Azure / Azure/PSRule.Rules.Azure

[BUG] Export-AzPolicyAssignmentRuleData unable to export Azure policy as PSRule (The function "field" was not found) [Custom policy: Prevent cross tenant Private Link for ampls]

Open
#2,731 1 comment 0 reactions 1 assignee Claimed by @ElinoraWhite View on GitHub
bug feature: policy-as-rules
Dominant language
PowerShell
Stars
447
Forks
109
Avg merge
2d 19h
Merged PRs (30d)
23

Description

### Existing rule

_No response_

### Description of the issue

Unable to export policy assignment data to PSRule.

``` json
{
"Name": "00000000-0000-0000-0000-000000000000",
"ResourceId": "/providers/Microsoft.Management/managementGroups/MyManagementGroup/providers/Microsoft.Authorization/policyDefinitions/00000000-0000-0000-0000-000000000000",
"ResourceName": "00000000-0000-0000-0000-000000000000",
"ResourceType": "Microsoft.Authorization/policyDefinitions",
"SubscriptionId": null,
"Properties": {
"Description": "This policy prevents private link between tenants for ampls.",
"DisplayName": "Prevent cross tenant Private Link for ampls",
"Metadata": {
"version": "0.0.2",
"category": "Network",
"status": "Active",
"Control": "ABC1, ABC2, ABC3, ABC4, ABC5",
"purpose": "This policy prevents private link between tenants for ampls.",
"tags": [
{
"managedpolicy": "true"
}
],
"createdBy": "00000000-0000-0000-0000-000000000000",
"createdOn": "2023-06-14T14:18:39.548002Z",
"updatedBy": null,
"updatedOn": null
},
"Mode": "All",
"Parameters": {
"effect": {
"type": "String",
"metadata": {
"description": "The effect of the policy",
"displayName": "Effect"
},
"allowedValues": [
"Audit",
"Deny",
"Disabled"
],
"defaultValue": "Deny"
}
},
"PolicyRule": {
"if": {
"allOf": [
{
"equals": "Microsoft.OperationalInsights/workspaces/privateEndpointConnections",
"field": "type"
},
{
"anyOf": [
{
"exists": false,
"field": "Microsoft.OperationalInsights/workspaces/privateEndpointConnections.privateEndpoint.id"
},
{
"notEquals": "[subscription().subscriptionId]",
"value": "[split(concat(field('Microsoft.OperationalInsights/workspaces/privateEndpointConnections.privateEndpoint.id'), '//'), '/')[2]]"
}
]
}
]
},
"then": {
"effect": "[parameters('effect')]"
}
},
"PolicyType": 1
},
"PolicyDefinitionId": "/providers/Microsoft.Management/managementGroups/MyManagementGroup/providers/Microsoft.Authorization/policyDefinitions/00000000-0000-0000-0000-000000000000"
}
```

### Error messages

An error occurred evaluating expression '[split(concat(field('Microsoft.OperationalInsights/workspaces/privateEndpointConnections.privateEndpoint.id'), '//'), '/')[2]]' line 57. The function "field" was not found.

### Reproduction

Exporting policy assignment data

### Version of PSRule

2.9.0

### Version of PSRule for Azure

1.33.2

### Additional context

This bug is related to #1323

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.