Azure / Azure/Azure-Landing-Zones

Add recommendation for 'Deny vNet peering to non-approved vNets'

Open
#249 4 comments 0 reactions 0 assignees View on GitHub
Transfer From: Enterprise-Scale :arrow_right:
Dominant language
PowerShell
Stars
96
Forks
70
Avg merge
3d 1h
Merged PRs (30d)
7

Description

The policy [Deny vNet peering to non-approved vNets](https://www.azadvertizer.net/azpolicyadvertizer/Deny-VNET-Peering-To-Non-Approved-VNETs.html) is (obviously) not found in list: https://github.com/Azure/Enterprise-Scale/wiki/ALZ-Policies#intermediate-root hence, it has no recommendation or guideline on usage.

The nearest guideline is this:
https://github.com/Azure/Enterprise-Scale/wiki/Whats-new#policy-17
*"This is useful in scenarios where you only want to allow vNet peering to say a central hub vNet and not allow other vNet peerings between landing zones to be enabled."*

**Recommendation**
For the hub and spoke architecture (AdventureWorks), best practice would be to enable (assign) this policy to LZ MG, to have all traffic from spokes go to the hub - not allowing VNet peering between spokes (landing zones).
This should be reflected.

Contributor guide

Open the contributing guide

Research direction

Review the ALZ-Policies#intermediate-root and What's-new#policy-17 wiki sections, along with the linked policy reference. Add the missing recommendation and usage guidance for “Deny vNet peering to non-approved vNets” in the hub-and-spoke AdventureWorks scenario. Done means the policy appears in the intermediate-root list with guidance consistent with the requested spoke-to-hub-only architecture.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure
Domain
documentation
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.