|
[2025年8月27日19:46:46 UTC]创建多云网关:<account name>
[2025年8月27日19:46:47 UTC]已成功获取资源组:云中的<account name>
[2025年8月27日19:46:47 UTC]在资源组下创建存储帐户:云中的<account name>
[2025年8月27日19:46:49 UTC]资源组下的存储帐户:无法在云中创建<account name>
[2025年8月27日19:46:49 UTC]其他详细信息:Azure错误:RequestDisallowedByPolicy
邮件:策略不允许资源“lcoix7mu7rcrswtdkyj0jsyw”。策略标识符:'[{"policyAssignment":{"name":"ASC默认(订阅:xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx)","id":"/subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/providers/Microsoft.Authorization/policyAssignments/SecurityCenterBuiltIn"},
"policyDefinition":{"name":"应该禁止存储帐户公共访问","id":"/providers/Microsoft.Authorization/policyDefinitions/yyyyyyyy-yyyy-yyyy-yyyyyyyyyyyy","version":"3.1.1"}, <<<表示Azure中的帐户类型不正确,订阅必须为企业级
"policySetDefinition":{"name":"Microsoft cloud security benchmark","id":"/providers/Microsoft.Authorization/policySetDefinitions/zzzzzzz-zzzz-zzzzz-zzzzzzzzzz","version":"57.53.0"}}]'。
目标:lcoix7mu7rcrswtdkyj0jsyw
其它信息:
type:PolicyViolation
信息:{
"评估详细信息":{
"evaluatedExpressions":[
{
"结果":"真",
"表达式类型":"字段",
"表达式":"类型",
"路径":"类型",
"表达式值":"Microsoft.存储/存储帐户",
"目标值":"Microsoft.存储/存储帐户",
"操作员":“等于”
},
{
"结果":"错误",
"表达式类型":"字段",
"表达式":"id",
"路径":"id",
"表达式值":"/subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/resourceGroups/<account name>/providers/Microsoft.Storage/storageAccounts/lcoix7mu7rcrswtdkyj0jsyw",
"目标值":"/resourceGroups/aro-",
"操作员":"包含"
},
{
"结果":"错误",
"表达式类型":"字段",
"表达式":"Microsoft.Storage/storageAccounts/allowBlobPublicAccess",
"路径":"properties.allowBlobPublicAccess",
"目标值":"假",
"操作员":“等于”
}
]
},
"policyDefinitionId":"/providers/Microsoft.Authorization/policyDefinitions/yyyyyyyy-yyyy-yyyy-yyyyyyyyyyyyyy",
"policySetDefinitionId":"/providers/Microsoft.Authorization/policySetDefinitions/zzzzzzz-zzzzz-zzzzz-zzzzzzzzzz",
"policyDefinitionReferenceId":"StorageDisallowPublicAccess",
"policySetDefinitionName":"zzzzzzz-zzzzz-zzzzzzzzz",
"policySetDefinitionDisplayName":"Microsoft云安全基准",
"policySetDefinitionVersion":"57.53.0",
"policyDefinitionName":"yyyyyyyy-yyyy-yyyy-yyyyyyyyyyyyyy",
"policyDefinitionDisplayName":"应禁止存储帐户公共访问",
"policyDefinitionVersion":"3.1.1",
"policyDefinitionEffect":"拒绝",
"policyAssignmentId":"/subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/providers/Microsoft.Authorization/policyAssignments/SecurityCenterBuiltIn",
"policyAssignmentName":"SecurityCenterBuiltIn",
"policyAssignmentDisplayName":“ASC默认(订用:xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx)",
"policyAssignmentScope":"/subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
"policyAssignmentParameters":{
"disallowPublicBlobAccessEffect":"拒绝"
},
"policyExemptionIds":[],
"policyEnrollmentIds":[]
}
[2025年8月27日19:46:49 UTC]正在回滚所做的更改……
[2025年8月27日19:46:49 UTC]回滚完成
[2025年8月27日19:46:49 UTC]创建或获取存储帐户时出现内部错误
|