Azure Resource Manager

Security and service configuration guidance for Azure Resource Manager templates.

Documentation

Article Path
Review AKS API server access scope azureResourceManager/aks_with_authorized_ip_ranges_disabled
AKS container log collection is disabled azureResourceManager/aks_logging_azure_monitoring_disabled
Review AKS Dashboard use azureResourceManager/aks_dashboard_enabled
AKS network policies are not configured azureResourceManager/aks_cluster_network_policy_not_configured
Review App Service HTTP/2 settings azureResourceManager/website_with_http20enabled_disabled
Review App Service managed identity use azureResourceManager/website_azure_active_directory_disabled
Review App Service authentication settings azureResourceManager/app_service_authentication_not_set
Review Azure Activity Log retention azureResourceManager/unrecommended_log_profile_retention_policy
Review Azure Log Profile export categories azureResourceManager/log_profile_incorrect_category
Review Azure SQL audit log retention azureResourceManager/sql_server_database_with_low_retention_days
SSH password authentication is allowed on an Azure Linux VM azureResourceManager/azure_instance_using_basic_authentication
Azure Key Vault secret has no expiration date azureResourceManager/secret_without_expiration_date
Review Defender for Cloud protection plans azureResourceManager/standard_price_not_selected
Review TLS enforcement for Azure MySQL azureResourceManager/mysql_server_ssl_enforcement_disabled
Azure NSG does not restrict SSH sources azureResourceManager/network_security_group_with_unrestricted_access_to_ssh
Review Network Watcher flow log retention azureResourceManager/unrecommended_network_watcher_flow_log_retention_policy
Review TLS enforcement for Azure PostgreSQL azureResourceManager/postgresql_server_ssl_disabled
Azure PostgreSQL checkpoint logging is disabled azureResourceManager/postgresql_server_log_checkpoint_disabled
Review connection throttling for Azure PostgreSQL azureResourceManager/postgresql_database_server_connection_throttling_disabled
Azure PostgreSQL connection logging is disabled azureResourceManager/postgresql_server_log_connections_disabled
Review Kubernetes RBAC settings for an AKS cluster azureResourceManager/aks_cluster_rbac_disabled
Azure NSG allows broad RDP access azureResourceManager/network_security_group_with_unrestricted_access_to_rdp
Azure SQL Database auditing is not configured azureResourceManager/sql_server_database_without_auditing
Azure SQL security alert types are disabled azureResourceManager/sql_server_database_with_alerts_disabled
Review Azure SQL security alert email recipients azureResourceManager/sql_alert_policy_without_emails
Review Azure security contact phone details azureResourceManager/phone_number_not_set_security_contacts
Review Storage Account default network access azureResourceManager/storage_account_allows_network_default_access
Storage account allows insecure transfer azureResourceManager/storage_account_allows_unsecure_transfer
Azure Queue Storage operation logs are disabled azureResourceManager/storage_logging_for_read_write_delete_requests_disabled
Review Trusted Microsoft Services exceptions azureResourceManager/trusted_microsoft_services_not_enabled
Review Web App HTTPS redirection azureResourceManager/website_not_forcing_https
Review the Web App minimum TLS version azureResourceManager/web_app_not_using_tls_last_version
Review Web App client certificate settings azureResourceManager/website_with_client_certificate_auth_disabled
Review Azure SQL account-administrator alert emails azureResourceManager/account_admins_not_notified_by_email
Azure Blob container permits public access azureResourceManager/storage_blob_service_container_with_public_access
Azure Storage account allows broad network access azureResourceManager/default_azure_storage_account_network_access_is_too_permissive
Azure SQL server firewall rule specifies the full IPv4 range azureResourceManager/sql_database_server_firewall_allows_all_ips
Review Defender for Cloud email notifications azureResourceManager/email_notifications_set_off
Azure Key Vault recovery protection needs review azureResourceManager/key_vault_not_recoverable
Azure role definition permits custom-role creation azureResourceManager/role_definitions_allow_custom_subscription_role_creation
Review Azure managed disk encryption requirements azureResourceManager/azure_managed_disk_without_encryption
secureString parameter has a hardcoded default azureResourceManager/hardcoded_securestring_parameter_default_value

Related pages42

Review AKS API server access scope

Restrict public API server access to the required management networks.

AKS container log collection is disabled

Enable AKS container log collection and verify that logs arrive.

Review AKS Dashboard use

Remove unnecessary management UIs and restrict access and permissions for those you retain.

AKS network policies are not configured

Apply network policies in AKS to allow only required pod traffic.

Review App Service HTTP/2 settings

Review App Service HTTP/2 compatibility and performance needs, and manage HTTPS and TLS separately.

Review App Service managed identity use

Reduce stored long-lived credentials when accessing supported Azure resources.

Review App Service authentication settings

Review App Service and application authentication policies, and restrict anonymous requests to protected paths.

Review Azure Activity Log retention

Check the actual destination’s retention and deletion policies against the required investigation history.

Review Azure Log Profile export categories

Verify that required management activity reaches the actual log destination.

Review Azure SQL audit log retention

Prevent logs from being deleted before the required investigation and audit period ends.

SSH password authentication is allowed on an Azure Linux VM

Use key authentication for SSH access to Azure Linux VMs.

Azure Key Vault secret has no expiration date

Set a rotation deadline and replace credentials before it.

Review Defender for Cloud protection plans

Review the required workload protection, coverage and cost together.

Review TLS enforcement for Azure MySQL

Require TLS connections to Azure MySQL and retain client verification of the server certificate.

Azure NSG does not restrict SSH sources

Restrict SSH access in Azure NSGs to required management addresses.

Review Network Watcher flow log retention

Verify that actual flow records remain available for the required investigation period.

Review TLS enforcement for Azure PostgreSQL

Require TLS connections to Azure PostgreSQL and verify the server certificate.

Azure PostgreSQL checkpoint logging is disabled

Use Azure PostgreSQL checkpoint logs to investigate write load and performance problems.

Review connection throttling for Azure PostgreSQL

Limit repeated connection attempts that use incorrect passwords in Azure PostgreSQL.

Azure PostgreSQL connection logging is disabled

Enable Azure PostgreSQL connection logs to investigate connection attempts and successful connections.

Review Kubernetes RBAC settings for an AKS cluster

Enable Kubernetes RBAC in AKS and grant only the required operations through roles and bindings.

Azure NSG allows broad RDP access

Restrict Azure NSG RDP access to approved administration paths and verify the VM’s actual connectivity and authentication settings.

Azure SQL Database auditing is not configured

Configure Azure SQL auditing to record required database activity.

Azure SQL security alert types are disabled

Check that required Azure SQL security alerts are not excluded.

Review Azure SQL security alert email recipients

Verify that Azure SQL alert delivery includes the people responsible for responding.

Review Azure security contact phone details

Maintain the contact details and delivery paths required by the incident-response process.

Review Storage Account default network access

Restrict storage network access to the required sources.

Storage account allows insecure transfer

Require HTTPS for storage REST requests and verify client and protocol-specific transport protection.

Azure Queue Storage operation logs are disabled

Send Queue Storage read, write and delete logs to the required destination.

Review Trusted Microsoft Services exceptions

Verify the required Azure service connection and data permissions before selecting a trusted-service exception.

Review Web App HTTPS redirection

Enable HTTPS redirection and configure clients to use encrypted URLs from the start.

Review the Web App minimum TLS version

Review the effective App Service minimum TLS version and client compatibility, and use TLS 1.2 or later.

Review Web App client certificate settings

For services that need client certificates, configure both certificate requirements and application validation.

Review Azure SQL account-administrator alert emails

Verify that Azure SQL security alerts reach the people responsible for responding.

Azure Blob container permits public access

Restrict anonymous reads of Azure Blob containers to prevent unintended disclosure of file contents and listings.

Azure Storage account allows broad network access

Limit the networks that can reach an Azure Storage account’s public endpoint to those that need access.

Azure SQL server firewall rule specifies the full IPv4 range

Restrict the full IPv4 range in an Azure SQL server firewall to required sources, and review public network access alongside database authentication.

Review Defender for Cloud email notifications

Align Defender for Cloud email recipients and severity thresholds with the response process.

Azure Key Vault recovery protection needs review

Review Azure Key Vault soft delete and purge protection so deleted keys, secrets and certificates remain recoverable during retention.

Azure role definition permits custom-role creation

Limit custom-role creation and modification to administrators who need it, and review role definitions together with assignment scope.

Review Azure managed disk encryption requirements

Distinguish default server-side encryption from Azure Disk Encryption and identify any additional protection needed.

secureString parameter has a hardcoded default

Remove secret defaults from secureString parameters and supply values through a protected deployment path.