Hamburger Icon
  • Labs icon Lab
  • Cloud
Azure icon
Labs

Govern Azure Arc-enabled Servers

In this hands-on lab, you'll configure Azure policies to check the compliance of software updates and schedule the installation of missing updates on both Windows and Linux using Azure Policy and Azure Update Manager.

Azure icon
Labs

Path Info

Level
Clock icon Intermediate
Duration
Clock icon 45m
Published
Clock icon Feb 18, 2025

Contact sales

By filling out this form and clicking submit, you acknowledge our privacy policy.

Table of Contents

  1. Challenge

    Create a Maintenance Configuration

    1. Create a maintenance configuration to schedule weekly updates on Arc-enabled VMs/servers using the default classifications, inclusions, and exclusions.
    2. Make a note of the maintenance configuration Resource ID, as it will be required to complete the following objectives.
  2. Challenge

    Assign Azure Policies

    1. Assign three Policies to the lab Resource Group:
      • Configure periodic checking for missing system updates on Azure Arc-enabled servers for Windows VMs/Servers.
      • Configure periodic checking for missing system updates on Azure Arc-enabled servers for Linux VMs/Servers.
      • Schedule recurring updates using Azure Update Manager for Arc-enabled Servers, and exclude Azure Virtual Machines from this policy.

    Important: Ensure policy remediation is performed using the existing Managed identity named id-policyremediation. This user assigned Managed identity has the approprate role-based access control assignements to perform Policy remedation.

  3. Challenge

    Review Configuration in Azure Update Manager

    1. Review the configuration in Azure Update Manager:
      • Ensure that Periodic assessment is enabled for the Arc-enabled Servers.
      • Ensure that the maintenance configuration is associated with the Arc-enabled Servers.
  4. Challenge

    Remediate Non-compliant Resources

    1. Remediate any non-compliant policie assignments using Remediation tasks.

    Note: Change the scope of the Remediation tasks blade to the Resource Group to remove the Access is denied to the requested resource... when the remediation tasks list is scoped to the Subscription. You have access to the Resource Group in this lab, not the entire Subscription.

The Cloud Content team comprises subject matter experts hyper focused on services offered by the leading cloud vendors (AWS, GCP, and Azure), as well as cloud-related technologies such as Linux and DevOps. The team is thrilled to share their knowledge to help you build modern tech solutions from the ground up, secure and optimize your environments, and so much more!

What's a lab?

Hands-on Labs are real environments created by industry experts to help you learn. These environments help you gain knowledge and experience, practice without compromising your system, test without risk, destroy without fear, and let you learn from your mistakes. Hands-on Labs: practice your skills before delivering in the real world.

Provided environment for hands-on practice

We will provide the credentials and environment necessary for you to practice right within your browser.

Guided walkthrough

Follow along with the author’s guided walkthrough and build something new in your provided environment!

Did you know?

On average, you retain 75% more of your learning if you get time for practice.