Documentation
| Article | Path |
|---|---|
| Review AKS network policy settings | ansible/azure/aks_network_policy_misconfigured |
| Review Azure Activity Log retention | ansible/azure/small_activity_log_retention_period |
| Review the Ansible Azure authentication user | ansible/azure/sql_server_predictable_active_directory_admin_account_name |
| Review the Microsoft Entra administrator for Azure SQL | ansible/azure/ad_admin_not_configured_for_sql_server |
| Review the Azure SQL administrator login name | ansible/azure/sql_server_predictable_admin_account_name |
| Review Cosmos DB account IP access restrictions | ansible/azure/cosmosdb_account_ip_range_filter_not_set |
| Cosmos DB account tags are missing | ansible/azure/cosmosdb_account_without_tags |
| Azure Web App permits HTTP access | ansible/azure/web_app_accepting_traffic_other_than_https |
| Azure Storage account does not require HTTPS | ansible/azure/storage_account_not_forcing_https |
| Kubernetes RBAC is disabled for AKS | ansible/azure/aks_rbac_disabled |
| Redis Cache firewall permits an excessive address range | ansible/azure/firewall_rule_allows_too_many_hosts_to_access_redis_cache |
| TLS enforcement is disabled for Azure PostgreSQL | ansible/azure/ssl_enforce_is_disabled |
| TLS enforcement is disabled for Azure MySQL | ansible/azure/mysql_ssl_connection_disabled |
| Review Azure Key Vault soft-delete protection | ansible/azure/key_vault_soft_delete_is_disabled |
| Review WAF protection for Azure Application Gateway | ansible/azure/waf_is_disabled_for_azure_application_gateway |
| Review the Redis firewall address range | ansible/azure/redis_publicly_accessible |
| Storage account network rules may allow broad access | ansible/azure/public_storage_account |
| Azure blob container allows anonymous reads | ansible/azure/storage_container_is_publicly_accessible |
| Review broad Azure SQL firewall ranges | ansible/azure/unrestricted_sql_server_acess |
| The Azure Container Registry admin account is enabled | ansible/azure/admin_user_enabled_for_container_registry |
| Storage account may lack public network restrictions | ansible/azure/default_azure_storage_account_network_access_is_too_permissive |
| Azure Linux VM allows SSH password authentication | ansible/azure/azure_instance_using_basic_authentication |
| Review Azure VM network-interface configuration | ansible/azure/vm_not_attached_to_network |
| PostgreSQL log retention needs review | ansible/azure/log_retention_is_not_set |
| AKS monitoring settings need review | ansible/azure/aks_monitoring_logging_disabled |
| Azure SQL firewall rule covers the entire IPv4 range | ansible/azure/sql_server_ingress_from_any_ip |
| Azure log profile omits activity export categories | ansible/azure/monitoring_log_profile_without_all_activities |
| Review access scope for service ports in Azure NSGs | ansible/azure/sensitive_port_is_exposed_to_entire_network |
| Review subnet NSG associations | ansible/azure/security_group_is_not_configured |
| Redis Cache permits unencrypted connections | ansible/azure/redis_cache_allows_non_ssl_connections |
| Azure role permits custom role creation | ansible/azure/role_definition_allows_custom_role_creation |
| Review trusted-service exceptions for Azure Storage | ansible/azure/trusted_microsoft_services_not_enabled |
| PostgreSQL login-failure throttling is disabled | ansible/azure/postgresql_server_without_connection_throttling |
| PostgreSQL disconnection logging is disabled | ansible/azure/postgresql_log_disconnections_not_set |
| Review resource locks for Azure Container Registry | ansible/azure/azure_container_registry_with_no_locks |
| Redis firewall allows all IPv4 addresses | ansible/azure/redis_entirely_accessible |
| PostgreSQL connection logging is disabled | ansible/azure/postgresql_log_connections_not_set |
| PostgreSQL checkpoint logging is disabled | ansible/azure/postgresql_log_checkpoints_disabled |
| Review the minimum TLS setting for Azure Storage | ansible/azure/storage_account_not_using_latest_tls_encryption_version |
| PostgreSQL duration logging needs review | ansible/azure/postgresql_log_duration_not_set |