SlideShare a Scribd company logo
Azure Policy + Azure RBAC
の導入に際して得たアレコレ
! "#$% &'()'$*+,-. /0.12
3-40$5+6+'(+ 7$89:;
<=<>7><7>?
!"#$%#&'()*+,-
.#$/)01203456789:;-
Azure Policy ?
or
Azure RBAC ?
<:=>?@ABCDEFGH%IJ#$KKK
Do everything with
Azure RBAC
... really?
EXPLANATION
Azure Policy
Azure LMNOEPQR
CSTUVWXPYEY
0Z[7]U^_
`a4bNcEdef7
$/);Ugh
Azure RBAC
Azure NOEPdij)
klmPUn;opq
Azure Resource Manager rd
stu"vwhcPSx
'yEzE`aU{|
<:=>?};#v;~@•€KKK
I kind of get it, so I'll
pick one.
Deny to use IaaS to all
01
Which do you have to use, Azure Policy or Azure RBAC?
"policyRule": {
"if": {
"anyOf": [
{
"field": "type",
"like": "Microsoft.Compute/*"
},
{
"field": "type",
"like": "Microsoft.SqlVirtualMachine/*"
}
]
},
"then": {
"effect": "deny"
}
}
Deny to use IaaS to all -> Use Azure Policy
Azure Policy • NOEP‚ƒ U
„…7$`aU deny u9)†0
4‡ˆBM'=‰Š‹ŒU•Ž=
bNcEU‰Š
•pq•YEQ‘’“PlNQc
”F‘NOEP•YEQ•
klc”F•`a•M–—d˜™
Bo IaaS šŠGHU{—‡ˆ
WHY?
Deny operating Azure Policy
Which do you have to use, Azure Policy or Azure RBAC?
02
Deny operating Azure Policy
-> Azure RBAC
Azure Policy MNOEP‚ƒ•
Microsoft.Authorization
Microsoft.PolicyInsights
›œB•GH Write –—UžŸ
bNcEU <0¡¢4`a£‡
Contributor 0; Reader 0;¤)¥¦
WHY?
Azure Policy Exclusion Settings
exclusion setting?
03
Exclusion Settings (preview)
Expiry date
!"#$%&'()*+
',-./012
Category
',-.3456789
',:;<=<2>0?
@A3-.012
BC'0D<=45EFGH
COST
!"#$%&''()*+,
-./001234/56
Don't you need Azure RBAC?
04
No, of course not.
Which mechanism should be adopted?
Azure Policy
want to enforce
the rule
Azure RBAC
want to allow or
deny some of
authority
Purpose
What you want to achieve
as Azure Administrators
WANT
Thing you want
to do
Azure Policy 0 Azure RBAC M /?H§¨©¥ª«Š¬-
1. Azure Policy-
Azure Resource Manager '®u")NOEPMQRCST=¯¥°±²MNOE
PQR³´µEMQRCSTU„…7$]U^_¶
klc”F§`a¬•{—7B/§vG7=’EVPšŠ·¸B%•{—‡¬
¹4AºU»#v;=¹4AºU»<klmP¼‡U½#$/);d˜™Bo=
¾¿7vVWXPYEYU‰Š¶
2. Azure RBAC-
u8À8BPÁEQd¯H)n;/yEzEM`aUpq¶
yEzEMklc”F§`a¬U^_7={|iÂMÃÄ•klc”FU{—¶
3. rŘ™-
Azure Policy > Azure RBAC
Azure RBAC '¼‡u"$/$Æ Azure Policy 'µÇB~µÇ¶
Summary
https://docs.microsoft.com/ja-jp/azure/governance/policy/overview#azure-policy-and-azure-rbac
IJKLDI>=M)NOPIQQ
CREDITS: This presentation template was created by Slidesgo, including
icons by Flaticon, and infographics & images by Freepik.
Please keep this slide for attribution.
THANKS
Does anyone have any questions?

More Related Content

PDF
How to fix kaspersky error 27300 - Easy Steps
DOCX
PDF
Engine department (2)
PDF
Mchugh Download Fitness
PDF
AWS Migration - As-Is Tool
PDF
You don't know people
ODP
Concern of Web Application Security
PPTX
I Love codeigniter, You?
How to fix kaspersky error 27300 - Easy Steps
Engine department (2)
Mchugh Download Fitness
AWS Migration - As-Is Tool
You don't know people
Concern of Web Application Security
I Love codeigniter, You?

Similar to Azure Policy + Azure RBAC の導入に際して得たアレコレ (20)

PDF
Empowering End-users to Find Point-of-interests with a Public Display
ODP
Mojolicious on Steroids
PPT
Exploiting Php With Php
PPT
Diva10
PPTX
PPTX
MysQL melhores práticas de seguranca
ODP
Schenker - DSL for quickly creating web applications in Perl
PPTX
SugarCon 2010 - Best Practices for Creating Custom Apps in Sugar
PDF
10 Excellent Ways to Secure Your Spring Boot Application - The Secure Develop...
PPT
Php frameworks
PPT
What's New in ZF 1.10
PPT
My sql presentation
PDF
Архитектура коммутаторов Cisco Catalyst 6500
PDF
Tlwin.moemaka.1
PPT
SQL Injection in PHP
PDF
10 Excellent Ways to Secure Your Spring Boot Application - Devoxx Belgium 2019
PDF
10 Excellent Ways to Secure Spring Boot Applications - Okta Webinar 2020
ODP
Evolving Software with Moose
PPTX
How did i steal your database
PPTX
5 Reasons To Love CodeIgniter
Empowering End-users to Find Point-of-interests with a Public Display
Mojolicious on Steroids
Exploiting Php With Php
Diva10
MysQL melhores práticas de seguranca
Schenker - DSL for quickly creating web applications in Perl
SugarCon 2010 - Best Practices for Creating Custom Apps in Sugar
10 Excellent Ways to Secure Your Spring Boot Application - The Secure Develop...
Php frameworks
What's New in ZF 1.10
My sql presentation
Архитектура коммутаторов Cisco Catalyst 6500
Tlwin.moemaka.1
SQL Injection in PHP
10 Excellent Ways to Secure Your Spring Boot Application - Devoxx Belgium 2019
10 Excellent Ways to Secure Spring Boot Applications - Okta Webinar 2020
Evolving Software with Moose
How did i steal your database
5 Reasons To Love CodeIgniter
Ad

More from Oshitari_kochi (20)

PDF
Azure SQL MI Link で移行も DR もポチッとな、の時代へ
PDF
SPS 開発から SPO 開発に変わる際に気をつけなければならないポイント 3 選
PDF
Updates of Azure NoSQL announced at Microsoft Ignite Spring 2021
PDF
試験スキルのアウトラインから得たMCP試験受験のコツ
PDF
PySpark Intro Part.2 with SQL Graph
PDF
ここから始めましょう、イチからーーいいえ、Cosmosから!
PDF
Azure Cosmos DB で始める Java + NoSQL 開発
PDF
Azure Cosmos DB の整合性レベルについて
PDF
Azure Cosmos DB のエンティティについて
PDF
About entities of Azure Cosmos DB
PDF
Azure Synapse Link for Azure Cosmos DB
PDF
20200809_2020年から始める Azure Cosmos DB 入門 with Azure Synapse Link recap
PDF
よわよわエンジニアがde:code 2020に感化されて新しくコミュニティを立ち上げてみた話
PPTX
Start learning Azure Cosmos DB with Azure Synapse Link
PDF
Get started with future C# .Net development with Docker
PDF
SQL Beginners Day #1 - SQL Server および Azure SQL のインストールと管理
PPTX
Start Cosmos DB with VSCode Extension
PPTX
Summary of SQL Database Updates
PDF
Summary of SQL Server 2019 new features
PDF
Start SQL Server with Docker
Azure SQL MI Link で移行も DR もポチッとな、の時代へ
SPS 開発から SPO 開発に変わる際に気をつけなければならないポイント 3 選
Updates of Azure NoSQL announced at Microsoft Ignite Spring 2021
試験スキルのアウトラインから得たMCP試験受験のコツ
PySpark Intro Part.2 with SQL Graph
ここから始めましょう、イチからーーいいえ、Cosmosから!
Azure Cosmos DB で始める Java + NoSQL 開発
Azure Cosmos DB の整合性レベルについて
Azure Cosmos DB のエンティティについて
About entities of Azure Cosmos DB
Azure Synapse Link for Azure Cosmos DB
20200809_2020年から始める Azure Cosmos DB 入門 with Azure Synapse Link recap
よわよわエンジニアがde:code 2020に感化されて新しくコミュニティを立ち上げてみた話
Start learning Azure Cosmos DB with Azure Synapse Link
Get started with future C# .Net development with Docker
SQL Beginners Day #1 - SQL Server および Azure SQL のインストールと管理
Start Cosmos DB with VSCode Extension
Summary of SQL Database Updates
Summary of SQL Server 2019 new features
Start SQL Server with Docker
Ad

Recently uploaded (20)

PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PPTX
Tartificialntelligence_presentation.pptx
PDF
Web App vs Mobile App What Should You Build First.pdf
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
Zenith AI: Advanced Artificial Intelligence
PPTX
TLE Review Electricity (Electricity).pptx
PDF
Mushroom cultivation and it's methods.pdf
PPTX
A Presentation on Artificial Intelligence
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PPTX
A Presentation on Touch Screen Technology
PDF
Enhancing emotion recognition model for a student engagement use case through...
PDF
Encapsulation_ Review paper, used for researhc scholars
PPTX
TechTalks-8-2019-Service-Management-ITIL-Refresh-ITIL-4-Framework-Supports-Ou...
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
NewMind AI Weekly Chronicles - August'25-Week II
PPTX
1. Introduction to Computer Programming.pptx
PDF
Approach and Philosophy of On baking technology
PDF
project resource management chapter-09.pdf
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
Group 1 Presentation -Planning and Decision Making .pptx
Tartificialntelligence_presentation.pptx
Web App vs Mobile App What Should You Build First.pdf
Assigned Numbers - 2025 - Bluetooth® Document
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Zenith AI: Advanced Artificial Intelligence
TLE Review Electricity (Electricity).pptx
Mushroom cultivation and it's methods.pdf
A Presentation on Artificial Intelligence
MIND Revenue Release Quarter 2 2025 Press Release
A Presentation on Touch Screen Technology
Enhancing emotion recognition model for a student engagement use case through...
Encapsulation_ Review paper, used for researhc scholars
TechTalks-8-2019-Service-Management-ITIL-Refresh-ITIL-4-Framework-Supports-Ou...
Unlocking AI with Model Context Protocol (MCP)
NewMind AI Weekly Chronicles - August'25-Week II
1. Introduction to Computer Programming.pptx
Approach and Philosophy of On baking technology
project resource management chapter-09.pdf
Accuracy of neural networks in brain wave diagnosis of schizophrenia

Azure Policy + Azure RBAC の導入に際して得たアレコレ

  • 1. Azure Policy + Azure RBAC の導入に際して得たアレコレ ! "#$% &'()'$*+,-. /0.12 3-40$5+6+'(+ 7$89:; <=<>7><7>?
  • 4. EXPLANATION Azure Policy Azure LMNOEPQR CSTUVWXPYEY 0Z[7]U^_ `a4bNcEdef7 $/);Ugh Azure RBAC Azure NOEPdij) klmPUn;opq Azure Resource Manager rd stu"vwhcPSx 'yEzE`aU{|
  • 5. <:=>?};#v;~@•€KKK I kind of get it, so I'll pick one.
  • 6. Deny to use IaaS to all 01 Which do you have to use, Azure Policy or Azure RBAC?
  • 7. "policyRule": { "if": { "anyOf": [ { "field": "type", "like": "Microsoft.Compute/*" }, { "field": "type", "like": "Microsoft.SqlVirtualMachine/*" } ] }, "then": { "effect": "deny" } } Deny to use IaaS to all -> Use Azure Policy Azure Policy • NOEP‚ƒ U „…7$`aU deny u9)†0 4‡ˆBM'=‰Š‹ŒU•Ž= bNcEU‰Š •pq•YEQ‘’“PlNQc ”F‘NOEP•YEQ• klc”F•`a•M–—d˜™ Bo IaaS šŠGHU{—‡ˆ WHY?
  • 8. Deny operating Azure Policy Which do you have to use, Azure Policy or Azure RBAC? 02
  • 9. Deny operating Azure Policy -> Azure RBAC Azure Policy MNOEP‚ƒ• Microsoft.Authorization Microsoft.PolicyInsights ›œB•GH Write –—UžŸ bNcEU <0¡¢4`a£‡ Contributor 0; Reader 0;¤)¥¦ WHY?
  • 10. Azure Policy Exclusion Settings exclusion setting? 03
  • 11. Exclusion Settings (preview) Expiry date !"#$%&'()*+ ',-./012 Category ',-.3456789 ',:;<=<2>0? @A3-.012 BC'0D<=45EFGH COST !"#$%&''()*+, -./001234/56
  • 12. Don't you need Azure RBAC? 04 No, of course not.
  • 13. Which mechanism should be adopted? Azure Policy want to enforce the rule Azure RBAC want to allow or deny some of authority Purpose What you want to achieve as Azure Administrators WANT Thing you want to do
  • 14. Azure Policy 0 Azure RBAC M /?H§¨©¥ª«Š¬- 1. Azure Policy- Azure Resource Manager '®u")NOEPMQRCST=¯¥°±²MNOE PQR³´µEMQRCSTU„…7$]U^_¶ klc”F§`a¬•{—7B/§vG7=’EVPšŠ·¸B%•{—‡¬ ¹4AºU»#v;=¹4AºU»<klmP¼‡U½#$/);d˜™Bo= ¾¿7vVWXPYEYU‰Š¶ 2. Azure RBAC- u8À8BPÁEQd¯H)n;/yEzEM`aUpq¶ yEzEMklc”F§`a¬U^_7={|iÂMÃÄ•klc”FU{—¶ 3. rŘ™- Azure Policy > Azure RBAC Azure RBAC '¼‡u"$/$Æ Azure Policy 'µÇB~µÇ¶ Summary https://docs.microsoft.com/ja-jp/azure/governance/policy/overview#azure-policy-and-azure-rbac IJKLDI>=M)NOPIQQ
  • 15. CREDITS: This presentation template was created by Slidesgo, including icons by Flaticon, and infographics & images by Freepik. Please keep this slide for attribution. THANKS Does anyone have any questions?