diff --git a/built-in-policies/policyDefinitions/Cosmos DB/CosmosDbAdvancedThreatProtection_Deploy.json b/built-in-policies/policyDefinitions/Cosmos DB/CosmosDbAdvancedThreatProtection_Deploy.json index ef18bf50a..ec3bdb182 100644 --- a/built-in-policies/policyDefinitions/Cosmos DB/CosmosDbAdvancedThreatProtection_Deploy.json +++ b/built-in-policies/policyDefinitions/Cosmos DB/CosmosDbAdvancedThreatProtection_Deploy.json @@ -25,8 +25,22 @@ }, "policyRule": { "if": { - "field": "type", - "equals": "Microsoft.DocumentDB/databaseAccounts" + "allOf": [ + { + "field": "type", + "equals": "Microsoft.DocumentDB/databaseAccounts" + }, + { + "field": "Microsoft.DocumentDB/databaseAccounts/capabilities[*].name", + "notin": [ + "EnableMongo", + "EnableCassandra", + "EnableTable", + "EnableGremlin" + ] + } + ] + }, "then": { "effect": "[parameters('effect')]", @@ -75,4 +89,4 @@ }, "id": "/providers/Microsoft.Authorization/policyDefinitions/b5f04e03-92a3-4b09-9410-2cc5e5047656", "name": "b5f04e03-92a3-4b09-9410-2cc5e5047656" -} \ No newline at end of file +}