Azure / Azure/PSRule.Rules.Azure

[BUG] Export-AzPolicyAssignmentRuleData unable to export Azure policy as PSRule (The function "field" was not found) [Custom policy: Deny creation of access policies with certificate authorities roles]

Open
#2,737 0 comments 0 reactions 0 assignees View on GitHub
bug feature: policy-as-rules
Dominant language
PowerShell
Stars
447
Forks
109
Avg merge
2d 19h
Merged PRs (30d)
23

Description

### Existing rule

_No response_

### Description of the issue

Unable to export policy assignment data to PSRule.

```json
{
"Name": "00000000-0000-0000-0000-000000000000",
"ResourceId": "/providers/Microsoft.Management/managementGroups/MyManagementGroup/providers/Microsoft.Authorization/policyDefinitions/00000000-0000-0000-0000-000000000000",
"ResourceName": "00000000-0000-0000-0000-000000000000",
"ResourceType": "Microsoft.Authorization/policyDefinitions",
"SubscriptionId": null,
"Properties": {
"Description": "This policy prevent creation of key vault access policies with certificate authorities roles.",
"DisplayName": "Deny creation of access policies with certificate authorities roles",
"Metadata": {
"version": "0.0.1",
"category": "Key Vault",
"status": "Active",
"Control": "ABC1, ABC2, ABC3, ABC4, ABC5",
"purpose": "This policy prevent creation of key vault access policies with certificate authorities roles.",
"tags": [
{
"managedpolicy": "true"
}
],
"createdBy": "00000000-0000-0000-0000-000000000000",
"createdOn": "2023-06-14T14:15:55.6006958Z",
"updatedBy": null,
"updatedOn": null
},
"Mode": "Indexed",
"Parameters": {
"disallowed_access_policy_certificates_roles": {
"type": "Array",
"metadata": {
"description": "Access policy certificates roles names to disallow",
"displayName": "Disallowed Roles"
},
"defaultValue": [
"ManageIssuers",
"GetIssuers",
"ListIssuers",
"SetIssuers",
"DeleteIssuers"
]
},
"effect": {
"type": "String",
"metadata": {
"description": "Enable or disable the execution of the policy",
"displayName": "Effect"
},
"allowedValues": [
"Audit",
"Deny",
"Disabled"
],
"defaultValue": "Deny"
}
},
"PolicyRule": {
"if": {
"allOf": [
{
"equals": "Microsoft.KeyVault/vaults",
"field": "type"
},
{
"equals": "true",
"value": "[greaterOrEquals(length(intersection(field('Microsoft.Keyvault/vaults/accessPolicies[*].permissions.certificates[*]'), parameters('disallowed_access_policy_certificates_roles'))), 1)]"
}
]
},
"then": {
"effect": "[parameters('effect')]"
}
},
"PolicyType": 1
},
"PolicyDefinitionId": "/providers/Microsoft.Management/managementGroups/MyManagementGroup/providers/Microsoft.Authorization/policyDefinitions/00000000-0000-0000-0000-000000000000"
}
```

### Error messages

An error occurred evaluating expression '[greaterOrEquals(length(intersection(field('Microsoft.Keyvault/vaults/accessPolicies[*].permissions.certificates[*]'), parameters('disallowed_access_policy_certificates_roles'))), 1)]' line 65. The function "field" was not found.

### Reproduction

Exporting policy assignment data

### Version of PSRule

2.9.0

### Version of PSRule for Azure

1.33.2

### Additional context

This bug is related to #1323

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.