Azure

Security and configuration guidance for Azure resources defined with Terraform.

Browse 148 documents on the security and configuration of Azure resources defined with Terraform.

Documentation

Article Path
Review Azure Policy configuration for AKS terraform/azure/aks_uses_azure_policies_addon_disabled
Review customer-managed keys for AKS disks terraform/azure/aks_disk_encryption_set_id_undefined
AKS RBAC is disabled terraform/azure/aks_rbac_disabled
Review AKS network policy settings terraform/azure/aks_network_policy_misconfigured
Review private access to the AKS API server terraform/azure/aks_private_cluster_disabled
Review Activity Log retention terraform/azure/small_activity_log_retention_period
Review App Service FTP transport protection terraform/azure/app_service_ftps_enforce_disabled
Review App Service HTTP/2 settings terraform/azure/app_service_http2_disabled
Review App Service managed identity use terraform/azure/app_service_managed_identity_disabled
Review App Service built-in authentication terraform/azure/app_service_authentication_disabled
Review App Service PHP runtime support terraform/azure/app_service_without_latest_php_version
Review App Service Python runtime support terraform/azure/app_service_without_latest_python_version
Review App Service client certificate requirements terraform/azure/azure_app_service_client_certificate_disabled
Review WAF configuration for Azure Application Gateway terraform/azure/waf_is_disabled_for_azure_application_gateway
Review public network access to Azure AI Search terraform/azure/azure_cognitive_search_public_network_access_enabled
Review Defender for Cloud protection plans terraform/azure/security_center_pricing_tier_is_not_standard
Review WAF policy associations for Azure Front Door terraform/azure/azure_front_door_waf_disabled
Review Azure role permissions for guest users terraform/azure/role_assignment_not_limit_guest_users_permissions
Review Key Vault secret expiration terraform/azure/secret_expiration_not_set
Review Azure Key Vault audit-log collection terraform/azure/vault_auditing_disabled
Review TLS enforcement for Azure MySQL terraform/azure/mysql_ssl_connection_disabled
Azure Network Watcher flow logs are disabled terraform/azure/network_watcher_flow_disabled
Review Azure PostgreSQL connection encryption terraform/azure/ssl_enforce_is_disabled
Review Azure PostgreSQL throttling of failed authentication terraform/azure/postgresql_server_without_connection_throttling
Azure PostgreSQL disconnection logging is disabled terraform/azure/postgresql_log_disconnections_not_set
Review Azure PostgreSQL threat detection terraform/azure/postgresql_server_threat_detection_policy_disabled
Review Azure PostgreSQL connection logging terraform/azure/postgresql_log_connections_not_set
Azure PostgreSQL checkpoint logging is disabled terraform/azure/postgresql_log_checkpoints_disabled
Review Azure PostgreSQL statement duration logging terraform/azure/postgresql_log_duration_not_set
Azure Redis allows unencrypted connections terraform/azure/redis_cache_allows_non_ssl_connections
Review the Azure Redis maintenance schedule terraform/azure/redis_not_updated_regularly
Review Azure SQL Database threat detection terraform/azure/sql_database_audit_disabled
Review Azure SQL server audit logging terraform/azure/sql_server_auditing_disabled
Review administrator emails for Azure SQL security alerts terraform/azure/sql_server_alert_email_disabled
Review Azure SQL server security alerts terraform/azure/mssql_server_database_with_alerts_disabled
Azure NSG allows internet access to SSH terraform/azure/ssh_is_exposed_to_the_internet
Review secure transfer for Azure Storage terraform/azure/storage_account_not_forcing_https
Excessive permissions in an Azure file-share access policy terraform/azure/storage_share_allows_all_acl_permissions
Azure Storage allows Shared Key access terraform/azure/storage_account_with_shared_access_key
Excessive permissions in an Azure Table access policy terraform/azure/storage_table_allows_all_acl_permissions
Review trusted-service exceptions for Azure Storage terraform/azure/trusted_microsoft_services_not_enabled
Review the minimum TLS version for Azure Storage terraform/azure/storage_account_not_using_latest_tls_encryption_version
Azure Storage allows cross-tenant object replication terraform/azure/storage_account_with_cross_tenant_replication_enabled
Review Azure User Access Administrator assignment scope terraform/azure/use_of_user_access_administrator_role_is_not_restricted
Review Azure VM migration to managed disks terraform/azure/vm_without_managed_disk
Review Azure VM network-interface attachment terraform/azure/vm_not_attached_to_network
Review Azure Web App HTTPS enforcement terraform/azure/web_app_accepting_traffic_other_than_https
Review IP forwarding on Azure network interfaces terraform/azure/network_interfaces_ip_forwarding_enabled
Review public IP associations on Azure network interfaces terraform/azure/network_interfaces_with_public_ip
Review Azure resource diagnostic settings terraform/azure/resource_without_diagnostic_settings
Review sensitive-port access in Azure NSGs terraform/azure/sensitive_port_is_exposed_to_small_public_network
Azure security contact email is missing terraform/azure/security_contact_email
Azure custom role permits role-definition changes terraform/azure/role_definition_allows_custom_role_creation
Review Azure service resource-log collection terraform/azure/service_without_resource_logging
Review Azure flow-log retention terraform/azure/small_flow_logs_retention_period
Review customer-managed key coverage for Azure Databricks terraform/azure/databricks_workspace_without_cmk
Container Registry admin user is enabled terraform/azure/admin_user_enabled_for_container_registry
Key Vault secret has no content type terraform/azure/key_vault_secrets_content_type_undefined
Cosmos DB account has no tags terraform/azure/cosmos_db_account_without_tags
Review Databricks diagnostic log collection terraform/azure/databricks_diagnostic_logging_unconfigured
Review Function App FTP transport protection terraform/azure/function_app_ftps_enforce_disabled
Review Function App HTTP/2 settings terraform/azure/function_app_http2_disabled
Function App has no managed identity configured terraform/azure/function_app_managed_identity_disabled
Review Function App authentication settings terraform/azure/function_app_authentication_disabled
Review Function App client certificate requirements terraform/azure/function_app_client_certificates_unrequired
Cosmos DB IP firewall configuration needs review terraform/azure/cosmosdb_account_ip_range_filter_not_set
Review Azure Backup Vault immutability terraform/azure/backup_vault_without_immutability
Review Recovery Services Vault backup immutability terraform/azure/recovery_services_vaut_without_immutability
Review Kubernetes Dashboard use in AKS terraform/azure/dashboard_is_enabled
Review Azure SQL server auditing policies terraform/azure/mssql_server_auditing_disabled
Review retention in Azure SQL auditing policies terraform/azure/small_mssql_audit_retention_period
Review Managed Disk encryption methods terraform/azure/encryption_on_managed_disk_disabled
Prepare regional disaster recovery for MariaDB workloads terraform/azure/mariadb_server_georedundant_backup_disabled
Review Activity Log alerts for Network Security Group deletion terraform/azure/activity_log_alert_for_delete_network_security_group_not_configured
Review Activity Log alerts for Network Security Group creation and updates terraform/azure/activity_log_alert_for_create_or_update_network_security_group_not_configured
Azure subnet NSG association needs review terraform/azure/security_group_is_not_configured
Review Activity Log alerts for Policy Assignment deletion terraform/azure/activity_log_alert_for_delete_policy_assignment_not_configured
Review Activity Log alerts for Policy Assignment creation and updates terraform/azure/activity_log_alert_for_create_policy_assignment_not_configured
Review Azure PostgreSQL log retention terraform/azure/log_retention_is_not_set
Review Azure PostgreSQL server log retention terraform/azure/small_postgresql_db_server_log_retention_period
Review Azure PostgreSQL encryption at rest terraform/azure/postgresql_server_infrastructure_encryption_disabled
Review geo-redundant backups for Azure PostgreSQL terraform/azure/geo_redundancy_is_disabled
Review Activity Log alerts for Public IP deletion terraform/azure/activity_log_alert_for_delete_public_ip_address_rule_not_configured
Review Activity Log alerts for Public IP creation and updates terraform/azure/activity_log_alert_for_create_or_update_public_ip_address_rule_not_configured
Review Azure Key Vault purge protection terraform/azure/key_vault_purge_protection_is_enabled
Azure RDP rule public-access scope needs review terraform/azure/rdp_is_exposed_to_the_internet
Review Activity Log alerts for SQL Server firewall-rule deletion terraform/azure/activity_log_alert_for_delete_sql_server_firewall_rule_not_configured
Review Activity Log alerts for SQL Server firewall rule creation and updates terraform/azure/activity_log_alert_for_create_or_update_sql_server_firewall_rule_not_configured
Review the Microsoft Entra administrator name for Azure SQL terraform/azure/sql_server_predictable_active_directory_admin_account_name
Review Azure SQL administrator login names terraform/azure/sql_server_predictable_admin_account_name
Review the Microsoft Entra administrator for Azure SQL terraform/azure/ad_admin_not_configured_for_sql_server
Review Azure SQL audit log retention terraform/azure/small_msql_server_audit_retention
Review Activity Log alerts for Security Solution deletion terraform/azure/activity_log_alert_for_delete_security_solution_not_configured
Review Activity Log alerts for Security Solution creation and updates terraform/azure/activity_log_alert_for_create_or_update_security_solution_not_configured
Review Service Fabric management authentication terraform/azure/azure_active_directory_authentication
Review Service Health Activity Log alerts terraform/azure/activity_log_alert_for_service_health_not_configured
Review Azure Backup Vault soft delete terraform/azure/backup_vault_without_soft_delete
Review Recovery Services Vault deleted-backup protection terraform/azure/recovery_services_vaut_without_soft_delete
Review Azure Blob container soft-delete retention terraform/azure/containers_without_soft_delete
Review Azure Blob soft-delete retention terraform/azure/blob_storage_without_soft_delete
Review Azure file share soft delete terraform/azure/file_share_without_soft_delete
Beta - Azure storage account deletion protection needs review terraform/azure/storage_account_without_delete_lock
Review Virtual Network DDoS protection plans terraform/azure/virtual_network_with_ddos_protection_plan_disabled
Redis firewall access range needs review terraform/azure/redis_publicly_accessible
Azure Storage Account public-access settings need review terraform/azure/public_storage_account
Azure Storage Container allows anonymous reads terraform/azure/storage_container_is_publicly_accessible
Azure MSSQL Server public network access needs review terraform/azure/mssql_server_public_network_access_enabled
Public network access is enabled on an Azure MariaDB Server terraform/azure/mariadb_public_network_access_enabled
Legacy Azure MySQL Server public network access needs review terraform/azure/mysql_server_public_access_enabled
Azure Recovery Services Vault public network access needs review terraform/azure/recovery_services_vaut_with_public_network_access
Review Azure Container Registry deletion locks terraform/azure/azure_container_registry_with_no_locks
Review Azure Databricks virtual-network placement terraform/azure/databricks_workspace_using_default_virtual_network
Azure Storage Account default network access needs review terraform/azure/default_azure_storage_account_network_access_is_too_permissive
Password authentication is allowed for an Azure Linux VM terraform/azure/azure_instance_using_basic_authentication
Review the allowed address range for Azure Redis terraform/azure/firewall_rule_allows_too_many_hosts_to_access_redis_cache
Review Key Vault key expiration terraform/azure/key_expiration_not_set
Review private-network access to sensitive ports in Azure NSGs terraform/azure/sensitive_port_is_exposed_to_wide_private_network
Azure management and internal service port access needs review terraform/azure/sensitive_port_is_exposed_to_entire_network
Review the Azure Files SMB channel cipher policy terraform/azure/storage_account_using_unsafe_smb_channel_encryption
Security alert emails are disabled terraform/azure/email_alerts_disabled
Review Azure SQL Database encryption at rest terraform/azure/sql_database_without_data_encryption
Review Diagnostic Setting log categories terraform/azure/diagnostic_settings_without_appropriate_logging
Redis firewall allows all IPv4 addresses terraform/azure/redis_entirely_accessible
Azure database firewall rule specifies the full IPv4 range terraform/azure/sql_server_ingress_from_any_ip
Review the Azure Files SMB version policy terraform/azure/storage_account_not_using_latest_smb_protocol_version
Review App Service minimum TLS settings terraform/azure/app_service_not_using_latest_tls_encryption_version
Review the Function App minimum TLS version terraform/azure/function_app_not_using_latest_tls_encryption_version
Azure database firewall permits broad access terraform/azure/unrestricted_sql_server_access
Review AKS audit log collection terraform/azure/aks_without_audit_logs
Review managed identity use for App Service slots terraform/azure/app_service_slot_managed_identity_disabled
Review Azure Container Registry permission scope terraform/azure/azure_container_registry_with_broad_permissions
Container App has no managed identity configured terraform/azure/container_app_managed_identity_disabled
Container Group has no managed identity configured terraform/azure/container_group_managed_identity_disabled
Review Azure Container Instances network exposure terraform/azure/container_instances_not_using_private_virtual_networks
Review customer-managed keys for Managed Disk terraform/azure/disk_encryption_on_managed_disk_disabled
Review the minimum TLS version of a Function App deployment slot terraform/azure/function_app_deployment_slot_not_using_latest_tls_encryption_version
Review HSM protection for Key Vault keys terraform/azure/key_vault_without_hsm_protection
Review managed identity use in AKS terraform/azure/kubernetes_cluster_managed_identity_disabled
Logic App has no managed identity configured terraform/azure/logic_app_managed_identity_disabled
Review the minimum TLS version for Azure SQL terraform/azure/mssql_not_using_latest_tls_encryption_version
Review the minimum TLS version for Azure PostgreSQL terraform/azure/postgresql_not_using_latest_tls_encryption_version
Review managed identity use for Azure Redis terraform/azure/redis_cache_managed_identity_is_not_set_to_system_assigned
Review the minimum TLS version for Azure Redis terraform/azure/redis_cache_not_using_latest_tls_encryption_version
Review customer-managed keys for Azure Storage terraform/azure/storage_account_without_cmk
Review Windows VM automatic updates terraform/azure/vm_with_automatic_updates_disabled
Review Azure VM extension operations terraform/azure/vm_with_extension_operations_enabled
Review administrator SSH keys for Azure VMs terraform/azure/vm_without_admin_ssh_public_key_set
Review Azure VM encryption at host terraform/azure/vm_without_encryption_at_host

Related pages148

Review Azure Policy configuration for AKS

Configure policy assignments and effects, then verify the required detection and blocking behavior.

Review customer-managed keys for AKS disks

Use supported disk encryption settings when the organization requires customer-managed keys.

AKS RBAC is disabled

Grant users and service accounts only the Kubernetes permissions they need.

Review AKS network policy settings

Use a supported policy engine and actual NetworkPolicy rules to allow only required pod traffic.

Review private access to the AKS API server

Prepare the management path first and restrict API access to the operators who need it.

Review Activity Log retention

Retain Activity Logs for the required investigation and audit period, and check destination policies.

Review App Service FTP transport protection

Use FTPS for file transfer and disable FTP access when it is unnecessary.

Review App Service HTTP/2 settings

Evaluate HTTP/2 against client compatibility and transport requirements.

Review App Service managed identity use

Reduce stored long-lived credentials when accessing supported Azure resources.

Review App Service built-in authentication

Apply appropriate authentication and authorization to protected paths.

Review App Service PHP runtime support

Use a supported PHP release, test app compatibility, and apply security updates.

Review App Service Python runtime support

Maintain security fixes and compatibility with a supported Python runtime and dependencies.

Review App Service client certificate requirements

Apply certificate requirements and validation to paths that need certificate-based caller authentication.

Review WAF configuration for Azure Application Gateway

Apply required WAF inspection and blocking to web traffic.

Review public network access to Azure AI Search

Limit search-service access to the required clients.

Review Defender for Cloud protection plans

Review the Defender for Cloud coverage your workloads need together with paid-plan costs.

Review WAF policy associations for Azure Front Door

Associate required WAF policies with request-handling endpoints.

Review Azure role permissions for guest users

Grant guests only the required actions and scope.

Review Key Vault secret expiration

Schedule credential replacement and update its consumers.

Review Azure Key Vault audit-log collection

Send Key Vault AuditEvent logs to the required destination and verify actual access records.

Review TLS enforcement for Azure MySQL

Require TLS for Azure MySQL connections and validate the server certificate on clients.

Azure Network Watcher flow logs are disabled

Collect the required network-traffic records with Azure Network Watcher flow logs.

Review Azure PostgreSQL connection encryption

Require TLS for database connections and retain client validation of the server certificate.

Review Azure PostgreSQL throttling of failed authentication

Limit repeated incorrect-password connections and monitor authentication failures.

Azure PostgreSQL disconnection logging is disabled

Use disconnection logs to investigate when PostgreSQL sessions end and how long they last.

Review Azure PostgreSQL threat detection

Verify Defender protection for suspicious PostgreSQL activity and actual alert delivery.

Review Azure PostgreSQL connection logging

Collect the logs needed to investigate PostgreSQL connection attempts and successful connections.

Azure PostgreSQL checkpoint logging is disabled

Use checkpoint logs to investigate PostgreSQL disk writes and performance problems.

Review Azure PostgreSQL statement duration logging

Collect statement durations for operational needs and manage logging overhead.

Azure Redis allows unencrypted connections

Disable the non-TLS port and configure applications to use TLS connections.

Review the Azure Redis maintenance schedule

Prepare a maintenance window and connection recovery for automatic updates.

Review Azure SQL Database threat detection

Enable the threat detection needed in addition to audit logging.

Review Azure SQL server audit logging

Configure an audit policy to record database activity on the server.

Review administrator emails for Azure SQL security alerts

Deliver security alerts through a channel their owners monitor.

Review Azure SQL server security alerts

Check that required security alerts are enabled and reach their owners.

Azure NSG allows internet access to SSH

Restrict SSH administration to approved access paths.

Review secure transfer for Azure Storage

Require encrypted connections for Storage requests.

Excessive permissions in an Azure file-share access policy

Grant only the permissions a file-share SAS needs.

Azure Storage allows Shared Key access

Reduce account-key use and grant access to individual users and applications.

Excessive permissions in an Azure Table access policy

Limit Table SAS permissions to required entity operations.

Review trusted-service exceptions for Azure Storage

Allow Storage firewall exceptions only for required Azure services.

Review the minimum TLS version for Azure Storage

Use TLS 1.2 or later in Storage clients.

Azure Storage allows cross-tenant object replication

Allow cross-tenant object replication only for approved purposes.

Review Azure User Access Administrator assignment scope

Limit access-management roles to the required principals and scope.

Review Azure VM migration to managed disks

Migrate retired unmanaged disks to managed disks and verify recovery procedures.

Review Azure VM network-interface attachment

Attach a valid NIC and configure subnet, NSG and routing controls separately.

Review Azure Web App HTTPS enforcement

Use HTTPS for web requests and never send sensitive information over plaintext HTTP.

Review IP forwarding on Azure network interfaces

Enable IP forwarding only on interfaces that need to relay traffic.

Review public IP associations on Azure network interfaces

Check whether the workload needs a directly associated public IP.

Review Azure resource diagnostic settings

Configure the required Azure diagnostic logs and destinations, then verify collection.