More Info:

Monitoring for create policy assignment events gives insight into changes done in ‘azure policy - assignments’ and may reduce the time it takes to detect unsolicited changes.

Risk Level

Low

Address

Security, Operational Maturity

Compliance Standards

CISAZURE, CBP, HIPAA, ISO27001, SOC2, NISTCSF, PCIDSS

Triage and Remediation

Remediation

Sure, here are the step-by-step instructions to remediate the misconfiguration “Ensure Activity Log Alert exists for Create Policy Assignment” in Azure using the Azure console:

  1. Log in to the Azure portal using your credentials.
  2. Click on the “Monitor” option from the left-hand side menu.
  3. Click on the “Activity log alerts” option from the “Monitor” menu.
  4. Click on the “New alert rule” button to create a new alert rule.
  5. In the “Basics” tab, provide a name for the alert rule and select the subscription to which it applies.
  6. In the “Condition” tab, select the “Signal logic” as “Activity log”.
  7. In the “Target” section, select “Resource Manager” as the “Resource type”.
  8. In the “Event types” section, select “Policy Assignment Created” as the event type.
  9. In the “Actions” tab, select the “Action group” that you want to associate with this alert rule.
  10. In the “Review + create” tab, review the alert rule configuration and click on the “Create” button to create the alert rule.

Once the alert rule is created, you will receive notifications whenever a policy assignment is created in your Azure environment. This will help you to ensure that all policy assignments are being created as per the defined policies and standards.

Additional Reading: