More Info:

Ensure that a Microsoft Azure activity log alert is fired whenever a ‘Power Off Virtual Machine’ event is triggered within your cloud account. An Azure activity log alert fires each time the action event that matches the condition defined in the alert configuration is triggered. The alert condition that this conformity rule checks for is Whenever the Administrative Activity Log 'Power Off Virtual Machine (Microsoft.Compute/virtualMachines)' has 'any' level, with 'any' status and event is initiated by 'any'

Risk Level

Medium

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

Sure, I can help you with that. Here are the step-by-step instructions to remediate the misconfiguration in Azure:

  1. Open the Azure portal and navigate to the Virtual Machines blade.

  2. Select the virtual machine for which you want to set up alerts.

  3. In the virtual machine’s Overview pane, click on the “Monitoring” option.

  4. In the Monitoring pane, click on the “Alerts” option.

  5. Click on the ”+ New alert rule” button to create a new alert rule.

  6. In the “Create rule” page, under the “Resource” section, select the virtual machine for which you want to set up alerts.

  7. Under the “Condition” section, click on the ”+ Add condition” button.

  8. In the “Add condition” page, select the “Virtual Machine” category and then select the “Power state” metric.

  9. Set the condition to “Power state” equals “VM deallocated”.

  10. Under the “Actions” section, click on the ”+ Add action group” button.

  11. In the “Add action group” page, click on the ”+ Create action group” button.

  12. In the “Create action group” page, enter a name for the action group and fill out the required fields.

  13. Under the “Actions” section, click on the ”+ Add action” button.

  14. In the “Add action” page, select the “Email/SMS/Push/Voice” option.

  15. Fill out the required fields, including the email address or phone number where you want to receive the alerts.

  16. Click on the “OK” button to save the action.

  17. Click on the “OK” button to save the action group.

  18. Click on the “OK” button to save the alert rule.

That’s it! You have successfully set up alerts for Power Off Virtual Machine Events in Azure. Now, whenever the virtual machine is deallocated, you will receive an email or SMS notification.

Additional Reading: