|
[2025年8月27日19:46:46 UTC]建立多雲網關:<帳戶名稱>
[2025年8月27日19:46:47 UTC]已成功獲取資源組:來自雲的<account name>
[2025年8月27日19:46:47 UTC]在資源組下建立儲存帳戶:雲中的<account name>
[2025年8月27日19:46:49 UTC]資源組下的儲存帳戶:無法在雲中建立<account name>
[2025年8月27日19:46:49 UTC]其他詳細資訊:Azure錯誤:RequestDisallowedByPolicy
消息:策略不允許資源「lcoix7mu7rcrswtdkyj0jsyw」。策略識別符號:'[{"policyAssignment":{"name":"ASC預設值(訂閱:xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx)","id":"/subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/providers/Microsoft.Authorization/policyAssignments/SecurityCenterBuiltIn"},
"policyDefinition":{"name":"Storage account public access should be disallowed","id":"/providers/Microsoft.Authorization/policyDefinitions/yyyyyy-yyyy-yyyy-yyyyyyyyyy","version":"3.1.1"}, <<<它引用Azure中的帳戶型別不正確,訂閱必須為Enterprise
"policySetDefinition":{"name":"Microsoft cloud security benchmark","id":"/providers/Microsoft.Authorization/policySetDefinitions/zzzzzzz-zzzz-zzzzz-zzzzzzzzz","version":"57.53.0"}}]'。
目標:lcoix7mu7rcrswtdkyj0jsyw
Additional Information:
Type:PolicyViolation
資訊:{
"評估詳細資訊":{
"evaluatedExpressions":[
{
"結果":"真",
"expressionKind":"欄位",
"表達式":"型別",
"路徑":"型別",
"expressionValue":"Microsoft.Storage/storageAccount",
"目標值":"Microsoft.Storage/storageAccount",
"操作員":「等於」
},
{
"結果":"假",
"expressionKind":"欄位",
"表達式":"id",
"路徑":"id",
"expressionValue":"/subscriptions/xxxxxxxx-xxxx-xxxx-xxxxxxxxxx/resourceGroups/<account name>/providers/Microsoft.Storage/storageAccounts/lcoix7mu7rcrswtdkyj0jsyw",
"目標值":"/resourceGroups/aro-",
"操作員":"包含"
},
{
"結果":"假",
"expressionKind":"欄位",
"表達式":"Microsoft.Storage/storageAccounts/allowBlobPublicAccess",
"路徑":"properties.allowBlobPublicAccess",
"目標值":"假",
"操作員":「等於」
}
]
},
"policyDefinitionId":"/providers/Microsoft.Authorization/policyDefinitions/yyyyyy-yyyy-yyyy-yyyyyyyyyyyy",
"policySetDefinitionId":"/providers/Microsoft.Authorization/policySetDefinitions/zzzzzz-zzzz-zzzz-zzzz-zzzzzzzzz",
"policyDefinitionReferenceId":"StorageDisallowPublicAccess",
"policySetDefinitionName":"zzzzzz-zzzz-zzzzz-zzzzzzzz",
"policySetDefinitionDisplayName":"Microsoft雲安全基準",
"policySetDefinitionVersion":"57.53.0",
"policyDefinitionName":"yyyyyyyy-yyyy-yyyy-yyyy-yyyyyyyyyy",
"policyDefinitionDisplayName":"應禁止儲存帳戶公共訪問",
"policyDefinitionVersion":"3.1.1",
"policyDefinitionEffect":"拒絕",
"policyAssignmentId":"/subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/providers/Microsoft.Authorization/policyAssignments/SecurityCenterBuiltIn",
"policyAssignmentName":"SecurityCenterBuiltIn",
"policyAssignmentDisplayName":"ASC預設(訂閱:xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx)」,
"policyAssignmentScope":"/subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
"policyAssignmentParameters":{
"disallowPublicBlobAccessEffect":"拒絕"
},
"policyExemptionIds":[],
"policyEnrollmentIds":[]
}
[2025年8月27日19:46:49 UTC]正在回滾所做的更改……
[2025年8月27日19:46:49 UTC]回滾完成
[2025年8月27日19:46:49 UTC]建立或提取儲存帳戶時出現內部錯誤
|