-
Notifications
You must be signed in to change notification settings - Fork 459
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Feature Request]: Allow Resource level policy exemption #2996
Labels
Comments
Draft
8 tasks
Draft
8 tasks
Team will revisit the issue next week |
AlexanderSehr
changed the title
[Feature Request]: StorageAccounts - Allow Resource level policy exemption
[Feature Request]: Allow Resource level policy exemption
Apr 13, 2023
Blocking the overall implementation for the moment until we were able to sort out the remaining questions in the PR. If the PR is rejected afterall, this issue will be closed too - if not (i.e., it is merged), we may move it out of blocked again. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
Description
The current policyExemption modules only support exemptions at the MG, Sub, or RG levels. When policyExemptions are deployed to resources, they are treated as extensions. We need this capability to allow the creation of a storage account with public access when we have a policy applied to the Sub or MG that blocks this access.
If implemented, this would need to be added to all resource types as assignments can be created on every resource's level.
The text was updated successfully, but these errors were encountered: