Azure / Azure/Azure-Landing-Zones
Move Enforce-EncryptTransit to higher scope
- Dominant language
- PowerShell
- Stars
- 96
- Forks
- 70
- Avg merge
- 3d 1h
- Merged PRs (30d)
- 7
Description
Consider moving “**Deny or Deploy and append TLS requirements and SSL enforcement on resources without Encryption in transit**" ([Enforce-EncryptTransit](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-EncryptTransit.html)) from Landing Zone MG to intermediate root group.
The resources under Platform MG should also use TLS.
From a security perspective, it does not make sense to only “protect” workloads in LZ MG.
Organizations potentially have PaaS services in the Platform MG as well that should also use TLS v1.2 (v1.3).
If not, no harm done by applying this policy to a higher scope. Better safe than sorry.
Contributor guide
Research direction
Start by locating the Enforce-EncryptTransit policy definition and its current Landing Zone MG assignment. Compare the intermediate root group and Platform MG structure, then verify the policy can be applied at the higher scope without unintended coverage changes. Done means the policy is assigned at the agreed higher scope and the affected resource coverage is documented.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure
- Domain
- cloud, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100