Ein Microsoft-Clouddienst, der die Bereitstellung von Azure-Diensten in Hybrid- und Multi-Cloud-Umgebungen ermöglicht
Hello Mhd Zaher Shaiban. we understand that you are managing Windows Server machines that are Azure Arc–enabled. You want to enforce OS-level security settings (for example, UAC and other security options). You first tried built-in Azure Policy Guest Configuration (Machine Configuration) policies, but they were audit-only. You then created a custom Azure Policy with DeployIfNotExists and a guestConfigurationAssignment to actively apply/remediate those settings. Although Policy evaluation succeeds and Remediation tasks complete successfully. No actual configuration changes occur on the servers, and they remain non-compliant.
Azure Policy Guest Configuration on Windows Server cannot enforce most OS security settings. Built-in and custom Guest Configuration policies for security options are audit-only by design. DeployIfNotExists only deploys the assignment; it does not force OS configuration changes. Remediation tasks re-run audits, they do not apply fixes for these settings.
To resolve this you can try the below steps:
Use Azure Policy Guest Configuration for auditing
Assign Azure Policy Guest Configuration policies to Azure Arc–enabled Windows servers to audit OS security settings such as UAC, password policy, and audit policy. This provides centralized compliance visibility but does not enforce changes.
Understand the enforcement limitation
Guest Configuration runs in a restricted mode on Windows and cannot enforce security-related OS settings. Remediation tasks and DeployIfNotExists only redeploy assignments and re-run audits.
Select a supported enforcement mechanism
Choose a tool that has full control of the Windows OS to apply security settings.
The Recommendation is Enforce using Group Policy
For domain-joined servers, use Group Policy Objects (GPOs) to enforce UAC, password policies, audit policies, and local security options. This is the native and fully supported method.
Other Alternative is Enforce using classic DSC
For non-domain servers, use Azure Automation DSC or another configuration management tool to apply and maintain OS security settings.
Monitor compliance with Azure Policy
Use Azure Policy compliance reports to track drift and non-compliance. Perform remediation through GPO or DSC, not Azure Policy.
Hope this helps, if you still encounter any issue, please help us with the below details.
- Can you confirm that the
Microsoft.GuestConfigurationresource provider is registered? - Have you checked the logs in
C:\ProgramData\GuestConfig\gc_agent_logs\gc_agent.logfor any errors or messages that could indicate what went wrong during the remediation? - Are there any specific settings or configurations that you're trying to enforce apart from User Account Control settings?
- Are your servers behind a proxy or firewall that might restrict communication with Azure?
- Have you validated that the DSC scripts or custom configuration you’ve created correctly align with Azure Policy’s requirements?
Here few reference document you can follow:
List of built-in policy definitions - Azure Policy | Microsoft Learn
Remediation options for guest configuration - Azure Policy | Azure Docs
Understand the guest configuration feature of Azure Policy - Azure Policy | Azure Docs
Cloud-native governance and policy with Azure Arc-enabled servers - Azure Arc | Microsoft Learn
Determine causes of non-compliance - Azure Policy | Microsoft Learn