Azure

Security and configuration guidance for Azure resources defined with Ansible.

Documentation

Article Path
Review AKS network policy settings ansible/azure/aks_network_policy_misconfigured
Review Azure Activity Log retention ansible/azure/small_activity_log_retention_period
Review the Ansible Azure authentication user ansible/azure/sql_server_predictable_active_directory_admin_account_name
Review the Microsoft Entra administrator for Azure SQL ansible/azure/ad_admin_not_configured_for_sql_server
Review the Azure SQL administrator login name ansible/azure/sql_server_predictable_admin_account_name
Review Cosmos DB account IP access restrictions ansible/azure/cosmosdb_account_ip_range_filter_not_set
Cosmos DB account tags are missing ansible/azure/cosmosdb_account_without_tags
Azure Web App permits HTTP access ansible/azure/web_app_accepting_traffic_other_than_https
Azure Storage account does not require HTTPS ansible/azure/storage_account_not_forcing_https
Kubernetes RBAC is disabled for AKS ansible/azure/aks_rbac_disabled
Redis Cache firewall permits an excessive address range ansible/azure/firewall_rule_allows_too_many_hosts_to_access_redis_cache
TLS enforcement is disabled for Azure PostgreSQL ansible/azure/ssl_enforce_is_disabled
TLS enforcement is disabled for Azure MySQL ansible/azure/mysql_ssl_connection_disabled
Review Azure Key Vault soft-delete protection ansible/azure/key_vault_soft_delete_is_disabled
Review WAF protection for Azure Application Gateway ansible/azure/waf_is_disabled_for_azure_application_gateway
Review the Redis firewall address range ansible/azure/redis_publicly_accessible
Storage account network rules may allow broad access ansible/azure/public_storage_account
Azure blob container allows anonymous reads ansible/azure/storage_container_is_publicly_accessible
Review broad Azure SQL firewall ranges ansible/azure/unrestricted_sql_server_acess
The Azure Container Registry admin account is enabled ansible/azure/admin_user_enabled_for_container_registry
Storage account may lack public network restrictions ansible/azure/default_azure_storage_account_network_access_is_too_permissive
Azure Linux VM allows SSH password authentication ansible/azure/azure_instance_using_basic_authentication
Review Azure VM network-interface configuration ansible/azure/vm_not_attached_to_network
PostgreSQL log retention needs review ansible/azure/log_retention_is_not_set
AKS monitoring settings need review ansible/azure/aks_monitoring_logging_disabled
Azure SQL firewall rule covers the entire IPv4 range ansible/azure/sql_server_ingress_from_any_ip
Azure log profile omits activity export categories ansible/azure/monitoring_log_profile_without_all_activities
Review access scope for service ports in Azure NSGs ansible/azure/sensitive_port_is_exposed_to_entire_network
Review subnet NSG associations ansible/azure/security_group_is_not_configured
Redis Cache permits unencrypted connections ansible/azure/redis_cache_allows_non_ssl_connections
Azure role permits custom role creation ansible/azure/role_definition_allows_custom_role_creation
Review trusted-service exceptions for Azure Storage ansible/azure/trusted_microsoft_services_not_enabled
PostgreSQL login-failure throttling is disabled ansible/azure/postgresql_server_without_connection_throttling
PostgreSQL disconnection logging is disabled ansible/azure/postgresql_log_disconnections_not_set
Review resource locks for Azure Container Registry ansible/azure/azure_container_registry_with_no_locks
Redis firewall allows all IPv4 addresses ansible/azure/redis_entirely_accessible
PostgreSQL connection logging is disabled ansible/azure/postgresql_log_connections_not_set
PostgreSQL checkpoint logging is disabled ansible/azure/postgresql_log_checkpoints_disabled
Review the minimum TLS setting for Azure Storage ansible/azure/storage_account_not_using_latest_tls_encryption_version
PostgreSQL duration logging needs review ansible/azure/postgresql_log_duration_not_set

Related pages40

Review AKS network policy settings

Use a supported AKS network policy configuration and actual NetworkPolicies to allow only required Pod communication.

Review Azure Activity Log retention

Retain Activity Logs for investigation and audit needs, and check deletion policies at the actual destination.

Review the Ansible Azure authentication user

Verify the actual user Ansible authenticates to Azure as, and manage authentication and permissions rather than relying on a complex name.

Review the Microsoft Entra administrator for Azure SQL

Configure a Microsoft Entra administrator for the Azure SQL logical server to support organizational authentication.

Review the Azure SQL administrator login name

Review the Azure SQL administrator login name and protect the account with strong authentication and restricted access.

Review Cosmos DB account IP access restrictions

Review IP allow-lists and private connectivity so that only the required clients can connect to Cosmos DB.

Cosmos DB account tags are missing

Apply organizational tags to Cosmos DB accounts to track ownership, purpose, and costs.

Azure Web App permits HTTP access

Require HTTPS for user connections to Azure Web App.

Azure Storage account does not require HTTPS

Require HTTPS for Azure Storage REST requests.

Kubernetes RBAC is disabled for AKS

Use Kubernetes RBAC in AKS to limit user and service-account permissions.

Redis Cache firewall permits an excessive address range

Limit Redis Cache firewall rules to clients that need a connection.

TLS enforcement is disabled for Azure PostgreSQL

Require TLS for Azure PostgreSQL connections and verify the server certificate.

TLS enforcement is disabled for Azure MySQL

Require TLS for Azure MySQL connections and verify the server certificate on clients.

Review Azure Key Vault soft-delete protection

Check Key Vault recovery protection and any required protection against permanent deletion.

Review WAF protection for Azure Application Gateway

Configure both a WAF tier and an effective blocking policy for Application Gateway.

Review the Redis firewall address range

Check that Azure Cache for Redis firewall rules allow only required client source addresses, alongside public and private connectivity settings.

Storage account network rules may allow broad access

Limit public network access to the clients that need the storage account, and review allowed sources and service exceptions.

Azure blob container allows anonymous reads

Anonymous read access to an Azure blob container can expose private files. Review container and account settings and limit reads to the clients that need them.

Review broad Azure SQL firewall ranges

Narrow broad Azure SQL firewall ranges to required client addresses and review the access granted by all applicable rules.

The Azure Container Registry admin account is enabled

Use identity-specific registry access instead of shared administrator credentials.

Storage account may lack public network restrictions

Set an explicit Azure Storage network policy so that public access is limited to the clients that need it, instead of relying on default settings.

Azure Linux VM allows SSH password authentication

Use SSH keys for Azure Linux VMs and restrict password logins.

Review Azure VM network-interface configuration

Check the NIC, subnet, and network-access policies applied to an Azure VM.

PostgreSQL log retention needs review

Review whether PostgreSQL log retention and storage meet investigation and audit requirements.

AKS monitoring settings need review

Missing AKS logs and metrics can make failures and unusual activity harder to investigate.

Azure SQL firewall rule covers the entire IPv4 range

Restrict Azure SQL firewall access to required client addresses, and review public connectivity alongside database authentication.

Azure log profile omits activity export categories

Omitting required categories from activity log export can leave gaps in externally retained change history.

Review access scope for service ports in Azure NSGs

Restrict administrative and internal service ports to the clients that need them.

Review subnet NSG associations

Check that the subnet has appropriate NSG associations and effective security rules.

Redis Cache permits unencrypted connections

Disable the non-TLS port and move Redis Cache clients to TLS.

Azure role permits custom role creation

Limit creation and modification of Azure custom roles to the administrators who need it.

Review trusted-service exceptions for Azure Storage

Use Azure Storage network exceptions only for required service integrations.

PostgreSQL login-failure throttling is disabled

Throttling repeated failed logins helps reduce password-guessing attempts against PostgreSQL.

PostgreSQL disconnection logging is disabled

PostgreSQL disconnection logs help investigate when sessions end and how long they last.

Review resource locks for Azure Container Registry

Apply resource locks where needed to protect a registry from accidental deletion or management changes.

Redis firewall allows all IPv4 addresses

Restrict the Redis firewall's full IPv4 allow-list to the required client addresses.

PostgreSQL connection logging is disabled

Insufficient PostgreSQL connection logs can make database access history harder to investigate.

PostgreSQL checkpoint logging is disabled

Disabled PostgreSQL checkpoint logging reduces the evidence available for I/O and performance analysis.

Review the minimum TLS setting for Azure Storage

Use TLS 1.2 or later for Azure Storage and remove obsolete settings.

PostgreSQL duration logging needs review

PostgreSQL duration logs provide evidence for investigating slow operations and performance problems.