Logic App should restrict trigger access
Medium
Azure
General
workflows-logic-app-restrict-trigger
Applies to
Microsoft.Logic/workflows
What CGPulse checks
A resource passes this rule when accessControl must be set true. Anything else is reported as a finding with the evaluated property value attached as evidence.
How to fix it
Configure access control to restrict who can trigger the Logic App workflow. In Azure Portal: Logic App > Settings > Access control (Preview) > restrict trigger access. See: https://learn.microsoft.com/en-us/azure/logic-apps/logic-apps-securing-a-logic-app
CLI
az resource update --ids "{id}" --set properties.accessControl.triggers.allowedCallerIpAddresses=[{{"addressRange":"<cidr>"}}]Terraform
resource "azurerm_logic_app_workflow" "{name}" {
name = "{name}"
resource_group_name = "{rg}"
location = var.location
access_control {
trigger {
allowed_caller_ip_address_range = ["<allowed-cidr>"]
}
}
}
Compliance frameworks
Is your environment compliant with this rule?
CGPulse checks it — and 621 others — against your Azure and AWS accounts with read-only access.
Related Azure rules
- Action Group should be enabled
- Activity Log Alert should be enabled
- AKS cluster logs should be sent to Log Analytics
- AKS cluster must enable RBAC
- AKS cluster must enable RBAC
- AKS cluster should be a private cluster
- AKS cluster should disable local accounts
- AKS cluster should enable Azure RBAC for Kubernetes