Cloud Security: Azure Foundations
Azure 177 automated checks
Industry-standard cloud security hardening rules aligned with the CIS Azure Foundations Benchmark
App Service Security
- App Service must enforce HTTPS only
- App Service must use TLS 1.2 or higher
- App Service must require FTPS or disable FTP
- App Service should enable HTTP/2
- App Service should disable remote debugging
- App Service should require client certificates
- Logic App should restrict trigger access
- App Service Plan should enable zone redundancy
- App Service Slot should enforce HTTPS only
- Spring Cloud service should be deployed in a virtual network
Backup & Recovery
Cache Security
Compute Security
- Virtual Machine should use managed OS disk
- Virtual Machine should enable encryption at host
- Virtual Machine should enable vTPM
- Managed Disk should be encrypted
- Orphaned managed disks should be deleted
- VM Scale Set should enable automatic OS upgrades
- Disk Encryption Set should enable automatic key rotation
- Disk Encryption Set should use EncryptionAtRestWithCustomerKey
- Desktop Virtualization host pool should limit max session count
- Desktop Virtualization host pool should be a validation environment for testing updates
- DevTest Lab should restrict environment permissions
- Availability Set should have at least 2 fault domains
- Proximity Placement Group should have associated VMs
Configuration Security
Container Security
- Container Registry must disable admin user
- AKS cluster must enable RBAC
- AKS cluster should use Azure AD integration
- AKS cluster should enable Azure RBAC for Kubernetes
- Container App ingress should not be externally accessible unless required
- Container Apps Environment should be deployed in a virtual network
- Container Apps Environment should enable zone redundancy
- AKS node pool should enable encryption at host
- Container Registry Webhook should be active
Data & AI Security
- Data Factory should disable public network access
- Synapse workspace should disable public network access
- Synapse workspace should use managed virtual network
- Synapse workspace should enable double encryption
- HDInsight cluster should enforce TLS 1.2+
- HDInsight cluster should enable encryption in transit
- Kusto cluster should enable disk encryption
- Machine Learning workspace should disable public network access
- Machine Learning workspace should be configured as high business impact
- Stream Analytics job should use latest compatibility level
- Purview account should disable public network access
- Search service should disable public network access
Database Security
- SQL Server should use Azure AD-only authentication
- SQL Server must use TLS 1.2 minimum
- PostgreSQL should disable public network access
- MySQL Flexible Server should disable public network access
- MySQL Flexible Server must require secure transport
- SQL Managed Instance should disable public data endpoint
- SQL Managed Instance should enforce TLS 1.2+
- SQL Database should enable zone redundancy
- SQL Database should use geo-redundant backup storage
- Cassandra cluster should use password authentication
- SQL Elastic Pool should enable zone redundancy
DDoS & WAF
General Security
Identity & Access
- Cosmos DB should disable local authentication
- App Service must use managed identity
- Redis Cache should use managed identity
- No more than 3 owners assigned to subscription
- No guest users should have Owner role
- No custom roles should grant Owner-equivalent permissions
- No service principals should be subscription owners
- Custom roles should be minimized
- Security defaults or conditional access must be enabled
- Conditional access policies should be active
- Guest access should be restricted
- Container App should use managed identity
- VM Scale Set should use managed identity
- Data Factory should use managed identity
- SQL Managed Instance should use managed identity
- IoT Hub should disable local authentication
- Automation Account should disable local authentication
- App Configuration should disable local authentication
- Container Instance should use managed identity
- Machine Learning workspace should use managed identity
- Purview account should use managed identity
- Search service should disable local authentication
- CDN profile should use managed identity
- Event Grid topic should disable local authentication
- Event Grid domain should disable local authentication
- Web PubSub should disable local authentication
- Communication Service should use managed identity
- Maps account should disable local authentication
- Event Grid System Topic should use managed identity
- User Assigned Identity should have a valid principal
IoT Security
Key Management
- Key Vault must enable soft delete
- Key Vault must enable purge protection
- Key Vault should use RBAC authorization
- Key Vault should restrict public network access
- Managed HSM should enable purge protection
- Managed HSM should disable public network access
- Key Vault Secret should have an expiration date set
- Key Vault Secret should be enabled
Logging & Monitoring
- Key Vault should have diagnostic logging enabled
- Key Vault diagnostic logs should be sent to Log Analytics
- Cosmos DB should have diagnostic settings configured
- SQL Server should have diagnostic settings configured
- Scheduled query rule should be enabled
- Scheduled query rule should have at least one scope
- Data collection rule should have data flows configured
- Data collection rule should have destinations configured
- Action Group should be enabled
- Activity Log Alert should be enabled
- Data Collection Endpoint should disable public network access
- Metric Alert should be enabled
- Automation Runbook should enable verbose logging
Messaging Security
- Event Grid topic should disable public network access
- Event Grid domain should disable public network access
- Web PubSub should disable public network access
- Relay namespace should use Standard SKU
- Notification Hub namespace should use Standard or higher SKU
- Service Bus queue should enable dead-lettering on message expiration
- Service Bus queue should enable duplicate detection
- Service Bus topic should enable partitioning
- Service Bus topic should enable duplicate detection
- Event Hub should have sufficient message retention
- Event Hub should have multiple partitions for availability
Network Security
- NSG must not allow SSH from Internet
- NSG must not allow RDP from Internet
- All VNet subnets should have NSG associated
- Public IP should use Standard SKU
- Load Balancer should use Standard SKU
- Bastion Host should use Standard SKU
- Bastion Host should disable shareable link
- Firewall Policy should enable threat intelligence in Deny mode
- Firewall Policy should use Premium SKU tier
- Virtual Network Gateway should enable active-active configuration
- Virtual Network Gateway should use Generation2 VPN
- VPN Gateway should be successfully provisioned
- VPN Gateway should not use internet routing preference
- ExpressRoute Circuit should use Premium SKU tier
- ExpressRoute Circuit should be successfully provisioned
- NAT Gateway should use Standard SKU
- NAT Gateway should have public IP addresses assigned
- Traffic Manager should use HTTPS for endpoint monitoring
- Traffic Manager profile should be enabled
- Private DNS Zone should be linked to at least one virtual network
- DNS Zone should have name servers configured
- Route Table should have a default route for internet traffic control
- Route Table should disable BGP route propagation
- Network Watcher should be successfully provisioned
- Network Interface should have a Network Security Group attached
- Network Interface should not have a public IP address
- CDN endpoint should disable HTTP and enforce HTTPS only
- Connection Monitor should be actively monitoring
- Application Security Group should be in succeeded state
- IP Group should have IP addresses configured
Private Endpoints
Storage Security
- Storage account must enforce HTTPS transfer
- Storage account must use TLS 1.2 minimum
- Storage account must deny public network access by default
- Storage account must disable anonymous blob public access
- Storage account should use customer-managed keys
- Snapshot should disable public network access
- Snapshot should restrict network access policy
- Blob service should enable soft delete
- Blob service should enable versioning
Measure your Cloud Security: Azure Foundations posture
CGPulse maps live Azure and AWS findings to these controls and tracks drift over time.