Azure

Terraform で定義する Azure リソースのセキュリティと設定に関する文書です。

Terraform で定義する Azure リソースのセキュリティと設定を扱う 148 件の文書です。

文書一覧

文書 パス
AKS の Azure Policy 適用設定の確認 terraform/azure/aks_uses_azure_policies_addon_disabled
AKS ディスクのカスタマー管理キー設定の確認 terraform/azure/aks_disk_encryption_set_id_undefined
AKS の RBAC が無効 terraform/azure/aks_rbac_disabled
AKS ネットワークポリシー設定の確認 terraform/azure/aks_network_policy_misconfigured
AKS API サーバーのプライベートアクセス設定の確認 terraform/azure/aks_private_cluster_disabled
Activity Logの保持期間の確認 terraform/azure/small_activity_log_retention_period
App Service の FTP 転送保護の確認 terraform/azure/app_service_ftps_enforce_disabled
App Service の HTTP/2 設定の確認 terraform/azure/app_service_http2_disabled
App Service のマネージド ID 使用の確認 terraform/azure/app_service_managed_identity_disabled
App Service の組み込み認証設定の確認 terraform/azure/app_service_authentication_disabled
App Service の PHP ランタイムサポート状況の確認 terraform/azure/app_service_without_latest_php_version
App Service の Python ランタイムサポート状況の確認 terraform/azure/app_service_without_latest_python_version
App Service のクライアント証明書要求設定の確認 terraform/azure/azure_app_service_client_certificate_disabled
Azure Application GatewayのWAF設定の確認 terraform/azure/waf_is_disabled_for_azure_application_gateway
Azure AI Searchのパブリックネットワークアクセスの確認 terraform/azure/azure_cognitive_search_public_network_access_enabled
Defender for Cloudの保護プランの確認 terraform/azure/security_center_pricing_tier_is_not_standard
Azure Front DoorのWAFポリシー関連付けの確認 terraform/azure/azure_front_door_waf_disabled
Azureゲストユーザーのロール権限の確認 terraform/azure/role_assignment_not_limit_guest_users_permissions
Key Vaultシークレットの有効期限設定の確認 terraform/azure/secret_expiration_not_set
Azure Key Vaultの監査ログ収集の確認 terraform/azure/vault_auditing_disabled
Azure MySQL の TLS 強制設定の確認 terraform/azure/mysql_ssl_connection_disabled
Azure Network Watcherのフローログが無効 terraform/azure/network_watcher_flow_disabled
Azure PostgreSQL の接続暗号化設定の確認 terraform/azure/ssl_enforce_is_disabled
Azure PostgreSQL の認証失敗時の接続制限設定の確認 terraform/azure/postgresql_server_without_connection_throttling
Azure PostgreSQL の切断ログが無効 terraform/azure/postgresql_log_disconnections_not_set
Azure PostgreSQL の脅威検出設定の確認 terraform/azure/postgresql_server_threat_detection_policy_disabled
Azure PostgreSQL の接続ログ設定の確認 terraform/azure/postgresql_log_connections_not_set
Azure PostgreSQL のチェックポイントログが無効 terraform/azure/postgresql_log_checkpoints_disabled
Azure PostgreSQL の文の実行時間ログ設定の確認 terraform/azure/postgresql_log_duration_not_set
Azure Redis で暗号化されていない接続を許可 terraform/azure/redis_cache_allows_non_ssl_connections
Azure Redis のメンテナンス予定の確認 terraform/azure/redis_not_updated_regularly
Azure SQL Databaseの脅威検出設定の確認 terraform/azure/sql_database_audit_disabled
Azure SQLサーバーの監査ログ設定の確認 terraform/azure/sql_server_auditing_disabled
Azure SQLセキュリティアラートの管理者メール設定の確認 terraform/azure/sql_server_alert_email_disabled
Azure SQLサーバーのセキュリティアラート設定の確認 terraform/azure/mssql_server_database_with_alerts_disabled
Azure NSGでインターネットからのSSHアクセスが許可されている terraform/azure/ssh_is_exposed_to_the_internet
Azure Storageの安全な転送設定の確認 terraform/azure/storage_account_not_forcing_https
Azureファイル共有のアクセスポリシーに過剰な権限がある terraform/azure/storage_share_allows_all_acl_permissions
Azure StorageでShared Keyアクセスが許可されている terraform/azure/storage_account_with_shared_access_key
Azure Tableのアクセスポリシーに過剰な権限がある terraform/azure/storage_table_allows_all_acl_permissions
Azure Storageの信頼されたサービスの例外設定の確認 terraform/azure/trusted_microsoft_services_not_enabled
Azure Storageの最小TLSバージョンの確認 terraform/azure/storage_account_not_using_latest_tls_encryption_version
Azure Storageでテナント間のオブジェクトレプリケーションが許可されている terraform/azure/storage_account_with_cross_tenant_replication_enabled
Azure User Access Administratorの割り当てスコープの確認 terraform/azure/use_of_user_access_administrator_role_is_not_restricted
Azure VM のマネージドディスク移行の確認 terraform/azure/vm_without_managed_disk
Azure VM のネットワークインターフェイス接続の確認 terraform/azure/vm_not_attached_to_network
Azure Web App の HTTPS 強制設定の確認 terraform/azure/web_app_accepting_traffic_other_than_https
AzureネットワークインターフェイスのIP転送設定の確認 terraform/azure/network_interfaces_ip_forwarding_enabled
AzureネットワークインターフェイスのパブリックIP関連付けの確認 terraform/azure/network_interfaces_with_public_ip
Azureリソースの診断設定の確認 terraform/azure/resource_without_diagnostic_settings
Azure NSGの重要なサービスへのアクセス確認 terraform/azure/sensitive_port_is_exposed_to_small_public_network
Azureセキュリティ連絡先のメールアドレスが未設定 terraform/azure/security_contact_email
Azureカスタムロールがロール定義の変更を許可している terraform/azure/role_definition_allows_custom_role_creation
Azureサービスのリソースログ収集の確認 terraform/azure/service_without_resource_logging
Azureフローログの保持期間の確認 terraform/azure/small_flow_logs_retention_period
Azure Databricksのカスタマーマネージドキー適用範囲の確認 terraform/azure/databricks_workspace_without_cmk
Container Registry の管理者ユーザーが有効 terraform/azure/admin_user_enabled_for_container_registry
Key Vaultシークレットにコンテンツの種類が設定されていない terraform/azure/key_vault_secrets_content_type_undefined
Cosmos DB アカウントのタグが未設定 terraform/azure/cosmos_db_account_without_tags
Databricks 診断ログ収集の確認 terraform/azure/databricks_diagnostic_logging_unconfigured
Function App の FTP 通信保護の確認 terraform/azure/function_app_ftps_enforce_disabled
Function App の HTTP/2 設定の確認 terraform/azure/function_app_http2_disabled
Function App のマネージド ID の未設定 terraform/azure/function_app_managed_identity_disabled
Function App の認証設定の確認 terraform/azure/function_app_authentication_disabled
Function App のクライアント証明書要件の確認 terraform/azure/function_app_client_certificates_unrequired
Cosmos DBのIPファイアウォール設定の見直し terraform/azure/cosmosdb_account_ip_range_filter_not_set
Azure Backup Vault の不変性保護の確認 terraform/azure/backup_vault_without_immutability
Recovery Services Vault のバックアップ不変性の確認 terraform/azure/recovery_services_vaut_without_immutability
AKS の Kubernetes Dashboard 使用の確認 terraform/azure/dashboard_is_enabled
Azure SQLサーバーの監査ポリシー設定の確認 terraform/azure/mssql_server_auditing_disabled
Azure SQL監査ポリシーの保持期間の確認 terraform/azure/small_mssql_audit_retention_period
Managed Disk の暗号化方式の確認 terraform/azure/encryption_on_managed_disk_disabled
MariaDB ワークロードのリージョン災害復旧の準備 terraform/azure/mariadb_server_georedundant_backup_disabled
Network Security Group 削除の Activity Log アラートの確認 terraform/azure/activity_log_alert_for_delete_network_security_group_not_configured
Network Security Group 作成・変更の Activity Log アラートの確認 terraform/azure/activity_log_alert_for_create_or_update_network_security_group_not_configured
Azure サブネットの NSG 関連付けの確認 terraform/azure/security_group_is_not_configured
Policy Assignment 削除の Activity Log アラートの確認 terraform/azure/activity_log_alert_for_delete_policy_assignment_not_configured
Policy Assignment 作成・変更の Activity Log アラートの確認 terraform/azure/activity_log_alert_for_create_policy_assignment_not_configured
Azure PostgreSQLのログ保持設定の確認 terraform/azure/log_retention_is_not_set
Azure PostgreSQL のサーバーログ保存期間の確認 terraform/azure/small_postgresql_db_server_log_retention_period
Azure PostgreSQL の保存データ暗号化設定の確認 terraform/azure/postgresql_server_infrastructure_encryption_disabled
Azure PostgreSQLの地理冗長バックアップ設定の確認 terraform/azure/geo_redundancy_is_disabled
Public IP 削除の Activity Log アラートの確認 terraform/azure/activity_log_alert_for_delete_public_ip_address_rule_not_configured
Public IP 作成・変更の Activity Log アラートの確認 terraform/azure/activity_log_alert_for_create_or_update_public_ip_address_rule_not_configured
Azure Key Vault の完全削除保護の確認 terraform/azure/key_vault_purge_protection_is_enabled
Azure RDP ルールの公開アクセス範囲の確認 terraform/azure/rdp_is_exposed_to_the_internet
SQL Server ファイアウォールルール削除の Activity Log アラートの確認 terraform/azure/activity_log_alert_for_delete_sql_server_firewall_rule_not_configured
SQL Server ファイアウォール規則作成・変更の Activity Log アラートの確認 terraform/azure/activity_log_alert_for_create_or_update_sql_server_firewall_rule_not_configured
Azure SQLのMicrosoft Entra管理者名の確認 terraform/azure/sql_server_predictable_active_directory_admin_account_name
Azure SQL管理者のログイン名の確認 terraform/azure/sql_server_predictable_admin_account_name
Azure SQLのMicrosoft Entra管理者設定の確認 terraform/azure/ad_admin_not_configured_for_sql_server
Azure SQL監査ログの保持期間の確認 terraform/azure/small_msql_server_audit_retention
Security Solution 削除の Activity Log アラートの確認 terraform/azure/activity_log_alert_for_delete_security_solution_not_configured
Security Solution 作成・変更の Activity Log アラートの確認 terraform/azure/activity_log_alert_for_create_or_update_security_solution_not_configured
Service Fabric の管理認証設定の確認 terraform/azure/azure_active_directory_authentication
Service Health Activity Log アラートの確認 terraform/azure/activity_log_alert_for_service_health_not_configured
Azure Backup Vault の論理的な削除の確認 terraform/azure/backup_vault_without_soft_delete
Recovery Services Vault の削除後の復旧保護の確認 terraform/azure/recovery_services_vaut_without_soft_delete
Azure Blob コンテナーの論理的な削除の保持期間の確認 terraform/azure/containers_without_soft_delete
Azure Blob の論理的な削除の保持期間の確認 terraform/azure/blob_storage_without_soft_delete
Azure ファイル共有の論理的な削除の確認 terraform/azure/file_share_without_soft_delete
Beta - 削除保護の確認が必要な Azure ストレージアカウント terraform/azure/storage_account_without_delete_lock
Virtual Network の DDoS 保護プランの確認 terraform/azure/virtual_network_with_ddos_protection_plan_disabled
Redisファイアウォールのアクセス範囲の見直し terraform/azure/redis_publicly_accessible
Azure Storage Account の公開アクセス設定の確認 terraform/azure/public_storage_account
匿名読み取りを許可した Azure Storage Container terraform/azure/storage_container_is_publicly_accessible
Azure MSSQL Server のパブリックネットワークアクセスの確認 terraform/azure/mssql_server_public_network_access_enabled
公開ネットワークアクセスが有効な Azure MariaDB Server terraform/azure/mariadb_public_network_access_enabled
旧 Azure MySQL Server のパブリックネットワークアクセスの確認 terraform/azure/mysql_server_public_access_enabled
Azure Recovery Services Vault のパブリックネットワークアクセスの確認 terraform/azure/recovery_services_vaut_with_public_network_access
Azure Container Registry の削除防止ロックの確認 terraform/azure/azure_container_registry_with_no_locks
Azure Databricksの仮想ネットワーク配置の確認 terraform/azure/databricks_workspace_using_default_virtual_network
Azure Storage Account の既定のネットワークアクセスの確認 terraform/azure/default_azure_storage_account_network_access_is_too_permissive
Azure Linux VM でパスワード認証が許可されている terraform/azure/azure_instance_using_basic_authentication
Azure Redis の許可アドレス範囲の確認 terraform/azure/firewall_rule_allows_too_many_hosts_to_access_redis_cache
Key Vaultキーの有効期限設定の確認 terraform/azure/key_expiration_not_set
Azure NSGのプライベートネットワークからの重要ポートへのアクセス確認 terraform/azure/sensitive_port_is_exposed_to_wide_private_network
Azure の管理用・内部サービス用ポートのアクセス範囲の確認 terraform/azure/sensitive_port_is_exposed_to_entire_network
Azure Files の SMB チャネル暗号ポリシーの確認 terraform/azure/storage_account_using_unsafe_smb_channel_encryption
セキュリティアラートメールが無効 terraform/azure/email_alerts_disabled
Azure SQL Database の保存時暗号化の確認 terraform/azure/sql_database_without_data_encryption
Diagnostic Setting のログカテゴリの確認 terraform/azure/diagnostic_settings_without_appropriate_logging
すべての IPv4 アドレスを許可する Redis ファイアウォール terraform/azure/redis_entirely_accessible
IPv4 全体を指定した Azure データベースのファイアウォール規則 terraform/azure/sql_server_ingress_from_any_ip
Azure Files の SMB バージョンポリシーの確認 terraform/azure/storage_account_not_using_latest_smb_protocol_version
App Service の最小 TLS バージョン設定の確認 terraform/azure/app_service_not_using_latest_tls_encryption_version
Function App の最小 TLS バージョンの確認 terraform/azure/function_app_not_using_latest_tls_encryption_version
Azureデータベースのファイアウォールが広範なアクセスを許可 terraform/azure/unrestricted_sql_server_access
AKS 監査ログ収集の確認 terraform/azure/aks_without_audit_logs
App Service スロットのマネージド ID 使用の確認 terraform/azure/app_service_slot_managed_identity_disabled
Azure Container Registry の権限範囲の確認 terraform/azure/azure_container_registry_with_broad_permissions
Container App のマネージド ID の未設定 terraform/azure/container_app_managed_identity_disabled
Container Group のマネージド ID の未設定 terraform/azure/container_group_managed_identity_disabled
Azure Container Instances のネットワーク公開範囲の確認 terraform/azure/container_instances_not_using_private_virtual_networks
Managed Disk のカスタマー管理キー設定の確認 terraform/azure/disk_encryption_on_managed_disk_disabled
Function App デプロイスロットの最小 TLS バージョンの確認 terraform/azure/function_app_deployment_slot_not_using_latest_tls_encryption_version
Key VaultキーのHSM保護設定の確認 terraform/azure/key_vault_without_hsm_protection
AKS のマネージド ID 使用の確認 terraform/azure/kubernetes_cluster_managed_identity_disabled
Logic App のマネージド ID の未設定 terraform/azure/logic_app_managed_identity_disabled
Azure SQLの最小TLSバージョンの確認 terraform/azure/mssql_not_using_latest_tls_encryption_version
Azure PostgreSQL の最小 TLS バージョン設定の確認 terraform/azure/postgresql_not_using_latest_tls_encryption_version
Azure Redis のマネージド ID 利用範囲の確認 terraform/azure/redis_cache_managed_identity_is_not_set_to_system_assigned
Azure Redis の最小 TLS バージョンの確認 terraform/azure/redis_cache_not_using_latest_tls_encryption_version
Azure Storageのカスタマーマネージドキー設定の確認 terraform/azure/storage_account_without_cmk
Windows VM の自動更新設定の確認 terraform/azure/vm_with_automatic_updates_disabled
Azure VM の拡張機能操作の確認 terraform/azure/vm_with_extension_operations_enabled
Azure VM の管理者 SSH 公開キー設定の確認 terraform/azure/vm_without_admin_ssh_public_key_set
Azure VM のホストでの暗号化設定の確認 terraform/azure/vm_without_encryption_at_host

関連ページ148

AKS の Azure Policy 適用設定の確認

ポリシーの割り当てと効果を設定し、必要な違反検出・拒否が機能することを確認してください。

AKS ディスクのカスタマー管理キー設定の確認

組織でカスタマー管理キーが必要な場合は、対応するディスク暗号化設定を適用してください。

AKS の RBAC が無効

ユーザーとサービスアカウントに必要な Kubernetes 権限だけを付与してください。

AKS ネットワークポリシー設定の確認

対応するポリシーエンジンと実際の NetworkPolicy ルールで、必要な Pod 通信だけを許可してください。

AKS API サーバーのプライベートアクセス設定の確認

先に管理経路を用意し、API へのアクセスを必要な運用担当者に限定してください。

Activity Logの保持期間の確認

調査と監査に必要な期間Activity Logを保存し、実際の保存先のポリシーを確認してください。

App Service の FTP 転送保護の確認

ファイル転送には FTPS を使い、不要な FTP アクセスは無効にしてください。

App Service の HTTP/2 設定の確認

クライアントの互換性と転送要件に合わせて HTTP/2 を検討してください。

App Service のマネージド ID 使用の確認

対応する Azure リソースへのアクセスで、保存する長期認証情報を減らしてください。

App Service の組み込み認証設定の確認

保護するパスに適切な認証と認可を適用してください。

App Service の PHP ランタイムサポート状況の確認

サポート対象の PHP を使い、互換性を確認しながらセキュリティ更新を適用してください。

App Service の Python ランタイムサポート状況の確認

サポート対象の Python と依存関係で、セキュリティ修正と互換性を維持してください。

App Service のクライアント証明書要求設定の確認

証明書による呼び出し元の認証が必要なパスで、適切に要求と検証を行ってください。

Azure Application GatewayのWAF設定の確認

必要なWebトラフィックにWAFの検査と遮断を適用してください。

Azure AI Searchのパブリックネットワークアクセスの確認

検索サービスへのアクセスを、必要なクライアントに限定してください。

Defender for Cloudの保護プランの確認

ワークロードに必要なDefender for Cloudの保護範囲と、有料プランの費用を併せて確認してください。

Azure Front DoorのWAFポリシー関連付けの確認

要求を処理するエンドポイントに、必要なWAFポリシーを関連付けてください。

Azureゲストユーザーのロール権限の確認

ゲストには必要な操作とスコープだけを許可してください。

Key Vaultシークレットの有効期限設定の確認

資格情報の交換を計画し、利用システムも更新してください。

Azure Key Vaultの監査ログ収集の確認

Key VaultのAuditEventログを必要な保存先へ送り、実際のアクセス記録を確認してください。

Azure MySQL の TLS 強制設定の確認

Azure MySQL 接続で TLS を必須にし、クライアントでサーバー証明書を検証してください。

Azure Network Watcherのフローログが無効

Azure Network Watcherのフローログで、必要なネットワーク通信記録を収集してください。

Azure PostgreSQL の接続暗号化設定の確認

データベース接続に TLS を要求し、クライアントによるサーバー証明書の検証を維持してください。

Azure PostgreSQL の認証失敗時の接続制限設定の確認

誤ったパスワードによる接続の繰り返しを制限し、認証失敗を監視してください。

Azure PostgreSQL の切断ログが無効

切断ログを使い、PostgreSQL セッションの終了時刻と継続時間を調査してください。

Azure PostgreSQL の脅威検出設定の確認

PostgreSQL の不審な活動に対する Defender 保護と実際の通知配信を確認してください。

Azure PostgreSQL の接続ログ設定の確認

PostgreSQL の接続試行と成功した接続を調べるために必要なログを収集してください。

Azure PostgreSQL のチェックポイントログが無効

チェックポイントログを使い、PostgreSQL のディスク書き込みや性能問題を調査してください。

Azure PostgreSQL の文の実行時間ログ設定の確認

運用要件に応じて文の実行時間を収集し、ログの負荷を管理してください。

Azure Redis で暗号化されていない接続を許可

非 TLS ポートを無効にし、アプリケーションが TLS 接続を使うように構成してください。

Azure Redis のメンテナンス予定の確認

自動更新に備え、メンテナンス時間帯と接続の復旧を準備してください。

Azure SQL Databaseの脅威検出設定の確認

監査記録とは別に、必要な脅威検出を有効にしてください。

Azure SQLサーバーの監査ログ設定の確認

サーバー内のデータベース活動を記録する監査ポリシーを設定してください。

Azure SQLセキュリティアラートの管理者メール設定の確認

担当者が確認する経路でセキュリティアラートを届けてください。

Azure SQLサーバーのセキュリティアラート設定の確認

必要なセキュリティアラートが有効で、担当者に届くことを確認してください。

Azure NSGでインターネットからのSSHアクセスが許可されている

SSH管理アクセスを承認された経路に限定してください。

Azure Storageの安全な転送設定の確認

Storageへの要求に暗号化された接続を使用してください。

Azureファイル共有のアクセスポリシーに過剰な権限がある

ファイル共有のSASに必要な権限だけを付与してください。

Azure StorageでShared Keyアクセスが許可されている

アカウントキーへの依存を減らし、ユーザーやアプリケーション単位でアクセス権を付与してください。

Azure Tableのアクセスポリシーに過剰な権限がある

Table SASの権限を、必要なエンティティ操作に限定してください。

Azure Storageの信頼されたサービスの例外設定の確認

必要なAzureサービスにだけ、Storageファイアウォールの例外を許可してください。

Azure Storageの最小TLSバージョンの確認

StorageクライアントでTLS 1.2以上を使用してください。

Azure Storageでテナント間のオブジェクトレプリケーションが許可されている

承認された用途に限り、テナント間のオブジェクトレプリケーションを許可してください。

Azure User Access Administratorの割り当てスコープの確認

アクセス管理ロールの対象とスコープを必要な範囲に限定してください。

Azure VM のマネージドディスク移行の確認

廃止された非マネージドディスクから移行し、復旧手順を検証してください。

Azure VM のネットワークインターフェイス接続の確認

有効な NIC を接続し、サブネット、NSG、ルーティングを別途設定してください。

Azure Web App の HTTPS 強制設定の確認

Web 要求には HTTPS を使い、平文 HTTP で機密情報を送らないでください。

AzureネットワークインターフェイスのIP転送設定の確認

トラフィックの中継が必要なインターフェイスだけでIP転送を有効にしてください。

AzureネットワークインターフェイスのパブリックIP関連付けの確認

ワークロードに直接関連付けるパブリックIPが必要か確認してください。

Azureリソースの診断設定の確認

Azureで必要な診断ログとエクスポート先を構成し、実際の収集を確認してください。