Azure Monitor Baseline Alerts
Download AlertsGlossaryGitHubGitHub IssuesToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeBack to homepage

Policy Initiatives

In this page

Overview
Service Health Initiative
Notification Assets Initiative
Connectivity Initiative - Part #1
Connectivity Initiative - Part #2
Management Initiative
Identity Initiative
Azure VM Initiative
Hybrid VM Initiative
Key Management Initiative
Load Balancing Initiative
Network Changes Initiative
Recovery Services Initiative
Storage Initiative
Web Initiative
Landing Zone Initiative (Deprecated)

Overview

This document details the AMBA-ALZ pattern Azure policy initiatives used for deploying the AMBA-ALZ baselines. For references on individual alerts/policies, refer to Alert Details.

Service Health initiative

This initiative is intended for relevant policy assignment service health alerts in ALZ. Using the guidance provided in Introduction to deploying the AMBA-ALZ Pattern, this will assign to the alz intermediate root management group structure in the ALZ reference architecture. For details on the initiative policies and their default enablement state, refer to the table below.

Policy Display NamePolicy Internal NamePolicy Reference IDPolicy code (JSON)Default policy effect
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Service Health Action GroupDeploy_ServiceHealth_ActionGroupsALZ_ServiceHealth_ActionGroupsDeploy-ServiceHealth-ActionGroups.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Resource Health Unhealthy AlertDeploy_activitylog_ResourceHealth_Unhealthy_AlertALZ_ResHlthUnhealthyDeploy-ActivityLog-ResourceHealth-UnHealthly-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Service Health Advisory AlertDeploy_activitylog_ServiceHealth_HealthAdvisoryALZ_SvcHlthAdvisoryDeploy-ActivityLog-ServiceHealth-Health.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Service Health Incident AlertDeploy_activitylog_ServiceHealth_IncidentALZ_SvcHlthIncidentDeploy-ActivityLog-ServiceHealth-Incident.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Service Health Maintenance AlertDeploy_activitylog_ServiceHealth_MaintenanceALZ_SvcHlthMaintenanceDeploy-ActivityLog-ServiceHealth-Maintenance.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Service Health Security Advisory AlertDeploy_activitylog_ServiceHealth_SecurityAdvisoryALZ_svcHlthSecAdvisoryDeploy-ActivityLog-ServiceHealth-Security.jsondisabled

Notification Assets initiative

This initiative is intended for relevant policy assignment to notification in AMBA-ALZ. Using the guidance provided in Introduction to deploying the AMBA-ALZ Pattern, this will assign to the alz intermediate root management group structure in the ALZ reference architecture. For details on the initiative policies and their default enablement state, refer to the table below.

Policy Display NamePolicy Internal NamePolicy Reference IDPolicy code (JSON)Default policy effect
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Notification AssetsDeploy_AlertProcessing_RuleALZ_AlertProcessing_RuleDeploy-AlertProcessingRule-Deploy.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Notification Suppression AssetsDeploy_Suppression_AlertProcessing_RuleALZ_Suppression_AlertProcessing_RuleDeploy-AlertProcessingRule-Suppression.jsondeployIfNotExists

Connectivity initiative - Part #1

This initiative is intended for relevant policy assignment to networking components in ALZ. Using the guidance provided in Introduction to deploying the AMBA-ALZ Pattern, this will assign policies to the alz-platform-connectivity management group structure in the ALZ reference architecture. For details on the initiative policies and their default enablement state, refer to the table below.

Policy Display NamePolicy Internal NamePolicy Reference IDPolicy code (JSON)Default policy effect
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ExpressRoute Circuits QosDropBitsInPerSecond AlertDeploy_ERCIR_QosDropBitsInPerSecond_AlertALZ_ERCIRQoSDropBitsinPerSecDeploy-ERCIR-QOSDropsBitsIn-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ExpressRoute Circuits QosDropBitsOutPerSecond AlertDeploy_ERCIR_QosDropBitsOutPerSecond_AlertALZ_ERCIRQoSDropBitsoutPerSecDeploy-ERCIR-QOSDropsBitsOut-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - VPNG BGP Peer Status AlertDeploy_VPNGw_BGPPeerStatus_AlertALZ_VPNGwBGPPeerStatusDeploy-VPNG-BGPPeerStatus-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - VNetG ExpressRoute CPU Utilization AlertDeploy_VnetGw_ExpressRouteCpuUtil_AlertALZ_VnetGwERCpuUtilDeploy-VNETG-ERGCPUUtilization-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - VNetG Tunnel Bandwidth AlertDeploy_VnetGw_TunnelBandwidth_AlertALZ_VnetGwTunnelBWDeploy-VNETG-BandwidthUtilization-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - VNetG Tunnel Egress AlertDeploy_VnetGw_TunnelEgress_AlertALZ_VnetGwTunnelEgressDeploy-VNETG-Egress-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - VNetG Tunnel Ingress AlertDeploy_VnetGw_TunnelIngress_AlertALZ_VnetGwTunnelIngressDeploy-VNETG-Ingress-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - VPNG Bandwidth Utilization AlertDeploy_VPNGw_BandwidthUtil_AlertALZ_VPNGWBandWidthUtilDeploy-VPNG-BandwidthUtilization-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - VPNG Egress AlertDeploy_VPNGw_Egress_AlertALZ_VPNGWEgressDeploy-VPNG-Egress-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - VPNG Egress Packet Drop Count AlertDeploy_VPNGw_TunnelEgressPacketDropCount_AlertALZ_VPNGWTunnelEgressPacketDropCountDeploy-VPNG-EgressPacketDropCount-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - VPNG Egress Packet Drop Mismatch AlertDeploy_VPNGw_TunnelEgressPacketDropMismatch_AlertALZ_VPNGWTunnelEgressPacketDropMismatchDeploy-VPNG-EgressPacketDropMismatch-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - VPNG Ingress AlertDeploy_VPNGw_Ingress_AlertALZ_VPNGWIngressDeploy-VPNG-Ingress-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - VPNG Ingress Packet Drop Count AlertDeploy_VPNGw_TunnelIngressPacketDropCount_AlertALZ_VPNGWTunnelIngressPacketDropCountDeploy-VPNG-IngressPacketDropCount-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - VPNG Ingress Packet Drop Mismatch AlertDeploy_VPNGw_TunnelIngressPacketDropMismatch_AlertALZ_VPNGWTunnelIngressPacketDropMismatchDeploy-VPNG-IngressPacketDropMismatch-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - PDNSZ Capacity Utilization AlertDeploy_PDNSZ_CapacityUtil_AlertALZ_PDNSZCapacityUtilDeploy-PDNSZ-CapacityUtilization-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - PDNSZ Query Volume AlertDeploy_PDNSZ_QueryVolume_AlertALZ_PDNSZQueryVolumeDeploy-PDNSZ-QueryVolume-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - PDNSZ Record Set Capacity AlertDeploy_PDNSZ_RecordSetCapacity_AlertALZ_PDNSZRecordSetCapacityDeploy-PDNSZ-RecordSetCapacity-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - PDNSZ Registration Capacity Utilization AlertDeploy_DNSZ_RegistrationCapacityUtil_AlertALZ_PDNSZRegistrationCapacityUtilDeploy-PDNSZ-RegistrationCapacityUtilization-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ERG ExpressRoute Bits In AlertDeploy_ERGw_ExpressRouteBitsIn_AlertALZ_ERGwExpressRouteBitsInDeploy-ERG-BitsInPerSecond-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ERG ExpressRoute Bits Out AlertDeploy_ERGw_ExpressRouteBitsOut_AlertALZ_ERGwExpressRouteBitsOutDeploy-ERG-BitsOutPerSecond-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ERG ExpressRoute CPU Utilization AlertDeploy_ERGw_ExpressRouteCpuUtil_AlertALZ_ERGwExpressRouteCpuUtilDeploy-ERG-CPUUtilization-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - VNetG Egress Packet Drop Count AlertDeploy_VnetGw_TunnelEgressPacketDropCount_AlertALZ_VnetGwTunnelEgressPacketDropCountDeploy-VNETG-EgressPacketDropCount-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - VNetG Egress Packet Drop Mismatch AlertDeploy_VnetGw_TunnelEgressPacketDropMismatch_AlertALZ_VnetGwTunnelEgressPacketDropMismatchDeploy-VNETG-EgressPacketDropMismatch-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - VNetG ExpressRoute Bits Per Second AlertDeploy_VnetGw_ExpressRouteBitsPerSecond_AlertALZ_VnetGwExpressRouteBitsPerSecondDeploy-VNETG-ERGBitsPerSecond-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - VNetG Ingress Packet Drop Mismatch AlertDeploy_VnetGw_TunnelIngressPacketDropMismatch_AlertALZ_VnetGwTunnelIngressPacketDropMismatchDeploy-VNETG-IngressPacketDropMismatch-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - VNetG Ingress Packet Drop Count AlertDeploy_VnetGw_TunnelIngressPacketDropCount_AlertALZ_VnetGwTunnelIngressPacketDropCountDeploy-VNETG-IngressPacketDropCount-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ExpressRoute Circuits Bgp Availability AlertDeploy_ERCIR_BgpAvailability_AlertALZ_ERCIRBgpAvailabilityDeploy-ERCIR-BGPAvailability-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ExpressRoute Circuits Arp Availability AlertDeploy_ERCIR_ArpAvailability_AlertALZ_ERCIRArpAvailabilityDeploy-ERCIR-ARPAvailability-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - AFW SNATPortUtilization AlertDeploy_AFW_SNATPortUtilization_AlertALZ_AFWSNATPortUtilizationDeploy-AFW-SNATPortUtilization-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - PIP Bytes in DDoS Attack AlertDeploy_PublicIp_BytesInDDoSAttack_AlertALZ_PIPBytesInDDoSEvaluationFrequencyDeploy-PIP-BytesInDDOSAttack-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - PIP DDoS Attack AlertDeploy_PublicIp_DDoSAttack_AlertALZ_PIPDDoSAttackDeploy-PIP-DDOSAttack-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - PIP Packets in DDoS Attack AlertDeploy_PublicIp_PacketsInDDoSAttack_AlertALZ_PIPPacketsInDDoSDeploy-PIP-PacketsInDDOS-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - PIP VIP Availability AlertDeploy_PublicIp_VIPAvailability_AlertALZ_PIPVIPAvailabilityDeploy-PIP-VIPAvailability-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - VNet DDoS Attack AlertDeploy_VNET_DDoSAttack_AlertALZ_VNETDDOSAttackDeploy-VNET-DDOSAttack-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - AFW FirewallHealth AlertDeploy_AFW_FirewallHealth_AlertALZ_FirewallHealthDeploy-AFW-FirewallHealth-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log Azure FireWall Delete AlertDeploy_activitylog_Firewall_DeleteALZ_activityFWDeleteDeploy-ActivityLog-AzureFirewall-Del.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log NSG Delete AlertDeploy_activitylog_NSG_DeleteALZ_activityNSGDeleteDeploy-ActivityLog-NSG-Del.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log Route Table Update AlertDeploy_activitylog_RouteTable_UpdateALZ_activityUDRUpdateDeploy-ActivityLog-RouteTable-Update.jsondeployIfNotExists
[Preview]: Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log Route Table Delete AlertDeploy_activitylog_RouteTable_DeleteALZ_activityUDRDeleteDeploy-ActivityLog-RouteTable-Delete.jsondeployIfNotExists
[Preview]: Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log Routes Delete AlertDeploy_activitylog_RouteTable_Routes_DeleteALZ_activityUDRRoutesDeleteDeploy-ActivityLog-RouteTable-Routes-Delete.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log VPN Gateway Delete AlertDeploy_activitylog_VPNGateway_DeleteALZ_activityVPNGWDeleteDeploy-ActivityLog-VPNG-Del.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ALB Data Path Availability AlertDeploy_ALB_DataPathAvailability_AlertALZ_LBDataPathAvailabilityDeploy-LB-DatapathAvailability-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ALB Global Backend Availability AlertDeploy_ALB_GlobalBackendAvailability_AlertALZ_LBGlobalBackendAvailabilityDeploy-LB-GlobalBackendAvailability-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ALB Health Probe Status AlertDeploy_ALB_HealthProbeStatus_AlertALZ_LBHealthProbeStatusDeploy-LB-HealthProbeStatus-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ALB Used SNAT Ports AlertDeploy_ALB_UsedSNATPorts_AlertALZ_LBUsedSNATPortsDeploy-LB-UsedSNATPorts-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ER Direct ExpressRoute Bits In AlertDeploy_ERP_ExpressRouteBitsIn_AlertALZ_ERPBitsInPerSecondDeploy-ERP-BitsInPerSecond-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ER Direct ExpressRoute Bits Out AlertDeploy_ERP_ExpressRouteBitsOut_AlertALZ_ERPBitsOutPerSecondDeploy-ERP-BitsOutPerSecond-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ER Direct ExpressRoute LineProtocol AlertDeploy_ERP_ExpressRoutLineProtocol_AlertALZ_ERPLineProtocolDeploy-ERP-LineProtocol-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ER Direct ExpressRoute RxLightLevel High AlertDeploy_ERP_ExpressRoutRxLightLevel_AlertALZ_ERPRxLightLevelHighDeploy-ERP-RxLightLevelHigh-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ER Direct ExpressRoute RxLightLevel Low AlertDeploy_ERP_ExpressRoutRxLightLevellow_AlertALZ_ERPRxLightLevelLowDeploy-ERP-RxLightLevelLow-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ER Direct ExpressRoute TxLightLevel High AlertDeploy_ERP_ExpressRoutTxLightLevell_AlertALZ_ERPTxLightLevelHighDeploy-ERP-TxLightLevelHigh-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ER Direct ExpressRoute TxLightLevel Low AlertDeploy_ERP_ExpressRoutTxLightLevellow_AlertALZ_ERPTxLightLevelLowDeploy-ERP-TxLightLevelLow-Alert.jsondisabled

Connectivity initiative - Part #2

This second part of the initiative is intended for relevant policy assignment to networking components in ALZ. Using the guidance provided in Introduction to deploying the AMBA-ALZ Pattern, this will assign policies to the alz-platform-connectivity management group structure in the ALZ reference architecture. For details on the initiative policies and their default enablement state, refer to the table below.

Policy Display NamePolicy Internal NamePolicy Reference IDPolicy code (JSON)Default policy effect
[Preview]: Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - P2S Bandwidth AlertDeploy-P2SVPNGateways-P2SBandwidth-AlertALZ_P2SVPNGatewaysP2SBandwidthDeploy-p2svpngateways-P2SBandwidth-Alert.jsondeployIfNotExists
[Preview]: Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - User Vpn Route Count AlertDeploy-P2SVPNGateways-P2SConnectionCount-AlertALZ_P2SVPNGatewaysP2SConnectionCountDeploy-p2svpngateways-P2SConnectionCount-Alert.jsondeployIfNotExists
[Preview]: Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - User Vpn Route Count AlertDeploy-P2SVPNGateways-UserVpnRouteCount-AlertALZ_P2SVPNGatewaysUserVpnRouteCountDeploy-p2svpngateways-UserVpnRouteCount-Alert.jsondeployIfNotExists
[Preview]: Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Virtual Hubs Bgp Peer Status AlertDeploy-VirtualHubs-BgpPeerStatus-AlertALZ_VirtualHubsBgpPeerStatusDeploy-VirtualHubs-BgpPeerStatus-Alert.jsondeployIfNotExists
[Preview]: Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Count Of Routes Learned From Peer AlertDeploy-VirtualHubs-CountOfRoutesLearnedFromPeer-AlertALZ_VirtualHubsCountOfRoutesLearnedFromPeerDeploy-VirtualHubs-CountOfRoutesLearnedFromPeer-Alert.jsondeployIfNotExists
[Preview]: Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Virtual Hubs Count Of Routes Advertised To Peer AlertDeploy-VirtualHubs-CountOfRoutesAdvertisedToPeer-AlertALZ_VirtualHubsCountOfRoutesAdvertisedToPeerDeploy-VirtualHubs-CountOfRoutesAdvertisedToPeer-Alert.jsondeployIfNotExists
[Preview]: Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Spoke VM Utilization AlertDeploy-VirtualHubs-SpokeVMUtilization-AlertALZ_VirtualHubsSpokeVMUtilizationDeploy-VirtualHubs-SpokeVMUtilization-Alert.jsondeployIfNotExists
[Preview]: Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Routing Infrastructure Units AlertDeploy-VirtualHubs-RoutingInfrastructureUnits-AlertALZ_VirtualHubsRoutingInfrastructureUnitsDeploy-VirtualHubs-RoutingInfrastructureUnits-Alert.jsondeployIfNotExists
[Preview]: Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Virtual Hub Data Processed AlertDeploy-VirtualHubs-VirtualHubDataProcessed-AlertALZ_VirtualHubsVirtualHubDataProcessedDeploy-VirtualHubs-VirtualHubDataProcessed-Alert.jsondeployIfNotExists
[Preview]: Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - AFW ApplicationRuleHit AlertDeploy_AFW_ApplicationRuleHit_AlertALZ_AFWApplicationRuleHitDeploy-AFW-ApplicationRuleHit-Alert.jsondeployIfNotExists
[Preview]: Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Express Route Gateway Active Flows AlertDeploy_ERGw_ExpressRouteGatewayActiveFlows_AlertALZ_ERGwExpressRouteGatewayActiveFlowsDeploy-ERG-ExpressRouteGatewayActiveFlows-Alert.jsondisabled
[Preview]: Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - AFW NetworkRuleHit AlertDeploy_AFW_NetworkRuleHit_AlertALZ_AFWNetworkRuleHitDeploy-AFW-NetworkRuleHit-Alert.jsondeployIfNotExists

Management initiative

This initiative is intended for relevant policy assignment to management components in AMBA-ALZ. Using the guidance provided in Introduction to deploying the AMBA-ALZ Pattern, this will assign policies to the alz-platform-management group structure in the ALZ reference architecture. For details on the initiative policies and their default enablement state, refer to the table below.

Policy Display NamePolicy Internal NamePolicy Reference IDPolicy code (JSON)Default policy effect
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log LA Workspace Delete AlertDeploy_activitylog_LAWorkspace_DeleteALZ_activityLAWDeleteDeploy-ActivityLog-LAWorkspace-Del.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log LA Workspace Regenerate Key AlertDeploy_activitylog_LAWorkspace_KeyRegenALZ_activityLAWKeyRegenDeploy-ActivityLog-LAWorkspace-KeyRegen.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - LA Workspace Daily Cap Limit Reached AlertDeploy_LAWorkspace_DailyCapLimitReached_AlertALZ_LAWorkspaceDailyCapLimitReachedDeploy-LAWorkspace-DailyCapLimitReached-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Automation Account TotalJob AlertDeploy_AA_TotalJob_AlertALZ_AATotalJobDeploy-AA-TotalJob-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - RV Backup Health Monitoring AlertsDeploy_RecoveryVault_BackupHealthMonitor_AlertALZ_RVBackupHealthModify-RSV-BackupHealth-Alert.jsonmodify
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - RV ASR Health Monitoring AlertsDeploy_RecoveryVault_ASRHealthMonitor_AlertALZ_RVASRHealthMonitorModify-RSV-ASRHealth-Alert.jsonmodify
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - SA Availability AlertDeploy_StorageAccount_Availability_AlertALZ_StorageAccountAvailabilityDeploy-SA-Availability-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log Storage Account Delete AlertDeploy_activitylog_StorageAccount_DeleteALZ_activitySADeleteDeploy-ActivityLog-SA-Delete-Alert.jsondeployIfNotExists

Identity initiative

This initiative is intended for relevant policy assignment to identity components in ALZ. Using the guidance provided in Introduction to deploying the AMBA-ALZ Pattern, this will assign policies to the alz-platform-identity management group structure in the ALZ reference architecture. For details on the initiative policies and their default enablement state, refer to the table below.

Policy Display NamePolicy Internal NamePolicy Reference IDPolicy code (JSON)Default policy effect
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Key Vault Requests AlertDeploy_KeyVault_Requests_AlertALZ_KVRequestDeploy-KV-Requests-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Key Vault Availability AlertDeploy_KeyVault_Availability_AlertALZ_KvAvailabilityDeploy-KV-Availability-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Key Vault Latency AlertDeploy_KeyVault_Latency_AlertALZ_KvLatencyAvailabilityDeploy-KV-Latency-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Key Vault Capacity AlertDeploy_KeyVault_Capacity_AlertALZ_KVCapacityDeploy-KV-Capacity-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log Key Vault Delete AlertDeploy_activitylog_KeyVault_DeleteALZ_activityKVDeleteDeploy-ActivityLog-KeyVault-Del.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Managed HSMs Availability AlertDeploy_ManagedHSMs_Availability_AlertALZ_ManagedHSMsAvailabilityDeploy-HSMs-Availability-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Managed HSMs Latency AlertDeploy_ManagedHSMs_Latency_AlertALZ_ManagedHSMsLatencyAvailabilityDeploy-HSMs-Latency-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log Managed HSMs Delete AlertDeploy_ActivityLog_ManagedHSMs_DeleteALZ_activityManagedHSMsDeleteDeploy-ActivityLog-HSMs-Del.jsondeployIfNotExists

Azure VM initiative

This initiative deploys Azure Monitor Baseline Alerts to monitor Azure Virtual Machines. Using the guidance provided in Introduction to deploying the AMBA-ALZ Pattern this will be assigned to the Landing Zones management group in the ALZ reference architecture. For details on the initiative policies and their default enablement state, refer to the table below.

Policy Display NamePolicy Internal NamePolicy Reference IDPolicy code (JSON)Default policy effect
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Azure VM HeartBeat AlertDeploy_VM_HeartBeat_AlertALZ_VMHeartBeatRGDeploy-VM-HeartBeat-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Azure VM Network Read AlertDeploy_VM_NetworkIn_AlertALZ_VMNetworkInDeploy-VM-NetworkIn-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Azure VM Network Write AlertDeploy_VM_NetworkOut_AlertALZ_VMNetworkOutDeploy-VM-NetworkOut-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Azure VM OS Disk Read Latency AlertDeploy_VM_OSDiskreadLatency_AlertALZ_VMOSDiskReadLatencyDeploy-VM-OSDiskReadLatency-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Azure VM OS Disk Write Latency AlertDeploy_VM_OSDiskwriteLatency_AlertALZ_VMOSDiskWriteLatencyDeploy-VM-OSDiskWriteLatency-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Azure VM OS Disk Space AlertDeploy_VM_OSDiskSpace_AlertALZ_VMOSDiskSpaceDeploy-VM-OSDiskSpace-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Azure VM CPU AlertDeploy_VM_CPU_AlertALZ_VMPercentCPUDeploy-VM-PercentCPU-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Azure VM Memory AlertDeploy_VM_Memory_AlertALZ_VMPercentMemoryDeploy-VM-PercentMemory-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Azure VM Data Disk Space AlertDeploy_VM_dataDiskSpace_AlertALZ_VMDataDiskSpaceDeploy-VM-DataDiskSpace-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Azure VM Data Disk Read Latency AlertDeploy_VM_dataDiskReadLatency_AlertALZ_VMDataDiskReadLatencyDeploy-VM-DataDiskReadLatency-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Azure VM Data Disk Write Latency AlertDeploy_VM_dataDiskWriteLatency_AlertALZ_VMDataDiskWriteLatencyDeploy-VM-DataDiskWriteLatency-Alert.jsondeployIfNotExists

Hybrid VM initiative

This initiative is intended for relevant policy assignment to Hybrid VM alerts in AMBA-ALZ. Using the guidance provided in Introduction to deploying the AMBA-ALZ Pattern, this will be assigned to the ‘alz’ intermediate root management group structure in the ALZ reference architecture. For details on the initiative policies and their default enablement state, refer to the table below.

Policy Display NamePolicy Internal NamePolicy Reference IDPolicy code (JSON)Default policy effect
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Hybrid VM HeartBeat AlertDeploy_Hybrid_VM_HeartBeat_AlertALZ_HybridVMHeartBeatRGDeploy-Hybrid-VM-HeartBeat-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Hybrid VM Network Read AlertDeploy_Hybrid_VM_NetworkIn_AlertALZ_HybridVMNetworkInDeploy-Hybrid-VM-NetworkIn-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Hybrid VM Network Write AlertDeploy_Hybrid_VM_NetworkOut_AlertALZ_HybridVMNetworkOutDeploy-Hybrid-VM-NetworkOut-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Hybrid VM OS Disk Read Latency AlertDeploy_Hybrid_VM_OSDiskreadLatency_AlertALZ_HybridVMOSDiskReadLatencyDeploy-Hybrid-VM-OSDiskReadLatency-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Hybrid VM OS Disk Write Latency AlertDeploy_Hybrid_VM_OSDiskwriteLatency_AlertALZ_HybridVMOSDiskWriteLatencyDeploy-Hybrid-VM-OSDiskWriteLatency-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Hybrid VM OS Disk Space AlertDeploy_Hybrid_VM_OSDiskSpace_AlertALZ_HybridVMOSDiskSpaceDeploy-Hybrid-VM-OSDiskSpace-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Hybrid VM CPU AlertDeploy_Hybrid_VM_CPU_AlertALZ_HybridVMPercentCPUDeploy-Hybrid-VM-PercentCPU-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Hybrid VM Memory AlertDeploy_Hybrid_VM_Memory_AlertALZ_HybridVMPercentMemoryDeploy-Hybrid-VM-PercentMemory-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Hybrid VM Data Disk Space AlertDeploy_Hybrid_VM_dataDiskSpace_AlertALZ_HybridVMDataDiskSpaceDeploy-Hybrid-VM-DataDiskSpace-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Hybrid VM Data Disk Read Latency AlertDeploy_Hybrid_VM_dataDiskReadLatency_AlertALZ_HybridVMDataDiskReadLatencyDeploy-Hybrid-VM-DataDiskReadLatency-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Hybrid VM Data Disk Write Latency AlertDeploy_Hybrid_VM_dataDiskWriteLatency_AlertALZ_HybridVMDataDiskWriteLatencyDeploy-Hybrid-VM-DataDiskWriteLatency-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Hybrid VM Disconnected AlertDeploy_Hybrid_VM_Disconnected_AlertALZ_HybridVMDisconnectedDeploy-Hybrid-VM-Disconnected-Alert.jsondeployIfNotExists

Key Management initiative

This initiative deploys Azure Monitor Baseline Alerts to monitor Key Management Services such as Azure Key Vault, and Managed HSM. Using the guidance provided in Introduction to deploying the AMBA-ALZ Pattern this will be assigned to the Landing Zones management group in the ALZ reference architecture. For details on the initiative policies and their default enablement state, refer to the table below.

Policy Display NamePolicy Internal NamePolicy Reference IDPolicy code (JSON)Default policy effect
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Key Vault Requests AlertDeploy_KeyVault_Requests_AlertALZ_KVRequestDeploy-KV-Requests-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Key Vault Availability AlertDeploy_KeyVault_Availability_AlertALZ_KvAvailabilityDeploy-KV-Availability-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Key Vault Latency AlertDeploy_KeyVault_Latency_AlertALZ_KvLatencyAvailabilityDeploy-KV-Latency-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Key Vault Capacity AlertDeploy_KeyVault_Capacity_AlertALZ_KVCapacityDeploy-KV-Capacity-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log Key Vault Delete AlertDeploy_activitylog_KeyVault_DeleteALZ_activityKVDeleteDeploy-ActivityLog-KeyVault-Del.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Managed HSMs Availability AlertDeploy_ManagedHSMs_Availability_AlertALZ_ManagedHSMsAvailabilityDeploy-HSMs-Availability-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Managed HSMs Latency AlertDeploy_ManagedHSMs_Latency_AlertALZ_ManagedHSMsLatencyAvailabilityDeploy-HSMs-Latency-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log Managed HSMs Delete AlertDeploy_ActivityLog_ManagedHSMs_DeleteALZ_activityManagedHSMsDeleteDeploy-ActivityLog-HSMs-Del.jsondeployIfNotExists

Load Balancing initiative

This initiative deploys Azure Monitor Baseline Alerts to monitor Load Balancing Services such as Load Balancer, Application Gateway, Traffic Manager, and Azure Front Door. Using the guidance provided in Introduction to deploying the AMBA-ALZ Pattern this will be assigned to the Landing Zones management group in the ALZ reference architecture. For details on the initiative policies and their default enablement state, refer to the table below.

Policy Display NamePolicy Internal NamePolicy Reference IDPolicy code (JSON)Default policy effect
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - PIP Bytes in DDoS Attack AlertDeploy_PublicIp_BytesInDDoSAttack_AlertALZ_PIPBytesInDDoSDeploy-PIP-BytesInDDOSAttack-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - PIP DDoS Attack AlertDeploy_PublicIp_DDoSAttack_AlertALZ_PIPDDoSAttackDeploy-PIP-DDOSAttack-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - PIP Packets in DDoS Attack AlertDeploy_PublicIp_PacketsInDDoSAttack_AlertALZ_PIPPacketsInDDoSDeploy-PIP-PacketsInDDOS-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - PIP VIP Availability AlertDeploy_PublicIp_VIPAvailability_AlertALZ_PIPVIPAvailabilityDeploy-PIP-VIPAvailability-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - VNet DDoS Attack AlertDeploy_VNET_DDoSAttack_AlertALZ_VNETDDOSAttackDeploy-VNET-DDOSAttack-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - AGW ApplicationGatewayTotalTime AlertDeploy_AG_ApplicationGatewayTotalTime_AlertALZ_AGWTotalTimeDeploy-AGW-ApplicationGatewayTotalTime-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - AGW BackendLastByteResponseTime AlertDeploy_AG_BackendLastByteResponseTime_AlertALZ_AGWBackendLastByteResponseTimeDeploy-AGW-BackendLastByteResponseTime-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - AGW Capacity Units AlertDeploy_AG_CapacityUnits_AlertALZ_AGWCapacityUnitsDeploy-AGW-CapacityUnits-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - AGW Compute Units AlertDeploy_AG_ComputeUnits_AlertALZ_AGWComputeUnitsDeploy-AGW-ComputeUnits-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - AGW CPU Utilization AlertDeploy_AG_CPUUtilization_AlertALZ_AGWCPUUtilizationDeploy-AGW-CPUUtil-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - AGW FailedRequests AlertDeploy_AG_FailedRequests_AlertALZ_AGWFailedRequestsDeploy-AGW-FailedRequests-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - AGW ResponseStatus AlertDeploy_AG_ResponseStatus_AlertALZ_AGWResponseStatusDeploy-AGW-ResponseStatus-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - AGW Unhealthy Host Count AlertDeploy_AG_UnhealthyHostCount_AlertALZ_AGWUnhealthyHostCountDeploy-AGW-UnhealthyHostCount-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ALB Data Path Availability AlertDeploy_ALB_DataPathAvailability_AlertALZ_LBDataPathAvailabilityDeploy-LB-DatapathAvailability-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ALB Global Backend Availability AlertDeploy_ALB_GlobalBackendAvailability_AlertALZ_LBGlobalBackendAvailabilityDeploy-LB-GlobalBackendAvailability-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ALB Health Probe Status AlertDeploy_ALB_HealthProbeStatus_AlertALZ_LBHealthProbeStatusDeploy-LB-HealthProbeStatus-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ALB Used SNAT Ports AlertDeploy_ALB_UsedSNATPorts_AlertALZ_LBUsedSNATPortsDeploy-LB-UsedSNATPorts-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - FrontDoor CDN Profile Origin Health Percentage AlertDeploy_FrontDoorCDN_OriginHealthPercentage_AlertALZ_CDNPOriginHealthPercentageDeploy-CDNP-OriginHealthPercentage-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - FrontDoor CDN Profile Origin Latency AlertDeploy_FrontDoorCDN_OriginLatency_AlertALZ_CDNPOriginLatencyDeploy-CDNP-OriginLatency-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - FrontDoor CDN Profile Percentage4XX AlertDeploy_FrontDoorCDN_Percentage4XX_AlertALZ_CDNPPercentage4XXDeploy-CDNP-Percentage4XX-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - FrontDoor CDN Profile Percentage5XX AlertDeploy_FrontDoorCDN_Percentage5XX_AlertALZ_CDNPPercentage5XXDeploy-CDNP-Percentage5XX-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Traffic Manager Endpoint Health AlertDeploy_TM_EndpointHealth_AlertALZ_TMEndpointHealthDeploy-TM-EndpointHealth-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Frontdoor Backend Health Percentage AlertDeploy_FD_BackendHealth_AlertALZ_FDBackendHealthDeploy-FD-BackendHealth-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Frontdoor Backend Request Latency AlertDeploy_FD_BackendRequestLatency_AlertALZ_FDBackendRequestLatencyDeploy-FD-BackendRequestLatency-Alert.jsondisabled

Network Changes initiative

This initiative implements Azure Monitor Baseline Alerts to monitor alterations in Network Routing and Security, such as modifications to Route Tables and the removal of Network Security Groups. Using the guidance provided in Introduction to deploying the AMBA-ALZ Pattern this will be assigned to the Landing Zones management group in the ALZ reference architecture. For details on the initiative policies and their default enablement state, refer to the table below.

Policy Display NamePolicy Internal NamePolicy Reference IDPolicy code (JSON)Default policy effect
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log NSG Delete AlertDeploy_activitylog_NSG_DeleteALZ_activityNSGDeleteDeploy-ActivityLog-NSG-Del.jsondeployIfNotExists
[Preview]: Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log Routes Delete AlertDeploy_activitylog_RouteTable_Routes_DeleteALZ_activityUDRRoutesDeleteDeploy-ActivityLog-RouteTable-Routes-Delete.jsondeployIfNotExists
[Preview]: Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log Route Table Delete AlertDeploy_activitylog_RouteTable_DeleteALZ_activityUDRDeleteDeploy-ActivityLog-RouteTable-Delete.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log Route Table Update AlertDeploy_activitylog_RouteTable_UpdateALZ_activityUDRUpdateDeploy-ActivityLog-RouteTable-Update.jsondeployIfNotExists

Recovery Services initiative

This initiative deploys Azure Monitor Baseline Alerts to monitor Recovery Services such as Azure Backup, and Azure Site Recovery. Using the guidance provided in Introduction to deploying the AMBA-ALZ Pattern this will be assigned to the Landing Zones management group in the ALZ reference architecture. For details on the initiative policies and their default enablement state, refer to the table below.

Policy Display NamePolicy Internal NamePolicy Reference IDPolicy code (JSON)Default policy effect
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - RV Backup Health Monitoring AlertsDeploy_RecoveryVault_BackupHealthMonitor_AlertALZ_RVBackupHealthMonitorModify-RSV-BackupHealth-Alert.jsonmodify
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - RV ASR Health Monitoring AlertsDeploy_RecoveryVault_ASRHealthMonitor_AlertALZ_RVASRHealthMonitorModify-RSV-ASRHealth-Alert.jsonmodify

Storage initiative

This initiative deploys Azure Monitor Baseline Alerts to monitor Storage Services such as Storage accounts. Using the guidance provided in Introduction to deploying the AMBA-ALZ Pattern this will be assigned to the Landing Zones management group in the ALZ reference architecture. For details on the initiative policies and their default enablement state, refer to the table below.

Policy Display NamePolicy Internal NamePolicy Reference IDPolicy code (JSON)Default policy effect
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - SA Availability AlertDeploy_StorageAccount_Availability_AlertALZ_StorageAccountAvailabilityDeploy-SA-Availability-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log Storage Account Delete AlertDeploy_activitylog_StorageAccount_DeleteALZ_activitySADeleteDeploy-ActivityLog-SA-Delete-Alert.jsondeployIfNotExists

Web initiative

This initiative deploys Azure Monitor Baseline Alerts to monitor Web Services such as App Services. It is intended for relevant policy assignment to a landing zone in the ALZ structure. Using the guidance provided in Introduction to deploying the AMBA-ALZ Pattern this will be assigned to the Landing Zones management group in the ALZ reference architecture. For details on the initiative policies and their default enablement state, refer to the table below.

Policy Display NamePolicy Internal NamePolicy Reference IDPolicy code (JSON)Default policy effect
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - App Service Plan CPU Percentage AlertDeploy_WSF_CPUPercentage_AlertALZ_WSFCPUPercentageDeploy-WSF-CPUPercentage-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - App Service Plan Memory Percentage AlertDeploy_WSF_MemoryPercentage_AlertALZ_WSFMemoryPercentageDeploy-WSF-MemoryPercentage-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - App Service Plan Disk Queue Length AlertDeploy_WSF_DiskQueueLength_AlertALZ_WSFDiskQueueLengthDeploy-WSF-DiskQueueLength-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - App Service Plan Http Queue Length AlertDeploy_WSF_HttpQueueLength_AlertALZ_WSFHttpQueueLengthDeploy-WSF-HttpQueueLength-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Application Insights Throttling Limit Reached AlertDeploy_AppInsightsThrottlingLimit_AlertALZ_AppInsightsThrottlingLimitReached_AlertDeploy-AppInsightsThrottlingLimit-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log Application Insights Delete AlertDeploy_ActivityLog_AppInsights_DeleteALZ_activityAppInsightsDeleteDeploy-ActivityLog-AppInsights-Del.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log LA Workspace Delete AlertDeploy_activitylog_LAWorkspace_DeleteALZ_activityLAWDeleteDeploy-ActivityLog-LAWorkspace-Del.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log LA Workspace Regenerate Key AlertDeploy_activitylog_LAWorkspace_KeyRegenALZ_activityLAWKeyRegenDeploy-ActivityLog-LAWorkspace-KeyRegen.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - LA Workspace Daily Cap Limit Reached AlertDeploy_LAWorkspace_DailyCapLimitReached_AlertALZ_LAWorkspaceDailyCapLimitReachedDeploy-LAWorkspace-DailyCapLimitReached-Alert.jsondeployIfNotExists

Landing Zone initiative (Deprecated)

This initiative has been DEPRECATED and the content is still included in the documentation for reference purpose only.

This initiative is intended for relevant policy assignment to a landing zone in the ALZ structure. Using the guidance provided in Introduction to deploying the AMBA-ALZ Pattern this will be assigned to the Landing Zones management group in the ALZ reference architecture. For details on the initiative policies and their default enablement state, refer to the table below.

Policy Display NamePolicy Internal NamePolicy Reference IDPolicy code (JSON)Default policy effect
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Key Vault Requests AlertDeploy_KeyVault_Requests_AlertALZ_KVRequestDeploy-KV-Requests-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Key Vault Availability AlertDeploy_KeyVault_Availability_AlertALZ_KvAvailabilityDeploy-KV-Availability-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Key Vault Latency AlertDeploy_KeyVault_Latency_AlertALZ_KvLatencyAvailabilityDeploy-KV-Latency-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Key Vault Capacity AlertDeploy_KeyVault_Capacity_AlertALZ_KVCapacityDeploy-KV-Capacity-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log Key Vault Delete AlertDeploy_activitylog_KeyVault_DeleteALZ_activityKVDeleteDeploy-ActivityLog-KeyVault-Del.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - SA Availability AlertDeploy_StorageAccount_Availability_AlertALZ_StorageAccountAvailabilityDeploy-SA-Availability-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log Storage Account Delete AlertDeploy_activitylog_StorageAccount_DeleteALZ_activitySADeleteDeploy-ActivityLog-SA-Delete-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - PIP Bytes in DDoS Attack AlertDeploy_PublicIp_BytesInDDoSAttack_AlertALZ_PIPBytesInDDoSDeploy-PIP-BytesInDDOSAttack-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - PIP DDoS Attack AlertDeploy_PublicIp_DDoSAttack_AlertALZ_PIPDDoSAttackDeploy-PIP-DDOSAttack-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - PIP Packets in DDoS Attack AlertDeploy_PublicIp_PacketsInDDoSAttack_AlertALZ_PIPPacketsInDDoSDeploy-PIP-PacketsInDDOS-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - PIP VIP Availability AlertDeploy_PublicIp_VIPAvailability_AlertALZ_PIPVIPAvailabilityDeploy-PIP-VIPAvailability-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log NSG Delete AlertDeploy_activitylog_NSG_DeleteALZ_activityNSGDeleteDeploy-ActivityLog-NSG-Del.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Activity Log Route Table Update AlertDeploy_activitylog_RouteTable_UpdateALZ_activityUDRUpdateDeploy-ActivityLog-RouteTable-Update.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - RV Backup Health Monitoring AlertsDeploy_RecoveryVault_BackupHealthMonitor_AlertALZ_RVBackupHealthMonitorModify-RSV-BackupHealth-Alert.jsonmodify
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - VNet DDoS Attack AlertDeploy_VNET_DDoSAttack_AlertALZ_VNETDDOSAttackDeploy-VNET-DDOSAttack-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Azure VM HeartBeat AlertDeploy_VM_HeartBeat_AlertALZ_VMHeartBeatRGDeploy-VM-HeartBeat-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Azure VM Network Read AlertDeploy_VM_NetworkIn_AlertALZ_VMNetworkInDeploy-VM-NetworkIn-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Azure VM Network Write AlertDeploy_VM_NetworkOut_AlertALZ_VMNetworkOutDeploy-VM-NetworkOut-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Azure VM OS Disk Read Latency AlertDeploy_VM_OSDiskreadLatency_AlertALZ_VMOSDiskReadLatencyDeploy-VM-OSDiskReadLatency-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Azure VM OS Disk Write Latency AlertDeploy_VM_OSDiskwriteLatency_AlertALZ_VMOSDiskWriteLatencyDeploy-VM-OSDiskWriteLatency-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Azure VM OS Disk Space AlertDeploy_VM_OSDiskSpace_AlertALZ_VMOSDiskSpaceDeploy-VM-OSDiskSpace-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Azure VM CPU AlertDeploy_VM_CPU_AlertALZ_VMPercentCPUDeploy-VM-PercentCPU-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Azure VM Memory AlertDeploy_VM_Memory_AlertALZ_VMPercentMemoryDeploy-VM-PercentMemory-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Azure VM Data Disk Space AlertDeploy_VM_dataDiskSpace_AlertALZ_VMDataDiskSpaceDeploy-VM-DataDiskSpace-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Azure VM Data Disk Read Latency AlertDeploy_VM_dataDiskReadLatency_AlertALZ_VMDataDiskReadLatencyDeploy-VM-DataDiskReadLatency-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Azure VM Data Disk Write Latency AlertDeploy_VM_dataDiskWriteLatency_AlertALZ_VMDataDiskWriteLatencyDeploy-VM-DataDiskWriteLatency-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - AGW ApplicationGatewayTotalTime AlertDeploy_AG_ApplicationGatewayTotalTime_AlertALZ_AGWTotalTimeDeploy-AGW-ApplicationGatewayTotalTime-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - AGW BackendLastByteResponseTime AlertDeploy_AG_BackendLastByteResponseTime_AlertALZ_AGWBackendLastByteResponseTimeDeploy-AGW-BackendLastByteResponseTime-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - AGW Capacity Units AlertDeploy_AG_CapacityUnits_AlertALZ_AGWCapacityUnitsDeploy-AGW-CapacityUnits-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - AGW Compute Units AlertDeploy_AG_ComputeUnits_AlertALZ_AGWComputeUnitsDeploy-AGW-ComputeUnits-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - AGW CPU Utilization AlertDeploy_AG_CPUUtilization_AlertALZ_AGWCPUUtilizationDeploy-AGW-CPUUtil-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - AGW FailedRequests AlertDeploy_AG_FailedRequests_AlertALZ_AGWFailedRequestsDeploy-AGW-FailedRequests-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - AGW ResponseStatus AlertDeploy_AG_ResponseStatus_AlertALZ_AGWResponseStatusDeploy-AGW-ResponseStatus-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - AGW Unhealthy Host Count AlertDeploy_AG_UnhealthyHostCount_AlertALZ_AGWUnhealthyHostCountDeploy-AGW-UnhealthyHostCount-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ALB Data Path Availability AlertDeploy_ALB_DataPathAvailability_AlertALZ_LBDataPathAvailabilityDeploy-LB-DatapathAvailability-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ALB Global Backend Availability AlertDeploy_ALB_GlobalBackendAvailability_AlertALZ_LBGlobalBackendAvailabilityDeploy-LB-GlobalBackendAvailability-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ALB Health Probe Status AlertDeploy_ALB_HealthProbeStatus_AlertALZ_LBHealthProbeStatusDeploy-LB-HealthProbeStatus-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - ALB Used SNAT Ports AlertDeploy_ALB_UsedSNATPorts_AlertALZ_LBUsedSNATPortsDeploy-LB-UsedSNATPorts-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - FrontDoor CDN Profile Origin Health Percentage AlertDeploy_FrontDoorCDN_OriginHealthPercentage_AlertALZ_CDNPOriginHealthPercentageDeploy-CDNP-OriginHealthPercentage-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - FrontDoor CDN Profile Origin Latency AlertDeploy_FrontDoorCDN_OriginLatency_AlertALZ_CDNPOriginLatencyDeploy-CDNP-OriginLatency-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - FrontDoor CDN Profile Percentage4XX AlertDeploy_FrontDoorCDN_Percentage4XX_AlertALZ_CDNPPercentage4XXDeploy-CDNP-Percentage4XX-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - FrontDoor CDN Profile Percentage5XX AlertDeploy_FrontDoorCDN_Percentage5XX_AlertALZ_CDNPPercentage5XXDeploy-CDNP-Percentage5XX-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Traffic Manager Endpoint Health AlertDeploy_TM_EndpointHealth_AlertALZ_TMEndpointHealthDeploy-TM-EndpointHealth-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - App Service Plan CPU Percentage AlertDeploy_WSF_CPUPercentage_AlertALZ_WSFCPUPercentageDeploy-WSF-CPUPercentage-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - App Service Plan Memory Percentage AlertDeploy_WSF_MemoryPercentage_AlertALZ_WSFMemoryPercentageDeploy-WSF-MemoryPercentage-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - App Service Plan Disk Queue Length AlertDeploy_WSF_DiskQueueLength_AlertALZ_WSFDiskQueueLengthDeploy-WSF-DiskQueueLength-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - App Service Plan Http Queue Length AlertDeploy_WSF_HttpQueueLength_AlertALZ_WSFHttpQueueLengthDeploy-WSF-HttpQueueLength-Alert.jsondeployIfNotExists
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Frontdoor Backend Health Percentage AlertDeploy_FD_BackendHealth_AlertALZ_FDBackendHealthDeploy-FD-BackendHealth-Alert.jsondisabled
Deploy Azure Monitor Baseline Alerts (AMBA-ALZ) - Frontdoor Backend Request Latency AlertDeploy_FD_BackendRequestLatency_AlertALZ_FDBackendRequestLatencyDeploy-FD-BackendRequestLatency-Alert.jsondisabled