Main areas covered
| Section | Area | Description |
|---|---|---|
| 1 | Identity and access management | RBAC configuration, restrictions on custom Subscription Owner roles, and diagnostic settings |
| 2 | Microsoft Defender for Cloud | Defender for Cloud plans, security contacts, and notifications |
| 3 | Storage accounts | Secure transfer enforcement, public-access blocking, blob soft delete, and infrastructure encryption |
| 4 | Database services | SQL TDE, SSL enforcement for MySQL and PostgreSQL, AAD integrated authentication, and audit log retention |
| 5 | Logging and monitoring | Diagnostic Settings, retention periods, and Activity Log alerts |
| 6 | Networking | NSG restrictions on SSH/RDP, Network Watcher Flow Logs, and Application Gateway WAF |
| 7 | Virtual machines | Managed disks, disk encryption, network connections, and limits on public IP and sensitive-port exposure |
| 8 | Key Vault | Soft delete, purge protection, key and secret expiration dates, and audit logs |
| 9 | App Service | HTTPS Only, TLS 1.2 or later, Managed Identity, and disabling FTP |