output/20260723_081532/govviz/ALZ_20260723_081601/Enterprise-Scale/src/resources/Microsoft.Authorization/policyDefinitions/Deny-StorageAccount-CustomDomain.json

{
    "name": "Deny-StorageAccount-CustomDomain",
    "type": "Microsoft.Authorization/policyDefinitions",
    "apiVersion": "2021-06-01",
    "scope": null,
    "properties": {
      "policyType": "Custom",
      "mode": "All",
      "displayName": "Storage Accounts with custom domains assigned should be denied",
      "description": "This policy denies the creation of Storage Accounts with custom domains assigned as communication cannot be encrypted, and always uses HTTP.",
      "metadata": {
        "version": "1.0.0",
        "category": "Storage",
        "source": "https://github.com/Azure/Enterprise-Scale/",
        "alzCloudEnvironments": [
          "AzureCloud",
          "AzureChinaCloud",
          "AzureUSGovernment"
        ]
      },
      "parameters": {
        "effect": {
          "type": "String",
          "defaultValue": "Deny",
          "allowedValues": [
            "Audit",
            "Deny",
            "Disabled"
          ],
          "metadata": {
            "displayName": "Effect",
            "description": "The effect determines what happens when the policy rule is evaluated to match"
          }
        }
      },
      "policyRule": {
        "if": {
            "allOf": [
              {
                "field": "type",
                "equals": "Microsoft.Storage/storageAccounts"
              },
              {
                "anyOf": [
                  {
                    "field": "Microsoft.Storage/storageAccounts/customDomain",
                    "exists": "true"
                  },
                  {
                    "field": "Microsoft.Storage/storageAccounts/customDomain.useSubDomainName",
                    "equals": "true"
                  }
                ]
              }
            ]
        },
        "then": {
          "effect": "[[parameters('effect')]"
        }
      }
    }
  }