Azure / Azure/Azure-Landing-Zones

Move Enforce-EncryptTransit to higher scope

Open
#246 5 comments 0 reactions 0 assignees View on GitHub
Status: Long Term :hourglass: Transfer From: Enterprise-Scale :arrow_right:
Dominant language
PowerShell
Stars
96
Forks
70
Avg merge
3d 1h
Merged PRs (30d)
7

Description

Consider moving “**Deny or Deploy and append TLS requirements and SSL enforcement on resources without Encryption in transit**" ([Enforce-EncryptTransit](https://www.azadvertizer.net/azpolicyinitiativesadvertizer/Enforce-EncryptTransit.html)) from Landing Zone MG to intermediate root group.
The resources under Platform MG should also use TLS.

From a security perspective, it does not make sense to only “protect” workloads in LZ MG.
Organizations potentially have PaaS services in the Platform MG as well that should also use TLS v1.2 (v1.3).
If not, no harm done by applying this policy to a higher scope. Better safe than sorry.

Contributor guide

Open the contributing guide

Research direction

Start by locating the Enforce-EncryptTransit policy definition and its current Landing Zone MG assignment. Compare the intermediate root group and Platform MG structure, then verify the policy can be applied at the higher scope without unintended coverage changes. Done means the policy is assigned at the agreed higher scope and the affected resource coverage is documented.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure
Domain
cloud, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.