More Info:

Monitoring for Delete policy assignment events gives insight into changes done in ‘azure policy - assignments’ and may reduce the time it takes to detect unsolicited changes.

Risk Level

Low

Address

Security, Operational Maturity

Compliance Standards

CISAZURE, CBP

Triage and Remediation

Remediation

To remediate the misconfiguration “Ensure Activity Log Alert exists for Delete Policy Assignment” in Azure using the Azure console, please follow the below steps:

  1. Log in to the Azure portal using your credentials.
  2. Navigate to the “Activity Log Alerts” page.
  3. Click on the “Add” button to create a new activity log alert.
  4. In the “Basics” tab, provide a name and description for the alert.
  5. In the “Condition” tab, select the “Delete Policy Assignment” option from the “Event name” dropdown list.
  6. In the “Actions” tab, select the action that you want to perform when the alert is triggered. For example, you can send an email notification to the concerned team.
  7. In the “Review + create” tab, review the alert configuration and click on the “Create” button to create the alert.

Once the activity log alert is created, it will trigger whenever a policy assignment is deleted in your Azure environment, and you will be notified via the configured action. This will help you to detect and remediate any unauthorized policy assignment deletions and ensure the security of your Azure resources.

Additional Reading: