Browse 148 documents on the security and configuration of Azure resources defined with Terraform.
Documentation
| Article | Path |
|---|---|
| Review Azure Policy configuration for AKS | terraform/azure/aks_uses_azure_policies_addon_disabled |
| Review customer-managed keys for AKS disks | terraform/azure/aks_disk_encryption_set_id_undefined |
| AKS RBAC is disabled | terraform/azure/aks_rbac_disabled |
| Review AKS network policy settings | terraform/azure/aks_network_policy_misconfigured |
| Review private access to the AKS API server | terraform/azure/aks_private_cluster_disabled |
| Review Activity Log retention | terraform/azure/small_activity_log_retention_period |
| Review App Service FTP transport protection | terraform/azure/app_service_ftps_enforce_disabled |
| Review App Service HTTP/2 settings | terraform/azure/app_service_http2_disabled |
| Review App Service managed identity use | terraform/azure/app_service_managed_identity_disabled |
| Review App Service built-in authentication | terraform/azure/app_service_authentication_disabled |
| Review App Service PHP runtime support | terraform/azure/app_service_without_latest_php_version |
| Review App Service Python runtime support | terraform/azure/app_service_without_latest_python_version |
| Review App Service client certificate requirements | terraform/azure/azure_app_service_client_certificate_disabled |
| Review WAF configuration for Azure Application Gateway | terraform/azure/waf_is_disabled_for_azure_application_gateway |
| Review public network access to Azure AI Search | terraform/azure/azure_cognitive_search_public_network_access_enabled |
| Review Defender for Cloud protection plans | terraform/azure/security_center_pricing_tier_is_not_standard |
| Review WAF policy associations for Azure Front Door | terraform/azure/azure_front_door_waf_disabled |
| Review Azure role permissions for guest users | terraform/azure/role_assignment_not_limit_guest_users_permissions |
| Review Key Vault secret expiration | terraform/azure/secret_expiration_not_set |
| Review Azure Key Vault audit-log collection | terraform/azure/vault_auditing_disabled |
| Review TLS enforcement for Azure MySQL | terraform/azure/mysql_ssl_connection_disabled |
| Azure Network Watcher flow logs are disabled | terraform/azure/network_watcher_flow_disabled |
| Review Azure PostgreSQL connection encryption | terraform/azure/ssl_enforce_is_disabled |
| Review Azure PostgreSQL throttling of failed authentication | terraform/azure/postgresql_server_without_connection_throttling |
| Azure PostgreSQL disconnection logging is disabled | terraform/azure/postgresql_log_disconnections_not_set |
| Review Azure PostgreSQL threat detection | terraform/azure/postgresql_server_threat_detection_policy_disabled |
| Review Azure PostgreSQL connection logging | terraform/azure/postgresql_log_connections_not_set |
| Azure PostgreSQL checkpoint logging is disabled | terraform/azure/postgresql_log_checkpoints_disabled |
| Review Azure PostgreSQL statement duration logging | terraform/azure/postgresql_log_duration_not_set |
| Azure Redis allows unencrypted connections | terraform/azure/redis_cache_allows_non_ssl_connections |
| Review the Azure Redis maintenance schedule | terraform/azure/redis_not_updated_regularly |
| Review Azure SQL Database threat detection | terraform/azure/sql_database_audit_disabled |
| Review Azure SQL server audit logging | terraform/azure/sql_server_auditing_disabled |
| Review administrator emails for Azure SQL security alerts | terraform/azure/sql_server_alert_email_disabled |
| Review Azure SQL server security alerts | terraform/azure/mssql_server_database_with_alerts_disabled |
| Azure NSG allows internet access to SSH | terraform/azure/ssh_is_exposed_to_the_internet |
| Review secure transfer for Azure Storage | terraform/azure/storage_account_not_forcing_https |
| Excessive permissions in an Azure file-share access policy | terraform/azure/storage_share_allows_all_acl_permissions |
| Azure Storage allows Shared Key access | terraform/azure/storage_account_with_shared_access_key |
| Excessive permissions in an Azure Table access policy | terraform/azure/storage_table_allows_all_acl_permissions |
| Review trusted-service exceptions for Azure Storage | terraform/azure/trusted_microsoft_services_not_enabled |
| Review the minimum TLS version for Azure Storage | terraform/azure/storage_account_not_using_latest_tls_encryption_version |
| Azure Storage allows cross-tenant object replication | terraform/azure/storage_account_with_cross_tenant_replication_enabled |
| Review Azure User Access Administrator assignment scope | terraform/azure/use_of_user_access_administrator_role_is_not_restricted |
| Review Azure VM migration to managed disks | terraform/azure/vm_without_managed_disk |
| Review Azure VM network-interface attachment | terraform/azure/vm_not_attached_to_network |
| Review Azure Web App HTTPS enforcement | terraform/azure/web_app_accepting_traffic_other_than_https |
| Review IP forwarding on Azure network interfaces | terraform/azure/network_interfaces_ip_forwarding_enabled |
| Review public IP associations on Azure network interfaces | terraform/azure/network_interfaces_with_public_ip |
| Review Azure resource diagnostic settings | terraform/azure/resource_without_diagnostic_settings |
| Review sensitive-port access in Azure NSGs | terraform/azure/sensitive_port_is_exposed_to_small_public_network |
| Azure security contact email is missing | terraform/azure/security_contact_email |
| Azure custom role permits role-definition changes | terraform/azure/role_definition_allows_custom_role_creation |
| Review Azure service resource-log collection | terraform/azure/service_without_resource_logging |
| Review Azure flow-log retention | terraform/azure/small_flow_logs_retention_period |
| Review customer-managed key coverage for Azure Databricks | terraform/azure/databricks_workspace_without_cmk |
| Container Registry admin user is enabled | terraform/azure/admin_user_enabled_for_container_registry |
| Key Vault secret has no content type | terraform/azure/key_vault_secrets_content_type_undefined |
| Cosmos DB account has no tags | terraform/azure/cosmos_db_account_without_tags |
| Review Databricks diagnostic log collection | terraform/azure/databricks_diagnostic_logging_unconfigured |
| Review Function App FTP transport protection | terraform/azure/function_app_ftps_enforce_disabled |
| Review Function App HTTP/2 settings | terraform/azure/function_app_http2_disabled |
| Function App has no managed identity configured | terraform/azure/function_app_managed_identity_disabled |
| Review Function App authentication settings | terraform/azure/function_app_authentication_disabled |
| Review Function App client certificate requirements | terraform/azure/function_app_client_certificates_unrequired |
| Cosmos DB IP firewall configuration needs review | terraform/azure/cosmosdb_account_ip_range_filter_not_set |
| Review Azure Backup Vault immutability | terraform/azure/backup_vault_without_immutability |
| Review Recovery Services Vault backup immutability | terraform/azure/recovery_services_vaut_without_immutability |
| Review Kubernetes Dashboard use in AKS | terraform/azure/dashboard_is_enabled |
| Review Azure SQL server auditing policies | terraform/azure/mssql_server_auditing_disabled |
| Review retention in Azure SQL auditing policies | terraform/azure/small_mssql_audit_retention_period |
| Review Managed Disk encryption methods | terraform/azure/encryption_on_managed_disk_disabled |
| Prepare regional disaster recovery for MariaDB workloads | terraform/azure/mariadb_server_georedundant_backup_disabled |
| Review Activity Log alerts for Network Security Group deletion | terraform/azure/activity_log_alert_for_delete_network_security_group_not_configured |
| Review Activity Log alerts for Network Security Group creation and updates | terraform/azure/activity_log_alert_for_create_or_update_network_security_group_not_configured |
| Azure subnet NSG association needs review | terraform/azure/security_group_is_not_configured |
| Review Activity Log alerts for Policy Assignment deletion | terraform/azure/activity_log_alert_for_delete_policy_assignment_not_configured |
| Review Activity Log alerts for Policy Assignment creation and updates | terraform/azure/activity_log_alert_for_create_policy_assignment_not_configured |
| Review Azure PostgreSQL log retention | terraform/azure/log_retention_is_not_set |
| Review Azure PostgreSQL server log retention | terraform/azure/small_postgresql_db_server_log_retention_period |
| Review Azure PostgreSQL encryption at rest | terraform/azure/postgresql_server_infrastructure_encryption_disabled |
| Review geo-redundant backups for Azure PostgreSQL | terraform/azure/geo_redundancy_is_disabled |
| Review Activity Log alerts for Public IP deletion | terraform/azure/activity_log_alert_for_delete_public_ip_address_rule_not_configured |
| Review Activity Log alerts for Public IP creation and updates | terraform/azure/activity_log_alert_for_create_or_update_public_ip_address_rule_not_configured |
| Review Azure Key Vault purge protection | terraform/azure/key_vault_purge_protection_is_enabled |
| Azure RDP rule public-access scope needs review | terraform/azure/rdp_is_exposed_to_the_internet |
| Review Activity Log alerts for SQL Server firewall-rule deletion | terraform/azure/activity_log_alert_for_delete_sql_server_firewall_rule_not_configured |
| Review Activity Log alerts for SQL Server firewall rule creation and updates | terraform/azure/activity_log_alert_for_create_or_update_sql_server_firewall_rule_not_configured |
| Review the Microsoft Entra administrator name for Azure SQL | terraform/azure/sql_server_predictable_active_directory_admin_account_name |
| Review Azure SQL administrator login names | terraform/azure/sql_server_predictable_admin_account_name |
| Review the Microsoft Entra administrator for Azure SQL | terraform/azure/ad_admin_not_configured_for_sql_server |
| Review Azure SQL audit log retention | terraform/azure/small_msql_server_audit_retention |
| Review Activity Log alerts for Security Solution deletion | terraform/azure/activity_log_alert_for_delete_security_solution_not_configured |
| Review Activity Log alerts for Security Solution creation and updates | terraform/azure/activity_log_alert_for_create_or_update_security_solution_not_configured |
| Review Service Fabric management authentication | terraform/azure/azure_active_directory_authentication |
| Review Service Health Activity Log alerts | terraform/azure/activity_log_alert_for_service_health_not_configured |
| Review Azure Backup Vault soft delete | terraform/azure/backup_vault_without_soft_delete |
| Review Recovery Services Vault deleted-backup protection | terraform/azure/recovery_services_vaut_without_soft_delete |
| Review Azure Blob container soft-delete retention | terraform/azure/containers_without_soft_delete |
| Review Azure Blob soft-delete retention | terraform/azure/blob_storage_without_soft_delete |
| Review Azure file share soft delete | terraform/azure/file_share_without_soft_delete |
| Beta - Azure storage account deletion protection needs review | terraform/azure/storage_account_without_delete_lock |
| Review Virtual Network DDoS protection plans | terraform/azure/virtual_network_with_ddos_protection_plan_disabled |
| Redis firewall access range needs review | terraform/azure/redis_publicly_accessible |
| Azure Storage Account public-access settings need review | terraform/azure/public_storage_account |
| Azure Storage Container allows anonymous reads | terraform/azure/storage_container_is_publicly_accessible |
| Azure MSSQL Server public network access needs review | terraform/azure/mssql_server_public_network_access_enabled |
| Public network access is enabled on an Azure MariaDB Server | terraform/azure/mariadb_public_network_access_enabled |
| Legacy Azure MySQL Server public network access needs review | terraform/azure/mysql_server_public_access_enabled |
| Azure Recovery Services Vault public network access needs review | terraform/azure/recovery_services_vaut_with_public_network_access |
| Review Azure Container Registry deletion locks | terraform/azure/azure_container_registry_with_no_locks |
| Review Azure Databricks virtual-network placement | terraform/azure/databricks_workspace_using_default_virtual_network |
| Azure Storage Account default network access needs review | terraform/azure/default_azure_storage_account_network_access_is_too_permissive |
| Password authentication is allowed for an Azure Linux VM | terraform/azure/azure_instance_using_basic_authentication |
| Review the allowed address range for Azure Redis | terraform/azure/firewall_rule_allows_too_many_hosts_to_access_redis_cache |
| Review Key Vault key expiration | terraform/azure/key_expiration_not_set |
| Review private-network access to sensitive ports in Azure NSGs | terraform/azure/sensitive_port_is_exposed_to_wide_private_network |
| Azure management and internal service port access needs review | terraform/azure/sensitive_port_is_exposed_to_entire_network |
| Review the Azure Files SMB channel cipher policy | terraform/azure/storage_account_using_unsafe_smb_channel_encryption |
| Security alert emails are disabled | terraform/azure/email_alerts_disabled |
| Review Azure SQL Database encryption at rest | terraform/azure/sql_database_without_data_encryption |
| Review Diagnostic Setting log categories | terraform/azure/diagnostic_settings_without_appropriate_logging |
| Redis firewall allows all IPv4 addresses | terraform/azure/redis_entirely_accessible |
| Azure database firewall rule specifies the full IPv4 range | terraform/azure/sql_server_ingress_from_any_ip |
| Review the Azure Files SMB version policy | terraform/azure/storage_account_not_using_latest_smb_protocol_version |
| Review App Service minimum TLS settings | terraform/azure/app_service_not_using_latest_tls_encryption_version |
| Review the Function App minimum TLS version | terraform/azure/function_app_not_using_latest_tls_encryption_version |
| Azure database firewall permits broad access | terraform/azure/unrestricted_sql_server_access |
| Review AKS audit log collection | terraform/azure/aks_without_audit_logs |
| Review managed identity use for App Service slots | terraform/azure/app_service_slot_managed_identity_disabled |
| Review Azure Container Registry permission scope | terraform/azure/azure_container_registry_with_broad_permissions |
| Container App has no managed identity configured | terraform/azure/container_app_managed_identity_disabled |
| Container Group has no managed identity configured | terraform/azure/container_group_managed_identity_disabled |
| Review Azure Container Instances network exposure | terraform/azure/container_instances_not_using_private_virtual_networks |
| Review customer-managed keys for Managed Disk | terraform/azure/disk_encryption_on_managed_disk_disabled |
| Review the minimum TLS version of a Function App deployment slot | terraform/azure/function_app_deployment_slot_not_using_latest_tls_encryption_version |
| Review HSM protection for Key Vault keys | terraform/azure/key_vault_without_hsm_protection |
| Review managed identity use in AKS | terraform/azure/kubernetes_cluster_managed_identity_disabled |
| Logic App has no managed identity configured | terraform/azure/logic_app_managed_identity_disabled |
| Review the minimum TLS version for Azure SQL | terraform/azure/mssql_not_using_latest_tls_encryption_version |
| Review the minimum TLS version for Azure PostgreSQL | terraform/azure/postgresql_not_using_latest_tls_encryption_version |
| Review managed identity use for Azure Redis | terraform/azure/redis_cache_managed_identity_is_not_set_to_system_assigned |
| Review the minimum TLS version for Azure Redis | terraform/azure/redis_cache_not_using_latest_tls_encryption_version |
| Review customer-managed keys for Azure Storage | terraform/azure/storage_account_without_cmk |
| Review Windows VM automatic updates | terraform/azure/vm_with_automatic_updates_disabled |
| Review Azure VM extension operations | terraform/azure/vm_with_extension_operations_enabled |
| Review administrator SSH keys for Azure VMs | terraform/azure/vm_without_admin_ssh_public_key_set |
| Review Azure VM encryption at host | terraform/azure/vm_without_encryption_at_host |