Remediation
From Azure Portalβ
- Navigate to the specific Azure Resource or Resource Group.
- For each mission critical resource, click
Locks. - Click
Add. - Give the lock a name and a description, then select the type,
Read-onlyorDeleteas appropriate. - Click
OK.
From Azure CLIβ
To lock a resource, provide the name of the resource, its resource type, and its resource group name:
az lock create \
--name {{lock-name}} \
--lock-type {{CanNotDelete/Read-only}} \
--resource-group {{resource-group-name}} \
--resource-name {{resource-name}} \
--resource-type {{resource-type}}
From Powershellβ
Get-AzResourceLock `
-ResourceName {{resource-name}} `
-ResourceType {{resource-type}} `
-ResourceGroupName {{resource-group-name}} `
-Locktype {{can-not-delete-or-read-only}}