IP Group should have IP addresses configured
Medium
Azure
General
ipgroups-group-addresses-configured
Applies to
Microsoft.Network/ipGroups
What CGPulse checks
A resource passes this rule when ipAddressCount must be greater than 0. Anything else is reported as a finding with the evaluated property value attached as evidence.
How to fix it
Configure IP addresses in the IP Group or remove unused groups to keep firewall rules clean. In Azure Portal: IP Groups > select group > add IP addresses. See: https://learn.microsoft.com/en-us/azure/firewall/ip-groups
CLI
az network ip-group update --ids "{id}" --add ipAddresses "<ip-address>"Terraform
resource "azurerm_ip_group" "{name}" {
name = "{name}"
resource_group_name = "{rg}"
location = var.location
cidrs = ["<ip-address-1>/32", "<ip-address-2>/32"]
}
Compliance frameworks
Is your environment compliant with this rule?
CGPulse checks it — and 621 others — against your Azure and AWS accounts with read-only access.
Related Azure rules
- Action Group should be enabled
- Activity Log Alert should be enabled
- AKS cluster logs should be sent to Log Analytics
- AKS cluster must enable RBAC
- AKS cluster must enable RBAC
- AKS cluster should be a private cluster
- AKS cluster should disable local accounts
- AKS cluster should enable Azure RBAC for Kubernetes