SOLVED

Automatically update newly released built-in policies

%3CLINGO-SUB%20id%3D%22lingo-sub-1603860%22%20slang%3D%22en-US%22%3EAutomatically%20update%20newly%20released%20built-in%20policies%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1603860%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20trying%20to%20understand%20if%20there%20is%20a%20way%20to%20automatically%20download%20newly%20built-in%20policies%20released%20by%20Microsoft%20in%20Audit%20mode%20or%20any%20way%20of%20getting%20notified%20when%20it%20is%20released%20in%20order%20to%20keep%20the%20policy%20initiative%20updated%20throughout%20the%20time%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAre%20there%20any%20suggestions%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20in%20advance.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBest%20regards%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1607499%22%20slang%3D%22en-US%22%3ERe%3A%20Automatically%20update%20newly%20released%20built-in%20policies%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1607499%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F766960%22%20target%3D%22_blank%22%3E%40gh91%3C%2FA%3E%2C%26nbsp%3B%3C%2FP%3E%0A%3CP%3Eif%20you%20are%20referring%20to%20the%20builtin%20policy%20initiative%2C%20Azure%20Security%20Center%20is%20using%2C%20then%20the%20answer%20is%20yes.%20The%20builtin%20(default)%20ASC%20policy%20initiative%20will%20automatically%20be%20updated%20with%20additional%20policies%20once%20they%20are%20published.%20If%20you%20are%20using%20a%20custom%20policy%20initiative%2C%20there%20are%20two%20different%20scenarios%3A%3C%2FP%3E%0A%3COL%3E%0A%3CLI%3Eif%20you%20are%20using%20builtin%20security%20policies%20in%20your%20custom%20initiative%2C%20these%20policies%20will%20also%20automatically%20be%20updated%20once%20there%20is%20a%20change.%20However%2C%20we%20will%20not%20update%20your%20policy%20initiative%20by%20adding%20additional%20policies%20once%20they%20are%20released.%3C%2FLI%3E%0A%3CLI%3Eif%20you%20are%20exclusively%20using%20custom%20policies%20in%20your%20custom%20initiative%2C%20these%20policies%20will%20%3CEM%3Enot%3C%2FEM%3E%20automatically%20be%20updated.%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3EBest%20regards%2C%3C%2FP%3E%0A%3CP%3ETom%20Janetscheck%3C%2FP%3E%0A%3CP%3ESenior%20Program%20Manager%3C%2FP%3E%0A%3CP%3ECxE%20%7C%20Azure%20Security%20Center%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1607989%22%20slang%3D%22en-US%22%3ERe%3A%20Automatically%20update%20newly%20released%20built-in%20policies%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1607989%22%20slang%3D%22en-US%22%3E%3CP%3EHello%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F699391%22%20target%3D%22_blank%22%3E%40Tom_Janetscheck%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20very%20much%20for%20the%20detailed%20reply.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20looking%20to%20the%20scenario%20where%20I%20have%20a%20custom%20initiative%20with%20a%20mix%20of%20custom%20%26amp%3B%20built-in%20policies.%20Based%20on%20your%20reply%2C%20new%20built-in%20policies%20will%20not%20be%20added%20to%20the%20custom%20initiative%20once%20released.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20that%20way%2C%20is%20there%20a%20method%20to%20receive%20alerts%20or%20any%20page%20where%20I%20can%20see%20the%20new%20built-in%20policies%20released%20by%20Microsoft%20in%20order%20to%20keep%20my%20custom%20initiative%20updated%20with%20the%20latest%20policies%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20in%20advance!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1608019%22%20slang%3D%22en-US%22%3ERe%3A%20Automatically%20update%20newly%20released%20built-in%20policies%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1608019%22%20slang%3D%22en-US%22%3E%3CP%3EHello%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F766960%22%20target%3D%22_blank%22%3E%40gh91%3C%2FA%3E%2C%26nbsp%3B%3C%2FP%3E%0A%3CP%3Ethere%20is%20no%20auto-notification%20option%2C%20but%20you'll%20find%20new%20policies%20mentioned%20in%20the%20Azure%20Security%20Center%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Frelease-notes%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Erelease%20notes%3C%2FA%3E%2C%20which%20are%20regularly%20updated%20every%20month.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EBest%20regards%2C%3C%2FP%3E%0A%3CP%3ETom%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1608033%22%20slang%3D%22en-US%22%3ERe%3A%20Automatically%20update%20newly%20released%20built-in%20policies%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1608033%22%20slang%3D%22en-US%22%3E%3CP%3EHello%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F699391%22%20target%3D%22_blank%22%3E%40Tom_Janetscheck%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20a%20lot%20for%20your%20help!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBest%20regards%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hello all,

 

I'm trying to understand if there is a way to automatically download newly built-in policies released by Microsoft in Audit mode or any way of getting notified when it is released in order to keep the policy initiative updated throughout the time

 

Are there any suggestions?

 

Thanks in advance.

 

Best regards

4 Replies
Best Response confirmed by gh91 (New Contributor)
Solution

Hi @gh91

if you are referring to the builtin policy initiative, Azure Security Center is using, then the answer is yes. The builtin (default) ASC policy initiative will automatically be updated with additional policies once they are published. If you are using a custom policy initiative, there are two different scenarios:

  1. if you are using builtin security policies in your custom initiative, these policies will also automatically be updated once there is a change. However, we will not update your policy initiative by adding additional policies once they are released.
  2. if you are exclusively using custom policies in your custom initiative, these policies will not automatically be updated.

Best regards,

Tom Janetscheck

Senior Program Manager

CxE | Azure Security Center

 

Hello @Tom_Janetscheck ,

 

Thank you very much for the detailed reply.

 

I'm looking to the scenario where I have a custom initiative with a mix of custom & built-in policies. Based on your reply, new built-in policies will not be added to the custom initiative once released.

 

In that way, is there a method to receive alerts or any page where I can see the new built-in policies released by Microsoft in order to keep my custom initiative updated with the latest policies? 

 

Thanks in advance!

Hello @gh91

there is no auto-notification option, but you'll find new policies mentioned in the Azure Security Center release notes, which are regularly updated every month. 

 

Best regards,

Tom

Hello @Tom_Janetscheck 

 

Thanks a lot for your help!

 

Best regards