS zone group to override the DNS resolution for a Azure SQL Server sqlserver groupID private endpoint.", + "strongType": "Microsoft.Network/privateDnsZones", + "assignPermissions": true + } + }, + "effect": { + "type": "String", + "metadata": { + "displayName": "Effect", + "description": "DeployIfNotExists, AuditIfNotExists or Disabled the execution of the Policy" + }, + "allowedValues": [ + "DeployIfNotExists", + "AuditIfNotExists", + "Disabled" + ], + "defaultValue": "DeployIfNotExists" + } +} diff --git a/policyDefinitions/SQL/configure-a-private-dns-zone-id-for-sql-server-sqlserver-groupid/azurepolicy.rules.json b/policyDefinitions/SQL/configure-a-private-dns-zone-id-for-sql-server-sqlserver-groupid/azurepolicy.rules.json new file mode 100644 index 00000000..3c81132c --- /dev/null +++ b/policyDefinitions/SQL/configure-a-private-dns-zone-id-for-sql-server-sqlserver-groupid/azurepolicy.rules.json @@ -0,0 +1,78 @@ +{ + "if": { + "allOf": [ + { + "field": "type", + "equals": "Microsoft.Network/privateEndpoints" + }, + { + "count": { + "field": "Microsoft.Network/privateEndpoints/privateLinkServiceConnections[*].groupIds[*]", + "where": { + "field": "Microsoft.Network/privateEndpoints/privateLinkServiceConnections[*].groupIds[*]", + "equals": "sqlServer" + } + }, + "greaterOrEquals": 1 + } + ] + }, + "then": { + "effect": "[parameters('effect')]", + "details": { + "type": "Microsoft.Network/privateEndpoints/privateDnsZoneGroups", + "roleDefinitionIds": [ + "/providers/Microsoft.Authorization/roleDefinitions/4d97b98b-1d4f-4787-a291-c67834d212e7" + ], + "deployment": { + "properties": { + "mode": "incremental", + "template": { + "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", + "contentVersion": "1.0.0.0", + "parameters": { + "privateDnsZoneId": { + "type": "string" + }, + "privateEndpointName": { + "type": "string" + }, + "location": { + "type": "string" + } + }, + "resources": [ + { + "name": "[concat(parameters('privateEndpointName'), '/deployedByPolicy')]", + "type": "Microsoft.Network/privateEndpoints/privateDnsZoneGroups", + "apiVersion": "2025-07-01", + "location": "[parameters('location')]", + "properties": { + "privateDnsZoneConfigs": [ + { + "name": "privateDnsZone", + "properties": { + "privateDnsZoneId": "[parameters('privateDnsZoneId')]" + } + } + ] + } + } + ] + }, + "parameters": { + "privateDnsZoneId": { + "value": "[parameters('privateDnsZoneId')]" + }, + "privateEndpointName": { + "value": "[field('name')]" + }, + "location": { + "value": "[field('location')]" + } + } + } + } + } + } +}