Enterprise-Scale icon indicating copy to clipboard operation
Enterprise-Scale copied to clipboard

Configure diagnostic settings on management groups in reference architecture templates

Open rohancragg opened this issue 3 years ago • 2 comments

I've only recently discovered that Diagnostic Settings can be enabled on Management Group scope (e.g. Administrative and Policy) (although this can only be configured via the Resource Manager API while in preview).

Once enabled this would allow us to log any changes to Policy and PolicySet definitions and assignments and therefore set up alerts when those resources are modified or deleted.

This would seem to be a very good best practice to have in place and therefore to include in one or all reference architectures (Wingtip etc).

It would probably need to be optional (and the desired Log Analytics workspace would need to be provided as a parameter to the custom deployment)

Perhaps cannot be made a feature until the feature becomes GA but worth having this on the roadmap?

rohancragg avatar Apr 28 '21 13:04 rohancragg

Thanks for submitting the issue, and this is something we have in our backlog, primarily to enable when deploying Enterprise-Scale. Regarding policy to enforce this; policy does currently not act on 'Microsoft.Management/managementGroups' resourceType, hence it will be a remediation scenario only, for now.

krnese avatar Apr 28 '21 18:04 krnese

Thank you. 'to enable when deploying Enterprise-Scale' was definitely what I had in mind when submitting this and I wasn't requesting that this be enforced in policy.

rohancragg avatar May 04 '21 06:05 rohancragg

closing as duplicate of #696

jtracey93 avatar Sep 01 '22 15:09 jtracey93