16

Trigger an on-demand Azure Policy compliance evaluation scan

 3 years ago
source link: https://www.danielstechblog.io/trigger-an-on-demand-azure-policy-compliance-evaluation-scan/
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

Trigger an on-demand Azure Policy compliance evaluation scan

Azure Policy evaluates resource compliance automatically every 24 hours for already assigned policies or initiatives.

New policy or initiative assignments start the evaluation after the assignment has been applied to the defined scope which might take up to 30 minutes.

Azure Policy Compliance Dashboard

What might be a hidden gem to some of you is the case that you can trigger an on-demand compliance evaluation scan whenever you want.

You trigger the evaluation for the current subscription by executing the following Azure CLI command.

az policy state trigger-scan
az policy state trigger-scan

To restrict the on-demand compliance evaluation scan on a specific resource group you provide an additional parameter.

az policy state trigger-scan --resource-group resource-group-name
az policy state trigger-scan --resource-group resource-group-name

More details when a compliance evaluation scan gets triggered is described in the Azure documentation.

-> https://docs.microsoft.com/en-us/azure/governance/policy/how-to/get-compliance-data

This entry was posted in Azure and tagged Cloud, Compliance, Governance, IaaS, Microsoft Azure, PaaS, Public Cloud, Security on 27. September 2020.

About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK