Azure security rules
331 checks CGPulse evaluates against live Azure resources.
General
- Action Group should be enabled
- Activity Log Alert should be enabled
- AKS cluster logs should be sent to Log Analytics
- AKS cluster must enable RBAC
- AKS cluster must enable RBAC
- AKS cluster should be a private cluster
- AKS cluster should disable local accounts
- AKS cluster should enable Azure RBAC for Kubernetes
- AKS cluster should have diagnostic settings configured
- AKS cluster should have network policy configured
- AKS cluster should use Azure AD integration
- AKS cluster should use managed identity
- AKS node pool should enable encryption at host
- All VNet subnets should have NSG associated
- API Management should be integrated with a Virtual Network
- API Management should disable public network access
- API Management should enforce TLS 1.2 or higher
- API Management should use Managed Identity
- App Configuration should disable local authentication
- App Configuration should disable public network access
- App Configuration should enable purge protection
- App Service logs should be sent to Log Analytics
- App Service must disable FTP or require FTPS only
- App Service must enforce HTTPS only
- App Service must require FTPS or disable FTP
- App Service must use managed identity
- App Service must use managed identity for automatic logoff and credential management
- App Service must use TLS 1.2 or higher
- App Service Plan should enable zone redundancy
- App Service should disable remote debugging
- App Service should enable HTTP/2
- App Service should have diagnostic settings configured
- App Service should require client certificates
- App Service should route all traffic through VNet
- App Service Slot should enforce HTTPS only
- Application Gateway logs should be sent to Log Analytics
- Application Gateway should have diagnostic settings configured
- Application Gateway should have WAF enabled
- Application Gateway should use TLS 1.2 or higher
- Application Gateway WAF should be in Prevention mode
- Application Security Group should be in succeeded state
- Automation Account should disable local authentication
- Automation Account should disable public network access
- Automation Runbook should enable verbose logging
- Availability Set should have at least 2 fault domains
- Azure Firewall logs should be sent to Log Analytics
- Azure Firewall Premium should enable intrusion detection (IDPS)
- Azure Firewall should have diagnostic settings configured
- Azure Firewall should have DNS Proxy enabled
- Azure Firewall should have Threat Intelligence enabled
- Azure Firewall should use Standard or Premium tier
- Bastion Host should disable shareable link
- Bastion Host should use Standard SKU
- Batch account should disable public network access
- Batch account should use customer-managed key encryption
- Batch account should use User Subscription pool allocation mode
- Blob service should enable soft delete
- Blob service should enable versioning
- Cassandra cluster should use password authentication
- CDN endpoint should disable HTTP and enforce HTTPS only
- CDN profile should use managed identity
- Cognitive Services should disable local authentication
- Cognitive Services should disable public network access
- Cognitive Services should restrict network access
- Cognitive Services should use Managed Identity
- Communication Service should use managed identity
- Compute Gallery should enable soft delete
- Conditional access policies should be active
- Connection Monitor should be actively monitoring
- Container App ingress should not be externally accessible unless required
- Container App should use managed identity
- Container Apps Environment should be deployed in a virtual network
- Container Apps Environment should enable zone redundancy
- Container Instance should use managed identity
- Container Registry logs should be sent to Log Analytics
- Container Registry must disable admin user
- Container Registry must not allow anonymous pull for asset control
- Container Registry should have diagnostic settings configured
- Container Registry should restrict network access
- Container Registry should restrict public network access
- Container Registry should use customer-managed key encryption
- Container Registry should use managed identity
- Container Registry should use private endpoints
- Container Registry Webhook should be active
- Cosmos DB logs should be sent to Log Analytics
- Cosmos DB should disable local authentication
- Cosmos DB should disable public network access
- Cosmos DB should enable automatic failover
- Cosmos DB should enforce TLS 1.2 or higher
- Cosmos DB should have diagnostic settings configured
- Cosmos DB should use managed identity
- Cosmos DB should use private endpoints
- Custom roles should be minimized
- Data Collection Endpoint should disable public network access
- Data collection rule should have data flows configured
- Data collection rule should have destinations configured
- Data Factory should disable public network access
- Data Factory should use managed identity
- DDoS Protection Plan should be associated with virtual networks
- DDoS Protection Plan should be successfully provisioned
- Defender for App Services should be enabled
- Defender for Containers should be enabled
- Defender for DNS should be enabled
- Defender for Key Vault should be enabled
- Defender for Resource Manager should be enabled
- Defender for SQL Servers should be enabled
- Defender for Storage should be enabled
- Defender for Virtual Machines should be enabled
- Desktop Virtualization host pool should be a validation environment for testing updates
- Desktop Virtualization host pool should limit max session count
- DevTest Lab should restrict environment permissions
- Disk Encryption Set should enable automatic key rotation
- Disk Encryption Set should use EncryptionAtRestWithCustomerKey
- DNS Zone should have name servers configured
- Event Grid domain should disable local authentication
- Event Grid domain should disable public network access
- Event Grid System Topic should use managed identity
- Event Grid topic should disable local authentication
- Event Grid topic should disable public network access
- Event Hub logs should be sent to Log Analytics
- Event Hub must use TLS 1.2 minimum
- Event Hub should disable local authentication
- Event Hub should have diagnostic settings configured
- Event Hub should have multiple partitions for availability
- Event Hub should have sufficient message retention
- Event Hub should restrict public network access
- ExpressRoute Circuit should be successfully provisioned
- ExpressRoute Circuit should use Premium SKU tier
- Firewall Policy should enable threat intelligence in Deny mode
- Firewall Policy should use Premium SKU tier
- Front Door should be in Enabled state
- Front Door should have health probes configured
- Front Door should have HTTPS enabled on all frontend endpoints
- Front Door should have Web Application Firewall enabled
- Front Door should redirect HTTP to HTTPS
- Guest access should be restricted
- HDInsight cluster should enable encryption in transit
- HDInsight cluster should enforce TLS 1.2+
- IoT Hub should disable local authentication
- IoT Hub should disable public network access
- IoT Hub should enforce TLS 1.2+
- IP Group should have IP addresses configured
- Key Vault diagnostic logs should be sent to Log Analytics
- Key Vault must enable purge protection
- Key Vault must enable soft delete
- Key Vault must have soft delete and purge protection for contingency planning
- Key Vault Secret should be enabled
- Key Vault Secret should have an expiration date set
- Key Vault should disable public network access
- Key Vault should have diagnostic logging enabled
- Key Vault should restrict public network access
- Key Vault should use private endpoints
- Key Vault should use RBAC authorization
- Kusto cluster should enable disk encryption
- Load Balancer should use Standard SKU
- Log Analytics workspace retention should be at least 90 days
- Log Analytics workspace should have diagnostic settings configured
- Logic App should restrict trigger access
- Machine Learning workspace should be configured as high business impact
- Machine Learning workspace should disable public network access
- Machine Learning workspace should use managed identity
- Managed Disk logs should be sent to Log Analytics
- Managed Disk should be encrypted
- Managed Disk should disable public network access
- Managed Disk should have diagnostic settings configured
- Managed HSM should disable public network access
- Managed HSM should enable purge protection
- Maps account should disable local authentication
- Metric Alert should be enabled
- MySQL backup retention should be at least 7 days
- MySQL Flexible Server must require secure transport
- MySQL Flexible Server should disable public network access
- MySQL logs should be sent to Log Analytics
- MySQL should have diagnostic settings configured
- MySQL should have geo-redundant backup enabled
- NAT Gateway should have public IP addresses assigned
- NAT Gateway should use Standard SKU
- Network Interface should have a Network Security Group attached
- Network Interface should not have a public IP address
- Network Security Group should have diagnostic settings configured
- Network Watcher should be successfully provisioned
- No custom roles should grant Owner-equivalent permissions
- No guest users should have Owner role
- No more than 3 owners assigned to subscription
- No service principals should be subscription owners
- Notification Hub namespace should use Standard or higher SKU
- NSG logs should be sent to Log Analytics
- NSG must have security rules configured to restrict inbound traffic
- NSG must not allow RDP from Internet
- NSG must not allow SSH from Internet
- NSG should not allow HTTP from Internet
- Organization should assess third-party vendor security
- Organization should conduct penetration testing
- Organization should conduct periodic risk assessments
- Organization should conduct security awareness training
- Organization should deploy and maintain anti-malware software
- Organization should establish a data management process
- Organization should establish a data recovery process
- Organization should establish a secure configuration process
- Organization should establish a security awareness program
- Organization should establish an access control process
- Organization should establish an account management process
- Organization should establish an audit log management process
- Organization should establish an incident response program
- Organization should establish network monitoring and defense
- Organization should have a business continuity and disaster recovery plan
- Organization should have a documented incident response plan
- Organization should have a formal change management process
- Organization should have a vulnerability management program
- Organization should implement email security protections
- Organization should implement HR security controls
- Organization should implement physical security controls
- Organization should maintain a data classification policy
- Organization should maintain a privacy policy
- Organization should maintain an inventory of enterprise hardware assets
- Organization should maintain an inventory of enterprise software assets
- Organization should perform periodic access reviews
- Orphaned managed disks should be deleted
- PostgreSQL backup retention should be at least 7 days
- PostgreSQL Flexible Server should have high availability enabled
- PostgreSQL Flexible Server should use managed identity
- PostgreSQL logs should be sent to Log Analytics
- PostgreSQL should disable public network access
- PostgreSQL should have diagnostic settings configured
- Private DNS Zone should be linked to at least one virtual network
- Private Endpoint connection should be in Approved state
- Private Endpoint should have custom DNS configuration
- Proximity Placement Group should have associated VMs
- Public IP address logs should be sent to Log Analytics
- Public IP address should have DDoS protection
- Public IP address should have diagnostic settings configured
- Public IP should be associated with a resource
- Public IP should use Standard SKU
- Purview account should disable public network access
- Purview account should use managed identity
- Recovery Services vault should disable public network access
- Recovery Services vault should enable immutability
- Recovery Services vault should enable soft delete
- Redis Cache logs should be sent to Log Analytics
- Redis Cache must disable non-SSL port
- Redis Cache must use TLS 1.2 minimum
- Redis Cache should have diagnostic settings configured
- Redis cache should have patch schedule configured
- Redis Cache should restrict public network access
- Redis Cache should use managed identity
- Redis Cache should use private endpoints
- Relay namespace should use Standard SKU
- Resource lock should use CanNotDelete or ReadOnly level
- Route Table should disable BGP route propagation
- Route Table should have a default route for internet traffic control
- Scheduled query rule should be enabled
- Scheduled query rule should have at least one scope
- Search service should disable local authentication
- Search service should disable public network access
- Security defaults or conditional access must be enabled
- Service Bus logs should be sent to Log Analytics
- Service Bus must use TLS 1.2 minimum
- Service Bus queue should enable dead-lettering on message expiration
- Service Bus queue should enable duplicate detection
- Service Bus should disable local authentication
- Service Bus should have diagnostic settings configured
- Service Bus should restrict public network access
- Service Bus topic should enable duplicate detection
- Service Bus topic should enable partitioning
- SignalR Service should disable local authentication
- SignalR Service should disable public network access
- SignalR Service should require client certificates
- Snapshot should disable public network access
- Snapshot should restrict network access policy
- Spring Cloud service should be deployed in a virtual network
- SQL Database should enable zone redundancy
- SQL Database should use geo-redundant backup storage
- SQL Elastic Pool should enable zone redundancy
- SQL Managed Instance should disable public data endpoint
- SQL Managed Instance should enforce TLS 1.2+
- SQL Managed Instance should use managed identity
- SQL Server must use TLS 1.2 minimum
- SQL Server must use TLS 1.2 or higher
- SQL Server should disable public network access
- SQL Server should have diagnostic settings configured
- SQL Server should have diagnostic settings configured
- SQL Server should use Azure AD-only authentication
- SQL Server should use Managed Identity
- SQL Server should use private endpoints
- Storage account blob encryption must be enabled
- Storage account logs should be sent to Log Analytics
- Storage account must deny public network access by default
- Storage account must disable anonymous blob public access
- Storage account must enforce HTTPS transfer
- Storage account must use customer-managed or Microsoft-managed encryption keys
- Storage account must use TLS 1.2 minimum
- Storage account should have diagnostic settings configured
- Storage account should have file service encryption enabled
- Storage account should use customer-managed keys
- Storage account should use Managed Identity
- Storage account should use private endpoints
- Stream Analytics job should use latest compatibility level
- Subscription should not have excessive role assignments
- Synapse workspace should disable public network access
- Synapse workspace should enable double encryption
- Synapse workspace should use managed virtual network
- Traffic Manager profile should be enabled
- Traffic Manager should use HTTPS for endpoint monitoring
- User Access Administrator count should be limited
- User Assigned Identity should have a valid principal
- Virtual Machine logs should be sent to Log Analytics
- Virtual Machine must enable encryption at host
- Virtual Machine must have endpoint protection installed
- Virtual Machine OS disk must use managed disks
- Virtual Machine should enable encryption at host
- Virtual Machine should enable Trusted Launch (Secure Boot)
- Virtual Machine should enable vTPM
- Virtual Machine should have antimalware extension installed
- Virtual Machine should have diagnostic settings configured
- Virtual Machine should have monitoring agent installed
- Virtual Machine should use managed identity
- Virtual Machine should use managed OS disk
- Virtual Network Gateway should enable active-active configuration
- Virtual Network Gateway should use Generation2 VPN
- Virtual Network logs should be sent to Log Analytics
- Virtual Network should have DDoS protection enabled
- Virtual Network should have diagnostic settings configured
- Virtual Network should have encryption enabled
- VM Scale Set should enable automatic OS upgrades
- VM Scale Set should use managed identity
- VPN Gateway should be successfully provisioned
- VPN Gateway should not use internet routing preference
- WAF Policy should be enabled
- WAF Policy should be in Prevention mode
- Web PubSub should disable local authentication
- Web PubSub should disable public network access