Cloud Security Baseline
Azure 166 automated checks
Recommended security best practices for cloud services, based on common compliance frameworks
Asset Management
Backup & Recovery
Data Protection
- Storage account must enforce HTTPS transfer
- Storage account must use TLS 1.2 minimum
- Storage account blob encryption must be enabled
- App Service must use TLS 1.2 or higher
- App Service must require FTPS or disable FTP
- Key Vault must enable soft delete
- Key Vault must enable purge protection
- SQL Server must use TLS 1.2 minimum
- Redis Cache must disable non-SSL port
- Redis Cache must use TLS 1.2 minimum
- Event Hub must use TLS 1.2 minimum
- Service Bus must use TLS 1.2 minimum
- MySQL Flexible Server must require secure transport
- Application Gateway should use TLS 1.2 or higher
- Virtual Machine should enable encryption at host
- Storage account should use customer-managed keys
- Managed Disk should be encrypted
- Virtual Network should have encryption enabled
- Cosmos DB should enforce TLS 1.2 or higher
- Container Registry should use customer-managed key encryption
- Storage account should have file service encryption enabled
- Front Door should have HTTPS enabled on all frontend endpoints
- Front Door should redirect HTTP to HTTPS
- API Management should enforce TLS 1.2 or higher
- Batch account should use customer-managed key encryption
Endpoint Security
Identity & Access
- App Service must use managed identity
- Key Vault should use RBAC authorization
- SQL Server should use Azure AD-only authentication
- Virtual Machine should use managed identity
- Container Registry must disable admin user
- Container Registry should use managed identity
- Cosmos DB should disable local authentication
- Cosmos DB should use managed identity
- Event Hub should disable local authentication
- Service Bus should disable local authentication
- PostgreSQL Flexible Server should use managed identity
- AKS cluster must enable RBAC
- AKS cluster should use Azure AD integration
- AKS cluster should disable local accounts
- AKS cluster should use managed identity
- No more than 3 owners assigned to subscription
- No guest users should have Owner role
- No service principals should be subscription owners
- No custom roles should grant Owner-equivalent permissions
- Custom roles should be minimized
- Security defaults or conditional access must be enabled
- Conditional access policies should be active
- Guest access should be restricted
- App Service should require client certificates
- Subscription should not have excessive role assignments
- User Access Administrator count should be limited
- Storage account should use Managed Identity
- SQL Server should use Managed Identity
- API Management should use Managed Identity
- Cognitive Services should disable local authentication
- Cognitive Services should use Managed Identity
- SignalR Service should disable local authentication
- SignalR Service should require client certificates
- Batch account should use User Subscription pool allocation mode
Logging & Monitoring
- Storage account should have diagnostic settings configured
- Key Vault should have diagnostic logging enabled
- SQL Server should have diagnostic settings configured
- App Service should have diagnostic settings configured
- Key Vault diagnostic logs should be sent to Log Analytics
- SQL Server should have diagnostic settings configured
- Virtual Machine should have diagnostic settings configured
- Network Security Group should have diagnostic settings configured
- Container Registry should have diagnostic settings configured
- Cosmos DB should have diagnostic settings configured
- Redis Cache should have diagnostic settings configured
- Event Hub should have diagnostic settings configured
- Service Bus should have diagnostic settings configured
- PostgreSQL should have diagnostic settings configured
- AKS cluster should have diagnostic settings configured
- MySQL should have diagnostic settings configured
- Application Gateway should have diagnostic settings configured
- Public IP address should have diagnostic settings configured
- Managed Disk should have diagnostic settings configured
- Virtual Network should have diagnostic settings configured
- Storage account logs should be sent to Log Analytics
- App Service logs should be sent to Log Analytics
- Virtual Machine logs should be sent to Log Analytics
- NSG logs should be sent to Log Analytics
- Container Registry logs should be sent to Log Analytics
- Cosmos DB logs should be sent to Log Analytics
- Redis Cache logs should be sent to Log Analytics
- Event Hub logs should be sent to Log Analytics
- Service Bus logs should be sent to Log Analytics
- PostgreSQL logs should be sent to Log Analytics
- AKS cluster logs should be sent to Log Analytics
- MySQL logs should be sent to Log Analytics
- Application Gateway logs should be sent to Log Analytics
- Public IP address logs should be sent to Log Analytics
- Managed Disk logs should be sent to Log Analytics
- Virtual Network logs should be sent to Log Analytics
- Defender for Virtual Machines should be enabled
- Defender for App Services should be enabled
- Defender for SQL Servers should be enabled
- Defender for Storage should be enabled
- Defender for Key Vault should be enabled
- Defender for Resource Manager should be enabled
- Defender for Containers should be enabled
- Defender for DNS should be enabled
- Log Analytics workspace retention should be at least 90 days
- Azure Firewall should have diagnostic settings configured
- Azure Firewall logs should be sent to Log Analytics
- Log Analytics workspace should have diagnostic settings configured
Network Security
- Storage account must deny public network access by default
- Storage account must disable anonymous blob public access
- App Service must enforce HTTPS only
- App Service should enable HTTP/2
- Key Vault should restrict public network access
- SQL Server should disable public network access
- NSG must not allow SSH from Internet
- NSG must not allow RDP from Internet
- NSG should not allow HTTP from Internet
- Container Registry should restrict public network access
- Cosmos DB should disable public network access
- Redis Cache should restrict public network access
- Event Hub should restrict public network access
- Service Bus should restrict public network access
- PostgreSQL should disable public network access
- Key Vault should use private endpoints
- SQL Server should use private endpoints
- Storage account should use private endpoints
- Cosmos DB should use private endpoints
- Redis Cache should use private endpoints
- Container Registry should use private endpoints
- AKS cluster should have network policy configured
- AKS cluster should be a private cluster
- MySQL Flexible Server should disable public network access
- Application Gateway should have WAF enabled
- Application Gateway WAF should be in Prevention mode
- App Service should disable remote debugging
- App Service should route all traffic through VNet
- Public IP should use Standard SKU
- Managed Disk should disable public network access
- Virtual Network should have DDoS protection enabled
- All VNet subnets should have NSG associated
- Azure Firewall should use Standard or Premium tier
- Azure Firewall Premium should enable intrusion detection (IDPS)
- Azure Firewall should have Threat Intelligence enabled
- Azure Firewall should have DNS Proxy enabled
- Key Vault should disable public network access
- Container Registry should restrict network access
- Public IP address should have DDoS protection
- Front Door should have Web Application Firewall enabled
- Front Door should have health probes configured
- Front Door should be in Enabled state
- API Management should disable public network access
- API Management should be integrated with a Virtual Network
- Cognitive Services should disable public network access
- Cognitive Services should restrict network access
- SignalR Service should disable public network access
- Batch account should disable public network access
Measure your Cloud Security Baseline posture
CGPulse maps live Azure and AWS findings to these controls and tracks drift over time.