I attempted to enforce security configuration changes on Windows Server machines using Azure Policy Guest Configuration (DeployIfNotExists), but despite successful evaluations and remediation tasks, the policies do not apply the changes

Anonym
2026-01-26T08:31:00.35+00:00

Problem description

I am trying to enforce security-related configuration changes on Windows Server machines using Azure Policy Guest Configuration.

What I did:

Initially, I used built-in Azure Guest Configuration policies to implement security option changes (e.g. User Account Control settings) on Windows Server machines (Azure Arc–enabled).

I noticed that the built-in policies are audit-only and do not enforce changes, even when remediation tasks are completed.

  • To address this, I created a custom Azure Policy using DeployIfNotExists with a guestConfigurationAssignment , intending to actively apply the configuration changes.

Issue:

The policy is evaluated and remediation tasks complete successfully.

However, no configuration changes are applied on the Windows Server machines.

  • The servers remain non-compliant, and the expected registry/settings values do not change.

Environment details:

OS: Windows Server

Management: Azure Arc–enabled servers

Policy type: Custom Azure Policy with Guest Configuration

  • Effect: DeployIfNotExists
  • Scope: Resource Group / Subscription

What I need help with:

  • Guidance on the correct and supported approach to enforce OS-level security settings on Windows Server using Azure Policy / Guest Configuration.
Azure Arc
Azure Arc

Ein Microsoft-Clouddienst, der die Bereitstellung von Azure-Diensten in Hybrid- und Multi-Cloud-Umgebungen ermöglicht


1 Antwort

Sortieren nach: Am hilfreichsten
  1. Bharath Y P 10,610 Zuverlässigkeitspunkte Externe Microsoft-Mitarbeiter Moderator
    2026-01-26T10:26:13.6666667+00:00

    Hello Mhd Zaher Shaiban. we understand that you are managing Windows Server machines that are Azure Arc–enabled. You want to enforce OS-level security settings (for example, UAC and other security options). You first tried built-in Azure Policy Guest Configuration (Machine Configuration) policies, but they were audit-only. You then created a custom Azure Policy with DeployIfNotExists and a guestConfigurationAssignment to actively apply/remediate those settings. Although Policy evaluation succeeds and Remediation tasks complete successfully. No actual configuration changes occur on the servers, and they remain non-compliant.

    Azure Policy Guest Configuration on Windows Server cannot enforce most OS security settings. Built-in and custom Guest Configuration policies for security options are audit-only by design. DeployIfNotExists only deploys the assignment; it does not force OS configuration changes. Remediation tasks re-run audits, they do not apply fixes for these settings.

    To resolve this you can try the below steps:

    Use Azure Policy Guest Configuration for auditing

    Assign Azure Policy Guest Configuration policies to Azure Arc–enabled Windows servers to audit OS security settings such as UAC, password policy, and audit policy. This provides centralized compliance visibility but does not enforce changes.

    Understand the enforcement limitation

    Guest Configuration runs in a restricted mode on Windows and cannot enforce security-related OS settings. Remediation tasks and DeployIfNotExists only redeploy assignments and re-run audits.

    Select a supported enforcement mechanism

    Choose a tool that has full control of the Windows OS to apply security settings.

    The Recommendation is Enforce using Group Policy

    For domain-joined servers, use Group Policy Objects (GPOs) to enforce UAC, password policies, audit policies, and local security options. This is the native and fully supported method.

    Other Alternative is Enforce using classic DSC

    For non-domain servers, use Azure Automation DSC or another configuration management tool to apply and maintain OS security settings.

    Monitor compliance with Azure Policy

    Use Azure Policy compliance reports to track drift and non-compliance. Perform remediation through GPO or DSC, not Azure Policy.

    Hope this helps, if you still encounter any issue, please help us with the below details.

    1. Can you confirm that the Microsoft.GuestConfiguration resource provider is registered?
    2. Have you checked the logs in C:\ProgramData\GuestConfig\gc_agent_logs\gc_agent.log for any errors or messages that could indicate what went wrong during the remediation?
    3. Are there any specific settings or configurations that you're trying to enforce apart from User Account Control settings?
    4. Are your servers behind a proxy or firewall that might restrict communication with Azure?
    5. Have you validated that the DSC scripts or custom configuration you’ve created correctly align with Azure Policy’s requirements?

    Here few reference document you can follow:

    List of built-in policy definitions - Azure Policy | Microsoft Learn

    Remediation options for guest configuration - Azure Policy | Azure Docs

    Understand the guest configuration feature of Azure Policy - Azure Policy | Azure Docs

    Cloud-native governance and policy with Azure Arc-enabled servers - Azure Arc | Microsoft Learn

    Determine causes of non-compliance - Azure Policy | Microsoft Learn

    War diese Antwort hilfreich?

    0 Kommentare Keine Kommentare

Ihre Antwort

Antworten können von Fragestellenden als „Angenommen“ und von Moderierenden als „Empfohlen“ gekennzeichnet werden, wodurch Benutzende wissen, dass diese Antwort das Problem des Fragestellenden gelöst hat.