From f5bf9564a713b2bc21303176b4d8e4fa5a8f6baa Mon Sep 17 00:00:00 2001
From: BernieWhite What's changed since v1.34.2: What's changed since pre-release v1.35.0-B0116: What's changed since pre-release v1.35.0-B0084:Change logupgrade notes for more information.
Unreleased#
+v1.35.0#
+
+
+
+
+
+
+
+
+Azure.Pillar.CostOptimization
Azure.Pillar.OperationalExcellence
Azure.Pillar.PerformanceEfficiency
Azure.Pillar.Reliability
Azure.Pillar.Security
Azure.GA_2024_03
and Azure.Preview_2024_03
by @BernieWhite.
+ #2781
+
+Azure.GA_2023_12
and Azure.Preview_2023_12
baselines as obsolete.
+
+Azure.AppService.NETVersion
to detect out of date .NET versions including .NET 5/6/7 by @BernieWhite.
+ #2766
+
+2024_03
.Azure.AppService.PHPVersion
to detect out of date PHP versions before 8.2 by @BernieWhite.
+ #2768
+
+Azure.AppService.PHPVersion
check fails when phpVersion is null.2024_03
.Azure.AKS.Version
to use 1.27.9
as the minimum version by @BernieWhite.
+ #2771
+
+
+
+Azure.Cognitive.*
have been renamed to Azure.AI.*
.
+
+
+
+
+
+Azure.LB.AvailabilityZone
when zone list is empty or null by @jtracey93.
+ #2759
+
+
+v1.35.0-B0116 (pre-release)#
BenchmarkDotNet=v0.13.1, OS=Windows 10.0.22000\nIntel Core i7-1065G7 CPU 1.30GHz, 1 CPU, 8 logical and 4 physical cores\n.NET SDK=5.0.404\n [Host] : .NET Core 3.1.22 (CoreCLR 4.700.21.56803, CoreFX 4.700.21.57101), X64 RyuJIT\n DefaultJob : .NET Core 3.1.22 (CoreCLR 4.700.21.56803, CoreFX 4.700.21.57101), X64 RyuJIT\n
| Method | Mean | Error | StdDev | Gen 0 | Gen 1 | Allocated | |--------------------- |---------:|---------:|---------:|----------:|----------:|----------:| | Template | 78.97 ms | 2.842 ms | 8.246 ms | 6000.0000 | 1000.0000 | 27 MB | | PropertyCopyLoop | 47.83 ms | 0.954 ms | 2.033 ms | 4400.0000 | 200.0000 | 18 MB | | UserDefinedFunctions | 29.42 ms | 0.587 ms | 1.172 ms | 1500.0000 | 62.5000 | 6 MB |"},{"location":"benchmark/results-v1.14.3/","title":"Results v1.14.3","text":"BenchmarkDotNet=v0.13.1, OS=Windows 10.0.22000\nIntel Core i7-1065G7 CPU 1.30GHz, 1 CPU, 8 logical and 4 physical cores\n.NET SDK=6.0.202\n [Host] : .NET Core 3.1.24 (CoreCLR 4.700.22.16002, CoreFX 4.700.22.17909), X64 RyuJIT\n DefaultJob : .NET Core 3.1.24 (CoreCLR 4.700.22.16002, CoreFX 4.700.22.17909), X64 RyuJIT\n
| Method | Mean | Error | StdDev | Gen 0 | Gen 1 | Allocated | |--------------------- |---------:|---------:|---------:|----------:|---------:|----------:| | Template | 80.07 ms | 2.250 ms | 6.598 ms | 6666.6667 | 666.6667 | 28 MB | | PropertyCopyLoop | 52.08 ms | 0.955 ms | 0.798 ms | 4500.0000 | 125.0000 | 18 MB | | UserDefinedFunctions | 35.51 ms | 0.705 ms | 1.635 ms | 1600.0000 | 66.6667 | 7 MB |"},{"location":"benchmark/results-v1.15.0/","title":"Results v1.15.0","text":"BenchmarkDotNet=v0.13.1, OS=Windows 10.0.22000\nIntel Core i7-1065G7 CPU 1.30GHz, 1 CPU, 8 logical and 4 physical cores\n.NET SDK=6.0.202\n [Host] : .NET Core 3.1.24 (CoreCLR 4.700.22.16002, CoreFX 4.700.22.17909), X64 RyuJIT\n DefaultJob : .NET Core 3.1.24 (CoreCLR 4.700.22.16002, CoreFX 4.700.22.17909), X64 RyuJIT\n
| Method | Mean | Error | StdDev | Median | Gen 0 | Gen 1 | Allocated | |----------------------- |----------------:|----------------:|----------------:|----------------:|----------:|----------:|-------------:| | Template | 58,758,457.6 ns | 1,368,418.79 ns | 3,859,649.48 ns | 57,989,600.0 ns | 6000.0000 | 2000.0000 | 28,881,656 B | | PropertyCopyLoop | 35,152,022.3 ns | 699,686.11 ns | 1,206,924.16 ns | 34,927,013.3 ns | 4466.6667 | 133.3333 | 19,040,308 B | | UserDefinedFunctions | 19,601,380.5 ns | 382,322.59 ns | 560,403.50 ns | 19,517,700.0 ns | 1562.5000 | 62.5000 | 6,821,540 B | | ResolvePolicyAliasPath | 2,194.6 ns | 42.05 ns | 84.93 ns | 2,154.7 ns | 0.2861 | - | 1,200 B | | GetResourceType | 293.9 ns | 1.82 ns | 1.52 ns | 293.9 ns | 0.0858 | - | 360 B |"},{"location":"benchmark/results-v1.34.2/","title":"Results v1.34.2","text":"BenchmarkDotNet v0.13.12, Windows 11 (10.0.22631.3155/23H2/2023Update/SunValley3)\nIntel Core i7-1065G7 CPU 1.30GHz, 1 CPU, 8 logical and 4 physical cores\n.NET SDK 8.0.200\n [Host] : .NET 7.0.16 (7.0.1624.6629), X64 RyuJIT AVX2\n DefaultJob : .NET 7.0.16 (7.0.1624.6629), X64 RyuJIT AVX2\n
| Method | Mean | Error | StdDev | Median | Gen0 | Gen1 | Allocated | |------------------------------------- |----------------:|----------------:|-----------------:|----------------:|----------:|----------:|-----------:| | Template | 91,883,381.6 ns | 3,632,849.07 ns | 10,597,191.25 ns | 89,313,550.0 ns | 8000.0000 | 2000.0000 | 35435008 B | | PropertyCopyLoop | 49,633,655.3 ns | 1,505,203.29 ns | 4,318,710.40 ns | 47,957,783.3 ns | 5500.0000 | 2666.6667 | 23333345 B | | UserDefinedFunctions | 29,551,473.2 ns | 677,400.84 ns | 1,910,621.08 ns | 29,457,092.2 ns | 2187.5000 | 62.5000 | 9336566 B | | ResolvePolicyAliasPath | 2,408.4 ns | 129.91 ns | 381.01 ns | 2,252.3 ns | 0.2861 | - | 1200 B | | GetResourceType | 297.3 ns | 9.93 ns | 28.18 ns | 287.5 ns | 0.0858 | - | 360 B | | CustomTypeDependencyGraph_GetOrdered | 876.7 ns | 17.50 ns | 31.55 ns | 878.1 ns | 0.1602 | - | 672 B |"},{"location":"benchmark/results-v1.35.0/","title":"Results v1.35.0","text":"BenchmarkDotNet v0.13.12, Windows 11 (10.0.22631.3155/23H2/2023Update/SunValley3)\nIntel Core i7-1065G7 CPU 1.30GHz, 1 CPU, 8 logical and 4 physical cores\n.NET SDK 8.0.200\n [Host] : .NET 7.0.16 (7.0.1624.6629), X64 RyuJIT AVX2\n DefaultJob : .NET 7.0.16 (7.0.1624.6629), X64 RyuJIT AVX2\n
| Method | Mean | Error | StdDev | Median | Gen0 | Gen1 | Gen2 | Allocated | |------------------------------------- |-----------------:|-----------------:|-----------------:|-----------------:|----------:|----------:|---------:|-----------:| | Template | 63,730,486.52 ns | 1,266,452.101 ns | 2,643,557.149 ns | 63,341,771.43 ns | 8285.7143 | 4142.8571 | 142.8571 | 35441751 B | | PropertyCopyLoop | 39,934,076.76 ns | 773,166.984 ns | 1,852,458.712 ns | 39,569,050.00 ns | 5400.0000 | 100.0000 | - | 23337248 B | | UserDefinedFunctions | 23,403,397.62 ns | 751,878.865 ns | 2,070,892.753 ns | 22,610,225.00 ns | 2156.2500 | 62.5000 | - | 9336567 B | | ResolvePolicyAliasPath | 2,284.19 ns | 70.184 ns | 197.956 ns | 2,275.12 ns | 0.2861 | - | - | 1200 B | | GetResourceType | 254.25 ns | 5.013 ns | 7.805 ns | 252.31 ns | 0.0858 | - | - | 360 B | | CustomTypeDependencyGraph_GetOrdered | 58.35 ns | 1.192 ns | 2.352 ns | 58.09 ns | 0.0401 | - | - | 168 B |"},{"location":"benchmark/results-v1.8.1/","title":"Results v1.8.1","text":"BenchmarkDotNet=v0.13.1, OS=Windows 10.0.22000\nIntel Core i7-1065G7 CPU 1.30GHz, 1 CPU, 8 logical and 4 physical cores\n.NET SDK=5.0.404\n [Host] : .NET Core 3.1.22 (CoreCLR 4.700.21.56803, CoreFX 4.700.21.57101), X64 RyuJIT\n DefaultJob : .NET Core 3.1.22 (CoreCLR 4.700.21.56803, CoreFX 4.700.21.57101), X64 RyuJIT\n
| Method | Mean | Error | StdDev | Gen 0 | Gen 1 | Allocated | |--------------------- |---------:|---------:|---------:|----------:|----------:|----------:| | Template | 49.11 ms | 1.871 ms | 5.307 ms | 5000.0000 | 1000.0000 | 21 MB | | PropertyCopyLoop | 42.65 ms | 0.815 ms | 1.001 ms | 3812.5000 | 125.0000 | 15 MB | | UserDefinedFunctions | 26.26 ms | 0.518 ms | 1.126 ms | 1125.0000 | 31.2500 | 5 MB |"},{"location":"benchmark/results-v1.9.1/","title":"Results v1.9.1","text":"BenchmarkDotNet=v0.13.1, OS=Windows 10.0.22000\nIntel Core i7-1065G7 CPU 1.30GHz, 1 CPU, 8 logical and 4 physical cores\n.NET SDK=5.0.404\n [Host] : .NET Core 3.1.22 (CoreCLR 4.700.21.56803, CoreFX 4.700.21.57101), X64 RyuJIT\n DefaultJob : .NET Core 3.1.22 (CoreCLR 4.700.21.56803, CoreFX 4.700.21.57101), X64 RyuJIT\n
| Method | Mean | Error | StdDev | Gen 0 | Gen 1 | Allocated | |--------------------- |---------:|---------:|---------:|----------:|---------:|----------:| | Template | 54.28 ms | 1.081 ms | 1.443 ms | 5333.3333 | 555.5556 | 21 MB | | PropertyCopyLoop | 42.15 ms | 0.823 ms | 0.881 ms | 3833.3333 | 166.6667 | 15 MB | | UserDefinedFunctions | 25.76 ms | 0.510 ms | 1.076 ms | 1125.0000 | 31.2500 | 5 MB |"},{"location":"commands/Export-AzPolicyAssignmentData/","title":"Export-AzPolicyAssignmentData","text":"Export policy assignment data.
"},{"location":"commands/Export-AzPolicyAssignmentData/#syntax","title":"SYNTAX","text":""},{"location":"commands/Export-AzPolicyAssignmentData/#default-default","title":"Default (Default)","text":"Export-AzPolicyAssignmentData [-OutputPath <String>] [-PassThru] [-WhatIf] [-Confirm] [<CommonParameters>]\n
"},{"location":"commands/Export-AzPolicyAssignmentData/#name","title":"Name","text":"Export-AzPolicyAssignmentData [-Name <String>] [-Scope <String>] [-PolicyDefinitionId <String>]\n [-OutputPath <String>] [-PassThru] [-WhatIf] [-Confirm] [<CommonParameters>]\n
"},{"location":"commands/Export-AzPolicyAssignmentData/#id","title":"Id","text":"Export-AzPolicyAssignmentData -Id <String> [-PolicyDefinitionId <String>] [-OutputPath <String>] [-PassThru]\n [-WhatIf] [-Confirm] [<CommonParameters>]\n
"},{"location":"commands/Export-AzPolicyAssignmentData/#includedescendent","title":"IncludeDescendent","text":"Export-AzPolicyAssignmentData [-Scope <String>] [-IncludeDescendent] [-OutputPath <String>] [-PassThru]\n [-WhatIf] [-Confirm] [<CommonParameters>]\n
"},{"location":"commands/Export-AzPolicyAssignmentData/#description","title":"Description","text":"This is an experimental cmdlet.
Export policy assignment data.
By default the current subscription context will be exported. i.e Get-AzContext
Policy assignment data will be exported to the current working directory by default as JSON files, one per subscription.
All output files include a .assignment.json
extension by default.
Export-AzPolicyAssignmentData\n
Directory: C:\\\n\n\nMode LastWriteTime Length Name\n---- ------------- ------ ----\n-a--- 26/03/2022 7:01 PM 740098 \ue60b 00000000-0000-0000-0000-000000000000.assignment.json\n
Export policy assignment data from current subscription context.
"},{"location":"commands/Export-AzPolicyAssignmentData/#example-2","title":"Example 2","text":"Export-AzPolicyAssignmentData -Name '000000000000000000000000' -Scope '/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/PolicyRG'\n
Directory: C:\\\n\n\nMode LastWriteTime Length Name\n---- ------------- ------ ----\n-a--- 26/03/2022 7:15 PM 4185 \ue60b 00000000-0000-0000-0000-000000000000.assignment.json\n
Export policy assignment with specific name and scope.
"},{"location":"commands/Export-AzPolicyAssignmentData/#example-3","title":"Example 3","text":"Export-AzPolicyAssignmentData -Id '/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/PolicyRG/providers/Microsoft.Authorization/policyAssignments/000000000000000000000000'\n
Directory: C:\\\n\n\nMode LastWriteTime Length Name\n---- ------------- ------ ----\n-a--- 26/03/2022 7:42 PM 4185 \ue60b 00000000-0000-0000-0000-00000000000.assignment.json\n
Export policy assignment with specific resource ID.
"},{"location":"commands/Export-AzPolicyAssignmentData/#parameters","title":"PARAMETERS","text":""},{"location":"commands/Export-AzPolicyAssignmentData/#-name","title":"-Name","text":"Specifies the name of the policy assignment.
Type: String\nParameter Sets: Name\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentData/#-id","title":"-Id","text":"Specifies the fully qualified resource ID for the policy assignment.
Type: String\nParameter Sets: Id\nAliases: AssignmentId\n\nRequired: True\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentData/#-scope","title":"-Scope","text":"Specifies the scope at which the policy is applied for the assignment.
Type: String\nParameter Sets: Name, IncludeDescendent\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentData/#-policydefinitionid","title":"-PolicyDefinitionId","text":"Specifies the ID of the policy definition of the policy assignment.
Type: String\nParameter Sets: Name, Id\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentData/#-includedescendent","title":"-IncludeDescendent","text":"Causes the list of returned policy assignments to include all assignments related to the given scope, including those from ancestor scopes and those from descendent scopes.
Type: SwitchParameter\nParameter Sets: IncludeDescendent\nAliases:\n\nRequired: True\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentData/#-outputpath","title":"-OutputPath","text":"The path to store generated JSON files containing policy assignment data.
Type: String\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: $PWD\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentData/#-passthru","title":"-PassThru","text":"By default, FileInfo objects are returned to the pipeline for each JSON file created. When -PassThru
is specified, JSON files are not created and Azure resource objects are returned to the pipeline instead.
Type: SwitchParameter\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentData/#commonparameters","title":"CommonParameters","text":"This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.
"},{"location":"commands/Export-AzPolicyAssignmentData/#inputs","title":"INPUTS","text":""},{"location":"commands/Export-AzPolicyAssignmentData/#none","title":"None","text":""},{"location":"commands/Export-AzPolicyAssignmentData/#outputs","title":"OUTPUTS","text":""},{"location":"commands/Export-AzPolicyAssignmentData/#systemiofileinfo","title":"System.IO.FileInfo","text":"Return FileInfo
for each of the output files created, one per subscription context. This is the default.
Return an object for each Azure resource, and configuration exported. This is returned when the -PassThru
switch is used.
Export JSON based rules from policy assignment data.
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#syntax","title":"SYNTAX","text":"Export-AzPolicyAssignmentRuleData [-Name <String>] -AssignmentFile <String>\n [-ResourceGroup <ResourceGroupReference>] [-Subscription <SubscriptionReference>] [-OutputPath <String>]\n [-RulePrefix <String>] [-PassThru] [-KeepDuplicates] [<CommonParameters>]\n
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#description","title":"Description","text":"This is an experimental cmdlet.
Export JSON based rules from policy assignment data.
Policy assignment data generated from Export-AzPolicyAssignmentData
is used to generate JSON rules.
By default this is an offline process, requiring no connectivity to Azure.
Policy definitions with the Disabled
effect are ignored.
The subscription()
function will return the following unless overridden:
The resourceGroup()
function will return the following unless overridden:
To override, set the AZURE_SUBSCRIPTION
and AZURE_RESOURCE_GROUP
in configuration.
The rule prefix Azure
is also applied to the policy names unless overridden with -RulePrefix
or AZURE_POLICY_RULE_PREFIX
in configuration.
Currently the following limitations apply:
field()
expressions are not expanded.value
cannot be expanded e.g. \"value\": \"[substring(field('name'), 0, 3)]\"
.Export-AzPolicyAssignmentRuleData -Name \"policy\" -AssignmentFile .\\00000000-0000-0000-0000-000000000000.assignment.json\n
Mode LastWriteTime Length Name\n---- ------------- ------ ----\n-a--- 26/03/2022 9:41 PM 361 \uf15b definitions-policy.Rule.jsonc\n
Export JSON rules to file in current working directory.
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#example-2","title":"Example 2","text":"$subscription = @{\n subscriptionId = 'nnnnnnnn-nnnn-nnnn-nnnn-nnnnnnnnnnnn'\n displayName = 'My Azure Subscription'\n tenantId = 'nnnnnnnn-nnnn-nnnn-nnnn-nnnnnnnnnnnn'\n}\n\nExport-AzPolicyAssignmentRuleData -Name \"policy\" -AssignmentFile .\\00000000-0000-0000-0000-000000000000.assignment.json -Subscription $subscription\n
Mode LastWriteTime Length Name\n---- ------------- ------ ----\n-a--- 26/03/2022 9:41 PM 361 \uf15b definitions-policy.Rule.jsonc\n
Export JSON rules to file in current working directory using a specific subscription.
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#example-3","title":"Example 3","text":"Get-AzPolicyAssignmentDataSource | Export-AzPolicyAssignmentRuleData\n
Mode LastWriteTime Length Name\n---- ------------- ------ ----\n-a--- 27/03/2022 11:26 AM 721 \uf15b definitions-export-1b474938.Rule.jsonc\n
Export JSON rules from the current working directory using discovered assignment sources in the current working directory.
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#parameters","title":"PARAMETERS","text":""},{"location":"commands/Export-AzPolicyAssignmentRuleData/#-name","title":"-Name","text":"The name of the assignment. If not specified export-<xxxxxxxx>
will be used as the name of the assignment.
Type: String\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#-assignmentfile","title":"-AssignmentFile","text":"The absolute or relative path to an assignment data file.
Type: String\nParameter Sets: (All)\nAliases:\n\nRequired: True\nPosition: Named\nDefault value: None\nAccept pipeline input: True (ByPropertyName)\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#-outputpath","title":"-OutputPath","text":"The path to store generated JSON files containing resources.
If this parameter is not specified, output will be written to the current working path. The file name definitions-<name>.Rule.jsonc
will be used when this parameter is not set or a directory is specified. Where <name>
is the name of the assignment specified by -Name
.
This parameter has no affect when -PassThru
is used.
Type: String\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: $PWD\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#-ruleprefix","title":"-RulePrefix","text":"By default, policy rule names use the Azure
prefix e.g. Azure.Policy.e749c2d003da
.
When -RulePrefix
is specified, the default prefix is overridden.
For example, with -RulePrefix 'CustomPolicyPrefix'
this would generate the policy rule name CustomPolicyPrefix.Policy.e749c2d003da
.
Type: String\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#-passthru","title":"-PassThru","text":"By default, FileInfo objects are returned to the pipeline for each JSON file created. When -PassThru
is specified, JSON files are not created and Azure resource objects are returned to the pipeline instead.
Type: SwitchParameter\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: False\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#-keepduplicates","title":"-KeepDuplicates","text":"Determines if Azure policy definitions that duplicate existing built-in rules are exported. By default, duplicates are not exported.
This only applies to built-in policy definitions.
Type: SwitchParameter\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: False\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#-resourcegroup","title":"-ResourceGroup","text":"A name or hashtable of the Resource Group in the assignment data file. This Resource Group specified here will be used to resolve the resourceGroup()
function.
When the name of Resource Group is specified, the Resource Group will be looked up and used during export. This requires an authenticated connection to Azure with permissions to read the specified Resource Group.
Alternately, a hashtable of a Resource Group object can be specified. This option does not require an authenticated Azure connection. The hashtable will override the defaults for any specified properties.
For more details see about_PSRule_Azure_Configuration.
Type: ResourceGroupReference\nParameter Sets: (All)\nAliases: ResourceGroupName\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#-subscription","title":"-Subscription","text":"The name or hashtable of the Subscription in the assignment data file. This subscription specified here will be used to resolve the subscription()
function.
When a subscription name is specified, the Subscription will be looked up and used during export. This requires an authenticated connection to Azure with permissions to read the specified Subscription.
Alternately, a hashtable of a Subscription object can be specified. This option does not require an authenticated Azure connection. The hashtable will override the defaults for any specified properties.
For more details see about_PSRule_Azure_Configuration.
Type: SubscriptionReference\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#commonparameters","title":"CommonParameters","text":"This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#inputs","title":"INPUTS","text":""},{"location":"commands/Export-AzPolicyAssignmentRuleData/#systemstring","title":"System.String","text":""},{"location":"commands/Export-AzPolicyAssignmentRuleData/#outputs","title":"OUTPUTS","text":""},{"location":"commands/Export-AzPolicyAssignmentRuleData/#systemiofileinfo","title":"System.IO.FileInfo","text":""},{"location":"commands/Export-AzPolicyAssignmentRuleData/#systemobject","title":"System.Object","text":""},{"location":"commands/Export-AzPolicyAssignmentRuleData/#notes","title":"Notes","text":""},{"location":"commands/Export-AzPolicyAssignmentRuleData/#related-links","title":"RELATED LINKS","text":""},{"location":"commands/Export-AzRuleData/","title":"Export-AzRuleData","text":"Export resource configuration data from one or more Azure subscriptions.
"},{"location":"commands/Export-AzRuleData/#syntax","title":"SYNTAX","text":""},{"location":"commands/Export-AzRuleData/#default-default","title":"Default (Default)","text":"Export-AzRuleData [[-OutputPath] <String>] [-Subscription <String[]>] [-Tenant <String[]>]\n [-ResourceGroupName <String[]>] [-Tag <Hashtable>] [-PassThru] [-SkipDiscovery] [-ResourceId <String[]>]\n [-WhatIf] [-Confirm] [<CommonParameters>]\n
"},{"location":"commands/Export-AzRuleData/#all","title":"All","text":"Export-AzRuleData [[-OutputPath] <String>] [-ResourceGroupName <String[]>] [-Tag <Hashtable>] [-PassThru]\n [-All] [-WhatIf] [-Confirm] [<CommonParameters>]\n
"},{"location":"commands/Export-AzRuleData/#description","title":"Description","text":"Export resource configuration data from deployed resources in one or more Azure subscriptions.
If no filters are specified then the current subscription context will be exported. i.e. Get-AzContext
To export all subscriptions contexts use the -All
switch. When the -All
switch is used, all subscriptions contexts will be exported. i.e. Get-AzContext -ListAvailable
Resource data will be exported to the current working directory by default as JSON files, one per subscription.
"},{"location":"commands/Export-AzRuleData/#examples","title":"Examples","text":""},{"location":"commands/Export-AzRuleData/#example-1","title":"Example 1","text":"Export-AzRuleData\n
Directory: C:\\\n\nMode LastWriteTime Length Name\n---- ------------- ------ ----\n-a---- 1/07/2019 10:03 AM 7304948 00000000-0000-0000-0000-000000000001.json\n
Export resource configuration data from current subscription context.
"},{"location":"commands/Export-AzRuleData/#example-2","title":"Example 2","text":"Export-AzRuleData -Subscription 'Contoso Production', 'Contoso Non-production'\n
Directory: C:\\\n\nMode LastWriteTime Length Name\n---- ------------- ------ ----\n-a---- 1/07/2019 10:03 AM 7304948 00000000-0000-0000-0000-000000000001.json\n-a---- 1/07/2019 10:03 AM 7304948 00000000-0000-0000-0000-000000000002.json\n
Export resource configuration data from subscriptions by name.
"},{"location":"commands/Export-AzRuleData/#example-3","title":"Example 3","text":"Export-AzRuleData -ResourceGroupName 'rg-app1-web', 'rg-app1-db'\n
Directory: C:\\\n\nMode LastWriteTime Length Name\n---- ------------- ------ ----\n-a---- 1/07/2019 10:03 AM 7304948 00000000-0000-0000-0000-000000000001.json\n
Export resource configuration data from two resource groups within the current subscription context.
"},{"location":"commands/Export-AzRuleData/#parameters","title":"PARAMETERS","text":""},{"location":"commands/Export-AzRuleData/#-all","title":"-All","text":"By default, resources from the current subscription context are extracted. Use -All
to extract resource data for all subscription contexts instead.
Type: SwitchParameter\nParameter Sets: All\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleData/#-outputpath","title":"-OutputPath","text":"The path to store generated JSON files containing resources.
Type: String\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: 0\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleData/#-passthru","title":"-PassThru","text":"By default, FileInfo objects are returned to the pipeline for each JSON file created. When -PassThru
is specified, JSON files are not created and Azure resource objects are returned to the pipeline instead.
Type: SwitchParameter\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleData/#-resourcegroupname","title":"-ResourceGroupName","text":"Optionally filter resources by Resource Group name.
Type: String[]\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleData/#-subscription","title":"-Subscription","text":"Optionally filter resources by subscription, Id or Name.
Type: String[]\nParameter Sets: Default\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleData/#-tag","title":"-Tag","text":"Optionally filter resources based on tag.
Type: Hashtable\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleData/#-tenant","title":"-Tenant","text":"Optionally filter resources by a unique Tenant identifer.
Type: String[]\nParameter Sets: Default\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleData/#-resourceid","title":"-ResourceId","text":"A list of resource Ids to expand.
Type: String[]\nParameter Sets: Default\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: True (ByValue)\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleData/#-skipdiscovery","title":"-SkipDiscovery","text":"Determines if resource discovery is skipped. When skipped resources are expanded based on provided resource Ids.
Type: SwitchParameter\nParameter Sets: Default\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleData/#-confirm","title":"-Confirm","text":"Prompts you for confirmation before running the cmdlet.
Type: SwitchParameter\nParameter Sets: (All)\nAliases: cf\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleData/#-whatif","title":"-WhatIf","text":"Shows what would happen if the cmdlet runs. The cmdlet is not run.
Type: SwitchParameter\nParameter Sets: (All)\nAliases: wi\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleData/#commonparameters","title":"CommonParameters","text":"This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.
"},{"location":"commands/Export-AzRuleData/#inputs","title":"INPUTS","text":""},{"location":"commands/Export-AzRuleData/#none","title":"None","text":""},{"location":"commands/Export-AzRuleData/#outputs","title":"OUTPUTS","text":""},{"location":"commands/Export-AzRuleData/#systemiofileinfo","title":"System.IO.FileInfo","text":"Return FileInfo
for each of the output files created, one per subscription. This is the default.
Return an object for each Azure resource, and configuration exported. This is returned when the -PassThru
switch is used.
Export resource configuration data from Azure templates.
"},{"location":"commands/Export-AzRuleTemplateData/#syntax","title":"SYNTAX","text":""},{"location":"commands/Export-AzRuleTemplateData/#template-default","title":"Template (Default)","text":"Export-AzRuleTemplateData [[-Name] <String>] -TemplateFile <String> [-ParameterFile <String[]>]\n [-ResourceGroup <ResourceGroupReference>] [-Subscription <SubscriptionReference>] [-OutputPath <String>]\n [-PassThru] [<CommonParameters>]\n
"},{"location":"commands/Export-AzRuleTemplateData/#source","title":"Source","text":"Export-AzRuleTemplateData [[-Name] <String>] -SourceFile <String> [-ResourceGroup <ResourceGroupReference>]\n [-Subscription <SubscriptionReference>] [-OutputPath <String>] [-PassThru] [<CommonParameters>]\n
"},{"location":"commands/Export-AzRuleTemplateData/#description","title":"Description","text":"Export resource configuration data by merging Azure Resource Manager (ARM) template and parameter files. Template and parameters are merged by resolving template parameters, variables and functions.
This function does not check template files for strict compliance with Azure schemas.
By default this is an offline process, requiring no connectivity to Azure. Some functions that may be included in templates dynamically query Azure for current state. For these functions standard placeholder values are used by default. Functions that use placeholders include reference
, list*
.
The subscription()
function will return the following unless overridden:
The resourceGroup()
function will return the following unless overridden:
To override, set the AZURE_SUBSCRIPTION
and AZURE_RESOURCE_GROUP
in configuration.
Currently the following limitations apply:
environment
template function always returns values for Azure public cloud.reference()
function will return objects for resources within the same template. For resources that are not in the same template, a placeholder value is used instead.Export-AzRuleTemplateData -TemplateFile .\\template.json -ParameterFile .\\parameters.json;\n
Export resource configuration data based on merging a template and parameter file together.
"},{"location":"commands/Export-AzRuleTemplateData/#example-2","title":"Example 2","text":"Get-AzRuleTemplateLink | Export-AzRuleTemplateData;\n
Recursively scan the current working path and export linked templates.
"},{"location":"commands/Export-AzRuleTemplateData/#example-3","title":"Example 3","text":"$subscription = @{\n subscriptionId = 'nnnnnnnn-nnnn-nnnn-nnnn-nnnnnnnnnnnn'\n displayName = 'My Azure Subscription'\n tenantId = 'nnnnnnnn-nnnn-nnnn-nnnn-nnnnnnnnnnnn'\n}\nGet-AzRuleTemplateLink | Export-AzRuleTemplateData -Subscription $subscription;\n
Export linked templates from the current working path using a specific subscription.
"},{"location":"commands/Export-AzRuleTemplateData/#example-4","title":"Example 4","text":"$rg = @{\n name = 'my-test-rg'\n location = 'australiaeast'\n tags = @{\n env = 'prod'\n }\n}\nGet-AzRuleTemplateLink | Export-AzRuleTemplateData -ResourceGroup $rg;\n
Export linked templates from the current working path using a specific resource group.
"},{"location":"commands/Export-AzRuleTemplateData/#parameters","title":"PARAMETERS","text":""},{"location":"commands/Export-AzRuleTemplateData/#-name","title":"-Name","text":"The name of the deployment. If not specified export-<xxxxxxxx>
will be used as the name of the deployment.
This parameter is used by the deployment()
function and is also used to name the output file.
Type: String\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: 0\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleTemplateData/#-templatefile","title":"-TemplateFile","text":"The absolute or relative file path to an Azure Resource Manager template file.
Type: String\nParameter Sets: Template\nAliases:\n\nRequired: True\nPosition: Named\nDefault value: None\nAccept pipeline input: True (ByPropertyName)\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleTemplateData/#-parameterfile","title":"-ParameterFile","text":"The absolute or relative file path to one or more Azure Resource Manager template parameter files.
Type: String[]\nParameter Sets: Template\nAliases: TemplateParameterFile\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: True (ByPropertyName)\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleTemplateData/#-sourcefile","title":"-SourceFile","text":"The absolute or relative file path to a file of a Bicep file.
Type: String\nParameter Sets: Source\nAliases: f, FullName\n\nRequired: True\nPosition: Named\nDefault value: None\nAccept pipeline input: True (ByPropertyName)\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleTemplateData/#-outputpath","title":"-OutputPath","text":"The path to store generated JSON files containing resources.
If this parameter is not specified, output will be written to the current working path. The file name resources-<name>.json
will be used when this parameter is not set or a directory is specified. Where <name>
is the name of the deployment specified by -Name
.
This parameter has no affect when -PassThru
is used.
Type: String\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: $PWD\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleTemplateData/#-passthru","title":"-PassThru","text":"By default, FileInfo objects are returned to the pipeline for each JSON file created. When -PassThru
is specified, JSON files are not created and Azure resource objects are returned to the pipeline instead.
Type: SwitchParameter\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleTemplateData/#-resourcegroup","title":"-ResourceGroup","text":"A name or hashtable of the Resource Group where the deployment will occur. This Resource Group specified here will be used to resolve the resourceGroup()
function.
When the name of Resource Group is specified, the Resource Group will be looked up and used during export. This requires an authenticated connection to Azure with permissions to read the specified Resource Group.
Alternately, a hashtable of a Resource Group object can be specified. This option does not require an authenticated Azure connection. The hashtable will override the defaults for any specified properties.
For more details see about_PSRule_Azure_Configuration.
Type: ResourceGroupReference\nParameter Sets: (All)\nAliases: ResourceGroupName\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleTemplateData/#-subscription","title":"-Subscription","text":"The name or hashtable of the Subscription where the deployment will occur. This subscription specified here will be used to resolve the subscription()
function.
When a subscription name is specified, the Subscription will be looked up and used during export. This requires an authenticated connection to Azure with permissions to read the specified Subscription.
Alternately, a hashtable of a Subscription object can be specified. This option does not require an authenticated Azure connection. The hashtable will override the defaults for any specified properties.
For more details see about_PSRule_Azure_Configuration.
Type: SubscriptionReference\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleTemplateData/#commonparameters","title":"CommonParameters","text":"This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.
"},{"location":"commands/Export-AzRuleTemplateData/#inputs","title":"INPUTS","text":""},{"location":"commands/Export-AzRuleTemplateData/#systemstring","title":"System.String","text":""},{"location":"commands/Export-AzRuleTemplateData/#systemstring_1","title":"System.String[]","text":""},{"location":"commands/Export-AzRuleTemplateData/#outputs","title":"OUTPUTS","text":""},{"location":"commands/Export-AzRuleTemplateData/#systemiofileinfo","title":"System.IO.FileInfo","text":""},{"location":"commands/Export-AzRuleTemplateData/#systemobject","title":"System.Object","text":""},{"location":"commands/Export-AzRuleTemplateData/#notes","title":"Notes","text":""},{"location":"commands/Export-AzRuleTemplateData/#related-links","title":"RELATED LINKS","text":""},{"location":"commands/Get-AzPolicyAssignmentDataSource/","title":"Get-AzPolicyAssignmentDataSource","text":"Get policy assignment sources.
"},{"location":"commands/Get-AzPolicyAssignmentDataSource/#syntax","title":"SYNTAX","text":"Get-AzPolicyAssignmentDataSource [-InputPath <String[]>] [[-Path] <String>] [<CommonParameters>]\n
"},{"location":"commands/Get-AzPolicyAssignmentDataSource/#description","title":"Description","text":"This is an experimental cmdlet.
Get policy assignment sources. By default *.assignment.json
sources are discovered from the current working directory.
Get-AzPolicyAssignmentDataSource\n
AssignmentFile\n--------------\nC:\\00000000-0000-0000-0000-000000000001.assignment.json\nC:\\Users\\user\\00000000-0000-0000-0000-000000000002.assignment.json\n
Gets policy assignment sources from any *.assignment.json
sources within any folder in the current working directory path.
A path or filter to search for assignment files within the path specified by -Path
. By default, files with *.assignment.json
suffix will be used.
When searching for assignment files all sub-directories will be scanned. To perform a shallow search, prefix input paths with ./
.
Type: String[]\nParameter Sets: (All)\nAliases: f, AssignmentFile, FullName\n\nRequired: False\nPosition: Named\nDefault value: '*.assignment.json'\nAccept pipeline input: True (ByPropertyName)\nAccept wildcard characters: True\n
"},{"location":"commands/Get-AzPolicyAssignmentDataSource/#-path","title":"-Path","text":"Sets the path to search for assignment files in. By default, this is the current working path.
Type: String\nParameter Sets: (All)\nAliases: p\n\nRequired: False\nPosition: 0\nDefault value: $PWD\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Get-AzPolicyAssignmentDataSource/#commonparameters","title":"CommonParameters","text":"This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.
"},{"location":"commands/Get-AzPolicyAssignmentDataSource/#inputs","title":"INPUTS","text":""},{"location":"commands/Get-AzPolicyAssignmentDataSource/#systemstring","title":"System.String[]","text":""},{"location":"commands/Get-AzPolicyAssignmentDataSource/#outputs","title":"OUTPUTS","text":""},{"location":"commands/Get-AzPolicyAssignmentDataSource/#psrulerulesazurepipelinepolicyassignmentsource","title":"PSRule.Rules.Azure.Pipeline.PolicyAssignmentSource","text":""},{"location":"commands/Get-AzPolicyAssignmentDataSource/#notes","title":"Notes","text":""},{"location":"commands/Get-AzPolicyAssignmentDataSource/#related-links","title":"RELATED LINKS","text":""},{"location":"commands/Get-AzRuleTemplateLink/","title":"Get-AzRuleTemplateLink","text":"Get a metadata link to a Azure template file.
"},{"location":"commands/Get-AzRuleTemplateLink/#syntax","title":"SYNTAX","text":"Get-AzRuleTemplateLink [[-InputPath] <String[]>] [-SkipUnlinked] [[-Path] <String>] [<CommonParameters>]\n
"},{"location":"commands/Get-AzRuleTemplateLink/#description","title":"Description","text":"Gets a link between an Azure Resource Manager (ARM) parameter file and its referenced template file. Parameter files reference a template file by defining metadata. Alternatively, template files are discovered by naming convention.
By default, when parameter files without a matching template are discovered an error is raised.
To reference a template, set the metadata.template
property to a file path. Referencing templates outside of the path specified with -Path
is not permitted.
To discover template files by naming convention:
.parameters.json
.<templateName>.parameters.json
.<templateName>.json
.For more information see the about_PSRule_Azure_Metadata_Link topic.
"},{"location":"commands/Get-AzRuleTemplateLink/#examples","title":"Examples","text":""},{"location":"commands/Get-AzRuleTemplateLink/#example-1","title":"Example 1","text":"Get-AzRuleTemplateLink\n
Get links from any *.parameters.json
files within any folder in the current working path.
A path or filter to search for parameter files within the path specified by -Path
. By default, files with *.parameters.json
suffix will be used.
When searching for parameter files all sub-directories will be scanned. To perform a shallow search, prefix input paths with ./
.
Type: String[]\nParameter Sets: (All)\nAliases: f, TemplateParameterFile, FullName\n\nRequired: False\nPosition: 1\nDefault value: '*.parameters.json'\nAccept pipeline input: True (ByPropertyName)\nAccept wildcard characters: True\n
"},{"location":"commands/Get-AzRuleTemplateLink/#-skipunlinked","title":"-SkipUnlinked","text":"Use this option to ignore parameter files that have no matching template. By default, when parameter files without a matching template are discovered an error is raised.
Type: SwitchParameter\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Get-AzRuleTemplateLink/#-path","title":"-Path","text":"Sets the path to search for parameter files in. By default, this is the current working path.
Type: String\nParameter Sets: (All)\nAliases: p\n\nRequired: False\nPosition: 0\nDefault value: $PWD\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Get-AzRuleTemplateLink/#commonparameters","title":"CommonParameters","text":"This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.
"},{"location":"commands/Get-AzRuleTemplateLink/#inputs","title":"INPUTS","text":""},{"location":"commands/Get-AzRuleTemplateLink/#systemstring","title":"System.String[]","text":""},{"location":"commands/Get-AzRuleTemplateLink/#outputs","title":"OUTPUTS","text":""},{"location":"commands/Get-AzRuleTemplateLink/#psrulerulesazuredatametadataitemplatelink","title":"PSRule.Rules.Azure.Data.Metadata.ITemplateLink","text":""},{"location":"commands/Get-AzRuleTemplateLink/#notes","title":"Notes","text":""},{"location":"commands/Get-AzRuleTemplateLink/#related-links","title":"RELATED LINKS","text":"about_PSRule_Azure_Metadata_Link
"},{"location":"commands/PSRule.Rules.Azure/","title":"PSRule.Rules.Azure Module","text":""},{"location":"commands/PSRule.Rules.Azure/#description","title":"Description","text":"Validate Azure resources and infrastructure as code using PSRule.
"},{"location":"commands/PSRule.Rules.Azure/#psrule-cmdlets","title":"PSRule Cmdlets","text":""},{"location":"commands/PSRule.Rules.Azure/#export-azruledata","title":"Export-AzRuleData","text":"Export resource configuration data from one or more Azure subscriptions.
"},{"location":"commands/PSRule.Rules.Azure/#export-azruletemplatedata","title":"Export-AzRuleTemplateData","text":"Export resource configuration data from Azure templates.
"},{"location":"commands/PSRule.Rules.Azure/#get-azruletemplatelink","title":"Get-AzRuleTemplateLink","text":"Get a metadata link to a Azure template file.
"},{"location":"concepts/about_PSRule_Azure_Configuration/","title":"Configuration options","text":"Describes PSRule configuration options specific to PSRule for Azure.
"},{"location":"concepts/about_PSRule_Azure_Configuration/#description","title":"Description","text":"PSRule exposes configuration options that can be used to customize execution of PSRule.Rules.Azure
. This topic describes what configuration options are available.
PSRule configuration options can be specified by setting the configuration option in ps-rule.yaml
. Additionally, configuration options can be configured in a baseline or set at runtime. For details of setting configuration options see PSRule options.
The following configurations options are available for use:
AZURE_STORAGE_DEFENDER_PER_ACCOUNT
This configuration option determines the minimum version of Kubernetes for AKS clusters and node pools. Rules that check the Kubernetes version fail when the version is older than the version specified.
Syntax:
configuration:\n Azure_AKSMinimumVersion: string # A version string\n
Default:
# YAML: The default Azure_AKSMinimumVersion configuration option\nconfiguration:\n Azure_AKSMinimumVersion: 1.20.5\n
Example:
# YAML: Set the Azure_AKSMinimumVersion configuration option to 1.19.7\nconfiguration:\n Azure_AKSMinimumVersion: 1.19.7\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_aksnodeminimummaxpods","title":"Azure_AKSNodeMinimumMaxPods","text":"This configuration option determines the minimum allowed max pods setting per node pool. When an AKS cluster node pool is created, a maxPods
option is used to determine the maximum number of pods for each node in the node pool.
Syntax:
configuration:\n Azure_AKSNodeMinimumMaxPods: integer\n
Default:
# YAML: The default Azure_AKSNodeMinimumMaxPods configuration option\nconfiguration:\n Azure_AKSNodeMinimumMaxPods: 50\n
Example:
# YAML: Set the Azure_AKSNodeMinimumMaxPods configuration option to 30\nconfiguration:\n Azure_AKSNodeMinimumMaxPods: 30\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_allowedregions","title":"Azure_AllowedRegions","text":"This configuration option specifies a list of allowed locations that resources can be deployed to. Rules that check the location of Azure resources fail when a resource or resource group is created in a different region.
By default, Azure_AllowedRegions
is not configured. The rule Azure.Resource.AllowedRegions
is skipped when no allowed locations are configured.
Syntax:
configuration:\n Azure_AllowedRegions: array # An array of regions\n
Default:
# YAML: The default Azure_AllowedRegions configuration option\nconfiguration:\n Azure_AllowedRegions: []\n
Example:
# YAML: Set the Azure_AllowedRegions configuration option to Australia East, Australia South East\nconfiguration:\n Azure_AllowedRegions:\n - 'australiaeast'\n - 'australiasoutheast'\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_minimumcertificatelifetime","title":"Azure_MinimumCertificateLifetime","text":"This configuration option determines the minimum number of days allowed before certificate expiry. Rules that check certificate lifetime fail when the days remaining before expiry drop below this number.
Syntax:
configuration:\n Azure_MinimumCertificateLifetime: integer\n
Default:
# YAML: The default Azure_MinimumCertificateLifetime configuration option\nconfiguration:\n Azure_MinimumCertificateLifetime: 30\n
Example:
# YAML: Set the Azure_MinimumCertificateLifetime configuration option to 90\nconfiguration:\n Azure_MinimumCertificateLifetime: 90\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_parameter_file_expansion","title":"AZURE_PARAMETER_FILE_EXPANSION","text":"This configuration option determines if Azure template parameter files will automatically be expanded. By default, parameter files will not be automatically expanded.
Parameter files are expanded when PSRule cmdlets with the -Format File
parameter are used.
Syntax:
configuration:\n AZURE_PARAMETER_FILE_EXPANSION: bool\n
Default:
# YAML: The default AZURE_PARAMETER_FILE_EXPANSION configuration option\nconfiguration:\n AZURE_PARAMETER_FILE_EXPANSION: false\n
Example:
# YAML: Set the AZURE_PARAMETER_FILE_EXPANSION configuration option to enable expansion\nconfiguration:\n AZURE_PARAMETER_FILE_EXPANSION: true\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_policy_waiver_max_expiry","title":"AZURE_POLICY_WAIVER_MAX_EXPIRY","text":"This configuration option determines the maximum number of days in the future for a waiver policy exemption.
Syntax:
configuration:\n AZURE_POLICY_WAIVER_MAX_EXPIRY: integer\n
Default:
# YAML: The default AZURE_POLICY_WAIVER_MAX_EXPIRY configuration option\nconfiguration:\n AZURE_POLICY_WAIVER_MAX_EXPIRY: 366\n
Example:
# YAML: Set the AZURE_POLICY_WAIVER_MAX_EXPIRY configuration option to 90\nconfiguration:\n AZURE_POLICY_WAIVER_MAX_EXPIRY: 90\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_resource_group","title":"AZURE_RESOURCE_GROUP","text":"This configuration option sets the resource group object used by the resourceGroup()
function. Configure this option to change the resource group object when using exporting templates for analysis. Provided properties will override the default. Any properties that are not provided with use the defaults as specified below.
This configuration option will be ignored when -ResourceGroup
is used with Export-AzRuleTemplateData
.
Syntax:
configuration:\n AZURE_RESOURCE_GROUP:\n name: string\n location: string\n tags: object\n properties:\n provisioningState: string\n
Default:
# YAML: The default AZURE_RESOURCE_GROUP configuration option\nconfiguration:\n AZURE_RESOURCE_GROUP:\n name: 'ps-rule-test-rg'\n location: 'eastus'\n tags: { }\n properties:\n provisioningState: 'Succeeded'\n
Example:
# YAML: Override the location of the resource group object.\nconfiguration:\n AZURE_RESOURCE_GROUP:\n location: 'australiasoutheast'\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_subscription","title":"AZURE_SUBSCRIPTION","text":"This configuration option sets the subscription object used by the subscription()
function. Configure this option to change the subscription object when using exporting templates for analysis. Provided properties will override the default. Any properties that are not provided with use the defaults as specified below.
This configuration option will be ignored when -Subscription
is used with Export-AzRuleTemplateData
.
Syntax:
configuration:\n AZURE_SUBSCRIPTION:\n subscriptionId: string\n tenantId: string\n displayName: string\n state: string\n
Default:
# YAML: The default AZURE_SUBSCRIPTION configuration option\nconfiguration:\n AZURE_SUBSCRIPTION:\n subscriptionId: 'ffffffff-ffff-ffff-ffff-ffffffffffff'\n tenantId: 'ffffffff-ffff-ffff-ffff-ffffffffffff'\n displayName: 'PSRule Test Subscription'\n state: 'NotDefined'\n
Example:
# YAML: Override the display name of the subscription object\n AZURE_SUBSCRIPTION:\n displayName: 'My test subscription'\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_policy_ignore_list","title":"AZURE_POLICY_IGNORE_LIST","text":"This configuration option configures a custom list policy definitions to ignore when exporting policy to rules. In addition to the custom list, a built-in list of policies are ignored. The built-in list can be found here.
Configure this option to ignore policy definitions that:
Syntax:
configuration:\n AZURE_POLICY_IGNORE_LIST: array\n
Default:
# YAML: The default AZURE_POLICY_IGNORE_LIST configuration option\nconfiguration:\n AZURE_POLICY_IGNORE_LIST: []\n
Example:
# YAML: Add a custom policy definition to ignore\nconfiguration:\n AZURE_POLICY_IGNORE_LIST:\n - '/providers/Microsoft.Authorization/policyDefinitions/1f314764-cb73-4fc9-b863-8eca98ac36e9'\n - '/providers/Microsoft.Authorization/policyDefinitions/b54ed75b-3e1a-44ac-a333-05ba39b99ff0'\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_policy_rule_prefix","title":"AZURE_POLICY_RULE_PREFIX","text":"This configuration option sets the prefix for names of exported rules. Configure this option to change the prefix, which defaults to Azure
.
This configuration option will be ignored when -Prefix
is used with Export-AzPolicyAssignmentRuleData
.
Syntax:
configuration:\n AZURE_POLICY_RULE_PREFIX: string\n
Default:
# YAML: The default AZURE_POLICY_RULE_PREFIX configuration option\nconfiguration:\n AZURE_POLICY_RULE_PREFIX: 'Azure'\n
Example:
# YAML: Override the prefix of exported policy rules\n AZURE_POLICY_RULE_PREFIX: 'AzureCustomPrefix'\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_apim_min_api_version","title":"AZURE_APIM_MIN_API_VERSION","text":"This configuration option sets the minimum API version used for control plane API calls to API Management instances. Configure this option to change the minimum API version, which defaults to '2021-08-01'
.
Syntax:
configuration:\n AZURE_APIM_MIN_API_VERSION: string\n
Default:
# YAML: The default AZURE_APIM_MIN_API_VERSION configuration option\nconfiguration:\n AZURE_APIM_MIN_API_VERSION: '2021-08-01'\n
Example:
# YAML: Set the AZURE_APIM_MIN_API_VERSION configuration option to '2021-12-01-preview'\nconfiguration:\n AZURE_APIM_MIN_API_VERSION: '2021-12-01-preview'\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_cosmos_defender_per_account","title":"AZURE_COSMOS_DEFENDER_PER_ACCOUNT","text":"This configuration option enables validation for that each Cosmos DB account is associated with a Microsoft Defender for Cosmos DB resource level plan. Configure this option to enable the per account validation, which defaults to false
.
Syntax:
configuration:\n AZURE_COSMOS_DEFENDER_PER_ACCOUNT: boolean\n
Default:
# YAML: The default AZURE_COSMOS_DEFENDER_PER_ACCOUNT configuration option\nconfiguration:\n AZURE_COSMOS_DEFENDER_PER_ACCOUNT: false\n
Example:
# YAML: Set the AZURE_COSMOS_DEFENDER_PER_ACCOUNT configuration option to true\nconfiguration:\n AZURE_COSMOS_DEFENDER_PER_ACCOUNT: true\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_storage_defender_per_account","title":"AZURE_STORAGE_DEFENDER_PER_ACCOUNT","text":"This configuration option enables validation for that each storage account is associated with a Microsoft Defender for Storage resource level plan. Configure this option to enable the per account validation, which defaults to false
.
Syntax:
configuration:\n AZURE_STORAGE_DEFENDER_PER_ACCOUNT: boolean\n
Default:
# YAML: The default AZURE_STORAGE_DEFENDER_PER_ACCOUNT configuration option\nconfiguration:\n AZURE_STORAGE_DEFENDER_PER_ACCOUNT: false\n
Example:
# YAML: Set the AZURE_STORAGE_DEFENDER_PER_ACCOUNT configuration option to true\nconfiguration:\n AZURE_STORAGE_DEFENDER_PER_ACCOUNT: true\n
"},{"location":"concepts/about_PSRule_Azure_Metadata_Link/","title":"PSRule_Azure_Metadata_Link","text":""},{"location":"concepts/about_PSRule_Azure_Metadata_Link/#about_psrule_azure_metadata_link","title":"about_PSRule_Azure_Metadata_Link","text":"Describes how Azure Resource Manager (ARM) parameter files reference a template file.
"},{"location":"concepts/about_PSRule_Azure_Metadata_Link/#description","title":"Description","text":"Azure Resource Manager (ARM) supports storing additional metadata within parameter files. PSRule uses this metadata to link template and parameter files together to improve unit testing of templates.
To reference a template within a parameter file:
metadata.template
property to the template../
. When ./
is not used, the template with is relative to the -Path
parameter.For example:
{\n \"$schema\": \"https://schema.management.azure.com/schemas/2015-01-01/deploymentParameters.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"metadata\": {\n \"template\": \"./Resources.Template.json\"\n },\n \"parameters\": {\n }\n}\n
"},{"location":"concepts/about_PSRule_Azure_Metadata_Link/#see-also","title":"SEE ALSO","text":"PSRule for Azure allows you to export your current Azure Policy assignments out as rules to enforce controls during development. This allows you to:
Abstract
This topic covers using policy as rules which allows you to use Azure Policy as rules to test Infrastructure as Code.
Experimental - Learn more
Policy as rules are a work in progress. As always if you find bugs/ errors or if something just doesn't work as your expect it to, please let us know. You can log a bug on GitHub or provide feedback here.
"},{"location":"concepts/policy-as-rules/#limitations","title":"Limitations","text":"This feature does not support:
Disabled
are ignored.Using policy as rules is a two step process:
Run Export-AzPolicyAssignmentData
to export assignments from Azure to an *.assignment.json
file.
Key points:
Az
PowerShell module and using Connect-AzAccount
.Set-AzContext
.Run Export-AzPolicyAssignmentRuleData
to convert assignments to rules. To run this command an -AssignmentFile
parameter with the path to the assignment JSON file generated in the previous step.
After the command completes a new file *.Rule.jsonc
should be generated containing generated rules.
PSRule for Azure allows you to:
Azure
. To change the prefix:-RulePrefix
parameter when running Export-AzPolicyAssignmentRuleData
. ORAZURE_POLICY_RULE_PREFIX
configuration option in ps-rule.yaml
.AZURE_POLICY_IGNORE_LIST
configuration option in ps-rule.yaml
. This option allows you to prevent specific policies from being exported as rules.For example:
ps-rule.yamlconfiguration:\n AZURE_POLICY_RULE_PREFIX: MyOrg\n AZURE_POLICY_IGNORE_LIST:\n - /providers/Microsoft.Authorization/policyDefinitions/1f314764-cb73-4fc9-b863-8eca98ac36e9\n - /providers/Microsoft.Authorization/policyDefinitions/b54ed75b-3e1a-44ac-a333-05ba39b99ff0\n
"},{"location":"concepts/policy-as-rules/#generated-baseline","title":"Generated baseline","text":"v1.33.0
When exporting policies, PSRule for Azure will automatically generate a baseline including any generated rules. By default, this baseline is called Azure.PolicyBaseline.All
. If you change the prefix of generated rules the baseline will be named <Prefix>.PolicyBaseline.All
.
See Using baselines for examples on how to use a baseline in a run.
"},{"location":"concepts/policy-as-rules/#duplicate-policies","title":"Duplicate policies","text":"v1.33.0
When exporting policies, you may encounter definitions that are duplicates of existing rules shipped with PSRule for Azure. By default, built-in Azure policies that are duplicates of existing rules are ignored. Additionally, PSRule for Azure will automatically switch in existing rules into the generated baseline.
Note
This only applies to built-in Azure policies that are duplicates of existing rules. Custom policies are not effected.
The list of built-in policies that are duplicates can be viewed here. If you believe a policy is missing from this list, please open an issue.
This allows you to:
To override this behavior use the -KeepDuplicates
parameter switch when running Export-AzPolicyAssignmentRuleData
.
By default, PSRule will attempt to read and test all files. You can configure options to:
Abstract
This topic covers how you can configure PSRule to ignore files, specific rules, or rules for special cases.
"},{"location":"concepts/suppression/#excluding-a-rule","title":"Excluding a rule","text":"Docs
You can exclude a rule to effectively disable the rule. When excluded, a rule is not used to test any Azure resources.
To exclude a rule, set the Rule.Exclude
option within the ps-rule.yaml
file.
rule:\n exclude:\n # Ignore the following rules for all resources\n - Azure.VM.UseHybridUseBenefit\n - Azure.VM.Standalone\n
"},{"location":"concepts/suppression/#suppress-a-rule-individually","title":"Suppress a rule individually","text":"Docs
You can suppress a rule to effectively skip or ignore a rule for a specific case or exception.
To suppress a rule, set Suppression
option within the ps-rule.yaml
file. PSRule allows you to specify the name of the rule and the name of the resources that will be suppressed.
suppression:\n Azure.Storage.SoftDelete:\n # Ignore soft delete on the following non-production storage accounts\n - storagedeveus6jo36t\n - storagedeveus1df278\n
Tip
Use comments within ps-rule.yaml
to describe the reason why rules are excluded or suppressed. Meaningful comments help during peer review within a Pull Request (PR). Also consider including a date if the exclusions or suppressions are temporary.
Docs
If you need to commonly suppress a rule for multiple resources you can use a Suppression Group. A Suppression Group allow you to define a condition for when a rule should be suppressed.
Example
For example, suppose you want to suppress the Azure.Storage.SoftDelete
rule for Storage Accounts based on a tag.
A Suppression Group can be defined within a .Rule.yaml
file within the .ps-rule/
sub-directory. Create this directory in your repository or current working path if it doesn't already exist.
---\n# Synopsis: Ignore soft delete for development storage accounts\napiVersion: github.com/microsoft/PSRule/v1\nkind: SuppressionGroup\nmetadata:\n name: Local.IgnoreNonProdStorage\nspec:\n rule:\n - Azure.Storage.SoftDelete\n if:\n field: tags.env\n equals: dev\n
Learn
To learn more, see suppression groups and expressions.
"},{"location":"concepts/suppression/#ignoring-files","title":"Ignoring files","text":"Docs
To exclude or ignore files from being processed, configure the Input.PathIgnore option. This option allows you to ignore files using a path spec.
To ignore files with common extensions, set the Input.PathIgnore
option within the ps-rule.yaml
file.
input:\n pathIgnore:\n # Exclude files with these extensions\n - '*.md'\n - '*.png'\n # Exclude specific configuration files\n - 'bicepconfig.json'\n
To ignore all files with some exceptions, set the Input.PathIgnore
option within the ps-rule.yaml
file.
input:\n pathIgnore:\n # Exclude all files\n - '*'\n # Only process deploy.bicep files\n - '!**/deploy.bicep'\n
Tip
Some common file exclusions are recommended for working with Azure Bicep source files. See Configuring path exclusions for details.
"},{"location":"customization/enforce-codeowners/","title":"Enforcing code ownership","text":"Abstract
The following scenario extends on existing code ownership features available in your tool of choice. This topic covers static analysis testing for the content (specific Azure resource) within file paths. This allows you to:
Pull requests (PRs) are a key concept within common Git workflows and DevOps culture to enforce peer review. Code ownership provides a mechanism to require one or more specific people review changes prior to merging a PR.
For Git repositories in GitHub and Azure Repos, code ownership is controlled based on file path. If a person or team owns a file or file path they are required to review the changes proposed in the PR. The specifics of how many approvals and if approval is optional vs required is controlled by branch protection/ policies.
In the context of Azure Infrastructure as Code (IaC) - Azure Bicep/ ARM templates, these changes may:
PSRule allows teams to layer on additional rules to ensure Azure resources fall within the paths expected by code ownership.
Info
Code ownership is implemented through CODEOWNERS in GitHub and required reviewers in Azure Repos.
"},{"location":"customization/enforce-codeowners/#creating-a-new-rule","title":"Creating a new rule","text":"Within the .ps-rule/
sub-directory create a new file called Org.Azure.Rule.ps1
. Use the following snippet to populate the rule file:
# Synopsis: Policy exemptions must be stored under designated paths for review.\nRule 'Org.Azure.Policy.Path' -Type 'Microsoft.Authorization/policyExemptions' {\n $Assert.WithinPath($PSRule.Source['Parameter'], '.', @(\n 'deployments/policy/'\n ));\n}\n
Some key points to call out with the rule snippet include:
Org.Azure.Policy.Path
. Each rule name must be unique.Microsoft.Authorization/policyExemptions
. i.e. Policy exemptions.$Assert.WithinPath
ensures the specifies path is within the deployments/policy/
sub-directory.$PSRule.Source
exposes the source path for the resource. PSRule for Azure exposes a Template
and Parameter
source for resources originating from a template.Tip
For recommendations on naming and storing rules see storing custom rules.
"},{"location":"customization/enforce-codeowners/#binding-type","title":"Binding type","text":"Rules packaged within PSRule for Azure will automatically detect Policy Exemptions by their type properties. Standalone rules will get their type binding configuration from ps-rule.yaml
instead.
To configure type binding:
ps-rule.yaml
file within the root of the repository.# Configure binding options\nbinding:\n targetType:\n - 'resourceType'\n - 'type'\n
Some key points to call out include:
targetType
allows rules to use the -Type
parameter. Our custom rule uses -Type 'Microsoft.Authorization/policyExemptions'
.resourceType
property if it exists, alternative it will use type
. If neither property exists, PSRule will use the object type.To test the custom rule within Visual Studio Code, see How to install PSRule for Azure. Alternatively you can test the rule manually by running the following from a PowerShell terminal.
PowerShellAssert-PSRule -Path '.ps-rule/' -Module 'PSRule.Rules.Azure' `\n -InputPath . -Format File\n
"},{"location":"customization/enforce-codeowners/#sample-code","title":"Sample code","text":"Grab the full sample code for each of these files from:
With PSRule, you can layer on custom rules with to implement organization specific requirements. These custom rules work side-by-side with PSRule for Azure.
Use of resource and resource group tags is recommended in the WAF, however implementations may vary. You may want to use PSRule to enforce tagging or something similar early in a DevOps pipeline.
Abstract
The following scenario shows how to create a custom rule to validate Resource Group tags. The scenario walks you through the process so that you can apply the same concepts for similar requirements.
"},{"location":"customization/enforce-custom-tags/#creating-a-new-rule","title":"Creating a new rule","text":"Within the .ps-rule
sub-directory create a new file called Org.Azure.Rule.ps1
. Use the following snippet to populate the rule file:
# Synopsis: Resource Groups must have all mandatory tags defined.\nRule 'Org.Azure.RG.Tags' -Type 'Microsoft.Resources/resourceGroups' {\n $hasTags = $Assert.HasField($TargetObject, 'Tags')\n if (!$hasTags.Result) {\n return $hasTags\n }\n\n # <Code for custom tags goes here>\n}\n
Some key points to call out with the rule snippet include:
Org.Azure.RG.Tags
. Each rule name must be unique.Microsoft.Resources/resourceGroups
. i.e. Resource Groups.$Assert.HasField
ensures that Resource Group has a tags property.$TargetObject
automatically exposes the current resource being processed.Tip
For recommendations on naming and storing rules see storing custom rules.
"},{"location":"customization/enforce-custom-tags/#adding-mandatory-tags","title":"Adding mandatory tags","text":"To require specific tags to be configured on Resource Groups append this code to the rule.
# Require tags be case-sensitive\n$Assert.HasField($TargetObject.tags, 'costCentre', <# case-sensitive #> $True)\n$Assert.HasField($TargetObject.tags, 'env', $True)\n
Some key points to call out include:
$Assert.HasField
assertions are case-sensitive which differs from the previous snippet.The updated rule should look like:
# Synopsis: Resource Groups must have all mandatory tags defined.\nRule 'Org.Azure.RG.Tags' -Type 'Microsoft.Resources/resourceGroups' {\n $hasTags = $Assert.HasField($TargetObject, 'Tags')\n if (!$hasTags.Result) {\n return $hasTags\n }\n\n # Require tags be case-sensitive\n $Assert.HasField($TargetObject.tags, 'costCentre', <# case-sensitive #> $True)\n $Assert.HasField($TargetObject.tags, 'env', $True)\n}\n
"},{"location":"customization/enforce-custom-tags/#limiting-tags-values","title":"Limiting tags values","text":"To require these tags to only accept allowed values, append this code to the rule.
<#\nThe costCentre tag must:\n- Start with a letter.\n- Be followed by a number between 10000-9999999999.\n#>\n$Assert.Match($TargetObject, 'tags.costCentre', '^([A-Z][1-9][0-9]{4,9})$', $True)\n\n# Require specific values for environment tag\n$Assert.In($TargetObject, 'tags.env', @(\n 'dev',\n 'prod',\n 'uat'\n), $True)\n
Some key points to call out include:
tags.costCentre
.The completed rule should look like:
# Synopsis: Resource Groups must have all mandatory tags defined.\nRule 'Org.Azure.RG.Tags' -Type 'Microsoft.Resources/resourceGroups' {\n $hasTags = $Assert.HasField($TargetObject, 'Tags')\n if (!$hasTags.Result) {\n return $hasTags\n }\n\n # Require tags be case-sensitive.\n $Assert.HasField($TargetObject.tags, 'costCentre', <# case-sensitive #> $True)\n $Assert.HasField($TargetObject.tags, 'env', $True)\n\n <#\n The costCentre tag must:\n - Start with a letter.\n - Be followed by a number between 10000-9999999999.\n #>\n $Assert.Match($TargetObject, 'tags.costCentre', '^([A-Z][1-9][0-9]{4,9})$', $True)\n\n # Require specific values for environment tag.\n $Assert.In($TargetObject, 'tags.env', @(\n 'dev',\n 'prod',\n 'uat'\n ), $True)\n}\n
"},{"location":"customization/enforce-custom-tags/#binding-type","title":"Binding type","text":"Rules packaged within PSRule for Azure will automatically detect Resource Groups by their type properties. Standalone rules will get their type binding configuration from ps-rule.yaml
instead.
To configure type binding:
ps-rule.yaml
file within the root of the repository.# Configure binding options\nbinding:\n targetType:\n - 'resourceType'\n - 'type'\n
Some key points to call out include:
targetType
allows rules to use the -Type
parameter. Our custom rule uses -Type 'Microsoft.Resources/resourceGroups'
.resourceType
property if it exists, alternative it will use type
. If neither property exists, PSRule will use the object type.To test the custom rule within Visual Studio Code, see How to install PSRule for Azure. Alternatively you can test the rule manually by running the following from a PowerShell terminal.
Assert-PSRule -Path '.ps-rule/' -Module 'PSRule.Rules.Azure' -InputPath . -Format File\n
"},{"location":"customization/enforce-custom-tags/#sample-code","title":"Sample code","text":"Grab the full sample code for each of these files from:
As discussed in Azure.NSG.LateralTraversal, outbound management traffic is expected from some subnets. Subnets that are expected allow outbound management traffic may include:
As a result, you may want to suppress the Azure.NSG.LateralTraversal rule on NSGs for these special cases.
Abstract
This topic provides an example you can use to configure PSRule to ignore special case NSGs.
"},{"location":"customization/permit-outbound-management/#create-a-suppression-group","title":"Create a suppression group","text":"Within the .ps-rule
sub-directory create a file called Org.Azure.Suppressions.Rule.yaml
. If the .ps-rule
sub-directory does not exist, create it in the root of your repository.
Use the following snippet to populate the suppression group:
---\n# Synopsis: Ignore NSG lateral movement for management subnet NSGs such as Azure Bastion.\napiVersion: github.com/microsoft/PSRule/v1\nkind: SuppressionGroup\nmetadata:\n name: Org.Azure.PermitOutboundManagement\nspec:\n rule:\n - PSRule.Rules.Azure\\Azure.NSG.LateralTraversal\n if:\n allOf:\n - type: '.'\n in:\n - Microsoft.Network/networkSecurityGroups\n\n # Suppress NSGs with bastion or management in thier name\n - name: '.'\n contains:\n - bastion\n - management\n
Some key points to call out with the suppression group snippet include:
Org.Azure.PermitOutboundManagement
. Each resource name must be unique.PSRule.Rules.Azure\\Azure.NSG.LateralTraversal
.Microsoft.Network/networkSecurityGroups
.bastion
or management
. The suppression group uses expressions to determine when a resource is suppressed. Update this condition to match your environment. For example, the following NSGs would be suppressed by this suppression group:nsg-bastion-prod-eus-001
nsg-hub-management-prod-001
Tip
Expressions can be combined within a suppression group using allOf
or anyOf
operators.
PSRule for Azure covers common use cases that align to the Microsoft Azure Well-Architected Framework (WAF). In addition to WAF alignment you may have a requirement to enforce organization specific rules.
For example:
PSRule allows custom rules to be layered on. These custom rules work side-by-side with PSRule for Azure.
"},{"location":"customization/storing-custom-rules/#using-a-standard-file-path","title":"Using a standard file path","text":"Rules can be standalone or packaged within a module. Standalone rules are ideal for a single project such as an Infrastructure as Code (IaC) repository. To reuse rules across multiple projects consider packaging these as a module.
The instructions for packaging rules in a module can be found here:
To store standalone rules we recommend that you:
.ps-rule
in the root of your repository. Use all lower-case in the sub-directory name. Put any custom rules within this sub-directory..Rule.ps1
.Note
Build pipelines are often case-sensitive or run on Linux-based systems. Using the casing rule above reduces confusion latter when you configure continuous integration (CI).
"},{"location":"customization/storing-custom-rules/#naming-rules","title":"Naming rules","text":"When running PSRule, rule names must be unique. PSRule for Azure uses the name prefix of Azure.
on all rules and resources included in the module.
Example
The following names are examples of rules included within PSRule for Azure:
Azure.AKS.Version
Azure.AKS.AuthorizedIPs
Azure.SQL.MinTLS
When naming custom rules we recommend that you:
Local.
or Org.
prefix for standalone rules.Invoke-PSRule
truncates longer names. PSRule supports longer rule names however if Invoke-PSRule
is called directly consider using Format-List
.Microsoft cloud security benchmark (MCSB) is a set of controls and recommendations that help improve the security of workloads on Azure and your multi-cloud environment. Controls from the MCSB are also mapped to industry frameworks, such as CIS, PCI-DSS, and NIST.
If you are new to MCSB or are looking for guidance on how to use it, please see the Introduction to the Microsoft cloud security benchmark.
"},{"location":"en/mcsb-v1/#microsoft-cloud-security-benchmark-v1","title":"Microsoft cloud security benchmark v1","text":"Is the latest version of the MCSB. Rules included within PSRule for Azure have been mapped to v1 so that you are able to understand the impact of the rules. This is particularly useful when you are looking to understand how to address a compliance requirement specific to your organization.
The following controls are included in the Microsoft cloud security benchmark v1:
Governance and Strategy (GS)
Experimental \u00b7 v1.25.0
To start using the MCSB v1 baseline with PSRule, configure the baseline parameter to use Azure.MCSB.v1
. View the list of rules associated with the MCSB v1 baseline.
Experimental - Learn more
MCSB baselines are a work in progress and subject to change. We hope to add more rules to the baseline in the future. Join or start a discussion to let us know how we can improve this feature going forward.
Note
It's important to note that the MCSB v1 baseline is subset of rules from the Well-Architected Framework. Not all rules for the Well-Architected Framework are included in MCSB. Using the MCSB v1 baseline is useful to understand alignment with the MCSB and other industry frameworks / standards. For a complete set of rules for the Well-Architected Framework, consider using a quarterly baseline.
"},{"location":"en/mcsb-v1/#recommended-content","title":"Recommended content","text":"Includes all Azure rules.
"},{"location":"en/baselines/Azure.All/#rules","title":"Rules","text":"The following rules are included within the Azure.All
baseline.
This baseline includes a total of 411 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.AnonymousAccess Disable anonymous pull access. Important Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.MinUserPoolNodes User node pools in an AKS cluster should have a minimum number of nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. Critical Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. Important Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppGwWAF.RuleGroups Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.NETVersion Configure applications to use newer .NET versions. Important Azure.AppService.PHPVersion Configure applications to use newer PHP runtime versions. Important Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Important Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Important Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. Important Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. Important Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.Databricks.PublicAccess Azure Databricks workspaces should disable public network access. Critical Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. Critical Azure.Databricks.SKU Ensure Databricks workspaces are non-trial SKUs for production workloads. Critical Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.Defender.Api Enable Microsoft Defender for APIs. Critical Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. Critical Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Azure.DevBox.ProjectLimit Limit the number of Dev Boxes a single user can create for a project. Important Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. Important Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. Critical Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). Critical Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. Critical Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. Critical Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. Important Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Important Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.Default/","title":"Azure.Default","text":"Default baseline for Azure rules.
"},{"location":"en/baselines/Azure.Default/#rules","title":"Rules","text":"The following rules are included within the Azure.Default
baseline.
This baseline includes a total of 402 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.MinUserPoolNodes User node pools in an AKS cluster should have a minimum number of nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. Critical Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. Important Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppGwWAF.RuleGroups Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.NETVersion Configure applications to use newer .NET versions. Important Azure.AppService.PHPVersion Configure applications to use newer PHP runtime versions. Important Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. Important Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. Important Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.Databricks.PublicAccess Azure Databricks workspaces should disable public network access. Critical Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. Critical Azure.Databricks.SKU Ensure Databricks workspaces are non-trial SKUs for production workloads. Critical Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.Defender.Api Enable Microsoft Defender for APIs. Critical Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. Critical Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Azure.DevBox.ProjectLimit Limit the number of Dev Boxes a single user can create for a project. Important Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. Important Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. Critical Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). Critical Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. Critical Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. Critical Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. Important Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.GA_2020_06/","title":"Azure.GA_2020_06","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released June 2020 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2020_06/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2020_06
baseline.
This baseline includes a total of 136 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important"},{"location":"en/baselines/Azure.GA_2020_09/","title":"Azure.GA_2020_09","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released September 2020 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2020_09/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2020_09
baseline.
This baseline includes a total of 152 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important"},{"location":"en/baselines/Azure.GA_2020_12/","title":"Azure.GA_2020_12","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released December 2020 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2020_12/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2020_12
baseline.
This baseline includes a total of 174 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important"},{"location":"en/baselines/Azure.GA_2021_03/","title":"Azure.GA_2021_03","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released March 2021 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2021_03/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2021_03
baseline.
This baseline includes a total of 189 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important"},{"location":"en/baselines/Azure.GA_2021_06/","title":"Azure.GA_2021_06","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released June 2021 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2021_06/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2021_06
baseline.
This baseline includes a total of 203 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important"},{"location":"en/baselines/Azure.GA_2021_09/","title":"Azure.GA_2021_09","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released September 2021 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2021_09/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2021_09
baseline.
This baseline includes a total of 222 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important"},{"location":"en/baselines/Azure.GA_2021_12/","title":"Azure.GA_2021_12","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released December 2021 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2021_12/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2021_12
baseline.
This baseline includes a total of 248 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness"},{"location":"en/baselines/Azure.GA_2022_03/","title":"Azure.GA_2022_03","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released March 2022 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2022_03/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2022_03
baseline.
This baseline includes a total of 264 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.GA_2022_06/","title":"Azure.GA_2022_06","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released June 2022 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2022_06/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2022_06
baseline.
This baseline includes a total of 268 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.GA_2022_09/","title":"Azure.GA_2022_09","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released September 2022 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2022_09/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2022_09
baseline.
This baseline includes a total of 299 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.GA_2022_12/","title":"Azure.GA_2022_12","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released December 2022 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2022_12/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2022_12
baseline.
This baseline includes a total of 337 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.GA_2023_03/","title":"Azure.GA_2023_03","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released March 2023 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2023_03/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2023_03
baseline.
This baseline includes a total of 357 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.GA_2023_06/","title":"Azure.GA_2023_06","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released June 2023 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2023_06/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2023_06
baseline.
This baseline includes a total of 372 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.GA_2023_09/","title":"Azure.GA_2023_09","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released September 2023 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2023_09/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2023_09
baseline.
This baseline includes a total of 383 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. Important Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. Important Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. Critical Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.GA_2023_12/","title":"Azure.GA_2023_12","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released December 2023 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2023_12/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2023_12
baseline.
This baseline includes a total of 392 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. Critical Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. Important Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. Important Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. Important Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. Critical Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.Defender.Api Enable Microsoft Defender for APIs. Critical Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. Critical Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. Critical Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). Critical Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. Critical Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. Critical Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. Important Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.GA_2024_03/","title":"Azure.GA_2024_03","text":"Include rules released March 2024 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2024_03/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2024_03
baseline.
This baseline includes a total of 402 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.MinUserPoolNodes User node pools in an AKS cluster should have a minimum number of nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. Critical Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. Important Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppGwWAF.RuleGroups Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.NETVersion Configure applications to use newer .NET versions. Important Azure.AppService.PHPVersion Configure applications to use newer PHP runtime versions. Important Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. Important Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. Important Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.Databricks.PublicAccess Azure Databricks workspaces should disable public network access. Critical Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. Critical Azure.Databricks.SKU Ensure Databricks workspaces are non-trial SKUs for production workloads. Critical Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.Defender.Api Enable Microsoft Defender for APIs. Critical Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. Critical Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Azure.DevBox.ProjectLimit Limit the number of Dev Boxes a single user can create for a project. Important Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. Important Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. Critical Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). Critical Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. Critical Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. Critical Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. Important Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.MCSB.v1/","title":"Azure.MCSB.v1","text":"Experimental
This baseline is experimental and subject to change.
Microsoft Cloud Security Benchmark v1.
"},{"location":"en/baselines/Azure.MCSB.v1/#controls","title":"Controls","text":"The following rules are included within the Azure.MCSB.v1
baseline.
This baseline includes a total of 131 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. Critical Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.Defender.Api Enable Microsoft Defender for APIs. Critical Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. Important Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). Critical Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. Critical Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. Important Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important"},{"location":"en/baselines/Azure.Pillar.CostOptimization/","title":"Azure.Pillar.CostOptimization","text":"v1.35.0
Microsoft Azure Well-Architected Framework - Cost Optimization pillar specific baseline.
"},{"location":"en/baselines/Azure.Pillar.CostOptimization/#rules","title":"Rules","text":"The following rules are included within the Azure.Pillar.CostOptimization
baseline.
This baseline includes a total of 14 rules.
Name Synopsis Severity Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.DevBox.ProjectLimit Limit the number of Dev Boxes a single user can create for a project. Important Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness"},{"location":"en/baselines/Azure.Pillar.OperationalExcellence/","title":"Azure.Pillar.OperationalExcellence","text":"v1.35.0
Microsoft Azure Well-Architected Framework - Operational Excellence pillar specific baseline.
"},{"location":"en/baselines/Azure.Pillar.OperationalExcellence/#rules","title":"Rules","text":"The following rules are included within the Azure.Pillar.OperationalExcellence
baseline.
This baseline includes a total of 109 rules.
Name Synopsis Severity Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. Important Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness"},{"location":"en/baselines/Azure.Pillar.PerformanceEfficiency/","title":"Azure.Pillar.PerformanceEfficiency","text":"v1.35.0
Microsoft Azure Well-Architected Framework - Performance Efficiency pillar specific baseline.
"},{"location":"en/baselines/Azure.Pillar.PerformanceEfficiency/#rules","title":"Rules","text":"The following rules are included within the Azure.Pillar.PerformanceEfficiency
baseline.
This baseline includes a total of 18 rules.
Name Synopsis Severity Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. Important Azure.Databricks.SKU Ensure Databricks workspaces are non-trial SKUs for production workloads. Critical Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important"},{"location":"en/baselines/Azure.Pillar.Reliability/","title":"Azure.Pillar.Reliability","text":"v1.35.0
Microsoft Azure Well-Architected Framework - Reliability pillar specific baseline.
"},{"location":"en/baselines/Azure.Pillar.Reliability/#rules","title":"Rules","text":"The following rules are included within the Azure.Pillar.Reliability
baseline.
This baseline includes a total of 61 rules.
Name Synopsis Severity Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.MinUserPoolNodes User node pools in an AKS cluster should have a minimum number of nodes for failover and updates. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. Important Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.Pillar.Security/","title":"Azure.Pillar.Security","text":"v1.35.0
Microsoft Azure Well-Architected Framework - Security pillar specific baseline.
"},{"location":"en/baselines/Azure.Pillar.Security/#rules","title":"Rules","text":"The following rules are included within the Azure.Pillar.Security
baseline.
This baseline includes a total of 200 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. Critical Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppGwWAF.RuleGroups Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.NETVersion Configure applications to use newer .NET versions. Important Azure.AppService.PHPVersion Configure applications to use newer PHP runtime versions. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.Databricks.PublicAccess Azure Databricks workspaces should disable public network access. Critical Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. Critical Azure.Defender.Api Enable Microsoft Defender for APIs. Critical Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. Critical Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. Important Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). Critical Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. Critical Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. Critical Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. Important Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important"},{"location":"en/baselines/Azure.Preview/","title":"Azure.Preview","text":"Includes rules for Azure GA and preview features.
"},{"location":"en/baselines/Azure.Preview/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview
baseline.
This baseline includes a total of 411 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.AnonymousAccess Disable anonymous pull access. Important Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.MinUserPoolNodes User node pools in an AKS cluster should have a minimum number of nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. Critical Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. Important Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppGwWAF.RuleGroups Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.NETVersion Configure applications to use newer .NET versions. Important Azure.AppService.PHPVersion Configure applications to use newer PHP runtime versions. Important Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Important Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Important Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. Important Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. Important Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.Databricks.PublicAccess Azure Databricks workspaces should disable public network access. Critical Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. Critical Azure.Databricks.SKU Ensure Databricks workspaces are non-trial SKUs for production workloads. Critical Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.Defender.Api Enable Microsoft Defender for APIs. Critical Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. Critical Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Azure.DevBox.ProjectLimit Limit the number of Dev Boxes a single user can create for a project. Important Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. Important Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. Critical Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). Critical Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. Critical Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. Critical Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. Important Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Important Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.Preview_2021_09/","title":"Azure.Preview_2021_09","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released September 2021 or prior for Azure preview only features.
"},{"location":"en/baselines/Azure.Preview_2021_09/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview_2021_09
baseline.
This baseline includes a total of 2 rules.
Name Synopsis Severity Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important"},{"location":"en/baselines/Azure.Preview_2021_12/","title":"Azure.Preview_2021_12","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released December 2021 or prior for Azure preview only features.
"},{"location":"en/baselines/Azure.Preview_2021_12/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview_2021_12
baseline.
This baseline includes a total of 2 rules.
Name Synopsis Severity Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important"},{"location":"en/baselines/Azure.Preview_2022_03/","title":"Azure.Preview_2022_03","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released March 2022 or prior for Azure preview only features.
"},{"location":"en/baselines/Azure.Preview_2022_03/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview_2022_03
baseline.
This baseline includes a total of 2 rules.
Name Synopsis Severity Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important"},{"location":"en/baselines/Azure.Preview_2022_06/","title":"Azure.Preview_2022_06","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released June 2022 or prior for Azure preview only features.
"},{"location":"en/baselines/Azure.Preview_2022_06/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview_2022_06
baseline.
This baseline includes a total of 2 rules.
Name Synopsis Severity Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important"},{"location":"en/baselines/Azure.Preview_2022_09/","title":"Azure.Preview_2022_09","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released September 2022 or prior for Azure preview only features.
"},{"location":"en/baselines/Azure.Preview_2022_09/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview_2022_09
baseline.
This baseline includes a total of 3 rules.
Name Synopsis Severity Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important"},{"location":"en/baselines/Azure.Preview_2022_12/","title":"Azure.Preview_2022_12","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released December 2022 or prior for Azure preview only features.
"},{"location":"en/baselines/Azure.Preview_2022_12/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview_2022_12
baseline.
This baseline includes a total of 3 rules.
Name Synopsis Severity Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important"},{"location":"en/baselines/Azure.Preview_2023_03/","title":"Azure.Preview_2023_03","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released March 2023 or prior for Azure preview only features.
"},{"location":"en/baselines/Azure.Preview_2023_03/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview_2023_03
baseline.
This baseline includes a total of 3 rules.
Name Synopsis Severity Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important"},{"location":"en/baselines/Azure.Preview_2023_06/","title":"Azure.Preview_2023_06","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released June 2023 or prior for Azure preview only features.
"},{"location":"en/baselines/Azure.Preview_2023_06/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview_2023_06
baseline.
This baseline includes a total of 8 rules.
Name Synopsis Severity Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Important Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Important Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Important"},{"location":"en/baselines/Azure.Preview_2023_09/","title":"Azure.Preview_2023_09","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released September 2023 or prior for Azure preview only features.
"},{"location":"en/baselines/Azure.Preview_2023_09/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview_2023_09
baseline.
This baseline includes a total of 9 rules.
Name Synopsis Severity Azure.ACR.AnonymousAccess Disable anonymous pull access. Important Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Important Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Important Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Important"},{"location":"en/baselines/Azure.Preview_2023_12/","title":"Azure.Preview_2023_12","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released December 2023 or prior for Azure preview only features.
"},{"location":"en/baselines/Azure.Preview_2023_12/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview_2023_12
baseline.
This baseline includes a total of 9 rules.
Name Synopsis Severity Azure.ACR.AnonymousAccess Disable anonymous pull access. Important Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Important Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Important Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Important"},{"location":"en/baselines/Azure.Preview_2024_03/","title":"Azure.Preview_2024_03","text":"Include rules released March 2024 or prior for Azure preview only features.
"},{"location":"en/baselines/Azure.Preview_2024_03/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview_2024_03
baseline.
This baseline includes a total of 9 rules.
Name Synopsis Severity Azure.ACR.AnonymousAccess Disable anonymous pull access. Important Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Important Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Important Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Important"},{"location":"en/rules/","title":"Reference","text":"The following rules and features are included in PSRule for Azure.
Info
The rule release indicates if the Azure feature is generally available (GA) or available under preview. Features provided under previews may have additional limits, availability restrictions, or terms. By default, PSRule for Azure will not provide recommendations that relate to preview features. To include rules for preview features see working with baselines.
"},{"location":"en/rules/#rules","title":"Rules","text":"The following rules are included in PSRule for Azure.
Reference Name Synopsis Release AZR-000001 Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. GA AZR-000002 Azure.ACR.ContainerScan Enable vulnerability scanning for container images. GA AZR-000003 Azure.ACR.ImageHealth Remove container images with known vulnerabilities. GA AZR-000004 Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. GA AZR-000005 Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. GA AZR-000006 Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. GA AZR-000007 Azure.ACR.Name Container registry names should meet naming requirements. GA AZR-000008 Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Preview AZR-000009 Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. GA AZR-000010 Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Preview AZR-000011 Azure.ADX.Usage Regularly remove unused resources to reduce costs. GA AZR-000012 Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. GA AZR-000013 Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. GA AZR-000014 Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. GA AZR-000015 Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. GA AZR-000016 Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. GA AZR-000017 Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. GA AZR-000018 Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. GA AZR-000019 Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. GA AZR-000020 Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. GA AZR-000021 Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. GA AZR-000022 Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. GA AZR-000023 Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. GA AZR-000024 Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. GA AZR-000025 Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. GA AZR-000026 Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. GA AZR-000027 Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. GA AZR-000028 Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. GA AZR-000029 Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. GA AZR-000030 Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. GA AZR-000031 Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. GA AZR-000032 Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. GA AZR-000033 Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. GA AZR-000034 Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. GA AZR-000035 Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. GA AZR-000036 Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. GA AZR-000038 Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. GA AZR-000039 Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. GA AZR-000040 Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. GA AZR-000041 Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. GA AZR-000042 Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. GA AZR-000043 Azure.APIM.APIDescriptors API Management APIs should have a display name and description. GA AZR-000044 Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. GA AZR-000045 Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. GA AZR-000046 Azure.APIM.ProductSubscription Configure products to require a subscription. GA AZR-000047 Azure.APIM.ProductApproval Configure products to require approval. GA AZR-000048 Azure.APIM.SampleProducts Remove starter and unlimited sample products. GA AZR-000049 Azure.APIM.ProductDescriptors API Management products should have a display name and description. GA AZR-000050 Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. GA AZR-000051 Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. GA AZR-000052 Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. GA AZR-000053 Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. GA AZR-000054 Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. GA AZR-000055 Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. GA AZR-000056 Azure.APIM.Name API Management service names should meet naming requirements. GA AZR-000057 Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. GA AZR-000058 Azure.AppConfig.Name App Configuration store names should meet naming requirements. GA AZR-000059 Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. GA AZR-000060 Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. GA AZR-000061 Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. GA AZR-000062 Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. GA AZR-000063 Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. GA AZR-000064 Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. GA AZR-000065 Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. GA AZR-000066 Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. GA AZR-000067 Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. GA AZR-000068 Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. GA AZR-000069 Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. GA AZR-000070 Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. GA AZR-000071 Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. GA AZR-000072 Azure.AppService.MinPlan Use at least a Standard App Service Plan. GA AZR-000073 Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. GA AZR-000074 Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. GA AZR-000075 Azure.AppService.NETVersion Configure applications to use newer .NET versions. GA AZR-000076 Azure.AppService.PHPVersion Configure applications to use newer PHP runtime versions. GA AZR-000077 Azure.AppService.AlwaysOn Configure Always On for App Service apps. GA AZR-000078 Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. GA AZR-000079 Azure.AppService.WebProbe Configure and enable instance health probes. GA AZR-000080 Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. GA AZR-000081 Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. GA AZR-000082 Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. GA AZR-000083 Azure.AppService.ARRAffinity Disable client affinity for stateless services. GA AZR-000084 Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. GA AZR-000085 Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. GA AZR-000086 Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. GA AZR-000087 Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). GA AZR-000088 Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. GA AZR-000089 Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. GA AZR-000090 Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. GA AZR-000091 Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. GA AZR-000092 Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. GA AZR-000093 Azure.CDN.HTTP Enforce HTTPS for client connections. GA AZR-000094 Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. GA AZR-000095 Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. GA AZR-000096 Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. GA AZR-000097 Azure.DataFactory.Version Consider migrating to DataFactory v2. GA AZR-000098 Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. GA AZR-000099 Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. GA AZR-000100 Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. GA AZR-000101 Azure.EventHub.Usage Regularly remove unused resources to reduce costs. GA AZR-000102 Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. GA AZR-000103 Azure.Firewall.Name Firewall names should meet naming requirements. GA AZR-000104 Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. GA AZR-000105 Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. GA AZR-000106 Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. GA AZR-000107 Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. GA AZR-000108 Azure.FrontDoor.Probe Use health probes to check the health of each backend. GA AZR-000109 Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. GA AZR-000110 Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. GA AZR-000111 Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. GA AZR-000112 Azure.FrontDoor.State Enable Azure Front Door Classic instance. GA AZR-000113 Azure.FrontDoor.Name Front Door names should meet naming requirements. GA AZR-000114 Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. GA AZR-000115 Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. GA AZR-000116 Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. GA AZR-000117 Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. GA AZR-000118 Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. GA AZR-000119 Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. GA AZR-000120 Azure.KeyVault.Name Key Vault names should meet naming requirements. GA AZR-000121 Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. GA AZR-000122 Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. GA AZR-000123 Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. GA AZR-000124 Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. GA AZR-000125 Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. GA AZR-000126 Azure.LB.Probe Use a specific probe for web protocols. GA AZR-000127 Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. GA AZR-000128 Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. GA AZR-000129 Azure.LB.Name Load Balancer names should meet naming requirements. GA AZR-000130 Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. GA AZR-000131 Azure.MySQL.UseSSL Enforce encrypted MySQL connections. GA AZR-000132 Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. GA AZR-000133 Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. GA AZR-000134 Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. GA AZR-000135 Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. GA AZR-000136 Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. GA AZR-000137 Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. GA AZR-000138 Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. GA AZR-000139 Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. GA AZR-000140 Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. GA AZR-000141 Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. GA AZR-000142 Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. GA AZR-000143 Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. GA AZR-000144 Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. GA AZR-000145 Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. GA AZR-000146 Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. GA AZR-000147 Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. GA AZR-000148 Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. GA AZR-000149 Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. GA AZR-000150 Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. GA AZR-000151 Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. GA AZR-000152 Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. GA AZR-000153 Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. GA AZR-000154 Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. GA AZR-000155 Azure.PublicIP.Name Public IP names should meet naming requirements. GA AZR-000156 Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. GA AZR-000157 Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. GA AZR-000158 Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. GA AZR-000159 Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. GA AZR-000160 Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. GA AZR-000161 Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. GA AZR-000162 Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. GA AZR-000163 Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. GA AZR-000164 Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. GA AZR-000165 Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. GA AZR-000166 Azure.Resource.UseTags Azure resources should be tagged using a standard convention. GA AZR-000167 Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. GA AZR-000168 Azure.ResourceGroup.Name Resource Group names should meet naming requirements. GA AZR-000169 Azure.Route.Name Route table names should meet naming requirements. GA AZR-000170 Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. GA AZR-000171 Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. GA AZR-000172 Azure.Search.SKU Use the basic and standard tiers for entry level workloads. GA AZR-000173 Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. GA AZR-000174 Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. GA AZR-000175 Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. GA AZR-000176 Azure.Search.Name AI Search service names should meet naming requirements. GA AZR-000177 Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. GA AZR-000178 Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. GA AZR-000179 Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. GA AZR-000180 Azure.SignalR.Name SignalR service instance names should meet naming requirements. GA AZR-000181 Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. GA AZR-000182 Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. GA AZR-000183 Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. GA AZR-000184 Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. GA AZR-000185 Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). GA AZR-000186 Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. GA AZR-000187 Azure.SQL.Auditing Enable auditing for Azure SQL logical server. GA AZR-000188 Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. GA AZR-000189 Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. GA AZR-000190 Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. GA AZR-000191 Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. GA AZR-000192 Azure.SQL.DBName Azure SQL Database names should meet naming requirements. GA AZR-000193 Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. GA AZR-000194 Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. GA AZR-000195 Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. GA AZR-000196 Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. GA AZR-000197 Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. GA AZR-000198 Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. GA AZR-000199 Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. GA AZR-000200 Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. GA AZR-000201 Azure.Storage.Name Storage Account names should meet naming requirements. GA AZR-000202 Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. GA AZR-000203 Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. GA AZR-000204 Azure.RBAC.LimitOwner Limit the number of subscription Owners. GA AZR-000205 Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. GA AZR-000206 Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). GA AZR-000207 Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. GA AZR-000208 Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. GA AZR-000209 Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. GA AZR-000210 Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. GA AZR-000211 Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. GA AZR-000212 Azure.Template.TemplateFile Use ARM template files that are valid. GA AZR-000213 Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. GA AZR-000214 Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. GA AZR-000215 Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. GA AZR-000216 Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. GA AZR-000217 Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. GA AZR-000218 Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. GA AZR-000219 Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. GA AZR-000220 Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. GA AZR-000221 Azure.Template.LocationType Location parameters should use a string value. GA AZR-000222 Azure.Template.ResourceLocation Template resource location should be an expression or global. GA AZR-000223 Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. GA AZR-000224 Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. GA AZR-000225 Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. GA AZR-000226 Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. GA AZR-000227 Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. GA AZR-000228 Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. GA AZR-000229 Azure.Template.ParameterFile Use ARM template parameter files that are valid. GA AZR-000230 Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. GA AZR-000231 Azure.Template.MetadataLink Configure a metadata link for each parameter file. GA AZR-000232 Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. GA AZR-000233 Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. GA AZR-000234 Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. GA AZR-000235 Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. GA AZR-000236 Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. GA AZR-000237 Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. GA AZR-000238 Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. GA AZR-000239 Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. GA AZR-000240 Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. GA AZR-000241 Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. GA AZR-000242 Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. GA AZR-000243 Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. GA AZR-000244 Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. GA AZR-000245 Azure.VM.PublicKey Linux virtual machines should use public keys. GA AZR-000246 Azure.VM.Agent Ensure the VM agent is provisioned automatically. GA AZR-000247 Azure.VM.Updates Ensure automatic updates are enabled at deployment. GA AZR-000248 Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. GA AZR-000249 Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. GA AZR-000250 Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. GA AZR-000251 Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. GA AZR-000252 Azure.VM.ADE Use Azure Disk Encryption (ADE). GA AZR-000253 Azure.VM.DiskName Managed Disk names should meet naming requirements. GA AZR-000254 Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. GA AZR-000255 Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). GA AZR-000256 Azure.VM.ASName Availability Set names should meet naming requirements. GA AZR-000257 Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. GA AZR-000258 Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. GA AZR-000259 Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. GA AZR-000260 Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. GA AZR-000261 Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. GA AZR-000262 Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. GA AZR-000263 Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. GA AZR-000264 Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. GA AZR-000265 Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. GA AZR-000266 Azure.VNET.PeerState VNET peering connections must be connected. GA AZR-000267 Azure.VNET.SubnetName Subnet names should meet naming requirements. GA AZR-000268 Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. GA AZR-000269 Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. GA AZR-000270 Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. GA AZR-000271 Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. GA AZR-000272 Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. GA AZR-000273 Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. GA AZR-000274 Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. GA AZR-000275 Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. GA AZR-000276 Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. GA AZR-000277 Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. GA AZR-000278 Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. GA AZR-000279 Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. GA AZR-000280 Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. GA AZR-000281 Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. GA AZR-000282 Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. GA AZR-000283 Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. GA AZR-000284 Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. GA AZR-000285 Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. GA AZR-000286 Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. GA AZR-000287 Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. GA AZR-000288 Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. GA AZR-000289 Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. GA AZR-000290 Azure.Defender.Containers Enable Microsoft Defender for Containers. GA AZR-000291 Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. GA AZR-000292 Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. GA AZR-000293 Azure.Defender.Servers Enable Microsoft Defender for Servers. GA AZR-000294 Azure.Defender.SQL Enable Microsoft Defender for SQL servers. GA AZR-000295 Azure.Defender.AppServices Enable Microsoft Defender for App Service. GA AZR-000296 Azure.Defender.Storage Enable Microsoft Defender for Storage. GA AZR-000297 Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. GA AZR-000298 Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. GA AZR-000299 Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. GA AZR-000300 Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. GA AZR-000301 Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. GA AZR-000302 Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. GA AZR-000303 Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. GA AZR-000304 Azure.AppGwWAF.RuleGroups Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. GA AZR-000305 Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. GA AZR-000306 Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. GA AZR-000307 Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. GA AZR-000308 Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. GA AZR-000309 Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. GA AZR-000310 Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Preview AZR-000311 Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. GA AZR-000312 Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. GA AZR-000313 Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. GA AZR-000314 Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. GA AZR-000315 Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. GA AZR-000316 Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. GA AZR-000317 Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. GA AZR-000318 Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. GA AZR-000319 Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. GA AZR-000320 Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. GA AZR-000321 Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. GA AZR-000322 Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. GA AZR-000323 Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. GA AZR-000324 Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. GA AZR-000325 Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. GA AZR-000326 Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. GA AZR-000327 Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. GA AZR-000328 Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. GA AZR-000329 Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. GA AZR-000330 Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. GA AZR-000331 Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. GA AZR-000332 Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. GA AZR-000333 Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. GA AZR-000334 Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. GA AZR-000335 Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. GA AZR-000336 Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. GA AZR-000337 Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. GA AZR-000338 Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. GA AZR-000339 Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. GA AZR-000340 Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. GA AZR-000341 Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. GA AZR-000342 Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. GA AZR-000343 Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. GA AZR-000344 Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. GA AZR-000345 Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. GA AZR-000346 Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. GA AZR-000347 Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. GA AZR-000348 Azure.AppGw.Name Application Gateways should meet naming requirements. GA AZR-000349 Azure.Bastion.Name Bastion hosts should meet naming requirements. GA AZR-000350 Azure.RSV.Name Recovery Services vaults should meet naming requirements. GA AZR-000351 Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. GA AZR-000352 Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. GA AZR-000353 Azure.Defender.Dns Enable Microsoft Defender for DNS. GA AZR-000354 Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). GA AZR-000355 Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. GA AZR-000356 Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. GA AZR-000357 Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. GA AZR-000358 Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. GA AZR-000359 Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. GA AZR-000360 Azure.ContainerApp.Name Container Apps should meet naming requirements. GA AZR-000361 Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. GA AZR-000362 Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. GA AZR-000363 Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. GA AZR-000364 Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. GA AZR-000365 Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. GA AZR-000366 Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. GA AZR-000367 Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. GA AZR-000368 Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. GA AZR-000369 Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. GA AZR-000370 Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. GA AZR-000371 Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. GA AZR-000372 Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. GA AZR-000373 Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Preview AZR-000374 Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Preview AZR-000375 Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Preview AZR-000376 Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. GA AZR-000377 Azure.Defender.Api Enable Microsoft Defender for APIs. GA AZR-000378 Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. GA AZR-000379 Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. GA AZR-000380 Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. GA AZR-000381 Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. GA AZR-000382 Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. GA AZR-000383 Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. GA AZR-000384 Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. GA AZR-000385 Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Preview AZR-000386 Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. GA AZR-000387 Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. GA AZR-000388 Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. GA AZR-000389 Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. GA AZR-000390 Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. GA AZR-000391 Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Preview AZR-000392 Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. GA AZR-000393 Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. GA AZR-000394 Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. GA AZR-000395 Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. GA AZR-000396 Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. GA AZR-000397 Azure.RSV.Immutable Ensure immutability is configured to protect backup data. GA AZR-000398 Azure.BV.Immutable Ensure immutability is configured to protect backup data. GA AZR-000399 Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. GA AZR-000400 Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. GA AZR-000401 Azure.ACR.AnonymousAccess Disable anonymous pull access. Preview AZR-000402 Azure.ACR.Firewall Limit network access of container registries to only trusted clients. GA AZR-000403 Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. GA AZR-000404 Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. GA AZR-000405 Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). GA AZR-000406 Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. GA AZR-000407 Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. GA AZR-000408 Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. GA AZR-000409 Azure.Databricks.SKU Ensure Databricks workspaces are non-trial SKUs for production workloads. GA AZR-000410 Azure.Databricks.PublicAccess Azure Databricks workspaces should disable public network access. GA AZR-000411 Azure.DevBox.ProjectLimit Limit the number of Dev Boxes a single user can create for a project. GA AZR-000412 Azure.AKS.MinUserPoolNodes User node pools in an AKS cluster should have a minimum number of nodes for failover and updates. GA"},{"location":"en/rules/Azure.ACR.AdminUser/","title":"Disable ACR admin user","text":"Azure.ACR.AdminUserAZR-000005ErrorSecurity \u00b7 Container Registry \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Use Entra ID identities instead of using the registry admin user.
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"en/rules/Azure.ACR.AdminUser/#description","title":"Description","text":"Azure Container Registry (ACR) includes a built-in local admin user account. The admin user account is a single user account with administrative access to the registry. This account provides single user access for early test and development. The admin user account is not intended for use with production container registries.
Instead of using the admin user account, consider using Entra ID (previously Azure AD) identities. Entra ID provides a centralized identity and authentication system for Azure. This provides a number of benefits including:
Consider disabling the admin user account and only use identity-based authentication for registry operations.
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"en/rules/Azure.ACR.AdminUser/#examples","title":"Examples","text":"","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"en/rules/Azure.ACR.AdminUser/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy registries that pass this rule:
properties.adminUserEnabled
to false
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2023-07-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"days\": 30,\n \"status\": \"enabled\"\n }\n }\n }\n}\n
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"en/rules/Azure.ACR.AdminUser/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy registries that pass this rule:
properties.adminUserEnabled
to false
.For example:
Azure Bicep snippetresource registry 'Microsoft.ContainerRegistry/registries@2023-07-01' = {\n name: name\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n days: 30\n status: 'enabled'\n }\n }\n }\n}\n
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"en/rules/Azure.ACR.AdminUser/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To configure registries that pass this rule:
Azure CLI snippetaz acr update -n '<name>' -g '<resource_group>' --admin-enabled false\n
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"en/rules/Azure.ACR.AdminUser/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To configure registries that pass this rule:
Azure PowerShell snippetUpdate-AzContainerRegistry -ResourceGroupName '<resource_group>' -Name '<name>' -DisableAdminUser\n
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"en/rules/Azure.ACR.AdminUser/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/dc921057-6b28-4fbe-9b83-f7bec05db6c2
./providers/Microsoft.Authorization/policyDefinitions/79fdfe03-ffcb-4e55-b4d0-b925b8241759
.Security \u00b7 Container Registry \u00b7 Rule \u00b7 Preview \u00b7 2023_09 \u00b7 Important
Disable anonymous pull access.
","tags":["Azure.ACR.AnonymousAccess","AZR-000401"]},{"location":"en/rules/Azure.ACR.AnonymousAccess/#description","title":"Description","text":"Azure Container Registry (ACR) allows you to pull or push content from an Azure container registry by being authenticated. However, it is possible to pull content from an Azure container registry by being unauthenticated (anonymous pull access).
By default, access to pull or push content from an Azure container registry is only available to authenticated users.
Generally speaking it is not a good practice to allow data-plane operations to unauthenticated users. However, anonymous pull access can be used in scenarios that do not require user authentication such as distributing public container images.
","tags":["Azure.ACR.AnonymousAccess","AZR-000401"]},{"location":"en/rules/Azure.ACR.AnonymousAccess/#recommendation","title":"Recommendation","text":"Consider disabling anonymous pull access in scenarios that require user authentication.
","tags":["Azure.ACR.AnonymousAccess","AZR-000401"]},{"location":"en/rules/Azure.ACR.AnonymousAccess/#examples","title":"Examples","text":"","tags":["Azure.ACR.AnonymousAccess","AZR-000401"]},{"location":"en/rules/Azure.ACR.AnonymousAccess/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy registries that pass this rule:
properties.anonymousPullEnabled
property to false
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2023-08-01-preview\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"anonymousPullEnabled\": false,\n \"policies\": {\n \"quarantinePolicy\": {\n \"status\": \"enabled\"\n },\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"days\": 30,\n \"status\": \"enabled\"\n },\n \"softDeletePolicy\": {\n \"retentionDays\": 90,\n \"status\": \"enabled\"\n }\n }\n }\n}\n
","tags":["Azure.ACR.AnonymousAccess","AZR-000401"]},{"location":"en/rules/Azure.ACR.AnonymousAccess/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy registries that pass this rule:
properties.anonymousPullEnabled
property to false
.For example:
Azure Bicep snippetresource registry 'Microsoft.ContainerRegistry/registries@2023-08-01-preview' = {\n name: name\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n anonymousPullEnabled: false\n policies: {\n quarantinePolicy: {\n status: 'enabled'\n }\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n days: 30\n status: 'enabled'\n }\n softDeletePolicy: {\n retentionDays: 90\n status: 'enabled'\n }\n }\n }\n}\n
","tags":["Azure.ACR.AnonymousAccess","AZR-000401"]},{"location":"en/rules/Azure.ACR.AnonymousAccess/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To configure registries that pass this rule:
Azure CLI snippetaz acr update -n '<name>' -g '<resource_group>' --anonymous-pull-enabled false\n
","tags":["Azure.ACR.AnonymousAccess","AZR-000401"]},{"location":"en/rules/Azure.ACR.AnonymousAccess/#notes","title":"Notes","text":"The anonymous pull access feature is currently in preview. Anonymous pull access is only available in the Standard
and Premium
service tiers.
Security \u00b7 Container Registry \u00b7 Rule \u00b7 2020_12 \u00b7 Critical
Enable vulnerability scanning for container images.
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"en/rules/Azure.ACR.ContainerScan/#description","title":"Description","text":"A potential risk with container-based workloads is un-patched security vulnerabilities in:
It is important to adopt a strategy to actively scan images for security vulnerabilities. One option for scanning container images is to use Microsoft Defender for container registries. Microsoft Defender for container registries scans each container image pushed to the registry.
Microsoft Defender for container registries scans images on push, import, and recently pulled images. Recently pulled images are scanned on a regular basis when they have been pulled within the last 30 days. When scanned, the container image is pulled and executed in an isolated sandbox for scanning. Any detected vulnerabilities are reported to Microsoft Defender for Cloud.
Container image vulnerability scanning with Microsoft Defender for container registries:
Consider using Microsoft Defender for Cloud to scan for security vulnerabilities in container images.
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"en/rules/Azure.ACR.ContainerScan/#examples","title":"Examples","text":"","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"en/rules/Azure.ACR.ContainerScan/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable container image scanning:
Standard
pricing tier for Microsoft Defender for container registries.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2018-06-01\",\n \"name\": \"ContainerRegistry\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"en/rules/Azure.ACR.ContainerScan/#configure-with-bicep","title":"Configure with Bicep","text":"To enable container image scanning:
Standard
pricing tier for Microsoft Defender for container registries.For example:
Azure Bicep snippetresource defenderForContainerRegistry 'Microsoft.Security/pricings@2018-06-01' = {\n name: 'ContainerRegistry'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"en/rules/Azure.ACR.ContainerScan/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz security pricing create -n 'ContainerRegistry' --tier 'standard'\n
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"en/rules/Azure.ACR.ContainerScan/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetSet-AzSecurityPricing -Name 'ContainerRegistry' -PricingTier 'Standard'\n
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"en/rules/Azure.ACR.ContainerScan/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"en/rules/Azure.ACR.ContainerScan/#links","title":"Links","text":"Security \u00b7 Container Registry \u00b7 Rule \u00b7 2020_12 \u00b7 Important
Use container images signed by a trusted image publisher.
","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"en/rules/Azure.ACR.ContentTrust/#description","title":"Description","text":"Azure Container Registry (ACR) content trust enables pushing and pulling of signed images. Signed images provides additional assurance that they have been built on a trusted source.
To enable content trust, the container registry must be using a Premium SKU.
Content trust is currently not supported in a registry that's encrypted with a customer-managed key. When using customer-managed keys, content trust can not be enabled.
","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"en/rules/Azure.ACR.ContentTrust/#recommendation","title":"Recommendation","text":"Consider enabling content trust on registries, clients, and sign container images.
","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"en/rules/Azure.ACR.ContentTrust/#examples","title":"Examples","text":"","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"en/rules/Azure.ACR.ContentTrust/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy registries that pass this rule:
properties.trustPolicy.status
to enabled
.properties.trustPolicy.type
to Notary
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2023-08-01-preview\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"days\": 30,\n \"status\": \"enabled\"\n }\n }\n }\n}\n
","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"en/rules/Azure.ACR.ContentTrust/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy registries that pass this rule:
properties.trustPolicy.status
to enabled
.properties.trustPolicy.type
to Notary
.For example:
Azure Bicep snippetresource registry 'Microsoft.ContainerRegistry/registries@2023-08-01-preview' = {\n name: name\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n days: 30\n status: 'enabled'\n }\n }\n }\n}\n
","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"en/rules/Azure.ACR.ContentTrust/#links","title":"Links","text":"Security \u00b7 Container Registry \u00b7 Rule \u00b7 2023_09 \u00b7 Important
Limit network access of container registries to only trusted clients.
","tags":["Azure.ACR.Firewall","AZR-000402"]},{"location":"en/rules/Azure.ACR.Firewall/#description","title":"Description","text":"Azure Container Registry (ACR) allows you to restrict network access to trusted clients and networks instead of any client.
Container registries using the Premium SKU can limit network access by setting firewall rules or using private endpoints. Firewall and private endpoints are not supported when using the Basic or Standard SKU.
In general, network access should be restricted to harden against unauthorized access or exfiltration attempts. However may not be required when publishing and distributing public container images to external parties.
","tags":["Azure.ACR.Firewall","AZR-000402"]},{"location":"en/rules/Azure.ACR.Firewall/#recommendation","title":"Recommendation","text":"Consider restricting network access to trusted clients to harden against unauthorized access or exfiltration attempts.
","tags":["Azure.ACR.Firewall","AZR-000402"]},{"location":"en/rules/Azure.ACR.Firewall/#examples","title":"Examples","text":"","tags":["Azure.ACR.Firewall","AZR-000402"]},{"location":"en/rules/Azure.ACR.Firewall/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Container Registries that pass this rule:
properties.publicNetworkAccess
property to Disabled
. ORproperties.networkRuleSet.defaultAction
property to Deny
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2023-01-01-preview\",\n \"name\": \"[parameters('registryName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"properties\": {\n \"publicNetworkAccess\": \"Enabled\",\n \"networkRuleBypassOptions\": \"AzureServices\",\n \"networkRuleSet\": {\n \"defaultAction\": \"Deny\",\n \"ipRules\": [\n {\n \"action\": \"Allow\",\n \"value\": \"_PublicIPv4Address_\"\n }\n ]\n }\n }\n}\n
","tags":["Azure.ACR.Firewall","AZR-000402"]},{"location":"en/rules/Azure.ACR.Firewall/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Container Registries that pass this rule:
properties.publicNetworkAccess
property to Disabled
. ORproperties.networkRuleSet.defaultAction
property to Deny
.For example:
Azure Bicep snippetresource acr 'Microsoft.ContainerRegistry/registries@2023-01-01-preview' = {\n name: registryName\n location: location\n sku: {\n name: 'Premium'\n }\n properties: {\n publicNetworkAccess: 'Enabled'\n networkRuleBypassOptions: 'AzureServices'\n networkRuleSet: {\n defaultAction: 'Deny'\n ipRules: [\n {\n action: 'Allow'\n value: '_PublicIPv4Address_'\n }\n ]\n }\n }\n}\n
","tags":["Azure.ACR.Firewall","AZR-000402"]},{"location":"en/rules/Azure.ACR.Firewall/#notes","title":"Notes","text":"Configuring firewall rules or using private endpoints is only available for the Premium SKU.
When used with Microsoft Defender for Containers, you must enable trusted Microsoft services for the vulnerability assessment feature to be able to scan the registry.
","tags":["Azure.ACR.Firewall","AZR-000402"]},{"location":"en/rules/Azure.ACR.Firewall/#links","title":"Links","text":"Reliability \u00b7 Container Registry \u00b7 Rule \u00b7 2020_12 \u00b7 Important
Use geo-replicated container registries to compliment a multi-region container deployments.
","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"en/rules/Azure.ACR.GeoReplica/#description","title":"Description","text":"A container registry is stored and maintained by default in a single region. Optionally geo-replication to one or more additional regions can be enabled.
Geo-replicating container registries provides the following benefits:
Consider using a geo-replicated container registry for multi-region deployments.
","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"en/rules/Azure.ACR.GeoReplica/#examples","title":"Examples","text":"","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"en/rules/Azure.ACR.GeoReplica/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable geo-replication for Container Registries that pass this rule:
sku.name
to Premium
(required for geo-replication).replications
child resource with location
set to the region to replicate to.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"metadata\": {\n \"_generator\": {\n \"name\": \"bicep\",\n \"version\": \"0.5.6.12127\",\n \"templateHash\": \"12610175857982700190\"\n }\n },\n \"parameters\": {\n \"acrName\": {\n \"type\": \"string\",\n \"defaultValue\": \"[format('acr{0}', uniqueString(resourceGroup().id))]\",\n \"maxLength\": 50,\n \"minLength\": 5,\n \"metadata\": {\n \"description\": \"Globally unique name of your Azure Container Registry\"\n }\n },\n \"acrAdminUserEnabled\": {\n \"type\": \"bool\",\n \"defaultValue\": false,\n \"metadata\": {\n \"description\": \"Enable admin user that has push / pull permission to the registry.\"\n }\n },\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"Location for registry home replica.\"\n }\n },\n \"acrSku\": {\n \"type\": \"string\",\n \"defaultValue\": \"Premium\",\n \"allowedValues\": [\n \"Premium\"\n ],\n \"metadata\": {\n \"description\": \"Tier of your Azure Container Registry. Geo-replication requires Premium SKU.\"\n }\n },\n \"acrReplicaLocation\": {\n \"type\": \"string\",\n \"metadata\": {\n \"description\": \"Short name for registry replica location.\"\n }\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2019-12-01-preview\",\n \"name\": \"[parameters('acrName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('acrSku')]\"\n },\n \"tags\": {\n \"displayName\": \"Container Registry\",\n \"container.registry\": \"[parameters('acrName')]\"\n },\n \"properties\": {\n \"adminUserEnabled\": \"[parameters('acrAdminUserEnabled')]\"\n }\n },\n {\n \"type\": \"Microsoft.ContainerRegistry/registries/replications\",\n \"apiVersion\": \"2019-12-01-preview\",\n \"name\": \"[format('{0}/{1}', parameters('acrName'), parameters('acrReplicaLocation'))]\",\n \"location\": \"[parameters('acrReplicaLocation')]\",\n \"properties\": {},\n \"dependsOn\": [\n \"[resourceId('Microsoft.ContainerRegistry/registries', parameters('acrName'))]\"\n ]\n }\n ],\n \"outputs\": {\n \"acrLoginServer\": {\n \"type\": \"string\",\n \"value\": \"[reference(resourceId('Microsoft.ContainerRegistry/registries', parameters('acrName'))).loginServer]\"\n }\n }\n}\n
","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"en/rules/Azure.ACR.GeoReplica/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Container Registries that pass this rule:
sku.name
to Premium
(required for geo-replication).replications
child resource with location
set to the region to replicate to.For example:
Azure Bicep snippetresource containerRegistry 'Microsoft.ContainerRegistry/registries@2019-12-01-preview' = {\n name: acrName\n location: location\n sku: {\n name: 'Premium'\n }\n tags: {\n displayName: 'Container Registry'\n 'container.registry': acrName\n }\n properties: {\n adminUserEnabled: acrAdminUserEnabled\n }\n}\n\nresource containerRegistryReplica 'Microsoft.ContainerRegistry/registries/replications@2019-12-01-preview' = {\n parent: containerRegistry\n name: '${acrReplicaLocation}'\n location: acrReplicaLocation\n properties: {\n }\n}\n
","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"en/rules/Azure.ACR.GeoReplica/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"en/rules/Azure.ACR.GeoReplica/#links","title":"Links","text":"Security \u00b7 Container Registry \u00b7 Rule \u00b7 2020_12 \u00b7 Critical
Remove container images with known vulnerabilities.
","tags":["Azure.ACR.ImageHealth","AZR-000003"]},{"location":"en/rules/Azure.ACR.ImageHealth/#description","title":"Description","text":"When Microsoft Defender for container registries is enabled, Microsoft Defender scans container images. Container images are scanned for known vulnerabilities and marked as healthy or unhealthy. Vulnerable container images should not be used.
","tags":["Azure.ACR.ImageHealth","AZR-000003"]},{"location":"en/rules/Azure.ACR.ImageHealth/#recommendation","title":"Recommendation","text":"Consider using removing container images with known vulnerabilities.
","tags":["Azure.ACR.ImageHealth","AZR-000003"]},{"location":"en/rules/Azure.ACR.ImageHealth/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.ACR.ImageHealth","AZR-000003"]},{"location":"en/rules/Azure.ACR.ImageHealth/#links","title":"Links","text":"Reliability \u00b7 Container Registry \u00b7 Rule \u00b7 2020_06 \u00b7 Important
ACR should use the Premium or Standard SKU for production deployments.
","tags":["Azure.ACR.MinSku","AZR-000006"]},{"location":"en/rules/Azure.ACR.MinSku/#description","title":"Description","text":"Azure Container Registry (ACR) provides a range of different service tiers (also known as SKUs). These service tiers provide different levels of performance and features.
Three service tiers are available: Basic, Standard, and Premium. Basic container registries are only recommended for non-production deployments. Use a minimum of Standard for production container registries.
The Premium SKU provides higher image throughput and included storage, and is required for:
Consider using the Premium Container Registry SKU for production deployments.
","tags":["Azure.ACR.MinSku","AZR-000006"]},{"location":"en/rules/Azure.ACR.MinSku/#examples","title":"Examples","text":"","tags":["Azure.ACR.MinSku","AZR-000006"]},{"location":"en/rules/Azure.ACR.MinSku/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy registries that pass this rule:
sku.name
property to Premium
or Standard
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2023-01-01-preview\",\n \"name\": \"[parameters('registryName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"quarantinePolicy\": {\n \"status\": \"enabled\"\n },\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"days\": 30,\n \"status\": \"enabled\"\n },\n \"softDeletePolicy\": {\n \"retentionDays\": 90,\n \"status\": \"enabled\"\n }\n }\n }\n}\n
","tags":["Azure.ACR.MinSku","AZR-000006"]},{"location":"en/rules/Azure.ACR.MinSku/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy registries that pass this rule:
sku.name
property to Premium
or Standard
.For example:
Azure Bicep snippetresource acr 'Microsoft.ContainerRegistry/registries@2023-01-01-preview' = {\n name: registryName\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n quarantinePolicy: {\n status: 'enabled'\n }\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n days: 30\n status: 'enabled'\n }\n softDeletePolicy: {\n retentionDays: 90\n status: 'enabled'\n }\n }\n }\n}\n
","tags":["Azure.ACR.MinSku","AZR-000006"]},{"location":"en/rules/Azure.ACR.MinSku/#links","title":"Links","text":"Operational Excellence \u00b7 Container Registry \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Container registry names should meet naming requirements.
","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"en/rules/Azure.ACR.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for container registry names are:
Consider using names that meet container registry naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"en/rules/Azure.ACR.Name/#examples","title":"Examples","text":"","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"en/rules/Azure.ACR.Name/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy registries that pass this rule, consider:
minLength
and maxLength
constraint for the resource name parameter.uniqueString()
function to generate a unique name.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"name\": {\n \"type\": \"string\",\n \"minLength\": 5,\n \"maxLength\": 50,\n \"metadata\": {\n \"description\": \"The name of the resource.\"\n }\n },\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"The location resources will be deployed.\"\n }\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2023-08-01-preview\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"days\": 30,\n \"status\": \"enabled\"\n }\n }\n }\n }\n ]\n}\n
","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"en/rules/Azure.ACR.Name/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy registries that pass this rule, consider:
minLength
and maxLength
constraint for the resource name parameter.uniqueString()
function to generate a unique name.For example:
Azure Bicep snippet@minLength(5)\n@maxLength(50)\n@sys.description('The name of the resource.')\nparam name string\n\n@sys.description('The location resources will be deployed.')\nparam location string = resourceGroup().location\n\nresource registry 'Microsoft.ContainerRegistry/registries@2023-08-01-preview' = {\n name: name\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n days: 30\n status: 'enabled'\n }\n }\n }\n}\n
","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"en/rules/Azure.ACR.Name/#notes","title":"Notes","text":"This rule does not check if container registry names are unique.
","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"en/rules/Azure.ACR.Name/#links","title":"Links","text":"Security \u00b7 Container Registry \u00b7 Rule \u00b7 Preview \u00b7 2020_12 \u00b7 Important
Enable container image quarantine, scan, and mark images as verified.
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"en/rules/Azure.ACR.Quarantine/#description","title":"Description","text":"Image quarantine is a configurable option for Azure Container Registry (ACR). When enabled, images pushed to the container registry are not available by default. Each image must be verified and marked as Passed
before it is available to pull.
To verify container images, integrate with an external security tool that supports this feature.
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"en/rules/Azure.ACR.Quarantine/#recommendation","title":"Recommendation","text":"Consider configuring a security tool to implement the image quarantine pattern. Enable image quarantine on the container registry to ensure each image is verified before use.
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"en/rules/Azure.ACR.Quarantine/#examples","title":"Examples","text":"","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"en/rules/Azure.ACR.Quarantine/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Container Registries that pass this rule:
properties.quarantinePolicy.status
to enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2023-01-01-preview\",\n \"name\": \"[parameters('registryName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"quarantinePolicy\": {\n \"status\": \"enabled\"\n },\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"days\": 30,\n \"status\": \"enabled\"\n },\n \"softDeletePolicy\": {\n \"retentionDays\": 90,\n \"status\": \"enabled\"\n }\n }\n }\n}\n
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"en/rules/Azure.ACR.Quarantine/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Container Registries that pass this rule:
properties.quarantinePolicy.status
to enabled
.For example:
Azure Bicep snippetresource acr 'Microsoft.ContainerRegistry/registries@2023-01-01-preview' = {\n name: registryName\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n quarantinePolicy: {\n status: 'enabled'\n }\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n days: 30\n status: 'enabled'\n }\n softDeletePolicy: {\n retentionDays: 90\n status: 'enabled'\n }\n }\n }\n}\n
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"en/rules/Azure.ACR.Quarantine/#notes","title":"Notes","text":"Image quarantine for Azure Container Registry is currently in preview.
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"en/rules/Azure.ACR.Quarantine/#links","title":"Links","text":"Cost Optimization \u00b7 Container Registry \u00b7 Rule \u00b7 Preview \u00b7 2020_12 \u00b7 Important
Use a retention policy to cleanup untagged manifests.
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"en/rules/Azure.ACR.Retention/#description","title":"Description","text":"Retention policy is a configurable option of Premium Azure Container Registry (ACR). When a retention policy is configured, untagged manifests in the registry are automatically deleted. A manifest is untagged when a more recent image is pushed using the same tag. i.e. latest.
The retention policy (in days) can be set to 0-365. The default is 7 days.
To configure a retention policy, the container registry must be using a Premium SKU.
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"en/rules/Azure.ACR.Retention/#recommendation","title":"Recommendation","text":"Consider enabling a retention policy for untagged manifests.
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"en/rules/Azure.ACR.Retention/#examples","title":"Examples","text":"","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"en/rules/Azure.ACR.Retention/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Container Registries that pass this rule:
properties.retentionPolicy.status
to enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2023-11-01-preview\",\n \"name\": \"[parameters('registryName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"quarantinePolicy\": {\n \"status\": \"enabled\"\n },\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"days\": 30,\n \"status\": \"enabled\"\n },\n \"softDeletePolicy\": {\n \"retentionDays\": 90,\n \"status\": \"enabled\"\n }\n }\n }\n}\n
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"en/rules/Azure.ACR.Retention/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Container Registries that pass this rule:
properties.retentionPolicy.status
to enabled
.For example:
Azure Bicep snippetresource acr 'Microsoft.ContainerRegistry/registries@2023-11-01-preview' = {\n name: registryName\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n quarantinePolicy: {\n status: 'enabled'\n }\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n days: 30\n status: 'enabled'\n }\n softDeletePolicy: {\n retentionDays: 90\n status: 'enabled'\n }\n }\n }\n}\n
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"en/rules/Azure.ACR.Retention/#notes","title":"Notes","text":"Retention policies for Azure Container Registry is currently in preview.
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"en/rules/Azure.ACR.Retention/#links","title":"Links","text":"Reliability \u00b7 Container Registry \u00b7 Rule \u00b7 Preview \u00b7 2022_09 \u00b7 Important
Azure Container Registries should have soft delete policy enabled.
","tags":["Azure.ACR.SoftDelete","AZR-000310"]},{"location":"en/rules/Azure.ACR.SoftDelete/#description","title":"Description","text":"Azure Container Registry (ACR) allows you to enable the soft delete policy to recover any accidentally deleted artifacts for a set retention period.
This feature is available in all the service tiers (also known as SKUs). For information about registry service tiers, see Azure Container Registry service tiers.
Once you enable the soft delete policy, ACR manages the deleted artifacts as the soft deleted artifacts with a set retention period. Thereby you have ability to list, filter, and restore the soft deleted artifacts. Once the retention period is complete, all the soft deleted artifacts are auto-purged.
Current preview limitations:
Azure Container Registries should have soft delete enabled to enable recovery of accidentally deleted artifacts.
","tags":["Azure.ACR.SoftDelete","AZR-000310"]},{"location":"en/rules/Azure.ACR.SoftDelete/#examples","title":"Examples","text":"","tags":["Azure.ACR.SoftDelete","AZR-000310"]},{"location":"en/rules/Azure.ACR.SoftDelete/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy an Azure Container Registry that pass this rule:
properties.policies.softDeletePolicy.status
property to enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2023-01-01-preview\",\n \"name\": \"[parameters('registryName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"quarantinePolicy\": {\n \"status\": \"enabled\"\n },\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"days\": 30,\n \"status\": \"enabled\"\n },\n \"softDeletePolicy\": {\n \"retentionDays\": 90,\n \"status\": \"enabled\"\n }\n }\n }\n}\n
","tags":["Azure.ACR.SoftDelete","AZR-000310"]},{"location":"en/rules/Azure.ACR.SoftDelete/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy an Azure Container Registry that pass this rule:
properties.policies.softDeletePolicy.status
property to enabled
.For example:
Azure Bicep snippetresource acr 'Microsoft.ContainerRegistry/registries@2023-01-01-preview' = {\n name: registryName\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n quarantinePolicy: {\n status: 'enabled'\n }\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n days: 30\n status: 'enabled'\n }\n softDeletePolicy: {\n retentionDays: 90\n status: 'enabled'\n }\n }\n }\n}\n
","tags":["Azure.ACR.SoftDelete","AZR-000310"]},{"location":"en/rules/Azure.ACR.SoftDelete/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz acr config soft-delete update -r '<name>' --days 90 --status enabled\n
","tags":["Azure.ACR.SoftDelete","AZR-000310"]},{"location":"en/rules/Azure.ACR.SoftDelete/#links","title":"Links","text":"Cost Optimization \u00b7 Container Registry \u00b7 Rule \u00b7 2020_12 \u00b7 Important
Regularly remove deprecated and unneeded images to reduce storage usage.
","tags":["Azure.ACR.Usage","AZR-000001"]},{"location":"en/rules/Azure.ACR.Usage/#description","title":"Description","text":"Each ACR SKU has an amount of included storage. When the amount of included storage is exceeded, additional storage costs per GiB are accrued.
It is good practice to regularly clean-up orphaned (or dangling) images. These images are a result of pushing updated images with the same tag.
","tags":["Azure.ACR.Usage","AZR-000001"]},{"location":"en/rules/Azure.ACR.Usage/#recommendation","title":"Recommendation","text":"Consider removing deprecated and unneeded images to reduce storage consumption. Also consider upgrading to the Premium SKU for Basic or Standard registries to increase included storage.
","tags":["Azure.ACR.Usage","AZR-000001"]},{"location":"en/rules/Azure.ACR.Usage/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.ACR.Usage","AZR-000001"]},{"location":"en/rules/Azure.ACR.Usage/#links","title":"Links","text":"Security \u00b7 Data Explorer \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Use disk encryption for Azure Data Explorer (ADX) clusters.
","tags":["Azure.ADX.DiskEncryption","AZR-000013"]},{"location":"en/rules/Azure.ADX.DiskEncryption/#description","title":"Description","text":"Azure storage is encrypted at rest, however computing resources can additionally use disk encryption. Disk encryption provides additional security for data at rest.
","tags":["Azure.ADX.DiskEncryption","AZR-000013"]},{"location":"en/rules/Azure.ADX.DiskEncryption/#recommendation","title":"Recommendation","text":"Consider enabling disk encryption on Azure Data Explorer clusters.
","tags":["Azure.ADX.DiskEncryption","AZR-000013"]},{"location":"en/rules/Azure.ADX.DiskEncryption/#examples","title":"Examples","text":"","tags":["Azure.ADX.DiskEncryption","AZR-000013"]},{"location":"en/rules/Azure.ADX.DiskEncryption/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy clusters that pass this rule:
properties.enableDiskEncryption
to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Kusto/clusters\",\n \"apiVersion\": \"2021-08-27\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_D11_v2\",\n \"tier\": \"Standard\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"enableDiskEncryption\": true\n }\n}\n
","tags":["Azure.ADX.DiskEncryption","AZR-000013"]},{"location":"en/rules/Azure.ADX.DiskEncryption/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy clusters that pass this rule:
properties.enableDiskEncryption
to true
.For example:
Azure Bicep snippetresource adx 'Microsoft.Kusto/clusters@2021-08-27' = {\n name: name\n location: location\n sku: {\n name: 'Standard_D11_v2'\n tier: 'Standard'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n enableDiskEncryption: true\n }\n}\n
","tags":["Azure.ADX.DiskEncryption","AZR-000013"]},{"location":"en/rules/Azure.ADX.DiskEncryption/#links","title":"Links","text":"Security \u00b7 Data Explorer \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Configure Data Explorer clusters to use managed identities to access Azure resources securely.
","tags":["Azure.ADX.ManagedIdentity","AZR-000012"]},{"location":"en/rules/Azure.ADX.ManagedIdentity/#description","title":"Description","text":"A managed identity allows your cluster to access other Azure AD-protected resources such as Azure Storage. The identity is managed by the Azure platform and doesn't require you to provision or rotate any secrets.
Using Azure managed identities have the following benefits:
Consider configuring a managed identity for each Azure Data Explorer cluster. Also consider using managed identities to authenticate to related Azure services.
","tags":["Azure.ADX.ManagedIdentity","AZR-000012"]},{"location":"en/rules/Azure.ADX.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.ADX.ManagedIdentity","AZR-000012"]},{"location":"en/rules/Azure.ADX.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy clusters that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Kusto/clusters\",\n \"apiVersion\": \"2021-08-27\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_D11_v2\",\n \"tier\": \"Standard\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"enableDiskEncryption\": true\n }\n}\n
","tags":["Azure.ADX.ManagedIdentity","AZR-000012"]},{"location":"en/rules/Azure.ADX.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy clusters that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource adx 'Microsoft.Kusto/clusters@2021-08-27' = {\n name: name\n location: location\n sku: {\n name: 'Standard_D11_v2'\n tier: 'Standard'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n enableDiskEncryption: true\n }\n}\n
","tags":["Azure.ADX.ManagedIdentity","AZR-000012"]},{"location":"en/rules/Azure.ADX.ManagedIdentity/#links","title":"Links","text":"Reliability \u00b7 Data Explorer \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters.
","tags":["Azure.ADX.SLA","AZR-000014"]},{"location":"en/rules/Azure.ADX.SLA/#description","title":"Description","text":"When choosing a SKU for an ADX cluster you should consider the SLA that is included in the SKU. ADX clusters offer a range of offerings. Development SKUs are designed for early non-production use and do not include any SLA.
","tags":["Azure.ADX.SLA","AZR-000014"]},{"location":"en/rules/Azure.ADX.SLA/#recommendation","title":"Recommendation","text":"Consider using a production ready SKU that includes a SLA.
","tags":["Azure.ADX.SLA","AZR-000014"]},{"location":"en/rules/Azure.ADX.SLA/#examples","title":"Examples","text":"","tags":["Azure.ADX.SLA","AZR-000014"]},{"location":"en/rules/Azure.ADX.SLA/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy clusters that pass this rule:
sku.tier
to Standard
.sku.name
to non-development SKU such as Standard_D11_v2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Kusto/clusters\",\n \"apiVersion\": \"2021-08-27\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_D11_v2\",\n \"tier\": \"Standard\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"enableDiskEncryption\": true\n }\n}\n
","tags":["Azure.ADX.SLA","AZR-000014"]},{"location":"en/rules/Azure.ADX.SLA/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy clusters that pass this rule:
sku.tier
to Standard
.sku.name
to non-development SKU such as Standard_D11_v2
.For example:
Azure Bicep snippetresource adx 'Microsoft.Kusto/clusters@2021-08-27' = {\n name: name\n location: location\n sku: {\n name: 'Standard_D11_v2'\n tier: 'Standard'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n enableDiskEncryption: true\n }\n}\n
","tags":["Azure.ADX.SLA","AZR-000014"]},{"location":"en/rules/Azure.ADX.SLA/#links","title":"Links","text":"Cost Optimization \u00b7 Data Explorer \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Regularly remove unused resources to reduce costs.
","tags":["Azure.ADX.Usage","AZR-000011"]},{"location":"en/rules/Azure.ADX.Usage/#description","title":"Description","text":"Billing starts for an Azure Data Explorer (ADX) cluster after it is provisioned. To store data in an ADX cluster, you must first create a database. Clusters without any databases are considered unused and can be removed to reduce costs and management overhead.
Additionally, ADX clusters on a paid tier can stopped. Stopping an ADX cluster de-allocates and removes compute resources. While in the stopped state, compute charges are not incurred. Any data stored in the cluster is persisted while the cluster is stopped.
","tags":["Azure.ADX.Usage","AZR-000011"]},{"location":"en/rules/Azure.ADX.Usage/#recommendation","title":"Recommendation","text":"Consider removing Data Explorer clusters that have no databases and are not used.
","tags":["Azure.ADX.Usage","AZR-000011"]},{"location":"en/rules/Azure.ADX.Usage/#notes","title":"Notes","text":"This rule applies when analyzing ADX clusters deployed (in-flight) and running within Azure. If the cluster is stopped, this rule is ignored.
","tags":["Azure.ADX.Usage","AZR-000011"]},{"location":"en/rules/Azure.ADX.Usage/#links","title":"Links","text":"Security \u00b7 Azure AI \u00b7 Rule \u00b7 2022_09 \u00b7 Important
Authenticate requests to Azure AI services with Entra ID identities.
","tags":["Azure.AI.DisableLocalAuth","AZR-000282"]},{"location":"en/rules/Azure.AI.DisableLocalAuth/#description","title":"Description","text":"To send requests to Azure AI service endpoints (previously known as Cognitive Services), each request must include an authentication header. Azure AI service endpoints supports authentication with keys or access tokens. Using an Entra ID access token instead of a cryptographic key has some additional security benefits.
With Entra ID authentication, an authorized identity is issued an OAuth2 access token issued by Entra ID. Using Entra ID as the identity provider centralizes identity management and auditing.
Once you decide to use Entra ID authentication, you can disable authentication using keys.
","tags":["Azure.AI.DisableLocalAuth","AZR-000282"]},{"location":"en/rules/Azure.AI.DisableLocalAuth/#recommendation","title":"Recommendation","text":"Consider only using Entra ID identities to authenticate requests to Azure AI service accounts. Once configured, disable authentication based on access keys.
","tags":["Azure.AI.DisableLocalAuth","AZR-000282"]},{"location":"en/rules/Azure.AI.DisableLocalAuth/#examples","title":"Examples","text":"","tags":["Azure.AI.DisableLocalAuth","AZR-000282"]},{"location":"en/rules/Azure.AI.DisableLocalAuth/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy accounts that pass this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.CognitiveServices/accounts\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"S0\"\n },\n \"kind\": \"CognitiveServices\",\n \"properties\": {\n \"publicNetworkAccess\": \"Disabled\",\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n },\n \"disableLocalAuth\": true\n }\n}\n
","tags":["Azure.AI.DisableLocalAuth","AZR-000282"]},{"location":"en/rules/Azure.AI.DisableLocalAuth/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy accounts that pass this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Bicep snippetresource account 'Microsoft.CognitiveServices/accounts@2023-05-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'S0'\n }\n kind: 'CognitiveServices'\n properties: {\n publicNetworkAccess: 'Disabled'\n networkAcls: {\n defaultAction: 'Deny'\n }\n disableLocalAuth: true\n }\n}\n
","tags":["Azure.AI.DisableLocalAuth","AZR-000282"]},{"location":"en/rules/Azure.AI.DisableLocalAuth/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/71ef260a-8f18-47b7-abcb-62d0673d94dc
/providers/Microsoft.Authorization/policyDefinitions/14de9e63-1b31-492e-a5a3-c3f7fd57f555
Security \u00b7 Azure AI \u00b7 Rule \u00b7 2022_09 \u00b7 Important
Configure managed identities to access Azure resources.
","tags":["Azure.AI.ManagedIdentity","AZR-000281"]},{"location":"en/rules/Azure.AI.ManagedIdentity/#description","title":"Description","text":"Azure AI services (previously known as Cognitive Services) must authenticate to Azure resources such storage accounts. To authenticate to Azure resources, Azure AI can use managed identities.
Using Azure managed identities have the following benefits:
Consider configuring a managed identity for each Azure AI services account.
","tags":["Azure.AI.ManagedIdentity","AZR-000281"]},{"location":"en/rules/Azure.AI.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.AI.ManagedIdentity","AZR-000281"]},{"location":"en/rules/Azure.AI.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy accounts that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.CognitiveServices/accounts\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"S0\"\n },\n \"kind\": \"TextAnalytics\",\n \"properties\": {\n \"publicNetworkAccess\": \"Disabled\",\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n },\n \"disableLocalAuth\": true\n }\n}\n
","tags":["Azure.AI.ManagedIdentity","AZR-000281"]},{"location":"en/rules/Azure.AI.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy accounts that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource language 'Microsoft.CognitiveServices/accounts@2023-05-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'S0'\n }\n kind: 'TextAnalytics'\n properties: {\n publicNetworkAccess: 'Disabled'\n networkAcls: {\n defaultAction: 'Deny'\n }\n disableLocalAuth: true\n }\n}\n
","tags":["Azure.AI.ManagedIdentity","AZR-000281"]},{"location":"en/rules/Azure.AI.ManagedIdentity/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/fe3fd216-4f83-4fc1-8984-2bbec80a3418
.Configuration of additional Azure resources is not required for all Azure AI services. This rule will run for the following Azure AI services:
TextAnalytics
- Language service.Security \u00b7 Azure AI \u00b7 Rule \u00b7 2022_09 \u00b7 Important
Use Private Endpoints to access Azure AI services accounts.
","tags":["Azure.AI.PrivateEndpoints","AZR-000283"]},{"location":"en/rules/Azure.AI.PrivateEndpoints/#description","title":"Description","text":"By default, a public endpoint is enabled for Azure AI services accounts (previously known as Cognitive Services). The public endpoint is used for all access except for requests that use a Private Endpoint. Access through the public endpoint can be disabled or restricted to authorized virtual networks.
Data exfiltration is an attack where an malicious actor does an unauthorized data transfer. Private Endpoints help prevent data exfiltration by an internal or external malicious actor. They do this by providing clear separation between public and private endpoints. As a result, broad access to public endpoints which could be operated by a malicious actor is not required.
","tags":["Azure.AI.PrivateEndpoints","AZR-000283"]},{"location":"en/rules/Azure.AI.PrivateEndpoints/#recommendation","title":"Recommendation","text":"Consider accessing Azure AI services accounts by Private Endpoints and disabling public endpoints.
","tags":["Azure.AI.PrivateEndpoints","AZR-000283"]},{"location":"en/rules/Azure.AI.PrivateEndpoints/#examples","title":"Examples","text":"","tags":["Azure.AI.PrivateEndpoints","AZR-000283"]},{"location":"en/rules/Azure.AI.PrivateEndpoints/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy accounts that pass this rule:
properties.publicNetworkAccess
property to Disabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.CognitiveServices/accounts\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"S0\"\n },\n \"kind\": \"CognitiveServices\",\n \"properties\": {\n \"publicNetworkAccess\": \"Disabled\",\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n },\n \"disableLocalAuth\": true\n }\n}\n
","tags":["Azure.AI.PrivateEndpoints","AZR-000283"]},{"location":"en/rules/Azure.AI.PrivateEndpoints/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy accounts that pass this rule:
properties.publicNetworkAccess
property to Disabled
.For example:
Azure Bicep snippetresource account 'Microsoft.CognitiveServices/accounts@2023-05-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'S0'\n }\n kind: 'CognitiveServices'\n properties: {\n publicNetworkAccess: 'Disabled'\n networkAcls: {\n defaultAction: 'Deny'\n }\n disableLocalAuth: true\n }\n}\n
","tags":["Azure.AI.PrivateEndpoints","AZR-000283"]},{"location":"en/rules/Azure.AI.PrivateEndpoints/#links","title":"Links","text":"Security \u00b7 Azure AI \u00b7 Rule \u00b7 2022_09 \u00b7 Important
Restrict access of Azure AI services to authorized virtual networks.
","tags":["Azure.AI.PublicAccess","AZR-000280"]},{"location":"en/rules/Azure.AI.PublicAccess/#description","title":"Description","text":"By default, public network access is enabled for a Azure AI service accounts (previously known as Cognitive Services). Service Endpoints and Private Link can be leveraged to restrict access to PaaS endpoints. When access is restricted, access by malicious actor is from an unauthorized virtual network is mitigated.
Configure service endpoints and private links where appropriate.
","tags":["Azure.AI.PublicAccess","AZR-000280"]},{"location":"en/rules/Azure.AI.PublicAccess/#recommendation","title":"Recommendation","text":"Consider configuring network access restrictions for Azure AI service accounts. Limit access to accounts so that access is permitted from authorized virtual networks only.
","tags":["Azure.AI.PublicAccess","AZR-000280"]},{"location":"en/rules/Azure.AI.PublicAccess/#examples","title":"Examples","text":"","tags":["Azure.AI.PublicAccess","AZR-000280"]},{"location":"en/rules/Azure.AI.PublicAccess/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy accounts that pass this rule:
properties.networkAcls.defaultAction
property to Deny
, orproperties.publicNetworkAccess
property to Disabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.CognitiveServices/accounts\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"S0\"\n },\n \"kind\": \"CognitiveServices\",\n \"properties\": {\n \"publicNetworkAccess\": \"Disabled\",\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n },\n \"disableLocalAuth\": true\n }\n}\n
","tags":["Azure.AI.PublicAccess","AZR-000280"]},{"location":"en/rules/Azure.AI.PublicAccess/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy accounts that pass this rule:
properties.networkAcls.defaultAction
property to Deny
, orproperties.publicNetworkAccess
property to Disabled
.For example:
Azure Bicep snippetresource account 'Microsoft.CognitiveServices/accounts@2023-05-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'S0'\n }\n kind: 'CognitiveServices'\n properties: {\n publicNetworkAccess: 'Disabled'\n networkAcls: {\n defaultAction: 'Deny'\n }\n disableLocalAuth: true\n }\n}\n
","tags":["Azure.AI.PublicAccess","AZR-000280"]},{"location":"en/rules/Azure.AI.PublicAccess/#links","title":"Links","text":"Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_09 \u00b7 Important
AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads.
","tags":["Azure.AKS.AuditLogs","AZR-000022"]},{"location":"en/rules/Azure.AKS.AuditLogs/#description","title":"Description","text":"To capture security-based audit logs from AKS clusters, the following diagnostic log categories should be enabled:
kube-audit
or kube-audit-admin
, or both.kube-audit
- Contains all audit log data for every audit event, including get, list, create, update, delete, patch, and post.kube-audit-admin
- Is a subset of the kube-audit
log category. kube-audit-admin
reduces the number of logs significantly by excluding the get and list audit events from the log.guard
- Contains logs for Azure Active Directory (AAD) authorization integration. For managed Azure AD, this includes token in and user info out. For Azure RBAC, this includes access reviews in and out.Consider configuring diagnostic settings to capture security-based audit logs from AKS clusters.
","tags":["Azure.AKS.AuditLogs","AZR-000022"]},{"location":"en/rules/Azure.AKS.AuditLogs/#examples","title":"Examples","text":"","tags":["Azure.AKS.AuditLogs","AZR-000022"]},{"location":"en/rules/Azure.AKS.AuditLogs/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
kube-audit
/kube-audit-admin
and guard
categories.For example:
Azure Template snippet{\n \"comments\": \"Azure Kubernetes Cluster\",\n \"apiVersion\": \"2020-12-01\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ],\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"location\": \"[parameters('location')]\",\n \"name\": \"[parameters('clusterName')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 32,\n \"count\": 3,\n \"minCount\": 3,\n \"maxCount\": 10,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D2s_v3\",\n \"osType\": \"Linux\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[variables('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\",\n \"scaleSetPriority\": \"Regular\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"Standard\",\n \"serviceCidr\": \"192.168.0.0/16\",\n \"dnsServiceIP\": \"192.168.0.4\",\n \"dockerBridgeCidr\": \"172.17.0.1/16\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true,\n \"config\": {\n \"version\": \"v2\"\n }\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"kubeDashboard\": {\n \"enabled\": false\n }\n }\n },\n \"resources\": [\n {\n \"apiVersion\": \"2016-09-01\",\n \"type\": \"Microsoft.ContainerService/managedClusters/providers/diagnosticSettings\",\n \"name\": \"[concat(parameters('clusterName'), '/Microsoft.Insights/service')]\",\n \"properties\": {\n \"workspaceId\": \"[parameters('workspaceId')]\",\n \"logs\": [\n {\n \"category\": \"kube-audit\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n },\n {\n \"category\": \"kube-audit-admin\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n },\n {\n \"category\": \"guard\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n }\n ],\n \"metrics\": []\n }\n }\n ]\n}\n
","tags":["Azure.AKS.AuditLogs","AZR-000022"]},{"location":"en/rules/Azure.AKS.AuditLogs/#links","title":"Links","text":"Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_06 \u00b7 Important
Restrict access to API server endpoints to authorized IP addresses.
","tags":["Azure.AKS.AuthorizedIPs","AZR-000030"]},{"location":"en/rules/Azure.AKS.AuthorizedIPs/#description","title":"Description","text":"In Kubernetes, the API server is the control plane of the cluster. Access to the API server is required by various cluster functions as well as all administrator activities.
All activities performed against the cluster require authorization. To improve cluster security, the API server can be restricted to a limited set of IP address ranges.
Restricting authorized IP addresses for the API server has the following limitations:
When configuring this feature, you must specify the IP address ranges that will be authorized. To allow only the outbound public IP of the Standard SKU load balancer, use 0.0.0.0/32
.
You should add these ranges to the allow list:
Consider restricting network traffic to the API server endpoints to trusted IP addresses.
","tags":["Azure.AKS.AuthorizedIPs","AZR-000030"]},{"location":"en/rules/Azure.AKS.AuthorizedIPs/#examples","title":"Examples","text":"","tags":["Azure.AKS.AuthorizedIPs","AZR-000030"]},{"location":"en/rules/Azure.AKS.AuthorizedIPs/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy clusters that pass this rule:
properties.apiServerAccessProfile.authorizedIPRanges
property to a list of authorized IP ranges.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-11-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": \"[variables('allPools')]\",\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\"\n },\n \"apiServerAccessProfile\": {\n \"authorizedIPRanges\": [\n \"0.0.0.0/32\"\n ]\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"oidcIssuerProfile\": {\n \"enabled\": true\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.AuthorizedIPs","AZR-000030"]},{"location":"en/rules/Azure.AKS.AuthorizedIPs/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy resource that pass this rule:
properties.apiServerAccessProfile.authorizedIPRanges
property to a list of authorized IP ranges.For example:
Azure Bicep snippetresource cluster 'Microsoft.ContainerService/managedClusters@2023-11-01' = {\n location: location\n name: name\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: allPools\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n }\n apiServerAccessProfile: {\n authorizedIPRanges: [\n '0.0.0.0/32'\n ]\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n oidcIssuerProfile: {\n enabled: true\n }\n addonProfiles: {\n azurepolicy: {\n enabled: true\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.AuthorizedIPs","AZR-000030"]},{"location":"en/rules/Azure.AKS.AuthorizedIPs/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz aks update -n '<name>' -g '<resource_group>' --api-server-authorized-ip-ranges '0.0.0.0/32'\n
","tags":["Azure.AKS.AuthorizedIPs","AZR-000030"]},{"location":"en/rules/Azure.AKS.AuthorizedIPs/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetSet-AzAksCluster -Name '<name>' -ResourceGroupName '<resource_group>' -ApiServerAccessAuthorizedIpRange '0.0.0.0/32'\n
","tags":["Azure.AKS.AuthorizedIPs","AZR-000030"]},{"location":"en/rules/Azure.AKS.AuthorizedIPs/#links","title":"Links","text":"Performance Efficiency \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_09 \u00b7 Important
Use autoscaling to scale clusters based on workload requirements.
","tags":["Azure.AKS.AutoScaling","AZR-000019"]},{"location":"en/rules/Azure.AKS.AutoScaling/#description","title":"Description","text":"In addition to perform manual scaling, AKS clusters support autoscaling. Autoscaling reduces manual intervention required to scale a cluster up/ down to keep up with changing workload requirements. Scaling is performed on a node pool, which is a group of nodes with the same configuration within a cluster.
Within AKS, the cluster autoscaler monitors pods and nodes in the cluster. When a pod cannot be scheduled due to resource constraints, the cluster autoscaler increases the number of nodes in the node pool. When a node is underutilized, the cluster autoscaler removes the node from the node pool. Scaling is performed within the range of minCount
and maxCount
properties set on the node pool.
In addition to performance efficiency, autoscaling can also help reduce costs when the cluster is underutilized enough to reduce the number of nodes.
When scaling an AKS cluster manually or with auto-scale, consider the following:
maxCount
nodes and nodes added during upgrades.minCount
and maxCount
nodes.Consider deploying AKS clusters with virtual machine scale sets node pools and enable autoscaling.
","tags":["Azure.AKS.AutoScaling","AZR-000019"]},{"location":"en/rules/Azure.AKS.AutoScaling/#examples","title":"Examples","text":"","tags":["Azure.AKS.AutoScaling","AZR-000019"]},{"location":"en/rules/Azure.AKS.AutoScaling/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
properties.agentPoolProfiles[*].enableAutoScaling
property to true
.properties.agentPoolProfiles[*].type
property to VirtualMachineScaleSets
.properties.agentPoolProfiles[*].minCount
and properties.agentPoolProfiles[*].maxCount
properties. The cluster autoscaler will adjust the number of nodes between (inclusive of) these values.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-11-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 5,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\"\n },\n {\n \"name\": \"user\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 20,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"User\",\n \"osDiskType\": \"Ephemeral\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\"\n },\n \"apiServerAccessProfile\": {\n \"authorizedIPRanges\": [\n \"0.0.0.0/32\"\n ]\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"oidcIssuerProfile\": {\n \"enabled\": true\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.AutoScaling","AZR-000019"]},{"location":"en/rules/Azure.AKS.AutoScaling/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
properties.agentPoolProfiles[*].enableAutoScaling
property to true
.properties.agentPoolProfiles[*].type
property to VirtualMachineScaleSets
.properties.agentPoolProfiles[*].minCount
and properties.agentPoolProfiles[*].maxCount
properties. The cluster autoscaler will adjust the number of nodes between (inclusive of) these values.For example:
Azure Bicep snippetresource clusterWithPools 'Microsoft.ContainerService/managedClusters@2023-11-01' = {\n location: location\n name: name\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: [\n {\n name: 'system'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 5\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'System'\n osDiskType: 'Ephemeral'\n }\n {\n name: 'user'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 20\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'User'\n osDiskType: 'Ephemeral'\n }\n ]\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n }\n apiServerAccessProfile: {\n authorizedIPRanges: [\n '0.0.0.0/32'\n ]\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n oidcIssuerProfile: {\n enabled: true\n }\n addonProfiles: {\n azurepolicy: {\n enabled: true\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.AutoScaling","AZR-000019"]},{"location":"en/rules/Azure.AKS.AutoScaling/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"","tags":["Azure.AKS.AutoScaling","AZR-000019"]},{"location":"en/rules/Azure.AKS.AutoScaling/#enable-cluster-autoscaler","title":"Enable cluster autoscaler","text":"Azure CLI snippetaz aks update \\\n --name '<name>' \\\n --resource-group '<resource_group>' \\\n --enable-cluster-autoscaler \\\n --min-count '<min_count>' \\\n --max-count '<max_count>'\n
","tags":["Azure.AKS.AutoScaling","AZR-000019"]},{"location":"en/rules/Azure.AKS.AutoScaling/#enable-cluster-nodepool-autoscaler","title":"Enable cluster nodepool autoscaler","text":"Azure CLI snippetaz aks nodepool update \\\n --name '<name>' \\\n --resource-group '<resource_group>' \\\n --cluster-name '<cluster_name>' \\\n --enable-cluster-autoscaler \\\n --min-count '<min_count>' \\\n --max-count '<max_count>'\n
","tags":["Azure.AKS.AutoScaling","AZR-000019"]},{"location":"en/rules/Azure.AKS.AutoScaling/#links","title":"Links","text":"Operational Excellence \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Configure AKS to automatically upgrade to newer supported AKS versions as they are made available.
","tags":["Azure.AKS.AutoUpgrade","AZR-000036"]},{"location":"en/rules/Azure.AKS.AutoUpgrade/#description","title":"Description","text":"In additional to performing manual upgrades, AKS supports auto-upgrades. Auto-upgrades reduces manual intervention required to maintain an AKS cluster.
To configure auto-upgrades select a release channel instead of the default none
. The following release channels are available:
none
- Disables auto-upgrades. The default setting.patch
- Automatically upgrade to the latest supported patch version of the current minor version.stable
- Automatically upgrade to the latest supported patch release of the recommended minor version. This is N-1 of the current AKS non-preview minor version.rapid
- Automatically upgrade to the latest supported patch of the latest support minor version.node-image
- Automatically upgrade to the latest node image version. Normally upgraded weekly.Consider enabling auto-upgrades for AKS clusters by setting an auto-upgrade channel.
","tags":["Azure.AKS.AutoUpgrade","AZR-000036"]},{"location":"en/rules/Azure.AKS.AutoUpgrade/#examples","title":"Examples","text":"","tags":["Azure.AKS.AutoUpgrade","AZR-000036"]},{"location":"en/rules/Azure.AKS.AutoUpgrade/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
properties.autoUpgradeProfile.upgradeChannel
to an upgrade channel such as stable
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2021-07-01\",\n \"name\": \"[parameters('clusterName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": \"[variables('allPools')]\",\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\",\n \"dockerBridgeCidr\": \"[variables('dockerBridgeCidr')]\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"addonProfiles\": {\n \"httpApplicationRouting\": {\n \"enabled\": false\n },\n \"azurepolicy\": {\n \"enabled\": true,\n \"config\": {\n \"version\": \"v2\"\n }\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"kubeDashboard\": {\n \"enabled\": false\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"tags\": \"[parameters('tags')]\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.AutoUpgrade","AZR-000036"]},{"location":"en/rules/Azure.AKS.AutoUpgrade/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
properties.autoUpgradeProfile.upgradeChannel
to an upgrade channel such as stable
.For example:
Azure Bicep snippetresource cluster 'Microsoft.ContainerService/managedClusters@2021-07-01' = {\n location: location\n name: clusterName\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: allPools\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n dockerBridgeCidr: dockerBridgeCidr\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n addonProfiles: {\n httpApplicationRouting: {\n enabled: false\n }\n azurepolicy: {\n enabled: true\n config: {\n version: 'v2'\n }\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n kubeDashboard: {\n enabled: false\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n tags: tags\n}\n
","tags":["Azure.AKS.AutoUpgrade","AZR-000036"]},{"location":"en/rules/Azure.AKS.AutoUpgrade/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz aks update -n '<name>' -g '<resource_group>' --auto-upgrade-channel 'stable'\n
","tags":["Azure.AKS.AutoUpgrade","AZR-000036"]},{"location":"en/rules/Azure.AKS.AutoUpgrade/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/5c345cdf-2049-47e0-b8fe-b0e96bc2df35
Reliability \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_09 \u00b7 Important
AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability.
","tags":["Azure.AKS.AvailabilityZone","AZR-000021"]},{"location":"en/rules/Azure.AKS.AvailabilityZone/#description","title":"Description","text":"AKS clusters using availability zones improve reliability and ensure availability during failure scenarios affecting a data center within a region. Nodes in one availability zone are physically separated from nodes defined in another availability zone. By spreading node pools across multiple zones, nodes in one node pool will continue running even if another zone has gone down.
","tags":["Azure.AKS.AvailabilityZone","AZR-000021"]},{"location":"en/rules/Azure.AKS.AvailabilityZone/#recommendation","title":"Recommendation","text":"Consider using availability zones for AKS clusters deployed with virtual machine scale sets.
","tags":["Azure.AKS.AvailabilityZone","AZR-000021"]},{"location":"en/rules/Azure.AKS.AvailabilityZone/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed to Azure using pre-flight and in-flight data.
This rule fails when \"availabilityZones\"
is null
, []
or not set when the AKS cluster is deployed to a virtual machine scale set and there are supported availability zones for the given region.
Configure AZURE_AKS_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
to set additional availability zones that need to be supported which are not in the existing providers for namespace Microsoft.Compute
and resource type virtualMachineScaleSets
.
# YAML: The default AZURE_AKS_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST configuration option\nconfiguration:\n AZURE_AKS_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST: []\n
","tags":["Azure.AKS.AvailabilityZone","AZR-000021"]},{"location":"en/rules/Azure.AKS.AvailabilityZone/#examples","title":"Examples","text":"","tags":["Azure.AKS.AvailabilityZone","AZR-000021"]},{"location":"en/rules/Azure.AKS.AvailabilityZone/#configure-with-azure-template","title":"Configure with Azure template","text":"To set availability zones for an AKS cluster:
properties.agentPoolProfiles[*].availabilityZones
to any or all of [\"1\", \"2\", \"3\"]
.properties.agentPoolProfiles[*].type
to VirtualMachineScaleSets
.For example:
Azure Template snippet{\n \"comments\": \"Azure Kubernetes Cluster\",\n \"apiVersion\": \"2020-12-01\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ],\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"location\": \"[parameters('location')]\",\n \"name\": \"[parameters('clusterName')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 32,\n \"count\": 3,\n \"minCount\": 3,\n \"maxCount\": 10,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D2s_v3\",\n \"osType\": \"Linux\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[variables('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\",\n \"scaleSetPriority\": \"Regular\",\n \"availabilityZones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"Standard\",\n \"serviceCidr\": \"192.168.0.0/16\",\n \"dnsServiceIP\": \"192.168.0.4\",\n \"dockerBridgeCidr\": \"172.17.0.1/16\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true,\n \"config\": {\n \"version\": \"v2\"\n }\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"kubeDashboard\": {\n \"enabled\": false\n }\n }\n }\n}\n
","tags":["Azure.AKS.AvailabilityZone","AZR-000021"]},{"location":"en/rules/Azure.AKS.AvailabilityZone/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"","tags":["Azure.AKS.AvailabilityZone","AZR-000021"]},{"location":"en/rules/Azure.AKS.AvailabilityZone/#create-aks-cluster-in-zone-1-2-and-3","title":"Create AKS Cluster in Zone 1, 2 and 3","text":"Azure CLI snippetaz aks create \\\n --resource-group '<resource_group>' \\\n --name '<cluster_name>' \\\n --generate-ssh-keys \\\n --vm-set-type VirtualMachineScaleSets \\\n --load-balancer-sku standard \\\n --node-count '<node_count>' \\\n --zones 1 2 3\n
","tags":["Azure.AKS.AvailabilityZone","AZR-000021"]},{"location":"en/rules/Azure.AKS.AvailabilityZone/#links","title":"Links","text":"Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_12 \u00b7 Important
Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes.
","tags":["Azure.AKS.AzurePolicyAddOn","AZR-000028"]},{"location":"en/rules/Azure.AKS.AzurePolicyAddOn/#description","title":"Description","text":"AKS clusters support integration with Azure Policy using an Open Policy Agent (OPA). Azure Policy integration is provided by an optional add-on that can be enabled on AKS clusters. Once enabled and Azure policies assigned, AKS clusters will enforce the configured constraints.
Examples of policies include:
Consider installing the Azure Policy Add-on for AKS clusters. Additionally, assign one or more Azure Policy definitions to security controls.
","tags":["Azure.AKS.AzurePolicyAddOn","AZR-000028"]},{"location":"en/rules/Azure.AKS.AzurePolicyAddOn/#examples","title":"Examples","text":"","tags":["Azure.AKS.AzurePolicyAddOn","AZR-000028"]},{"location":"en/rules/Azure.AKS.AzurePolicyAddOn/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
properties.addonProfiles.azurepolicy.enabled
to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2024-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 5,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\"\n },\n {\n \"name\": \"user\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 20,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"User\",\n \"osDiskType\": \"Ephemeral\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\"\n },\n \"apiServerAccessProfile\": {\n \"enablePrivateCluster\": true,\n \"enablePrivateClusterPublicFQDN\": false\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"oidcIssuerProfile\": {\n \"enabled\": true\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.AzurePolicyAddOn","AZR-000028"]},{"location":"en/rules/Azure.AKS.AzurePolicyAddOn/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
properties.addonProfiles.azurepolicy.enabled
to true
.For example:
Azure Bicep snippetresource privateCluster 'Microsoft.ContainerService/managedClusters@2024-01-01' = {\n location: location\n name: name\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: [\n {\n name: 'system'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 5\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'System'\n osDiskType: 'Ephemeral'\n }\n {\n name: 'user'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 20\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'User'\n osDiskType: 'Ephemeral'\n }\n ]\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n }\n apiServerAccessProfile: {\n enablePrivateCluster: true\n enablePrivateClusterPublicFQDN: false\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n oidcIssuerProfile: {\n enabled: true\n }\n addonProfiles: {\n azurepolicy: {\n enabled: true\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.AzurePolicyAddOn","AZR-000028"]},{"location":"en/rules/Azure.AKS.AzurePolicyAddOn/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/0a15ec92-a229-4763-bb14-0ea34a568f8d
/providers/Microsoft.Authorization/policyDefinitions/a8eff44f-8c92-45c3-a3fb-9880802d67a7
Azure Policy for AKS clusters is generally available (GA). Azure Policy for AKS Engine and Arc enabled Kubernetes are currently in preview.
","tags":["Azure.AKS.AzurePolicyAddOn","AZR-000028"]},{"location":"en/rules/Azure.AKS.AzurePolicyAddOn/#links","title":"Links","text":"Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_06 \u00b7 Important
Use Azure RBAC for Kubernetes Authorization with AKS clusters.
","tags":["Azure.AKS.AzureRBAC","AZR-000032"]},{"location":"en/rules/Azure.AKS.AzureRBAC/#description","title":"Description","text":"Azure Kubernetes Service (AKS) supports Role-based Access Control (RBAC). RBAC is supported using Kubernetes RBAC and optionally Azure RBAC.
Using authorization provided by Azure RBAC simplifies and centralizes authorization of Azure AD principals. Access to Kubernetes resource can be managed using Azure Resource Manager (ARM).
When Azure RBAC is enabled:
Consider using Azure RBAC for Kubernetes Authorization to centralize authorization of Azure AD principals.
","tags":["Azure.AKS.AzureRBAC","AZR-000032"]},{"location":"en/rules/Azure.AKS.AzureRBAC/#examples","title":"Examples","text":"","tags":["Azure.AKS.AzureRBAC","AZR-000032"]},{"location":"en/rules/Azure.AKS.AzureRBAC/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
properties.aadProfile.enableAzureRBAC
to true
.For example:
Azure Template snippet{\n \"comments\": \"Azure Kubernetes Cluster\",\n \"apiVersion\": \"2020-12-01\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ],\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"location\": \"[parameters('location')]\",\n \"name\": \"[parameters('clusterName')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 32,\n \"count\": 3,\n \"minCount\": 3,\n \"maxCount\": 10,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D2s_v3\",\n \"osType\": \"Linux\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[variables('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\",\n \"scaleSetPriority\": \"Regular\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"Standard\",\n \"serviceCidr\": \"192.168.0.0/16\",\n \"dnsServiceIP\": \"192.168.0.4\",\n \"dockerBridgeCidr\": \"172.17.0.1/16\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true,\n \"config\": {\n \"version\": \"v2\"\n }\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"kubeDashboard\": {\n \"enabled\": false\n }\n }\n }\n}\n
","tags":["Azure.AKS.AzureRBAC","AZR-000032"]},{"location":"en/rules/Azure.AKS.AzureRBAC/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz aks update -n '<name>' -g '<resource_group>' --enable-azure-rbac\n
","tags":["Azure.AKS.AzureRBAC","AZR-000032"]},{"location":"en/rules/Azure.AKS.AzureRBAC/#links","title":"Links","text":"Reliability \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_09 \u00b7 Important
AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues.
","tags":["Azure.AKS.CNISubnetSize","AZR-000020"]},{"location":"en/rules/Azure.AKS.CNISubnetSize/#description","title":"Description","text":"In addition to kubenet, AKS clusters support Azure Container Networking Interface (CNI). This enables every pod to be accessed directly from the subnet via an IP address. Each node supports a maximum number of pods, which are reserved as IP addresses. This approach requires more capacity planning ahead of time, and can result in IP address exhaustion or the need to rebuild AKS clusters into larger subnets as application workloads begin to grow.
","tags":["Azure.AKS.CNISubnetSize","AZR-000020"]},{"location":"en/rules/Azure.AKS.CNISubnetSize/#recommendation","title":"Recommendation","text":"Consider allocating a larger subnet (/23
or bigger) to your AKS cluster.
This rule applies when analyzing resources deployed to Azure using Export in-flight resource data.
","tags":["Azure.AKS.CNISubnetSize","AZR-000020"]},{"location":"en/rules/Azure.AKS.CNISubnetSize/#rule-configuration","title":"Rule configuration","text":"AZURE_AKS_CNI_MINIMUM_CLUSTER_SUBNET_SIZE
This rule fails when the CNI subnet size is smaller than /23
.
Configure AZURE_AKS_CNI_MINIMUM_CLUSTER_SUBNET_SIZE
to set the minimum AKS CNI cluster subnet size.
# YAML: The default AZURE_AKS_CNI_MINIMUM_CLUSTER_SUBNET_SIZE configuration option\nconfiguration:\n AZURE_AKS_CNI_MINIMUM_CLUSTER_SUBNET_SIZE: 23\n
","tags":["Azure.AKS.CNISubnetSize","AZR-000020"]},{"location":"en/rules/Azure.AKS.CNISubnetSize/#links","title":"Links","text":"Operational Excellence \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_09 \u00b7 Important
Enable Container insights to monitor AKS cluster workloads.
","tags":["Azure.AKS.ContainerInsights","AZR-000041"]},{"location":"en/rules/Azure.AKS.ContainerInsights/#description","title":"Description","text":"With Container insights, you can use performance charts and health status to monitor AKS clusters, nodes and pods. Container insights delivers quick, visual and actionable information: from the CPU and memory pressure of your nodes to the logs of individual Kubernetes pods.
","tags":["Azure.AKS.ContainerInsights","AZR-000041"]},{"location":"en/rules/Azure.AKS.ContainerInsights/#recommendation","title":"Recommendation","text":"Consider enabling Container insights for AKS clusters. Monitoring containers is critical, especially when running production AKS clusters at scale with multiple applications.
","tags":["Azure.AKS.ContainerInsights","AZR-000041"]},{"location":"en/rules/Azure.AKS.ContainerInsights/#examples","title":"Examples","text":"","tags":["Azure.AKS.ContainerInsights","AZR-000041"]},{"location":"en/rules/Azure.AKS.ContainerInsights/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Container insights for an AKS cluster:
properties.addonProfiles.omsAgent.enabled
to true
.properties.addonProfiles.omsAgent.config.logAnalyticsWorkspaceResourceID
.For example:
Azure Template snippet{\n \"comments\": \"Azure Kubernetes Cluster\",\n \"apiVersion\": \"2020-12-01\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ],\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"location\": \"[parameters('location')]\",\n \"name\": \"[parameters('clusterName')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 32,\n \"count\": 3,\n \"minCount\": 3,\n \"maxCount\": 10,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D2s_v3\",\n \"osType\": \"Linux\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[variables('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\",\n \"scaleSetPriority\": \"Regular\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"Standard\",\n \"serviceCidr\": \"192.168.0.0/16\",\n \"dnsServiceIP\": \"192.168.0.4\",\n \"dockerBridgeCidr\": \"172.17.0.1/16\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true,\n \"config\": {\n \"version\": \"v2\"\n }\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"kubeDashboard\": {\n \"enabled\": false\n }\n }\n }\n}\n
","tags":["Azure.AKS.ContainerInsights","AZR-000041"]},{"location":"en/rules/Azure.AKS.ContainerInsights/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"","tags":["Azure.AKS.ContainerInsights","AZR-000041"]},{"location":"en/rules/Azure.AKS.ContainerInsights/#enable-for-default-log-analytics-workspace","title":"Enable for default Log Analytics workspace","text":"Azure CLI snippetaz aks enable-addons \\\n --addons monitoring \\\n --name '<cluster_name>' \\\n --resource-group '<cluster_resource_group>'\n
","tags":["Azure.AKS.ContainerInsights","AZR-000041"]},{"location":"en/rules/Azure.AKS.ContainerInsights/#enable-for-an-existing-log-analytics-workspace","title":"Enable for an existing Log Analytics workspace","text":"Azure CLI snippetaz aks enable-addons \\\n --addons monitoring \\\n --name '<cluster_name>' \\\n --resource-group '<cluster_resource_group>' \\\n --workspace-resource-id '<workspace_id>'\n
","tags":["Azure.AKS.ContainerInsights","AZR-000041"]},{"location":"en/rules/Azure.AKS.ContainerInsights/#links","title":"Links","text":"Operational Excellence \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements.
","tags":["Azure.AKS.DNSPrefix","AZR-000040"]},{"location":"en/rules/Azure.AKS.DNSPrefix/#description","title":"Description","text":"The DNS prefix for AKS clusters has different requirements then the cluster name. The requirements for DNS prefixes are:
Consider using a DNS prefix that meets naming requirements.
","tags":["Azure.AKS.DNSPrefix","AZR-000040"]},{"location":"en/rules/Azure.AKS.DNSPrefix/#links","title":"Links","text":"Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2023_03 \u00b7 Important
Enable the Defender profile with Azure Kubernetes Service (AKS) cluster.
","tags":["Azure.AKS.DefenderProfile","AZR-000370"]},{"location":"en/rules/Azure.AKS.DefenderProfile/#description","title":"Description","text":"To collect and provide data plane protections of Microsoft Defender for Containers some additional daemon set and deployments needs to be deployed to the AKS clusters.
These components are installed when the Defender profile is enabled on the cluster.
The Defender profile deployed to each node provides the runtime protections and collects signals from nodes.
","tags":["Azure.AKS.DefenderProfile","AZR-000370"]},{"location":"en/rules/Azure.AKS.DefenderProfile/#recommendation","title":"Recommendation","text":"Consider enabling the Defender profile with Azure Kubernetes Service (AKS) cluster.
","tags":["Azure.AKS.DefenderProfile","AZR-000370"]},{"location":"en/rules/Azure.AKS.DefenderProfile/#examples","title":"Examples","text":"","tags":["Azure.AKS.DefenderProfile","AZR-000370"]},{"location":"en/rules/Azure.AKS.DefenderProfile/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable the Defender profile with Azure Kubernetes Service clusters:
properties.securityProfile.defender.securityMonitoring.enabled
to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-01-02-preview\",\n \"name\": \"[parameters('clusterName')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"securityProfile\": {\n \"defender\": {\n \"logAnalyticsWorkspaceResourceId\": \"[parameters('logAnalyticsWorkspaceResourceId')]\",\n \"securityMonitoring\": {\n \"enabled\": true\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.DefenderProfile","AZR-000370"]},{"location":"en/rules/Azure.AKS.DefenderProfile/#configure-with-bicep","title":"Configure with Bicep","text":"To enable the Defender profile with Azure Kubernetes Service clusters:
properties.securityProfile.defender.securityMonitoring.enabled
to true
.For example:
Azure Bicep snippetresource cluster 'Microsoft.ContainerService/managedClusters@2023-01-02-preview' = {\n location: location\n name: clusterName\n properties: {\n securityProfile: {\n defender: {\n logAnalyticsWorkspaceResourceId: logAnalyticsWorkspaceResourceId\n securityMonitoring: {\n enabled: true\n }\n }\n }\n } \n}\n
","tags":["Azure.AKS.DefenderProfile","AZR-000370"]},{"location":"en/rules/Azure.AKS.DefenderProfile/#notes","title":"Notes","text":"Outbound access so that the Defender profile can connect to Microsoft Defender for Cloud to send security data and events is required.
","tags":["Azure.AKS.DefenderProfile","AZR-000370"]},{"location":"en/rules/Azure.AKS.DefenderProfile/#links","title":"Links","text":"Performance Efficiency \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2022_09 \u00b7 Important
AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades.
","tags":["Azure.AKS.EphemeralOSDisk","AZR-000287"]},{"location":"en/rules/Azure.AKS.EphemeralOSDisk/#description","title":"Description","text":"By default, Azure automatically replicates the operating system disk for a virtual machine to Azure storage to avoid data loss if the VM needs to be relocated to another host. However, since containers aren't designed to have local state persisted, this behavior offers limited value while providing some drawbacks, including slower node provisioning and higher read/write latency.
By contrast, ephemeral OS disks are stored only on the host machine, just like a temporary disk. This provides lower read/write latency, along with faster node scaling and cluster upgrades.
Like the temporary disk, an ephemeral OS disk is included in the price of the virtual machine, so you incur no additional storage costs.
NB: When a user does not explicitly request managed disks for the OS, AKS will default to ephemeral OS if possible for a given node pool configuration. The rule is therefore configured with -Level Warning
as it can give inaccurate information.
When using ephemeral OS, the OS disk must fit in the VM cache. The sizes for VM cache are available in the Azure documentation in parentheses next to IO throughput (\"cache size in GiB\").
Examples:
AKS clusters should use ephemeral OS disks.
","tags":["Azure.AKS.EphemeralOSDisk","AZR-000287"]},{"location":"en/rules/Azure.AKS.EphemeralOSDisk/#examples","title":"Examples","text":"","tags":["Azure.AKS.EphemeralOSDisk","AZR-000287"]},{"location":"en/rules/Azure.AKS.EphemeralOSDisk/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy an AKS cluster that pass this rule:
properties.agentPoolProfiles.osDiskType
to Ephemeral
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2022-06-02-preview\",\n \"name\": \"[parameters('clusterName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Basic\",\n \"tier\": \"Paid\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"agentpool\",\n \"osDiskSizeGB\": 60,\n \"count\": \"[parameters('agentCount')]\",\n \"vmSize\": \"[parameters('agentVMSize')]\",\n \"osDiskType\": \"Ephemeral\",\n \"osType\": \"Linux\",\n \"mode\": \"System\"\n }\n ],\n \"linuxProfile\": {\n \"adminUsername\": \"[parameters('linuxAdminUsername')]\",\n \"ssh\": {\n \"publicKeys\": [\n {\n \"keyData\": \"[parameters('sshRSAPublicKey')]\"\n }\n ]\n }\n }\n }\n}\n
To deploy an AKS agent pool that pass this rule:
properties.osDiskType
to Ephemeral
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters/agentPools\",\n \"apiVersion\": \"2022-07-01\",\n \"name\": \"[format('{0}/{1}', parameters('clusterName'), variables('poolName'))]\",\n \"properties\": {\n \"count\": \"[variables('minCount')]\",\n \"vmSize\": \"[variables('vmSize')]\",\n \"osDiskSizeGB\": 60,\n \"osType\": \"Linux\",\n \"osDiskType\": \"Ephemeral\",\n \"maxPods\": 50,\n \"mode\": \"User\"\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ContainerService/managedClusters', parameters('clusterName'))]\"\n ]\n}\n
","tags":["Azure.AKS.EphemeralOSDisk","AZR-000287"]},{"location":"en/rules/Azure.AKS.EphemeralOSDisk/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy an AKS cluster that pass this rule:
properties.agentPoolProfiles.osDiskType
to Ephemeral
.For example:
Azure Bicep snippetresource aks 'Microsoft.ContainerService/managedClusters@2022-06-02-preview' = {\n name: clusterName\n location: location\n sku: {\n name: 'Basic'\n tier: 'Paid'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n dnsPrefix: dnsPrefix\n agentPoolProfiles: [\n {\n name: 'agentpool'\n osDiskSizeGB: 60\n count: agentCount\n vmSize: agentVMSize\n osDiskType: 'Ephemeral'\n osType: 'Linux'\n mode: 'System'\n }\n ]\n linuxProfile: {\n adminUsername: linuxAdminUsername\n ssh: {\n publicKeys: [\n {\n keyData: sshRSAPublicKey\n }\n ]\n }\n }\n }\n}\n
To deploy an AKS agent pool that pass this rule:
properties.osDiskType
to Ephemeral
.For example:
Azure Bicep snippetresource userPool 'Microsoft.ContainerService/managedClusters/agentPools@2022-07-01' = {\n parent: cluster\n name: poolName\n properties: {\n count: minCount\n vmSize: vmSize\n osDiskSizeGB: 60\n osType: 'Linux'\n osDiskType: 'Ephemeral'\n maxPods: 50\n mode: 'User'\n }\n}\n
","tags":["Azure.AKS.EphemeralOSDisk","AZR-000287"]},{"location":"en/rules/Azure.AKS.EphemeralOSDisk/#links","title":"Links","text":"Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Disable HTTP application routing add-on in AKS clusters.
","tags":["Azure.AKS.HttpAppRouting","AZR-000035"]},{"location":"en/rules/Azure.AKS.HttpAppRouting/#description","title":"Description","text":"The HTTP application routing add-on is designed to quickly expose HTTP endpoints to the public internet. This may be helpful in some limited scenarios, but should not be used in production.
When exposing application endpoints consider using an ingress controller that supports:
Azure provides a production ready ingress controller Application Gateway Ingress Controller (AGIC).
","tags":["Azure.AKS.HttpAppRouting","AZR-000035"]},{"location":"en/rules/Azure.AKS.HttpAppRouting/#recommendation","title":"Recommendation","text":"Consider disabling the HTTP application routing add-on in your AKS cluster. Also consider using Application Gateway Ingress Controller (AGIC) instead to protect application endpoints.
","tags":["Azure.AKS.HttpAppRouting","AZR-000035"]},{"location":"en/rules/Azure.AKS.HttpAppRouting/#examples","title":"Examples","text":"","tags":["Azure.AKS.HttpAppRouting","AZR-000035"]},{"location":"en/rules/Azure.AKS.HttpAppRouting/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
Properties.addonProfiles.httpApplicationRouting.enabled
to false
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2021-07-01\",\n \"name\": \"[parameters('clusterName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": \"[variables('allPools')]\",\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\",\n \"dockerBridgeCidr\": \"[variables('dockerBridgeCidr')]\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"addonProfiles\": {\n \"httpApplicationRouting\": {\n \"enabled\": false\n },\n \"azurepolicy\": {\n \"enabled\": true,\n \"config\": {\n \"version\": \"v2\"\n }\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"kubeDashboard\": {\n \"enabled\": false\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"tags\": \"[parameters('tags')]\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.HttpAppRouting","AZR-000035"]},{"location":"en/rules/Azure.AKS.HttpAppRouting/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
Properties.addonProfiles.httpApplicationRouting.enabled
to false
.For example:
Azure Bicep snippetresource cluster 'Microsoft.ContainerService/managedClusters@2021-07-01' = {\n location: location\n name: clusterName\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: allPools\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n dockerBridgeCidr: dockerBridgeCidr\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n addonProfiles: {\n httpApplicationRouting: {\n enabled: false\n }\n azurepolicy: {\n enabled: true\n config: {\n version: 'v2'\n }\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n kubeDashboard: {\n enabled: false\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n tags: tags\n}\n
","tags":["Azure.AKS.HttpAppRouting","AZR-000035"]},{"location":"en/rules/Azure.AKS.HttpAppRouting/#links","title":"Links","text":"Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2023_09 \u00b7 Important
Enforce named user accounts with RBAC assigned permissions.
","tags":["Azure.AKS.LocalAccounts","AZR-000031"]},{"location":"en/rules/Azure.AKS.LocalAccounts/#description","title":"Description","text":"AKS clusters support Role-based Access Control (RBAC) authorization. RBAC allows users, groups, and service accounts to be granted access to resources on an as needed basis. Actions performed by each identity can be logged for auditing with Kubernetes audit policies.
When a cluster is deployed, local accounts are enabled by default even when RBAC is enabled. These local accounts such as clusterAdmin
and clusterUser
are shared accounts that are not tied to an identity.
If local account credentials are used, Kubernetes auditing logs the local account instead of named accounts. Who performed an action cannot be determined from the audit logs, creating an audit log gap for privileged actions.
In an AKS cluster with local account disabled administrator will be unable to get the clusterAdmin credential. For example, using az aks get-credentials -g '<resource-group>' -n '<cluster-name>' --admin
will fail.
Consider enforcing usage of named accounts by disabling local Kubernetes account credentials. Also consider enforcing this setting using Azure Policy.
","tags":["Azure.AKS.LocalAccounts","AZR-000031"]},{"location":"en/rules/Azure.AKS.LocalAccounts/#examples","title":"Examples","text":"","tags":["Azure.AKS.LocalAccounts","AZR-000031"]},{"location":"en/rules/Azure.AKS.LocalAccounts/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
properties.disableLocalAccounts
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-07-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 5,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\"\n },\n {\n \"name\": \"user\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 20,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"User\",\n \"osDiskType\": \"Ephemeral\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"oidcIssuerProfile\": {\n \"enabled\": true\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.LocalAccounts","AZR-000031"]},{"location":"en/rules/Azure.AKS.LocalAccounts/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
properties.disableLocalAccounts
property to true
.For example:
Azure Bicep snippetresource clusterWithPools 'Microsoft.ContainerService/managedClusters@2023-07-01' = {\n location: location\n name: name\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: [\n {\n name: 'system'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 5\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'System'\n osDiskType: 'Ephemeral'\n }\n {\n name: 'user'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 20\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'User'\n osDiskType: 'Ephemeral'\n }\n ]\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n oidcIssuerProfile: {\n enabled: true\n }\n addonProfiles: {\n azurepolicy: {\n enabled: true\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.LocalAccounts","AZR-000031"]},{"location":"en/rules/Azure.AKS.LocalAccounts/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz aks update -n '<name>' -g '<resource_group>' --enable-aad --aad-admin-group-object-ids '<aad-group-id>' --disable-local\n
","tags":["Azure.AKS.LocalAccounts","AZR-000031"]},{"location":"en/rules/Azure.AKS.LocalAccounts/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/993c2fcd-2b29-49d2-9eb0-df2c3a730c32
Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_06 \u00b7 Important
Use AKS-managed Azure AD to simplify authorization and improve security.
","tags":["Azure.AKS.ManagedAAD","AZR-000029"]},{"location":"en/rules/Azure.AKS.ManagedAAD/#description","title":"Description","text":"AKS-managed integration provides an easy way to use Azure AD authorization for AKS. Previous Azure AD integration with AKS required app registration and management within Azure AD.
","tags":["Azure.AKS.ManagedAAD","AZR-000029"]},{"location":"en/rules/Azure.AKS.ManagedAAD/#recommendation","title":"Recommendation","text":"Consider configuring AKS-managed Azure AD integration for AKS clusters.
","tags":["Azure.AKS.ManagedAAD","AZR-000029"]},{"location":"en/rules/Azure.AKS.ManagedAAD/#examples","title":"Examples","text":"","tags":["Azure.AKS.ManagedAAD","AZR-000029"]},{"location":"en/rules/Azure.AKS.ManagedAAD/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
properties.aadProfile.managed
to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2021-10-01\",\n \"name\": \"[parameters('clusterName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": \"[variables('allPools')]\",\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\",\n \"dockerBridgeCidr\": \"[variables('dockerBridgeCidr')]\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"addonProfiles\": {\n \"httpApplicationRouting\": {\n \"enabled\": false\n },\n \"azurepolicy\": {\n \"enabled\": true,\n \"config\": {\n \"version\": \"v2\"\n }\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"kubeDashboard\": {\n \"enabled\": false\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n },\n \"podIdentityProfile\": {\n \"enabled\": true\n }\n },\n \"tags\": \"[parameters('tags')]\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.ManagedAAD","AZR-000029"]},{"location":"en/rules/Azure.AKS.ManagedAAD/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
properties.aadProfile.managed
to true
.For example:
Azure Bicep snippetresource cluster 'Microsoft.ContainerService/managedClusters@2021-10-01' = {\n location: location\n name: clusterName\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: allPools\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n dockerBridgeCidr: dockerBridgeCidr\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n addonProfiles: {\n httpApplicationRouting: {\n enabled: false\n }\n azurepolicy: {\n enabled: true\n config: {\n version: 'v2'\n }\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n kubeDashboard: {\n enabled: false\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n podIdentityProfile: {\n enabled: true\n }\n }\n tags: tags\n}\n
","tags":["Azure.AKS.ManagedAAD","AZR-000029"]},{"location":"en/rules/Azure.AKS.ManagedAAD/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz aks update -n '<name>' -g '<resource_group>' --enable-aad --aad-admin-group-object-ids '<group_id>'\n
","tags":["Azure.AKS.ManagedAAD","AZR-000029"]},{"location":"en/rules/Azure.AKS.ManagedAAD/#links","title":"Links","text":"Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Configure AKS clusters to use managed identities for managing cluster infrastructure.
","tags":["Azure.AKS.ManagedIdentity","AZR-000025"]},{"location":"en/rules/Azure.AKS.ManagedIdentity/#description","title":"Description","text":"During the lifecycle of an AKS cluster, the control plane configures a number of Azure resources. This includes node pools, networking, storage and other supporting services.
When making calls against the Azure REST APIs, an identity must be used to authenticate requests. The type of identity the control plane will use is configurable at cluster creation. Either a service principal or system-assigned managed identity can be used.
By default, the service principal credentials are valid for one year. Service principal credentials must be rotated before expiry to prevent issues. You can update or rotate the service principal credentials at any time.
Using a system-assigned managed identity abstracts the process of managing a service principal. The managed identity is automatically created/ removed with the cluster. Managed identities also reduce maintenance (and improve security) by automatically rotating credentials.
Separately, applications within an AKS cluster may use managed identities with AAD Pod Identity.
","tags":["Azure.AKS.ManagedIdentity","AZR-000025"]},{"location":"en/rules/Azure.AKS.ManagedIdentity/#recommendation","title":"Recommendation","text":"Consider using managed identities during AKS cluster creation. Additionally, consider redeploying the AKS cluster with managed identities instead of service principals.
","tags":["Azure.AKS.ManagedIdentity","AZR-000025"]},{"location":"en/rules/Azure.AKS.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.AKS.ManagedIdentity","AZR-000025"]},{"location":"en/rules/Azure.AKS.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-11-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 5,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\"\n },\n {\n \"name\": \"user\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 20,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"User\",\n \"osDiskType\": \"Ephemeral\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\"\n },\n \"apiServerAccessProfile\": {\n \"authorizedIPRanges\": [\n \"0.0.0.0/32\"\n ]\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"oidcIssuerProfile\": {\n \"enabled\": true\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.ManagedIdentity","AZR-000025"]},{"location":"en/rules/Azure.AKS.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource clusterWithPools 'Microsoft.ContainerService/managedClusters@2023-11-01' = {\n location: location\n name: name\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: [\n {\n name: 'system'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 5\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'System'\n osDiskType: 'Ephemeral'\n }\n {\n name: 'user'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 20\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'User'\n osDiskType: 'Ephemeral'\n }\n ]\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n }\n apiServerAccessProfile: {\n authorizedIPRanges: [\n '0.0.0.0/32'\n ]\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n oidcIssuerProfile: {\n enabled: true\n }\n addonProfiles: {\n azurepolicy: {\n enabled: true\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.ManagedIdentity","AZR-000025"]},{"location":"en/rules/Azure.AKS.ManagedIdentity/#notes","title":"Notes","text":"Managed identities can only be configured during initial cluster creation. Existing AKS clusters must be redeployed to enable managed identities.
","tags":["Azure.AKS.ManagedIdentity","AZR-000025"]},{"location":"en/rules/Azure.AKS.ManagedIdentity/#links","title":"Links","text":"Reliability \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
AKS clusters should have minimum number of system nodes for failover and updates.
","tags":["Azure.AKS.MinNodeCount","AZR-000024"]},{"location":"en/rules/Azure.AKS.MinNodeCount/#description","title":"Description","text":"Azure Kubernetes (AKS) clusters support multiple nodes and node pools. Each node is a virtual machine (VM) that runs Kubernetes components and a container runtime. A node pool is a grouping of nodes that run the same configuration. Application or system pods can be scheduled to run across multiple nodes to ensure resiliency and high availability. AKS supports configuring one or more system node pools, and zero or more user node pools.
System node pools are intended for pods that perform important management and infrastructure functions for cluster operation. This includes CoreDNS, konnectivity, and Azure Policy to name a few. The number of pods that are scheduled to run on system node pools varies based on the configuration of your cluster.
User node pools are intended for application pods. In general, schedule application workloads to run on user node pools to avoid disrupting the operation of system pods.
A minimum number of nodes in each node pool should be maintained to ensure resiliency during node failures or disruptions. Also consider how your nodes are distributed across availability zones when deploying to a supported region. Understanding that adding new nodes to a node pool can take time.
For example, in a three-node node pool:
For example, in a 2x two-node node pool:
1
, 2
. AKS will automatically spread the nodes across the two availability zones as it scales out.1
fails, 50% capacity on the remaining nodes in availability zone 2
will continue to run pods.1
will be rescheduled to run pending enough capacity.Consider configuring AKS clusters with at least three (3) agent nodes in system node pools.
","tags":["Azure.AKS.MinNodeCount","AZR-000024"]},{"location":"en/rules/Azure.AKS.MinNodeCount/#examples","title":"Examples","text":"","tags":["Azure.AKS.MinNodeCount","AZR-000024"]},{"location":"en/rules/Azure.AKS.MinNodeCount/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
To deploy AKS clusters that pass this rule:
properties.agentPoolProfiles
:minCount
property to at least 3
for node pools with auto-scale. ORcount
property to at least 3
for node pools without auto-scale. OR3
across all pools. For example, two node pools with minCount
set to 2
totalling 4 nodes.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-11-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 5,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\"\n },\n {\n \"name\": \"user\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 20,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"User\",\n \"osDiskType\": \"Ephemeral\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\"\n },\n \"apiServerAccessProfile\": {\n \"authorizedIPRanges\": [\n \"0.0.0.0/32\"\n ]\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"oidcIssuerProfile\": {\n \"enabled\": true\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.MinNodeCount","AZR-000024"]},{"location":"en/rules/Azure.AKS.MinNodeCount/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
properties.agentPoolProfiles
:minCount
property to at least 3
for node pools with auto-scale. ORcount
property to at least 3
for node pools without auto-scale. OR3
across all pools. For example, two node pools with minCount
set to 2
totalling 4 nodes.For example:
Azure Bicep snippetresource clusterWithPools 'Microsoft.ContainerService/managedClusters@2023-11-01' = {\n location: location\n name: name\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: [\n {\n name: 'system'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 5\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'System'\n osDiskType: 'Ephemeral'\n }\n {\n name: 'user'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 20\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'User'\n osDiskType: 'Ephemeral'\n }\n ]\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n }\n apiServerAccessProfile: {\n authorizedIPRanges: [\n '0.0.0.0/32'\n ]\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n oidcIssuerProfile: {\n enabled: true\n }\n addonProfiles: {\n azurepolicy: {\n enabled: true\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.MinNodeCount","AZR-000024"]},{"location":"en/rules/Azure.AKS.MinNodeCount/#notes","title":"Notes","text":"","tags":["Azure.AKS.MinNodeCount","AZR-000024"]},{"location":"en/rules/Azure.AKS.MinNodeCount/#rule-configuration","title":"Rule configuration","text":"AZURE_AKS_CLUSTER_MINIMUM_SYSTEM_NODES
This rule fails by default if you have less than three (3) nodes in the cluster across all system node pools. To change the default, set the AZURE_AKS_CLUSTER_MINIMUM_SYSTEM_NODES
configuration option.
Reliability \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2024_03 \u00b7 Important
User node pools in an AKS cluster should have a minimum number of nodes for failover and updates.
","tags":["Azure.AKS.MinUserPoolNodes","AZR-000412"]},{"location":"en/rules/Azure.AKS.MinUserPoolNodes/#description","title":"Description","text":"Azure Kubernetes (AKS) clusters support multiple nodes and node pools. Each node is a virtual machine (VM) that runs Kubernetes components and a container runtime. A node pool is a grouping of nodes that run the same configuration. Application or system pods can be scheduled to run across multiple nodes to ensure resiliency and high availability. AKS supports configuring one or more system node pools, and zero or more user node pools.
User node pools are intended for application pods.
A minimum number of nodes in each node pool should be maintained to ensure resiliency during node failures or disruptions. Resiliency in application pods is also dependent on the number of replicas and the distribution of pods across nodes. Application pods may be configured to use specific node pools based on access features such as GPU or access to storage.
Also consider how your nodes are distributed across availability zones when deploying to a supported region. Understanding that adding new nodes to a node pool can take time.
","tags":["Azure.AKS.MinUserPoolNodes","AZR-000412"]},{"location":"en/rules/Azure.AKS.MinUserPoolNodes/#recommendation","title":"Recommendation","text":"Consider configuring AKS clusters with at least three (3) agent nodes in each user node pools.
","tags":["Azure.AKS.MinUserPoolNodes","AZR-000412"]},{"location":"en/rules/Azure.AKS.MinUserPoolNodes/#examples","title":"Examples","text":"","tags":["Azure.AKS.MinUserPoolNodes","AZR-000412"]},{"location":"en/rules/Azure.AKS.MinUserPoolNodes/#configure-with-azure-template","title":"Configure with Azure template","text":"properties.agentPoolProfiles
:minCount
property to at least 3
for node pools with auto-scale. ORcount
property to at least 3
for node pools without auto-scale.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-11-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 5,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\"\n },\n {\n \"name\": \"user\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 20,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"User\",\n \"osDiskType\": \"Ephemeral\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\"\n },\n \"apiServerAccessProfile\": {\n \"authorizedIPRanges\": [\n \"0.0.0.0/32\"\n ]\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"oidcIssuerProfile\": {\n \"enabled\": true\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.MinUserPoolNodes","AZR-000412"]},{"location":"en/rules/Azure.AKS.MinUserPoolNodes/#configure-with-bicep","title":"Configure with Bicep","text":"properties.agentPoolProfiles
:minCount
property to at least 3
for node pools with auto-scale. ORcount
property to at least 3
for node pools without auto-scale.For example:
Azure Bicep snippetresource clusterWithPools 'Microsoft.ContainerService/managedClusters@2023-11-01' = {\n location: location\n name: name\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: [\n {\n name: 'system'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 5\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'System'\n osDiskType: 'Ephemeral'\n }\n {\n name: 'user'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 20\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'User'\n osDiskType: 'Ephemeral'\n }\n ]\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n }\n apiServerAccessProfile: {\n authorizedIPRanges: [\n '0.0.0.0/32'\n ]\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n oidcIssuerProfile: {\n enabled: true\n }\n addonProfiles: {\n azurepolicy: {\n enabled: true\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.MinUserPoolNodes","AZR-000412"]},{"location":"en/rules/Azure.AKS.MinUserPoolNodes/#notes","title":"Notes","text":"Node pools that are configured for spot instances are excluded from this rule. Spot instances can be used for burst capacity but do not provide a guarantee of availability.
","tags":["Azure.AKS.MinUserPoolNodes","AZR-000412"]},{"location":"en/rules/Azure.AKS.MinUserPoolNodes/#rule-configuration","title":"Rule configuration","text":"AZURE_AKS_CLUSTER_USER_POOL_MINIMUM_NODES
This rule fails by default if you have less than three (3) nodes in each user node pool. To change the default, set the AZURE_AKS_CLUSTER_USER_POOL_MINIMUM_NODES
configuration option.
AZURE_AKS_CLUSTER_USER_POOL_EXCLUDED_FROM_MINIMUM_NODES
To exclude a specific user node pool by name from this rule, set the AZURE_AKS_CLUSTER_USER_POOL_EXCLUDED_FROM_MINIMUM_NODES
configuration option.
Operational Excellence \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Azure Kubernetes Service (AKS) cluster names should meet naming requirements.
","tags":["Azure.AKS.Name","AZR-000039"]},{"location":"en/rules/Azure.AKS.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for AKS cluster names are:
Consider using names that meet AKS cluster naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.AKS.Name","AZR-000039"]},{"location":"en/rules/Azure.AKS.Name/#notes","title":"Notes","text":"This rule does not check if cluster names are unique.
Cluster DNS prefix has different naming requirements then cluster name. The requirements for DNS prefixes are:
Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Deploy AKS clusters with Network Policies enabled.
","tags":["Azure.AKS.NetworkPolicy","AZR-000027"]},{"location":"en/rules/Azure.AKS.NetworkPolicy/#description","title":"Description","text":"AKS clusters provides a platform to host containerized workloads. The running of these applications or services is orchestrated by Kubernetes. Workloads may elastic scale or change network addressing.
By default, all pods in an AKS cluster can send and receive traffic without limitations. Network Policy defines access policies for limiting network communication of pods. Using Network Policies allows network controls to be applied with the context of the workload.
For improved security, define network policy rules to control the flow of traffic. For example, only permit backend components to receive traffic from frontend components.
To use Network Policy it must be enabled at cluster deployment time. AKS supports two implementations of network policies, Azure Network Policies and Calico Network Policies. Azure Network Policies are supported by Azure support and engineering teams.
","tags":["Azure.AKS.NetworkPolicy","AZR-000027"]},{"location":"en/rules/Azure.AKS.NetworkPolicy/#recommendation","title":"Recommendation","text":"Consider deploying AKS clusters with network policy enabled to extend network segmentation into clusters.
","tags":["Azure.AKS.NetworkPolicy","AZR-000027"]},{"location":"en/rules/Azure.AKS.NetworkPolicy/#examples","title":"Examples","text":"","tags":["Azure.AKS.NetworkPolicy","AZR-000027"]},{"location":"en/rules/Azure.AKS.NetworkPolicy/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
properties.networkProfile.networkPolicy
to azure
or calico
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-11-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 5,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\"\n },\n {\n \"name\": \"user\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 20,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"User\",\n \"osDiskType\": \"Ephemeral\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\"\n },\n \"apiServerAccessProfile\": {\n \"authorizedIPRanges\": [\n \"0.0.0.0/32\"\n ]\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"oidcIssuerProfile\": {\n \"enabled\": true\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.NetworkPolicy","AZR-000027"]},{"location":"en/rules/Azure.AKS.NetworkPolicy/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
properties.networkProfile.networkPolicy
to azure
or calico
.For example:
Azure Bicep snippetresource clusterWithPools 'Microsoft.ContainerService/managedClusters@2023-11-01' = {\n location: location\n name: name\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: [\n {\n name: 'system'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 5\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'System'\n osDiskType: 'Ephemeral'\n }\n {\n name: 'user'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 20\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'User'\n osDiskType: 'Ephemeral'\n }\n ]\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n }\n apiServerAccessProfile: {\n authorizedIPRanges: [\n '0.0.0.0/32'\n ]\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n oidcIssuerProfile: {\n enabled: true\n }\n addonProfiles: {\n azurepolicy: {\n enabled: true\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.NetworkPolicy","AZR-000027"]},{"location":"en/rules/Azure.AKS.NetworkPolicy/#notes","title":"Notes","text":"Network Policy can only be set during initial cluster creation. Existing AKS clusters must be redeployed to enable Network Policy.
","tags":["Azure.AKS.NetworkPolicy","AZR-000027"]},{"location":"en/rules/Azure.AKS.NetworkPolicy/#links","title":"Links","text":"Performance Efficiency \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods.
","tags":["Azure.AKS.NodeMinPods","AZR-000018"]},{"location":"en/rules/Azure.AKS.NodeMinPods/#description","title":"Description","text":"Node pools within a Azure Kubernetes Cluster (AKS) support between 30 and 250 pods per node. The maximum number of pods for nodes within a node pool is set at creation time.
When deploying AKS clusters with kubernet networking the default maximum number of pods is 110. For Azure CNI AKS clusters, the default maximum number of pods is 30.
In many environments, deploying DaemonSets for monitoring and management tools can exhaust the CNI default.
When you are using Azure CNI, ensure that there is enough IP address space in the node pool subnet. Each pod and host requires at least one IP address. Additionally, other resources such as load balancers will consuming additional IP addresses based on configuration. The node pools subnet should have enough IP address space to accommodate the maxCount
nodes and nodes added during upgrades.
Consider deploying node pools with a minimum number of pods per node.
","tags":["Azure.AKS.NodeMinPods","AZR-000018"]},{"location":"en/rules/Azure.AKS.NodeMinPods/#examples","title":"Examples","text":"","tags":["Azure.AKS.NodeMinPods","AZR-000018"]},{"location":"en/rules/Azure.AKS.NodeMinPods/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy clusters that pass this rule:
properties.agentPoolProfiles[].maxPods
property to at least 50
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-11-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 5,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\"\n },\n {\n \"name\": \"user\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 20,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"User\",\n \"osDiskType\": \"Ephemeral\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\"\n },\n \"apiServerAccessProfile\": {\n \"authorizedIPRanges\": [\n \"0.0.0.0/32\"\n ]\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"oidcIssuerProfile\": {\n \"enabled\": true\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.NodeMinPods","AZR-000018"]},{"location":"en/rules/Azure.AKS.NodeMinPods/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy clusters that pass this rule:
properties.agentPoolProfiles[].maxPods
property to at least 50
.For example:
Azure Bicep snippetresource clusterWithPools 'Microsoft.ContainerService/managedClusters@2023-11-01' = {\n location: location\n name: name\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: [\n {\n name: 'system'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 5\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'System'\n osDiskType: 'Ephemeral'\n }\n {\n name: 'user'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 20\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'User'\n osDiskType: 'Ephemeral'\n }\n ]\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n }\n apiServerAccessProfile: {\n authorizedIPRanges: [\n '0.0.0.0/32'\n ]\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n oidcIssuerProfile: {\n enabled: true\n }\n addonProfiles: {\n azurepolicy: {\n enabled: true\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.NodeMinPods","AZR-000018"]},{"location":"en/rules/Azure.AKS.NodeMinPods/#notes","title":"Notes","text":"","tags":["Azure.AKS.NodeMinPods","AZR-000018"]},{"location":"en/rules/Azure.AKS.NodeMinPods/#rule-configuration","title":"Rule configuration","text":"Azure_AKSNodeMinimumMaxPods
By default, this rule fails when node pools have maxPods
set to less than 50. To configure this rule override the Azure_AKSNodeMinimumMaxPods
configuration value with the minimum maxPods.
Operational Excellence \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_09 \u00b7 Important
AKS clusters should collect platform diagnostic logs to monitor the state of workloads.
","tags":["Azure.AKS.PlatformLogs","AZR-000023"]},{"location":"en/rules/Azure.AKS.PlatformLogs/#description","title":"Description","text":"To capture platform logs from AKS clusters, the following diagnostic log/metric categories should be enabled:
cluster-autoscaler
kube-apiserver
kube-controller-manager
kube-scheduler
AllMetrics
Consider configuring diagnostic settings to capture platform logs from AKS clusters.
","tags":["Azure.AKS.PlatformLogs","AZR-000023"]},{"location":"en/rules/Azure.AKS.PlatformLogs/#notes","title":"Notes","text":"Configure AZURE_AKS_ENABLED_PLATFORM_LOG_CATEGORIES_LIST
to enable selective log categories. By default all log categories are selected, as shown below.
# YAML: The default AZURE_AKS_ENABLED_PLATFORM_LOG_CATEGORIES_LIST configuration option\nconfiguration:\n AZURE_AKS_ENABLED_PLATFORM_LOG_CATEGORIES_LIST: ['cluster-autoscaler', 'kube-apiserver', 'kube-controller-manager', 'kube-scheduler', 'AllMetrics']\n
","tags":["Azure.AKS.PlatformLogs","AZR-000023"]},{"location":"en/rules/Azure.AKS.PlatformLogs/#examples","title":"Examples","text":"","tags":["Azure.AKS.PlatformLogs","AZR-000023"]},{"location":"en/rules/Azure.AKS.PlatformLogs/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
cluster-autoscaler
, kube-apiserver
, kube-controller-manager
, kube-scheduler
and AllMetrics
categories.For example:
Azure Template snippet{\n \"comments\": \"Azure Kubernetes Cluster\",\n \"apiVersion\": \"2020-12-01\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ],\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"location\": \"[parameters('location')]\",\n \"name\": \"[parameters('clusterName')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 32,\n \"count\": 3,\n \"minCount\": 3,\n \"maxCount\": 10,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D2s_v3\",\n \"osType\": \"Linux\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[variables('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\",\n \"scaleSetPriority\": \"Regular\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"Standard\",\n \"serviceCidr\": \"192.168.0.0/16\",\n \"dnsServiceIP\": \"192.168.0.4\",\n \"dockerBridgeCidr\": \"172.17.0.1/16\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true,\n \"config\": {\n \"version\": \"v2\"\n }\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"kubeDashboard\": {\n \"enabled\": false\n }\n }\n },\n \"resources\": [\n {\n \"apiVersion\": \"2016-09-01\",\n \"type\": \"Microsoft.ContainerService/managedClusters/providers/diagnosticSettings\",\n \"name\": \"[concat(parameters('clusterName'), '/Microsoft.Insights/service')]\",\n \"properties\": {\n \"workspaceId\": \"[parameters('workspaceId')]\",\n \"logs\": [\n {\n \"category\": \"kube-apiserver\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n },\n {\n \"category\": \"kube-controller-manager\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n },\n {\n \"category\": \"kube-scheduler\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n },\n {\n \"category\": \"cluster-autoscaler\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n }\n ],\n \"metrics\": [\n {\n \"category\": \"AllMetrics\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n }\n ]\n }\n }\n ]\n}\n
","tags":["Azure.AKS.PlatformLogs","AZR-000023"]},{"location":"en/rules/Azure.AKS.PlatformLogs/#links","title":"Links","text":"Performance Efficiency \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Deploy AKS clusters with nodes pools based on VM scale sets.
","tags":["Azure.AKS.PoolScaleSet","AZR-000017"]},{"location":"en/rules/Azure.AKS.PoolScaleSet/#description","title":"Description","text":"When deploying AKS clusters, Azure node pool VMs can be deployed using Availability Sets or VM Scale Sets. New AKS clusters default to VM scale set node pools.
Deploying AKS clusters with scale set node pools is required for some cluster features such as multiple node pools and cluster autoscaler.
","tags":["Azure.AKS.PoolScaleSet","AZR-000017"]},{"location":"en/rules/Azure.AKS.PoolScaleSet/#recommendation","title":"Recommendation","text":"Multiple node pools and the cluster autoscaler can be used to improve the scalability and performance of a cluster while minimizing cost.
Using VM scale sets is a deployment time configuration. Consider redeploying the AKS cluster with VM Scale Sets instead of Availability Sets.
","tags":["Azure.AKS.PoolScaleSet","AZR-000017"]},{"location":"en/rules/Azure.AKS.PoolScaleSet/#examples","title":"Examples","text":"","tags":["Azure.AKS.PoolScaleSet","AZR-000017"]},{"location":"en/rules/Azure.AKS.PoolScaleSet/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy clusters that pass this rule:
properties.agentPoolProfiles[].type
property to VirtualMachineScaleSets
for each node pool.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 5,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\"\n },\n {\n \"name\": \"user\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 20,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"User\",\n \"osDiskType\": \"Ephemeral\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"oidcIssuerProfile\": {\n \"enabled\": true\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"identity\"\n ]\n}\n
","tags":["Azure.AKS.PoolScaleSet","AZR-000017"]},{"location":"en/rules/Azure.AKS.PoolScaleSet/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy clusters that pass this rule:
properties.agentPoolProfiles[].type
property to VirtualMachineScaleSets
for each node pool.For example:
Azure Bicep snippetresource clusterWithPools 'Microsoft.ContainerService/managedClusters@2023-04-01' = {\n location: location\n name: name\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: [\n {\n name: 'system'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 5\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'System'\n osDiskType: 'Ephemeral'\n }\n {\n name: 'user'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 20\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'User'\n osDiskType: 'Ephemeral'\n }\n ]\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n oidcIssuerProfile: {\n enabled: true\n }\n addonProfiles: {\n azurepolicy: {\n enabled: true\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.PoolScaleSet","AZR-000017"]},{"location":"en/rules/Azure.AKS.PoolScaleSet/#links","title":"Links","text":"Reliability \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
AKS node pools should match Kubernetes control plane version.
","tags":["Azure.AKS.PoolVersion","AZR-000016"]},{"location":"en/rules/Azure.AKS.PoolVersion/#description","title":"Description","text":"AKS supports multiple node pools. In a multi-node pool configuration, it is possible that the control plane and node pools could be running a different version of Kubernetes.
Different versions of Kubernetes between the control plane and node pools is intended as a short term option to allow rolling upgrades. For general operation, the control plane and node pool Kubernetes versions should match.
","tags":["Azure.AKS.PoolVersion","AZR-000016"]},{"location":"en/rules/Azure.AKS.PoolVersion/#recommendation","title":"Recommendation","text":"Consider upgrading node pools to match AKS control plan version.
","tags":["Azure.AKS.PoolVersion","AZR-000016"]},{"location":"en/rules/Azure.AKS.PoolVersion/#links","title":"Links","text":"Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault.
","tags":["Azure.AKS.SecretStore","AZR-000033"]},{"location":"en/rules/Azure.AKS.SecretStore/#description","title":"Description","text":"AKS clusters may need to store and retrieve secrets, keys, and certificates. The Secrets Store CSI Driver provides cluster support to integrate with Key Vault. When enabled and configured secrets, keys, and certificates can be securely accessed from a pod.
The Secrets Store CSI Driver can automatically refresh secrets and keys periodically from Key Vault. To enable this feature, enable Secrets Store CSI Driver autorotation.
Avoid storing secrets to access Azure resources. Use a Managed Identity when possible instead of cryptographic keys or a regular service principal.
","tags":["Azure.AKS.SecretStore","AZR-000033"]},{"location":"en/rules/Azure.AKS.SecretStore/#recommendation","title":"Recommendation","text":"Consider deploying AKS clusters with the Secrets Store CSI Driver and store Secrets in Key Vault.
","tags":["Azure.AKS.SecretStore","AZR-000033"]},{"location":"en/rules/Azure.AKS.SecretStore/#examples","title":"Examples","text":"","tags":["Azure.AKS.SecretStore","AZR-000033"]},{"location":"en/rules/Azure.AKS.SecretStore/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
Properties.addonProfiles.azureKeyvaultSecretsProvider.enabled
to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2021-07-01\",\n \"name\": \"[parameters('clusterName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": \"[variables('allPools')]\",\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\",\n \"dockerBridgeCidr\": \"[variables('dockerBridgeCidr')]\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"addonProfiles\": {\n \"httpApplicationRouting\": {\n \"enabled\": false\n },\n \"azurepolicy\": {\n \"enabled\": true,\n \"config\": {\n \"version\": \"v2\"\n }\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"kubeDashboard\": {\n \"enabled\": false\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"tags\": \"[parameters('tags')]\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.SecretStore","AZR-000033"]},{"location":"en/rules/Azure.AKS.SecretStore/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
Properties.addonProfiles.azureKeyvaultSecretsProvider.enabled
to true
.For example:
Azure Bicep snippetresource cluster 'Microsoft.ContainerService/managedClusters@2021-07-01' = {\n location: location\n name: clusterName\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: allPools\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n dockerBridgeCidr: dockerBridgeCidr\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n addonProfiles: {\n httpApplicationRouting: {\n enabled: false\n }\n azurepolicy: {\n enabled: true\n config: {\n version: 'v2'\n }\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n kubeDashboard: {\n enabled: false\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n tags: tags\n}\n
","tags":["Azure.AKS.SecretStore","AZR-000033"]},{"location":"en/rules/Azure.AKS.SecretStore/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz aks enable-addons --addons azure-keyvault-secrets-provider -n '<name>' -g '<resource_group>'\n
","tags":["Azure.AKS.SecretStore","AZR-000033"]},{"location":"en/rules/Azure.AKS.SecretStore/#links","title":"Links","text":"Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters.
","tags":["Azure.AKS.SecretStoreRotation","AZR-000034"]},{"location":"en/rules/Azure.AKS.SecretStoreRotation/#description","title":"Description","text":"AKS clusters may need to store and retrieve secrets, keys, and certificates. The Secrets Store CSI Driver provides cluster support to integrate with Key Vault. When enabled and configured secrets, keys, and certificates can be securely accessed from a pod.
When secrets are updated in Key Vault, pods may need to be restarted to pick up the new secrets. Enabling autorotation with the Secrets Store CSI Driver, automatically refreshed pods with new secrets. It does this by periodically polling for updates to the secrets in Key Vault. The default interval is every 2 minutes.
The Secrets Store CSI Driver does not automatically change secrets in Key Vault. Updating the secrets in Key Vault must be done by an external process, such as an Azure Function.
","tags":["Azure.AKS.SecretStoreRotation","AZR-000034"]},{"location":"en/rules/Azure.AKS.SecretStoreRotation/#recommendation","title":"Recommendation","text":"Consider enabling autorotation of Secrets Store CSI Driver secrets for AKS clusters.
","tags":["Azure.AKS.SecretStoreRotation","AZR-000034"]},{"location":"en/rules/Azure.AKS.SecretStoreRotation/#examples","title":"Examples","text":"","tags":["Azure.AKS.SecretStoreRotation","AZR-000034"]},{"location":"en/rules/Azure.AKS.SecretStoreRotation/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
Properties.addonProfiles.azureKeyvaultSecretsProvider.config.enableSecretRotation
to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2021-07-01\",\n \"name\": \"[parameters('clusterName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": \"[variables('allPools')]\",\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\",\n \"dockerBridgeCidr\": \"[variables('dockerBridgeCidr')]\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"addonProfiles\": {\n \"httpApplicationRouting\": {\n \"enabled\": false\n },\n \"azurepolicy\": {\n \"enabled\": true,\n \"config\": {\n \"version\": \"v2\"\n }\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"kubeDashboard\": {\n \"enabled\": false\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"tags\": \"[parameters('tags')]\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.SecretStoreRotation","AZR-000034"]},{"location":"en/rules/Azure.AKS.SecretStoreRotation/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
Properties.addonProfiles.azureKeyvaultSecretsProvider.config.enableSecretRotation
to true
.For example:
Azure Bicep snippetresource cluster 'Microsoft.ContainerService/managedClusters@2021-07-01' = {\n location: location\n name: clusterName\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: allPools\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n dockerBridgeCidr: dockerBridgeCidr\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n addonProfiles: {\n httpApplicationRouting: {\n enabled: false\n }\n azurepolicy: {\n enabled: true\n config: {\n version: 'v2'\n }\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n kubeDashboard: {\n enabled: false\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n tags: tags\n}\n
","tags":["Azure.AKS.SecretStoreRotation","AZR-000034"]},{"location":"en/rules/Azure.AKS.SecretStoreRotation/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz aks update --enable-secret-rotation -n '<name>' -g '<resource_group>'\n
","tags":["Azure.AKS.SecretStoreRotation","AZR-000034"]},{"location":"en/rules/Azure.AKS.SecretStoreRotation/#links","title":"Links","text":"Performance Efficiency \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU.
","tags":["Azure.AKS.StandardLB","AZR-000026"]},{"location":"en/rules/Azure.AKS.StandardLB/#description","title":"Description","text":"When deploying an AKS cluster, either a Standard or Basic load balancer SKU can be configured. A Standard load balancer SKU is required for several AKS features including:
These features improve the scalability and reliability of the cluster.
AKS clusters can not be updated to use a Standard load balancer SKU after deployment. For switch to an Standard load balancer SKU, the cluster must be redeployed.
","tags":["Azure.AKS.StandardLB","AZR-000026"]},{"location":"en/rules/Azure.AKS.StandardLB/#recommendation","title":"Recommendation","text":"Consider using Standard load balancer SKU during AKS cluster creation. Additionally, consider redeploying the AKS clusters with a Standard load balancer SKU configured.
","tags":["Azure.AKS.StandardLB","AZR-000026"]},{"location":"en/rules/Azure.AKS.StandardLB/#examples","title":"Examples","text":"","tags":["Azure.AKS.StandardLB","AZR-000026"]},{"location":"en/rules/Azure.AKS.StandardLB/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy clusters that pass this rule:
properties.networkProfile.loadBalancerSku
property to standard
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": \"[variables('allPools')]\",\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"oidcIssuerProfile\": {\n \"enabled\": true\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"identity\"\n ]\n}\n
","tags":["Azure.AKS.StandardLB","AZR-000026"]},{"location":"en/rules/Azure.AKS.StandardLB/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy clusters that pass this rule:
properties.networkProfile.loadBalancerSku
property to standard
.For example:
Azure Bicep snippetresource cluster 'Microsoft.ContainerService/managedClusters@2023-04-01' = {\n location: location\n name: name\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: allPools\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n oidcIssuerProfile: {\n enabled: true\n }\n addonProfiles: {\n azurepolicy: {\n enabled: true\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.StandardLB","AZR-000026"]},{"location":"en/rules/Azure.AKS.StandardLB/#links","title":"Links","text":"AKS clusters should have Uptime SLA enabled for a financially backed SLA.
"},{"location":"en/rules/Azure.AKS.UptimeSLA/#description","title":"Description","text":"Azure Kubernetes Service (AKS) offers two pricing tiers for cluster management.
The Standard
tier is suitable for financially backed SLA scenarios as it enables Uptime SLA by default on the cluster.
Benefits:
Consider enabling Uptime SLA for a financially backed SLA.
"},{"location":"en/rules/Azure.AKS.UptimeSLA/#examples","title":"Examples","text":""},{"location":"en/rules/Azure.AKS.UptimeSLA/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy an AKS cluster that pass this rule:
sku.tier
to Standard
.For example:
{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-02-01\",\n \"name\": \"[parameters('clusterName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Basic\",\n \"tier\": \"Standard\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"agentpool\",\n \"osDiskSizeGB\": \"[parameters('osDiskSizeGB')]\",\n \"count\": \"[parameters('agentCount')]\",\n \"vmSize\": \"[parameters('agentVMSize')]\",\n \"osType\": \"Linux\",\n \"mode\": \"System\"\n }\n ],\n \"linuxProfile\": {\n \"adminUsername\": \"[parameters('linuxAdminUsername')]\",\n \"ssh\": {\n \"publicKeys\": [\n {\n \"keyData\": \"[parameters('sshRSAPublicKey')]\"\n }\n ]\n }\n }\n }\n}\n
"},{"location":"en/rules/Azure.AKS.UptimeSLA/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy an AKS cluster that pass this rule:
sku.tier
to Standard
.For example:
resource aks 'Microsoft.ContainerService/managedClusters@2023-02-01' = {\n name: clusterName\n location: location\n sku: {\n name: 'Basic'\n tier: 'Standard'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n dnsPrefix: dnsPrefix\n agentPoolProfiles: [\n {\n name: 'agentpool'\n osDiskSizeGB: osDiskSizeGB\n count: agentCount\n vmSize: agentVMSize\n osType: 'Linux'\n mode: 'System'\n }\n ]\n linuxProfile: {\n adminUsername: linuxAdminUsername\n ssh: {\n publicKeys: [\n {\n keyData: sshRSAPublicKey\n }\n ]\n }\n }\n }\n}\n
"},{"location":"en/rules/Azure.AKS.UptimeSLA/#notes","title":"Notes","text":"Basic
and Paid
are removed in the 2023-02-01
and 2023-02-02 Preview
API version, and this will be a breaking change in API versions 2023-02-01
and 2023-02-02 Preview
or newer.
Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Deploy AKS cluster with role-based access control (RBAC) enabled.
","tags":["Azure.AKS.UseRBAC","AZR-000038"]},{"location":"en/rules/Azure.AKS.UseRBAC/#description","title":"Description","text":"AKS supports granting access to cluster resources using role-based access control (RBAC). Additionally Azure Active Directory (AAD) integration with AKS allows, RBAC to be granted based on AAD user or group.
","tags":["Azure.AKS.UseRBAC","AZR-000038"]},{"location":"en/rules/Azure.AKS.UseRBAC/#recommendation","title":"Recommendation","text":"Azure AD integration with AKS provides granular access control for Kubernetes resources using RBAC.
RBAC is a deployment time configuration. Consider redeploying the AKS cluster with RBAC enabled.
","tags":["Azure.AKS.UseRBAC","AZR-000038"]},{"location":"en/rules/Azure.AKS.UseRBAC/#links","title":"Links","text":"Reliability \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
AKS control plane and nodes pools should use a current stable release.
","tags":["Azure.AKS.Version","AZR-000015"]},{"location":"en/rules/Azure.AKS.Version/#description","title":"Description","text":"The AKS Kubernetes support policy provides support for the latest generally available (GA) three minor versions (N-2). This version support policy is based on the Kubernetes community support policy, who maintain the Kubernetes project. As the Kubernetes releases new minor versions, the old minor versions are deprecated and eventually removed from support.
When your cluster or cluster nodes are running a version that is no longer supported, you may:
Additionally, AKS provides Platform Support for subset of components following an N-3.
AKS supports a feature called cluster auto-upgrade, which can be used to reduce operational overhead of upgrading your cluster. This feature allows you to configure your cluster to automatically upgrade to the latest supported minor version of Kubernetes. When you enable cluster auto-upgrade, the control plane and node pools are upgraded to the latest supported minor version. Two channels are available for cluster auto-upgrade that maintain Kubernetes minor versions stable
and rapid
. For details on the differences between the two channels, see the references below.
You are able to define a planned maintenance window to schedule and control upgrades to your cluster. Use the Planned Maintenance window to schedule upgrades to your cluster during times of low business impact. Alternatively, consider using blue / green clusters.
","tags":["Azure.AKS.Version","AZR-000015"]},{"location":"en/rules/Azure.AKS.Version/#recommendation","title":"Recommendation","text":"Consider upgrading AKS control plane and nodes pools to the latest stable version of Kubernetes. Also consider enabling cluster auto-upgrade within a maintenance window to minimize operational overhead of cluster upgrades.
","tags":["Azure.AKS.Version","AZR-000015"]},{"location":"en/rules/Azure.AKS.Version/#examples","title":"Examples","text":"","tags":["Azure.AKS.Version","AZR-000015"]},{"location":"en/rules/Azure.AKS.Version/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
properties.autoUpgradeProfile.upgradeChannel
to rapid
or stable
. ORproperties.kubernetesVersion
to a newer stable version.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-07-01\",\n \"name\": \"[parameters('clusterName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"1.27.9\",\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": \"[variables('allPools')]\",\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\",\n \"dockerBridgeCidr\": \"[variables('dockerBridgeCidr')]\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"addonProfiles\": {\n \"httpApplicationRouting\": {\n \"enabled\": false\n },\n \"azurepolicy\": {\n \"enabled\": true,\n \"config\": {\n \"version\": \"v2\"\n }\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"kubeDashboard\": {\n \"enabled\": false\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n },\n \"podIdentityProfile\": {\n \"enabled\": true\n }\n },\n \"tags\": \"[parameters('tags')]\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.Version","AZR-000015"]},{"location":"en/rules/Azure.AKS.Version/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
properties.autoUpgradeProfile.upgradeChannel
to rapid
or stable
. ORproperties.kubernetesVersion
to a newer stable version.For example:
Azure Bicep snippetresource cluster 'Microsoft.ContainerService/managedClusters@2023-07-01' = {\n location: location\n name: clusterName\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: '1.27.9'\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: allPools\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n dockerBridgeCidr: dockerBridgeCidr\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n addonProfiles: {\n httpApplicationRouting: {\n enabled: false\n }\n azurepolicy: {\n enabled: true\n config: {\n version: 'v2'\n }\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n kubeDashboard: {\n enabled: false\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n podIdentityProfile: {\n enabled: true\n }\n }\n tags: tags\n}\n
","tags":["Azure.AKS.Version","AZR-000015"]},{"location":"en/rules/Azure.AKS.Version/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz aks update -n '<name>' -g '<resource_group>' --auto-upgrade-channel 'stable'\n
Azure CLI snippetaz aks upgrade -n '<name>' -g '<resource_group>' --kubernetes-version '1.27.9'\n
","tags":["Azure.AKS.Version","AZR-000015"]},{"location":"en/rules/Azure.AKS.Version/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetSet-AzAksCluster -Name '<name>' -ResourceGroupName '<resource_group>' -KubernetesVersion '1.27.9'\n
","tags":["Azure.AKS.Version","AZR-000015"]},{"location":"en/rules/Azure.AKS.Version/#notes","title":"Notes","text":"A list of available Kubernetes versions can be found using the az aks get-versions -o table --location <location>
CLI command.
If you must maintain AKS clusters for longer then the community support period, consider switching to Long Term Support (LTS). AKS LTS provides support for a specific Kubernetes version for a longer period of time. The first LTS release is 1.27.
","tags":["Azure.AKS.Version","AZR-000015"]},{"location":"en/rules/Azure.AKS.Version/#rule-configuration","title":"Rule configuration","text":"AZURE_AKS_CLUSTER_MINIMUM_VERSION
To configure this rule override the AZURE_AKS_CLUSTER_MINIMUM_VERSION
configuration value with the minimum Kubernetes version.
Operational Excellence \u00b7 API Management \u00b7 Rule \u00b7 2020_09 \u00b7 Awareness
API Management APIs should have a display name and description.
","tags":["Azure.APIM.APIDescriptors","AZR-000043"]},{"location":"en/rules/Azure.APIM.APIDescriptors/#description","title":"Description","text":"Each API created in API Management can have a display name and description set. Using easy to understand descriptions and metadata greatly assist identification for management and usage.
During monitoring from service provider and consumer perspectives:
This information is visible within the developer portal and exported OpenAPI definitions.
","tags":["Azure.APIM.APIDescriptors","AZR-000043"]},{"location":"en/rules/Azure.APIM.APIDescriptors/#recommendation","title":"Recommendation","text":"Consider using display name and description fields on APIs to convey intended purpose and usage. Display name and description fields should be human readable and easy to understand.
","tags":["Azure.APIM.APIDescriptors","AZR-000043"]},{"location":"en/rules/Azure.APIM.APIDescriptors/#examples","title":"Examples","text":"","tags":["Azure.APIM.APIDescriptors","AZR-000043"]},{"location":"en/rules/Azure.APIM.APIDescriptors/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management APIs that pass this rule:
properties.displayName
with a human readable name.properties.description
with an description of the APIs purpose.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service/apis\",\n \"apiVersion\": \"2021-08-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'echo-v1')]\",\n \"properties\": {\n \"displayName\": \"Echo API\",\n \"description\": \"An echo API service.\",\n \"type\": \"http\",\n \"path\": \"echo\",\n \"serviceUrl\": \"https://echo.contoso.com\",\n \"protocols\": [\n \"https\"\n ],\n \"apiVersion\": \"v1\",\n \"apiVersionSetId\": \"[resourceId('Microsoft.ApiManagement/service/apiVersionSets', parameters('name'), 'echo')]\",\n \"subscriptionRequired\": true\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ApiManagement/service', parameters('name'))]\",\n \"[resourceId('Microsoft.ApiManagement/service/apiVersionSets', parameters('name'), 'echo')]\"\n ]\n}\n
","tags":["Azure.APIM.APIDescriptors","AZR-000043"]},{"location":"en/rules/Azure.APIM.APIDescriptors/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management APIs that pass this rule:
properties.displayName
with a human readable name.properties.description
with an description of the APIs purpose.For example:
Azure Bicep snippetresource api 'Microsoft.ApiManagement/service/apis@2021-08-01' = {\n parent: service\n name: 'echo-v1'\n properties: {\n displayName: 'Echo API'\n description: 'An echo API service.'\n type: 'http'\n path: 'echo'\n serviceUrl: 'https://echo.contoso.com'\n protocols: [\n 'https'\n ]\n apiVersion: 'v1'\n apiVersionSetId: version.id\n subscriptionRequired: true\n }\n}\n
","tags":["Azure.APIM.APIDescriptors","AZR-000043"]},{"location":"en/rules/Azure.APIM.APIDescriptors/#links","title":"Links","text":"Reliability \u00b7 API Management \u00b7 Rule \u00b7 2021_12 \u00b7 Important
API management services deployed with Premium SKU should use availability zones in supported regions for high availability.
","tags":["Azure.APIM.AvailabilityZone","AZR-000052"]},{"location":"en/rules/Azure.APIM.AvailabilityZone/#description","title":"Description","text":"API management services using availability zones improve reliability and ensure availability during failure scenarios affecting a data center within a region. With zone redundancy, the gateway and the control plane of your API Management instance (Management API, developer portal, Git configuration) are replicated across data centers in physically separated zones, making it resilient to a zone failure.
","tags":["Azure.APIM.AvailabilityZone","AZR-000052"]},{"location":"en/rules/Azure.APIM.AvailabilityZone/#recommendation","title":"Recommendation","text":"Consider using availability zones for API management services deployed with Premium SKU.
","tags":["Azure.APIM.AvailabilityZone","AZR-000052"]},{"location":"en/rules/Azure.APIM.AvailabilityZone/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed to Azure using pre-flight and in-flight data.
This rule fails when \"zones\"
is null
, []
or less than two zones when API management service is deployed with Premium SKU and there are supported availability zones for the given region.
Configure AZURE_APIM_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
to set additional availability zones that need to be supported which are not in the existing providers for namespace Microsoft.ApiManagement
and resource type services
.
# YAML: The default AZURE_APIM_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST configuration option\nconfiguration:\n AZURE_APIM_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST: []\n
","tags":["Azure.APIM.AvailabilityZone","AZR-000052"]},{"location":"en/rules/Azure.APIM.AvailabilityZone/#examples","title":"Examples","text":"","tags":["Azure.APIM.AvailabilityZone","AZR-000052"]},{"location":"en/rules/Azure.APIM.AvailabilityZone/#configure-with-azure-template","title":"Configure with Azure template","text":"To set availability zones for a API management service
zones
to a minimum of two zones from [\"1\", \"2\", \"3\"]
, ensuring the number of zones match sku.capacity
.properties.additionalLocations[*].zones
to a minimum of two zones from [\"1\", \"2\", \"3\"]
, ensuring the number of zones match properties.additionalLocations[*].sku.capacity
. sku.name
and/or properties.additionalLocations[*].sku.name
to Premium
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service\",\n \"apiVersion\": \"2021-01-01-preview\",\n \"name\": \"[parameters('service_api_mgmt_test2_name')]\",\n \"location\": \"Australia East\",\n \"sku\": {\n \"name\": \"Premium\",\n \"capacity\": 3\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ],\n \"properties\": {\n \"publisherEmail\": \"john.doe@contoso.com\",\n \"publisherName\": \"contoso\",\n \"notificationSenderEmail\": \"apimgmt-noreply@mail.windowsazure.com\",\n \"hostnameConfigurations\": [\n {\n \"type\": \"Proxy\",\n \"hostName\": \"[concat(parameters('service_api_mgmt_test2_name'), '.azure-api.net')]\",\n \"negotiateClientCertificate\": false,\n \"defaultSslBinding\": true,\n \"certificateSource\": \"BuiltIn\"\n }\n ],\n \"additionalLocations\": [\n {\n \"location\": \"East US\",\n \"sku\": {\n \"name\": \"Premium\",\n \"capacity\": 3\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ],\n \"disableGateway\": false\n }\n ],\n \"customProperties\": {\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168\": \"false\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11\": \"false\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10\": \"false\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30\": \"false\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11\": \"false\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10\": \"false\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30\": \"false\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2\": \"false\"\n },\n \"virtualNetworkType\": \"None\",\n \"disableGateway\": false,\n \"apiVersionConstraint\": {}\n }\n}\n
","tags":["Azure.APIM.AvailabilityZone","AZR-000052"]},{"location":"en/rules/Azure.APIM.AvailabilityZone/#configure-with-bicep","title":"Configure with Bicep","text":"To set availability zones for a API management service
zones
to a minimum of two zones from [\"1\", \"2\", \"3\"]
, ensuring the number of zones match sku.capacity
.properties.additionalLocations[*].zones
to a minimum of two zones from [\"1\", \"2\", \"3\"]
, ensuring the number of zones match properties.additionalLocations[*].sku.capacity
. sku.name
and/or properties.additionalLocations[*].sku.name
to Premium
.For example:
Azure Bicep snippetresource service_api_mgmt_test2_name_resource 'Microsoft.ApiManagement/service@2021-01-01-preview' = {\n name: service_api_mgmt_test2_name\n location: 'Australia East'\n sku: {\n name: 'Premium'\n capacity: 3\n }\n zones: [\n '1',\n '2',\n '3'\n ]\n properties: {\n publisherEmail: 'john.doe@contoso.com'\n publisherName: 'contoso'\n notificationSenderEmail: 'apimgmt-noreply@mail.windowsazure.com'\n hostnameConfigurations: [\n {\n type: 'Proxy'\n hostName: '${service_api_mgmt_test2_name}.azure-api.net'\n negotiateClientCertificate: false\n defaultSslBinding: true\n certificateSource: 'BuiltIn'\n }\n ]\n additionalLocations: [\n {\n location: 'East US'\n sku: {\n name: 'Premium'\n capacity: 1\n }\n zones: [\n '1'\n ]\n disableGateway: false\n }\n ]\n customProperties: {\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168': 'false'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11': 'false'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10': 'false'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30': 'false'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11': 'false'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10': 'false'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30': 'false'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2': 'false'\n }\n virtualNetworkType: 'None'\n disableGateway: false\n apiVersionConstraint: {}\n }\n}\n
","tags":["Azure.APIM.AvailabilityZone","AZR-000052"]},{"location":"en/rules/Azure.APIM.AvailabilityZone/#links","title":"Links","text":"Security \u00b7 API Management \u00b7 Rule \u00b7 2023_03 \u00b7 Important
Avoid using wildcard for any configuration option in CORS policies.
","tags":["Azure.APIM.CORSPolicy","AZR-000365"]},{"location":"en/rules/Azure.APIM.CORSPolicy/#description","title":"Description","text":"The API Management cors
policy adds cross-origin resource sharing (CORS) support to an operation or APIs.
CORS is not a security feature. CORS is a W3C standard that allows a server to relax the same-origin policy enforced by modern browsers. CORS uses HTTP headers that allows API Management (and other HTTP servers) to indicate any allowed origins.
Using wildcard (*
) in any policy is overly permissive and may reduce the effectiveness of browser same-origin policy enforcement.
Consider configuring the CORS policy by specifying explicit values for each property.
","tags":["Azure.APIM.CORSPolicy","AZR-000365"]},{"location":"en/rules/Azure.APIM.CORSPolicy/#examples","title":"Examples","text":"","tags":["Azure.APIM.CORSPolicy","AZR-000365"]},{"location":"en/rules/Azure.APIM.CORSPolicy/#configure-api-management-policy","title":"Configure API Management policy","text":"To deploy API Management CORS policies that pass this rule:
cors
policies provide the exact values for all propeties.cors
policy including:allowed-origins
allowed-methods
allowed-headers
expose-headers
For example a global scoped policy:
API Management policy<policies>\n <inbound>\n <cors allow-credentials=\"true\">\n <allowed-origins>\n <origin>https://contoso.developer.azure-api.net</origin>\n <origin>https://developer.contoso.com</origin>\n </allowed-origins>\n <allowed-methods preflight-result-max-age=\"300\">\n <method>GET</method>\n <method>PUT</method>\n <method>POST</method>\n <method>PATCH</method>\n <method>HEAD</method>\n <method>DELETE</method>\n <method>OPTIONS</method>\n </allowed-methods>\n <allowed-headers>\n <header>Content-Type</header>\n <header>Cache-Control</header>\n <header>Authorization</header>\n </allowed-headers>\n </cors>\n </inbound>\n <backend>\n <forward-request />\n </backend>\n <outbound />\n <on-error />\n</policies>\n
","tags":["Azure.APIM.CORSPolicy","AZR-000365"]},{"location":"en/rules/Azure.APIM.CORSPolicy/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management CORS policies that pass this rule:
*
for any CORS policy element in properties.value
property. Instead provide exact values.For example a global scoped policy:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service/policies\",\n \"apiVersion\": \"2022-08-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'policy')]\",\n \"properties\": {\n \"value\": \"<policies><inbound><cors allow-credentials=\\\"true\\\"><allowed-origins><origin>https://contoso.developer.azure-api.net</origin><origin>https://developer.contoso.com</origin></allowed-origins><allowed-methods preflight-result-max-age=\\\"300\\\"><method>GET</method><method>PUT</method><method>POST</method><method>PATCH</method><method>HEAD</method><method>DELETE</method><method>OPTIONS</method></allowed-methods><allowed-headers><header>Content-Type</header><header>Cache-Control</header><header>Authorization</header></allowed-headers></cors></inbound><backend><forward-request /></backend><outbound /><on-error /></policies>\",\n \"format\": \"xml\"\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ApiManagement/service', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.APIM.CORSPolicy","AZR-000365"]},{"location":"en/rules/Azure.APIM.CORSPolicy/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management CORS policies that pass this rule:
*
for any CORS policy element in properties.value
property. Instead provide exact values.For example a global scoped policy:
Azure Bicep snippetresource globalPolicy 'Microsoft.ApiManagement/service/policies@2022-08-01' = {\n parent: service\n name: 'policy'\n properties: {\n value: '<policies><inbound><cors allow-credentials=\"true\"><allowed-origins><origin>https://contoso.developer.azure-api.net</origin><origin>https://developer.contoso.com</origin></allowed-origins><allowed-methods preflight-result-max-age=\"300\"><method>GET</method><method>PUT</method><method>POST</method><method>PATCH</method><method>HEAD</method><method>DELETE</method><method>OPTIONS</method></allowed-methods><allowed-headers><header>Content-Type</header><header>Cache-Control</header><header>Authorization</header></allowed-headers></cors></inbound><backend><forward-request /></backend><outbound /><on-error /></policies>'\n format: 'xml'\n }\n}\n
","tags":["Azure.APIM.CORSPolicy","AZR-000365"]},{"location":"en/rules/Azure.APIM.CORSPolicy/#notes","title":"Notes","text":"The rule only checks against rawxml
and xml
policy formatted content.
When using Azure Bicep, the policy XML can be loaded from an external file by using the loadTextContent
function.
Operational Excellence \u00b7 API Management \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Renew certificates used for custom domain bindings.
","tags":["Azure.APIM.CertificateExpiry","AZR-000051"]},{"location":"en/rules/Azure.APIM.CertificateExpiry/#description","title":"Description","text":"When custom domains are configured within an API Management service. A certificate must be assigned to allow traffic to be transmitted using TLS.
Each certificate has an expiry date, after which the certificate is not valid. After expiry, client connections to the API Management service will reject the certificate.
","tags":["Azure.APIM.CertificateExpiry","AZR-000051"]},{"location":"en/rules/Azure.APIM.CertificateExpiry/#recommendation","title":"Recommendation","text":"Consider renewing certificates before expiry to prevent service issues.
","tags":["Azure.APIM.CertificateExpiry","AZR-000051"]},{"location":"en/rules/Azure.APIM.CertificateExpiry/#notes","title":"Notes","text":"By default, this rule fails when certificates have less than 30 days remaining before expiry.
To configure this rule:
Azure_MinimumCertificateLifetime
configuration value with the minimum number of days until expiry.Security \u00b7 API Management \u00b7 Rule \u00b7 2022_03 \u00b7 Critical
API Management should not accept weak or deprecated ciphers for client or backend communication.
","tags":["Azure.APIM.Ciphers","AZR-000055"]},{"location":"en/rules/Azure.APIM.Ciphers/#description","title":"Description","text":"API Management provides support for weak or deprecated ciphers. These older versions are provided for compatibility with clients and backends but are not consider secure. These many of these ciphers are enabled by default and need to be set to 'False'
.
The following ciphers are considered weak or deprecated:
TripleDes168
TLS_RSA_WITH_AES_128_CBC_SHA
TLS_RSA_WITH_AES_256_CBC_SHA
TLS_RSA_WITH_AES_128_CBC_SHA256
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
TLS_RSA_WITH_AES_256_CBC_SHA256
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
TLS_RSA_WITH_AES_128_GCM_SHA256
Consider disabling weak or deprecated ciphers from API Management Services. Also consider disabling weak or deprecated protocols.
","tags":["Azure.APIM.Ciphers","AZR-000055"]},{"location":"en/rules/Azure.APIM.Ciphers/#examples","title":"Examples","text":"","tags":["Azure.APIM.Ciphers","AZR-000055"]},{"location":"en/rules/Azure.APIM.Ciphers/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management Services that pass this rule:
\"False\"
(as a string) within the properties.customProperties
property:Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256
For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service\",\n \"apiVersion\": \"2021-08-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\",\n \"capacity\": 1\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"publisherEmail\": \"[parameters('publisherEmail')]\",\n \"publisherName\": \"[parameters('publisherName')]\",\n \"customProperties\": {\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2\": \"True\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256\": \"False\"\n },\n \"apiVersionConstraint\": {\n \"minApiVersion\": \"2021-08-01\"\n }\n }\n}\n
","tags":["Azure.APIM.Ciphers","AZR-000055"]},{"location":"en/rules/Azure.APIM.Ciphers/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management Services that pass this rule:
'False'
(as a string) within the properties.customProperties
property:Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256
For example:
Azure Bicep snippetresource service 'Microsoft.ApiManagement/service@2021-08-01' = {\n name: name\n location: location\n sku: {\n name: 'Premium'\n capacity: 1\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n publisherEmail: publisherEmail\n publisherName: publisherName\n customProperties: {\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2': 'True'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256': 'False'\n }\n apiVersionConstraint: {\n minApiVersion: '2021-08-01'\n }\n }\n}\n
","tags":["Azure.APIM.Ciphers","AZR-000055"]},{"location":"en/rules/Azure.APIM.Ciphers/#links","title":"Links","text":"Security \u00b7 API Management \u00b7 Rule \u00b7 2023_12 \u00b7 Critical
APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs.
","tags":["Azure.APIM.DefenderCloud","AZR-000387"]},{"location":"en/rules/Azure.APIM.DefenderCloud/#description","title":"Description","text":"Microsoft Defender for APIs provides additional security for APIs published in Azure API Management. Protection is provided by analyzing onboarded APIs.
Which allows Microsoft Defender for Cloud to produce security findings. These security findings includes API recommendations and runtime threats.
The inventory and security findings for onboarded APIs is reviewed in the Defender for Cloud API Security dashboard. Defender for APIs can be enabled together with the Defender CSPM plan, offering further capabilities.
To use Microsoft Defender for APIs:
Consider onboarding APIs published in Azure API Management to Microsoft Defender for APIs.
","tags":["Azure.APIM.DefenderCloud","AZR-000387"]},{"location":"en/rules/Azure.APIM.DefenderCloud/#examples","title":"Examples","text":"","tags":["Azure.APIM.DefenderCloud","AZR-000387"]},{"location":"en/rules/Azure.APIM.DefenderCloud/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management APIs that pass this rule:
Microsoft.Security/apiCollections
sub-resource (extension resource).name
property to the name as the API.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/apiCollections\",\n \"apiVersion\": \"2022-11-20-preview\",\n \"scope\": \"[format('Microsoft.ApiManagement/service/{0}', parameters('apiManagementServiceName'))]\",\n \"name\": \"[parameters('apiName')]\"\n}\n
","tags":["Azure.APIM.DefenderCloud","AZR-000387"]},{"location":"en/rules/Azure.APIM.DefenderCloud/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management APIs that pass this rule:
Microsoft.Security/apiCollections
sub-resource (extension resource).name
property to the name as the API.For example:
Azure Bicep snippetresource apiManagementService 'Microsoft.ApiManagement/service@2022-08-01' existing = {\n name: apiManagementServiceName\n}\n\nresource onboardDefender 'Microsoft.Security/apiCollections@2022-11-20-preview' = {\n name: apiName\n scope: apiManagementService\n}\n
","tags":["Azure.APIM.DefenderCloud","AZR-000387"]},{"location":"en/rules/Azure.APIM.DefenderCloud/#notes","title":"Notes","text":"Microsoft Defender for APIs has the following limitations:
This rule may currently generate false positive results for APIs only hosted on self-hosted gateways or managed using workspaces.
","tags":["Azure.APIM.DefenderCloud","AZR-000387"]},{"location":"en/rules/Azure.APIM.DefenderCloud/#links","title":"Links","text":"Security \u00b7 API Management \u00b7 Rule \u00b7 2023_06 \u00b7 Important
Encrypt all API Management named values with Key Vault secrets.
","tags":["Azure.APIM.EncryptValues","AZR-000045"]},{"location":"en/rules/Azure.APIM.EncryptValues/#description","title":"Description","text":"Named values can be used to manage constant string values and secrets across all API configurations and policies.
Named values are a global collection of name/value pairs in each API Management instance, which may contain sensitive information.
Secret values can be stored either as encrypted strings in API Management (custom secrets) or by referencing secrets in Azure Key Vault.
All secrets in Key Vault are stored encrypted.
Using Key Vault secrets is recommended because it helps improve API Management security by:
Consider encrypting all API Management named values with Key Vault secrets.
","tags":["Azure.APIM.EncryptValues","AZR-000045"]},{"location":"en/rules/Azure.APIM.EncryptValues/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management named values that pass this rule:
properties.keyVault.secretIdentifier
property.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service/namedValues\",\n \"apiVersion\": \"2022-08-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), parameters('namedValue'))]\",\n \"properties\": {\n \"displayName\": \"[parameters('namedValue')]\",\n \"keyVault\": {\n \"identityClientId\": null,\n \"secretIdentifier\": \"[format('https://myVault.vault.azure.net/secrets/{0}', parameters('namedValue'))]\"\n },\n \"tags\": []\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ApiManagement/service', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.APIM.EncryptValues","AZR-000045"]},{"location":"en/rules/Azure.APIM.EncryptValues/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management named values that pass this rule:
properties.keyVault.secretIdentifier
property.For example:
Azure Bicep snippetresource apimNamedValue 'Microsoft.ApiManagement/service/namedValues@2022-08-01' = {\n name: namedValue\n parent: apim\n properties: {\n displayName: namedValue\n keyVault: {\n identityClientId: null\n secretIdentifier: 'https://myVault.vault.azure.net/secrets/${namedValue}'\n }\n tags: []\n }\n}\n
","tags":["Azure.APIM.EncryptValues","AZR-000045"]},{"location":"en/rules/Azure.APIM.EncryptValues/#notes","title":"Notes","text":"Using Key Vault secrets requires a system-assigned or user-assigned managed identity assigned to the API Management instance. The identity needs permissions to get and list secrets from the Key Vault. Also make sure to read the Prerequisites for key vault integration
section in links.
Security \u00b7 API Management \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Use HTTPS for communication to backend services.
","tags":["Azure.APIM.HTTPBackend","AZR-000044"]},{"location":"en/rules/Azure.APIM.HTTPBackend/#description","title":"Description","text":"When API Management connects to the backend API it can use HTTP or HTTPS. When using HTTP, sensitive information may be exposed to an untrusted party.
Additionally, when configuring backends:
Consider configuring only backend services configured with HTTPS-based URLs.
","tags":["Azure.APIM.HTTPBackend","AZR-000044"]},{"location":"en/rules/Azure.APIM.HTTPBackend/#examples","title":"Examples","text":"","tags":["Azure.APIM.HTTPBackend","AZR-000044"]},{"location":"en/rules/Azure.APIM.HTTPBackend/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy APIs that pass this rule:
properties.serviceUrl
property to a URL that starts with https://
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service/apis\",\n \"apiVersion\": \"2021-08-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'echo-v1')]\",\n \"properties\": {\n \"displayName\": \"Echo API\",\n \"description\": \"An echo API service.\",\n \"path\": \"echo\",\n \"serviceUrl\": \"https://echo.contoso.com\",\n \"protocols\": [\n \"https\"\n ],\n \"apiVersion\": \"v1\",\n \"apiVersionSetId\": \"[resourceId('Microsoft.ApiManagement/service/apiVersionSets', parameters('name'), 'echo')]\",\n \"subscriptionRequired\": true\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ApiManagement/service', parameters('name'))]\",\n \"[resourceId('Microsoft.ApiManagement/service/apiVersionSets', parameters('name'), 'echo')]\"\n ]\n}\n
To deploy API backends that pass this rule:
properties.url
property to a URL that starts with https://
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service/backends\",\n \"apiVersion\": \"2021-08-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'echo')]\",\n \"properties\": {\n \"title\": \"echo\",\n \"description\": \"A backend service for the Each API.\",\n \"protocol\": \"http\",\n \"url\": \"https://echo.contoso.com\"\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ApiManagement/service', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.APIM.HTTPBackend","AZR-000044"]},{"location":"en/rules/Azure.APIM.HTTPBackend/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy APIs that pass this rule:
properties.serviceUrl
property to a URL that starts with https://
.For example:
Azure Bicep snippetresource api 'Microsoft.ApiManagement/service/apis@2021-08-01' = {\n parent: service\n name: 'echo-v1'\n properties: {\n displayName: 'Echo API'\n description: 'An echo API service.'\n path: 'echo'\n serviceUrl: 'https://echo.contoso.com'\n protocols: [\n 'https'\n ]\n apiVersion: 'v1'\n apiVersionSetId: version.id\n subscriptionRequired: true\n }\n}\n
To deploy API backends that pass this rule:
properties.url
property to a URL that starts with https://
.For example:
Azure Bicep snippetresource backend 'Microsoft.ApiManagement/service/backends@2021-08-01' = {\n parent: service\n name: 'echo'\n properties: {\n title: 'echo'\n description: 'A backend service for the Each API.'\n protocol: 'http'\n url: 'https://echo.contoso.com'\n }\n}\n
","tags":["Azure.APIM.HTTPBackend","AZR-000044"]},{"location":"en/rules/Azure.APIM.HTTPBackend/#links","title":"Links","text":"Security \u00b7 API Management \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Enforce HTTPS for communication to API clients.
","tags":["Azure.APIM.HTTPEndpoint","AZR-000042"]},{"location":"en/rules/Azure.APIM.HTTPEndpoint/#description","title":"Description","text":"When an client connects to API Management it can use HTTP or HTTPS. Each API can be configured to accept connection for HTTP and/ or HTTPS. When using HTTP, sensitive information may be exposed to an untrusted party.
","tags":["Azure.APIM.HTTPEndpoint","AZR-000042"]},{"location":"en/rules/Azure.APIM.HTTPEndpoint/#recommendation","title":"Recommendation","text":"Consider setting the each API to only accept HTTPS connections. In the portal, this is done by configuring the HTTPS URL scheme.
","tags":["Azure.APIM.HTTPEndpoint","AZR-000042"]},{"location":"en/rules/Azure.APIM.HTTPEndpoint/#links","title":"Links","text":"Security \u00b7 API Management \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Configure managed identities to access Azure resources.
","tags":["Azure.APIM.ManagedIdentity","AZR-000053"]},{"location":"en/rules/Azure.APIM.ManagedIdentity/#description","title":"Description","text":"API Management must authenticate to access Azure resources such as Key Vault. Use Key Vault to store certificates and secrets used within API Management.
","tags":["Azure.APIM.ManagedIdentity","AZR-000053"]},{"location":"en/rules/Azure.APIM.ManagedIdentity/#recommendation","title":"Recommendation","text":"Consider configuring a managed identity for each API Management instance. Also consider using managed identities to authenticate to related Azure services.
","tags":["Azure.APIM.ManagedIdentity","AZR-000053"]},{"location":"en/rules/Azure.APIM.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.APIM.ManagedIdentity","AZR-000053"]},{"location":"en/rules/Azure.APIM.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management services that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service\",\n \"apiVersion\": \"2021-08-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\",\n \"capacity\": 1\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"publisherEmail\": \"[parameters('publisherEmail')]\",\n \"publisherName\": \"[parameters('publisherName')]\",\n \"customProperties\": {\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2\": \"True\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256\": \"False\"\n },\n \"apiVersionConstraint\": {\n \"minApiVersion\": \"2021-08-01\"\n }\n }\n}\n
","tags":["Azure.APIM.ManagedIdentity","AZR-000053"]},{"location":"en/rules/Azure.APIM.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management services that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource service 'Microsoft.ApiManagement/service@2021-08-01' = {\n name: name\n location: location\n sku: {\n name: 'Premium'\n capacity: 1\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n publisherEmail: publisherEmail\n publisherName: publisherName\n customProperties: {\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2': 'True'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256': 'False'\n }\n apiVersionConstraint: {\n minApiVersion: '2021-08-01'\n }\n }\n}\n
","tags":["Azure.APIM.ManagedIdentity","AZR-000053"]},{"location":"en/rules/Azure.APIM.ManagedIdentity/#links","title":"Links","text":"Operational Excellence \u00b7 API Management \u00b7 Rule \u00b7 2022_12 \u00b7 Important
API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer.
","tags":["Azure.APIM.MinAPIVersion","AZR-000321"]},{"location":"en/rules/Azure.APIM.MinAPIVersion/#description","title":"Description","text":"On 30 September 2023, all API versions prior to 2021-08-01 will be retired and API calls using those API versions will fail. This means you'll no longer be able to create or manage your API Management services using your existing templates, tools, scripts, and programs until they've been updated. Data operations (such as accessing the APIs or Products configured on Azure API Management) will be unaffected by this update, including after 30 September 2023.
From now through 30 September 2023, you can continue to use the templates, tools, and programs without impact. You can transition to API version 2021-08-01 or later at any point prior to 30 September 2023.
","tags":["Azure.APIM.MinAPIVersion","AZR-000321"]},{"location":"en/rules/Azure.APIM.MinAPIVersion/#recommendation","title":"Recommendation","text":"Limit control plane API calls to API Management with version '2021-08-01' or newer.
","tags":["Azure.APIM.MinAPIVersion","AZR-000321"]},{"location":"en/rules/Azure.APIM.MinAPIVersion/#examples","title":"Examples","text":"","tags":["Azure.APIM.MinAPIVersion","AZR-000321"]},{"location":"en/rules/Azure.APIM.MinAPIVersion/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management services that pass this rule:
apiVersion
property to '2021-08-01'
or newer.properties.apiVersionConstraint.minApiVersion
property to '2021-08-01'
or newer.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service\",\n \"apiVersion\": \"2021-08-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\",\n \"capacity\": 1\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"publisherEmail\": \"[parameters('publisherEmail')]\",\n \"publisherName\": \"[parameters('publisherName')]\",\n \"customProperties\": {\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2\": \"True\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256\": \"False\"\n },\n \"apiVersionConstraint\": {\n \"minApiVersion\": \"2021-08-01\"\n }\n }\n}\n
","tags":["Azure.APIM.MinAPIVersion","AZR-000321"]},{"location":"en/rules/Azure.APIM.MinAPIVersion/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management services that pass this rule:
Microsoft.ApiManagement/service@2021-08-01
or newer.properties.apiVersionConstraint.minApiVersion
property to '2021-08-01'
or newer.For example:
Azure Bicep snippetresource service 'Microsoft.ApiManagement/service@2021-08-01' = {\n name: name\n location: location\n sku: {\n name: 'Premium'\n capacity: 1\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n publisherEmail: publisherEmail\n publisherName: publisherName\n customProperties: {\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2': 'True'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256': 'False'\n }\n apiVersionConstraint: {\n minApiVersion: '2021-08-01'\n }\n }\n}\n
","tags":["Azure.APIM.MinAPIVersion","AZR-000321"]},{"location":"en/rules/Azure.APIM.MinAPIVersion/#notes","title":"Notes","text":"This rule fails:
properties.apiVersionConstraint.minApiVersion
property is not configured.properties.apiVersionConstraint.minApiVersion
property value is less than the default value 2021-08-01
and no configuration option property value is set to overwrite the default value.properties.apiVersionConstraint.minApiVersion
property value is less than the configuration option property value specified.Important Currently, depending on how you delete an API Management instance, the instance is either soft-deleted and recoverable during a retention period, or it's permanently deleted:
Configure AZURE_APIM_MIN_API_VERSION
to set the minimum API version used for control plane API calls to the API Management instance.
# YAML: The default AZURE_APIM_MIN_API_VERSION configuration option\nconfiguration:\n AZURE_APIM_MIN_API_VERSION: '2021-08-01'\n
","tags":["Azure.APIM.MinAPIVersion","AZR-000321"]},{"location":"en/rules/Azure.APIM.MinAPIVersion/#links","title":"Links","text":"Reliability \u00b7 API Management \u00b7 Rule \u00b7 2022_12 \u00b7 Important
API Management instances should use multi-region deployment to improve service availability.
","tags":["Azure.APIM.MultiRegion","AZR-000340"]},{"location":"en/rules/Azure.APIM.MultiRegion/#description","title":"Description","text":"Azure API Management supports multi-region deployment. Multi-region deployment provides availability of the API gateway in more than one region and provides service availability if one region goes offline.
This feature is currently only available for the Premium tier of API Management.
","tags":["Azure.APIM.MultiRegion","AZR-000340"]},{"location":"en/rules/Azure.APIM.MultiRegion/#recommendation","title":"Recommendation","text":"Consider deploying an API Management service across multiple regions to improve service availability.
","tags":["Azure.APIM.MultiRegion","AZR-000340"]},{"location":"en/rules/Azure.APIM.MultiRegion/#examples","title":"Examples","text":"","tags":["Azure.APIM.MultiRegion","AZR-000340"]},{"location":"en/rules/Azure.APIM.MultiRegion/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management instances that pass this rule:
properties.additionalLocations
property.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service\",\n \"apiVersion\": \"2021-12-01-preview\",\n \"name\": \"[parameters('apiManagementServiceName')]\",\n \"location\": \"eastus\",\n \"sku\": {\n \"name\": \"Premium\",\n \"capacity\": 1\n },\n \"properties\": {\n \"additionalLocations\": [\n {\n \"location\": \"westeurope\",\n \"sku\": {\n \"name\": \"Premium\",\n \"capacity\": 1\n },\n \"disableGateway\": false\n }\n ]\n }\n}\n
","tags":["Azure.APIM.MultiRegion","AZR-000340"]},{"location":"en/rules/Azure.APIM.MultiRegion/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management instances that pass this rule:
properties.additionalLocations
property.For example:
Azure Bicep snippetresource apiManagementService 'Microsoft.ApiManagement/service@2021-12-01-preview' = {\n name: apiManagementServiceName\n location: 'eastus'\n sku: {\n name: 'Premium'\n capacity: 1\n }\n properties: {\n additionalLocations: [\n {\n location: 'westeurope'\n sku: {\n name: 'Premium'\n capacity: 1\n }\n disableGateway: false\n }\n ]\n }\n}\n
","tags":["Azure.APIM.MultiRegion","AZR-000340"]},{"location":"en/rules/Azure.APIM.MultiRegion/#notes","title":"Notes","text":"This rule is only applicable for API Management instances configured with a Premium tier.
It is recommended to configure zone redundancy if the region supports it.
Virtual network settings must be configured in the added region, if networking is configured in the existing region or regions. The rule does not take this into consideration.
","tags":["Azure.APIM.MultiRegion","AZR-000340"]},{"location":"en/rules/Azure.APIM.MultiRegion/#links","title":"Links","text":"Reliability \u00b7 API Management \u00b7 Rule \u00b7 2022_12 \u00b7 Important
API Management instances should have multi-region deployment gateways enabled.
","tags":["Azure.APIM.MultiRegionGateway","AZR-000341"]},{"location":"en/rules/Azure.APIM.MultiRegionGateway/#description","title":"Description","text":"Azure API Management supports multi-region deployment. Deploy API Management in multiple locations to:
API gateways can be disabled to enabled you to test failover of your API workloads to another region. When disabled, an API gateway will not route API traffic. You should reenable API gateways after you have concluded failover testing to ensure that the API gateway is available for failover if another region becomes unavailable.
If a region goes offline, API requests are automatically routed around the failed region to the next closest gateway.
","tags":["Azure.APIM.MultiRegionGateway","AZR-000341"]},{"location":"en/rules/Azure.APIM.MultiRegionGateway/#recommendation","title":"Recommendation","text":"Consider enabling each regional API gateway location for multi-region redundancy.
","tags":["Azure.APIM.MultiRegionGateway","AZR-000341"]},{"location":"en/rules/Azure.APIM.MultiRegionGateway/#examples","title":"Examples","text":"","tags":["Azure.APIM.MultiRegionGateway","AZR-000341"]},{"location":"en/rules/Azure.APIM.MultiRegionGateway/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management instances that pass this rule:
properties.additionalLocations.disableGateway
property to false
for each additional location.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service\",\n \"apiVersion\": \"2021-12-01-preview\",\n \"name\": \"[parameters('apiManagementServiceName')]\",\n \"location\": \"eastus\",\n \"sku\": {\n \"name\": \"Premium\",\n \"capacity\": 1\n },\n \"properties\": {\n \"additionalLocations\": [\n {\n \"location\": \"westeurope\",\n \"sku\": {\n \"name\": \"Premium\",\n \"capacity\": 1\n },\n \"disableGateway\": false\n }\n ]\n }\n}\n
","tags":["Azure.APIM.MultiRegionGateway","AZR-000341"]},{"location":"en/rules/Azure.APIM.MultiRegionGateway/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management instances that pass this rule:
properties.additionalLocations.disableGateway
property to false
for each additional location.For example:
Azure Bicep snippetresource apiManagementService 'Microsoft.ApiManagement/service@2021-12-01-preview' = {\n name: apiManagementServiceName\n location: 'eastus'\n sku: {\n name: 'Premium'\n capacity: 1\n }\n properties: {\n additionalLocations: [\n {\n location: 'westeurope'\n sku: {\n name: 'Premium'\n capacity: 1\n }\n disableGateway: false\n }\n ]\n }\n}\n
","tags":["Azure.APIM.MultiRegionGateway","AZR-000341"]},{"location":"en/rules/Azure.APIM.MultiRegionGateway/#links","title":"Links","text":"Operational Excellence \u00b7 API Management \u00b7 Rule \u00b7 2020_09 \u00b7 Awareness
API Management service names should meet naming requirements.
","tags":["Azure.APIM.Name","AZR-000056"]},{"location":"en/rules/Azure.APIM.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for API Management service names are:
Consider using names that meet API Management naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.APIM.Name","AZR-000056"]},{"location":"en/rules/Azure.APIM.Name/#examples","title":"Examples","text":"","tags":["Azure.APIM.Name","AZR-000056"]},{"location":"en/rules/Azure.APIM.Name/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy services that pass this rule, consider:
minLength
and maxLength
constraint for the resource name parameter.uniqueString()
function to generate a unique name.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"name\": {\n \"type\": \"string\",\n \"minLength\": 1,\n \"maxLength\": 50,\n \"metadata\": {\n \"description\": \"The name of the resource.\"\n }\n },\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"The location resources will be deployed.\"\n }\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.ApiManagement/service\",\n \"apiVersion\": \"2022-08-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\",\n \"capacity\": 1\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"publisherEmail\": \"[parameters('publisherEmail')]\",\n \"publisherName\": \"[parameters('publisherName')]\",\n \"customProperties\": {\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2\": \"True\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256\": \"False\"\n },\n \"apiVersionConstraint\": {\n \"minApiVersion\": \"2021-08-01\"\n }\n },\n \"metadata\": {\n \"description\": \"An example API Management service.\"\n }\n }\n ]\n}\n
","tags":["Azure.APIM.Name","AZR-000056"]},{"location":"en/rules/Azure.APIM.Name/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy services that pass this rule, consider:
minLength
and maxLength
constraint for the resource name parameter.uniqueString()
function to generate a unique name.For example:
Azure Bicep snippet@minLength(1)\n@maxLength(50)\n@sys.description('The name of the resource.')\nparam name string\n\n@sys.description('The location resources will be deployed.')\nparam location string = resourceGroup().location\n\nresource service 'Microsoft.ApiManagement/service@2022-08-01' = {\n name: name\n location: location\n sku: {\n name: 'Premium'\n capacity: 1\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n publisherEmail: publisherEmail\n publisherName: publisherName\n customProperties: {\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2': 'True'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256': 'False'\n }\n apiVersionConstraint: {\n minApiVersion: '2021-08-01'\n }\n }\n}\n
","tags":["Azure.APIM.Name","AZR-000056"]},{"location":"en/rules/Azure.APIM.Name/#notes","title":"Notes","text":"This rule does not check if API Management service names are unique.
","tags":["Azure.APIM.Name","AZR-000056"]},{"location":"en/rules/Azure.APIM.Name/#links","title":"Links","text":"Security \u00b7 API Management \u00b7 Rule \u00b7 2023_06 \u00b7 Important
Base element for any policy element in a section should be configured.
","tags":["Azure.APIM.PolicyBase","AZR-000371"]},{"location":"en/rules/Azure.APIM.PolicyBase/#description","title":"Description","text":"Determine the policy evaluation order by placement of the base (<base />
) element in each section in the policy definition at each scope.
API Management supports the following scopes Global (all API), Workspace, Product, API, or Operation.
The base element inherits the policies configured in that section at the next broader (parent) scope. Otherwise inherited security or other controls may not apply. The base element can be placed before or after any policy element in a section, depending on the wanted evaluation order. However, if security controls are defined in inherited scopes it may decrease the effectiveness of these controls. For most cases, unless otherwise specified in the policy reference (such as cors
) the base element should be specified as the first element in each section.
A specific exception is at the Global scope. The Global scope does not need the base element because this is the peak scope from which all others inherit.
","tags":["Azure.APIM.PolicyBase","AZR-000371"]},{"location":"en/rules/Azure.APIM.PolicyBase/#recommendation","title":"Recommendation","text":"Consider configuring the base element for any policy element in a section.
","tags":["Azure.APIM.PolicyBase","AZR-000371"]},{"location":"en/rules/Azure.APIM.PolicyBase/#examples","title":"Examples","text":"","tags":["Azure.APIM.PolicyBase","AZR-000371"]},{"location":"en/rules/Azure.APIM.PolicyBase/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management policies that pass this rule:
properties.value
property.For example an API policy:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service/apis/policies\",\n \"apiVersion\": \"2021-08-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'policy')]\",\n \"properties\": {\n \"value\": \"<policies><inbound><base /><ip-filter action=\\\"allow\\\"><address-range from=\\\"10.1.0.1\\\" to=\\\"10.1.0.255\\\" /></ip-filter></inbound><backend><base /></backend><outbound><base /></outbound><on-error><base /></on-error></policies>\",\n \"format\": \"xml\"\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ApiManagement/service/apis', parameters('name'))]\"\n ],\n}\n
","tags":["Azure.APIM.PolicyBase","AZR-000371"]},{"location":"en/rules/Azure.APIM.PolicyBase/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management policies that pass this rule:
properties.value
property.For example an API policy:
Azure Bicep snippetresource apiName_policy 'Microsoft.ApiManagement/service/apis/policies@2021-08-01' = {\n parent: api\n name: 'policy'\n properties: {\n value: '<policies><inbound><base /><ip-filter action=\\\"allow\\\"><address-range from=\\\"10.1.0.1\\\" to=\\\"10.1.0.255\\\" /></ip-filter></inbound><backend><base /></backend><outbound><base /></outbound><on-error><base /></on-error></policies>'\n format: 'xml'\n }\n}\n
","tags":["Azure.APIM.PolicyBase","AZR-000371"]},{"location":"en/rules/Azure.APIM.PolicyBase/#notes","title":"Notes","text":"The rule only checks against rawxml
and xml
policy formatted content. Global policies are excluded since they don't benefit from the base element.
Security \u00b7 API Management \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Configure products to require approval.
","tags":["Azure.APIM.ProductApproval","AZR-000047"]},{"location":"en/rules/Azure.APIM.ProductApproval/#description","title":"Description","text":"When publishing APIs through Azure API Management (APIM), APIs can optionally be assigned to products. Products are a grouping and management construct within API Management. API Management uses products:
Requiring subscriptions on products and requiring approval is an optional security control within API Management. However, for authorizing access to APIs it is recommended to use stronger forms of authorization such as OAuth 2.0.
Using subscriptions and approval on products helps by:
If a product does not require subscriptions (called an open product):
If a product requires subscriptions, but does not require approval:
Consider configuring all API Management products to require approval.
","tags":["Azure.APIM.ProductApproval","AZR-000047"]},{"location":"en/rules/Azure.APIM.ProductApproval/#examples","title":"Examples","text":"","tags":["Azure.APIM.ProductApproval","AZR-000047"]},{"location":"en/rules/Azure.APIM.ProductApproval/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management Products that pass this rule:
properties.approvalRequired
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service/products\",\n \"apiVersion\": \"2022-08-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'echo')]\",\n \"properties\": {\n \"displayName\": \"Echo\",\n \"description\": \"Echo API services for Contoso.\",\n \"approvalRequired\": true,\n \"subscriptionRequired\": true\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ApiManagement/service', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.APIM.ProductApproval","AZR-000047"]},{"location":"en/rules/Azure.APIM.ProductApproval/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management Products that pass this rule:
properties.approvalRequired
property to true
.For example:
Azure Bicep snippetresource product 'Microsoft.ApiManagement/service/products@2022-08-01' = {\n parent: service\n name: 'echo'\n properties: {\n displayName: 'Echo'\n description: 'Echo API services for Contoso.'\n approvalRequired: true\n subscriptionRequired: true\n }\n}\n
","tags":["Azure.APIM.ProductApproval","AZR-000047"]},{"location":"en/rules/Azure.APIM.ProductApproval/#links","title":"Links","text":"API Management products should have a display name and description.
"},{"location":"en/rules/Azure.APIM.ProductDescriptors/#description","title":"Description","text":"Each product created in API Management can have a display name and description set. Using easy to understand descriptions and metadata greatly assists identification for management and usage.
During monitoring from service provider perspective:
This information is visible within the developer portal. Accurate information can be used to assist developers in understanding the purpose of a product.
"},{"location":"en/rules/Azure.APIM.ProductDescriptors/#recommendation","title":"Recommendation","text":"Consider using display name and description fields on products to convey intended purpose and usage. Display name and description fields should be human readable and easy to understand.
"},{"location":"en/rules/Azure.APIM.ProductDescriptors/#examples","title":"Examples","text":""},{"location":"en/rules/Azure.APIM.ProductDescriptors/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management Products that pass this rule:
properties.displayName
with a human readable name.properties.description
with an description of the APIs purpose.For example:
{\n \"type\": \"Microsoft.ApiManagement/service/products\",\n \"apiVersion\": \"2022-08-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'echo')]\",\n \"properties\": {\n \"displayName\": \"Echo\",\n \"description\": \"Echo API services for Contoso.\",\n \"approvalRequired\": true,\n \"subscriptionRequired\": true\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ApiManagement/service', parameters('name'))]\"\n ]\n}\n
"},{"location":"en/rules/Azure.APIM.ProductDescriptors/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management Products that pass this rule:
properties.displayName
with a human readable name.properties.description
with an description of the APIs purpose.For example:
resource product 'Microsoft.ApiManagement/service/products@2022-08-01' = {\n parent: service\n name: 'echo'\n properties: {\n displayName: 'Echo'\n description: 'Echo API services for Contoso.'\n approvalRequired: true\n subscriptionRequired: true\n }\n}\n
"},{"location":"en/rules/Azure.APIM.ProductDescriptors/#links","title":"Links","text":"Security \u00b7 API Management \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Configure products to require a subscription.
","tags":["Azure.APIM.ProductSubscription","AZR-000046"]},{"location":"en/rules/Azure.APIM.ProductSubscription/#description","title":"Description","text":"When publishing APIs through Azure API Management (APIM), APIs can optionally be assigned to products. Products are a grouping and management construct within API Management. API Management uses products:
Requiring subscriptions on products and requiring approval is an optional security control within API Management. However, for authorizing access to APIs it is recommended to use stronger forms of authorization such as OAuth 2.0.
Using subscriptions and approval on products helps by:
If a product does not require subscriptions (called an open product):
If a product requires subscriptions, but does not require approval:
Consider configuring all API Management products to require a subscription.
","tags":["Azure.APIM.ProductSubscription","AZR-000046"]},{"location":"en/rules/Azure.APIM.ProductSubscription/#examples","title":"Examples","text":"","tags":["Azure.APIM.ProductSubscription","AZR-000046"]},{"location":"en/rules/Azure.APIM.ProductSubscription/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management Products that pass this rule:
properties.subscriptionRequired
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service/products\",\n \"apiVersion\": \"2022-08-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'echo')]\",\n \"properties\": {\n \"displayName\": \"Echo\",\n \"description\": \"Echo API services for Contoso.\",\n \"approvalRequired\": true,\n \"subscriptionRequired\": true\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ApiManagement/service', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.APIM.ProductSubscription","AZR-000046"]},{"location":"en/rules/Azure.APIM.ProductSubscription/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management Products that pass this rule:
properties.subscriptionRequired
property to true
.For example:
Azure Bicep snippetresource product 'Microsoft.ApiManagement/service/products@2022-08-01' = {\n parent: service\n name: 'echo'\n properties: {\n displayName: 'Echo'\n description: 'Echo API services for Contoso.'\n approvalRequired: true\n subscriptionRequired: true\n }\n}\n
","tags":["Azure.APIM.ProductSubscription","AZR-000046"]},{"location":"en/rules/Azure.APIM.ProductSubscription/#links","title":"Links","text":"Operational Excellence \u00b7 API Management \u00b7 Rule \u00b7 2020_09 \u00b7 Important
Set legal terms for each product registered in API Management.
","tags":["Azure.APIM.ProductTerms","AZR-000050"]},{"location":"en/rules/Azure.APIM.ProductTerms/#description","title":"Description","text":"Within API Management a product is created to publish one or more APIs. For each product legal terms can be specified. When set, developers using the developer portal are required to accept the terms to subscribe to a product. Use these terms to set expectations on acceptable use of the included APIs.
Acceptance of legal terms is bypassed when an administrator creates a subscription.
","tags":["Azure.APIM.ProductTerms","AZR-000050"]},{"location":"en/rules/Azure.APIM.ProductTerms/#recommendation","title":"Recommendation","text":"Consider configuring legal terms for all products to declare acceptable use of included APIs.
","tags":["Azure.APIM.ProductTerms","AZR-000050"]},{"location":"en/rules/Azure.APIM.ProductTerms/#links","title":"Links","text":"Security \u00b7 API Management \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
API Management should only accept a minimum of TLS 1.2 for client and backend communication.
","tags":["Azure.APIM.Protocols","AZR-000054"]},{"location":"en/rules/Azure.APIM.Protocols/#description","title":"Description","text":"API Management provides support for older TLS/ SSL protocols, which are disabled by default. These older versions are provided for compatibility but are not consider secure.
The following protocols are considered weak or deprecated:
SSL 3.0
TLS 1.0
TLS 1.1
Consider configuring the minimum supported TLS version to be 1.2. Also consider disabling weak or deprecated ciphers.
","tags":["Azure.APIM.Protocols","AZR-000054"]},{"location":"en/rules/Azure.APIM.Protocols/#examples","title":"Examples","text":"","tags":["Azure.APIM.Protocols","AZR-000054"]},{"location":"en/rules/Azure.APIM.Protocols/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management Services that pass this rule:
\"False\"
(as a string) within the properties.customProperties
property:Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30
For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service\",\n \"apiVersion\": \"2021-08-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\",\n \"capacity\": 1\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"publisherEmail\": \"[parameters('publisherEmail')]\",\n \"publisherName\": \"[parameters('publisherName')]\",\n \"customProperties\": {\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2\": \"True\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256\": \"False\"\n },\n \"apiVersionConstraint\": {\n \"minApiVersion\": \"2021-08-01\"\n }\n }\n}\n
","tags":["Azure.APIM.Protocols","AZR-000054"]},{"location":"en/rules/Azure.APIM.Protocols/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management Services that pass this rule:
'False'
(as a string) within the properties.customProperties
property:Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30
For example:
Azure Bicep snippetresource service 'Microsoft.ApiManagement/service@2021-08-01' = {\n name: name\n location: location\n sku: {\n name: 'Premium'\n capacity: 1\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n publisherEmail: publisherEmail\n publisherName: publisherName\n customProperties: {\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2': 'True'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256': 'False'\n }\n apiVersionConstraint: {\n minApiVersion: '2021-08-01'\n }\n }\n}\n
","tags":["Azure.APIM.Protocols","AZR-000054"]},{"location":"en/rules/Azure.APIM.Protocols/#links","title":"Links","text":"Operational Excellence \u00b7 API Management \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Remove starter and unlimited sample products.
","tags":["Azure.APIM.SampleProducts","AZR-000048"]},{"location":"en/rules/Azure.APIM.SampleProducts/#description","title":"Description","text":"API Management includes two sample products Starter and Unlimited. Accidentally adding APIs to these sample products may expose APIs more than intended.
","tags":["Azure.APIM.SampleProducts","AZR-000048"]},{"location":"en/rules/Azure.APIM.SampleProducts/#recommendation","title":"Recommendation","text":"Consider removing starter and unlimited sample products from API Management.
","tags":["Azure.APIM.SampleProducts","AZR-000048"]},{"location":"en/rules/Azure.APIM.SampleProducts/#links","title":"Links","text":"Operational Excellence \u00b7 App Service Environment \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2.
","tags":["Azure.ASE.MigrateV3","AZR-000319"]},{"location":"en/rules/Azure.ASE.MigrateV3/#description","title":"Description","text":"The classic App Service Environment version 1 (ASEv1) and version 2 (ASEv2) will be retired on August 31, 2024. To avoid service disruption, migrate to App Service Environment version 3 (ASEv3). App Service Environment v3 has advantages and feature differences that provide enhanced support for your workloads and can reduce overall costs.
App Service Environment v3 differs from earlier versions in the following ways:
A few features that were available in earlier versions of App Service Environment aren't available in App Service Environment v3. For example, you can no longer do the following:
Classic App Service Environments should migrate to App Service Environment v3.
","tags":["Azure.ASE.MigrateV3","AZR-000319"]},{"location":"en/rules/Azure.ASE.MigrateV3/#examples","title":"Examples","text":"","tags":["Azure.ASE.MigrateV3","AZR-000319"]},{"location":"en/rules/Azure.ASE.MigrateV3/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy app service environments pass this rule:
kind
to 'ASEV3'
.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"metadata\": {\n \"_generator\": {\n \"name\": \"bicep\",\n \"version\": \"0.11.1.770\",\n \"templateHash\": \"13381170219553357893\"\n }\n },\n \"parameters\": {\n \"aseName\": {\n \"type\": \"string\",\n \"defaultValue\": \"001-ase\",\n \"metadata\": {\n \"description\": \"Name of the App Service Environment\"\n }\n },\n \"virtualNetworkName\": {\n \"type\": \"string\",\n \"defaultValue\": \"ase-001-vnet\",\n \"metadata\": {\n \"description\": \"The name of the vnet\"\n }\n },\n \"vnetResourceGroupName\": {\n \"type\": \"string\",\n \"defaultValue\": \"ase-001-rg\",\n \"metadata\": {\n \"description\": \"The resource group name that contains the vnet\"\n }\n },\n \"subnetName\": {\n \"type\": \"string\",\n \"defaultValue\": \"ase-001-sn\",\n \"metadata\": {\n \"description\": \"Subnet name that will contain the App Service Environment\"\n }\n },\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"Location for the resources\"\n }\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Web/hostingEnvironments\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"[parameters('aseName')]\",\n \"location\": \"[parameters('location')]\",\n \"kind\": \"ASEV3\",\n \"tags\": {\n \"displayName\": \"App Service Environment\",\n \"usage\": \"Hosting awesome applications\",\n \"owner\": \"Platform\"\n },\n \"properties\": {\n \"virtualNetwork\": {\n \"id\": \"[extensionResourceId(format('/subscriptions/{0}/resourceGroups/{1}', subscription().subscriptionId, parameters('vnetResourceGroupName')), 'Microsoft.Network/virtualNetworks/subnets', parameters('virtualNetworkName'), parameters('subnetName'))]\"\n }\n }\n }\n ]\n}\n
","tags":["Azure.ASE.MigrateV3","AZR-000319"]},{"location":"en/rules/Azure.ASE.MigrateV3/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy app service environments pass this rule:
kind
to 'ASEV3'
.For example:
Azure Bicep snippet@description('Name of the App Service Environment')\nparam aseName string = '001-ase'\n\n@description('The name of the vnet')\nparam virtualNetworkName string = 'ase-001-vnet'\n\n@description('The resource group name that contains the vnet')\nparam vnetResourceGroupName string = 'ase-001-rg'\n\n@description('Subnet name that will contain the App Service Environment')\nparam subnetName string = 'ase-001-sn'\n\n@description('Location for the resources')\nparam location string = resourceGroup().location\n\nresource virtualNetwork 'Microsoft.Network/virtualNetworks@2022-05-01' existing = {\n scope: resourceGroup(vnetResourceGroupName)\n name: virtualNetworkName\n}\n\nresource subnet 'Microsoft.Network/virtualNetworks/subnets@2022-05-01' existing = {\n parent: virtualNetwork\n name: subnetName\n}\n\nresource hostingEnvironment 'Microsoft.Web/hostingEnvironments@2022-03-01' = {\n name: aseName\n location: location\n kind: 'ASEV3'\n tags: {\n displayName: 'App Service Environment'\n usage: 'Hosting awesome applications'\n owner: 'Platform'\n }\n properties: {\n virtualNetwork: {\n id: subnet.id\n }\n }\n}\n
","tags":["Azure.ASE.MigrateV3","AZR-000319"]},{"location":"en/rules/Azure.ASE.MigrateV3/#links","title":"Links","text":"Operational Excellence \u00b7 Application Security Group \u00b7 Rule \u00b7 2021_12 \u00b7 Awareness
Application Security Group (ASG) names should meet naming requirements.
","tags":["Azure.ASG.Name","AZR-000085"]},{"location":"en/rules/Azure.ASG.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for ASG names are:
Consider using names that meet Application Security Group naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.ASG.Name","AZR-000085"]},{"location":"en/rules/Azure.ASG.Name/#examples","title":"Examples","text":"","tags":["Azure.ASG.Name","AZR-000085"]},{"location":"en/rules/Azure.ASG.Name/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Application Security Groups that pass this rule:
name
to a value that meets the requirements.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/applicationSecurityGroups\",\n \"apiVersion\": \"2022-01-01\",\n \"name\": \"[parameters('asgName')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {}\n}\n
","tags":["Azure.ASG.Name","AZR-000085"]},{"location":"en/rules/Azure.ASG.Name/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Application Security Groups that pass this rule:
name
to a value that meets the requirements.For example:
Azure Bicep snippetresource asg 'Microsoft.Network/applicationSecurityGroups@2022-01-01' = {\n name: asgName\n location:location\n properties: {}\n}\n
","tags":["Azure.ASG.Name","AZR-000085"]},{"location":"en/rules/Azure.ASG.Name/#notes","title":"Notes","text":"This rule does not check if ASG names are unique.
","tags":["Azure.ASG.Name","AZR-000085"]},{"location":"en/rules/Azure.ASG.Name/#links","title":"Links","text":"Security \u00b7 App Configuration \u00b7 Rule \u00b7 2022_09 \u00b7 Important
Ensure app configuration store audit diagnostic logs are enabled.
","tags":["Azure.AppConfig.AuditLogs","AZR-000311"]},{"location":"en/rules/Azure.AppConfig.AuditLogs/#description","title":"Description","text":"To capture logs that record interactions with data or the settings of the app configuration store, diagnostic settings must be configured.
When configuring diagnostic settings, enable one of the following:
Audit
category.audit
category group.allLogs
category group.Management operations for App Configuration Store are captured automatically within Azure Activity Logs.
","tags":["Azure.AppConfig.AuditLogs","AZR-000311"]},{"location":"en/rules/Azure.AppConfig.AuditLogs/#recommendation","title":"Recommendation","text":"Consider configuring diagnostic settings to record interactions with data or the settings of the App Configuration Store.
","tags":["Azure.AppConfig.AuditLogs","AZR-000311"]},{"location":"en/rules/Azure.AppConfig.AuditLogs/#examples","title":"Examples","text":"","tags":["Azure.AppConfig.AuditLogs","AZR-000311"]},{"location":"en/rules/Azure.AppConfig.AuditLogs/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy an App Configuration Store that pass this rule:
Audit
category or audit
category group or allLogs
category group.For example:
Azure Template snippet{\n \"parameters\": {\n \"name\": {\n \"type\": \"string\",\n \"metadata\": {\n \"description\": \"The name of the App Configuration Store.\"\n }\n },\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"The location resources will be deployed.\"\n }\n },\n \"workspaceId\": {\n \"type\": \"string\",\n \"metadata\": {\n \"description\": \"The resource id of the Log Analytics workspace to send diagnostic logs to.\"\n }\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.AppConfiguration/configurationStores\",\n \"apiVersion\": \"2022-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"enablePurgeProtection\": true\n }\n },\n {\n \"type\": \"Microsoft.Insights/diagnosticSettings\",\n \"apiVersion\": \"2021-05-01-preview\",\n \"scope\": \"[format('Microsoft.AppConfiguration/configurationStores/{0}', parameters('name'))]\",\n \"name\": \"[format('{0}-diagnostic', parameters('name'))]\",\n \"properties\": {\n \"logs\": [\n {\n \"categoryGroup\": \"audit\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 90,\n \"enabled\": true\n }\n }\n ],\n \"workspaceId\": \"[parameters('workspaceId')]\"\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.AppConfiguration/configurationStores', parameters('name'))]\"\n ]\n }\n ]\n}\n
","tags":["Azure.AppConfig.AuditLogs","AZR-000311"]},{"location":"en/rules/Azure.AppConfig.AuditLogs/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy an App Configuration Store that pass this rule:
Audit
category or audit
category group or allLogs
category group.For example:
Azure Bicep snippetresource store 'Microsoft.AppConfiguration/configurationStores@2023-03-01' = {\n name: name\n location: location\n sku: {\n name: 'standard'\n }\n properties: {\n disableLocalAuth: true\n enablePurgeProtection: true\n publicNetworkAccess: 'Disabled'\n }\n}\n\nresource diagnostic 'Microsoft.Insights/diagnosticSettings@2021-05-01-preview' = {\n scope: store\n name: '${name}-diagnostic'\n properties: {\n logs: [\n {\n categoryGroup: 'audit'\n enabled: true\n retentionPolicy: {\n days: 90\n enabled: true\n }\n }\n ]\n workspaceId: workspaceId\n }\n}\n
","tags":["Azure.AppConfig.AuditLogs","AZR-000311"]},{"location":"en/rules/Azure.AppConfig.AuditLogs/#configure-with-bicep-public-registry","title":"Configure with Bicep Public Registry","text":"To deploy an App Configuration Store that pass this rule:
diagnosticSettingsProperties.logs
parameter.Audit
category or audit
category group or allLogs
category group.For example:
Azure Bicep snippetmodule store 'br/public:app/app-configuration:1.1.1' = {\n name: 'store'\n params: {\n skuName: 'Standard'\n disableLocalAuth: true\n enablePurgeProtection: true\n publicNetworkAccess: 'Disabled'\n diagnosticSettingsProperties: {\n diagnosticReceivers: {\n workspaceId: workspaceId\n }\n logs: [\n {\n categoryGroup: 'audit'\n enabled: true\n retentionPolicy: {\n days: 90\n enabled: true\n }\n }\n ]\n }\n }\n}\n
","tags":["Azure.AppConfig.AuditLogs","AZR-000311"]},{"location":"en/rules/Azure.AppConfig.AuditLogs/#links","title":"Links","text":"Security \u00b7 App Configuration \u00b7 Rule \u00b7 2022_09 \u00b7 Important
Authenticate App Configuration clients with Entra ID identities.
","tags":["Azure.AppConfig.DisableLocalAuth","AZR-000291"]},{"location":"en/rules/Azure.AppConfig.DisableLocalAuth/#description","title":"Description","text":"Every request to an Azure App Configuration resource must be authenticated. App Configuration supports authenticating requests using either Entra ID (previously Azure AD) identities or access keys. Using Entra ID identities:
To require clients to use Entra ID to authenticate requests, you can disable the usage of access keys for an Azure App Configuration resource.
When you disable access key authentication for an Azure App Configuration resource, any existing access keys for that resource are deleted. Any subsequent requests to the resource using the previously existing access keys will be rejected. Only requests that are authenticated using Entra ID will succeed.
","tags":["Azure.AppConfig.DisableLocalAuth","AZR-000291"]},{"location":"en/rules/Azure.AppConfig.DisableLocalAuth/#recommendation","title":"Recommendation","text":"Consider only using Entra ID identities to access App Configuration data. Then disable authentication based on access keys or SAS tokens.
","tags":["Azure.AppConfig.DisableLocalAuth","AZR-000291"]},{"location":"en/rules/Azure.AppConfig.DisableLocalAuth/#examples","title":"Examples","text":"","tags":["Azure.AppConfig.DisableLocalAuth","AZR-000291"]},{"location":"en/rules/Azure.AppConfig.DisableLocalAuth/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy configuration stores that pass this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.AppConfiguration/configurationStores\",\n \"apiVersion\": \"2023-03-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"enablePurgeProtection\": true,\n \"publicNetworkAccess\": \"Disabled\"\n }\n}\n
","tags":["Azure.AppConfig.DisableLocalAuth","AZR-000291"]},{"location":"en/rules/Azure.AppConfig.DisableLocalAuth/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy configuration stores that pass this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Bicep snippetresource store 'Microsoft.AppConfiguration/configurationStores@2023-03-01' = {\n name: name\n location: location\n sku: {\n name: 'standard'\n }\n properties: {\n disableLocalAuth: true\n enablePurgeProtection: true\n publicNetworkAccess: 'Disabled'\n }\n}\n
","tags":["Azure.AppConfig.DisableLocalAuth","AZR-000291"]},{"location":"en/rules/Azure.AppConfig.DisableLocalAuth/#configure-with-bicep-public-registry","title":"Configure with Bicep Public Registry","text":"To deploy App Configuration Stores that pass this rule:
params.disableLocalAuth
parameter to true
.For example:
Azure Bicep snippetmodule br_public_store 'br/public:app/app-configuration:1.1.2' = {\n name: 'store'\n params: {\n skuName: 'Standard'\n disableLocalAuth: true\n enablePurgeProtection: true\n publicNetworkAccess: 'Disabled'\n replicas: [\n {\n name: 'eastus'\n location: 'eastus'\n }\n ]\n }\n}\n
","tags":["Azure.AppConfig.DisableLocalAuth","AZR-000291"]},{"location":"en/rules/Azure.AppConfig.DisableLocalAuth/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
Name Resource App Configuration stores should have local authentication methods disabled/providers/Microsoft.Authorization/policyDefinitions/b08ab3ca-1062-4db3-8803-eec9cae605d6
Configure App Configuration stores to disable local authentication methods /providers/Microsoft.Authorization/policyDefinitions/72bc14af-4ab8-43af-b4e4-38e7983f9a1f
","tags":["Azure.AppConfig.DisableLocalAuth","AZR-000291"]},{"location":"en/rules/Azure.AppConfig.DisableLocalAuth/#links","title":"Links","text":"Reliability \u00b7 App Configuration \u00b7 Rule \u00b7 2023_12 \u00b7 Important
Replicate app configuration store across all points of presence for an application.
","tags":["Azure.AppConfig.GeoReplica","AZR-000312"]},{"location":"en/rules/Azure.AppConfig.GeoReplica/#description","title":"Description","text":"By default, an app configuration store is stored and maintained in a single region.
The app configuration geo-replication feature allows you to replicate your configuration store to additional regions. Each new replica will be in a different region with a new endpoint for your applications to send requests to. The original endpoint of your configuration store is called the origin. The origin can't be removed, but otherwise behaves like any replica.
Replicating your configuration store adds the following benefits:
When considering where to place replicas, consider the following; where does the application run from?
Consider replicating app configuration stores to improve resiliency to region outages.
","tags":["Azure.AppConfig.GeoReplica","AZR-000312"]},{"location":"en/rules/Azure.AppConfig.GeoReplica/#examples","title":"Examples","text":"","tags":["Azure.AppConfig.GeoReplica","AZR-000312"]},{"location":"en/rules/Azure.AppConfig.GeoReplica/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy App Configuration Stores that pass this rule:
sku.name
to Standard
(required for geo-replication).location
on replica sub-resource to a different location than the app configuration store.For example:
Azure Template snippet{\n \"resources\": [\n {\n \"type\": \"Microsoft.AppConfiguration/configurationStores\",\n \"apiVersion\": \"2023-03-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"enablePurgeProtection\": true,\n \"publicNetworkAccess\": \"Disabled\"\n }\n },\n {\n \"type\": \"Microsoft.AppConfiguration/configurationStores/replicas\",\n \"apiVersion\": \"2023-03-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), parameters('replicaName'))]\",\n \"location\": \"[parameters('replicaLocation')]\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.AppConfiguration/configurationStores', parameters('name'))]\"\n ]\n }\n ]\n}\n
","tags":["Azure.AppConfig.GeoReplica","AZR-000312"]},{"location":"en/rules/Azure.AppConfig.GeoReplica/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Configuration Stores that pass this rule:
sku.name
to Standard
(required for geo-replication).location
on replica sub-resource to a different location than the app configuration store.For example:
Azure Bicep snippetresource store 'Microsoft.AppConfiguration/configurationStores@2023-03-01' = {\n name: name\n location: location\n sku: {\n name: 'standard'\n }\n properties: {\n disableLocalAuth: true\n enablePurgeProtection: true\n publicNetworkAccess: 'Disabled'\n }\n}\n\nresource replica 'Microsoft.AppConfiguration/configurationStores/replicas@2023-03-01' = {\n parent: store\n name: replicaName\n location: replicaLocation\n}\n
","tags":["Azure.AppConfig.GeoReplica","AZR-000312"]},{"location":"en/rules/Azure.AppConfig.GeoReplica/#configure-with-bicep-public-registry","title":"Configure with Bicep Public Registry","text":"To deploy App Configuration Stores that pass this rule:
params.skuName
to Standard
(required for geo-replication).params.replicas
to an array of objects.location
on each replica to a different location than the app configuration store.For example:
Azure Bicep snippetmodule br_public_store 'br/public:app/app-configuration:1.1.2' = {\n name: 'store'\n params: {\n skuName: 'Standard'\n disableLocalAuth: true\n enablePurgeProtection: true\n publicNetworkAccess: 'Disabled'\n replicas: [\n {\n name: 'eastus'\n location: 'eastus'\n }\n ]\n }\n}\n
","tags":["Azure.AppConfig.GeoReplica","AZR-000312"]},{"location":"en/rules/Azure.AppConfig.GeoReplica/#links","title":"Links","text":"Operational Excellence \u00b7 App Configuration \u00b7 Rule \u00b7 2020_12 \u00b7 Awareness
App Configuration store names should meet naming requirements.
","tags":["Azure.AppConfig.Name","AZR-000058"]},{"location":"en/rules/Azure.AppConfig.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for App Configuration store names are:
Consider using names that meet App Configuration store naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.AppConfig.Name","AZR-000058"]},{"location":"en/rules/Azure.AppConfig.Name/#examples","title":"Examples","text":"","tags":["Azure.AppConfig.Name","AZR-000058"]},{"location":"en/rules/Azure.AppConfig.Name/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy configuration stores that pass this rule:
name
to a value that meets the requirements.For example:
Azure Template snippet{\n \"type\": \"Microsoft.AppConfiguration/configurationStores\",\n \"apiVersion\": \"2022-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"enablePurgeProtection\": true\n }\n}\n
","tags":["Azure.AppConfig.Name","AZR-000058"]},{"location":"en/rules/Azure.AppConfig.Name/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy configuration stores that pass this rule:
name
to a value that meets the requirements.For example:
Azure Bicep snippetresource store 'Microsoft.AppConfiguration/configurationStores@2022-05-01' = {\n name: name\n location: location\n sku: {\n name: 'standard'\n }\n properties: {\n disableLocalAuth: true\n enablePurgeProtection: true\n }\n}\n
","tags":["Azure.AppConfig.Name","AZR-000058"]},{"location":"en/rules/Azure.AppConfig.Name/#configure-with-bicep-public-registry","title":"Configure with Bicep Public Registry","text":"To deploy App Configuration Stores that pass this rule:
params.name
to a value that meets the requirements.For example:
Azure Bicep snippetmodule br_public_store 'br/public:app/app-configuration:1.1.2' = {\n name: 'store'\n params: {\n skuName: 'Standard'\n disableLocalAuth: true\n enablePurgeProtection: true\n publicNetworkAccess: 'Disabled'\n replicas: [\n {\n name: 'eastus'\n location: 'eastus'\n }\n ]\n }\n}\n
","tags":["Azure.AppConfig.Name","AZR-000058"]},{"location":"en/rules/Azure.AppConfig.Name/#notes","title":"Notes","text":"This rule does not check if App Configuration store names are unique.
","tags":["Azure.AppConfig.Name","AZR-000058"]},{"location":"en/rules/Azure.AppConfig.Name/#links","title":"Links","text":"Reliability \u00b7 App Configuration \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Consider purge protection for app configuration store to ensure store cannot be purged in the retention period.
","tags":["Azure.AppConfig.PurgeProtect","AZR-000313"]},{"location":"en/rules/Azure.AppConfig.PurgeProtect/#description","title":"Description","text":"With purge protection enabled, soft deleted stores can't be purged in the retention period. If disabled, the soft deleted store can be purged before the retention period expires. Once purge protection is enabled on a store, it can't be disabled.
Purge protection is only available for configuration stores that use the standard SKU.
","tags":["Azure.AppConfig.PurgeProtect","AZR-000313"]},{"location":"en/rules/Azure.AppConfig.PurgeProtect/#recommendation","title":"Recommendation","text":"Consider enabling purge protection for app configuration stores.
","tags":["Azure.AppConfig.PurgeProtect","AZR-000313"]},{"location":"en/rules/Azure.AppConfig.PurgeProtect/#examples","title":"Examples","text":"","tags":["Azure.AppConfig.PurgeProtect","AZR-000313"]},{"location":"en/rules/Azure.AppConfig.PurgeProtect/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy App Configuration Stores that pass this rule:
properties.enablePurgeProtection
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.AppConfiguration/configurationStores\",\n \"apiVersion\": \"2023-03-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"enablePurgeProtection\": true,\n \"publicNetworkAccess\": \"Disabled\"\n }\n}\n
","tags":["Azure.AppConfig.PurgeProtect","AZR-000313"]},{"location":"en/rules/Azure.AppConfig.PurgeProtect/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Configuration Stores that pass this rule:
properties.enablePurgeProtection
property to true
.For example:
Azure Bicep snippetresource store 'Microsoft.AppConfiguration/configurationStores@2023-03-01' = {\n name: name\n location: location\n sku: {\n name: 'standard'\n }\n properties: {\n disableLocalAuth: true\n enablePurgeProtection: true\n publicNetworkAccess: 'Disabled'\n }\n}\n
","tags":["Azure.AppConfig.PurgeProtect","AZR-000313"]},{"location":"en/rules/Azure.AppConfig.PurgeProtect/#configure-with-bicep-public-registry","title":"Configure with Bicep Public Registry","text":"To deploy App Configuration Stores that pass this rule:
params.enablePurgeProtection
parameter to true
.For example:
Azure Bicep snippetmodule br_public_store 'br/public:app/app-configuration:1.1.2' = {\n name: 'store'\n params: {\n skuName: 'Standard'\n disableLocalAuth: true\n enablePurgeProtection: true\n publicNetworkAccess: 'Disabled'\n replicas: [\n {\n name: 'eastus'\n location: 'eastus'\n }\n ]\n }\n}\n
","tags":["Azure.AppConfig.PurgeProtect","AZR-000313"]},{"location":"en/rules/Azure.AppConfig.PurgeProtect/#links","title":"Links","text":"Reliability \u00b7 App Configuration \u00b7 Rule \u00b7 2020_12 \u00b7 Important
App Configuration should use a minimum size of Standard.
","tags":["Azure.AppConfig.SKU","AZR-000057"]},{"location":"en/rules/Azure.AppConfig.SKU/#description","title":"Description","text":"App Configuration is offered in two different SKUs; Free, and Standard. Standard includes additional features, increases scalability, and 99.9% SLA. The Free SKU does not include a SLA.
","tags":["Azure.AppConfig.SKU","AZR-000057"]},{"location":"en/rules/Azure.AppConfig.SKU/#recommendation","title":"Recommendation","text":"Consider upgrading App Configuration instances to Standard. Free instances are intended only for early development and testing scenarios.
","tags":["Azure.AppConfig.SKU","AZR-000057"]},{"location":"en/rules/Azure.AppConfig.SKU/#examples","title":"Examples","text":"","tags":["Azure.AppConfig.SKU","AZR-000057"]},{"location":"en/rules/Azure.AppConfig.SKU/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy configuration stores that pass this rule:
sku.name
property to standard
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.AppConfiguration/configurationStores\",\n \"apiVersion\": \"2023-03-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"enablePurgeProtection\": true,\n \"publicNetworkAccess\": \"Disabled\"\n }\n}\n
","tags":["Azure.AppConfig.SKU","AZR-000057"]},{"location":"en/rules/Azure.AppConfig.SKU/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy configuration stores that pass this rule:
sku.name
property to standard
.For example:
Azure Bicep snippetresource store 'Microsoft.AppConfiguration/configurationStores@2023-03-01' = {\n name: name\n location: location\n sku: {\n name: 'standard'\n }\n properties: {\n disableLocalAuth: true\n enablePurgeProtection: true\n publicNetworkAccess: 'Disabled'\n }\n}\n
","tags":["Azure.AppConfig.SKU","AZR-000057"]},{"location":"en/rules/Azure.AppConfig.SKU/#configure-with-bicep-public-registry","title":"Configure with Bicep Public Registry","text":"To deploy App Configuration Stores that pass this rule:
params.skuName
parameter to Standard
.For example:
Azure Bicep snippetmodule br_public_store 'br/public:app/app-configuration:1.1.2' = {\n name: 'store'\n params: {\n skuName: 'Standard'\n disableLocalAuth: true\n enablePurgeProtection: true\n publicNetworkAccess: 'Disabled'\n replicas: [\n {\n name: 'eastus'\n location: 'eastus'\n }\n ]\n }\n}\n
","tags":["Azure.AppConfig.SKU","AZR-000057"]},{"location":"en/rules/Azure.AppConfig.SKU/#links","title":"Links","text":"Reliability \u00b7 Application Gateway \u00b7 Rule \u00b7 2021_09 \u00b7 Important
Application gateways should use availability zones in supported regions for high availability.
","tags":["Azure.AppGw.AvailabilityZone","AZR-000060"]},{"location":"en/rules/Azure.AppGw.AvailabilityZone/#description","title":"Description","text":"Application gateways using availability zones improve reliability and ensure availability during failure scenarios affecting a data center within a region. A zone redundant Application gateway or Web Application Firewall (WAF) deployment can spread across multiple availability zones, which ensures the application gateway will continue running even if another zone has gone down. Backend pools for applications can be similarly distributed across availability zones.
","tags":["Azure.AppGw.AvailabilityZone","AZR-000060"]},{"location":"en/rules/Azure.AppGw.AvailabilityZone/#recommendation","title":"Recommendation","text":"Consider using availability zones for Application gateways deployed with V2 SKU (Standard_v2, WAF_v2).
","tags":["Azure.AppGw.AvailabilityZone","AZR-000060"]},{"location":"en/rules/Azure.AppGw.AvailabilityZone/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed to Azure using pre-flight and in-flight data.
This rule fails when \"zones\"
is null
, []
or not set when the Application gateway is deployed with V2 SKU (Standard_v2, WAF_v2) and there are supported availability zones for the given region.
Configure AZURE_APPGW_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
to set additional availability zones that need to be supported which are not in the existing providers for namespace Microsoft.Network
and resource type applicationGateways
.
# YAML: The default AZURE_APPGW_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST configuration option\nconfiguration:\n AZURE_APPGW_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST: []\n
","tags":["Azure.AppGw.AvailabilityZone","AZR-000060"]},{"location":"en/rules/Azure.AppGw.AvailabilityZone/#examples","title":"Examples","text":"","tags":["Azure.AppGw.AvailabilityZone","AZR-000060"]},{"location":"en/rules/Azure.AppGw.AvailabilityZone/#configure-with-azure-template","title":"Configure with Azure template","text":"To set availability zones for an Application gateway
zones
to any or all of [\"1\", \"2\", \"3\"]
.properties.sku.name
and properties.sku.tier
to Standard_v2
or WAF_v2
.For example:
Azure Template snippet {\n \"name\": \"appGw-001\",\n \"type\": \"Microsoft.Network/applicationGateways\",\n \"apiVersion\": \"2019-09-01\",\n \"location\": \"[resourceGroup().location]\",\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ],\n \"tags\": {},\n \"properties\": {\n \"sku\": {\n \"name\": \"WAF_v2\",\n \"tier\": \"WAF_v2\"\n },\n \"autoscaleConfiguration\": {\n \"minCapacity\": 2,\n \"maxCapacity\": 3\n }\n }\n }\n
","tags":["Azure.AppGw.AvailabilityZone","AZR-000060"]},{"location":"en/rules/Azure.AppGw.AvailabilityZone/#configure-with-bicep","title":"Configure with Bicep","text":"To set availability zones for an Application gateway
zones
to any or all of [\"1\", \"2\", \"3\"]
.properties.sku.name
and properties.sku.tier
to Standard_v2
or WAF_v2
.For example:
Azure Bicep snippetresource name_resource 'Microsoft.Network/applicationGateways@2019-09-01' = {\n name: 'appGw-001'\n location: location\n zones: [\n '1'\n '2'\n '3'\n ]\n tags: {}\n properties: {\n sku: {\n name: 'WAF_v2'\n tier: 'WAF_v2'\n }\n autoscaleConfiguration: {\n minCapacity: 2\n maxCapacity: 3\n }\n }\n}\n
","tags":["Azure.AppGw.AvailabilityZone","AZR-000060"]},{"location":"en/rules/Azure.AppGw.AvailabilityZone/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"","tags":["Azure.AppGw.AvailabilityZone","AZR-000060"]},{"location":"en/rules/Azure.AppGw.AvailabilityZone/#create-wafv2-application-gateway-in-zone-1-2-and-3","title":"Create WAFv2 Application Gateway in Zone 1, 2 and 3","text":"Azure CLI snippetaz network application-gateway create \\\n --name '<application_gateway_name>' \\\n --location '<location>' \\\n --resource-group '<resource_group>' \\\n --capacity '<capacity>' \\\n --sku WAF_v2 \\\n --public-ip-address '<public_ip_address>' \\\n --vnet-name '<virtual_network_name>' \\\n --subnet '<subnet_name>' \\\n --zones 1 2 3 \\\n --servers '<address_1>' '<address_2>'\n
","tags":["Azure.AppGw.AvailabilityZone","AZR-000060"]},{"location":"en/rules/Azure.AppGw.AvailabilityZone/#links","title":"Links","text":"Operational Excellence \u00b7 Application Gateway \u00b7 Rule \u00b7 2023_06 \u00b7 Important
Use a Application Gateway v2 SKU.
","tags":["Azure.AppGw.MigrateV2","AZR-000376"]},{"location":"en/rules/Azure.AppGw.MigrateV2/#description","title":"Description","text":"The Application Gateway v1 SKUs (Standard and WAF) will be retired on April 28, 2026. To avoid service disruption, migrate to Application Gateway v2 SKUs.
The v2 SKUs offers performance enhancements, security controls and adds support for critical new features like autoscaling, zone redundancy, support for static VIPs, header rewrite, key vault integration, mutual authentication (mTLS), Azure Kubernetes Service ingress controller and private link.
","tags":["Azure.AppGw.MigrateV2","AZR-000376"]},{"location":"en/rules/Azure.AppGw.MigrateV2/#recommendation","title":"Recommendation","text":"Migrate deprecated v1 Application Gateways to a v2 SKU before retirement to avoid service disruption.
","tags":["Azure.AppGw.MigrateV2","AZR-000376"]},{"location":"en/rules/Azure.AppGw.MigrateV2/#examples","title":"Examples","text":"","tags":["Azure.AppGw.MigrateV2","AZR-000376"]},{"location":"en/rules/Azure.AppGw.MigrateV2/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Application Gateways that pass this rule:
properties.sku.tier
or properties.sku.name
to Standard_v2
(Application Gateway) or WAF_v2
(Web Application Firewall).For example:
Azure Template snippet{\n \"name\": \"[parameters('name')]\",\n \"type\": \"Microsoft.Network/applicationGateways\",\n \"apiVersion\": \"2022-07-01\",\n \"location\": \"[resourceGroup().location]\",\n \"properties\": {\n \"sku\": {\n \"capacity\": 2,\n \"name\": \"WAF_v2\",\n \"tier\": \"WAF_v2\"\n }\n }\n}\n
","tags":["Azure.AppGw.MigrateV2","AZR-000376"]},{"location":"en/rules/Azure.AppGw.MigrateV2/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Application Gateways that pass this rule:
properties.sku.tier
or properties.sku.name
to Standard_v2
(Application Gateway) or WAF_v2
(Web Application Firewall).For example:
Azure Bicep snippetresource appGw 'Microsoft.Network/applicationGateways@2022-07-01' = {\n name: \n location: location\n properties: {\n sku: {\n capacity: 2\n name: 'WAF_v2'\n tier: 'WAF_v2'\n }\n }\n}\n
","tags":["Azure.AppGw.MigrateV2","AZR-000376"]},{"location":"en/rules/Azure.AppGw.MigrateV2/#notes","title":"Notes","text":"This rule is applicable for both Application Gateways and Application Gateways with Web Application Firewall (WAF).
Not all existing features under the v1 SKUs are supported in the v2 SKUs. The v2 SKUs are not currently available in all regions.
","tags":["Azure.AppGw.MigrateV2","AZR-000376"]},{"location":"en/rules/Azure.AppGw.MigrateV2/#links","title":"Links","text":"Reliability \u00b7 Application Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Application Gateways should use a minimum of two instances.
","tags":["Azure.AppGw.MinInstance","AZR-000061"]},{"location":"en/rules/Azure.AppGw.MinInstance/#description","title":"Description","text":"Application Gateways should use two or more instances to be covered by the Service Level Agreement (SLA). By having two or more instances this allows the App Gateway to meet high availability requirements and reduce downtime.
","tags":["Azure.AppGw.MinInstance","AZR-000061"]},{"location":"en/rules/Azure.AppGw.MinInstance/#recommendation","title":"Recommendation","text":"When using Application Gateway v1 or v2 with auto-scaling disabled, specify the number of instances to be two or more. When auto-scaling is enabled with Application Gateway v2, configure the minimum number of instances to be two or more.
","tags":["Azure.AppGw.MinInstance","AZR-000061"]},{"location":"en/rules/Azure.AppGw.MinInstance/#examples","title":"Examples","text":"","tags":["Azure.AppGw.MinInstance","AZR-000061"]},{"location":"en/rules/Azure.AppGw.MinInstance/#configure-with-azure-template","title":"Configure with Azure template","text":"To set capacity for an Application gateway
Autoscaling:
autoscaleConfiguration.minCapacity
to any or all of 2
.Manual Scaling:
sku.capacitiy
to 2
or more.For example:
Azure Template snippet{\n \"name\": \"appGw-001\",\n \"type\": \"Microsoft.Network/applicationGateways\",\n \"apiVersion\": \"2019-09-01\",\n \"location\": \"[resourceGroup().location]\",\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ],\n \"properties\": {\n \"sku\": {\n \"capacity\": 2, // Manual Scale\n \"name\": \"WAF_v2\",\n \"tier\": \"WAF_v2\"\n },\n \"autoscaleConfiguration\": { //Autoscale\n \"minCapacity\": 2,\n \"maxCapacity\": 3\n },\n \"webApplicationFirewallConfiguration\": {\n \"enabled\": true,\n \"firewallMode\": \"Detection\",\n \"ruleSetType\": \"OWASP\",\n \"ruleSetVersion\": \"3.0\"\n }\n }\n}\n
","tags":["Azure.AppGw.MinInstance","AZR-000061"]},{"location":"en/rules/Azure.AppGw.MinInstance/#configure-with-bicep","title":"Configure with Bicep","text":"To set capacity for an Application gateway
Autoscaling:
autoscaleConfiguration.minCapacity
to any or all of 2
.Manual Scaling:
sku.capacitiy
to 2
or more.For example:
Azure Bicep snippetresource name_resource 'Microsoft.Network/applicationGateways@2019-09-01' = {\n name: 'appGw-001'\n location: location\n zones: [\n '1'\n '2'\n '3'\n ]\n properties: {\n sku: {\n capacity: 2 // Manual scale\n name: 'WAF_v2'\n tier: 'WAF_v2'\n }\n autoscaleConfiguration: { // Autoscale\n minCapacity: 1\n maxCapacity: 2\n }\n webApplicationFirewallConfiguration: {\n enabled: true\n firewallMode: 'Detection'\n ruleSetType: 'OWASP'\n ruleSetVersion: '3.0'\n }\n }\n}\n
","tags":["Azure.AppGw.MinInstance","AZR-000061"]},{"location":"en/rules/Azure.AppGw.MinInstance/#links","title":"Links","text":"Operational Excellence \u00b7 Application Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Application Gateway should use a minimum instance size of Medium.
","tags":["Azure.AppGw.MinSku","AZR-000062"]},{"location":"en/rules/Azure.AppGw.MinSku/#description","title":"Description","text":"An Application Gateway is offered in different versions v1 and v2. When deploying an Application Gateway v1, three different instance sizes are available: Small, Medium and Large.
Application Gateway v2, Standard_v2 and WAF_v2 SKUs don't offer different instance sizes.
","tags":["Azure.AppGw.MinSku","AZR-000062"]},{"location":"en/rules/Azure.AppGw.MinSku/#recommendation","title":"Recommendation","text":"Application Gateways using v1 SKUs should be deployed with an instance size of Medium or Large. Small instance sizes are intended for development and testing scenarios.
","tags":["Azure.AppGw.MinSku","AZR-000062"]},{"location":"en/rules/Azure.AppGw.MinSku/#examples","title":"Examples","text":"","tags":["Azure.AppGw.MinSku","AZR-000062"]},{"location":"en/rules/Azure.AppGw.MinSku/#configure-with-azure-template","title":"Configure with Azure template","text":"To set the instance size for an Application Gateway V1:
properties.sku.name
to Standard_Medium
or Standard_Large
.For example:
Azure Template snippet{\n\n \"name\": \"appGw-001\",\n \"type\": \"Microsoft.Network/applicationGateways\",\n \"apiVersion\": \"2019-09-01\",\n \"location\": \"[resourceGroup().location]\",\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ],\n \"tags\": {},\n \"properties\": {\n \"sku\": {\n \"capacity\": 2,\n \"name\": \"Standard_Large\",\n \"tier\": \"Standard\"\n },\n \"enableHttp2\": false\n }\n\n}\n
","tags":["Azure.AppGw.MinSku","AZR-000062"]},{"location":"en/rules/Azure.AppGw.MinSku/#configure-with-bicep","title":"Configure with Bicep","text":"To set the instance size for an Application Gateway V1:
properties.sku.name
to Standard_Medium
or Standard_Large
.For example:
Azure Bicep snippetresource name_resource 'Microsoft.Network/applicationGateways@2019-09-01' = {\n name: 'appGw-001'\n location: location\n zones: [\n '1'\n '2'\n '3'\n ]\n tags: {}\n properties: {\n sku: {\n capacity: 2\n name: 'Standard_Large'\n tier: 'Standard'\n }\n enableHttp2: false\n }\n}\n
","tags":["Azure.AppGw.MinSku","AZR-000062"]},{"location":"en/rules/Azure.AppGw.MinSku/#links","title":"Links","text":"Operational Excellence \u00b7 Application Gateway \u00b7 Rule \u00b7 2022_12 \u00b7 Awareness
Application Gateways should meet naming requirements.
","tags":["Azure.AppGw.Name","AZR-000348"]},{"location":"en/rules/Azure.AppGw.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Application Gateway names are:
Consider using names that meet Application Gateway naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.AppGw.Name","AZR-000348"]},{"location":"en/rules/Azure.AppGw.Name/#notes","title":"Notes","text":"This rule does not check if Application Gateways names are unique.
","tags":["Azure.AppGw.Name","AZR-000348"]},{"location":"en/rules/Azure.AppGw.Name/#links","title":"Links","text":"Security \u00b7 Application Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules.
","tags":["Azure.AppGw.OWASP","AZR-000067"]},{"location":"en/rules/Azure.AppGw.OWASP/#description","title":"Description","text":"Application Gateways deployed with WAF features support configuration of OWASP rule sets for detection and / or prevention of malicious attacks. Two rule set versions are available; OWASP 2.x and OWASP 3.x.
","tags":["Azure.AppGw.OWASP","AZR-000067"]},{"location":"en/rules/Azure.AppGw.OWASP/#recommendation","title":"Recommendation","text":"Consider configuring Application Gateways to use OWASP 3.x rules instead of 2.x rule set versions.
","tags":["Azure.AppGw.OWASP","AZR-000067"]},{"location":"en/rules/Azure.AppGw.OWASP/#examples","title":"Examples","text":"","tags":["Azure.AppGw.OWASP","AZR-000067"]},{"location":"en/rules/Azure.AppGw.OWASP/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Application Gateways that pass this rule:
properties.webApplicationFirewallConfiguration.ruleSetType
property to OWASP
.properties.webApplicationFirewallConfiguration.ruleSetVersion
property to a minimum of 3.2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/applicationGateways\",\n \"apiVersion\": \"2020-11-01\",\n \"name\": \"appGw-001\",\n \"location\": \"[resourceGroup().location]\",\n \"properties\": {\n \"sku\": {\n \"name\": \"WAF_v2\",\n \"tier\": \"WAF_v2\"\n },\n \"webApplicationFirewallConfiguration\": {\n \"enabled\": true,\n \"firewallMode\": \"Prevention\",\n \"ruleSetType\": \"OWASP\",\n \"ruleSetVersion\": \"3.2\",\n \"disabledRuleGroups\": [],\n \"requestBodyCheck\": true,\n \"maxRequestBodySizeInKb\": 128,\n \"fileUploadLimitInMb\": 100\n }\n }\n}\n
","tags":["Azure.AppGw.OWASP","AZR-000067"]},{"location":"en/rules/Azure.AppGw.OWASP/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Application Gateways that pass this rule:
properties.webApplicationFirewallConfiguration.ruleSetType
property to OWASP
.properties.webApplicationFirewallConfiguration.ruleSetVersion
property to a minimum of 3.2
.For example:
Azure Bicep snippetresource appGw 'Microsoft.Network/applicationGateways@2021-02-01' = {\n name: 'appGw-001'\n location: location\n properties: {\n sku: {\n name: 'WAF_v2'\n tier: 'WAF_v2'\n }\n webApplicationFirewallConfiguration: {\n enabled: true\n firewallMode: 'Prevention'\n ruleSetType: 'OWASP'\n ruleSetVersion: '3.2'\n }\n }\n}\n
","tags":["Azure.AppGw.OWASP","AZR-000067"]},{"location":"en/rules/Azure.AppGw.OWASP/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz network application-gateway waf-config set --enabled true --rule-set-type OWASP --rule-set-version '3.2' -n '<name>' -g '<resource_group>'\n
","tags":["Azure.AppGw.OWASP","AZR-000067"]},{"location":"en/rules/Azure.AppGw.OWASP/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippet$AppGw = Get-AzApplicationGateway -Name '<name>' -ResourceGroupName '<resource_group>'\nSet-AzApplicationGatewayWebApplicationFirewallConfiguration -ApplicationGateway $AppGw -Enabled $True -FirewallMode 'Prevention' -RuleSetType 'OWASP' -RuleSetVersion '3.2'\n
","tags":["Azure.AppGw.OWASP","AZR-000067"]},{"location":"en/rules/Azure.AppGw.OWASP/#links","title":"Links","text":"Security \u00b7 Application Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Internet exposed Application Gateways should use prevention mode to protect backend resources.
","tags":["Azure.AppGw.Prevention","AZR-000065"]},{"location":"en/rules/Azure.AppGw.Prevention/#description","title":"Description","text":"Application Gateways with Web Application Firewall (WAF) enabled support two modes of operation:
Consider switching Internet exposed Application Gateways to use prevention mode to protect backend resources.
","tags":["Azure.AppGw.Prevention","AZR-000065"]},{"location":"en/rules/Azure.AppGw.Prevention/#examples","title":"Examples","text":"","tags":["Azure.AppGw.Prevention","AZR-000065"]},{"location":"en/rules/Azure.AppGw.Prevention/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Application Gateways that pass this rule:
properties.webApplicationFirewallConfiguration.firewallMode
property to Prevention
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/applicationGateways\",\n \"apiVersion\": \"2020-11-01\",\n \"name\": \"appGw-001\",\n \"location\": \"[resourceGroup().location]\",\n \"properties\": {\n \"sku\": {\n \"name\": \"WAF_v2\",\n \"tier\": \"WAF_v2\"\n },\n \"webApplicationFirewallConfiguration\": {\n \"enabled\": true,\n \"firewallMode\": \"Prevention\",\n \"ruleSetType\": \"OWASP\",\n \"ruleSetVersion\": \"3.2\",\n \"disabledRuleGroups\": [],\n \"requestBodyCheck\": true,\n \"maxRequestBodySizeInKb\": 128,\n \"fileUploadLimitInMb\": 100\n }\n }\n}\n
","tags":["Azure.AppGw.Prevention","AZR-000065"]},{"location":"en/rules/Azure.AppGw.Prevention/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Application Gateways that pass this rule:
properties.webApplicationFirewallConfiguration.firewallMode
property to Prevention
.For example:
Azure Bicep snippetresource name_resource 'Microsoft.Network/applicationGateways@2019-09-01' = {\n name: 'appGw-001'\n location: location\n properties: {\n sku: {\n name: 'WAF_v2'\n tier: 'WAF_v2'\n }\n webApplicationFirewallConfiguration: {\n enabled: true\n firewallMode: 'Prevention'\n ruleSetType: 'OWASP'\n ruleSetVersion: '3.2'\n disabledRuleGroups: []\n requestBodyCheck: true\n maxRequestBodySizeInKb: 128\n fileUploadLimitInMb: 100\n }\n }\n}\n
","tags":["Azure.AppGw.Prevention","AZR-000065"]},{"location":"en/rules/Azure.AppGw.Prevention/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz network application-gateway waf-config set --enabled true --firewall-mode Prevention -n '<name>' -g '<resource_group>'\n
","tags":["Azure.AppGw.Prevention","AZR-000065"]},{"location":"en/rules/Azure.AppGw.Prevention/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippet$AppGw = Get-AzApplicationGateway -Name '<name>' -ResourceGroupName '<resource_group>'\nSet-AzApplicationGatewayWebApplicationFirewallConfiguration -ApplicationGateway $AppGw -Enabled $True -FirewallMode 'Prevention'\n
","tags":["Azure.AppGw.Prevention","AZR-000065"]},{"location":"en/rules/Azure.AppGw.Prevention/#links","title":"Links","text":"Security \u00b7 Application Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Application Gateway should only accept a minimum of TLS 1.2.
","tags":["Azure.AppGw.SSLPolicy","AZR-000064"]},{"location":"en/rules/Azure.AppGw.SSLPolicy/#description","title":"Description","text":"The minimum version of TLS that Application Gateways accept is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Azure lets you disable outdated protocols and require connections to use a minimum of TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 is accepted.
Application Gateway should only accept a minimum of TLS 1.2 to ensure secure connections.
","tags":["Azure.AppGw.SSLPolicy","AZR-000064"]},{"location":"en/rules/Azure.AppGw.SSLPolicy/#recommendation","title":"Recommendation","text":"Consider configuring Application Gateways to accept a minimum of TLS 1.2.
","tags":["Azure.AppGw.SSLPolicy","AZR-000064"]},{"location":"en/rules/Azure.AppGw.SSLPolicy/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Application Gateways that pass this rule use a predefined or custom policy:
properties.sslPolicy.policyType
property to Custom
.properties.sslPolicy.minProtocolVersion
property to TLSv1_2
.properties.sslPolicy.cipherSuites
property to a list of supported ciphers. For example:TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
properties.sslPolicy.policyType
property to Predefined
.properties.sslPolicy.policyName
property to a supported predefined policy such as AppGwSslPolicy20220101S
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/applicationGateways\",\n \"apiVersion\": \"2023-09-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ],\n \"properties\": {\n \"sku\": {\n \"name\": \"WAF_v2\",\n \"tier\": \"WAF_v2\"\n },\n \"sslPolicy\": {\n \"policyType\": \"Custom\",\n \"minProtocolVersion\": \"TLSv1_2\",\n \"cipherSuites\": [\n \"TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384\",\n \"TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256\",\n \"TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384\",\n \"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256\"\n ]\n }\n }\n}\n
","tags":["Azure.AppGw.SSLPolicy","AZR-000064"]},{"location":"en/rules/Azure.AppGw.SSLPolicy/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Application Gateways that pass this rule use a predefined or custom policy:
properties.sslPolicy.policyType
property to Custom
.properties.sslPolicy.minProtocolVersion
property to TLSv1_2
.properties.sslPolicy.cipherSuites
property to a list of supported ciphers. For example:TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
properties.sslPolicy.policyType
property to Predefined
.properties.sslPolicy.policyName
property to a supported predefined policy such as AppGwSslPolicy20220101S
.For example:
Azure Bicep snippetresource app_gw 'Microsoft.Network/applicationGateways@2023-09-01' = {\n name: name\n location: location\n zones: [\n '1'\n '2'\n '3'\n ]\n properties: {\n sku: {\n name: 'WAF_v2'\n tier: 'WAF_v2'\n }\n sslPolicy: {\n policyType: 'Custom'\n minProtocolVersion: 'TLSv1_2'\n cipherSuites: [\n 'TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384'\n 'TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256'\n 'TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384'\n 'TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256'\n ]\n }\n }\n}\n
","tags":["Azure.AppGw.SSLPolicy","AZR-000064"]},{"location":"en/rules/Azure.AppGw.SSLPolicy/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippet$gw = Get-AzApplicationGateway -Name '<name>' -ResourceGroupName '<resource_group>'\nSet-AzApplicationGatewaySslPolicy -ApplicationGateway $gw -PolicyType Custom -MinProtocolVersion TLSv1_2 -CipherSuite 'TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384', 'TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256', 'TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384', 'TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256'\n
","tags":["Azure.AppGw.SSLPolicy","AZR-000064"]},{"location":"en/rules/Azure.AppGw.SSLPolicy/#links","title":"Links","text":"Security \u00b7 Application Gateway \u00b7 Rule \u00b7 2021_09 \u00b7 Critical
Application Gateways should only expose frontend HTTP endpoints over HTTPS.
","tags":["Azure.AppGw.UseHTTPS","AZR-000059"]},{"location":"en/rules/Azure.AppGw.UseHTTPS/#description","title":"Description","text":"Application Gateways support HTTP and HTTPS endpoints for backend and frontend traffic. When using frontend HTTP (80
) endpoints, traffic between client and Application Gateway is not encrypted.
Unencrypted communication could allow disclosure of information to an un-trusted party.
","tags":["Azure.AppGw.UseHTTPS","AZR-000059"]},{"location":"en/rules/Azure.AppGw.UseHTTPS/#recommendation","title":"Recommendation","text":"Consider configuring Application Gateways to only expose HTTPS endpoints. For client applications such as progressive web apps, consider redirecting HTTP traffic to HTTPS.
","tags":["Azure.AppGw.UseHTTPS","AZR-000059"]},{"location":"en/rules/Azure.AppGw.UseHTTPS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Application Gateways that pass this rule:
properties.frontendPorts.properties.port
property to 443
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/applicationGateways\",\n \"apiVersion\": \"2023-09-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ],\n \"properties\": {\n \"sku\": {\n \"name\": \"WAF_v2\",\n \"tier\": \"WAF_v2\"\n },\n \"sslPolicy\": {\n \"policyType\": \"Custom\",\n \"minProtocolVersion\": \"TLSv1_2\",\n \"cipherSuites\": [\n \"TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384\",\n \"TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256\",\n \"TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384\",\n \"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256\"\n ]\n },\n \"frontendPorts\": [\n {\n \"name\": \"https\",\n \"properties\": {\n \"Port\": 443\n }\n }\n ]\n }\n}\n
","tags":["Azure.AppGw.UseHTTPS","AZR-000059"]},{"location":"en/rules/Azure.AppGw.UseHTTPS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Application Gateways that pass this rule:
properties.frontendPorts.properties.port
property to 443
.For example:
Azure Bicep snippetresource app_gw 'Microsoft.Network/applicationGateways@2023-09-01' = {\n name: name\n location: location\n zones: [\n '1'\n '2'\n '3'\n ]\n properties: {\n sku: {\n name: 'WAF_v2'\n tier: 'WAF_v2'\n }\n sslPolicy: {\n policyType: 'Custom'\n minProtocolVersion: 'TLSv1_2'\n cipherSuites: [\n 'TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384'\n 'TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256'\n 'TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384'\n 'TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256'\n ]\n }\n frontendPorts: [\n {\n name: 'https'\n properties: {\n Port: 443\n }\n }\n ]\n }\n}\n
","tags":["Azure.AppGw.UseHTTPS","AZR-000059"]},{"location":"en/rules/Azure.AppGw.UseHTTPS/#links","title":"Links","text":"Security \u00b7 Application Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Internet accessible Application Gateways should use protect endpoints with WAF.
","tags":["Azure.AppGw.UseWAF","AZR-000063"]},{"location":"en/rules/Azure.AppGw.UseWAF/#description","title":"Description","text":"Application Gateway endpoints can optionally be configured with a Web Application Firewall (WAF) policy. When configured, every incoming request is filtered by the WAF policy.
To use a WAF policy, the Application Gateway must be deployed with a Web Application Firewall SKU.
","tags":["Azure.AppGw.UseWAF","AZR-000063"]},{"location":"en/rules/Azure.AppGw.UseWAF/#recommendation","title":"Recommendation","text":"Consider deploying Application Gateways with a WAF SKU to protect against common attacks.
","tags":["Azure.AppGw.UseWAF","AZR-000063"]},{"location":"en/rules/Azure.AppGw.UseWAF/#examples","title":"Examples","text":"","tags":["Azure.AppGw.UseWAF","AZR-000063"]},{"location":"en/rules/Azure.AppGw.UseWAF/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Application Gateways that pass this rule:
WAF
or WAF_v2
SKU.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/applicationGateways\",\n \"apiVersion\": \"2020-11-01\",\n \"name\": \"appGw-001\",\n \"location\": \"[resourceGroup().location]\",\n \"properties\": {\n \"sku\": {\n \"name\": \"WAF_v2\",\n \"tier\": \"WAF_v2\"\n },\n \"webApplicationFirewallConfiguration\": {\n \"enabled\": true,\n \"firewallMode\": \"Prevention\",\n \"ruleSetType\": \"OWASP\",\n \"ruleSetVersion\": \"3.2\",\n \"disabledRuleGroups\": [],\n \"requestBodyCheck\": true,\n \"maxRequestBodySizeInKb\": 128,\n \"fileUploadLimitInMb\": 100\n }\n }\n}\n
","tags":["Azure.AppGw.UseWAF","AZR-000063"]},{"location":"en/rules/Azure.AppGw.UseWAF/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Application Gateways that pass this rule:
WAF
or WAF_v2
SKU.For example:
Azure Bicep snippetresource appGw 'Microsoft.Network/applicationGateways@2021-02-01' = {\n name: 'appGw-001'\n location: location\n properties: {\n sku: {\n name: 'WAF_v2'\n tier: 'WAF_v2'\n }\n webApplicationFirewallConfiguration: {\n enabled: true\n firewallMode: 'Prevention'\n ruleSetType: 'OWASP'\n ruleSetVersion: '3.2'\n }\n }\n}\n
","tags":["Azure.AppGw.UseWAF","AZR-000063"]},{"location":"en/rules/Azure.AppGw.UseWAF/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz network application-gateway update --sku WAF_v2 -n '<name>' -g '<resource_group>'\n
","tags":["Azure.AppGw.UseWAF","AZR-000063"]},{"location":"en/rules/Azure.AppGw.UseWAF/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippet$AppGw = Get-AzApplicationGateway -Name '<name>' -ResourceGroupName '<resource_group>'\n$AppGw = Set-AzApplicationGatewaySku -ApplicationGateway $AppGw -Name 'WAF_v2' -Tier 'WAF_v2'\n
","tags":["Azure.AppGw.UseWAF","AZR-000063"]},{"location":"en/rules/Azure.AppGw.UseWAF/#links","title":"Links","text":"Security \u00b7 Application Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources.
","tags":["Azure.AppGw.WAFEnabled","AZR-000066"]},{"location":"en/rules/Azure.AppGw.WAFEnabled/#description","title":"Description","text":"Security features of Application Gateways deployed with WAF may be toggled on or off.
When WAF is disabled network traffic is still processed by the Application Gateway however detection and/ or prevention of malicious attacks does not occur.
To protect backend resources from potentially malicious network traffic, WAF must be enabled.
","tags":["Azure.AppGw.WAFEnabled","AZR-000066"]},{"location":"en/rules/Azure.AppGw.WAFEnabled/#recommendation","title":"Recommendation","text":"Consider enabling WAF for Application Gateway instances connected to un-trusted or low-trust networks such as the Internet.
","tags":["Azure.AppGw.WAFEnabled","AZR-000066"]},{"location":"en/rules/Azure.AppGw.WAFEnabled/#examples","title":"Examples","text":"","tags":["Azure.AppGw.WAFEnabled","AZR-000066"]},{"location":"en/rules/Azure.AppGw.WAFEnabled/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Application Gateways that pass this rule:
properties.webApplicationFirewallConfiguration.enabled
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/applicationGateways\",\n \"apiVersion\": \"2020-11-01\",\n \"name\": \"appGw-001\",\n \"location\": \"[resourceGroup().location]\",\n \"properties\": {\n \"sku\": {\n \"name\": \"WAF_v2\",\n \"tier\": \"WAF_v2\"\n },\n \"webApplicationFirewallConfiguration\": {\n \"enabled\": true,\n \"firewallMode\": \"Prevention\",\n \"ruleSetType\": \"OWASP\",\n \"ruleSetVersion\": \"3.2\",\n \"disabledRuleGroups\": [],\n \"requestBodyCheck\": true,\n \"maxRequestBodySizeInKb\": 128,\n \"fileUploadLimitInMb\": 100\n }\n }\n}\n
","tags":["Azure.AppGw.WAFEnabled","AZR-000066"]},{"location":"en/rules/Azure.AppGw.WAFEnabled/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Application Gateways that pass this rule:
properties.webApplicationFirewallConfiguration.enabled
property to true
.For example:
Azure Bicep snippetresource appGw 'Microsoft.Network/applicationGateways@2021-02-01' = {\n name: 'appGw-001'\n location: location\n properties: {\n sku: {\n name: 'WAF_v2'\n tier: 'WAF_v2'\n }\n webApplicationFirewallConfiguration: {\n enabled: true\n firewallMode: 'Prevention'\n ruleSetType: 'OWASP'\n ruleSetVersion: '3.2'\n }\n }\n}\n
","tags":["Azure.AppGw.WAFEnabled","AZR-000066"]},{"location":"en/rules/Azure.AppGw.WAFEnabled/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz network application-gateway waf-config set --enabled true -n '<name>' -g '<resource_group>'\n
","tags":["Azure.AppGw.WAFEnabled","AZR-000066"]},{"location":"en/rules/Azure.AppGw.WAFEnabled/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippet$AppGw = Get-AzApplicationGateway -Name '<name>' -ResourceGroupName '<resource_group>'\nSet-AzApplicationGatewayWebApplicationFirewallConfiguration -ApplicationGateway $AppGw -Enabled $True -FirewallMode 'Prevention'\n
","tags":["Azure.AppGw.WAFEnabled","AZR-000066"]},{"location":"en/rules/Azure.AppGw.WAFEnabled/#links","title":"Links","text":"Security \u00b7 Application Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Application Gateway Web Application Firewall (WAF) should have all rules enabled.
","tags":["Azure.AppGw.WAFRules","AZR-000068"]},{"location":"en/rules/Azure.AppGw.WAFRules/#description","title":"Description","text":"Application Gateway instances with WAF allow OWASP detection/ prevention rules to be toggled on or off. All OWASP rules are turned on by default.
When OWASP rules are turned off, the protection they provide is disabled.
","tags":["Azure.AppGw.WAFRules","AZR-000068"]},{"location":"en/rules/Azure.AppGw.WAFRules/#recommendation","title":"Recommendation","text":"Consider enabling all OWASP rules within Application Gateway instances.
Before disabling OWASP rules, ensure that the backend workload has alternative protections in-place. Alternatively consider updating application code to use safe web standards.
","tags":["Azure.AppGw.WAFRules","AZR-000068"]},{"location":"en/rules/Azure.AppGw.WAFRules/#examples","title":"Examples","text":"","tags":["Azure.AppGw.WAFRules","AZR-000068"]},{"location":"en/rules/Azure.AppGw.WAFRules/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Application Gateways that pass this rule:
properties.webApplicationFirewallConfiguration.disabledRuleGroups.ruleGroupName
property to $ruleName
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/applicationGateways\",\n \"apiVersion\": \"2020-11-01\",\n \"name\": \"appGw-001\",\n \"location\": \"[resourceGroup().location]\",\n \"properties\": {\n \"sku\": {\n \"name\": \"WAF_v2\",\n \"tier\": \"WAF_v2\"\n },\n \"webApplicationFirewallConfiguration\": {\n \"enabled\": true,\n \"firewallMode\": \"Prevention\",\n \"ruleSetType\": \"OWASP\",\n \"ruleSetVersion\": \"3.2\",\n \"disabledRuleGroups\": [\n {\n \"ruleGroupName\": \"exampleRule\",\n \"rules\": []\n }\n ],\n \"requestBodyCheck\": true,\n \"maxRequestBodySizeInKb\": 128,\n \"fileUploadLimitInMb\": 100\n }\n }\n}\n
","tags":["Azure.AppGw.WAFRules","AZR-000068"]},{"location":"en/rules/Azure.AppGw.WAFRules/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Application Gateways that pass this rule:
properties.webApplicationFirewallConfiguration.enabled
property to true
.For example:
Azure Bicep snippetresource appGw 'Microsoft.Network/applicationGateways@2021-02-01' = {\n name: 'appGw-001'\n location: location\n properties: {\n sku: {\n name: 'WAF_v2'\n tier: 'WAF_v2'\n }\n webApplicationFirewallConfiguration: {\n enabled: true\n firewallMode: 'Prevention'\n ruleSetType: 'OWASP'\n ruleSetVersion: '3.2'\n disabledRuleGroups: [\n {\n ruleGroupName: 'exampleRule',\n rules: []\n }\n ]\n }\n }\n}\n
","tags":["Azure.AppGw.WAFRules","AZR-000068"]},{"location":"en/rules/Azure.AppGw.WAFRules/#links","title":"Links","text":"Security \u00b7 Application Gateway \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources.
","tags":["Azure.AppGwWAF.Enabled","AZR-000309"]},{"location":"en/rules/Azure.AppGwWAF.Enabled/#description","title":"Description","text":"Security features of Application Gateways deployed with WAF may be toggled on or off.
When WAF is disabled network traffic is still processed by the Application Gateway however detection and/ or prevention of malicious attacks does not occur.
To protect backend resources from potentially malicious network traffic, WAF must be enabled.
","tags":["Azure.AppGwWAF.Enabled","AZR-000309"]},{"location":"en/rules/Azure.AppGwWAF.Enabled/#recommendation","title":"Recommendation","text":"Consider enabling WAF for Application Gateway instances connected to un-trusted or low-trust networks such as the Internet.
","tags":["Azure.AppGwWAF.Enabled","AZR-000309"]},{"location":"en/rules/Azure.AppGwWAF.Enabled/#examples","title":"Examples","text":"","tags":["Azure.AppGwWAF.Enabled","AZR-000309"]},{"location":"en/rules/Azure.AppGwWAF.Enabled/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Application Gateways that pass this rule:
properties.policySettings.state
property to Enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies\",\n \"apiVersion\": \"2022-01-01\",\n \"name\": \"agwwaf\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"managedRules\": {\n \"managedRuleSets\": [\n {\n \"ruleSetType\": \"OWASP\",\n \"ruleSetVersion\": \"3.2\"\n },\n {\n \"ruleSetType\": \"Microsoft_BotManagerRuleSet\",\n \"ruleSetVersion\": \"0.1\"\n }\n ]\n },\n \"policySettings\": {\n \"state\": \"Enabled\",\n \"mode\": \"Prevention\"\n }\n }\n}\n
","tags":["Azure.AppGwWAF.Enabled","AZR-000309"]},{"location":"en/rules/Azure.AppGwWAF.Enabled/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Application Gateways that pass this rule:
properties.policySettings.state
property to Enabled
.For example:
Azure Bicep snippetresource waf 'Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies@2022-01-01' = {\n name: 'agwwaf'\n location: location\n properties: {\n managedRules: {\n managedRuleSets: [\n {\n ruleSetType: 'OWASP'\n ruleSetVersion: '3.2'\n }\n {\n ruleSetType: 'Microsoft_BotManagerRuleSet'\n ruleSetVersion: '0.1'\n }\n ]\n }\n policySettings: {\n state: 'Enabled'\n mode: 'Prevention'\n }\n }\n}\n
","tags":["Azure.AppGwWAF.Enabled","AZR-000309"]},{"location":"en/rules/Azure.AppGwWAF.Enabled/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz network application-gateway waf-config set --enabled true -n '<name>' -g '<resource_group>'\n
","tags":["Azure.AppGwWAF.Enabled","AZR-000309"]},{"location":"en/rules/Azure.AppGwWAF.Enabled/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippet$AppGw = Get-AzApplicationGateway -Name '<name>' -ResourceGroupName '<resource_group>'\nSet-AzApplicationGatewayWebApplicationFirewallConfiguration -ApplicationGateway $AppGw -Enabled $True -FirewallMode 'Prevention'\n
","tags":["Azure.AppGwWAF.Enabled","AZR-000309"]},{"location":"en/rules/Azure.AppGwWAF.Enabled/#links","title":"Links","text":"Security \u00b7 Application Gateway \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Application Gateway Web Application Firewall (WAF) should have all rules enabled.
","tags":["Azure.AppGwWAF.Exclusions","AZR-000303"]},{"location":"en/rules/Azure.AppGwWAF.Exclusions/#description","title":"Description","text":"Application Gateway instances with WAF allow OWASP detection/ prevention rules to be toggled on or off. All OWASP rules are turned on by default.
When OWASP rules are turned off, the protection they provide is disabled.
","tags":["Azure.AppGwWAF.Exclusions","AZR-000303"]},{"location":"en/rules/Azure.AppGwWAF.Exclusions/#recommendation","title":"Recommendation","text":"Consider enabling all OWASP rules within Application Gateway instances.
Before disabling OWASP rules, ensure that the backend workload has alternative protections in-place. Alternatively consider updating application code to use safe web standards.
","tags":["Azure.AppGwWAF.Exclusions","AZR-000303"]},{"location":"en/rules/Azure.AppGwWAF.Exclusions/#links","title":"Links","text":"Security \u00b7 Application Gateway \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources.
","tags":["Azure.AppGwWAF.PreventionMode","AZR-000302"]},{"location":"en/rules/Azure.AppGwWAF.PreventionMode/#description","title":"Description","text":"Application Gateway WAF policies support two modes of operation, detection and prevention. By default, prevention is configured.
Consider setting Application Gateway WAF policy to use protection mode.
","tags":["Azure.AppGwWAF.PreventionMode","AZR-000302"]},{"location":"en/rules/Azure.AppGwWAF.PreventionMode/#links","title":"Links","text":"Security \u00b7 Application Gateway \u00b7 Rule \u00b7 2024_03 \u00b7 Critical
Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources.
","tags":["Azure.AppGwWAF.RuleGroups","AZR-000304"]},{"location":"en/rules/Azure.AppGwWAF.RuleGroups/#description","title":"Description","text":"Application Gateway WAF policies support two main Rule Groups.
Consider configuring Application Gateway WAF policy to use the recommended rule sets.
","tags":["Azure.AppGwWAF.RuleGroups","AZR-000304"]},{"location":"en/rules/Azure.AppGwWAF.RuleGroups/#links","title":"Links","text":"Operational Excellence \u00b7 Application Insights \u00b7 Rule \u00b7 2021_06 \u00b7 Awareness
Azure Application Insights resources names should meet naming requirements.
","tags":["Azure.AppInsights.Name","AZR-000070"]},{"location":"en/rules/Azure.AppInsights.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Application Insights resource names are:
Consider using names that meet Application Insights resource naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.AppInsights.Name","AZR-000070"]},{"location":"en/rules/Azure.AppInsights.Name/#notes","title":"Notes","text":"This rule does not check if Application Insights resource names are unique.
","tags":["Azure.AppInsights.Name","AZR-000070"]},{"location":"en/rules/Azure.AppInsights.Name/#links","title":"Links","text":"Operational Excellence \u00b7 Application Insights \u00b7 Rule \u00b7 2021_06 \u00b7 Important
Configure Application Insights resources to store data in workspaces.
","tags":["Azure.AppInsights.Workspace","AZR-000069"]},{"location":"en/rules/Azure.AppInsights.Workspace/#description","title":"Description","text":"Application Insights (App Insights) can be deployed as either classic or workspace-based resources. When configured as workspace-based, telemetry is sent from App Insights to a common Log Analytics workspace.
Using a Log Analytics workspace for App Insights:
App Insights resources can be configured as workspace-based either during or after initial deployment.
","tags":["Azure.AppInsights.Workspace","AZR-000069"]},{"location":"en/rules/Azure.AppInsights.Workspace/#recommendation","title":"Recommendation","text":"Consider using workspace-based Application Insights resources to collect telemetry in shared storage.
","tags":["Azure.AppInsights.Workspace","AZR-000069"]},{"location":"en/rules/Azure.AppInsights.Workspace/#examples","title":"Examples","text":"","tags":["Azure.AppInsights.Workspace","AZR-000069"]},{"location":"en/rules/Azure.AppInsights.Workspace/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Application Insights resources that pass this rule:
properties.WorkspaceResourceId
property to a valid Log Analytics workspace.For example:
Azure Template snippet{\n \"type\": \"microsoft.insights/components\",\n \"apiVersion\": \"2020-02-02\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"kind\": \"web\",\n \"properties\": {\n \"Application_Type\": \"web\",\n \"Flow_Type\": \"Redfield\",\n \"Request_Source\": \"IbizaAIExtension\",\n \"WorkspaceResourceId\": \"[parameters('workspaceId')]\"\n }\n}\n
","tags":["Azure.AppInsights.Workspace","AZR-000069"]},{"location":"en/rules/Azure.AppInsights.Workspace/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Application Insights resources that pass this rule:
properties.WorkspaceResourceId
property to a valid Log Analytics workspace.For example:
Azure Bicep snippetresource appInsights 'Microsoft.Insights/components@2020-02-02' = {\n name: name\n location: location\n kind: 'web'\n properties: {\n Application_Type: 'web'\n Flow_Type: 'Redfield'\n Request_Source: 'IbizaAIExtension'\n WorkspaceResourceId: workspaceId\n }\n}\n
","tags":["Azure.AppInsights.Workspace","AZR-000069"]},{"location":"en/rules/Azure.AppInsights.Workspace/#links","title":"Links","text":"Performance Efficiency \u00b7 App Service \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Disable client affinity for stateless services.
","tags":["Azure.AppService.ARRAffinity","AZR-000083"]},{"location":"en/rules/Azure.AppService.ARRAffinity/#description","title":"Description","text":"Azure App Service apps use Application Request Routing (ARR) by default. ARR uses a cookie to route subsequent client requests back to the same instance when an app is scaled to two or more instances. This benefits stateful applications, which may hold session information in instance memory.
For stateless applications, disabling ARR allows Azure App Service more evenly distribute load.
","tags":["Azure.AppService.ARRAffinity","AZR-000083"]},{"location":"en/rules/Azure.AppService.ARRAffinity/#recommendation","title":"Recommendation","text":"Azure App Service sites make use of Application Request Routing (ARR) by default. Consider disabling ARR affinity for stateless applications.
","tags":["Azure.AppService.ARRAffinity","AZR-000083"]},{"location":"en/rules/Azure.AppService.ARRAffinity/#links","title":"Links","text":"Reliability \u00b7 App Service \u00b7 Rule \u00b7 2020_12 \u00b7 Important
Configure Always On for App Service apps.
","tags":["Azure.AppService.AlwaysOn","AZR-000077"]},{"location":"en/rules/Azure.AppService.AlwaysOn/#description","title":"Description","text":"Azure App Service apps are automatically unloaded when there's no traffic. Unloading apps reduces resource consumption when apps share a single App Services Plan. After an app have been unloaded, the next web request will trigger a cold start of the app. A cold start of the app can cause request timeouts.
Web apps using continuous WebJobs or WebJobs triggered with a CRON expression must use always on to start.
","tags":["Azure.AppService.AlwaysOn","AZR-000077"]},{"location":"en/rules/Azure.AppService.AlwaysOn/#recommendation","title":"Recommendation","text":"Consider enabling Always On for each App Services app.
","tags":["Azure.AppService.AlwaysOn","AZR-000077"]},{"location":"en/rules/Azure.AppService.AlwaysOn/#examples","title":"Examples","text":"","tags":["Azure.AppService.AlwaysOn","AZR-000077"]},{"location":"en/rules/Azure.AppService.AlwaysOn/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy App Services that pass this rule:
properties.siteConfig.alwaysOn
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/sites\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"kind\": \"web\",\n \"properties\": {\n \"serverFarmId\": \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\",\n \"httpsOnly\": true,\n \"siteConfig\": {\n \"alwaysOn\": true,\n \"minTlsVersion\": \"1.2\",\n \"ftpsState\": \"Disabled\",\n \"remoteDebuggingEnabled\": false,\n \"http20Enabled\": true,\n \"netFrameworkVersion\": \"v8.0\",\n \"healthCheckPath\": \"/healthz\",\n \"metadata\": [\n {\n \"name\": \"CURRENT_STACK\",\n \"value\": \"dotnet\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\"\n ]\n}\n
","tags":["Azure.AppService.AlwaysOn","AZR-000077"]},{"location":"en/rules/Azure.AppService.AlwaysOn/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Services that pass this rule:
properties.siteConfig.alwaysOn
property to true
.For example:
Azure Bicep snippetresource web 'Microsoft.Web/sites@2023-01-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n kind: 'web'\n properties: {\n serverFarmId: plan.id\n httpsOnly: true\n siteConfig: {\n alwaysOn: true\n minTlsVersion: '1.2'\n ftpsState: 'Disabled'\n remoteDebuggingEnabled: false\n http20Enabled: true\n netFrameworkVersion: 'v8.0'\n healthCheckPath: '/healthz'\n metadata: [\n {\n name: 'CURRENT_STACK'\n value: 'dotnet'\n }\n ]\n }\n }\n}\n
","tags":["Azure.AppService.AlwaysOn","AZR-000077"]},{"location":"en/rules/Azure.AppService.AlwaysOn/#notes","title":"Notes","text":"The Always On feature of App Service is not applicable to Azure Functions and Standard Logic Apps under most circumstances. To reduce false positives, this rule ignores apps based on Azure Functions and Standard Logic Apps.
When running in a Consumption Plan or Premium Plan you should not enable Always On. On a Consumption plan the platform activates function apps automatically. On a Premium plan the platform keeps your desired number of pre-warmed instances always on automatically.
","tags":["Azure.AppService.AlwaysOn","AZR-000077"]},{"location":"en/rules/Azure.AppService.AlwaysOn/#links","title":"Links","text":"Performance Efficiency \u00b7 App Service \u00b7 Rule \u00b7 2020_12 \u00b7 Awareness
Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency.
","tags":["Azure.AppService.HTTP2","AZR-000078"]},{"location":"en/rules/Azure.AppService.HTTP2/#description","title":"Description","text":"Azure App Service has native support for HTTP/2, but by default it is disabled. HTTP/2 offers a number of improvements over HTTP/1.1, including:
Consider using HTTP/2 for Azure Services apps to improve protocol efficiency.
","tags":["Azure.AppService.HTTP2","AZR-000078"]},{"location":"en/rules/Azure.AppService.HTTP2/#examples","title":"Examples","text":"","tags":["Azure.AppService.HTTP2","AZR-000078"]},{"location":"en/rules/Azure.AppService.HTTP2/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy App Services that pass this rule:
properties.siteConfig.http20Enabled
to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/sites\",\n \"apiVersion\": \"2021-02-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"kind\": \"web\",\n \"properties\": {\n \"serverFarmId\": \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\",\n \"httpsOnly\": true,\n \"siteConfig\": {\n \"alwaysOn\": true,\n \"minTlsVersion\": \"1.2\",\n \"ftpsState\": \"FtpsOnly\",\n \"remoteDebuggingEnabled\": false,\n \"http20Enabled\": true\n }\n },\n \"tags\": \"[parameters('tags')]\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\"\n ]\n}\n
","tags":["Azure.AppService.HTTP2","AZR-000078"]},{"location":"en/rules/Azure.AppService.HTTP2/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Services that pass this rule:
properties.siteConfig.http20Enabled
to true
.For example:
Azure Bicep snippetresource webApp 'Microsoft.Web/sites@2021-02-01' = {\n name: name\n location: location\n kind: 'web'\n properties: {\n serverFarmId: appPlan.id\n httpsOnly: true\n siteConfig: {\n alwaysOn: true\n minTlsVersion: '1.2'\n ftpsState: 'FtpsOnly'\n remoteDebuggingEnabled: false\n http20Enabled: true\n }\n }\n tags: tags\n}\n
","tags":["Azure.AppService.HTTP2","AZR-000078"]},{"location":"en/rules/Azure.AppService.HTTP2/#links","title":"Links","text":"Security \u00b7 App Service \u00b7 Rule \u00b7 2020_12 \u00b7 Important
Configure managed identities to access Azure resources.
","tags":["Azure.AppService.ManagedIdentity","AZR-000082"]},{"location":"en/rules/Azure.AppService.ManagedIdentity/#description","title":"Description","text":"Azure App Service apps must authenticate to Azure resources such as Azure SQL Databases. App Service can use managed identities to authenticate to Azure resource without storing credentials.
Using Azure managed identities have the following benefits:
Consider configuring a managed identity for each App Service app. Also consider using managed identities to authenticate to related Azure services.
","tags":["Azure.AppService.ManagedIdentity","AZR-000082"]},{"location":"en/rules/Azure.AppService.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.AppService.ManagedIdentity","AZR-000082"]},{"location":"en/rules/Azure.AppService.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy App Services that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/sites\",\n \"apiVersion\": \"2021-02-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"kind\": \"web\",\n \"properties\": {\n \"serverFarmId\": \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\",\n \"httpsOnly\": true,\n \"siteConfig\": {\n \"alwaysOn\": true,\n \"minTlsVersion\": \"1.2\",\n \"ftpsState\": \"FtpsOnly\",\n \"remoteDebuggingEnabled\": false,\n \"http20Enabled\": true\n }\n },\n \"tags\": \"[parameters('tags')]\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\"\n ]\n}\n
","tags":["Azure.AppService.ManagedIdentity","AZR-000082"]},{"location":"en/rules/Azure.AppService.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Services that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource webApp 'Microsoft.Web/sites@2021-02-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n kind: 'web'\n properties: {\n serverFarmId: plan.id\n httpsOnly: true\n siteConfig: {\n alwaysOn: true\n minTlsVersion: '1.2'\n ftpsState: 'FtpsOnly'\n remoteDebuggingEnabled: false\n http20Enabled: true\n }\n }\n tags: tags\n}\n
","tags":["Azure.AppService.ManagedIdentity","AZR-000082"]},{"location":"en/rules/Azure.AppService.ManagedIdentity/#links","title":"Links","text":"Performance Efficiency \u00b7 App Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use at least a Standard App Service Plan.
","tags":["Azure.AppService.MinPlan","AZR-000072"]},{"location":"en/rules/Azure.AppService.MinPlan/#description","title":"Description","text":"Azure App Services provide a range of different plans that can be used to scale your application. Each plan provides different levels of performance and features.
To get you started a number of entry level plans are available. The Free
, Shared
, and Basic
plans can be used for limited testing and development. However these plans are not suitable for production use. Production workloads are best suited to standard and premium plans with PremiumV3
the newest plan.
This rule does not apply to consumption or elastic App Services Plans used for Azure Functions.
","tags":["Azure.AppService.MinPlan","AZR-000072"]},{"location":"en/rules/Azure.AppService.MinPlan/#recommendation","title":"Recommendation","text":"Consider using a standard or premium plan for hosting apps on Azure App Service.
","tags":["Azure.AppService.MinPlan","AZR-000072"]},{"location":"en/rules/Azure.AppService.MinPlan/#examples","title":"Examples","text":"","tags":["Azure.AppService.MinPlan","AZR-000072"]},{"location":"en/rules/Azure.AppService.MinPlan/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy App Services Plans that pass this rule:
sku.tier
to a plan equal to or greater than Standard
. For example: PremiumV3
, PremiumV2
, Premium
, Standard
For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/serverfarms\",\n \"apiVersion\": \"2022-09-01\",\n \"name\": \"[parameters('planName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"S1\",\n \"tier\": \"Standard\",\n \"capacity\": 2\n }\n}\n
","tags":["Azure.AppService.MinPlan","AZR-000072"]},{"location":"en/rules/Azure.AppService.MinPlan/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Services Plans that pass this rule:
sku.tier
to a plan equal to or greater than Standard
. For example: PremiumV3
, PremiumV2
, Premium
, Standard
For example:
Azure Bicep snippetresource plan 'Microsoft.Web/serverfarms@2022-09-01' = {\n name: planName\n location: location\n sku: {\n name: 'S1'\n tier: 'Standard'\n capacity: 2\n }\n}\n
","tags":["Azure.AppService.MinPlan","AZR-000072"]},{"location":"en/rules/Azure.AppService.MinPlan/#links","title":"Links","text":"Security \u00b7 App Service \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
App Service should reject TLS versions older than 1.2.
","tags":["Azure.AppService.MinTLS","AZR-000073"]},{"location":"en/rules/Azure.AppService.MinTLS/#description","title":"Description","text":"The minimum version of TLS that Azure App Service accepts is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
App Service lets you disable outdated protocols and enforce TLS 1.2. By default, a minimum of TLS 1.2 is enforced.
","tags":["Azure.AppService.MinTLS","AZR-000073"]},{"location":"en/rules/Azure.AppService.MinTLS/#recommendation","title":"Recommendation","text":"Consider configuring the minimum supported TLS version to be 1.2. Also consider using Azure Policy to audit or enforce this configuration.
","tags":["Azure.AppService.MinTLS","AZR-000073"]},{"location":"en/rules/Azure.AppService.MinTLS/#examples","title":"Examples","text":"","tags":["Azure.AppService.MinTLS","AZR-000073"]},{"location":"en/rules/Azure.AppService.MinTLS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy App Services that pass this rule:
properties.siteConfig.minTlsVersion
property to 1.2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/sites\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"kind\": \"web\",\n \"properties\": {\n \"serverFarmId\": \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\",\n \"httpsOnly\": true,\n \"siteConfig\": {\n \"alwaysOn\": true,\n \"minTlsVersion\": \"1.2\",\n \"ftpsState\": \"Disabled\",\n \"remoteDebuggingEnabled\": false,\n \"http20Enabled\": true,\n \"netFrameworkVersion\": \"v8.0\",\n \"healthCheckPath\": \"/healthz\",\n \"metadata\": [\n {\n \"name\": \"CURRENT_STACK\",\n \"value\": \"dotnet\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\"\n ]\n}\n
","tags":["Azure.AppService.MinTLS","AZR-000073"]},{"location":"en/rules/Azure.AppService.MinTLS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Services that pass this rule:
properties.siteConfig.minTlsVersion
property to 1.2
.For example:
Azure Bicep snippetresource web 'Microsoft.Web/sites@2023-01-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n kind: 'web'\n properties: {\n serverFarmId: plan.id\n httpsOnly: true\n siteConfig: {\n alwaysOn: true\n minTlsVersion: '1.2'\n ftpsState: 'Disabled'\n remoteDebuggingEnabled: false\n http20Enabled: true\n netFrameworkVersion: 'v8.0'\n healthCheckPath: '/healthz'\n metadata: [\n {\n name: 'CURRENT_STACK'\n value: 'dotnet'\n }\n ]\n }\n }\n}\n
","tags":["Azure.AppService.MinTLS","AZR-000073"]},{"location":"en/rules/Azure.AppService.MinTLS/#links","title":"Links","text":"Security \u00b7 App Service \u00b7 Rule \u00b7 2024_03 \u00b7 Important
Configure applications to use newer .NET versions.
","tags":["Azure.AppService.NETVersion","AZR-000075"]},{"location":"en/rules/Azure.AppService.NETVersion/#description","title":"Description","text":"Within a App Service app, the version of .NET used to run application/ site code is configurable.
Overtime, a specific version of .NET may become outdated and no longer supported by Microsoft. This can lead to security vulnerabilities or are simply not able to use the latest security features.
.NET 6.0 and .NET 7.0 are approaching end of support.
","tags":["Azure.AppService.NETVersion","AZR-000075"]},{"location":"en/rules/Azure.AppService.NETVersion/#recommendation","title":"Recommendation","text":"Consider updating the site to use a newer .NET version such as v8.0
.
To deploy App Services that pass this rule:
properties.siteConfig.netFrameworkVersion
property to v4.0
or v8.0
.properties.siteConfig.linuxFxVersion
property to DOTNET|8.0
. .NET Framework is not supported on Linux-based plans.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/sites\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"kind\": \"web\",\n \"properties\": {\n \"serverFarmId\": \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\",\n \"httpsOnly\": true,\n \"siteConfig\": {\n \"alwaysOn\": true,\n \"minTlsVersion\": \"1.2\",\n \"ftpsState\": \"Disabled\",\n \"remoteDebuggingEnabled\": false,\n \"http20Enabled\": true,\n \"netFrameworkVersion\": \"v8.0\",\n \"healthCheckPath\": \"/healthz\",\n \"metadata\": [\n {\n \"name\": \"CURRENT_STACK\",\n \"value\": \"dotnet\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\"\n ]\n}\n
","tags":["Azure.AppService.NETVersion","AZR-000075"]},{"location":"en/rules/Azure.AppService.NETVersion/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Services that pass this rule:
properties.siteConfig.netFrameworkVersion
property to v4.0
or v8.0
.properties.siteConfig.linuxFxVersion
property to DOTNET|8.0
. .NET Framework is not supported on Linux-based plans.For example:
Azure Bicep snippetresource web 'Microsoft.Web/sites@2023-01-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n kind: 'web'\n properties: {\n serverFarmId: plan.id\n httpsOnly: true\n siteConfig: {\n alwaysOn: true\n minTlsVersion: '1.2'\n ftpsState: 'Disabled'\n remoteDebuggingEnabled: false\n http20Enabled: true\n netFrameworkVersion: 'v8.0'\n healthCheckPath: '/healthz'\n metadata: [\n {\n name: 'CURRENT_STACK'\n value: 'dotnet'\n }\n ]\n }\n }\n}\n
","tags":["Azure.AppService.NETVersion","AZR-000075"]},{"location":"en/rules/Azure.AppService.NETVersion/#_1","title":"Azure.AppService.NETVersion","text":"","tags":["Azure.AppService.NETVersion","AZR-000075"]},{"location":"en/rules/Azure.AppService.NETVersion/#links","title":"Links","text":"Security \u00b7 App Service \u00b7 Rule \u00b7 2024_03 \u00b7 Important
Configure applications to use newer PHP runtime versions.
","tags":["Azure.AppService.PHPVersion","AZR-000076"]},{"location":"en/rules/Azure.AppService.PHPVersion/#description","title":"Description","text":"Within a App Service app, the version of PHP runtime used to run application/ site code is configurable.
Overtime, a specific version of PHP may become outdated and no longer supported by Microsoft in Azure App Service. This can lead to security vulnerabilities or are simply not able to use the latest security features.
PHP 8.0 and 8.1 are approaching end of support.
","tags":["Azure.AppService.PHPVersion","AZR-000076"]},{"location":"en/rules/Azure.AppService.PHPVersion/#recommendation","title":"Recommendation","text":"Consider updating the site to use a newer PHP runtime version such as 8.2
.
To deploy App Services that pass this rule:
properties.siteConfig.linuxFxVersion
to a minimum of PHP|8.2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/sites\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"kind\": \"web\",\n \"properties\": {\n \"serverFarmId\": \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\",\n \"httpsOnly\": true,\n \"clientAffinityEnabled\": false,\n \"siteConfig\": {\n \"alwaysOn\": true,\n \"minTlsVersion\": \"1.2\",\n \"ftpsState\": \"Disabled\",\n \"http20Enabled\": true,\n \"healthCheckPath\": \"/healthz\",\n \"linuxFxVersion\": \"PHP|8.2\"\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\"\n ]\n}\n
","tags":["Azure.AppService.PHPVersion","AZR-000076"]},{"location":"en/rules/Azure.AppService.PHPVersion/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Services that pass this rule:
properties.siteConfig.linuxFxVersion
to a minimum of PHP|8.2
.For example:
Azure Bicep snippetresource php 'Microsoft.Web/sites@2023-01-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n kind: 'web'\n properties: {\n serverFarmId: plan.id\n httpsOnly: true\n clientAffinityEnabled: false\n siteConfig: {\n alwaysOn: true\n minTlsVersion: '1.2'\n ftpsState: 'Disabled'\n http20Enabled: true\n healthCheckPath: '/healthz'\n linuxFxVersion: 'PHP|8.2'\n }\n }\n}\n
","tags":["Azure.AppService.PHPVersion","AZR-000076"]},{"location":"en/rules/Azure.AppService.PHPVersion/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/7261b898-8a84-4db8-9e04-18527132abb3
/providers/Microsoft.Authorization/policyDefinitions/f466b2a6-823d-470d-8ea5-b031e72d79ae
From November 2022 - PHP is only supported on Linux-based plans.
","tags":["Azure.AppService.PHPVersion","AZR-000076"]},{"location":"en/rules/Azure.AppService.PHPVersion/#links","title":"Links","text":"Reliability \u00b7 App Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
App Service Plan should use a minimum number of instances for failover.
","tags":["Azure.AppService.PlanInstanceCount","AZR-000071"]},{"location":"en/rules/Azure.AppService.PlanInstanceCount/#description","title":"Description","text":"App Services Plans provides a configurable number of instances that will run apps. When a single instance is configured your app may be temporarily unavailable during unplanned interruptions. In most circumstances, Azure will self heal faulty app service instances automatically. However during this time there may interruptions to your workload.
This rule does not apply to consumption or elastic App Services Plans.
","tags":["Azure.AppService.PlanInstanceCount","AZR-000071"]},{"location":"en/rules/Azure.AppService.PlanInstanceCount/#recommendation","title":"Recommendation","text":"Consider using an App Service Plan with at least two (2) instances.
","tags":["Azure.AppService.PlanInstanceCount","AZR-000071"]},{"location":"en/rules/Azure.AppService.PlanInstanceCount/#examples","title":"Examples","text":"","tags":["Azure.AppService.PlanInstanceCount","AZR-000071"]},{"location":"en/rules/Azure.AppService.PlanInstanceCount/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy App Services Plans that pass this rule:
sku.capacity
to 2
or more.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/serverfarms\",\n \"apiVersion\": \"2021-01-15\",\n \"name\": \"[parameters('planName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"S1\",\n \"tier\": \"Standard\",\n \"capacity\": 2\n }\n}\n
","tags":["Azure.AppService.PlanInstanceCount","AZR-000071"]},{"location":"en/rules/Azure.AppService.PlanInstanceCount/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Services Plans that pass this rule:
sku.capacity
to 2
or more.For example:
Azure Bicep snippetresource appPlan 'Microsoft.Web/serverfarms@2021-01-15' = {\n name: planName\n location: location\n sku: {\n name: 'S1'\n tier: 'Standard'\n capacity: 2\n }\n}\n
","tags":["Azure.AppService.PlanInstanceCount","AZR-000071"]},{"location":"en/rules/Azure.AppService.PlanInstanceCount/#links","title":"Links","text":"Security \u00b7 App Service \u00b7 Rule \u00b7 2020_12 \u00b7 Important
Disable remote debugging on App Service apps when not in use.
","tags":["Azure.AppService.RemoteDebug","AZR-000074"]},{"location":"en/rules/Azure.AppService.RemoteDebug/#description","title":"Description","text":"Remote debugging can be enabled on apps running within Azure App Services.
To enable remote debugging, App Service allows connectivity to additional ports. While access to remote debugging ports is authenticated, the attack service for an app is increased.
","tags":["Azure.AppService.RemoteDebug","AZR-000074"]},{"location":"en/rules/Azure.AppService.RemoteDebug/#recommendation","title":"Recommendation","text":"Consider disabling remote debugging when not in use.
","tags":["Azure.AppService.RemoteDebug","AZR-000074"]},{"location":"en/rules/Azure.AppService.RemoteDebug/#examples","title":"Examples","text":"","tags":["Azure.AppService.RemoteDebug","AZR-000074"]},{"location":"en/rules/Azure.AppService.RemoteDebug/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy App Services that pass this rule:
properties.siteConfig.remoteDebuggingEnabled
property to false
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/sites\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"kind\": \"web\",\n \"properties\": {\n \"serverFarmId\": \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\",\n \"httpsOnly\": true,\n \"siteConfig\": {\n \"alwaysOn\": true,\n \"minTlsVersion\": \"1.2\",\n \"ftpsState\": \"Disabled\",\n \"remoteDebuggingEnabled\": false,\n \"http20Enabled\": true,\n \"netFrameworkVersion\": \"v8.0\",\n \"healthCheckPath\": \"/healthz\",\n \"metadata\": [\n {\n \"name\": \"CURRENT_STACK\",\n \"value\": \"dotnet\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\"\n ]\n}\n
","tags":["Azure.AppService.RemoteDebug","AZR-000074"]},{"location":"en/rules/Azure.AppService.RemoteDebug/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Services that pass this rule:
properties.siteConfig.remoteDebuggingEnabled
property to false
.For example:
Azure Bicep snippetresource web 'Microsoft.Web/sites@2023-01-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n kind: 'web'\n properties: {\n serverFarmId: plan.id\n httpsOnly: true\n siteConfig: {\n alwaysOn: true\n minTlsVersion: '1.2'\n ftpsState: 'Disabled'\n remoteDebuggingEnabled: false\n http20Enabled: true\n netFrameworkVersion: 'v8.0'\n healthCheckPath: '/healthz'\n metadata: [\n {\n name: 'CURRENT_STACK'\n value: 'dotnet'\n }\n ]\n }\n }\n}\n
","tags":["Azure.AppService.RemoteDebug","AZR-000074"]},{"location":"en/rules/Azure.AppService.RemoteDebug/#links","title":"Links","text":"Security \u00b7 App Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Azure App Service apps should only accept encrypted connections.
","tags":["Azure.AppService.UseHTTPS","AZR-000084"]},{"location":"en/rules/Azure.AppService.UseHTTPS/#description","title":"Description","text":"Azure App Service apps are configured by default to accept encrypted and unencrypted connections. HTTP connections can be automatically redirected to use HTTPS when the HTTPS Only setting is enabled.
Unencrypted communication to App Service apps could allow disclosure of information to an untrusted party.
","tags":["Azure.AppService.UseHTTPS","AZR-000084"]},{"location":"en/rules/Azure.AppService.UseHTTPS/#recommendation","title":"Recommendation","text":"When access using unencrypted HTTP connection is not required consider enabling HTTPS Only. Also consider using Azure Policy to audit or enforce this configuration.
","tags":["Azure.AppService.UseHTTPS","AZR-000084"]},{"location":"en/rules/Azure.AppService.UseHTTPS/#examples","title":"Examples","text":"","tags":["Azure.AppService.UseHTTPS","AZR-000084"]},{"location":"en/rules/Azure.AppService.UseHTTPS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy App Services that pass this rule:
properties.httpsOnly
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/sites\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"kind\": \"web\",\n \"properties\": {\n \"serverFarmId\": \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\",\n \"httpsOnly\": true,\n \"siteConfig\": {\n \"alwaysOn\": true,\n \"minTlsVersion\": \"1.2\",\n \"ftpsState\": \"Disabled\",\n \"remoteDebuggingEnabled\": false,\n \"http20Enabled\": true,\n \"netFrameworkVersion\": \"v8.0\",\n \"healthCheckPath\": \"/healthz\",\n \"metadata\": [\n {\n \"name\": \"CURRENT_STACK\",\n \"value\": \"dotnet\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\"\n ]\n}\n
","tags":["Azure.AppService.UseHTTPS","AZR-000084"]},{"location":"en/rules/Azure.AppService.UseHTTPS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Services that pass this rule:
properties.httpsOnly
property to true
.For example:
Azure Bicep snippetresource web 'Microsoft.Web/sites@2023-01-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n kind: 'web'\n properties: {\n serverFarmId: plan.id\n httpsOnly: true\n siteConfig: {\n alwaysOn: true\n minTlsVersion: '1.2'\n ftpsState: 'Disabled'\n remoteDebuggingEnabled: false\n http20Enabled: true\n netFrameworkVersion: 'v8.0'\n healthCheckPath: '/healthz'\n metadata: [\n {\n name: 'CURRENT_STACK'\n value: 'dotnet'\n }\n ]\n }\n }\n}\n
","tags":["Azure.AppService.UseHTTPS","AZR-000084"]},{"location":"en/rules/Azure.AppService.UseHTTPS/#links","title":"Links","text":"Reliability \u00b7 App Service \u00b7 Rule \u00b7 2022_06 \u00b7 Important
Configure and enable instance health probes.
","tags":["Azure.AppService.WebProbe","AZR-000079"]},{"location":"en/rules/Azure.AppService.WebProbe/#description","title":"Description","text":"Azure App Service monitors a specific path for each web app instance to determine health status. The monitored path should implement functional checks to determine if the app is performing correctly. The checks should include dependencies including those that may not be regularly called.
Regular checks of the monitored path allow Azure App Service to route traffic based on availability.
","tags":["Azure.AppService.WebProbe","AZR-000079"]},{"location":"en/rules/Azure.AppService.WebProbe/#recommendation","title":"Recommendation","text":"Consider configuring a health probe to monitor instance availability.
","tags":["Azure.AppService.WebProbe","AZR-000079"]},{"location":"en/rules/Azure.AppService.WebProbe/#examples","title":"Examples","text":"","tags":["Azure.AppService.WebProbe","AZR-000079"]},{"location":"en/rules/Azure.AppService.WebProbe/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Web Apps that pass this rule:
properties.siteConfig.healthCheckPath
property to a valid application path such as /healthz
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/sites\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"kind\": \"web\",\n \"properties\": {\n \"serverFarmId\": \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\",\n \"httpsOnly\": true,\n \"siteConfig\": {\n \"alwaysOn\": true,\n \"minTlsVersion\": \"1.2\",\n \"ftpsState\": \"Disabled\",\n \"remoteDebuggingEnabled\": false,\n \"http20Enabled\": true,\n \"netFrameworkVersion\": \"v8.0\",\n \"healthCheckPath\": \"/healthz\",\n \"metadata\": [\n {\n \"name\": \"CURRENT_STACK\",\n \"value\": \"dotnet\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\"\n ]\n}\n
","tags":["Azure.AppService.WebProbe","AZR-000079"]},{"location":"en/rules/Azure.AppService.WebProbe/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Web Apps that pass this rule:
properties.siteConfig.healthCheckPath
property to a valid application path such as /healthz
.For example:
Azure Bicep snippetresource web 'Microsoft.Web/sites@2023-01-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n kind: 'web'\n properties: {\n serverFarmId: plan.id\n httpsOnly: true\n siteConfig: {\n alwaysOn: true\n minTlsVersion: '1.2'\n ftpsState: 'Disabled'\n remoteDebuggingEnabled: false\n http20Enabled: true\n netFrameworkVersion: 'v8.0'\n healthCheckPath: '/healthz'\n metadata: [\n {\n name: 'CURRENT_STACK'\n value: 'dotnet'\n }\n ]\n }\n }\n}\n
","tags":["Azure.AppService.WebProbe","AZR-000079"]},{"location":"en/rules/Azure.AppService.WebProbe/#links","title":"Links","text":"Reliability \u00b7 App Service \u00b7 Rule \u00b7 2022_06 \u00b7 Important
Configure a dedicated path for health probe requests.
","tags":["Azure.AppService.WebProbePath","AZR-000080"]},{"location":"en/rules/Azure.AppService.WebProbePath/#description","title":"Description","text":"Azure App Service monitors a specific path for each web app instance to determine health status. The monitored path should implement functional checks to determine if the app is performing correctly. The checks should include dependencies including those that may not be regularly called.
Regular checks of the monitored path allow Azure App Service to route traffic based on availability.
","tags":["Azure.AppService.WebProbePath","AZR-000080"]},{"location":"en/rules/Azure.AppService.WebProbePath/#recommendation","title":"Recommendation","text":"Consider using a dedicated health probe endpoint that implements functional checks.
","tags":["Azure.AppService.WebProbePath","AZR-000080"]},{"location":"en/rules/Azure.AppService.WebProbePath/#examples","title":"Examples","text":"","tags":["Azure.AppService.WebProbePath","AZR-000080"]},{"location":"en/rules/Azure.AppService.WebProbePath/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Web Apps that pass this rule:
properties.siteConfig.healthCheckPath
property to a dedicated application path such as /healthz
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/sites\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"kind\": \"web\",\n \"properties\": {\n \"serverFarmId\": \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\",\n \"httpsOnly\": true,\n \"siteConfig\": {\n \"alwaysOn\": true,\n \"minTlsVersion\": \"1.2\",\n \"ftpsState\": \"Disabled\",\n \"remoteDebuggingEnabled\": false,\n \"http20Enabled\": true,\n \"netFrameworkVersion\": \"v8.0\",\n \"healthCheckPath\": \"/healthz\",\n \"metadata\": [\n {\n \"name\": \"CURRENT_STACK\",\n \"value\": \"dotnet\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\"\n ]\n}\n
","tags":["Azure.AppService.WebProbePath","AZR-000080"]},{"location":"en/rules/Azure.AppService.WebProbePath/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Web Apps that pass this rule:
properties.siteConfig.healthCheckPath
property to a dedicated application path such as /healthz
.For example:
Azure Bicep snippetresource web 'Microsoft.Web/sites@2023-01-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n kind: 'web'\n properties: {\n serverFarmId: plan.id\n httpsOnly: true\n siteConfig: {\n alwaysOn: true\n minTlsVersion: '1.2'\n ftpsState: 'Disabled'\n remoteDebuggingEnabled: false\n http20Enabled: true\n netFrameworkVersion: 'v8.0'\n healthCheckPath: '/healthz'\n metadata: [\n {\n name: 'CURRENT_STACK'\n value: 'dotnet'\n }\n ]\n }\n }\n}\n
","tags":["Azure.AppService.WebProbePath","AZR-000080"]},{"location":"en/rules/Azure.AppService.WebProbePath/#links","title":"Links","text":"Security \u00b7 App Service \u00b7 Rule \u00b7 2022_06 \u00b7 Important
Web apps should disable insecure FTP and configure SFTP when required.
","tags":["Azure.AppService.WebSecureFtp","AZR-000081"]},{"location":"en/rules/Azure.AppService.WebSecureFtp/#description","title":"Description","text":"Azure App Service supports configuration of FTP and SFTP for uploading site content. By default, both FTP and SFTP are enabled. In many circumstances, use of FTP or SFTP is not required for automated deployments.
When interactive deployments are required consider using SFTP instead of FTP. Use of FTP alone is not sufficient to prevent disclosure of sensitive information that may be transferred.
","tags":["Azure.AppService.WebSecureFtp","AZR-000081"]},{"location":"en/rules/Azure.AppService.WebSecureFtp/#recommendation","title":"Recommendation","text":"Consider disabling insecure FTP and configure SFTP only when required. Also consider using Azure Policy to audit or enforce this configuration.
","tags":["Azure.AppService.WebSecureFtp","AZR-000081"]},{"location":"en/rules/Azure.AppService.WebSecureFtp/#examples","title":"Examples","text":"","tags":["Azure.AppService.WebSecureFtp","AZR-000081"]},{"location":"en/rules/Azure.AppService.WebSecureFtp/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Web Apps that pass this rule:
properties.siteConfig.ftpsState
property to FtpsOnly
or Disabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/sites\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"kind\": \"web\",\n \"properties\": {\n \"serverFarmId\": \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\",\n \"httpsOnly\": true,\n \"siteConfig\": {\n \"alwaysOn\": true,\n \"minTlsVersion\": \"1.2\",\n \"ftpsState\": \"Disabled\",\n \"remoteDebuggingEnabled\": false,\n \"http20Enabled\": true,\n \"netFrameworkVersion\": \"v8.0\",\n \"healthCheckPath\": \"/healthz\",\n \"metadata\": [\n {\n \"name\": \"CURRENT_STACK\",\n \"value\": \"dotnet\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\"\n ]\n}\n
","tags":["Azure.AppService.WebSecureFtp","AZR-000081"]},{"location":"en/rules/Azure.AppService.WebSecureFtp/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Web Apps that pass this rule:
properties.siteConfig.ftpsState
property to FtpsOnly
or Disabled
.For example:
Azure Bicep snippetresource web 'Microsoft.Web/sites@2023-01-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n kind: 'web'\n properties: {\n serverFarmId: plan.id\n httpsOnly: true\n siteConfig: {\n alwaysOn: true\n minTlsVersion: '1.2'\n ftpsState: 'Disabled'\n remoteDebuggingEnabled: false\n http20Enabled: true\n netFrameworkVersion: 'v8.0'\n healthCheckPath: '/healthz'\n metadata: [\n {\n name: 'CURRENT_STACK'\n value: 'dotnet'\n }\n ]\n }\n }\n}\n
","tags":["Azure.AppService.WebSecureFtp","AZR-000081"]},{"location":"en/rules/Azure.AppService.WebSecureFtp/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/4d24b6d4-5e53-4a4f-a7f4-618fa573ee4b
/providers/Microsoft.Authorization/policyDefinitions/c285a320-8830-4665-9cc7-bbd05fc7c5c0
/providers/Microsoft.Authorization/policyDefinitions/399b2637-a50f-4f95-96f8-3a145476eb15
/providers/Microsoft.Authorization/policyDefinitions/e1a09430-221d-4d4c-a337-1edb5a1fa9bb
/providers/Microsoft.Authorization/policyDefinitions/9a1b8c48-453a-4044-86c3-d8bfd823e4f5
Security \u00b7 Arc \u00b7 Rule \u00b7 Preview \u00b7 2023_06 \u00b7 Important
Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters.
","tags":["Azure.Arc.Kubernetes.Defender","AZR-000373"]},{"location":"en/rules/Azure.Arc.Kubernetes.Defender/#description","title":"Description","text":"Defender for Containers relies on the Defender extension for several features.
To collect and provide data plane protections of Microsoft Defender for Containers, the extension must be deployed to the Arc connected Kubernetes cluster. The extension will deploy some additional daemon set and deployments to the cluster.
","tags":["Azure.Arc.Kubernetes.Defender","AZR-000373"]},{"location":"en/rules/Azure.Arc.Kubernetes.Defender/#recommendation","title":"Recommendation","text":"Consider deploying the Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters.
","tags":["Azure.Arc.Kubernetes.Defender","AZR-000373"]},{"location":"en/rules/Azure.Arc.Kubernetes.Defender/#examples","title":"Examples","text":"","tags":["Azure.Arc.Kubernetes.Defender","AZR-000373"]},{"location":"en/rules/Azure.Arc.Kubernetes.Defender/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Arc-enabled Kubernetes clusters that pass this rule:
Microsoft.KubernetesConfiguration/extensions
sub-resource (extension resource).properties.extensionType
property to microsoft.azuredefender.kubernetes
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.KubernetesConfiguration/extensions\",\n \"apiVersion\": \"2022-11-01\",\n \"scope\": \"[format('Microsoft.Kubernetes/connectedClusters/{0}', parameters('name'))]\",\n \"name\": \"microsoft.azuredefender.kubernetes\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"extensionType\": \"microsoft.azuredefender.kubernetes\",\n \"configurationSettings\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('logAnalyticsWorkspaceResourceID')]\",\n \"auditLogPath\": \"/var/log/kube-apiserver/audit.log\"\n },\n \"configurationProtectedSettings\": {\n \"omsagent.secret.wsid\": \"[parameters('wsid')]\",\n \"omsagent.secret.key\": \"[parameters('key')]\"\n },\n \"autoUpgradeMinorVersion\": true,\n \"releaseTrain\": \"Stable\",\n \"scope\": {\n \"cluster\": {\n \"releaseNamespace\": \"azuredefender\"\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Kubernetes/connectedClusters', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.Arc.Kubernetes.Defender","AZR-000373"]},{"location":"en/rules/Azure.Arc.Kubernetes.Defender/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Arc-enabled Kubernetes clusters that pass this rule:
Microsoft.KubernetesConfiguration/extensions
sub-resource (extension resource).properties.extensionType
property to microsoft.azuredefender.kubernetes
.For example:
Azure Bicep snippetresource defenderExtension 'Microsoft.KubernetesConfiguration/extensions@2022-11-01' = {\n name: 'microsoft.azuredefender.kubernetes'\n scope: arcKubernetesCluster\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n extensionType: 'microsoft.azuredefender.kubernetes'\n configurationSettings: {\n logAnalyticsWorkspaceResourceID: logAnalyticsWorkspaceResourceID\n auditLogPath: '/var/log/kube-apiserver/audit.log'\n }\n configurationProtectedSettings: {\n 'omsagent.secret.wsid': wsid\n 'omsagent.secret.key': key\n }\n autoUpgradeMinorVersion: true\n releaseTrain: 'Stable'\n scope: {\n cluster: {\n releaseNamespace: 'azuredefender'\n }\n }\n }\n}\n
","tags":["Azure.Arc.Kubernetes.Defender","AZR-000373"]},{"location":"en/rules/Azure.Arc.Kubernetes.Defender/#links","title":"Links","text":"Operational Excellence \u00b7 Arc \u00b7 Rule \u00b7 Preview \u00b7 2023_06 \u00b7 Important
Use a maintenance configuration for Arc-enabled servers.
","tags":["Azure.Arc.Server.MaintenanceConfig","AZR-000374"]},{"location":"en/rules/Azure.Arc.Server.MaintenanceConfig/#description","title":"Description","text":"Arc-enabled servers can be attached to a maintenance configuration which allows customer managed assessments and updates for machine patches within the guest operating system.
","tags":["Azure.Arc.Server.MaintenanceConfig","AZR-000374"]},{"location":"en/rules/Azure.Arc.Server.MaintenanceConfig/#recommendation","title":"Recommendation","text":"Consider automatically managing and applying operating system updates with a maintenance configuration.
","tags":["Azure.Arc.Server.MaintenanceConfig","AZR-000374"]},{"location":"en/rules/Azure.Arc.Server.MaintenanceConfig/#examples","title":"Examples","text":"","tags":["Azure.Arc.Server.MaintenanceConfig","AZR-000374"]},{"location":"en/rules/Azure.Arc.Server.MaintenanceConfig/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Arc-enabled servers that pass this rule:
Microsoft.Maintenance/configurationAssignments
sub-resource (extension resource).properties.maintenanceConfigurationId
property to the linked maintenance configuration resource Id.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Maintenance/configurationAssignments\",\n \"apiVersion\": \"2022-11-01-preview\",\n \"name\": \"[parameters('assignmentName')]\",\n \"location\": \"[parameters('location')]\",\n \"scope\": \"[format('Microsoft.HybridCompute/machines/{0}', parameters('name'))]\",\n \"properties\": {\n \"maintenanceConfigurationId\": \"[parameters('maintenanceConfigurationId')]\"\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.HybridCompute/machines', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.Arc.Server.MaintenanceConfig","AZR-000374"]},{"location":"en/rules/Azure.Arc.Server.MaintenanceConfig/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Arc-enabled servers that pass this rule:
Microsoft.Maintenance/configurationAssignments
sub-resource (extension resource).properties.maintenanceConfigurationId
property to the linked maintenance configuration resource Id.For example:
Azure Bicep snippetresource config 'Microsoft.Maintenance/configurationAssignments@2022-11-01-preview' = {\n name: assignmentName\n location: location\n scope: arcServer\n properties: {\n maintenanceConfigurationId: maintenanceConfigurationId\n }\n}\n
","tags":["Azure.Arc.Server.MaintenanceConfig","AZR-000374"]},{"location":"en/rules/Azure.Arc.Server.MaintenanceConfig/#notes","title":"Notes","text":"Operating system updates with Update Managment center is a preview feature. Not all regions or operating systems are supported, check out the LINKS
section for supported regions. Update management center doesn't support driver updates.
Security \u00b7 Automation Account \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Ensure automation account audit diagnostic logs are enabled.
","tags":["Azure.Automation.AuditLogs","AZR-000088"]},{"location":"en/rules/Azure.Automation.AuditLogs/#description","title":"Description","text":"To capture logs that record interactions with data or the settings of the automation account, diagnostic settings must be configured.
When configuring diagnostic settings, enabled one of the following:
AuditEvent
category.audit
category group.allLogs
category group.Management operations for Automation Account is captured automatically within Azure Activity Logs.
","tags":["Azure.Automation.AuditLogs","AZR-000088"]},{"location":"en/rules/Azure.Automation.AuditLogs/#recommendation","title":"Recommendation","text":"Consider configuring diagnostic settings to record interactions with data or the settings of the Automation Account.
","tags":["Azure.Automation.AuditLogs","AZR-000088"]},{"location":"en/rules/Azure.Automation.AuditLogs/#examples","title":"Examples","text":"","tags":["Azure.Automation.AuditLogs","AZR-000088"]},{"location":"en/rules/Azure.Automation.AuditLogs/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Automation accounts that pass this rule:
AuditEvent
category or audit
category group or allLogs
category group.For example:
Azure Template snippet{\n \"parameters\": {\n \"automationAccountName\": {\n \"defaultValue\": \"automation-account1\",\n \"type\": \"String\"\n },\n \"location\": {\n \"type\": \"String\"\n },\n \"workspaceId\": {\n \"type\": \"String\"\n }\n },\n \"variables\": {},\n \"resources\": [\n {\n \"type\": \"Microsoft.Automation/automationAccounts\",\n \"apiVersion\": \"2021-06-22\",\n \"name\": \"[parameters('automationAccountName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"disableLocalAuth\": false,\n \"sku\": {\n \"name\": \"Basic\"\n },\n \"encryption\": {\n \"keySource\": \"Microsoft.Automation\",\n \"identity\": {}\n }\n }\n },\n {\n \"comments\": \"Enable monitoring of Automation Account operations.\",\n \"type\": \"Microsoft.Insights/diagnosticSettings\",\n \"name\": \"[concat(parameters('automationAccountName'), '/Microsoft.Insights/service')]\",\n \"apiVersion\": \"2021-05-01-preview\",\n \"dependsOn\": [\n \"[concat('Microsoft.Automation/automationAccounts/', parameters('automationAccountName'))]\"\n ],\n \"properties\": {\n \"workspaceId\": \"[parameters('workspaceId')]\",\n \"logs\": [\n {\n \"category\": \"AuditEvent\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n }\n ]\n }\n }\n ]\n}\n
","tags":["Azure.Automation.AuditLogs","AZR-000088"]},{"location":"en/rules/Azure.Automation.AuditLogs/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Automation accounts that pass this rule:
AuditEvent
category or audit
category group or allLogs
category group.For example:
Azure Bicep snippetparam automationAccountName string = 'automation-account1'\nparam location string\nparam workspaceId string\n\nresource automationAccountResource 'Microsoft.Automation/automationAccounts@2021-06-22' = {\n name: automationAccountName\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n disableLocalAuth: false\n sku: {\n name: 'Basic'\n }\n encryption: {\n keySource: 'Microsoft.Automation'\n identity: {}\n }\n }\n}\n\nresource automationAccountName_Microsoft_Insights_service 'Microsoft.Insights/diagnosticSettings@2021-05-01-preview' = {\n name: 'diagnosticSettings'\n properties: {\n workspaceId: workspaceId\n logs: [\n {\n category: 'AuditEvent'\n enabled: true\n retentionPolicy: {\n days: 0\n enabled: false\n }\n }\n ]\n }\n dependsOn: [\n automationAccountResource\n ]\n}\n
","tags":["Azure.Automation.AuditLogs","AZR-000088"]},{"location":"en/rules/Azure.Automation.AuditLogs/#links","title":"Links","text":"Security \u00b7 Automation Account \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Azure Automation variables should be encrypted.
","tags":["Azure.Automation.EncryptVariables","AZR-000086"]},{"location":"en/rules/Azure.Automation.EncryptVariables/#description","title":"Description","text":"Azure Automation allows configuration properties to be saved as variables. Variables are a key/ value pairs, which may contain sensitive information.
When variables are encrypted they can only be access from within the runbook context. Variables not encrypted are visible to anyone with read permissions.
","tags":["Azure.Automation.EncryptVariables","AZR-000086"]},{"location":"en/rules/Azure.Automation.EncryptVariables/#recommendation","title":"Recommendation","text":"Consider encrypting all automation account variables.
Additionally consider, using Key Vault to store secrets. Key Vault improves security by tightly controlling access to secrets and improving management controls.
","tags":["Azure.Automation.EncryptVariables","AZR-000086"]},{"location":"en/rules/Azure.Automation.EncryptVariables/#links","title":"Links","text":"Security \u00b7 Automation Account \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Ensure Managed Identity is used for authentication.
","tags":["Azure.Automation.ManagedIdentity","AZR-000090"]},{"location":"en/rules/Azure.Automation.ManagedIdentity/#description","title":"Description","text":"Azure automation can use Managed Identities to authenticate to Azure resources without storing credentials.
Using managed identities have the following benefits:
Consider configure a managed identity for each Automation Account.
","tags":["Azure.Automation.ManagedIdentity","AZR-000090"]},{"location":"en/rules/Azure.Automation.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.Automation.ManagedIdentity","AZR-000090"]},{"location":"en/rules/Azure.Automation.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Automation Accounts that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Automation/automationAccounts\",\n \"apiVersion\": \"2021-06-22\",\n \"name\": \"[parameters('automation_account_name')]\",\n \"location\": \"australiaeast\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"disableLocalAuth\": false,\n \"sku\": {\n \"name\": \"Basic\"\n },\n \"encryption\": {\n \"keySource\": \"Microsoft.Automation\",\n \"identity\": {}\n }\n }\n}\n
","tags":["Azure.Automation.ManagedIdentity","AZR-000090"]},{"location":"en/rules/Azure.Automation.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Automation Accounts that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource automation_account_name_resource 'Microsoft.Automation/automationAccounts@2021-06-22' = {\n name: automation_account_name\n location: 'australiaeast'\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n disableLocalAuth: false\n sku: {\n name: 'Basic'\n }\n encryption: {\n keySource: 'Microsoft.Automation'\n identity: {}\n }\n }\n}\n
","tags":["Azure.Automation.ManagedIdentity","AZR-000090"]},{"location":"en/rules/Azure.Automation.ManagedIdentity/#links","title":"Links","text":"Operational Excellence \u00b7 Automation Account \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Ensure automation account platform diagnostic logs are enabled.
","tags":["Azure.Automation.PlatformLogs","AZR-000089"]},{"location":"en/rules/Azure.Automation.PlatformLogs/#description","title":"Description","text":"To capture platform logs from Automation Accounts, the following diagnostic log categories should be enabled:
We can also enable all the above with the allLogs
category group.
To capture metric log categories, th following must be enabled as well:
Consider configuring diagnostic settings to capture platform logs from Automation accounts.
","tags":["Azure.Automation.PlatformLogs","AZR-000089"]},{"location":"en/rules/Azure.Automation.PlatformLogs/#notes","title":"Notes","text":"Configure AZURE_AUTOMATIONACCOUNT_ENABLED_PLATFORM_LOG_CATEGORIES_LIST
to enable selective log categories. By default all log categories are selected, as shown below.
# YAML: The default AZURE_AUTOMATIONACCOUNT_ENABLED_PLATFORM_LOG_CATEGORIES_LIST configuration option\nconfiguration:\n AZURE_AUTOMATIONACCOUNT_ENABLED_PLATFORM_LOG_CATEGORIES_LIST: ['JobLogs', 'JobStreams', 'DscNodeStatus', 'AllMetrics']\n
","tags":["Azure.Automation.PlatformLogs","AZR-000089"]},{"location":"en/rules/Azure.Automation.PlatformLogs/#examples","title":"Examples","text":"","tags":["Azure.Automation.PlatformLogs","AZR-000089"]},{"location":"en/rules/Azure.Automation.PlatformLogs/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Automation accounts that pass this rule:
JobLogs
, JobStreams
, DSCNodeStatus
and AllMetrics
categories.For example:
Azure Template snippet{\n \"parameters\": {\n \"automationAccountName\": {\n \"defaultValue\": \"automation-account1\",\n \"type\": \"String\"\n },\n \"location\": {\n \"type\": \"String\"\n },\n \"workspaceId\": {\n \"type\": \"String\"\n }\n },\n \"variables\": {},\n \"resources\": [\n {\n \"type\": \"Microsoft.Automation/automationAccounts\",\n \"apiVersion\": \"2021-06-22\",\n \"name\": \"[parameters('automationAccountName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"disableLocalAuth\": false,\n \"sku\": {\n \"name\": \"Basic\"\n },\n \"encryption\": {\n \"keySource\": \"Microsoft.Automation\",\n \"identity\": {}\n }\n }\n },\n {\n \"comments\": \"Enable monitoring of Automation Account operations.\",\n \"type\": \"Microsoft.Insights/diagnosticSettings\",\n \"name\": \"[concat(parameters('automationAccountName'), '/Microsoft.Insights/service')]\",\n \"apiVersion\": \"2021-05-01-preview\",\n \"dependsOn\": [\n \"[concat('Microsoft.Automation/automationAccounts/', parameters('automationAccountName'))]\"\n ],\n \"properties\": {\n \"workspaceId\": \"[parameters('workspaceId')]\",\n \"logs\": [\n {\n \"category\": \"JobLogs\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n },\n {\n \"category\": \"JobStreams\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n },\n {\n \"category\": \"DSCNodeStatus\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n }\n ],\n \"metrics\": [\n {\n \"category\": \"AllMetrics\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n }\n ]\n }\n }\n ]\n}\n
","tags":["Azure.Automation.PlatformLogs","AZR-000089"]},{"location":"en/rules/Azure.Automation.PlatformLogs/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Automation accounts that pass this rule:
JobLogs
, JobStreams
, DSCNodeStatus
and AllMetrics
categories.For example:
Azure Bicep snippetparam automationAccountName string = 'automation-account1'\nparam location string\nparam workspaceId string\n\nresource automationAccountResource 'Microsoft.Automation/automationAccounts@2021-06-22' = {\n name: automationAccountName\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n disableLocalAuth: false\n sku: {\n name: 'Basic'\n }\n encryption: {\n keySource: 'Microsoft.Automation'\n identity: {}\n }\n }\n}\n\nresource automationAccountName_Microsoft_Insights_service 'Microsoft.Insights/diagnosticSettings@2021-05-01-preview' = {\n name: 'diagnosticSettings'\n properties: {\n workspaceId: workspaceId\n logs: [\n {\n category: 'JobLogs'\n enabled: true\n retentionPolicy: {\n days: 0\n enabled: false\n }\n },\n {\n category: 'JobStreams'\n enabled: true\n retentionPolicy: {\n days: 0\n enabled: false\n }\n },\n {\n category: 'DSCNodeStatus'\n enabled: true\n retentionPolicy: {\n days: 0\n enabled: false\n }\n }\n ]\n metrics: [\n {\n category: 'AllMetrics'\n enabled: true\n retentionPolicy: {\n days: 0\n enabled: false\n }\n }\n ]\n }\n dependsOn: [\n automationAccountResource\n ]\n}\n
","tags":["Azure.Automation.PlatformLogs","AZR-000089"]},{"location":"en/rules/Azure.Automation.PlatformLogs/#links","title":"Links","text":"Security \u00b7 Automation Account \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Do not create webhooks with an expiry time greater than 1 year (default).
","tags":["Azure.Automation.WebHookExpiry","AZR-000087"]},{"location":"en/rules/Azure.Automation.WebHookExpiry/#description","title":"Description","text":"Do not create webhooks with an expiry time greater than 1 year (default).
","tags":["Azure.Automation.WebHookExpiry","AZR-000087"]},{"location":"en/rules/Azure.Automation.WebHookExpiry/#recommendation","title":"Recommendation","text":"An expiry time of 1 year is the default for webhook creation. Webhooks should be programmatically rotated at regular intervals - Microsoft recommends setting a shorter time than the default of 1 year. If authentication is required for a webhook consider implementing a pre-shared key in the header - or using an Azure Function.
","tags":["Azure.Automation.WebHookExpiry","AZR-000087"]},{"location":"en/rules/Azure.BV.Immutable/","title":"Immutability","text":"Azure.BV.ImmutableAZR-000398ErrorSecurity \u00b7 Backup Vault \u00b7 Rule \u00b7 2023_09 \u00b7 Important
Ensure immutability is configured to protect backup data.
","tags":["Azure.BV.Immutable","AZR-000398"]},{"location":"en/rules/Azure.BV.Immutable/#description","title":"Description","text":"Immutability is supported for Backup vaults by configuring the Immutable vault setting.
Immutable vault helps protecting backup data by blocking any operations that could lead to loss of recovery points. Additionally, locking the Immutable vault setting makes it irreversible to prevent any malicious actors from disabling immutability and deleting backups.
For example, an malicious attack may attempt to remove data or delete vaults to prevent recovery to a known good state.
The Immutable vault setting is not enabled per default.
","tags":["Azure.BV.Immutable","AZR-000398"]},{"location":"en/rules/Azure.BV.Immutable/#recommendation","title":"Recommendation","text":"Consider configuring immutability to protect backup data from accidental or malicious deletion.
","tags":["Azure.BV.Immutable","AZR-000398"]},{"location":"en/rules/Azure.BV.Immutable/#examples","title":"Examples","text":"","tags":["Azure.BV.Immutable","AZR-000398"]},{"location":"en/rules/Azure.BV.Immutable/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Backup vaults that pass this rule:
properties.securitySettings.immutabilitySettings.state
to Unlocked
or Locked
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DataProtection/backupVaults\",\n \"apiVersion\": \"2022-11-01-preview\",\n \"name\": \"[parameters('vaultName')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"securitySettings\": {\n \"immutabilitySettings\": {\n \"state\": \"Locked\"\n }\n }\n }\n}\n
","tags":["Azure.BV.Immutable","AZR-000398"]},{"location":"en/rules/Azure.BV.Immutable/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Backup vaults that pass this rule:
properties.securitySettings.immutabilitySettings.state
to Unlocked
or Locked
.For example:
Azure Bicep snippetresource backupVault 'Microsoft.DataProtection/backupVaults@2022-11-01-preview' = {\n name: vaultName\n location: location\n properties: {\n securitySettings: {\n immutabilitySettings: {\n state: 'Locked'\n }\n }\n }\n}\n
","tags":["Azure.BV.Immutable","AZR-000398"]},{"location":"en/rules/Azure.BV.Immutable/#notes","title":"Notes","text":"Note that immutability locking Locked
is irreversible, so ensure to take a well-informed decision when opting to lock. For example, for vaults containing production workloads consider using Locked
. For cases where you are creating and destroying backups and vaults on a regulary basis such as temporary environments consider Unlocked
.
Operational Excellence \u00b7 Bastion \u00b7 Rule \u00b7 2022_12 \u00b7 Awareness
Bastion hosts should meet naming requirements.
","tags":["Azure.Bastion.Name","AZR-000349"]},{"location":"en/rules/Azure.Bastion.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Bastion host names are:
Consider using names that meet Bastion host naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.Bastion.Name","AZR-000349"]},{"location":"en/rules/Azure.Bastion.Name/#notes","title":"Notes","text":"This rule does not check if Bastion host names are unique.
","tags":["Azure.Bastion.Name","AZR-000349"]},{"location":"en/rules/Azure.Bastion.Name/#links","title":"Links","text":"Operational Excellence \u00b7 Content Delivery Network \u00b7 Rule \u00b7 2020_09 \u00b7 Awareness
Azure CDN Endpoint names should meet naming requirements.
","tags":["Azure.CDN.EndpointName","AZR-000091"]},{"location":"en/rules/Azure.CDN.EndpointName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for CDN endpoint names are:
Consider using names that meet CDN endpoint naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.CDN.EndpointName","AZR-000091"]},{"location":"en/rules/Azure.CDN.EndpointName/#notes","title":"Notes","text":"This rule does not check if CDN endpoint names are unique.
","tags":["Azure.CDN.EndpointName","AZR-000091"]},{"location":"en/rules/Azure.CDN.EndpointName/#links","title":"Links","text":"Security \u00b7 Content Delivery Network \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Enforce HTTPS for client connections.
","tags":["Azure.CDN.HTTP","AZR-000093"]},{"location":"en/rules/Azure.CDN.HTTP/#description","title":"Description","text":"When a client connect to CDN content it can use HTTP or HTTPS. Support for both HTTP and HTTPS is enabled by default. When using HTTP, sensitive information may be exposed to an untrusted party.
","tags":["Azure.CDN.HTTP","AZR-000093"]},{"location":"en/rules/Azure.CDN.HTTP/#recommendation","title":"Recommendation","text":"Consider disabling HTTP support on the CDN endpoint origin.
","tags":["Azure.CDN.HTTP","AZR-000093"]},{"location":"en/rules/Azure.CDN.HTTP/#links","title":"Links","text":"Security \u00b7 Content Delivery Network \u00b7 Rule \u00b7 2020_09 \u00b7 Important
Azure CDN endpoints should reject TLS versions older than 1.2.
","tags":["Azure.CDN.MinTLS","AZR-000092"]},{"location":"en/rules/Azure.CDN.MinTLS/#description","title":"Description","text":"The minimum version of TLS that Azure CDN endpoints accept is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Azure lets you disable outdated protocols and require connections to use a minimum of TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 is accepted.
To configure the minimum TLS version, a custom domain must be configured.
","tags":["Azure.CDN.MinTLS","AZR-000092"]},{"location":"en/rules/Azure.CDN.MinTLS/#recommendation","title":"Recommendation","text":"Consider configuring a custom domain and setting the minimum supported TLS version to be 1.2.
","tags":["Azure.CDN.MinTLS","AZR-000092"]},{"location":"en/rules/Azure.CDN.MinTLS/#links","title":"Links","text":"Performance Efficiency \u00b7 Front Door \u00b7 Rule \u00b7 2022_09 \u00b7 Important
Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities.
","tags":["Azure.CDN.UseFrontDoor","AZR-000286"]},{"location":"en/rules/Azure.CDN.UseFrontDoor/#description","title":"Description","text":"Using a CDN is a good way to minimize the load on your application, and maximize availability and performance.
Standard content delivery network (CDN) capability includes the ability to cache files closer to end users to speed up delivery of static files. However, with dynamic web applications, caching that content in edge locations isn't possible because the server generates the content in response to user behavior. Speeding up the delivery of such content is more complex than traditional edge caching and requires an end-to-end solution that finely tunes each element along the entire data path from inception to delivery. With Azure CDN dynamic site acceleration (DSA) optimization, the performance of web pages with dynamic content is measurably improved.
Azure Front Door Standard or Premium SKU offers modern cloud Content Delivery Network (CDN). These SKUs in particular provides fast, reliable, and secure access between users and dynamic web content across the globe.
","tags":["Azure.CDN.UseFrontDoor","AZR-000286"]},{"location":"en/rules/Azure.CDN.UseFrontDoor/#recommendation","title":"Recommendation","text":"Consider using Front Door Standard or Premium SKU to improve performance.
","tags":["Azure.CDN.UseFrontDoor","AZR-000286"]},{"location":"en/rules/Azure.CDN.UseFrontDoor/#examples","title":"Examples","text":"","tags":["Azure.CDN.UseFrontDoor","AZR-000286"]},{"location":"en/rules/Azure.CDN.UseFrontDoor/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy an front door profile that pass this rule:
sku.name
to Standard_AzureFrontDoor
or Premium_AzureFrontDoor
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cdn/profiles\",\n \"apiVersion\": \"2022-05-01-preview\",\n \"name\": \"myFrontDoor\",\n \"location\": \"global\",\n \"sku\": {\n \"name\": \"Standard_AzureFrontDoor\"\n }\n}\n
","tags":["Azure.CDN.UseFrontDoor","AZR-000286"]},{"location":"en/rules/Azure.CDN.UseFrontDoor/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy an front door profile that pass this rule:
sku.name
to Standard_AzureFrontDoor
or Premium_AzureFrontDoor
.For example:
Azure Bicep snippetresource frontDoorProfile 'Microsoft.Cdn/profiles@2021-06-01' = {\n name: 'myFrontDoor'\n location: 'global'\n sku: {\n name: 'Standard_AzureFrontDoor'\n }\n}\n
","tags":["Azure.CDN.UseFrontDoor","AZR-000286"]},{"location":"en/rules/Azure.CDN.UseFrontDoor/#links","title":"Links","text":"Operational Excellence \u00b7 Container App \u00b7 Rule \u00b7 2023_09 \u00b7 Important
Migrate from retired API version to a supported version.
","tags":["Azure.ContainerApp.APIVersion","AZR-000400"]},{"location":"en/rules/Azure.ContainerApp.APIVersion/#description","title":"Description","text":"The API Azure Container Apps control plane API versions 2022-06-01-preview
and 2022-11-01-preview
are on the retirement path and will be retired on the November 16, 2023.
This means you'll no longer be able to create or manage your Azure Container Apps using your existing templates, tools, scripts and programs until they've been updated to a supported API version.
","tags":["Azure.ContainerApp.APIVersion","AZR-000400"]},{"location":"en/rules/Azure.ContainerApp.APIVersion/#recommendation","title":"Recommendation","text":"Consider migrating from a retired API version to a supported version.
","tags":["Azure.ContainerApp.APIVersion","AZR-000400"]},{"location":"en/rules/Azure.ContainerApp.APIVersion/#examples","title":"Examples","text":"","tags":["Azure.ContainerApp.APIVersion","AZR-000400"]},{"location":"en/rules/Azure.ContainerApp.APIVersion/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Container Apps that pass this rule:
apiVersion
to a supported version.For example:
Azure Template snippet{\n \"type\": \"Microsoft.App/containerApps\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('appName')]\",\n \"location\": \"[parameters('location')]\"\n}\n
","tags":["Azure.ContainerApp.APIVersion","AZR-000400"]},{"location":"en/rules/Azure.ContainerApp.APIVersion/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Container Apps that pass this rule:
apiVersion
to a supported version.For example:
Azure Bicep snippetresource containerApp 'Microsoft.App/containerApps@2023-05-01' = {\n name: appName\n location: location\n}\n
","tags":["Azure.ContainerApp.APIVersion","AZR-000400"]},{"location":"en/rules/Azure.ContainerApp.APIVersion/#links","title":"Links","text":"Performance Efficiency \u00b7 Container App \u00b7 Rule \u00b7 2023_09 \u00b7 Important
Disable session affinity to prevent unbalanced distribution.
","tags":["Azure.ContainerApp.DisableAffinity","AZR-000378"]},{"location":"en/rules/Azure.ContainerApp.DisableAffinity/#description","title":"Description","text":"Container apps allows you to configure session affinity (sticky sessions). When enabled, this feature route requests from the same client to the same replica. This feature might be useful for stateful applications that require a consistent connection to the same replica.
However, for stateless applications there is drawbacks to using session affinity. As connections are opened and closed, a subset of replicas might become overloaded with requests, while others are dormant. This can lead to: poor performance and resource utilization; less predictable scaling.
","tags":["Azure.ContainerApp.DisableAffinity","AZR-000378"]},{"location":"en/rules/Azure.ContainerApp.DisableAffinity/#recommendation","title":"Recommendation","text":"Consider using stateful application design and disabling session affinity to evenly distribute requests across each replica.
","tags":["Azure.ContainerApp.DisableAffinity","AZR-000378"]},{"location":"en/rules/Azure.ContainerApp.DisableAffinity/#examples","title":"Examples","text":"","tags":["Azure.ContainerApp.DisableAffinity","AZR-000378"]},{"location":"en/rules/Azure.ContainerApp.DisableAffinity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Container Apps that pass this rule:
properties.configuration.ingress.stickySessions.affinity
to none
or don't specify the property at all.For example:
Azure Template snippet{\n \"type\": \"Microsoft.App/containerApps\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('appName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"environmentId\": \"[resourceId('Microsoft.App/managedEnvironments', parameters('envName'))]\",\n \"template\": {\n \"revisionSuffix\": \"[parameters('revision')]\",\n \"containers\": \"[variables('containers')]\"\n },\n \"configuration\": {\n \"ingress\": {\n \"allowInsecure\": false,\n \"stickySessions\": {\n \"affinity\": \"none\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.App/managedEnvironments', parameters('envName'))]\"\n ]\n}\n
","tags":["Azure.ContainerApp.DisableAffinity","AZR-000378"]},{"location":"en/rules/Azure.ContainerApp.DisableAffinity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Container Apps that pass this rule:
properties.configuration.ingress.stickySessions.affinity
to none
or don't specify the property at all.For example:
Azure Bicep snippetresource containerApp 'Microsoft.App/containerApps@2023-05-01' = {\n name: appName\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n environmentId: containerEnv.id\n template: {\n revisionSuffix: revision\n containers: containers\n }\n configuration: {\n ingress: {\n allowInsecure: false\n stickySessions: {\n affinity: 'none'\n }\n }\n }\n }\n}\n
","tags":["Azure.ContainerApp.DisableAffinity","AZR-000378"]},{"location":"en/rules/Azure.ContainerApp.DisableAffinity/#notes","title":"Notes","text":"This rule may generate false positive results for stateful applications.
","tags":["Azure.ContainerApp.DisableAffinity","AZR-000378"]},{"location":"en/rules/Azure.ContainerApp.DisableAffinity/#links","title":"Links","text":"Security \u00b7 Container App \u00b7 Rule \u00b7 2023_03 \u00b7 Important
Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment.
","tags":["Azure.ContainerApp.ExternalIngress","AZR-000362"]},{"location":"en/rules/Azure.ContainerApp.ExternalIngress/#description","title":"Description","text":"Container apps allows you to expose your container app to the Internet, your VNET, or to other container apps within the same environment by enabling ingress.
When inbound access to the app is required, configure the ingress. Applications that do batch processing or consume events may not require ingress to be enabled.
When external ingress is configured, communication outside the container apps environment is enabled from your private VNET or the Internet. To restrict communication to a private VNET your Container App Environment must be deployed on a custom VNET with an Internal load balancer.
If communication outside your Container Apps Environment is not required, disable external ingress.
","tags":["Azure.ContainerApp.ExternalIngress","AZR-000362"]},{"location":"en/rules/Azure.ContainerApp.ExternalIngress/#recommendation","title":"Recommendation","text":"Consider disabling external ingress.
","tags":["Azure.ContainerApp.ExternalIngress","AZR-000362"]},{"location":"en/rules/Azure.ContainerApp.ExternalIngress/#examples","title":"Examples","text":"","tags":["Azure.ContainerApp.ExternalIngress","AZR-000362"]},{"location":"en/rules/Azure.ContainerApp.ExternalIngress/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Container Apps that pass this rule:
properties.configuration.ingress.external
to false
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.App/containerApps\",\n \"apiVersion\": \"2022-10-01\",\n \"name\": \"[parameters('appName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\",\n \"userAssignedIdentities\": {}\n },\n \"properties\": {\n \"environmentId\": \"[parameters('environmentId')]\",\n \"template\": {\n \"revisionSuffix\": \"\",\n \"containers\": \"[variables('containers')]\"\n },\n \"configuration\": {\n \"ingress\": {\n \"external\": false\n }\n }\n }\n}\n
","tags":["Azure.ContainerApp.ExternalIngress","AZR-000362"]},{"location":"en/rules/Azure.ContainerApp.ExternalIngress/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Container Apps that pass this rule:
properties.configuration.ingress.external
to false
.For example:
Azure Bicep snippetresource containerApp 'Microsoft.App/containerApps@2022-10-01' = {\n name: appName\n location: location\n identity: {\n type: 'SystemAssigned'\n userAssignedIdentities: {}\n }\n properties: {\n environmentId: environmentId\n template: {\n revisionSuffix: ''\n containers: containers\n }\n configuration: {\n ingress: {\n external: false\n }\n }\n }\n}\n
","tags":["Azure.ContainerApp.ExternalIngress","AZR-000362"]},{"location":"en/rules/Azure.ContainerApp.ExternalIngress/#notes","title":"Notes","text":"This rule is skipped by default because there are common cases where external ingress is required. If you don't need external ingress, enable this rule by:
AZURE_CONTAINERAPPS_RESTRICT_INGRESS
configuration option to true
.Security \u00b7 Container App \u00b7 Rule \u00b7 2023_06 \u00b7 Important
Ensure insecure inbound traffic is not permitted to the container app.
","tags":["Azure.ContainerApp.Insecure","AZR-000094"]},{"location":"en/rules/Azure.ContainerApp.Insecure/#description","title":"Description","text":"Container Apps by default will automatically redirect any HTTP requests to HTTPS. In this default configuration any inbound requests will occur over a minimum of TLS 1.2. This secure by default behavior can be overridden by allowing insecure HTTP traffic.
Unencrypted communication to Container Apps could allow disclosure of information to an untrusted party.
","tags":["Azure.ContainerApp.Insecure","AZR-000094"]},{"location":"en/rules/Azure.ContainerApp.Insecure/#recommendation","title":"Recommendation","text":"Consider disabling insecure traffic and require all inbound traffic to be over TLS 1.2.
","tags":["Azure.ContainerApp.Insecure","AZR-000094"]},{"location":"en/rules/Azure.ContainerApp.Insecure/#examples","title":"Examples","text":"","tags":["Azure.ContainerApp.Insecure","AZR-000094"]},{"location":"en/rules/Azure.ContainerApp.Insecure/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy resource that pass this rule:
properties.configuration.ingress.allowInsecure
to false
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.App/containerApps\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('appName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"environmentId\": \"[resourceId('Microsoft.App/managedEnvironments', parameters('envName'))]\",\n \"template\": {\n \"revisionSuffix\": \"[parameters('revision')]\",\n \"containers\": \"[variables('containers')]\"\n },\n \"configuration\": {\n \"ingress\": {\n \"allowInsecure\": false,\n \"stickySessions\": {\n \"affinity\": \"none\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.App/managedEnvironments', parameters('envName'))]\"\n ]\n}\n
","tags":["Azure.ContainerApp.Insecure","AZR-000094"]},{"location":"en/rules/Azure.ContainerApp.Insecure/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy resource that pass this rule:
properties.configuration.ingress.allowInsecure
to false
.For example:
Azure Bicep snippetresource containerApp 'Microsoft.App/containerApps@2023-05-01' = {\n name: appName\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n environmentId: containerEnv.id\n template: {\n revisionSuffix: revision\n containers: containers\n }\n configuration: {\n ingress: {\n allowInsecure: false\n stickySessions: {\n affinity: 'none'\n }\n }\n }\n }\n}\n
","tags":["Azure.ContainerApp.Insecure","AZR-000094"]},{"location":"en/rules/Azure.ContainerApp.Insecure/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/0e80e269-43a4-4ae9-b5bc-178126b8a5cb
Security \u00b7 Container App \u00b7 Rule \u00b7 2023_03 \u00b7 Important
Ensure managed identity is used for authentication.
","tags":["Azure.ContainerApp.ManagedIdentity","AZR-000361"]},{"location":"en/rules/Azure.ContainerApp.ManagedIdentity/#description","title":"Description","text":"Using managed identities have the following benefits:
Consider configure a managed identity for each container app.
","tags":["Azure.ContainerApp.ManagedIdentity","AZR-000361"]},{"location":"en/rules/Azure.ContainerApp.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.ContainerApp.ManagedIdentity","AZR-000361"]},{"location":"en/rules/Azure.ContainerApp.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Container Apps that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
or SystemAssigned,UserAssigned
.identity.type
is UserAssigned
or SystemAssigned,UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.App/containerApps\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('appName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"environmentId\": \"[resourceId('Microsoft.App/managedEnvironments', parameters('envName'))]\",\n \"template\": {\n \"revisionSuffix\": \"[parameters('revision')]\",\n \"containers\": \"[variables('containers')]\"\n },\n \"configuration\": {\n \"ingress\": {\n \"allowInsecure\": false,\n \"stickySessions\": {\n \"affinity\": \"none\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.App/managedEnvironments', parameters('envName'))]\"\n ]\n}\n
","tags":["Azure.ContainerApp.ManagedIdentity","AZR-000361"]},{"location":"en/rules/Azure.ContainerApp.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Container Apps that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
or SystemAssigned,UserAssigned
.identity.type
is UserAssigned
or SystemAssigned,UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource containerApp 'Microsoft.App/containerApps@2023-05-01' = {\n name: appName\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n environmentId: containerEnv.id\n template: {\n revisionSuffix: revision\n containers: containers\n }\n configuration: {\n ingress: {\n allowInsecure: false\n stickySessions: {\n affinity: 'none'\n }\n }\n }\n }\n}\n
","tags":["Azure.ContainerApp.ManagedIdentity","AZR-000361"]},{"location":"en/rules/Azure.ContainerApp.ManagedIdentity/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/b874ab2d-72dd-47f1-8cb5-4a306478a4e7
Using managed identities in scale rules isn't supported. Init containers can't access managed identities.
","tags":["Azure.ContainerApp.ManagedIdentity","AZR-000361"]},{"location":"en/rules/Azure.ContainerApp.ManagedIdentity/#links","title":"Links","text":"Operational Excellence \u00b7 Container App \u00b7 Rule \u00b7 2023_03 \u00b7 Awareness
Container Apps should meet naming requirements.
","tags":["Azure.ContainerApp.Name","AZR-000360"]},{"location":"en/rules/Azure.ContainerApp.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for container app names are:
Consider using container app names thas meets naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.ContainerApp.Name","AZR-000360"]},{"location":"en/rules/Azure.ContainerApp.Name/#notes","title":"Notes","text":"This rule does not check if container app names are unique.
","tags":["Azure.ContainerApp.Name","AZR-000360"]},{"location":"en/rules/Azure.ContainerApp.Name/#links","title":"Links","text":"Security \u00b7 Container App \u00b7 Rule \u00b7 2023_03 \u00b7 Important
Ensure public network access for Container Apps environment is disabled.
","tags":["Azure.ContainerApp.PublicAccess","AZR-000363"]},{"location":"en/rules/Azure.ContainerApp.PublicAccess/#description","title":"Description","text":"Container apps environments allows you to expose your container app to the Internet.
Container apps environments deployed as external resources are available for public requests. External environments are deployed with a virtual IP on an external, public facing IP address.
Disable public network access to improve security by exposing the Container Apps environment through an internal load balancer.
This removes the need for a public IP address and prevents internet access to all Container Apps within the environment.
To provide secure access, instead consider using an Application Gateway or Azure Front Door premium in front of your Container Apps on your private VNET.
","tags":["Azure.ContainerApp.PublicAccess","AZR-000363"]},{"location":"en/rules/Azure.ContainerApp.PublicAccess/#recommendation","title":"Recommendation","text":"Consider disabling public network access.
","tags":["Azure.ContainerApp.PublicAccess","AZR-000363"]},{"location":"en/rules/Azure.ContainerApp.PublicAccess/#examples","title":"Examples","text":"","tags":["Azure.ContainerApp.PublicAccess","AZR-000363"]},{"location":"en/rules/Azure.ContainerApp.PublicAccess/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Container Apps environments that pass this rule:
properties.vnetConfiguration.infrastructureSubnetId
with the resource Id of a subnet.properties.vnetConfiguration.internal
to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.App/containerApps\",\n \"apiVersion\": \"2022-10-01\",\n \"name\": \"[parameters('envName')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"vnetConfiguration\": {\n \"dockerBridgeCidr\": \"[parameters('dockerBridgeCidr')]\",\n \"infrastructureSubnetId\": \"[parameters('infrastructureSubnetId')]\",\n \"internal\": true,\n \"outboundSettings\": {},\n \"platformReservedCidr\": \"[parameters('platformReservedCidr')]\",\n \"platformReservedDnsIP\": \"[parameters('platformReservedDnsIP')]\",\n }\n }\n}\n
","tags":["Azure.ContainerApp.PublicAccess","AZR-000363"]},{"location":"en/rules/Azure.ContainerApp.PublicAccess/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Container Apps environments that pass this rule:
properties.vnetConfiguration.infrastructureSubnetId
with the resource Id of a subnet.properties.vnetConfiguration.internal
to true
.For example:
Azure Bicep snippetresource containerAppEnv 'Microsoft.App/managedEnvironments@2022-10-01' = {\n name: envName\n location: location\n properties: {\n vnetConfiguration: {\n dockerBridgeCidr: dockerBridgeCidr\n infrastructureSubnetId: infrastructureSubnetId\n internal: true\n outboundSettings: {}\n platformReservedCidr: platformReservedCidr\n platformReservedDnsIP: platformReservedDnsIP\n }\n }\n}\n
","tags":["Azure.ContainerApp.PublicAccess","AZR-000363"]},{"location":"en/rules/Azure.ContainerApp.PublicAccess/#links","title":"Links","text":"Security \u00b7 Container App \u00b7 Rule \u00b7 2023_06 \u00b7 Important
IP ingress restrictions mode should be set to allow action for all rules defined.
","tags":["Azure.ContainerApp.RestrictIngress","AZR-000380"]},{"location":"en/rules/Azure.ContainerApp.RestrictIngress/#description","title":"Description","text":"Container apps supports restricting inbound traffic by IP addresses.
This allows container apps to restrict inbound HTTP or TCP traffic by allowing or denying access to a specific list of IP address ranges.
However, configuring a rule with the Deny
action leads to traffic being denied from the IPv4 address or range, but allows all other traffic.
Instead by configuring a rule or multiple rules with the Allow
action traffic is allowed from the IPv4 address or range, but denies all other traffic.
When no IP restriction rules are defined, all inbound traffic is allowed.
IP ingress restrictions mode can be used for container apps within external and internal environments, but internal ones are limited to private addresses only, where external ones supports both public and private addresses.
","tags":["Azure.ContainerApp.RestrictIngress","AZR-000380"]},{"location":"en/rules/Azure.ContainerApp.RestrictIngress/#recommendation","title":"Recommendation","text":"Consider configuring IP restrictions to limit ingress traffic to allowed IP addresses.
","tags":["Azure.ContainerApp.RestrictIngress","AZR-000380"]},{"location":"en/rules/Azure.ContainerApp.RestrictIngress/#examples","title":"Examples","text":"","tags":["Azure.ContainerApp.RestrictIngress","AZR-000380"]},{"location":"en/rules/Azure.ContainerApp.RestrictIngress/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Container Apps that pass this rule:
properties.configuration.ingress.ipSecurityRestrictions
.properties.configuration.ingress.ipSecurityRestrictions
to action Allow
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.App/containerApps\",\n \"apiVersion\": \"2022-11-01-preview\",\n \"name\": \"[parameters('appName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\",\n \"userAssignedIdentities\": {}\n },\n \"properties\": {\n \"environmentId\": \"[parameters('environmentId')]\",\n \"template\": {\n \"revisionSuffix\": \"\",\n \"containers\": \"[variables('containers')]\"\n },\n \"configuration\": {\n \"ingress\": {\n \"external\": false,\n \"ipSecurityRestrictions\": [\n {\n \"action\": \"Allow\",\n \"description\": \"ClientIPAddress_1\",\n \"ipAddressRange\": \"10.1.1.1/32\",\n \"name\": \"ClientIPAddress_1\"\n },\n {\n \"action\": \"Allow\",\n \"description\": \"ClientIPAddress_2\",\n \"ipAddressRange\": \"10.1.2.1/32\",\n \"name\": \"ClientIPAddress_2\"\n }\n ]\n }\n }\n }\n}\n
","tags":["Azure.ContainerApp.RestrictIngress","AZR-000380"]},{"location":"en/rules/Azure.ContainerApp.RestrictIngress/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Container Apps that pass this rule:
properties.configuration.ingress.ipSecurityRestrictions
.properties.configuration.ingress.ipSecurityRestrictions
to action Allow
.For example:
Azure Bicep snippetresource containerApp 'Microsoft.App/containerApps@2022-11-01-preview' = {\n name: appName\n location: location\n identity: {\n type: 'SystemAssigned'\n userAssignedIdentities: {}\n }\n properties: {\n environmentId: environmentId\n template: {\n revisionSuffix: ''\n containers: containers\n }\n configuration: {\n ingress: {\n external: false\n ipSecurityRestrictions: [\n {\n action: 'Allow'\n description: 'ClientIPAddress_1'\n ipAddressRange: '10.1.1.1/32'\n name: 'ClientIPAddress_1'\n }\n {\n action: 'Allow'\n description: 'ClientIPAddress_2'\n ipAddressRange: '10.1.2.1/32'\n name: 'ClientIPAddress_2'\n }\n ]\n }\n }\n }\n}\n
","tags":["Azure.ContainerApp.RestrictIngress","AZR-000380"]},{"location":"en/rules/Azure.ContainerApp.RestrictIngress/#notes","title":"Notes","text":"All rules must be the same type. It is not supported to combine allow rules and deny rules. If no rules are defined at all, the rule will not pass as it expects at least one allow rule to be configured.
","tags":["Azure.ContainerApp.RestrictIngress","AZR-000380"]},{"location":"en/rules/Azure.ContainerApp.RestrictIngress/#links","title":"Links","text":"Reliability \u00b7 Container App \u00b7 Rule \u00b7 2023_03 \u00b7 Awareness
Use of Azure Files volume mounts to persistent storage container data.
","tags":["Azure.ContainerApp.Storage","AZR-000364"]},{"location":"en/rules/Azure.ContainerApp.Storage/#description","title":"Description","text":"Container apps allows you to use different types of storage. This can be achieved by using volume mounts.
There are considerations to be taken, whether persistent storage is suitable for your app or if non-persistent storage is suitable. Apps may require no storage.
By default all files created inside a container are stored on a writable container layer.
Some considerations when using container file system storage:
Usage examples for this can be a stateless web API or a single page application (that just calls APIs).
Some considerations when using storage volume mounts:
Usage examples for this can be a main app container that write log files that are processed by a sidecar container or writing files to a file share to make data accessible by other systems.
","tags":["Azure.ContainerApp.Storage","AZR-000364"]},{"location":"en/rules/Azure.ContainerApp.Storage/#recommendation","title":"Recommendation","text":"Consider using Azure File volume mounts to persistent storage across containers and replicas.
","tags":["Azure.ContainerApp.Storage","AZR-000364"]},{"location":"en/rules/Azure.ContainerApp.Storage/#examples","title":"Examples","text":"","tags":["Azure.ContainerApp.Storage","AZR-000364"]},{"location":"en/rules/Azure.ContainerApp.Storage/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Container Apps that pass this rule:
properties.template.volumes
array to define a volume or several volumes.storageType
of AzureFile
.properties.template.containers.volumeMounts
array.For example with an Azure Files volume:
Azure Template snippet{\n \"type\": \"Microsoft.App/containerApps\",\n \"apiVersion\": \"2022-10-01\",\n \"name\": \"[parameters('appName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\",\n \"userAssignedIdentities\": {}\n },\n \"properties\": {\n \"environmentId\": \"[parameters('environmentId')]\",\n \"template\": {\n \"revisionSuffix\": \"\",\n \"containers\": [\n {\n \"image\": \"mcr.microsoft.com/azuredocs/containerapps-helloworld:latest\",\n \"name\": \"simple-hello-world-container\",\n \"resources\": {\n \"cpu\": \"[json('.25')]\",\n \"memory\": \".5Gi\"\n },\n \"volumeMounts\": [\n {\n \"mountPath\": \"/myfiles\",\n \"volumeName\": \"azure-files-volume\"\n }\n ]\n }\n ],\n \"scale\": {\n \"minReplicas\": 1,\n \"maxReplicas\": 3\n },\n \"volumes\": [\n {\n \"name\": \"azure-files-volume\",\n \"storageType\": \"AzureFile\",\n \"storageName\": \"myazurefiles\"\n }\n ]\n }\n }\n}\n
","tags":["Azure.ContainerApp.Storage","AZR-000364"]},{"location":"en/rules/Azure.ContainerApp.Storage/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Container Apps that pass this rule:
properties.template.volumes
array to define a volume or several volumes.storageType
of AzureFile
.properties.template.containers.volumeMounts
array.For example with an Azure Files volume:
Azure Bicep snippetresource containerApp 'Microsoft.App/containerApps@2022-10-01' = {\n name: appName\n location: location\n identity: {\n type: 'SystemAssigned'\n userAssignedIdentities: {}\n }\n properties: {\n environmentId: environmentId\n template: {\n revisionSuffix: ''\n containers: [\n {\n image: 'mcr.microsoft.com/azuredocs/containerapps-helloworld:latest'\n name: 'simple-hello-world-container'\n resources: {\n cpu: json('.25')\n memory: '.5Gi'\n }\n volumeMounts: [\n {\n mountPath: '/myfiles'\n volumeName: 'azure-files-volume'\n }\n ]\n }\n ]\n scale: {\n minReplicas: 1\n maxReplicas: 3\n }\n volumes: [\n {\n name: 'azure-files-volume'\n storageType: 'AzureFile'\n storageName: 'myazurefiles'\n }\n ]\n }\n }\n}\n
","tags":["Azure.ContainerApp.Storage","AZR-000364"]},{"location":"en/rules/Azure.ContainerApp.Storage/#notes","title":"Notes","text":"To enable Azure Files storage, a storage definition must be defined in the Container Apps Environment.
","tags":["Azure.ContainerApp.Storage","AZR-000364"]},{"location":"en/rules/Azure.ContainerApp.Storage/#links","title":"Links","text":"Operational Excellence \u00b7 Cosmos DB \u00b7 Rule \u00b7 2021_09 \u00b7 Awareness
Cosmos DB account names should meet naming requirements.
","tags":["Azure.Cosmos.AccountName","AZR-000096"]},{"location":"en/rules/Azure.Cosmos.AccountName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Cosmos DB account names are:
Consider using names that meet Cosmos DB account naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.Cosmos.AccountName","AZR-000096"]},{"location":"en/rules/Azure.Cosmos.AccountName/#notes","title":"Notes","text":"This rule does not check if Cosmos DB account names are unique.
","tags":["Azure.Cosmos.AccountName","AZR-000096"]},{"location":"en/rules/Azure.Cosmos.AccountName/#links","title":"Links","text":"Security \u00b7 Cosmos DB \u00b7 Rule \u00b7 2023_06 \u00b7 Critical
Enable Microsoft Defender for Azure Cosmos DB.
","tags":["Azure.Cosmos.DefenderCloud","AZR-000382"]},{"location":"en/rules/Azure.Cosmos.DefenderCloud/#description","title":"Description","text":"Microsoft Defender for Azure Cosmos DB provides additional security insight for Azure Cosmos DB accounts.
Protection is provided by analyzing onboarded Cosmos DB accounts for unusual and potentially harmful attempts to access or exploit the accounts. Which allows Microsoft Defender for Cloud to produce security alerts that are triggered when anomalies in activity occur.
Security alerts for onboarded Cosmos DB accounts shows up in Defender for Cloud with details of the suspicious activity and recommendations on how to investigate and remediate the threats.
Microsoft Defender for Cosmos DB can be enabled at the resource level, but the general recommandation is to enable it at the subscription level and by doing so ensures all Cosmos DB accounts in the subscription will be protected, including future ones. However, enabling it at resource level can be done to protect a specific Azure Cosmos DB account.
","tags":["Azure.Cosmos.DefenderCloud","AZR-000382"]},{"location":"en/rules/Azure.Cosmos.DefenderCloud/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for Azure Cosmos DB to provide additional security insights for Azure Cosmos DB accounts.
","tags":["Azure.Cosmos.DefenderCloud","AZR-000382"]},{"location":"en/rules/Azure.Cosmos.DefenderCloud/#examples","title":"Examples","text":"","tags":["Azure.Cosmos.DefenderCloud","AZR-000382"]},{"location":"en/rules/Azure.Cosmos.DefenderCloud/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Microsoft Defender for Azure Cosmos DB accounts:
Microsoft.DBforMySQL/servers/securityAlertPolicies
sub-resource (extension resource).properties.isEnabled
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/advancedThreatProtectionSettings\",\n \"apiVersion\": \"2019-01-01\",\n \"scope\": \"[format('Microsoft.DocumentDB/databaseAccounts/{0}', parameters('accountName'))]\",\n \"name\": \"current\",\n \"properties\": {\n \"isEnabled\": true\n },\n \"dependsOn\": [\n \"cosmosDbAccount\"\n ]\n}\n
","tags":["Azure.Cosmos.DefenderCloud","AZR-000382"]},{"location":"en/rules/Azure.Cosmos.DefenderCloud/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Microsoft Defender for Azure Cosmos DB accounts:
Microsoft.DBforMySQL/servers/securityAlertPolicies
sub-resource (extension resource).properties.isEnabled
property to true
.For example:
Azure Bicep snippetresource defenderForCosmosDb 'Microsoft.Security/advancedThreatProtectionSettings@2019-01-01' = {\n scope: cosmosDbAccount\n name: 'current'\n properties: {\n isEnabled: true\n }\n}\n
","tags":["Azure.Cosmos.DefenderCloud","AZR-000382"]},{"location":"en/rules/Azure.Cosmos.DefenderCloud/#notes","title":"Notes","text":"Microsoft Defender for Azure Cosmos DB is currently available only for the NoSQL API. When Microsoft Defender for Cosmos DB is enabled at the subscription level, the resource level enablement has no effect as it will be handled by the plan at the subscription level.
","tags":["Azure.Cosmos.DefenderCloud","AZR-000382"]},{"location":"en/rules/Azure.Cosmos.DefenderCloud/#links","title":"Links","text":"Security \u00b7 Cosmos DB \u00b7 Rule \u00b7 2021_09 \u00b7 Important
Use Azure AD identities for management place operations in Azure Cosmos DB.
","tags":["Azure.Cosmos.DisableMetadataWrite","AZR-000095"]},{"location":"en/rules/Azure.Cosmos.DisableMetadataWrite/#description","title":"Description","text":"Cosmos DB provides two authorization options for interacting with the database:
Resource management operations include management of databases, indexes, and containers. By default, keys are permitted to perform resource management operations. You can restrict these operations to Azure Resource Manager (ARM) calls only.
","tags":["Azure.Cosmos.DisableMetadataWrite","AZR-000095"]},{"location":"en/rules/Azure.Cosmos.DisableMetadataWrite/#recommendation","title":"Recommendation","text":"Consider limiting key and resource tokens to data plane operations only. Use Azure AD identities for authorizing account and resource management operations.
","tags":["Azure.Cosmos.DisableMetadataWrite","AZR-000095"]},{"location":"en/rules/Azure.Cosmos.DisableMetadataWrite/#examples","title":"Examples","text":"","tags":["Azure.Cosmos.DisableMetadataWrite","AZR-000095"]},{"location":"en/rules/Azure.Cosmos.DisableMetadataWrite/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Cosmos DB accounts that pass this rule:
Properties.disableKeyBasedMetadataWriteAccess
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DocumentDB/databaseAccounts\",\n \"apiVersion\": \"2021-06-15\",\n \"name\": \"[parameters('dbAccountName')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"consistencyPolicy\": {\n \"defaultConsistencyLevel\": \"Session\"\n },\n \"databaseAccountOfferType\": \"Standard\",\n \"locations\": [\n {\n \"locationName\": \"[parameters('location')]\",\n \"failoverPriority\": 0,\n \"isZoneRedundant\": false\n }\n ],\n \"disableKeyBasedMetadataWriteAccess\": true\n }\n}\n
","tags":["Azure.Cosmos.DisableMetadataWrite","AZR-000095"]},{"location":"en/rules/Azure.Cosmos.DisableMetadataWrite/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Cosmos DB accounts that pass this rule:
Properties.disableKeyBasedMetadataWriteAccess
property to true
.For example:
Azure Bicep snippetresource dbAccount 'Microsoft.DocumentDB/databaseAccounts@2021-06-15' = {\n name: dbAccountName\n location: location\n properties: {\n consistencyPolicy: {\n defaultConsistencyLevel: 'Session'\n }\n databaseAccountOfferType: 'Standard'\n locations: [\n {\n locationName: location\n failoverPriority: 0\n isZoneRedundant: false\n }\n ]\n disableKeyBasedMetadataWriteAccess: true\n }\n}\n
","tags":["Azure.Cosmos.DisableMetadataWrite","AZR-000095"]},{"location":"en/rules/Azure.Cosmos.DisableMetadataWrite/#links","title":"Links","text":"Operational Excellence \u00b7 Data Factory \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Consider migrating to DataFactory v2.
","tags":["Azure.DataFactory.Version","AZR-000097"]},{"location":"en/rules/Azure.DataFactory.Version/#description","title":"Description","text":"Consider migrating to DataFactory v2.
","tags":["Azure.DataFactory.Version","AZR-000097"]},{"location":"en/rules/Azure.DataFactory.Version/#recommendation","title":"Recommendation","text":"Consider migrating to DataFactory v2.
","tags":["Azure.DataFactory.Version","AZR-000097"]},{"location":"en/rules/Azure.Databricks.PublicAccess/","title":"Azure Databricks workspaces should disable public network access","text":"Azure.Databricks.PublicAccessAZR-000410ErrorSecurity \u00b7 Databricks \u00b7 Rule \u00b7 2024_03 \u00b7 Critical
Azure Databricks workspaces should disable public network access.
","tags":["Azure.Databricks.PublicAccess","AZR-000410"]},{"location":"en/rules/Azure.Databricks.PublicAccess/#description","title":"Description","text":"Disabling public network access improves security by ensuring that the resource isn't exposed on the public internet. You can control exposure of your resources by creating private endpoints instead.
","tags":["Azure.Databricks.PublicAccess","AZR-000410"]},{"location":"en/rules/Azure.Databricks.PublicAccess/#recommendation","title":"Recommendation","text":"Consider configuring Databricks workspaces to disable public network access, using private endpoints to control connectivity.
","tags":["Azure.Databricks.PublicAccess","AZR-000410"]},{"location":"en/rules/Azure.Databricks.PublicAccess/#examples","title":"Examples","text":"","tags":["Azure.Databricks.PublicAccess","AZR-000410"]},{"location":"en/rules/Azure.Databricks.PublicAccess/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy workspaces that pass this rule:
properties.publicNetworkAccess
property to Disabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Databricks/workspaces\",\n \"apiVersion\": \"2023-02-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"managedResourceGroupId\": \"[subscriptionResourceId('Microsoft.Resources/resourceGroups', 'example-mg')]\",\n \"publicNetworkAccess\": \"Disabled\",\n \"parameters\": {\n \"enableNoPublicIp\": {\n \"value\": true\n }\n }\n }\n}\n
","tags":["Azure.Databricks.PublicAccess","AZR-000410"]},{"location":"en/rules/Azure.Databricks.PublicAccess/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy workspaces that pass this rule:
properties.publicNetworkAccess
property to Disabled
.For example:
Azure Bicep snippetresource databricks 'Microsoft.Databricks/workspaces@2023-02-01' = {\n name: name\n location: location\n sku: {\n name: 'standard'\n }\n properties: {\n managedResourceGroupId: managedRg.id\n publicNetworkAccess: 'Disabled'\n parameters: {\n enableNoPublicIp: {\n value: true\n }\n }\n }\n}\n
","tags":["Azure.Databricks.PublicAccess","AZR-000410"]},{"location":"en/rules/Azure.Databricks.PublicAccess/#links","title":"Links","text":"Performance Efficiency \u00b7 Databricks \u00b7 Rule \u00b7 2024_03 \u00b7 Critical
Ensure Databricks workspaces are non-trial SKUs for production workloads.
","tags":["Azure.Databricks.SKU","AZR-000409"]},{"location":"en/rules/Azure.Databricks.SKU/#description","title":"Description","text":"An Azure Databricks workspace has three available SKU types to support the compute demands of a workspace.
The Trial SKU is a time-bound offer which has feature and compute limitations, making it unsuitable for production workloads. NB - The Trial SKU is a strong candidate for non-production or innovation workloads which can accept the tiers constraints.
","tags":["Azure.Databricks.SKU","AZR-000409"]},{"location":"en/rules/Azure.Databricks.SKU/#recommendation","title":"Recommendation","text":"Consider configuring Databricks workspaces to use either Standard or Premium tiers, dependant on the workload demands and non-functional requirements (NFRs).
","tags":["Azure.Databricks.SKU","AZR-000409"]},{"location":"en/rules/Azure.Databricks.SKU/#examples","title":"Examples","text":"","tags":["Azure.Databricks.SKU","AZR-000409"]},{"location":"en/rules/Azure.Databricks.SKU/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy workspaces that pass this rule:
sku.name
to a a non-trial tier, i.e. standard
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Databricks/workspaces\",\n \"apiVersion\": \"2023-02-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"managedResourceGroupId\": \"[subscriptionResourceId('Microsoft.Resources/resourceGroups', 'example-mg')]\",\n \"publicNetworkAccess\": \"Disabled\",\n \"parameters\": {\n \"enableNoPublicIp\": {\n \"value\": true\n }\n }\n }\n}\n
","tags":["Azure.Databricks.SKU","AZR-000409"]},{"location":"en/rules/Azure.Databricks.SKU/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy workspaces that pass this rule:
sku.name
to a a non-trial tier, i.e. standard
.For example:
Azure Bicep snippetresource databricks 'Microsoft.Databricks/workspaces@2023-02-01' = {\n name: name\n location: location\n sku: {\n name: 'standard'\n }\n properties: {\n managedResourceGroupId: managedRg.id\n publicNetworkAccess: 'Disabled'\n parameters: {\n enableNoPublicIp: {\n value: true\n }\n }\n }\n}\n
","tags":["Azure.Databricks.SKU","AZR-000409"]},{"location":"en/rules/Azure.Databricks.SKU/#links","title":"Links","text":"Security \u00b7 Databricks \u00b7 Rule \u00b7 2023_09 \u00b7 Critical
Use Databricks workspaces configured for secure cluster connectivity.
","tags":["Azure.Databricks.SecureConnectivity","AZR-000393"]},{"location":"en/rules/Azure.Databricks.SecureConnectivity/#description","title":"Description","text":"An Azure Databricks workspace uses one or more runtime clusters to execute data processing workloads.
When configuring Databricks workspaces, runtime clusters can be configured with or without public IP addresses. Secure cluster connectivity is used when a Databricks workspace is deployed without public IP addresses. Use secure cluster connectivity to simplify security and administration of Databricks networking within Azure.
With secure cluster connectivity enabled:
Consider configuring Databricks workspaces to use secure cluster connectivity.
","tags":["Azure.Databricks.SecureConnectivity","AZR-000393"]},{"location":"en/rules/Azure.Databricks.SecureConnectivity/#examples","title":"Examples","text":"","tags":["Azure.Databricks.SecureConnectivity","AZR-000393"]},{"location":"en/rules/Azure.Databricks.SecureConnectivity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy workspaces that pass this rule:
properties.parameters.enableNoPublicIp.value
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Databricks/workspaces\",\n \"apiVersion\": \"2023-02-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"managedResourceGroupId\": \"[subscriptionResourceId('Microsoft.Resources/resourceGroups', 'example-mg')]\",\n \"publicNetworkAccess\": \"Disabled\",\n \"parameters\": {\n \"enableNoPublicIp\": {\n \"value\": true\n }\n }\n }\n}\n
","tags":["Azure.Databricks.SecureConnectivity","AZR-000393"]},{"location":"en/rules/Azure.Databricks.SecureConnectivity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy workspaces that pass this rule:
properties.parameters.enableNoPublicIp.value
property to true
.For example:
Azure Bicep snippetresource databricks 'Microsoft.Databricks/workspaces@2023-02-01' = {\n name: name\n location: location\n sku: {\n name: 'standard'\n }\n properties: {\n managedResourceGroupId: managedRg.id\n publicNetworkAccess: 'Disabled'\n parameters: {\n enableNoPublicIp: {\n value: true\n }\n }\n }\n}\n
","tags":["Azure.Databricks.SecureConnectivity","AZR-000393"]},{"location":"en/rules/Azure.Databricks.SecureConnectivity/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2023_12 \u00b7 Critical
Enable Microsoft Defender for APIs.
","tags":["Azure.Defender.Api","AZR-000377"]},{"location":"en/rules/Azure.Defender.Api/#description","title":"Description","text":"Microsoft Defender for APIs provides additional security for APIs published in Azure API Management.
Protection is provided by analyzing onboarded APIs. Which allows Microsoft Defender for Cloud to produce security findings.
The inventory and security findings for onboarded APIs is reviewed in the Defender for Cloud API Security dashboard.
These security findings includes API recommendations and runtime threats.
Defender for APIs can be enabled together with the Defender CSPM plan, offering further capabilities.
Microsoft Defender for APIs can be enabled at the subscription level.
","tags":["Azure.Defender.Api","AZR-000377"]},{"location":"en/rules/Azure.Defender.Api/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for APIs to provide additional security for APIs published in Azure API Management.
","tags":["Azure.Defender.Api","AZR-000377"]},{"location":"en/rules/Azure.Defender.Api/#examples","title":"Examples","text":"","tags":["Azure.Defender.Api","AZR-000377"]},{"location":"en/rules/Azure.Defender.Api/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy and enable Defender for APIs configurations that pass this rule:
properties.pricingTier
property to to Standard
.properties.subPlan
property to a plan such as P1
. Other plans are available, currently these are: P1
, P2
, P3
, P4
, and P5
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"Api\",\n \"properties\": {\n \"subPlan\": \"P1\",\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.Defender.Api","AZR-000377"]},{"location":"en/rules/Azure.Defender.Api/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy and enable Defender for APIs configurations that pass this rule:
properties.pricingTier
property to to Standard
.properties.subPlan
property to a plan such as P1
. Other plans are available, currently these are: P1
, P2
, P3
, P4
, and P5
.For example:
Azure Bicep snippetresource defenderForApi 'Microsoft.Security/pricings@2023-01-01' = {\n name: 'Api'\n properties: {\n subPlan: 'P1'\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.Defender.Api","AZR-000377"]},{"location":"en/rules/Azure.Defender.Api/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To enable Microsoft Defender for APIs:
Standard
pricing tier for Microsoft Defender for APIs.For example:
Azure CLI snippetaz security pricing create -n Api --tier standard --subplan P1\n
","tags":["Azure.Defender.Api","AZR-000377"]},{"location":"en/rules/Azure.Defender.Api/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To enable Microsoft Defender for APIs:
Standard
pricing tier for Microsoft Defender for APIs.For example:
Azure PowerShell snippetSet-AzSecurityPricing -Name 'Api' -PricingTier 'Standard' -SubPlan 'P1'\n
","tags":["Azure.Defender.Api","AZR-000377"]},{"location":"en/rules/Azure.Defender.Api/#notes","title":"Notes","text":"Currently only REST APIs published in Azure API Management is supported. Not all regions are supported.
","tags":["Azure.Defender.Api","AZR-000377"]},{"location":"en/rules/Azure.Defender.Api/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Enable Microsoft Defender for App Service.
","tags":["Azure.Defender.AppServices","AZR-000295"]},{"location":"en/rules/Azure.Defender.AppServices/#description","title":"Description","text":"Many attacks are performed first by probing web applications to find and exploit weaknesses. It is crucial to secure your applications, even while running in PaaS services like App Service.
Microsoft Defender for App Service identifies attacks over App Service thanks to cloud scale data analysis. It offers:
The solution is particularly efficient as it can can identify attack methodologies applying to multiple targets. The log data and the infrastructure together are used to enhance Defender for App Service globally.
","tags":["Azure.Defender.AppServices","AZR-000295"]},{"location":"en/rules/Azure.Defender.AppServices/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for App Service to protect your web apps and APIs.
","tags":["Azure.Defender.AppServices","AZR-000295"]},{"location":"en/rules/Azure.Defender.AppServices/#examples","title":"Examples","text":"","tags":["Azure.Defender.AppServices","AZR-000295"]},{"location":"en/rules/Azure.Defender.AppServices/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Defender for App Service:
Standard
pricing tier for Microsoft Defender for App Service.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"AppServices\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.Defender.AppServices","AZR-000295"]},{"location":"en/rules/Azure.Defender.AppServices/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Defender for App Service:
Standard
pricing tier for Microsoft Defender for App Service.For example:
Azure Bicep snippetresource defenderForAppService 'Microsoft.Security/pricings@2022-03-01' = {\n name: 'AppServices'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.Defender.AppServices","AZR-000295"]},{"location":"en/rules/Azure.Defender.AppServices/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz security pricing create -n 'AppServices' --tier 'standard'\n
","tags":["Azure.Defender.AppServices","AZR-000295"]},{"location":"en/rules/Azure.Defender.AppServices/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetSet-AzSecurityPricing -Name 'AppServices' -PricingTier 'Standard'\n
","tags":["Azure.Defender.AppServices","AZR-000295"]},{"location":"en/rules/Azure.Defender.AppServices/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.Defender.AppServices","AZR-000295"]},{"location":"en/rules/Azure.Defender.AppServices/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2023_03 \u00b7 Critical
Enable Microsoft Defender for Azure Resource Manager (ARM).
","tags":["Azure.Defender.Arm","AZR-000354"]},{"location":"en/rules/Azure.Defender.Arm/#description","title":"Description","text":"Microsoft Defender for ARM provides additional protection for control plane activities. It does this by detecting suspicious activities such as disabling security features or attempts at lateral movement.
Protection is provided by analyzing telemetry from Azure Resource Manager operations. Which allows Microsoft Defender for Cloud to detect anomalous activities regardless of the tool used to perform the operation. For example: Azure CLI, Azure Portal, PowerShell, REST API, Terraform, etc.
When anomalous activities occur, Microsoft Defender for ARM shows alerts to relevant members of your organization. These alerts include the details of the suspicious activity and recommendations on how to investigate and remediate threats.
Microsoft Defender for ARM can be enabled at the subscription level.
","tags":["Azure.Defender.Arm","AZR-000354"]},{"location":"en/rules/Azure.Defender.Arm/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for Resource Manager to provide additional protection to control plane activities.
","tags":["Azure.Defender.Arm","AZR-000354"]},{"location":"en/rules/Azure.Defender.Arm/#examples","title":"Examples","text":"","tags":["Azure.Defender.Arm","AZR-000354"]},{"location":"en/rules/Azure.Defender.Arm/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Microsoft Defender for Resource Manager:
Standard
pricing tier for Microsoft Defender for Resource Manager.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"Arm\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.Defender.Arm","AZR-000354"]},{"location":"en/rules/Azure.Defender.Arm/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Microsoft Defender for Resource Manager:
Standard
pricing tier for Microsoft Defender for Resource Manager.For example:
Azure Bicep snippetresource defenderForArm 'Microsoft.Security/pricings@2022-03-01' = {\n name: 'Arm'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.Defender.Arm","AZR-000354"]},{"location":"en/rules/Azure.Defender.Arm/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To enable Microsoft Defender for Resource Manager:
Standard
pricing tier for Microsoft Defender for Resource Manager.For example:
Azure CLI snippetaz security pricing create -n 'Arm' --tier 'standard'\n
","tags":["Azure.Defender.Arm","AZR-000354"]},{"location":"en/rules/Azure.Defender.Arm/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To enable Microsoft Defender for Resource Manager:
Standard
pricing tier for Microsoft Defender for Resource Manager.For example:
Azure PowerShell snippetSet-AzSecurityPricing -Name 'Arm' -PricingTier 'Standard'\n
","tags":["Azure.Defender.Arm","AZR-000354"]},{"location":"en/rules/Azure.Defender.Arm/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.Defender.Arm","AZR-000354"]},{"location":"en/rules/Azure.Defender.Arm/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Enable Microsoft Defender for Containers.
","tags":["Azure.Defender.Containers","AZR-000290"]},{"location":"en/rules/Azure.Defender.Containers/#description","title":"Description","text":"Container-based workloads should be carefully monitored the following three core security aspects:
It is important to adopt a strategy to actively perform those three aspects. One option for doing so is to use Microsoft Defender for Containers.
Defender for Cloud continuously assesses the configurations of your clusters. If any misconfigurations is found, it generates security recommendations. The recommendations available in the Recommendations page allow you to investigate and remediate issues.
Defender for Containers also provides real-time threat protection for your containerized environments. If any suspicious activities is detected, Defender for Container generates an alert. Threat protection at the cluster level is provided by the Defender agent and analysis of the Kubernetes audit logs.
Defender for Containers scans images on push, import, and recently pulled images. Recently pulled images are scanned on a regular basis when they have been pulled within the last 30 days. When scanned, the container image is pulled and executed in an isolated sandbox for scanning. Any detected vulnerabilities are reported to Microsoft Defender for Cloud.
","tags":["Azure.Defender.Containers","AZR-000290"]},{"location":"en/rules/Azure.Defender.Containers/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for Containers to protect your container-based workloads.
","tags":["Azure.Defender.Containers","AZR-000290"]},{"location":"en/rules/Azure.Defender.Containers/#examples","title":"Examples","text":"","tags":["Azure.Defender.Containers","AZR-000290"]},{"location":"en/rules/Azure.Defender.Containers/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Microsoft Defender for Containers:
Standard
pricing tier for Microsoft Defender for Containers.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"Containers\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.Defender.Containers","AZR-000290"]},{"location":"en/rules/Azure.Defender.Containers/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Microsoft Defender for Containers:
Standard
pricing tier for Microsoft Defender for Containers.For example:
Azure Bicep snippetresource defenderForContainers 'Microsoft.Security/pricings@2022-03-01' = {\n name: 'Containers'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.Defender.Containers","AZR-000290"]},{"location":"en/rules/Azure.Defender.Containers/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To enable Microsoft Defender for Containers:
Standard
pricing tier for Microsoft Defender for Containers.For example:
Azure CLI snippetaz security pricing create -n 'Containers' --tier 'standard'\n
","tags":["Azure.Defender.Containers","AZR-000290"]},{"location":"en/rules/Azure.Defender.Containers/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To enable Microsoft Defender for Containers:
Standard
pricing tier for Microsoft Defender for Containers.For example:
Azure PowerShell snippetSet-AzSecurityPricing -Name 'Containers' -PricingTier 'Standard'\n
","tags":["Azure.Defender.Containers","AZR-000290"]},{"location":"en/rules/Azure.Defender.Containers/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.Defender.Containers","AZR-000290"]},{"location":"en/rules/Azure.Defender.Containers/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2023_06 \u00b7 Critical
Enable Microsoft Defender for Azure Cosmos DB.
","tags":["Azure.Defender.CosmosDb","AZR-000379"]},{"location":"en/rules/Azure.Defender.CosmosDb/#description","title":"Description","text":"Microsoft Defender for Azure Cosmos DB provides additional security insight for Azure Cosmos DB accounts.
Protection is provided by analyzing onboarded Cosmos DB accounts for unusual and potentially harmful attempts to access or exploit the accounts. Which allows Microsoft Defender for Cloud to produce security alerts that are triggered when anomalies in activity occur.
Security alerts for onboarded Cosmos DB accounts shows up in Defender for Cloud with details of the suspicious activity and recommendations on how to investigate and remediate the threats.
Microsoft Defender for Cosmos DB can be enabled at the subscription level and by doing so ensures all Cosmos DB accounts in the subscription will be protected, including future ones.
","tags":["Azure.Defender.CosmosDb","AZR-000379"]},{"location":"en/rules/Azure.Defender.CosmosDb/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for Azure Cosmos DB to provide additional security insights for Azure Cosmos DB accounts.
","tags":["Azure.Defender.CosmosDb","AZR-000379"]},{"location":"en/rules/Azure.Defender.CosmosDb/#examples","title":"Examples","text":"","tags":["Azure.Defender.CosmosDb","AZR-000379"]},{"location":"en/rules/Azure.Defender.CosmosDb/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Microsoft Defender for Azure Cosmos DB accounts:
Standard
pricing tier for Microsoft Defender for Azure Cosmos DB.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"CosmosDbs\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.Defender.CosmosDb","AZR-000379"]},{"location":"en/rules/Azure.Defender.CosmosDb/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Microsoft Defender for Azure Cosmos DB accounts:
Standard
pricing tier for Microsoft Defender for Azure Cosmos DB.For example:
Azure Bicep snippetresource defenderForCosmosDb 'Microsoft.Security/pricings@2022-03-01' = {\n name: 'CosmosDbs'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.Defender.CosmosDb","AZR-000379"]},{"location":"en/rules/Azure.Defender.CosmosDb/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To enable Microsoft Defender for Azure Cosmos DB accounts:
Standard
pricing tier for Microsoft Defender for Azure Cosmos DB.For example:
Azure CLI snippetaz security pricing create -n 'CosmosDbs' --tier 'standard'\n
","tags":["Azure.Defender.CosmosDb","AZR-000379"]},{"location":"en/rules/Azure.Defender.CosmosDb/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To enable Microsoft Defender for Azure Cosmos DB accounts:
Standard
pricing tier for Microsoft Defender for Azure Cosmos DB.For example:
Azure PowerShell snippetSet-AzSecurityPricing -Name 'CosmosDbs' -PricingTier 'Standard'\n
","tags":["Azure.Defender.CosmosDb","AZR-000379"]},{"location":"en/rules/Azure.Defender.CosmosDb/#notes","title":"Notes","text":"Microsoft Defender for Azure Cosmos DB is currently available only for the NoSQL API.
","tags":["Azure.Defender.CosmosDb","AZR-000379"]},{"location":"en/rules/Azure.Defender.CosmosDb/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2023_06 \u00b7 Critical
Enable Microsoft Defender Cloud Security Posture Management Standard plan.
","tags":["Azure.Defender.Cspm","AZR-000372"]},{"location":"en/rules/Azure.Defender.Cspm/#description","title":"Description","text":"Microsoft Defender Cloud Security Posture Management (CSPM) provides additional visibility across cloud environments to quickly detect configuration errors and remediate them through automation. It does this by keeping constant eye on the security state of your cloud resources in different environments.
By enabling the Defender Cloud CSPM Standard plan, Microsoft Defender provides advanced posture management capabilities such as:
Microsoft Defender Cloud Security Posture Management (CSPM) can be enabled at the subscription level.
","tags":["Azure.Defender.Cspm","AZR-000372"]},{"location":"en/rules/Azure.Defender.Cspm/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender Cloud Security Posture Management (CSPM) Standard plan to provide additional visibility across cloud environments.
","tags":["Azure.Defender.Cspm","AZR-000372"]},{"location":"en/rules/Azure.Defender.Cspm/#examples","title":"Examples","text":"","tags":["Azure.Defender.Cspm","AZR-000372"]},{"location":"en/rules/Azure.Defender.Cspm/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Microsoft Defender Cloud Security Posture Management Standard plan:
Standard
pricing tier for Microsoft Defender Cloud Security Posture Management.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"CloudPosture\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.Defender.Cspm","AZR-000372"]},{"location":"en/rules/Azure.Defender.Cspm/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Microsoft Defender Cloud Security Posture Management Standard plan:
Standard
pricing tier for Microsoft Defender Cloud Security Posture Management.For example:
Azure Bicep snippetresource defenderCspm 'Microsoft.Security/pricings@2022-03-01' = {\n name: 'CloudPosture'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.Defender.Cspm","AZR-000372"]},{"location":"en/rules/Azure.Defender.Cspm/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"TTo enable Microsoft Defender Cloud Security Posture Management Standard plan:
Standard
pricing tier for Microsoft Defender Cloud Security Posture Management.For example:
Azure CLI snippetaz security pricing create -n 'CloudPosture' --tier 'standard'\n
","tags":["Azure.Defender.Cspm","AZR-000372"]},{"location":"en/rules/Azure.Defender.Cspm/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To enable Microsoft Defender Cloud Security Posture Management Standard plan:
Standard
pricing tier for Microsoft Defender Cloud Security Posture Management.For example:
Azure PowerShell snippetSet-AzSecurityPricing -Name 'CloudPosture' -PricingTier 'Standard'\n
","tags":["Azure.Defender.Cspm","AZR-000372"]},{"location":"en/rules/Azure.Defender.Cspm/#notes","title":"Notes","text":"This rule applies when analyzing resources before deployed (pre-flight) and deployed (in-flight) to Azure.
","tags":["Azure.Defender.Cspm","AZR-000372"]},{"location":"en/rules/Azure.Defender.Cspm/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2023_03 \u00b7 Critical
Enable Microsoft Defender for DNS.
","tags":["Azure.Defender.Dns","AZR-000353"]},{"location":"en/rules/Azure.Defender.Dns/#description","title":"Description","text":"Microsoft Defender for DNS provides additional protection for virtual networks and resources. It does this by monitoring Azure-provided DNS for suspicious and anomalous activity. By analyzing telemetry for DNS, Microsoft Defender for DNS can detect and alert on persistent threats such as:
Microsoft Defender for DNS can be enabled at the subscription level.
","tags":["Azure.Defender.Dns","AZR-000353"]},{"location":"en/rules/Azure.Defender.Dns/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for DNS to provide additional protection to virtual network and resources.
","tags":["Azure.Defender.Dns","AZR-000353"]},{"location":"en/rules/Azure.Defender.Dns/#examples","title":"Examples","text":"","tags":["Azure.Defender.Dns","AZR-000353"]},{"location":"en/rules/Azure.Defender.Dns/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Microsoft Defender for DNS:
Standard
pricing tier for Microsoft Defender for DNS.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"Dns\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.Defender.Dns","AZR-000353"]},{"location":"en/rules/Azure.Defender.Dns/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Microsoft Defender for DNS:
Standard
pricing tier for Microsoft Defender for DNS.For example:
Azure Bicep snippetresource defenderForDns 'Microsoft.Security/pricings@2022-03-01' = {\n name: 'Dns'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.Defender.Dns","AZR-000353"]},{"location":"en/rules/Azure.Defender.Dns/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To enable Microsoft Defender for DNS:
Standard
pricing tier for Microsoft Defender for DNS.For example:
Azure CLI snippetaz security pricing create -n 'Dns' --tier 'standard'\n
","tags":["Azure.Defender.Dns","AZR-000353"]},{"location":"en/rules/Azure.Defender.Dns/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To enable Microsoft Defender for DNS:
Standard
pricing tier for Microsoft Defender for DNS.For example:
Azure PowerShell snippetSet-AzSecurityPricing -Name 'Dns' -PricingTier 'Standard'\n
","tags":["Azure.Defender.Dns","AZR-000353"]},{"location":"en/rules/Azure.Defender.Dns/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.Defender.Dns","AZR-000353"]},{"location":"en/rules/Azure.Defender.Dns/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2023_03 \u00b7 Critical
Enable Microsoft Defender for Key Vault.
","tags":["Azure.Defender.KeyVault","AZR-000352"]},{"location":"en/rules/Azure.Defender.KeyVault/#description","title":"Description","text":"Microsoft Defender for Key Vault provides additional protection for keys and secrets stored in Key Vaults. It does this by detecting unusual and potentially harmful attempts to access or exploit Key Vault accounts. This protection is provided by analyzing telemetry from Key Vault and Microsoft Defender for Cloud.
When anomalous activities occur, Defender for Key Vault shows alerts to relevant members of your organization. These alerts include the details of the suspicious activity and recommendations on how to investigate and remediate threats.
Microsoft Defender for Key Vault can be enabled at the subscription level for all Key Vaults in the subscription. Azure Policy can be used to automatically enable Microsoft Defender for Key Vault a subscription.
","tags":["Azure.Defender.KeyVault","AZR-000352"]},{"location":"en/rules/Azure.Defender.KeyVault/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for Key Vault to provide additional protection to Key Vaults.
","tags":["Azure.Defender.KeyVault","AZR-000352"]},{"location":"en/rules/Azure.Defender.KeyVault/#examples","title":"Examples","text":"","tags":["Azure.Defender.KeyVault","AZR-000352"]},{"location":"en/rules/Azure.Defender.KeyVault/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Microsoft Defender for Key Vault:
Standard
pricing tier for Microsoft Defender for Key Vault.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"KeyVaults\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.Defender.KeyVault","AZR-000352"]},{"location":"en/rules/Azure.Defender.KeyVault/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Microsoft Defender for Key Vault:
Standard
pricing tier for Microsoft Defender for Key Vault.For example:
Azure Bicep snippetresource defenderForKeyVaults 'Microsoft.Security/pricings@2022-03-01' = {\n name: 'KeyVaults'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.Defender.KeyVault","AZR-000352"]},{"location":"en/rules/Azure.Defender.KeyVault/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To enable Microsoft Defender for Key Vault:
Standard
pricing tier for Microsoft Defender for Key Vault.For example:
Azure CLI snippetaz security pricing create -n 'KeyVaults' --tier 'standard'\n
","tags":["Azure.Defender.KeyVault","AZR-000352"]},{"location":"en/rules/Azure.Defender.KeyVault/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To enable Microsoft Defender for Key Vault:
Standard
pricing tier for Microsoft Defender for Key Vault.For example:
Azure PowerShell snippetSet-AzSecurityPricing -Name 'KeyVaults' -PricingTier 'Standard'\n
","tags":["Azure.Defender.KeyVault","AZR-000352"]},{"location":"en/rules/Azure.Defender.KeyVault/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.Defender.KeyVault","AZR-000352"]},{"location":"en/rules/Azure.Defender.KeyVault/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2023_06 \u00b7 Critical
Enable Microsoft Defender for open-source relational databases.
","tags":["Azure.Defender.OssRdb","AZR-000381"]},{"location":"en/rules/Azure.Defender.OssRdb/#description","title":"Description","text":"Microsoft Defender for open-source relational databases provides additional security for open-source relational databases.
The following open-source relational databases are supported:
Protection is provided by analyzing onboarded databases for unusual and potentially harmful attempts to access or exploit databases. Which allows Microsoft Defender for Cloud to produce security alerts that are triggered when anomalies in activity occur.
Security alerts for onboarded databases shows up in Defender for Cloud with details of the suspicious activity and recommendations on how to investigate and remediate the threats.
Microsoft Defender for open-source relational databases can be enabled at the subscription level and by doing so ensures all supported databases in the subscription will be protected, including future ones.
","tags":["Azure.Defender.OssRdb","AZR-000381"]},{"location":"en/rules/Azure.Defender.OssRdb/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for for open-source relational databases to provide additional security for open-source relational databases.
","tags":["Azure.Defender.OssRdb","AZR-000381"]},{"location":"en/rules/Azure.Defender.OssRdb/#examples","title":"Examples","text":"","tags":["Azure.Defender.OssRdb","AZR-000381"]},{"location":"en/rules/Azure.Defender.OssRdb/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Microsoft Defender for open-source relational databases:
Standard
pricing tier for Microsoft Defender for open-source relational databases.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"OpenSourceRelationalDatabases\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.Defender.OssRdb","AZR-000381"]},{"location":"en/rules/Azure.Defender.OssRdb/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Microsoft Defender for open-source relational databases:
Standard
pricing tier for Microsoft Defender for open-source relational databases.For example:
Azure Bicep snippetresource defenderForOssRdb 'Microsoft.Security/pricings@2022-03-01' = {\n name: 'OpenSourceRelationalDatabases'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.Defender.OssRdb","AZR-000381"]},{"location":"en/rules/Azure.Defender.OssRdb/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To enable Microsoft Defender for open-source relational databases:
Standard
pricing tier for Microsoft Defender for open-source relational databases.For example:
Azure CLI snippetaz security pricing create -n 'OpenSourceRelationalDatabases' --tier 'standard'\n
","tags":["Azure.Defender.OssRdb","AZR-000381"]},{"location":"en/rules/Azure.Defender.OssRdb/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To enable Microsoft Defender for open-source relational databases:
Standard
pricing tier for Microsoft Defender for open-source relational databases.For example:
Azure PowerShell snippetSet-AzSecurityPricing -Name 'OpenSourceRelationalDatabases' -PricingTier 'Standard'\n
","tags":["Azure.Defender.OssRdb","AZR-000381"]},{"location":"en/rules/Azure.Defender.OssRdb/#notes","title":"Notes","text":"Microsoft Defender for open-source relational databases is currently available only for the single server deployment model for PostgreSQL and the single server deployment model for MySQL. For PostgreSQL, MySQL and MariaDB General Purpose
and Memory Optimized
tiers are required in order to be protected.
Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Enable Microsoft Defender for SQL servers.
","tags":["Azure.Defender.SQL","AZR-000294"]},{"location":"en/rules/Azure.Defender.SQL/#description","title":"Description","text":"SQL databases are used to store critical and strategic assets for your company and should be carefully secured. Microsoft Defender for SQL represents a single go-to location to manage security capabilities.
Enabling Defender for SQL automatically enables the following advanced SQL security capabilities:
When enable at subscription level, all databases in Azure SQL Database and Azure SQL Managed Instance are protected.
","tags":["Azure.Defender.SQL","AZR-000294"]},{"location":"en/rules/Azure.Defender.SQL/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for SQL to protect your SQL databases.
","tags":["Azure.Defender.SQL","AZR-000294"]},{"location":"en/rules/Azure.Defender.SQL/#examples","title":"Examples","text":"","tags":["Azure.Defender.SQL","AZR-000294"]},{"location":"en/rules/Azure.Defender.SQL/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Microsoft Defender for SQL:
Standard
pricing tier for Microsoft Defender for SQL.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"SqlServers\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.Defender.SQL","AZR-000294"]},{"location":"en/rules/Azure.Defender.SQL/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Microsoft Defender for SQL:
Standard
pricing tier for Microsoft Defender for SQL.For example:
Azure Bicep snippetresource defenderForSQL 'Microsoft.Security/pricings@2022-03-01' = {\n name: 'SqlServers'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.Defender.SQL","AZR-000294"]},{"location":"en/rules/Azure.Defender.SQL/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To enable Microsoft Defender for SQL:
Standard
pricing tier for Microsoft Defender for SQL.For example:
Azure CLI snippetaz security pricing create -n 'SqlServers' --tier 'standard'\n
","tags":["Azure.Defender.SQL","AZR-000294"]},{"location":"en/rules/Azure.Defender.SQL/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To enable Microsoft Defender for SQL:
Standard
pricing tier for Microsoft Defender for SQL.For example:
Azure PowerShell snippetSet-AzSecurityPricing -Name 'SqlServers' -PricingTier 'Standard'\n
","tags":["Azure.Defender.SQL","AZR-000294"]},{"location":"en/rules/Azure.Defender.SQL/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.Defender.SQL","AZR-000294"]},{"location":"en/rules/Azure.Defender.SQL/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Enable Microsoft Defender for SQL servers on machines.
","tags":["Azure.Defender.SQLOnVM","AZR-000297"]},{"location":"en/rules/Azure.Defender.SQLOnVM/#description","title":"Description","text":"SQL databases are used to store critical and strategic assets for your company and should be carefully secured. Microsoft Defender for SQL Servers on machines represents a single go-to location to manage security capabilities.
Enabling Defender for SQL automatically enables vulnerability Assessment for your SQL databases hosted in a VM. It discovers, tracks, and provides guidance to remediate potential database vulnerabilities.
Enabling at subscription level doesn't protect all your SQL servers. A Log Analytics agent must be deployed on the machine and the Log Analytics workspace must have Defender for SQL enabled.
","tags":["Azure.Defender.SQLOnVM","AZR-000297"]},{"location":"en/rules/Azure.Defender.SQLOnVM/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for SQL Servers on machines to protect your SQL servers running on VMs.
","tags":["Azure.Defender.SQLOnVM","AZR-000297"]},{"location":"en/rules/Azure.Defender.SQLOnVM/#examples","title":"Examples","text":"","tags":["Azure.Defender.SQLOnVM","AZR-000297"]},{"location":"en/rules/Azure.Defender.SQLOnVM/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Defender for SQL servers on machines:
Standard
pricing tier for Microsoft Defender for SQL servers on machines.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"SqlServerVirtualMachines\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.Defender.SQLOnVM","AZR-000297"]},{"location":"en/rules/Azure.Defender.SQLOnVM/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Defender for SQL servers on machines:
Standard
pricing tier for Microsoft Defender for SQL servers on machines.For example:
Azure Bicep snippetresource defenderForSQLOnVM 'Microsoft.Security/pricings@2022-03-01' = {\n name: 'SqlServerVirtualMachines'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.Defender.SQLOnVM","AZR-000297"]},{"location":"en/rules/Azure.Defender.SQLOnVM/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz security pricing create -n 'SqlServerVirtualMachines' --tier 'standard'\n
","tags":["Azure.Defender.SQLOnVM","AZR-000297"]},{"location":"en/rules/Azure.Defender.SQLOnVM/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetSet-AzSecurityPricing -Name 'SqlServerVirtualMachines' -PricingTier 'Standard'\n
","tags":["Azure.Defender.SQLOnVM","AZR-000297"]},{"location":"en/rules/Azure.Defender.SQLOnVM/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.Defender.SQLOnVM","AZR-000297"]},{"location":"en/rules/Azure.Defender.SQLOnVM/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Enable Microsoft Defender for Servers.
","tags":["Azure.Defender.Servers","AZR-000293"]},{"location":"en/rules/Azure.Defender.Servers/#description","title":"Description","text":"Microsoft Defender for Servers automatically deploys an agent into your Windows and Linux machines to protect them.
With the unified integration of Microsoft Defender for Endpoint (MDE) you benefit from features like:
Consider using Microsoft Defender for Servers P2 to protect your virtual machines.
","tags":["Azure.Defender.Servers","AZR-000293"]},{"location":"en/rules/Azure.Defender.Servers/#examples","title":"Examples","text":"","tags":["Azure.Defender.Servers","AZR-000293"]},{"location":"en/rules/Azure.Defender.Servers/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Defender for Servers:
Standard
pricing tier for Microsoft Defender for Servers and set the P2
sub plan.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"VirtualMachines\",\n \"properties\": {\n \"pricingTier\": \"Standard\",\n \"subPlan\": \"P2\"\n }\n}\n
","tags":["Azure.Defender.Servers","AZR-000293"]},{"location":"en/rules/Azure.Defender.Servers/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Defender for Servers:
Standard
pricing tier for Microsoft Defender for Servers and set the P2
sub plan.For example:
Azure Bicep snippetresource defenderForServers 'Microsoft.Security/pricings@2022-03-01' = {\n name: 'VirtualMachines'\n properties: {\n pricingTier: 'Standard',\n subPlan: 'P2'\n }\n}\n
","tags":["Azure.Defender.Servers","AZR-000293"]},{"location":"en/rules/Azure.Defender.Servers/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz security pricing create -n 'VirtualMachines' --tier 'standard'\n
","tags":["Azure.Defender.Servers","AZR-000293"]},{"location":"en/rules/Azure.Defender.Servers/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetSet-AzSecurityPricing -Name 'VirtualMachines' -PricingTier 'Standard'\n
","tags":["Azure.Defender.Servers","AZR-000293"]},{"location":"en/rules/Azure.Defender.Servers/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.Defender.Servers","AZR-000293"]},{"location":"en/rules/Azure.Defender.Servers/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 Preview \u00b7 2023_06 \u00b7 Critical
Enable sensitive data threat detection in Microsoft Defender for Storage.
","tags":["Azure.Defender.Storage.DataScan","AZR-000385"]},{"location":"en/rules/Azure.Defender.Storage.DataScan/#description","title":"Description","text":"Sensitive data threat detection is an additional security feature for Microsoft Defender for Storage. When enabled Defender for Storage provides alerts when sensitive data is discovered.
The sensitive data threat detection capability helps teams:
When enabling sensitive data threat detection, the sensitive data categories include built-in sensitive information types (SITs) in the default list of Microsoft Purview. It is possible to customize the Data Sensitivity Discovery for a organization, by creating custom sensitive information types (SITs).
Sensitive data threat detection in Microsoft Defender for Storage can be enabled at the subscription level and by doing so ensures all storage accounts in the subscription will be protected, including future ones.
","tags":["Azure.Defender.Storage.DataScan","AZR-000385"]},{"location":"en/rules/Azure.Defender.Storage.DataScan/#recommendation","title":"Recommendation","text":"Consider using sensitive data threat detection in Microsoft Defender for Storage for all storage accounts in the subscription.
","tags":["Azure.Defender.Storage.DataScan","AZR-000385"]},{"location":"en/rules/Azure.Defender.Storage.DataScan/#examples","title":"Examples","text":"","tags":["Azure.Defender.Storage.DataScan","AZR-000385"]},{"location":"en/rules/Azure.Defender.Storage.DataScan/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable sensitive data threat detection in Microsoft Defender for Storage:
properties.pricingTier
property to Standard
.properties.subPlan
property to DefenderForStorageV2
.SensitiveDataDiscovery
extension.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2024-01-01\",\n \"name\": \"StorageAccounts\",\n \"properties\": {\n \"pricingTier\": \"Standard\",\n \"subPlan\": \"DefenderForStorageV2\",\n \"extensions\": [\n {\n \"name\": \"OnUploadMalwareScanning\",\n \"isEnabled\": \"True\",\n \"additionalExtensionProperties\": {\n \"CapGBPerMonthPerStorageAccount\": \"5000\"\n }\n },\n {\n \"name\": \"SensitiveDataDiscovery\",\n \"isEnabled\": \"True\"\n }\n ]\n }\n}\n
","tags":["Azure.Defender.Storage.DataScan","AZR-000385"]},{"location":"en/rules/Azure.Defender.Storage.DataScan/#configure-with-bicep","title":"Configure with Bicep","text":"To enable sensitive data threat detection in Microsoft Defender for Storage:
properties.pricingTier
property to Standard
.properties.subPlan
property to DefenderForStorageV2
.SensitiveDataDiscovery
extension.For example:
Azure Bicep snippetresource defenderForStorage 'Microsoft.Security/pricings@2024-01-01' = {\n name: 'StorageAccounts'\n properties: {\n pricingTier: 'Standard'\n subPlan: 'DefenderForStorageV2'\n extensions: [\n {\n name: 'OnUploadMalwareScanning'\n isEnabled: 'True'\n additionalExtensionProperties: {\n CapGBPerMonthPerStorageAccount: '5000'\n }\n }\n {\n name: 'SensitiveDataDiscovery'\n isEnabled: 'True'\n }\n ]\n }\n}\n
","tags":["Azure.Defender.Storage.DataScan","AZR-000385"]},{"location":"en/rules/Azure.Defender.Storage.DataScan/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/640d2586-54d2-465f-877f-9ffc1d2109f4
/providers/Microsoft.Authorization/policyDefinitions/cfdc5972-75b3-4418-8ae1-7f5c36839390
This feature is currently in preview.
Sensitive data threat detection is only available in the DefenderForStorageV2
sub plan for Defender for Storage, which offers new features that aren't included in the classic plan.
Not all services and blob types within storage accounts are currently supported. See limitations for more information.
","tags":["Azure.Defender.Storage.DataScan","AZR-000385"]},{"location":"en/rules/Azure.Defender.Storage.DataScan/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2024_03 \u00b7 Critical
Enable Malware Scanning in Microsoft Defender for Storage.
","tags":["Azure.Defender.Storage.MalwareScan","AZR-000383"]},{"location":"en/rules/Azure.Defender.Storage.MalwareScan/#description","title":"Description","text":"Microsoft Defender for Storage provides additional security for storage accounts. One of the features in the Defender for Storage service is malware scanning that is powered by Microsoft Defender Antivirus.
Content uploaded to cloud storage could be malware. Storage accounts can be an entry point and distribution point for malware in the organization. To protect organizations from this threat, content in cloud storage must be scanned for malware before it's accessed.
Malware scanning in Defender for Storage helps protect storage accounts from malicious content by, performing a malware scan on uploaded content in near real time. When the malware scan identifies a malicious file, detailed Microsoft Defenders for Cloud security alerts are generated.
Malware Scanning in Microsoft Defender for Storage can be enabled at the subscription level. This ensures all storage accounts in the subscription will be protected, including future ones.
This can be helpful:
Consider using malware scanning in Microsoft Defender for Storage for all storage accounts in the subscription.
","tags":["Azure.Defender.Storage.MalwareScan","AZR-000383"]},{"location":"en/rules/Azure.Defender.Storage.MalwareScan/#examples","title":"Examples","text":"","tags":["Azure.Defender.Storage.MalwareScan","AZR-000383"]},{"location":"en/rules/Azure.Defender.Storage.MalwareScan/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable malware scanning in Microsoft Defender for Storage:
properties.pricingTier
property to Standard
.properties.subPlan
property to DefenderForStorageV2
.OnUploadMalwareScanning
extension.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2024-01-01\",\n \"name\": \"StorageAccounts\",\n \"properties\": {\n \"pricingTier\": \"Standard\",\n \"subPlan\": \"DefenderForStorageV2\",\n \"extensions\": [\n {\n \"name\": \"OnUploadMalwareScanning\",\n \"isEnabled\": \"True\",\n \"additionalExtensionProperties\": {\n \"CapGBPerMonthPerStorageAccount\": \"5000\"\n }\n },\n {\n \"name\": \"SensitiveDataDiscovery\",\n \"isEnabled\": \"True\"\n }\n ]\n }\n}\n
","tags":["Azure.Defender.Storage.MalwareScan","AZR-000383"]},{"location":"en/rules/Azure.Defender.Storage.MalwareScan/#configure-with-bicep","title":"Configure with Bicep","text":"To enable malware scanning in Microsoft Defender for Storage:
properties.pricingTier
property to Standard
.properties.subPlan
property to DefenderForStorageV2
.OnUploadMalwareScanning
extension.For example:
Azure Bicep snippetresource defenderForStorage 'Microsoft.Security/pricings@2024-01-01' = {\n name: 'StorageAccounts'\n properties: {\n pricingTier: 'Standard'\n subPlan: 'DefenderForStorageV2'\n extensions: [\n {\n name: 'OnUploadMalwareScanning'\n isEnabled: 'True'\n additionalExtensionProperties: {\n CapGBPerMonthPerStorageAccount: '5000'\n }\n }\n {\n name: 'SensitiveDataDiscovery'\n isEnabled: 'True'\n }\n ]\n }\n}\n
","tags":["Azure.Defender.Storage.MalwareScan","AZR-000383"]},{"location":"en/rules/Azure.Defender.Storage.MalwareScan/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/640d2586-54d2-465f-877f-9ffc1d2109f4
/providers/Microsoft.Authorization/policyDefinitions/cfdc5972-75b3-4418-8ae1-7f5c36839390
Malware scanning is only available in the DefenderForStorageV2
sub plan for Defender for Storage, which offers new features that aren't included in the classic plan.
Not all services and blob types within storage accounts are currently supported. See limitations for more information.
","tags":["Azure.Defender.Storage.MalwareScan","AZR-000383"]},{"location":"en/rules/Azure.Defender.Storage.MalwareScan/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2023_06 \u00b7 Critical
Enable Microsoft Defender for Storage.
","tags":["Azure.Defender.Storage","AZR-000296"]},{"location":"en/rules/Azure.Defender.Storage/#description","title":"Description","text":"Microsoft Defender for Storage provides additional security for storage accounts.
Protection is provided by the following which allows Microsoft Defender for Cloud to discover and mitigate potential threats:
Security findings for on-boarded storage accounts shows up in Defender for Cloud with details of the security threats with contextual information.
Defender for Storage can be enabled at the subscription level. This ensures all storage accounts in the subscription will be protected, including future ones.
","tags":["Azure.Defender.Storage","AZR-000296"]},{"location":"en/rules/Azure.Defender.Storage/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for Storage to protect your data hosted in storage accounts.
","tags":["Azure.Defender.Storage","AZR-000296"]},{"location":"en/rules/Azure.Defender.Storage/#examples","title":"Examples","text":"","tags":["Azure.Defender.Storage","AZR-000296"]},{"location":"en/rules/Azure.Defender.Storage/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Defender for Storage:
properties.pricingTier
property to Standard
.properties.subPlan
property to DefenderForStorageV2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2024-01-01\",\n \"name\": \"StorageAccounts\",\n \"properties\": {\n \"pricingTier\": \"Standard\",\n \"subPlan\": \"DefenderForStorageV2\",\n \"extensions\": [\n {\n \"name\": \"OnUploadMalwareScanning\",\n \"isEnabled\": \"True\",\n \"additionalExtensionProperties\": {\n \"CapGBPerMonthPerStorageAccount\": \"5000\"\n }\n },\n {\n \"name\": \"SensitiveDataDiscovery\",\n \"isEnabled\": \"True\"\n }\n ]\n }\n}\n
","tags":["Azure.Defender.Storage","AZR-000296"]},{"location":"en/rules/Azure.Defender.Storage/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Defender for Storage:
properties.pricingTier
property to Standard
.properties.subPlan
property to DefenderForStorageV2
.For example:
Azure Bicep snippetresource defenderForStorage 'Microsoft.Security/pricings@2024-01-01' = {\n name: 'StorageAccounts'\n properties: {\n pricingTier: 'Standard'\n subPlan: 'DefenderForStorageV2'\n extensions: [\n {\n name: 'OnUploadMalwareScanning'\n isEnabled: 'True'\n additionalExtensionProperties: {\n CapGBPerMonthPerStorageAccount: '5000'\n }\n }\n {\n name: 'SensitiveDataDiscovery'\n isEnabled: 'True'\n }\n ]\n }\n}\n
","tags":["Azure.Defender.Storage","AZR-000296"]},{"location":"en/rules/Azure.Defender.Storage/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetSet-AzSecurityPricing -Name 'StorageAccounts' -PricingTier 'Standard' -SubPlan 'DefenderForStorageV2'\n
","tags":["Azure.Defender.Storage","AZR-000296"]},{"location":"en/rules/Azure.Defender.Storage/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/640d2586-54d2-465f-877f-9ffc1d2109f4
/providers/Microsoft.Authorization/policyDefinitions/cfdc5972-75b3-4418-8ae1-7f5c36839390
The DefenderForStorageV2
sub plan represents the new Defender for Storage plan which offers several new benefits that aren't included in the classic plan. The new plan includes more advanced capabilities that can help improve the security of the data and help prevent malicious file uploads, sensitive data exfiltration, and data corruption.
Currently only the Blob Storage
, Azure Files
and Azure Data Lake Storage Gen2
service is supported by Defender for Storage.
Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Microsoft Defender for Cloud email and phone contact details should be set.
","tags":["Azure.DefenderCloud.Contact","AZR-000209"]},{"location":"en/rules/Azure.DefenderCloud.Contact/#description","title":"Description","text":"Security contact details configured in Microsoft Defender for Cloud are used by Microsoft to notify you in response to certain security events.
","tags":["Azure.DefenderCloud.Contact","AZR-000209"]},{"location":"en/rules/Azure.DefenderCloud.Contact/#recommendation","title":"Recommendation","text":"Consider configuring Microsoft Defender for Cloud email and phone contact details.
","tags":["Azure.DefenderCloud.Contact","AZR-000209"]},{"location":"en/rules/Azure.DefenderCloud.Contact/#link","title":"LINK","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Enable auto-provisioning on to improve Microsoft Defender for Cloud insights.
","tags":["Azure.DefenderCloud.Provisioning","AZR-000210"]},{"location":"en/rules/Azure.DefenderCloud.Provisioning/#description","title":"Description","text":"Select resources such as virtual machines (VMs) and VM scale sets require an agent to be installed to collect additional information from the operating system (OS). This information is used to identify missing security updates and additional threats.
By turning auto-provisioning on, Microsoft Defender for Cloud automatically deploys an Azure Monitor agent to VMs on a regular basis.
","tags":["Azure.DefenderCloud.Provisioning","AZR-000210"]},{"location":"en/rules/Azure.DefenderCloud.Provisioning/#recommendation","title":"Recommendation","text":"Consider enabling auto-provisioning to improve Azure Microsoft Defender for Cloud VM insights.
","tags":["Azure.DefenderCloud.Provisioning","AZR-000210"]},{"location":"en/rules/Azure.DefenderCloud.Provisioning/#links","title":"Links","text":"Security \u00b7 Deployment \u00b7 Rule \u00b7 2022_09 \u00b7 Awareness
Use secure parameters for sensitive resource properties.
","tags":["Azure.Deployment.AdminUsername","AZR-000284"]},{"location":"en/rules/Azure.Deployment.AdminUsername/#description","title":"Description","text":"Resource properties can be configured using a hardcoded value or Azure Bicep/ template expressions. When specifying sensitive values use secure parameters such as secureString
or secureObject
.
Sensitive values that use deterministic expressions such as hardcodes string literals or variables are not secure.
","tags":["Azure.Deployment.AdminUsername","AZR-000284"]},{"location":"en/rules/Azure.Deployment.AdminUsername/#recommendation","title":"Recommendation","text":"Sensitive properties should be passed as parameters. Avoid using deterministic values for sensitive properties.
","tags":["Azure.Deployment.AdminUsername","AZR-000284"]},{"location":"en/rules/Azure.Deployment.AdminUsername/#examples","title":"Examples","text":"","tags":["Azure.Deployment.AdminUsername","AZR-000284"]},{"location":"en/rules/Azure.Deployment.AdminUsername/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy resources that pass this rule:
For example:
Azure Template snippet{\n \"type\": \"Microsoft.Compute/virtualMachines\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"zones\": [\n \"1\"\n ],\n \"properties\": {\n \"hardwareProfile\": {\n \"vmSize\": \"Standard_D2s_v3\"\n },\n \"osProfile\": {\n \"computerName\": \"[parameters('name')]\",\n \"adminUsername\": \"[parameters('adminUsername')]\",\n \"adminPassword\": \"[parameters('adminPassword')]\"\n },\n \"storageProfile\": {\n \"imageReference\": {\n \"publisher\": \"MicrosoftWindowsServer\",\n \"offer\": \"WindowsServer\",\n \"sku\": \"[parameters('sku')]\",\n \"version\": \"latest\"\n },\n \"osDisk\": {\n \"name\": \"[format('{0}-disk0', parameters('name'))]\",\n \"caching\": \"ReadWrite\",\n \"createOption\": \"FromImage\",\n \"managedDisk\": {\n \"storageAccountType\": \"Premium_LRS\"\n }\n }\n },\n \"licenseType\": \"Windows_Server\",\n \"networkProfile\": {\n \"networkInterfaces\": [\n {\n \"id\": \"[resourceId('Microsoft.Network/networkInterfaces', format('{0}-nic0', parameters('name')))]\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Network/networkInterfaces', format('{0}-nic0', parameters('name')))]\"\n ]\n}\n
","tags":["Azure.Deployment.AdminUsername","AZR-000284"]},{"location":"en/rules/Azure.Deployment.AdminUsername/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy resources that pass this rule:
For example:
Azure Bicep snippet@secure()\n@description('The name of the local administrator account.')\nparam adminUsername string\n\n@secure()\n@description('A password for the local administrator account.')\nparam adminPassword string\n\nresource vm1 'Microsoft.Compute/virtualMachines@2022-03-01' = {\n name: name\n location: location\n zones: [\n '1'\n ]\n properties: {\n hardwareProfile: {\n vmSize: 'Standard_D2s_v3'\n }\n osProfile: {\n computerName: name\n adminUsername: adminUsername\n adminPassword: adminPassword\n }\n storageProfile: {\n imageReference: {\n publisher: 'MicrosoftWindowsServer'\n offer: 'WindowsServer'\n sku: sku\n version: 'latest'\n }\n osDisk: {\n name: '${name}-disk0'\n caching: 'ReadWrite'\n createOption: 'FromImage'\n managedDisk: {\n storageAccountType: 'Premium_LRS'\n }\n }\n }\n licenseType: 'Windows_Server'\n networkProfile: {\n networkInterfaces: [\n {\n id: nic.id\n }\n ]\n }\n }\n}\n
","tags":["Azure.Deployment.AdminUsername","AZR-000284"]},{"location":"en/rules/Azure.Deployment.AdminUsername/#notes","title":"Notes","text":"Configure AZURE_DEPLOYMENT_SENSITIVE_PROPERTY_NAMES
to specify sensitive property names. By default, the following values are used:
adminUsername
administratorLogin
administratorLoginPassword
Operational Excellence \u00b7 Deployment \u00b7 Rule \u00b7 2023_03 \u00b7 Awareness
Nested deployments should meet naming requirements of deployments.
","tags":["Azure.Deployment.Name","AZR-000359"]},{"location":"en/rules/Azure.Deployment.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Azure deployments names are:
Consider using nested deployment names thas meets naming requirements of deployments. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.Deployment.Name","AZR-000359"]},{"location":"en/rules/Azure.Deployment.Name/#notes","title":"Notes","text":"This rule does not check if nested deployment names are unique.
","tags":["Azure.Deployment.Name","AZR-000359"]},{"location":"en/rules/Azure.Deployment.Name/#links","title":"Links","text":"Security \u00b7 Deployment \u00b7 Rule \u00b7 2022_12 \u00b7 Critical
Do not use Outer deployments when references SecureString or SecureObject parameters.
","tags":["Azure.Deployment.OuterSecret","AZR-000331"]},{"location":"en/rules/Azure.Deployment.OuterSecret/#description","title":"Description","text":"Template child deployments can be scoped as either outer
or inner
. When using outer
scope evaluated deployments, parameters from the parent template are used directly within nested templates instead of enforcing secureString
and secureObject
types.
When passing secure values to nested deployments always use inner
scope deployments to ensure secure values are not logging. Bicep modules always use inner
scope evaluated deployments.
Consider using inner
deployments to prevent secure values from being exposed.
Nested Deployments within an ARM template need the property expressionEvaluationOptions.Scope
to be set to inner
.
{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"adminUsername\": {\n \"type\": \"securestring\",\n \"defaultValue\": \"admin\"\n }\n },\n \"resources\": [\n {\n \"name\": \"nestedDeployment-A\",\n \"type\": \"Microsoft.Resources/deployments\",\n \"apiVersion\": \"2020-10-01\",\n \"properties\": {\n \"expressionEvaluationOptions\": {\n \"scope\": \"inner\"\n },\n \"mode\": \"Incremental\",\n \"template\": {\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"adminUsername\": {\n \"type\": \"securestring\",\n \"defaultValue\": \"password\"\n }\n },\n \"variables\": {},\n \"resources\": [\n {\n \"apiVersion\": \"2019-12-01\",\n \"type\": \"Microsoft.Compute/virtualMachines\",\n \"name\": \"vm-example\",\n \"location\": \"australiaeast\",\n \"properties\": {\n \"osProfile\": {\n \"computerName\": \"vm-example\",\n \"adminUsername\": \"[parameters('adminUsername')]\"\n }\n }\n }\n ]\n }\n }\n }\n ]\n}\n
","tags":["Azure.Deployment.OuterSecret","AZR-000331"]},{"location":"en/rules/Azure.Deployment.OuterSecret/#configure-with-bicep","title":"Configure with Bicep","text":"Bicep templates will do this by default when performing nested deployments.
","tags":["Azure.Deployment.OuterSecret","AZR-000331"]},{"location":"en/rules/Azure.Deployment.OuterSecret/#links","title":"Links","text":"Security \u00b7 Deployment \u00b7 Rule \u00b7 2022_06 \u00b7 Critical
Avoid outputting sensitive deployment values.
","tags":["Azure.Deployment.OutputSecretValue","AZR-000279"]},{"location":"en/rules/Azure.Deployment.OutputSecretValue/#description","title":"Description","text":"Don't include any values in an ARM template or Bicep output that could potentially expose secrets. The output from a template is stored in the deployment history, so a malicious user could find that information.
Examples of secrets are:
secureString
or secureObject
type.list*
functions such as listKeys
.Consider removing any output values that return secret values in code.
","tags":["Azure.Deployment.OutputSecretValue","AZR-000279"]},{"location":"en/rules/Azure.Deployment.OutputSecretValue/#examples","title":"Examples","text":"","tags":["Azure.Deployment.OutputSecretValue","AZR-000279"]},{"location":"en/rules/Azure.Deployment.OutputSecretValue/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy securely pass secrets within Infrastructure as Code:
secureString
or secureObject
type.Example using secureString
type:
{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"adminPassword\": {\n \"type\": \"secureString\",\n \"metadata\": {\n \"description\": \"Local administrator password for virtual machine.\"\n }\n }\n },\n \"resources\": []\n}\n
The following example fails because it returns a secret:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"adminPassword\": {\n \"type\": \"secureString\",\n \"metadata\": {\n \"description\": \"Local administrator password for virtual machine.\"\n }\n }\n },\n \"resources\": [],\n \"outputs\": {\n \"accountPassword\": {\n \"type\": \"string\",\n \"value\": \"[parameters('adminPassword')]\"\n }\n }\n}\n
","tags":["Azure.Deployment.OutputSecretValue","AZR-000279"]},{"location":"en/rules/Azure.Deployment.OutputSecretValue/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy securely pass secrets within Infrastructure as Code:
@secure()
annotation.Example using @secure()
annotation:
@secure()\n@description('Local administrator password for virtual machine.')\nparam adminPassword string\n
The following example fails because it returns a secret:
Azure Bicep snippetoutput accountPassword string = adminPassword\n
","tags":["Azure.Deployment.OutputSecretValue","AZR-000279"]},{"location":"en/rules/Azure.Deployment.OutputSecretValue/#links","title":"Links","text":"Security \u00b7 Deployment \u00b7 Rule \u00b7 2023_12 \u00b7 Critical
Use secure parameters for any parameter that contains sensitive information.
","tags":["Azure.Deployment.SecureParameter","AZR-000408"]},{"location":"en/rules/Azure.Deployment.SecureParameter/#description","title":"Description","text":"Azure Bicep and Azure Resource Manager (ARM) templates can be used to deploy resources to Azure. When deploying Azure resources, sensitive values such as passwords, certificates, and keys should be passed as secure parameters. Secure parameters use the secureString
or secureObject
type.
Parameters that do not use secure types are recorded in logs and deployment history. These values can be retrieved by anyone with access to the deployment history.
","tags":["Azure.Deployment.SecureParameter","AZR-000408"]},{"location":"en/rules/Azure.Deployment.SecureParameter/#recommendation","title":"Recommendation","text":"Consider using secure parameters for parameters that contain sensitive information.
","tags":["Azure.Deployment.SecureParameter","AZR-000408"]},{"location":"en/rules/Azure.Deployment.SecureParameter/#examples","title":"Examples","text":"","tags":["Azure.Deployment.SecureParameter","AZR-000408"]},{"location":"en/rules/Azure.Deployment.SecureParameter/#configure-with-azure-template","title":"Configure with Azure template","text":"To configure deployments that pass this rule:
secureString
or secureObject
.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"secret\": {\n \"type\": \"secureString\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.KeyVault/vaults/secrets\",\n \"apiVersion\": \"2022-07-01\",\n \"name\": \"keyvault/good\",\n \"properties\": {\n \"value\": \"[parameters('secret')]\"\n }\n }\n ]\n}\n
","tags":["Azure.Deployment.SecureParameter","AZR-000408"]},{"location":"en/rules/Azure.Deployment.SecureParameter/#configure-with-bicep","title":"Configure with Bicep","text":"To configure deployments that pass this rule:
@secure()
attribute on sensitive parameters.For example:
Azure Bicep snippet@secure()\nparam secret string\n\nresource goodSecret 'Microsoft.KeyVault/vaults/secrets@2022-07-01' = {\n parent: vault\n name: 'good'\n properties: {\n value: secret\n }\n}\n
","tags":["Azure.Deployment.SecureParameter","AZR-000408"]},{"location":"en/rules/Azure.Deployment.SecureParameter/#notes","title":"Notes","text":"This rule uses a heuristics to determine if a parameter should use a secure type:
int
or bool
are ignored regardless of how they are named.password
, secret
, or token
will be considered sensitive.passwordlength
, secretname
, secreturl
, secreturi
, secretrotation
, secretinterval
, secretprovider
, secretsprovider
, secretref
, secretid
, disablepassword
, sync*passwords
, or tokenname
.key
or keys
will be considered sensitive.publickey
or publickeys
.If you identify a parameter that is not sensitive, and is incorrectly flagged by this rule, you can override the rule. To override this rule:
AZURE_DEPLOYMENT_NONSENSITIVE_PARAMETER_NAMES
configuration value to identify parameters that are not sensitive.Security \u00b7 Deployment \u00b7 Rule \u00b7 2022_12 \u00b7 Critical
Use secure parameters for setting properties of resources that contain sensitive information.
","tags":["Azure.Deployment.SecureValue","AZR-000316"]},{"location":"en/rules/Azure.Deployment.SecureValue/#description","title":"Description","text":"Azure Bicep and Azure Resource Manager (ARM) templates can be used to deploy resources to Azure. When deploying Azure resources, sensitive values such as passwords, certificates, and keys should be passed as secure parameters. Secure parameters use the secureString
or secureObject
type.
Parameters that do not use secure types are recorded in logs and deployment history. These values can be retrieved by anyone with access to the deployment history.
","tags":["Azure.Deployment.SecureValue","AZR-000316"]},{"location":"en/rules/Azure.Deployment.SecureValue/#recommendation","title":"Recommendation","text":"Consider using secure parameters for sensitive resource properties.
","tags":["Azure.Deployment.SecureValue","AZR-000316"]},{"location":"en/rules/Azure.Deployment.SecureValue/#examples","title":"Examples","text":"","tags":["Azure.Deployment.SecureValue","AZR-000316"]},{"location":"en/rules/Azure.Deployment.SecureValue/#configure-with-azure-template","title":"Configure with Azure template","text":"To configure deployments that pass this rule:
secureString
or secureObject
.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"secret\": {\n \"type\": \"secureString\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.KeyVault/vaults/secrets\",\n \"apiVersion\": \"2022-07-01\",\n \"name\": \"keyvault/good\",\n \"properties\": {\n \"value\": \"[parameters('secret')]\"\n }\n }\n ]\n}\n
","tags":["Azure.Deployment.SecureValue","AZR-000316"]},{"location":"en/rules/Azure.Deployment.SecureValue/#configure-with-bicep","title":"Configure with Bicep","text":"To configure deployments that pass this rule:
@secure()
attribute on parameters used to set sensitive resource properties.For example:
Azure Bicep snippet@secure()\nparam secret string\n\nresource goodSecret 'Microsoft.KeyVault/vaults/secrets@2022-07-01' = {\n name: 'keyvault/good'\n properties: {\n value: secret\n }\n}\n
","tags":["Azure.Deployment.SecureValue","AZR-000316"]},{"location":"en/rules/Azure.Deployment.SecureValue/#notes","title":"Notes","text":"This rule checks the following resource type properties:
Microsoft.KeyVault/vaults/secrets
:properties.value
Microsoft.Compute/virtualMachineScaleSets
:properties.virtualMachineProfile.osProfile.adminPassword
Cost Optimization \u00b7 Dev Box \u00b7 Rule \u00b7 2024_03 \u00b7 Important
Limit the number of Dev Boxes a single user can create for a project.
","tags":["Azure.DevBox.ProjectLimit","AZR-000411"]},{"location":"en/rules/Azure.DevBox.ProjectLimit/#description","title":"Description","text":"Microsoft Dev Box is a service that allows users to create and manage a developer workstation in the cloud (Dev Boxes). Dev Boxes are virtual machines with specifications and configuration designed for developers. Each Dev Box is billed based on usage to a capped amount per month.
Dev Box Projects are used to manage Dev Boxes. By default, a single user can create multiple Dev Boxes for a single Dev Box Project. This can lead to unexpected costs.
Organizations should consider how many Dev Boxes are required for a single user and set reasonable limits.
","tags":["Azure.DevBox.ProjectLimit","AZR-000411"]},{"location":"en/rules/Azure.DevBox.ProjectLimit/#recommendation","title":"Recommendation","text":"Consider limiting the number of Dev Boxes a single user can create for any projects. Additional consider, configuring budgets and alerts to monitor cost exceptions.
","tags":["Azure.DevBox.ProjectLimit","AZR-000411"]},{"location":"en/rules/Azure.DevBox.ProjectLimit/#examples","title":"Examples","text":"","tags":["Azure.DevBox.ProjectLimit","AZR-000411"]},{"location":"en/rules/Azure.DevBox.ProjectLimit/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Dev Box Projects that pass this rule:
properties.maxDevBoxesPerUser
property to limit the number of Dev Box a single user can create. E.g. 2
For example:
Azure Template snippet{\n \"type\": \"Microsoft.DevCenter/projects\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"devCenterId\": \"[resourceId('Microsoft.DevCenter/devcenters', parameters('name'))]\",\n \"maxDevBoxesPerUser\": 2\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.DevCenter/devcenters', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.DevBox.ProjectLimit","AZR-000411"]},{"location":"en/rules/Azure.DevBox.ProjectLimit/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Dev Box Projects that pass this rule:
properties.maxDevBoxesPerUser
property to limit the number of Dev Box a single user can create. E.g. 2
For example:
Azure Bicep snippetresource project 'Microsoft.DevCenter/projects@2023-04-01' = {\n name: name\n location: location\n properties: {\n devCenterId: center.id\n maxDevBoxesPerUser: 2\n }\n}\n
","tags":["Azure.DevBox.ProjectLimit","AZR-000411"]},{"location":"en/rules/Azure.DevBox.ProjectLimit/#notes","title":"Notes","text":"The properties.maxDevBoxesPerUser
property does not limit the number of Dev Boxes a user can create across multiple projects.
Security \u00b7 Event Grid \u00b7 Rule \u00b7 2022_09 \u00b7 Important
Authenticate publishing clients with Azure AD identities.
","tags":["Azure.EventGrid.DisableLocalAuth","AZR-000100"]},{"location":"en/rules/Azure.EventGrid.DisableLocalAuth/#description","title":"Description","text":"To publish events to Event Grid access keys, SAS tokens, or Azure AD identities can be used. With Azure AD authentication, the identity is validated against the Microsoft Identity Platform. Using Azure AD identities centralizes identity management and auditing.
Once you decide to use Azure AD authentication, you can disable authentication using keys or SAS tokens.
","tags":["Azure.EventGrid.DisableLocalAuth","AZR-000100"]},{"location":"en/rules/Azure.EventGrid.DisableLocalAuth/#recommendation","title":"Recommendation","text":"Consider only using Azure AD identities to publish events to Event Grid. Then disable authentication based on access keys or SAS tokens.
","tags":["Azure.EventGrid.DisableLocalAuth","AZR-000100"]},{"location":"en/rules/Azure.EventGrid.DisableLocalAuth/#examples","title":"Examples","text":"","tags":["Azure.EventGrid.DisableLocalAuth","AZR-000100"]},{"location":"en/rules/Azure.EventGrid.DisableLocalAuth/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Event Grid Topics that pass this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.EventGrid/topics\",\n \"apiVersion\": \"2022-06-15\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"publicNetworkAccess\": \"Disabled\",\n \"inputSchema\": \"CloudEventSchemaV1_0\"\n }\n}\n
","tags":["Azure.EventGrid.DisableLocalAuth","AZR-000100"]},{"location":"en/rules/Azure.EventGrid.DisableLocalAuth/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Event Grid Topics that pass this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Bicep snippetresource eventGrid 'Microsoft.EventGrid/topics@2022-06-15' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n disableLocalAuth: true\n publicNetworkAccess: 'Disabled'\n inputSchema: 'CloudEventSchemaV1_0'\n }\n}\n
","tags":["Azure.EventGrid.DisableLocalAuth","AZR-000100"]},{"location":"en/rules/Azure.EventGrid.DisableLocalAuth/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
Security \u00b7 Event Grid \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Use managed identities to deliver Event Grid Topic events.
","tags":["Azure.EventGrid.ManagedIdentity","AZR-000099"]},{"location":"en/rules/Azure.EventGrid.ManagedIdentity/#description","title":"Description","text":"When delivering events you can use Managed Identities to authenticate event delivery. You can enable either system-assigned identity or user-assigned identity but not both. You can have at most two user-assigned identities assigned to a topic or domain.
","tags":["Azure.EventGrid.ManagedIdentity","AZR-000099"]},{"location":"en/rules/Azure.EventGrid.ManagedIdentity/#recommendation","title":"Recommendation","text":"Consider configuring a managed identity for each Event Grid Topic.
","tags":["Azure.EventGrid.ManagedIdentity","AZR-000099"]},{"location":"en/rules/Azure.EventGrid.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.EventGrid.ManagedIdentity","AZR-000099"]},{"location":"en/rules/Azure.EventGrid.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Event Grid Topics that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.EventGrid/topics\",\n \"apiVersion\": \"2022-06-15\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"publicNetworkAccess\": \"Disabled\",\n \"inputSchema\": \"CloudEventSchemaV1_0\"\n }\n}\n
","tags":["Azure.EventGrid.ManagedIdentity","AZR-000099"]},{"location":"en/rules/Azure.EventGrid.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Event Grid Topics that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource eventGrid 'Microsoft.EventGrid/topics@2022-06-15' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n disableLocalAuth: true\n publicNetworkAccess: 'Disabled'\n inputSchema: 'CloudEventSchemaV1_0'\n }\n}\n
","tags":["Azure.EventGrid.ManagedIdentity","AZR-000099"]},{"location":"en/rules/Azure.EventGrid.ManagedIdentity/#links","title":"Links","text":"Security \u00b7 Event Grid \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Use Private Endpoints to access Event Grid topics and domains.
","tags":["Azure.EventGrid.TopicPublicAccess","AZR-000098"]},{"location":"en/rules/Azure.EventGrid.TopicPublicAccess/#description","title":"Description","text":"By default, public network access is enabled for an Event Grid topic or domain. To allow access via private endpoints only, disable public network access.
","tags":["Azure.EventGrid.TopicPublicAccess","AZR-000098"]},{"location":"en/rules/Azure.EventGrid.TopicPublicAccess/#recommendation","title":"Recommendation","text":"Consider using Private Endpoints to access Event Grid topics and domains. To limit access to Event Grid topics and domains, disable public access.
","tags":["Azure.EventGrid.TopicPublicAccess","AZR-000098"]},{"location":"en/rules/Azure.EventGrid.TopicPublicAccess/#examples","title":"Examples","text":"","tags":["Azure.EventGrid.TopicPublicAccess","AZR-000098"]},{"location":"en/rules/Azure.EventGrid.TopicPublicAccess/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Event Grid Topics that pass this rule:
properties.publicNetworkAccess
property to Disabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.EventGrid/topics\",\n \"apiVersion\": \"2022-06-15\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"publicNetworkAccess\": \"Disabled\",\n \"inputSchema\": \"CloudEventSchemaV1_0\"\n }\n}\n
","tags":["Azure.EventGrid.TopicPublicAccess","AZR-000098"]},{"location":"en/rules/Azure.EventGrid.TopicPublicAccess/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Event Grid Topics that pass this rule:
properties.publicNetworkAccess
property to Disabled
.For example:
Azure Bicep snippetresource eventGrid 'Microsoft.EventGrid/topics@2022-06-15' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n disableLocalAuth: true\n publicNetworkAccess: 'Disabled'\n inputSchema: 'CloudEventSchemaV1_0'\n }\n}\n
","tags":["Azure.EventGrid.TopicPublicAccess","AZR-000098"]},{"location":"en/rules/Azure.EventGrid.TopicPublicAccess/#links","title":"Links","text":"Security \u00b7 Event Hub \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Authenticate Event Hub publishers and consumers with Entra ID identities.
","tags":["Azure.EventHub.DisableLocalAuth","AZR-000102"]},{"location":"en/rules/Azure.EventHub.DisableLocalAuth/#description","title":"Description","text":"To publish or consume events from Event Hubs cryptographic keys, or Entra ID (previously Azure AD) identities can be used. Cryptographic keys include Shared Access Policy keys or Shared Access Signature (SAS) tokens. With Entra ID authentication, the identity is validated against Azure AD. Using Entra ID identities centralizes identity management and auditing.
Once you decide to use Entra ID authentication, you can disable authentication using keys or SAS tokens.
","tags":["Azure.EventHub.DisableLocalAuth","AZR-000102"]},{"location":"en/rules/Azure.EventHub.DisableLocalAuth/#recommendation","title":"Recommendation","text":"Consider only using Entra ID identities to publish or consume events from Event Hub. Then disable authentication based on access keys or SAS tokens.
","tags":["Azure.EventHub.DisableLocalAuth","AZR-000102"]},{"location":"en/rules/Azure.EventHub.DisableLocalAuth/#examples","title":"Examples","text":"","tags":["Azure.EventHub.DisableLocalAuth","AZR-000102"]},{"location":"en/rules/Azure.EventHub.DisableLocalAuth/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Event Hub namespaces that pass this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.EventHub/namespaces\",\n \"apiVersion\": \"2024-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"Standard\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"minimumTlsVersion\": \"1.2\",\n \"publicNetworkAccess\": \"Disabled\",\n \"isAutoInflateEnabled\": true,\n \"maximumThroughputUnits\": 10,\n \"zoneRedundant\": true\n }\n}\n
","tags":["Azure.EventHub.DisableLocalAuth","AZR-000102"]},{"location":"en/rules/Azure.EventHub.DisableLocalAuth/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Event Hub namespaces that pass this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Bicep snippetresource ns 'Microsoft.EventHub/namespaces@2024-01-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'Standard'\n }\n properties: {\n disableLocalAuth: true\n minimumTlsVersion: '1.2'\n publicNetworkAccess: 'Disabled'\n isAutoInflateEnabled: true\n maximumThroughputUnits: 10\n zoneRedundant: true\n }\n}\n
","tags":["Azure.EventHub.DisableLocalAuth","AZR-000102"]},{"location":"en/rules/Azure.EventHub.DisableLocalAuth/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
Security \u00b7 Event Hub \u00b7 Rule \u00b7 2023_03 \u00b7 Critical
Event Hub namespaces should reject TLS versions older than 1.2.
","tags":["Azure.EventHub.MinTLS","AZR-000356"]},{"location":"en/rules/Azure.EventHub.MinTLS/#description","title":"Description","text":"The minimum version of TLS that Event Hub namespaces accept is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Azure lets you disable outdated protocols and require connections to use a minimum of TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 is accepted.
","tags":["Azure.EventHub.MinTLS","AZR-000356"]},{"location":"en/rules/Azure.EventHub.MinTLS/#recommendation","title":"Recommendation","text":"Configure the minimum supported TLS version to be 1.2.
","tags":["Azure.EventHub.MinTLS","AZR-000356"]},{"location":"en/rules/Azure.EventHub.MinTLS/#examples","title":"Examples","text":"","tags":["Azure.EventHub.MinTLS","AZR-000356"]},{"location":"en/rules/Azure.EventHub.MinTLS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Event Hub namespaces that pass this rule:
properties.minimumTlsVersion
property to 1.2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.EventHub/namespaces\",\n \"apiVersion\": \"2024-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"Standard\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"minimumTlsVersion\": \"1.2\",\n \"publicNetworkAccess\": \"Disabled\",\n \"isAutoInflateEnabled\": true,\n \"maximumThroughputUnits\": 10,\n \"zoneRedundant\": true\n }\n}\n
","tags":["Azure.EventHub.MinTLS","AZR-000356"]},{"location":"en/rules/Azure.EventHub.MinTLS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Event Hub namespaces that pass this rule:
properties.minimumTlsVersion
property to 1.2
.For example:
Azure Bicep snippetresource ns 'Microsoft.EventHub/namespaces@2024-01-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'Standard'\n }\n properties: {\n disableLocalAuth: true\n minimumTlsVersion: '1.2'\n publicNetworkAccess: 'Disabled'\n isAutoInflateEnabled: true\n maximumThroughputUnits: 10\n zoneRedundant: true\n }\n}\n
","tags":["Azure.EventHub.MinTLS","AZR-000356"]},{"location":"en/rules/Azure.EventHub.MinTLS/#links","title":"Links","text":"Cost Optimization \u00b7 Event Hub \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Regularly remove unused resources to reduce costs.
","tags":["Azure.EventHub.Usage","AZR-000101"]},{"location":"en/rules/Azure.EventHub.Usage/#description","title":"Description","text":"Billing starts for an Event Hub namespace after it is provisioned. To receive events in a Event Hub namespace, you must first create an Event Hub. Namespaces without any Event Hubs are considered unused.
","tags":["Azure.EventHub.Usage","AZR-000101"]},{"location":"en/rules/Azure.EventHub.Usage/#recommendation","title":"Recommendation","text":"Consider removing Event Hub namespaces that are not used.
","tags":["Azure.EventHub.Usage","AZR-000101"]},{"location":"en/rules/Azure.EventHub.Usage/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.EventHub.Usage","AZR-000101"]},{"location":"en/rules/Azure.EventHub.Usage/#links","title":"Links","text":"Security \u00b7 Firewall \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls.
","tags":["Azure.Firewall.Mode","AZR-000105"]},{"location":"en/rules/Azure.Firewall.Mode/#description","title":"Description","text":"Threat intelligence-based filtering can optionally be enabled on Azure Firewall. When enabled, Azure Firewall alerts and deny traffic to/ from known malicious IP addresses and domains.
By default, Azure Firewall alerts on triggered threat intelligence rules.
Specifically, this rule only applies using an Azure Firewall in classic management mode. If the Azure Firewall is connected to a Secured Virtual Hub this rule will not apply.
Classic managed Azure Firewalls are standalone. Alternatively you can manage Azure Firewalls at scale through Firewall Manager by using policy. When using firewall policies, threat intelligence is configured centrally instead of on each firewall.
","tags":["Azure.Firewall.Mode","AZR-000105"]},{"location":"en/rules/Azure.Firewall.Mode/#recommendation","title":"Recommendation","text":"Consider configuring Azure Firewall to alert and deny IP addresses and domains detected as malicious. Alternatively, consider using firewall policies to manage Azure Firewalls at scale.
","tags":["Azure.Firewall.Mode","AZR-000105"]},{"location":"en/rules/Azure.Firewall.Mode/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Firewalls that pass this rule:
properties.threatIntelMode
to Deny
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/azureFirewalls\",\n \"apiVersion\": \"2021-05-01\",\n \"name\": \"[format('{0}_classic', parameters('name'))]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"sku\": {\n \"name\": \"AZFW_VNet\"\n },\n \"threatIntelMode\": \"Deny\"\n }\n}\n
","tags":["Azure.Firewall.Mode","AZR-000105"]},{"location":"en/rules/Azure.Firewall.Mode/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Firewalls that pass this rule:
properties.threatIntelMode
to Deny
.For example:
Azure Bicep snippetresource firewall_classic 'Microsoft.Network/azureFirewalls@2021-05-01' = {\n name: '${name}_classic'\n location: location\n properties: {\n sku: {\n name: 'AZFW_VNet'\n }\n threatIntelMode: 'Deny'\n }\n}\n
","tags":["Azure.Firewall.Mode","AZR-000105"]},{"location":"en/rules/Azure.Firewall.Mode/#links","title":"Links","text":"Operational Excellence \u00b7 Firewall \u00b7 Rule \u00b7 2021_12 \u00b7 Awareness
Firewall names should meet naming requirements.
","tags":["Azure.Firewall.Name","AZR-000103"]},{"location":"en/rules/Azure.Firewall.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Firewall names are:
Consider using names that meet Firewall naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.Firewall.Name","AZR-000103"]},{"location":"en/rules/Azure.Firewall.Name/#examples","title":"Examples","text":"","tags":["Azure.Firewall.Name","AZR-000103"]},{"location":"en/rules/Azure.Firewall.Name/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy firewalls that pass this rule:
name
property to align to resource naming requirements.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/azureFirewalls\",\n \"apiVersion\": \"2023-02-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"sku\": {\n \"name\": \"AZFW_VNet\",\n \"tier\": \"Premium\"\n },\n \"firewallPolicy\": {\n \"id\": \"[resourceId('Microsoft.Network/firewallPolicies', format('{0}_policy', parameters('name')))]\"\n }\n },\n \"dependsOn\": [\n \"firewall_policy\"\n ]\n}\n
","tags":["Azure.Firewall.Name","AZR-000103"]},{"location":"en/rules/Azure.Firewall.Name/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy firewalls that pass this rule:
name
property to align to resource naming requirements.For example:
Azure Bicep snippetresource firewall 'Microsoft.Network/azureFirewalls@2023-02-01' = {\n name: name\n location: location\n properties: {\n sku: {\n name: 'AZFW_VNet'\n tier: 'Premium'\n }\n firewallPolicy: {\n id: firewall_policy.id\n }\n }\n}\n
","tags":["Azure.Firewall.Name","AZR-000103"]},{"location":"en/rules/Azure.Firewall.Name/#notes","title":"Notes","text":"This rule does not check if Firewall names are unique.
","tags":["Azure.Firewall.Name","AZR-000103"]},{"location":"en/rules/Azure.Firewall.Name/#links","title":"Links","text":"Security \u00b7 Firewall \u00b7 Rule \u00b7 2023_09 \u00b7 Critical
Deny high confidence malicious IP addresses, domains and URLs.
","tags":["Azure.Firewall.PolicyMode","AZR-000399"]},{"location":"en/rules/Azure.Firewall.PolicyMode/#description","title":"Description","text":"Threat intelligence-based filtering can optionally be enabled on Azure Firewall, by associating one or more policies with threat intelligence-based filtering configured.
When configured, Azure Firewall alerts and deny traffic to/from known malicious IP addresses, domains and URLs.
By default, threat intelligence-based filtering is enabled and in alert
mode on each policy unless otherwise is specified.
By configuring threat intelligence-based filtering in alert and deny
mode, threat intelligence-based filtering may deny traffic before any configured rules are processed.
Consider configuring Azure Firewall to alert and deny IP addresses, domains and URLs detected as malicious.
","tags":["Azure.Firewall.PolicyMode","AZR-000399"]},{"location":"en/rules/Azure.Firewall.PolicyMode/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Firewall polices that pass this rule:
properties.threatIntelMode
to Deny
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/firewallPolicies\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"sku\": {\n \"tier\": \"Premium\"\n },\n \"threatIntelMode\": \"Deny\"\n }\n}\n
","tags":["Azure.Firewall.PolicyMode","AZR-000399"]},{"location":"en/rules/Azure.Firewall.PolicyMode/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Firewall polices that pass this rule:
properties.threatIntelMode
to Deny
.For example:
Azure Bicep snippetresource firewallPolicy 'Microsoft.Network/firewallPolicies@2023-04-01' = {\n name: name\n location: location\n properties: {\n sku: {\n tier: 'Premium'\n }\n threatIntelMode: 'Deny'\n }\n}\n
","tags":["Azure.Firewall.PolicyMode","AZR-000399"]},{"location":"en/rules/Azure.Firewall.PolicyMode/#notes","title":"Notes","text":"Azure Firewall Premium SKU is required for associating standalone resource firewall policies. Only Standard and Premium firewall policies supports threat intelligence-based filtering in alert and deny
mode.
In order to take advantage of URL filtering with HTTPS
traffic included in threat intelligence-based filtering, TLS inspection must be configured first.
Operational Excellence \u00b7 Firewall \u00b7 Rule \u00b7 2021_12 \u00b7 Awareness
Firewall policy names should meet naming requirements.
","tags":["Azure.Firewall.PolicyName","AZR-000104"]},{"location":"en/rules/Azure.Firewall.PolicyName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Firewall policy names are:
Consider using names that meet Firewall policy naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.Firewall.PolicyName","AZR-000104"]},{"location":"en/rules/Azure.Firewall.PolicyName/#notes","title":"Notes","text":"This rule does not check if Firewall policy names are unique.
","tags":["Azure.Firewall.PolicyName","AZR-000104"]},{"location":"en/rules/Azure.Firewall.PolicyName/#links","title":"Links","text":"Security \u00b7 Front Door \u00b7 Rule \u00b7 2024_03 \u00b7 Important
Audit and monitor access through Azure Front Door profiles.
","tags":["Azure.FrontDoor.Logs","AZR-000107"]},{"location":"en/rules/Azure.FrontDoor.Logs/#description","title":"Description","text":"Azure Front Door (AFD) supports logging network access to resources through the service. This includes access logs and web application firewall logs. Capturing these logs can help detect and respond to security threats as part of a security monitoring strategy. Additionally, many compliance standards require logging and monitoring of network access.
Like all security monitoring, it is only effective if the logs are reviewed and correlated with other security events. Microsoft Sentinel can be used to analyze and correlate logs, or third-party solutions can be used.
To capture network access events through Front Door, diagnostic settings must be configured. When configuring diagnostics settings enable collection of the following logs:
FrontdoorAccessLog
- Can be used to monitor network activity and access through Front Door.FrontdoorWebApplicationFirewallLog
- Can be used to detect potential attacks, or false positive detections. This log will be empty if a WAF policy is not configured.Management operations for Front Door is captured automatically within Azure Activity Logs.
","tags":["Azure.FrontDoor.Logs","AZR-000107"]},{"location":"en/rules/Azure.FrontDoor.Logs/#recommendation","title":"Recommendation","text":"Consider configuring diagnostics setting to log network activity and access through Azure Front Door (AFD). Also consider correlating logs with other security events to detect and respond to security threats.
","tags":["Azure.FrontDoor.Logs","AZR-000107"]},{"location":"en/rules/Azure.FrontDoor.Logs/#examples","title":"Examples","text":"","tags":["Azure.FrontDoor.Logs","AZR-000107"]},{"location":"en/rules/Azure.FrontDoor.Logs/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Front Door Premium/ Standard profiles that passes this rule:
FrontdoorAccessLog
category.FrontdoorWebApplicationFirewallLog
category if a WAF policy is configured.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Insights/diagnosticSettings\",\n \"apiVersion\": \"2021-05-01-preview\",\n \"scope\": \"[format('Microsoft.Cdn/profiles/{0}', parameters('name'))]\",\n \"name\": \"audit\",\n \"properties\": {\n \"workspaceId\": \"[parameters('workspaceId')]\",\n \"logs\": [\n {\n \"category\": \"FrontdoorAccessLog\",\n \"enabled\": true\n },\n {\n \"category\": \"FrontdoorWebApplicationFirewallLog\",\n \"enabled\": true\n }\n ]\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Cdn/profiles', parameters('name'))]\"\n ]\n}\n
To deploy Azure Front Door Classic profiles that passes this rule:
FrontdoorAccessLog
category.FrontdoorWebApplicationFirewallLog
category if a WAF policy is configured.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Insights/diagnosticSettings\",\n \"apiVersion\": \"2021-05-01-preview\",\n \"scope\": \"[format('Microsoft.Network/frontDoors/{0}', parameters('name'))]\",\n \"name\": \"audit\",\n \"properties\": {\n \"workspaceId\": \"[parameters('workspaceId')]\",\n \"logs\": [\n {\n \"category\": \"FrontdoorAccessLog\",\n \"enabled\": true\n },\n {\n \"category\": \"FrontdoorWebApplicationFirewallLog\",\n \"enabled\": true\n }\n ]\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Network/frontDoors', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.FrontDoor.Logs","AZR-000107"]},{"location":"en/rules/Azure.FrontDoor.Logs/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Front Door Premium/ Standard profiles that passes this rule:
FrontdoorAccessLog
category.FrontdoorWebApplicationFirewallLog
category.For example:
Azure Bicep snippetresource audit 'Microsoft.Insights/diagnosticSettings@2021-05-01-preview' = {\n name: 'audit'\n scope: afd_profile\n properties: {\n workspaceId: workspaceId\n logs: [\n {\n category: 'FrontdoorAccessLog'\n enabled: true\n }\n {\n category: 'FrontdoorWebApplicationFirewallLog'\n enabled: true\n }\n ]\n }\n}\n
To deploy Azure Front Door Classic profiles that passes this rule:
FrontdoorAccessLog
category.FrontdoorWebApplicationFirewallLog
category.For example:
Azure Bicep snippetresource audit_classic 'Microsoft.Insights/diagnosticSettings@2021-05-01-preview' = {\n name: 'audit'\n scope: afd_classic\n properties: {\n workspaceId: workspaceId\n logs: [\n {\n category: 'FrontdoorAccessLog'\n enabled: true\n }\n {\n category: 'FrontdoorWebApplicationFirewallLog'\n enabled: true\n }\n ]\n }\n}\n
","tags":["Azure.FrontDoor.Logs","AZR-000107"]},{"location":"en/rules/Azure.FrontDoor.Logs/#notes","title":"Notes","text":"This rule applies to Azure Front Door Premium/ Standard/ Classic profiles.
","tags":["Azure.FrontDoor.Logs","AZR-000107"]},{"location":"en/rules/Azure.FrontDoor.Logs/#links","title":"Links","text":"Security \u00b7 Front Door \u00b7 Rule \u00b7 2023_09 \u00b7 Important
Ensure Front Door uses a managed identity to authorize access to Azure resources.
","tags":["Azure.FrontDoor.ManagedIdentity","AZR-000396"]},{"location":"en/rules/Azure.FrontDoor.ManagedIdentity/#description","title":"Description","text":"When configuring a Standard or Premium SKU with a custom domain using bring your own certificate (BYOC) access to a Key Vault is required. Standard and Premium Front Door profiles support two methods for authorizing access to Azure resources:
205478c0-bd83-4e1b-a9d6-db63a3e1e1c8
.d4631ece-daab-479b-be77-ccb713491fc0
.The multi-tenant app registration has a number of challenges:
Using an managed identity allows access to Key Vault to be granted using RBAC on an individual basis.
","tags":["Azure.FrontDoor.ManagedIdentity","AZR-000396"]},{"location":"en/rules/Azure.FrontDoor.ManagedIdentity/#recommendation","title":"Recommendation","text":"Consider configure a managed identity to allow support for Azure AD authentication.
","tags":["Azure.FrontDoor.ManagedIdentity","AZR-000396"]},{"location":"en/rules/Azure.FrontDoor.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.FrontDoor.ManagedIdentity","AZR-000396"]},{"location":"en/rules/Azure.FrontDoor.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Front Door instances that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
or SystemAssigned,UserAssigned
.identity.type
is UserAssigned
or SystemAssigned,UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cdn/profiles\",\n \"apiVersion\": \"2022-11-01-preview\",\n \"name\": \"myFrontDoor\",\n \"location\": \"global\",\n \"sku\": {\n \"name\": \"Standard_AzureFrontDoor\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\",\n \"userAssignedIdentities\": {}\n }\n}\n
","tags":["Azure.FrontDoor.ManagedIdentity","AZR-000396"]},{"location":"en/rules/Azure.FrontDoor.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Front Door instances that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
or SystemAssigned,UserAssigned
.identity.type
is UserAssigned
or SystemAssigned,UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource frontDoorProfile 'Microsoft.Cdn/profiles@2022-11-01-preview' = {\n name: 'myFrontDoor'\n location: 'global'\n sku: {\n name: 'Standard_AzureFrontDoor'\n }\n identity: {\n type: 'SystemAssigned'\n userAssignedIdentities: {}\n }\n}\n
","tags":["Azure.FrontDoor.ManagedIdentity","AZR-000396"]},{"location":"en/rules/Azure.FrontDoor.ManagedIdentity/#notes","title":"Notes","text":"Currently Azure Front Door only supports authentication using an Entra ID (Azure AD) to Key Vault. To use a managed identity, the Standard or Premium SKU is required. Managed identities are not supported with the Classic SKU.
If you only use Azure Front Door (AFD) managed certificates for custom domains, a managed identity is not required.
","tags":["Azure.FrontDoor.ManagedIdentity","AZR-000396"]},{"location":"en/rules/Azure.FrontDoor.ManagedIdentity/#links","title":"Links","text":"Security \u00b7 Front Door \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Front Door Classic instances should reject TLS versions older than 1.2.
","tags":["Azure.FrontDoor.MinTLS","AZR-000106"]},{"location":"en/rules/Azure.FrontDoor.MinTLS/#description","title":"Description","text":"The minimum version of TLS that Azure Front Door accepts is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Front Door lets you disable outdated protocols and enforce TLS 1.2. By default, a minimum of TLS 1.2 is enforced.
","tags":["Azure.FrontDoor.MinTLS","AZR-000106"]},{"location":"en/rules/Azure.FrontDoor.MinTLS/#recommendation","title":"Recommendation","text":"Consider configuring the minimum supported TLS version to be 1.2 for each endpoint. This applies to Azure Front Door Classic instances only.
","tags":["Azure.FrontDoor.MinTLS","AZR-000106"]},{"location":"en/rules/Azure.FrontDoor.MinTLS/#examples","title":"Examples","text":"","tags":["Azure.FrontDoor.MinTLS","AZR-000106"]},{"location":"en/rules/Azure.FrontDoor.MinTLS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy a Front Door resource that passes this rule:
properties.frontendEndpoints[*].properties.customHttpsConfiguration.minimumTlsVersion
property to 1.2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/frontDoors\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"global\",\n \"properties\": {\n \"enabledState\": \"Enabled\",\n \"frontendEndpoints\": [\n {\n \"name\": \"[variables('frontEndEndpointName')]\",\n \"properties\": {\n \"hostName\": \"[format('{0}.azurefd.net', parameters('name'))]\",\n \"sessionAffinityEnabledState\": \"Disabled\",\n \"customHttpsConfiguration\": {\n \"minimumTlsVersion\": \"1.2\"\n }\n }\n }\n ],\n \"loadBalancingSettings\": \"[variables('loadBalancingSettings')]\",\n \"backendPools\": \"[variables('backendPools')]\",\n \"healthProbeSettings\": \"[variables('healthProbeSettings')]\",\n \"routingRules\": \"[variables('routingRules')]\"\n }\n}\n
","tags":["Azure.FrontDoor.MinTLS","AZR-000106"]},{"location":"en/rules/Azure.FrontDoor.MinTLS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy a Front Door resource that passes this rule:
properties.frontendEndpoints[*].properties.customHttpsConfiguration.minimumTlsVersion
property to 1.2
.For example:
Azure Bicep snippetresource afd_classic 'Microsoft.Network/frontDoors@2021-06-01' = {\n name: name\n location: 'global'\n properties: {\n enabledState: 'Enabled'\n frontendEndpoints: [\n {\n name: frontEndEndpointName\n properties: {\n hostName: '${name}.azurefd.net'\n sessionAffinityEnabledState: 'Disabled'\n customHttpsConfiguration: {\n minimumTlsVersion: '1.2'\n }\n }\n }\n ]\n loadBalancingSettings: loadBalancingSettings\n backendPools: backendPools\n healthProbeSettings: healthProbeSettings\n routingRules: routingRules\n }\n}\n
","tags":["Azure.FrontDoor.MinTLS","AZR-000106"]},{"location":"en/rules/Azure.FrontDoor.MinTLS/#links","title":"Links","text":"Operational Excellence \u00b7 Front Door \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Front Door names should meet naming requirements.
","tags":["Azure.FrontDoor.Name","AZR-000113"]},{"location":"en/rules/Azure.FrontDoor.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Front Door names are:
Consider using names that meet Front Door naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.FrontDoor.Name","AZR-000113"]},{"location":"en/rules/Azure.FrontDoor.Name/#notes","title":"Notes","text":"This rule does not check if Front Door names are unique.
","tags":["Azure.FrontDoor.Name","AZR-000113"]},{"location":"en/rules/Azure.FrontDoor.Name/#links","title":"Links","text":"Reliability \u00b7 Front Door \u00b7 Rule \u00b7 2021_03 \u00b7 Important
Use health probes to check the health of each backend.
","tags":["Azure.FrontDoor.Probe","AZR-000108"]},{"location":"en/rules/Azure.FrontDoor.Probe/#description","title":"Description","text":"The health and performance of an application can degrade over time. Degradation might not be noticeable until the application fails.
Azure Front Door can use periodic health probes against backend endpoints to determine health status. When one or more backend in a pool is healthy traffic is routed to healthy endpoints only. If all endpoints in a pool is unhealthy Front Door sends the request to any enabled endpoint.
Health probes allow Front Door to select a backend endpoint able to respond to the request.
","tags":["Azure.FrontDoor.Probe","AZR-000108"]},{"location":"en/rules/Azure.FrontDoor.Probe/#recommendation","title":"Recommendation","text":"Consider configuring and enabling a health probe for each Front Door backend.
","tags":["Azure.FrontDoor.Probe","AZR-000108"]},{"location":"en/rules/Azure.FrontDoor.Probe/#examples","title":"Examples","text":"","tags":["Azure.FrontDoor.Probe","AZR-000108"]},{"location":"en/rules/Azure.FrontDoor.Probe/#configure-with-azure-template","title":"Configure with Azure template","text":"Premium / StandardClassicTo deploy a Front Door resource that passes this rule:
properties.healthProbeSettings
property of the originGroups
sub-resource.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cdn/profiles\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"Global\",\n \"sku\": {\n \"name\": \"Premium_AzureFrontDoor\"\n }\n},\n{\n \"type\": \"Microsoft.Cdn/profiles/originGroups\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), parameters('name'))]\",\n \"properties\": {\n \"loadBalancingSettings\": {\n \"sampleSize\": 4,\n \"successfulSamplesRequired\": 3\n },\n \"healthProbeSettings\": {\n \"probePath\": \"/healthz\",\n \"probeRequestType\": \"HEAD\",\n \"probeProtocol\": \"Http\",\n \"probeIntervalInSeconds\": 100\n }\n },\n \"dependsOn\": [\n \"[parameters('name')]\"\n ]\n}\n
To deploy a Front Door resource that passes this rule:
properties.healthProbeSettings[*].properties.enabledState
property to Enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/frontDoors\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"global\",\n \"properties\": {\n \"enabledState\": \"Enabled\",\n \"frontendEndpoints\": \"[variables('frontendEndpoints')]\",\n \"loadBalancingSettings\": \"[variables('loadBalancingSettings')]\",\n \"backendPools\": \"[variables('backendPools')]\",\n \"healthProbeSettings\": [\n {\n \"name\": \"[variables('healthProbeSettingsName')]\",\n \"properties\": {\n \"enabledState\": \"Enabled\",\n \"path\": \"/healthz\",\n \"protocol\": \"Http\",\n \"intervalInSeconds\": 120,\n \"healthProbeMethod\": \"HEAD\"\n }\n }\n ],\n \"routingRules\": \"[variables('routingRules')]\"\n }\n}\n
","tags":["Azure.FrontDoor.Probe","AZR-000108"]},{"location":"en/rules/Azure.FrontDoor.Probe/#configure-with-bicep","title":"Configure with Bicep","text":"Premium / StandardClassic To deploy a Front Door resource that passes this rule:
properties.healthProbeSettings
property of the originGroups
sub-resource.For example:
Azure Bicep snippetresource afd_premium 'Microsoft.Cdn/profiles@2021-06-01' = {\n name: name\n location: 'Global'\n sku: {\n name: 'Premium_AzureFrontDoor'\n }\n}\n\nresource frontDoorOriginGroup 'Microsoft.Cdn/profiles/originGroups@2021-06-01' = {\n name: name\n parent: afd_premium\n properties: {\n loadBalancingSettings: {\n sampleSize: 4\n successfulSamplesRequired: 3\n }\n healthProbeSettings: {\n probePath: '/healthz'\n probeRequestType: 'HEAD'\n probeProtocol: 'Http'\n probeIntervalInSeconds: 100\n }\n }\n}\n
To deploy a Front Door resource that passes this rule:
properties.healthProbeSettings[*].properties.enabledState
property to Enabled
.For example:
Azure Bicep snippetresource afd_classic 'Microsoft.Network/frontDoors@2021-06-01' = {\n name: name\n location: 'global'\n properties: {\n enabledState: 'Enabled'\n frontendEndpoints: frontendEndpoints\n loadBalancingSettings: loadBalancingSettings\n backendPools: backendPools\n healthProbeSettings: [\n {\n name: healthProbeSettingsName\n properties: {\n enabledState: 'Enabled'\n path: '/healthz'\n protocol: 'Http'\n intervalInSeconds: 120\n healthProbeMethod: 'HEAD'\n }\n }\n ]\n routingRules: routingRules\n }\n}\n
","tags":["Azure.FrontDoor.Probe","AZR-000108"]},{"location":"en/rules/Azure.FrontDoor.Probe/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz network front-door probe update --front-door-name '<front_door>' -n '<probe_name>' -g '<resource_group>' --enabled 'Enabled' --path '/healthz'\n
","tags":["Azure.FrontDoor.Probe","AZR-000108"]},{"location":"en/rules/Azure.FrontDoor.Probe/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippet$probeSetting = New-AzFrontDoorHealthProbeSettingObject -Name '<probe_name>' -EnabledState 'Enabled' -Path '/healthz'\nSet-AzFrontDoor -Name '<front_door>' -ResourceGroupName '<resource_group>' -HealthProbeSetting $probeSetting\n
","tags":["Azure.FrontDoor.Probe","AZR-000108"]},{"location":"en/rules/Azure.FrontDoor.Probe/#links","title":"Links","text":"Reliability \u00b7 Front Door \u00b7 Rule \u00b7 2021_03 \u00b7 Important
Configure health probes to use HEAD
requests to reduce performance overhead.
Azure Front Door supports sending HEAD
or GET
requests for health probes to backend endpoints. HTTP HEAD
requests are identical to GET
requests except that the server does not send a response body. As a result, HEAD
request typically have a lower performance impact then GET
request.
By eliminating a response body:
Consider configuring health probes to query backend health endpoints using HEAD
requests to reduce performance overhead.
To deploy a Front Door resource that passes this rule:
properties.healthProbeSettings.probeRequestType
property to HEAD
of the originGroups
sub-resource.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cdn/profiles\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"Global\",\n \"sku\": {\n \"name\": \"Premium_AzureFrontDoor\"\n }\n},\n{\n \"type\": \"Microsoft.Cdn/profiles/originGroups\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), parameters('name'))]\",\n \"properties\": {\n \"loadBalancingSettings\": {\n \"sampleSize\": 4,\n \"successfulSamplesRequired\": 3\n },\n \"healthProbeSettings\": {\n \"probePath\": \"/healthz\",\n \"probeRequestType\": \"HEAD\",\n \"probeProtocol\": \"Http\",\n \"probeIntervalInSeconds\": 100\n }\n },\n \"dependsOn\": [\n \"[parameters('name')]\"\n ]\n}\n
To deploy a Front Door resource that passes this rule:
properties.healthProbeSettings[*].properties.healthProbeMethod
property to HEAD
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/frontDoors\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"global\",\n \"properties\": {\n \"enabledState\": \"Enabled\",\n \"frontendEndpoints\": \"[variables('frontendEndpoints')]\",\n \"loadBalancingSettings\": \"[variables('loadBalancingSettings')]\",\n \"backendPools\": \"[variables('backendPools')]\",\n \"healthProbeSettings\": [\n {\n \"name\": \"[variables('healthProbeSettingsName')]\",\n \"properties\": {\n \"enabledState\": \"Enabled\",\n \"path\": \"/healthz\",\n \"protocol\": \"Http\",\n \"intervalInSeconds\": 120,\n \"healthProbeMethod\": \"HEAD\"\n }\n }\n ],\n \"routingRules\": \"[variables('routingRules')]\"\n }\n}\n
","tags":["Azure.FrontDoor.ProbeMethod","AZR-000109"]},{"location":"en/rules/Azure.FrontDoor.ProbeMethod/#configure-with-bicep","title":"Configure with Bicep","text":"Premium / StandardClassic To deploy a Front Door resource that passes this rule:
properties.healthProbeSettings.probeRequestType
property to HEAD
of the originGroups
sub-resource.For example:
Azure Bicep snippetresource afd_premium 'Microsoft.Cdn/profiles@2021-06-01' = {\n name: name\n location: 'Global'\n sku: {\n name: 'Premium_AzureFrontDoor'\n }\n}\n\nresource frontDoorOriginGroup 'Microsoft.Cdn/profiles/originGroups@2021-06-01' = {\n name: name\n parent: afd_premium\n properties: {\n loadBalancingSettings: {\n sampleSize: 4\n successfulSamplesRequired: 3\n }\n healthProbeSettings: {\n probePath: '/healthz'\n probeRequestType: 'HEAD'\n probeProtocol: 'Http'\n probeIntervalInSeconds: 100\n }\n }\n}\n
To deploy a Front Door resource that passes this rule:
properties.healthProbeSettings[*].properties.healthProbeMethod
property to HEAD
.For example:
Azure Bicep snippetresource afd_classic 'Microsoft.Network/frontDoors@2021-06-01' = {\n name: name\n location: 'global'\n properties: {\n enabledState: 'Enabled'\n frontendEndpoints: frontendEndpoints\n loadBalancingSettings: loadBalancingSettings\n backendPools: backendPools\n healthProbeSettings: [\n {\n name: healthProbeSettingsName\n properties: {\n enabledState: 'Enabled'\n path: '/healthz'\n protocol: 'Http'\n intervalInSeconds: 120\n healthProbeMethod: 'HEAD'\n }\n }\n ]\n routingRules: routingRules\n }\n}\n
","tags":["Azure.FrontDoor.ProbeMethod","AZR-000109"]},{"location":"en/rules/Azure.FrontDoor.ProbeMethod/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz network front-door probe update --front-door-name '<front_door>' -n '<probe_name>' -g '<resource_group>' --probeMethod 'HEAD' --path '/healthz'\n
","tags":["Azure.FrontDoor.ProbeMethod","AZR-000109"]},{"location":"en/rules/Azure.FrontDoor.ProbeMethod/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippet$probeSetting = New-AzFrontDoorHealthProbeSettingObject -Name '<probe_name>' -HealthProbeMethod 'HEAD' -Path '/healthz'\nSet-AzFrontDoor -Name '<front_door>' -ResourceGroupName '<resource_group>' -HealthProbeSetting $probeSetting\n
","tags":["Azure.FrontDoor.ProbeMethod","AZR-000109"]},{"location":"en/rules/Azure.FrontDoor.ProbeMethod/#links","title":"Links","text":"Reliability \u00b7 Front Door \u00b7 Rule \u00b7 2021_03 \u00b7 Important
Configure a dedicated path for health probe requests.
","tags":["Azure.FrontDoor.ProbePath","AZR-000110"]},{"location":"en/rules/Azure.FrontDoor.ProbePath/#description","title":"Description","text":"Azure Front Door monitors a specific path for each backend to determine health status. The monitored path should implement functional checks to determine if the backend is performing correctly. The checks should include dependencies including those that may not be regularly called.
Regular checks of the monitored path allow Front Door to make load balancing decisions based on status.
","tags":["Azure.FrontDoor.ProbePath","AZR-000110"]},{"location":"en/rules/Azure.FrontDoor.ProbePath/#recommendation","title":"Recommendation","text":"Consider using a dedicated health probe endpoint that implements functional checks.
","tags":["Azure.FrontDoor.ProbePath","AZR-000110"]},{"location":"en/rules/Azure.FrontDoor.ProbePath/#examples","title":"Examples","text":"","tags":["Azure.FrontDoor.ProbePath","AZR-000110"]},{"location":"en/rules/Azure.FrontDoor.ProbePath/#configure-with-azure-template","title":"Configure with Azure template","text":"Premium / StandardClassicTo deploy a Front Door resource that passes this rule:
properties.healthProbeSettings.probePath
property to a dedicated path of the originGroups
sub-resource.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cdn/profiles\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"Global\",\n \"sku\": {\n \"name\": \"Premium_AzureFrontDoor\"\n }\n},\n{\n \"type\": \"Microsoft.Cdn/profiles/originGroups\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), parameters('name'))]\",\n \"properties\": {\n \"loadBalancingSettings\": {\n \"sampleSize\": 4,\n \"successfulSamplesRequired\": 3\n },\n \"healthProbeSettings\": {\n \"probePath\": \"/healthz\",\n \"probeRequestType\": \"HEAD\",\n \"probeProtocol\": \"Http\",\n \"probeIntervalInSeconds\": 100\n }\n },\n \"dependsOn\": [\n \"[parameters('name')]\"\n ]\n}\n
To deploy a Front Door resource that passes this rule:
properties.healthProbeSettings[*].properties.path
property to a dedicated path.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/frontDoors\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"global\",\n \"properties\": {\n \"enabledState\": \"Enabled\",\n \"frontendEndpoints\": \"[variables('frontendEndpoints')]\",\n \"loadBalancingSettings\": \"[variables('loadBalancingSettings')]\",\n \"backendPools\": \"[variables('backendPools')]\",\n \"healthProbeSettings\": [\n {\n \"name\": \"[variables('healthProbeSettingsName')]\",\n \"properties\": {\n \"enabledState\": \"Enabled\",\n \"path\": \"/healthz\",\n \"protocol\": \"Http\",\n \"intervalInSeconds\": 120,\n \"healthProbeMethod\": \"HEAD\"\n }\n }\n ],\n \"routingRules\": \"[variables('routingRules')]\"\n }\n}\n
","tags":["Azure.FrontDoor.ProbePath","AZR-000110"]},{"location":"en/rules/Azure.FrontDoor.ProbePath/#configure-with-bicep","title":"Configure with Bicep","text":"Premium / StandardClassic To deploy a Front Door resource that passes this rule:
properties.healthProbeSettings.probePath
property to a dedicated path of the originGroups
sub-resource.For example:
Azure Bicep snippetresource afd_premium 'Microsoft.Cdn/profiles@2021-06-01' = {\n name: name\n location: 'Global'\n sku: {\n name: 'Premium_AzureFrontDoor'\n }\n}\n\nresource frontDoorOriginGroup 'Microsoft.Cdn/profiles/originGroups@2021-06-01' = {\n name: name\n parent: afd_premium\n properties: {\n loadBalancingSettings: {\n sampleSize: 4\n successfulSamplesRequired: 3\n }\n healthProbeSettings: {\n probePath: '/healthz'\n probeRequestType: 'HEAD'\n probeProtocol: 'Http'\n probeIntervalInSeconds: 100\n }\n }\n}\n
To deploy a Front Door resource that passes this rule:
properties.healthProbeSettings[*].properties.path
property to a dedicated path.For example:
Azure Bicep snippetresource afd_classic 'Microsoft.Network/frontDoors@2021-06-01' = {\n name: name\n location: 'global'\n properties: {\n enabledState: 'Enabled'\n frontendEndpoints: frontendEndpoints\n loadBalancingSettings: loadBalancingSettings\n backendPools: backendPools\n healthProbeSettings: [\n {\n name: healthProbeSettingsName\n properties: {\n enabledState: 'Enabled'\n path: '/healthz'\n protocol: 'Http'\n intervalInSeconds: 120\n healthProbeMethod: 'HEAD'\n }\n }\n ]\n routingRules: routingRules\n }\n}\n
","tags":["Azure.FrontDoor.ProbePath","AZR-000110"]},{"location":"en/rules/Azure.FrontDoor.ProbePath/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz network front-door probe update --front-door-name '<front_door>' -n '<probe_name>' -g '<resource_group>' --path '/healthz'\n
","tags":["Azure.FrontDoor.ProbePath","AZR-000110"]},{"location":"en/rules/Azure.FrontDoor.ProbePath/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippet$probeSetting = New-AzFrontDoorHealthProbeSettingObject -Name '<probe_name>' -Path '/healthz'\nSet-AzFrontDoor -Name '<front_door>' -ResourceGroupName '<resource_group>' -HealthProbeSetting $probeSetting\n
","tags":["Azure.FrontDoor.ProbePath","AZR-000110"]},{"location":"en/rules/Azure.FrontDoor.ProbePath/#links","title":"Links","text":"Cost Optimization \u00b7 Front Door \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Enable Azure Front Door Classic instance.
","tags":["Azure.FrontDoor.State","AZR-000112"]},{"location":"en/rules/Azure.FrontDoor.State/#description","title":"Description","text":"The operational state of a Front Door Classic instance is configurable, either enabled or disabled. By default, a Front Door is enabled.
Optionally, a Front Door Classic instance may be disabled to temporarily prevent traffic being processed.
","tags":["Azure.FrontDoor.State","AZR-000112"]},{"location":"en/rules/Azure.FrontDoor.State/#recommendation","title":"Recommendation","text":"Consider enabling the Front Door service or remove the instance if it is no longer required. This applies to Azure Front Door Classic instances only.
","tags":["Azure.FrontDoor.State","AZR-000112"]},{"location":"en/rules/Azure.FrontDoor.State/#examples","title":"Examples","text":"","tags":["Azure.FrontDoor.State","AZR-000112"]},{"location":"en/rules/Azure.FrontDoor.State/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy a Front Door resource that passes this rule:
properties.enabledState
property to Enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/frontDoors\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"global\",\n \"properties\": {\n \"enabledState\": \"Enabled\",\n \"frontendEndpoints\": \"[variables('frontendEndpoints')]\",\n \"loadBalancingSettings\": \"[variables('loadBalancingSettings')]\",\n \"backendPools\": \"[variables('backendPools')]\",\n \"healthProbeSettings\": \"[variables('healthProbeSettings')]\",\n \"routingRules\": \"[variables('routingRules')]\"\n }\n}\n
","tags":["Azure.FrontDoor.State","AZR-000112"]},{"location":"en/rules/Azure.FrontDoor.State/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy a Front Door resource that passes this rule:
properties.enabledState
property to Enabled
.For example:
Azure Bicep snippetresource afd_classic 'Microsoft.Network/frontDoors@2021-06-01' = {\n name: name\n location: 'global'\n properties: {\n enabledState: 'Enabled'\n frontendEndpoints: frontendEndpoints\n loadBalancingSettings: loadBalancingSettings\n backendPools: backendPools\n healthProbeSettings: healthProbeSettings\n routingRules: routingRules\n }\n}\n
","tags":["Azure.FrontDoor.State","AZR-000112"]},{"location":"en/rules/Azure.FrontDoor.State/#links","title":"Links","text":"Performance Efficiency \u00b7 Front Door \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Use caching to reduce retrieving contents from origins.
","tags":["Azure.FrontDoor.UseCaching","AZR-000320"]},{"location":"en/rules/Azure.FrontDoor.UseCaching/#description","title":"Description","text":"Azure Front Door delivers large files without a cap on file size. Front Door uses a technique called object chunking. When a large file is requested, Front Door retrieves smaller pieces of the file from the backend. After receiving a full or byte-range file request, the Front Door environment requests the file from the backend in chunks of 8 MB.
After the chunk arrives at the Front Door environment, it's cached and immediately served to the user. Front Door then pre-fetches the next chunk in parallel. This pre-fetch ensures that the content stays one chunk ahead of the user, which reduces latency. This process continues until the entire file gets downloaded (if requested) or the client closes the connection.
For more information on the byte-range request, read RFC 7233. Front Door caches any chunks as they're received so the entire file doesn't need to be cached on the Front Door cache. Ensuing requests for the file or byte ranges are served from the cache. If the chunks aren't all cached, pre-fetching is used to request chunks from the backend. This optimization relies on the backend's ability to support byte-range requests. If the backend doesn't support byte-range requests, this optimization isn't effective.
","tags":["Azure.FrontDoor.UseCaching","AZR-000320"]},{"location":"en/rules/Azure.FrontDoor.UseCaching/#recommendation","title":"Recommendation","text":"Use caching to reduce retrieving contents from origins and improve overall performance.
","tags":["Azure.FrontDoor.UseCaching","AZR-000320"]},{"location":"en/rules/Azure.FrontDoor.UseCaching/#examples","title":"Examples","text":"","tags":["Azure.FrontDoor.UseCaching","AZR-000320"]},{"location":"en/rules/Azure.FrontDoor.UseCaching/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy front door instances pass this rule:
properties.routingRules.properties.routeConfiguration.cacheConfiguration
.Important The rule checks also for rule sets (child resources) that are overwriting the cache configuration from routing rules. Check the link Routing architecture overview
for more information around this.
For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/frontDoors\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[parameters('frontDoorName')]\",\n \"location\": \"global\",\n \"properties\": {\n \"enabledState\": \"Enabled\",\n \"frontendEndpoints\": [\n {\n \"name\": \"[variables('frontEndEndpointName')]\",\n \"properties\": {\n \"hostName\": \"[format('{0}.azurefd.net', parameters('frontDoorName'))]\",\n \"sessionAffinityEnabledState\": \"Disabled\"\n }\n }\n ],\n \"loadBalancingSettings\": [\n {\n \"name\": \"[variables('loadBalancingSettingsName')]\",\n \"properties\": {\n \"sampleSize\": 4,\n \"successfulSamplesRequired\": 2\n }\n }\n ],\n \"healthProbeSettings\": [\n {\n \"name\": \"[variables('healthProbeSettingsName')]\",\n \"properties\": {\n \"path\": \"/\",\n \"protocol\": \"Http\",\n \"intervalInSeconds\": 120\n }\n }\n ],\n \"backendPools\": [\n {\n \"name\": \"[variables('backendPoolName')]\",\n \"properties\": {\n \"backends\": [\n {\n \"address\": \"[parameters('backendAddress')]\",\n \"backendHostHeader\": \"[parameters('backendAddress')]\",\n \"httpPort\": 80,\n \"httpsPort\": 443,\n \"weight\": 50,\n \"priority\": 1,\n \"enabledState\": \"Enabled\"\n }\n ],\n \"loadBalancingSettings\": {\n \"id\": \"[resourceId('Microsoft.Network/frontDoors/loadBalancingSettings', parameters('frontDoorName'), variables('loadBalancingSettingsName'))]\"\n },\n \"healthProbeSettings\": {\n \"id\": \"[resourceId('Microsoft.Network/frontDoors/healthProbeSettings', parameters('frontDoorName'), variables('healthProbeSettingsName'))]\"\n }\n }\n }\n ],\n \"routingRules\": [\n {\n \"name\": \"[variables('routingRuleName')]\",\n \"properties\": {\n \"frontendEndpoints\": [\n {\n \"id\": \"[resourceId('Microsoft.Network/frontDoors/frontEndEndpoints', parameters('frontDoorName'), variables('frontEndEndpointName'))]\"\n }\n ],\n \"acceptedProtocols\": [\n \"Http\",\n \"Https\"\n ],\n \"patternsToMatch\": [\n \"/*\"\n ],\n \"routeConfiguration\": {\n \"@odata.type\": \"#Microsoft.Azure.FrontDoor.Models.FrontdoorForwardingConfiguration\",\n \"cacheConfiguration\": {\n \"cacheDuration\": \"P12DT1H\",\n \"dynamicCompression\": \"Disabled\",\n \"queryParameters\": \"customerId\",\n \"queryParameterStripDirective\": \"StripAll\"\n },\n \"forwardingProtocol\": \"MatchRequest\",\n \"backendPool\": {\n \"id\": \"[resourceId('Microsoft.Network/frontDoors/backEndPools', parameters('frontDoorName'), variables('backendPoolName'))]\"\n }\n },\n \"enabledState\": \"Enabled\"\n }\n }\n ]\n }\n}\n
","tags":["Azure.FrontDoor.UseCaching","AZR-000320"]},{"location":"en/rules/Azure.FrontDoor.UseCaching/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy front door instances pass this rule:
properties.routingRules.properties.routeConfiguration.cacheConfiguration
.Important The rule checks also for rule sets (child resources) that are overwriting the cache configuration from routing rules. Check the link Routing architecture overview
for more information around this.
For example:
Azure Bicep snippet@description('The name of the Front Door profile.')\nparam frontDoorName string\n\n@description('The hostname of the backend. Must be an IP address or FQDN.')\nparam backendAddress string\n\nvar frontEndEndpointName = 'frontEndEndpoint'\nvar loadBalancingSettingsName = 'loadBalancingSettings'\nvar healthProbeSettingsName = 'healthProbeSettings'\nvar routingRuleName = 'routingRule'\nvar backendPoolName = 'backendPool'\n\nresource frontDoor 'Microsoft.Network/frontDoors@2021-06-01' = {\n name: frontDoorName\n location: 'global'\n properties: {\n enabledState: 'Enabled'\n\n frontendEndpoints: [\n {\n name: frontEndEndpointName\n properties: {\n hostName: '${frontDoorName}.azurefd.net'\n sessionAffinityEnabledState: 'Disabled'\n }\n }\n ]\n\n loadBalancingSettings: [\n {\n name: loadBalancingSettingsName\n properties: {\n sampleSize: 4\n successfulSamplesRequired: 2\n }\n }\n ]\n\n healthProbeSettings: [\n {\n name: healthProbeSettingsName\n properties: {\n path: '/'\n protocol: 'Http'\n intervalInSeconds: 120\n }\n }\n ]\n\n backendPools: [\n {\n name: backendPoolName\n properties: {\n backends: [\n {\n address: backendAddress\n backendHostHeader: backendAddress\n httpPort: 80\n httpsPort: 443\n weight: 50\n priority: 1\n enabledState: 'Enabled'\n }\n ]\n loadBalancingSettings: {\n id: resourceId('Microsoft.Network/frontDoors/loadBalancingSettings', frontDoorName, loadBalancingSettingsName)\n }\n healthProbeSettings: {\n id: resourceId('Microsoft.Network/frontDoors/healthProbeSettings', frontDoorName, healthProbeSettingsName)\n }\n }\n }\n ]\n\n routingRules: [\n {\n name: routingRuleName\n properties: {\n frontendEndpoints: [\n {\n id: resourceId('Microsoft.Network/frontDoors/frontEndEndpoints', frontDoorName, frontEndEndpointName)\n }\n ]\n acceptedProtocols: [\n 'Http'\n 'Https'\n ]\n patternsToMatch: [\n '/*'\n ]\n routeConfiguration: {\n '@odata.type': '#Microsoft.Azure.FrontDoor.Models.FrontdoorForwardingConfiguration'\n cacheConfiguration: {\n cacheDuration: 'P12DT1H'\n dynamicCompression: 'Disabled'\n queryParameters: 'customerId'\n queryParameterStripDirective: 'StripAll'\n }\n forwardingProtocol: 'MatchRequest'\n backendPool: {\n id: resourceId('Microsoft.Network/frontDoors/backEndPools', frontDoorName, backendPoolName)\n }\n }\n enabledState: 'Enabled'\n }\n }\n ]\n }\n}\n
","tags":["Azure.FrontDoor.UseCaching","AZR-000320"]},{"location":"en/rules/Azure.FrontDoor.UseCaching/#notes","title":"Notes","text":"This rule only applies to Azure Front Door Classic profiles (Microsoft.Network/frontDoors
).
Security \u00b7 Front Door \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Enable Web Application Firewall (WAF) policies on each Front Door endpoint.
","tags":["Azure.FrontDoor.UseWAF","AZR-000111"]},{"location":"en/rules/Azure.FrontDoor.UseWAF/#description","title":"Description","text":"Front Door endpoints can optionally be configured with a WAF policy. When configured, every incoming request through Front Door is filtered by the WAF policy.
","tags":["Azure.FrontDoor.UseWAF","AZR-000111"]},{"location":"en/rules/Azure.FrontDoor.UseWAF/#recommendation","title":"Recommendation","text":"Consider enabling a WAF policy on each Front Door endpoint.
","tags":["Azure.FrontDoor.UseWAF","AZR-000111"]},{"location":"en/rules/Azure.FrontDoor.UseWAF/#links","title":"Links","text":"Security \u00b7 Front Door \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources.
","tags":["Azure.FrontDoor.WAF.Enabled","AZR-000115"]},{"location":"en/rules/Azure.FrontDoor.WAF.Enabled/#description","title":"Description","text":"The operational state of a Front Door WAF policy instance is configurable, either enabled or disabled. By default, a WAF policy is enabled.
When disabled, incoming requests bypass the WAF policy and are sent to back ends based on routing rules.
","tags":["Azure.FrontDoor.WAF.Enabled","AZR-000115"]},{"location":"en/rules/Azure.FrontDoor.WAF.Enabled/#recommendation","title":"Recommendation","text":"Consider enabling WAF policy.
","tags":["Azure.FrontDoor.WAF.Enabled","AZR-000115"]},{"location":"en/rules/Azure.FrontDoor.WAF.Enabled/#links","title":"Links","text":"Security \u00b7 Front Door \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources.
","tags":["Azure.FrontDoor.WAF.Mode","AZR-000114"]},{"location":"en/rules/Azure.FrontDoor.WAF.Mode/#description","title":"Description","text":"Front Door WAF policies support two modes of operation, detection and prevention. By default, prevention is configured.
Consider setting Front Door WAF policy to use protection mode.
","tags":["Azure.FrontDoor.WAF.Mode","AZR-000114"]},{"location":"en/rules/Azure.FrontDoor.WAF.Mode/#links","title":"Links","text":"Operational Excellence \u00b7 Front Door \u00b7 Rule \u00b7 2020_12 \u00b7 Awareness
Front Door WAF policy names should meet naming requirements.
","tags":["Azure.FrontDoor.WAF.Name","AZR-000116"]},{"location":"en/rules/Azure.FrontDoor.WAF.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Front Door Web Application Firewall (WAF) policy names are:
Consider using names that meet Front Door WAF policy naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.FrontDoor.WAF.Name","AZR-000116"]},{"location":"en/rules/Azure.FrontDoor.WAF.Name/#notes","title":"Notes","text":"This rule does not check if Front Door WAF policy names are unique.
","tags":["Azure.FrontDoor.WAF.Name","AZR-000116"]},{"location":"en/rules/Azure.FrontDoor.WAF.Name/#links","title":"Links","text":"Security \u00b7 Front Door \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources.
","tags":["Azure.FrontDoorWAF.Enabled","AZR-000305"]},{"location":"en/rules/Azure.FrontDoorWAF.Enabled/#description","title":"Description","text":"The operational state of a Front Door WAF policy instance is configurable, either enabled or disabled. By default, a WAF policy is enabled.
When disabled, incoming requests bypass the WAF policy and are sent to back ends based on routing rules.
","tags":["Azure.FrontDoorWAF.Enabled","AZR-000305"]},{"location":"en/rules/Azure.FrontDoorWAF.Enabled/#recommendation","title":"Recommendation","text":"Consider enabling WAF policy.
","tags":["Azure.FrontDoorWAF.Enabled","AZR-000305"]},{"location":"en/rules/Azure.FrontDoorWAF.Enabled/#examples","title":"Examples","text":"","tags":["Azure.FrontDoorWAF.Enabled","AZR-000305"]},{"location":"en/rules/Azure.FrontDoorWAF.Enabled/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy WAF policies that pass this rule:
properties.policySettings.enabledState
property to Enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/FrontDoorWebApplicationFirewallPolicies\",\n \"apiVersion\": \"2022-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"Global\",\n \"sku\": {\n \"name\": \"Premium_AzureFrontDoor\"\n },\n \"properties\": {\n \"managedRules\": {\n \"managedRuleSets\": [\n {\n \"ruleSetType\": \"Microsoft_DefaultRuleSet\",\n \"ruleSetVersion\": \"2.0\",\n \"ruleSetAction\": \"Block\",\n \"exclusions\": [],\n \"ruleGroupOverrides\": []\n },\n {\n \"ruleSetType\": \"Microsoft_BotManagerRuleSet\",\n \"ruleSetVersion\": \"1.0\",\n \"ruleSetAction\": \"Block\",\n \"exclusions\": [],\n \"ruleGroupOverrides\": []\n }\n ]\n },\n \"policySettings\": {\n \"enabledState\": \"Enabled\",\n \"mode\": \"Prevention\"\n }\n }\n}\n
","tags":["Azure.FrontDoorWAF.Enabled","AZR-000305"]},{"location":"en/rules/Azure.FrontDoorWAF.Enabled/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy WAF policies that pass this rule:
properties.policySettings.enabledState
property to Enabled
.For example:
Azure Bicep snippetresource waf 'Microsoft.Network/FrontDoorWebApplicationFirewallPolicies@2022-05-01' = {\n name: name\n location: 'Global'\n sku: {\n name: 'Premium_AzureFrontDoor'\n }\n properties: {\n managedRules: {\n managedRuleSets: [\n {\n ruleSetType: 'Microsoft_DefaultRuleSet'\n ruleSetVersion: '2.0'\n ruleSetAction: 'Block'\n exclusions: []\n ruleGroupOverrides: []\n }\n {\n ruleSetType: 'Microsoft_BotManagerRuleSet'\n ruleSetVersion: '1.0'\n ruleSetAction: 'Block'\n exclusions: []\n ruleGroupOverrides: []\n }\n ]\n }\n policySettings: {\n enabledState: 'Enabled'\n mode: 'Prevention'\n }\n }\n}\n
","tags":["Azure.FrontDoorWAF.Enabled","AZR-000305"]},{"location":"en/rules/Azure.FrontDoorWAF.Enabled/#links","title":"Links","text":"Security \u00b7 Front Door \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions.
","tags":["Azure.FrontDoorWAF.Exclusions","AZR-000307"]},{"location":"en/rules/Azure.FrontDoorWAF.Exclusions/#description","title":"Description","text":"Front Door WAF supports exclusions lists.
Sometimes Web Application Firewall (WAF) might block a request that you want to allow for your application. WAF exclusion lists allow you to omit certain request attributes from a WAF evaluation. However, it should be allowed and only used as a last resort.
","tags":["Azure.FrontDoorWAF.Exclusions","AZR-000307"]},{"location":"en/rules/Azure.FrontDoorWAF.Exclusions/#recommendation","title":"Recommendation","text":"Avoid configuring Front Door WAF rule exclusions.
","tags":["Azure.FrontDoorWAF.Exclusions","AZR-000307"]},{"location":"en/rules/Azure.FrontDoorWAF.Exclusions/#examples","title":"Examples","text":"","tags":["Azure.FrontDoorWAF.Exclusions","AZR-000307"]},{"location":"en/rules/Azure.FrontDoorWAF.Exclusions/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy WAF policies that pass this rule:
exclusions
property for each managed rule group to an empty array. ORexclusions
property for each managed rule group.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/FrontDoorWebApplicationFirewallPolicies\",\n \"apiVersion\": \"2022-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"Global\",\n \"sku\": {\n \"name\": \"Premium_AzureFrontDoor\"\n },\n \"properties\": {\n \"managedRules\": {\n \"managedRuleSets\": [\n {\n \"ruleSetType\": \"Microsoft_DefaultRuleSet\",\n \"ruleSetVersion\": \"2.0\",\n \"ruleSetAction\": \"Block\",\n \"exclusions\": [],\n \"ruleGroupOverrides\": []\n },\n {\n \"ruleSetType\": \"Microsoft_BotManagerRuleSet\",\n \"ruleSetVersion\": \"1.0\",\n \"ruleSetAction\": \"Block\",\n \"exclusions\": [],\n \"ruleGroupOverrides\": []\n }\n ]\n },\n \"policySettings\": {\n \"enabledState\": \"Enabled\",\n \"mode\": \"Prevention\"\n }\n }\n}\n
","tags":["Azure.FrontDoorWAF.Exclusions","AZR-000307"]},{"location":"en/rules/Azure.FrontDoorWAF.Exclusions/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy WAF policies that pass this rule:
exclusions
property for each managed rule group to an empty array. ORexclusions
property for each managed rule group.For example:
Azure Bicep snippetresource waf 'Microsoft.Network/FrontDoorWebApplicationFirewallPolicies@2022-05-01' = {\n name: name\n location: 'Global'\n sku: {\n name: 'Premium_AzureFrontDoor'\n }\n properties: {\n managedRules: {\n managedRuleSets: [\n {\n ruleSetType: 'Microsoft_DefaultRuleSet'\n ruleSetVersion: '2.0'\n ruleSetAction: 'Block'\n exclusions: []\n ruleGroupOverrides: []\n }\n {\n ruleSetType: 'Microsoft_BotManagerRuleSet'\n ruleSetVersion: '1.0'\n ruleSetAction: 'Block'\n exclusions: []\n ruleGroupOverrides: []\n }\n ]\n }\n policySettings: {\n enabledState: 'Enabled'\n mode: 'Prevention'\n }\n }\n}\n
","tags":["Azure.FrontDoorWAF.Exclusions","AZR-000307"]},{"location":"en/rules/Azure.FrontDoorWAF.Exclusions/#links","title":"Links","text":"Security \u00b7 Front Door \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources.
","tags":["Azure.FrontDoorWAF.PreventionMode","AZR-000306"]},{"location":"en/rules/Azure.FrontDoorWAF.PreventionMode/#description","title":"Description","text":"Front Door WAF policies support two modes of operation, detection and prevention. By default, prevention is configured.
Consider setting Front Door WAF policy to use protection mode.
","tags":["Azure.FrontDoorWAF.PreventionMode","AZR-000306"]},{"location":"en/rules/Azure.FrontDoorWAF.PreventionMode/#examples","title":"Examples","text":"","tags":["Azure.FrontDoorWAF.PreventionMode","AZR-000306"]},{"location":"en/rules/Azure.FrontDoorWAF.PreventionMode/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy WAF policies that pass this rule:
properties.policySettings.mode
property to Prevention
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/FrontDoorWebApplicationFirewallPolicies\",\n \"apiVersion\": \"2022-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"Global\",\n \"sku\": {\n \"name\": \"Premium_AzureFrontDoor\"\n },\n \"properties\": {\n \"managedRules\": {\n \"managedRuleSets\": [\n {\n \"ruleSetType\": \"Microsoft_DefaultRuleSet\",\n \"ruleSetVersion\": \"2.0\",\n \"ruleSetAction\": \"Block\",\n \"exclusions\": [],\n \"ruleGroupOverrides\": []\n },\n {\n \"ruleSetType\": \"Microsoft_BotManagerRuleSet\",\n \"ruleSetVersion\": \"1.0\",\n \"ruleSetAction\": \"Block\",\n \"exclusions\": [],\n \"ruleGroupOverrides\": []\n }\n ]\n },\n \"policySettings\": {\n \"enabledState\": \"Enabled\",\n \"mode\": \"Prevention\"\n }\n }\n}\n
","tags":["Azure.FrontDoorWAF.PreventionMode","AZR-000306"]},{"location":"en/rules/Azure.FrontDoorWAF.PreventionMode/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy WAF policies that pass this rule:
properties.policySettings.mode
property to Prevention
.For example:
Azure Bicep snippetresource waf 'Microsoft.Network/FrontDoorWebApplicationFirewallPolicies@2022-05-01' = {\n name: name\n location: 'Global'\n sku: {\n name: 'Premium_AzureFrontDoor'\n }\n properties: {\n managedRules: {\n managedRuleSets: [\n {\n ruleSetType: 'Microsoft_DefaultRuleSet'\n ruleSetVersion: '2.0'\n ruleSetAction: 'Block'\n exclusions: []\n ruleGroupOverrides: []\n }\n {\n ruleSetType: 'Microsoft_BotManagerRuleSet'\n ruleSetVersion: '1.0'\n ruleSetAction: 'Block'\n exclusions: []\n ruleGroupOverrides: []\n }\n ]\n }\n policySettings: {\n enabledState: 'Enabled'\n mode: 'Prevention'\n }\n }\n}\n
","tags":["Azure.FrontDoorWAF.PreventionMode","AZR-000306"]},{"location":"en/rules/Azure.FrontDoorWAF.PreventionMode/#links","title":"Links","text":"Security \u00b7 Front Door \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources.
","tags":["Azure.FrontDoorWAF.RuleGroups","AZR-000308"]},{"location":"en/rules/Azure.FrontDoorWAF.RuleGroups/#description","title":"Description","text":"Front Door WAF policies support two main Rule Groups.
Consider configuring Front Door WAF policy to use the recommended rule sets.
","tags":["Azure.FrontDoorWAF.RuleGroups","AZR-000308"]},{"location":"en/rules/Azure.FrontDoorWAF.RuleGroups/#examples","title":"Examples","text":"","tags":["Azure.FrontDoorWAF.RuleGroups","AZR-000308"]},{"location":"en/rules/Azure.FrontDoorWAF.RuleGroups/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy WAF policies that pass this rule:
Microsoft_DefaultRuleSet
rule set to the properties.managedRules.managedRuleSets
property.2.0
or greater.Microsoft_BotManagerRuleSet
rule set to the properties.managedRules.managedRuleSets
property.1.0
or greater.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/FrontDoorWebApplicationFirewallPolicies\",\n \"apiVersion\": \"2022-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"Global\",\n \"sku\": {\n \"name\": \"Premium_AzureFrontDoor\"\n },\n \"properties\": {\n \"managedRules\": {\n \"managedRuleSets\": [\n {\n \"ruleSetType\": \"Microsoft_DefaultRuleSet\",\n \"ruleSetVersion\": \"2.0\",\n \"ruleSetAction\": \"Block\",\n \"exclusions\": [],\n \"ruleGroupOverrides\": []\n },\n {\n \"ruleSetType\": \"Microsoft_BotManagerRuleSet\",\n \"ruleSetVersion\": \"1.0\",\n \"ruleSetAction\": \"Block\",\n \"exclusions\": [],\n \"ruleGroupOverrides\": []\n }\n ]\n },\n \"policySettings\": {\n \"enabledState\": \"Enabled\",\n \"mode\": \"Prevention\"\n }\n }\n}\n
","tags":["Azure.FrontDoorWAF.RuleGroups","AZR-000308"]},{"location":"en/rules/Azure.FrontDoorWAF.RuleGroups/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy WAF policies that pass this rule:
Microsoft_DefaultRuleSet
rule set to the properties.managedRules.managedRuleSets
property.2.0
or greater.Microsoft_BotManagerRuleSet
rule set to the properties.managedRules.managedRuleSets
property.1.0
or greater.For example:
Azure Bicep snippetresource waf 'Microsoft.Network/FrontDoorWebApplicationFirewallPolicies@2022-05-01' = {\n name: name\n location: 'Global'\n sku: {\n name: 'Premium_AzureFrontDoor'\n }\n properties: {\n managedRules: {\n managedRuleSets: [\n {\n ruleSetType: 'Microsoft_DefaultRuleSet'\n ruleSetVersion: '2.0'\n ruleSetAction: 'Block'\n exclusions: []\n ruleGroupOverrides: []\n }\n {\n ruleSetType: 'Microsoft_BotManagerRuleSet'\n ruleSetVersion: '1.0'\n ruleSetAction: 'Block'\n exclusions: []\n ruleGroupOverrides: []\n }\n ]\n }\n policySettings: {\n enabledState: 'Enabled'\n mode: 'Prevention'\n }\n }\n}\n
","tags":["Azure.FrontDoorWAF.RuleGroups","AZR-000308"]},{"location":"en/rules/Azure.FrontDoorWAF.RuleGroups/#links","title":"Links","text":"Operational Excellence \u00b7 User Assigned Managed Identity \u00b7 Rule \u00b7 2021_12 \u00b7 Awareness
Managed Identity names should meet naming requirements.
","tags":["Azure.Identity.UserAssignedName","AZR-000117"]},{"location":"en/rules/Azure.Identity.UserAssignedName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Managed Identity names are:
Consider using names that meet Managed Identity naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.Identity.UserAssignedName","AZR-000117"]},{"location":"en/rules/Azure.Identity.UserAssignedName/#notes","title":"Notes","text":"This rule does not check if Managed Identity names are unique.
","tags":["Azure.Identity.UserAssignedName","AZR-000117"]},{"location":"en/rules/Azure.Identity.UserAssignedName/#links","title":"Links","text":"Security \u00b7 IoT Hub \u00b7 Rule \u00b7 2023_03 \u00b7 Critical
IoT Hubs should reject TLS versions older than 1.2.
","tags":["Azure.IoTHub.MinTLS","AZR-000357"]},{"location":"en/rules/Azure.IoTHub.MinTLS/#description","title":"Description","text":"The minimum version of TLS that IoT Hubs accept is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Azure lets you disable outdated protocols and require connections to use a minimum of TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 is accepted.
","tags":["Azure.IoTHub.MinTLS","AZR-000357"]},{"location":"en/rules/Azure.IoTHub.MinTLS/#recommendation","title":"Recommendation","text":"Configure the minimum supported TLS version to be 1.2.
","tags":["Azure.IoTHub.MinTLS","AZR-000357"]},{"location":"en/rules/Azure.IoTHub.MinTLS/#examples","title":"Examples","text":"","tags":["Azure.IoTHub.MinTLS","AZR-000357"]},{"location":"en/rules/Azure.IoTHub.MinTLS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy IoT Hubs that pass this rule:
properties.minTlsVersion
property to 1.2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Devices/IotHubs\",\n \"apiVersion\": \"2022-04-30-preview\",\n \"name\": \"[parameters('iotHubName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"S1\",\n \"capacity\": 1,\n },\n \"properties\": {\n \"minimumTlsVersion\": \"1.2\",\n }\n}\n
","tags":["Azure.IoTHub.MinTLS","AZR-000357"]},{"location":"en/rules/Azure.IoTHub.MinTLS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy IoT Hubs that pass this rule:
properties.minTlsVersion
property to 1.2
.For example:
Azure Bicep snippetresource IoTHub 'Microsoft.Devices/IotHubs@2022-04-30-preview' = {\n name: iotHubName\n location: location\n sku: {\n name: 'S1'\n capacity: 1\n }\n properties: {\n minTlsVersion: '1.2'\n }\n}\n
","tags":["Azure.IoTHub.MinTLS","AZR-000357"]},{"location":"en/rules/Azure.IoTHub.MinTLS/#notes","title":"Notes","text":"The minimum TLS version feature is currently only supported in these regions: - East US - South Central US - West US 2 - US Gov Arizona - US Gov Virginia
The minTlsVersion
property is read-only and cannot be changed once your IoT Hub resource is created. It is therefore important to properly test and validate that all oT devices and services are compatible with TLS 1.2 and the recommended ciphers in advance.
Security \u00b7 Key Vault \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use the principal of least privilege when assigning access to Key Vault.
","tags":["Azure.KeyVault.AccessPolicy","AZR-000118"]},{"location":"en/rules/Azure.KeyVault.AccessPolicy/#description","title":"Description","text":"Key Vault is a service designed to securely store sensitive items such as secrets, keys and certificates. Access Policies determine the permissions user accounts, groups or applications have to Key Vaults items.
The ability for applications and administrators to get, set and list within a Key Vault is commonly required. However should only be assigned to security principals that require access. The purge permission should be rarely assigned.
","tags":["Azure.KeyVault.AccessPolicy","AZR-000118"]},{"location":"en/rules/Azure.KeyVault.AccessPolicy/#recommendation","title":"Recommendation","text":"Consider assigning access to Key Vault data based on the principle of least privilege.
","tags":["Azure.KeyVault.AccessPolicy","AZR-000118"]},{"location":"en/rules/Azure.KeyVault.AccessPolicy/#examples","title":"Examples","text":"","tags":["Azure.KeyVault.AccessPolicy","AZR-000118"]},{"location":"en/rules/Azure.KeyVault.AccessPolicy/#azure-templates","title":"Azure templates","text":"To deploy Key Vaults that pass this rule:
purge
and all
permissions for Key Vault objects. Use specific permissions such as get
and set
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.KeyVault/vaults\",\n \"apiVersion\": \"2022-07-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"sku\": {\n \"family\": \"A\",\n \"name\": \"premium\"\n },\n \"tenantId\": \"[tenant().tenantId]\",\n \"softDeleteRetentionInDays\": 90,\n \"enableSoftDelete\": true,\n \"enablePurgeProtection\": true,\n \"accessPolicies\": [\n {\n \"objectId\": \"[parameters('objectId')]\",\n \"permissions\": {\n \"secrets\": [\n \"get\",\n \"list\",\n \"set\"\n ]\n },\n \"tenantId\": \"[tenant().tenantId]\"\n }\n ]\n }\n}\n
","tags":["Azure.KeyVault.AccessPolicy","AZR-000118"]},{"location":"en/rules/Azure.KeyVault.AccessPolicy/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Key Vaults that pass this rule:
purge
and all
permissions for Key Vault objects. Use specific permissions such as get
and set
.For example:
Azure Bicep snippetresource vault 'Microsoft.KeyVault/vaults@2022-07-01' = {\n name: name\n location: location\n properties: {\n sku: {\n family: 'A'\n name: 'premium'\n }\n tenantId: tenant().tenantId\n softDeleteRetentionInDays: 90\n enableSoftDelete: true\n enablePurgeProtection: true\n accessPolicies: [\n {\n objectId: objectId\n permissions: {\n secrets: [\n 'get'\n 'list'\n 'set'\n ]\n }\n tenantId: tenant().tenantId\n }\n ]\n }\n}\n
","tags":["Azure.KeyVault.AccessPolicy","AZR-000118"]},{"location":"en/rules/Azure.KeyVault.AccessPolicy/#links","title":"Links","text":"Security \u00b7 Key Vault \u00b7 Rule \u00b7 2022_09 \u00b7 Important
Key Vault keys should have auto-rotation enabled.
","tags":["Azure.KeyVault.AutoRotationPolicy","AZR-000123"]},{"location":"en/rules/Azure.KeyVault.AutoRotationPolicy/#description","title":"Description","text":"Automated key rotation in Key Vault allows users to configure Key Vault to automatically generate a new key version at a specified frequency.
Key rotation is often a cause of many application outages. It's critical that the rotation of keys be scheduled and automated to ensure effectiveness.
","tags":["Azure.KeyVault.AutoRotationPolicy","AZR-000123"]},{"location":"en/rules/Azure.KeyVault.AutoRotationPolicy/#recommendation","title":"Recommendation","text":"Consider enabling auto-rotation on Key Vault keys.
","tags":["Azure.KeyVault.AutoRotationPolicy","AZR-000123"]},{"location":"en/rules/Azure.KeyVault.AutoRotationPolicy/#examples","title":"Examples","text":"","tags":["Azure.KeyVault.AutoRotationPolicy","AZR-000123"]},{"location":"en/rules/Azure.KeyVault.AutoRotationPolicy/#configure-with-azure-template","title":"Configure with Azure template","text":"To set auto-rotation for a key:
properties.rotationPolicy.lifetimeActions[*].action.type
to Rotate
.properties.rotationPolicy.lifetimeActions[*].trigger.timeAfterCreate
to the time duration after key creation to rotate.For example:
Azure Template snippet{\n \"type\": \"Microsoft.KeyVault/vaults/keys\",\n \"apiVersion\": \"2021-06-01-preview\",\n \"name\": \"[concat(parameters('vaultName'), '/', 'key1')]\",\n \"properties\": {\n \"keyOps\": [\n \"sign\",\n \"verify\",\n \"wrapKey\",\n \"unwrapKey\",\n \"encrypt\",\n \"decrypt\"\n ],\n \"keySize\": 2048,\n \"kty\": \"RSA\",\n \"rotationPolicy\": {\n \"lifetimeActions\": [\n {\n \"action\": {\n \"type\": \"Rotate\"\n },\n \"trigger\": {\n \"timeAfterCreate\": \"P18D\"\n }\n },\n {\n \"action\": {\n \"type\": \"Notify\"\n },\n \"trigger\": {\n \"timeAfterCreate\": \"P30D\"\n }\n }\n ]\n }\n }\n}\n
","tags":["Azure.KeyVault.AutoRotationPolicy","AZR-000123"]},{"location":"en/rules/Azure.KeyVault.AutoRotationPolicy/#configure-with-bicep","title":"Configure with Bicep","text":"To set auto-rotation for a key:
properties.rotationPolicy.lifetimeActions[*].action.type
to Rotate
.properties.rotationPolicy.lifetimeActions[*].trigger.timeAfterCreate
to the time duration after key creation to rotate.For example:
Azure Bicep snippetresource vaultName_key1 'Microsoft.KeyVault/vaults/keys@2021-06-01-preview' = {\n parent: vaultName_resource\n name: 'key1'\n properties: {\n keyOps: [\n 'sign'\n 'verify'\n 'wrapKey'\n 'unwrapKey'\n 'encrypt'\n 'decrypt'\n ]\n keySize: 2048\n kty: 'RSA'\n rotationPolicy: {\n lifetimeActions: [\n {\n action: {\n type: 'rotate'\n }\n trigger: {\n timeAfterCreate: 'P18D'\n }\n }\n {\n action: {\n type: 'notify'\n }\n trigger: {\n timeAfterCreate: 'P30D'\n }\n }\n ]\n }\n }\n}\n
","tags":["Azure.KeyVault.AutoRotationPolicy","AZR-000123"]},{"location":"en/rules/Azure.KeyVault.AutoRotationPolicy/#links","title":"Links","text":"Security \u00b7 Key Vault \u00b7 Rule \u00b7 2023_03 \u00b7 Important
Key Vault should only accept explicitly allowed traffic.
","tags":["Azure.KeyVault.Firewall","AZR-000355"]},{"location":"en/rules/Azure.KeyVault.Firewall/#description","title":"Description","text":"By default, Key Vault accept connections from clients on any network. To limit access to selected networks, you must first change the default action.
After changing the default action from Allow
to Deny
, configure one or more rules to allow traffic. Traffic can be allowed from:
If any of the following options are enabled you must also enable Allow trusted Microsoft services to bypass this firewall:
enabledForDeployment
- Azure Virtual Machines for deployment.enabledForDiskEncryption
- Azure Disk Encryption for volume encryption.enabledForTemplateDeployment
- Azure Resource Manager for template deployment.Consider configuring Key Vault firewall to restrict network access to permitted clients only. Also consider enforcing this setting using Azure Policy.
","tags":["Azure.KeyVault.Firewall","AZR-000355"]},{"location":"en/rules/Azure.KeyVault.Firewall/#examples","title":"Examples","text":"","tags":["Azure.KeyVault.Firewall","AZR-000355"]},{"location":"en/rules/Azure.KeyVault.Firewall/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Key Vaults that pass this rule:
properties.networkAcls.defaultAction
property to Deny
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.KeyVault/vaults\",\n \"apiVersion\": \"2023-02-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"sku\": {\n \"family\": \"A\",\n \"name\": \"premium\"\n },\n \"tenantId\": \"[tenant().tenantId]\",\n \"softDeleteRetentionInDays\": 90,\n \"enableSoftDelete\": true,\n \"enablePurgeProtection\": true,\n \"enableRbacAuthorization\": true,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\",\n \"bypass\": \"AzureServices\"\n }\n }\n}\n
","tags":["Azure.KeyVault.Firewall","AZR-000355"]},{"location":"en/rules/Azure.KeyVault.Firewall/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Key Vaults that pass this rule:
properties.networkAcls.defaultAction
property to Deny
.For example:
Azure Bicep snippetresource vault 'Microsoft.KeyVault/vaults@2023-02-01' = {\n name: name\n location: location\n properties: {\n sku: {\n family: 'A'\n name: 'premium'\n }\n tenantId: tenant().tenantId\n softDeleteRetentionInDays: 90\n enableSoftDelete: true\n enablePurgeProtection: true\n enableRbacAuthorization: true\n networkAcls: {\n defaultAction: 'Deny'\n bypass: 'AzureServices'\n }\n }\n}\n
","tags":["Azure.KeyVault.Firewall","AZR-000355"]},{"location":"en/rules/Azure.KeyVault.Firewall/#links","title":"Links","text":"Operational Excellence \u00b7 Key Vault \u00b7 Rule \u00b7 2021_03 \u00b7 Awareness
Key Vault Key names should meet naming requirements.
","tags":["Azure.KeyVault.KeyName","AZR-000122"]},{"location":"en/rules/Azure.KeyVault.KeyName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Key Vault Key names are:
Consider using key names that meet Key Vault naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.KeyVault.KeyName","AZR-000122"]},{"location":"en/rules/Azure.KeyVault.KeyName/#notes","title":"Notes","text":"This rule does not check if Key names are unique.
","tags":["Azure.KeyVault.KeyName","AZR-000122"]},{"location":"en/rules/Azure.KeyVault.KeyName/#links","title":"Links","text":"Security \u00b7 Key Vault \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Ensure audit diagnostics logs are enabled to audit Key Vault access.
","tags":["Azure.KeyVault.Logs","AZR-000119"]},{"location":"en/rules/Azure.KeyVault.Logs/#description","title":"Description","text":"To capture logs that record interactions with data or the settings of key vault, diagnostic settings must be configured.
When configuring diagnostics settings, enable one of the following:
AuditEvent
category.audit
category group.allLogs
category group.Management operations for Key Vault is captured automatically within Azure Activity Logs.
","tags":["Azure.KeyVault.Logs","AZR-000119"]},{"location":"en/rules/Azure.KeyVault.Logs/#recommendation","title":"Recommendation","text":"Configure audit diagnostics logs to audit Key Vault access.
","tags":["Azure.KeyVault.Logs","AZR-000119"]},{"location":"en/rules/Azure.KeyVault.Logs/#examples","title":"Examples","text":"","tags":["Azure.KeyVault.Logs","AZR-000119"]},{"location":"en/rules/Azure.KeyVault.Logs/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy key vaults that pass this rule:
AuditEvent
category or audit
category group or allLogs
category group.For example:
Azure Template snippet{\n \"type\": \"Microsoft.KeyVault/vaults\",\n \"apiVersion\": \"2023-02-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"sku\": {\n \"family\": \"A\",\n \"name\": \"premium\"\n },\n \"tenantId\": \"[tenant().tenantId]\",\n \"softDeleteRetentionInDays\": 90,\n \"enableSoftDelete\": true,\n \"enablePurgeProtection\": true,\n \"enableRbacAuthorization\": true,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\",\n \"bypass\": \"AzureServices\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Insights/diagnosticSettings\",\n \"apiVersion\": \"2021-05-01-preview\",\n \"scope\": \"[format('Microsoft.KeyVault/vaults/{0}', parameters('name'))]\",\n \"name\": \"logs\",\n \"properties\": {\n \"workspaceId\": \"[parameters('workspaceId')]\",\n \"logs\": [\n {\n \"category\": \"AuditEvent\",\n \"enabled\": true\n }\n ]\n },\n \"dependsOn\": [\n \"[parameters('name')]\"\n ]\n }\n ]\n}\n
","tags":["Azure.KeyVault.Logs","AZR-000119"]},{"location":"en/rules/Azure.KeyVault.Logs/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy key vaults that pass this rule:
AuditEvent
category or audit
category group or allLogs
category group.For example:
Azure Bicep snippetresource vault 'Microsoft.KeyVault/vaults@2023-02-01' = {\n name: name\n location: location\n properties: {\n sku: {\n family: 'A'\n name: 'premium'\n }\n tenantId: tenant().tenantId\n softDeleteRetentionInDays: 90\n enableSoftDelete: true\n enablePurgeProtection: true\n enableRbacAuthorization: true\n networkAcls: {\n defaultAction: 'Deny'\n bypass: 'AzureServices'\n }\n }\n}\n\nresource logs 'Microsoft.Insights/diagnosticSettings@2021-05-01-preview' = {\n name: 'logs'\n scope: vault\n properties: {\n workspaceId: workspaceId\n logs: [\n {\n category: 'AuditEvent'\n enabled: true\n }\n ]\n }\n}\n
","tags":["Azure.KeyVault.Logs","AZR-000119"]},{"location":"en/rules/Azure.KeyVault.Logs/#links","title":"Links","text":"Operational Excellence \u00b7 Key Vault \u00b7 Rule \u00b7 2021_03 \u00b7 Awareness
Key Vault names should meet naming requirements.
","tags":["Azure.KeyVault.Name","AZR-000120"]},{"location":"en/rules/Azure.KeyVault.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Key Vault names are:
Consider using names that meet Key Vault naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.KeyVault.Name","AZR-000120"]},{"location":"en/rules/Azure.KeyVault.Name/#notes","title":"Notes","text":"This rule does not check if Key Vault names are unique.
","tags":["Azure.KeyVault.Name","AZR-000120"]},{"location":"en/rules/Azure.KeyVault.Name/#links","title":"Links","text":"Reliability \u00b7 Key Vault \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items.
","tags":["Azure.KeyVault.PurgeProtect","AZR-000125"]},{"location":"en/rules/Azure.KeyVault.PurgeProtect/#description","title":"Description","text":"Purge Protection is a feature of Key Vault that prevents purging of vaults and vault items. When soft delete is configured without purge protection, deleted vaults and vault items can be purged. Purging deletes the vault and/ or vault items immediately, and is irreversible.
When purge protection is enabled, vaults and vault items can no longer be purged. Deleted vaults and vault items will be recoverable until the configured retention period. By default, the retention period is 90 days.
Purge protection is not enabled by default.
","tags":["Azure.KeyVault.PurgeProtect","AZR-000125"]},{"location":"en/rules/Azure.KeyVault.PurgeProtect/#recommendation","title":"Recommendation","text":"Consider enabling purge protection on Key Vaults to enforce retention of vaults and vault items for up to 90 days.
","tags":["Azure.KeyVault.PurgeProtect","AZR-000125"]},{"location":"en/rules/Azure.KeyVault.PurgeProtect/#examples","title":"Examples","text":"","tags":["Azure.KeyVault.PurgeProtect","AZR-000125"]},{"location":"en/rules/Azure.KeyVault.PurgeProtect/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Key Vaults that pass this rule:
properties.enablePurgeProtection
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.KeyVault/vaults\",\n \"apiVersion\": \"2023-07-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"sku\": {\n \"family\": \"A\",\n \"name\": \"premium\"\n },\n \"tenantId\": \"[tenant().tenantId]\",\n \"softDeleteRetentionInDays\": 90,\n \"enableSoftDelete\": true,\n \"enablePurgeProtection\": true,\n \"enableRbacAuthorization\": true,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\",\n \"bypass\": \"AzureServices\"\n }\n }\n}\n
","tags":["Azure.KeyVault.PurgeProtect","AZR-000125"]},{"location":"en/rules/Azure.KeyVault.PurgeProtect/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Key Vaults that pass this rule:
properties.enablePurgeProtection
property to true
.For example:
Azure Bicep snippetresource vault 'Microsoft.KeyVault/vaults@2023-07-01' = {\n name: name\n location: location\n properties: {\n sku: {\n family: 'A'\n name: 'premium'\n }\n tenantId: tenant().tenantId\n softDeleteRetentionInDays: 90\n enableSoftDelete: true\n enablePurgeProtection: true\n enableRbacAuthorization: true\n networkAcls: {\n defaultAction: 'Deny'\n bypass: 'AzureServices'\n }\n }\n}\n
","tags":["Azure.KeyVault.PurgeProtect","AZR-000125"]},{"location":"en/rules/Azure.KeyVault.PurgeProtect/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz keyvault update -n '<name>' -g '<resource_group>' --enable-purge-protection\n
","tags":["Azure.KeyVault.PurgeProtect","AZR-000125"]},{"location":"en/rules/Azure.KeyVault.PurgeProtect/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetUpdate-AzKeyVault -ResourceGroupName '<resource_group>' -Name '<name>' -EnablePurgeProtection\n
","tags":["Azure.KeyVault.PurgeProtect","AZR-000125"]},{"location":"en/rules/Azure.KeyVault.PurgeProtect/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
Security \u00b7 Key Vault \u00b7 Rule \u00b7 2023_06 \u00b7 Awareness
Key Vaults should use Azure RBAC as the authorization system for the data plane.
","tags":["Azure.KeyVault.RBAC","AZR-000388"]},{"location":"en/rules/Azure.KeyVault.RBAC/#description","title":"Description","text":"Azure RBAC is the recommended authorization system for the Azure Key Vault data plane.
Azure RBAC allows users to manage key, secrets, and certificates permissions. It provides one place to manage all permissions across all Key Vaults.
Azure RBAC for Key Vault also allows users to have separate permissions on individual keys, secrets, and certificates.
The Azure RBAC permission model is not enabled by default.
","tags":["Azure.KeyVault.RBAC","AZR-000388"]},{"location":"en/rules/Azure.KeyVault.RBAC/#recommendation","title":"Recommendation","text":"Consider using Azure RBAC as the authorization system on Key Vaults for the data plane.
","tags":["Azure.KeyVault.RBAC","AZR-000388"]},{"location":"en/rules/Azure.KeyVault.RBAC/#examples","title":"Examples","text":"","tags":["Azure.KeyVault.RBAC","AZR-000388"]},{"location":"en/rules/Azure.KeyVault.RBAC/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Key Vaults that pass this rule:
properties.enableRbacAuthorization
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.KeyVault/vaults\",\n \"apiVersion\": \"2023-07-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"sku\": {\n \"family\": \"A\",\n \"name\": \"premium\"\n },\n \"tenantId\": \"[tenant().tenantId]\",\n \"softDeleteRetentionInDays\": 90,\n \"enableSoftDelete\": true,\n \"enablePurgeProtection\": true,\n \"enableRbacAuthorization\": true,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\",\n \"bypass\": \"AzureServices\"\n }\n }\n}\n
","tags":["Azure.KeyVault.RBAC","AZR-000388"]},{"location":"en/rules/Azure.KeyVault.RBAC/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Key Vaults that pass this rule:
properties.enableRbacAuthorization
property to true
.For example:
Azure Bicep snippetresource vault 'Microsoft.KeyVault/vaults@2023-07-01' = {\n name: name\n location: location\n properties: {\n sku: {\n family: 'A'\n name: 'premium'\n }\n tenantId: tenant().tenantId\n softDeleteRetentionInDays: 90\n enableSoftDelete: true\n enablePurgeProtection: true\n enableRbacAuthorization: true\n networkAcls: {\n defaultAction: 'Deny'\n bypass: 'AzureServices'\n }\n }\n}\n
","tags":["Azure.KeyVault.RBAC","AZR-000388"]},{"location":"en/rules/Azure.KeyVault.RBAC/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz keyvault update -n '<name>' -g '<resource_group>' --enable-rbac-authorization\n
","tags":["Azure.KeyVault.RBAC","AZR-000388"]},{"location":"en/rules/Azure.KeyVault.RBAC/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetUpdate-AzKeyVault -ResourceGroupName '<resource_group>' -Name '<name>' -EnableRbacAuthorization\n
","tags":["Azure.KeyVault.RBAC","AZR-000388"]},{"location":"en/rules/Azure.KeyVault.RBAC/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
The RBAC permission model may not be suitable for all use cases. If this rule is not suitable for your use case, you can exclude or suppress the rule. For information about limitations see Azure role-based access control vs. access policies in the LINKS
section.
Operational Excellence \u00b7 Key Vault \u00b7 Rule \u00b7 2021_03 \u00b7 Awareness
Key Vault Secret names should meet naming requirements.
","tags":["Azure.KeyVault.SecretName","AZR-000121"]},{"location":"en/rules/Azure.KeyVault.SecretName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Key Vault Secret names are:
Consider using secret names that meet Key Vault naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.KeyVault.SecretName","AZR-000121"]},{"location":"en/rules/Azure.KeyVault.SecretName/#notes","title":"Notes","text":"This rule does not check if Secret names are unique.
","tags":["Azure.KeyVault.SecretName","AZR-000121"]},{"location":"en/rules/Azure.KeyVault.SecretName/#links","title":"Links","text":"Reliability \u00b7 Key Vault \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion.
","tags":["Azure.KeyVault.SoftDelete","AZR-000124"]},{"location":"en/rules/Azure.KeyVault.SoftDelete/#description","title":"Description","text":"Soft Delete is a feature of Key Vault that retains Key Vaults and Key Vault items after initial deletion. A soft deleted vault or vault item can be restored within the configured retention period.
By default, new Key Vaults created through the portal will have soft delete for 90 days configured.
Once enabled, soft delete can not be disabled. When soft delete is enabled, it is possible to purge soft deleted vaults and vault items.
","tags":["Azure.KeyVault.SoftDelete","AZR-000124"]},{"location":"en/rules/Azure.KeyVault.SoftDelete/#recommendation","title":"Recommendation","text":"Consider enabling soft delete on Key Vaults to enable recovery of vaults and vault items.
","tags":["Azure.KeyVault.SoftDelete","AZR-000124"]},{"location":"en/rules/Azure.KeyVault.SoftDelete/#examples","title":"Examples","text":"","tags":["Azure.KeyVault.SoftDelete","AZR-000124"]},{"location":"en/rules/Azure.KeyVault.SoftDelete/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Key Vaults that pass this rule:
properties.enableSoftDelete
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.KeyVault/vaults\",\n \"apiVersion\": \"2023-07-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"sku\": {\n \"family\": \"A\",\n \"name\": \"premium\"\n },\n \"tenantId\": \"[tenant().tenantId]\",\n \"softDeleteRetentionInDays\": 90,\n \"enableSoftDelete\": true,\n \"enablePurgeProtection\": true,\n \"enableRbacAuthorization\": true,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\",\n \"bypass\": \"AzureServices\"\n }\n }\n}\n
","tags":["Azure.KeyVault.SoftDelete","AZR-000124"]},{"location":"en/rules/Azure.KeyVault.SoftDelete/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Key Vaults that pass this rule:
properties.enableSoftDelete
property to true
.For example:
Azure Bicep snippetresource vault 'Microsoft.KeyVault/vaults@2023-07-01' = {\n name: name\n location: location\n properties: {\n sku: {\n family: 'A'\n name: 'premium'\n }\n tenantId: tenant().tenantId\n softDeleteRetentionInDays: 90\n enableSoftDelete: true\n enablePurgeProtection: true\n enableRbacAuthorization: true\n networkAcls: {\n defaultAction: 'Deny'\n bypass: 'AzureServices'\n }\n }\n}\n
","tags":["Azure.KeyVault.SoftDelete","AZR-000124"]},{"location":"en/rules/Azure.KeyVault.SoftDelete/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz keyvault update -n '<name>' -g '<resource_group>' --retention-days 90\n
","tags":["Azure.KeyVault.SoftDelete","AZR-000124"]},{"location":"en/rules/Azure.KeyVault.SoftDelete/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
Reliability \u00b7 Load Balancer \u00b7 Rule \u00b7 2021_09 \u00b7 Important
Load balancers deployed with Standard SKU should be zone-redundant for high availability.
","tags":["Azure.LB.AvailabilityZone","AZR-000127"]},{"location":"en/rules/Azure.LB.AvailabilityZone/#description","title":"Description","text":"Load balancers using availability zones improve reliability and ensure availability during failure scenarios affecting a data center within a region. A single zone redundant frontend IP address will survive zone failure. The frontend IP may be used to reach all (non-impacted) backend pool members no matter the zone. One or more availability zones can fail and the data path survives as long as one zone in the region remains healthy.
","tags":["Azure.LB.AvailabilityZone","AZR-000127"]},{"location":"en/rules/Azure.LB.AvailabilityZone/#recommendation","title":"Recommendation","text":"Consider using zone-redundant load balancers deployed with Standard SKU.
","tags":["Azure.LB.AvailabilityZone","AZR-000127"]},{"location":"en/rules/Azure.LB.AvailabilityZone/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed to Azure using pre-flight and in-flight data.
This rule fails when \"zones\"
is constrained to a single(zonal) zone or is not configured, and passes when set to [\"1\", \"2\", \"3\"]
.
To configure zone-redundancy for a load balancer.
sku.name
to Standard
.properties.frontendIPConfigurations[*].zones
to [\"1\", \"2\", \"3\"]
.For example:
Azure Template snippet{\n \"apiVersion\": \"2020-07-01\",\n \"name\": \"[parameters('name')]\",\n \"type\": \"Microsoft.Network/loadBalancers\",\n \"location\": \"[parameters('location')]\",\n \"dependsOn\": [],\n \"tags\": {},\n \"properties\": {\n \"frontendIPConfigurations\": [\n {\n \"name\": \"frontend-ip-config\",\n \"properties\": {\n \"privateIPAddress\": null,\n \"privateIPAddressVersion\": \"IPv4\",\n \"privateIPAllocationMethod\": \"Dynamic\",\n \"subnet\": {\n \"id\": \"/subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/resourceGroups/lb-rg/providers/Microsoft.Network/virtualNetworks/lb-vnet/subnets/default\"\n }\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n }\n ],\n \"backendAddressPools\": [],\n \"probes\": [],\n \"loadBalancingRules\": [],\n \"inboundNatRules\": [],\n \"outboundRules\": []\n },\n \"sku\": {\n \"name\": \"[parameters('sku')]\",\n \"tier\": \"[parameters('tier')]\"\n }\n}\n
","tags":["Azure.LB.AvailabilityZone","AZR-000127"]},{"location":"en/rules/Azure.LB.AvailabilityZone/#configure-with-bicep","title":"Configure with Bicep","text":"To configure zone-redundancy for a load balancer.
sku.name
to Standard
.properties.frontendIPConfigurations[*].zones
to ['1', '2', '3']
.For example:
Azure Bicep snippetresource lb_001 'Microsoft.Network/loadBalancers@2021-02-01' = {\n name: lbName\n location: location\n sku: {\n name: 'Standard'\n }\n properties: {\n frontendIPConfigurations: [\n {\n name: 'frontendIPConfig'\n properties: {\n privateIPAllocationMethod: 'Dynamic'\n subnet: {\n id: vnet.properties.subnets[1].id\n }\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n }\n ]\n }\n}\n
","tags":["Azure.LB.AvailabilityZone","AZR-000127"]},{"location":"en/rules/Azure.LB.AvailabilityZone/#links","title":"Links","text":"Operational Excellence \u00b7 Load Balancer \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Load Balancer names should meet naming requirements.
","tags":["Azure.LB.Name","AZR-000129"]},{"location":"en/rules/Azure.LB.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Load Balancer names are:
Consider using names that meet Load Balancer naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.LB.Name","AZR-000129"]},{"location":"en/rules/Azure.LB.Name/#notes","title":"Notes","text":"This rule does not check if Load Balancer names are unique.
","tags":["Azure.LB.Name","AZR-000129"]},{"location":"en/rules/Azure.LB.Name/#links","title":"Links","text":"Reliability \u00b7 Load Balancer \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use a specific probe for web protocols.
","tags":["Azure.LB.Probe","AZR-000126"]},{"location":"en/rules/Azure.LB.Probe/#description","title":"Description","text":"A load balancer probe can be configured as TCP/ HTTP or HTTPS.
","tags":["Azure.LB.Probe","AZR-000126"]},{"location":"en/rules/Azure.LB.Probe/#recommendation","title":"Recommendation","text":"Consider using a dedicated health check endpoint for HTTP or HTTPS health probes.
","tags":["Azure.LB.Probe","AZR-000126"]},{"location":"en/rules/Azure.LB.Probe/#links","title":"Links","text":"Reliability \u00b7 Load Balancer \u00b7 Rule \u00b7 2021_09 \u00b7 Important
Load balancers should be deployed with Standard SKU for production workloads.
","tags":["Azure.LB.StandardSKU","AZR-000128"]},{"location":"en/rules/Azure.LB.StandardSKU/#description","title":"Description","text":"Standard Load Balancer enables you to scale your applications and create high availability for small scale deployments to large and complex multi-zone architectures. It supports inbound as well as outbound connections, provides low latency and high throughput, and scales up to millions of flows for all TCP and UDP applications. It enables Availability Zones with zone-redundant and zonal front ends as well as cross-zone load balancing for public and internal scenarios. You can scale Network Virtual Appliance scenarios and make them more resilient by using internal HA Ports load balancing rules. It also provides new diagnostics insights with multi-dimensional metrics in Azure Monitor.
","tags":["Azure.LB.StandardSKU","AZR-000128"]},{"location":"en/rules/Azure.LB.StandardSKU/#recommendation","title":"Recommendation","text":"Consider using Standard SKU for load balancers deployed in production.
","tags":["Azure.LB.StandardSKU","AZR-000128"]},{"location":"en/rules/Azure.LB.StandardSKU/#examples","title":"Examples","text":"","tags":["Azure.LB.StandardSKU","AZR-000128"]},{"location":"en/rules/Azure.LB.StandardSKU/#configure-with-azure-template","title":"Configure with Azure template","text":"To configure Standard SKU for a load balancer.
sku.name
to Standard
.For example:
Azure Template snippet{\n \"apiVersion\": \"2020-07-01\",\n \"name\": \"[parameters('name')]\",\n \"type\": \"Microsoft.Network/loadBalancers\",\n \"location\": \"[parameters('location')]\",\n \"dependsOn\": [],\n \"tags\": {},\n \"properties\": {\n \"frontendIPConfigurations\": [\n {\n \"name\": \"frontend-ip-config\",\n \"properties\": {\n \"privateIPAddress\": null,\n \"privateIPAddressVersion\": \"IPv4\",\n \"privateIPAllocationMethod\": \"Dynamic\",\n \"subnet\": {\n \"id\": \"/subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/resourceGroups/lb-rg/providers/Microsoft.Network/virtualNetworks/lb-vnet/subnets/default\"\n }\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n }\n ],\n \"backendAddressPools\": [],\n \"probes\": [],\n \"loadBalancingRules\": [],\n \"inboundNatRules\": [],\n \"outboundRules\": []\n },\n \"sku\": {\n \"name\": \"Standard\",\n \"tier\": \"[parameters('tier')]\"\n }\n}\n
","tags":["Azure.LB.StandardSKU","AZR-000128"]},{"location":"en/rules/Azure.LB.StandardSKU/#configure-with-bicep","title":"Configure with Bicep","text":"To configure Standard SKU for a load balancer.
sku.name
to Standard
.For example:
Azure Bicep snippetresource lb_001 'Microsoft.Network/loadBalancers@2021-02-01' = {\n name: lbName\n location: location\n sku: {\n name: 'Standard'\n }\n properties: {\n frontendIPConfigurations: [\n {\n name: 'frontendIPConfig'\n properties: {\n privateIPAllocationMethod: 'Dynamic'\n subnet: {\n id: vnet.properties.subnets[1].id\n }\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n }\n ]\n }\n}\n
","tags":["Azure.LB.StandardSKU","AZR-000128"]},{"location":"en/rules/Azure.LB.StandardSKU/#links","title":"Links","text":"Security \u00b7 Logic App \u00b7 Rule \u00b7 2020_12 \u00b7 Critical
Limit HTTP request trigger access to trusted IP addresses.
","tags":["Azure.LogicApp.LimitHTTPTrigger","AZR-000130"]},{"location":"en/rules/Azure.LogicApp.LimitHTTPTrigger/#description","title":"Description","text":"When a Logic App uses a HTTP request trigger by default any source IP address can trigger the workflow. Logic Apps can be configured to limit the IP addresses that are accepted to trigger the workflow.
","tags":["Azure.LogicApp.LimitHTTPTrigger","AZR-000130"]},{"location":"en/rules/Azure.LogicApp.LimitHTTPTrigger/#recommendation","title":"Recommendation","text":"Consider limiting Logic Apps with HTTP request triggers to trusted IP addresses.
","tags":["Azure.LogicApp.LimitHTTPTrigger","AZR-000130"]},{"location":"en/rules/Azure.LogicApp.LimitHTTPTrigger/#links","title":"Links","text":"Cost Optimization \u00b7 Machine Learning \u00b7 Rule \u00b7 2023_12 \u00b7 Critical
Configure an idle shutdown timeout for Machine Learning compute instances.
","tags":["Azure.ML.ComputeIdleShutdown","AZR-000403"]},{"location":"en/rules/Azure.ML.ComputeIdleShutdown/#description","title":"Description","text":"Machine Learning uses compute instances as a training or inference compute for development and testing. It's similar to a virtual machine on the cloud.
To avoid getting charged for a compute instance that is switched on but not being actively used, you can configure when to automatically shutdown compute instances due to inactivity.
","tags":["Azure.ML.ComputeIdleShutdown","AZR-000403"]},{"location":"en/rules/Azure.ML.ComputeIdleShutdown/#recommendation","title":"Recommendation","text":"Consider configuring ML - Compute Instances to automatically shutdown after a period of inactivity to optimize compute costs.
","tags":["Azure.ML.ComputeIdleShutdown","AZR-000403"]},{"location":"en/rules/Azure.ML.ComputeIdleShutdown/#examples","title":"Examples","text":"","tags":["Azure.ML.ComputeIdleShutdown","AZR-000403"]},{"location":"en/rules/Azure.ML.ComputeIdleShutdown/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy compute instances that passes this rule:
properties.properties.idleTimeBeforeShutdown
property with a ISO 8601 formatted string. i.e. For an idle shutdown time of 15 minutes use PT15M
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.MachineLearningServices/workspaces/computes\",\n \"apiVersion\": \"2023-06-01-preview\",\n \"name\": \"[format('{0}/{1}', parameters('name'), parameters('name'))]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"computeType\": \"ComputeInstance\",\n \"disableLocalAuth\": true,\n \"properties\": {\n \"vmSize\": \"[parameters('vmSize')]\",\n \"idleTimeBeforeShutdown\": \"PT15M\"\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.MachineLearningServices/workspaces', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.ML.ComputeIdleShutdown","AZR-000403"]},{"location":"en/rules/Azure.ML.ComputeIdleShutdown/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy compute instances that passes this rule:
properties.properties.idleTimeBeforeShutdown
property with a ISO 8601 formatted string. i.e. For an idle shutdown time of 15 minutes use PT15M
.For example:
Azure Bicep snippetresource compute_instance 'Microsoft.MachineLearningServices/workspaces/computes@2023-06-01-preview' = {\n parent: workspace\n name: name\n location: location\n properties: {\n computeType: 'ComputeInstance'\n disableLocalAuth: true\n properties: {\n vmSize: vmSize\n idleTimeBeforeShutdown: 'PT15M'\n }\n }\n}\n
","tags":["Azure.ML.ComputeIdleShutdown","AZR-000403"]},{"location":"en/rules/Azure.ML.ComputeIdleShutdown/#links","title":"Links","text":"Security \u00b7 Machine Learning \u00b7 Rule \u00b7 2023_12 \u00b7 Critical
Azure Machine Learning Computes should be hosted in a virtual network (VNet).
","tags":["Azure.ML.ComputeVnet","AZR-000405"]},{"location":"en/rules/Azure.ML.ComputeVnet/#description","title":"Description","text":"When using Azure Machine Learning (ML), you can configure compute instances to be private or accessible from the public Internet. By default, the ML compute is configured to be accessible from the public Internet.
ML compute can be deployed into an virtual network (VNet) to provide private connectivity, enhanaced security, and isolation. Using a VNet reduces the attack surface for your solution, and the chances of data exfiltration. Additionally, network controls such as Network Security Groups (NSGs) can be used to further restrict access.
","tags":["Azure.ML.ComputeVnet","AZR-000405"]},{"location":"en/rules/Azure.ML.ComputeVnet/#recommendation","title":"Recommendation","text":"Consider using ML - compute hosted in a VNet to provide private connectivity, enhanaced security, and isolation.
","tags":["Azure.ML.ComputeVnet","AZR-000405"]},{"location":"en/rules/Azure.ML.ComputeVnet/#examples","title":"Examples","text":"","tags":["Azure.ML.ComputeVnet","AZR-000405"]},{"location":"en/rules/Azure.ML.ComputeVnet/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy an ML - compute that passes this rule:
properties.properties.subnet.id
property with a resource Id of a specific VNET subnet.For example:
Azure Template snippet{\n \"type\": \"Microsoft.MachineLearningServices/workspaces/computes\",\n \"apiVersion\": \"2023-06-01-preview\",\n \"name\": \"[format('{0}/{1}', parameters('name'), parameters('name'))]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"computeType\": \"ComputeInstance\",\n \"disableLocalAuth\": true,\n \"properties\": {\n \"vmSize\": \"[parameters('vmSize')]\",\n \"idleTimeBeforeShutdown\": \"PT15M\",\n \"subnet\": {\n \"id\": \"[resourceId('Microsoft.Network/virtualNetworks/subnets', split('vnet/subnet', '/')[0], split('vnet/subnet', '/')[1])]\"\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.MachineLearningServices/workspaces', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.ML.ComputeVnet","AZR-000405"]},{"location":"en/rules/Azure.ML.ComputeVnet/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy an ML - compute that passes this rule:
properties.properties.subnet.id
property with a resource Id of a specific VNET subnet.For example:
Azure Bicep snippetresource compute_instance 'Microsoft.MachineLearningServices/workspaces/computes@2023-06-01-preview' = {\n parent: workspace\n name: name\n location: location\n properties: {\n computeType: 'ComputeInstance'\n disableLocalAuth: true\n properties: {\n vmSize: vmSize\n idleTimeBeforeShutdown: 'PT15M'\n subnet: {\n id: subnet.id\n }\n }\n }\n}\n
","tags":["Azure.ML.ComputeVnet","AZR-000405"]},{"location":"en/rules/Azure.ML.ComputeVnet/#links","title":"Links","text":"Security \u00b7 Machine Learning \u00b7 Rule \u00b7 2023_12 \u00b7 Critical
Azure Machine Learning compute resources should have local authentication methods disabled.
","tags":["Azure.ML.DisableLocalAuth","AZR-000404"]},{"location":"en/rules/Azure.ML.DisableLocalAuth/#description","title":"Description","text":"Azure Machine Learning (ML) compute can have local authenication enabled or disabled. When enabled local authentication methods must be managed and audited separately.
Disabling local authentication ensures that Entra ID (previously Azure Active Directory) is used exclusively for authentication. Using Entra ID, provides consistency as a single authoritative source which:
Consider disabling local authentication on ML - Compute as part of a broader security strategy.
","tags":["Azure.ML.DisableLocalAuth","AZR-000404"]},{"location":"en/rules/Azure.ML.DisableLocalAuth/#examples","title":"Examples","text":"","tags":["Azure.ML.DisableLocalAuth","AZR-000404"]},{"location":"en/rules/Azure.ML.DisableLocalAuth/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy ML - compute that passes this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.MachineLearningServices/workspaces/computes\",\n \"apiVersion\": \"2023-06-01-preview\",\n \"name\": \"[format('{0}/{1}', parameters('name'), parameters('name'))]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"computeType\": \"ComputeInstance\",\n \"disableLocalAuth\": true,\n \"properties\": {\n \"vmSize\": \"[parameters('vmSize')]\",\n \"idleTimeBeforeShutdown\": \"PT15M\"\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.MachineLearningServices/workspaces', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.ML.DisableLocalAuth","AZR-000404"]},{"location":"en/rules/Azure.ML.DisableLocalAuth/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy ML - compute that passes this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Bicep snippetresource compute_instance 'Microsoft.MachineLearningServices/workspaces/computes@2023-06-01-preview' = {\n parent: workspace\n name: name\n location: location\n properties: {\n computeType: 'ComputeInstance'\n disableLocalAuth: true\n properties: {\n vmSize: vmSize\n idleTimeBeforeShutdown: 'PT15M'\n subnet: {\n id: subnet.id\n }\n }\n }\n}\n
","tags":["Azure.ML.DisableLocalAuth","AZR-000404"]},{"location":"en/rules/Azure.ML.DisableLocalAuth/#links","title":"Links","text":"Security \u00b7 Machine Learning \u00b7 Rule \u00b7 2023_12 \u00b7 Critical
Disable public network access from a Azure Machine Learning workspace.
","tags":["Azure.ML.PublicAccess","AZR-000406"]},{"location":"en/rules/Azure.ML.PublicAccess/#description","title":"Description","text":"Disabling public network access improves security by ensuring that the Machine Learning Workspaces aren't exposed on the public internet. You can control exposure of your workspaces by creating private endpoints instead. By default, a public endpoint is enabled for Machine Learning workspaces. The public endpoint is used for all access except for requests that use a Private Endpoint. Access through the public endpoint can be disabled or restricted to authorized virtual networks.
Data exfiltration is an attack where an malicious actor does an unauthorized data transfer. Private Endpoints help control exposure of a workspace to data exfiltration by an internal or external malicious actor. They do this by providing clear separation between public and private endpoints. As a result, broad access to public endpoints which could be operated by a malicious actor are not required.
","tags":["Azure.ML.PublicAccess","AZR-000406"]},{"location":"en/rules/Azure.ML.PublicAccess/#recommendation","title":"Recommendation","text":"Consider disabling access from public endpoints by setting the publicNetworkAccess
property to Disabled
as part of a broader security strategy.
To deploy an ML - Workspace that passes this rule:
properties.publicNetworkAccess
property to Disabled
.properties.allowPublicAccessWhenBehindVnet
property is defined remove the property. Switch to using the properties.publicNetworkAccess
property instead. Configuring both properties is not required.For example:
Azure Template snippet{\n \"type\": \"Microsoft.MachineLearningServices/workspaces\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"basic\",\n \"tier\": \"basic\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"friendlyName\": \"[parameters('name')]\",\n \"keyVault\": \"[resourceId('Microsoft.KeyVault/vaults', parameters('KeyVaultName'))]\",\n \"storageAccount\": \"[resourceId('Microsoft.Storage/storageAccounts', parameters('StorageAccountName'))]\",\n \"applicationInsights\": \"[resourceId('Microsoft.Insights/components', parameters('AppInsightsName'))]\",\n \"containerRegistry\": \"[resourceId('Microsoft.ContainerRegistry/registries', parameters('ContainerRegistryName'))]\",\n \"publicNetworkAccess\": \"Disabled\"\n }\n}\n
","tags":["Azure.ML.PublicAccess","AZR-000406"]},{"location":"en/rules/Azure.ML.PublicAccess/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy an ML - Workspace that passes this rule:
properties.publicNetworkAccess
property to Disabled
.properties.allowPublicAccessWhenBehindVnet
property is defined remove the property. Switch to using the properties.publicNetworkAccess
property instead. Configuring both properties is not required.For example:
Azure Bicep snippetresource workspace 'Microsoft.MachineLearningServices/workspaces@2023-04-01' = {\n name: name\n location: location\n sku: {\n name: 'basic'\n tier: 'basic'\n }\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n friendlyName: friendlyName\n keyVault: keyVault.id\n storageAccount: storageAccount.id\n applicationInsights: appInsights.id\n containerRegistry: containerRegistry.id\n publicNetworkAccess: 'Disabled'\n primaryUserAssignedIdentity: identity.id\n }\n}\n
","tags":["Azure.ML.PublicAccess","AZR-000406"]},{"location":"en/rules/Azure.ML.PublicAccess/#links","title":"Links","text":"Security \u00b7 Machine Learning \u00b7 Rule \u00b7 2023_12 \u00b7 Important
ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity.
","tags":["Azure.ML.UserManagedIdentity","AZR-000407"]},{"location":"en/rules/Azure.ML.UserManagedIdentity/#description","title":"Description","text":"Manange access to Azure ML workspace and associated resources, Azure Container Registry, KeyVault, Storage, and App Insights using user-assigned managed identity. By default, system-assigned managed identity is used by Azure ML workspace to access the associated resources. User-assigned managed identity allows you to create the identity as an Azure resource and maintain the life cycle of that identity.
","tags":["Azure.ML.UserManagedIdentity","AZR-000407"]},{"location":"en/rules/Azure.ML.UserManagedIdentity/#recommendation","title":"Recommendation","text":"Consider using a User-Assigned Managed Identity, as part of a broader security and lifecycle management strategy.
","tags":["Azure.ML.UserManagedIdentity","AZR-000407"]},{"location":"en/rules/Azure.ML.UserManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.ML.UserManagedIdentity","AZR-000407"]},{"location":"en/rules/Azure.ML.UserManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy an ML - Workspace that passes this rule:
identity.type
property to UserAssigned
.identity.userAssignedIdentities
.properties.primaryUserAssignedIdentity
property value to the User-Assigned Managed Identity.For example:
Azure Template snippet{\n \"type\": \"Microsoft.MachineLearningServices/workspaces\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"basic\",\n \"tier\": \"basic\"\n },\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', 'example'))]\": {}\n }\n },\n \"properties\": {\n \"friendlyName\": \"[parameters('friendlyName')]\",\n \"keyVault\": \"[resourceId('Microsoft.KeyVault/vaults', 'example')]\",\n \"storageAccount\": \"[resourceId('Microsoft.Storage/storageAccounts', 'example')]\",\n \"applicationInsights\": \"[resourceId('Microsoft.Insights/components', 'example')]\",\n \"containerRegistry\": \"[resourceId('Microsoft.ContainerRegistry/registries', 'example')]\",\n \"publicNetworkAccess\": \"Disabled\",\n \"primaryUserAssignedIdentity\": \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', 'example')]\"\n }\n}\n
","tags":["Azure.ML.UserManagedIdentity","AZR-000407"]},{"location":"en/rules/Azure.ML.UserManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy an ML - Workspace that passes this rule:
identity.type
property to UserAssigned
.identity.userAssignedIdentities
.properties.primaryUserAssignedIdentity
property value to the User-Assigned Managed Identity.For example:
Azure Bicep snippetresource workspace 'Microsoft.MachineLearningServices/workspaces@2023-04-01' = {\n name: name\n location: location\n sku: {\n name: 'basic'\n tier: 'basic'\n }\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n friendlyName: friendlyName\n keyVault: keyVault.id\n storageAccount: storageAccount.id\n applicationInsights: appInsights.id\n containerRegistry: containerRegistry.id\n publicNetworkAccess: 'Disabled'\n primaryUserAssignedIdentity: identity.id\n }\n}\n
","tags":["Azure.ML.UserManagedIdentity","AZR-000407"]},{"location":"en/rules/Azure.ML.UserManagedIdentity/#links","title":"Links","text":"Security \u00b7 Azure Database for MariaDB \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Determine if access from Azure services is required.
","tags":["Azure.MariaDB.AllowAzureAccess","AZR-000342"]},{"location":"en/rules/Azure.MariaDB.AllowAzureAccess/#description","title":"Description","text":"Allow access to Azure services, permits any Azure service including other Azure customers, network based-access to databases on the same Azure Database for MariaDB server instance. If network based access is permitted, authentication is still required.
Enabling access from Azure services is useful in certain cases where fixed outgoing IP addresses isn't available for the services.
","tags":["Azure.MariaDB.AllowAzureAccess","AZR-000342"]},{"location":"en/rules/Azure.MariaDB.AllowAzureAccess/#recommendation","title":"Recommendation","text":"Where fixed outgoing IP addresses are available for the Azure services, configure IP or virtual network based firewall rules instead of using Allow access to Azure services.
Determine if access from Azure services is required for the services connecting to the hosted databases.
","tags":["Azure.MariaDB.AllowAzureAccess","AZR-000342"]},{"location":"en/rules/Azure.MariaDB.AllowAzureAccess/#examples","title":"Examples","text":"","tags":["Azure.MariaDB.AllowAzureAccess","AZR-000342"]},{"location":"en/rules/Azure.MariaDB.AllowAzureAccess/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for MariaDB Servers that pass this rule:
Microsoft.DBforMariaDB servers/firewallRules
sub-resource (child resource).properties.startIpAddress
and properties.endIpAddress
property to a valid IPv4 address format.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMariaDB/servers\",\n \"apiVersion\": \"2018-06-01\",\n \"name\": \"[parameters('serverName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('skuName')]\",\n \"tier\": \"[parameters('skuTier')]\",\n \"capacity\": \"[parameters('skuCapacity')]\",\n \"size\": \"[format('{0}', parameters('skuSizeMB'))]\",\n \"family\": \"[parameters('skuFamily')]\"\n },\n \"properties\": {\n \"createMode\": \"Default\",\n \"version\": \"[parameters('mariadbVersion')]\",\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"storageProfile\": {\n \"storageMB\": \"[parameters('skuSizeMB')]\",\n \"backupRetentionDays\": \"[parameters('backupRetentionDays')]\",\n \"geoRedundantBackup\": \"[parameters('geoRedundantBackup')]\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.DBforMariaDB/servers/firewallRules\",\n \"apiVersion\": \"2018-06-01\",\n \"name\": \"MariaDbServer001/FunctionApp\",\n \"properties\": {\n \"startIpAddress\": \"20.67.176.40\",\n \"endIpAddress\": \"20.67.176.40\"\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.DBforMariaDB/servers', parameters('serverName'))]\"\n ]\n }\n ]\n}\n
","tags":["Azure.MariaDB.AllowAzureAccess","AZR-000342"]},{"location":"en/rules/Azure.MariaDB.AllowAzureAccess/#configure-with-bicep","title":"Configure with Bicep","text":"Microsoft.DBforMariaDB servers/firewallRules
sub-resource (child resource).properties.startIpAddress
and properties.endIpAddress
property to a valid IPv4 address format.For example:
Azure Bicep snippetresource mariaDbServer 'Microsoft.DBforMariaDB/servers@2018-06-01' = {\n name: serverName\n location: location\n sku: {\n name: skuName\n tier: skuTier\n capacity: skuCapacity\n size: '${skuSizeMB}' \n family: skuFamily\n }\n properties: {\n createMode: 'Default'\n version: mariadbVersion\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n storageProfile: {\n storageMB: skuSizeMB\n backupRetentionDays: backupRetentionDays\n geoRedundantBackup: geoRedundantBackup\n }\n }\n}\n\nresource mariaDbServerFirewallRule 'Microsoft.DBforMariaDB/servers/firewallRules@2018-06-01' = {\n name: 'MariaDbServer001/FunctionApp'\n parent: mariaDbServer\n properties: {\n startIpAddress: '20.67.176.40'\n endIpAddress: '20.67.176.40'\n }\n}\n
","tags":["Azure.MariaDB.AllowAzureAccess","AZR-000342"]},{"location":"en/rules/Azure.MariaDB.AllowAzureAccess/#links","title":"Links","text":"Operational Excellence \u00b7 Azure Database for MariaDB \u00b7 Rule \u00b7 2022_12 \u00b7 Awareness
Azure Database for MariaDB databases should meet naming requirements.
","tags":["Azure.MariaDB.DatabaseName","AZR-000337"]},{"location":"en/rules/Azure.MariaDB.DatabaseName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Azure Database for MariaDB database names are:
Consider using names that meet Azure Database for MariaDB database naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.MariaDB.DatabaseName","AZR-000337"]},{"location":"en/rules/Azure.MariaDB.DatabaseName/#notes","title":"Notes","text":"This rule does not check if Azure Database for MariaDB database names are unique.
","tags":["Azure.MariaDB.DatabaseName","AZR-000337"]},{"location":"en/rules/Azure.MariaDB.DatabaseName/#links","title":"Links","text":"Security \u00b7 Azure Database for MariaDB \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Enable Microsoft Defender for Cloud for Azure Database for MariaDB.
","tags":["Azure.MariaDB.DefenderCloud","AZR-000330"]},{"location":"en/rules/Azure.MariaDB.DefenderCloud/#description","title":"Description","text":"Defender for Cloud detects anomalous activities indicating unusual and potentially harmful attempts to access or exploit databases.
","tags":["Azure.MariaDB.DefenderCloud","AZR-000330"]},{"location":"en/rules/Azure.MariaDB.DefenderCloud/#recommendation","title":"Recommendation","text":"Enable Microsoft Defender for Cloud for Azure Database for MariaDB.
","tags":["Azure.MariaDB.DefenderCloud","AZR-000330"]},{"location":"en/rules/Azure.MariaDB.DefenderCloud/#examples","title":"Examples","text":"","tags":["Azure.MariaDB.DefenderCloud","AZR-000330"]},{"location":"en/rules/Azure.MariaDB.DefenderCloud/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for MariaDB Servers that pass this rule:
Microsoft.DBforMariaDB/servers/securityAlertPolicies
sub-resource (child resource).properties.state
property to Enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMariaDB/servers\",\n \"apiVersion\": \"2018-06-01\",\n \"name\": \"[parameters('serverName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('skuName')]\",\n \"tier\": \"GeneralPurpose\",\n \"capacity\": \"[parameters('SkuCapacity')]\",\n \"size\": \"[format('{0}', parameters('skuSizeMB'))]\",\n \"family\": \"[parameters('skuFamily')]\"\n },\n \"properties\": {\n \"createMode\": \"Default\",\n \"version\": \"[parameters('mariadbVersion')]\",\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"storageProfile\": {\n \"storageMB\": \"[parameters('skuSizeMB')]\",\n \"backupRetentionDays\": 7,\n \"geoRedundantBackup\": \"Enabled\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.DBforMariaDB/servers/securityAlertPolicies\",\n \"apiVersion\": \"2018-06-01\",\n \"name\": \"Default\",\n \"dependsOn\": [\"[parameters('serverName')]\"],\n \"properties\": {\n \"emailAccountAdmins\": true,\n \"emailAddresses\": [\"soc@contoso.com\"],\n \"retentionDays\": 14,\n \"state\": \"Enabled\",\n \"storageAccountAccessKey\": \"account-key\",\n \"storageEndpoint\": \"https://contoso.blob.core.windows.net\"\n }\n }\n ]\n}\n
","tags":["Azure.MariaDB.DefenderCloud","AZR-000330"]},{"location":"en/rules/Azure.MariaDB.DefenderCloud/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for MariaDB Servers that pass this rule:
Microsoft.DBforMariaDB/servers/securityAlertPolicies
sub-resource (child resource).properties.state
property to Enabled
.For example:
Azure Bicep snippetresource mariaDbServer 'Microsoft.DBforMariaDB/servers@2018-06-01' = {\n name: serverName\n location: location\n sku: {\n name: skuName\n tier: 'GeneralPurpose'\n capacity: skuCapacity\n size: '${skuSizeMB}' \n family: skuFamily\n }\n properties: {\n createMode: 'Default'\n version: mariadbVersion\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n storageProfile: {\n storageMB: skuSizeMB\n backupRetentionDays: 7\n geoRedundantBackup: 'Enabled'\n }\n }\n}\n\nresource mariaDbDefender 'Microsoft.DBforMariaDB/servers/securityAlertPolicies@2018-06-01' = {\n name: 'Default'\n parent: MariaDbServer\n properties: {\n emailAccountAdmins: true\n emailAddresses: ['soc@contoso.com']\n retentionDays: 14\n state: 'Enabled'\n storageAccountAccessKey: 'account-key'\n storageEndpoint: 'https://contoso.blob.core.windows.net'\n }\n}\n
","tags":["Azure.MariaDB.DefenderCloud","AZR-000330"]},{"location":"en/rules/Azure.MariaDB.DefenderCloud/#links","title":"Links","text":"Security \u00b7 Azure Database for MariaDB \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Determine if there is an excessive number of permitted IP addresses.
","tags":["Azure.MariaDB.FirewallIPRange","AZR-000344"]},{"location":"en/rules/Azure.MariaDB.FirewallIPRange/#description","title":"Description","text":"Typically the number of IP address rules permitted through the firewall is minimal, with management connectivity from on-premises and cloud application connectivity.
Server-level firewall permitted IP addresses apply to all databases on the Azure Database for MariaDB server.
","tags":["Azure.MariaDB.FirewallIPRange","AZR-000344"]},{"location":"en/rules/Azure.MariaDB.FirewallIPRange/#recommendation","title":"Recommendation","text":"Review the number of Azure for MariaDB server firewall permitted public IP addresses configured. Consider to removing IP addresses that are no longer needed.
","tags":["Azure.MariaDB.FirewallIPRange","AZR-000344"]},{"location":"en/rules/Azure.MariaDB.FirewallIPRange/#notes","title":"Notes","text":"This rule fails when the number of configured public IP addresses exceeds ten (10).
","tags":["Azure.MariaDB.FirewallIPRange","AZR-000344"]},{"location":"en/rules/Azure.MariaDB.FirewallIPRange/#links","title":"Links","text":"Security \u00b7 Azure Database for MariaDB \u00b7 Rule \u00b7 2022_12 \u00b7 Awareness
Determine if there is an excessive number of firewall rules.
","tags":["Azure.MariaDB.FirewallRuleCount","AZR-000343"]},{"location":"en/rules/Azure.MariaDB.FirewallRuleCount/#description","title":"Description","text":"Typically the number of firewall rules required is minimal, with management connectivity from on-premises and cloud application connectivity.
Server-level firewall rules apply to all databases on the Azure Database for MariaDB server.
","tags":["Azure.MariaDB.FirewallRuleCount","AZR-000343"]},{"location":"en/rules/Azure.MariaDB.FirewallRuleCount/#recommendation","title":"Recommendation","text":"Review the number of Azure for MariaDB server firewall rules configured. Consider to removing rules that are no longer needed.
","tags":["Azure.MariaDB.FirewallRuleCount","AZR-000343"]},{"location":"en/rules/Azure.MariaDB.FirewallRuleCount/#notes","title":"Notes","text":"This rule fails when the number of configured firewall rules exceeds ten (10).
","tags":["Azure.MariaDB.FirewallRuleCount","AZR-000343"]},{"location":"en/rules/Azure.MariaDB.FirewallRuleCount/#links","title":"Links","text":"Operational Excellence \u00b7 Azure Database for MariaDB \u00b7 Rule \u00b7 2022_12 \u00b7 Awareness
Azure Database for MariaDB firewall rules should meet naming requirements.
","tags":["Azure.MariaDB.FirewallRuleName","AZR-000338"]},{"location":"en/rules/Azure.MariaDB.FirewallRuleName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Azure Database for MariaDB firewall rule names are:
Consider using names that meet Azure Database for MariaDB firewall rule naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.MariaDB.FirewallRuleName","AZR-000338"]},{"location":"en/rules/Azure.MariaDB.FirewallRuleName/#notes","title":"Notes","text":"This rule does not check if Azure Database for MariaDB firewall rule names are unique.
","tags":["Azure.MariaDB.FirewallRuleName","AZR-000338"]},{"location":"en/rules/Azure.MariaDB.FirewallRuleName/#links","title":"Links","text":"Reliability \u00b7 Azure Database for MariaDB \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Azure Database for MariaDB should store backups in a geo-redundant storage.
","tags":["Azure.MariaDB.GeoRedundantBackup","AZR-000329"]},{"location":"en/rules/Azure.MariaDB.GeoRedundantBackup/#description","title":"Description","text":"Geo-redundant backup helps to protect your Azure Database for MariaDB Servers against outages impacting backup storage in the primary region and allows you to restore your server to the geo-paired region in the event of a disaster.
When the backups are stored in geo-redundant backup storage, they are not only stored within the region in which your server is hosted, but are also replicated to a paired data center.
Check out the NOTES
and the LINKS
section for more details about geo-redundant backup.
Configure geo-redundant backup for Azure Database for MariaDB.
","tags":["Azure.MariaDB.GeoRedundantBackup","AZR-000329"]},{"location":"en/rules/Azure.MariaDB.GeoRedundantBackup/#examples","title":"Examples","text":"","tags":["Azure.MariaDB.GeoRedundantBackup","AZR-000329"]},{"location":"en/rules/Azure.MariaDB.GeoRedundantBackup/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for MariaDB Servers that pass this rule:
properties.storageProfile.geoRedundantBackup
property to Enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMariaDB/servers\",\n \"apiVersion\": \"2018-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('sku')]\",\n \"tier\": \"GeneralPurpose\",\n \"capacity\": \"[parameters('skuCapacity')]\",\n \"size\": \"[format('{0}', parameters('skuSizeMB'))]\",\n \"family\": \"Gen5\"\n },\n \"properties\": {\n \"sslEnforcement\": \"Enabled\",\n \"minimalTlsVersion\": \"TLS1_2\",\n \"createMode\": \"Default\",\n \"version\": \"10.3\",\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"publicNetworkAccess\": \"Disabled\",\n \"storageProfile\": {\n \"storageMB\": \"[parameters('skuSizeMB')]\",\n \"backupRetentionDays\": 7,\n \"geoRedundantBackup\": \"Enabled\"\n }\n }\n}\n
","tags":["Azure.MariaDB.GeoRedundantBackup","AZR-000329"]},{"location":"en/rules/Azure.MariaDB.GeoRedundantBackup/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for MariaDB Servers that pass this rule:
properties.storageProfile.geoRedundantBackup
property to Enabled
.For example:
Azure Bicep snippetresource server 'Microsoft.DBforMariaDB/servers@2018-06-01' = {\n name: name\n location: location\n sku: {\n name: sku\n tier: 'GeneralPurpose'\n capacity: skuCapacity\n size: '${skuSizeMB}'\n family: 'Gen5'\n }\n properties: {\n sslEnforcement: 'Enabled'\n minimalTlsVersion: 'TLS1_2'\n createMode: 'Default'\n version: '10.3'\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n publicNetworkAccess: 'Disabled'\n storageProfile: {\n storageMB: skuSizeMB\n backupRetentionDays: 7\n geoRedundantBackup: 'Enabled'\n }\n }\n}\n
","tags":["Azure.MariaDB.GeoRedundantBackup","AZR-000329"]},{"location":"en/rules/Azure.MariaDB.GeoRedundantBackup/#notes","title":"Notes","text":"This rule is only applicable for Azure Database for Maria DB Servers with General Purpose
and Memory Optimized
tiers. The Basic
tier does not support geo-redundant backup storage.
Security \u00b7 Azure Database for MariaDB \u00b7 Rule \u00b7 2022_12 \u00b7 Critical
Azure Database for MariaDB servers should reject TLS versions older than 1.2.
","tags":["Azure.MariaDB.MinTLS","AZR-000335"]},{"location":"en/rules/Azure.MariaDB.MinTLS/#description","title":"Description","text":"The minimum version of TLS that Azure Database for MariaDB servers accept is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Azure lets you disable outdated protocols and require connections to use a minimum of TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 is accepted.
","tags":["Azure.MariaDB.MinTLS","AZR-000335"]},{"location":"en/rules/Azure.MariaDB.MinTLS/#recommendation","title":"Recommendation","text":"Configure the minimum supported TLS version to be 1.2.
","tags":["Azure.MariaDB.MinTLS","AZR-000335"]},{"location":"en/rules/Azure.MariaDB.MinTLS/#examples","title":"Examples","text":"","tags":["Azure.MariaDB.MinTLS","AZR-000335"]},{"location":"en/rules/Azure.MariaDB.MinTLS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for MariaDB Servers that pass this rule:
properties.minimalTlsVersion
property to TLS1_2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMariaDB/servers\",\n \"apiVersion\": \"2018-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('sku')]\",\n \"tier\": \"GeneralPurpose\",\n \"capacity\": \"[parameters('skuCapacity')]\",\n \"size\": \"[format('{0}', parameters('skuSizeMB'))]\",\n \"family\": \"Gen5\"\n },\n \"properties\": {\n \"sslEnforcement\": \"Enabled\",\n \"minimalTlsVersion\": \"TLS1_2\",\n \"createMode\": \"Default\",\n \"version\": \"10.3\",\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"publicNetworkAccess\": \"Disabled\",\n \"storageProfile\": {\n \"storageMB\": \"[parameters('skuSizeMB')]\",\n \"backupRetentionDays\": 7,\n \"geoRedundantBackup\": \"Enabled\"\n }\n }\n}\n
","tags":["Azure.MariaDB.MinTLS","AZR-000335"]},{"location":"en/rules/Azure.MariaDB.MinTLS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for MariaDB Servers that pass this rule:
properties.minimalTlsVersion
property to TLS1_2
.For example:
Azure Bicep snippetresource server 'Microsoft.DBforMariaDB/servers@2018-06-01' = {\n name: name\n location: location\n sku: {\n name: sku\n tier: 'GeneralPurpose'\n capacity: skuCapacity\n size: '${skuSizeMB}'\n family: 'Gen5'\n }\n properties: {\n sslEnforcement: 'Enabled'\n minimalTlsVersion: 'TLS1_2'\n createMode: 'Default'\n version: '10.3'\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n publicNetworkAccess: 'Disabled'\n storageProfile: {\n storageMB: skuSizeMB\n backupRetentionDays: 7\n geoRedundantBackup: 'Enabled'\n }\n }\n}\n
","tags":["Azure.MariaDB.MinTLS","AZR-000335"]},{"location":"en/rules/Azure.MariaDB.MinTLS/#links","title":"Links","text":"Operational Excellence \u00b7 Azure Database for MariaDB \u00b7 Rule \u00b7 2022_12 \u00b7 Awareness
Azure Database for MariaDB servers should meet naming requirements.
","tags":["Azure.MariaDB.ServerName","AZR-000336"]},{"location":"en/rules/Azure.MariaDB.ServerName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Azure Database for MariaDB server names are:
Consider using names that meet Azure Database for MariaDB server naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.MariaDB.ServerName","AZR-000336"]},{"location":"en/rules/Azure.MariaDB.ServerName/#examples","title":"Examples","text":"","tags":["Azure.MariaDB.ServerName","AZR-000336"]},{"location":"en/rules/Azure.MariaDB.ServerName/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy servers that pass this rule:
name
property to align to resource naming requirements.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMariaDB/servers\",\n \"apiVersion\": \"2018-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('sku')]\",\n \"tier\": \"GeneralPurpose\",\n \"capacity\": \"[parameters('skuCapacity')]\",\n \"size\": \"[format('{0}', parameters('skuSizeMB'))]\",\n \"family\": \"Gen5\"\n },\n \"properties\": {\n \"sslEnforcement\": \"Enabled\",\n \"minimalTlsVersion\": \"TLS1_2\",\n \"createMode\": \"Default\",\n \"version\": \"10.3\",\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"publicNetworkAccess\": \"Disabled\",\n \"storageProfile\": {\n \"storageMB\": \"[parameters('skuSizeMB')]\",\n \"backupRetentionDays\": 7,\n \"geoRedundantBackup\": \"Enabled\"\n }\n }\n}\n
","tags":["Azure.MariaDB.ServerName","AZR-000336"]},{"location":"en/rules/Azure.MariaDB.ServerName/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy servers that pass this rule:
name
property to align to resource naming requirements.For example:
Azure Bicep snippetresource server 'Microsoft.DBforMariaDB/servers@2018-06-01' = {\n name: name\n location: location\n sku: {\n name: sku\n tier: 'GeneralPurpose'\n capacity: skuCapacity\n size: '${skuSizeMB}'\n family: 'Gen5'\n }\n properties: {\n sslEnforcement: 'Enabled'\n minimalTlsVersion: 'TLS1_2'\n createMode: 'Default'\n version: '10.3'\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n publicNetworkAccess: 'Disabled'\n storageProfile: {\n storageMB: skuSizeMB\n backupRetentionDays: 7\n geoRedundantBackup: 'Enabled'\n }\n }\n}\n
","tags":["Azure.MariaDB.ServerName","AZR-000336"]},{"location":"en/rules/Azure.MariaDB.ServerName/#notes","title":"Notes","text":"This rule does not check if Azure Database for MariaDB server names are unique.
","tags":["Azure.MariaDB.ServerName","AZR-000336"]},{"location":"en/rules/Azure.MariaDB.ServerName/#links","title":"Links","text":"Security \u00b7 Azure Database for MariaDB \u00b7 Rule \u00b7 2022_12 \u00b7 Critical
Azure Database for MariaDB servers should only accept encrypted connections.
","tags":["Azure.MariaDB.UseSSL","AZR-000334"]},{"location":"en/rules/Azure.MariaDB.UseSSL/#description","title":"Description","text":"Azure Database for MariaDB is configured to only accept encrypted connections by default. When the setting enforce SSL connections is disabled, encrypted and unencrypted connections are permitted. This does not indicate that unencrypted connections are being used.
Unencrypted communication to MariaDB server instances could allow disclosure of information to an untrusted party.
","tags":["Azure.MariaDB.UseSSL","AZR-000334"]},{"location":"en/rules/Azure.MariaDB.UseSSL/#recommendation","title":"Recommendation","text":"Azure Database for MariaDB should be configured to only accept encrypted connections. Unless explicitly required, consider enabling enforce SSL connections.
Also consider using Azure Policy to audit or enforce this configuration.
","tags":["Azure.MariaDB.UseSSL","AZR-000334"]},{"location":"en/rules/Azure.MariaDB.UseSSL/#examples","title":"Examples","text":"","tags":["Azure.MariaDB.UseSSL","AZR-000334"]},{"location":"en/rules/Azure.MariaDB.UseSSL/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for MariaDB Servers that pass this rule:
properties.sslEnforcement
property to Enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMariaDB/servers\",\n \"apiVersion\": \"2018-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('sku')]\",\n \"tier\": \"GeneralPurpose\",\n \"capacity\": \"[parameters('skuCapacity')]\",\n \"size\": \"[format('{0}', parameters('skuSizeMB'))]\",\n \"family\": \"Gen5\"\n },\n \"properties\": {\n \"sslEnforcement\": \"Enabled\",\n \"minimalTlsVersion\": \"TLS1_2\",\n \"createMode\": \"Default\",\n \"version\": \"10.3\",\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"publicNetworkAccess\": \"Disabled\",\n \"storageProfile\": {\n \"storageMB\": \"[parameters('skuSizeMB')]\",\n \"backupRetentionDays\": 7,\n \"geoRedundantBackup\": \"Enabled\"\n }\n }\n}\n
","tags":["Azure.MariaDB.UseSSL","AZR-000334"]},{"location":"en/rules/Azure.MariaDB.UseSSL/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for MariaDB Servers that pass this rule:
properties.sslEnforcement
property to Enabled
.For example:
Azure Bicep snippetresource server 'Microsoft.DBforMariaDB/servers@2018-06-01' = {\n name: name\n location: location\n sku: {\n name: sku\n tier: 'GeneralPurpose'\n capacity: skuCapacity\n size: '${skuSizeMB}'\n family: 'Gen5'\n }\n properties: {\n sslEnforcement: 'Enabled'\n minimalTlsVersion: 'TLS1_2'\n createMode: 'Default'\n version: '10.3'\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n publicNetworkAccess: 'Disabled'\n storageProfile: {\n storageMB: skuSizeMB\n backupRetentionDays: 7\n geoRedundantBackup: 'Enabled'\n }\n }\n}\n
","tags":["Azure.MariaDB.UseSSL","AZR-000334"]},{"location":"en/rules/Azure.MariaDB.UseSSL/#links","title":"Links","text":"Operational Excellence \u00b7 Azure Database for MariaDB \u00b7 Rule \u00b7 2022_12 \u00b7 Awareness
Azure Database for MariaDB VNET rules should meet naming requirements.
","tags":["Azure.MariaDB.VNETRuleName","AZR-000339"]},{"location":"en/rules/Azure.MariaDB.VNETRuleName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Azure Database for MariaDB VNET rule names are:
Consider using names that meet Azure Database for MariaDB VNET rule naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.MariaDB.VNETRuleName","AZR-000339"]},{"location":"en/rules/Azure.MariaDB.VNETRuleName/#notes","title":"Notes","text":"This rule does not check if Azure Database for MariaDB VNET rule names are unique.
","tags":["Azure.MariaDB.VNETRuleName","AZR-000339"]},{"location":"en/rules/Azure.MariaDB.VNETRuleName/#links","title":"Links","text":"Operational Excellence \u00b7 Monitor \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Configure Service Health alerts to notify administrators.
","tags":["Azure.Monitor.ServiceHealth","AZR-000211"]},{"location":"en/rules/Azure.Monitor.ServiceHealth/#description","title":"Description","text":"Azure provides events and can alert administrators when one of the following occurs in your subscriptions:
Consider configuring an alert to notify administrators when services you are using are potentially impacted.
","tags":["Azure.Monitor.ServiceHealth","AZR-000211"]},{"location":"en/rules/Azure.Monitor.ServiceHealth/#links","title":"Links","text":"Security \u00b7 Azure Database for MySQL \u00b7 Rule \u00b7 2023_06 \u00b7 Critical
Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases.
","tags":["Azure.MySQL.AAD","AZR-000392"]},{"location":"en/rules/Azure.MySQL.AAD/#description","title":"Description","text":"Azure Database for MySQL offer two authentication models, Azure Active Directory (AAD) and MySQL logins. AAD authentication supports centialized identity management in addition to modern password protections. Some of the benefits of AAD authentication over MySQL authentication including:
It is also possible to disable MySQL authentication entirely for the flexible server deployment model.
","tags":["Azure.MySQL.AAD","AZR-000392"]},{"location":"en/rules/Azure.MySQL.AAD/#recommendation","title":"Recommendation","text":"Consider using Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Additionally, consider disabling MySQL authentication.
","tags":["Azure.MySQL.AAD","AZR-000392"]},{"location":"en/rules/Azure.MySQL.AAD/#examples","title":"Examples","text":"","tags":["Azure.MySQL.AAD","AZR-000392"]},{"location":"en/rules/Azure.MySQL.AAD/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for MySQL flexible servers that pass this rule:
Microsoft.DBforMySQL/flexibleServers/administrators
sub-resource.properties.administratorType
to ActiveDirectory
.properties.identityResourceId
to the resource ID of the user-assigned identity used for AAD authentication.properties.login
to the AAD administrator login object name.properties.sid
to the object ID GUID of the AAD administrator user, group, or application.properties.tenantId
to the tenant ID of the AAD administrator user, group, or application.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMySQL/flexibleServers/administrators\",\n \"apiVersion\": \"2022-12-01-preview\",\n \"name\": \"[format('{0}/{1}', parameters('serverName'), 'activeDirectory')]\",\n \"properties\": {\n \"administratorType\": \"ActiveDirectory\",\n \"identityResourceId\": \"[parameters('identityResourceId')]\",\n \"login\": \"[parameters('login')]\",\n \"sid\": \"[parameters('sid')]\",\n \"tenantId\": \"[parameters('tenantId')]\"\n\n },\n \"dependsOn\": [\n \"mySqlFlexibleServer\"\n ]\n}\n
To deploy Azure Database for MySQL single servers that pass this rule:
Microsoft.DBforMySQL/servers/administrators
sub-resource.properties.administratorType
to ActiveDirectory
.properties.login
to the AAD administrator login object name.properties.sid
to the object ID GUID of the AAD administrator user, group, or application.properties.tenantId
to the tenant ID of the AAD administrator user, group, or application.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMySQL/servers/administrators\",\n \"apiVersion\": \"2017-12-01\",\n \"name\": \"[format('{0}/{1}', parameters('serverName'), 'activeDirectory')]\",\n \"properties\": {\n \"administratorType\": \"ActiveDirectory\",\n \"login\": \"[parameters('login')]\",\n \"sid\": \"[parameters('sid')]\",\n \"tenantId\": \"[parameters('tenantId')]\"\n },\n \"dependsOn\": [\n \"mySqlSingleServer\"\n ]\n}\n
","tags":["Azure.MySQL.AAD","AZR-000392"]},{"location":"en/rules/Azure.MySQL.AAD/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for MySQL flexible servers that pass this rule:
Microsoft.DBforMySQL/flexibleServers/administrators
sub-resource.properties.administratorType
to ActiveDirectory
.properties.identityResourceId
to the resource ID of the user-assigned identity used for AAD authentication.properties.login
to the AAD administrator login object name.properties.sid
to the object ID GUID of the AAD administrator user, group, or application.properties.tenantId
to the tenant ID of the AAD administrator user, group, or application.For example:
Azure Bicep snippetresource aadAdmin 'Microsoft.DBforMySQL/flexibleServers/administrators@2021-12-01-preview' = {\n name: 'activeDirectory'\n parent: mySqlFlexibleServer\n properties: {\n administratorType: 'ActiveDirectory'\n identityResourceId: identityResourceId\n login: login\n sid: sid\n tenantId: tenantId\n }\n}\n
To deploy Azure Database for MySQL single servers that pass this rule:
Microsoft.DBforMySQL/servers/administrators
sub-resource.properties.administratorType
to ActiveDirectory
.properties.login
to the AAD administrator login object name.properties.sid
to the object ID GUID of the AAD administrator user, group, or application.properties.tenantId
to the tenant ID of the AAD administrator user, group, or application.For example:
Azure Bicep snippetresource aadAdmin 'Microsoft.DBforMySQL/servers/administrators@2017-12-01' = {\n name: 'activeDirectory'\n parent: mySqlSingleServer\n properties: {\n administratorType: 'ActiveDirectory'\n login: login\n sid: sid\n tenantId: tenantId\n }\n}\n
","tags":["Azure.MySQL.AAD","AZR-000392"]},{"location":"en/rules/Azure.MySQL.AAD/#notes","title":"Notes","text":"For the flexible server deployment model a user-assigned identity is required in order to use AAD-authentication. The single server deployment model does not support enforcing AAD-authentication only.
","tags":["Azure.MySQL.AAD","AZR-000392"]},{"location":"en/rules/Azure.MySQL.AAD/#links","title":"Links","text":"Security \u00b7 Azure Database for MySQL \u00b7 Rule \u00b7 2023_09 \u00b7 Important
Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases.
","tags":["Azure.MySQL.AADOnly","AZR-000394"]},{"location":"en/rules/Azure.MySQL.AADOnly/#description","title":"Description","text":"Azure Database for MySQL supports authentication with MySQL logins and Azure AD authentication.
By default, authentication with MySQL logins is enabled. MySQL logins are unable to provide sufficient protection for identities. Azure AD authentication provides strong protection controls including conditional access, identity governance, and privileged identity management.
Once you decide to use Azure AD authentication, you can disable authentication with MySQL logins.
Azure AD-only authentication is only supported for the flexible server deployment model with MySQL 5.7 and newer.
","tags":["Azure.MySQL.AADOnly","AZR-000394"]},{"location":"en/rules/Azure.MySQL.AADOnly/#recommendation","title":"Recommendation","text":"Consider using Azure AD-only authentication. Also consider using Azure Policy for Azure AD-only authentication with Azure Database for MySQL.
","tags":["Azure.MySQL.AADOnly","AZR-000394"]},{"location":"en/rules/Azure.MySQL.AADOnly/#examples","title":"Examples","text":"","tags":["Azure.MySQL.AADOnly","AZR-000394"]},{"location":"en/rules/Azure.MySQL.AADOnly/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for MySQL flexible servers that pass this rule:
Microsoft.DBforMySQL/flexibleServers/configurations
sub-resource.name
to aad_auth_only
.properties.value
to ON
.properties.source
to user-override
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMySQL/flexibleServers/configurations\",\n \"apiVersion\": \"2022-01-01\",\n \"name\": \"[format('{0}/{1}', parameters('serverName'), 'aad_auth_only')]\",\n \"properties\": {\n \"value\": \"ON\",\n \"source\": \"user-override\"\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.DBforMySQL/flexibleServers', parameters('serverName'))]\"\n ]\n}\n
","tags":["Azure.MySQL.AADOnly","AZR-000394"]},{"location":"en/rules/Azure.MySQL.AADOnly/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for MySQL flexible servers that pass this rule:
Microsoft.DBforMySQL/flexibleServers/configurations
sub-resource.name
to aad_auth_only
.properties.value
to ON
.properties.source
to user-override
.For example:
Azure Bicep snippetresource aadOnly 'Microsoft.DBforMySQL/flexibleServers/configurations@2022-01-01' = {\n name: 'aad_auth_only'\n parent: mySqlFlexibleServer\n properties: {\n value: 'ON'\n source: 'user-override'\n }\n}\n
","tags":["Azure.MySQL.AADOnly","AZR-000394"]},{"location":"en/rules/Azure.MySQL.AADOnly/#notes","title":"Notes","text":"The Azure AD admin must be set before enabling Azure AD-only authentication. Azure AD-only authentication is only suppored for the flexible server deployment model.
","tags":["Azure.MySQL.AADOnly","AZR-000394"]},{"location":"en/rules/Azure.MySQL.AADOnly/#links","title":"Links","text":"Security \u00b7 Azure Database for MySQL \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Determine if access from Azure services is required.
","tags":["Azure.MySQL.AllowAzureAccess","AZR-000134"]},{"location":"en/rules/Azure.MySQL.AllowAzureAccess/#description","title":"Description","text":"Allow access to Azure services, permits any Azure service including other Azure customers, network based-access to databases on the same MySQL server instance. If network based access is permitted, authentication is still required.
Enabling access from Azure Services is useful in certain cases for serverless PaaS workloads where configuring a stable IP address is not possible. For example Azure Functions, Container Instances and Logic Apps.
","tags":["Azure.MySQL.AllowAzureAccess","AZR-000134"]},{"location":"en/rules/Azure.MySQL.AllowAzureAccess/#recommendation","title":"Recommendation","text":"Where a stable IP addresses are able to be configured, configure IP or virtual network based firewall rules instead of using Allow access to Azure services.
Determine if access from Azure services is required for the services connecting to the hosted databases.
","tags":["Azure.MySQL.AllowAzureAccess","AZR-000134"]},{"location":"en/rules/Azure.MySQL.AllowAzureAccess/#links","title":"Links","text":"Security \u00b7 Azure Database for MySQL \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Enable Microsoft Defender for Cloud for Azure Database for MySQL.
","tags":["Azure.MySQL.DefenderCloud","AZR-000328"]},{"location":"en/rules/Azure.MySQL.DefenderCloud/#description","title":"Description","text":"Defender for Cloud detects anomalous activities indicating unusual and potentially harmful attempts to access or exploit databases.
","tags":["Azure.MySQL.DefenderCloud","AZR-000328"]},{"location":"en/rules/Azure.MySQL.DefenderCloud/#recommendation","title":"Recommendation","text":"Enable Microsoft Defender for Cloud for Azure Database for MySQL.
","tags":["Azure.MySQL.DefenderCloud","AZR-000328"]},{"location":"en/rules/Azure.MySQL.DefenderCloud/#examples","title":"Examples","text":"","tags":["Azure.MySQL.DefenderCloud","AZR-000328"]},{"location":"en/rules/Azure.MySQL.DefenderCloud/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for MySQL Single Servers that pass this rule:
Microsoft.DBforMySQL/servers/securityAlertPolicies
sub-resource (child resource).properties.state
property to Enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMySQL/servers\",\n \"apiVersion\": \"2017-12-01\",\n \"name\": \"[parameters('serverName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('skuName')]\",\n \"tier\": \"GeneralPurpose\",\n \"capacity\": \"[parameters('skuCapacity')]\",\n \"size\": \"[format('{0}', parameters('SkuSizeMB'))]\",\n \"family\": \"[parameters('skuFamily')]\"\n },\n \"properties\": {\n \"createMode\": \"Default\",\n \"version\": \"[parameters('mysqlVersion')]\",\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"storageProfile\": {\n \"storageMB\": \"[parameters('SkuSizeMB')]\",\n \"backupRetentionDays\": 7,\n \"geoRedundantBackup\": \"Enabled\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.DBforMySQL/servers/securityAlertPolicies\",\n \"apiVersion\": \"2017-12-01\",\n \"name\": \"Default\",\n \"dependsOn\": [\"[parameters('serverName')]\"],\n \"properties\": {\n \"emailAccountAdmins\": true,\n \"emailAddresses\": [\"soc@contoso.com\"],\n \"retentionDays\": 14,\n \"state\": \"Enabled\",\n \"storageAccountAccessKey\": \"account-key\",\n \"storageEndpoint\": \"https://contoso.blob.core.windows.net\"\n }\n }\n ]\n}\n
","tags":["Azure.MySQL.DefenderCloud","AZR-000328"]},{"location":"en/rules/Azure.MySQL.DefenderCloud/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for MySQL Single Servers that pass this rule:
Microsoft.DBforMySQL/servers/securityAlertPolicies
sub-resource (child resource).properties.state
property to Enabled
.For example:
Azure Bicep snippetresource mysqlDbServer 'Microsoft.DBforMySQL/servers@2017-12-01' = {\n name: serverName\n location: location\n sku: {\n name: skuName\n tier: 'GeneralPurpose'\n capacity: skuCapacity\n size: '${SkuSizeMB}'\n family: skuFamily\n }\n properties: {\n createMode: 'Default'\n version: mysqlVersion\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n storageProfile: {\n storageMB: SkuSizeMB\n backupRetentionDays: 7\n geoRedundantBackup: 'Enabled'\n }\n }\n}\n\nresource mysqlDefender 'Microsoft.DBforMySQL/servers/securityAlertPolicies@2017-12-01' = {\n name: 'Default'\n parent: mysqlDbServer\n properties: {\n emailAccountAdmins: true\n emailAddresses: ['soc@contoso.com']\n retentionDays: 14\n state: 'Enabled'\n storageAccountAccessKey: 'account-key'\n storageEndpoint: 'https://contoso.blob.core.windows.net'\n }\n}\n
","tags":["Azure.MySQL.DefenderCloud","AZR-000328"]},{"location":"en/rules/Azure.MySQL.DefenderCloud/#notes","title":"Notes","text":"This rule is only applicable for the Azure Database for MySQL Single Server deployment model.
Azure Database for MySQL Flexible Server deployment model does not currently support Microsoft Defender for Cloud.
","tags":["Azure.MySQL.DefenderCloud","AZR-000328"]},{"location":"en/rules/Azure.MySQL.DefenderCloud/#links","title":"Links","text":"Security \u00b7 Azure Database for MySQL \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Determine if there is an excessive number of permitted IP addresses.
","tags":["Azure.MySQL.FirewallIPRange","AZR-000135"]},{"location":"en/rules/Azure.MySQL.FirewallIPRange/#description","title":"Description","text":"Typically the number of IP address rules permitted through the firewall is minimal, with management connectivity from on-premises and cloud application connectivity the most common.
","tags":["Azure.MySQL.FirewallIPRange","AZR-000135"]},{"location":"en/rules/Azure.MySQL.FirewallIPRange/#recommendation","title":"Recommendation","text":"The MySQL server has greater then ten (10) public IP addresses that are permitted network access. Some rules may not be needed or can be reduced.
","tags":["Azure.MySQL.FirewallIPRange","AZR-000135"]},{"location":"en/rules/Azure.MySQL.FirewallIPRange/#links","title":"Links","text":"Security \u00b7 Azure Database for MySQL \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Determine if there is an excessive number of firewall rules.
","tags":["Azure.MySQL.FirewallRuleCount","AZR-000133"]},{"location":"en/rules/Azure.MySQL.FirewallRuleCount/#description","title":"Description","text":"Typically the number of firewall rules required is minimal, with management connectivity from on-premises and cloud application connectivity the most common.
","tags":["Azure.MySQL.FirewallRuleCount","AZR-000133"]},{"location":"en/rules/Azure.MySQL.FirewallRuleCount/#recommendation","title":"Recommendation","text":"The MySQL server has greater then ten (10) firewall rules. Some rules may not be needed.
","tags":["Azure.MySQL.FirewallRuleCount","AZR-000133"]},{"location":"en/rules/Azure.MySQL.FirewallRuleCount/#links","title":"Links","text":"Reliability \u00b7 Azure Database for MySQL \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Azure Database for MySQL should store backups in a geo-redundant storage.
","tags":["Azure.MySQL.GeoRedundantBackup","AZR-000323"]},{"location":"en/rules/Azure.MySQL.GeoRedundantBackup/#description","title":"Description","text":"Geo-redundant backup helps to protect your Azure Database for MySQL Servers against outages impacting backup storage in the primary region and allows you to restore your server to the geo-paired region in the event of a disaster.
When the backups are stored in geo-redundant backup storage, they are not only stored within the region in which your server is hosted, but are also replicated to a paired data center. Both the Azure Database for MySQL Flexible Server and the Azure Database for MySQL Single Server deployment model supports geo-redundant backup.
For the flexible deployment model the geo-redundant backup is supported for all tiers, but for the single deployment model either General Purpose
or Memory Optimized
tier is required.
Check out the NOTES
section for more details about geo-redundant backup for each of the deployment models.
Configure geo-redundant backup for Azure Database for MySQL.
","tags":["Azure.MySQL.GeoRedundantBackup","AZR-000323"]},{"location":"en/rules/Azure.MySQL.GeoRedundantBackup/#examples","title":"Examples","text":"","tags":["Azure.MySQL.GeoRedundantBackup","AZR-000323"]},{"location":"en/rules/Azure.MySQL.GeoRedundantBackup/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for MySQL Flexible Servers that pass this rule:
properties.backup.geoRedundantBackup
property to the value 'Enabled'
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMySQL/flexibleServers\",\n \"apiVersion\": \"2021-12-01-preview\",\n \"name\": \"[parameters('serverName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_D16as\",\n \"tier\": \"GeneralPurpose\"\n },\n \"properties\": {\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"storage\": {\n \"autoGrow\": \"Enabled\",\n \"iops\": \"[parameters('StorageIops')]\",\n \"storageSizeGB\": \"[parameters('StorageSizeGB')]\"\n },\n \"createMode\": \"Default\",\n \"version\": \"[parameters('mysqlVersion')]\",\n \"backup\": {\n \"backupRetentionDays\": 7,\n \"geoRedundantBackup\": \"Enabled\"\n },\n \"highAvailability\": {\n \"mode\": \"Disabled\"\n }\n }\n}\n
To deploy Azure Database for MySQL Single Servers that pass this rule:
properties.storageProfile.geoRedundantBackup
property to the value 'Enabled'
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMySQL/servers\",\n \"apiVersion\": \"2017-12-01\",\n \"name\": \"[parameters('serverName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('skuName')]\",\n \"tier\": \"GeneralPurpose\",\n \"capacity\": \"[parameters('skuCapacity')]\",\n \"size\": \"[format('{0}', parameters('SkuSizeMB'))]\",\n \"family\": \"[parameters('skuFamily')]\"\n },\n \"properties\": {\n \"createMode\": \"Default\",\n \"version\": \"[parameters('mysqlVersion')]\",\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"storageProfile\": {\n \"storageMB\": \"[parameters('SkuSizeMB')]\",\n \"backupRetentionDays\": 7,\n \"geoRedundantBackup\": \"Enabled\"\n }\n }\n}\n
","tags":["Azure.MySQL.GeoRedundantBackup","AZR-000323"]},{"location":"en/rules/Azure.MySQL.GeoRedundantBackup/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for MySQL Flexible Servers that pass this rule:
properties.backup.geoRedundantBackup
property to the value 'Enabled'
.For example:
Azure Bicep snippetresource mysqlDbServer 'Microsoft.DBforMySQL/flexibleServers@2021-12-01-preview' = {\n name: serverName\n location: location\n sku: {\n name: 'Standard_D16as'\n tier: 'GeneralPurpose'\n }\n properties: {\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n storage: {\n autoGrow: 'Enabled'\n iops: StorageIops\n storageSizeGB: StorageSizeGB\n }\n createMode: 'Default'\n version: mysqlVersion\n backup: {\n backupRetentionDays: 7\n geoRedundantBackup: 'Enabled'\n }\n highAvailability: {\n mode: 'Disabled'\n }\n }\n}\n
To deploy Azure Database for MySQL Single Servers that pass this rule:
properties.storageProfile.geoRedundantBackup
property to the value 'Enabled'
.For example:
Azure Bicep snippetresource mysqlDbServer 'Microsoft.DBforMySQL/servers@2017-12-01' = {\n name: serverName\n location: location\n sku: {\n name: skuName\n tier: 'GeneralPurpose'\n capacity: skuCapacity\n size: '${SkuSizeMB}'\n family: skuFamily\n }\n properties: {\n createMode: 'Default'\n version: mysqlVersion\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n storageProfile: {\n storageMB: SkuSizeMB\n backupRetentionDays: 7\n geoRedundantBackup: 'Enabled'\n }\n }\n}\n
","tags":["Azure.MySQL.GeoRedundantBackup","AZR-000323"]},{"location":"en/rules/Azure.MySQL.GeoRedundantBackup/#notes","title":"Notes","text":"This rule is applicable for both the Azure Database for MySQL Flexible Server deployment model and the Azure Database for MySQL Single Server deployment model.
For the Single Server deployment model, it runs only against 'General Purpose'
and 'Memory Optimized'
tiers. The 'Basic'
tier does not support geo-redundant backup storage.
Security \u00b7 Azure Database for MySQL \u00b7 Rule \u00b7 2020_09 \u00b7 Critical
MySQL DB servers should reject TLS versions older than 1.2.
","tags":["Azure.MySQL.MinTLS","AZR-000132"]},{"location":"en/rules/Azure.MySQL.MinTLS/#description","title":"Description","text":"The minimum version of TLS that MySQL DB servers accept is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Azure lets you disable outdated protocols and require connections to use a minimum of TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 is accepted.
","tags":["Azure.MySQL.MinTLS","AZR-000132"]},{"location":"en/rules/Azure.MySQL.MinTLS/#recommendation","title":"Recommendation","text":"Consider configuring the minimum supported TLS version to be 1.2.
","tags":["Azure.MySQL.MinTLS","AZR-000132"]},{"location":"en/rules/Azure.MySQL.MinTLS/#links","title":"Links","text":"Operational Excellence \u00b7 Azure Database for MySQL \u00b7 Rule \u00b7 2020_12 \u00b7 Awareness
Azure MySQL DB server names should meet naming requirements.
","tags":["Azure.MySQL.ServerName","AZR-000136"]},{"location":"en/rules/Azure.MySQL.ServerName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for MySQL DB server names are:
Consider using names that meet Azure MySQL DB server naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.MySQL.ServerName","AZR-000136"]},{"location":"en/rules/Azure.MySQL.ServerName/#notes","title":"Notes","text":"This rule does not check if Azure MySQL DB server names are unique.
","tags":["Azure.MySQL.ServerName","AZR-000136"]},{"location":"en/rules/Azure.MySQL.ServerName/#links","title":"Links","text":"Reliability \u00b7 Azure Database for MySQL \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Use Azure Database for MySQL Flexible Server deployment model.
","tags":["Azure.MySQL.UseFlexible","AZR-000325"]},{"location":"en/rules/Azure.MySQL.UseFlexible/#description","title":"Description","text":"Azure Database for MySQL Single Server is on the retirement path. Upgrade to Azure Database for MySQL Flexible Server.
Azure Database for MySQL Flexible Server provides additional options for resilience and scalability above the Single Server deployment model.
","tags":["Azure.MySQL.UseFlexible","AZR-000325"]},{"location":"en/rules/Azure.MySQL.UseFlexible/#recommendation","title":"Recommendation","text":"Consider migrating to Azure Database for MySQL Flexible Server deployment model.
","tags":["Azure.MySQL.UseFlexible","AZR-000325"]},{"location":"en/rules/Azure.MySQL.UseFlexible/#links","title":"Links","text":"Security \u00b7 Azure Database for MySQL \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Enforce encrypted MySQL connections.
","tags":["Azure.MySQL.UseSSL","AZR-000131"]},{"location":"en/rules/Azure.MySQL.UseSSL/#description","title":"Description","text":"Azure Database for MySQL is configured to only accept encrypted connections by default. When the setting enforce SSL connections is disabled, encrypted and unencrypted connections are permitted. This does not indicate that unencrypted connections are being used.
Unencrypted communication to MySQL server instances could allow disclosure of information to an untrusted party.
","tags":["Azure.MySQL.UseSSL","AZR-000131"]},{"location":"en/rules/Azure.MySQL.UseSSL/#recommendation","title":"Recommendation","text":"Azure Database for MySQL should be configured to only accept encrypted connections. Unless explicitly required, consider enabling enforce SSL connections.
Also consider using Azure Policy to audit or enforce this configuration.
","tags":["Azure.MySQL.UseSSL","AZR-000131"]},{"location":"en/rules/Azure.MySQL.UseSSL/#links","title":"Links","text":"Cost Optimization \u00b7 Network Interface \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Network interfaces (NICs) that are not used should be removed.
","tags":["Azure.NIC.Attached","AZR-000257"]},{"location":"en/rules/Azure.NIC.Attached/#description","title":"Description","text":"Network interfaces (NICs) are used to attach services to a virtual network (VNET). Each NIC is deployed as a separate resource, however they are intended to be used with a related service. A NIC that is not attached to a related service performs no purpose.
Keeping unused resources in code or deployed in Azure can lead to confusion and distract attention away from active resources. Avoid unnecessary complexity that can increase the time required to develop, test, and maintain the workload.
Example of services that use NICs include:
Consider removing network interfaces that are not required to keep deployments lean and focus personnel time on active resources. Also consider using Resource Groups to help manage the lifecycle of related resources together.
","tags":["Azure.NIC.Attached","AZR-000257"]},{"location":"en/rules/Azure.NIC.Attached/#links","title":"Links","text":"Operational Excellence \u00b7 Network Interface \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Network Interface (NIC) names should meet naming requirements.
","tags":["Azure.NIC.Name","AZR-000259"]},{"location":"en/rules/Azure.NIC.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Network Interface names are:
Consider using names that meet Network Interface naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.NIC.Name","AZR-000259"]},{"location":"en/rules/Azure.NIC.Name/#examples","title":"Examples","text":"","tags":["Azure.NIC.Name","AZR-000259"]},{"location":"en/rules/Azure.NIC.Name/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy network interfaces that pass this rule:
minLength
and maxLength
constraint for the resource name parameter.uniqueString()
function to generate a unique name.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"The location resources will be deployed.\"\n }\n },\n \"subnetId\": {\n \"type\": \"string\",\n \"metadata\": {\n \"description\": \"A reference to the VNET subnet where the VM will be deployed.\"\n }\n },\n \"nicName\": {\n \"type\": \"string\",\n \"minLength\": 1,\n \"maxLength\": 80,\n \"metadata\": {\n \"description\": \"The name of the resource.\"\n }\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Network/networkInterfaces\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('nicName')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"ipConfigurations\": [\n {\n \"name\": \"ipconfig-1\",\n \"properties\": {\n \"privateIPAllocationMethod\": \"Dynamic\",\n \"subnet\": {\n \"id\": \"[parameters('subnetId')]\"\n }\n }\n }\n ]\n }\n }\n ]\n}\n
","tags":["Azure.NIC.Name","AZR-000259"]},{"location":"en/rules/Azure.NIC.Name/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy network interfaces that pass this rule:
minLength
and maxLength
constraint for the resource name parameter.uniqueString()
function to generate a unique name.For example:
Azure Bicep snippet@minLength(1)\n@maxLength(80)\n@sys.description('The name of the resource.')\nparam nicName string\n\nresource nic 'Microsoft.Network/networkInterfaces@2023-05-01' = {\n name: nicName\n location: location\n properties: {\n ipConfigurations: [\n {\n name: 'ipconfig-1'\n properties: {\n privateIPAllocationMethod: 'Dynamic'\n subnet: {\n id: subnetId\n }\n }\n }\n ]\n }\n}\n
","tags":["Azure.NIC.Name","AZR-000259"]},{"location":"en/rules/Azure.NIC.Name/#notes","title":"Notes","text":"This rule does not check if Network Interface names are unique.
","tags":["Azure.NIC.Name","AZR-000259"]},{"location":"en/rules/Azure.NIC.Name/#links","title":"Links","text":"Operational Excellence \u00b7 Network Interface \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Network interfaces (NICs) should inherit DNS from virtual networks.
","tags":["Azure.NIC.UniqueDns","AZR-000258"]},{"location":"en/rules/Azure.NIC.UniqueDns/#description","title":"Description","text":"By default Virtual machine (VM) NICs automatically use a DNS configuration inherited from the virtual network they connect to. Optionally, DNS servers can be overridden on a per NIC basis with a custom configuration.
Using network interfaces with individual DNS server settings may increase management overhead and complexity.
","tags":["Azure.NIC.UniqueDns","AZR-000258"]},{"location":"en/rules/Azure.NIC.UniqueDns/#recommendation","title":"Recommendation","text":"Consider updating NIC DNS server settings to inherit from virtual network.
","tags":["Azure.NIC.UniqueDns","AZR-000258"]},{"location":"en/rules/Azure.NIC.UniqueDns/#links","title":"Links","text":"Operational Excellence \u00b7 Network Security Group \u00b7 Rule \u00b7 2022_09 \u00b7 Awareness
AKS Network Security Group (NSG) should not have custom rules.
","tags":["Azure.NSG.AKSRules","AZR-000292"]},{"location":"en/rules/Azure.NSG.AKSRules/#description","title":"Description","text":"AKS manages the Network Security Group (NSG) allocated to the cluster. There should be no custom rules added as it may cause conflicts, break the AKS cluster or have an unexpected result.
","tags":["Azure.NSG.AKSRules","AZR-000292"]},{"location":"en/rules/Azure.NSG.AKSRules/#recommendation","title":"Recommendation","text":"Do not create custom Network Security Group (NSG) rules for an AKS managed NSG.
","tags":["Azure.NSG.AKSRules","AZR-000292"]},{"location":"en/rules/Azure.NSG.AKSRules/#links","title":"Links","text":"Security \u00b7 Network Security Group \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source.
","tags":["Azure.NSG.AnyInboundSource","AZR-000137"]},{"location":"en/rules/Azure.NSG.AnyInboundSource/#description","title":"Description","text":"NSGs filter network traffic for Azure services connected to a virtual network subnet. In addition to the built-in security rules, a number of custom rules may be defined. Custom security rules can be defined that allow or deny inbound or outbound communication.
When defining custom rules, avoid using rules that allow any as the inbound source. The intent of custom rules that allow any inbound source may not be clearly understood by support teams. Additionally, custom rules with any inbound source may expose services if a public IP address is attached.
When inbound network traffic from the Internet is intended also consider the following:
Consider updating inbound rules to use a specified source such as an IP range, application security group, or service tag. If inbound access from Internet-based sources is intended, consider using the service tag Internet
.
To deploy Network Security Groups that pass this rule:
sourceAddressPrefix
or sourceAddressPrefixes
property to a value other then *
for inbound allow rules.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/networkSecurityGroups\",\n \"apiVersion\": \"2023-09-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"securityRules\": [\n {\n \"name\": \"AllowLoadBalancerHealthInbound\",\n \"properties\": {\n \"description\": \"Allow inbound Azure Load Balancer health check.\",\n \"access\": \"Allow\",\n \"direction\": \"Inbound\",\n \"priority\": 100,\n \"protocol\": \"*\",\n \"sourcePortRange\": \"*\",\n \"sourceAddressPrefix\": \"AzureLoadBalancer\",\n \"destinationPortRange\": \"*\",\n \"destinationAddressPrefix\": \"*\"\n }\n },\n {\n \"name\": \"AllowApplicationInbound\",\n \"properties\": {\n \"description\": \"Allow internal web traffic into application.\",\n \"access\": \"Allow\",\n \"direction\": \"Inbound\",\n \"priority\": 300,\n \"protocol\": \"Tcp\",\n \"sourcePortRange\": \"*\",\n \"sourceAddressPrefix\": \"10.0.0.0/8\",\n \"destinationPortRange\": \"443\",\n \"destinationAddressPrefix\": \"VirtualNetwork\"\n }\n },\n {\n \"name\": \"DenyAllInbound\",\n \"properties\": {\n \"description\": \"Deny all other inbound traffic.\",\n \"access\": \"Deny\",\n \"direction\": \"Inbound\",\n \"priority\": 4000,\n \"protocol\": \"*\",\n \"sourcePortRange\": \"*\",\n \"sourceAddressPrefix\": \"*\",\n \"destinationPortRange\": \"*\",\n \"destinationAddressPrefix\": \"*\"\n }\n },\n {\n \"name\": \"DenyTraversalOutbound\",\n \"properties\": {\n \"description\": \"Deny outbound double hop traversal.\",\n \"access\": \"Deny\",\n \"direction\": \"Outbound\",\n \"priority\": 200,\n \"protocol\": \"Tcp\",\n \"sourcePortRange\": \"*\",\n \"sourceAddressPrefix\": \"VirtualNetwork\",\n \"destinationAddressPrefix\": \"*\",\n \"destinationPortRanges\": [\n \"3389\",\n \"22\"\n ]\n }\n }\n ]\n }\n}\n
To create an Application Security Group, use the Microsoft.Network/applicationSecurityGroups
resource. For example:
{\n \"type\": \"Microsoft.Network/applicationSecurityGroups\",\n \"apiVersion\": \"2023-09-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {}\n}\n
","tags":["Azure.NSG.AnyInboundSource","AZR-000137"]},{"location":"en/rules/Azure.NSG.AnyInboundSource/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Network Security Groups that pass this rule:
sourceAddressPrefix
or sourceAddressPrefixes
property to a value other then *
for inbound allow rules.For example:
Azure Bicep snippetresource nsg 'Microsoft.Network/networkSecurityGroups@2023-09-01' = {\n name: name\n location: location\n properties: {\n securityRules: [\n {\n name: 'AllowLoadBalancerHealthInbound'\n properties: {\n description: 'Allow inbound Azure Load Balancer health check.'\n access: 'Allow'\n direction: 'Inbound'\n priority: 100\n protocol: '*'\n sourcePortRange: '*'\n sourceAddressPrefix: 'AzureLoadBalancer'\n destinationPortRange: '*'\n destinationAddressPrefix: '*'\n }\n }\n {\n name: 'AllowApplicationInbound'\n properties: {\n description: 'Allow internal web traffic into application.'\n access: 'Allow'\n direction: 'Inbound'\n priority: 300\n protocol: 'Tcp'\n sourcePortRange: '*'\n sourceAddressPrefix: '10.0.0.0/8'\n destinationPortRange: '443'\n destinationAddressPrefix: 'VirtualNetwork'\n }\n }\n {\n name: 'DenyAllInbound'\n properties: {\n description: 'Deny all other inbound traffic.'\n access: 'Deny'\n direction: 'Inbound'\n priority: 4000\n protocol: '*'\n sourcePortRange: '*'\n sourceAddressPrefix: '*'\n destinationPortRange: '*'\n destinationAddressPrefix: '*'\n }\n }\n {\n name: 'DenyTraversalOutbound'\n properties: {\n description: 'Deny outbound double hop traversal.'\n access: 'Deny'\n direction: 'Outbound'\n priority: 200\n protocol: 'Tcp'\n sourcePortRange: '*'\n sourceAddressPrefix: 'VirtualNetwork'\n destinationAddressPrefix: '*'\n destinationPortRanges: [\n '3389'\n '22'\n ]\n }\n }\n ]\n }\n}\n
To create an Application Security Group, use the Microsoft.Network/applicationSecurityGroups
resource. For example:
resource asg 'Microsoft.Network/applicationSecurityGroups@2023-09-01' = {\n name: name\n location: location\n properties: {}\n}\n
","tags":["Azure.NSG.AnyInboundSource","AZR-000137"]},{"location":"en/rules/Azure.NSG.AnyInboundSource/#links","title":"Links","text":"Operational Excellence \u00b7 Network Security Group \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Network Security Groups (NSGs) should be associated to a subnet or network interface.
","tags":["Azure.NSG.Associated","AZR-000140"]},{"location":"en/rules/Azure.NSG.Associated/#description","title":"Description","text":"NSGs are basic stateful firewalls that are deployed as separate resources within your subscriptions. Each NSG can be associated to one or more network interfaces or subnets. NSGs that are not associated with a network interface or subnet perform no purpose and add to administration overhead.
","tags":["Azure.NSG.Associated","AZR-000140"]},{"location":"en/rules/Azure.NSG.Associated/#recommendation","title":"Recommendation","text":"Consider cleaning up NSGs that are not required to reduce technical debt. Also consider using Resource Groups to help manage the lifecycle of related resources together. Apply tags to all resources to help identify resources that are attached to specific workloads
To find orphaned NSG's run the following Azure CLI command
Azure CLI snippetaz network nsg list -g $rgName --query \"[?(subnets==null) && (networkInterfaces==null)].id\" -o tsv\n
","tags":["Azure.NSG.Associated","AZR-000140"]},{"location":"en/rules/Azure.NSG.Associated/#links","title":"Links","text":"Operational Excellence \u00b7 Network Security Group \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Avoid denying all inbound traffic.
","tags":["Azure.NSG.DenyAllInbound","AZR-000138"]},{"location":"en/rules/Azure.NSG.DenyAllInbound/#description","title":"Description","text":"Network Security Groups (NSGs) are configured to block all inbound network traffic by default. Blocking all inbound traffic will fail load balancer health probes and other required traffic.
When using a custom deny all inbound rule, also add rules to allow permitted traffic. To permit network traffic, add a custom allow rule with a lower priority number then the deny all rule. Rules with a lower priority number will be processed first. 100 is the lowest priority number.
","tags":["Azure.NSG.DenyAllInbound","AZR-000138"]},{"location":"en/rules/Azure.NSG.DenyAllInbound/#recommendation","title":"Recommendation","text":"Consider using a higher priority number for deny all rules to allow permitted traffic rules to be added. Consider enabling Flow Logs on all critical subnets in your subscription as an auditability and security best practice.
","tags":["Azure.NSG.DenyAllInbound","AZR-000138"]},{"location":"en/rules/Azure.NSG.DenyAllInbound/#examples","title":"Examples","text":"","tags":["Azure.NSG.DenyAllInbound","AZR-000138"]},{"location":"en/rules/Azure.NSG.DenyAllInbound/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Network Security Groups that pass this rule:
For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/networkSecurityGroups\",\n \"apiVersion\": \"2022-01-01\",\n \"name\": \"[parameters('nsgName')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"securityRules\": [\n {\n \"name\": \"AllowLoadBalancerHealthInbound\",\n \"properties\": {\n \"description\": \"Allow inbound Azure Load Balancer health check.\",\n \"access\": \"Allow\",\n \"direction\": \"Inbound\",\n \"priority\": 100,\n \"protocol\": \"*\",\n \"sourcePortRange\": \"*\",\n \"sourceAddressPrefix\": \"AzureLoadBalancer\",\n \"destinationPortRange\": \"*\",\n \"destinationAddressPrefix\": \"*\"\n }\n },\n {\n \"name\": \"AllowApplicationInbound\",\n \"properties\": {\n \"description\": \"Allow internal web traffic into application.\",\n \"access\": \"Allow\",\n \"direction\": \"Inbound\",\n \"priority\": 300,\n \"protocol\": \"Tcp\",\n \"sourcePortRange\": \"*\",\n \"sourceAddressPrefix\": \"10.0.0.0/8\",\n \"destinationPortRange\": \"443\",\n \"destinationAddressPrefix\": \"VirtualNetwork\"\n }\n },\n {\n \"name\": \"DenyAllInbound\",\n \"properties\": {\n \"description\": \"Deny all other inbound traffic.\",\n \"access\": \"Deny\",\n \"direction\": \"Inbound\",\n \"priority\": 4000,\n \"protocol\": \"*\",\n \"sourcePortRange\": \"*\",\n \"sourceAddressPrefix\": \"*\",\n \"destinationPortRange\": \"*\",\n \"destinationAddressPrefix\": \"*\"\n }\n },\n {\n \"name\": \"DenyTraversalOutbound\",\n \"properties\": {\n \"description\": \"Deny outbound double hop traversal.\",\n \"access\": \"Deny\",\n \"direction\": \"Outbound\",\n \"priority\": 200,\n \"protocol\": \"Tcp\",\n \"sourcePortRange\": \"*\",\n \"sourceAddressPrefix\": \"VirtualNetwork\",\n \"destinationAddressPrefix\": \"*\",\n \"destinationPortRanges\": [\n \"3389\",\n \"22\"\n ]\n }\n }\n ]\n }\n}\n
","tags":["Azure.NSG.DenyAllInbound","AZR-000138"]},{"location":"en/rules/Azure.NSG.DenyAllInbound/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Network Security Groups that pass this rule:
For example:
Azure Bicep snippetresource nsg 'Microsoft.Network/networkSecurityGroups@2022-01-01' = {\n name: nsgName\n location: location\n properties: {\n securityRules: [\n {\n name: 'AllowLoadBalancerHealthInbound'\n properties: {\n description: 'Allow inbound Azure Load Balancer health check.'\n access: 'Allow'\n direction: 'Inbound'\n priority: 100\n protocol: '*'\n sourcePortRange: '*'\n sourceAddressPrefix: 'AzureLoadBalancer'\n destinationPortRange: '*'\n destinationAddressPrefix: '*'\n }\n }\n {\n name: 'AllowApplicationInbound'\n properties: {\n description: 'Allow internal web traffic into application.'\n access: 'Allow'\n direction: 'Inbound'\n priority: 300\n protocol: 'Tcp'\n sourcePortRange: '*'\n sourceAddressPrefix: '10.0.0.0/8'\n destinationPortRange: '443'\n destinationAddressPrefix: 'VirtualNetwork'\n }\n }\n {\n name: 'DenyAllInbound'\n properties: {\n description: 'Deny all other inbound traffic.'\n access: 'Deny'\n direction: 'Inbound'\n priority: 4000\n protocol: '*'\n sourcePortRange: '*'\n sourceAddressPrefix: '*'\n destinationPortRange: '*'\n destinationAddressPrefix: '*'\n }\n }\n {\n name: 'DenyTraversalOutbound'\n properties: {\n description: 'Deny outbound double hop traversal.'\n access: 'Deny'\n direction: 'Outbound'\n priority: 200\n protocol: 'Tcp'\n sourcePortRange: '*'\n sourceAddressPrefix: 'VirtualNetwork'\n destinationAddressPrefix: '*'\n destinationPortRanges: [\n '3389'\n '22'\n ]\n }\n }\n ]\n }\n}\n
","tags":["Azure.NSG.DenyAllInbound","AZR-000138"]},{"location":"en/rules/Azure.NSG.DenyAllInbound/#links","title":"Links","text":"Security \u00b7 Network Security Group \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Deny outbound management connections from non-management hosts.
","tags":["Azure.NSG.LateralTraversal","AZR-000139"]},{"location":"en/rules/Azure.NSG.LateralTraversal/#description","title":"Description","text":"Network Security Groups (NSGs) are basic stateful firewalls that provide network isolation and security. NSGs allow or deny network traffic to and from Azure resources in an Azure virtual network. i.e. Traffic between VMs on the same or different subnet can be restricted. NSGs do this by enforcing ordered access rules for all traffic in or out services attached to a subnet.
This micro-segmentation approach provides a control to reduce lateral movement between services.
Typically, a subset of trusted hosts such as privileged access workstations (PAWs), bastion hosts, or jump boxes will be used for management. Management protocols originating from application workload hosts should be blocked.
For example:
This helps improve security in two ways:
Consider configuring NSGs rules to block common outbound management traffic from non-management hosts.
","tags":["Azure.NSG.LateralTraversal","AZR-000139"]},{"location":"en/rules/Azure.NSG.LateralTraversal/#notes","title":"Notes","text":"Specifically this rule checks if either 3389 (RDP) or 22 (SSH) has been blocked for outbound traffic.
To suppress this rule for NSGs protecting subnets expected to allow outbound management traffic see Permit outbound management.
","tags":["Azure.NSG.LateralTraversal","AZR-000139"]},{"location":"en/rules/Azure.NSG.LateralTraversal/#examples","title":"Examples","text":"","tags":["Azure.NSG.LateralTraversal","AZR-000139"]},{"location":"en/rules/Azure.NSG.LateralTraversal/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy NSGs that pass this rule:
For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/networkSecurityGroups\",\n \"name\": \"[parameters('nsgName')]\",\n \"apiVersion\": \"2019-04-01\",\n \"location\": \"[resourceGroup().location]\",\n \"properties\": {\n \"securityRules\": [\n {\n \"name\": \"deny-hop-outbound\",\n \"properties\": {\n \"protocol\": \"*\",\n \"sourcePortRange\": \"*\",\n \"destinationPortRanges\": [\n \"3389\",\n \"22\"\n ],\n \"access\": \"Deny\",\n \"priority\": 200,\n \"direction\": \"Outbound\",\n \"sourceAddressPrefix\": \"VirtualNetwork\",\n \"destinationAddressPrefix\": \"*\"\n }\n }\n ]\n }\n}\n
","tags":["Azure.NSG.LateralTraversal","AZR-000139"]},{"location":"en/rules/Azure.NSG.LateralTraversal/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy NSGs that pass this rule:
For example:
Azure Bicep snippetresource nsg 'Microsoft.Network/networkSecurityGroups@2021-02-01' = {\n name: 'nsg-001'\n properties: {\n securityRules: [\n {\n name: 'deny-hop-outbound'\n properties: {\n priority: 200\n access: 'Deny'\n protocol: 'Tcp'\n direction: 'Outbound'\n sourceAddressPrefix: 'VirtualNetwork'\n destinationAddressPrefix: '*'\n destinationPortRanges: [\n '3389'\n '22'\n ]\n }\n }\n ]\n }\n}\n
","tags":["Azure.NSG.LateralTraversal","AZR-000139"]},{"location":"en/rules/Azure.NSG.LateralTraversal/#links","title":"Links","text":"Operational Excellence \u00b7 Network Security Group \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Network Security Group (NSG) names should meet naming requirements.
","tags":["Azure.NSG.Name","AZR-000141"]},{"location":"en/rules/Azure.NSG.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for NSG names are:
Consider using names that meet Network Security Group naming requirements. Additionally consider naming resources with a standard naming convention. If creating resources using CI/CD pipelines consider programmatically Generating Cloud Resource Names using PowerShell or Bicep
","tags":["Azure.NSG.Name","AZR-000141"]},{"location":"en/rules/Azure.NSG.Name/#notes","title":"Notes","text":"This rule does not check if NSG names are unique.
","tags":["Azure.NSG.Name","AZR-000141"]},{"location":"en/rules/Azure.NSG.Name/#links","title":"Links","text":"Operational Excellence \u00b7 Policy \u00b7 Rule \u00b7 2021_06 \u00b7 Awareness
Policy assignments should use assignedBy
metadata.
When using the Azure Portal, policy assignment automatically set the assignedBy
metadata. This metadata field is intended to indicate the person or team assigning the policy to a resource scope.
When automating policy management, it may be helpful to identify assignments managed by code.
","tags":["Azure.Policy.AssignmentAssignedBy","AZR-000144"]},{"location":"en/rules/Azure.Policy.AssignmentAssignedBy/#recommendation","title":"Recommendation","text":"Consider setting assignedBy
metadata for each policy assignment.
To deploy policy assignments that pass this rule:
properties.metadata.assignedBy
property with a valid value.For example:
Azure Template snippet{\n \"comments\": \"Initiative assignment\",\n \"name\": \"assignment-001\",\n \"type\": \"Microsoft.Authorization/policyAssignments\",\n \"apiVersion\": \"2019-06-01\",\n \"properties\": {\n \"displayName\": \"Assignment 001\",\n \"description\": \"An example policy assignment.\",\n \"metadata\": {\n \"assignedBy\": \"DevOps pipeline\"\n },\n \"enforcementMode\": \"Default\"\n }\n}\n
","tags":["Azure.Policy.AssignmentAssignedBy","AZR-000144"]},{"location":"en/rules/Azure.Policy.AssignmentAssignedBy/#links","title":"Links","text":"Operational Excellence \u00b7 Policy \u00b7 Rule \u00b7 2021_06 \u00b7 Awareness
Policy assignments should use a display name and description.
","tags":["Azure.Policy.AssignmentDescriptors","AZR-000143"]},{"location":"en/rules/Azure.Policy.AssignmentDescriptors/#description","title":"Description","text":"Policy assignments can be configured with a display name and description. Use these additional properties to clearly convey the intent of the policy assignment.
","tags":["Azure.Policy.AssignmentDescriptors","AZR-000143"]},{"location":"en/rules/Azure.Policy.AssignmentDescriptors/#recommendation","title":"Recommendation","text":"Consider setting a display name and description for each policy assignment.
","tags":["Azure.Policy.AssignmentDescriptors","AZR-000143"]},{"location":"en/rules/Azure.Policy.AssignmentDescriptors/#examples","title":"Examples","text":"","tags":["Azure.Policy.AssignmentDescriptors","AZR-000143"]},{"location":"en/rules/Azure.Policy.AssignmentDescriptors/#azure-templates","title":"Azure templates","text":"To deploy policy assignments that pass this rule:
properties.displayName
property with a valid value.properties.description
property with a valid value.For example:
Azure Template snippet{\n \"comments\": \"Initiative assignment\",\n \"name\": \"assignment-001\",\n \"type\": \"Microsoft.Authorization/policyAssignments\",\n \"apiVersion\": \"2019-06-01\",\n \"properties\": {\n \"displayName\": \"Assignment 001\",\n \"description\": \"An example policy assignment.\",\n \"metadata\": {\n \"assignedBy\": \"DevOps pipeline\"\n },\n \"enforcementMode\": \"Default\"\n }\n}\n
","tags":["Azure.Policy.AssignmentDescriptors","AZR-000143"]},{"location":"en/rules/Azure.Policy.AssignmentDescriptors/#links","title":"Links","text":"Operational Excellence \u00b7 Policy \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Policy and initiative definitions should use a display name, description, and category.
","tags":["Azure.Policy.Descriptors","AZR-000142"]},{"location":"en/rules/Azure.Policy.Descriptors/#description","title":"Description","text":"Policy and initiative definitions can be configured with a display name, description, and category. Use these additional properties to clearly convey the purpose when creating custom definitions.
","tags":["Azure.Policy.Descriptors","AZR-000142"]},{"location":"en/rules/Azure.Policy.Descriptors/#recommendation","title":"Recommendation","text":"Consider setting a display name, description and category for each policy and initiatives definition.
","tags":["Azure.Policy.Descriptors","AZR-000142"]},{"location":"en/rules/Azure.Policy.Descriptors/#examples","title":"Examples","text":"","tags":["Azure.Policy.Descriptors","AZR-000142"]},{"location":"en/rules/Azure.Policy.Descriptors/#azure-templates","title":"Azure templates","text":"To deploy initiative and policy definitions that pass this rule:
properties.displayName
property with a valid value.properties.description
property with a valid value.properties.metadata.category
property with a valid value.For example:
Azure Template snippet{\n \"comments\": \"Initiative definition\",\n \"name\": \"initiative-001\",\n \"type\": \"Microsoft.Authorization/policySetDefinitions\",\n \"apiVersion\": \"2019-06-01\",\n \"properties\": {\n \"policyType\": \"Custom\",\n \"displayName\": \"Initiative 001\",\n \"description\": \"An example initiative.\",\n \"metadata\": {\n \"category\": \"Security\"\n },\n \"policyDefinitions\": []\n }\n}\n
","tags":["Azure.Policy.Descriptors","AZR-000142"]},{"location":"en/rules/Azure.Policy.Descriptors/#links","title":"Links","text":"Operational Excellence \u00b7 Policy \u00b7 Rule \u00b7 2021_06 \u00b7 Awareness
Policy exemptions should use a display name and description.
","tags":["Azure.Policy.ExemptionDescriptors","AZR-000145"]},{"location":"en/rules/Azure.Policy.ExemptionDescriptors/#description","title":"Description","text":"Policy assignments can be configured with a display name and description. Use these additional properties to clearly convey the reason for the policy exemption. Additionally, consider providing a link or reference to track exemption conditions and approval.
","tags":["Azure.Policy.ExemptionDescriptors","AZR-000145"]},{"location":"en/rules/Azure.Policy.ExemptionDescriptors/#recommendation","title":"Recommendation","text":"Consider setting a display name and description for each policy exemption.
","tags":["Azure.Policy.ExemptionDescriptors","AZR-000145"]},{"location":"en/rules/Azure.Policy.ExemptionDescriptors/#examples","title":"Examples","text":"","tags":["Azure.Policy.ExemptionDescriptors","AZR-000145"]},{"location":"en/rules/Azure.Policy.ExemptionDescriptors/#azure-templates","title":"Azure templates","text":"To deploy policy exemptions that pass this rule:
properties.displayName
property with a valid value.properties.description
property with a valid value.For example:
Azure Template snippet{\n \"comments\": \"An example exemption.\",\n \"name\": \"exemption-001\",\n \"type\": \"Microsoft.Authorization/policyExemptions\",\n \"apiVersion\": \"2020-07-01-preview\",\n \"properties\": {\n \"policyAssignmentId\": \"<assignment_id>\",\n \"policyDefinitionReferenceIds\": [],\n \"exemptionCategory\": \"Waiver\",\n \"expiresOn\": \"2021-04-27T14:00:00Z\",\n \"displayName\": \"Exemption 001\",\n \"description\": \"An example exemption.\",\n \"metadata\": {\n \"requestedBy\": \"Apps team\",\n \"approvedBy\": \"Security team\",\n \"createdBy\": \"DevOps pipeline\"\n }\n }\n}\n
","tags":["Azure.Policy.ExemptionDescriptors","AZR-000145"]},{"location":"en/rules/Azure.Policy.ExemptionDescriptors/#links","title":"Links","text":"Operational Excellence \u00b7 Policy \u00b7 Rule \u00b7 2021_06 \u00b7 Awareness
Configure policy waiver exemptions to expire.
","tags":["Azure.Policy.WaiverExpiry","AZR-000146"]},{"location":"en/rules/Azure.Policy.WaiverExpiry/#description","title":"Description","text":"Azure Policy waiver exemptions are intended to be temporary acceptance of a non-compliance state. Use the Mitigated
category when the issue intent has been met through an another method.
Consider configuring an expiry for policy exemption waivers within the maximum threshold.
","tags":["Azure.Policy.WaiverExpiry","AZR-000146"]},{"location":"en/rules/Azure.Policy.WaiverExpiry/#examples","title":"Examples","text":"","tags":["Azure.Policy.WaiverExpiry","AZR-000146"]},{"location":"en/rules/Azure.Policy.WaiverExpiry/#azure-templates","title":"Azure templates","text":"To deploy policy assignments that pass this rule:
properties.expiresOn
property with a valid date earlier than the maximum number of days.For example:
Azure Template snippet{\n \"comments\": \"An example exemption.\",\n \"name\": \"exemption-001\",\n \"type\": \"Microsoft.Authorization/policyExemptions\",\n \"apiVersion\": \"2020-07-01-preview\",\n \"properties\": {\n \"policyAssignmentId\": \"<assignment_id>\",\n \"policyDefinitionReferenceIds\": [],\n \"exemptionCategory\": \"Waiver\",\n \"expiresOn\": \"2021-04-27T14:00:00Z\",\n \"displayName\": \"Exemption 001\",\n \"description\": \"An example exemption.\",\n \"metadata\": {\n \"requestedBy\": \"Apps team\",\n \"approvedBy\": \"Security team\",\n \"createdBy\": \"DevOps pipeline\"\n }\n }\n}\n
","tags":["Azure.Policy.WaiverExpiry","AZR-000146"]},{"location":"en/rules/Azure.Policy.WaiverExpiry/#notes","title":"Notes","text":"This rule fails:
Configure AZURE_POLICY_WAIVER_MAX_EXPIRY
to set the maximum expiry date threshold.
# YAML: The default AZURE_POLICY_WAIVER_MAX_EXPIRY configuration option\nconfiguration:\n AZURE_POLICY_WAIVER_MAX_EXPIRY: 366\n
","tags":["Azure.Policy.WaiverExpiry","AZR-000146"]},{"location":"en/rules/Azure.Policy.WaiverExpiry/#links","title":"Links","text":"Security \u00b7 Azure Database for PostgreSQL \u00b7 Rule \u00b7 2023_06 \u00b7 Critical
Use Entra ID authentication with Azure Database for PostgreSQL databases.
","tags":["Azure.PostgreSQL.AAD","AZR-000389"]},{"location":"en/rules/Azure.PostgreSQL.AAD/#description","title":"Description","text":"Azure Database for PostgreSQL offer two authentication models, Entra ID (previously knows as Azure AD) and PostgreSQL logins. Entra ID authentication supports centralized identity management in addition to modern password protections. Some of the benefits of Entra ID authentication over PostgreSQL authentication including:
It is also possible to disable PostgreSQL authentication entirely for the flexible server deployment model.
","tags":["Azure.PostgreSQL.AAD","AZR-000389"]},{"location":"en/rules/Azure.PostgreSQL.AAD/#recommendation","title":"Recommendation","text":"Consider using Entra ID authentication with Azure Database for PostgreSQL databases. Additionally, consider disabling PostgreSQL authentication.
","tags":["Azure.PostgreSQL.AAD","AZR-000389"]},{"location":"en/rules/Azure.PostgreSQL.AAD/#examples","title":"Examples","text":"","tags":["Azure.PostgreSQL.AAD","AZR-000389"]},{"location":"en/rules/Azure.PostgreSQL.AAD/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for PostgreSQL flexible servers that pass this rule:
Microsoft.DBforPostgreSQL/flexibleServers/administrators
sub-resource.properties.principalName
to the user principal name of the Entra ID administrator user, group, or application.properties.principalType
to the principal type used to represent the type of Entra ID administrator.properties.tenantId
to the tenant ID of the Entra ID administrator user, group, or application.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforPostgreSQL/flexibleServers/administrators\",\n \"apiVersion\": \"2022-12-01\",\n \"name\": \"[format('{0}/{1}', parameters('serverName'), parameters('name'))]\",\n \"properties\": {\n \"principalName\": \"[parameters('principalName')]\",\n \"principalType\": \"[parameters('principalType')]\",\n \"tenantId\": \"[parameters('tenantId')]\"\n },\n \"dependsOn\": [\n \"postgreSqlFlexibleServer\"\n ]\n}\n
To deploy Azure Database for PostgreSQL single servers that pass this rule:
Microsoft.DBforPostgreSQL/servers/administrators
sub-resource.properties.administratorType
to ActiveDirectory
.properties.login
to the Entra ID administrator login object name.properties.sid
to the object ID GUID of the Entra ID administrator user, group, or application.properties.tenantId
to the tenant ID of the Entra ID administrator user, group, or application.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforPostgreSQL/servers/administrators\",\n \"apiVersion\": \"2017-12-01\",\n \"name\": \"[format('{0}/{1}', parameters('serverName'), 'activeDirectory')]\",\n \"properties\": {\n \"administratorType\": \"ActiveDirectory\",\n \"login\": \"[parameters('login')]\",\n \"sid\": \"[parameters('sid')]\",\n \"tenantId\": \"[parameters('tenantId')]\"\n },\n \"dependsOn\": [\n \"postgreSqlSingleServer\"\n ]\n}\n
","tags":["Azure.PostgreSQL.AAD","AZR-000389"]},{"location":"en/rules/Azure.PostgreSQL.AAD/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for PostgreSQL flexible servers that pass this rule:
Microsoft.DBforPostgreSQL/flexibleServers/administrators
sub-resource.properties.principalName
to the user principal name of the Entra ID administrator user, group, or application.properties.principalType
to the principal type used to represent the type of Entra ID administrator.properties.tenantId
to the tenant ID of the Entra ID administrator user, group, or application.For example:
Azure Bicep snippetresource aadAdmin 'Microsoft.DBforPostgreSQL/flexibleServers/administrators@2022-12-01' = {\n name: name\n parent: postgreSqlFlexibleServer\n properties: {\n principalName: principalName\n principalType: principalType\n tenantId: tenantId\n }\n}\n
To deploy Azure Database for PostgreSQL single servers that pass this rule:
Microsoft.DBforPostgreSQL/servers/administrators
sub-resource.properties.administratorType
to ActiveDirectory
.properties.login
to the Entra ID administrator login object name.properties.sid
to the object ID GUID of the Entra ID administrator user, group, or application.properties.tenantId
to the tenant ID of the Entra ID administrator user, group, or application.For example:
Azure Bicep snippetresource aadAdmin 'Microsoft.DBforPostgreSQL/servers/administrators@2017-12-01' = {\n name: 'activeDirectory'\n parent: postgreSqlSingleServer\n properties: {\n administratorType: 'ActiveDirectory'\n login: login\n sid: sid\n tenantId: tenantId\n }\n}\n
","tags":["Azure.PostgreSQL.AAD","AZR-000389"]},{"location":"en/rules/Azure.PostgreSQL.AAD/#notes","title":"Notes","text":"The single server deployment model is limited to:
Security \u00b7 Azure Database for PostgreSQL \u00b7 Rule \u00b7 2023_06 \u00b7 Important
Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases.
","tags":["Azure.PostgreSQL.AADOnly","AZR-000390"]},{"location":"en/rules/Azure.PostgreSQL.AADOnly/#description","title":"Description","text":"Azure Database for PostgreSQL supports authentication with PostgreSQL logins and Azure AD authentication.
By default, authentication with PostgreSQL logins is enabled. PostgreSQL logins are unable to provide sufficient protection for identities. Azure AD authentication provides strong protection controls including conditional access, identity governance, and privileged identity management.
Once you decide to use Azure AD authentication, you can disable authentication with PostgreSQL logins.
Azure AD-only authentication is only supported for the flexible server deployment model.
","tags":["Azure.PostgreSQL.AADOnly","AZR-000390"]},{"location":"en/rules/Azure.PostgreSQL.AADOnly/#recommendation","title":"Recommendation","text":"Consider using Azure AD-only authentication. Also consider using Azure Policy for Azure AD-only authentication with Azure Database for PostgreSQL.
","tags":["Azure.PostgreSQL.AADOnly","AZR-000390"]},{"location":"en/rules/Azure.PostgreSQL.AADOnly/#examples","title":"Examples","text":"","tags":["Azure.PostgreSQL.AADOnly","AZR-000390"]},{"location":"en/rules/Azure.PostgreSQL.AADOnly/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for PostgreSQL flexible servers that pass this rule:
properties.authConfig.activeDirectoryAuth
property to true
.properties.authConfig.passwordAuth
property to false
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforPostgreSQL/flexibleServers\",\n \"apiVersion\": \"2022-12-01\",\n \"name\": \"[parameters('serverName')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"authConfig\": {\n \"activeDirectoryAuth\": \"Enabled\",\n \"passwordAuth\": \"Disabled\",\n \"tenantId\": \"[parameters('tenantId')]\"\n }\n }\n}\n
","tags":["Azure.PostgreSQL.AADOnly","AZR-000390"]},{"location":"en/rules/Azure.PostgreSQL.AADOnly/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for PostgreSQL flexible servers that pass this rule:
properties.authConfig.activeDirectoryAuth
property to true
.properties.authConfig.passwordAuth
property to false
.For example:
Azure Bicep snippetresource postgreSqlFlexibleServer 'Microsoft.DBforPostgreSQL/flexibleServers@2022-12-01' = {\n name: serverName\n location: location\n properties: {\n authConfig: {\n activeDirectoryAuth: 'Enabled'\n passwordAuth: 'Disabled'\n tenantId: tenantId\n }\n }\n}\n
","tags":["Azure.PostgreSQL.AADOnly","AZR-000390"]},{"location":"en/rules/Azure.PostgreSQL.AADOnly/#notes","title":"Notes","text":"The Azure AD admin must be set before enabling Azure AD-only authentication. Azure AD-only authentication is only suppored for the flexible server deployment model.
","tags":["Azure.PostgreSQL.AADOnly","AZR-000390"]},{"location":"en/rules/Azure.PostgreSQL.AADOnly/#links","title":"Links","text":"Security \u00b7 Azure Database for PostgreSQL \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Determine if access from Azure services is required.
","tags":["Azure.PostgreSQL.AllowAzureAccess","AZR-000150"]},{"location":"en/rules/Azure.PostgreSQL.AllowAzureAccess/#description","title":"Description","text":"Allow access to Azure services, permits any Azure service including other Azure customers, network based-access to databases on the same PostgreSQL server instance. If network based access is permitted, authentication is still required.
Enabling access from Azure Services is useful in certain cases for serverless PaaS workloads where configuring a stable IP address is not possible. For example Azure Functions, Container Instances and Logic Apps.
","tags":["Azure.PostgreSQL.AllowAzureAccess","AZR-000150"]},{"location":"en/rules/Azure.PostgreSQL.AllowAzureAccess/#recommendation","title":"Recommendation","text":"Where a stable IP addresses are able to be configured, configure IP or virtual network based firewall rules instead of using Allow access to Azure services.
Determine if access from Azure services is required for the services connecting to the hosted databases.
","tags":["Azure.PostgreSQL.AllowAzureAccess","AZR-000150"]},{"location":"en/rules/Azure.PostgreSQL.AllowAzureAccess/#links","title":"Links","text":"Security \u00b7 Azure Database for PostgreSQL \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL.
","tags":["Azure.PostgreSQL.DefenderCloud","AZR-000327"]},{"location":"en/rules/Azure.PostgreSQL.DefenderCloud/#description","title":"Description","text":"Defender for Cloud detects anomalous activities indicating unusual and potentially harmful attempts to access or exploit databases.
","tags":["Azure.PostgreSQL.DefenderCloud","AZR-000327"]},{"location":"en/rules/Azure.PostgreSQL.DefenderCloud/#recommendation","title":"Recommendation","text":"Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL.
","tags":["Azure.PostgreSQL.DefenderCloud","AZR-000327"]},{"location":"en/rules/Azure.PostgreSQL.DefenderCloud/#examples","title":"Examples","text":"","tags":["Azure.PostgreSQL.DefenderCloud","AZR-000327"]},{"location":"en/rules/Azure.PostgreSQL.DefenderCloud/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for PostgreSQL Single Servers that pass this rule:
Microsoft.DBforPostgreSQL/servers/securityAlertPolicies
sub-resource (child resource).properties.state
property to Enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforPostgreSQL/servers\",\n \"apiVersion\": \"2017-12-01\",\n \"name\": \"[parameters('serverName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('skuName')]\",\n \"tier\": \"GeneralPurpose\",\n \"capacity\": \"[parameters('SkuCapacity')]\",\n \"size\": \"[format('{0}', parameters('skuSizeMB'))]\",\n \"family\": \"[parameters('skuFamily')]\"\n },\n \"properties\": {\n \"createMode\": \"Default\",\n \"version\": \"[parameters('postgresqlVersion')]\",\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"storageProfile\": {\n \"storageMB\": \"[parameters('skuSizeMB')]\",\n \"backupRetentionDays\": 7,\n \"geoRedundantBackup\": \"Enabled\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.DBforPostgreSQL/servers/securityAlertPolicies\",\n \"apiVersion\": \"2017-12-01\",\n \"name\": \"Default\",\n \"dependsOn\": [\"[parameters('serverName')]\"],\n \"properties\": {\n \"emailAccountAdmins\": true,\n \"emailAddresses\": [\"soc@contoso.com\"],\n \"retentionDays\": 14,\n \"state\": \"Enabled\",\n \"storageAccountAccessKey\": \"account-key\",\n \"storageEndpoint\": \"https://contoso.blob.core.windows.net\"\n }\n }\n ]\n}\n
","tags":["Azure.PostgreSQL.DefenderCloud","AZR-000327"]},{"location":"en/rules/Azure.PostgreSQL.DefenderCloud/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for PostgreSQL Single Servers that pass this rule:
Microsoft.DBforPostgreSQL/servers/securityAlertPolicies
sub-resource (child resource).properties.state
property to Enabled
.For example:
Azure Bicep snippetresource postgresqlDbServer 'Microsoft.DBforPostgreSQL/servers@2017-12-01' = {\n name: serverName\n location: location\n sku: {\n name: skuName\n tier: 'GeneralPurpose'\n capacity: skuCapacity\n size: '${skuSizeMB}'\n family: skuFamily\n }\n properties: {\n createMode: 'Default'\n version: postgresqlVersion\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n storageProfile: {\n storageMB: SkuSizeMB\n backupRetentionDays: 7\n geoRedundantBackup: 'Enabled'\n }\n }\n}\n\nresource postgresqlDefender 'Microsoft.DBforPostgreSQL/servers/securityAlertPolicies@2017-12-01' = {\n name: 'Default'\n parent: postgresqlDbServer\n properties: {\n emailAccountAdmins: true\n emailAddresses: ['soc@contoso.com']\n retentionDays: 14\n state: 'Enabled'\n storageAccountAccessKey: 'account-key'\n storageEndpoint: 'https://contoso.blob.core.windows.net'\n }\n}\n
","tags":["Azure.PostgreSQL.DefenderCloud","AZR-000327"]},{"location":"en/rules/Azure.PostgreSQL.DefenderCloud/#notes","title":"Notes","text":"This rule is only applicable for the Azure Database for PostgreSQL Single Server deployment model.
Azure Database for PostgreSQL Flexible Server deployment model does not currently support Microsoft Defender for Cloud.
","tags":["Azure.PostgreSQL.DefenderCloud","AZR-000327"]},{"location":"en/rules/Azure.PostgreSQL.DefenderCloud/#links","title":"Links","text":"Security \u00b7 Azure Database for PostgreSQL \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Determine if there is an excessive number of permitted IP addresses.
","tags":["Azure.PostgreSQL.FirewallIPRange","AZR-000151"]},{"location":"en/rules/Azure.PostgreSQL.FirewallIPRange/#description","title":"Description","text":"Typically the number of IP address rules permitted through the firewall is minimal, with management connectivity from on-premises and cloud application connectivity the most common.
","tags":["Azure.PostgreSQL.FirewallIPRange","AZR-000151"]},{"location":"en/rules/Azure.PostgreSQL.FirewallIPRange/#recommendation","title":"Recommendation","text":"The PostgreSQL server has greater then ten (10) public IP addresses that are permitted network access. Some rules may not be needed or can be reduced.
","tags":["Azure.PostgreSQL.FirewallIPRange","AZR-000151"]},{"location":"en/rules/Azure.PostgreSQL.FirewallIPRange/#links","title":"Links","text":"Security \u00b7 Azure Database for PostgreSQL \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Determine if there is an excessive number of firewall rules.
","tags":["Azure.PostgreSQL.FirewallRuleCount","AZR-000149"]},{"location":"en/rules/Azure.PostgreSQL.FirewallRuleCount/#description","title":"Description","text":"Typically the number of firewall rules required is minimal, with management connectivity from on-premises and cloud application connectivity the most common.
","tags":["Azure.PostgreSQL.FirewallRuleCount","AZR-000149"]},{"location":"en/rules/Azure.PostgreSQL.FirewallRuleCount/#recommendation","title":"Recommendation","text":"The PostgreSQL server has greater then ten (10) firewall rules. Some rules may not be needed.
","tags":["Azure.PostgreSQL.FirewallRuleCount","AZR-000149"]},{"location":"en/rules/Azure.PostgreSQL.FirewallRuleCount/#links","title":"Links","text":"Reliability \u00b7 Azure Database for PostgreSQL \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Azure Database for PostgreSQL should store backups in a geo-redundant storage.
","tags":["Azure.PostgreSQL.GeoRedundantBackup","AZR-000326"]},{"location":"en/rules/Azure.PostgreSQL.GeoRedundantBackup/#description","title":"Description","text":"Geo-redundant backup helps to protect your Azure Database for PostgreSQL Servers against outages impacting backup storage in the primary region and allows you to restore your server to the geo-paired region in the event of a disaster.
When the backups are stored in geo-redundant backup storage, they are not only stored within the region in which your server is hosted, but are also replicated to a paired data center. Both the Azure Database for PostgreSQL Flexible Server and the Azure Database for PostgreSQL Single Server deployment model supports geo-redundant backup.
For the flexible deployment model the geo-redundant backup is supported for all tiers, but for the single deployment model either General Purpose
or Memory Optimized
tier is required.
Check out the NOTES
and the LINKS
section for more details about geo-redundant backup for each of the deployment models.
Configure geo-redundant backup for Azure Database for PostgreSQL.
","tags":["Azure.PostgreSQL.GeoRedundantBackup","AZR-000326"]},{"location":"en/rules/Azure.PostgreSQL.GeoRedundantBackup/#examples","title":"Examples","text":"","tags":["Azure.PostgreSQL.GeoRedundantBackup","AZR-000326"]},{"location":"en/rules/Azure.PostgreSQL.GeoRedundantBackup/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for PostgreSQL Flexible Servers that pass this rule:
properties.backup.geoRedundantBackup
property to the value 'Enabled'
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforPostgreSQL/flexibleServers\",\n \"apiVersion\": \"2022-01-20-preview\",\n \"name\": \"[parameters('serverName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_D16as\",\n \"tier\": \"GeneralPurpose\"\n },\n \"properties\": {\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"storage\": {\n \"storageSizeGB\": \"[parameters('StorageSizeGB')]\"\n },\n \"createMode\": \"Default\",\n \"version\": \"[parameters('postgresqlVersion')]\",\n \"backup\": {\n \"backupRetentionDays\": 7,\n \"geoRedundantBackup\": \"Enabled\"\n },\n \"highAvailability\": {\n \"mode\": \"Disabled\"\n }\n }\n}\n
To deploy Azure Database for PostgreSQL Single Servers that pass this rule:
properties.storageProfile.geoRedundantBackup
property to the value 'Enabled'
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforPostgreSQL/servers\",\n \"apiVersion\": \"2017-12-01\",\n \"name\": \"[parameters('serverName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('skuName')]\",\n \"tier\": \"GeneralPurpose\",\n \"capacity\": \"[parameters('SkuCapacity')]\",\n \"size\": \"[format('{0}', parameters('skuSizeMB'))]\",\n \"family\": \"[parameters('skuFamily')]\"\n },\n \"properties\": {\n \"createMode\": \"Default\",\n \"version\": \"[parameters('postgresqlVersion')]\",\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"storageProfile\": {\n \"storageMB\": \"[parameters('skuSizeMB')]\",\n \"backupRetentionDays\": 7,\n \"geoRedundantBackup\": \"Enabled\"\n }\n }\n}\n
","tags":["Azure.PostgreSQL.GeoRedundantBackup","AZR-000326"]},{"location":"en/rules/Azure.PostgreSQL.GeoRedundantBackup/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for PostgreSQL Flexible Servers that pass this rule:
properties.backup.geoRedundantBackup
property to the value 'Enabled'
.For example:
Azure Bicep snippetresource postgresqlDbServer 'Microsoft.DBforPostgreSQL/flexibleServers@2022-01-20-preview' = {\n name: serverName\n location: location\n sku: {\n name: 'Standard_D16as'\n tier: 'GeneralPurpose'\n }\n properties: {\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n storage: {\n storageSizeGB: StorageSizeGB\n }\n createMode: 'Default'\n version: postgresqlVersion\n backup: {\n backupRetentionDays: 7\n geoRedundantBackup: 'Enabled'\n }\n highAvailability: {\n mode: 'Disabled'\n }\n }\n}\n
To deploy Azure Database for PostgreSQL Single Servers that pass this rule:
properties.storageProfile.geoRedundantBackup
property to the value 'Enabled'
.For example:
Azure Bicep snippetresource postgresqlDbServer 'Microsoft.DBforPostgreSQL/servers@2017-12-01' = {\n name: serverName\n location: location\n sku: {\n name: skuName\n tier: 'GeneralPurpose'\n capacity: skuCapacity\n size: '${skuSizeMB}'\n family: skuFamily\n }\n properties: {\n createMode: 'Default'\n version: postgresqlVersion\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n storageProfile: {\n storageMB: SkuSizeMB\n backupRetentionDays: 7\n geoRedundantBackup: 'Enabled'\n }\n }\n}\n
","tags":["Azure.PostgreSQL.GeoRedundantBackup","AZR-000326"]},{"location":"en/rules/Azure.PostgreSQL.GeoRedundantBackup/#notes","title":"Notes","text":"This rule is applicable for both the Azure Database for PostgreSQL Flexible Server deployment model and the Azure Database for PostgreSQL Single Server deployment model.
For the Single Server deployment model, it runs only against 'General Purpose'
and 'Memory Optimized'
tiers. The 'Basic'
tier does not support geo-redundant backup storage.
Security \u00b7 Azure Database for PostgreSQL \u00b7 Rule \u00b7 2020_09 \u00b7 Critical
PostgreSQL DB servers should reject TLS versions older than 1.2.
","tags":["Azure.PostgreSQL.MinTLS","AZR-000148"]},{"location":"en/rules/Azure.PostgreSQL.MinTLS/#description","title":"Description","text":"The minimum version of TLS that PostgreSQL DB servers accept is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Azure lets you disable outdated protocols and require connections to use a minimum of TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 is accepted.
","tags":["Azure.PostgreSQL.MinTLS","AZR-000148"]},{"location":"en/rules/Azure.PostgreSQL.MinTLS/#recommendation","title":"Recommendation","text":"Consider configuring the minimum supported TLS version to be 1.2.
","tags":["Azure.PostgreSQL.MinTLS","AZR-000148"]},{"location":"en/rules/Azure.PostgreSQL.MinTLS/#links","title":"Links","text":"Operational Excellence \u00b7 Azure Database for PostgreSQL \u00b7 Rule \u00b7 2020_12 \u00b7 Awareness
Azure PostgreSQL DB server names should meet naming requirements.
","tags":["Azure.PostgreSQL.ServerName","AZR-000152"]},{"location":"en/rules/Azure.PostgreSQL.ServerName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for PostgreSQL DB server names are:
Consider using names that meet Azure PostgreSQL DB server naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.PostgreSQL.ServerName","AZR-000152"]},{"location":"en/rules/Azure.PostgreSQL.ServerName/#notes","title":"Notes","text":"This rule does not check if Azure PostgreSQL DB server names are unique.
","tags":["Azure.PostgreSQL.ServerName","AZR-000152"]},{"location":"en/rules/Azure.PostgreSQL.ServerName/#links","title":"Links","text":"Security \u00b7 Azure Database for PostgreSQL \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Enforce encrypted PostgreSQL connections.
","tags":["Azure.PostgreSQL.UseSSL","AZR-000147"]},{"location":"en/rules/Azure.PostgreSQL.UseSSL/#description","title":"Description","text":"Azure Database for PostgreSQL is configured to only accept encrypted connections by default. When the setting enforce SSL connections is disabled, encrypted and unencrypted connections are permitted. This does not indicate that unencrypted connections are being used.
Unencrypted communication to PostgreSQL server instances could allow disclosure of information to an untrusted party.
","tags":["Azure.PostgreSQL.UseSSL","AZR-000147"]},{"location":"en/rules/Azure.PostgreSQL.UseSSL/#recommendation","title":"Recommendation","text":"Azure Database for PostgreSQL should be configured to only accept encrypted connections. Unless explicitly required, consider enabling enforce SSL connections.
Also consider using Azure Policy to audit or enforce this configuration.
","tags":["Azure.PostgreSQL.UseSSL","AZR-000147"]},{"location":"en/rules/Azure.PostgreSQL.UseSSL/#links","title":"Links","text":"Operational Excellence \u00b7 Private Endpoint \u00b7 Rule \u00b7 2021_12 \u00b7 Awareness
Private Endpoint names should meet naming requirements.
","tags":["Azure.PrivateEndpoint.Name","AZR-000153"]},{"location":"en/rules/Azure.PrivateEndpoint.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Private Endpoint names are:
Consider using names that meet Private Endpoint naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.PrivateEndpoint.Name","AZR-000153"]},{"location":"en/rules/Azure.PrivateEndpoint.Name/#notes","title":"Notes","text":"This rule does not check if Private Endpoint names are unique.
","tags":["Azure.PrivateEndpoint.Name","AZR-000153"]},{"location":"en/rules/Azure.PrivateEndpoint.Name/#links","title":"Links","text":"Reliability \u00b7 Public IP address \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability.
","tags":["Azure.PublicIP.AvailabilityZone","AZR-000157"]},{"location":"en/rules/Azure.PublicIP.AvailabilityZone/#description","title":"Description","text":"Public IP addresses using availability zones improve reliability and ensure availability during failure scenarios affecting a data center within a region. A zone redundant Public IP address can spread across multiple availability zones, which ensures the Public IP address will continue running even if another zone has gone down. Furthermore, this ensures Public Standard Load balancer frontend IPs using a zone-redundant Public IP address can survive zone failure.
","tags":["Azure.PublicIP.AvailabilityZone","AZR-000157"]},{"location":"en/rules/Azure.PublicIP.AvailabilityZone/#recommendation","title":"Recommendation","text":"Consider using zone-redundant Public IP addresses deployed with Standard SKU.
","tags":["Azure.PublicIP.AvailabilityZone","AZR-000157"]},{"location":"en/rules/Azure.PublicIP.AvailabilityZone/#examples","title":"Examples","text":"","tags":["Azure.PublicIP.AvailabilityZone","AZR-000157"]},{"location":"en/rules/Azure.PublicIP.AvailabilityZone/#configure-with-azure-template","title":"Configure with Azure template","text":"To configure zone-redundancy for a Public IP address.
sku.name
to Standard
.zones
to [\"1\", \"2\", \"3\"]
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/publicIPAddresses\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard\",\n \"tier\": \"Regional\"\n },\n \"properties\": {\n \"publicIPAddressVersion\": \"IPv4\",\n \"publicIPAllocationMethod\": \"Static\",\n \"idleTimeoutInMinutes\": 4\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n}\n
","tags":["Azure.PublicIP.AvailabilityZone","AZR-000157"]},{"location":"en/rules/Azure.PublicIP.AvailabilityZone/#configure-with-bicep","title":"Configure with Bicep","text":"To configure zone-redundancy for a Public IP address.
sku.name
to Standard
.zones
to ['1', '2', '3']
.For example:
Azure Bicep snippetresource pip 'Microsoft.Network/publicIPAddresses@2023-05-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard'\n tier: 'Regional'\n }\n properties: {\n publicIPAddressVersion: 'IPv4'\n publicIPAllocationMethod: 'Static'\n idleTimeoutInMinutes: 4\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n}\n
","tags":["Azure.PublicIP.AvailabilityZone","AZR-000157"]},{"location":"en/rules/Azure.PublicIP.AvailabilityZone/#notes","title":"Notes","text":"This rule is not applicable for public IP addresses used for Azure Bastion. Azure Bastion does not currently support Availability Zones. Public IP addresses with the following tags are automatically excluded from this rule:
resource-usage
tag set to azure-bastion
.This rule fails when \"zones\"
is constrained to a single(zonal) zone, or set to null
, []
when there are supported availability zones for the given region.
This rule passes if no zones exist for a given region or \"zones\"
is set to [\"1\", \"2\", \"3\"]
.
Configure AZURE_PUBLICIP_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
to set additional availability zones that need to be supported which are not in the existing providers for namespace Microsoft.Network
and resource type publicIpAddresses
.
# YAML: The default AZURE_PUBLICIP_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST configuration option\nconfiguration:\n AZURE_PUBLICIP_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST: []\n
","tags":["Azure.PublicIP.AvailabilityZone","AZR-000157"]},{"location":"en/rules/Azure.PublicIP.AvailabilityZone/#links","title":"Links","text":"Operational Excellence \u00b7 Public IP address \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Public IP domain name labels should meet naming requirements.
","tags":["Azure.PublicIP.DNSLabel","AZR-000156"]},{"location":"en/rules/Azure.PublicIP.DNSLabel/#description","title":"Description","text":"When configuring Azure Public IP addresses domain name labels must meet naming requirements. The requirements for Public IP domain name labels are:
Consider using domain name labels that meet Public IP naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.PublicIP.DNSLabel","AZR-000156"]},{"location":"en/rules/Azure.PublicIP.DNSLabel/#notes","title":"Notes","text":"This rule does not check if Public IP domain name labels are unique.
","tags":["Azure.PublicIP.DNSLabel","AZR-000156"]},{"location":"en/rules/Azure.PublicIP.DNSLabel/#links","title":"Links","text":"Cost Optimization \u00b7 Public IP address \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Public IP addresses should be attached or cleaned up if not in use.
","tags":["Azure.PublicIP.IsAttached","AZR-000154"]},{"location":"en/rules/Azure.PublicIP.IsAttached/#description","title":"Description","text":"Unattached static Public IP address are charged when not in use.
","tags":["Azure.PublicIP.IsAttached","AZR-000154"]},{"location":"en/rules/Azure.PublicIP.IsAttached/#recommendation","title":"Recommendation","text":"Consider removing Public IP addresses that are no used.
","tags":["Azure.PublicIP.IsAttached","AZR-000154"]},{"location":"en/rules/Azure.PublicIP.IsAttached/#notes","title":"Notes","text":"This rule applies when analyzing public IP addresses (in-flight) running within Azure.
","tags":["Azure.PublicIP.IsAttached","AZR-000154"]},{"location":"en/rules/Azure.PublicIP.IsAttached/#links","title":"Links","text":"Operational Excellence \u00b7 Public IP address \u00b7 Rule \u00b7 2023_09 \u00b7 Important
Use the Standard SKU for Public IP addresses as the Basic SKU will be retired.
","tags":["Azure.PublicIP.MigrateStandard","AZR-000395"]},{"location":"en/rules/Azure.PublicIP.MigrateStandard/#description","title":"Description","text":"The Basic SKU for Public IP addresses will be retired on September 30, 2025. To avoid service disruption, migrate to Standard SKU for Public IP addresses.
The Standard SKU additionally offers security by default and supports redundancy.
","tags":["Azure.PublicIP.MigrateStandard","AZR-000395"]},{"location":"en/rules/Azure.PublicIP.MigrateStandard/#recommendation","title":"Recommendation","text":"Migrate Basic SKU for Public IP addresses to the Standard SKU before retirement to avoid service disruption.
","tags":["Azure.PublicIP.MigrateStandard","AZR-000395"]},{"location":"en/rules/Azure.PublicIP.MigrateStandard/#examples","title":"Examples","text":"","tags":["Azure.PublicIP.MigrateStandard","AZR-000395"]},{"location":"en/rules/Azure.PublicIP.MigrateStandard/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Public IP addresses that pass this rule:
sku.name
to Standard
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/publicIPAddresses\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard\",\n \"tier\": \"Regional\"\n },\n \"properties\": {\n \"publicIPAddressVersion\": \"IPv4\",\n \"publicIPAllocationMethod\": \"Static\",\n \"idleTimeoutInMinutes\": 4\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n}\n
","tags":["Azure.PublicIP.MigrateStandard","AZR-000395"]},{"location":"en/rules/Azure.PublicIP.MigrateStandard/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Public IP addresses that pass this rule:
sku.name
to Standard
.For example:
Azure Bicep snippetresource pip 'Microsoft.Network/publicIPAddresses@2023-05-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard'\n tier: 'Regional'\n }\n properties: {\n publicIPAddressVersion: 'IPv4'\n publicIPAllocationMethod: 'Static'\n idleTimeoutInMinutes: 4\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n}\n
","tags":["Azure.PublicIP.MigrateStandard","AZR-000395"]},{"location":"en/rules/Azure.PublicIP.MigrateStandard/#links","title":"Links","text":"Operational Excellence \u00b7 Public IP address \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Public IP names should meet naming requirements.
","tags":["Azure.PublicIP.Name","AZR-000155"]},{"location":"en/rules/Azure.PublicIP.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Public IP names are:
Consider using names that meet Public IP naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.PublicIP.Name","AZR-000155"]},{"location":"en/rules/Azure.PublicIP.Name/#examples","title":"Examples","text":"","tags":["Azure.PublicIP.Name","AZR-000155"]},{"location":"en/rules/Azure.PublicIP.Name/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy public IPs that pass this rule, consider:
minLength
and maxLength
constraint for the resource name parameter.uniqueString()
function to generate a unique name.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"name\": {\n \"type\": \"string\",\n \"minLength\": 1,\n \"maxLength\": 80,\n \"metadata\": {\n \"description\": \"The name of the resource.\"\n }\n },\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"The location resources will be deployed.\"\n }\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Network/publicIPAddresses\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard\",\n \"tier\": \"Regional\"\n },\n \"properties\": {\n \"publicIPAddressVersion\": \"IPv4\",\n \"publicIPAllocationMethod\": \"Static\",\n \"idleTimeoutInMinutes\": 4\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n }\n ]\n}\n
","tags":["Azure.PublicIP.Name","AZR-000155"]},{"location":"en/rules/Azure.PublicIP.Name/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy public IPs that pass this rule, consider:
minLength
and maxLength
constraint for the resource name parameter.uniqueString()
function to generate a unique name.For example:
Azure Bicep snippet@minLength(1)\n@maxLength(80)\n@sys.description('The name of the resource.')\nparam name string\n\n@sys.description('The location resources will be deployed.')\nparam location string = resourceGroup().location\n\nresource pip 'Microsoft.Network/publicIPAddresses@2023-05-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard'\n tier: 'Regional'\n }\n properties: {\n publicIPAddressVersion: 'IPv4'\n publicIPAllocationMethod: 'Static'\n idleTimeoutInMinutes: 4\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n}\n
","tags":["Azure.PublicIP.Name","AZR-000155"]},{"location":"en/rules/Azure.PublicIP.Name/#notes","title":"Notes","text":"This rule does not check if Public IP names are unique.
","tags":["Azure.PublicIP.Name","AZR-000155"]},{"location":"en/rules/Azure.PublicIP.Name/#links","title":"Links","text":"Reliability \u00b7 Public IP address \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Public IP addresses should be deployed with Standard SKU for production workloads.
","tags":["Azure.PublicIP.StandardSKU","AZR-000158"]},{"location":"en/rules/Azure.PublicIP.StandardSKU/#description","title":"Description","text":"Public IP addresses allow Internet resources to communicate inbound to Azure resources. Currently two SKUs are supported: Basic and Standard.
However, the Basic SKU for Public IP addresses will be retired on September 30, 2025.
The Standard SKU additionally offers security and redundancy improvements over the Basic SKU. Including:
Consider using Standard SKU for Public IP addresses deployed in production.
","tags":["Azure.PublicIP.StandardSKU","AZR-000158"]},{"location":"en/rules/Azure.PublicIP.StandardSKU/#examples","title":"Examples","text":"","tags":["Azure.PublicIP.StandardSKU","AZR-000158"]},{"location":"en/rules/Azure.PublicIP.StandardSKU/#configure-with-azure-template","title":"Configure with Azure template","text":"To configure Standard SKU for a Public IP address.
sku.name
to Standard
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/publicIPAddresses\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard\",\n \"tier\": \"Regional\"\n },\n \"properties\": {\n \"publicIPAddressVersion\": \"IPv4\",\n \"publicIPAllocationMethod\": \"Static\",\n \"idleTimeoutInMinutes\": 4\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n}\n
","tags":["Azure.PublicIP.StandardSKU","AZR-000158"]},{"location":"en/rules/Azure.PublicIP.StandardSKU/#configure-with-bicep","title":"Configure with Bicep","text":"To configure Standard SKU for a Public IP address.
sku.name
to Standard
.For example:
For example:
Azure Bicep snippetresource pip 'Microsoft.Network/publicIPAddresses@2023-05-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard'\n tier: 'Regional'\n }\n properties: {\n publicIPAddressVersion: 'IPv4'\n publicIPAllocationMethod: 'Static'\n idleTimeoutInMinutes: 4\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n}\n
","tags":["Azure.PublicIP.StandardSKU","AZR-000158"]},{"location":"en/rules/Azure.PublicIP.StandardSKU/#links","title":"Links","text":"Security \u00b7 Subscription \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Delegate access to manage Azure resources using role-based access control (RBAC).
","tags":["Azure.RBAC.CoAdministrator","AZR-000206"]},{"location":"en/rules/Azure.RBAC.CoAdministrator/#description","title":"Description","text":"Use of Co-administrator is intended to support management of resources deployed using the Classic deployment model. Resources deployed in the Resource Manager model do not require delegation of Co-administrators.
Azure RBAC provides greater flexibility and control providing over 100 built-in roles. Additionally RBAC works with advanced advanced security features like Privileged Identity Management (PIM).
","tags":["Azure.RBAC.CoAdministrator","AZR-000206"]},{"location":"en/rules/Azure.RBAC.CoAdministrator/#recommendation","title":"Recommendation","text":"Consider delegating access to manage Azure resources using RBAC instead of classic Co-administrator roles. Limit delegation of Co-administrator roles only to subscription that contain resources deployed in the Classic deployment model.
","tags":["Azure.RBAC.CoAdministrator","AZR-000206"]},{"location":"en/rules/Azure.RBAC.CoAdministrator/#links","title":"Links","text":"Security \u00b7 Subscription \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Limit Role-Base Access Control (RBAC) inheritance from Management Groups.
","tags":["Azure.RBAC.LimitMGDelegation","AZR-000205"]},{"location":"en/rules/Azure.RBAC.LimitMGDelegation/#description","title":"Description","text":"RBAC in Azure inherits from management group to subscription to resource group to resource. Management group RBAC assignments have broad impact.
","tags":["Azure.RBAC.LimitMGDelegation","AZR-000205"]},{"location":"en/rules/Azure.RBAC.LimitMGDelegation/#recommendation","title":"Recommendation","text":"Consider limiting the number of assignment inherited from Management Groups by scoping permission to individual Resource Group.
Azure Blueprints can be used to rollout standard RBAC assignments to common resources. Additionally RBAC assignments can be deployed using Azure Resource Manager templates.
","tags":["Azure.RBAC.LimitMGDelegation","AZR-000205"]},{"location":"en/rules/Azure.RBAC.LimitOwner/","title":"Limit use of subscription scoped Owner role","text":"Azure.RBAC.LimitOwnerAZR-000204ErrorSecurity \u00b7 Subscription \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Limit the number of subscription Owners.
","tags":["Azure.RBAC.LimitOwner","AZR-000204"]},{"location":"en/rules/Azure.RBAC.LimitOwner/#description","title":"Description","text":"Azure provides a flexible delegation model using Role-Base Access Control (RBAC). RBAC allows administrators to grant fine grained permissions using roles to Azure resources. Over 100 built-in roles exist, and custom roles can be created to perform specific tasks. Permissions can be scoped to management group, subscription, resource group or individual resources.
The Owner role provides the ability to create, delete, update and configure permissions for any resource. When assigned at the subscription scope, these permissions apply to the whole subscription and all resources in the subscription.
","tags":["Azure.RBAC.LimitOwner","AZR-000204"]},{"location":"en/rules/Azure.RBAC.LimitOwner/#recommendation","title":"Recommendation","text":"Consider limiting the number of subscription Owners by using a more specific role or scoping Owner permission to a Resource Group.
","tags":["Azure.RBAC.LimitOwner","AZR-000204"]},{"location":"en/rules/Azure.RBAC.LimitOwner/#links","title":"Links","text":"Security \u00b7 Subscription \u00b7 Rule \u00b7 2020_09 \u00b7 Important
Use just-in-time (JiT) activation of roles instead of persistent role assignment.
","tags":["Azure.RBAC.PIM","AZR-000208"]},{"location":"en/rules/Azure.RBAC.PIM/#description","title":"Description","text":"PIM helps manage the impact of identity compromise or misuse of permissions by reducing persistent access. With PIM, eligible identities can activate time-bound role assignments on an as needed basis (just-in-time). Activation typically occurs before a schedule change or management operation.
PIM is an Azure Active Directory (AD) feature included in Azure AD Premium P2.
","tags":["Azure.RBAC.PIM","AZR-000208"]},{"location":"en/rules/Azure.RBAC.PIM/#recommendation","title":"Recommendation","text":"Consider using Privileged Identity Management (PIM) to activate privileged roles on an as needed basis.
","tags":["Azure.RBAC.PIM","AZR-000208"]},{"location":"en/rules/Azure.RBAC.PIM/#links","title":"Links","text":"Security \u00b7 Subscription \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use groups for assigning permissions instead of individual user accounts.
","tags":["Azure.RBAC.UseGroups","AZR-000203"]},{"location":"en/rules/Azure.RBAC.UseGroups/#description","title":"Description","text":"Granting access with individual user accounts can bypass existing on-premises identity management tools and processes.
","tags":["Azure.RBAC.UseGroups","AZR-000203"]},{"location":"en/rules/Azure.RBAC.UseGroups/#recommendation","title":"Recommendation","text":"Consider using groups for assigning permissions instead of individual user accounts.
","tags":["Azure.RBAC.UseGroups","AZR-000203"]},{"location":"en/rules/Azure.RBAC.UseGroups/#links","title":"Links","text":"Security \u00b7 Subscription \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use RBAC assignments on resource groups instead of individual resources.
","tags":["Azure.RBAC.UseRGDelegation","AZR-000207"]},{"location":"en/rules/Azure.RBAC.UseRGDelegation/#description","title":"Description","text":"Azure provides a flexible delegation model using RBAC that allows administrators to grant fine grained permissions using roles to Azure resources. Permissions can be scoped to management group, subscription, resource group or individual resources.
","tags":["Azure.RBAC.UseRGDelegation","AZR-000207"]},{"location":"en/rules/Azure.RBAC.UseRGDelegation/#recommendation","title":"Recommendation","text":"Consider using RBAC assignments on resource groups instead of individual resources.
","tags":["Azure.RBAC.UseRGDelegation","AZR-000207"]},{"location":"en/rules/Azure.RBAC.UseRGDelegation/#links","title":"Links","text":"Security \u00b7 Recovery Services Vault \u00b7 Rule \u00b7 2023_09 \u00b7 Important
Ensure immutability is configured to protect backup data.
","tags":["Azure.RSV.Immutable","AZR-000397"]},{"location":"en/rules/Azure.RSV.Immutable/#description","title":"Description","text":"Immutability is supported for Recovery Services vaults by configuring the Immutable vault setting.
Immutable vault helps protecting backup data by blocking any operations that could lead to loss of recovery points. Additionally, locking the Immutable vault setting makes it irreversible to prevent any malicious actors from disabling immutability and deleting backups.
For example, an malicious attack may attempt to remove data or delete vaults to prevent recovery to a known good state.
The Immutable vault setting is not enabled per default.
","tags":["Azure.RSV.Immutable","AZR-000397"]},{"location":"en/rules/Azure.RSV.Immutable/#recommendation","title":"Recommendation","text":"Consider configuring immutability to protect backup data from accidental or malicious deletion.
","tags":["Azure.RSV.Immutable","AZR-000397"]},{"location":"en/rules/Azure.RSV.Immutable/#examples","title":"Examples","text":"","tags":["Azure.RSV.Immutable","AZR-000397"]},{"location":"en/rules/Azure.RSV.Immutable/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Recovery Services vaults that pass this rule:
properties.securitySettings.immutabilitySettings.state
to Unlocked
or Locked
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.RecoveryServices/vaults\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('vaultName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('skuName')]\",\n \"tier\": \"[parameters('skuTier')]\"\n },\n \"properties\": {\n \"securitySettings\": {\n \"immutabilitySettings\": {\n \"state\": \"Locked\"\n }\n }\n }\n}\n
","tags":["Azure.RSV.Immutable","AZR-000397"]},{"location":"en/rules/Azure.RSV.Immutable/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Recovery Services vaults that pass this rule:
properties.securitySettings.immutabilitySettings.state
to Unlocked
or Locked
.For example:
Azure Bicep snippetresource recoveryServicesVault 'Microsoft.RecoveryServices/vaults@2023-01-01' = {\n name: vaultName\n location: location\n sku: {\n name: skuName\n tier: skuTier\n }\n properties: {\n securitySettings: {\n immutabilitySettings: {\n state: 'Locked'\n }\n }\n }\n}\n
","tags":["Azure.RSV.Immutable","AZR-000397"]},{"location":"en/rules/Azure.RSV.Immutable/#notes","title":"Notes","text":"Note that immutability locking Locked
is irreversible, so ensure to take a well-informed decision when opting to lock. For example, for vaults containing production workloads consider using Locked
. For cases where you are creating and destroying backups and vaults on a regulary basis such as temporary environments consider Unlocked
.
Operational Excellence \u00b7 Recovery Services Vault \u00b7 Rule \u00b7 2022_12 \u00b7 Awareness
Recovery Services vaults should meet naming requirements.
","tags":["Azure.RSV.Name","AZR-000350"]},{"location":"en/rules/Azure.RSV.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Recovery Services vault names are:
Consider using names that meet Recovery Services vault naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.RSV.Name","AZR-000350"]},{"location":"en/rules/Azure.RSV.Name/#notes","title":"Notes","text":"This rule does not check if Recovery Services vault names are unique.
","tags":["Azure.RSV.Name","AZR-000350"]},{"location":"en/rules/Azure.RSV.Name/#links","title":"Links","text":"Reliability \u00b7 Recovery Services Vault \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Recovery Services Vaults (RSV) without replication alerts configured may be at risk.
","tags":["Azure.RSV.ReplicationAlert","AZR-000171"]},{"location":"en/rules/Azure.RSV.ReplicationAlert/#description","title":"Description","text":"Recovery Services Vaults (RSV) can be used to replicate virtual machines between Azure Regions. Alerts can be configured to send notifications when replication issues occur.
The replication alerts can be configured for:
Configure replication alerts for Recovery Service Vaults that are performing replication tasks.
","tags":["Azure.RSV.ReplicationAlert","AZR-000171"]},{"location":"en/rules/Azure.RSV.ReplicationAlert/#examples","title":"Examples","text":"","tags":["Azure.RSV.ReplicationAlert","AZR-000171"]},{"location":"en/rules/Azure.RSV.ReplicationAlert/#configure-with-azure-template","title":"Configure with Azure template","text":"By default a Recovery Services vaults does not have replication alerts setup. To define a replication alert via ARM templates either configure the sendToOwners
or CustomerEmailAddress
properties:
properties.sendToOwners
to Send
.properties.customEmailAddresses
to [ \"example@email.com\" ]
For example:
Azure Template snippet{\n \"type\": \"Microsoft.RecoveryServices/vaults/replicationAlertSettings\",\n \"apiVersion\": \"2021-08-01\",\n \"name\": \"replicationAlert\",\n \"properties\": {\n \"sendToOwners\": \"Send\",\n \"customEmailAddresses\": [\n \"example@email.com\"\n ],\n \"locale\": \"en-US\"\n }\n}\n
","tags":["Azure.RSV.ReplicationAlert","AZR-000171"]},{"location":"en/rules/Azure.RSV.ReplicationAlert/#configure-with-bicep","title":"Configure with Bicep","text":"By default a Recovery Services vaults does not have replication alerts setup. To define a replication alert via a Bicep either configure the sendToOwners
or CustomerEmailAddress
properties:
properties.sendToOwners
to Send
.properties.customEmailAddresses
to [ \"example@email.com\" ]
For example:
Azure Bicep snippetresource testRecoveryServices 'Microsoft.RecoveryServices/vaults/replicationAlertSettings@2021-08-01' = {\n name: 'replicationAlert'\n parent: resourceSymbolicName\n properties: {\n sendToOwners: 'Sender'\n customEmailAddresses: [\n 'example@email.com'\n ]\n locale: 'en-US'\n }\n}\n
","tags":["Azure.RSV.ReplicationAlert","AZR-000171"]},{"location":"en/rules/Azure.RSV.ReplicationAlert/#notes","title":"Notes","text":"With the locale
property you can define the locale for the email notification.
Reliability \u00b7 Recovery Services Vault \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk.
","tags":["Azure.RSV.StorageType","AZR-000170"]},{"location":"en/rules/Azure.RSV.StorageType/#description","title":"Description","text":"Recovery Services Vaults can be configured with several different durability options. Azure provides a number of geo-replicated options for storage including; Geo-redundant storage and read access geo-zone-redundant storage. The default storage type used will be Geo-redundant Geo-zone-redundant storage is only available in supported regions.
The following geo-replicated options are available for recovery services vaults:
GeoRedundant
ReadAccessGeoZoneRedundant
Consider using GeoRedundant for recovery services vaults that contain data.
","tags":["Azure.RSV.StorageType","AZR-000170"]},{"location":"en/rules/Azure.RSV.StorageType/#examples","title":"Examples","text":"","tags":["Azure.RSV.StorageType","AZR-000170"]},{"location":"en/rules/Azure.RSV.StorageType/#configure-with-azure-template","title":"Configure with Azure template","text":"The default storage type used by Recovery Services vaults is Geo-redundant. However if you're defining the backup config in an ARM template:
properties.storageType
to either GeoRedundant
or ReadAccessGeoZoneRedundant
. For example:{\n \"type\": \"Microsoft.RecoveryServices/vaults/backupconfig\",\n \"apiVersion\": \"2021-10-01\",\n \"name\": \"vaultconfig-a\",\n \"location\": \"australiaeast\",\n \"tags\": {},\n \"properties\": {\n \"storageType\": \"GeoRedundant\"\n }\n}\n
","tags":["Azure.RSV.StorageType","AZR-000170"]},{"location":"en/rules/Azure.RSV.StorageType/#configure-with-bicep","title":"Configure with Bicep","text":"The default storage type used by Recovery Services vaults is Geo-redundant. However if you're defining the backup config via Bicep:
properties.storageType
to either GeoRedundant
or ReadAccessGeoZoneRedundant
.For example:
Azure Bicep snippetresource testRecoveryServices 'Microsoft.RecoveryServices/vaults/backupconfig@2021-10-01' = {\n name: 'vaultconfig'\n location: 'string'\n parent: resourceSymbolicName\n properties: {\n storageType: 'GeoRedundant'\n }\n}\n
","tags":["Azure.RSV.StorageType","AZR-000170"]},{"location":"en/rules/Azure.RSV.StorageType/#links","title":"Links","text":"Reliability \u00b7 Azure Cache for Redis \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Premium Redis cache should be deployed with availability zones for high availability.
","tags":["Azure.Redis.AvailabilityZone","AZR-000161"]},{"location":"en/rules/Azure.Redis.AvailabilityZone/#description","title":"Description","text":"Redis Cache using availability zones improve reliability and ensure availability during failure scenarios affecting a data center within a region. Nodes in one availability zone are physically separated from nodes defined in another availability zone. By spreading node pools across multiple zones, nodes in one node pool will continue running even if another zone has gone down.
","tags":["Azure.Redis.AvailabilityZone","AZR-000161"]},{"location":"en/rules/Azure.Redis.AvailabilityZone/#recommendation","title":"Recommendation","text":"Consider using availability zones for Premium Redis Cache deployed in supported regions.
","tags":["Azure.Redis.AvailabilityZone","AZR-000161"]},{"location":"en/rules/Azure.Redis.AvailabilityZone/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed to Azure using pre-flight and in-flight data.
This rule fails when \"zones\"
is null
, []
or less than two zones are used when there are availability zones for the given region.
This rule fails when cache is not zone redundant(1, 2 and 3) when there are availability zones for the given region.
Configure AZURE_REDISCACHE_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
to set additional availability zones that need to be supported which are not in the existing providers for namespace Microsoft.Cache
and resource type Redis
.
# YAML: The default AZURE_REDISCACHE_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST configuration option\nconfiguration:\n AZURE_REDISCACHE_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST: []\n
","tags":["Azure.Redis.AvailabilityZone","AZR-000161"]},{"location":"en/rules/Azure.Redis.AvailabilityZone/#examples","title":"Examples","text":"","tags":["Azure.Redis.AvailabilityZone","AZR-000161"]},{"location":"en/rules/Azure.Redis.AvailabilityZone/#configure-with-azure-template","title":"Configure with Azure template","text":"To set availability zones for Premium SKU Redis Cache:
zones
to a minimum of two zones from [\"1\", \"2\", \"3\"]
.Properties.replicasPerMaster
to number of zones - 1, to ensure you have at least as many nodes as zones you are replicating to.Properties.sku.name
to Premium
.Properties.sku.family
to P
.Properties.sku.capacity
to one of [1, 2, 3, 4, 5]
, depending on the SKU you picked:P1
- 6 GBP2
- 13 GBP3
- 26 GBP4
- 53 GBP5
- 120 GBFor example:
Azure Template snippet{\n \"type\": \"Microsoft.Cache/redis\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"minimumTlsVersion\": \"1.2\",\n \"redisVersion\": \"latest\",\n \"sku\": {\n \"name\": \"Premium\",\n \"family\": \"P\",\n \"capacity\": 1\n },\n \"redisConfiguration\": {\n \"maxmemory-reserved\": \"615\"\n },\n \"enableNonSslPort\": false\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n}\n
","tags":["Azure.Redis.AvailabilityZone","AZR-000161"]},{"location":"en/rules/Azure.Redis.AvailabilityZone/#configure-with-bicep","title":"Configure with Bicep","text":"To set availability zones for Premium SKU Redis Cache:
zones
to a minimum of two zones from [\"1\", \"2\", \"3\"]
.Properties.replicasPerMaster
to number of zones - 1, to ensure you have at least as many nodes as zones you are replicating to.Properties.sku.name
to Premium
.Properties.sku.family
to P
.Properties.sku.capacity
to one of [1, 2, 3, 4, 5]
, depending on the SKU you picked:P1
- 6 GBP2
- 13 GBP3
- 26 GBP4
- 53 GBP5
- 120 GBFor example:
Azure Bicep snippetresource cache 'Microsoft.Cache/redis@2023-04-01' = {\n name: name\n location: location\n properties: {\n minimumTlsVersion: '1.2'\n redisVersion: 'latest'\n sku: {\n name: 'Premium'\n family: 'P'\n capacity: 1\n }\n redisConfiguration: {\n 'maxmemory-reserved': '615'\n }\n enableNonSslPort: false\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n}\n
","tags":["Azure.Redis.AvailabilityZone","AZR-000161"]},{"location":"en/rules/Azure.Redis.AvailabilityZone/#links","title":"Links","text":"Security \u00b7 Azure Cache for Redis \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Determine if there is an excessive number of permitted IP addresses for the Redis cache.
","tags":["Azure.Redis.FirewallIPRange","AZR-000300"]},{"location":"en/rules/Azure.Redis.FirewallIPRange/#description","title":"Description","text":"When using Azure Cache for Redis, injected into a VNET you are able to create firewall rules to limit access to the cache. Each firewall rules specifies a range of IP addresses that are allowed to access the cache.
If no firewall rules are set and public access is not disabled, then all IP addresses are allowed to access the cache. By default, the cache is configured to allow access from all IP addresses.
Consider using private endpoints to limit access to the cache. If this is not possible, use firewall rules to limit access to the cache. However, avoid using overly permissive firewall rules that are:
The Redis cache has greater than ten (10) public IP addresses that are permitted network access. Some rules may not be needed or can be reduced.
","tags":["Azure.Redis.FirewallIPRange","AZR-000300"]},{"location":"en/rules/Azure.Redis.FirewallIPRange/#examples","title":"Examples","text":"","tags":["Azure.Redis.FirewallIPRange","AZR-000300"]},{"location":"en/rules/Azure.Redis.FirewallIPRange/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy caches that pass this rule:
properties.startIP
property to the start of the IP address range.properties.endIP
property to the end of the IP address range.{\n \"type\": \"Microsoft.Cache/redis/firewallRules\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'allow-on-premises')]\",\n \"properties\": {\n \"startIP\": \"10.0.1.1\",\n \"endIP\": \"10.0.1.31\"\n },\n \"dependsOn\": [\n \"cache\"\n ]\n}\n
","tags":["Azure.Redis.FirewallIPRange","AZR-000300"]},{"location":"en/rules/Azure.Redis.FirewallIPRange/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy caches that pass this rule:
properties.startIP
property to the start of the IP address range.properties.endIP
property to the end of the IP address range.resource rule 'Microsoft.Cache/redis/firewallRules@2023-04-01' = {\n parent: cache\n name: 'allow-on-premises'\n properties: {\n startIP: '10.0.1.1'\n endIP: '10.0.1.31'\n }\n}\n
","tags":["Azure.Redis.FirewallIPRange","AZR-000300"]},{"location":"en/rules/Azure.Redis.FirewallIPRange/#notes","title":"Notes","text":"This rule is not applicable when Redis is configured to allow private connectivity by setting properties.publicNetworkAccess
to Disabled
. Firewall rules can be used with VNET injected caches, but not private endpoints.
Security \u00b7 Azure Cache for Redis \u00b7 Rule \u00b7 2022_09 \u00b7 Awareness
Determine if there is an excessive number of firewall rules for the Redis cache.
","tags":["Azure.Redis.FirewallRuleCount","AZR-000299"]},{"location":"en/rules/Azure.Redis.FirewallRuleCount/#description","title":"Description","text":"When using Azure Cache for Redis, injected into a VNET you are able to create firewall rules to limit access to the cache. Each firewall rules specifies a range of IP addresses that are allowed to access the cache.
If no firewall rules are set and public access is not disabled, then all IP addresses are allowed to access the cache. By default, the cache is configured to allow access from all IP addresses.
Consider using private endpoints to limit access to the cache. If this is not possible, use firewall rules to limit access to the cache. However, avoid using overly permissive firewall rules that are:
The Redis cache has more than ten (10) firewall rules. Some rules may not be needed.
","tags":["Azure.Redis.FirewallRuleCount","AZR-000299"]},{"location":"en/rules/Azure.Redis.FirewallRuleCount/#examples","title":"Examples","text":"","tags":["Azure.Redis.FirewallRuleCount","AZR-000299"]},{"location":"en/rules/Azure.Redis.FirewallRuleCount/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy caches that pass this rule:
properties.startIP
property to the start of the IP address range.properties.endIP
property to the end of the IP address range.{\n \"type\": \"Microsoft.Cache/redis/firewallRules\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'allow-on-premises')]\",\n \"properties\": {\n \"startIP\": \"10.0.1.1\",\n \"endIP\": \"10.0.1.31\"\n },\n \"dependsOn\": [\n \"cache\"\n ]\n}\n
","tags":["Azure.Redis.FirewallRuleCount","AZR-000299"]},{"location":"en/rules/Azure.Redis.FirewallRuleCount/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy caches that pass this rule:
properties.startIP
property to the start of the IP address range.properties.endIP
property to the end of the IP address range.resource rule 'Microsoft.Cache/redis/firewallRules@2023-04-01' = {\n parent: cache\n name: 'allow-on-premises'\n properties: {\n startIP: '10.0.1.1'\n endIP: '10.0.1.31'\n }\n}\n
","tags":["Azure.Redis.FirewallRuleCount","AZR-000299"]},{"location":"en/rules/Azure.Redis.FirewallRuleCount/#notes","title":"Notes","text":"This rule is not applicable when Redis is configured to allow private connectivity by setting properties.publicNetworkAccess
to Disabled
. Firewall rules can be used with VNet injected caches, but not private endpoints.
Performance Efficiency \u00b7 Azure Cache for Redis \u00b7 Rule \u00b7 2020_12 \u00b7 Important
Configure maxmemory-reserved
to reserve memory for non-cache operations.
Azure Cache for Redis supports configuration of the maxmemory-reserved
setting. The maxmemory-reserved
setting configures the amount of memory reserved for non-cache operations. Non-cache operations include background tasks, eviction, and compaction.
By reserving memory for these operations, you prevent Redis cache from using all available memory for cache. If enough memory is not reserved for these operations it can lead to performance degradation and instability.
Setting this value allows you to have a more consistent experience when your load varies. This value should be set higher for workloads that are write heavy.
When memory reserved by maxmemory-reserved
, it is unavailable for storage of cached data.
Consider configuring maxmemory-reserved
to at least 10% of available cache memory.
To deploy caches that pass this rule:
properties.redisConfiguration.maxmemory-reserved
property to at least 10% of the cache memory.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cache/redis\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"minimumTlsVersion\": \"1.2\",\n \"redisVersion\": \"latest\",\n \"sku\": {\n \"name\": \"Premium\",\n \"family\": \"P\",\n \"capacity\": 1\n },\n \"redisConfiguration\": {\n \"maxmemory-reserved\": \"615\"\n },\n \"enableNonSslPort\": false\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n}\n
","tags":["Azure.Redis.MaxMemoryReserved","AZR-000160"]},{"location":"en/rules/Azure.Redis.MaxMemoryReserved/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy caches that pass this rule:
properties.redisConfiguration.maxmemory-reserved
property to at least 10% of the cache memory.For example:
Azure Bicep snippetresource cache 'Microsoft.Cache/redis@2023-04-01' = {\n name: name\n location: location\n properties: {\n minimumTlsVersion: '1.2'\n redisVersion: 'latest'\n sku: {\n name: 'Premium'\n family: 'P'\n capacity: 1\n }\n redisConfiguration: {\n 'maxmemory-reserved': '615'\n }\n enableNonSslPort: false\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n}\n
","tags":["Azure.Redis.MaxMemoryReserved","AZR-000160"]},{"location":"en/rules/Azure.Redis.MaxMemoryReserved/#links","title":"Links","text":"Performance Efficiency \u00b7 Azure Cache for Redis \u00b7 Rule \u00b7 2020_12 \u00b7 Important
Use Azure Cache for Redis instances of at least Standard C1.
","tags":["Azure.Redis.MinSKU","AZR-000159"]},{"location":"en/rules/Azure.Redis.MinSKU/#description","title":"Description","text":"Azure Cache for Redis supports a range of different scale options. Basic tier or Standard C0 caches are not suitable for production workloads.
Consider using a minimum of a Standard C1 instance for production workloads.
","tags":["Azure.Redis.MinSKU","AZR-000159"]},{"location":"en/rules/Azure.Redis.MinSKU/#examples","title":"Examples","text":"","tags":["Azure.Redis.MinSKU","AZR-000159"]},{"location":"en/rules/Azure.Redis.MinSKU/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy caches that pass this rule:
properties.sku.name
property to Premium
or Standard
.properties.sku.family
property to P
or C
.properties.sku.capacity
property to a capacity valid for the SKU 1
or higher.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cache/redis\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"minimumTlsVersion\": \"1.2\",\n \"redisVersion\": \"latest\",\n \"sku\": {\n \"name\": \"Premium\",\n \"family\": \"P\",\n \"capacity\": 1\n },\n \"redisConfiguration\": {\n \"maxmemory-reserved\": \"615\"\n },\n \"enableNonSslPort\": false\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n}\n
","tags":["Azure.Redis.MinSKU","AZR-000159"]},{"location":"en/rules/Azure.Redis.MinSKU/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy caches that pass this rule:
properties.sku.name
property to Premium
or Standard
.properties.sku.family
property to P
or C
.properties.sku.capacity
property to a capacity valid for the SKU 1
or higher.For example:
Azure Bicep snippetresource cache 'Microsoft.Cache/redis@2023-04-01' = {\n name: name\n location: location\n properties: {\n minimumTlsVersion: '1.2'\n redisVersion: 'latest'\n sku: {\n name: 'Premium'\n family: 'P'\n capacity: 1\n }\n redisConfiguration: {\n 'maxmemory-reserved': '615'\n }\n enableNonSslPort: false\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n}\n
","tags":["Azure.Redis.MinSKU","AZR-000159"]},{"location":"en/rules/Azure.Redis.MinSKU/#links","title":"Links","text":"Security \u00b7 Azure Cache for Redis \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Redis Cache should reject TLS versions older than 1.2.
","tags":["Azure.Redis.MinTLS","AZR-000164"]},{"location":"en/rules/Azure.Redis.MinTLS/#description","title":"Description","text":"The minimum version of TLS that Redis Cache accepts is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Azure lets you disable outdated protocols and require connections to use a minimum of TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 is accepted.
","tags":["Azure.Redis.MinTLS","AZR-000164"]},{"location":"en/rules/Azure.Redis.MinTLS/#recommendation","title":"Recommendation","text":"Consider configuring the minimum supported TLS version to be 1.2. Support for TLS 1.0/ 1.1 version will be removed.
","tags":["Azure.Redis.MinTLS","AZR-000164"]},{"location":"en/rules/Azure.Redis.MinTLS/#examples","title":"Examples","text":"","tags":["Azure.Redis.MinTLS","AZR-000164"]},{"location":"en/rules/Azure.Redis.MinTLS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy caches that pass this rule:
properties.minimumTlsVersion
property to a minimum of 1.2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cache/redis\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"minimumTlsVersion\": \"1.2\",\n \"redisVersion\": \"latest\",\n \"sku\": {\n \"name\": \"Premium\",\n \"family\": \"P\",\n \"capacity\": 1\n },\n \"redisConfiguration\": {\n \"maxmemory-reserved\": \"615\"\n },\n \"enableNonSslPort\": false\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n}\n
","tags":["Azure.Redis.MinTLS","AZR-000164"]},{"location":"en/rules/Azure.Redis.MinTLS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy caches that pass this rule:
properties.minimumTlsVersion
property to a minimum of 1.2
.For example:
Azure Bicep snippetresource cache 'Microsoft.Cache/redis@2023-04-01' = {\n name: name\n location: location\n properties: {\n minimumTlsVersion: '1.2'\n redisVersion: 'latest'\n sku: {\n name: 'Premium'\n family: 'P'\n capacity: 1\n }\n redisConfiguration: {\n 'maxmemory-reserved': '615'\n }\n enableNonSslPort: false\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n}\n
","tags":["Azure.Redis.MinTLS","AZR-000164"]},{"location":"en/rules/Azure.Redis.MinTLS/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To deploy caches that pass this rule:
--set
parameter.For example:
Azure CLI snippetaz redis update -n '<name>' -g '<resource_group>' --set minimumTlsVersion=1.2\n
","tags":["Azure.Redis.MinTLS","AZR-000164"]},{"location":"en/rules/Azure.Redis.MinTLS/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To deploy caches that pass this rule:
-MinimumTlsVersion
parameter.For example:
Azure PowerShell snippetSet-AzRedisCache -Name '<name>' -MinimumTlsVersion '1.2'\n
","tags":["Azure.Redis.MinTLS","AZR-000164"]},{"location":"en/rules/Azure.Redis.MinTLS/#links","title":"Links","text":"Security \u00b7 Azure Cache for Redis \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Azure Cache for Redis should only accept secure connections.
","tags":["Azure.Redis.NonSslPort","AZR-000163"]},{"location":"en/rules/Azure.Redis.NonSslPort/#description","title":"Description","text":"Azure Cache for Redis can be configured to accept encrypted and unencrypted connections. By default, only encrypted communication is accepted. To accept unencrypted connections, the non-SSL port must be enabled. Using the non-SSL port for Azure Redis cache allows unencrypted communication to Redis cache.
Unencrypted communication can potentially allow disclosure of sensitive information to an untrusted party.
","tags":["Azure.Redis.NonSslPort","AZR-000163"]},{"location":"en/rules/Azure.Redis.NonSslPort/#recommendation","title":"Recommendation","text":"Consider only using secure connections to Redis cache by enabling SSL and disabling the non-SSL port.
","tags":["Azure.Redis.NonSslPort","AZR-000163"]},{"location":"en/rules/Azure.Redis.NonSslPort/#examples","title":"Examples","text":"","tags":["Azure.Redis.NonSslPort","AZR-000163"]},{"location":"en/rules/Azure.Redis.NonSslPort/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy caches that pass this rule:
properties.enableNonSslPort
property to false
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cache/redis\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"minimumTlsVersion\": \"1.2\",\n \"redisVersion\": \"latest\",\n \"sku\": {\n \"name\": \"Premium\",\n \"family\": \"P\",\n \"capacity\": 1\n },\n \"redisConfiguration\": {\n \"maxmemory-reserved\": \"615\"\n },\n \"enableNonSslPort\": false\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n}\n
","tags":["Azure.Redis.NonSslPort","AZR-000163"]},{"location":"en/rules/Azure.Redis.NonSslPort/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy caches that pass this rule:
properties.enableNonSslPort
property to false
.For example:
Azure Bicep snippetresource cache 'Microsoft.Cache/redis@2023-04-01' = {\n name: name\n location: location\n properties: {\n minimumTlsVersion: '1.2'\n redisVersion: 'latest'\n sku: {\n name: 'Premium'\n family: 'P'\n capacity: 1\n }\n redisConfiguration: {\n 'maxmemory-reserved': '615'\n }\n enableNonSslPort: false\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n}\n
","tags":["Azure.Redis.NonSslPort","AZR-000163"]},{"location":"en/rules/Azure.Redis.NonSslPort/#links","title":"Links","text":"Security \u00b7 Azure Cache for Redis \u00b7 Rule \u00b7 2022_03 \u00b7 Critical
Redis cache should disable public network access.
","tags":["Azure.Redis.PublicNetworkAccess","AZR-000165"]},{"location":"en/rules/Azure.Redis.PublicNetworkAccess/#description","title":"Description","text":"When using Azure Cache for Redis, you can configure the cache to be private or accessible from the public Internet. By default, the cache is configured to be accessible from the public Internet.
To limit network access to the cache you can use firewall rules or private endpoints. Using private endpoints with Azure Cache for Redis is the recommend approach for most scenarios.
Use private endpoints to improve the security posture of your Redis cache and reduce the risk of data breaches.
A private endpoint provides secure and private connectivity to Redis instances by:
If you are using VNET injection, it is recommended to migrate to private endpoints.
","tags":["Azure.Redis.PublicNetworkAccess","AZR-000165"]},{"location":"en/rules/Azure.Redis.PublicNetworkAccess/#recommendation","title":"Recommendation","text":"Consider using private endpoints to limit network connectivity to the cache and help reduce data exfiltration risks.
","tags":["Azure.Redis.PublicNetworkAccess","AZR-000165"]},{"location":"en/rules/Azure.Redis.PublicNetworkAccess/#examples","title":"Examples","text":"","tags":["Azure.Redis.PublicNetworkAccess","AZR-000165"]},{"location":"en/rules/Azure.Redis.PublicNetworkAccess/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy caches that pass this rule:
properties.publicNetworkAccess
property to Disabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cache/redis\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"minimumTlsVersion\": \"1.2\",\n \"redisVersion\": \"latest\",\n \"sku\": {\n \"name\": \"Premium\",\n \"family\": \"P\",\n \"capacity\": 1\n },\n \"redisConfiguration\": {\n \"maxmemory-reserved\": \"615\"\n },\n \"enableNonSslPort\": false,\n \"publicNetworkAccess\": \"Disabled\"\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n}\n
","tags":["Azure.Redis.PublicNetworkAccess","AZR-000165"]},{"location":"en/rules/Azure.Redis.PublicNetworkAccess/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy caches that pass this rule:
properties.publicNetworkAccess
property to Disabled
.For example:
Azure Bicep snippetresource cache 'Microsoft.Cache/redis@2023-04-01' = {\n name: name\n location: location\n properties: {\n minimumTlsVersion: '1.2'\n redisVersion: 'latest'\n sku: {\n name: 'Premium'\n family: 'P'\n capacity: 1\n }\n redisConfiguration: {\n 'maxmemory-reserved': '615'\n }\n enableNonSslPort: false\n publicNetworkAccess: 'Disabled'\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n}\n
","tags":["Azure.Redis.PublicNetworkAccess","AZR-000165"]},{"location":"en/rules/Azure.Redis.PublicNetworkAccess/#links","title":"Links","text":"Reliability \u00b7 Azure Cache for Redis \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Azure Cache for Redis should use the latest supported version of Redis.
","tags":["Azure.Redis.Version","AZR-000347"]},{"location":"en/rules/Azure.Redis.Version/#description","title":"Description","text":"Azure Cache for Redis supports Redis 6. Redis 6 brings new security features and better performance.
Version 4 for Azure Cache for Redis instances will be retired on June 30, 3023.
","tags":["Azure.Redis.Version","AZR-000347"]},{"location":"en/rules/Azure.Redis.Version/#recommendation","title":"Recommendation","text":"Consider upgrading Redis version for Azure Cache for Redis to the latest supported version (>=6.0).
","tags":["Azure.Redis.Version","AZR-000347"]},{"location":"en/rules/Azure.Redis.Version/#examples","title":"Examples","text":"","tags":["Azure.Redis.Version","AZR-000347"]},{"location":"en/rules/Azure.Redis.Version/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy caches that pass this rule:
properties.redisVersion
property to latest
or 6
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cache/redis\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"minimumTlsVersion\": \"1.2\",\n \"redisVersion\": \"latest\",\n \"sku\": {\n \"name\": \"Premium\",\n \"family\": \"P\",\n \"capacity\": 1\n },\n \"redisConfiguration\": {\n \"maxmemory-reserved\": \"615\"\n },\n \"enableNonSslPort\": false\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n}\n
","tags":["Azure.Redis.Version","AZR-000347"]},{"location":"en/rules/Azure.Redis.Version/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy caches that pass this rule:
properties.redisVersion
property to latest
or 6
.For example:
Azure Bicep snippetresource cache 'Microsoft.Cache/redis@2023-04-01' = {\n name: name\n location: location\n properties: {\n minimumTlsVersion: '1.2'\n redisVersion: 'latest'\n sku: {\n name: 'Premium'\n family: 'P'\n capacity: 1\n }\n redisConfiguration: {\n 'maxmemory-reserved': '615'\n }\n enableNonSslPort: false\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n}\n
","tags":["Azure.Redis.Version","AZR-000347"]},{"location":"en/rules/Azure.Redis.Version/#notes","title":"Notes","text":"This rule is only applicable for Azure Cache for Redis (OSS Redis) offering.
","tags":["Azure.Redis.Version","AZR-000347"]},{"location":"en/rules/Azure.Redis.Version/#links","title":"Links","text":"Security \u00b7 Azure Cache for Redis Enterprise \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Redis Cache should reject TLS versions older than 1.2.
","tags":["Azure.RedisEnterprise.MinTLS","AZR-000301"]},{"location":"en/rules/Azure.RedisEnterprise.MinTLS/#description","title":"Description","text":"The minimum version of TLS that Redis Cache accepts is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Azure lets you disable outdated protocols and require connections to use a minimum of TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 is accepted.
","tags":["Azure.RedisEnterprise.MinTLS","AZR-000301"]},{"location":"en/rules/Azure.RedisEnterprise.MinTLS/#recommendation","title":"Recommendation","text":"Consider configuring the minimum supported TLS version to be 1.2. Support for TLS 1.0/ 1.1 version will be removed.
","tags":["Azure.RedisEnterprise.MinTLS","AZR-000301"]},{"location":"en/rules/Azure.RedisEnterprise.MinTLS/#examples","title":"Examples","text":"","tags":["Azure.RedisEnterprise.MinTLS","AZR-000301"]},{"location":"en/rules/Azure.RedisEnterprise.MinTLS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy caches that pass this rule:
properties.minimumTlsVersion
property to 1.2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cache/redisEnterprise\",\n \"apiVersion\": \"2022-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Enterprise_E10\"\n },\n \"properties\": {\n \"minimumTlsVersion\": \"1.2\"\n }\n}\n
","tags":["Azure.RedisEnterprise.MinTLS","AZR-000301"]},{"location":"en/rules/Azure.RedisEnterprise.MinTLS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy caches that pass this rule:
properties.minimumTlsVersion
property to 1.2
.For example:
Azure Bicep snippetresource cache 'Microsoft.Cache/redisEnterprise@2022-01-01' = {\n name: name\n location: location\n sku: {\n name: 'Enterprise_E10'\n }\n properties: {\n minimumTlsVersion: '1.2'\n }\n}\n
","tags":["Azure.RedisEnterprise.MinTLS","AZR-000301"]},{"location":"en/rules/Azure.RedisEnterprise.MinTLS/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To deploy caches that pass this rule:
--set
parameter.For example:
Azure CLI snippetaz redis update -n '<name>' -g '<resource_group>' --set minimumTlsVersion=1.2\n
","tags":["Azure.RedisEnterprise.MinTLS","AZR-000301"]},{"location":"en/rules/Azure.RedisEnterprise.MinTLS/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To deploy caches that pass this rule:
-MinimumTlsVersion
parameter.For example:
Azure PowerShell snippetSet-AzRedisCache -Name '<name>' -MinimumTlsVersion '1.2'\n
","tags":["Azure.RedisEnterprise.MinTLS","AZR-000301"]},{"location":"en/rules/Azure.RedisEnterprise.MinTLS/#links","title":"Links","text":"Reliability \u00b7 Azure Cache for Redis Enterprise \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Enterprise Redis cache should be zone-redundant for high availability.
","tags":["Azure.RedisEnterprise.Zones","AZR-000162"]},{"location":"en/rules/Azure.RedisEnterprise.Zones/#description","title":"Description","text":"Redis Cache using availability zones improve reliability and ensure availability during failure scenarios affecting a data center within a region. Nodes in one availability zone are physically separated from nodes defined in another availability zone. By spreading node pools across multiple zones, nodes in one node pool will continue running even if another zone has gone down.
","tags":["Azure.RedisEnterprise.Zones","AZR-000162"]},{"location":"en/rules/Azure.RedisEnterprise.Zones/#recommendation","title":"Recommendation","text":"Consider using availability zones for Enterprise Redis Cache deployed in supported regions.
","tags":["Azure.RedisEnterprise.Zones","AZR-000162"]},{"location":"en/rules/Azure.RedisEnterprise.Zones/#notes","title":"Notes","text":"This rule fails when cache is not zone redundant(1, 2 and 3) when there are availability zones for the given region.
Configure AZURE_REDISENTERPRISECACHE_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
to set additional availability zones that need to be supported which are not in the existing providers for namespace Microsoft.Cache
and resource type redisEnterprise
.
# YAML: The default AZURE_REDISENTERPRISECACHE_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST configuration option\nconfiguration:\n AZURE_REDISENTERPRISECACHE_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST: []\n
","tags":["Azure.RedisEnterprise.Zones","AZR-000162"]},{"location":"en/rules/Azure.RedisEnterprise.Zones/#examples","title":"Examples","text":"","tags":["Azure.RedisEnterprise.Zones","AZR-000162"]},{"location":"en/rules/Azure.RedisEnterprise.Zones/#configure-with-azure-template","title":"Configure with Azure template","text":"To set availability zones for Enterprise SKU Redis Cache:
zones
to [\"1\", \"2\", \"3\"]
or zone-redundancy.Properties.sku.name
to one of:Enterprise_E10
- 12 GBEnterprise_E20
- 25 GBEnterprise_E50
- 50 GBEnterprise_E100
- 100 GBEnterpriseFlash_F300
- 345 GBEnterpriseFlash_F700
- 715 GBEnterpriseFlash_F1500
- 1455 GBProperties.sku.capacity
to:[2, 4, 6, 8, 10]
if using Enterprise_E10
, Enterprise_E20
, Enterprise_E50
or Enterprise_E100
.3
or 9
if using EnterpriseFlash_F300
, EnterpriseFlash_F700
, EnterpriseFlash_F1500
.For example:
Azure Template snippet{\n \"name\": \"testrediscache\",\n \"type\": \"Microsoft.Cache/redisEnterprise\",\n \"apiVersion\": \"2021-02-01-preview\",\n \"properties\": {},\n \"location\": \"australiaeast\",\n \"dependsOn\": [],\n \"sku\": {\n \"name\": \"EnterpriseFlash_F700\",\n \"capacity\": 3\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ],\n \"tags\": {},\n \"resources\": [\n {\n \"name\": \"testrediscache/default\",\n \"type\": \"Microsoft.Cache/redisEnterprise/databases\",\n \"apiVersion\": \"2021-02-01-preview\",\n \"properties\": {\n \"clientProtocol\": \"Encrypted\",\n \"evictionPolicy\": \"NoEviction\",\n \"clusteringPolicy\": \"OSSCluster\",\n \"persistence\": {\n \"aofEnabled\": false,\n \"rdbEnabled\": false\n }\n },\n \"dependsOn\": [\n \"Microsoft.Cache/redisEnterprise/testrediscache\"\n ],\n \"tags\": {}\n }\n ]\n}\n
","tags":["Azure.RedisEnterprise.Zones","AZR-000162"]},{"location":"en/rules/Azure.RedisEnterprise.Zones/#configure-with-bicep","title":"Configure with Bicep","text":"To set availability zones for Enterprise SKU Redis Cache:
zones
to [\"1\", \"2\", \"3\"]
or zone-redundancy.Properties.sku.name
to one of:Enterprise_E10
- 12 GBEnterprise_E20
- 25 GBEnterprise_E50
- 50 GBEnterprise_E100
- 100 GBEnterpriseFlash_F300
- 345 GBEnterpriseFlash_F700
- 715 GBEnterpriseFlash_F1500
- 1455 GBProperties.sku.capacity
to:[2, 4, 6, 8, 10]
if using Enterprise_E10
, Enterprise_E20
, Enterprise_E50
or Enterprise_E100
.3
or 9
if using EnterpriseFlash_F300
, EnterpriseFlash_F700
, EnterpriseFlash_F1500
.For example:
Azure Bicep snippetresource testrediscache 'Microsoft.Cache/redisEnterprise@2021-02-01-preview' = {\n name: 'testrediscache'\n properties: {}\n location: 'australiaeast'\n sku: {\n name: 'EnterpriseFlash_F700'\n capacity: 3\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n tags: {}\n dependsOn: []\n}\n\nresource testrediscache_default 'Microsoft.Cache/redisEnterprise/databases@2021-02-01-preview' = {\n parent: testrediscache\n name: 'default'\n properties: {\n clientProtocol: 'Encrypted'\n evictionPolicy: 'NoEviction'\n clusteringPolicy: 'OSSCluster'\n persistence: {\n aofEnabled: false\n rdbEnabled: false\n }\n }\n tags: {}\n}\n
","tags":["Azure.RedisEnterprise.Zones","AZR-000162"]},{"location":"en/rules/Azure.RedisEnterprise.Zones/#links","title":"Links","text":"Security \u00b7 All resources \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Resources should be deployed to allowed regions.
","tags":["Azure.Resource.AllowedRegions","AZR-000167"]},{"location":"en/rules/Azure.Resource.AllowedRegions/#description","title":"Description","text":"Azure supports deployment to many locations around the world called regions. Many organizations have requirements that limit where data can be stored or processed. This is commonly known as data residency.
Most Azure resources must be deployed to a specific region. To align with your organizational requirements, you may choose to limit the regions that resources can be deployed to.
Some resources, particularly those related to preview services or features, may not be available in all regions.
","tags":["Azure.Resource.AllowedRegions","AZR-000167"]},{"location":"en/rules/Azure.Resource.AllowedRegions/#recommendation","title":"Recommendation","text":"Consider deploying resources to allowed regions to align with your organizational requirements. Also consider using Azure Policy to enforce allowed regions at runtime.
","tags":["Azure.Resource.AllowedRegions","AZR-000167"]},{"location":"en/rules/Azure.Resource.AllowedRegions/#examples","title":"Examples","text":"","tags":["Azure.Resource.AllowedRegions","AZR-000167"]},{"location":"en/rules/Azure.Resource.AllowedRegions/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy resources that pass this rule:
location
property to an allowed region. ORFor example:
Azure Template snippet{\n \"type\": \"Microsoft.Storage/storageAccounts\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_GRS\"\n },\n \"kind\": \"StorageV2\",\n \"properties\": {\n \"allowBlobPublicAccess\": false,\n \"supportsHttpsTrafficOnly\": true,\n \"minimumTlsVersion\": \"TLS1_2\",\n \"accessTier\": \"Hot\",\n \"allowSharedKeyAccess\": false,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n }\n }\n}\n
","tags":["Azure.Resource.AllowedRegions","AZR-000167"]},{"location":"en/rules/Azure.Resource.AllowedRegions/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy resources that pass this rule:
location
property to an allowed region. ORFor example:
Azure Bicep snippet@sys.description('The location resources will be deployed.')\nparam location string = resourceGroup().location\n\nresource storageAccount 'Microsoft.Storage/storageAccounts@2023-01-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard_GRS'\n }\n kind: 'StorageV2'\n properties: {\n allowBlobPublicAccess: false\n supportsHttpsTrafficOnly: true\n minimumTlsVersion: 'TLS1_2'\n accessTier: 'Hot'\n allowSharedKeyAccess: false\n networkAcls: {\n defaultAction: 'Deny'\n }\n }\n}\n
","tags":["Azure.Resource.AllowedRegions","AZR-000167"]},{"location":"en/rules/Azure.Resource.AllowedRegions/#notes","title":"Notes","text":"This rule requires one or more allowed regions to be configured. By default, all regions are allowed.
","tags":["Azure.Resource.AllowedRegions","AZR-000167"]},{"location":"en/rules/Azure.Resource.AllowedRegions/#rule-configuration","title":"Rule configuration","text":"AZURE_RESOURCE_ALLOWED_LOCATIONS
To configure this rule set the AZURE_RESOURCE_ALLOWED_LOCATIONS
configuration value to a set of allowed regions.
For example:
configuration:\n AZURE_RESOURCE_ALLOWED_LOCATIONS:\n - australiaeast\n - australiasoutheast\n
If you configure this AZURE_RESOURCE_ALLOWED_LOCATIONS
configuration value, also consider setting AZURE_RESOURCE_GROUP
the configuration value to when resources use the location of the resource group.
For example:
configuration:\n AZURE_RESOURCE_GROUP:\n location: australiaeast\n
","tags":["Azure.Resource.AllowedRegions","AZR-000167"]},{"location":"en/rules/Azure.Resource.AllowedRegions/#links","title":"Links","text":"Cost Optimization \u00b7 All resources \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Azure resources should be tagged using a standard convention.
","tags":["Azure.Resource.UseTags","AZR-000166"]},{"location":"en/rules/Azure.Resource.UseTags/#description","title":"Description","text":"Azure Resource Manager (ARM) supports a flexible tagging model that allows each resource to be tagged. Tags are additional metadata that improves identification of resources and aids lifecycle management.
Azure stores tags as name/ value pairs such as environment = production
or costCode = 349921
.
A well defined tagging approach improves the management, billing, and automation operations of resources. When planning tags, identify information that is meaningful to business and technical staff.
Azure provides several built-in policies to managed tags. Using these policies help enforce a tagging standard can reduce overall management Resource tags can be inherited from subscriptions or resource groups using Azure Policy.
","tags":["Azure.Resource.UseTags","AZR-000166"]},{"location":"en/rules/Azure.Resource.UseTags/#recommendation","title":"Recommendation","text":"Consider tagging resources using a standard convention. Identify mandatory and optional tags then tag all resources and resource groups using this standard.
Also consider using Azure Policy to enforce mandatory tags.
","tags":["Azure.Resource.UseTags","AZR-000166"]},{"location":"en/rules/Azure.Resource.UseTags/#examples","title":"Examples","text":"","tags":["Azure.Resource.UseTags","AZR-000166"]},{"location":"en/rules/Azure.Resource.UseTags/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy resource that pass this rule:
tags
property tags that align to your tagging standard.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Resources/resourceGroups\",\n \"apiVersion\": \"2022-09-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"tags\": {\n \"environment\": \"production\",\n \"costCode\": \"349921\"\n }\n}\n
","tags":["Azure.Resource.UseTags","AZR-000166"]},{"location":"en/rules/Azure.Resource.UseTags/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy resource that pass this rule:
tags
property tags that align to your tagging standard.For example:
Azure Bicep snippetresource rg 'Microsoft.Resources/resourceGroups@2022-09-01' = {\n name: name\n location: location\n tags: {\n environment: 'production'\n costCode: '349921'\n }\n}\n
","tags":["Azure.Resource.UseTags","AZR-000166"]},{"location":"en/rules/Azure.Resource.UseTags/#notes","title":"Notes","text":"Azure Policy includes several built-in policies to enforce tagging such as:
If you find resources that incorrectly report they should be tagged, please let us know by opening an issue.
","tags":["Azure.Resource.UseTags","AZR-000166"]},{"location":"en/rules/Azure.Resource.UseTags/#links","title":"Links","text":"Operational Excellence \u00b7 Resource Group \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Resource Group names should meet naming requirements.
","tags":["Azure.ResourceGroup.Name","AZR-000168"]},{"location":"en/rules/Azure.ResourceGroup.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Resource Group names are:
Consider using names that meet Resource Group naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.ResourceGroup.Name","AZR-000168"]},{"location":"en/rules/Azure.ResourceGroup.Name/#notes","title":"Notes","text":"This rule does not check if Resource Group names are unique.
","tags":["Azure.ResourceGroup.Name","AZR-000168"]},{"location":"en/rules/Azure.ResourceGroup.Name/#links","title":"Links","text":"Operational Excellence \u00b7 Route table \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Route table names should meet naming requirements.
","tags":["Azure.Route.Name","AZR-000169"]},{"location":"en/rules/Azure.Route.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Route table names are:
Consider using names that meet Route table naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.Route.Name","AZR-000169"]},{"location":"en/rules/Azure.Route.Name/#notes","title":"Notes","text":"This rule does not check if Route table names are unique.
","tags":["Azure.Route.Name","AZR-000169"]},{"location":"en/rules/Azure.Route.Name/#links","title":"Links","text":"Security \u00b7 SQL Database \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Use Entra ID authentication with Azure SQL databases.
","tags":["Azure.SQL.AAD","AZR-000188"]},{"location":"en/rules/Azure.SQL.AAD/#description","title":"Description","text":"Azure SQL Database offer two authentication models, Entra ID (previously known as Azure AD) and SQL authentication. Entra ID authentication supports centralized identity management in addition to modern password protections. Some of the benefits of Entra ID authentication over SQL authentication including:
It is also possible to disable SQL authentication entirely and only use Entra ID authentication.
","tags":["Azure.SQL.AAD","AZR-000188"]},{"location":"en/rules/Azure.SQL.AAD/#recommendation","title":"Recommendation","text":"Consider using Entra ID authentication with SQL databases. Additionally, consider disabling SQL authentication.
","tags":["Azure.SQL.AAD","AZR-000188"]},{"location":"en/rules/Azure.SQL.AAD/#examples","title":"Examples","text":"","tags":["Azure.SQL.AAD","AZR-000188"]},{"location":"en/rules/Azure.SQL.AAD/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy logical SQL Servers that pass this rule:
properties.administrators.administratorType
to ActiveDirectory
.properties.administrators.login
to the administrator login object name.properties.administrators.sid
to the object ID GUID of the administrator user, group, or application.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Sql/servers\",\n \"apiVersion\": \"2022-11-01-preview\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"publicNetworkAccess\": \"Disabled\",\n \"minimalTlsVersion\": \"1.2\",\n \"administrators\": {\n \"azureADOnlyAuthentication\": true,\n \"administratorType\": \"ActiveDirectory\",\n \"login\": \"[parameters('adminLogin')]\",\n \"principalType\": \"Group\",\n \"sid\": \"[parameters('adminPrincipalId')]\",\n \"tenantId\": \"[tenant().tenantId]\"\n }\n }\n}\n
Alternatively, you can configure the Microsoft.Sql/servers/administrators
sub-resource. To deploy Microsoft.Sql/servers/administrators
sub-resources that pass this rule:
properties.administratorType
to ActiveDirectory
.properties.login
to the administrator login object name.properties.sid
to the object ID GUID of the administrator user, group, or application.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Sql/servers/administrators\",\n \"apiVersion\": \"2022-02-01-preview\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'ActiveDirectory')]\",\n \"properties\": {\n \"administratorType\": \"ActiveDirectory\",\n \"login\": \"[parameters('adminLogin')]\",\n \"sid\": \"[parameters('adminPrincipalId')]\"\n },\n \"dependsOn\": [\n \"server\"\n ]\n}\n
","tags":["Azure.SQL.AAD","AZR-000188"]},{"location":"en/rules/Azure.SQL.AAD/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy logical SQL Servers that pass this rule:
properties.administrators.administratorType
to ActiveDirectory
.properties.administrators.login
to the administrator login object name.properties.administrators.sid
to the object ID GUID of the administrator user, group, or application.For example:
Azure Bicep snippetresource server 'Microsoft.Sql/servers@2022-11-01-preview' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n publicNetworkAccess: 'Disabled'\n minimalTlsVersion: '1.2'\n administrators: {\n azureADOnlyAuthentication: true\n administratorType: 'ActiveDirectory'\n login: adminLogin\n principalType: 'Group'\n sid: adminPrincipalId\n tenantId: tenant().tenantId\n }\n }\n}\n
Alternatively, you can configure the Microsoft.Sql/servers/administrators
sub-resource. To deploy Microsoft.Sql/servers/administrators
sub-resources that pass this rule:
properties.administratorType
to ActiveDirectory
.properties.login
to the administrator login object name.properties.sid
to the object ID GUID of the administrator user, group, or application.For example:
Azure Bicep snippetresource sqlAdministrator 'Microsoft.Sql/servers/administrators@2022-02-01-preview' = {\n parent: server\n name: 'ActiveDirectory'\n properties: {\n administratorType: 'ActiveDirectory'\n login: adminLogin\n sid: adminPrincipalId\n }\n}\n
","tags":["Azure.SQL.AAD","AZR-000188"]},{"location":"en/rules/Azure.SQL.AAD/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz sql server ad-admin create -s '<server_name>' -g '<resource_group>' -u '<user_name>' -i '<object_id>'\n
","tags":["Azure.SQL.AAD","AZR-000188"]},{"location":"en/rules/Azure.SQL.AAD/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetSet-AzSqlServerActiveDirectoryAdministrator -ResourceGroupName '<resource_group>' -ServerName '<server_name>' -DisplayName '<user_name>'\n
","tags":["Azure.SQL.AAD","AZR-000188"]},{"location":"en/rules/Azure.SQL.AAD/#notes","title":"Notes","text":"In newer API versions the properties.administrators
property can be configured. Entra ID authentication can also be configured using the Microsoft.Sql/servers/administrators
sub-resource.
If both the properties.administrators
property and Microsoft.Sql/servers/administrators
are set, the sub-resource will override the property.
Security \u00b7 SQL Database \u00b7 Rule \u00b7 2023_03 \u00b7 Important
Ensure Azure AD-only authentication is enabled with Azure SQL Database.
","tags":["Azure.SQL.AADOnly","AZR-000369"]},{"location":"en/rules/Azure.SQL.AADOnly/#description","title":"Description","text":"Azure SQL Database supports authentication with SQL logins and Azure AD authentication. By default, authentication with SQL logins is enabled. SQL logins are unable to provide sufficient protection for identities.
Azure AD authentication provides:
Additionally you can disable SQL authentication entirely, by enabling Azure AD-only authentication.
Some features may have limitations when using Azure AD-only authentication is enabled, including:
Continue reading Limitations for Azure AD-only authentication in SQL Database.
","tags":["Azure.SQL.AADOnly","AZR-000369"]},{"location":"en/rules/Azure.SQL.AADOnly/#recommendation","title":"Recommendation","text":"Consider using Azure AD-only authentication. Also consider using Azure Policy for Azure AD-only authentication with SQL Database.
","tags":["Azure.SQL.AADOnly","AZR-000369"]},{"location":"en/rules/Azure.SQL.AADOnly/#examples","title":"Examples","text":"Azure AD-only authentication can be enabled in two different ways.
","tags":["Azure.SQL.AADOnly","AZR-000369"]},{"location":"en/rules/Azure.SQL.AADOnly/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy SQL Logical Servers that pass this rule:
properties.administrators.azureADOnlyAuthentication
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Sql/servers\",\n \"apiVersion\": \"2022-05-01-preview\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\",\n \"userAssignedIdentities\": {}\n },\n \"properties\": {\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"administrators\": {\n \"administratorType\": \"ActiveDirectory\",\n \"azureADOnlyAuthentication\": true,\n \"login\": \"[parameters('login')]\",\n \"principalType\": \"[parameters('principalType')]\",\n \"sid\": \"[parameters('sid')]\",\n \"tenantId\": \"[parameters('tenantId')]\"\n }\n }\n}\n
Alternatively, you can configure the Microsoft.Sql/servers/azureADOnlyAuthentications
sub-resource. To deploy Microsoft.Sql/servers/azureADOnlyAuthentications
sub-resources that pass this rule:
properties.azureADOnlyAuthentication
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Sql/servers/azureADOnlyAuthentications\",\n \"apiVersion\": \"2022-05-01-preview\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'Default')]\",\n \"properties\": {\n \"azureADOnlyAuthentication\": true\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Sql/servers', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.SQL.AADOnly","AZR-000369"]},{"location":"en/rules/Azure.SQL.AADOnly/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy SQL Logical Servers that pass this rule:
properties.administrators.azureADOnlyAuthentication
property to true
.For example:
Azure Bicep snippetresource logicalServer 'Microsoft.Sql/servers@2022-05-01-preview' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n userAssignedIdentities: {}\n }\n properties: {\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n administrators: {\n administratorType: 'ActiveDirectory'\n azureADOnlyAuthentication: true\n login: login\n principalType: principalType\n sid: sid\n tenantId: tenantId\n }\n }\n}\n
Alternatively, you can configure the Microsoft.Sql/servers/azureADOnlyAuthentications
sub-resource. To deploy Microsoft.Sql/servers/azureADOnlyAuthentications
sub-resources that pass this rule:
properties.azureADOnlyAuthentication
property to true
.For example:
Azure Bicep snippetresource aadOnly 'Microsoft.Sql/servers/azureADOnlyAuthentications@2022-05-01-preview' = {\n name: 'Default'\n parent: logicalServer\n properties: {\n azureADOnlyAuthentication: true\n }\n}\n
","tags":["Azure.SQL.AADOnly","AZR-000369"]},{"location":"en/rules/Azure.SQL.AADOnly/#notes","title":"Notes","text":"The Azure AD admin must be set before enabling Azure AD-only authentication. A managed identity is required if an Azure AD service principal (Azure AD application) oversees creating and managing Azure AD users, groups, or applications in the logical server.
","tags":["Azure.SQL.AADOnly","AZR-000369"]},{"location":"en/rules/Azure.SQL.AADOnly/#links","title":"Links","text":"Security \u00b7 SQL Database \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Determine if access from Azure services is required.
","tags":["Azure.SQL.AllowAzureAccess","AZR-000184"]},{"location":"en/rules/Azure.SQL.AllowAzureAccess/#description","title":"Description","text":"Allow access to Azure services, permits any Azure service network based access to databases. Network based access it not limited to a single customer, all Azure IP addresses are permitted. Network access can also be allowed/ blocked on individual databases, which takes precedence over server firewall rules.
If network based access is permitted, authentication is still required.
Enabling access from Azure Services is useful in certain cases for on demand PaaS workloads where configuring a stable IP address is not possible. For example Azure Functions, Container Instances and Logic Apps.
","tags":["Azure.SQL.AllowAzureAccess","AZR-000184"]},{"location":"en/rules/Azure.SQL.AllowAzureAccess/#recommendation","title":"Recommendation","text":"Consider using a stable IP address or configure virtual network based firewall rules. Determine if access from Azure services is required for the services connecting to the hosted databases.
","tags":["Azure.SQL.AllowAzureAccess","AZR-000184"]},{"location":"en/rules/Azure.SQL.AllowAzureAccess/#links","title":"Links","text":"Security \u00b7 SQL Database \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Enable auditing for Azure SQL logical server.
","tags":["Azure.SQL.Auditing","AZR-000187"]},{"location":"en/rules/Azure.SQL.Auditing/#description","title":"Description","text":"Auditing for Azure SQL Database tracks database events and writes them to an audit log. Audit logs help you find suspicious events, unusual activity, and trends.
","tags":["Azure.SQL.Auditing","AZR-000187"]},{"location":"en/rules/Azure.SQL.Auditing/#recommendation","title":"Recommendation","text":"Consider enabling auditing for each SQL Database logical server and review reports on a regular basis.
","tags":["Azure.SQL.Auditing","AZR-000187"]},{"location":"en/rules/Azure.SQL.Auditing/#examples","title":"Examples","text":"","tags":["Azure.SQL.Auditing","AZR-000187"]},{"location":"en/rules/Azure.SQL.Auditing/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy logical servers that pass this rule:
Microsoft.Sql/servers/auditingSettings
sub-resource with each logical server.properties.state
property to Enabled
for the Microsoft.Sql/servers/auditingSettings
sub-resource.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Sql/servers/auditingSettings\",\n \"apiVersion\": \"2022-08-01-preview\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'default')]\",\n \"properties\": {\n \"isAzureMonitorTargetEnabled\": true,\n \"state\": \"Enabled\",\n \"retentionDays\": 7,\n \"auditActionsAndGroups\": [\n \"SUCCESSFUL_DATABASE_AUTHENTICATION_GROUP\",\n \"FAILED_DATABASE_AUTHENTICATION_GROUP\",\n \"BATCH_COMPLETED_GROUP\"\n ]\n },\n \"dependsOn\": [\n \"server\"\n ]\n}\n
","tags":["Azure.SQL.Auditing","AZR-000187"]},{"location":"en/rules/Azure.SQL.Auditing/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy logical servers that pass this rule:
Microsoft.Sql/servers/auditingSettings
sub-resource with each logical server.properties.state
property to Enabled
for the Microsoft.Sql/servers/auditingSettings
sub-resource.For example:
Azure Bicep snippetresource server 'Microsoft.Sql/servers@2022-11-01-preview' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n publicNetworkAccess: 'Disabled'\n minimalTlsVersion: '1.2'\n administrators: {\n azureADOnlyAuthentication: true\n administratorType: 'ActiveDirectory'\n login: adminLogin\n principalType: 'Group'\n sid: adminPrincipalId\n tenantId: tenant().tenantId\n }\n }\n}\n\nresource sqlAuditSettings 'Microsoft.Sql/servers/auditingSettings@2022-08-01-preview' = {\n name: 'default'\n parent: server\n properties: {\n isAzureMonitorTargetEnabled: true\n state: 'Enabled'\n retentionDays: 7\n auditActionsAndGroups: [\n 'SUCCESSFUL_DATABASE_AUTHENTICATION_GROUP'\n 'FAILED_DATABASE_AUTHENTICATION_GROUP'\n 'BATCH_COMPLETED_GROUP'\n ]\n }\n}\n
","tags":["Azure.SQL.Auditing","AZR-000187"]},{"location":"en/rules/Azure.SQL.Auditing/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz sql server audit-policy update -g '<resource_group>' -n '<server_name>' --state Enabled --bsts Enabled --storage-account '<storage_account_name>'\n
","tags":["Azure.SQL.Auditing","AZR-000187"]},{"location":"en/rules/Azure.SQL.Auditing/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetSet-AzSqlServerAudit -ResourceGroupName '<resource_group>' -ServerName '<server_name>' -BlobStorageTargetState Enabled -StorageAccountResourceId '<storage_resource_id>'\n
","tags":["Azure.SQL.Auditing","AZR-000187"]},{"location":"en/rules/Azure.SQL.Auditing/#links","title":"Links","text":"Operational Excellence \u00b7 SQL Database \u00b7 Rule \u00b7 2020_12 \u00b7 Awareness
Azure SQL Database names should meet naming requirements.
","tags":["Azure.SQL.DBName","AZR-000192"]},{"location":"en/rules/Azure.SQL.DBName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for SQL Database names are:
<>*%&:\\/?
The following reserved database names can not be used:
master
model
tempdb
Consider using names that meet Azure SQL Database naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.SQL.DBName","AZR-000192"]},{"location":"en/rules/Azure.SQL.DBName/#notes","title":"Notes","text":"This rule does not check if Azure SQL Database names are unique.
","tags":["Azure.SQL.DBName","AZR-000192"]},{"location":"en/rules/Azure.SQL.DBName/#links","title":"Links","text":"Security \u00b7 SQL Database \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Enable Microsoft Defender for Azure SQL logical server.
","tags":["Azure.SQL.DefenderCloud","AZR-000186"]},{"location":"en/rules/Azure.SQL.DefenderCloud/#description","title":"Description","text":"Enable Microsoft Defender for Azure SQL logical server.
","tags":["Azure.SQL.DefenderCloud","AZR-000186"]},{"location":"en/rules/Azure.SQL.DefenderCloud/#recommendation","title":"Recommendation","text":"Consider enabling Advanced Data Security and configuring Microsoft Defender for SQL logical servers.
","tags":["Azure.SQL.DefenderCloud","AZR-000186"]},{"location":"en/rules/Azure.SQL.DefenderCloud/#examples","title":"Examples","text":"","tags":["Azure.SQL.DefenderCloud","AZR-000186"]},{"location":"en/rules/Azure.SQL.DefenderCloud/#configure-with-azure-template","title":"Configure with Azure template","text":"Azure Template snippet{\n \"comments\": \"Create or update an Azure SQL logical server.\",\n \"type\": \"Microsoft.Sql/servers\",\n \"apiVersion\": \"2019-06-01-preview\",\n \"name\": \"[parameters('serverName')]\",\n \"location\": \"[parameters('location')]\",\n \"tags\": \"[parameters('tags')]\",\n \"kind\": \"v12.0\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"administratorLogin\": \"[parameters('adminUsername')]\",\n \"version\": \"12.0\",\n \"publicNetworkAccess\": \"[if(parameters('allowPublicAccess'), 'Enabled', 'Disabled')]\",\n \"administratorLoginPassword\": \"[parameters('adminPassword')]\",\n \"minimalTLSVersion\": \"1.2\"\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Sql/servers/securityAlertPolicies\",\n \"apiVersion\": \"2020-02-02-preview\",\n \"name\": \"[concat(parameters('serverName'), '/Default')]\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.Sql/servers', parameters('serverName'))]\"\n ],\n \"properties\": {\n \"state\": \"Enabled\"\n }\n }\n ]\n}\n
","tags":["Azure.SQL.DefenderCloud","AZR-000186"]},{"location":"en/rules/Azure.SQL.DefenderCloud/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetSet-AzSqlDatabaseThreatDetectionPolicy -ResourceGroupName '<resource_group>' -ServerName '<server_name>' -DatabaseName '<database>' -StorageAccountName '<account_name>' -NotificationRecipientsEmails '<email>' -EmailAdmins $False\n
","tags":["Azure.SQL.DefenderCloud","AZR-000186"]},{"location":"en/rules/Azure.SQL.DefenderCloud/#links","title":"Links","text":"Operational Excellence \u00b7 SQL Database \u00b7 Rule \u00b7 2020_12 \u00b7 Awareness
Azure SQL failover group names should meet naming requirements.
","tags":["Azure.SQL.FGName","AZR-000193"]},{"location":"en/rules/Azure.SQL.FGName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for SQL failover group names are:
Consider using names that meet Azure SQL failover group naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.SQL.FGName","AZR-000193"]},{"location":"en/rules/Azure.SQL.FGName/#notes","title":"Notes","text":"This rule does not check if Azure SQL failover group names are unique.
","tags":["Azure.SQL.FGName","AZR-000193"]},{"location":"en/rules/Azure.SQL.FGName/#links","title":"Links","text":"Security \u00b7 SQL Database \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range).
","tags":["Azure.SQL.FirewallIPRange","AZR-000185"]},{"location":"en/rules/Azure.SQL.FirewallIPRange/#description","title":"Description","text":"Typically the number of IP address rules permitted through the firewall is minimal, with management connectivity from on-premises and cloud application connectivity the most common. This rule assesses the combined IP addresses from each Allowed IP firewall entry to check that the total allowed addresses is less than (10).
","tags":["Azure.SQL.FirewallIPRange","AZR-000185"]},{"location":"en/rules/Azure.SQL.FirewallIPRange/#recommendation","title":"Recommendation","text":"Reduce the size or count of the IP ranges set in the Firewall rules so that the total Allowed IPs are less than (10).
","tags":["Azure.SQL.FirewallIPRange","AZR-000185"]},{"location":"en/rules/Azure.SQL.FirewallIPRange/#example","title":"Example","text":"","tags":["Azure.SQL.FirewallIPRange","AZR-000185"]},{"location":"en/rules/Azure.SQL.FirewallIPRange/#links","title":"Links","text":"Security \u00b7 SQL Database \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Determine if there is an excessive number of firewall rules.
","tags":["Azure.SQL.FirewallRuleCount","AZR-000183"]},{"location":"en/rules/Azure.SQL.FirewallRuleCount/#description","title":"Description","text":"Typically the number of firewall rules required is minimal, with management connectivity from on-premises and cloud application connectivity the most common.
","tags":["Azure.SQL.FirewallRuleCount","AZR-000183"]},{"location":"en/rules/Azure.SQL.FirewallRuleCount/#recommendation","title":"Recommendation","text":"The logical SQL Server has greater then ten (10) firewall rules. Some rules may not be needed.
","tags":["Azure.SQL.FirewallRuleCount","AZR-000183"]},{"location":"en/rules/Azure.SQL.FirewallRuleCount/#links","title":"Links","text":"Security \u00b7 SQL Database \u00b7 Rule \u00b7 2020_09 \u00b7 Critical
Azure SQL Database servers should reject TLS versions older than 1.2.
","tags":["Azure.SQL.MinTLS","AZR-000189"]},{"location":"en/rules/Azure.SQL.MinTLS/#description","title":"Description","text":"The minimum version of TLS that Azure SQL Database servers accept is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Azure lets you disable outdated protocols and require connections to use a minimum of TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 is accepted.
","tags":["Azure.SQL.MinTLS","AZR-000189"]},{"location":"en/rules/Azure.SQL.MinTLS/#recommendation","title":"Recommendation","text":"Consider configuring the minimum supported TLS version to be 1.2.
","tags":["Azure.SQL.MinTLS","AZR-000189"]},{"location":"en/rules/Azure.SQL.MinTLS/#examples","title":"Examples","text":"","tags":["Azure.SQL.MinTLS","AZR-000189"]},{"location":"en/rules/Azure.SQL.MinTLS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy logical SQL Servers that pass this rule:
properties.minimalTlsVersion
to 1.2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Sql/servers\",\n \"apiVersion\": \"2022-11-01-preview\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"publicNetworkAccess\": \"Disabled\",\n \"minimalTlsVersion\": \"1.2\",\n \"administrators\": {\n \"azureADOnlyAuthentication\": true,\n \"administratorType\": \"ActiveDirectory\",\n \"login\": \"[parameters('adminLogin')]\",\n \"principalType\": \"Group\",\n \"sid\": \"[parameters('adminPrincipalId')]\",\n \"tenantId\": \"[tenant().tenantId]\"\n }\n }\n}\n
","tags":["Azure.SQL.MinTLS","AZR-000189"]},{"location":"en/rules/Azure.SQL.MinTLS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy logical SQL Servers that pass this rule:
properties.minimalTlsVersion
to 1.2
.For example:
Azure Bicep snippetresource server 'Microsoft.Sql/servers@2022-11-01-preview' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n publicNetworkAccess: 'Disabled'\n minimalTlsVersion: '1.2'\n administrators: {\n azureADOnlyAuthentication: true\n administratorType: 'ActiveDirectory'\n login: adminLogin\n principalType: 'Group'\n sid: adminPrincipalId\n tenantId: tenant().tenantId\n }\n }\n}\n
","tags":["Azure.SQL.MinTLS","AZR-000189"]},{"location":"en/rules/Azure.SQL.MinTLS/#links","title":"Links","text":"Operational Excellence \u00b7 SQL Database \u00b7 Rule \u00b7 2020_12 \u00b7 Awareness
Azure SQL logical server names should meet naming requirements.
","tags":["Azure.SQL.ServerName","AZR-000190"]},{"location":"en/rules/Azure.SQL.ServerName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for SQL logical server names are:
Consider using names that meet Azure SQL logical server naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.SQL.ServerName","AZR-000190"]},{"location":"en/rules/Azure.SQL.ServerName/#notes","title":"Notes","text":"This rule does not check if Azure SQL logical server names are unique.
","tags":["Azure.SQL.ServerName","AZR-000190"]},{"location":"en/rules/Azure.SQL.ServerName/#links","title":"Links","text":"Security \u00b7 SQL Database \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Use Transparent Data Encryption (TDE) with Azure SQL Database.
","tags":["Azure.SQL.TDE","AZR-000191"]},{"location":"en/rules/Azure.SQL.TDE/#description","title":"Description","text":"TDE helps protect Azure SQL Databases against malicious offline access by encrypting data at rest. SQL Databases perform real-time encryption and decryption of the database, backups, and log files. Encryption is perform at rest without requiring changes to the application.
","tags":["Azure.SQL.TDE","AZR-000191"]},{"location":"en/rules/Azure.SQL.TDE/#recommendation","title":"Recommendation","text":"Consider enable Transparent Data Encryption (TDE) for Azure SQL Databases to perform encryption at rest.
","tags":["Azure.SQL.TDE","AZR-000191"]},{"location":"en/rules/Azure.SQL.TDE/#examples","title":"Examples","text":"","tags":["Azure.SQL.TDE","AZR-000191"]},{"location":"en/rules/Azure.SQL.TDE/#configure-with-azure-template","title":"Configure with Azure template","text":"Azure Template snippet{\n \"type\": \"Microsoft.Sql/servers/databases\",\n \"apiVersion\": \"2020-08-01-preview\",\n \"name\": \"[variables('dbName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('sku')]\"\n },\n \"kind\": \"v12.0,user\",\n \"properties\": {\n \"collation\": \"SQL_Latin1_General_CP1_CI_AS\",\n \"maxSizeBytes\": \"[mul(parameters('maxSizeMB'), 1048576)]\",\n \"catalogCollation\": \"SQL_Latin1_General_CP1_CI_AS\",\n \"zoneRedundant\": false,\n \"readScale\": \"Disabled\",\n \"storageAccountType\": \"GRS\"\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Sql/servers/databases/transparentDataEncryption\",\n \"apiVersion\": \"2014-04-01\",\n \"name\": \"[concat(variables('dbName'), '/current')]\",\n \"location\": \"[parameters('location')]\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.Sql/servers/databases', parameters('serverName'), parameters('databaseName'))]\"\n ],\n \"properties\": {\n \"status\": \"Enabled\"\n }\n }\n ]\n}\n
","tags":["Azure.SQL.TDE","AZR-000191"]},{"location":"en/rules/Azure.SQL.TDE/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz sql db tde set --status Enabled -s '<server_name>' -d '<database>' -g '<resource_group>'\n
","tags":["Azure.SQL.TDE","AZR-000191"]},{"location":"en/rules/Azure.SQL.TDE/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetSet-AzSqlDatabaseTransparentDataEncryption -ResourceGroupName '<resource_group>' -ServerName '<server_name>' -DatabaseName '<database>' -State Enabled\n
","tags":["Azure.SQL.TDE","AZR-000191"]},{"location":"en/rules/Azure.SQL.TDE/#links","title":"Links","text":"Security \u00b7 SQL Managed Instance \u00b7 Rule \u00b7 2023_03 \u00b7 Critical
Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance.
","tags":["Azure.SQLMI.AAD","AZR-000368"]},{"location":"en/rules/Azure.SQLMI.AAD/#description","title":"Description","text":"Azure SQL Managed Instance supports authentication with SQL logins and Azure AD authentication.
By default, authentication with SQL logins is enabled. SQL logins are unable to provide sufficient protection for identities. Azure AD authentication provides strong protection controls including conditional access, identity governance, and privileged identity management.
Using Azure AD authentication requires an Azure AD administrator provisioned, if a instance does not have an Azure AD administrator, then Azure AD logins and users receive a Cannot connect
to instance error.
Once you decide to use Azure AD authentication, you can disable authentication with SQL logins.
","tags":["Azure.SQLMI.AAD","AZR-000368"]},{"location":"en/rules/Azure.SQLMI.AAD/#recommendation","title":"Recommendation","text":"Consider using Azure Active Directory (AAD) authentication with SQL Managed Instance. Additionally, consider disabling SQL authentication.
","tags":["Azure.SQLMI.AAD","AZR-000368"]},{"location":"en/rules/Azure.SQLMI.AAD/#examples","title":"Examples","text":"An Azure AD administrator can be provisioned in two different ways.
","tags":["Azure.SQLMI.AAD","AZR-000368"]},{"location":"en/rules/Azure.SQLMI.AAD/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy SQL Managed Instances that pass this rule:
properties.administrators.administratorType
to ActiveDirectory
.properties.administrators.login
to the administrator login object name.properties.administrators.sid
to the object ID GUID of the administrator user, group, or application.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Sql/managedInstances\",\n \"apiVersion\": \"2022-05-01-preview\",\n \"name\": \"[parameters('managedInstanceName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\",\n \"userAssignedIdentities\": {}\n },\n \"properties\": {\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"administrators\": {\n \"administratorType\": \"ActiveDirectory\",\n \"azureADOnlyAuthentication\": true,\n \"login\": \"[parameters('login')]\",\n \"principalType\": \"[parameters('principalType')]\",\n \"sid\": \"[parameters('sid')]\",\n \"tenantId\": \"[parameters('tenantId')]\"\n }\n }\n}\n
Alternatively, you can configure the Microsoft.Sql/managedInstances/administrators
sub-resource. To deploy Microsoft.Sql/managedInstances/administrators
sub-resources that pass this rule:
properties.administratorType
to ActiveDirectory
.properties.login
to the administrator login object name.properties.sid
to the object ID GUID of the administrator user, group, or application.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Sql/managedInstances/administrators\",\n \"apiVersion\": \"2022-05-01-preview\",\n \"name\": \"[format('{0}/{1}', parameters('managedInstanceName'), 'ActiveDirectory')]\",\n \"properties\": {\n \"administratorType\": \"ActiveDirectory\",\n \"login\": \"[parameters('login')]\",\n \"sid\": \"[parameters('sid')]\"\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Sql/managedInstances', parameters('managedInstanceName'))]\"\n ]\n}\n
","tags":["Azure.SQLMI.AAD","AZR-000368"]},{"location":"en/rules/Azure.SQLMI.AAD/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy SQL Managed Instances that pass this rule:
properties.administrators.administratorType
to ActiveDirectory
.properties.administrators.login
to the administrator login object name.properties.administrators.sid
to the object ID GUID of the administrator user, group, or application.For example:
Azure Bicep snippetresource managedInstance 'Microsoft.Sql/managedInstances@2022-05-01-preview' = {\n name: managedInstanceName\n location: location\n identity: {\n type: 'SystemAssigned'\n userAssignedIdentities: {}\n }\n properties: {\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n administrators: {\n administratorType: 'ActiveDirectory'\n azureADOnlyAuthentication: true\n login: login\n principalType: principalType\n sid: sid\n tenantId: tenantId\n }\n }\n}\n
Alternatively, you can configure the Microsoft.Sql/managedInstances/administrators
sub-resource. To deploy Microsoft.Sql/managedInstances/administrators
sub-resources that pass this rule:
properties.administratorType
to ActiveDirectory
.properties.login
to the administrator login object name.properties.sid
to the object ID GUID of the administrator user, group, or application.For example:
Azure Bicep snippetresource sqlAdministrator 'Microsoft.Sql/managedInstances//administrators@2022-05-01-preview' = {\n parent: managedInstance\n name: 'ActiveDirectory'\n properties: {\n administratorType: 'ActiveDirectory'\n login: login\n sid: sid\n }\n}\n
","tags":["Azure.SQLMI.AAD","AZR-000368"]},{"location":"en/rules/Azure.SQLMI.AAD/#notes","title":"Notes","text":"If both the properties.administrators
property and Microsoft.Sql/managedInstances/administrators
are set, the sub-resoure will override the property.
Managed identity is required to allow support for Azure AD authentication in SQL Managed Instance.
","tags":["Azure.SQLMI.AAD","AZR-000368"]},{"location":"en/rules/Azure.SQLMI.AAD/#links","title":"Links","text":"Security \u00b7 SQL Managed Instance \u00b7 Rule \u00b7 2023_03 \u00b7 Important
Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance.
","tags":["Azure.SQLMI.AADOnly","AZR-000366"]},{"location":"en/rules/Azure.SQLMI.AADOnly/#description","title":"Description","text":"Azure SQL Managed Instance supports authentication with SQL logins and Azure AD authentication.
By default, authentication with SQL logins is enabled. SQL logins are unable to provide sufficient protection for identities. Azure AD authentication provides strong protection controls including conditional access, identity governance, and privileged identity management.
Once you decide to use Azure AD authentication, you can disable authentication with SQL logins.
","tags":["Azure.SQLMI.AADOnly","AZR-000366"]},{"location":"en/rules/Azure.SQLMI.AADOnly/#recommendation","title":"Recommendation","text":"Consider using Azure AD-only authentication. Also consider using Azure Policy for Azure AD-only authentication with SQL Managed Instance.
","tags":["Azure.SQLMI.AADOnly","AZR-000366"]},{"location":"en/rules/Azure.SQLMI.AADOnly/#examples","title":"Examples","text":"Azure AD-only authentication can be enabled in two different ways.
","tags":["Azure.SQLMI.AADOnly","AZR-000366"]},{"location":"en/rules/Azure.SQLMI.AADOnly/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy SQL Managed Instances that pass this rule:
properties.administrators.azureADOnlyAuthentication
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Sql/managedInstances\",\n \"apiVersion\": \"2022-05-01-preview\",\n \"name\": \"[parameters('managedInstanceName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\",\n \"userAssignedIdentities\": {}\n },\n \"properties\": {\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"administrators\": {\n \"administratorType\": \"ActiveDirectory\",\n \"azureADOnlyAuthentication\": true,\n \"login\": \"[parameters('login')]\",\n \"principalType\": \"[parameters('principalType')]\",\n \"sid\": \"[parameters('sid')]\",\n \"tenantId\": \"[parameters('tenantId')]\"\n }\n }\n}\n
Alternatively, you can configure the Microsoft.Sql/managedInstances/azureADOnlyAuthentications
sub-resource. To deploy Microsoft.Sql/managedInstances/azureADOnlyAuthentications
sub-resources that pass this rule:
properties.azureADOnlyAuthentication
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Sql/managedInstances/azureADOnlyAuthentications\",\n \"apiVersion\": \"2022-05-01-preview\",\n \"name\": \"[format('{0}/{1}', parameters('managedInstanceName'), 'Default')]\",\n \"properties\": {\n \"azureADOnlyAuthentication\": true\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Sql/managedInstances', parameters('managedInstanceName'))]\"\n ]\n}\n
","tags":["Azure.SQLMI.AADOnly","AZR-000366"]},{"location":"en/rules/Azure.SQLMI.AADOnly/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy SQL Managed Instances that pass this rule:
properties.administrators.azureADOnlyAuthentication
property to true
.For example:
Azure Bicep snippetresource managedInstance 'Microsoft.Sql/managedInstances@2022-05-01-preview' = {\n name: managedInstanceName\n location: location\n identity: {\n type: 'SystemAssigned'\n userAssignedIdentities: {}\n }\n properties: {\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n administrators: {\n administratorType: 'ActiveDirectory'\n azureADOnlyAuthentication: true\n login: login\n principalType: principalType\n sid: sid\n tenantId: tenantId\n }\n }\n}\n
Alternatively, you can configure the Microsoft.Sql/managedInstances/azureADOnlyAuthentications
sub-resource. To deploy Microsoft.Sql/managedInstances/azureADOnlyAuthentications
sub-resources that pass this rule:
properties.azureADOnlyAuthentication
property to true
.For example:
Azure Bicep snippetresource aadOnly 'Microsoft.Sql/managedInstances/azureADOnlyAuthentications@2022-05-01-preview' = {\n name: 'Default'\n parent: managedInstance\n properties: {\n azureADOnlyAuthentication: true\n }\n}\n
","tags":["Azure.SQLMI.AADOnly","AZR-000366"]},{"location":"en/rules/Azure.SQLMI.AADOnly/#notes","title":"Notes","text":"The Azure AD admin must be set before enabling Azure AD-only authentication. Managed identity is required to allow support for Azure AD authentication in SQL Managed Instance.
","tags":["Azure.SQLMI.AADOnly","AZR-000366"]},{"location":"en/rules/Azure.SQLMI.AADOnly/#links","title":"Links","text":"Security \u00b7 SQL Managed Instance \u00b7 Rule \u00b7 2023_03 \u00b7 Important
Ensure managed identity is used to allow support for Azure AD authentication.
","tags":["Azure.SQLMI.ManagedIdentity","AZR-000367"]},{"location":"en/rules/Azure.SQLMI.ManagedIdentity/#description","title":"Description","text":"A managed identity is required for allowing support for Azure AD authentication in SQL Managed Instance.
You must enable the instance identity (SMI or UMI) to allow support for Azure AD authentication in SQL Managed Instance.
Additionally, a managed identity is required for transparent data encryption with customer-managed key.
","tags":["Azure.SQLMI.ManagedIdentity","AZR-000367"]},{"location":"en/rules/Azure.SQLMI.ManagedIdentity/#recommendation","title":"Recommendation","text":"Consider configure a managed identity to allow support for Azure AD authentication.
","tags":["Azure.SQLMI.ManagedIdentity","AZR-000367"]},{"location":"en/rules/Azure.SQLMI.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.SQLMI.ManagedIdentity","AZR-000367"]},{"location":"en/rules/Azure.SQLMI.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy SQL Managed Instances that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
or SystemAssigned,UserAssigned
.identity.type
is UserAssigned
or SystemAssigned,UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Sql/managedInstances\",\n \"apiVersion\": \"2022-05-01-preview\",\n \"name\": \"[parameters('managedInstanceName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\",\n \"userAssignedIdentities\": {}\n },\n \"properties\": {}\n}\n
","tags":["Azure.SQLMI.ManagedIdentity","AZR-000367"]},{"location":"en/rules/Azure.SQLMI.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy SQL Managed Instances that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
or SystemAssigned,UserAssigned
.identity.type
is UserAssigned
or SystemAssigned,UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource managedInstance 'Microsoft.Sql/managedInstances@2022-05-01-preview' = {\n name: appName\n location: location\n name: managedInstanceName\n location: location\n identity: {\n type: 'SystemAssigned'\n userAssignedIdentities: {}\n }\n properties: {}\n}\n
","tags":["Azure.SQLMI.ManagedIdentity","AZR-000367"]},{"location":"en/rules/Azure.SQLMI.ManagedIdentity/#notes","title":"Notes","text":"To grant permissions to access Microsoft Graph through an SMI or a UMI, you need to use PowerShell. You can't grant these permissions by using the Azure portal.
","tags":["Azure.SQLMI.ManagedIdentity","AZR-000367"]},{"location":"en/rules/Azure.SQLMI.ManagedIdentity/#links","title":"Links","text":"Operational Excellence \u00b7 SQL Managed Instance \u00b7 Rule \u00b7 2020_12 \u00b7 Awareness
SQL Managed Instance names should meet naming requirements.
","tags":["Azure.SQLMI.Name","AZR-000194"]},{"location":"en/rules/Azure.SQLMI.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for SQL Managed Instance names are:
Consider using names that meet SQL Managed Instance naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.SQLMI.Name","AZR-000194"]},{"location":"en/rules/Azure.SQLMI.Name/#notes","title":"Notes","text":"This rule does not check if SQL Managed Instance names are unique.
","tags":["Azure.SQLMI.Name","AZR-000194"]},{"location":"en/rules/Azure.SQLMI.Name/#links","title":"Links","text":"Reliability \u00b7 AI Search \u00b7 Rule \u00b7 2021_06 \u00b7 Important
Use a minimum of 3 replicas to receive an SLA for query and index updates.
","tags":["Azure.Search.IndexSLA","AZR-000174"]},{"location":"en/rules/Azure.Search.IndexSLA/#description","title":"Description","text":"AI Search (Previously known as Cognitive Search) services support indexing and querying. Indexing is the process of loading content into the service to make it searchable. Querying is the process where a client searches for content by sending queries to the index.
AI Search supports a configurable number of replicas. Having multiple replicas allows queries and index updates to load balance across multiple replicas.
To receive a Service Level Agreement (SLA) for Search index updates a minimum of 3 replicas is required.
","tags":["Azure.Search.IndexSLA","AZR-000174"]},{"location":"en/rules/Azure.Search.IndexSLA/#recommendation","title":"Recommendation","text":"Consider increasing the number of replicas to a minimum of 3 to receive an SLA on index update requests.
","tags":["Azure.Search.IndexSLA","AZR-000174"]},{"location":"en/rules/Azure.Search.IndexSLA/#examples","title":"Examples","text":"","tags":["Azure.Search.IndexSLA","AZR-000174"]},{"location":"en/rules/Azure.Search.IndexSLA/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AI Search services that pass this rule:
properties.replicaCount
property to a minimum of 3
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Search/searchServices\",\n \"apiVersion\": \"2022-09-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"replicaCount\": 3,\n \"partitionCount\": 1,\n \"hostingMode\": \"default\"\n }\n}\n
","tags":["Azure.Search.IndexSLA","AZR-000174"]},{"location":"en/rules/Azure.Search.IndexSLA/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AI Search services that pass this rule:
properties.replicaCount
property to a minimum of 3
.For example:
Azure Bicep snippetresource search 'Microsoft.Search/searchServices@2022-09-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'standard'\n }\n properties: {\n replicaCount: 3\n partitionCount: 1\n hostingMode: 'default'\n }\n}\n
","tags":["Azure.Search.IndexSLA","AZR-000174"]},{"location":"en/rules/Azure.Search.IndexSLA/#links","title":"Links","text":"Security \u00b7 AI Search \u00b7 Rule \u00b7 2021_06 \u00b7 Important
Configure managed identities to access Azure resources.
","tags":["Azure.Search.ManagedIdentity","AZR-000175"]},{"location":"en/rules/Azure.Search.ManagedIdentity/#description","title":"Description","text":"AI Search (Previously known as Cognitive Search) may require connection to other Azure resources. Connections to Azure resources are required to use some features including indexing and customer managed-keys. AI Search can use managed identities to authenticate to Azure resources without storing credentials.
Using Azure managed identities have the following benefits:
Consider configuring a managed identity for each AI Search service. Also consider using managed identities to authenticate to related Azure services.
","tags":["Azure.Search.ManagedIdentity","AZR-000175"]},{"location":"en/rules/Azure.Search.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.Search.ManagedIdentity","AZR-000175"]},{"location":"en/rules/Azure.Search.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AI Search services that pass this rule:
identity.type
property to SystemAssigned
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Search/searchServices\",\n \"apiVersion\": \"2022-09-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"replicaCount\": 3,\n \"partitionCount\": 1,\n \"hostingMode\": \"default\"\n }\n}\n
","tags":["Azure.Search.ManagedIdentity","AZR-000175"]},{"location":"en/rules/Azure.Search.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AI Search Search services that pass this rule:
identity.type
property to SystemAssigned
.For example:
Azure Bicep snippetresource search 'Microsoft.Search/searchServices@2022-09-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'standard'\n }\n properties: {\n replicaCount: 3\n partitionCount: 1\n hostingMode: 'default'\n }\n}\n
","tags":["Azure.Search.ManagedIdentity","AZR-000175"]},{"location":"en/rules/Azure.Search.ManagedIdentity/#links","title":"Links","text":"Operational Excellence \u00b7 AI Search \u00b7 Rule \u00b7 2021_06 \u00b7 Awareness
AI Search service names should meet naming requirements.
","tags":["Azure.Search.Name","AZR-000176"]},{"location":"en/rules/Azure.Search.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for AI Search (Previously known as Cognitive Search) service names are:
Consider using names that meet Azure AI Search service naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.Search.Name","AZR-000176"]},{"location":"en/rules/Azure.Search.Name/#notes","title":"Notes","text":"This rule does not check if Azure AI Search service names are unique.
","tags":["Azure.Search.Name","AZR-000176"]},{"location":"en/rules/Azure.Search.Name/#links","title":"Links","text":"Reliability \u00b7 AI Search \u00b7 Rule \u00b7 2021_06 \u00b7 Important
Use a minimum of 2 replicas to receive an SLA for index queries.
","tags":["Azure.Search.QuerySLA","AZR-000173"]},{"location":"en/rules/Azure.Search.QuerySLA/#description","title":"Description","text":"AI Search (Previously known as Cognitive Search) services support indexing and querying. Indexing is the process of loading content into the service to make it searchable. Querying is the process where a client searches for content by sending queries to the index.
AI Search supports a configurable number of replicas. Having multiple replicas allows queries and index updates to load balance across multiple replicas.
To receive a Service Level Agreement (SLA) for Search index queries a minimum of 2 replicas is required.
","tags":["Azure.Search.QuerySLA","AZR-000173"]},{"location":"en/rules/Azure.Search.QuerySLA/#recommendation","title":"Recommendation","text":"Consider increasing the number of replicas to a minimum of 2 to receive an SLA on index query requests.
","tags":["Azure.Search.QuerySLA","AZR-000173"]},{"location":"en/rules/Azure.Search.QuerySLA/#examples","title":"Examples","text":"","tags":["Azure.Search.QuerySLA","AZR-000173"]},{"location":"en/rules/Azure.Search.QuerySLA/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AI Search services that pass this rule:
properties.replicaCount
property to a minimum of 2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Search/searchServices\",\n \"apiVersion\": \"2022-09-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"replicaCount\": 3,\n \"partitionCount\": 1,\n \"hostingMode\": \"default\"\n }\n}\n
","tags":["Azure.Search.QuerySLA","AZR-000173"]},{"location":"en/rules/Azure.Search.QuerySLA/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AI Search services that pass this rule:
properties.replicaCount
property to a minimum of 2
.For example:
Azure Bicep snippetresource search 'Microsoft.Search/searchServices@2022-09-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'standard'\n }\n properties: {\n replicaCount: 3\n partitionCount: 1\n hostingMode: 'default'\n }\n}\n
","tags":["Azure.Search.QuerySLA","AZR-000173"]},{"location":"en/rules/Azure.Search.QuerySLA/#links","title":"Links","text":"Performance Efficiency \u00b7 AI Search \u00b7 Rule \u00b7 2021_06 \u00b7 Critical
Use the basic and standard tiers for entry level workloads.
","tags":["Azure.Search.SKU","AZR-000172"]},{"location":"en/rules/Azure.Search.SKU/#description","title":"Description","text":"AI Search (Previously known as Cognitive Search) services using the Free tier run on resources shared across multiple subscribers. The Free tier is only suggested for limited small scale tests such as running code samples or tutorials.
Running more demanding workloads on the Free tier may experience unpredictable performance or issues.
To select a tier for your workload, estimate and test your required capacity.
","tags":["Azure.Search.SKU","AZR-000172"]},{"location":"en/rules/Azure.Search.SKU/#recommendation","title":"Recommendation","text":"Consider deploying AI Search services using basic or higher tier.
","tags":["Azure.Search.SKU","AZR-000172"]},{"location":"en/rules/Azure.Search.SKU/#examples","title":"Examples","text":"","tags":["Azure.Search.SKU","AZR-000172"]},{"location":"en/rules/Azure.Search.SKU/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AI Search services that pass this rule:
sku.name
to a minimum of basic
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Search/searchServices\",\n \"apiVersion\": \"2022-09-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"replicaCount\": 3,\n \"partitionCount\": 1,\n \"hostingMode\": \"default\"\n }\n}\n
","tags":["Azure.Search.SKU","AZR-000172"]},{"location":"en/rules/Azure.Search.SKU/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AI Search services that pass this rule:
sku.name
to a minimum of basic
.For example:
Azure Bicep snippetresource search 'Microsoft.Search/searchServices@2022-09-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'standard'\n }\n properties: {\n replicaCount: 3\n partitionCount: 1\n hostingMode: 'default'\n }\n}\n
","tags":["Azure.Search.SKU","AZR-000172"]},{"location":"en/rules/Azure.Search.SKU/#links","title":"Links","text":"Security \u00b7 Service Bus \u00b7 Rule \u00b7 2023_03 \u00b7 Important
Ensure namespaces audit diagnostic logs are enabled.
","tags":["Azure.ServiceBus.AuditLogs","AZR-000358"]},{"location":"en/rules/Azure.ServiceBus.AuditLogs/#description","title":"Description","text":"To capture logs that record data plane access operations (such as send or receive messages) in the service bus, diagnostic settings must be configured.
When configuring diagnostic settings, enabled one of the following:
RuntimeAuditLogs
category.audit
category group.allLogs
category group.Management operations for Service Bus is captured automatically within Azure Activity Logs.
","tags":["Azure.ServiceBus.AuditLogs","AZR-000358"]},{"location":"en/rules/Azure.ServiceBus.AuditLogs/#recommendation","title":"Recommendation","text":"Consider configuring diagnostic settings to record interactions with data of the Service Bus.
","tags":["Azure.ServiceBus.AuditLogs","AZR-000358"]},{"location":"en/rules/Azure.ServiceBus.AuditLogs/#examples","title":"Examples","text":"","tags":["Azure.ServiceBus.AuditLogs","AZR-000358"]},{"location":"en/rules/Azure.ServiceBus.AuditLogs/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Service Bus namespaces that pass this rule:
RuntimeAuditLogs
category or audit
category group or allLogs
category group.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ServiceBus/namespaces\",\n \"apiVersion\": \"2022-10-01-preview\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"minimumTlsVersion\": \"1.2\"\n }\n},\n{\n \"type\": \"Microsoft.Insights/diagnosticSettings\",\n \"apiVersion\": \"2021-05-01-preview\",\n \"scope\": \"[format('Microsoft.ServiceBus/namespaces/{0}', parameters('name'))]\",\n \"name\": \"[parameters('diagName')]\",\n \"properties\": {\n \"workspaceId\": \"[parameters('workspaceId')]\",\n \"logs\": [\n {\n \"category\": \"RuntimeAuditLogs\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n }\n ]\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ServiceBus/namespaces', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.ServiceBus.AuditLogs","AZR-000358"]},{"location":"en/rules/Azure.ServiceBus.AuditLogs/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Service Bus namespaces that pass this rule:
RuntimeAuditLogs
category or audit
category group or allLogs
category group.For example:
Azure Bicep snippetresource ns 'Microsoft.ServiceBus/namespaces@2022-10-01-preview' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'Premium'\n }\n properties: {\n disableLocalAuth: true\n minimumTlsVersion: '1.2'\n }\n}\n\nresource nsDiagnosticSettings 'Microsoft.Insights/diagnosticSettings@2021-05-01-preview' = {\n name: diagName\n properties: {\n workspaceId: workspaceId\n logs: [\n {\n category: 'RuntimeAuditLogs'\n enabled: true\n retentionPolicy: {\n days: 0\n enabled: false\n }\n }\n ]\n }\n scope: ns\n}\n
","tags":["Azure.ServiceBus.AuditLogs","AZR-000358"]},{"location":"en/rules/Azure.ServiceBus.AuditLogs/#notes","title":"Notes","text":"This rule only applies to premium tier Service Bus instances. Runtime audit logs are currently available only in the Premium
tier.
Security \u00b7 Service Bus \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Authenticate Service Bus publishers and consumers with Entra ID identities.
","tags":["Azure.ServiceBus.DisableLocalAuth","AZR-000178"]},{"location":"en/rules/Azure.ServiceBus.DisableLocalAuth/#description","title":"Description","text":"To publish or consume messages from Service Bus cryptographic keys, or Entra ID identities can be used. Cryptographic keys include Shared Access Policy keys or Shared Access Signature (SAS) tokens. With Entra ID authentication, the identity is validated against Entra ID. Using Entra ID identities centralizes identity management and auditing.
Once you decide to use Entra ID authentication, you can disable authentication using keys or SAS tokens.
","tags":["Azure.ServiceBus.DisableLocalAuth","AZR-000178"]},{"location":"en/rules/Azure.ServiceBus.DisableLocalAuth/#recommendation","title":"Recommendation","text":"Consider only using Entra ID identities to publish or consume messages from Service Bus. Then disable authentication based on access keys or SAS tokens.
","tags":["Azure.ServiceBus.DisableLocalAuth","AZR-000178"]},{"location":"en/rules/Azure.ServiceBus.DisableLocalAuth/#examples","title":"Examples","text":"","tags":["Azure.ServiceBus.DisableLocalAuth","AZR-000178"]},{"location":"en/rules/Azure.ServiceBus.DisableLocalAuth/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy namespaces that pass this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ServiceBus/namespaces\",\n \"apiVersion\": \"2022-10-01-preview\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"Standard\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"minimumTlsVersion\": \"1.2\"\n }\n}\n
","tags":["Azure.ServiceBus.DisableLocalAuth","AZR-000178"]},{"location":"en/rules/Azure.ServiceBus.DisableLocalAuth/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy namespaces that pass this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Bicep snippetresource ns 'Microsoft.ServiceBus/namespaces@2022-10-01-preview' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'Standard'\n }\n properties: {\n disableLocalAuth: true\n minimumTlsVersion: '1.2'\n }\n}\n
","tags":["Azure.ServiceBus.DisableLocalAuth","AZR-000178"]},{"location":"en/rules/Azure.ServiceBus.DisableLocalAuth/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/cfb11c26-f069-4c14-8e36-56c394dae5af
/providers/Microsoft.Authorization/policyDefinitions/910711a6-8aa2-4f15-ae62-1e5b2ed3ef9e
Security \u00b7 Service Bus \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Service Bus namespaces should reject TLS versions older than 1.2.
","tags":["Azure.ServiceBus.MinTLS","AZR-000315"]},{"location":"en/rules/Azure.ServiceBus.MinTLS/#description","title":"Description","text":"Clients connect to Azure Service Bus to send and receive messages over a Transport Layer Security (TLS) encrypted connection. The minimum version of TLS that Service Bus accepts is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS. Additionally, support for TLS 1.0 and 1.1 are on a deprecation path across Azure services.
Azure lets you disable outdated protocols and require connections to use a minimum of TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 are accepted.
When clients connect using an older version of TLS that is disabled, the connection will fail.
","tags":["Azure.ServiceBus.MinTLS","AZR-000315"]},{"location":"en/rules/Azure.ServiceBus.MinTLS/#recommendation","title":"Recommendation","text":"Consider configuring the minimum supported TLS version for Service Bus clients to be 1.2. Support for TLS 1.0/ 1.1 version will be removed.
","tags":["Azure.ServiceBus.MinTLS","AZR-000315"]},{"location":"en/rules/Azure.ServiceBus.MinTLS/#examples","title":"Examples","text":"","tags":["Azure.ServiceBus.MinTLS","AZR-000315"]},{"location":"en/rules/Azure.ServiceBus.MinTLS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy namespaces that pass this rule:
properties.minimumTlsVersion
property to 1.2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ServiceBus/namespaces\",\n \"apiVersion\": \"2022-10-01-preview\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"Standard\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"minimumTlsVersion\": \"1.2\"\n }\n}\n
","tags":["Azure.ServiceBus.MinTLS","AZR-000315"]},{"location":"en/rules/Azure.ServiceBus.MinTLS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy namespaces that pass this rule:
properties.minimumTlsVersion
property to 1.2
.For example:
Azure Bicep snippetresource ns 'Microsoft.ServiceBus/namespaces@2022-10-01-preview' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'Standard'\n }\n properties: {\n disableLocalAuth: true\n minimumTlsVersion: '1.2'\n }\n}\n
","tags":["Azure.ServiceBus.MinTLS","AZR-000315"]},{"location":"en/rules/Azure.ServiceBus.MinTLS/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz servicebus namespace update -n '<name>' -g '<resource_group>' --minimum-tls-version '1.2'\n
","tags":["Azure.ServiceBus.MinTLS","AZR-000315"]},{"location":"en/rules/Azure.ServiceBus.MinTLS/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippet$ns = Get-AzServiceBusNamespace -Name '<name>' -ResourceGroupName '<resource_group>'\nSet-AzServiceBusNamespace -InputObject $ns -MinimumTlsVersion '1.2'\n
","tags":["Azure.ServiceBus.MinTLS","AZR-000315"]},{"location":"en/rules/Azure.ServiceBus.MinTLS/#links","title":"Links","text":"Cost Optimization \u00b7 Service Bus \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Regularly remove unused resources to reduce costs.
","tags":["Azure.ServiceBus.Usage","AZR-000177"]},{"location":"en/rules/Azure.ServiceBus.Usage/#description","title":"Description","text":"Billing starts for a Standard or Premium Service Bus namespace after it is provisioned. To to receive messages you must first create at least one queue or topic. Namespaces without any queues or topics are considered unused.
","tags":["Azure.ServiceBus.Usage","AZR-000177"]},{"location":"en/rules/Azure.ServiceBus.Usage/#recommendation","title":"Recommendation","text":"Consider removing Service Bus namespaces that are not used.
","tags":["Azure.ServiceBus.Usage","AZR-000177"]},{"location":"en/rules/Azure.ServiceBus.Usage/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.ServiceBus.Usage","AZR-000177"]},{"location":"en/rules/Azure.ServiceBus.Usage/#links","title":"Links","text":"Security \u00b7 Service Fabric \u00b7 Rule \u00b7 2021_03 \u00b7 Critical
Use Azure Active Directory (AAD) client authentication for Service Fabric clusters.
","tags":["Azure.ServiceFabric.AAD","AZR-000179"]},{"location":"en/rules/Azure.ServiceFabric.AAD/#description","title":"Description","text":"When deploying Service Fabric clusters on Azure, AAD can optionally be used to secure management endpoints. If configured, client authentication (client-to-node security) uses AAD. Additionally Azure Role-based Access Control (RBAC) can be used to delegate cluster access.
For Service Fabric clusters running on Azure, AAD is recommended to secure access to management endpoints.
","tags":["Azure.ServiceFabric.AAD","AZR-000179"]},{"location":"en/rules/Azure.ServiceFabric.AAD/#recommendation","title":"Recommendation","text":"Consider enabling Azure Active Directory (AAD) client authentication for Service Fabric clusters.
","tags":["Azure.ServiceFabric.AAD","AZR-000179"]},{"location":"en/rules/Azure.ServiceFabric.AAD/#notes","title":"Notes","text":"For Linux clusters, AAD authentication must be configured at cluster creation time. Windows cluster can be updated to support AAD authentication after initial deployment.
","tags":["Azure.ServiceFabric.AAD","AZR-000179"]},{"location":"en/rules/Azure.ServiceFabric.AAD/#links","title":"Links","text":"Security \u00b7 SignalR Service \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Configure SignalR Services to use managed identities to access Azure resources securely.
","tags":["Azure.SignalR.ManagedIdentity","AZR-000181"]},{"location":"en/rules/Azure.SignalR.ManagedIdentity/#description","title":"Description","text":"A managed identity allows your service to access other Azure AD-protected resources such as Azure Functions. The identity is managed by the Azure platform and doesn't require you to provision or rotate any secrets.
Using Azure managed identities have the following benefits:
Consider configuring a managed identity for each SignalR Service. Also consider using managed identities to authenticate to related Azure services.
","tags":["Azure.SignalR.ManagedIdentity","AZR-000181"]},{"location":"en/rules/Azure.SignalR.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.SignalR.ManagedIdentity","AZR-000181"]},{"location":"en/rules/Azure.SignalR.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy services that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.SignalRService/signalR\",\n \"apiVersion\": \"2021-10-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"kind\": \"SignalR\",\n \"sku\": {\n \"name\": \"Standard_S1\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"features\": [\n {\n \"flag\": \"ServiceMode\",\n \"value\": \"Serverless\"\n }\n ]\n }\n}\n
","tags":["Azure.SignalR.ManagedIdentity","AZR-000181"]},{"location":"en/rules/Azure.SignalR.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy services that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource service 'Microsoft.SignalRService/signalR@2021-10-01' = {\n name: name\n location: location\n kind: 'SignalR'\n sku: {\n name: 'Standard_S1'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n disableLocalAuth: true\n features: [\n {\n flag: 'ServiceMode'\n value: 'Serverless'\n }\n ]\n }\n}\n
","tags":["Azure.SignalR.ManagedIdentity","AZR-000181"]},{"location":"en/rules/Azure.SignalR.ManagedIdentity/#links","title":"Links","text":"Operational Excellence \u00b7 SignalR Service \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
SignalR service instance names should meet naming requirements.
","tags":["Azure.SignalR.Name","AZR-000180"]},{"location":"en/rules/Azure.SignalR.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for SignalR service names are:
Consider using names that meet SignalR service naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.SignalR.Name","AZR-000180"]},{"location":"en/rules/Azure.SignalR.Name/#notes","title":"Notes","text":"This rule does not check if SignalR service names are unique.
","tags":["Azure.SignalR.Name","AZR-000180"]},{"location":"en/rules/Azure.SignalR.Name/#links","title":"Links","text":"Reliability \u00b7 SignalR Service \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Use SKUs that include an SLA when configuring SignalR Services.
","tags":["Azure.SignalR.SLA","AZR-000182"]},{"location":"en/rules/Azure.SignalR.SLA/#description","title":"Description","text":"When choosing a SKU for a SignalR Service you should consider the SLA that is included in the SKU. SignalR Services offer a range of SKU offerings:
Free
- Are designed for early non-production use and do not include any SLA.Standard
- Are designed for production use and include an SLA.Premium
- Are designed for production use and include an SLA. Additional, Premium SKUs support increased resilience with Availablity Zones.Consider using a Standard or Premium SKU that includes an SLA.
","tags":["Azure.SignalR.SLA","AZR-000182"]},{"location":"en/rules/Azure.SignalR.SLA/#examples","title":"Examples","text":"","tags":["Azure.SignalR.SLA","AZR-000182"]},{"location":"en/rules/Azure.SignalR.SLA/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy services that pass this rule:
sku.name
to Standard_S1
or Premium_P1
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.SignalRService/signalR\",\n \"apiVersion\": \"2021-10-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"kind\": \"SignalR\",\n \"sku\": {\n \"name\": \"Standard_S1\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"features\": [\n {\n \"flag\": \"ServiceMode\",\n \"value\": \"Serverless\"\n }\n ]\n }\n}\n
","tags":["Azure.SignalR.SLA","AZR-000182"]},{"location":"en/rules/Azure.SignalR.SLA/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy services that pass this rule:
sku.name
to Standard_S1
or Premium_P1
.For example:
Azure Bicep snippetresource service 'Microsoft.SignalRService/signalR@2021-10-01' = {\n name: name\n location: location\n kind: 'SignalR'\n sku: {\n name: 'Standard_S1'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n disableLocalAuth: true\n features: [\n {\n flag: 'ServiceMode'\n value: 'Serverless'\n }\n ]\n }\n}\n
","tags":["Azure.SignalR.SLA","AZR-000182"]},{"location":"en/rules/Azure.SignalR.SLA/#links","title":"Links","text":"Security \u00b7 Storage Account \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use containers configured with a private access type that requires authorization.
","tags":["Azure.Storage.BlobAccessType","AZR-000199"]},{"location":"en/rules/Azure.Storage.BlobAccessType/#description","title":"Description","text":"Azure Storage Account blob containers use the Private access type by default. Additional access types Blob and Container provide anonymous access to blobs without authorization. Blob and Container access types are not intended for access to customer data. When authorization is required, clients must use cryptographic keys or identity-based tokens to authenticate.
Blob and Container access types are designed for public access scenarios. For example, storage of web assets like .css and .js files used in public websites.
","tags":["Azure.Storage.BlobAccessType","AZR-000199"]},{"location":"en/rules/Azure.Storage.BlobAccessType/#recommendation","title":"Recommendation","text":"To provide secure access to data always use the Private access type (default). Also consider, disabling public access for the storage account.
","tags":["Azure.Storage.BlobAccessType","AZR-000199"]},{"location":"en/rules/Azure.Storage.BlobAccessType/#examples","title":"Examples","text":"","tags":["Azure.Storage.BlobAccessType","AZR-000199"]},{"location":"en/rules/Azure.Storage.BlobAccessType/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Storage Account blob containers that pass this rule:
properties.publicAccess
property to None
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Storage/storageAccounts/blobServices/containers\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[format('{0}/{1}/{2}', parameters('name'), 'default', variables('containerName'))]\",\n \"properties\": {\n \"publicAccess\": \"None\"\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Storage/storageAccounts/blobServices', parameters('name'), 'default')]\",\n \"[resourceId('Microsoft.Storage/storageAccounts', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.Storage.BlobAccessType","AZR-000199"]},{"location":"en/rules/Azure.Storage.BlobAccessType/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Storage Account blob containers that pass this rule:
properties.publicAccess
property to None
.For example:
Azure Bicep snippetresource container 'Microsoft.Storage/storageAccounts/blobServices/containers@2021-06-01' = {\n parent: blobService\n name: containerName\n properties: {\n publicAccess: 'None'\n }\n}\n
","tags":["Azure.Storage.BlobAccessType","AZR-000199"]},{"location":"en/rules/Azure.Storage.BlobAccessType/#links","title":"Links","text":"Security \u00b7 Storage Account \u00b7 Rule \u00b7 2020_09 \u00b7 Important
Storage Accounts should only accept authorized requests.
","tags":["Azure.Storage.BlobPublicAccess","AZR-000198"]},{"location":"en/rules/Azure.Storage.BlobPublicAccess/#description","title":"Description","text":"Blob containers in Azure Storage Accounts can be configured for private or anonymous public access. By default, containers are private and only accessible with a credential or access token. When a container is configured with an access type other than private, anonymous access is permitted.
Anonymous access to blobs or containers can be restricted by setting allowBlobPublicAccess
to false
. This enhanced security setting for a storage account overrides the individual settings for blob containers. When you disallow public access for a storage account, blobs are no longer accessible anonymously.
Consider disallowing anonymous access to storage account blobs unless specifically required. Also consider enforcing this setting using Azure Policy.
","tags":["Azure.Storage.BlobPublicAccess","AZR-000198"]},{"location":"en/rules/Azure.Storage.BlobPublicAccess/#examples","title":"Examples","text":"","tags":["Azure.Storage.BlobPublicAccess","AZR-000198"]},{"location":"en/rules/Azure.Storage.BlobPublicAccess/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Storage Accounts that pass this rule:
properties.allowBlobPublicAccess
property to false
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Storage/storageAccounts\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_GRS\"\n },\n \"kind\": \"StorageV2\",\n \"properties\": {\n \"allowBlobPublicAccess\": false,\n \"supportsHttpsTrafficOnly\": true,\n \"minimumTlsVersion\": \"TLS1_2\",\n \"accessTier\": \"Hot\",\n \"allowSharedKeyAccess\": false,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n }\n }\n}\n
","tags":["Azure.Storage.BlobPublicAccess","AZR-000198"]},{"location":"en/rules/Azure.Storage.BlobPublicAccess/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Storage Accounts that pass this rule:
properties.allowBlobPublicAccess
property to false
.For example:
Azure Bicep snippetresource storageAccount 'Microsoft.Storage/storageAccounts@2023-01-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard_GRS'\n }\n kind: 'StorageV2'\n properties: {\n allowBlobPublicAccess: false\n supportsHttpsTrafficOnly: true\n minimumTlsVersion: 'TLS1_2'\n accessTier: 'Hot'\n allowSharedKeyAccess: false\n networkAcls: {\n defaultAction: 'Deny'\n }\n }\n}\n
","tags":["Azure.Storage.BlobPublicAccess","AZR-000198"]},{"location":"en/rules/Azure.Storage.BlobPublicAccess/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/13502221-8df0-4414-9937-de9c5c4e396b
Reliability \u00b7 Storage Account \u00b7 Rule \u00b7 2022_09 \u00b7 Important
Enable container soft delete on Storage Accounts.
","tags":["Azure.Storage.ContainerSoftDelete","AZR-000289"]},{"location":"en/rules/Azure.Storage.ContainerSoftDelete/#description","title":"Description","text":"Container soft delete protects your data from being accidentally or erroneously modified or deleted. When container soft delete is enabled for a storage account, a container and its contents may be recovered after it has been deleted, within a retention period that you specify.
Blob container soft delete should be considered part of the strategy to protect and retain data. Also consider:
Blob containers can be configured to retain deleted containers for a period of time between 1 and 365 days.
","tags":["Azure.Storage.ContainerSoftDelete","AZR-000289"]},{"location":"en/rules/Azure.Storage.ContainerSoftDelete/#recommendation","title":"Recommendation","text":"Consider enabling container soft delete on storage accounts to protect blob containers from accidental deletion or modification.
","tags":["Azure.Storage.ContainerSoftDelete","AZR-000289"]},{"location":"en/rules/Azure.Storage.ContainerSoftDelete/#examples","title":"Examples","text":"","tags":["Azure.Storage.ContainerSoftDelete","AZR-000289"]},{"location":"en/rules/Azure.Storage.ContainerSoftDelete/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Storage Accounts that pass this rule:
properties.containerDeleteRetentionPolicy.enabled
property to true
on the blob services sub-resource.properties.containerDeleteRetentionPolicy.days
property to the number of days to retain blobs.{\n \"type\": \"Microsoft.Storage/storageAccounts\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_GRS\"\n },\n \"kind\": \"StorageV2\",\n \"properties\": {\n \"allowBlobPublicAccess\": false,\n \"supportsHttpsTrafficOnly\": true,\n \"minimumTlsVersion\": \"TLS1_2\",\n \"accessTier\": \"Hot\",\n \"allowSharedKeyAccess\": false,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Storage/storageAccounts/blobServices\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'default')]\",\n \"properties\": {\n \"deleteRetentionPolicy\": {\n \"enabled\": true,\n \"days\": 7\n },\n \"containerDeleteRetentionPolicy\": {\n \"enabled\": true,\n \"days\": 7\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Storage/storageAccounts', parameters('name'))]\"\n ]\n }\n ]\n}\n
","tags":["Azure.Storage.ContainerSoftDelete","AZR-000289"]},{"location":"en/rules/Azure.Storage.ContainerSoftDelete/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Storage Accounts that pass this rule:
properties.containerDeleteRetentionPolicy.enabled
property to true
on the blob services sub-resource.properties.containerDeleteRetentionPolicy.days
property to the number of days to retain blobs.For example:
Azure Bicep snippetresource storageAccount 'Microsoft.Storage/storageAccounts@2023-01-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard_GRS'\n }\n kind: 'StorageV2'\n properties: {\n allowBlobPublicAccess: false\n supportsHttpsTrafficOnly: true\n minimumTlsVersion: 'TLS1_2'\n accessTier: 'Hot'\n allowSharedKeyAccess: false\n networkAcls: {\n defaultAction: 'Deny'\n }\n }\n}\n\nresource blobService 'Microsoft.Storage/storageAccounts/blobServices@2023-01-01' = {\n parent: storageAccount\n name: 'default'\n properties: {\n deleteRetentionPolicy: {\n enabled: true\n days: 7\n }\n containerDeleteRetentionPolicy: {\n enabled: true\n days: 7\n }\n }\n}\n
","tags":["Azure.Storage.ContainerSoftDelete","AZR-000289"]},{"location":"en/rules/Azure.Storage.ContainerSoftDelete/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz storage account blob-service-properties update --enable-container-delete-retention true --container-delete-retention-days 7 -n '<name>' -g '<resource_group>'\n
","tags":["Azure.Storage.ContainerSoftDelete","AZR-000289"]},{"location":"en/rules/Azure.Storage.ContainerSoftDelete/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetEnable-AzStorageContainerDeleteRetentionPolicy -ResourceGroupName '<resource_group>' -StorageAccountName '<name>' -RetentionDays 7\n
","tags":["Azure.Storage.ContainerSoftDelete","AZR-000289"]},{"location":"en/rules/Azure.Storage.ContainerSoftDelete/#notes","title":"Notes","text":"Cloud Shell storage with the tag ms-resource-usage = 'azure-cloud-shell'
is excluded. Storage accounts used for Cloud Shell are not intended to store data.
Storage accounts with:
FileStorage
storage account do not support blob soft delete.Security \u00b7 Storage Account \u00b7 Rule \u00b7 Preview \u00b7 2023_06 \u00b7 Critical
Enable sensitive data threat detection in Microsoft Defender for Storage.
","tags":["Azure.Storage.Defender.DataScan","AZR-000391"]},{"location":"en/rules/Azure.Storage.Defender.DataScan/#description","title":"Description","text":"Sensitive data threat detection is an additional security feature for Microsoft Defender for Storage. When enabled Defender for Storage provides alerts when sensitive data is discovered.
The sensitive data threat detection capability helps teams:
When enabling sensitive data threat detection, the sensitive data categories include built-in sensitive information types (SITs) in the default list of Microsoft Purview. It is possible to customize the Data Sensitivity Discovery for a organization, by creating custom sensitive information types (SITs).
Sensitive data threat detection in Microsoft Defender for Storage can be enabled at the subscription level and by doing so ensures all storage accounts in the subscription will be protected, including future ones.
When overriding sensitive data threat detection on individual Storage Account it is possible to configure custom sensitive data threat detection settings that differ from the settings configured at the subscription level.
","tags":["Azure.Storage.Defender.DataScan","AZR-000391"]},{"location":"en/rules/Azure.Storage.Defender.DataScan/#recommendation","title":"Recommendation","text":"Consider enabling sensitive data threat detection using Microsoft Defender for Storage on the Storage Account. Additionally, consider enabling sensitive data threat detection for all Storage Accounts within a subscription.
","tags":["Azure.Storage.Defender.DataScan","AZR-000391"]},{"location":"en/rules/Azure.Storage.Defender.DataScan/#examples","title":"Examples","text":"","tags":["Azure.Storage.Defender.DataScan","AZR-000391"]},{"location":"en/rules/Azure.Storage.Defender.DataScan/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Storage Accounts that pass this rule:
Microsoft.Security/DefenderForStorageSettings
sub-resource (extension resource).properties.sensitiveDataDiscovery.isEnabled
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/defenderForStorageSettings\",\n \"apiVersion\": \"2022-12-01-preview\",\n \"scope\": \"[format('Microsoft.Storage/storageAccounts/{0}', parameters('name'))]\",\n \"name\": \"current\",\n \"properties\": {\n \"isEnabled\": true,\n \"malwareScanning\": {\n \"onUpload\": {\n \"isEnabled\": true,\n \"capGBPerMonth\": 5000\n }\n },\n \"sensitiveDataDiscovery\": {\n \"isEnabled\": true\n },\n \"overrideSubscriptionLevelSettings\": false\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Storage/storageAccounts', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.Storage.Defender.DataScan","AZR-000391"]},{"location":"en/rules/Azure.Storage.Defender.DataScan/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Storage Accounts that pass this rule:
Microsoft.Security/DefenderForStorageSettings
sub-resource (extension resource).properties.sensitiveDataDiscovery.isEnabled
property to true
.For example:
Azure Bicep snippetresource defenderForStorageSettings 'Microsoft.Security/defenderForStorageSettings@2022-12-01-preview' = {\n name: 'current'\n scope: storageAccount\n properties: {\n isEnabled: true\n malwareScanning: {\n onUpload: {\n isEnabled: true\n capGBPerMonth: 5000\n }\n }\n sensitiveDataDiscovery: {\n isEnabled: true\n }\n overrideSubscriptionLevelSettings: false\n }\n}\n
","tags":["Azure.Storage.Defender.DataScan","AZR-000391"]},{"location":"en/rules/Azure.Storage.Defender.DataScan/#notes","title":"Notes","text":"This feature is currently in preview.
The following limitations currently apply for Microsoft Defender for Storage:
properties.overrideSubscriptionLevelSettings
property to true
.Security \u00b7 Storage Account \u00b7 Rule \u00b7 2024_03 \u00b7 Critical
Enable Malware Scanning in Microsoft Defender for Storage.
","tags":["Azure.Storage.Defender.MalwareScan","AZR-000384"]},{"location":"en/rules/Azure.Storage.Defender.MalwareScan/#description","title":"Description","text":"Microsoft Defender for Storage provides additional security for storage accounts.
One of the features in the Defender for Storage service is malware scanning that is powered by Microsoft Defender Antivirus.
Content uploaded to cloud storage could be malware. Storage accounts can be a malware entry point into the organization and a malware distribution point. To protect organizations from this threat, content in cloud storage must be scanned for malware before it's accessed.
Malware Scanning in Defender for Storage helps protect storage accounts from malicious content by performing a full malware scan on uploaded content in near real time.
This can be helpful when:
When the malware scan identifies a malicious file, detailed Microsoft Defenders for Cloud security alerts are generated.
Malware Scanning in Microsoft Defender for Storage can be enabled at the resource level. However, the general recommendation is to enable it at the subscription level and by doing so ensures all storage accounts in the subscription will be protected, including future ones. Defender for Storage settings on each storage account is inherited by the subscription level settings.
It is also worth to mention that the resource level enablement can be useful when:
Consider enabling Malware Scanning using Microsoft Defender for Storage on the Storage Account. Alternatively, enable Malware Scanning for all Storage Accounts within a subscription.
","tags":["Azure.Storage.Defender.MalwareScan","AZR-000384"]},{"location":"en/rules/Azure.Storage.Defender.MalwareScan/#examples","title":"Examples","text":"","tags":["Azure.Storage.Defender.MalwareScan","AZR-000384"]},{"location":"en/rules/Azure.Storage.Defender.MalwareScan/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Storage Accounts that pass this rule:
Microsoft.Security/DefenderForStorageSettings
sub-resource (extension resource).properties.malwareScanning.onUpload.isEnabled
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/defenderForStorageSettings\",\n \"apiVersion\": \"2022-12-01-preview\",\n \"scope\": \"[format('Microsoft.Storage/storageAccounts/{0}', parameters('name'))]\",\n \"name\": \"current\",\n \"properties\": {\n \"isEnabled\": true,\n \"malwareScanning\": {\n \"onUpload\": {\n \"isEnabled\": true,\n \"capGBPerMonth\": 5000\n }\n },\n \"sensitiveDataDiscovery\": {\n \"isEnabled\": true\n },\n \"overrideSubscriptionLevelSettings\": false\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Storage/storageAccounts', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.Storage.Defender.MalwareScan","AZR-000384"]},{"location":"en/rules/Azure.Storage.Defender.MalwareScan/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Storage Accounts that pass this rule:
Microsoft.Security/DefenderForStorageSettings
sub-resource (extension resource).properties.malwareScanning.onUpload.isEnabled
property to true
.For example:
Azure Bicep snippetresource defenderForStorageSettings 'Microsoft.Security/defenderForStorageSettings@2022-12-01-preview' = {\n name: 'current'\n scope: storageAccount\n properties: {\n isEnabled: true\n malwareScanning: {\n onUpload: {\n isEnabled: true\n capGBPerMonth: 5000\n }\n }\n sensitiveDataDiscovery: {\n isEnabled: true\n }\n overrideSubscriptionLevelSettings: false\n }\n}\n
","tags":["Azure.Storage.Defender.MalwareScan","AZR-000384"]},{"location":"en/rules/Azure.Storage.Defender.MalwareScan/#notes","title":"Notes","text":"Not all services within storage accounts are currently supported.
overrideSubscriptionLevelSettings
value is false
, the resource level enablement will be ignored and the subscription level (plan) will still be used.overrideSubscriptionLevelSettings
value is true
, the resource level enablement will be honored and a dedicated plan will be configured for the storage account.Security \u00b7 Storage Account \u00b7 Rule \u00b7 2023_06 \u00b7 Critical
Enable Microsoft Defender for Storage for storage accounts.
","tags":["Azure.Storage.DefenderCloud","AZR-000386"]},{"location":"en/rules/Azure.Storage.DefenderCloud/#description","title":"Description","text":"Microsoft Defender for Storage analyzes data and control plane logs from protected Storage Accounts. Which allows Microsoft Defender for Cloud to surface findings with details of the security threats and contextual information.
Additionally, Microsoft Defender for Storage provides security extensions to analyze data stored within Storage Accounts:
Microsoft Defender for Storage can be enabled on a per subscription or per resource basis. Enabling at the subscription level is recommended because it protects current and future Storage Accounts. However, enabling at the resource level may be preferred for specific Storage Account to apply custom settings.
","tags":["Azure.Storage.DefenderCloud","AZR-000386"]},{"location":"en/rules/Azure.Storage.DefenderCloud/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for Storage to protect your data hosted in storage accounts. Additionally, consider using Microsoft Defender for Storage to protect all storage accounts within a subscription.
","tags":["Azure.Storage.DefenderCloud","AZR-000386"]},{"location":"en/rules/Azure.Storage.DefenderCloud/#examples","title":"Examples","text":"","tags":["Azure.Storage.DefenderCloud","AZR-000386"]},{"location":"en/rules/Azure.Storage.DefenderCloud/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy storage accounts that pass this rule:
Microsoft.Security/DefenderForStorageSettings
sub-resource (extension resource).properties.isEnabled
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/defenderForStorageSettings\",\n \"apiVersion\": \"2022-12-01-preview\",\n \"scope\": \"[format('Microsoft.Storage/storageAccounts/{0}', parameters('name'))]\",\n \"name\": \"current\",\n \"properties\": {\n \"isEnabled\": true,\n \"malwareScanning\": {\n \"onUpload\": {\n \"isEnabled\": true,\n \"capGBPerMonth\": 5000\n }\n },\n \"sensitiveDataDiscovery\": {\n \"isEnabled\": true\n },\n \"overrideSubscriptionLevelSettings\": false\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Storage/storageAccounts', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.Storage.DefenderCloud","AZR-000386"]},{"location":"en/rules/Azure.Storage.DefenderCloud/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy storage accounts that pass this rule:
Microsoft.Security/DefenderForStorageSettings
sub-resource (extension resource).properties.isEnabled
property to true
.For example:
Azure Bicep snippetresource defenderForStorageSettings 'Microsoft.Security/defenderForStorageSettings@2022-12-01-preview' = {\n name: 'current'\n scope: storageAccount\n properties: {\n isEnabled: true\n malwareScanning: {\n onUpload: {\n isEnabled: true\n capGBPerMonth: 5000\n }\n }\n sensitiveDataDiscovery: {\n isEnabled: true\n }\n overrideSubscriptionLevelSettings: false\n }\n}\n
","tags":["Azure.Storage.DefenderCloud","AZR-000386"]},{"location":"en/rules/Azure.Storage.DefenderCloud/#notes","title":"Notes","text":"The following limitations currently apply for Microsoft Defender for Storage:
Blob Storage
, Azure Files
and Azure Data Lake Storage Gen2
. Other storage types are not supported.properties.overrideSubscriptionLevelSettings
property to true
.AZURE_STORAGE_DEFENDER_PER_ACCOUNT
This rule is not processed by default because configuration at the subscription level is recommended. To enable this rule, set the AZURE_STORAGE_DEFENDER_PER_ACCOUNT
configuration value to true
.
Reliability \u00b7 Storage Account \u00b7 Rule \u00b7 2022_09 \u00b7 Important
","tags":["Azure.Storage.FileShareSoftDelete","AZR-000298"]},{"location":"en/rules/Azure.Storage.FileShareSoftDelete/#synopsis","title":"Synopsis","text":"Enable soft delete on Storage Accounts file shares.
","tags":["Azure.Storage.FileShareSoftDelete","AZR-000298"]},{"location":"en/rules/Azure.Storage.FileShareSoftDelete/#description","title":"Description","text":"Soft delete for Azure Files protects your shares from being accidentally deleted. This feature does not protect against individual files being deleted or modified. When soft delete is enabled for a Azure Files on a Storage Account, a share and its contents may be recovered after it has been deleted, within a retention period that you specify.
Soft delete on file shares should be considered part of the strategy to protect and retain data for Azure Files. Also consider:
Storage Accounts can be configured to retain deleted share for a period of time between 1 and 365 days.
","tags":["Azure.Storage.FileShareSoftDelete","AZR-000298"]},{"location":"en/rules/Azure.Storage.FileShareSoftDelete/#recommendation","title":"Recommendation","text":"Consider enabling soft delete on Azure Files to protect against accidental deletion of shares.
","tags":["Azure.Storage.FileShareSoftDelete","AZR-000298"]},{"location":"en/rules/Azure.Storage.FileShareSoftDelete/#examples","title":"Examples","text":"","tags":["Azure.Storage.FileShareSoftDelete","AZR-000298"]},{"location":"en/rules/Azure.Storage.FileShareSoftDelete/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Storage Accounts that pass this rule:
properties.deleteRetentionPolicy.enabled
property to true
on the fileServices
sub-resourceproperties.deleteRetentionPolicy.days
property to the number of days to retain files.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Storage/storageAccounts/fileServices\",\n \"apiVersion\": \"2022-05-01\",\n \"name\": \"default\",\n \"properties\": {\n \"shareDeleteRetentionPolicy\": {\n \"days\": \"7\",\n \"enabled\": \"true\"\n }\n }\n}\n
","tags":["Azure.Storage.FileShareSoftDelete","AZR-000298"]},{"location":"en/rules/Azure.Storage.FileShareSoftDelete/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Storage Accounts that pass this rule:
properties.deleteRetentionPolicy.enabled
property to true
on the fileServices
sub-resourceproperties.deleteRetentionPolicy.days
property to the number of days to retain files.For example:
Azure Bicep snippetresource fileServices 'Microsoft.Storage/storageAccounts/fileServices@2023-01-01' = {\n parent: storageAccount\n name: 'default'\n properties: {\n shareDeleteRetentionPolicy: {\n enabled: true\n days: 7\n }\n }\n}\n
","tags":["Azure.Storage.FileShareSoftDelete","AZR-000298"]},{"location":"en/rules/Azure.Storage.FileShareSoftDelete/#notes","title":"Notes","text":"Cloud Shell storage with the tag ms-resource-usage = 'azure-cloud-shell'
is excluded. Storage accounts used for Cloud Shell are not intended to store data.
Security \u00b7 Storage Account \u00b7 Rule \u00b7 2021_09 \u00b7 Important
Storage Accounts should only accept explicitly allowed traffic.
","tags":["Azure.Storage.Firewall","AZR-000202"]},{"location":"en/rules/Azure.Storage.Firewall/#description","title":"Description","text":"By default, storage accounts accept connections from clients on any network. To limit access to selected networks, you must first change the default action.
After changing the default action from Allow
to Deny
, configure one or more rules to allow traffic. Traffic can be allowed from:
Consider configuring storage firewall to restrict network access to permitted clients only. Also consider enforcing this setting using Azure Policy.
","tags":["Azure.Storage.Firewall","AZR-000202"]},{"location":"en/rules/Azure.Storage.Firewall/#examples","title":"Examples","text":"","tags":["Azure.Storage.Firewall","AZR-000202"]},{"location":"en/rules/Azure.Storage.Firewall/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Storage Accounts that pass this rule:
properties.networkAcls.defaultAction
property to Deny
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Storage/storageAccounts\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_GRS\"\n },\n \"kind\": \"StorageV2\",\n \"properties\": {\n \"allowBlobPublicAccess\": false,\n \"supportsHttpsTrafficOnly\": true,\n \"minimumTlsVersion\": \"TLS1_2\",\n \"accessTier\": \"Hot\",\n \"allowSharedKeyAccess\": false,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n }\n }\n}\n
","tags":["Azure.Storage.Firewall","AZR-000202"]},{"location":"en/rules/Azure.Storage.Firewall/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Storage Accounts that pass this rule:
properties.networkAcls.defaultAction
property to Deny
.For example:
Azure Bicep snippetresource storageAccount 'Microsoft.Storage/storageAccounts@2023-01-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard_GRS'\n }\n kind: 'StorageV2'\n properties: {\n allowBlobPublicAccess: false\n supportsHttpsTrafficOnly: true\n minimumTlsVersion: 'TLS1_2'\n accessTier: 'Hot'\n allowSharedKeyAccess: false\n networkAcls: {\n defaultAction: 'Deny'\n }\n }\n}\n
","tags":["Azure.Storage.Firewall","AZR-000202"]},{"location":"en/rules/Azure.Storage.Firewall/#notes","title":"Notes","text":"Cloud Shell storage with the tag ms-resource-usage = 'azure-cloud-shell'
is excluded. Azure storage firewall is not supported for Cloud Shell storage accounts.
Security \u00b7 Storage Account \u00b7 Rule \u00b7 2020_09 \u00b7 Critical
Storage Accounts should reject TLS versions older than 1.2.
","tags":["Azure.Storage.MinTLS","AZR-000200"]},{"location":"en/rules/Azure.Storage.MinTLS/#description","title":"Description","text":"The minimum version of TLS that Azure Storage Accounts accept for blob storage is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Storage Accounts lets you disable outdated protocols and enforce TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 is accepted.
","tags":["Azure.Storage.MinTLS","AZR-000200"]},{"location":"en/rules/Azure.Storage.MinTLS/#recommendation","title":"Recommendation","text":"Consider configuring the minimum supported TLS version to be 1.2. Also consider enforcing this setting using Azure Policy.
","tags":["Azure.Storage.MinTLS","AZR-000200"]},{"location":"en/rules/Azure.Storage.MinTLS/#examples","title":"Examples","text":"","tags":["Azure.Storage.MinTLS","AZR-000200"]},{"location":"en/rules/Azure.Storage.MinTLS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Storage Accounts that pass this rule:
properties.minimumTlsVersion
property to TLS1_2
or newer.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Storage/storageAccounts\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_GRS\"\n },\n \"kind\": \"StorageV2\",\n \"properties\": {\n \"allowBlobPublicAccess\": false,\n \"supportsHttpsTrafficOnly\": true,\n \"minimumTlsVersion\": \"TLS1_2\",\n \"accessTier\": \"Hot\",\n \"allowSharedKeyAccess\": false,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n }\n }\n}\n
","tags":["Azure.Storage.MinTLS","AZR-000200"]},{"location":"en/rules/Azure.Storage.MinTLS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Storage Accounts that pass this rule:
properties.minimumTlsVersion
property to TLS1_2
or newer.For example:
Azure Bicep snippetresource storageAccount 'Microsoft.Storage/storageAccounts@2023-01-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard_GRS'\n }\n kind: 'StorageV2'\n properties: {\n allowBlobPublicAccess: false\n supportsHttpsTrafficOnly: true\n minimumTlsVersion: 'TLS1_2'\n accessTier: 'Hot'\n allowSharedKeyAccess: false\n networkAcls: {\n defaultAction: 'Deny'\n }\n }\n}\n
","tags":["Azure.Storage.MinTLS","AZR-000200"]},{"location":"en/rules/Azure.Storage.MinTLS/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/fe83a0eb-a853-422d-aac2-1bffd182c5d0
Operational Excellence \u00b7 Storage Account \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Storage Account names should meet naming requirements.
","tags":["Azure.Storage.Name","AZR-000201"]},{"location":"en/rules/Azure.Storage.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Storage Account names are:
Consider using names that meet Storage Account naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.Storage.Name","AZR-000201"]},{"location":"en/rules/Azure.Storage.Name/#notes","title":"Notes","text":"This rule does not check if Storage Account names are unique.
","tags":["Azure.Storage.Name","AZR-000201"]},{"location":"en/rules/Azure.Storage.Name/#links","title":"Links","text":"Security \u00b7 Storage Account \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Storage accounts should only accept encrypted connections.
","tags":["Azure.Storage.SecureTransfer","AZR-000196"]},{"location":"en/rules/Azure.Storage.SecureTransfer/#description","title":"Description","text":"Azure Storage Accounts can be configured to allow unencrypted connections. Unencrypted communication could allow disclosure of information to an un-trusted party. Storage Accounts can be configured to require encrypted connections.
To do this set the Secure transfer required option. When secure transfer required is enabled, attempts to connect to storage using HTTP or unencrypted SMB connections are rejected.
Storage Accounts that are deployed with a newer API version will have this option enabled by default. However, this does not prevent the option from being disabled.
","tags":["Azure.Storage.SecureTransfer","AZR-000196"]},{"location":"en/rules/Azure.Storage.SecureTransfer/#recommendation","title":"Recommendation","text":"Storage accounts should only accept secure traffic. Consider only accepting encrypted connections by setting the Secure transfer required option. Also consider using Azure Policy to audit or enforce this configuration.
","tags":["Azure.Storage.SecureTransfer","AZR-000196"]},{"location":"en/rules/Azure.Storage.SecureTransfer/#examples","title":"Examples","text":"","tags":["Azure.Storage.SecureTransfer","AZR-000196"]},{"location":"en/rules/Azure.Storage.SecureTransfer/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Storage Accounts that pass this rule:
properties.supportsHttpsTrafficOnly
property to true
.properties.supportsHttpsTrafficOnly
property ORproperties.supportsHttpsTrafficOnly
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Storage/storageAccounts\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_GRS\"\n },\n \"kind\": \"StorageV2\",\n \"properties\": {\n \"allowBlobPublicAccess\": false,\n \"supportsHttpsTrafficOnly\": true,\n \"minimumTlsVersion\": \"TLS1_2\",\n \"accessTier\": \"Hot\",\n \"allowSharedKeyAccess\": false,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n }\n }\n}\n
","tags":["Azure.Storage.SecureTransfer","AZR-000196"]},{"location":"en/rules/Azure.Storage.SecureTransfer/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Storage Accounts that pass this rule:
properties.supportsHttpsTrafficOnly
property to true
.properties.supportsHttpsTrafficOnly
property ORproperties.supportsHttpsTrafficOnly
property to true
.For example:
Azure Bicep snippetresource storageAccount 'Microsoft.Storage/storageAccounts@2023-01-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard_GRS'\n }\n kind: 'StorageV2'\n properties: {\n allowBlobPublicAccess: false\n supportsHttpsTrafficOnly: true\n minimumTlsVersion: 'TLS1_2'\n accessTier: 'Hot'\n allowSharedKeyAccess: false\n networkAcls: {\n defaultAction: 'Deny'\n }\n }\n}\n
","tags":["Azure.Storage.SecureTransfer","AZR-000196"]},{"location":"en/rules/Azure.Storage.SecureTransfer/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/404c3081-a854-4457-ae30-26a93ef643f9
/providers/Microsoft.Authorization/policyDefinitions/f81e3117-0093-4b17-8a60-82363134f0eb
Reliability \u00b7 Storage Account \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Enable blob soft delete on Storage Accounts.
","tags":["Azure.Storage.SoftDelete","AZR-000197"]},{"location":"en/rules/Azure.Storage.SoftDelete/#description","title":"Description","text":"Soft delete provides an easy way to recover deleted or modified blob data stored within Storage Accounts. When soft delete is enabled, deleted blobs are kept and can be restored within the configured interval.
Blob soft delete should be considered part of the strategy to protect and retain data. Also consider:
Blobs can be configured to retain deleted blobs for a period of time between 1 and 365 days.
","tags":["Azure.Storage.SoftDelete","AZR-000197"]},{"location":"en/rules/Azure.Storage.SoftDelete/#recommendation","title":"Recommendation","text":"Consider enabling soft delete on storage accounts to protect blobs from accidental deletion or modification.
","tags":["Azure.Storage.SoftDelete","AZR-000197"]},{"location":"en/rules/Azure.Storage.SoftDelete/#examples","title":"Examples","text":"","tags":["Azure.Storage.SoftDelete","AZR-000197"]},{"location":"en/rules/Azure.Storage.SoftDelete/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Storage Accounts that pass this rule:
properties.deleteRetentionPolicy.enabled
property to true
on the blob services sub-resource.properties.deleteRetentionPolicy.days
property to the number of days to retain blobs.{\n \"type\": \"Microsoft.Storage/storageAccounts\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_GRS\"\n },\n \"kind\": \"StorageV2\",\n \"properties\": {\n \"allowBlobPublicAccess\": false,\n \"supportsHttpsTrafficOnly\": true,\n \"minimumTlsVersion\": \"TLS1_2\",\n \"accessTier\": \"Hot\",\n \"allowSharedKeyAccess\": false,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Storage/storageAccounts/blobServices\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'default')]\",\n \"properties\": {\n \"deleteRetentionPolicy\": {\n \"enabled\": true,\n \"days\": 7\n },\n \"containerDeleteRetentionPolicy\": {\n \"enabled\": true,\n \"days\": 7\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Storage/storageAccounts', parameters('name'))]\"\n ]\n }\n ]\n}\n
","tags":["Azure.Storage.SoftDelete","AZR-000197"]},{"location":"en/rules/Azure.Storage.SoftDelete/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Storage Accounts that pass this rule:
properties.deleteRetentionPolicy.enabled
property to true
on the blob services sub-resource.properties.deleteRetentionPolicy.days
property to the number of days to retain blobs.For example:
Azure Bicep snippetresource storageAccount 'Microsoft.Storage/storageAccounts@2023-01-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard_GRS'\n }\n kind: 'StorageV2'\n properties: {\n allowBlobPublicAccess: false\n supportsHttpsTrafficOnly: true\n minimumTlsVersion: 'TLS1_2'\n accessTier: 'Hot'\n allowSharedKeyAccess: false\n networkAcls: {\n defaultAction: 'Deny'\n }\n }\n}\n\nresource blobService 'Microsoft.Storage/storageAccounts/blobServices@2023-01-01' = {\n parent: storageAccount\n name: 'default'\n properties: {\n deleteRetentionPolicy: {\n enabled: true\n days: 7\n }\n containerDeleteRetentionPolicy: {\n enabled: true\n days: 7\n }\n }\n}\n
","tags":["Azure.Storage.SoftDelete","AZR-000197"]},{"location":"en/rules/Azure.Storage.SoftDelete/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz storage account blob-service-properties update --enable-delete-retention true --delete-retention-days 7 -n '<name>' -g '<resource_group>'\n
","tags":["Azure.Storage.SoftDelete","AZR-000197"]},{"location":"en/rules/Azure.Storage.SoftDelete/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetEnable-AzStorageBlobDeleteRetentionPolicy -ResourceGroupName '<resource_group>' -AccountName '<name>' -RetentionDays 7\n
","tags":["Azure.Storage.SoftDelete","AZR-000197"]},{"location":"en/rules/Azure.Storage.SoftDelete/#notes","title":"Notes","text":"Cloud Shell storage with the tag ms-resource-usage = 'azure-cloud-shell'
is excluded. Storage accounts used for Cloud Shell are not intended to store data.
Storage accounts with:
FileStorage
storage account do not support blob soft delete.Reliability \u00b7 Storage Account \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Storage Accounts not using geo-replicated storage (GRS) may be at risk.
","tags":["Azure.Storage.UseReplication","AZR-000195"]},{"location":"en/rules/Azure.Storage.UseReplication/#description","title":"Description","text":"Storage Accounts can be configured with several different durability options. Azure provides a number of geo-replicated options including; Geo-redundant storage and geo-zone-redundant storage. Geo-zone-redundant storage is only available in supported regions.
The following geo-replicated options are available within Azure:
Standard_GRS
Standard_RAGRS
Standard_GZRS
Standard_RAGZRS
Consider using GRS for storage accounts that contain data.
","tags":["Azure.Storage.UseReplication","AZR-000195"]},{"location":"en/rules/Azure.Storage.UseReplication/#examples","title":"Examples","text":"","tags":["Azure.Storage.UseReplication","AZR-000195"]},{"location":"en/rules/Azure.Storage.UseReplication/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Storage Accounts that pass this rule:
sku.name
property to a geo-replicated SKU. Such as Standard_GRS
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Storage/storageAccounts\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_GRS\"\n },\n \"kind\": \"StorageV2\",\n \"properties\": {\n \"allowBlobPublicAccess\": false,\n \"supportsHttpsTrafficOnly\": true,\n \"minimumTlsVersion\": \"TLS1_2\",\n \"accessTier\": \"Hot\",\n \"allowSharedKeyAccess\": false,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n }\n }\n}\n
","tags":["Azure.Storage.UseReplication","AZR-000195"]},{"location":"en/rules/Azure.Storage.UseReplication/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Storage Accounts that pass this rule:
sku.name
property to a geo-replicated SKU. Such as Standard_GRS
.For example:
Azure Bicep snippetresource storageAccount 'Microsoft.Storage/storageAccounts@2023-01-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard_GRS'\n }\n kind: 'StorageV2'\n properties: {\n allowBlobPublicAccess: false\n supportsHttpsTrafficOnly: true\n minimumTlsVersion: 'TLS1_2'\n accessTier: 'Hot'\n allowSharedKeyAccess: false\n networkAcls: {\n defaultAction: 'Deny'\n }\n }\n}\n
","tags":["Azure.Storage.UseReplication","AZR-000195"]},{"location":"en/rules/Azure.Storage.UseReplication/#notes","title":"Notes","text":"This rule is not applicable for premium storage accounts. Storage Accounts with the following tags are automatically excluded from this rule:
ms-resource-usage = 'azure-cloud-shell'
- Storage Accounts used for Cloud Shell are not intended to store data. This tag is applied by Azure to Cloud Shell Storage Accounts by default.resource-usage = 'azure-functions'
- Storage Accounts used for Azure Functions. This tag can be optionally configured.resource-usage = 'azure-monitor'
- Storage Accounts used by Azure Monitor are intended for diagnostic logs. This tag can be optionally configured.Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_03 \u00b7 Awareness
Use default deployment detail level for nested deployments.
","tags":["Azure.Template.DebugDeployment","AZR-000225"]},{"location":"en/rules/Azure.Template.DebugDeployment/#description","title":"Description","text":"When creating Azure template, nested deployments can be created with debugging settings enabled. Deployment debugging detail is intended for troubleshooting deployments during development. Debugging settings may log sensitive values. Use caution when using this setting to debug of nested deployments.
To reduce nested deployment detail, remove or configure the properties.debugSetting.detailLevel
property to none
for nested deployments.
Consider disabling debugging of nested deployments before release.
","tags":["Azure.Template.DebugDeployment","AZR-000225"]},{"location":"en/rules/Azure.Template.DebugDeployment/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_03 \u00b7 Awareness
Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters.
","tags":["Azure.Template.DefineParameters","AZR-000218"]},{"location":"en/rules/Azure.Template.DefineParameters/#description","title":"Description","text":"Azure templates support parameters, which are inputs you can specify when deploying the template resources. Each template can support up to 256 parameters.
When defining template parameters:
defaultValue
.Consider defining a minimal number of parameters to make the template reusable.
","tags":["Azure.Template.DefineParameters","AZR-000218"]},{"location":"en/rules/Azure.Template.DefineParameters/#examples","title":"Examples","text":"","tags":["Azure.Template.DefineParameters","AZR-000218"]},{"location":"en/rules/Azure.Template.DefineParameters/#configure-with-azure-template","title":"Configure with Azure template","text":"To author templates that pass this rule:
For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"metadata\": {\n \"name\": \"Managed Identity\",\n \"description\": \"Create or update a Managed Identity.\"\n },\n \"parameters\": {\n \"identityName\": {\n \"type\": \"string\",\n \"metadata\": {\n \"description\": \"The name of the Managed Identity.\"\n }\n },\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"The Azure region to deploy to.\",\n \"example\": \"eastus\"\n }\n },\n \"tags\": {\n \"type\": \"object\",\n \"metadata\": {\n \"description\": \"Tags to apply to the resource.\",\n \"example\": {\n \"service\": \"app1\",\n \"env\": \"prod\"\n }\n }\n }\n },\n \"variables\": {\n \"tenantId\": \"[subscription().tenantId]\"\n },\n \"resources\": [\n {\n \"comments\": \"Create or update a Managed Identity\",\n \"type\": \"Microsoft.ManagedIdentity/userAssignedIdentities\",\n \"apiVersion\": \"2018-11-30\",\n \"name\": \"[parameters('identityName')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"tenantId\": \"[variables('tenantId')]\"\n },\n \"tags\": \"[parameters('tags')]\"\n }\n ]\n}\n
","tags":["Azure.Template.DefineParameters","AZR-000218"]},{"location":"en/rules/Azure.Template.DefineParameters/#notes","title":"Notes","text":"This rule is not applicable and ignored for templates generated with Bicep, PSArm and AzOps. Generated templates from these tools may not require any parameters to be set.
","tags":["Azure.Template.DefineParameters","AZR-000218"]},{"location":"en/rules/Azure.Template.DefineParameters/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_12 \u00b7 Awareness
Template expressions should not exceed the maximum length.
","tags":["Azure.Template.ExpressionLength","AZR-000228"]},{"location":"en/rules/Azure.Template.ExpressionLength/#description","title":"Description","text":"Extremely long expressions may be difficult to read and debug. Avoid using expressions that exceed 24,576 characters in length.
","tags":["Azure.Template.ExpressionLength","AZR-000228"]},{"location":"en/rules/Azure.Template.ExpressionLength/#recommendation","title":"Recommendation","text":"Consider updating the expression to reduce complexity and length.
","tags":["Azure.Template.ExpressionLength","AZR-000228"]},{"location":"en/rules/Azure.Template.ExpressionLength/#notes","title":"Notes","text":"This rule is not applicable and ignored for templates generated with Bicep, PSArm, and AzOps. Generated templates from these tools may not require any parameters to be set.
","tags":["Azure.Template.ExpressionLength","AZR-000228"]},{"location":"en/rules/Azure.Template.ExpressionLength/#links","title":"Links","text":"Reliability \u00b7 All resources \u00b7 Rule \u00b7 2021_03 \u00b7 Awareness
Set the default value for the location parameter within an ARM template to resource group location.
","tags":["Azure.Template.LocationDefault","AZR-000220"]},{"location":"en/rules/Azure.Template.LocationDefault/#description","title":"Description","text":"In the event of a regional outage in the resource group location, you will be unable to control resources inside that resource group, regardless of what region those resources are actually in. Resources for regional services should be deployed into a resource group on the same region.
When authoring templates, the resource group location should be the default resource location. This approach minimizes the number of times users are asked to provide location information.
","tags":["Azure.Template.LocationDefault","AZR-000220"]},{"location":"en/rules/Azure.Template.LocationDefault/#recommendation","title":"Recommendation","text":"Consider updating the location
parameter to use [resourceGroup().location]
as the default value.
To author templates that pass this rule:
location
parameter is specified, it should be set to [resourceGroup().location]
.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"The location resources will be deployed.\"\n }\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Network/networkSecurityGroups\",\n \"apiVersion\": \"2021-02-01\",\n \"name\": \"nsg-001\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"securityRules\": [\n {\n \"name\": \"deny-hop-outbound\",\n \"properties\": {\n \"priority\": 200,\n \"access\": \"Deny\",\n \"protocol\": \"Tcp\",\n \"direction\": \"Outbound\",\n \"sourceAddressPrefix\": \"VirtualNetwork\",\n \"destinationAddressPrefix\": \"*\",\n \"destinationPortRanges\": [\n \"3389\",\n \"22\"\n ]\n }\n }\n ]\n }\n }\n ]\n}\n
","tags":["Azure.Template.LocationDefault","AZR-000220"]},{"location":"en/rules/Azure.Template.LocationDefault/#configure-with-bicep","title":"Configure with Bicep","text":"To author bicep source files that pass this rule:
location
parameter is specified, it should be set to resourceGroup().location
.For example:
Azure Bicep snippet@description('The location resources will be deployed.')\nparam location string = resourceGroup().location\n
","tags":["Azure.Template.LocationDefault","AZR-000220"]},{"location":"en/rules/Azure.Template.LocationDefault/#notes","title":"Notes","text":"This rule ignores templates using tenant, Management Group, and Subscription deployment schemas. Deployment to these scopes does not occur against a resource group.
","tags":["Azure.Template.LocationDefault","AZR-000220"]},{"location":"en/rules/Azure.Template.LocationDefault/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_03 \u00b7 Important
Location parameters should use a string value.
","tags":["Azure.Template.LocationType","AZR-000221"]},{"location":"en/rules/Azure.Template.LocationType/#description","title":"Description","text":"The template parameter location
is a standard parameter recommended for deployment templates. The location
parameter is a intended for specifying the deployment location of the primary resource. When including location parameters in templates use the type string
.
Additionally, the template may include other resources. Use the location
parameter value for resources that are likely to be in the same location. This approach minimizes the number of times users are asked to provide location information.
Consider updating the location
parameter to be of type string
.
To author templates that pass this rule:
location
parameter is specified, it should be set to a string
type.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"The location resources will be deployed.\"\n }\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Network/networkSecurityGroups\",\n \"apiVersion\": \"2021-02-01\",\n \"name\": \"nsg-001\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"securityRules\": [\n {\n \"name\": \"deny-hop-outbound\",\n \"properties\": {\n \"priority\": 200,\n \"access\": \"Deny\",\n \"protocol\": \"Tcp\",\n \"direction\": \"Outbound\",\n \"sourceAddressPrefix\": \"VirtualNetwork\",\n \"destinationAddressPrefix\": \"*\",\n \"destinationPortRanges\": [\n \"3389\",\n \"22\"\n ]\n }\n }\n ]\n }\n }\n ]\n}\n
","tags":["Azure.Template.LocationType","AZR-000221"]},{"location":"en/rules/Azure.Template.LocationType/#configure-with-bicep","title":"Configure with Bicep","text":"To author bicep source files that pass this rule:
location
parameter is specified, it should be set to a string
type.For example:
Azure Bicep snippet@description('The location resources will be deployed.')\nparam location string = resourceGroup().location\n
","tags":["Azure.Template.LocationType","AZR-000221"]},{"location":"en/rules/Azure.Template.LocationType/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_09 \u00b7 Important
Configure a metadata link for each parameter file.
","tags":["Azure.Template.MetadataLink","AZR-000231"]},{"location":"en/rules/Azure.Template.MetadataLink/#description","title":"Description","text":"A parameter file can include an additional metadata. This metadata provides additional context for use of the parameter file.
PSRule for Azure uses the metadata.template
property within parameter files to store a metadata link. A metadata link, is an explicit association between a parameter file it's intended template file.
This rule is disabled by default but can be enabled by configuring AZURE_PARAMETER_FILE_METADATA_LINK
. Enable this rule to ensure that each parameter file has a metadata link to a valid template file.
Consider setting metadata for each parameter file linking to the deployment template.
","tags":["Azure.Template.MetadataLink","AZR-000231"]},{"location":"en/rules/Azure.Template.MetadataLink/#examples","title":"Examples","text":"","tags":["Azure.Template.MetadataLink","AZR-000231"]},{"location":"en/rules/Azure.Template.MetadataLink/#configure-parameter-file","title":"Configure parameter file","text":"To create parameter files that pass this rule:
metadata.template
property to a valid template file path.For example:
Azure Template snippet{\n \"$schema\": \"http://schema.management.azure.com/schemas/2015-01-01/deploymentParameters.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"metadata\": {\n \"template\": \"templates/storage/v1/template.json\"\n },\n \"parameters\": {\n \"storageAccountName\": {\n \"value\": \"...\"\n }\n }\n}\n
","tags":["Azure.Template.MetadataLink","AZR-000231"]},{"location":"en/rules/Azure.Template.MetadataLink/#notes","title":"Notes","text":"Enable this rule by setting the AZURE_PARAMETER_FILE_METADATA_LINK
option to true
.
Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_03 \u00b7 Important
Set the parameter default value to a value of the same type.
","tags":["Azure.Template.ParameterDataTypes","AZR-000226"]},{"location":"en/rules/Azure.Template.ParameterDataTypes/#description","title":"Description","text":"Azure Resource Manager (ARM) template support parameters with a range of types, including:
bool
int
string
array
object
secureString
secureObject
When including a defaultValue
, the default value should match the same type at the type
property. For example:
{\n \"boolParam\": {\n \"type\": \"bool\",\n \"defaultValue\": false\n },\n \"intParam\": {\n \"type\": \"int\",\n \"defaultValue\": 5\n },\n \"stringParam\": {\n \"type\": \"string\",\n \"defaultValue\": \"test-rg\"\n },\n \"arrayParam\": {\n \"type\": \"array\",\n \"defaultValue\": [ 1, 2, 3 ]\n },\n \"objectParam\": {\n \"type\": \"object\",\n \"defaultValue\": {\n \"one\": \"a\",\n \"two\": \"b\"\n }\n }\n}\n
","tags":["Azure.Template.ParameterDataTypes","AZR-000226"]},{"location":"en/rules/Azure.Template.ParameterDataTypes/#recommendation","title":"Recommendation","text":"Consider updating the parameter default value to a value of the same type.
","tags":["Azure.Template.ParameterDataTypes","AZR-000226"]},{"location":"en/rules/Azure.Template.ParameterDataTypes/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use ARM template parameter files that are valid.
","tags":["Azure.Template.ParameterFile","AZR-000229"]},{"location":"en/rules/Azure.Template.ParameterFile/#description","title":"Description","text":"Azure Resource Manager (ARM) template parameter files have a pre-defined structure. ARM template parameter files require $schema
, contentVersion
and parameters
sections to be defined. If any of these sections are missing, ARM will not accept the parameter file.
Consider reviewing the requirements for this file. Also consider using Visual Studio Code to assist with authoring these files.
","tags":["Azure.Template.ParameterFile","AZR-000229"]},{"location":"en/rules/Azure.Template.ParameterFile/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2020_09 \u00b7 Awareness
Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter.
","tags":["Azure.Template.ParameterMetadata","AZR-000215"]},{"location":"en/rules/Azure.Template.ParameterMetadata/#description","title":"Description","text":"ARM templates supports an additional metadata description to be added to each parameter. The parameter description is visible in Azure when using portal deployment pages. Additionally, descriptions provide context for people editing template and parameter files.
For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"storageAccountType\": {\n \"type\": \"string\",\n \"metadata\": {\n \"description\": \"The type of the new storage account created to store the VM disks.\"\n }\n }\n }\n}\n
","tags":["Azure.Template.ParameterMetadata","AZR-000215"]},{"location":"en/rules/Azure.Template.ParameterMetadata/#recommendation","title":"Recommendation","text":"Consider defining a metadata description for each template parameter.
","tags":["Azure.Template.ParameterMetadata","AZR-000215"]},{"location":"en/rules/Azure.Template.ParameterMetadata/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_03 \u00b7 Important
Template parameters minValue
and maxValue
constraints must be valid.
When defining Azure template parameters the minValue
or maxValue
constraints can be added to parameters. These constraints are only valid for parameters using the int
type. When configuring minValue
and maxValue
an integer must be used.
Consider updating parameter definitions using minValue
or maxValue
. When using minValue
or maxValue
these values must be integers and only apply to int
parameters.
Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_09 \u00b7 Awareness
Use an Azure template parameter file schema with the https scheme.
","tags":["Azure.Template.ParameterScheme","AZR-000230"]},{"location":"en/rules/Azure.Template.ParameterScheme/#description","title":"Description","text":"JSON schemas are used to validate the structure of Azure template parameter files. The JSON schema specification permits schemas to use https or http schemes. When using referencing schemas served by schema.management.azure.com
the http scheme redirects to https.
While http://schema.management.azure.com/schemas/2019-04-01/deploymentParameters.json#
points to a file. All supported Azure template parameter schemas use the https scheme.
Consider using a schema with the https scheme.
","tags":["Azure.Template.ParameterScheme","AZR-000230"]},{"location":"en/rules/Azure.Template.ParameterScheme/#examples","title":"Examples","text":"","tags":["Azure.Template.ParameterScheme","AZR-000230"]},{"location":"en/rules/Azure.Template.ParameterScheme/#configure-with-azure-template","title":"Configure with Azure template","text":"To define Azure template parameter files that pass this rule:
https://
URI prefix, such as https://schema.management.azure.com/schemas/2019-04-01/deploymentParameters.json#
.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentParameters.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": { }\n}\n
","tags":["Azure.Template.ParameterScheme","AZR-000230"]},{"location":"en/rules/Azure.Template.ParameterScheme/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_12 \u00b7 Awareness
Set the parameter value to a value that matches the specified strong type.
","tags":["Azure.Template.ParameterStrongType","AZR-000227"]},{"location":"en/rules/Azure.Template.ParameterStrongType/#description","title":"Description","text":"Template string parameters can optionally specify a strong type. When parameter files are expanded, if the parameter value does not match the type this rule fails. Support is provided by PSRule for Azure for the following types:
Microsoft.OperationalInsights/workspaces
. If a resource type is specified the parameter value must be a resource id of that type.location
as the strong type. If location
is specified, the parameter value must be a valid Azure location.Consider updating the parameter value to a value that matches the specifed strong type.
","tags":["Azure.Template.ParameterStrongType","AZR-000227"]},{"location":"en/rules/Azure.Template.ParameterStrongType/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_09 \u00b7 Awareness
Specify a value for each parameter in template parameter files.
","tags":["Azure.Template.ParameterValue","AZR-000232"]},{"location":"en/rules/Azure.Template.ParameterValue/#description","title":"Description","text":"When defining a template parameter file:
Consider defining a value for each parameter in the template parameter file.
","tags":["Azure.Template.ParameterValue","AZR-000232"]},{"location":"en/rules/Azure.Template.ParameterValue/#examples","title":"Examples","text":"","tags":["Azure.Template.ParameterValue","AZR-000232"]},{"location":"en/rules/Azure.Template.ParameterValue/#configure-with-azure-template","title":"Configure with Azure template","text":"To define Azure template parameter files that pass this rule:
For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentParameters.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"parameter1\": {\n \"value\": \"value1\"\n },\n \"parameter2\": {\n \"value\": []\n }\n }\n}\n
","tags":["Azure.Template.ParameterValue","AZR-000232"]},{"location":"en/rules/Azure.Template.ParameterValue/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_03 \u00b7 Awareness
Template resource location should be an expression or global
.
The template parameter location
is a standard parameter recommended for deployment templates. The location
parameter is a intended for specifying the deployment location of the primary resource.
When defining a resource that requires a location, use the location
parameter. For example:
{\n \"type\": \"Microsoft.Network/virtualNetworks\",\n \"name\": \"[parameters('VNETName')]\",\n \"apiVersion\": \"2020-06-01\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {}\n}\n
Additionally, the template may include other resources. Use the location
parameter value for resources that are likely to be in the same location. This approach minimizes the number of times users are asked to provide location information. For resources that aren't available in all locations, use a separate parameter.
For non-regional resources such as Front Door and DNS Zones specify a literal location global
.
Consider updating the resource location
property to use [parameters('location)]
.
Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2020_09 \u00b7 Awareness
Each Azure Resource Manager (ARM) template file should deploy at least one resource.
","tags":["Azure.Template.Resources","AZR-000216"]},{"location":"en/rules/Azure.Template.Resources/#description","title":"Description","text":"An ARM template file is used to create or update one or more Azure resources. The resources
property of an ARM template includes a definition of the resources to deploy.
Consider removing Azure template files that do not deploy any resources.
","tags":["Azure.Template.Resources","AZR-000216"]},{"location":"en/rules/Azure.Template.Resources/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use ARM template files that are valid.
","tags":["Azure.Template.TemplateFile","AZR-000212"]},{"location":"en/rules/Azure.Template.TemplateFile/#description","title":"Description","text":"Azure Resource Manager (ARM) template files have a pre-defined structure. ARM templates require $schema
, contentVersion
and resources
sections to be defined. If any of these sections are missing, ARM will not accept the template.
Consider reviewing the requirements for this file. Also consider using Visual Studio Code to assist with authoring these files.
","tags":["Azure.Template.TemplateFile","AZR-000212"]},{"location":"en/rules/Azure.Template.TemplateFile/#examples","title":"Examples","text":"","tags":["Azure.Template.TemplateFile","AZR-000212"]},{"location":"en/rules/Azure.Template.TemplateFile/#configure-with-azure-template","title":"Configure with Azure template","text":"To define Azure template files that pass this rule:
$schema
, contentVersion
and resources
properties.languageVersion
, definitions
, metadata
, parameters
, functions
, variables
, and outputs
properties.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": { },\n \"variables\": { },\n \"resources\": [ ]\n}\n
","tags":["Azure.Template.TemplateFile","AZR-000212"]},{"location":"en/rules/Azure.Template.TemplateFile/#notes","title":"Notes","text":"This rule is not applicable to Azure Bicep files as they have a different structure. If you are running analysis over pre-built Bicep files and they generate a rule failure, please raise an issue.
","tags":["Azure.Template.TemplateFile","AZR-000212"]},{"location":"en/rules/Azure.Template.TemplateFile/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_09 \u00b7 Awareness
Use a more recent version of the Azure template schema.
","tags":["Azure.Template.TemplateSchema","AZR-000213"]},{"location":"en/rules/Azure.Template.TemplateSchema/#description","title":"Description","text":"The JSON schemas used to define Azure templates are versioned. When defining templates use templates with a supported schema.
The following template schemas are deprecated:
https://schema.management.azure.com/schemas/2015-01-01/deploymentTemplate.json#
Consider using a more recent schema version for Azure template files.
","tags":["Azure.Template.TemplateSchema","AZR-000213"]},{"location":"en/rules/Azure.Template.TemplateSchema/#examples","title":"Examples","text":"","tags":["Azure.Template.TemplateSchema","AZR-000213"]},{"location":"en/rules/Azure.Template.TemplateSchema/#configure-with-azure-template","title":"Configure with Azure template","text":"To define Azure template files that pass this rule:
https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#
https://schema.management.azure.com/schemas/2018-05-01/subscriptionDeploymentTemplate.json#
https://schema.management.azure.com/schemas/2019-08-01/tenantDeploymentTemplate.json#
https://schema.management.azure.com/schemas/2019-08-01/managementGroupDeploymentTemplate.json#
For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": { },\n \"functions\": [],\n \"resources\": [ ]\n}\n
","tags":["Azure.Template.TemplateSchema","AZR-000213"]},{"location":"en/rules/Azure.Template.TemplateSchema/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_09 \u00b7 Awareness
Use an Azure template file schema with the https scheme.
","tags":["Azure.Template.TemplateScheme","AZR-000214"]},{"location":"en/rules/Azure.Template.TemplateScheme/#description","title":"Description","text":"JSON schemas are used to validate the structure of Azure template files. The JSON schema specification permits schemas to use https or http schemes. When using referencing schemas served by schema.management.azure.com
the http scheme redirects to https.
While http://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#
points to a file. All supported Azure template schemas use the https scheme.
Consider using a schema with the https scheme.
","tags":["Azure.Template.TemplateScheme","AZR-000214"]},{"location":"en/rules/Azure.Template.TemplateScheme/#examples","title":"Examples","text":"","tags":["Azure.Template.TemplateScheme","AZR-000214"]},{"location":"en/rules/Azure.Template.TemplateScheme/#configure-with-azure-template","title":"Configure with Azure template","text":"To define Azure template files that pass this rule:
https://
URI prefix, such as https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#
.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": { },\n \"functions\": [],\n \"resources\": [ ]\n}\n
","tags":["Azure.Template.TemplateScheme","AZR-000214"]},{"location":"en/rules/Azure.Template.TemplateScheme/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_12 \u00b7 Awareness
Use comments for each resource in ARM template to communicate purpose.
","tags":["Azure.Template.UseComments","AZR-000234"]},{"location":"en/rules/Azure.Template.UseComments/#description","title":"Description","text":"ARM templates can optionally include comments in resources. This helps other contributors understand the purpose of the resource.
","tags":["Azure.Template.UseComments","AZR-000234"]},{"location":"en/rules/Azure.Template.UseComments/#recommendation","title":"Recommendation","text":"Specify comments for each resource in the template.
","tags":["Azure.Template.UseComments","AZR-000234"]},{"location":"en/rules/Azure.Template.UseComments/#examples","title":"Examples","text":"","tags":["Azure.Template.UseComments","AZR-000234"]},{"location":"en/rules/Azure.Template.UseComments/#configure-with-azure-template","title":"Configure with Azure template","text":"To define Azure template files that pass this rule:
comments
for each resource in the template.For example:
Azure Template snippet\"resources\": [\n {\n \"name\": \"[variables('storageAccountName')]\",\n \"type\": \"Microsoft.Storage/storageAccounts\",\n \"apiVersion\": \"2019-06-01\",\n \"location\": \"[resourceGroup().location]\",\n \"comments\": \"This storage account is used to store the VM disks.\",\n ...\n }\n]\n
","tags":["Azure.Template.UseComments","AZR-000234"]},{"location":"en/rules/Azure.Template.UseComments/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_12 \u00b7 Awareness
Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose.
","tags":["Azure.Template.UseDescriptions","AZR-000235"]},{"location":"en/rules/Azure.Template.UseDescriptions/#description","title":"Description","text":"Generated templates can optionally include descriptions in resources. This helps other contributors understand the purpose of the resource.
","tags":["Azure.Template.UseDescriptions","AZR-000235"]},{"location":"en/rules/Azure.Template.UseDescriptions/#recommendation","title":"Recommendation","text":"Specify descriptions for each resource in the template.
","tags":["Azure.Template.UseDescriptions","AZR-000235"]},{"location":"en/rules/Azure.Template.UseDescriptions/#examples","title":"Examples","text":"","tags":["Azure.Template.UseDescriptions","AZR-000235"]},{"location":"en/rules/Azure.Template.UseDescriptions/#configure-with-bicep","title":"Configure with Bicep","text":"To define Bicep template files that pass this rule:
@description()
or @sys.description()
decorator for each resource in the template.For example:
Azure Bicep snippet// An example container registry\n@description('abc')\nresource acr 'Microsoft.ContainerRegistry/registries@2021-06-01-preview' = {\n name: registryName\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n quarantinePolicy: {\n status: 'enabled'\n }\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n status: 'enabled'\n days: 30\n }\n }\n }\n}\n
","tags":["Azure.Template.UseDescriptions","AZR-000235"]},{"location":"en/rules/Azure.Template.UseDescriptions/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_03 \u00b7 Awareness
Template should reference a location parameter to specify resource location.
","tags":["Azure.Template.UseLocationParameter","AZR-000223"]},{"location":"en/rules/Azure.Template.UseLocationParameter/#description","title":"Description","text":"The template parameter location
is a standard parameter recommended for deployment templates. The location
parameter is a intended for specifying the deployment location of the primary resource.
When defining a resource that requires a location, use the location
parameter. For example:
{\n \"type\": \"Microsoft.Network/virtualNetworks\",\n \"name\": \"[parameters('VNETName')]\",\n \"apiVersion\": \"2020-06-01\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {}\n}\n
Additionally, the template may include other resources. Use the location
parameter value for resources that are likely to be in the same location. This approach minimizes the number of times users are asked to provide location information. For resources that aren't available in all locations, use a separate parameter.
Consider using parameters('location)
instead of resourceGroup().location
. Using a location parameter enabled users of the template to specify the location of deployed resources.
To author templates that pass this rule:
location
.[parameters('location')]
.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"metadata\": {\n \"name\": \"Managed Identity\",\n \"description\": \"Create or update a Managed Identity.\"\n },\n \"parameters\": {\n \"identityName\": {\n \"type\": \"string\",\n \"metadata\": {\n \"description\": \"The name of the Managed Identity.\"\n }\n },\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"The Azure region to deploy to.\",\n \"example\": \"eastus\"\n }\n },\n \"tags\": {\n \"type\": \"object\",\n \"metadata\": {\n \"description\": \"Tags to apply to the resource.\",\n \"example\": {\n \"service\": \"app1\",\n \"env\": \"prod\"\n }\n }\n }\n },\n \"variables\": {\n \"tenantId\": \"[subscription().tenantId]\"\n },\n \"resources\": [\n {\n \"comments\": \"Create or update a Managed Identity\",\n \"type\": \"Microsoft.ManagedIdentity/userAssignedIdentities\",\n \"apiVersion\": \"2018-11-30\",\n \"name\": \"[parameters('identityName')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"tenantId\": \"[variables('tenantId')]\"\n },\n \"tags\": \"[parameters('tags')]\"\n }\n ]\n}\n
","tags":["Azure.Template.UseLocationParameter","AZR-000223"]},{"location":"en/rules/Azure.Template.UseLocationParameter/#notes","title":"Notes","text":"This rule is not applicable and ignored for templates generated with Bicep, PSArm, and AzOps. Generated templates from these tools may not require any parameters to be set.
","tags":["Azure.Template.UseLocationParameter","AZR-000223"]},{"location":"en/rules/Azure.Template.UseLocationParameter/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2020_09 \u00b7 Awareness
Each Azure Resource Manager (ARM) template parameter should be used or removed from template files.
","tags":["Azure.Template.UseParameters","AZR-000217"]},{"location":"en/rules/Azure.Template.UseParameters/#description","title":"Description","text":"ARM templates can optionally define parameters that can be reused throughout the template. Parameters that are not used may make template use more complex for no benefit.
","tags":["Azure.Template.UseParameters","AZR-000217"]},{"location":"en/rules/Azure.Template.UseParameters/#recommendation","title":"Recommendation","text":"Consider removing unused parameters from Azure template files.
","tags":["Azure.Template.UseParameters","AZR-000217"]},{"location":"en/rules/Azure.Template.UseParameters/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2020_09 \u00b7 Awareness
Each Azure Resource Manager (ARM) template variable should be used or removed from template files.
","tags":["Azure.Template.UseVariables","AZR-000219"]},{"location":"en/rules/Azure.Template.UseVariables/#description","title":"Description","text":"ARM templates can optionally define variables that can be reused throughout the template. Variables that are not used may add template complexity for no benefit.
","tags":["Azure.Template.UseVariables","AZR-000219"]},{"location":"en/rules/Azure.Template.UseVariables/#recommendation","title":"Recommendation","text":"Consider removing unused variables from Azure template files.
","tags":["Azure.Template.UseVariables","AZR-000219"]},{"location":"en/rules/Azure.Template.UseVariables/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_09 \u00b7 Awareness
Use a valid secret reference within parameter files.
","tags":["Azure.Template.ValidSecretRef","AZR-000233"]},{"location":"en/rules/Azure.Template.ValidSecretRef/#description","title":"Description","text":"When referencing secrets in a template parameter file:
Check the secret value Key Vault reference is valid.
","tags":["Azure.Template.ValidSecretRef","AZR-000233"]},{"location":"en/rules/Azure.Template.ValidSecretRef/#examples","title":"Examples","text":"","tags":["Azure.Template.ValidSecretRef","AZR-000233"]},{"location":"en/rules/Azure.Template.ValidSecretRef/#configure-with-azure-template","title":"Configure with Azure template","text":"To define Azure template parameter files that pass this rule:
For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentParameters.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"gatewayName\": {\n \"value\": \"gateway-A\"\n },\n \"sku\": {\n \"value\": \"VpnGw1\"\n },\n \"subnetId\": {\n \"value\": \"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/virtualNetworks/vnet-A/subnets/GatewaySubnet\"\n },\n \"sharedKey\": {\n \"reference\": {\n \"keyVault\": {\n \"id\": \"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.KeyVault/vaults/kv-001\"\n },\n \"secretName\": \"valid-secret\"\n }\n }\n }\n}\n
","tags":["Azure.Template.ValidSecretRef","AZR-000233"]},{"location":"en/rules/Azure.Template.ValidSecretRef/#links","title":"Links","text":"Reliability \u00b7 Traffic Manager \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Traffic Manager should use at lest two enabled endpoints.
","tags":["Azure.TrafficManager.Endpoints","AZR-000236"]},{"location":"en/rules/Azure.TrafficManager.Endpoints/#description","title":"Description","text":"Traffic Manager is a DNS service that enables you to distribute traffic to improve availability and responsiveness. Traffic is distributed across endpoints, which can be located in different availability zones and regions.
When only one enabled endpoint exists, routing for high availability and/ or responsiveness is not possible.
","tags":["Azure.TrafficManager.Endpoints","AZR-000236"]},{"location":"en/rules/Azure.TrafficManager.Endpoints/#recommendation","title":"Recommendation","text":"Consider adding additional endpoints or enabling disabled endpoints. Also consider, using endpoints deployed across different regions to provide high availability.
","tags":["Azure.TrafficManager.Endpoints","AZR-000236"]},{"location":"en/rules/Azure.TrafficManager.Endpoints/#links","title":"Links","text":"Security \u00b7 Traffic Manager \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Monitor Traffic Manager web-based endpoints with HTTPS.
","tags":["Azure.TrafficManager.Protocol","AZR-000237"]},{"location":"en/rules/Azure.TrafficManager.Protocol/#description","title":"Description","text":"Traffic Manager can use TCP, HTTP or HTTPS to monitor endpoint health. For web-based endpoints use HTTPS.
If TCP is used, Traffic Manager only checks that it can open a TCP port on the endpoint. This alone does not indicate that the endpoint is operational and ready to receive requests. Additionally when using HTTP and HTTPS, Traffic Manager check HTTP response codes.
If HTTP is used, Traffic Manager will send unencrypted health checks to the endpoint. HTTPS-based health checks additionally check if a certificate is present, but do not validate if the certificate is valid.
","tags":["Azure.TrafficManager.Protocol","AZR-000237"]},{"location":"en/rules/Azure.TrafficManager.Protocol/#recommendation","title":"Recommendation","text":"Consider using HTTPS to monitor web-based endpoint health. HTTPS-based monitoring improves security and increases accuracy of health probes.
","tags":["Azure.TrafficManager.Protocol","AZR-000237"]},{"location":"en/rules/Azure.TrafficManager.Protocol/#examples","title":"Examples","text":"","tags":["Azure.TrafficManager.Protocol","AZR-000237"]},{"location":"en/rules/Azure.TrafficManager.Protocol/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Traffic Manager profiles that pass this rule:
properties.monitorConfig.protocol
property to HTTPS
for HTTP-based endpoints.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/trafficmanagerprofiles\",\n \"apiVersion\": \"2022-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"global\",\n \"properties\": {\n \"endpoints\": \"[parameters('endpoints')]\",\n \"trafficRoutingMethod\": \"Performance\",\n \"monitorConfig\": {\n \"protocol\": \"HTTPS\",\n \"port\": 443,\n \"intervalInSeconds\": 30,\n \"timeoutInSeconds\": 5,\n \"toleratedNumberOfFailures\": 3,\n \"path\": \"/healthz\"\n }\n }\n}\n
","tags":["Azure.TrafficManager.Protocol","AZR-000237"]},{"location":"en/rules/Azure.TrafficManager.Protocol/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Traffic Manager profiles that pass this rule:
properties.monitorConfig.protocol
property to HTTPS
for HTTP-based endpoints.For example:
Azure Bicep snippetresource profile 'Microsoft.Network/trafficmanagerprofiles@2022-04-01' = {\n name: name\n location: 'global'\n properties: {\n endpoints: endpoints\n trafficRoutingMethod: 'Performance'\n monitorConfig: {\n protocol: 'HTTPS'\n port: 443\n intervalInSeconds: 30\n timeoutInSeconds: 5\n toleratedNumberOfFailures: 3\n path: '/healthz'\n }\n }\n}\n
","tags":["Azure.TrafficManager.Protocol","AZR-000237"]},{"location":"en/rules/Azure.TrafficManager.Protocol/#links","title":"Links","text":"Security \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use Azure Disk Encryption (ADE).
","tags":["Azure.VM.ADE","AZR-000252"]},{"location":"en/rules/Azure.VM.ADE/#description","title":"Description","text":"Virtual machines (VMs) can be encrypted using ADE to protect disks with full disk encryption. Storage Service Encryption (SSE) is encryption as rest for Managed Disks and Storage Accounts. SSE automatically decrypts storage as it is read. Full disk encryption varies from SSE by decrypting disks on read within the operating system.
ADE protects disk decryption keys within Key Vault.
","tags":["Azure.VM.ADE","AZR-000252"]},{"location":"en/rules/Azure.VM.ADE/#recommendation","title":"Recommendation","text":"Consider using Azure Disk Encryption (ADE) to protect VM disks from being downloaded and accessed offline.
","tags":["Azure.VM.ADE","AZR-000252"]},{"location":"en/rules/Azure.VM.ADE/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Machine \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Use Azure Monitor Agent for collecting monitoring data from VMs.
","tags":["Azure.VM.AMA","AZR-000345"]},{"location":"en/rules/Azure.VM.AMA/#description","title":"Description","text":"Azure Monitor is the platform capability for monitoring and observability in Azure. Azure Monitor collects monitoring telemetry from a variety of on-premises, multi-cloud, and Azure sources.
To monitor Windows and Linux operating systems the Azure Monitor Agent (AMA) is deployed. Once the AMA the agent is deployed, collected data gets delivered to Azure Monitor, where is can be used for:
For Azure virtual machines (VMs), virtual machine scale sets (VMSS), and Azure Arc enabled servers the monitoring agent is deployed as an extension. The extension also supports modern management capabilities such as Azure Policy, automatic updates, and deployment as Infrastructure as Code.
The AMA replaces Azure Monitor's legacy monitoring agents.
","tags":["Azure.VM.AMA","AZR-000345"]},{"location":"en/rules/Azure.VM.AMA/#recommendation","title":"Recommendation","text":"Consider monitoring virtual machines (VMs) with the Azure Monitor Agent.
","tags":["Azure.VM.AMA","AZR-000345"]},{"location":"en/rules/Azure.VM.AMA/#examples","title":"Examples","text":"","tags":["Azure.VM.AMA","AZR-000345"]},{"location":"en/rules/Azure.VM.AMA/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy virtual machines that pass this rule:
Microsoft.Compute/virtualMachines/extensions
.properties.publisher
to Microsoft.Azure.Monitor
.properties.type
to AzureMonitorWindowsAgent
(Windows) or AzureMonitorLinuxAgent
(Linux).For example:
Azure Template snippet{\n \"type\": \"Microsoft.Compute/virtualMachines/extensions\",\n \"apiVersion\": \"2023-09-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'AzureMonitorWindowsAgent')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"publisher\": \"Microsoft.Azure.Monitor\",\n \"type\": \"AzureMonitorWindowsAgent\",\n \"typeHandlerVersion\": \"1.0\",\n \"autoUpgradeMinorVersion\": true,\n \"enableAutomaticUpgrade\": true,\n \"settings\": {\n \"authentication\": {\n \"managedIdentity\": {\n \"identifier-name\": \"mi_res_id\",\n \"identifier-value\": \"[parameters('amaIdentityId')]\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Compute/virtualMachines', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.VM.AMA","AZR-000345"]},{"location":"en/rules/Azure.VM.AMA/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy virtual machines that pass this rule:
Microsoft.Compute/virtualMachines/extensions
.properties.publisher
to Microsoft.Azure.Monitor
.properties.type
to AzureMonitorWindowsAgent
(Windows) or AzureMonitorLinuxAgent
(Linux).For example:
Azure Bicep snippetresource windowsAgent 'Microsoft.Compute/virtualMachines/extensions@2023-09-01' = {\n parent: vm\n name: 'AzureMonitorWindowsAgent'\n location: location\n properties: {\n publisher: 'Microsoft.Azure.Monitor'\n type: 'AzureMonitorWindowsAgent'\n typeHandlerVersion: '1.0'\n autoUpgradeMinorVersion: true\n enableAutomaticUpgrade: true\n settings: {\n authentication: {\n managedIdentity: {\n 'identifier-name': 'mi_res_id'\n 'identifier-value': amaIdentityId\n }\n }\n }\n }\n}\n
","tags":["Azure.VM.AMA","AZR-000345"]},{"location":"en/rules/Azure.VM.AMA/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To configure virtual machine using a user-assigned identity:
Microsoft.Compute/virtualMachines/extensions
.--name
parameter to AzureMonitorWindowsAgent
(Windows) or AzureMonitorLinuxAgent
(Linux).For example:
Azure CLI snippetaz vm extension set --name 'AzureMonitorWindowsAgent' --publisher Microsoft.Azure.Monitor --ids '<vm-resource-id>' --enable-auto-upgrade true --settings '{\"authentication\":{\"managedIdentity\":{\"identifier-name\":\"mi_res_id\",\"identifier-value\":\"/subscriptions/<my-subscription-id>/resourceGroups/<my-resource-group>/providers/Microsoft.ManagedIdentity/userAssignedIdentities/<my-user-assigned-identity>\"}}}'\n
","tags":["Azure.VM.AMA","AZR-000345"]},{"location":"en/rules/Azure.VM.AMA/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To configure virtual machine using a user-assigned identity:
Microsoft.Compute/virtualMachines/extensions
.-ExtensionType
parameter to AzureMonitorWindowsAgent
(Windows) or AzureMonitorLinuxAgent
(Linux).For example:
Azure PowerShell snippetSet-AzVMExtension -Name AzureMonitorWindowsAgent -ExtensionType 'AzureMonitorWindowsAgent' -Publisher Microsoft.Azure.Monitor -ResourceGroupName '<resource-group-name>' -VMName '<virtual-machine-name>' -Location '<location>' -TypeHandlerVersion '1.0' -EnableAutomaticUpgrade $true -SettingString '{\"authentication\":{\"managedIdentity\":{\"identifier-name\":\"mi_res_id\",\"identifier-value\":\"/subscriptions/<my-subscription-id>/resourceGroups/<my-resource-group>/providers/Microsoft.ManagedIdentity/userAssignedIdentities/<my-user-assigned-identity>\"}}}'\n
","tags":["Azure.VM.AMA","AZR-000345"]},{"location":"en/rules/Azure.VM.AMA/#notes","title":"Notes","text":"Deploying Azure Monitor Agent (AMA) extension alone does not include all configuration needed. Additionally data collection rules and associations are required to specify what data is collected and where it is sent.
","tags":["Azure.VM.AMA","AZR-000345"]},{"location":"en/rules/Azure.VM.AMA/#links","title":"Links","text":"Reliability \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use availability sets aligned with managed disks fault domains.
","tags":["Azure.VM.ASAlignment","AZR-000254"]},{"location":"en/rules/Azure.VM.ASAlignment/#description","title":"Description","text":"Availability sets can be configured to align with managed disk fault domains. When aligned, the fault domain for storage is co-located with compute. Aligned availability sets help prevent compute and storage from a single VM spanning multiple fault domains.
","tags":["Azure.VM.ASAlignment","AZR-000254"]},{"location":"en/rules/Azure.VM.ASAlignment/#recommendation","title":"Recommendation","text":"Consider deploying VMs with managed disks into aligned availability sets.
","tags":["Azure.VM.ASAlignment","AZR-000254"]},{"location":"en/rules/Azure.VM.ASAlignment/#links","title":"Links","text":"Reliability \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Availability sets should be deployed with at least two virtual machines (VMs).
","tags":["Azure.VM.ASMinMembers","AZR-000255"]},{"location":"en/rules/Azure.VM.ASMinMembers/#description","title":"Description","text":"An availability set is a logical grouping of VMs that allows Azure to optimize the placement of VMs. Azure uses this grouping to separate VMs within the availablity set across fault and update domains. Each VM in your availability set is assigned an update domain and a fault domain. VMs in different update and fault domains is mapped to different underlying physical hardware. The reason for doing this is to improve reliability by removing some single points of failure.
Deploy two or more VMs within an availability set to provide for a highly available application. There is no cost for the Availability Set itself, you only pay for each VM instance that you create.
","tags":["Azure.VM.ASMinMembers","AZR-000255"]},{"location":"en/rules/Azure.VM.ASMinMembers/#recommendation","title":"Recommendation","text":"Consider deploying at least two VMs within an availability set to gain availability benefits.
","tags":["Azure.VM.ASMinMembers","AZR-000255"]},{"location":"en/rules/Azure.VM.ASMinMembers/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed to Azure (in-flight).
","tags":["Azure.VM.ASMinMembers","AZR-000255"]},{"location":"en/rules/Azure.VM.ASMinMembers/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Availability Set names should meet naming requirements.
","tags":["Azure.VM.ASName","AZR-000256"]},{"location":"en/rules/Azure.VM.ASName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Availability Set names are:
Consider using names that meet Availability Set naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.VM.ASName","AZR-000256"]},{"location":"en/rules/Azure.VM.ASName/#notes","title":"Notes","text":"This rule does not check if Availability Set names are unique.
","tags":["Azure.VM.ASName","AZR-000256"]},{"location":"en/rules/Azure.VM.ASName/#links","title":"Links","text":"Performance Efficiency \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use accelerated networking for supported operating systems and VM types.
","tags":["Azure.VM.AcceleratedNetworking","AZR-000244"]},{"location":"en/rules/Azure.VM.AcceleratedNetworking/#description","title":"Description","text":"Enabling accelerated networking for a virtual machine (VM) greatly improves networking performance. Accelerated networking work by enabling single root I/O virtualization (SR-IOV) to a VM. SR-IOV reduces latency, jitter, and CPU utilization network demanding workloads.
Accelerated networking is available for supported operating systems and VM types.
","tags":["Azure.VM.AcceleratedNetworking","AZR-000244"]},{"location":"en/rules/Azure.VM.AcceleratedNetworking/#recommendation","title":"Recommendation","text":"Consider enabling accelerated networking for supported operating systems and VM types.
","tags":["Azure.VM.AcceleratedNetworking","AZR-000244"]},{"location":"en/rules/Azure.VM.AcceleratedNetworking/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Ensure the VM agent is provisioned automatically.
","tags":["Azure.VM.Agent","AZR-000246"]},{"location":"en/rules/Azure.VM.Agent/#description","title":"Description","text":"The virtual machine (VM) agent is required for most functionality that interacts with the guest operating system.
VM extensions help reduce management overhead by providing an entry point to bootstrap monitoring and configuration of the guest operating system. The VM agent is required to use any VM extensions.
","tags":["Azure.VM.Agent","AZR-000246"]},{"location":"en/rules/Azure.VM.Agent/#recommendation","title":"Recommendation","text":"Automatically provision the VM agent for all supported operating systems, this is the default.
","tags":["Azure.VM.Agent","AZR-000246"]},{"location":"en/rules/Azure.VM.BasicSku/","title":"Avoid Basic VM SKU","text":"Azure.VM.BasicSkuAZR-000241ErrorOperational Excellence \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Virtual machines (VMs) should not use Basic sizes.
","tags":["Azure.VM.BasicSku","AZR-000241"]},{"location":"en/rules/Azure.VM.BasicSku/#description","title":"Description","text":"VMs can be deployed in Basic or Standard sizes. Basic VM sizes are suitable only for entry level development scenarios.
","tags":["Azure.VM.BasicSku","AZR-000241"]},{"location":"en/rules/Azure.VM.BasicSku/#recommendation","title":"Recommendation","text":"Basic VM sizes are not suitable for production workloads or intensive development workloads. Consider migration to an alternative Standard VM size.
","tags":["Azure.VM.BasicSku","AZR-000241"]},{"location":"en/rules/Azure.VM.BasicSku/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Virtual Machine (VM) computer name should meet naming requirements.
","tags":["Azure.VM.ComputerName","AZR-000249"]},{"location":"en/rules/Azure.VM.ComputerName/#description","title":"Description","text":"When configuring Azure VMs the assigned computer name must meet operation system (OS) requirements.
The requirements for Windows VMs are:
The requirements for Linux VMs are:
Consider using computer names that meet OS naming requirements. Additionally, consider using computer names that match the VM resource name.
","tags":["Azure.VM.ComputerName","AZR-000249"]},{"location":"en/rules/Azure.VM.ComputerName/#notes","title":"Notes","text":"VM resource names have different naming restrictions. See Azure.VM.Name
for details.
Cost Optimization \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Managed disks should be attached to virtual machines or removed.
","tags":["Azure.VM.DiskAttached","AZR-000250"]},{"location":"en/rules/Azure.VM.DiskAttached/#description","title":"Description","text":"Unattached managed disks are charged but not in use. Unattached managed disks still consume storage and are charged on their size.
","tags":["Azure.VM.DiskAttached","AZR-000250"]},{"location":"en/rules/Azure.VM.DiskAttached/#recommendation","title":"Recommendation","text":"Consider removing managed disks that are no longer required to reduce complexity and costs.
","tags":["Azure.VM.DiskAttached","AZR-000250"]},{"location":"en/rules/Azure.VM.DiskAttached/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.VM.DiskAttached","AZR-000250"]},{"location":"en/rules/Azure.VM.DiskAttached/#links","title":"Links","text":"Performance Efficiency \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Check disk caching is configured correctly for the workload.
","tags":["Azure.VM.DiskCaching","AZR-000242"]},{"location":"en/rules/Azure.VM.DiskCaching/#description","title":"Description","text":"Check disk caching is configured correctly for the workload.
","tags":["Azure.VM.DiskCaching","AZR-000242"]},{"location":"en/rules/Azure.VM.DiskCaching/#recommendation","title":"Recommendation","text":"Check disk caching is configured correctly for the workload.
","tags":["Azure.VM.DiskCaching","AZR-000242"]},{"location":"en/rules/Azure.VM.DiskName/","title":"Use valid Managed Disk names","text":"Azure.VM.DiskNameAZR-000253ErrorOperational Excellence \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Managed Disk names should meet naming requirements.
","tags":["Azure.VM.DiskName","AZR-000253"]},{"location":"en/rules/Azure.VM.DiskName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Managed Disk names are:
Consider using names that meet Managed Disk naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.VM.DiskName","AZR-000253"]},{"location":"en/rules/Azure.VM.DiskName/#notes","title":"Notes","text":"This rule does not check if Managed Disk names are unique.
","tags":["Azure.VM.DiskName","AZR-000253"]},{"location":"en/rules/Azure.VM.DiskName/#links","title":"Links","text":"Cost Optimization \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Align to the Managed Disk billing increments to improve cost efficiency.
","tags":["Azure.VM.DiskSizeAlignment","AZR-000251"]},{"location":"en/rules/Azure.VM.DiskSizeAlignment/#description","title":"Description","text":"Azure managed disks are billed based on predefined size increments. The billing increments are based on the disk storage type. These include:
Premium SSD
- 4/ 8/ 16/ 32/ 64/ 128/ 256/ 512/ 1024/ 2048/ 4096/ 8192/ 16384/ 32768 GiB.Standard SSD
- 4/ 8/ 16/ 32/ 64/ 128/ 256/ 512/ 1024/ 2048/ 4096/ 8192/ 16384/ 32768 GiB.Standard HDD
- 32/ 64/ 128/ 256/ 512/ 1024/ 2048/ 4096/ 8192/ 16384/ 32768 GiB.Ultra SSD
- 4/ 8/ 16/ 32/ 64/ 128/ 256/ 512 GiB, then 1 TiB increments to 64 TiB.If you provision a disk that is not aligned to the billing model, you will be billed for the next increment. For example, if a disk is provisioned at 33 GiB, the disk is billed as 64 GiB.
","tags":["Azure.VM.DiskSizeAlignment","AZR-000251"]},{"location":"en/rules/Azure.VM.DiskSizeAlignment/#recommendation","title":"Recommendation","text":"Consider aligning provisioned disk sizes to the billing increments for Managed Disks to improve cost efficiency.
","tags":["Azure.VM.DiskSizeAlignment","AZR-000251"]},{"location":"en/rules/Azure.VM.DiskSizeAlignment/#examples","title":"Examples","text":"","tags":["Azure.VM.DiskSizeAlignment","AZR-000251"]},{"location":"en/rules/Azure.VM.DiskSizeAlignment/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy managed disks that pass this rule:
properties.diskSizeGB
property to a value that aligns to the billing model of the disk storage type. E.g. 32
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Compute/disks\",\n \"apiVersion\": \"2023-04-02\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium_ZRS\"\n },\n \"properties\": {\n \"creationData\": {\n \"createOption\": \"Empty\"\n },\n \"diskSizeGB\": 32\n }\n}\n
","tags":["Azure.VM.DiskSizeAlignment","AZR-000251"]},{"location":"en/rules/Azure.VM.DiskSizeAlignment/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy managed disks that pass this rule:
properties.diskSizeGB
property to a value that aligns to the billing model of the disk storage type. E.g. 32
.For example:
Azure Bicep snippetresource dataDisk 'Microsoft.Compute/disks@2023-04-02' = {\n name: name\n location: location\n sku: {\n name: 'Premium_ZRS'\n }\n properties: {\n creationData: {\n createOption: 'Empty'\n }\n diskSizeGB: 32\n }\n}\n
","tags":["Azure.VM.DiskSizeAlignment","AZR-000251"]},{"location":"en/rules/Azure.VM.DiskSizeAlignment/#notes","title":"Notes","text":"This rule has the following limitations:
Operational Excellence \u00b7 Virtual Machine \u00b7 Rule \u00b7 Preview \u00b7 2023_06 \u00b7 Important
Use a maintenance configuration for virtual machines.
","tags":["Azure.VM.MaintenanceConfig","AZR-000375"]},{"location":"en/rules/Azure.VM.MaintenanceConfig/#description","title":"Description","text":"Virtual machines can be attached to a maintenance configuration which allows customer managed assessments and updates for machine patches within the guest operating system.
","tags":["Azure.VM.MaintenanceConfig","AZR-000375"]},{"location":"en/rules/Azure.VM.MaintenanceConfig/#recommendation","title":"Recommendation","text":"Consider automatically managing and applying operating system updates by associating a maintenance configuration.
","tags":["Azure.VM.MaintenanceConfig","AZR-000375"]},{"location":"en/rules/Azure.VM.MaintenanceConfig/#examples","title":"Examples","text":"","tags":["Azure.VM.MaintenanceConfig","AZR-000375"]},{"location":"en/rules/Azure.VM.MaintenanceConfig/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy virtual machines that pass this rule:
Microsoft.Maintenance/configurationAssignments
sub-resource (extension resource).properties.maintenanceConfigurationId
property to the linked maintenance configuration resource Id.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Maintenance/configurationAssignments\",\n \"apiVersion\": \"2022-11-01-preview\",\n \"name\": \"[parameters('assignmentName')]\",\n \"location\": \"[parameters('location')]\",\n \"scope\": \"[format('Microsoft.Compute/virtualMachines/{0}', parameters('name'))]\",\n \"properties\": {\n \"maintenanceConfigurationId\": \"[parameters('maintenanceConfigurationId')]\"\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Compute/virtualMachines', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.VM.MaintenanceConfig","AZR-000375"]},{"location":"en/rules/Azure.VM.MaintenanceConfig/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy virtual machines that pass this rule:
Microsoft.Maintenance/configurationAssignments
sub-resource (extension resource).properties.maintenanceConfigurationId
property to the linked maintenance configuration resource Id.For example:
Azure Bicep snippetresource config 'Microsoft.Maintenance/configurationAssignments@2022-11-01-preview' = {\n name: assignmentName\n location: location\n scope: vm\n properties: {\n maintenanceConfigurationId: maintenanceConfigurationId\n }\n}\n
","tags":["Azure.VM.MaintenanceConfig","AZR-000375"]},{"location":"en/rules/Azure.VM.MaintenanceConfig/#notes","title":"Notes","text":"Operating system updates with Update Management center is a preview feature. Not all operating systems are supported, check out the LINKS
section for more information. Update management center doesn't support driver updates.
Operational Excellence \u00b7 Virtual Machine \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Use Azure Monitor Agent as replacement for Log Analytics Agent.
","tags":["Azure.VM.MigrateAMA","AZR-000317"]},{"location":"en/rules/Azure.VM.MigrateAMA/#description","title":"Description","text":"The legacy Log Analytics agent will be retired on August 31, 2024. Before that date, you'll need to start using the Azure Monitor agent to monitor your VMs and servers in Azure. The Azure Monitor agent provdes the following benefits over legacy agents:
Virtual Machines should migrate to Azure Monitor Agent.
","tags":["Azure.VM.MigrateAMA","AZR-000317"]},{"location":"en/rules/Azure.VM.MigrateAMA/#examples","title":"Examples","text":"","tags":["Azure.VM.MigrateAMA","AZR-000317"]},{"location":"en/rules/Azure.VM.MigrateAMA/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy virtual machines that pass this rule:
properties.publisher
to 'Microsoft.Azure.Monitor'
.properties.type
to 'AzureMonitorWindowsAgent'
(Windows) or 'AzureMonitorLinuxAgent'
(Linux).For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"vmName\": {\n \"type\": \"string\"\n },\n \"location\": {\n \"type\": \"string\"\n },\n \"userAssignedManagedIdentity\": {\n \"type\": \"string\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Compute/virtualMachines/extensions\",\n \"apiVersion\": \"2022-08-01\",\n \"name\": \"[format('{0}/AzureMonitorWindowsAgent', parameters('vmName'))]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"publisher\": \"Microsoft.Azure.Monitor\",\n \"type\": \"AzureMonitorWindowsAgent\",\n \"typeHandlerVersion\": \"1.0\",\n \"settings\": {\n \"authentication\": {\n \"managedIdentity\": {\n \"identifier-name\": \"mi_res_id\",\n \"identifier-value\": \"[parameters('userAssignedManagedIdentity')]\"\n }\n }\n },\n \"autoUpgradeMinorVersion\": true,\n \"enableAutomaticUpgrade\": true\n }\n }\n ]\n}\n
","tags":["Azure.VM.MigrateAMA","AZR-000317"]},{"location":"en/rules/Azure.VM.MigrateAMA/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy virtual machines that pass this rule:
properties.publisher
to 'Microsoft.Azure.Monitor'
.properties.type
to 'AzureMonitorWindowsAgent'
(Windows) or 'AzureMonitorLinuxAgent'
(Linux).For example:
Azure Bicep snippetparam vmName string\nparam location string\nparam userAssignedManagedIdentity string\n\nresource windowsAgent 'Microsoft.Compute/virtualMachines/extensions@2022-08-01' = {\n name: '${vmName}/AzureMonitorWindowsAgent'\n location: location\n properties: {\n publisher: 'Microsoft.Azure.Monitor'\n type: 'AzureMonitorWindowsAgent'\n typeHandlerVersion: '1.0'\n autoUpgradeMinorVersion: true\n enableAutomaticUpgrade: true\n settings: {\n authentication: {\n managedIdentity: {\n identifier-name: 'mi_res_id'\n identifier-value: userAssignedManagedIdentity\n }\n }\n }\n }\n}\n
","tags":["Azure.VM.MigrateAMA","AZR-000317"]},{"location":"en/rules/Azure.VM.MigrateAMA/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Virtual Machine (VM) names should meet naming requirements.
","tags":["Azure.VM.Name","AZR-000248"]},{"location":"en/rules/Azure.VM.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for VM names are:
Consider using names that meet VM resource name requirements. Additionally, consider using a resource name that meeting OS naming requirements.
","tags":["Azure.VM.Name","AZR-000248"]},{"location":"en/rules/Azure.VM.Name/#notes","title":"Notes","text":"This rule does not check if VM names are unique. Additionally, VM computer names have additional restrictions. See Azure.VM.ComputerName
for details.
Operational Excellence \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Proximity Placement Group (PPG) names should meet naming requirements.
","tags":["Azure.VM.PPGName","AZR-000260"]},{"location":"en/rules/Azure.VM.PPGName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for placement groups names are:
Consider using names that meet Proximity Placement Group naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.VM.PPGName","AZR-000260"]},{"location":"en/rules/Azure.VM.PPGName/#notes","title":"Notes","text":"This rule does not check if Proximity Placement Group names are unique.
","tags":["Azure.VM.PPGName","AZR-000260"]},{"location":"en/rules/Azure.VM.PPGName/#links","title":"Links","text":"Cost Optimization \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Virtual machines (VMs) should not use expired promotional SKU.
","tags":["Azure.VM.PromoSku","AZR-000240"]},{"location":"en/rules/Azure.VM.PromoSku/#description","title":"Description","text":"Some VM sizes may offer promotional rates that can be used by deploying VMs with a designated SKU. Promotional rates expire, and while this does not cause interruption to running VMs, the rate that VMs are billed at returns to the original price.
Promo SKUs are not eligible for savings from reserved instances. Expired promo SKUs may confuse billing reconciliation when the promotional period expires.
VMs should not use expired promo SKU.
","tags":["Azure.VM.PromoSku","AZR-000240"]},{"location":"en/rules/Azure.VM.PromoSku/#recommendation","title":"Recommendation","text":"Consider moving from promotional SKUs to SKUs eligible for reserved instances for VMs with an extended life cycle. Alternatively, consider moving from promotional SKUs to the regular SKU once the promotional period has expired.
","tags":["Azure.VM.PromoSku","AZR-000240"]},{"location":"en/rules/Azure.VM.PromoSku/#links","title":"Links","text":"Security \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Linux virtual machines should use public keys.
","tags":["Azure.VM.PublicKey","AZR-000245"]},{"location":"en/rules/Azure.VM.PublicKey/#description","title":"Description","text":"Linux virtual machines support either password or public key based authentication for the default administrator account.
","tags":["Azure.VM.PublicKey","AZR-000245"]},{"location":"en/rules/Azure.VM.PublicKey/#recommendation","title":"Recommendation","text":"Consider using public key based authentication instead of passwords.
","tags":["Azure.VM.PublicKey","AZR-000245"]},{"location":"en/rules/Azure.VM.SQLServerDisk/","title":"Configure Premium disks or above","text":"Azure.VM.SQLServerDiskAZR-000324ErrorPerformance Efficiency \u00b7 Virtual Machine \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Use Premium SSD disks or greater for data and log files for production SQL Server workloads.
","tags":["Azure.VM.SQLServerDisk","AZR-000324"]},{"location":"en/rules/Azure.VM.SQLServerDisk/#description","title":"Description","text":"Use premium SSD disks or greater for data and log files for production SQL Server workloads.
This is an advanced topic with many considerations, so we highly suggest to follow the LINKS
section for more around this with aligned and up-to-date documentation.
Configure Premium SSD disks or greater for data and log files for production SQL Server workloads.
","tags":["Azure.VM.SQLServerDisk","AZR-000324"]},{"location":"en/rules/Azure.VM.SQLServerDisk/#examples","title":"Examples","text":"","tags":["Azure.VM.SQLServerDisk","AZR-000324"]},{"location":"en/rules/Azure.VM.SQLServerDisk/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Virtual Machines that pass this rule:
properties.storageProfile.osDisk.managedDisk.storageAccountType
property to Premium_LRS
or greater.properties.storageProfile.dataDisks
to use Premium_LRS
or greater by setting the property managedDisk.storageAccountType
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Compute/virtualMachines\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"[parameters('virtualMachineName')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"hardwareProfile\": {\n \"vmSize\": \"[parameters('virtualMachineSize')]\"\n },\n \"storageProfile\": {\n \"osDisk\": {\n \"createOption\": \"FromImage\",\n \"managedDisk\": {\n \"storageAccountType\": \"Premium_LRS\"\n },\n \"diskSizeGB\": 127\n },\n \"imageReference\": {\n \"publisher\": \"MicrosoftSQLServer\",\n \"offer\": \"SQL2019-WS2019\",\n \"sku\": \"Enterprise\",\n \"version\": \"latest\"\n },\n \"dataDisks\": [\n {\n \"lun\": 0,\n \"caching\": \"ReadOnly\",\n \"createOption\": \"Empty\",\n \"writeAcceleratorEnabled\": false,\n \"managedDisk\": {\n \"storageAccountType\": \"UltraSSD_LRS\"\n },\n \"diskSizeGB\": 1023\n }\n ]\n },\n \"networkProfile\": {\n \"networkInterfaces\": [\n {\n \"id\": \"[resourceId('Microsoft.Network/networkInterfaces', variables('networkInterfaceName'))]\"\n }\n ]\n },\n \"osProfile\": {\n \"computerName\": \"[parameters('virtualMachineName')]\",\n \"adminUsername\": \"[parameters('adminUsername')]\",\n \"adminPassword\": \"[parameters('adminPassword')]\",\n \"windowsConfiguration\": {\n \"enableAutomaticUpdates\": true,\n \"provisionVMAgent\": true\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Network/networkInterfaces', variables('networkInterfaceName'))]\"\n ]\n}\n
","tags":["Azure.VM.SQLServerDisk","AZR-000324"]},{"location":"en/rules/Azure.VM.SQLServerDisk/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Virtual Machines that pass this rule:
properties.storageProfile.osDisk.managedDisk.storageAccountType
property to Premium_LRS
or greater.properties.storageProfile.dataDisks
to use Premium_LRS
or greater by setting the property managedDisk.storageAccountType
.For example:
Azure Bicep snippetresource virtualMachine 'Microsoft.Compute/virtualMachines@2022-03-01' = {\n name: virtualMachineName\n location: location\n properties: {\n hardwareProfile: {\n vmSize: virtualMachineSize\n }\n storageProfile: {\n osDisk: {\n createOption: 'FromImage'\n managedDisk: {\n storageAccountType: 'Premium_LRS'\n }\n diskSizeGB: 127\n }\n imageReference: {\n publisher: 'MicrosoftSQLServer'\n offer: 'SQL2019-WS2019'\n sku: 'Enterprise'\n version: 'latest'\n }\n dataDisks: [\n {\n lun: 0\n caching: 'ReadOnly'\n createOption: 'Empty'\n writeAcceleratorEnabled: false\n managedDisk: {\n storageAccountType: 'UltraSSD_LRS'\n }\n diskSizeGB: 1023\n }\n ]\n }\n networkProfile: {\n networkInterfaces: [\n {\n id: networkInterface.id\n }\n ]\n }\n osProfile: {\n computerName: virtualMachineName\n adminUsername: adminUsername\n adminPassword: adminPassword\n windowsConfiguration: {\n enableAutomaticUpdates: true\n provisionVMAgent: true\n }\n }\n }\n}\n
","tags":["Azure.VM.SQLServerDisk","AZR-000324"]},{"location":"en/rules/Azure.VM.SQLServerDisk/#notes","title":"Notes","text":"This rule is only applicable for OS disk and data disks configured with the property properties.storageProfile.osDisk.managedDisk.storageAccountType
and the property properties.storageProfile.dataDisks.managedDisk.storageAccountType
.
Resources declarations can therefore pass the rule which are using not using Premium disks or above.
","tags":["Azure.VM.SQLServerDisk","AZR-000324"]},{"location":"en/rules/Azure.VM.SQLServerDisk/#links","title":"Links","text":"Security \u00b7 Virtual Machine \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Custom Script Extensions scripts that reference secret values must use the protectedSettings.
","tags":["Azure.VM.ScriptExtensions","AZR-000332"]},{"location":"en/rules/Azure.VM.ScriptExtensions/#description","title":"Description","text":"Virtual Machines support the ability to execute custom scripts on launch. This can be configured via user data and custom script extensions. When the template is rendered, anything in the settings section will be rendered in clear text. To ensure they're kept secret, use the protectedSettings section instead.
","tags":["Azure.VM.ScriptExtensions","AZR-000332"]},{"location":"en/rules/Azure.VM.ScriptExtensions/#recommendation","title":"Recommendation","text":"Consider specifying secure values within protectedSettings
to avoid exposing secrets during extension deployments.
To deploy VM extensions that pass this rule:
properties.protectedSettings
.{\n \"type\": \"Microsoft.Compute/virtualMachines/extensions\",\n \"name\": \"installcustomscript\",\n \"apiVersion\": \"2015-06-15\",\n \"location\": \"australiaeast\",\n \"properties\": {\n \"publisher\": \"Microsoft.Azure.Extensions\",\n \"type\": \"CustomScript\",\n \"typeHandlerVersion\": \"2.0\",\n \"autoUpgradeMinorVersion\": true,\n \"protectedSettings\": {\n \"commandToExecute\": \"Write-Output 'hello-world'\"\n }\n }\n}\n
","tags":["Azure.VM.ScriptExtensions","AZR-000332"]},{"location":"en/rules/Azure.VM.ScriptExtensions/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy VM extensions that pass this rule:
properties.protectedSettings
.resource script 'Microsoft.Compute/virtualMachines/extensions@2015-06-15' = {\n name: 'installcustomscript'\n location: location\n properties: {\n publisher: 'Microsoft.Azure.Extensions'\n type: 'CustomScript'\n typeHandlerVersion: '2.0'\n autoUpgradeMinorVersion: true\n protectedSettings: {\n commandToExecute: 'Write-Output \"hello-world\"'\n }\n }\n}\n
","tags":["Azure.VM.ScriptExtensions","AZR-000332"]},{"location":"en/rules/Azure.VM.ScriptExtensions/#links","title":"Links","text":"Cost Optimization \u00b7 Virtual Machine \u00b7 Rule \u00b7 2023_03 \u00b7 Important
Azure VMs should be running or in a deallocated state.
","tags":["Azure.VM.ShouldNotBeStopped","AZR-000351"]},{"location":"en/rules/Azure.VM.ShouldNotBeStopped/#description","title":"Description","text":"Azure Virtual Machines in a stopped state are still billed hourly for compute usage. Therefor VMs should generally be in a deallocated or running state.
","tags":["Azure.VM.ShouldNotBeStopped","AZR-000351"]},{"location":"en/rules/Azure.VM.ShouldNotBeStopped/#recommendation","title":"Recommendation","text":"Consider fully de-allocating VMs instead of stopping VMs to reduce cost.
","tags":["Azure.VM.ShouldNotBeStopped","AZR-000351"]},{"location":"en/rules/Azure.VM.ShouldNotBeStopped/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.VM.ShouldNotBeStopped","AZR-000351"]},{"location":"en/rules/Azure.VM.ShouldNotBeStopped/#links","title":"Links","text":"Reliability \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use VM features to increase reliability and improve covered SLA for VM configurations.
","tags":["Azure.VM.Standalone","AZR-000239"]},{"location":"en/rules/Azure.VM.Standalone/#description","title":"Description","text":"All VM configurations within Azure offer an SLA. However, the SLA provided and the overall availability of the system varies depending on the configuration.
First, consider performing a Failure Mode Analysis (FMA) of the system. A FMA is the process of analyzing the system to determine the possible failure points.
For Virtual Machines (VMs), running a single instance is often a single point of failure. In many but not all cases, the number of VMs can be increased to add redundancy to the system. Taking advantage of some of the features of Azure can further increase the availability of the system.
Consider using availability zones/ sets or only premium/ ultra disks to improve SLA.
","tags":["Azure.VM.Standalone","AZR-000239"]},{"location":"en/rules/Azure.VM.Standalone/#examples","title":"Examples","text":"","tags":["Azure.VM.Standalone","AZR-000239"]},{"location":"en/rules/Azure.VM.Standalone/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy VMs that pass this rule with on of the following:
properties.availabilitySet.id
in code.zones
with 1
, 2
, or 3
in code.storageAccountType
as Premium_LRS
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Compute/virtualMachines\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"zones\": [\n \"1\"\n ],\n \"properties\": {\n \"hardwareProfile\": {\n \"vmSize\": \"Standard_D2s_v3\"\n },\n \"osProfile\": {\n \"computerName\": \"[parameters('name')]\",\n \"adminUsername\": \"[parameters('adminUsername')]\",\n \"adminPassword\": \"[parameters('adminPassword')]\"\n },\n \"storageProfile\": {\n \"imageReference\": {\n \"publisher\": \"MicrosoftWindowsServer\",\n \"offer\": \"WindowsServer\",\n \"sku\": \"[parameters('sku')]\",\n \"version\": \"latest\"\n },\n \"osDisk\": {\n \"name\": \"[format('{0}-disk0', parameters('name'))]\",\n \"caching\": \"ReadWrite\",\n \"createOption\": \"FromImage\",\n \"managedDisk\": {\n \"storageAccountType\": \"Premium_LRS\"\n }\n }\n },\n \"licenseType\": \"Windows_Server\",\n \"networkProfile\": {\n \"networkInterfaces\": [\n {\n \"id\": \"[resourceId('Microsoft.Network/networkInterfaces', format('{0}-nic0', parameters('name')))]\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Network/networkInterfaces', format('{0}-nic0', parameters('name')))]\"\n ]\n}\n
","tags":["Azure.VM.Standalone","AZR-000239"]},{"location":"en/rules/Azure.VM.Standalone/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy VMs that pass this rule with on of the following:
properties.availabilitySet.id
in code.zones
with 1
, 2
, or 3
in code.storageAccountType
as Premium_LRS
.For example:
Azure Bicep snippetresource vm1 'Microsoft.Compute/virtualMachines@2022-03-01' = {\n name: name\n location: location\n zones: [\n '1'\n ]\n properties: {\n hardwareProfile: {\n vmSize: 'Standard_D2s_v3'\n }\n osProfile: {\n computerName: name\n adminUsername: adminUsername\n adminPassword: adminPassword\n }\n storageProfile: {\n imageReference: {\n publisher: 'MicrosoftWindowsServer'\n offer: 'WindowsServer'\n sku: sku\n version: 'latest'\n }\n osDisk: {\n name: '${name}-disk0'\n caching: 'ReadWrite'\n createOption: 'FromImage'\n managedDisk: {\n storageAccountType: 'Premium_LRS'\n }\n }\n }\n licenseType: 'Windows_Server'\n networkProfile: {\n networkInterfaces: [\n {\n id: nic.id\n }\n ]\n }\n }\n}\n
","tags":["Azure.VM.Standalone","AZR-000239"]},{"location":"en/rules/Azure.VM.Standalone/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Ensure automatic updates are enabled at deployment.
","tags":["Azure.VM.Updates","AZR-000247"]},{"location":"en/rules/Azure.VM.Updates/#description","title":"Description","text":"Window virtual machines (VMs) have automatic updates turned on at deployment time by default. The option can be enabled/ disabled at deployment time or updated for VM scale sets.
Enabling this option does not prevent automatic updates being disabled or reconfigured within the operating system after deployment.
","tags":["Azure.VM.Updates","AZR-000247"]},{"location":"en/rules/Azure.VM.Updates/#recommendation","title":"Recommendation","text":"Enable automatic updates at deployment time, then reconfigure as required to meet patch management requirements.
","tags":["Azure.VM.Updates","AZR-000247"]},{"location":"en/rules/Azure.VM.UseHybridUseBenefit/","title":"Use Azure Hybrid Benefit","text":"Azure.VM.UseHybridUseBenefitAZR-000243ErrorCost Optimization \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads.
","tags":["Azure.VM.UseHybridUseBenefit","AZR-000243"]},{"location":"en/rules/Azure.VM.UseHybridUseBenefit/#description","title":"Description","text":"The running cost of Virtual machine (VM) workloads in Azure is composed of several components, including:
Azure Hybrid Benefit is a licensing benefit that helps you to reduce your overall cost of ownership. With Azure Hybrid Benefit you to use your existing on-premises licenses to pay a reduced rate on Azure.
When Azure Hybrid Benefit enabled on supported VM images:
For additional information on Azure Hybrid Benefit, see the Azure Hybrid Benefit FAQ.
","tags":["Azure.VM.UseHybridUseBenefit","AZR-000243"]},{"location":"en/rules/Azure.VM.UseHybridUseBenefit/#recommendation","title":"Recommendation","text":"Consider using Azure Hybrid Benefit for eligible virtual machine (VM) workloads.
","tags":["Azure.VM.UseHybridUseBenefit","AZR-000243"]},{"location":"en/rules/Azure.VM.UseHybridUseBenefit/#examples","title":"Examples","text":"","tags":["Azure.VM.UseHybridUseBenefit","AZR-000243"]},{"location":"en/rules/Azure.VM.UseHybridUseBenefit/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy VMs that pass this rule:
properties.licenseType
property to one of the following:Windows_Server
Windows_Client
For example:
Azure Template snippet{\n \"type\": \"Microsoft.Compute/virtualMachines\",\n \"apiVersion\": \"2023-09-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"zones\": [\n \"1\"\n ],\n \"properties\": {\n \"hardwareProfile\": {\n \"vmSize\": \"Standard_D2s_v3\"\n },\n \"osProfile\": {\n \"computerName\": \"[parameters('name')]\",\n \"adminUsername\": \"[parameters('adminUsername')]\",\n \"adminPassword\": \"[parameters('adminPassword')]\"\n },\n \"storageProfile\": {\n \"imageReference\": {\n \"publisher\": \"MicrosoftWindowsServer\",\n \"offer\": \"WindowsServer\",\n \"sku\": \"[parameters('sku')]\",\n \"version\": \"latest\"\n },\n \"osDisk\": {\n \"name\": \"[format('{0}-disk0', parameters('name'))]\",\n \"caching\": \"ReadWrite\",\n \"createOption\": \"FromImage\",\n \"managedDisk\": {\n \"storageAccountType\": \"Premium_LRS\"\n }\n }\n },\n \"licenseType\": \"Windows_Server\",\n \"networkProfile\": {\n \"networkInterfaces\": [\n {\n \"id\": \"[resourceId('Microsoft.Network/networkInterfaces', parameters('nicName'))]\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Network/networkInterfaces', parameters('nicName'))]\"\n ]\n}\n
","tags":["Azure.VM.UseHybridUseBenefit","AZR-000243"]},{"location":"en/rules/Azure.VM.UseHybridUseBenefit/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy VMs that pass this rule:
properties.licenseType
property to one of the following:Windows_Server
Windows_Client
For example:
Azure Bicep snippetresource vm_with_benefit 'Microsoft.Compute/virtualMachines@2023-09-01' = {\n name: name\n location: location\n zones: [\n '1'\n ]\n properties: {\n hardwareProfile: {\n vmSize: 'Standard_D2s_v3'\n }\n osProfile: {\n computerName: name\n adminUsername: adminUsername\n adminPassword: adminPassword\n }\n storageProfile: {\n imageReference: {\n publisher: 'MicrosoftWindowsServer'\n offer: 'WindowsServer'\n sku: sku\n version: 'latest'\n }\n osDisk: {\n name: '${name}-disk0'\n caching: 'ReadWrite'\n createOption: 'FromImage'\n managedDisk: {\n storageAccountType: 'Premium_LRS'\n }\n }\n }\n licenseType: 'Windows_Server'\n networkProfile: {\n networkInterfaces: [\n {\n id: nic.id\n }\n ]\n }\n }\n}\n
","tags":["Azure.VM.UseHybridUseBenefit","AZR-000243"]},{"location":"en/rules/Azure.VM.UseHybridUseBenefit/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz vm update -n '<name>' -g '<resource_group>' --set licenseType=Windows_Server\n
","tags":["Azure.VM.UseHybridUseBenefit","AZR-000243"]},{"location":"en/rules/Azure.VM.UseHybridUseBenefit/#notes","title":"Notes","text":"This rule is not processed by default. To enable this rule, set the AZURE_VM_USE_AZURE_HYBRID_BENEFIT
configuration value to true
.
For example:
ps-rule.yamlconfiguration:\n AZURE_VM_USE_AZURE_HYBRID_BENEFIT: true\n
The following limitations currently apply:
Reliability \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Virtual machines (VMs) should use managed disks.
","tags":["Azure.VM.UseManagedDisks","AZR-000238"]},{"location":"en/rules/Azure.VM.UseManagedDisks/#description","title":"Description","text":"VMs can be configured with un-managed or managed disks. Un-managed disks, are .vhd
files stored on a Storage Account that you manage as files. Managed disks are the successor to un-managed disks and improve durability and availability of VMs by the following:
Additionally, managed disks provide the following benefits:
Consider using managed disks for virtual machine (VM) storage.
","tags":["Azure.VM.UseManagedDisks","AZR-000238"]},{"location":"en/rules/Azure.VM.UseManagedDisks/#examples","title":"Examples","text":"","tags":["Azure.VM.UseManagedDisks","AZR-000238"]},{"location":"en/rules/Azure.VM.UseManagedDisks/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy VMs that pass this rule:
properties.storageProfile.osDisk.managedDisk.storageAccountType
property to valid storage type.properties.storageProfile.osDisk.createOption
property to FromImage
.properties.storageProfile.osDisk.createOption
property to Attach
.properties.storageProfile.osDisk.managedDisk.id
property to the resource ID of an existing disk resource.properties.storageProfile.dataDisks[*].managedDisk.storageAccountType
property to valid storage type.properties.storageProfile.dataDisks[*].createOption
property to Empty
or FromImage
.properties.storageProfile.dataDisks[*].managedDisk.id
property to the resource ID of an existing disk resource.properties.storageProfile.dataDisks[*].createOption
property to Attach
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Compute/virtualMachines\",\n \"apiVersion\": \"2023-09-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"zones\": [\n \"1\"\n ],\n \"properties\": {\n \"hardwareProfile\": {\n \"vmSize\": \"Standard_D2s_v3\"\n },\n \"osProfile\": {\n \"computerName\": \"[parameters('name')]\",\n \"adminUsername\": \"[parameters('adminUsername')]\",\n \"adminPassword\": \"[parameters('adminPassword')]\"\n },\n \"storageProfile\": {\n \"imageReference\": {\n \"publisher\": \"MicrosoftWindowsServer\",\n \"offer\": \"WindowsServer\",\n \"sku\": \"[parameters('sku')]\",\n \"version\": \"latest\"\n },\n \"osDisk\": {\n \"name\": \"[format('{0}-disk0', parameters('name'))]\",\n \"caching\": \"ReadWrite\",\n \"createOption\": \"FromImage\",\n \"managedDisk\": {\n \"storageAccountType\": \"Premium_LRS\"\n }\n },\n \"dataDisks\": [\n {\n \"createOption\": \"Attach\",\n \"lun\": 0,\n \"managedDisk\": {\n \"id\": \"[parameters('dataDiskId')]\"\n }\n }\n ]\n },\n \"networkProfile\": {\n \"networkInterfaces\": [\n {\n \"id\": \"[resourceId('Microsoft.Network/networkInterfaces', parameters('nicName'))]\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Network/networkInterfaces', parameters('nicName'))]\"\n ]\n}\n
","tags":["Azure.VM.UseManagedDisks","AZR-000238"]},{"location":"en/rules/Azure.VM.UseManagedDisks/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy VMs that pass this rule:
properties.storageProfile.osDisk.managedDisk.storageAccountType
property to valid storage type.properties.storageProfile.osDisk.createOption
property to FromImage
.properties.storageProfile.osDisk.createOption
property to Attach
.properties.storageProfile.osDisk.managedDisk.id
property to the resource ID of an existing disk resource.properties.storageProfile.dataDisks[*].managedDisk.storageAccountType
property to valid storage type.properties.storageProfile.dataDisks[*].createOption
property to Empty
or FromImage
.properties.storageProfile.dataDisks[*].managedDisk.id
property to the resource ID of an existing disk resource.properties.storageProfile.dataDisks[*].createOption
property to Attach
.For example:
Azure Bicep snippetresource vm 'Microsoft.Compute/virtualMachines@2023-09-01' = {\n name: name\n location: location\n zones: [\n '1'\n ]\n properties: {\n hardwareProfile: {\n vmSize: 'Standard_D2s_v3'\n }\n osProfile: {\n computerName: name\n adminUsername: adminUsername\n adminPassword: adminPassword\n }\n storageProfile: {\n imageReference: {\n publisher: 'MicrosoftWindowsServer'\n offer: 'WindowsServer'\n sku: sku\n version: 'latest'\n }\n osDisk: {\n name: '${name}-disk0'\n caching: 'ReadWrite'\n createOption: 'FromImage'\n managedDisk: {\n storageAccountType: 'Premium_LRS'\n }\n }\n dataDisks: [\n {\n createOption: 'Attach'\n lun: 0\n managedDisk: {\n id: dataDiskId\n }\n }\n ]\n }\n networkProfile: {\n networkInterfaces: [\n {\n id: nic.id\n }\n ]\n }\n }\n}\n
","tags":["Azure.VM.UseManagedDisks","AZR-000238"]},{"location":"en/rules/Azure.VM.UseManagedDisks/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/06a78e20-9358-41c9-923c-fb736d382a4d
.Operational Excellence \u00b7 Virtual Machine Scale Sets \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Use Azure Monitor Agent for collecting monitoring data from VM scale sets.
","tags":["Azure.VMSS.AMA","AZR-000346"]},{"location":"en/rules/Azure.VMSS.AMA/#description","title":"Description","text":"Azure Monitor Agent (AMA) collects monitoring data from the guest operating system of virtual machine scale sets (VMSS) instances. Data collected gets delivered to Azure Monitor for use by features, insights and other services, such as Microsoft Defender for Cloud.
Azure Monitor Agent replaces all of Azure Monitor's legacy monitoring agents.
","tags":["Azure.VMSS.AMA","AZR-000346"]},{"location":"en/rules/Azure.VMSS.AMA/#recommendation","title":"Recommendation","text":"Consider monitoring Virtual Machine Scale Sets instances using the Azure Monitor Agent.
","tags":["Azure.VMSS.AMA","AZR-000346"]},{"location":"en/rules/Azure.VMSS.AMA/#examples","title":"Examples","text":"","tags":["Azure.VMSS.AMA","AZR-000346"]},{"location":"en/rules/Azure.VMSS.AMA/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy virtual machine scale sets that pass this rule:
properties.virtualMachineProfile.extensionProfile.extensions.properties.publisher
to Microsoft.Azure.Monitor
.properties.virtualMachineProfile.extensionProfile.extensions.properties.type
to AzureMonitorWindowsAgent
(Windows) or AzureMonitorLinuxAgent
(Linux).For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"vmssName\": {\n \"type\": \"string\",\n \"defaultValue\": \"vmss-01\"\n },\n \"location\": {\n \"type\": \"string\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Compute/virtualMachineScaleSets\",\n \"apiVersion\": \"2022-08-01\",\n \"name\": \"[parameters('vmssName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"b2ms\",\n \"tier\": \"Standard\",\n \"capacity\": 1\n },\n \"properties\": {\n \"overprovision\": true,\n \"upgradePolicy\": {\n \"mode\": \"Automatic\"\n },\n \"singlePlacementGroup\": true,\n \"platformFaultDomainCount\": 3,\n \"virtualMachineProfile\": {\n \"extensionProfile\": {\n \"extensions\": [\n {\n \"name\": \"[format('{0}/AzureMonitorLinuxAgent', parameters('vmssName'))]\",\n \"properties\": {\n \"autoUpgradeMinorVersion\": true,\n \"enableAutomaticUpgrade\": true,\n \"publisher\": \"Microsoft.Azure.Monitor\",\n \"type\": \"AzureMonitorLinuxAgent\",\n \"typeHandlerVersion\": \"1.21\"\n }\n }\n ]\n },\n \"storageProfile\": {\n \"osDisk\": {\n \"caching\": \"ReadWrite\",\n \"createOption\": \"FromImage\"\n },\n \"imageReference\": {\n \"publisher\": \"microsoft-aks\",\n \"offer\": \"aks\",\n \"sku\": \"aks-ubuntu-1804-202208\",\n \"version\": \"2022.08.29\"\n }\n },\n \"osProfile\": {\n \"adminUsername\": \"azureuser\",\n \"computerNamePrefix\": \"vmss-01\",\n \"linuxConfiguration\": {\n \"disablePasswordAuthentication\": true\n },\n \"provisionVMAgent\": true,\n \"ssh\": {\n \"publicKeys\": [\n {\n \"path\": \"/home/azureuser/.ssh/authorized_keys\"\n }\n ]\n }\n },\n \"networkProfile\": {\n \"networkInterfaceConfigurations\": [\n {\n \"name\": \"vmss-001\",\n \"properties\": {\n \"primary\": true,\n \"enableAcceleratedNetworking\": true,\n \"networkSecurityGroup\": {\n \"id\": \"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/networkSecurityGroups/nsg-001\"\n },\n \"ipConfigurations\": [\n {\n \"name\": \"ipconfig1\",\n \"properties\": {\n \"primary\": true,\n \"subnet\": {\n \"id\": \"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/virtualNetworks/vnet-001/subnets/subnet-001\"\n },\n \"privateIPAddressVersion\": \"IPv4\",\n \"loadBalancerBackendAddressPools\": [\n {\n \"id\": \"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/loadBalancers/kubernetes/backendAddressPools/kubernetes\"\n }\n ]\n }\n }\n ]\n }\n }\n ]\n }\n }\n }\n }\n ]\n}\n
To deploy virtual machine scale sets with a extension sub resource that pass this rule:
Microsoft.Compute/virtualMachines/extensions
.properties.publisher
to Microsoft.Azure.Monitor
.properties.type
to AzureMonitorWindowsAgent
(Windows) or AzureMonitorLinuxAgent
(Linux).For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"vmssName\": {\n \"type\": \"string\"\n },\n \"location\": {\n \"type\": \"string\"\n },\n \"userAssignedManagedIdentity\": {\n \"type\": \"string\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Compute/virtualMachineScaleSets/extensions\",\n \"apiVersion\": \"2022-08-01\",\n \"name\": \"[format('{0}/AzureMonitorLinuxAgent', parameters('vmssName'))]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"publisher\": \"Microsoft.Azure.Monitor\",\n \"type\": \"AzureMonitorLinuxAgent\",\n \"typeHandlerVersion\": \"1.21\",\n \"settings\": {\n \"authentication\": {\n \"managedIdentity\": {\n \"identifier-name\": \"mi_res_id\",\n \"identifier-value\": \"[parameters('userAssignedManagedIdentity')]\"\n }\n }\n },\n \"autoUpgradeMinorVersion\": true,\n \"enableAutomaticUpgrade\": true\n }\n }\n ]\n}\n
","tags":["Azure.VMSS.AMA","AZR-000346"]},{"location":"en/rules/Azure.VMSS.AMA/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy virtual machine scale sets that pass this rule:
properties.virtualMachineProfile.extensionProfile.extensions.properties.publisher
to Microsoft.Azure.Monitor
.properties.virtualMachineProfile.extensionProfile.extensions.properties.type
to AzureMonitorWindowsAgent
(Windows) or AzureMonitorLinuxAgent
(Linux).For example:
Azure Bicep snippetparam vmssName string = 'vmss-01'\nparam location string\n\nresource vmScaleSet 'Microsoft.Compute/virtualMachineScaleSets@2022-08-01' = {\n name: vmssName\n location: location\n sku: {\n name: 'b2ms'\n tier: 'Standard'\n capacity: 1\n }\n properties: {\n overprovision: true\n upgradePolicy: {\n mode: 'Automatic'\n }\n singlePlacementGroup: true\n platformFaultDomainCount: 3\n virtualMachineProfile: {\n extensionProfile: {\n extensions: [\n {\n name: '${vmssName}/AzureMonitorLinuxAgent'\n\n properties: {\n autoUpgradeMinorVersion: true\n enableAutomaticUpgrade: true\n publisher: 'Microsoft.Azure.Monitor'\n type: 'AzureMonitorLinuxAgent'\n typeHandlerVersion: '1.21'\n }\n }\n ]\n }\n storageProfile: {\n osDisk: {\n caching: 'ReadWrite'\n createOption: 'FromImage'\n }\n imageReference: {\n publisher: 'microsoft-aks'\n offer: 'aks'\n sku: 'aks-ubuntu-1804-202208'\n version: '2022.08.29'\n }\n }\n osProfile: {\n adminUsername: 'azureuser'\n computerNamePrefix: 'vmss-01'\n linuxConfiguration: {\n disablePasswordAuthentication: true\n }\n provisionVMAgent: true\n ssh: {\n publicKeys: [\n {\n path: '/home/azureuser/.ssh/authorized_keys'\n }\n ]\n }\n }\n networkProfile: {\n networkInterfaceConfigurations: [\n {\n name: 'vmss-001'\n properties: {\n primary: true\n enableAcceleratedNetworking: true\n networkSecurityGroup: {\n id: '/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/networkSecurityGroups/nsg-001'\n }\n ipConfigurations: [\n {\n name: 'ipconfig1'\n properties: {\n primary: true\n subnet: {\n id: '/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/virtualNetworks/vnet-001/subnets/subnet-001'\n }\n privateIPAddressVersion: 'IPv4'\n loadBalancerBackendAddressPools: [\n {\n id: '/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/loadBalancers/kubernetes/backendAddressPools/kubernetes'\n }\n ]\n }\n }\n ]\n }\n }\n ]\n }\n }\n }\n}\n
To deploy virtual machine scale sets with a extension sub resource that pass this rule:
Microsoft.Compute/virtualMachines/extensions
.properties.publisher
to Microsoft.Azure.Monitor
.properties.type
to AzureMonitorWindowsAgent
(Windows) or AzureMonitorLinuxAgent
(Linux).For example:
Azure Bicep snippetparam vmssName string\nparam location string\nparam userAssignedManagedIdentity string\n\nresource linuxAgent 'Microsoft.Compute/virtualMachineScaleSets/extensions@2022-08-01' = {\n name: '${vmssName}/AzureMonitorLinuxAgent'\n location: location\n properties: {\n publisher: 'Microsoft.Azure.Monitor'\n type: 'AzureMonitorLinuxAgent'\n typeHandlerVersion: '1.21'\n autoUpgradeMinorVersion: true\n enableAutomaticUpgrade: true\n settings: {\n authentication: {\n managedIdentity: {\n identifier-name: 'mi_res_id'\n identifier-value: userAssignedManagedIdentity\n }\n }\n }\n }\n}\n
","tags":["Azure.VMSS.AMA","AZR-000346"]},{"location":"en/rules/Azure.VMSS.AMA/#notes","title":"Notes","text":"The Azure Monitor Agent (AMA) itself does not include all configuration needed, additionally data collection rules and associations are required.
","tags":["Azure.VMSS.AMA","AZR-000346"]},{"location":"en/rules/Azure.VMSS.AMA/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Machine Scale Sets \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Virtual Machine Scale Set (VMSS) computer name should meet naming requirements.
","tags":["Azure.VMSS.ComputerName","AZR-000262"]},{"location":"en/rules/Azure.VMSS.ComputerName/#description","title":"Description","text":"When configuring Azure VMSS the assigned computer name prefix must meet operation system (OS) requirements.
The requirements for Windows VM instances are:
The requirements for Linux VM instances are:
Consider using computer names that meet OS naming requirements. Additionally, consider using computer names that match the VMSS resource name.
","tags":["Azure.VMSS.ComputerName","AZR-000262"]},{"location":"en/rules/Azure.VMSS.ComputerName/#notes","title":"Notes","text":"VMSS resource names have different naming restrictions. See Azure.VMSS.Name
for details.
Operational Excellence \u00b7 Virtual Machine Scale Sets \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Use Azure Monitor Agent as replacement for Log Analytics Agent.
","tags":["Azure.VMSS.MigrateAMA","AZR-000318"]},{"location":"en/rules/Azure.VMSS.MigrateAMA/#description","title":"Description","text":"The legacy Log Analytics agent will be retired on August 31, 2024. Before that date, you'll need to start using the Azure Monitor agent to monitor your virtual machine scale sets. The Azure Monitor agent provdes the following benefits over legacy agents:
Virtual Machine Scale Sets should migrate to Azure Monitor Agent.
","tags":["Azure.VMSS.MigrateAMA","AZR-000318"]},{"location":"en/rules/Azure.VMSS.MigrateAMA/#examples","title":"Examples","text":"","tags":["Azure.VMSS.MigrateAMA","AZR-000318"]},{"location":"en/rules/Azure.VMSS.MigrateAMA/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy virtual machine scale sets that pass this rule:
properties.virtualMachineProfile.extensionProfile.extensions.properties.publisher
to 'Microsoft.Azure.Monitor'
.properties.virtualMachineProfile.extensionProfile.extensions.properties.type
to 'AzureMonitorWindowsAgent'
(Windows) or 'AzureMonitorLinuxAgent'
(Linux).For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"vmssName\": {\n \"type\": \"string\",\n \"defaultValue\": \"vmss-01\"\n },\n \"location\": {\n \"type\": \"string\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Compute/virtualMachineScaleSets\",\n \"apiVersion\": \"2022-08-01\",\n \"name\": \"[parameters('vmssName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"b2ms\",\n \"tier\": \"Standard\",\n \"capacity\": 1\n },\n \"properties\": {\n \"overprovision\": true,\n \"upgradePolicy\": {\n \"mode\": \"Automatic\"\n },\n \"singlePlacementGroup\": true,\n \"platformFaultDomainCount\": 3,\n \"virtualMachineProfile\": {\n \"extensionProfile\": {\n \"extensions\": [\n {\n \"name\": \"[format('{0}/AzureMonitorLinuxAgent', parameters('vmssName'))]\",\n \"properties\": {\n \"autoUpgradeMinorVersion\": true,\n \"enableAutomaticUpgrade\": true,\n \"publisher\": \"Microsoft.Azure.Monitor\",\n \"type\": \"AzureMonitorLinuxAgent\",\n \"typeHandlerVersion\": \"1.21\"\n }\n }\n ]\n },\n \"storageProfile\": {\n \"osDisk\": {\n \"caching\": \"ReadWrite\",\n \"createOption\": \"FromImage\"\n },\n \"imageReference\": {\n \"publisher\": \"microsoft-aks\",\n \"offer\": \"aks\",\n \"sku\": \"aks-ubuntu-1804-202208\",\n \"version\": \"2022.08.29\"\n }\n },\n \"osProfile\": {\n \"adminUsername\": \"azureuser\",\n \"computerNamePrefix\": \"vmss-01\",\n \"linuxConfiguration\": {\n \"disablePasswordAuthentication\": true\n },\n \"provisionVMAgent\": true,\n \"ssh\": {\n \"publicKeys\": [\n {\n \"path\": \"/home/azureuser/.ssh/authorized_keys\"\n }\n ]\n }\n },\n \"networkProfile\": {\n \"networkInterfaceConfigurations\": [\n {\n \"name\": \"vmss-001\",\n \"properties\": {\n \"primary\": true,\n \"enableAcceleratedNetworking\": true,\n \"networkSecurityGroup\": {\n \"id\": \"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/networkSecurityGroups/nsg-001\"\n },\n \"ipConfigurations\": [\n {\n \"name\": \"ipconfig1\",\n \"properties\": {\n \"primary\": true,\n \"subnet\": {\n \"id\": \"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/virtualNetworks/vnet-001/subnets/subnet-001\"\n },\n \"privateIPAddressVersion\": \"IPv4\",\n \"loadBalancerBackendAddressPools\": [\n {\n \"id\": \"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/loadBalancers/kubernetes/backendAddressPools/kubernetes\"\n }\n ]\n }\n }\n ]\n }\n }\n ]\n }\n }\n }\n }\n ]\n}\n
To deploy virtual machine scale sets with a extension sub resource that pass this rule:
properties.publisher
to 'Microsoft.Azure.Monitor'
.properties.type
to 'AzureMonitorWindowsAgent'
(Windows) or 'AzureMonitorLinuxAgent'
(Linux).For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"vmssName\": {\n \"type\": \"string\"\n },\n \"location\": {\n \"type\": \"string\"\n },\n \"userAssignedManagedIdentity\": {\n \"type\": \"string\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Compute/virtualMachineScaleSets/extensions\",\n \"apiVersion\": \"2022-08-01\",\n \"name\": \"[format('{0}/AzureMonitorLinuxAgent', parameters('vmssName'))]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"publisher\": \"Microsoft.Azure.Monitor\",\n \"type\": \"AzureMonitorLinuxAgent\",\n \"typeHandlerVersion\": \"1.21\",\n \"settings\": {\n \"authentication\": {\n \"managedIdentity\": {\n \"identifier-name\": \"mi_res_id\",\n \"identifier-value\": \"[parameters('userAssignedManagedIdentity')]\"\n }\n }\n },\n \"autoUpgradeMinorVersion\": true,\n \"enableAutomaticUpgrade\": true\n }\n }\n ]\n}\n
","tags":["Azure.VMSS.MigrateAMA","AZR-000318"]},{"location":"en/rules/Azure.VMSS.MigrateAMA/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy virtual machine scale sets that pass this rule:
properties.virtualMachineProfile.extensionProfile.extensions.properties.publisher
to 'Microsoft.Azure.Monitor'
.properties.virtualMachineProfile.extensionProfile.extensions.properties.type
to 'AzureMonitorWindowsAgent'
(Windows) or 'AzureMonitorLinuxAgent'
(Linux).For example:
Azure Bicep snippetparam vmssName string = 'vmss-01'\nparam location string\n\nresource vmScaleSet 'Microsoft.Compute/virtualMachineScaleSets@2022-08-01' = {\n name: vmssName\n location: location\n sku: {\n name: 'b2ms'\n tier: 'Standard'\n capacity: 1\n }\n properties: {\n overprovision: true\n upgradePolicy: {\n mode: 'Automatic'\n }\n singlePlacementGroup: true\n platformFaultDomainCount: 3\n virtualMachineProfile: {\n extensionProfile: {\n extensions: [\n {\n name: '${vmssName}/AzureMonitorLinuxAgent'\n\n properties: {\n autoUpgradeMinorVersion: true\n enableAutomaticUpgrade: true\n publisher: 'Microsoft.Azure.Monitor'\n type: 'AzureMonitorLinuxAgent'\n typeHandlerVersion: '1.21'\n }\n }\n ]\n }\n storageProfile: {\n osDisk: {\n caching: 'ReadWrite'\n createOption: 'FromImage'\n }\n imageReference: {\n publisher: 'microsoft-aks'\n offer: 'aks'\n sku: 'aks-ubuntu-1804-202208'\n version: '2022.08.29'\n }\n }\n osProfile: {\n adminUsername: 'azureuser'\n computerNamePrefix: 'vmss-01'\n linuxConfiguration: {\n disablePasswordAuthentication: true\n }\n provisionVMAgent: true\n ssh: {\n publicKeys: [\n {\n path: '/home/azureuser/.ssh/authorized_keys'\n }\n ]\n }\n }\n networkProfile: {\n networkInterfaceConfigurations: [\n {\n name: 'vmss-001'\n properties: {\n primary: true\n enableAcceleratedNetworking: true\n networkSecurityGroup: {\n id: '/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/networkSecurityGroups/nsg-001'\n }\n ipConfigurations: [\n {\n name: 'ipconfig1'\n properties: {\n primary: true\n subnet: {\n id: '/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/virtualNetworks/vnet-001/subnets/subnet-001'\n }\n privateIPAddressVersion: 'IPv4'\n loadBalancerBackendAddressPools: [\n {\n id: '/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/loadBalancers/kubernetes/backendAddressPools/kubernetes'\n }\n ]\n }\n }\n ]\n }\n }\n ]\n }\n }\n }\n}\n
To deploy virtual machine scale sets with a extension sub resource that pass this rule:
properties.publisher
to 'Microsoft.Azure.Monitor'
.properties.type
to 'AzureMonitorWindowsAgent'
(Windows) or 'AzureMonitorLinuxAgent'
(Linux).For example:
Azure Bicep snippetparam vmssName string\nparam location string\nparam userAssignedManagedIdentity string\n\nresource linuxAgent 'Microsoft.Compute/virtualMachineScaleSets/extensions@2022-08-01' = {\n name: '${vmssName}/AzureMonitorLinuxAgent'\n location: location\n properties: {\n publisher: 'Microsoft.Azure.Monitor'\n type: 'AzureMonitorLinuxAgent'\n typeHandlerVersion: '1.21'\n autoUpgradeMinorVersion: true\n enableAutomaticUpgrade: true\n settings: {\n authentication: {\n managedIdentity: {\n identifier-name: 'mi_res_id'\n identifier-value: userAssignedManagedIdentity\n }\n }\n }\n }\n}\n
","tags":["Azure.VMSS.MigrateAMA","AZR-000318"]},{"location":"en/rules/Azure.VMSS.MigrateAMA/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Machine Scale Sets \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Virtual Machine Scale Set (VMSS) names should meet naming requirements.
","tags":["Azure.VMSS.Name","AZR-000261"]},{"location":"en/rules/Azure.VMSS.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for VMSS names are:
Consider using names that meet VMSS resource name requirements. Additionally, consider using a resource name that meeting OS naming requirements.
","tags":["Azure.VMSS.Name","AZR-000261"]},{"location":"en/rules/Azure.VMSS.Name/#notes","title":"Notes","text":"This rule does not check if VMSS names are unique. Additionally, VMSS computer names have additional restrictions. See Azure.VMSS.ComputerName
for details.
Security \u00b7 Virtual Machine Scale Sets \u00b7 Rule \u00b7 2022_09 \u00b7 Important
Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities.
","tags":["Azure.VMSS.PublicKey","AZR-000288"]},{"location":"en/rules/Azure.VMSS.PublicKey/#description","title":"Description","text":"Linux virtual machine scale sets should have password authentication disabled to help with eliminating password-based attacks.
A common tactic observed used by adversaries against customers running Linux Virtual Machines (VMs) in Azure is password-based attacks.
","tags":["Azure.VMSS.PublicKey","AZR-000288"]},{"location":"en/rules/Azure.VMSS.PublicKey/#recommendation","title":"Recommendation","text":"Linux virtual machine scale sets should have password authentication disabled and instead use SSH keys.
","tags":["Azure.VMSS.PublicKey","AZR-000288"]},{"location":"en/rules/Azure.VMSS.PublicKey/#examples","title":"Examples","text":"","tags":["Azure.VMSS.PublicKey","AZR-000288"]},{"location":"en/rules/Azure.VMSS.PublicKey/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy an virtual machine scale set that pass this rule:
properties.virtualMachineProfile.OsProfile.linuxConfiguration.disablePasswordAuthentication
to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Compute/virtualMachineScaleSets\",\n \"apiVersion\": \"2021-11-01\",\n \"name\": \"vmss-01\",\n \"location\": \"[resourceGroup().location]\",\n \"sku\": {\n \"name\": \"b2ms\",\n \"tier\": \"Standard\",\n \"capacity\": 1\n },\n \"properties\": {\n \"overprovision\": true,\n \"upgradePolicy\": {\n \"mode\": \"Automatic\"\n },\n \"singlePlacementGroup\": true,\n \"platformFaultDomainCount\": 3,\n \"virtualMachineProfile\": {\n \"storageProfile\": {\n \"osDisk\": {\n \"caching\": \"ReadWrite\",\n \"createOption\": \"FromImage\"\n },\n \"imageReference\": {\n \"publisher\": \"microsoft-aks\",\n \"offer\": \"aks\",\n \"sku\": \"aks-ubuntu-1804-202208\",\n \"version\": \"2022.08.29\"\n }\n },\n \"osProfile\": {\n \"adminUsername\": \"azureuser\",\n \"computerNamePrefix\": \"vmss-01\",\n \"linuxConfiguration\": {\n \"disablePasswordAuthentication\": true\n },\n \"provisionVMAgent\": true,\n \"ssh\": {\n \"publicKeys\": [\n {\n \"path\": \"/home/azureuser/.ssh/authorized_keys\"\n }\n ]\n }\n },\n \"networkProfile\": {\n \"networkInterfaceConfigurations\": [\n {\n \"name\": \"vmss-001\",\n \"properties\": {\n \"primary\": true,\n \"enableAcceleratedNetworking\": true,\n \"networkSecurityGroup\": {\n \"id\": \"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/networkSecurityGroups/nsg-001\"\n },\n \"ipConfigurations\": [\n {\n \"name\": \"ipconfig1\",\n \"properties\": {\n \"primary\": true,\n \"subnet\": {\n \"id\": \"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/virtualNetworks/vnet-001/subnets/subnet-001\"\n },\n \"privateIPAddressVersion\": \"IPv4\",\n \"loadBalancerBackendAddressPools\": [\n {\n \"id\": \"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/loadBalancers/kubernetes/backendAddressPools/kubernetes\"\n }\n ]\n }\n }\n ]\n }\n }\n ]\n }\n }\n }\n }\n
","tags":["Azure.VMSS.PublicKey","AZR-000288"]},{"location":"en/rules/Azure.VMSS.PublicKey/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy an virtual machine scale set that pass this rule:
properties.virtualMachineProfile.OsProfile.linuxConfiguration.disablePasswordAuthentication
to true
.For example:
Azure Bicep snippetresource vmScaleSet 'Microsoft.Compute/virtualMachineScaleSets@2021-11-01' = {\n name: 'vmss-01'\n location: resourceGroup().location\n sku: {\n name: 'b2ms'\n tier: 'Standard'\n capacity: 1\n }\n properties: {\n overprovision: true\n upgradePolicy: {\n mode: 'Automatic'\n }\n singlePlacementGroup: true\n platformFaultDomainCount: 3\n virtualMachineProfile: {\n storageProfile: {\n osDisk: {\n caching: 'ReadWrite'\n createOption: 'FromImage'\n }\n imageReference: {\n publisher: 'microsoft-aks'\n offer: 'aks'\n sku: 'aks-ubuntu-1804-202208'\n version: '2022.08.29'\n } \n }\n osProfile: {\n adminUsername: 'azureuser'\n computerNamePrefix: 'vmss-01'\n linuxConfiguration: {\n disablePasswordAuthentication: true\n }\n provisionVMAgent: true\n ssh: {\n publicKeys: [\n {\n path: '/home/azureuser/.ssh/authorized_keys'\n }\n ]\n }\n }\n networkProfile: {\n networkInterfaceConfigurations: [\n {\n name: 'vmss-001'\n properties: {\n primary: true\n enableAcceleratedNetworking: true\n networkSecurityGroup: {\n id: '/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/networkSecurityGroups/nsg-001'\n }\n ipConfigurations: [\n {\n name: 'ipconfig1'\n properties: {\n primary: true\n subnet: {\n id: '/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/virtualNetworks/vnet-001/subnets/subnet-001'\n }\n privateIPAddressVersion: 'IPv4'\n loadBalancerBackendAddressPools: [\n {\n id: '/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/loadBalancers/kubernetes/backendAddressPools/kubernetes'\n }\n ]\n }\n }\n ]\n }\n }\n ]\n }\n }\n }\n}\n
","tags":["Azure.VMSS.PublicKey","AZR-000288"]},{"location":"en/rules/Azure.VMSS.PublicKey/#links","title":"Links","text":"Security \u00b7 Virtual Machine Scale Sets \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Custom Script Extensions scripts that reference secret values must use the protectedSettings.
","tags":["Azure.VMSS.ScriptExtensions","AZR-000333"]},{"location":"en/rules/Azure.VMSS.ScriptExtensions/#description","title":"Description","text":"Virtual Machines Scale Sets support the ability to execute custom scripts on launch. This can be configured via user data and custom script extensions. When the template is rendered, anything in the settings section will be rendered in clear text. To ensure they're kept secret, use the protectedSettings section instead.
","tags":["Azure.VMSS.ScriptExtensions","AZR-000333"]},{"location":"en/rules/Azure.VMSS.ScriptExtensions/#recommendation","title":"Recommendation","text":"Consider specifying secure values within properties.extensionProfile.extensions.protectedSettings
to avoid exposing secrets during extension deployments.
To deploy VMSS extensions that pass this rule:
properties.extensionProfile.extensions.protectedSettings
\"extensionProfile\": {\n \"extensions\": [\n {\n \"name\": \"customScript\",\n \"properties\": {\n \"publisher\": \"Microsoft.Compute\",\n \"protectedSettings\": {\n \"commandToExecute\": \"Write-Output 'example'\"\n },\n \"typeHandlerVersion\": \"1.8\",\n \"autoUpgradeMinorVersion\": true,\n \"type\": \"CustomScriptExtension\"\n }\n }\n ]\n}\n
","tags":["Azure.VMSS.ScriptExtensions","AZR-000333"]},{"location":"en/rules/Azure.VMSS.ScriptExtensions/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy VMSS extensions that pass this rule:
properties.extensionProfile.extensions.protectedSettings
extensionProfile: {\n extensions: [\n {\n name: 'customScript'\n properties: {\n publisher: 'Microsoft.Compute'\n protectedSettings: {\n commandToExecute: 'Write-Output \"example\"'\n },\n typeHandlerVersion: '1.8'\n autoUpgradeMinorVersion: true\n type: 'CustomScriptExtension'\n }\n }\n ]\n}\n
","tags":["Azure.VMSS.ScriptExtensions","AZR-000333"]},{"location":"en/rules/Azure.VMSS.ScriptExtensions/#links","title":"Links","text":"Reliability \u00b7 Virtual Network \u00b7 Rule \u00b7 2022_12 \u00b7 Important
VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs.
","tags":["Azure.VNET.BastionSubnet","AZR-000314"]},{"location":"en/rules/Azure.VNET.BastionSubnet/#description","title":"Description","text":"Azure Bastion lets you securely connect to a virtual machine using your browser or native SSH/RDP client on Windows workstations or the Azure portal. An Azure Bastion host is deployed inside an Azure Virtual Network and can access virtual machines in the virtual network (VNet), or virtual machines in peered VNets.
Azure Bastion is a fully managed service that provides more secure and seamless Remote Desktop Protocol (RDP) and Secure Shell Protocol (SSH) access to virtual machines (VMs), without any exposure through public IP addresses.
This is a recommended pattern for virtual machine remote access.
Adding Azure Bastion in your configuration adds the following benefits:
Consider an Azure Bastion Subnet to allow for out of band remote access to VMs and provide an extra layer of control.
","tags":["Azure.VNET.BastionSubnet","AZR-000314"]},{"location":"en/rules/Azure.VNET.BastionSubnet/#examples","title":"Examples","text":"","tags":["Azure.VNET.BastionSubnet","AZR-000314"]},{"location":"en/rules/Azure.VNET.BastionSubnet/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Virtual Networks that pass this rule:
AzureBastionSubnet
defined in properties.subnets
.For example:
Azure Template snippet{\n \"apiVersion\": \"2023-05-01\",\n \"type\": \"Microsoft.Network/virtualNetworks\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"addressSpace\": {\n \"addressPrefixes\": [\"10.0.0.0/16\"]\n },\n \"subnets\": [\n {\n \"name\": \"GatewaySubnet\",\n \"properties\": {\n \"addressPrefix\": \"10.0.0.0/27\"\n }\n },\n {\n \"name\": \"AzureBastionSubnet\",\n \"properties\": {\n \"addressPrefix\": \"10.0.1.64/26\"\n }\n }\n ]\n }\n}\n
To deploy Virtual Networks with a subnet sub-resource that pass this rule:
AzureBastionSubnet
sub-resource.For example:
Azure Template snippet{\n \"apiVersion\": \"2023-05-01\",\n \"type\": \"Microsoft.Network/virtualNetworks/subnets\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'AzureBastionSubnet')]\",\n \"properties\": {\n \"addressPrefix\": \"10.0.1.64/26\"\n },\n \"dependsOn\": [\"[resourceId('Microsoft.Network/virtualNetworks', parameters('name'))]\"]\n}\n
","tags":["Azure.VNET.BastionSubnet","AZR-000314"]},{"location":"en/rules/Azure.VNET.BastionSubnet/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Virtual Networks that pass this rule:
AzureBastionSubnet
defined in properties.subnets
.For example:
Azure Bicep snippetresource vnet 'Microsoft.Network/virtualNetworks@2023-05-01' = {\n name: name\n location: location\n properties: {\n addressSpace: {\n addressPrefixes: [\n '10.0.0.0/16'\n ]\n }\n subnets: [\n {\n name: 'GatewaySubnet'\n properties: {\n addressPrefix: '10.0.0.0/27'\n }\n }\n {\n name: 'AzureBastionSubnet'\n properties: {\n addressPrefix: '10.0.1.64/26'\n }\n }\n ]\n }\n}\n
To deploy Virtual Networks with a subnet sub-resource that pass this rule:
AzureBastionSubnet
sub-resource.For example:
Azure Bicep snippetresource bastionSubnet 'Microsoft.Network/virtualNetworks/subnets@2023-05-01' = {\n name: 'AzureBastionSubnet'\n parent: vnet\n properties: {\n addressPrefix: '10.0.1.64/26'\n }\n}\n
","tags":["Azure.VNET.BastionSubnet","AZR-000314"]},{"location":"en/rules/Azure.VNET.BastionSubnet/#links","title":"Links","text":"Security \u00b7 Virtual Network \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Use Azure Firewall to filter network traffic to and from Azure resources.
","tags":["Azure.VNET.FirewallSubnet","AZR-000322"]},{"location":"en/rules/Azure.VNET.FirewallSubnet/#description","title":"Description","text":"Network segmentation is a key component of a secure network architecture. Azure provides several features that work together to provide strong network segmentation controls.
Azure Firewall is a cloud native stateful Firewall as a service. It can be used to perform deep packet inspection on both east-west and north-south traffic. Firewalls rules can be defined as policies and centrally managed.
Some key advantages that Azure Firewall has over traditional solutions include:
For guidance on defining your network topology in Azure see Cloud Adoption Framework (CAF).
","tags":["Azure.VNET.FirewallSubnet","AZR-000322"]},{"location":"en/rules/Azure.VNET.FirewallSubnet/#recommendation","title":"Recommendation","text":"Consider deploying an Azure Firewall within hub networks to filter traffic between VNETs and on-premises networks.
","tags":["Azure.VNET.FirewallSubnet","AZR-000322"]},{"location":"en/rules/Azure.VNET.FirewallSubnet/#examples","title":"Examples","text":"","tags":["Azure.VNET.FirewallSubnet","AZR-000322"]},{"location":"en/rules/Azure.VNET.FirewallSubnet/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Virtual Networks that pass this rule:
AzureFirewallSubnet
defined in properties.subnets
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/virtualNetworks\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"addressSpace\": {\n \"addressPrefixes\": [\n \"10.0.0.0/16\"\n ]\n },\n \"subnets\": [\n {\n \"name\": \"GatewaySubnet\",\n \"properties\": {\n \"addressPrefix\": \"10.0.0.0/27\"\n }\n },\n {\n \"name\": \"AzureFirewallSubnet\",\n \"properties\": {\n \"addressPrefix\": \"10.0.1.0/26\"\n }\n }\n ]\n }\n}\n
","tags":["Azure.VNET.FirewallSubnet","AZR-000322"]},{"location":"en/rules/Azure.VNET.FirewallSubnet/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Virtual Networks that pass this rule:
AzureFirewallSubnet
defined in properties.subnets
.For example:
Azure Bicep snippetresource vnet 'Microsoft.Network/virtualNetworks@2023-05-01' = {\n name: name\n location: location\n properties: {\n addressSpace: {\n addressPrefixes: [\n '10.0.0.0/16'\n ]\n }\n subnets: [\n {\n name: 'GatewaySubnet'\n properties: {\n addressPrefix: '10.0.0.0/27'\n }\n }\n {\n name: 'AzureFirewallSubnet'\n properties: {\n addressPrefix: '10.0.1.0/26'\n }\n }\n ]\n }\n}\n
","tags":["Azure.VNET.FirewallSubnet","AZR-000322"]},{"location":"en/rules/Azure.VNET.FirewallSubnet/#links","title":"Links","text":"Reliability \u00b7 Virtual Network \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Virtual networks (VNETs) should use DNS servers deployed within the same Azure region.
","tags":["Azure.VNET.LocalDNS","AZR-000265"]},{"location":"en/rules/Azure.VNET.LocalDNS/#description","title":"Description","text":"Virtual networks allow one or more custom DNS servers to be specified. These DNS servers are inherited by connected services such as virtual machines.
When configuring custom DNS server IP addresses, these servers must be accessible for name resolution to occur. Connectivity between services may be impacted if DNS server IP addresses are temporarily or permanently unavailable.
Avoid taking a dependency on external DNS servers for local communication such as those deployed on-premises. This can be achieved by using DNS services deployed into the same Azure region.
Where possible consider deploying:
Alternatively, redundant virtual machines (VMs) can be deployed into Azure to perform DNS resolution.
","tags":["Azure.VNET.LocalDNS","AZR-000265"]},{"location":"en/rules/Azure.VNET.LocalDNS/#recommendation","title":"Recommendation","text":"Consider deploying redundant DNS services within a connected Azure VNET.
","tags":["Azure.VNET.LocalDNS","AZR-000265"]},{"location":"en/rules/Azure.VNET.LocalDNS/#examples","title":"Examples","text":"","tags":["Azure.VNET.LocalDNS","AZR-000265"]},{"location":"en/rules/Azure.VNET.LocalDNS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Virtual Networks that pass this rule:
properties.dhcpOptions.dnsServers
to an IP address within the same or peered network within Azure. ORFor example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/virtualNetworks\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"addressSpace\": {\n \"addressPrefixes\": [\n \"10.0.0.0/16\"\n ]\n },\n \"dhcpOptions\": {\n \"dnsServers\": [\n \"10.0.1.4\",\n \"10.0.1.5\"\n ]\n }\n }\n}\n
","tags":["Azure.VNET.LocalDNS","AZR-000265"]},{"location":"en/rules/Azure.VNET.LocalDNS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Virtual Networks that pass this rule:
properties.dhcpOptions.dnsServers
to an IP address within the same or peered network within Azure. ORFor example:
Azure Bicep snippetresource vnet 'Microsoft.Network/virtualNetworks@2023-05-01' = {\n name: name\n location: location\n properties: {\n addressSpace: {\n addressPrefixes: [\n '10.0.0.0/16'\n ]\n }\n dhcpOptions: {\n dnsServers: [\n '10.0.1.4'\n '10.0.1.5'\n ]\n }\n }\n}\n
","tags":["Azure.VNET.LocalDNS","AZR-000265"]},{"location":"en/rules/Azure.VNET.LocalDNS/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed to Azure (in-flight).
When deploying Active Directory Domain Services (ADDS) within Azure, you may decide to:
When you do this, this rule may report a false positive by default. If you are using this configuration, we recommend you set the configuration option AZURE_VNET_DNS_WITH_IDENTITY
to true
.
For example:
configuration:\n AZURE_VNET_DNS_WITH_IDENTITY: true\n
","tags":["Azure.VNET.LocalDNS","AZR-000265"]},{"location":"en/rules/Azure.VNET.LocalDNS/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Network \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Virtual Network (VNET) names should meet naming requirements.
","tags":["Azure.VNET.Name","AZR-000268"]},{"location":"en/rules/Azure.VNET.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Virtual Network names are:
Consider using names that meet Virtual Network naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.VNET.Name","AZR-000268"]},{"location":"en/rules/Azure.VNET.Name/#notes","title":"Notes","text":"This rule does not check if Virtual Network names are unique.
","tags":["Azure.VNET.Name","AZR-000268"]},{"location":"en/rules/Azure.VNET.Name/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Network \u00b7 Rule \u00b7 2020_06 \u00b7 Important
VNET peering connections must be connected.
","tags":["Azure.VNET.PeerState","AZR-000266"]},{"location":"en/rules/Azure.VNET.PeerState/#description","title":"Description","text":"When peering virtual networks, a peering connection must be established from both virtual networks. Only once both peering connections are in the Connected state will traffic be allowed to flow between the virtual networks.
Connections in the Initiated
or Disconnected
state should be investigated to determine if the connection is required. When the connection is no longer required, it should be removed to prevent confusion during management and monitoring operations.
Most customers will use a hub and spoke topology to connect virtual networks. For guidance on defining your network topology in Azure see Cloud Adoption Framework (CAF).
","tags":["Azure.VNET.PeerState","AZR-000266"]},{"location":"en/rules/Azure.VNET.PeerState/#recommendation","title":"Recommendation","text":"Consider removing peering connections that are not longer required or complete peering connections.
","tags":["Azure.VNET.PeerState","AZR-000266"]},{"location":"en/rules/Azure.VNET.PeerState/#examples","title":"Examples","text":"","tags":["Azure.VNET.PeerState","AZR-000266"]},{"location":"en/rules/Azure.VNET.PeerState/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy virtual networks that pass this rule:
For example a peering connection from a spoke to a hub:
Azure Template snippet{\n \"type\": \"Microsoft.Network/virtualNetworks/virtualNetworkPeerings\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[format('{0}/{1}', parameters('spokeName'), format('peer-to-{0}', parameters('hubName')))]\",\n \"properties\": {\n \"remoteVirtualNetwork\": {\n \"id\": \"[resourceId('Microsoft.Network/virtualNetworks', parameters('hubName'))]\"\n },\n \"allowVirtualNetworkAccess\": true,\n \"allowForwardedTraffic\": true,\n \"allowGatewayTransit\": false,\n \"useRemoteGateways\": true\n }\n}\n
For example a peering connection from a hub to a spoke:
Azure Template snippet{\n \"type\": \"Microsoft.Network/virtualNetworks/virtualNetworkPeerings\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[format('{0}/{1}', parameters('hubName'), format('peer-to-{0}', parameters('spokeName')))]\",\n \"properties\": {\n \"remoteVirtualNetwork\": {\n \"id\": \"[resourceId('Microsoft.Network/virtualNetworks', parameters('spokeName'))]\"\n },\n \"allowVirtualNetworkAccess\": true,\n \"allowForwardedTraffic\": false,\n \"allowGatewayTransit\": true,\n \"useRemoteGateways\": false\n }\n}\n
","tags":["Azure.VNET.PeerState","AZR-000266"]},{"location":"en/rules/Azure.VNET.PeerState/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy virtual networks that pass this rule:
For example a peering connection from a spoke to a hub:
Azure Bicep snippetresource toHub 'Microsoft.Network/virtualNetworks/virtualNetworkPeerings@2023-05-01' = {\n parent: spoke\n name: 'peer-to-${hub.name}'\n properties: {\n remoteVirtualNetwork: {\n id: hub.id\n }\n allowVirtualNetworkAccess: true\n allowForwardedTraffic: true\n allowGatewayTransit: false\n useRemoteGateways: true\n }\n}\n
For example a peering connection from a hub to a spoke:
Azure Bicep snippetresource toSpoke 'Microsoft.Network/virtualNetworks/virtualNetworkPeerings@2023-05-01' = {\n parent: hub\n name: 'peer-to-${spoke.name}'\n properties: {\n remoteVirtualNetwork: {\n id: spoke.id\n }\n allowVirtualNetworkAccess: true\n allowForwardedTraffic: false\n allowGatewayTransit: true\n useRemoteGateways: false\n }\n}\n
","tags":["Azure.VNET.PeerState","AZR-000266"]},{"location":"en/rules/Azure.VNET.PeerState/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed to Azure (in-flight).
","tags":["Azure.VNET.PeerState","AZR-000266"]},{"location":"en/rules/Azure.VNET.PeerState/#links","title":"Links","text":"Reliability \u00b7 Virtual Network \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Virtual networks (VNETs) should have at least two DNS servers assigned.
","tags":["Azure.VNET.SingleDNS","AZR-000264"]},{"location":"en/rules/Azure.VNET.SingleDNS/#description","title":"Description","text":"Virtual networks (VNETs) should have at least two (2) DNS servers assigned. Using a single DNS server may indicate a single point of failure where the DNS IP address is not load balanced.
","tags":["Azure.VNET.SingleDNS","AZR-000264"]},{"location":"en/rules/Azure.VNET.SingleDNS/#recommendation","title":"Recommendation","text":"Virtual networks should have at least two (2) DNS servers set when not using Azure-provided DNS.
","tags":["Azure.VNET.SingleDNS","AZR-000264"]},{"location":"en/rules/Azure.VNET.SingleDNS/#examples","title":"Examples","text":"","tags":["Azure.VNET.SingleDNS","AZR-000264"]},{"location":"en/rules/Azure.VNET.SingleDNS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Virtual Networks that pass this rule:
properties.dhcpOptions.dnsServers
to at least two DNS server addresses. ORFor example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/virtualNetworks\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"addressSpace\": {\n \"addressPrefixes\": [\n \"10.0.0.0/16\"\n ]\n },\n \"dhcpOptions\": {\n \"dnsServers\": [\n \"10.0.1.4\",\n \"10.0.1.5\"\n ]\n }\n }\n}\n
","tags":["Azure.VNET.SingleDNS","AZR-000264"]},{"location":"en/rules/Azure.VNET.SingleDNS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Virtual Networks that pass this rule:
properties.dhcpOptions.dnsServers
to at least two DNS server addresses. ORFor example:
Azure Bicep snippetresource vnet 'Microsoft.Network/virtualNetworks@2023-05-01' = {\n name: name\n location: location\n properties: {\n addressSpace: {\n addressPrefixes: [\n '10.0.0.0/16'\n ]\n }\n dhcpOptions: {\n dnsServers: [\n '10.0.1.4'\n '10.0.1.5'\n ]\n }\n }\n}\n
","tags":["Azure.VNET.SingleDNS","AZR-000264"]},{"location":"en/rules/Azure.VNET.SingleDNS/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Network \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Subnet names should meet naming requirements.
","tags":["Azure.VNET.SubnetName","AZR-000267"]},{"location":"en/rules/Azure.VNET.SubnetName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Route table names are:
Consider using names that meet subnet naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.VNET.SubnetName","AZR-000267"]},{"location":"en/rules/Azure.VNET.SubnetName/#notes","title":"Notes","text":"This rule does not check if subnet names are unique.
","tags":["Azure.VNET.SubnetName","AZR-000267"]},{"location":"en/rules/Azure.VNET.SubnetName/#links","title":"Links","text":"Security \u00b7 Virtual Network \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned.
","tags":["Azure.VNET.UseNSGs","AZR-000263"]},{"location":"en/rules/Azure.VNET.UseNSGs/#description","title":"Description","text":"Each VNET subnet should have a network security group (NSG) assigned. NSGs are basic stateful firewalls that provide network isolation and security within a VNET. A key benefit of NSGS is that they provide network segmentation between and within a subnet.
NSGs can be assigned to a virtual machine network interface or a subnet. When assigning NSGs to a subnet, all network traffic within the subnet is subject to the NSG rules.
There is a small subset of special purpose subnets that do not support NSGs. These subnets are:
GatewaySubnet
- used for hybrid connectivity with VPN and ExpressRoute gateways.AzureFirewallSubnet
and AzureFirewallManagementSubnet
- are for Azure Firewall. Azure Firewall includes an intrinsic NSG that is not directly manageable or visible.RouteServerSubnet
- used by managed routing provided by Azure Route Server.Microsoft.HardwareSecurityModules/dedicatedHSMs
.Consider assigning a network security group (NSG) to each virtual network subnet.
","tags":["Azure.VNET.UseNSGs","AZR-000263"]},{"location":"en/rules/Azure.VNET.UseNSGs/#examples","title":"Examples","text":"","tags":["Azure.VNET.UseNSGs","AZR-000263"]},{"location":"en/rules/Azure.VNET.UseNSGs/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy virtual networks subnets that pass this rule:
properties.networkSecurityGroup.id
property for each supported subnet to a NSG resource id.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/virtualNetworks\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"addressSpace\": {\n \"addressPrefixes\": [\n \"10.0.0.0/16\"\n ]\n },\n \"dhcpOptions\": {\n \"dnsServers\": [\n \"10.0.1.4\",\n \"10.0.1.5\"\n ]\n },\n \"subnets\": [\n {\n \"name\": \"GatewaySubnet\",\n \"properties\": {\n \"addressPrefix\": \"10.0.0.0/24\"\n }\n },\n {\n \"name\": \"snet-001\",\n \"properties\": {\n \"addressPrefix\": \"10.0.1.0/24\",\n \"networkSecurityGroup\": {\n \"id\": \"[resourceId('Microsoft.Network/networkSecurityGroups', parameters('nsgName'))]\"\n }\n }\n }\n ]\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Network/networkSecurityGroups', parameters('nsgName'))]\"\n ]\n}\n
","tags":["Azure.VNET.UseNSGs","AZR-000263"]},{"location":"en/rules/Azure.VNET.UseNSGs/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy virtual network subnets that pass this rule:
properties.networkSecurityGroup.id
property for each supported subnet to a NSG resource id.For example:
Azure Bicep snippetresource vnet 'Microsoft.Network/virtualNetworks@2023-05-01' = {\n name: name\n location: location\n properties: {\n addressSpace: {\n addressPrefixes: [\n '10.0.0.0/16'\n ]\n }\n dhcpOptions: {\n dnsServers: [\n '10.0.1.4'\n '10.0.1.5'\n ]\n }\n subnets: [\n {\n name: 'GatewaySubnet'\n properties: {\n addressPrefix: '10.0.0.0/24'\n }\n }\n {\n name: 'snet-001'\n properties: {\n addressPrefix: '10.0.1.0/24'\n networkSecurityGroup: {\n id: nsg.id\n }\n }\n }\n ]\n }\n}\n
","tags":["Azure.VNET.UseNSGs","AZR-000263"]},{"location":"en/rules/Azure.VNET.UseNSGs/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz network vnet subnet update -n '<subnet>' -g '<resource_group>' --vnet-name '<vnet_name>' --network-security-group '<nsg_name>`\n
","tags":["Azure.VNET.UseNSGs","AZR-000263"]},{"location":"en/rules/Azure.VNET.UseNSGs/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippet$vnet = Get-AzVirtualNetwork -Name '<vnet_name>' -ResourceGroupName '<resource_group>'\n$nsg = Get-AzNetworkSecurityGroup -Name '<nsg_name>' -ResourceGroupName '<resource_group>'\nSet-AzVirtualNetworkSubnetConfig -Name '<subnet>' -VirtualNetwork $vnet -AddressPrefix '10.0.1.0/24' -NetworkSecurityGroup $nsg\n
","tags":["Azure.VNET.UseNSGs","AZR-000263"]},{"location":"en/rules/Azure.VNET.UseNSGs/#notes","title":"Notes","text":"If you identify a false postive for an Azure service that does not support NSGs, please open an issue to help us improve this rule.
To exclude subnets that are specific to your environment, use the AZURE_VNET_SUBNET_EXCLUDED_FROM_NSG
configuration option. Any subnet names specified by this option will be ignored by this rule.
For example:
configuration:\n AZURE_VNET_SUBNET_EXCLUDED_FROM_NSG:\n - subnet-1\n - subnet-2\n
","tags":["Azure.VNET.UseNSGs","AZR-000263"]},{"location":"en/rules/Azure.VNET.UseNSGs/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Network Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Virtual Network Gateway (VNG) connection names should meet naming requirements.
","tags":["Azure.VNG.ConnectionName","AZR-000275"]},{"location":"en/rules/Azure.VNG.ConnectionName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for connection names are:
Consider using names that meet connection naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.VNG.ConnectionName","AZR-000275"]},{"location":"en/rules/Azure.VNG.ConnectionName/#notes","title":"Notes","text":"This rule does not check if connection names are unique.
","tags":["Azure.VNG.ConnectionName","AZR-000275"]},{"location":"en/rules/Azure.VNG.ConnectionName/#links","title":"Links","text":"Reliability \u00b7 Virtual Network Gateway \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type.
","tags":["Azure.VNG.ERAvailabilityZoneSKU","AZR-000273"]},{"location":"en/rules/Azure.VNG.ERAvailabilityZoneSKU/#description","title":"Description","text":"ExpressRoute gateways can be deployed in Availability Zones with the following SKUs:
This brings resiliency, scalability, and higher availability to ExpressRoute gateways. Deploying ExpressRoute gateways in Azure Availability Zones physically and logically separates gateways within a region, while protecting your on-premises network connectivity to Azure from zone-level failures.
","tags":["Azure.VNG.ERAvailabilityZoneSKU","AZR-000273"]},{"location":"en/rules/Azure.VNG.ERAvailabilityZoneSKU/#recommendation","title":"Recommendation","text":"Consider deploying ExpressRoute gateways with an availability zone SKU to improve reliability of virtual network gateways.
","tags":["Azure.VNG.ERAvailabilityZoneSKU","AZR-000273"]},{"location":"en/rules/Azure.VNG.ERAvailabilityZoneSKU/#notes","title":"Notes","text":"ExpressRoute gateway availability zones are managed via Public IP addresses, and are flagged separately under the Azure.PublicIP.AvailabilityZone
rule.
To configure an AZ SKU for an ExpressRoute gateway:
properties.gatewayType
to 'ExpressRoute'
properties.sku.name
and properties.sku.tier
to one of the following AZ SKUs:'ErGw1AZ'
'ErGw2AZ'
'ErGw3AZ'
For example:
Azure Template snippet{\n \"apiVersion\": \"2020-11-01\",\n \"name\": \"[parameters('name')]\",\n \"type\": \"Microsoft.Network/virtualNetworkGateways\",\n \"location\": \"[parameters('location')]\",\n \"dependsOn\": [\n \"[concat('Microsoft.Network/publicIPAddresses/', parameters('newPublicIpAddressName'))]\"\n ],\n \"tags\": {},\n \"properties\": {\n \"gatewayType\": \"ExpressRoute\",\n \"ipConfigurations\": [\n {\n \"name\": \"default\",\n \"properties\": {\n \"privateIPAllocationMethod\": \"Dynamic\",\n \"subnet\": {\n \"id\": \"[parameters('subnetId')]\"\n },\n \"publicIpAddress\": {\n \"id\": \"[resourceId('vpn-rg', 'Microsoft.Network/publicIPAddresses', parameters('newPublicIpAddressName'))]\"\n }\n }\n }\n ],\n \"vpnType\": \"[parameters('vpnType')]\",\n \"vpnGatewayGeneration\": \"[parameters('vpnGatewayGeneration')]\",\n \"sku\": {\n \"name\": \"ErGw1AZ\",\n \"tier\": \"ErGw1AZ\"\n }\n }\n}\n
","tags":["Azure.VNG.ERAvailabilityZoneSKU","AZR-000273"]},{"location":"en/rules/Azure.VNG.ERAvailabilityZoneSKU/#configure-with-bicep","title":"Configure with Bicep","text":"To configure an AZ SKU for an ExpressRoute gateway:
properties.gatewayType
to 'ExpressRoute'
properties.sku.name
and properties.sku.tier
to one of the following AZ SKUs:'ErGw1AZ'
'ErGw2AZ'
'ErGw3AZ'
For example:
Azure Bicep snippetresource name_resource 'Microsoft.Network/virtualNetworkGateways@2020-11-01' = {\n name: name\n location: location\n tags: {}\n properties: {\n gatewayType: 'ExpressRoute'\n ipConfigurations: [\n {\n name: 'default'\n properties: {\n privateIPAllocationMethod: 'Dynamic'\n subnet: {\n id: subnetId\n }\n publicIPAddress: {\n id: resourceId('vpn-rg', 'Microsoft.Network/publicIPAddresses', newPublicIpAddressName)\n }\n }\n }\n ]\n vpnType: vpnType\n vpnGatewayGeneration: vpnGatewayGeneration\n sku: {\n name: 'ErGw1AZ'\n tier: 'ErGw1AZ'\n }\n }\n dependsOn: [\n newPublicIpAddressName_resource\n ]\n}\n
","tags":["Azure.VNG.ERAvailabilityZoneSKU","AZR-000273"]},{"location":"en/rules/Azure.VNG.ERAvailabilityZoneSKU/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Network Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways.
","tags":["Azure.VNG.ERLegacySKU","AZR-000271"]},{"location":"en/rules/Azure.VNG.ERLegacySKU/#description","title":"Description","text":"When deploying a ER gateway a number of options are available including SKU/ size. The gateway SKU affects the reliance and performance of the underlying gateway instances. Previously the following SKUs were available however have been depreciated.
Consider redeploying ER gateways using new SKUs to improve reliability and performance of gateways.
","tags":["Azure.VNG.ERLegacySKU","AZR-000271"]},{"location":"en/rules/Azure.VNG.ERLegacySKU/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Network Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Virtual Network Gateway (VNG) names should meet naming requirements.
","tags":["Azure.VNG.Name","AZR-000274"]},{"location":"en/rules/Azure.VNG.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for VNG names are:
Consider using names that meet Virtual Network Gateway (VNG) naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.VNG.Name","AZR-000274"]},{"location":"en/rules/Azure.VNG.Name/#notes","title":"Notes","text":"This rule does not check if VNG names are unique.
","tags":["Azure.VNG.Name","AZR-000274"]},{"location":"en/rules/Azure.VNG.Name/#links","title":"Links","text":"Reliability \u00b7 Virtual Network Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime.
","tags":["Azure.VNG.VPNActiveActive","AZR-000270"]},{"location":"en/rules/Azure.VNG.VPNActiveActive/#description","title":"Description","text":"VPN Gateways can be configured as either Active-Passive or Active-Active for Site-to-Site (S2S) connections. When deploying VPN gateways, Azure deploys two instances for high-availability (HA).
When using an Active-Passive configuration, one instance is designated a standby for failover.
Gateways configured to use an Active-Active configuration:
Consider using Active-Active VPN gateways to reduce connectivity downtime during HA failover.
","tags":["Azure.VNG.VPNActiveActive","AZR-000270"]},{"location":"en/rules/Azure.VNG.VPNActiveActive/#notes","title":"Notes","text":"Azure provisions a single instance for Basic (legacy) VPN gateways. As a result, Basic VPN gateways do not support Active-Active connections. To use Active-Active VPN connections, migrate to a gateway configured as VpnGw1 or higher SKU.
","tags":["Azure.VNG.VPNActiveActive","AZR-000270"]},{"location":"en/rules/Azure.VNG.VPNActiveActive/#links","title":"Links","text":"Reliability \u00b7 Virtual Network Gateway \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Use availability zone SKU for virtual network gateways deployed with VPN gateway type.
","tags":["Azure.VNG.VPNAvailabilityZoneSKU","AZR-000272"]},{"location":"en/rules/Azure.VNG.VPNAvailabilityZoneSKU/#description","title":"Description","text":"VPN gateways can be deployed in Availability Zones with the following SKUs:
This brings resiliency, scalability, and higher availability to VPN gateways. Deploying VPN gateways in Azure Availability Zones physically and logically separates gateways within a region, while protecting your on-premises network connectivity to Azure from zone-level failures.
","tags":["Azure.VNG.VPNAvailabilityZoneSKU","AZR-000272"]},{"location":"en/rules/Azure.VNG.VPNAvailabilityZoneSKU/#recommendation","title":"Recommendation","text":"Consider deploying VPN gateways with an availability zone SKU to improve reliability of virtual network gateways.
","tags":["Azure.VNG.VPNAvailabilityZoneSKU","AZR-000272"]},{"location":"en/rules/Azure.VNG.VPNAvailabilityZoneSKU/#examples","title":"Examples","text":"","tags":["Azure.VNG.VPNAvailabilityZoneSKU","AZR-000272"]},{"location":"en/rules/Azure.VNG.VPNAvailabilityZoneSKU/#configure-with-azure-template","title":"Configure with Azure template","text":"To configure an AZ SKU for a VPN gateway:
properties.gatewayType
to 'Vpn'
properties.sku.name
and properties.sku.tier
to one of the following AZ SKUs:'VpnGw1AZ'
'VpnGw2AZ'
'VpnGw3AZ'
'VpnGw4AZ'
'VpnGw5AZ'
For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/virtualNetworkGateways\",\n \"apiVersion\": \"2023-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"gatewayType\": \"Vpn\",\n \"ipConfigurations\": [\n {\n \"name\": \"default\",\n \"properties\": {\n \"privateIPAllocationMethod\": \"Dynamic\",\n \"subnet\": {\n \"id\": \"[parameters('subnetId')]\"\n },\n \"publicIPAddress\": {\n \"id\": \"[parameters('pipId')]\"\n }\n }\n }\n ],\n \"vpnType\": \"RouteBased\",\n \"vpnGatewayGeneration\": \"Generation2\",\n \"sku\": {\n \"name\": \"VpnGw1AZ\",\n \"tier\": \"VpnGw1AZ\"\n }\n }\n}\n
","tags":["Azure.VNG.VPNAvailabilityZoneSKU","AZR-000272"]},{"location":"en/rules/Azure.VNG.VPNAvailabilityZoneSKU/#configure-with-bicep","title":"Configure with Bicep","text":"To configure an AZ SKU for a VPN gateway:
properties.gatewayType
to 'Vpn'
properties.sku.name
and properties.sku.tier
to one of the following AZ SKUs:'VpnGw1AZ'
'VpnGw2AZ'
'VpnGw3AZ'
'VpnGw4AZ'
'VpnGw5AZ'
For example:
Azure Bicep snippetresource vng 'Microsoft.Network/virtualNetworkGateways@2023-06-01' = {\n name: name\n location: location\n properties: {\n gatewayType: 'Vpn'\n ipConfigurations: [\n {\n name: 'default'\n properties: {\n privateIPAllocationMethod: 'Dynamic'\n subnet: {\n id: subnetId\n }\n publicIPAddress: {\n id: pipId\n }\n }\n }\n ]\n vpnType: 'RouteBased'\n vpnGatewayGeneration: 'Generation2'\n sku: {\n name: 'VpnGw1AZ'\n tier: 'VpnGw1AZ'\n }\n }\n}\n
","tags":["Azure.VNG.VPNAvailabilityZoneSKU","AZR-000272"]},{"location":"en/rules/Azure.VNG.VPNAvailabilityZoneSKU/#notes","title":"Notes","text":"VPN gateway availability zones are managed via Public IP addresses, and are flagged separately under the Azure.PublicIP.AvailabilityZone
rule.
Operational Excellence \u00b7 Virtual Network Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Migrate from legacy SKUs to improve reliability and performance of VPN gateways.
","tags":["Azure.VNG.VPNLegacySKU","AZR-000269"]},{"location":"en/rules/Azure.VNG.VPNLegacySKU/#description","title":"Description","text":"When deploying a VPN gateway a number of options are available including SKU/ size. The gateway SKU affects the reliance and performance of the underlying gateway instances. Previously the following SKUs were available however have been depreciated.
Consider redeploying VPN gateways using new SKUs to improve reliability and performance of gateways.
","tags":["Azure.VNG.VPNLegacySKU","AZR-000269"]},{"location":"en/rules/Azure.VNG.VPNLegacySKU/#links","title":"Links","text":"Security \u00b7 Web PubSub Service \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Configure Web PubSub Services to use managed identities to access Azure resources securely.
","tags":["Azure.WebPubSub.ManagedIdentity","AZR-000277"]},{"location":"en/rules/Azure.WebPubSub.ManagedIdentity/#description","title":"Description","text":"A managed identity allows your service to access other Azure AD-protected resources such as Azure Functions. The identity is managed by the Azure platform and doesn't require you to provision or rotate any secrets.
Using Azure managed identities have the following benefits:
Consider configuring a managed identity for each Web PubSub Service. Also consider using managed identities to authenticate to related Azure services.
","tags":["Azure.WebPubSub.ManagedIdentity","AZR-000277"]},{"location":"en/rules/Azure.WebPubSub.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.WebPubSub.ManagedIdentity","AZR-000277"]},{"location":"en/rules/Azure.WebPubSub.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy services that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.SignalRService/webPubSub\",\n \"apiVersion\": \"2023-02-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_S1\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"disableLocalAuth\": true\n }\n}\n
","tags":["Azure.WebPubSub.ManagedIdentity","AZR-000277"]},{"location":"en/rules/Azure.WebPubSub.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy services that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource service 'Microsoft.SignalRService/webPubSub@2023-02-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard_S1'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n disableLocalAuth: true\n }\n}\n
","tags":["Azure.WebPubSub.ManagedIdentity","AZR-000277"]},{"location":"en/rules/Azure.WebPubSub.ManagedIdentity/#links","title":"Links","text":"Reliability \u00b7 Web PubSub Service \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Use SKUs that include an SLA when configuring Web PubSub Services.
","tags":["Azure.WebPubSub.SLA","AZR-000278"]},{"location":"en/rules/Azure.WebPubSub.SLA/#description","title":"Description","text":"When choosing a SKU for a Web PubSub Service you should consider the SLA that is included in the SKU. Web PubSub Services offer a range of SKU offerings:
Free
- Are designed for early non-production use and do not include any SLA.Standard
- Are designed for production use and include an SLA.Consider using a Standard SKU that includes an SLA.
","tags":["Azure.WebPubSub.SLA","AZR-000278"]},{"location":"en/rules/Azure.WebPubSub.SLA/#examples","title":"Examples","text":"","tags":["Azure.WebPubSub.SLA","AZR-000278"]},{"location":"en/rules/Azure.WebPubSub.SLA/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy services that pass this rule:
sku.name
to Standard_S1
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.SignalRService/webPubSub\",\n \"apiVersion\": \"2021-10-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_S1\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"disableLocalAuth\": true\n }\n}\n
","tags":["Azure.WebPubSub.SLA","AZR-000278"]},{"location":"en/rules/Azure.WebPubSub.SLA/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy services that pass this rule:
sku.name
to Standard_S1
.For example:
Azure Bicep snippetresource service 'Microsoft.SignalRService/webPubSub@2021-10-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard_S1'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n disableLocalAuth: true\n }\n}\n
","tags":["Azure.WebPubSub.SLA","AZR-000278"]},{"location":"en/rules/Azure.WebPubSub.SLA/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual WAN \u00b7 Rule \u00b7 2021_12 \u00b7 Awareness
Virtual WAN (vWAN) names should meet naming requirements.
","tags":["Azure.vWAN.Name","AZR-000276"]},{"location":"en/rules/Azure.vWAN.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for vWAN names are:
Consider using names that meet Virtual WAN (vWAN) naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.vWAN.Name","AZR-000276"]},{"location":"en/rules/Azure.vWAN.Name/#notes","title":"Notes","text":"This rule does not check if vWAN names are unique.
","tags":["Azure.vWAN.Name","AZR-000276"]},{"location":"en/rules/Azure.vWAN.Name/#links","title":"Links","text":"PSRule for Azure includes the following rules across five pillars of the Microsoft Azure Well-Architected Framework.
"},{"location":"en/rules/module/#cost-optimization","title":"Cost Optimization","text":""},{"location":"en/rules/module/#co03-cost-data-and-reporting","title":"CO:03 Cost data and reporting","text":"Name Synopsis Severity Level Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Error"},{"location":"en/rules/module/#co04-spending-guardrails","title":"CO:04 Spending guardrails","text":"Name Synopsis Severity Level Azure.DevBox.ProjectLimit Limit the number of Dev Boxes a single user can create for a project. Important Error"},{"location":"en/rules/module/#co05-rate-optimization","title":"CO:05 Rate optimization","text":"Name Synopsis Severity Level Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Error Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Error"},{"location":"en/rules/module/#co06-usage-and-billing-increments","title":"CO:06 Usage and billing increments","text":"Name Synopsis Severity Level Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. Critical Error Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Error"},{"location":"en/rules/module/#co07-component-costs","title":"CO:07 Component costs","text":"Name Synopsis Severity Level Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Error Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Error Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Error"},{"location":"en/rules/module/#co10-data-costs","title":"CO:10 Data costs","text":"Name Synopsis Severity Level Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Error"},{"location":"en/rules/module/#co13-personnel-time","title":"CO:13 Personnel time","text":"Name Synopsis Severity Level Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Error"},{"location":"en/rules/module/#co14-consolidation","title":"CO:14 Consolidation","text":"Name Synopsis Severity Level Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Error Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Error Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Error Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Error Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Error"},{"location":"en/rules/module/#operational-excellence","title":"Operational Excellence","text":""},{"location":"en/rules/module/#configuration","title":"Configuration","text":"Name Synopsis Severity Level Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Error Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Error Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Error"},{"location":"en/rules/module/#deployment","title":"Deployment","text":"Name Synopsis Severity Level Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Error Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Error Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Error Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Error Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Error Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Error Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Error Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Error Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Error"},{"location":"en/rules/module/#infrastructure-provisioning","title":"Infrastructure provisioning","text":"Name Synopsis Severity Level Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Error Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Error"},{"location":"en/rules/module/#instrumentation","title":"Instrumentation","text":"Name Synopsis Severity Level Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Warning"},{"location":"en/rules/module/#monitor","title":"Monitor","text":"Name Synopsis Severity Level Azure.VNET.PeerState VNET peering connections must be connected. Important Error"},{"location":"en/rules/module/#monitoring","title":"Monitoring","text":"Name Synopsis Severity Level Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Error Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Error Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Error Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Error Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Error Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Error Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Error"},{"location":"en/rules/module/#oe04-continuous-integration","title":"OE:04 Continuous integration","text":"Name Synopsis Severity Level Azure.ACR.Name Container registry names should meet naming requirements. Awareness Error Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Error Azure.APIM.Name API Management service names should meet naming requirements. Awareness Error Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Error Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Error Azure.Search.Name AI Search service names should meet naming requirements. Awareness Error Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Error Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Error Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Error Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Error"},{"location":"en/rules/module/#oe04-tools-and-processes","title":"OE:04 Tools and processes","text":"Name Synopsis Severity Level Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Warning"},{"location":"en/rules/module/#oe05-infrastructure-as-code","title":"OE:05 Infrastructure as code","text":"Name Synopsis Severity Level Azure.Template.TemplateFile Use ARM template files that are valid. Important Error Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Error"},{"location":"en/rules/module/#oe07-monitoring-system","title":"OE:07 Monitoring system","text":"Name Synopsis Severity Level Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Error Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Error"},{"location":"en/rules/module/#oe09-task-automation","title":"OE:09 Task automation","text":"Name Synopsis Severity Level Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Error"},{"location":"en/rules/module/#principles","title":"Principles","text":"Name Synopsis Severity Level Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Error"},{"location":"en/rules/module/#release-engineering","title":"Release engineering","text":"Name Synopsis Severity Level Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Error Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Error Azure.Template.LocationType Location parameters should use a string value. Important Error Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Error Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Error Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Error Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Error Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Error Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Error Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Warning Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Error Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Error"},{"location":"en/rules/module/#repeatable-infrastructure","title":"Repeatable infrastructure","text":"Name Synopsis Severity Level Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Error Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Error Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Error Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Error Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Important Error Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Error Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Error Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Error Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. Important Error Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Error Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Error Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Error Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Error Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Error Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Error Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Error Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Error Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Error Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Error Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Error Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Error Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Error Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Error Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Error Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Error Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Error Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Error Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Error Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Error Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Error Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Error Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Error Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Error Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Error Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Error Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Error Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. Important Error Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Error Azure.Route.Name Route table names should meet naming requirements. Awareness Error Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Error Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Error Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Error Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Error Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Error Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Error Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Error Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Error Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Error Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Error Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Error Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Error Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Error Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Information Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Information Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Error Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Error Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Error Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Important Error Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Error Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Error Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Error Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Error Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Error Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Error"},{"location":"en/rules/module/#tagging-and-resource-naming","title":"Tagging and resource naming","text":"Name Synopsis Severity Level Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Error"},{"location":"en/rules/module/#performance-efficiency","title":"Performance Efficiency","text":""},{"location":"en/rules/module/#application-capacity","title":"Application capacity","text":"Name Synopsis Severity Level Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Error Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Error Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Error"},{"location":"en/rules/module/#application-design","title":"Application design","text":"Name Synopsis Severity Level Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Error Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Error"},{"location":"en/rules/module/#application-scalability","title":"Application scalability","text":"Name Synopsis Severity Level Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Error Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Error"},{"location":"en/rules/module/#design-for-performance","title":"Design for performance","text":"Name Synopsis Severity Level Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Error"},{"location":"en/rules/module/#design-for-performance-efficiency","title":"Design for performance efficiency","text":"Name Synopsis Severity Level Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. Important Error"},{"location":"en/rules/module/#pe02-capacity-planning","title":"PE:02 Capacity planning","text":"Name Synopsis Severity Level Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Error"},{"location":"en/rules/module/#pe03-selecting-services","title":"PE:03 Selecting services","text":"Name Synopsis Severity Level Azure.Databricks.SKU Ensure Databricks workspaces are non-trial SKUs for production workloads. Critical Error"},{"location":"en/rules/module/#pe05-scaling-and-partitioning","title":"PE:05 Scaling and partitioning","text":"Name Synopsis Severity Level Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Error Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Error"},{"location":"en/rules/module/#pe08-data-performance","title":"PE:08 Data performance","text":"Name Synopsis Severity Level Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Error"},{"location":"en/rules/module/#performance","title":"Performance","text":"Name Synopsis Severity Level Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Error Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Error"},{"location":"en/rules/module/#performance-efficiency-checklist","title":"Performance efficiency checklist","text":"Name Synopsis Severity Level Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Warning Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Error"},{"location":"en/rules/module/#reliability","title":"Reliability","text":""},{"location":"en/rules/module/#application-design_1","title":"Application design","text":"Name Synopsis Severity Level Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Error"},{"location":"en/rules/module/#availability","title":"Availability","text":"Name Synopsis Severity Level Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Error Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Error"},{"location":"en/rules/module/#best-practices","title":"Best practices","text":"Name Synopsis Severity Level Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Error"},{"location":"en/rules/module/#data-management","title":"Data management","text":"Name Synopsis Severity Level Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Error Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important Error Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Error Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Error Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Error Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Error"},{"location":"en/rules/module/#design","title":"Design","text":"Name Synopsis Severity Level Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Error Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Error Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Error Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Error Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Error Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Error Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Error Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Error Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Error Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Error"},{"location":"en/rules/module/#health-modeling","title":"Health modeling","text":"Name Synopsis Severity Level Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Error Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Error Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Error"},{"location":"en/rules/module/#load-balancing-and-failover","title":"Load balancing and failover","text":"Name Synopsis Severity Level Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Error Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Error"},{"location":"en/rules/module/#re01-simplicity-and-efficiency","title":"RE:01 Simplicity and efficiency","text":"Name Synopsis Severity Level Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Error"},{"location":"en/rules/module/#re04-target-metrics","title":"RE:04 Target metrics","text":"Name Synopsis Severity Level Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Error Azure.AppService.WebProbe Configure and enable instance health probes. Important Error Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Error Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Error"},{"location":"en/rules/module/#re05-redundancy","title":"RE:05 Redundancy","text":"Name Synopsis Severity Level Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Error Azure.AKS.MinUserPoolNodes User node pools in an AKS cluster should have a minimum number of nodes for failover and updates. Important Error Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. Important Error Azure.LB.Probe Use a specific probe for web protocols. Important Error Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Warning Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Error Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Error Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Error"},{"location":"en/rules/module/#re05-regions-and-availability-zones","title":"RE:05 Regions and availability zones","text":"Name Synopsis Severity Level Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Error"},{"location":"en/rules/module/#re06-data-partitioning","title":"RE:06 Data partitioning","text":"Name Synopsis Severity Level Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Error Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Error"},{"location":"en/rules/module/#re07-self-preservation","title":"RE:07 Self-preservation","text":"Name Synopsis Severity Level Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Error Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Error"},{"location":"en/rules/module/#reliability-design-principles","title":"Reliability design principles","text":"Name Synopsis Severity Level Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Error"},{"location":"en/rules/module/#requirements","title":"Requirements","text":"Name Synopsis Severity Level Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Error Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Error Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Error Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Error Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Error Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Error Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Error Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Error Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important Error"},{"location":"en/rules/module/#resiliency-and-dependencies","title":"Resiliency and dependencies","text":"Name Synopsis Severity Level Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Error Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Error Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Error Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Error Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Error"},{"location":"en/rules/module/#resource-deployment","title":"Resource deployment","text":"Name Synopsis Severity Level Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Error"},{"location":"en/rules/module/#scalability","title":"Scalability","text":"Name Synopsis Severity Level Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Error"},{"location":"en/rules/module/#target-and-non-functional-requirements","title":"Target and non-functional requirements","text":"Name Synopsis Severity Level Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Error Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Error Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Error"},{"location":"en/rules/module/#security","title":"Security","text":""},{"location":"en/rules/module/#application-endpoints","title":"Application endpoints","text":"Name Synopsis Severity Level Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Error Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Error Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Error Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Error Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Error Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Error Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Error Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Error"},{"location":"en/rules/module/#authentication","title":"Authentication","text":"Name Synopsis Severity Level Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Error Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Error Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Error Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. Critical Error Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Error Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Error Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Error Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Error Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Error"},{"location":"en/rules/module/#authorization","title":"Authorization","text":"Name Synopsis Severity Level Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Error"},{"location":"en/rules/module/#azure-resources","title":"Azure resources","text":"Name Synopsis Severity Level Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Error Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Error Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Error Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Error"},{"location":"en/rules/module/#connectivity","title":"Connectivity","text":"Name Synopsis Severity Level Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). Critical Error Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. Critical Error Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Error Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Error Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Error"},{"location":"en/rules/module/#data-protection","title":"Data protection","text":"Name Synopsis Severity Level Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Error Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Error Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Error Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Error Azure.CDN.HTTP Enforce HTTPS for client connections. Important Error Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Error Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Error Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Error Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Error Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Error Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Error"},{"location":"en/rules/module/#design_1","title":"Design","text":"Name Synopsis Severity Level Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Error Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Error"},{"location":"en/rules/module/#encryption","title":"Encryption","text":"Name Synopsis Severity Level Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Error Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Error Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Error Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Error Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Error Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Error Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Error Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Error Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Error Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Error Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Error Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Error"},{"location":"en/rules/module/#identity-and-access-management","title":"Identity and access management","text":"Name Synopsis Severity Level Azure.ACR.AnonymousAccess Disable anonymous pull access. Important Error Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Error Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Error Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Error Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Error Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Error Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. Important Error Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Error Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Error Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Error Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Error Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Error Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Error Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Error Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Error Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Error Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Error Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Error Azure.VM.PublicKey Linux virtual machines should use public keys. Important Error Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Error"},{"location":"en/rules/module/#infrastructure-provisioning_1","title":"Infrastructure provisioning","text":"Name Synopsis Severity Level Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Error Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Error Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Error Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. Critical Error Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Error"},{"location":"en/rules/module/#key-and-secret-management","title":"Key and secret management","text":"Name Synopsis Severity Level Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Error Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Error Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Error"},{"location":"en/rules/module/#monitor_1","title":"Monitor","text":"Name Synopsis Severity Level Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Error Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Error Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Error"},{"location":"en/rules/module/#network-security-and-containment","title":"Network security and containment","text":"Name Synopsis Severity Level Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Error Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Error Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Error Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Error Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Error Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Error Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.AppGwWAF.RuleGroups Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Error Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Error Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Error Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Error Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Error Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Error Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Error Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Error Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error"},{"location":"en/rules/module/#network-segmentation","title":"Network segmentation","text":"Name Synopsis Severity Level Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Error Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Error"},{"location":"en/rules/module/#review-and-remediate","title":"Review and remediate","text":"Name Synopsis Severity Level Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Error"},{"location":"en/rules/module/#se01-security-baseline","title":"SE:01 Security baseline","text":"Name Synopsis Severity Level Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Error"},{"location":"en/rules/module/#se02-secured-development-lifecycle","title":"SE:02 Secured development lifecycle","text":"Name Synopsis Severity Level Azure.AppService.NETVersion Configure applications to use newer .NET versions. Important Error Azure.AppService.PHPVersion Configure applications to use newer PHP runtime versions. Important Error"},{"location":"en/rules/module/#se04-segmentation","title":"SE:04 Segmentation","text":"Name Synopsis Severity Level Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Error"},{"location":"en/rules/module/#se05-identity-and-access-management","title":"SE:05 Identity and access management","text":"Name Synopsis Severity Level Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Error Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Error Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Error Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Error Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.APIM.ProductApproval Configure products to require approval. Important Error Azure.APIM.ProductSubscription Configure products to require a subscription. Important Error Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Error Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Error Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Error Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Error Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Error Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Warning Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Error Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Error Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Error Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Error Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Error"},{"location":"en/rules/module/#se06-network-controls","title":"SE:06 Network controls","text":"Name Synopsis Severity Level Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Error Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Error Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Error Azure.Databricks.PublicAccess Azure Databricks workspaces should disable public network access. Critical Error Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. Critical Error Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Error Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Error Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Error"},{"location":"en/rules/module/#se07-encryption","title":"SE:07 Encryption","text":"Name Synopsis Severity Level Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Error Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Error Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Error Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Error Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Error Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Error Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Error Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Error Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Error Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Error Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Error Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Error Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Error"},{"location":"en/rules/module/#se08-hardening-resources","title":"SE:08 Hardening resources","text":"Name Synopsis Severity Level Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Error Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Error"},{"location":"en/rules/module/#se10-monitoring-and-threat-detection","title":"SE:10 Monitoring and threat detection","text":"Name Synopsis Severity Level Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. Critical Error Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Error Azure.Defender.Api Enable Microsoft Defender for APIs. Critical Error Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Error Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Error Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Error Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. Important Error Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Error Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Error Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Error Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Error"},{"location":"en/rules/module/#secrets","title":"Secrets","text":"Name Synopsis Severity Level Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Error Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Error"},{"location":"en/rules/module/#security-design-principles","title":"Security design principles","text":"Name Synopsis Severity Level Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Error Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Error"},{"location":"en/rules/module/#security-operations","title":"Security operations","text":"Name Synopsis Severity Level Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Important Error Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Error Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Error Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Error Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Error Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Error Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Error Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Error Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Error Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Error Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Error Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Error Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Error Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Error Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Error Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Error Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Error"},{"location":"en/rules/module/#virtual-machine","title":"Virtual Machine","text":"Name Synopsis Severity Level Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Error"},{"location":"en/rules/resource/","title":"Rules by resource type","text":"PSRule for Azure includes the following rules organized by resource type.
"},{"location":"en/rules/resource/#ai-search","title":"AI Search","text":"Name Synopsis Severity Level Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Error Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.Search.Name AI Search service names should meet naming requirements. Awareness Error Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Error Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Error"},{"location":"en/rules/resource/#all-resources","title":"All resources","text":"Name Synopsis Severity Level Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Error Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Error Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Error Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Error Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Error Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Error Azure.Template.LocationType Location parameters should use a string value. Important Error Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Error Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Error Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Error Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Error Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Error Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Error Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Error Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Error Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Error Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Error Azure.Template.TemplateFile Use ARM template files that are valid. Important Error Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Error Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Error Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Information Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Information Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Warning Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Error Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Error Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Error"},{"location":"en/rules/resource/#api-management","title":"API Management","text":"Name Synopsis Severity Level Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Warning Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Error Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Error Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Error Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Error Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. Critical Error Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Error Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Error Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Error Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Error Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Error Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Error Azure.APIM.Name API Management service names should meet naming requirements. Awareness Error Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Error Azure.APIM.ProductApproval Configure products to require approval. Important Error Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Warning Azure.APIM.ProductSubscription Configure products to require a subscription. Important Error Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Error Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Error Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Error"},{"location":"en/rules/resource/#app-configuration","title":"App Configuration","text":"Name Synopsis Severity Level Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Error Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Error Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. Important Error Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Error Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Error Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Error"},{"location":"en/rules/resource/#app-service","title":"App Service","text":"Name Synopsis Severity Level Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Error Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Error Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Error Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Error Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Error Azure.AppService.NETVersion Configure applications to use newer .NET versions. Important Error Azure.AppService.PHPVersion Configure applications to use newer PHP runtime versions. Important Error Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Error Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Error Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Error Azure.AppService.WebProbe Configure and enable instance health probes. Important Error Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Error Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Error"},{"location":"en/rules/resource/#app-service-environment","title":"App Service Environment","text":"Name Synopsis Severity Level Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Error"},{"location":"en/rules/resource/#application-gateway","title":"Application Gateway","text":"Name Synopsis Severity Level Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Error Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Error Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Error Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Error Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Error Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Error Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Error Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Error Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Error Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Error Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Error Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Error Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Error Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Error Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.AppGwWAF.RuleGroups Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Error"},{"location":"en/rules/resource/#application-insights","title":"Application Insights","text":"Name Synopsis Severity Level Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Error Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Error"},{"location":"en/rules/resource/#application-security-group","title":"Application Security Group","text":"Name Synopsis Severity Level Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Error"},{"location":"en/rules/resource/#arc","title":"Arc","text":"Name Synopsis Severity Level Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Important Error Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Important Error"},{"location":"en/rules/resource/#automation-account","title":"Automation Account","text":"Name Synopsis Severity Level Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Error Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Error Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Error Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Error Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Error"},{"location":"en/rules/resource/#azure-ai","title":"Azure AI","text":"Name Synopsis Severity Level Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Error Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Error Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Error"},{"location":"en/rules/resource/#azure-cache-for-redis","title":"Azure Cache for Redis","text":"Name Synopsis Severity Level Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Error Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Error Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Error Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Error Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Error Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Error Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Error Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Error Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Error"},{"location":"en/rules/resource/#azure-cache-for-redis-enterprise","title":"Azure Cache for Redis Enterprise","text":"Name Synopsis Severity Level Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Error Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Error"},{"location":"en/rules/resource/#azure-database-for-mariadb","title":"Azure Database for MariaDB","text":"Name Synopsis Severity Level Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Error Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Error Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Error Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Error Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Error Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Error Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Error Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Error"},{"location":"en/rules/resource/#azure-database-for-mysql","title":"Azure Database for MySQL","text":"Name Synopsis Severity Level Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Error Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Error Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Error Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Error Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Error Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Error Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Warning Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Error"},{"location":"en/rules/resource/#azure-database-for-postgresql","title":"Azure Database for PostgreSQL","text":"Name Synopsis Severity Level Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Error Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Error Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Error Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Error Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Error Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Error Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Error"},{"location":"en/rules/resource/#azure-kubernetes-service","title":"Azure Kubernetes Service","text":"Name Synopsis Severity Level Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Error Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Error Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Error Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Error Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Error Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Error Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Error Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Error Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Error Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Error Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Error Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Warning Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Error Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Error Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Error Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Error Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Error Azure.AKS.MinUserPoolNodes User node pools in an AKS cluster should have a minimum number of nodes for failover and updates. Important Error Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Error Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Error Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Error Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Error Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Error Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Error Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Error Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Error Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Error Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Error Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Error Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Error"},{"location":"en/rules/resource/#backup-vault","title":"Backup Vault","text":"Name Synopsis Severity Level Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Error"},{"location":"en/rules/resource/#bastion","title":"Bastion","text":"Name Synopsis Severity Level Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Error"},{"location":"en/rules/resource/#container-app","title":"Container App","text":"Name Synopsis Severity Level Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. Important Error Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. Important Error Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Error Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Error Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Error Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Error Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Error Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Error Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Error"},{"location":"en/rules/resource/#container-registry","title":"Container Registry","text":"Name Synopsis Severity Level Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Error Azure.ACR.AnonymousAccess Disable anonymous pull access. Important Error Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Error Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Error Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Error Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Error Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Error Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Error Azure.ACR.Name Container registry names should meet naming requirements. Awareness Error Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Error Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Error Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important Error Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Error"},{"location":"en/rules/resource/#content-delivery-network","title":"Content Delivery Network","text":"Name Synopsis Severity Level Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Error Azure.CDN.HTTP Enforce HTTPS for client connections. Important Error Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Error"},{"location":"en/rules/resource/#cosmos-db","title":"Cosmos DB","text":"Name Synopsis Severity Level Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Error Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Error Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Error"},{"location":"en/rules/resource/#data-explorer","title":"Data Explorer","text":"Name Synopsis Severity Level Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Error Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Error Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Error Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Error"},{"location":"en/rules/resource/#data-factory","title":"Data Factory","text":"Name Synopsis Severity Level Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Error"},{"location":"en/rules/resource/#databricks","title":"Databricks","text":"Name Synopsis Severity Level Azure.Databricks.PublicAccess Azure Databricks workspaces should disable public network access. Critical Error Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. Critical Error Azure.Databricks.SKU Ensure Databricks workspaces are non-trial SKUs for production workloads. Critical Error"},{"location":"en/rules/resource/#deployment","title":"Deployment","text":"Name Synopsis Severity Level Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Error Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Error Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Error Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Error Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. Critical Error Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Error"},{"location":"en/rules/resource/#dev-box","title":"Dev Box","text":"Name Synopsis Severity Level Azure.DevBox.ProjectLimit Limit the number of Dev Boxes a single user can create for a project. Important Error"},{"location":"en/rules/resource/#event-grid","title":"Event Grid","text":"Name Synopsis Severity Level Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Error Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Error Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Error"},{"location":"en/rules/resource/#event-hub","title":"Event Hub","text":"Name Synopsis Severity Level Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Error Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Error Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Error"},{"location":"en/rules/resource/#firewall","title":"Firewall","text":"Name Synopsis Severity Level Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Error Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Error Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Error Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Error"},{"location":"en/rules/resource/#front-door","title":"Front Door","text":"Name Synopsis Severity Level Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Error Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. Important Error Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Error Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Error Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Error Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Error Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Error Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Error Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Error Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Error Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Error Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Error Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Error Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Error Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Error Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error"},{"location":"en/rules/resource/#iot-hub","title":"IoT Hub","text":"Name Synopsis Severity Level Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Error"},{"location":"en/rules/resource/#key-vault","title":"Key Vault","text":"Name Synopsis Severity Level Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Error Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Error Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Error Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Error Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Error Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Error Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Error Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Warning Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Error Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Error"},{"location":"en/rules/resource/#load-balancer","title":"Load Balancer","text":"Name Synopsis Severity Level Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Error Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Error Azure.LB.Probe Use a specific probe for web protocols. Important Error Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Error"},{"location":"en/rules/resource/#logic-app","title":"Logic App","text":"Name Synopsis Severity Level Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Error"},{"location":"en/rules/resource/#machine-learning","title":"Machine Learning","text":"Name Synopsis Severity Level Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. Critical Error Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). Critical Error Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. Critical Error Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. Critical Error Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. Important Error"},{"location":"en/rules/resource/#microsoft-defender-for-cloud","title":"Microsoft Defender for Cloud","text":"Name Synopsis Severity Level Azure.Defender.Api Enable Microsoft Defender for APIs. Critical Error Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Error Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Error Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Error Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Error Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Error Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Error Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Error Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Error Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Error Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Error Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Error Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Error Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Error Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Error Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Error Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Error"},{"location":"en/rules/resource/#monitor","title":"Monitor","text":"Name Synopsis Severity Level Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Error"},{"location":"en/rules/resource/#network-interface","title":"Network Interface","text":"Name Synopsis Severity Level Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Error Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Error Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Error"},{"location":"en/rules/resource/#network-security-group","title":"Network Security Group","text":"Name Synopsis Severity Level Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Error Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Error Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Error Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Error Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Error Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Error"},{"location":"en/rules/resource/#policy","title":"Policy","text":"Name Synopsis Severity Level Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Error Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Error Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Error Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Error Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Error"},{"location":"en/rules/resource/#private-endpoint","title":"Private Endpoint","text":"Name Synopsis Severity Level Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Error"},{"location":"en/rules/resource/#public-ip-address","title":"Public IP address","text":"Name Synopsis Severity Level Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Error Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Error Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Error Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. Important Error Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Error Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Error"},{"location":"en/rules/resource/#recovery-services-vault","title":"Recovery Services Vault","text":"Name Synopsis Severity Level Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Error Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Error Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Error Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Error"},{"location":"en/rules/resource/#resource-group","title":"Resource Group","text":"Name Synopsis Severity Level Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Error"},{"location":"en/rules/resource/#route-table","title":"Route table","text":"Name Synopsis Severity Level Azure.Route.Name Route table names should meet naming requirements. Awareness Error"},{"location":"en/rules/resource/#service-bus","title":"Service Bus","text":"Name Synopsis Severity Level Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Error Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Error Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Error Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Error"},{"location":"en/rules/resource/#service-fabric","title":"Service Fabric","text":"Name Synopsis Severity Level Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Error"},{"location":"en/rules/resource/#signalr-service","title":"SignalR Service","text":"Name Synopsis Severity Level Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Error Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Error Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Error"},{"location":"en/rules/resource/#sql-database","title":"SQL Database","text":"Name Synopsis Severity Level Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Error Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Error Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Error Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Error Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Error Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Error Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Error Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Error Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Error Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Error"},{"location":"en/rules/resource/#sql-managed-instance","title":"SQL Managed Instance","text":"Name Synopsis Severity Level Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Error Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Error Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Error Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Error"},{"location":"en/rules/resource/#storage-account","title":"Storage Account","text":"Name Synopsis Severity Level Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Error Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Error Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Error Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Error Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Error Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Error Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Error Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Error Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Error Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Error Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Error Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Error Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Error"},{"location":"en/rules/resource/#subscription","title":"Subscription","text":"Name Synopsis Severity Level Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Error Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Error Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Error Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Error Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Error Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Error"},{"location":"en/rules/resource/#traffic-manager","title":"Traffic Manager","text":"Name Synopsis Severity Level Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Error Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Error"},{"location":"en/rules/resource/#user-assigned-managed-identity","title":"User Assigned Managed Identity","text":"Name Synopsis Severity Level Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Error"},{"location":"en/rules/resource/#virtual-machine","title":"Virtual Machine","text":"Name Synopsis Severity Level Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Error Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Error Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Error Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Error Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Error Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Error Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Error Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Error Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Error Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Error Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Error Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Error Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Error Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Important Error Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Error Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Error Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Error Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Error Azure.VM.PublicKey Linux virtual machines should use public keys. Important Error Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Error Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Error Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Error Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Error Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Error Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Error Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Error"},{"location":"en/rules/resource/#virtual-machine-scale-sets","title":"Virtual Machine Scale Sets","text":"Name Synopsis Severity Level Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Error Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Error Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Error Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Error Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Error Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Error"},{"location":"en/rules/resource/#virtual-network","title":"Virtual Network","text":"Name Synopsis Severity Level Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Error Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Error Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Error Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Error Azure.VNET.PeerState VNET peering connections must be connected. Important Error Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Error Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Error Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Error"},{"location":"en/rules/resource/#virtual-network-gateway","title":"Virtual Network Gateway","text":"Name Synopsis Severity Level Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Error Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Error Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Error Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Error Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Error Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Error Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Error"},{"location":"en/rules/resource/#virtual-wan","title":"Virtual WAN","text":"Name Synopsis Severity Level Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Error"},{"location":"en/rules/resource/#web-pubsub-service","title":"Web PubSub Service","text":"Name Synopsis Severity Level Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Error Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important Error"},{"location":"en/selectors/Azure.AppService.IsAPIApp/","title":"Azure.AppService.IsAPIApp","text":"Azure App Services API apps.
"},{"location":"en/selectors/Azure.AppService.IsAPIApp/#description","title":"Description","text":"Use this selector to filter rules to only run against API apps.
"},{"location":"en/selectors/Azure.AppService.IsAPIApp/#examples","title":"Examples","text":""},{"location":"en/selectors/Azure.AppService.IsAPIApp/#configure-with-yaml-based-rules","title":"Configure with YAML-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.AppService.IsAPIApp
.---\n# Synopsis: An example rule.\napiVersion: github.com/microsoft/PSRule/v1\nkind: Rule\nmetadata:\n name: Local.MyRule\nspec:\n with:\n - PSRule.Rules.Azure\\Azure.AppService.IsAPIApp\n condition:\n # Rule logic goes here\n
"},{"location":"en/selectors/Azure.AppService.IsAPIApp/#configure-with-json-based-rules","title":"Configure with JSON-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.AppService.IsAPIApp
.{\n // Synopsis: An example rule.\n \"apiVersion\": \"github.com/microsoft/PSRule/v1\",\n \"kind\": \"Rule\",\n \"metadata\": {\n \"name\": \"Local.MyRule\"\n },\n \"spec\": {\n \"with\": [\n \"PSRule.Rules.Azure\\\\Azure.AppService.IsAPIApp\"\n ],\n \"condition\": {\n // Rule logic goes here\n }\n }\n}\n
"},{"location":"en/selectors/Azure.AppService.IsAPIApp/#configure-with-powershell-based-rules","title":"Configure with PowerShell-based rules","text":"-With
parameter to set PSRule.Rules.Azure\\Azure.AppService.IsAPIApp
.# Synopsis: An example rule.\nRule 'Local.MyRule' -With 'PSRule.Rules.Azure\\Azure.AppService.IsAPIApp' {\n # Rule logic goes here\n}\n
"},{"location":"en/selectors/Azure.AppService.IsFunctionApp/","title":"Azure.AppService.IsFunctionApp","text":"Azure App Services function apps.
"},{"location":"en/selectors/Azure.AppService.IsFunctionApp/#description","title":"Description","text":"Use this selector to filter rules to only run against Azure Functions apps.
"},{"location":"en/selectors/Azure.AppService.IsFunctionApp/#examples","title":"Examples","text":""},{"location":"en/selectors/Azure.AppService.IsFunctionApp/#configure-with-yaml-based-rules","title":"Configure with YAML-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.AppService.IsFunctionApp
.---\n# Synopsis: An example rule.\napiVersion: github.com/microsoft/PSRule/v1\nkind: Rule\nmetadata:\n name: Local.MyRule\nspec:\n with:\n - PSRule.Rules.Azure\\Azure.AppService.IsFunctionApp\n condition:\n # Rule logic goes here\n
"},{"location":"en/selectors/Azure.AppService.IsFunctionApp/#configure-with-json-based-rules","title":"Configure with JSON-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.AppService.IsFunctionApp
.{\n // Synopsis: An example rule.\n \"apiVersion\": \"github.com/microsoft/PSRule/v1\",\n \"kind\": \"Rule\",\n \"metadata\": {\n \"name\": \"Local.MyRule\"\n },\n \"spec\": {\n \"with\": [\n \"PSRule.Rules.Azure\\\\Azure.AppService.IsFunctionApp\"\n ],\n \"condition\": {\n // Rule logic goes here\n }\n }\n}\n
"},{"location":"en/selectors/Azure.AppService.IsFunctionApp/#configure-with-powershell-based-rules","title":"Configure with PowerShell-based rules","text":"-With
parameter to set PSRule.Rules.Azure\\Azure.AppService.IsFunctionApp
.# Synopsis: An example rule.\nRule 'Local.MyRule' -With 'PSRule.Rules.Azure\\Azure.AppService.IsFunctionApp' {\n # Rule logic goes here\n}\n
"},{"location":"en/selectors/Azure.AppService.IsLogicApp/","title":"Azure.AppService.IsLogicApp","text":"Single tenanted Logic Apps.
"},{"location":"en/selectors/Azure.AppService.IsLogicApp/#description","title":"Description","text":"Use this selector to filter rules to only run against Logic Apps with the Standard SKU.
"},{"location":"en/selectors/Azure.AppService.IsLogicApp/#examples","title":"Examples","text":""},{"location":"en/selectors/Azure.AppService.IsLogicApp/#configure-with-yaml-based-rules","title":"Configure with YAML-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.AppService.IsLogicApp
.---\n# Synopsis: An example rule.\napiVersion: github.com/microsoft/PSRule/v1\nkind: Rule\nmetadata:\n name: Local.MyRule\nspec:\n with:\n - PSRule.Rules.Azure\\Azure.AppService.IsLogicApp\n condition:\n # Rule logic goes here\n
"},{"location":"en/selectors/Azure.AppService.IsLogicApp/#configure-with-json-based-rules","title":"Configure with JSON-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.AppService.IsLogicApp
.{\n // Synopsis: An example rule.\n \"apiVersion\": \"github.com/microsoft/PSRule/v1\",\n \"kind\": \"Rule\",\n \"metadata\": {\n \"name\": \"Local.MyRule\"\n },\n \"spec\": {\n \"with\": [\n \"PSRule.Rules.Azure\\\\Azure.AppService.IsLogicApp\"\n ],\n \"condition\": {\n // Rule logic goes here\n }\n }\n}\n
"},{"location":"en/selectors/Azure.AppService.IsLogicApp/#configure-with-powershell-based-rules","title":"Configure with PowerShell-based rules","text":"-With
parameter to set PSRule.Rules.Azure\\Azure.AppService.IsLogicApp
.# Synopsis: An example rule.\nRule 'Local.MyRule' -With 'PSRule.Rules.Azure\\Azure.AppService.IsLogicApp' {\n # Rule logic goes here\n}\n
"},{"location":"en/selectors/Azure.AppService.IsWebApp/","title":"Azure.AppService.IsWebApp","text":"Azure App Services web apps.
"},{"location":"en/selectors/Azure.AppService.IsWebApp/#description","title":"Description","text":"Use this selector to filter rules to only run against web apps.
"},{"location":"en/selectors/Azure.AppService.IsWebApp/#examples","title":"Examples","text":""},{"location":"en/selectors/Azure.AppService.IsWebApp/#configure-with-yaml-based-rules","title":"Configure with YAML-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.AppService.IsWebApp
.---\n# Synopsis: An example rule.\napiVersion: github.com/microsoft/PSRule/v1\nkind: Rule\nmetadata:\n name: Local.MyRule\nspec:\n with:\n - PSRule.Rules.Azure\\Azure.AppService.IsWebApp\n condition:\n # Rule logic goes here\n
"},{"location":"en/selectors/Azure.AppService.IsWebApp/#configure-with-json-based-rules","title":"Configure with JSON-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.AppService.IsWebApp
.{\n // Synopsis: An example rule.\n \"apiVersion\": \"github.com/microsoft/PSRule/v1\",\n \"kind\": \"Rule\",\n \"metadata\": {\n \"name\": \"Local.MyRule\"\n },\n \"spec\": {\n \"with\": [\n \"PSRule.Rules.Azure\\\\Azure.AppService.IsWebApp\"\n ],\n \"condition\": {\n // Rule logic goes here\n }\n }\n}\n
"},{"location":"en/selectors/Azure.AppService.IsWebApp/#configure-with-powershell-based-rules","title":"Configure with PowerShell-based rules","text":"-With
parameter to set PSRule.Rules.Azure\\Azure.AppService.IsWebApp
.# Synopsis: An example rule.\nRule 'Local.MyRule' -With 'PSRule.Rules.Azure\\Azure.AppService.IsWebApp' {\n # Rule logic goes here\n}\n
"},{"location":"en/selectors/Azure.FrontDoor.IsClassic/","title":"AAzure.FrontDoor.IsClassic","text":"Azure Front Door profiles using the Classic SKU.
"},{"location":"en/selectors/Azure.FrontDoor.IsClassic/#description","title":"Description","text":"Use this selector to filter rules to only run against Azure Front Door profiles using the Classic SKU.
"},{"location":"en/selectors/Azure.FrontDoor.IsClassic/#examples","title":"Examples","text":""},{"location":"en/selectors/Azure.FrontDoor.IsClassic/#configure-with-yaml-based-rules","title":"Configure with YAML-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.FrontDoor.IsClassic
.---\n# Synopsis: An example rule.\napiVersion: github.com/microsoft/PSRule/v1\nkind: Rule\nmetadata:\n name: Local.MyRule\nspec:\n with:\n - PSRule.Rules.Azure\\Azure.FrontDoor.IsClassic\n condition:\n # Rule logic goes here\n
"},{"location":"en/selectors/Azure.FrontDoor.IsClassic/#configure-with-json-based-rules","title":"Configure with JSON-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.FrontDoor.IsClassic
.{\n // Synopsis: An example rule.\n \"apiVersion\": \"github.com/microsoft/PSRule/v1\",\n \"kind\": \"Rule\",\n \"metadata\": {\n \"name\": \"Local.MyRule\"\n },\n \"spec\": {\n \"with\": [\n \"PSRule.Rules.Azure\\\\Azure.FrontDoor.IsClassic\"\n ],\n \"condition\": {\n // Rule logic goes here\n }\n }\n}\n
"},{"location":"en/selectors/Azure.FrontDoor.IsClassic/#configure-with-powershell-based-rules","title":"Configure with PowerShell-based rules","text":"-With
parameter to set PSRule.Rules.Azure\\Azure.FrontDoor.IsClassic
.# Synopsis: An example rule.\nRule 'Local.MyRule' -With 'PSRule.Rules.Azure\\Azure.FrontDoor.IsClassic' {\n # Rule logic goes here\n}\n
"},{"location":"en/selectors/Azure.FrontDoor.IsStandardOrPremium/","title":"Azure.FrontDoor.IsStandardOrPremium","text":"Azure Front Door profiles using the Standard or Premium SKU.
"},{"location":"en/selectors/Azure.FrontDoor.IsStandardOrPremium/#description","title":"Description","text":"Use this selector to filter rules to only run against Azure Front Door profiles using the Standard or Premium SKU.
"},{"location":"en/selectors/Azure.FrontDoor.IsStandardOrPremium/#examples","title":"Examples","text":""},{"location":"en/selectors/Azure.FrontDoor.IsStandardOrPremium/#configure-with-yaml-based-rules","title":"Configure with YAML-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.FrontDoor.IsStandardOrPremium
.---\n# Synopsis: An example rule.\napiVersion: github.com/microsoft/PSRule/v1\nkind: Rule\nmetadata:\n name: Local.MyRule\nspec:\n with:\n - PSRule.Rules.Azure\\Azure.FrontDoor.IsStandardOrPremium\n condition:\n # Rule logic goes here\n
"},{"location":"en/selectors/Azure.FrontDoor.IsStandardOrPremium/#configure-with-json-based-rules","title":"Configure with JSON-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.FrontDoor.IsStandardOrPremium
.{\n // Synopsis: An example rule.\n \"apiVersion\": \"github.com/microsoft/PSRule/v1\",\n \"kind\": \"Rule\",\n \"metadata\": {\n \"name\": \"Local.MyRule\"\n },\n \"spec\": {\n \"with\": [\n \"PSRule.Rules.Azure\\\\Azure.FrontDoor.IsStandardOrPremium\"\n ],\n \"condition\": {\n // Rule logic goes here\n }\n }\n}\n
"},{"location":"en/selectors/Azure.FrontDoor.IsStandardOrPremium/#configure-with-powershell-based-rules","title":"Configure with PowerShell-based rules","text":"-With
parameter to set PSRule.Rules.Azure\\Azure.FrontDoor.IsStandardOrPremium
.# Synopsis: An example rule.\nRule 'Local.MyRule' -With 'PSRule.Rules.Azure\\Azure.FrontDoor.IsStandardOrPremium' {\n # Rule logic goes here\n}\n
"},{"location":"en/selectors/Azure.Resource.SupportsTags/","title":"Azure.Resource.SupportsTags","text":"Resources that supports tags.
"},{"location":"en/selectors/Azure.Resource.SupportsTags/#description","title":"Description","text":"Use this selector to filter rules to only run against resources that support tags.
"},{"location":"en/selectors/Azure.Resource.SupportsTags/#examples","title":"Examples","text":""},{"location":"en/selectors/Azure.Resource.SupportsTags/#configure-with-yaml-based-rules","title":"Configure with YAML-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.Resource.SupportsTags
.---\n# Synopsis: An example rule.\napiVersion: github.com/microsoft/PSRule/v1\nkind: Rule\nmetadata:\n name: Local.MyRule\nspec:\n with:\n - PSRule.Rules.Azure\\Azure.Resource.SupportsTags\n condition:\n # Rule logic goes here\n
"},{"location":"en/selectors/Azure.Resource.SupportsTags/#configure-with-json-based-rules","title":"Configure with JSON-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.Resource.SupportsTags
.{\n // Synopsis: An example rule.\n \"apiVersion\": \"github.com/microsoft/PSRule/v1\",\n \"kind\": \"Rule\",\n \"metadata\": {\n \"name\": \"Local.MyRule\"\n },\n \"spec\": {\n \"with\": [\n \"PSRule.Rules.Azure\\\\Azure.Resource.SupportsTags\"\n ],\n \"condition\": {\n // Rule logic goes here\n }\n }\n}\n
"},{"location":"en/selectors/Azure.Resource.SupportsTags/#configure-with-powershell-based-rules","title":"Configure with PowerShell-based rules","text":"-With
parameter to set PSRule.Rules.Azure\\Azure.Resource.SupportsTags
.# Synopsis: An example rule.\nRule 'Local.MyRule' -With 'PSRule.Rules.Azure\\Azure.Resource.SupportsTags' {\n # Rule logic goes here\n}\n
"},{"location":"en/selectors/Azure.ServiceBus.IsPremium/","title":"Azure.ServiceBus.IsPremium","text":"Azure Service Bus premium namespaces.
"},{"location":"en/selectors/Azure.ServiceBus.IsPremium/#description","title":"Description","text":"Use this selector to filter rules to only run against premium Service Bus namespaces.
"},{"location":"en/selectors/Azure.ServiceBus.IsPremium/#examples","title":"Examples","text":""},{"location":"en/selectors/Azure.ServiceBus.IsPremium/#configure-with-yaml-based-rules","title":"Configure with YAML-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.ServiceBus.IsPremium
.---\n# Synopsis: An example rule.\napiVersion: github.com/microsoft/PSRule/v1\nkind: Rule\nmetadata:\n name: Local.MyRule\nspec:\n with:\n - PSRule.Rules.Azure\\Azure.ServiceBus.IsPremium\n condition:\n # Rule logic goes here\n
"},{"location":"en/selectors/Azure.ServiceBus.IsPremium/#configure-with-json-based-rules","title":"Configure with JSON-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.ServiceBus.IsPremium
.{\n // Synopsis: An example rule.\n \"apiVersion\": \"github.com/microsoft/PSRule/v1\",\n \"kind\": \"Rule\",\n \"metadata\": {\n \"name\": \"Local.MyRule\"\n },\n \"spec\": {\n \"with\": [\n \"PSRule.Rules.Azure\\\\Azure.ServiceBus.IsPremium\"\n ],\n \"condition\": {\n // Rule logic goes here\n }\n }\n}\n
"},{"location":"en/selectors/Azure.ServiceBus.IsPremium/#configure-with-powershell-based-rules","title":"Configure with PowerShell-based rules","text":"-With
parameter to set PSRule.Rules.Azure\\Azure.ServiceBus.IsPremium
.# Synopsis: An example rule.\nRule 'Local.MyRule' -With 'PSRule.Rules.Azure\\Azure.ServiceBus.IsPremium' {\n # Rule logic goes here\n}\n
"},{"location":"es/asb-v3/","title":"Azure Security Benchmark","text":"Azure Security Benchmark (ASB) es un conjunto de controles y recomendaciones que ayudan a mejorar la seguridad de las cargas de trabajo en Azure. Los controles del ASB tambi\u00e9n se asignan a los marcos de la industria, como CIS, PCI-DSS y NIST. Si esta es su primera introduccion a ASB o esta busecano por ayudo a como utilizarlo, refiera a la Introducci\u00f3n a Azure Security Benchmark
"},{"location":"es/asb-v3/#azure-security-benchmark-v3","title":"Azure Security Benchmark v3","text":"Esta es la versi\u00f3n mas reciente del ASB. Las reglas incluidas en PSRule para Azure se han asignado a v3 para que pueda comprender el impacto de las reglas. Esto es particularmente \u00fatil cuando busca comprender c\u00f3mo abordar un requisito de cumplimiento espec\u00edfico de su organizaci\u00f3n.
Los siguientes controles est\u00e1n incluidos en Azure Security Benchmark v3:
Gobernanza y estrategia (GS)
The following rules and features are included in PSRule for Azure.
Info
The rule release indicates if the Azure feature is generally available (GA) or available under preview. Features provided under previews may have additional limits, availability restrictions, or terms. By default, PSRule for Azure will not provide recommendations that relate to preview features. To include rules for preview features see working with baselines.
"},{"location":"es/rules/#rules","title":"Rules","text":"The following rules are included in PSRule for Azure.
Reference Name Synopsis Release AZR-000001 Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. GA AZR-000002 Azure.ACR.ContainerScan Enable vulnerability scanning for container images. GA AZR-000003 Azure.ACR.ImageHealth Remove container images with known vulnerabilities. GA AZR-000004 Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. GA AZR-000005 Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. GA AZR-000006 Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. GA AZR-000007 Azure.ACR.Name Container registry names should meet naming requirements. GA AZR-000008 Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Preview AZR-000009 Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. GA AZR-000010 Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Preview AZR-000011 Azure.ADX.Usage Regularly remove unused resources to reduce costs. GA AZR-000012 Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. GA AZR-000013 Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. GA AZR-000014 Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. GA AZR-000015 Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. GA AZR-000016 Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. GA AZR-000017 Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. GA AZR-000018 Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. GA AZR-000019 Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. GA AZR-000020 Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. GA AZR-000021 Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. GA AZR-000022 Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. GA AZR-000023 Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. GA AZR-000024 Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. GA AZR-000025 Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. GA AZR-000026 Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. GA AZR-000027 Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. GA AZR-000028 Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. GA AZR-000029 Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. GA AZR-000030 Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. GA AZR-000031 Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. GA AZR-000032 Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. GA AZR-000033 Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. GA AZR-000034 Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. GA AZR-000035 Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. GA AZR-000036 Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. GA AZR-000038 Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. GA AZR-000039 Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. GA AZR-000040 Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. GA AZR-000041 Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. GA AZR-000042 Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. GA AZR-000043 Azure.APIM.APIDescriptors API Management APIs should have a display name and description. GA AZR-000044 Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. GA AZR-000045 Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. GA AZR-000046 Azure.APIM.ProductSubscription Configure products to require a subscription. GA AZR-000047 Azure.APIM.ProductApproval Configure products to require approval. GA AZR-000048 Azure.APIM.SampleProducts Remove starter and unlimited sample products. GA AZR-000049 Azure.APIM.ProductDescriptors API Management products should have a display name and description. GA AZR-000050 Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. GA AZR-000051 Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. GA AZR-000052 Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. GA AZR-000053 Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. GA AZR-000054 Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. GA AZR-000055 Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. GA AZR-000056 Azure.APIM.Name API Management service names should meet naming requirements. GA AZR-000057 Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. GA AZR-000058 Azure.AppConfig.Name App Configuration store names should meet naming requirements. GA AZR-000059 Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. GA AZR-000060 Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. GA AZR-000061 Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. GA AZR-000062 Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. GA AZR-000063 Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. GA AZR-000064 Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. GA AZR-000065 Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. GA AZR-000066 Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. GA AZR-000067 Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. GA AZR-000068 Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. GA AZR-000069 Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. GA AZR-000070 Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. GA AZR-000071 Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. GA AZR-000072 Azure.AppService.MinPlan Use at least a Standard App Service Plan. GA AZR-000073 Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. GA AZR-000074 Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. GA AZR-000075 Azure.AppService.NETVersion Configure applications to use newer .NET versions. GA AZR-000076 Azure.AppService.PHPVersion Configure applications to use newer PHP runtime versions. GA AZR-000077 Azure.AppService.AlwaysOn Configure Always On for App Service apps. GA AZR-000078 Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. GA AZR-000079 Azure.AppService.WebProbe Configure and enable instance health probes. GA AZR-000080 Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. GA AZR-000081 Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. GA AZR-000082 Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. GA AZR-000083 Azure.AppService.ARRAffinity Disable client affinity for stateless services. GA AZR-000084 Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. GA AZR-000085 Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. GA AZR-000086 Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. GA AZR-000087 Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). GA AZR-000088 Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. GA AZR-000089 Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. GA AZR-000090 Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. GA AZR-000091 Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. GA AZR-000092 Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. GA AZR-000093 Azure.CDN.HTTP Enforce HTTPS for client connections. GA AZR-000094 Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. GA AZR-000095 Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. GA AZR-000096 Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. GA AZR-000097 Azure.DataFactory.Version Consider migrating to DataFactory v2. GA AZR-000098 Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. GA AZR-000099 Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. GA AZR-000100 Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. GA AZR-000101 Azure.EventHub.Usage Regularly remove unused resources to reduce costs. GA AZR-000102 Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. GA AZR-000103 Azure.Firewall.Name Firewall names should meet naming requirements. GA AZR-000104 Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. GA AZR-000105 Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. GA AZR-000106 Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. GA AZR-000107 Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. GA AZR-000108 Azure.FrontDoor.Probe Use health probes to check the health of each backend. GA AZR-000109 Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. GA AZR-000110 Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. GA AZR-000111 Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. GA AZR-000112 Azure.FrontDoor.State Enable Azure Front Door Classic instance. GA AZR-000113 Azure.FrontDoor.Name Front Door names should meet naming requirements. GA AZR-000114 Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. GA AZR-000115 Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. GA AZR-000116 Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. GA AZR-000117 Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. GA AZR-000118 Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. GA AZR-000119 Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. GA AZR-000120 Azure.KeyVault.Name Key Vault names should meet naming requirements. GA AZR-000121 Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. GA AZR-000122 Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. GA AZR-000123 Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. GA AZR-000124 Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. GA AZR-000125 Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. GA AZR-000126 Azure.LB.Probe Use a specific probe for web protocols. GA AZR-000127 Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. GA AZR-000128 Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. GA AZR-000129 Azure.LB.Name Load Balancer names should meet naming requirements. GA AZR-000130 Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. GA AZR-000131 Azure.MySQL.UseSSL Enforce encrypted MySQL connections. GA AZR-000132 Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. GA AZR-000133 Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. GA AZR-000134 Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. GA AZR-000135 Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. GA AZR-000136 Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. GA AZR-000137 Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. GA AZR-000138 Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. GA AZR-000139 Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. GA AZR-000140 Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. GA AZR-000141 Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. GA AZR-000142 Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. GA AZR-000143 Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. GA AZR-000144 Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. GA AZR-000145 Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. GA AZR-000146 Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. GA AZR-000147 Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. GA AZR-000148 Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. GA AZR-000149 Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. GA AZR-000150 Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. GA AZR-000151 Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. GA AZR-000152 Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. GA AZR-000153 Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. GA AZR-000154 Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. GA AZR-000155 Azure.PublicIP.Name Public IP names should meet naming requirements. GA AZR-000156 Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. GA AZR-000157 Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. GA AZR-000158 Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. GA AZR-000159 Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. GA AZR-000160 Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. GA AZR-000161 Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. GA AZR-000162 Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. GA AZR-000163 Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. GA AZR-000164 Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. GA AZR-000165 Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. GA AZR-000166 Azure.Resource.UseTags Azure resources should be tagged using a standard convention. GA AZR-000167 Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. GA AZR-000168 Azure.ResourceGroup.Name Resource Group names should meet naming requirements. GA AZR-000169 Azure.Route.Name Route table names should meet naming requirements. GA AZR-000170 Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. GA AZR-000171 Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. GA AZR-000172 Azure.Search.SKU Use the basic and standard tiers for entry level workloads. GA AZR-000173 Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. GA AZR-000174 Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. GA AZR-000175 Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. GA AZR-000176 Azure.Search.Name AI Search service names should meet naming requirements. GA AZR-000177 Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. GA AZR-000178 Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. GA AZR-000179 Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. GA AZR-000180 Azure.SignalR.Name SignalR service instance names should meet naming requirements. GA AZR-000181 Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. GA AZR-000182 Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. GA AZR-000183 Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. GA AZR-000184 Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. GA AZR-000185 Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). GA AZR-000186 Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. GA AZR-000187 Azure.SQL.Auditing Enable auditing for Azure SQL logical server. GA AZR-000188 Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. GA AZR-000189 Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. GA AZR-000190 Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. GA AZR-000191 Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. GA AZR-000192 Azure.SQL.DBName Azure SQL Database names should meet naming requirements. GA AZR-000193 Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. GA AZR-000194 Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. GA AZR-000195 Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. GA AZR-000196 Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. GA AZR-000197 Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. GA AZR-000198 Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. GA AZR-000199 Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. GA AZR-000200 Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. GA AZR-000201 Azure.Storage.Name Storage Account names should meet naming requirements. GA AZR-000202 Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. GA AZR-000203 Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. GA AZR-000204 Azure.RBAC.LimitOwner Limit the number of subscription Owners. GA AZR-000205 Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. GA AZR-000206 Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). GA AZR-000207 Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. GA AZR-000208 Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. GA AZR-000209 Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. GA AZR-000210 Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. GA AZR-000211 Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. GA AZR-000212 Azure.Template.TemplateFile Use ARM template files that are valid. GA AZR-000213 Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. GA AZR-000214 Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. GA AZR-000215 Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. GA AZR-000216 Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. GA AZR-000217 Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. GA AZR-000218 Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. GA AZR-000219 Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. GA AZR-000220 Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. GA AZR-000221 Azure.Template.LocationType Location parameters should use a string value. GA AZR-000222 Azure.Template.ResourceLocation Template resource location should be an expression or global. GA AZR-000223 Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. GA AZR-000224 Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. GA AZR-000225 Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. GA AZR-000226 Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. GA AZR-000227 Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. GA AZR-000228 Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. GA AZR-000229 Azure.Template.ParameterFile Use ARM template parameter files that are valid. GA AZR-000230 Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. GA AZR-000231 Azure.Template.MetadataLink Configure a metadata link for each parameter file. GA AZR-000232 Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. GA AZR-000233 Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. GA AZR-000234 Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. GA AZR-000235 Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. GA AZR-000236 Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. GA AZR-000237 Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. GA AZR-000238 Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. GA AZR-000239 Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. GA AZR-000240 Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. GA AZR-000241 Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. GA AZR-000242 Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. GA AZR-000243 Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. GA AZR-000244 Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. GA AZR-000245 Azure.VM.PublicKey Linux virtual machines should use public keys. GA AZR-000246 Azure.VM.Agent Ensure the VM agent is provisioned automatically. GA AZR-000247 Azure.VM.Updates Ensure automatic updates are enabled at deployment. GA AZR-000248 Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. GA AZR-000249 Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. GA AZR-000250 Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. GA AZR-000251 Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. GA AZR-000252 Azure.VM.ADE Use Azure Disk Encryption (ADE). GA AZR-000253 Azure.VM.DiskName Managed Disk names should meet naming requirements. GA AZR-000254 Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. GA AZR-000255 Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). GA AZR-000256 Azure.VM.ASName Availability Set names should meet naming requirements. GA AZR-000257 Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. GA AZR-000258 Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. GA AZR-000259 Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. GA AZR-000260 Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. GA AZR-000261 Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. GA AZR-000262 Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. GA AZR-000263 Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. GA AZR-000264 Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. GA AZR-000265 Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. GA AZR-000266 Azure.VNET.PeerState VNET peering connections must be connected. GA AZR-000267 Azure.VNET.SubnetName Subnet names should meet naming requirements. GA AZR-000268 Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. GA AZR-000269 Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. GA AZR-000270 Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. GA AZR-000271 Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. GA AZR-000272 Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. GA AZR-000273 Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. GA AZR-000274 Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. GA AZR-000275 Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. GA AZR-000276 Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. GA AZR-000277 Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. GA AZR-000278 Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. GA AZR-000279 Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. GA AZR-000280 Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. GA AZR-000281 Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. GA AZR-000282 Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. GA AZR-000283 Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. GA AZR-000284 Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. GA AZR-000285 Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. GA AZR-000286 Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. GA AZR-000287 Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. GA AZR-000288 Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. GA AZR-000289 Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. GA AZR-000290 Azure.Defender.Containers Enable Microsoft Defender for Containers. GA AZR-000291 Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. GA AZR-000292 Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. GA AZR-000293 Azure.Defender.Servers Enable Microsoft Defender for Servers. GA AZR-000294 Azure.Defender.SQL Enable Microsoft Defender for SQL servers. GA AZR-000295 Azure.Defender.AppServices Enable Microsoft Defender for App Service. GA AZR-000296 Azure.Defender.Storage Enable Microsoft Defender for Storage. GA AZR-000297 Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. GA AZR-000298 Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. GA AZR-000299 Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. GA AZR-000300 Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. GA AZR-000301 Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. GA AZR-000302 Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. GA AZR-000303 Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. GA AZR-000304 Azure.AppGwWAF.RuleGroups Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. GA AZR-000305 Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. GA AZR-000306 Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. GA AZR-000307 Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. GA AZR-000308 Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. GA AZR-000309 Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. GA AZR-000310 Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Preview AZR-000311 Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. GA AZR-000312 Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. GA AZR-000313 Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. GA AZR-000314 Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. GA AZR-000315 Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. GA AZR-000316 Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. GA AZR-000317 Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. GA AZR-000318 Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. GA AZR-000319 Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. GA AZR-000320 Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. GA AZR-000321 Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. GA AZR-000322 Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. GA AZR-000323 Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. GA AZR-000324 Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. GA AZR-000325 Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. GA AZR-000326 Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. GA AZR-000327 Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. GA AZR-000328 Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. GA AZR-000329 Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. GA AZR-000330 Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. GA AZR-000331 Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. GA AZR-000332 Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. GA AZR-000333 Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. GA AZR-000334 Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. GA AZR-000335 Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. GA AZR-000336 Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. GA AZR-000337 Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. GA AZR-000338 Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. GA AZR-000339 Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. GA AZR-000340 Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. GA AZR-000341 Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. GA AZR-000342 Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. GA AZR-000343 Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. GA AZR-000344 Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. GA AZR-000345 Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. GA AZR-000346 Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. GA AZR-000347 Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. GA AZR-000348 Azure.AppGw.Name Application Gateways should meet naming requirements. GA AZR-000349 Azure.Bastion.Name Bastion hosts should meet naming requirements. GA AZR-000350 Azure.RSV.Name Recovery Services vaults should meet naming requirements. GA AZR-000351 Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. GA AZR-000352 Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. GA AZR-000353 Azure.Defender.Dns Enable Microsoft Defender for DNS. GA AZR-000354 Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). GA AZR-000355 Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. GA AZR-000356 Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. GA AZR-000357 Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. GA AZR-000358 Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. GA AZR-000359 Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. GA AZR-000360 Azure.ContainerApp.Name Container Apps should meet naming requirements. GA AZR-000361 Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. GA AZR-000362 Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. GA AZR-000363 Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. GA AZR-000364 Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. GA AZR-000365 Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. GA AZR-000366 Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. GA AZR-000367 Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. GA AZR-000368 Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. GA AZR-000369 Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. GA AZR-000370 Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. GA AZR-000371 Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. GA AZR-000372 Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. GA AZR-000373 Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Preview AZR-000374 Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Preview AZR-000375 Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Preview AZR-000376 Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. GA AZR-000377 Azure.Defender.Api Enable Microsoft Defender for APIs. GA AZR-000378 Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. GA AZR-000379 Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. GA AZR-000380 Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. GA AZR-000381 Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. GA AZR-000382 Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. GA AZR-000383 Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. GA AZR-000384 Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. GA AZR-000385 Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Preview AZR-000386 Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. GA AZR-000387 Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. GA AZR-000388 Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. GA AZR-000389 Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. GA AZR-000390 Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. GA AZR-000391 Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Preview AZR-000392 Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. GA AZR-000393 Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. GA AZR-000394 Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. GA AZR-000395 Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. GA AZR-000396 Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. GA AZR-000397 Azure.RSV.Immutable Ensure immutability is configured to protect backup data. GA AZR-000398 Azure.BV.Immutable Ensure immutability is configured to protect backup data. GA AZR-000399 Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. GA AZR-000400 Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. GA AZR-000401 Azure.ACR.AnonymousAccess Disable anonymous pull access. Preview AZR-000402 Azure.ACR.Firewall Limit network access of container registries to only trusted clients. GA AZR-000403 Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. GA AZR-000404 Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. GA AZR-000405 Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). GA AZR-000406 Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. GA AZR-000407 Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. GA AZR-000408 Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. GA AZR-000409 Azure.Databricks.SKU Ensure Databricks workspaces are non-trial SKUs for production workloads. GA AZR-000410 Azure.Databricks.PublicAccess Azure Databricks workspaces should disable public network access. GA AZR-000411 Azure.DevBox.ProjectLimit Limit the number of Dev Boxes a single user can create for a project. GA AZR-000412 Azure.AKS.MinUserPoolNodes User node pools in an AKS cluster should have a minimum number of nodes for failover and updates. GA"},{"location":"es/rules/Azure.ACR.AdminUser/","title":"Deshabilitar el usuario adminstrador para ACR","text":"Azure.ACR.AdminUserAZR-000005ErrorSeguridad \u00b7 Container Registry \u00b7 Rule \u00b7 2020_06 \u00b7 Critico
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"es/rules/Azure.ACR.AdminUser/#sinopsis","title":"Sinopsis","text":"Usar identidades de Azure AD en lugar de usar el usuario administrador del registro.
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"es/rules/Azure.ACR.AdminUser/#descripcion","title":"Descripci\u00f3n","text":"Azure Container Registry (ACR) incluye una cuenta de usuario administrador incorporada. La cuenta de usuario administrador es una cuenta de usuario \u00fanica con acceso administrativo al registro. Esta cuenta proporciona acceso de usuario \u00fanico para pruebas y desarrollo tempranos. La cuenta de usuario administrador no est\u00e1 dise\u00f1ada para usarse con registros de contenedores de producci\u00f3n.
En su lugar, utilice el control de acceso basado en roles (RBAC). RBAC se puede usar para delegar permisos de registro a una identidad de Azure AD (AAD).
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"es/rules/Azure.ACR.AdminUser/#recomendacion","title":"Recomendaci\u00f3n","text":"Considere deshabilitar la cuenta de usuario administrador y solo use la autenticaci\u00f3n basada en identidad para las operaciones de registro.
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"es/rules/Azure.ACR.AdminUser/#ejemplos","title":"Ejemplos","text":"","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"es/rules/Azure.ACR.AdminUser/#configurar-con-plantilla-de-arm","title":"Configurar con plantilla de ARM","text":"Para implementar Container Registries, pasa la siguiente regla:
properties.adminUserEnabled
a false
.Por ejemplo:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2023-07-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"days\": 30,\n \"status\": \"enabled\"\n }\n }\n }\n}\n
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"es/rules/Azure.ACR.AdminUser/#configurar-con-bicep","title":"Configurar con Bicep","text":"Para implementar Container Registries, pasa la siguiente regla:
properties.adminUserEnabled
a false
.Por ejemplo:
Azure Bicep snippetresource registry 'Microsoft.ContainerRegistry/registries@2023-07-01' = {\n name: name\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n days: 30\n status: 'enabled'\n }\n }\n }\n}\n
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"es/rules/Azure.ACR.AdminUser/#configurar-con-azure-cli","title":"Configurar con Azure CLI","text":"Azure CLI snippetaz acr update -n '<name>' -g '<resource_group>' --admin-enabled false\n
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"es/rules/Azure.ACR.AdminUser/#configurar-con-azure-powershell","title":"Configurar con Azure PowerShell","text":"Azure PowerShell snippetUpdate-AzContainerRegistry -ResourceGroupName '<resource_group>' -Name '<name>' -DisableAdminUser\n
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"es/rules/Azure.ACR.AdminUser/#enlaces","title":"Enlaces","text":"Seguridad \u00b7 Container Registry \u00b7 Rule \u00b7 2020_12 \u00b7 Critico
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"es/rules/Azure.ACR.ContainerScan/#sinopsis","title":"Sinopsis","text":"Habilite el an\u00e1lisis de vulnerabilidades para im\u00e1genes de contenedores.
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"es/rules/Azure.ACR.ContainerScan/#descripcion","title":"Descripci\u00f3n","text":"Un riesgo potencial con las cargas de trabajo basadas en contenedores son las vulnerabilidades de seguridad sin parches en:
Es importante adoptar una estrategia para escanear activamente las im\u00e1genes en busca de vulnerabilidades de seguridad. Una opci\u00f3n para escanear im\u00e1genes de contenedores es usar Microsoft Defender para registros de contenedores. Microsoft Defender para registros de contenedores analiza cada imagen de contenedor enviada al registro.
Microsoft Defender para registros de contenedores analiza im\u00e1genes en im\u00e1genes insertadas, importadas y extra\u00eddas recientemente. Las im\u00e1genes extra\u00eddas recientemente se escanean peri\u00f3dicamente cuando se extrajeron en los \u00faltimos 30 d\u00edas. Cualquier vulnerabilidad detectada se informa a Microsoft Defender for Cloud.
Escaneo de vulnerabilidades de im\u00e1genes de contenedores con Microsoft Defender para registros de contenedores:
Considere usar Microsoft Defender para la nube para buscar vulnerabilidades de seguridad en im\u00e1genes de contenedores.
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"es/rules/Azure.ACR.ContainerScan/#ejemplos","title":"Ejemplos","text":"","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"es/rules/Azure.ACR.ContainerScan/#configurar-con-plantilla-de-arm","title":"Configurar con plantilla de ARM","text":"Para habilitar el escaneo de im\u00e1genes de contenedores:
pricingTier
a Standard
para Microsoft Defender para container registries.Por ejemplo:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2018-06-01\",\n \"name\": \"ContainerRegistry\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"es/rules/Azure.ACR.ContainerScan/#configurar-con-bicep","title":"Configurar con Bicep","text":"Para habilitar el escaneo de im\u00e1genes de contenedores:
pricingTier
a Standard
para Microsoft Defender para container registries.Por ejemplo:
Azure Bicep snippetresource defenderForContainerRegistry 'Microsoft.Security/pricings@2018-06-01' = {\n name: 'ContainerRegistry'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"es/rules/Azure.ACR.ContainerScan/#configurar-con-azure-cli","title":"Configurar con Azure CLI","text":"Azure CLI snippetaz security pricing create -n 'ContainerRegistry' --tier 'standard'\n
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"es/rules/Azure.ACR.ContainerScan/#configurar-con-azure-powershell","title":"Configurar con Azure PowerShell","text":"Azure PowerShell snippetSet-AzSecurityPricing -Name 'ContainerRegistry' -PricingTier 'Standard'\n
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"es/rules/Azure.ACR.ContainerScan/#notas","title":"Notas","text":"Esta regla se aplica cuando se analizan los recursos implementados en Azure.
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"es/rules/Azure.ACR.ContainerScan/#enlaces","title":"Enlaces","text":"Seguridad \u00b7 Container Registry \u00b7 Rule \u00b7 2020_12 \u00b7 Importante
","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"es/rules/Azure.ACR.ContentTrust/#sinopsis","title":"Sinopsis","text":"Utilica im\u00e1genes de contenedores firmadas por un publicador de im\u00e1genes de confianza. Use container images signed by a trusted image publisher.
","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"es/rules/Azure.ACR.ContentTrust/#descripcion","title":"Descripci\u00f3n","text":"La confianza en el contenido de Azure Container Registry (ACR) permite insertar y extraer im\u00e1genes firmadas. Las im\u00e1genes firmadas brindan una garant\u00eda adicional de que se han creado en una fuente confiable. Para habilitar la confianza en el contenido, el registro del contenedor debe usar una SKU Premium.
","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"es/rules/Azure.ACR.ContentTrust/#recomendacion","title":"Recomendaci\u00f3n","text":"Considere habilitar la confianza en el contenido en registros, clientes e im\u00e1genes de contenedores de firmas.
","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"es/rules/Azure.ACR.ContentTrust/#ejemplos","title":"Ejemplos","text":"","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"es/rules/Azure.ACR.ContentTrust/#configurar-con-plantilla-de-arm","title":"Configurar con plantilla de ARM","text":"Para implementar resgistros de contenedores que superen esta regla:
properties.trustPolicy.status
a enabled
.properties.trustPolicy.type
a Notary
.Por ejemplo:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2021-06-01-preview\",\n \"name\": \"[parameters('registryName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"quarantinePolicy\": {\n \"status\": \"enabled\"\n },\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"status\": \"enabled\",\n \"days\": 30\n }\n }\n }\n}\n
","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"es/rules/Azure.ACR.ContentTrust/#configurar-con-bicep","title":"Configurar con Bicep","text":"Para implementar resgistros de contenedores que superen esta regla:
properties.trustPolicy.status
a enabled
.properties.trustPolicy.type
a Notary
.Por ejemplo:
Azure Bicep snippetresource acr 'Microsoft.ContainerRegistry/registries@2021-06-01-preview' = {\n name: registryName\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n quarantinePolicy: {\n status: 'enabled'\n }\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n status: 'enabled'\n days: 30\n }\n }\n }\n}\n
","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"es/rules/Azure.ACR.ContentTrust/#enlaces","title":"Enlaces","text":"Confiabilidad \u00b7 Container Registry \u00b7 Rule \u00b7 2020_12 \u00b7 Importante
","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"es/rules/Azure.ACR.GeoReplica/#sinopsis","title":"Sinopsis","text":"Utilice registros de contenedores replicados geogr\u00e1ficamente para complementar las implementaciones de contenedores en varias regiones.
","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"es/rules/Azure.ACR.GeoReplica/#descripcion","title":"Descripci\u00f3n","text":"Un registro de contenedor se almacena y mantiene de forma predeterminada en una sola regi\u00f3n. Opcionalmente, se puede habilitar la replicaci\u00f3n geogr\u00e1fica en una o m\u00e1s regiones adicionales.
Los registros de contenedores de replicaci\u00f3n geogr\u00e1fica brindan los siguientes beneficios:
Considere usar un registro de contenedor replicado geogr\u00e1ficamente para implementaciones en varias regiones.
","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"es/rules/Azure.ACR.GeoReplica/#ejemplos","title":"Ejemplos","text":"","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"es/rules/Azure.ACR.GeoReplica/#configurar-con-plantilla-de-arm","title":"Configurar con plantilla de ARM","text":"Para habilitar la replicaci\u00f3n geogr\u00e1fica para registros de contenedores que pasan esta regla:
sku.name
a Premium
(necesario para la replicaci\u00f3n geogr\u00e1fica).replications
con location
establecida en la regi\u00f3n para replicar.Por ejemplo:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"metadata\": {\n \"_generator\": {\n \"name\": \"bicep\",\n \"version\": \"0.5.6.12127\",\n \"templateHash\": \"12610175857982700190\"\n }\n },\n \"parameters\": {\n \"acrName\": {\n \"type\": \"string\",\n \"defaultValue\": \"[format('acr{0}', uniqueString(resourceGroup().id))]\",\n \"maxLength\": 50,\n \"minLength\": 5,\n \"metadata\": {\n \"description\": \"Globally unique name of your Azure Container Registry\"\n }\n },\n \"acrAdminUserEnabled\": {\n \"type\": \"bool\",\n \"defaultValue\": false,\n \"metadata\": {\n \"description\": \"Enable admin user that has push / pull permission to the registry.\"\n }\n },\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"Location for registry home replica.\"\n }\n },\n \"acrSku\": {\n \"type\": \"string\",\n \"defaultValue\": \"Premium\",\n \"allowedValues\": [\"Premium\"],\n \"metadata\": {\n \"description\": \"Tier of your Azure Container Registry. Geo-replication requires Premium SKU.\"\n }\n },\n \"acrReplicaLocation\": {\n \"type\": \"string\",\n \"metadata\": {\n \"description\": \"Short name for registry replica location.\"\n }\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2019-12-01-preview\",\n \"name\": \"[parameters('acrName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('acrSku')]\"\n },\n \"tags\": {\n \"displayName\": \"Container Registry\",\n \"container.registry\": \"[parameters('acrName')]\"\n },\n \"properties\": {\n \"adminUserEnabled\": \"[parameters('acrAdminUserEnabled')]\"\n }\n },\n {\n \"type\": \"Microsoft.ContainerRegistry/registries/replications\",\n \"apiVersion\": \"2019-12-01-preview\",\n \"name\": \"[format('{0}/{1}', parameters('acrName'), parameters('acrReplicaLocation'))]\",\n \"location\": \"[parameters('acrReplicaLocation')]\",\n \"properties\": {},\n \"dependsOn\": [\n \"[resourceId('Microsoft.ContainerRegistry/registries', parameters('acrName'))]\"\n ]\n }\n ],\n \"outputs\": {\n \"acrLoginServer\": {\n \"type\": \"string\",\n \"value\": \"[reference(resourceId('Microsoft.ContainerRegistry/registries', parameters('acrName'))).loginServer]\"\n }\n }\n}\n
","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"es/rules/Azure.ACR.GeoReplica/#configurar-con-bicep","title":"Configurar con Bicep","text":"Para habilitar la replicaci\u00f3n geogr\u00e1fica para registros de contenedores que pasan esta regla:
sku.name
a Premium
(necesario para la replicaci\u00f3n geogr\u00e1fica).replications
con location
establecida en la regi\u00f3n para replicar.Por ejemplo:
Azure Bicep snippetresource containerRegistry 'Microsoft.ContainerRegistry/registries@2019-12-01-preview' = {\n name: acrName\n location: location\n sku: {\n name: 'Premium'\n }\n tags: {\n displayName: 'Container Registry'\n 'container.registry': acrName\n }\n properties: {\n adminUserEnabled: acrAdminUserEnabled\n }\n}\n\nresource containerRegistryReplica 'Microsoft.ContainerRegistry/registries/replications@2019-12-01-preview' = {\n parent: containerRegistry\n name: '${acrReplicaLocation}'\n location: acrReplicaLocation\n properties: {\n }\n}\n
","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"es/rules/Azure.ACR.GeoReplica/#notas","title":"Notas","text":"Esta regla se aplica cuando se analizan los recursos implementados en Azure.
","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"es/rules/Azure.ACR.GeoReplica/#elaces","title":"Elaces","text":"Seguridad \u00b7 Container Registry \u00b7 Rule \u00b7 2020_12 \u00b7 Critico
","tags":["Azure.ACR.ImageHealth","AZR-000003"]},{"location":"es/rules/Azure.ACR.ImageHealth/#sinopsis","title":"Sinopsis","text":"Eliminar im\u00e1genes de contenedores con vulnerabilidades conocidas.
","tags":["Azure.ACR.ImageHealth","AZR-000003"]},{"location":"es/rules/Azure.ACR.ImageHealth/#descripcion","title":"Descripci\u00f3n","text":"Cuando Microsoft Defender para registros de contenedores est\u00e1 habilitado, Microsoft Defender analiza las im\u00e1genes de contenedores. Las im\u00e1genes de contenedores se escanean en busca de vulnerabilidades conocidas y se marcan como saludables o no saludables. No se deben utilizar im\u00e1genes de contenedores vulnerables.
","tags":["Azure.ACR.ImageHealth","AZR-000003"]},{"location":"es/rules/Azure.ACR.ImageHealth/#recomendacion","title":"Recomendaci\u00f3n","text":"Considere usar la eliminaci\u00f3n de im\u00e1genes de contenedores con vulnerabilidades conocidas.
","tags":["Azure.ACR.ImageHealth","AZR-000003"]},{"location":"es/rules/Azure.ACR.ImageHealth/#notas","title":"Notas","text":"Esta regla se aplica cuando se analizan los recursos implementados en Azure.
","tags":["Azure.ACR.ImageHealth","AZR-000003"]},{"location":"es/rules/Azure.ACR.ImageHealth/#enlaces","title":"Enlaces","text":"Confiabilidad \u00b7 Container Registry \u00b7 Rule \u00b7 2020_06 \u00b7 Importante
","tags":["Azure.ACR.MinSku","AZR-000006"]},{"location":"es/rules/Azure.ACR.MinSku/#sinopsis","title":"Sinopsis","text":"ACR debe usar el SKU Premium o Est\u00e1ndar para las implementaciones de producci\u00f3n.
","tags":["Azure.ACR.MinSku","AZR-000006"]},{"location":"es/rules/Azure.ACR.MinSku/#descripcion","title":"Descripci\u00f3n","text":"Azure Container Registry (ACR) proporciona una gama de diferentes niveles de servicio (tambi\u00e9n conocidos como SKU). Estos niveles de servicio proporcionan diferentes niveles de rendimiento y caracter\u00edsticas.
Hay tres niveles de servicio disponibles: B\u00e1sico, Est\u00e1ndar y Premium. Los registros de contenedores b\u00e1sicos solo se recomiendan para implementaciones que no sean de producci\u00f3n. Utilice un m\u00ednimo de Est\u00e1ndar para registros de contenedores de producci\u00f3n.
El SKU Premium proporciona un mayor rendimiento de im\u00e1genes y almacenamiento incluido, y es necesario para:
Considere usar el SKU de Premium de registros de contenedores para implementaciones de producci\u00f3n.
","tags":["Azure.ACR.MinSku","AZR-000006"]},{"location":"es/rules/Azure.ACR.MinSku/#ejemplos","title":"Ejemplos","text":"","tags":["Azure.ACR.MinSku","AZR-000006"]},{"location":"es/rules/Azure.ACR.MinSku/#configurar-con-plantilla-de-arm","title":"Configurar con plantilla de ARM","text":"Para implementar registros de contenedores que superen esta regla:
sku.name
a Premium
o Standard
.Por ejemplo:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2021-06-01-preview\",\n \"name\": \"[parameters('registryName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"quarantinePolicy\": {\n \"status\": \"enabled\"\n },\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"status\": \"enabled\",\n \"days\": 30\n }\n }\n }\n}\n
","tags":["Azure.ACR.MinSku","AZR-000006"]},{"location":"es/rules/Azure.ACR.MinSku/#configurar-con-bicep","title":"Configurar con Bicep","text":"Para implementar registros de contenedores que superen esta regla:
sku.name
a Premium
o Standard
.Por ejemplo:
Azure Bicep snippetresource acr 'Microsoft.ContainerRegistry/registries@2021-06-01-preview' = {\n name: registryName\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n quarantinePolicy: {\n status: 'enabled'\n }\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n status: 'enabled'\n days: 30\n }\n }\n }\n}\n
","tags":["Azure.ACR.MinSku","AZR-000006"]},{"location":"es/rules/Azure.ACR.MinSku/#elaces","title":"Elaces","text":"Excelencia operativa \u00b7 Container Registry \u00b7 Rule \u00b7 2020_06 \u00b7 Consciente
","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"es/rules/Azure.ACR.Name/#sinopsis","title":"Sinopsis","text":"Los nombres de registro de contenedores deben cumplir con los requisitos de denominaci\u00f3n.
","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"es/rules/Azure.ACR.Name/#descripcion","title":"Descripci\u00f3n","text":"Al nombrar los recursos de Azure, los nombres de los recursos deben cumplir con los requisitos del servicio. Los requisitos para los nombres de registro de contenedores son:
Considere usar nombres que cumplan con los requisitos de nombres del registro de contenedores. Adem\u00e1s, considere nombrar recursos con una convenci\u00f3n de nomenclatura est\u00e1ndar.
","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"es/rules/Azure.ACR.Name/#ejemplos","title":"Ejemplos","text":"","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"es/rules/Azure.ACR.Name/#configurar-con-plantilla-de-arm","title":"Configurar con plantilla de ARM","text":"Puede asegurarse de que el par\u00e1metro acrName
cumpla con los requisitos de nomenclatura utilizando las propiedades de los par\u00e1metros MinLength
y maxLength
. Tambi\u00e9n puede usar una funci\u00f3n uniqueString()
para asegurarse de que el nombre sea globalmente \u00fanico.
Por ejemplo
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"acrName\": {\n \"type\": \"string\",\n \"defaultValue\": \"[format('acr{0}', uniqueString(resourceGroup().id))]\",\n \"maxLength\": 50,\n \"minLength\": 5,\n \"metadata\": {\n \"description\": \"Globally unique name of your Azure Container Registry\"\n }\n },\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"Location for registry home replica.\"\n }\n },\n \"acrSku\": {\n \"type\": \"string\",\n \"defaultValue\": \"Premium\",\n \"allowedValues\": [\n \"Standard\"\n \"Premium\"\n ],\n \"metadata\": {\n \"description\": \"Tier of your Azure Container Registry.\"\n }\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2019-12-01-preview\",\n \"name\": \"[parameters('acrName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('acrSku')]\"\n },\n \"tags\": {\n \"displayName\": \"Container Registry\",\n \"container.registry\": \"[parameters('acrName')]\"\n }\n }\n ],\n \"outputs\": {\n \"acrLoginServer\": {\n \"type\": \"string\",\n \"value\": \"[reference(resourceId('Microsoft.ContainerRegistry/registries', parameters('acrName'))).loginServer]\"\n }\n }\n}\n
","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"es/rules/Azure.ACR.Name/#configurar-con-bicep","title":"Configurar con Bicep","text":"Puede asegurarse de que el par\u00e1metro acrName
cumpla con los requisitos de nomenclatura utilizando las propiedades de los par\u00e1metros MinLength
y maxLength
. Tambi\u00e9n puede usar una funci\u00f3n uniqueString()
para asegurarse de que el nombre sea globalmente \u00fanico.
Por ejemplo:
Azure Bicep snippet@description('Globally unique name of your Azure Container Registry')\n@minLength(5)\n@maxLength(50)\nparam acrName string = 'acr${uniqueString(resourceGroup().id)}'\n\n@description('Location for registry home replica.')\nparam location string = resourceGroup().location\n\n@description('Tier of your Azure Container Registry. Geo-replication requires Premium SKU.')\n@allowed([\n 'Standard'\n 'Premium'\n])\nparam acrSku string = 'Premium'\n\nresource containerRegistry 'Microsoft.ContainerRegistry/registries@2019-12-01-preview' = {\n name: acrName\n location: location\n sku: {\n name: acrSku\n }\n tags: {\n displayName: 'Container Registry'\n 'container.registry': acrName\n }\n}\n\noutput acrLoginServer string = containerRegistry.properties.loginServer\n
","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"es/rules/Azure.ACR.Name/#notas","title":"Notas","text":"Esta regla no comprueba si los nombres de registro de contenedores son \u00fanicos.
","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"es/rules/Azure.ACR.Name/#enlaces","title":"Enlaces","text":"Seguridad \u00b7 Container Registry \u00b7 Rule \u00b7 Preview \u00b7 2020_12 \u00b7 Importante
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"es/rules/Azure.ACR.Quarantine/#sinopsis","title":"Sinopsis","text":"Habilite la cuarentena de im\u00e1genes de contenedores, escanee y marque im\u00e1genes como verificadas.
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"es/rules/Azure.ACR.Quarantine/#descripcion","title":"Descripci\u00f3n","text":"La cuarentena de im\u00e1genes es una opci\u00f3n configurable para Azure Container Registry (ACR). Cuando est\u00e1 habilitado, las im\u00e1genes enviadas al registro del contenedor no est\u00e1n disponibles de forma predeterminada. Cada imagen debe verificarse y marcarse como Aprobada
antes de que est\u00e9 disponible para extraer.
Para verificar im\u00e1genes de contenedores, integre con una herramienta de seguridad externa que admita esta funci\u00f3n.
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"es/rules/Azure.ACR.Quarantine/#recomendacion","title":"Recomendaci\u00f3n","text":"Considere configurar una herramienta de seguridad para implementar el patr\u00f3n de cuarentena de im\u00e1genes. Habilite la cuarentena de im\u00e1genes en el registro de contenedores para garantizar que cada imagen se verifique antes de su uso.
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"es/rules/Azure.ACR.Quarantine/#ejemplos","title":"Ejemplos","text":"","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"es/rules/Azure.ACR.Quarantine/#configurar-con-plantilla-de-arm","title":"Configurar con plantilla de ARM","text":"Para implementar registros de contenedores que superen esta regla:
properties.quarantinePolicy.status
a enabled
.Por ejemplo:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2021-06-01-preview\",\n \"name\": \"[parameters('registryName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"quarantinePolicy\": {\n \"status\": \"enabled\"\n },\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"status\": \"enabled\",\n \"days\": 30\n }\n }\n }\n}\n
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"es/rules/Azure.ACR.Quarantine/#configurar-con-bicep","title":"Configurar con Bicep","text":"Para implementar registros de contenedores que superen esta regla:
properties.quarantinePolicy.status
a enabled
.Por ejemplo:
Azure Bicep snippetresource acr 'Microsoft.ContainerRegistry/registries@2021-06-01-preview' = {\n name: registryName\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n quarantinePolicy: {\n status: 'enabled'\n }\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n status: 'enabled'\n days: 30\n }\n }\n }\n}\n
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"es/rules/Azure.ACR.Quarantine/#notas","title":"Notas","text":"La cuarentena de im\u00e1genes para Azure Container Registry se encuentra actualmente en versi\u00f3n preliminar.
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"es/rules/Azure.ACR.Quarantine/#enlaces","title":"Enlaces","text":"Optimizaci\u00f3n de costos \u00b7 Container Registry \u00b7 Rule \u00b7 Preview \u00b7 2020_12 \u00b7 Importante
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"es/rules/Azure.ACR.Retention/#sinopsis","title":"Sinopsis","text":"Use una directiva de retenci\u00f3n para limpiar los manifiestos sin etiquetar.
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"es/rules/Azure.ACR.Retention/#descripcion","title":"Descripci\u00f3n","text":"La directiva de retenci\u00f3n es una opci\u00f3n configurable de Premium Azure Container Registry (ACR). Cuando se configura una directiva de retenci\u00f3n, los manifiestos sin etiquetar en el registro se eliminan autom\u00e1ticamente. Un manifiesto no est\u00e1 etiquetado cuando se env\u00eda una imagen m\u00e1s reciente con la misma etiqueta. es decir, lo \u00faltimo.
La directiva de retenci\u00f3n (en d\u00edas) se puede establecer en 0-365. El valor predeterminado es 7 d\u00edas.
Para configurar una directiva de retenci\u00f3n, el registro del contenedor debe usar una SKU Premium.
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"es/rules/Azure.ACR.Retention/#recomendacion","title":"Recomendaci\u00f3n","text":"Considere habilitar una directiva de retenci\u00f3n para manifiestos sin etiquetar.
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"es/rules/Azure.ACR.Retention/#ejemplos","title":"Ejemplos","text":"","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"es/rules/Azure.ACR.Retention/#configurar-con-plantilla-de-arm","title":"Configurar con plantilla de ARM","text":"Para implementar registros de contenedores que superen esta regla:
properties.retentionPolicy.status
a enabled
.Por ejemplo:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2021-06-01-preview\",\n \"name\": \"[parameters('registryName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"quarantinePolicy\": {\n \"status\": \"enabled\"\n },\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"status\": \"enabled\",\n \"days\": 30\n }\n }\n }\n}\n
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"es/rules/Azure.ACR.Retention/#configurar-con-bicep","title":"Configurar con Bicep","text":"Para implementar registros de contenedores que superen esta regla:
properties.retentionPolicy.status
a enabled
.Por ejemplo:
Azure Bicep snippetresource acr 'Microsoft.ContainerRegistry/registries@2021-06-01-preview' = {\n name: registryName\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n quarantinePolicy: {\n status: 'enabled'\n }\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n status: 'enabled'\n days: 30\n }\n }\n }\n}\n
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"es/rules/Azure.ACR.Retention/#notas","title":"Notas","text":"Las directivas de retenci\u00f3n para Azure Container Registry est\u00e1n actualmente en versi\u00f3n preliminar.
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"es/rules/Azure.ACR.Retention/#enlaces","title":"Enlaces","text":"Optimizaci\u00f3n de costos \u00b7 Container Registry \u00b7 Rule \u00b7 2020_12 \u00b7 Importante
","tags":["Azure.ACR.Usage","AZR-000001"]},{"location":"es/rules/Azure.ACR.Usage/#sinopsis","title":"Sinopsis","text":"Elimine peri\u00f3dicamente las im\u00e1genes obsoletas e innecesarias para reducir el uso del almacenamiento.
","tags":["Azure.ACR.Usage","AZR-000001"]},{"location":"es/rules/Azure.ACR.Usage/#descripcion","title":"Descripci\u00f3n","text":"Cada SKU de ACR tiene una cantidad de almacenamiento incluido. Cuando se excede la cantidad de almacenamiento incluido, se acumulan costos de almacenamiento adicionales por GiB.
Es una buena pr\u00e1ctica limpiar regularmente las im\u00e1genes hu\u00e9rfanas. Estas im\u00e1genes son el resultado de enviar im\u00e1genes actualizadas con la misma etiqueta.
","tags":["Azure.ACR.Usage","AZR-000001"]},{"location":"es/rules/Azure.ACR.Usage/#recomendacion","title":"Recomendaci\u00f3n","text":"Considere eliminar las im\u00e1genes obsoletas e innecesarias para reducir el consumo de almacenamiento. Tambi\u00e9n considere actualizar a Premium SKU para registros b\u00e1sicos o est\u00e1ndar para aumentar el almacenamiento incluido.
","tags":["Azure.ACR.Usage","AZR-000001"]},{"location":"es/rules/Azure.ACR.Usage/#notas","title":"Notas","text":"Esta regla se aplica cuando se analizan los recursos implementados en Azure.
","tags":["Azure.ACR.Usage","AZR-000001"]},{"location":"es/rules/Azure.ACR.Usage/#enlaces","title":"Enlaces","text":"PSRule for Azure includes the following rules across five pillars of the Microsoft Azure Well-Architected Framework.
"},{"location":"es/rules/module/#cost-optimization","title":"Cost Optimization","text":""},{"location":"es/rules/module/#co03-cost-data-and-reporting","title":"CO:03 Cost data and reporting","text":"Name Synopsis Severity Level Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Error"},{"location":"es/rules/module/#co04-spending-guardrails","title":"CO:04 Spending guardrails","text":"Name Synopsis Severity Level Azure.DevBox.ProjectLimit Limit the number of Dev Boxes a single user can create for a project. Important Error"},{"location":"es/rules/module/#co05-rate-optimization","title":"CO:05 Rate optimization","text":"Name Synopsis Severity Level Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Error Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Error"},{"location":"es/rules/module/#co06-usage-and-billing-increments","title":"CO:06 Usage and billing increments","text":"Name Synopsis Severity Level Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. Critical Error Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Error"},{"location":"es/rules/module/#co07-component-costs","title":"CO:07 Component costs","text":"Name Synopsis Severity Level Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Error Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Error Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Error"},{"location":"es/rules/module/#co10-data-costs","title":"CO:10 Data costs","text":"Name Synopsis Severity Level Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Error"},{"location":"es/rules/module/#co13-personnel-time","title":"CO:13 Personnel time","text":"Name Synopsis Severity Level Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Error"},{"location":"es/rules/module/#co14-consolidation","title":"CO:14 Consolidation","text":"Name Synopsis Severity Level Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Error Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Error Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Error Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Error Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Error"},{"location":"es/rules/module/#operational-excellence","title":"Operational Excellence","text":""},{"location":"es/rules/module/#configuration","title":"Configuration","text":"Name Synopsis Severity Level Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Error Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Error Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Error"},{"location":"es/rules/module/#deployment","title":"Deployment","text":"Name Synopsis Severity Level Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Error Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Error Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Error Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Error Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Error Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Error Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Error Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Error Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Error"},{"location":"es/rules/module/#infrastructure-provisioning","title":"Infrastructure provisioning","text":"Name Synopsis Severity Level Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Error Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Error"},{"location":"es/rules/module/#instrumentation","title":"Instrumentation","text":"Name Synopsis Severity Level Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Warning"},{"location":"es/rules/module/#monitor","title":"Monitor","text":"Name Synopsis Severity Level Azure.VNET.PeerState VNET peering connections must be connected. Important Error"},{"location":"es/rules/module/#monitoring","title":"Monitoring","text":"Name Synopsis Severity Level Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Error Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Error Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Error Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Error Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Error Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Error Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Error"},{"location":"es/rules/module/#oe04-continuous-integration","title":"OE:04 Continuous integration","text":"Name Synopsis Severity Level Azure.ACR.Name Container registry names should meet naming requirements. Awareness Error Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Error Azure.APIM.Name API Management service names should meet naming requirements. Awareness Error Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Error Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Error Azure.Search.Name AI Search service names should meet naming requirements. Awareness Error Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Error Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Error Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Error Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Error"},{"location":"es/rules/module/#oe04-tools-and-processes","title":"OE:04 Tools and processes","text":"Name Synopsis Severity Level Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Warning"},{"location":"es/rules/module/#oe05-infrastructure-as-code","title":"OE:05 Infrastructure as code","text":"Name Synopsis Severity Level Azure.Template.TemplateFile Use ARM template files that are valid. Important Error Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Error"},{"location":"es/rules/module/#oe07-monitoring-system","title":"OE:07 Monitoring system","text":"Name Synopsis Severity Level Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Error Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Error"},{"location":"es/rules/module/#oe09-task-automation","title":"OE:09 Task automation","text":"Name Synopsis Severity Level Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Error"},{"location":"es/rules/module/#principles","title":"Principles","text":"Name Synopsis Severity Level Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Error"},{"location":"es/rules/module/#release-engineering","title":"Release engineering","text":"Name Synopsis Severity Level Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Error Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Error Azure.Template.LocationType Location parameters should use a string value. Important Error Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Error Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Error Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Error Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Error Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Error Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Error Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Warning Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Error Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Error"},{"location":"es/rules/module/#repeatable-infrastructure","title":"Repeatable infrastructure","text":"Name Synopsis Severity Level Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Error Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Error Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Error Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Error Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Important Error Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Error Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Error Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Error Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. Important Error Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Error Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Error Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Error Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Error Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Error Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Error Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Error Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Error Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Error Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Error Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Error Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Error Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Error Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Error Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Error Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Error Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Error Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Error Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Error Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Error Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Error Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Error Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Error Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Error Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Error Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Error Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Error Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. Important Error Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Error Azure.Route.Name Route table names should meet naming requirements. Awareness Error Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Error Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Error Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Error Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Error Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Error Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Error Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Error Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Error Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Error Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Error Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Error Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Error Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Error Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Information Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Information Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Error Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Error Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Error Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Important Error Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Error Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Error Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Error Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Error Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Error Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Error"},{"location":"es/rules/module/#tagging-and-resource-naming","title":"Tagging and resource naming","text":"Name Synopsis Severity Level Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Error"},{"location":"es/rules/module/#performance-efficiency","title":"Performance Efficiency","text":""},{"location":"es/rules/module/#application-capacity","title":"Application capacity","text":"Name Synopsis Severity Level Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Error Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Error Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Error"},{"location":"es/rules/module/#application-design","title":"Application design","text":"Name Synopsis Severity Level Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Error Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Error"},{"location":"es/rules/module/#application-scalability","title":"Application scalability","text":"Name Synopsis Severity Level Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Error Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Error"},{"location":"es/rules/module/#design-for-performance","title":"Design for performance","text":"Name Synopsis Severity Level Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Error"},{"location":"es/rules/module/#design-for-performance-efficiency","title":"Design for performance efficiency","text":"Name Synopsis Severity Level Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. Important Error"},{"location":"es/rules/module/#pe02-capacity-planning","title":"PE:02 Capacity planning","text":"Name Synopsis Severity Level Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Error"},{"location":"es/rules/module/#pe03-selecting-services","title":"PE:03 Selecting services","text":"Name Synopsis Severity Level Azure.Databricks.SKU Ensure Databricks workspaces are non-trial SKUs for production workloads. Critical Error"},{"location":"es/rules/module/#pe05-scaling-and-partitioning","title":"PE:05 Scaling and partitioning","text":"Name Synopsis Severity Level Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Error Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Error"},{"location":"es/rules/module/#pe08-data-performance","title":"PE:08 Data performance","text":"Name Synopsis Severity Level Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Error"},{"location":"es/rules/module/#performance","title":"Performance","text":"Name Synopsis Severity Level Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Error Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Error"},{"location":"es/rules/module/#performance-efficiency-checklist","title":"Performance efficiency checklist","text":"Name Synopsis Severity Level Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Warning Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Error"},{"location":"es/rules/module/#reliability","title":"Reliability","text":""},{"location":"es/rules/module/#application-design_1","title":"Application design","text":"Name Synopsis Severity Level Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Error"},{"location":"es/rules/module/#availability","title":"Availability","text":"Name Synopsis Severity Level Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Error Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Error"},{"location":"es/rules/module/#best-practices","title":"Best practices","text":"Name Synopsis Severity Level Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Error"},{"location":"es/rules/module/#data-management","title":"Data management","text":"Name Synopsis Severity Level Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Error Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important Error Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Error Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Error Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Error Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Error"},{"location":"es/rules/module/#design","title":"Design","text":"Name Synopsis Severity Level Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Error Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Error Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Error Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Error Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Error Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Error Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Error Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Error Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Error Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Error"},{"location":"es/rules/module/#health-modeling","title":"Health modeling","text":"Name Synopsis Severity Level Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Error Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Error Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Error"},{"location":"es/rules/module/#load-balancing-and-failover","title":"Load balancing and failover","text":"Name Synopsis Severity Level Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Error Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Error"},{"location":"es/rules/module/#re01-simplicity-and-efficiency","title":"RE:01 Simplicity and efficiency","text":"Name Synopsis Severity Level Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Error"},{"location":"es/rules/module/#re04-target-metrics","title":"RE:04 Target metrics","text":"Name Synopsis Severity Level Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Error Azure.AppService.WebProbe Configure and enable instance health probes. Important Error Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Error Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Error"},{"location":"es/rules/module/#re05-redundancy","title":"RE:05 Redundancy","text":"Name Synopsis Severity Level Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Error Azure.AKS.MinUserPoolNodes User node pools in an AKS cluster should have a minimum number of nodes for failover and updates. Important Error Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. Important Error Azure.LB.Probe Use a specific probe for web protocols. Important Error Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Warning Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Error Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Error Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Error"},{"location":"es/rules/module/#re05-regions-and-availability-zones","title":"RE:05 Regions and availability zones","text":"Name Synopsis Severity Level Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Error"},{"location":"es/rules/module/#re06-data-partitioning","title":"RE:06 Data partitioning","text":"Name Synopsis Severity Level Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Error Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Error"},{"location":"es/rules/module/#re07-self-preservation","title":"RE:07 Self-preservation","text":"Name Synopsis Severity Level Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Error Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Error"},{"location":"es/rules/module/#reliability-design-principles","title":"Reliability design principles","text":"Name Synopsis Severity Level Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Error"},{"location":"es/rules/module/#requirements","title":"Requirements","text":"Name Synopsis Severity Level Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Error Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Error Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Error Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Error Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Error Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Error Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Error Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Error Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important Error"},{"location":"es/rules/module/#resiliency-and-dependencies","title":"Resiliency and dependencies","text":"Name Synopsis Severity Level Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Error Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Error Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Error Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Error Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Error"},{"location":"es/rules/module/#resource-deployment","title":"Resource deployment","text":"Name Synopsis Severity Level Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Error"},{"location":"es/rules/module/#scalability","title":"Scalability","text":"Name Synopsis Severity Level Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Error"},{"location":"es/rules/module/#target-and-non-functional-requirements","title":"Target and non-functional requirements","text":"Name Synopsis Severity Level Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Error Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Error Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Error"},{"location":"es/rules/module/#security","title":"Security","text":""},{"location":"es/rules/module/#application-endpoints","title":"Application endpoints","text":"Name Synopsis Severity Level Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Error Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Error Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Error Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Error Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Error Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Error Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Error Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Error"},{"location":"es/rules/module/#authentication","title":"Authentication","text":"Name Synopsis Severity Level Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Error Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Error Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Error Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. Critical Error Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Error Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Error Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Error Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Error Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Error"},{"location":"es/rules/module/#authorization","title":"Authorization","text":"Name Synopsis Severity Level Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Error"},{"location":"es/rules/module/#azure-resources","title":"Azure resources","text":"Name Synopsis Severity Level Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Error Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Error Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Error Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Error"},{"location":"es/rules/module/#connectivity","title":"Connectivity","text":"Name Synopsis Severity Level Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). Critical Error Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. Critical Error Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Error Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Error Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Error"},{"location":"es/rules/module/#data-protection","title":"Data protection","text":"Name Synopsis Severity Level Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Error Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Error Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Error Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Error Azure.CDN.HTTP Enforce HTTPS for client connections. Important Error Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Error Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Error Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Error Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Error Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Error Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Error"},{"location":"es/rules/module/#design_1","title":"Design","text":"Name Synopsis Severity Level Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Error Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Error"},{"location":"es/rules/module/#encryption","title":"Encryption","text":"Name Synopsis Severity Level Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Error Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Error Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Error Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Error Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Error Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Error Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Error Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Error Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Error Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Error Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Error Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Error"},{"location":"es/rules/module/#identity-and-access-management","title":"Identity and access management","text":"Name Synopsis Severity Level Azure.ACR.AnonymousAccess Disable anonymous pull access. Important Error Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Error Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Error Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Error Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Error Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Error Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. Important Error Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Error Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Error Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Error Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Error Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Error Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Error Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Error Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Error Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Error Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Error Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Error Azure.VM.PublicKey Linux virtual machines should use public keys. Important Error Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Error"},{"location":"es/rules/module/#infrastructure-provisioning_1","title":"Infrastructure provisioning","text":"Name Synopsis Severity Level Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Error Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Error Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Error Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. Critical Error Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Error"},{"location":"es/rules/module/#key-and-secret-management","title":"Key and secret management","text":"Name Synopsis Severity Level Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Error Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Error Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Error"},{"location":"es/rules/module/#monitor_1","title":"Monitor","text":"Name Synopsis Severity Level Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Error Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Error Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Error"},{"location":"es/rules/module/#network-security-and-containment","title":"Network security and containment","text":"Name Synopsis Severity Level Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Error Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Error Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Error Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Error Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Error Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Error Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.AppGwWAF.RuleGroups Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Error Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Error Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Error Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Error Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Error Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Error Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Error Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Error Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error"},{"location":"es/rules/module/#network-segmentation","title":"Network segmentation","text":"Name Synopsis Severity Level Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Error Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Error"},{"location":"es/rules/module/#review-and-remediate","title":"Review and remediate","text":"Name Synopsis Severity Level Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Error"},{"location":"es/rules/module/#se01-security-baseline","title":"SE:01 Security baseline","text":"Name Synopsis Severity Level Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Error"},{"location":"es/rules/module/#se02-secured-development-lifecycle","title":"SE:02 Secured development lifecycle","text":"Name Synopsis Severity Level Azure.AppService.NETVersion Configure applications to use newer .NET versions. Important Error Azure.AppService.PHPVersion Configure applications to use newer PHP runtime versions. Important Error"},{"location":"es/rules/module/#se04-segmentation","title":"SE:04 Segmentation","text":"Name Synopsis Severity Level Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Error"},{"location":"es/rules/module/#se05-identity-and-access-management","title":"SE:05 Identity and access management","text":"Name Synopsis Severity Level Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Error Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Error Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Error Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Error Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.APIM.ProductApproval Configure products to require approval. Important Error Azure.APIM.ProductSubscription Configure products to require a subscription. Important Error Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Error Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Error Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Error Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Error Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Error Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Warning Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Error Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Error Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Error Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Error Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Error"},{"location":"es/rules/module/#se06-network-controls","title":"SE:06 Network controls","text":"Name Synopsis Severity Level Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Error Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Error Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Error Azure.Databricks.PublicAccess Azure Databricks workspaces should disable public network access. Critical Error Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. Critical Error Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Error Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Error Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Error"},{"location":"es/rules/module/#se07-encryption","title":"SE:07 Encryption","text":"Name Synopsis Severity Level Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Error Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Error Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Error Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Error Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Error Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Error Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Error Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Error Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Error Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Error Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Error Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Error Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Error"},{"location":"es/rules/module/#se08-hardening-resources","title":"SE:08 Hardening resources","text":"Name Synopsis Severity Level Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Error Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Error"},{"location":"es/rules/module/#se10-monitoring-and-threat-detection","title":"SE:10 Monitoring and threat detection","text":"Name Synopsis Severity Level Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. Critical Error Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Error Azure.Defender.Api Enable Microsoft Defender for APIs. Critical Error Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Error Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Error Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Error Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. Important Error Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Error Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Error Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Error Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Error"},{"location":"es/rules/module/#secrets","title":"Secrets","text":"Name Synopsis Severity Level Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Error Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Error"},{"location":"es/rules/module/#security-design-principles","title":"Security design principles","text":"Name Synopsis Severity Level Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Error Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Error"},{"location":"es/rules/module/#security-operations","title":"Security operations","text":"Name Synopsis Severity Level Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Important Error Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Error Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Error Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Error Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Error Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Error Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Error Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Error Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Error Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Error Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Error Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Error Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Error Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Error Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Error Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Error Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Error"},{"location":"es/rules/module/#virtual-machine","title":"Virtual Machine","text":"Name Synopsis Severity Level Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Error"},{"location":"es/rules/resource/","title":"Rules by resource type","text":"PSRule for Azure includes the following rules organized by resource type.
"},{"location":"es/rules/resource/#ai-search","title":"AI Search","text":"Name Synopsis Severity Level Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Error Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.Search.Name AI Search service names should meet naming requirements. Awareness Error Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Error Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Error"},{"location":"es/rules/resource/#all-resources","title":"All resources","text":"Name Synopsis Severity Level Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Error Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Error Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Error Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Error Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Error Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Error Azure.Template.LocationType Location parameters should use a string value. Important Error Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Error Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Error Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Error Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Error Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Error Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Error Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Error Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Error Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Error Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Error Azure.Template.TemplateFile Use ARM template files that are valid. Important Error Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Error Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Error Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Information Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Information Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Warning Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Error Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Error Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Error"},{"location":"es/rules/resource/#api-management","title":"API Management","text":"Name Synopsis Severity Level Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Warning Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Error Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Error Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Error Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Error Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. Critical Error Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Error Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Error Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Error Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Error Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Error Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Error Azure.APIM.Name API Management service names should meet naming requirements. Awareness Error Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Error Azure.APIM.ProductApproval Configure products to require approval. Important Error Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Warning Azure.APIM.ProductSubscription Configure products to require a subscription. Important Error Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Error Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Error Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Error"},{"location":"es/rules/resource/#app-configuration","title":"App Configuration","text":"Name Synopsis Severity Level Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Error Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Error Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. Important Error Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Error Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Error Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Error"},{"location":"es/rules/resource/#app-service","title":"App Service","text":"Name Synopsis Severity Level Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Error Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Error Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Error Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Error Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Error Azure.AppService.NETVersion Configure applications to use newer .NET versions. Important Error Azure.AppService.PHPVersion Configure applications to use newer PHP runtime versions. Important Error Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Error Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Error Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Error Azure.AppService.WebProbe Configure and enable instance health probes. Important Error Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Error Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Error"},{"location":"es/rules/resource/#app-service-environment","title":"App Service Environment","text":"Name Synopsis Severity Level Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Error"},{"location":"es/rules/resource/#application-gateway","title":"Application Gateway","text":"Name Synopsis Severity Level Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Error Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Error Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Error Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Error Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Error Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Error Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Error Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Error Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Error Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Error Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Error Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Error Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Error Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Error Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.AppGwWAF.RuleGroups Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Error"},{"location":"es/rules/resource/#application-insights","title":"Application Insights","text":"Name Synopsis Severity Level Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Error Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Error"},{"location":"es/rules/resource/#application-security-group","title":"Application Security Group","text":"Name Synopsis Severity Level Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Error"},{"location":"es/rules/resource/#arc","title":"Arc","text":"Name Synopsis Severity Level Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Important Error Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Important Error"},{"location":"es/rules/resource/#automation-account","title":"Automation Account","text":"Name Synopsis Severity Level Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Error Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Error Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Error Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Error Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Error"},{"location":"es/rules/resource/#azure-ai","title":"Azure AI","text":"Name Synopsis Severity Level Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Error Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Error Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Error"},{"location":"es/rules/resource/#azure-cache-for-redis","title":"Azure Cache for Redis","text":"Name Synopsis Severity Level Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Error Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Error Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Error Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Error Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Error Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Error Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Error Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Error Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Error"},{"location":"es/rules/resource/#azure-cache-for-redis-enterprise","title":"Azure Cache for Redis Enterprise","text":"Name Synopsis Severity Level Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Error Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Error"},{"location":"es/rules/resource/#azure-database-for-mariadb","title":"Azure Database for MariaDB","text":"Name Synopsis Severity Level Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Error Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Error Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Error Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Error Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Error Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Error Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Error Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Error"},{"location":"es/rules/resource/#azure-database-for-mysql","title":"Azure Database for MySQL","text":"Name Synopsis Severity Level Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Error Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Error Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Error Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Error Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Error Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Error Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Warning Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Error"},{"location":"es/rules/resource/#azure-database-for-postgresql","title":"Azure Database for PostgreSQL","text":"Name Synopsis Severity Level Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Error Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Error Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Error Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Error Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Error Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Error Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Error"},{"location":"es/rules/resource/#azure-kubernetes-service","title":"Azure Kubernetes Service","text":"Name Synopsis Severity Level Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Error Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Error Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Error Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Error Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Error Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Error Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Error Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Error Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Error Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Error Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Error Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Warning Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Error Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Error Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Error Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Error Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Error Azure.AKS.MinUserPoolNodes User node pools in an AKS cluster should have a minimum number of nodes for failover and updates. Important Error Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Error Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Error Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Error Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Error Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Error Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Error Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Error Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Error Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Error Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Error Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Error Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Error"},{"location":"es/rules/resource/#backup-vault","title":"Backup Vault","text":"Name Synopsis Severity Level Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Error"},{"location":"es/rules/resource/#bastion","title":"Bastion","text":"Name Synopsis Severity Level Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Error"},{"location":"es/rules/resource/#container-app","title":"Container App","text":"Name Synopsis Severity Level Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. Important Error Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. Important Error Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Error Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Error Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Error Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Error Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Error Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Error Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Error"},{"location":"es/rules/resource/#container-registry","title":"Container Registry","text":"Name Synopsis Severity Level Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Error Azure.ACR.AnonymousAccess Disable anonymous pull access. Important Error Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Error Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Error Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Error Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Error Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Error Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Error Azure.ACR.Name Container registry names should meet naming requirements. Awareness Error Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Error Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Error Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important Error Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Error"},{"location":"es/rules/resource/#content-delivery-network","title":"Content Delivery Network","text":"Name Synopsis Severity Level Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Error Azure.CDN.HTTP Enforce HTTPS for client connections. Important Error Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Error"},{"location":"es/rules/resource/#cosmos-db","title":"Cosmos DB","text":"Name Synopsis Severity Level Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Error Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Error Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Error"},{"location":"es/rules/resource/#data-explorer","title":"Data Explorer","text":"Name Synopsis Severity Level Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Error Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Error Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Error Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Error"},{"location":"es/rules/resource/#data-factory","title":"Data Factory","text":"Name Synopsis Severity Level Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Error"},{"location":"es/rules/resource/#databricks","title":"Databricks","text":"Name Synopsis Severity Level Azure.Databricks.PublicAccess Azure Databricks workspaces should disable public network access. Critical Error Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. Critical Error Azure.Databricks.SKU Ensure Databricks workspaces are non-trial SKUs for production workloads. Critical Error"},{"location":"es/rules/resource/#deployment","title":"Deployment","text":"Name Synopsis Severity Level Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Error Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Error Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Error Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Error Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. Critical Error Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Error"},{"location":"es/rules/resource/#dev-box","title":"Dev Box","text":"Name Synopsis Severity Level Azure.DevBox.ProjectLimit Limit the number of Dev Boxes a single user can create for a project. Important Error"},{"location":"es/rules/resource/#event-grid","title":"Event Grid","text":"Name Synopsis Severity Level Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Error Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Error Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Error"},{"location":"es/rules/resource/#event-hub","title":"Event Hub","text":"Name Synopsis Severity Level Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Error Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Error Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Error"},{"location":"es/rules/resource/#firewall","title":"Firewall","text":"Name Synopsis Severity Level Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Error Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Error Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Error Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Error"},{"location":"es/rules/resource/#front-door","title":"Front Door","text":"Name Synopsis Severity Level Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Error Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. Important Error Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Error Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Error Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Error Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Error Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Error Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Error Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Error Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Error Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Error Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Error Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Error Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Error Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Error Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error"},{"location":"es/rules/resource/#iot-hub","title":"IoT Hub","text":"Name Synopsis Severity Level Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Error"},{"location":"es/rules/resource/#key-vault","title":"Key Vault","text":"Name Synopsis Severity Level Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Error Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Error Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Error Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Error Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Error Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Error Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Error Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Warning Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Error Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Error"},{"location":"es/rules/resource/#load-balancer","title":"Load Balancer","text":"Name Synopsis Severity Level Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Error Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Error Azure.LB.Probe Use a specific probe for web protocols. Important Error Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Error"},{"location":"es/rules/resource/#logic-app","title":"Logic App","text":"Name Synopsis Severity Level Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Error"},{"location":"es/rules/resource/#machine-learning","title":"Machine Learning","text":"Name Synopsis Severity Level Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. Critical Error Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). Critical Error Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. Critical Error Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. Critical Error Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. Important Error"},{"location":"es/rules/resource/#microsoft-defender-for-cloud","title":"Microsoft Defender for Cloud","text":"Name Synopsis Severity Level Azure.Defender.Api Enable Microsoft Defender for APIs. Critical Error Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Error Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Error Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Error Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Error Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Error Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Error Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Error Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Error Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Error Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Error Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Error Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Error Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Error Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Error Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Error Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Error"},{"location":"es/rules/resource/#monitor","title":"Monitor","text":"Name Synopsis Severity Level Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Error"},{"location":"es/rules/resource/#network-interface","title":"Network Interface","text":"Name Synopsis Severity Level Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Error Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Error Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Error"},{"location":"es/rules/resource/#network-security-group","title":"Network Security Group","text":"Name Synopsis Severity Level Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Error Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Error Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Error Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Error Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Error Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Error"},{"location":"es/rules/resource/#policy","title":"Policy","text":"Name Synopsis Severity Level Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Error Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Error Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Error Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Error Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Error"},{"location":"es/rules/resource/#private-endpoint","title":"Private Endpoint","text":"Name Synopsis Severity Level Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Error"},{"location":"es/rules/resource/#public-ip-address","title":"Public IP address","text":"Name Synopsis Severity Level Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Error Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Error Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Error Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. Important Error Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Error Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Error"},{"location":"es/rules/resource/#recovery-services-vault","title":"Recovery Services Vault","text":"Name Synopsis Severity Level Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Error Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Error Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Error Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Error"},{"location":"es/rules/resource/#resource-group","title":"Resource Group","text":"Name Synopsis Severity Level Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Error"},{"location":"es/rules/resource/#route-table","title":"Route table","text":"Name Synopsis Severity Level Azure.Route.Name Route table names should meet naming requirements. Awareness Error"},{"location":"es/rules/resource/#service-bus","title":"Service Bus","text":"Name Synopsis Severity Level Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Error Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Error Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Error Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Error"},{"location":"es/rules/resource/#service-fabric","title":"Service Fabric","text":"Name Synopsis Severity Level Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Error"},{"location":"es/rules/resource/#signalr-service","title":"SignalR Service","text":"Name Synopsis Severity Level Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Error Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Error Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Error"},{"location":"es/rules/resource/#sql-database","title":"SQL Database","text":"Name Synopsis Severity Level Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Error Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Error Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Error Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Error Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Error Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Error Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Error Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Error Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Error Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Error"},{"location":"es/rules/resource/#sql-managed-instance","title":"SQL Managed Instance","text":"Name Synopsis Severity Level Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Error Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Error Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Error Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Error"},{"location":"es/rules/resource/#storage-account","title":"Storage Account","text":"Name Synopsis Severity Level Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Error Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Error Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Error Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Error Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Error Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Error Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Error Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Error Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Error Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Error Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Error Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Error Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Error"},{"location":"es/rules/resource/#subscription","title":"Subscription","text":"Name Synopsis Severity Level Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Error Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Error Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Error Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Error Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Error Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Error"},{"location":"es/rules/resource/#traffic-manager","title":"Traffic Manager","text":"Name Synopsis Severity Level Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Error Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Error"},{"location":"es/rules/resource/#user-assigned-managed-identity","title":"User Assigned Managed Identity","text":"Name Synopsis Severity Level Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Error"},{"location":"es/rules/resource/#virtual-machine","title":"Virtual Machine","text":"Name Synopsis Severity Level Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Error Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Error Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Error Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Error Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Error Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Error Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Error Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Error Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Error Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Error Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Error Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Error Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Error Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Important Error Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Error Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Error Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Error Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Error Azure.VM.PublicKey Linux virtual machines should use public keys. Important Error Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Error Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Error Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Error Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Error Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Error Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Error Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Error"},{"location":"es/rules/resource/#virtual-machine-scale-sets","title":"Virtual Machine Scale Sets","text":"Name Synopsis Severity Level Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Error Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Error Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Error Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Error Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Error Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Error"},{"location":"es/rules/resource/#virtual-network","title":"Virtual Network","text":"Name Synopsis Severity Level Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Error Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Error Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Error Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Error Azure.VNET.PeerState VNET peering connections must be connected. Important Error Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Error Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Error Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Error"},{"location":"es/rules/resource/#virtual-network-gateway","title":"Virtual Network Gateway","text":"Name Synopsis Severity Level Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Error Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Error Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Error Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Error Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Error Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Error Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Error"},{"location":"es/rules/resource/#virtual-wan","title":"Virtual WAN","text":"Name Synopsis Severity Level Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Error"},{"location":"es/rules/resource/#web-pubsub-service","title":"Web PubSub Service","text":"Name Synopsis Severity Level Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Error Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important Error"},{"location":"learn/learn-video-series/","title":"Learn PSRule for Azure series","text":""},{"location":"learn/learn-video-series/#introducing-psrule-for-azure","title":"Introducing PSRule for Azure","text":"An introduction to PSRule for Azure and how it relates to the Azure Well-Architected Framework. We also give an quick overview of baselines, handling exceptions, and reporting options.
"},{"location":"learn/learn-video-series/#getting-started-using-github","title":"Getting started using GitHub","text":"Getting started with PSRule for Azure using GitHub. We create a GitHub Actions workflow, enabled expansion, and iterate on Bicep code.
"},{"location":"learn/official/","title":"Official learning","text":""},{"location":"learn/official/#blog-posts","title":"Blog posts","text":""},{"location":"learn/official/#2022","title":"2022","text":"PSRule for Azure is licensed with an MIT License, which means it's free to use and modify. But please check out the details.
We open source at Microsoft.
In addition to our team, we hope you will think about contributing too. Here is how you can get started:
Please read our contributing guidelines and code of conduct to learn how to contribute.
"},{"location":"license-contributing/hackathons/","title":"Past hackathons","text":""},{"location":"license-contributing/hackathons/#microsoft-global-hackathon-2022","title":"Microsoft Global Hackathon 2022","text":"Thanks to the team who made the following contributions during the hackathon:
Azure.SQL.ThreatDetection
to Azure.SQL.DefenderCloud
.Azure.SecurityCenter.Contact
to Azure.DefenderCloud.Contact
.Azure.SecurityCenter.Provisioning
to Azure.DefenderCloud.Provisioning
.PSRule for Azure contains documentation ranging from conceptual, code examples, to recommendations. All of this documentation is written in markdown, open source, and available for you to contribute to.
Some of the documentation that you might like to improve includes:
docs/en/rules/
).docs/customization/
and docs/scenarios/
).docs/commands/
and docs/concepts/
).Abstract
This topic covers contributing documentation in PSRule for Azure.
"},{"location":"license-contributing/writing-documentation/#rule-help","title":"Rule help","text":"PSRule for Azure includes recommendations and expanded documentation with each rule. The recommendations are written in markdown and consumed by PSRule during analysis. This allows us to present easy to read web documentation without writing it separately for anaylsis.
As a result, PSRule does require rule documentation to be structured in a standard way. Also we have standards about the metadata we required to ensure there is consistency across documentation.
Some key points for writing rule help:
Please read our contributing guidelines and code of conduct to learn how to contribute.
"},{"location":"quickstarts/test-bicep-with-github/","title":"Test a Bicep deployment with GitHub Actions","text":"Bicep supports using a parameter file to deploy a module to Azure.
Abstract
Learn how to setup your GitHub repository to automatically test Bicep deployments referenced using .bicepparam
files.
This quickstart assumes you have already:
Installed an editor or IDE locally to edit your repository files. For more information, see Visual Studio Code.
If you don't already have a Bicep deployment in your repository, add a sample deployment.
deployments
.deployments
folder, create a new file called dev.bicepparam
.deployments
folder, create a new file called main.bicep
.using 'main.bicep'\n\nparam environment = 'dev'\nparam name = 'kv-example-001'\nparam defaultAction = 'Deny'\nparam workspaceId = '/subscriptions/00000000-0000-0000-0000-000000000000/resourcegroups/rg-test/providers/microsoft.operationalinsights/workspaces/workspace-001'\n
Example deployment module deployments/main.biceptargetScope = 'resourceGroup'\n\nparam name string\nparam location string = resourceGroup().location\n\n@allowed([\n 'Allow'\n 'Deny'\n])\nparam defaultAction string = 'Deny'\nparam environment string\nparam workspaceId string = ''\n\nresource vault 'Microsoft.KeyVault/vaults@2023-02-01' = {\n name: name\n location: location\n properties: {\n sku: {\n family: 'A'\n name: 'standard'\n }\n tenantId: tenant().tenantId\n enableSoftDelete: true\n enablePurgeProtection: true\n enableRbacAuthorization: true\n networkAcls: {\n defaultAction: defaultAction\n }\n }\n tags: {\n env: environment\n }\n}\n\n@sys.description('Configure auditing for Key Vault.')\nresource logs 'Microsoft.Insights/diagnosticSettings@2021-05-01-preview' = if (!empty(workspaceId)) {\n name: 'service'\n scope: vault\n properties: {\n workspaceId: workspaceId\n logs: [\n {\n category: 'AuditEvent'\n enabled: true\n }\n ]\n }\n}\n
You can also find a copy of these files in the quickstart sample repository.
"},{"location":"quickstarts/test-bicep-with-github/#create-an-options-file","title":"Create an options file","text":"PSRule can be configured using a default YAML options file called ps-rule.yaml
. Many of configuration options you are likely to want to use can be set using this file. Options in this file will automatically be detected by other PSRule commands and tools.
ps-rule.yaml
.#\n# PSRule configuration\n#\n\n# Please see the documentation for all configuration options:\n# https://aka.ms/ps-rule-azure/options\n\n# Require a minimum version of PSRule for Azure.\nrequires:\n PSRule.Rules.Azure: '>=1.34.0' # (1)\n\n# Automatically use rules for Azure.\ninclude:\n module:\n - PSRule.Rules.Azure # (2)\n\n# Ignore all files except .bicepparam files.\ninput:\n pathIgnore:\n - '**' # (3)\n - '!**/*.bicepparam' # (4)\n
.bicepparam
files.GitHub Actions are configured using a YAML file called a workflow. A workflow is made up of one or more jobs and steps.
.github/workflows
..github/workflows
folder, create a new file called analysis.yaml
.#\n# Analyze repository with PSRule\n#\n\n# For PSRule documentation see:\n# https://aka.ms/ps-rule\n# https://aka.ms/ps-rule-azure\n\n# For action details see:\n# https://aka.ms/ps-rule-action\n\nname: Analyze repository\n\n# Run analysis for main or PRs against main\non:\n push:\n branches:\n - main\n pull_request:\n branches:\n - main\n\njobs:\n analyze:\n name: Analyze repository\n runs-on: ubuntu-latest\n steps:\n\n - name: Checkout\n uses: actions/checkout@v4\n\n - name: Run PSRule analysis\n uses: microsoft/ps-rule@v2.9.0 # (1)\n with:\n modules: PSRule.Rules.Azure # (2)\n
main
branch in GitHub. For more information, see Creating a pull request.Navigate to the Actions tab in your repository to check the status of the workflow.
Enforcing custom tags
Azure Resource Manager (ARM) templates are a JSON-based file structure. ARM templates are typically not static, they include parameters, functions and conditions. Depending on the parameters provided to a template, resources may differ significantly.
Important resource properties that should be validated are often variables, parameters or deployed conditionally. Under these circumstances, to correctly validate resources in a template, parameters must be resolved.
The following scenario shows how PSRule can be used to validate Azure resource templates within an Azure Pipeline.
This scenario covers the following:
PSRule includes an extension that can be installed from the Visual Studio Marketplace. Once installed, Azure Pipelines tasks are available to install PSRule modules and run analysis.
"},{"location":"scenarios/azure-pipelines-ci/azure-pipelines-ci/#linking-parameter-files-to-templates","title":"Linking parameter files to templates","text":"ARM template parameter files allows parameters for a deployment to be saved and checked into source control. PSRule can automatically resolve ARM templates from parameter files by using a metadata link.
To link a parameter file to an ARM template add the metadata.template
property within a parameter file.
For example:
{\n \"$schema\": \"https://schema.management.azure.com/schemas/2015-01-01/deploymentParameters.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"metadata\": {\n \"template\": \"./azuredeploy.json\"\n },\n \"parameters\": {\n \"vnetName\": {\n \"value\": \"vnet-001\"\n },\n \"addressPrefix\": {\n \"value\": [\n \"10.1.0.0/24\"\n ]\n }\n }\n}\n
In the example parameter file azuredeploy.parameters.json
is linked to the template azuredeploy.json
. The prefix of ./
indicates that the template file is in a relative path to the parameter file. If ./
is not included, PSRule will look for the template relative to the working directory.
For example:
{\n \"$schema\": \"https://schema.management.azure.com/schemas/2015-01-01/deploymentParameters.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"metadata\": {\n \"template\": \"templates/vnet-hub/v1/template.json\"\n },\n \"parameters\": {\n \"vnetName\": {\n \"value\": \"vnet-001\"\n },\n \"addressPrefix\": {\n \"value\": [\n \"10.1.0.0/24\"\n ]\n }\n }\n}\n
"},{"location":"scenarios/azure-pipelines-ci/azure-pipelines-ci/#creating-a-yaml-pipeline","title":"Creating a YAML pipeline","text":"Azure Pipelines supports defining pipelines in YAML. PSRule uses a number of configurable task steps to install modules, export data and perform analysis.
"},{"location":"scenarios/azure-pipelines-ci/azure-pipelines-ci/#installing-azure-rules","title":"Installing Azure rules","text":"To install the module containing Azure rules use the ps-rule-install
YAML task.
# Install PSRule.Rules.Azure from the PowerShell Gallery.\n- task: ps-rule-install@2\n inputs:\n module: PSRule.Rules.Azure # Install PSRule.Rules.Azure from the PowerShell Gallery.\n
"},{"location":"scenarios/azure-pipelines-ci/azure-pipelines-ci/#exporting-resource-data-for-analysis","title":"Exporting resource data for analysis","text":"PSRule provides a pre-built cmdlets for finding template files within a path and exporting resource data.
Get-AzRuleTemplateLink
finds linked templates from parameter files. By default, parameter files with the *.parameters.json
extension are discovered. Files are found recursively from the current working path.Export-AzRuleTemplateData
exports resource data from template files.To generate data for analysis use a PowerShell YAML task to export resource data from linked templates.
# Export resource data from parameter files within the current working directory.\n- powershell: Get-AzRuleTemplateLink | Export-AzRuleTemplateData -OutputPath out/templates/;\n displayName: 'Export template data'\n
If parameter files are located in a specific sub-directory the path can be updated as follows.
# Export resource data from parameter files in the deployments/ sub-directory.\n- powershell: Get-AzRuleTemplateLink ./deployments/ | Export-AzRuleTemplateData -OutputPath out/templates/;\n displayName: 'Export template data'\n
If parameter files do not use the file extension .parameters.json
input path can be set.
# Export resource data from parameter files ending in *.json instead of default *.parameters.json.\n- powershell: Get-AzRuleTemplateLink -InputPath *.json | Export-AzRuleTemplateData -OutputPath out/templates/;\n displayName: 'Export template data'\n
In both cases, resource data for analysis is exported to out/templates/
.
To validate exported resources use the ps-rule-assert
YAML task. The following task uses previously exported resource data for analysis.
# Run analysis from JSON files using the `PSRule.Rules.Azure` module and custom rules from `.ps-rule/`.\n- task: ps-rule-assert@2\n inputs:\n inputType: inputPath\n inputPath: 'out/templates/*.json' # Read exported resource data from 'out/templates/'.\n modules: 'PSRule.Rules.Azure' # Analyze objects using the rules within the PSRule.Rules.Azure PowerShell module.\n # Optionally, also analyze objects using custom rules from '.ps-rule/'.\n source: '.ps-rule/'\n # Optionally, save results to an NUnit report.\n outputFormat: NUnit3\n outputPath: reports/ps-rule-resources.xml\n
In the example:
out/templates/
..ps-rule/
these are also evaluated.NUnit is a popular unit test framework for .NET. PSRule supports publishing validation results in the NUnit format. With Azure DevOps, an NUnit report can be published using Publish Test Results task.
An example YAML snippet is included below:
# Publish NUnit report as test results\n- task: PublishTestResults@2\n displayName: 'Publish PSRule results'\n inputs:\n testRunTitle: 'PSRule' # The title to use for the test run.\n testRunner: NUnit # Import report using the NUnit format.\n testResultsFiles: 'reports/ps-rule-results.xml' # The previously saved NUnit report.\n condition: succeededOrFailed() # Run this task if previous steps succeeded of failed.\n
"},{"location":"scenarios/azure-pipelines-ci/azure-pipelines-ci/#complete-example","title":"Complete example","text":"Putting each of these steps together.
"},{"location":"scenarios/azure-pipelines-ci/azure-pipelines-ci/#azure-devops-pipeline","title":"Azure DevOps Pipeline","text":"#\n# PSRule with Azure Pipelines\n#\n\ntrigger:\n- main\n\npool:\n vmImage: 'ubuntu-latest'\n\nsteps:\n\n# Install PSRule.Rules.Azure from the PowerShell Gallery\n- task: ps-rule-install@2\n inputs:\n module: PSRule.Rules.Azure # Install PSRule.Rules.Azure from the PowerShell Gallery.\n\n# Export resource data from parameter files within the current working directory.\n- powershell: Get-AzRuleTemplateLink | Export-AzRuleTemplateData -OutputPath out/templates/;\n displayName: 'Export template data'\n\n# Run analysis from JSON files using the `PSRule.Rules.Azure` module and custom rules from `.ps-rule/`.\n- task: ps-rule-assert@2\n inputs:\n inputType: inputPath\n inputPath: 'out/templates/*.json' # Read exported resource data from 'out/templates/'.\n modules: 'PSRule.Rules.Azure' # Analyze objects using the rules within the PSRule.Rules.Azure PowerShell module.\n # Optionally, also analyze objects using custom rules from '.ps-rule/'.\n source: '.ps-rule/'\n # Optionally, save results to an NUnit report.\n outputFormat: NUnit3\n outputPath: reports/ps-rule-resources.xml\n\n# Publish NUnit report as test results\n- task: PublishTestResults@2\n displayName: 'Publish PSRule results'\n inputs:\n testRunTitle: 'PSRule' # The title to use for the test run.\n testRunner: NUnit # Import report using the NUnit format.\n testResultsFiles: 'reports/ps-rule-*.xml' # Use previously saved NUnit reports.\n mergeTestResults: true # Merge multiple reports.\n condition: succeededOrFailed() # Run this task if previous steps succeeded of failed.\n
"},{"location":"scenarios/azure-pipelines-ci/azure-pipelines-ci/#more-information","title":"More information","text":"Azure Resource Manager (ARM) templates are a JSON-based file structure. ARM templates are typically not static, they include parameters, functions and conditions. Depending on the parameters provided to a template, resources may differ significantly.
Important resource properties that should be validated are often variables, parameters or deployed conditionally. Under these circumstances, to correctly validate resources in a template, parameters must be resolved.
The following scenario shows how to validate Azure resources from templates using a generic pipeline. The examples provided can be integrated into a continuous integration (CI) pipeline able to run PowerShell.
For integrating into Azure DevOps see Validate Azure resources from templates with Azure Pipelines.
This scenario covers the following:
Typically, PSRule is not pre-installed on CI worker nodes and must be installed within the pipeline. PSRule PowerShell modules need to be installed prior to calling PSRule cmdlets.
If your CI pipeline runs on a persistent virtual machine that you control, consider pre-installing PSRule. The following examples focus on installing PSRule dynamically during execution of the pipeline. Which is suitable for cloud-based CI worker nodes.
To install PSRule within a CI pipeline, execute the Install-Module
PowerShell cmdlet.
Depending on your environment, the CI worker process may not have administrative permissions. To install modules into the current context running the CI pipeline use -Scope CurrentUser
. The PowerShell Gallery is not a trusted source by default. Use the -Force
switch to suppress a prompt to install modules from PowerShell Gallery.
For example:
$Null = Install-Module -Name PSRule.Rules.Azure -Scope CurrentUser -Force;\n
Installing PSRule.Rules.Azure
also installs the base PSRule
module and associated Azure dependencies. The PSRule.Rules.Azure
module includes cmdlets and pre-built rules for validating Azure resources. Using the pre-built rules is completely optional.
In some cases, installing NuGet and PowerShellGet may be required to connect to the PowerShell Gallery. The NuGet package provider can be installed using the Install-PackageProvider
PowerShell cmdlet.
$Null = Install-PackageProvider -Name NuGet -Scope CurrentUser -Force;\n
The example below includes both steps together with checks:
if ($Null -eq (Get-PackageProvider -Name NuGet -ErrorAction SilentlyContinue)) {\n $Null = Install-PackageProvider -Name NuGet -Scope CurrentUser -Force;\n}\n\nif ($Null -eq (Get-InstalledModule -Name PowerShellGet -MinimumVersion 2.2.1 -ErrorAction Ignore)) {\n Install-Module PowerShellGet -MinimumVersion 2.2.1 -Scope CurrentUser -Force -AllowClobber;\n}\n\nif ($Null -eq (Get-InstalledModule -Name PSRule.Rules.Azure -MinimumVersion '0.12.1' -ErrorAction SilentlyContinue)) {\n $Null = Install-Module -Name PSRule.Rules.Azure -Scope CurrentUser -MinimumVersion '0.12.1' -Force;\n}\n
Add -AllowPrerelease
to install pre-release versions. See the change log for the latest version.
In PSRule, the Export-AzRuleTemplateData
cmdlet resolves a template and returns a resultant set of resources. The resultant set of resources can then be validated.
No connectivity to Azure is required by default when calling Export-AzRuleTemplateData
.
To run Export-AzRuleTemplateData
two key parameters are required:
-TemplateFile
- An absolute or relative path to the template JSON file.-ParameterFile
- An absolute or relative path to one or more parameter JSON files.The -ParameterFile
parameter is optional when all parameters defined in the template have defaultValue
set.
Optionally the following parameters can be used:
-Name
- The name of the deployment. If not specified a default name of export-<xxxxxxxx>
will be used.-OutputPath
- An absolute or relative path where the resultant resources will be written to JSON. If not specified the current working path be used.-ResourceGroup
- The name of a resource group where the deployment is intended to be run. If not specified placeholder values will be used.-Subscription
- The name or subscription Id of a subscription where the deployment is intended to be run. If not specified placeholder values will be used.See cmdlet help for a full list of parameters.
If -OutputPath
is a directory or is not set, the output file will be automatically named resources-<name>.json
.
For example:
Export-AzRuleTemplateData -TemplateFile .\\template.json -ParameterFile .\\parameters.json;\n
Multiple parameter files that map to the same template can be supplied in a single cmdlet call. Additional templates can be exported by calling Export-AzRuleTemplateData
multiple times.
A number of functions that can be used within Azure templates retrieve information from Azure. Some examples include reference
, subscription
, resourceGroup
, list*
.
The default for Export-AzRuleTemplateData
is to operate without requiring authenticated connectivity to Azure. As a result, functions that retrieve information from Azure use placeholders such as {{Subscription.SubscriptionId}}
.
To provide a real value for subscription
and resourceGroup
use the -Subscription
and -ResourceGroup
parameters. When using -Subscription
and -ResourceGroup
the subscription and resource group must already exist. Additionally the context running the cmdlet must have at least read access (i.e. Reader
).
It is currently not possible to provide a real value for reference
and list*
, only placeholders will be used.
Key Vault references in parameter files use placeholders instead of the real value to prevent accidental exposure of secrets.
"},{"location":"scenarios/azure-template-ci/azure-template-ci/#validating-exported-resources","title":"Validating exported resources","text":"To validate exported resources use Invoke-PSRule
, Assert-PSRule
or Test-PSRuleTarget
. In a CI pipeline, Assert-PSRule
is recommended. Assert-PSRule
outputs preformatted results ideal for use within a CI pipeline.
Use Assert-PSRule
with the resolved resource output as an input using -InputPath
.
In the following example, resources from .\\resources.json
are validated against pre-built rules:
Assert-PSRule -InputPath .\\resources-export-*.json -Module PSRule.Rules.Azure;\n
Example output:
-> vnet-001 : Microsoft.Network/virtualNetworks\n\n [PASS] Azure.Resource.UseTags\n [PASS] Azure.VirtualNetwork.UseNSGs\n [PASS] Azure.VirtualNetwork.SingleDNS\n [PASS] Azure.VirtualNetwork.LocalDNS\n\n -> vnet-001/subnet2 : Microsoft.Network/virtualNetworks/subnets\n\n [FAIL] Azure.Resource.UseTags\n
To process multiple input files a wildcard *
can be used.
Assert-PSRule -InputPath .\\out\\*.json -Module PSRule.Rules.Azure;\n
"},{"location":"scenarios/azure-template-ci/azure-template-ci/#formatting-output","title":"Formatting output","text":"When executing a CI pipeline, feedback on any validation failures is important. The Assert-PSRule
cmdlet provides easy to read formatted output instead of PowerShell objects.
Additionally, Assert-PSRule
supports styling formatted output for Azure Pipelines and GitHub Actions. Use the -Style AzurePipelines
or -Style GitHubActions
parameter to style output.
For example:
Assert-PSRule -InputPath .\\out\\*.json -Style AzurePipelines -Module PSRule.Rules.Azure;\n
"},{"location":"scenarios/azure-template-ci/azure-template-ci/#failing-the-pipeline","title":"Failing the pipeline","text":"When using PSRule within a CI pipeline, a failed rule should stop the pipeline. When using Assert-PSRule
if any rules fail, an error will be generated.
Assert-PSRule : One or more rules reported failure.\nAt line:1 char:1\n+ Assert-PSRule -Module PSRule.Rules.Azure -InputPath .\\out\\tests\\Resou ...\n+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n+ CategoryInfo : InvalidData: (:) [Assert-PSRule], FailPipelineException\n+ FullyQualifiedErrorId : PSRule.Fail,Assert-PSRule\n
A single PowerShell error is typically enough to stop a CI pipeline. If you are using a different configuration additionally -ErrorAction Stop
can be used.
For example:
Assert-PSRule -Module PSRule.Rules.Azure -InputPath .\\out\\*.json -ErrorAction Stop;\n
"},{"location":"scenarios/azure-template-ci/azure-template-ci/#generating-nunit-output","title":"Generating NUnit output","text":"NUnit is a popular unit test framework for .NET. NUnit generates a test report format that is widely interpreted by CI systems. While PSRule does not use NUnit directly, it support outputting validation results in the NUnit3 format. Using a common format allows integration with any system that supports the NUnit3 for publishing test results.
To generate an NUnit report:
-OutputFormat NUnit3
parameter.-OutputPath
parameter to specify the path of the report file to write.Assert-PSRule -OutputFormat NUnit3 -OutputPath .\\reports\\rule-report.xml -Module PSRule.Rules.Azure -InputPath .\\out\\*.json;\n
The output path will be created if it does not exist.
"},{"location":"scenarios/azure-template-ci/azure-template-ci/#complete-example","title":"Complete example","text":"Putting each of these steps together.
"},{"location":"scenarios/azure-template-ci/azure-template-ci/#install-dependencies","title":"Install dependencies","text":"# Install dependencies for connecting to PowerShell Gallery\nif ($Null -eq (Get-PackageProvider -Name NuGet -ErrorAction Ignore)) {\n Install-PackageProvider -Name NuGet -Force -Scope CurrentUser;\n}\n\nif ($Null -eq (Get-InstalledModule -Name PowerShellGet -MinimumVersion 2.2.1 -ErrorAction Ignore)) {\n Install-Module PowerShellGet -MinimumVersion 2.2.1 -Scope CurrentUser -Force -AllowClobber;\n}\n
"},{"location":"scenarios/azure-template-ci/azure-template-ci/#validate-templates","title":"Validate templates","text":"# Install PSRule.Rules.Azure module\nif ($Null -eq (Get-InstalledModule -Name PSRule.Rules.Azure -MinimumVersion '0.12.1' -ErrorAction SilentlyContinue)) {\n $Null = Install-Module -Name PSRule.Rules.Azure -Scope CurrentUser -MinimumVersion '0.12.1' -Force;\n}\n\n# Resolve resources\nExport-AzRuleTemplateData -TemplateFile .\\template.json -ParameterFile .\\parameters.json -OutputPath out/;\n\n# Validate resources\n$assertParams = @{\n InputPath = 'out/*.json'\n Module = 'PSRule.Rules.Azure'\n Style = 'AzurePipelines'\n OutputFormat = 'NUnit3'\n OutputPath = 'reports/rule-report.xml'\n}\nAssert-PSRule @assertParams;\n
"},{"location":"scenarios/azure-template-ci/azure-template-ci/#additional-options","title":"Additional options","text":""},{"location":"scenarios/azure-template-ci/azure-template-ci/#using-invoke-build","title":"Using Invoke-Build","text":"Invoke-Build
is a build automation cmdlet that can be installed from the PowerShell Gallery by installing the InvokeBuild module. Within Invoke-Build, each build process is broken into tasks.
The following example shows an example of using PSRule.Rules.Azure with InvokeBuild tasks.
# Synopsis: Install PSRule modules\ntask InstallPSRule {\n if ($Null -eq (Get-InstalledModule -Name PSRule.Rules.Azure -MinimumVersion '0.12.1' -ErrorAction SilentlyContinue)) {\n $Null = Install-Module -Name PSRule.Rules.Azure -Scope CurrentUser -MinimumVersion '0.12.1' -Force;\n }\n}\n\n# Synopsis: Run validation\ntask ValidateTemplate InstallPSRule, {\n # Resolve resources\n Export-AzRuleTemplateData -TemplateFile .\\template.json -ParameterFile .\\parameters.json -OutputPath out/;\n\n # Validate resources\n $assertParams = @{\n InputPath = 'out/*.json'\n Module = 'PSRule.Rules.Azure'\n Style = 'AzurePipelines'\n OutputFormat = 'NUnit3'\n OutputPath = 'reports/rule-report.xml'\n }\n Assert-PSRule @assertParams;\n}\n\n# Synopsis: Run all build tasks\ntask Build ValidateTemplate\n
Invoke-Build Build;\n
"},{"location":"scenarios/azure-template-ci/azure-template-ci/#calling-from-pester","title":"Calling from Pester","text":"Pester is a unit test framework for PowerShell that can be installed from the PowerShell Gallery.
Typically, Pester unit tests are built for a particular pipeline. PSRule can complement Pester unit tests by providing dynamic and sharable rules that are easy to reuse. By using -If
or -Type
pre-conditions, rules can dynamically provide validation for a range of use cases.
When calling PSRule from Pester use Invoke-PSRule
instead of Assert-PSRule
. Invoke-PSRule
returns validation result objects that can be tested by Pester Should
conditions.
Additionally, the Logging.RuleFail
option can be included to generate an error message for each failing rule.
For example:
Describe 'Azure' {\n Context 'Resource templates' {\n It 'Use content rules' {\n Export-AzRuleTemplateData -TemplateFile .\\template.json -ParameterFile .\\parameters.json -OutputPath .\\out\\resources.json;\n\n # Validate resources\n $invokeParams = @{\n InputPath = 'out/*.json'\n Module = 'PSRule.Rules.Azure'\n OutputFormat = 'NUnit3'\n OutputPath = 'reports/rule-report.xml'\n Option = (New-PSRuleOption -LoggingRuleFail Error)\n }\n Invoke-PSRule @invokeParams -Outcome Fail,Error | Should -BeNullOrEmpty;\n }\n }\n}\n
"},{"location":"scenarios/azure-template-ci/azure-template-ci/#more-information","title":"More information","text":"PSRule for Azure can automatically resolve Azure resource context at runtime from infrastructure code. This feature can be enabled by using the following configuration options.
"},{"location":"setup/configuring-expansion/#configuration","title":"Configuration","text":"Tip
Each of these configuration options are set within the ps-rule.yaml
file. To learn how to set configuration options see Configuring options.
v1.4.1
This configuration option determines if Azure template parameter files will automatically be expanded. By default, parameter files will not be automatically expanded. When enabled, PSRule will discover and expand JSON parameter files for Azure templates or Bicep modules.
Parameter files are expanded when PSRule cmdlets with the -Format File
parameter are used.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_PARAMETER_FILE_EXPANSION: bool\n
Default:
ps-rule.yaml# YAML: The default AZURE_PARAMETER_FILE_EXPANSION configuration option\nconfiguration:\n AZURE_PARAMETER_FILE_EXPANSION: false\n
Example:
ps-rule.yaml# YAML: Set the AZURE_PARAMETER_FILE_EXPANSION configuration option to enable expansion\nconfiguration:\n AZURE_PARAMETER_FILE_EXPANSION: true\n
"},{"location":"setup/configuring-expansion/#bicep-source-expansion","title":"Bicep source expansion","text":"v1.11.0
This configuration option determines if Azure Bicep source files will automatically be expanded. By default, Bicep files will not be automatically expanded.
Bicep files are expanded when PSRule cmdlets with the -Format File
parameter are used.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_BICEP_FILE_EXPANSION: bool\n
Default:
ps-rule.yaml# YAML: The default AZURE_BICEP_FILE_EXPANSION configuration option\nconfiguration:\n AZURE_BICEP_FILE_EXPANSION: false\n
Example:
ps-rule.yaml# YAML: Set the AZURE_BICEP_FILE_EXPANSION configuration option to enable expansion\nconfiguration:\n AZURE_BICEP_FILE_EXPANSION: true\n
"},{"location":"setup/configuring-expansion/#bicep-parameter-expansion","title":"Bicep parameter expansion","text":"v1.34.0
This configuration option determines if Azure Bicep parameter files (.bicepparam
) are expanded. By default, Bicep parameter files will be automatically expanded.
Bicep files are expanded when PSRule cmdlets with the -Format File
parameter are used.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_BICEP_PARAMS_FILE_EXPANSION: bool\n
Default:
ps-rule.yaml# YAML: The default AZURE_BICEP_PARAMS_FILE_EXPANSION configuration option\nconfiguration:\n AZURE_BICEP_PARAMS_FILE_EXPANSION: true\n
Example:
ps-rule.yaml# YAML: Set the AZURE_BICEP_PARAMS_FILE_EXPANSION configuration option to enable expansion\nconfiguration:\n AZURE_BICEP_PARAMS_FILE_EXPANSION: false\n
"},{"location":"setup/configuring-expansion/#bicep-compilation-timeout","title":"Bicep compilation timeout","text":"v1.13.3
This configuration option determines the maximum time to spend building a single Bicep source file. The timeout is configured in seconds.
When a timeout occurs, PSRule for Azure stops the build and returns an error. Any resources contained within Bicep source files that exceeded the timeout are not analyzed.
The default timeout is 5 seconds, however the timeout can be set to an integer between 1
and 120
.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_BICEP_FILE_EXPANSION_TIMEOUT: int\n
Default:
ps-rule.yaml# YAML: The default AZURE_BICEP_FILE_EXPANSION_TIMEOUT configuration option\nconfiguration:\n AZURE_BICEP_FILE_EXPANSION_TIMEOUT: 5\n
Example:
ps-rule.yaml# YAML: Set the AZURE_BICEP_FILE_EXPANSION_TIMEOUT configuration option to enable expansion\nconfiguration:\n AZURE_BICEP_FILE_EXPANSION_TIMEOUT: 15\n
"},{"location":"setup/configuring-expansion/#require-template-metadata-link","title":"Require template metadata link","text":"v1.7.0
This configuration option determines if Azure template parameter files require a metadata link. When configured to true
, the Azure.Template.MetadataLink
rule is enabled. Any Azure template parameter files that do not include a metadata link will report a fail for this rule.
The rule Azure.Template.MetadataLink
is not enabled by default. Additionally, when enabled this rule can still be excluded or suppressed like all other rules.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_PARAMETER_FILE_METADATA_LINK: bool\n
Default:
ps-rule.yaml# YAML: The default AZURE_PARAMETER_FILE_METADATA_LINK configuration option\nconfiguration:\n AZURE_PARAMETER_FILE_METADATA_LINK: false\n
Example:
ps-rule.yaml# YAML: Set the AZURE_PARAMETER_FILE_METADATA_LINK configuration option to enable expansion\nconfiguration:\n AZURE_PARAMETER_FILE_METADATA_LINK: true\n
"},{"location":"setup/configuring-expansion/#deployment-properties","title":"Deployment properties","text":"v1.17.0
This configuration option sets the deployment object use by the deployment()
function. Configure this option to change the details of the deployment when exporting templates for analysis. Provided properties will override the default. Any properties that are not provided with use the defaults as specified below.
This configuration option applies to the parent deployment. Nested deployments will use any properties configured within code. Additionally, this configuration option will be ignore when -Name
is used with Export-AzRuleTemplateData
.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_DEPLOYMENT:\n name: string\n
Default:
ps-rule.yaml# YAML: The default AZURE_DEPLOYMENT configuration option\nconfiguration:\n AZURE_DEPLOYMENT:\n name: 'ps-rule-test-deployment'\n
Example:
ps-rule.yaml# YAML: Override the name of the deployment object.\nconfiguration:\n AZURE_DEPLOYMENT:\n name: 'deploy-web-application'\n
"},{"location":"setup/configuring-expansion/#deployment-resource-group","title":"Deployment resource group","text":"v1.1.0
This configuration option sets the resource group object used by the resourceGroup()
function. Configure this option to change the resource group object when using exporting templates for analysis. Provided properties will override the default. Any properties that are not provided with use the defaults as specified below.
This configuration option will be ignored when -ResourceGroup
is used with Export-AzRuleTemplateData
.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_RESOURCE_GROUP:\n name: string\n location: string\n tags: object\n properties:\n provisioningState: string\n
Default:
ps-rule.yaml# YAML: The default AZURE_RESOURCE_GROUP configuration option\nconfiguration:\n AZURE_RESOURCE_GROUP:\n name: 'ps-rule-test-rg'\n location: 'eastus'\n tags: { }\n properties:\n provisioningState: 'Succeeded'\n
Example:
ps-rule.yaml# YAML: Override the location of the resource group object.\nconfiguration:\n AZURE_RESOURCE_GROUP:\n location: 'australiasoutheast'\n
"},{"location":"setup/configuring-expansion/#deployment-subscription","title":"Deployment subscription","text":"v1.1.0
This configuration option sets the subscription object used by the subscription()
function. Configure this option to change the subscription object when using exporting templates for analysis. Provided properties will override the default. Any properties that are not provided with use the defaults as specified below.
This configuration option will be ignored when -Subscription
is used with Export-AzRuleTemplateData
.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_SUBSCRIPTION:\n subscriptionId: string\n displayName: string\n state: string\n
Default:
ps-rule.yaml# YAML: The default AZURE_SUBSCRIPTION configuration option\nconfiguration:\n AZURE_SUBSCRIPTION:\n subscriptionId: 'ffffffff-ffff-ffff-ffff-ffffffffffff'\n displayName: 'PSRule Test Subscription'\n state: 'NotDefined'\n
Example:
ps-rule.yaml# YAML: Override the display name of the subscription object\nconfiguration:\n AZURE_SUBSCRIPTION:\n displayName: 'My test subscription'\n
"},{"location":"setup/configuring-expansion/#deployment-tenant","title":"Deployment tenant","text":"v1.11.0
This configuration option sets the tenant object used by the tenant()
function. Configure this option to change the tenant object when using exporting templates for analysis. Provided properties will override the default. Any properties that are not provided with use the defaults as specified below.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_TENANT:\n countryCode: string\n tenantId: string\n displayName: string\n
Default:
ps-rule.yaml# YAML: The default AZURE_TENANT configuration option\nconfiguration:\n AZURE_TENANT:\n countryCode: 'US'\n tenantId: 'ffffffff-ffff-ffff-ffff-ffffffffffff'\n displayName: 'PSRule'\n
Example:
ps-rule.yaml# YAML: Override the display name of the tenant object\nconfiguration:\n AZURE_TENANT:\n displayName: 'Contoso'\n
"},{"location":"setup/configuring-expansion/#deployment-management-group","title":"Deployment management group","text":"v1.11.0
This configuration option sets the management group object used by the managementGroup()
function. Configure this option to change the management group object when using exporting templates for analysis. Provided properties will override the default. Any properties that are not provided with use the defaults as specified below.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_MANAGEMENT_GROUP:\n name: string\n properties:\n displayName: string\n
Default:
ps-rule.yaml# YAML: The default AZURE_MANAGEMENT_GROUP configuration option\nconfiguration:\n AZURE_MANAGEMENT_GROUP:\n name: 'psrule-test'\n properties:\n displyName: 'PSRule Test Management Group'\n
Example:
ps-rule.yaml# YAML: Override the display name of the management group object\nconfiguration:\n AZURE_MANAGEMENT_GROUP:\n properties:\n displayName: 'My test management group'\n
"},{"location":"setup/configuring-expansion/#required-parameter-defaults","title":"Required parameter defaults","text":"v1.13.0
This configuration option allows a fallback value to be configured for required parameters. When a parameter value is not provided and a default is not set, the fallback value will be used.
Configure this option when you are providing a set of common parameters dynamically during a pipeline. In this scenario, it may not make sense to add the parameters to a parameter file or Bicep deployment.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_PARAMETER_DEFAULTS:\n <parameter>: <value>\n
Default:
ps-rule.yaml# YAML: The default AZURE_PARAMETER_DEFAULTS configuration option\nconfiguration:\n AZURE_PARAMETER_DEFAULTS: { }\n
Example:
ps-rule.yaml# YAML: Set fallback values for adminPassword and workspaceId parameters.\nconfiguration:\n AZURE_PARAMETER_DEFAULTS:\n adminPassword: $CREDENTIAL_PLACEHOLDER$\n workspaceId: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.OperationalInsights/workspaces/{workspaceName}\n
"},{"location":"setup/configuring-expansion/#excluding-files","title":"Excluding files","text":"Template or Bicep source files can be excluded from being processed by PSRule and expansion. To exclude a file, configure the input.pathIgnore
option by providing a path spec to ignore.
Syntax:
ps-rule.yamlinput:\n pathIgnore:\n - string\n - string\n
Default:
ps-rule.yaml# YAML: The default input.pathIgnore option\ninput:\n pathIgnore: []\n
Example:
ps-rule.yaml# YAML: Exclude a file from being processed by PSRule and expansion\ninput:\n pathIgnore:\n - 'out/'\n - 'modules/**/*.bicep'\n
"},{"location":"setup/configuring-options/","title":"Configuring options","text":"PSRule for Azure comes with many configuration options. Additionally, the PSRule engine includes several options that apply to all rules. You can visit the about_PSRule_Options topic to read about general PSRule options.
"},{"location":"setup/configuring-options/#setting-options","title":"Setting options","text":"Configuration options are set within the ps-rule.yaml
file. PSRule will automatically find this file within the current working directory. To set options, create a new file named ps-rule.yaml
in the root directory of your repository.
For configuring pre-flight analysis, create a ps-rule.yaml
in your current working directory.
Tip
This file should be committed to your repository so it is available when your pipeline runs.
Note
Use all lowercase characters ps-rule.yaml
to name the file. On case-sensitive file systems, a file with uppercase characters may not be found.
Configuration can be combined as indented keys. Use comments to add context.
Example ps-rule.yaml
requires:\n # Require a minimum of PSRule for Azure v1.34.2\n PSRule.Rules.Azure: '>=1.34.2'\n\nconfiguration:\n # Enable expansion of Azure Template files.\n AZURE_PARAMETER_FILE_EXPANSION: true\n\n # Enable expansion of Azure Bicep files.\n AZURE_BICEP_FILE_EXPANSION: true\n\n # Configure the timeout for bicep build to 15 seconds.\n AZURE_BICEP_FILE_EXPANSION_TIMEOUT: 15\n\n # Enable Bicep CLI checks.\n AZURE_BICEP_CHECK_TOOL: true\n\n # Optionally, configure the minimum version of the Bicep CLI.\n AZURE_BICEP_MINIMUM_VERSION: '0.16.2'\n\n # Configure the minimum AKS cluster version.\n AZURE_AKS_CLUSTER_MINIMUM_VERSION: '1.27.9'\n\nrule:\n # Enable custom rules that don't exist in the baseline\n includeLocal: true\n exclude:\n # Ignore the following rules for all resources\n - Azure.VM.UseHybridUseBenefit\n - Azure.VM.Standalone\n\nsuppression:\n Azure.AKS.AuthorizedIPs:\n # Exclude the following externally managed AKS clusters\n - aks-cluster-prod-eus-001\n Azure.Storage.SoftDelete:\n # Exclude the following non-production storage accounts\n - storagedeveus6jo36t\n - storagedeveus1df278\n
Tip
YAML can be a bit particular about indenting. If something is not working, double check that you have consistent spacing in your options file. We recommend using two (2) spaces to indent.
"},{"location":"setup/configuring-options/#setting-environment-variables","title":"Setting environment variables","text":"In addition to ps-rule.yaml
, most options can be set using environment variables. When configuring environment variables we recommend that all capital letters are used. This is because environment variables are case-sensitive on some operating systems.
PSRule environment variables use a consistent naming pattern of PSRULE_<PARENT>_<NAME>
. Where <PARENT>
is the parent class and <NAME>
is the specific option.
When setting environment variables:
PSRULE_OUTPUT_FORMAT
could be set to Yaml
.true
, false
, 1
, or 0
and are not case-sensitive. For example PSRULE_CONFIGURATION_AZURE_BICEP_FILE_EXPANSION
could be set to true
.PSRULE_RULE_EXCLUDE
could be set to 'Azure.VM.UseHybridUseBenefit;Azure.VM.Standalone'
.env:\n PSRULE_CONFIGURATION_AZURE_BICEP_FILE_EXPANSION: true\n PSRULE_OUTPUT_FORMAT: Yaml\n PSRULE_RULE_EXCLUDE: 'Azure.VM.UseHybridUseBenefit;Azure.VM.Standalone'\n
variables:\n- name: PSRULE_CONFIGURATION_AZURE_BICEP_FILE_EXPANSION\n value: true\n- name: PSRULE_OUTPUT_FORMAT\n value: Yaml\n- name: PSRULE_RULE_EXCLUDE\n value: 'Azure.VM.UseHybridUseBenefit;Azure.VM.Standalone'\n
$Env:PSRULE_CONFIGURATION_AZURE_BICEP_FILE_EXPANSION = 'true'\n$Env:PSRULE_OUTPUT_FORMAT = 'Yaml'\n$Env:PSRULE_RULE_EXCLUDE = 'Azure.VM.UseHybridUseBenefit;Azure.VM.Standalone'\n
export PSRULE_CONFIGURATION_AZURE_BICEP_FILE_EXPANSION=true\nexport PSRULE_OUTPUT_FORMAT=Yaml\nexport PSRULE_RULE_EXCLUDE='Azure.VM.UseHybridUseBenefit;Azure.VM.Standalone'\n
"},{"location":"setup/configuring-rules/","title":"Configuring rule defaults","text":"PSRule for Azure include several rules that can be configured. Setting these values overrides the default configuration with organization specific values.
To use a configuration option, you must use the minimum version specified. Earlier versions of PSRule for Azure will ignore the configuration option.
Tip
Each of these configuration options are set within the ps-rule.yaml
file. To learn how to set configuration options see Configuring options.
v1.34.0 Azure.AKS.MinNodeCount
This configuration option determines the minimum number of nodes in an AKS clusters across all system node pools.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_AKS_CLUSTER_MINIMUM_SYSTEM_NODES: integer\n
Default:
ps-rule.yaml# YAML: The default AZURE_AKS_CLUSTER_MINIMUM_SYSTEM_NODES configuration option\nconfiguration:\n AZURE_AKS_CLUSTER_MINIMUM_SYSTEM_NODES: 3\n
Example:
ps-rule.yaml# YAML: Set the AZURE_AKS_CLUSTER_MINIMUM_SYSTEM_NODES configuration option to 2\nconfiguration:\n AZURE_AKS_CLUSTER_MINIMUM_SYSTEM_NODES: 2\n
"},{"location":"setup/configuring-rules/#azure_aks_cluster_minimum_version","title":"AZURE_AKS_CLUSTER_MINIMUM_VERSION","text":"v1.12.0 Azure.AKS.Version
This configuration option determines the minimum version of Kubernetes for AKS clusters and node pools. Rules that check the Kubernetes version fail when the version is older than the version specified.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_AKS_CLUSTER_MINIMUM_VERSION: string # A version string\n
Default:
ps-rule.yaml# YAML: The default AZURE_AKS_CLUSTER_MINIMUM_VERSION configuration option\nconfiguration:\n AZURE_AKS_CLUSTER_MINIMUM_VERSION: 1.27.9\n
Example:
ps-rule.yaml# YAML: Set the AZURE_AKS_CLUSTER_MINIMUM_VERSION configuration option to 1.22.4\nconfiguration:\n AZURE_AKS_CLUSTER_MINIMUM_VERSION: 1.22.4\n
"},{"location":"setup/configuring-rules/#azure_aks_cni_minimum_cluster_subnet_size","title":"AZURE_AKS_CNI_MINIMUM_CLUSTER_SUBNET_SIZE","text":"v1.7.0 Azure.AKS.CNISubnetSize
This configuration option determines the minimum subnet size for Azure AKS CNI.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_AKS_CNI_MINIMUM_CLUSTER_SUBNET_SIZE: integer\n
Default:
ps-rule.yaml# YAML: The default AZURE_AKS_CNI_MINIMUM_CLUSTER_SUBNET_SIZE configuration option\nconfiguration:\n AZURE_AKS_CNI_MINIMUM_CLUSTER_SUBNET_SIZE: 23\n
Example:
ps-rule.yaml# YAML: Set the AZURE_AKS_CNI_MINIMUM_CLUSTER_SUBNET_SIZE configuration option to 26\nconfiguration:\n AZURE_AKS_CNI_MINIMUM_CLUSTER_SUBNET_SIZE: 26\n
"},{"location":"setup/configuring-rules/#azure_aks_additional_region_availability_zone_list","title":"AZURE_AKS_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST","text":"This configuration option adds availability zones that are not included in the existing providers. You can use this option to add availability zones that are not included in the default list.
The following providers are supported:
Microsoft.Compute/virtualMachineScaleSets
Microsoft.Network/applicationGateways
Microsoft.Network/publicIPAddresses
Microsoft.ApiManagement/service
Microsoft.Cache/Redis
Microsoft.Cache/redisEnterprise
The following rules and configuration options are supported:
Azure.AKS.AvailabilityZone
- AZURE_AKS_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
Azure.AppGw.AvailabilityZone
- AZURE_APPGW_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
Azure.PublicIP.AvailabilityZone
- AZURE_PUBLICIP_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
Azure.APIM.AvailabilityZone
- AZURE_APIM_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
Azure.Redis.AvailabilityZone
- AZURE_REDISCACHE_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
Azure.RedisEnterprise.Zones
- AZURE_REDISENTERPRISECACHE_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
Syntax:
ps-rule.yamlconfiguration:\n AZURE_AKS_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST: array\n
Default:
ps-rule.yaml# YAML: The default AZURE_AKS_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST configuration option\nconfiguration:\n AZURE_AKS_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST: []\n
Example:
ps-rule.yaml# YAML: Set the AZURE_AKS_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST configuration option to Antarctica North and Antarctica South, with zones 1, 2, 3.\nconfiguration:\n AZURE_AKS_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST:\n - location: Antarctica North\n zones:\n - '1'\n - '2'\n - '3'\n - location: Antarctica South\n zones:\n - '1'\n - '2'\n - '3'\n
The above example, both these forms of location are accepted:
Antarctica North
or antarcticanorth
Antarctica South
or antarcticasouth
The rules normalize these location formats so either is accepted in the configuration.
Note
The above are examples for illustration purpose only. At the time of writing, Antarctica North
and Antarctica South
are fictional locations. If they do in the future exist, use this option add them prior to PSRule for Azure support. The above shows examples specific to Azure.AKS.AvailabilityZone
, but behavior is consistent across all supported rules.
This configuration option sets selective platform diagnostic categories to report on being enabled.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_AKS_ENABLED_PLATFORM_LOG_CATEGORIES_LIST: array\n
Default:
ps-rule.yaml# YAML: The default AZURE_AKS_ENABLED_PLATFORM_LOG_CATEGORIES_LIST configuration option\nconfiguration:\n AZURE_AKS_ENABLED_PLATFORM_LOG_CATEGORIES_LIST:\n - cluster-autoscaler\n - kube-apiserver\n - kube-controller-manager\n - kube-scheduler\n - AllMetrics\n
Example:
# YAML: Set the AZURE_AKS_ENABLED_PLATFORM_LOG_CATEGORIES_LIST configuration option to cluster-autoscaler and AllMetrics categories only.\nconfiguration:\n AZURE_AKS_ENABLED_PLATFORM_LOG_CATEGORIES_LIST:\n - cluster-autoscaler\n - AllMetrics\n
"},{"location":"setup/configuring-rules/#azure_automationaccount_enabled_platform_log_categories_list","title":"AZURE_AUTOMATIONACCOUNT_ENABLED_PLATFORM_LOG_CATEGORIES_LIST","text":"This configuration option sets selective platform diagnostic categories to report on being enabled.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_AUTOMATIONACCOUNT_ENABLED_PLATFORM_LOG_CATEGORIES_LIST: array\n
Default:
ps-rule.yaml# YAML: The default AZURE_AUTOMATIONACCOUNT_ENABLED_PLATFORM_LOG_CATEGORIES_LIST configuration option\nconfiguration:\n AZURE_AUTOMATIONACCOUNT_ENABLED_PLATFORM_LOG_CATEGORIES_LIST:\n - JobLogs\n - JobStreams\n - DscNodeStatus\n - AllMetrics\n
Example:
ps-rule.yaml# YAML: Set the AZURE_AUTOMATIONACCOUNT_ENABLED_PLATFORM_LOG_CATEGORIES_LIST configuration option to JobLogs and AllMetrics categories only.\nconfiguration:\n AZURE_AUTOMATIONACCOUNT_ENABLED_PLATFORM_LOG_CATEGORIES_LIST:\n - JobLogs\n - AllMetrics\n
"},{"location":"setup/configuring-rules/#set-the-minimum-maxpods-for-a-node-pool","title":"Set the minimum MaxPods for a node pool","text":"v1.0.0
This configuration option determines the minimum allowed max pods setting per node pool. When an AKS cluster node pool is created, a maxPods
option is used to determine the maximum number of pods for each node in the node pool.
Depending on your workloads it may make sense to change this option:
Syntax:
ps-rule.yamlconfiguration:\n Azure_AKSNodeMinimumMaxPods: integer\n
Default:
ps-rule.yaml# YAML: The default Azure_AKSNodeMinimumMaxPods configuration option\nconfiguration:\n Azure_AKSNodeMinimumMaxPods: 50\n
Example:
ps-rule.yaml# YAML: Set the Azure_AKSNodeMinimumMaxPods configuration option to 30\nconfiguration:\n Azure_AKSNodeMinimumMaxPods: 30\n
"},{"location":"setup/configuring-rules/#azure_aks_cluster_user_pool_minimum_nodes","title":"AZURE_AKS_CLUSTER_USER_POOL_MINIMUM_NODES","text":"v1.34.0 Azure.AKS.MinUserPoolNodes
This configuration option determines the minimum number of nodes in each user node pool for an AKS clusters.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_AKS_CLUSTER_USER_POOL_MINIMUM_NODES: integer\n
Default:
ps-rule.yaml# YAML: The default AZURE_AKS_CLUSTER_USER_POOL_MINIMUM_NODES configuration option\nconfiguration:\n AZURE_AKS_CLUSTER_USER_POOL_MINIMUM_NODES: 3\n
Example:
ps-rule.yaml# YAML: Set the AZURE_AKS_CLUSTER_USER_POOL_MINIMUM_NODES configuration option to 2\nconfiguration:\n AZURE_AKS_CLUSTER_USER_POOL_MINIMUM_NODES: 2\n
"},{"location":"setup/configuring-rules/#azure_aks_cluster_user_pool_excluded_from_minimum_nodes","title":"AZURE_AKS_CLUSTER_USER_POOL_EXCLUDED_FROM_MINIMUM_NODES","text":"v1.34.0 Azure.AKS.MinUserPoolNodes
This configuration option excludes specific user node pools by name from requiring a minimum number of nodes. By default, no user node pools are configured to be excluded.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_AKS_CLUSTER_USER_POOL_EXCLUDED_FROM_MINIMUM_NODES: array\n
Default:
ps-rule.yaml# YAML: The default AZURE_AKS_CLUSTER_USER_POOL_EXCLUDED_FROM_MINIMUM_NODES configuration option\nconfiguration:\n AZURE_AKS_CLUSTER_USER_POOL_EXCLUDED_FROM_MINIMUM_NODES: []\n
Example:
ps-rule.yaml# YAML: Set the AZURE_AKS_CLUSTER_USER_POOL_EXCLUDED_FROM_MINIMUM_NODES configuration option to exclude nodepool2\nconfiguration:\n AZURE_AKS_CLUSTER_USER_POOL_EXCLUDED_FROM_MINIMUM_NODES:\n - nodepool2\n
"},{"location":"setup/configuring-rules/#azure_apim_min_api_version","title":"AZURE_APIM_MIN_API_VERSION","text":"v1.22.0 Azure.APIM.MinAPIVersion
This configuration option sets the minimum API version used for control plane API calls to API Management instances. Configure this option to change the minimum API version, which defaults to '2021-08-01'
.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_APIM_MIN_API_VERSION: string\n
Default:
ps-rule.yaml# YAML: The default AZURE_APIM_MIN_API_VERSION configuration option\nconfiguration:\n AZURE_APIM_MIN_API_VERSION: '2021-08-01'\n
Example:
ps-rule.yaml# YAML: Set the AZURE_APIM_MIN_API_VERSION configuration option to '2021-12-01-preview'\nconfiguration:\n AZURE_APIM_MIN_API_VERSION: '2021-12-01-preview'\n
"},{"location":"setup/configuring-rules/#azure_containerapps_restrict_ingress","title":"AZURE_CONTAINERAPPS_RESTRICT_INGRESS","text":"This configuration specifies whether if external ingress should be enabled or disabled.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_CONTAINERAPPS_RESTRICT_INGRESS: boolean\n
Default:
ps-rule.yaml# YAML: The default AZURE_CONTAINERAPPS_RESTRICT_INGRESS configuration option\nconfiguration:\n AZURE_CONTAINERAPPS_RESTRICT_INGRESS: false\n
Example:
ps-rule.yaml# YAML: Set the AZURE_CONTAINERAPPS_RESTRICT_INGRESS configuration option to enabled\nconfiguration:\n AZURE_CONTAINERAPPS_RESTRICT_INGRESS: true\n
"},{"location":"setup/configuring-rules/#azure_cosmos_defender_per_account","title":"AZURE_COSMOS_DEFENDER_PER_ACCOUNT","text":"This configuration option enables validation for that each Cosmos DB account is associated with a Microsoft Defender for Cosmos DB resource level plan. Configure this option to enable the per account validation, which defaults to false
.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_COSMOS_DEFENDER_PER_ACCOUNT: boolean\n
Default:
ps-rule.yaml# YAML: The default AZURE_COSMOS_DEFENDER_PER_ACCOUNT configuration option\nconfiguration:\n AZURE_COSMOS_DEFENDER_PER_ACCOUNT: false\n
Example:
ps-rule.yaml# YAML: Set the AZURE_COSMOS_DEFENDER_PER_ACCOUNT configuration option to true\nconfiguration:\n AZURE_COSMOS_DEFENDER_PER_ACCOUNT: true\n
"},{"location":"setup/configuring-rules/#azure_deployment_nonsensitive_parameter_names","title":"AZURE_DEPLOYMENT_NONSENSITIVE_PARAMETER_NAMES","text":"v1.31.1 Azure.Deployment.SecureParameter
This configuration overrides the default list of parameter names that are considered sensitive. By setting this configuration option, any parameters names specified are not considered sensitive.
By default, AZURE_DEPLOYMENT_NONSENSITIVE_PARAMETER_NAMES
is not configured.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_DEPLOYMENT_NONSENSITIVE_PARAMETER_NAMES: array\n
Default:
ps-rule.yaml# YAML: The default AZURE_DEPLOYMENT_NONSENSITIVE_PARAMETER_NAMES configuration option\nconfiguration:\n AZURE_DEPLOYMENT_NONSENSITIVE_PARAMETER_NAMES: []\n
Example:
ps-rule.yaml# YAML: Set the AZURE_DEPLOYMENT_NONSENSITIVE_PARAMETER_NAMES configuration option to enabled\nconfiguration:\n AZURE_DEPLOYMENT_NONSENSITIVE_PARAMETER_NAMES:\n - notSecret\n
"},{"location":"setup/configuring-rules/#azure_deployment_sensitive_property_names","title":"AZURE_DEPLOYMENT_SENSITIVE_PROPERTY_NAMES","text":"v1.20.0 Azure.Deployment.AdminUsername
This configuration identifies potentially sensitive properties that should not use hardcoded values. By setting this configuration option, properties with the specified names will generate a failure when a hardcoded value is detected.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_DEPLOYMENT_SENSITIVE_PROPERTY_NAMES: array\n
Default:
ps-rule.yaml# YAML: The default AZURE_DEPLOYMENT_SENSITIVE_PROPERTY_NAMES configuration option\nconfiguration:\n AZURE_DEPLOYMENT_SENSITIVE_PROPERTY_NAMES:\n - adminUsername\n - administratorLogin\n - administratorLoginPassword\n
Example:
ps-rule.yaml# YAML: Set the AZURE_DEPLOYMENT_SENSITIVE_PROPERTY_NAMES configuration option to enabled\nconfiguration:\n AZURE_DEPLOYMENT_SENSITIVE_PROPERTY_NAMES:\n - adminUsername\n - administratorLogin\n - administratorLoginPassword\n - loginName\n
"},{"location":"setup/configuring-rules/#azure_resource_allowed_locations","title":"AZURE_RESOURCE_ALLOWED_LOCATIONS","text":"v1.30.0 Azure.Resource.AllowedRegions
This configuration option specifies a list of allowed locations that resources can be deployed to. Rules that check the location of Azure resources fail when a resource or resource group is created in a different region.
By default, AZURE_RESOURCE_ALLOWED_LOCATIONS
is not configured.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_RESOURCE_ALLOWED_LOCATIONS: array # An array of regions\n
Default:
# YAML: The default Azure_AllowedRegions configuration option\nconfiguration:\n AZURE_RESOURCE_ALLOWED_LOCATIONS: []\n
Example:
ps-rule.yaml# YAML: Set the AZURE_RESOURCE_ALLOWED_LOCATIONS configuration option to Australia East, Australia South East\nconfiguration:\n AZURE_RESOURCE_ALLOWED_LOCATIONS:\n - australiaeast\n - australiasoutheast\n
If you configure the AZURE_RESOURCE_ALLOWED_LOCATIONS
configuration value, also consider setting AZURE_RESOURCE_GROUP
the configuration value to when resources use the location of the resource group.
For example:
ps-rule.yamlconfiguration:\n AZURE_RESOURCE_GROUP:\n location: australiaeast\n
"},{"location":"setup/configuring-rules/#azure_minimumcertificatelifetime","title":"Azure_MinimumCertificateLifetime","text":"This configuration option determines the minimum number of days allowed before certificate expiry. Rules that check certificate lifetime fail when the days remaining before expiry drop below this number.
Syntax:
ps-rule.yamlconfiguration:\n Azure_MinimumCertificateLifetime: integer\n
Default:
# YAML: The default Azure_MinimumCertificateLifetime configuration option\nconfiguration:\n Azure_MinimumCertificateLifetime: 30\n
Example:
ps-rule.yaml# YAML: Set the Azure_MinimumCertificateLifetime configuration option to 90\nconfiguration:\n Azure_MinimumCertificateLifetime: 90\n
"},{"location":"setup/configuring-rules/#azure_linux_os_offers","title":"AZURE_LINUX_OS_OFFERS","text":"v1.20.0
This configurations specifies names of offers corresponding to the Linux OS. It's mostly intended to be used when analyzing templates that use private Linux offerings. Rules that check if a VM or VMSS has Linux OS also validate against the values set by this configuration.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_LINUX_OS_OFFERS: array # An array of offer names\n
Default:
# YAML: The default AZURE_LINUX_OS_OFFERS configuration option\nconfiguration:\n AZURE_LINUX_OS_OFFERS: []\n
Example:
ps-rule.yaml# YAML: Set the AZURE_LINUX_OS_OFFERS configuration option to aLinuxOffer, anotherLinuxOffer\nconfiguration:\n AZURE_LINUX_OS_OFFERS:\n - 'aLinuxOffer'\n - 'anotherLinuxOffer'\n
"},{"location":"setup/configuring-rules/#azure_policy_ignore_list","title":"AZURE_POLICY_IGNORE_LIST","text":"v1.21.0
This configuration option configures a custom list policy definitions to ignore when exporting policy to rules. In addition to the custom list, a built-in list of policies are ignored. The built-in list can be found here.
Configure this option to ignore policy definitions that:
Syntax:
ps-rule.yamlconfiguration:\n AZURE_POLICY_IGNORE_LIST: array\n
Default:
ps-rule.yaml# YAML: The default AZURE_POLICY_IGNORE_LIST configuration option\nconfiguration:\n AZURE_POLICY_IGNORE_LIST: []\n
Example:
ps-rule.yaml# YAML: Add a custom policy definition to ignore\n AZURE_POLICY_IGNORE_LIST:\n - '/providers/Microsoft.Authorization/policyDefinitions/1f314764-cb73-4fc9-b863-8eca98ac36e9'\n - '/providers/Microsoft.Authorization/policyDefinitions/b54ed75b-3e1a-44ac-a333-05ba39b99ff0'\n
"},{"location":"setup/configuring-rules/#azure_policy_rule_prefix","title":"AZURE_POLICY_RULE_PREFIX","text":"This configuration option sets the prefix for names of exported rules. Configure this option to change the prefix, which defaults to Azure
.
This configuration option will be ignored when -Prefix
is used with Export-AzPolicyAssignmentRuleData
.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_POLICY_RULE_PREFIX: string\n
Default:
ps-rule.yaml# YAML: The default AZURE_POLICY_RULE_PREFIX configuration option\nconfiguration:\n AZURE_POLICY_RULE_PREFIX: Azure\n
Example:
ps-rule.yaml# YAML: Override the prefix of exported policy rules\n AZURE_POLICY_RULE_PREFIX: AzureCustomPrefix\n
"},{"location":"setup/configuring-rules/#azure_policy_waiver_max_expiry","title":"AZURE_POLICY_WAIVER_MAX_EXPIRY","text":"This configuration option determines the maximum number of days in the future for a waiver policy exemption.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_POLICY_WAIVER_MAX_EXPIRY: integer\n
Default:
ps-rule.yaml# YAML: The default AZURE_POLICY_WAIVER_MAX_EXPIRY configuration option\nconfiguration:\n AZURE_POLICY_WAIVER_MAX_EXPIRY: 366\n
Example:
ps-rule.yaml# YAML: Set the AZURE_POLICY_WAIVER_MAX_EXPIRY configuration option to 90\nconfiguration:\n AZURE_POLICY_WAIVER_MAX_EXPIRY: 90\n
"},{"location":"setup/configuring-rules/#azure_storage_defender_per_account","title":"AZURE_STORAGE_DEFENDER_PER_ACCOUNT","text":"v1.27.0 Azure.Storage.DefenderCloud
This configuration option enables validation that storage accounts are associated with a resource level Microsoft Defender for Storage plan. By default, this option is set to false
because configuration at the subscription level is recommended. Configure this option to enable the per account validation, which defaults to false
.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_STORAGE_DEFENDER_PER_ACCOUNT: boolean\n
Default:
# YAML: The default AZURE_STORAGE_DEFENDER_PER_ACCOUNT configuration option\nconfiguration:\n AZURE_STORAGE_DEFENDER_PER_ACCOUNT: false\n
Example:
ps-rule.yaml# YAML: Set the AZURE_STORAGE_DEFENDER_PER_ACCOUNT configuration option to true\nconfiguration:\n AZURE_STORAGE_DEFENDER_PER_ACCOUNT: true\n
"},{"location":"setup/configuring-rules/#azure_vm_use_azure_hybrid_benefit","title":"AZURE_VM_USE_AZURE_HYBRID_BENEFIT","text":"v1.33.0 Azure.VM.UseHybridUseBenefit
This configuration option determines whether to check for Azure Hybrid Benefit (AHB) when deploying Windows VMs. When enabled, rules that check for AHB fail when the VM is not configured to use AHB.
To use AHB, you must separately have eligible licenses, such as Windows Server or SQL Server.
By default, this configuration option is set to false
.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_VM_USE_AZURE_HYBRID_BENEFIT: boolean\n
Default:
ps-rule.yamlconfiguration:\n AZURE_VM_USE_AZURE_HYBRID_BENEFIT: false\n
Example:
ps-rule.yaml# Set the configuration option to enabled.\nconfiguration:\n AZURE_VNET_DNS_WITH_IDENTITY: true\n
"},{"location":"setup/configuring-rules/#azure_vnet_dns_with_identity","title":"AZURE_VNET_DNS_WITH_IDENTITY","text":"v1.30.0 Azure.VNET.LocalDNS
Set this configuration option to true
when DNS is deployed within the Identity subscription to avoid false positives.
When deploying Active Directory Domain Services (ADDS) within Azure, you may decide to:
If you are using this configuration, we recommend you set the configuration option AZURE_VNET_DNS_WITH_IDENTITY
to true
. By default, this configuration option is set to false
.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_VNET_DNS_WITH_IDENTITY: boolean\n
Default:
ps-rule.yamlconfiguration:\n AZURE_VNET_DNS_WITH_IDENTITY: false\n
Example:
ps-rule.yaml# Set the configuration option to enabled.\nconfiguration:\n AZURE_VNET_DNS_WITH_IDENTITY: true\n
"},{"location":"setup/configuring-rules/#azure_vnet_subnet_excluded_from_nsg","title":"AZURE_VNET_SUBNET_EXCLUDED_FROM_NSG","text":"v1.33.0 Azure.VNET.UseNSGs
This configuration option excludes subnets from requiring a Network Security Group (NSG). You can use this configuration option to exclude subnets that are specific to your environment. To configure this option, specify a list of subnet names to exclude.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_VNET_SUBNET_EXCLUDED_FROM_NSG: array\n
Default:
ps-rule.yamlconfiguration:\n AZURE_VNET_SUBNET_EXCLUDED_FROM_NSG: []\n
Example:
ps-rule.yaml# Configure two customs subnets to be excluded from NSG checks.\nconfiguration:\n AZURE_VNET_SUBNET_EXCLUDED_FROM_NSG:\n - subnet-1\n - subnet-2\n
"},{"location":"setup/setup-azure-monitor-logs/","title":"Setup Azure Monitor logs","text":"When analyzing Azure resources, you may want to capture the results of each analysis run. Azure Monitor provides a central storage location for log data through Log Analytics workspaces. Centrally storing PSRule results enables the following scenarios:
Abstract
This topic covers setting up PSRule to log rule results into a Log Analytics workspace.
"},{"location":"setup/setup-azure-monitor-logs/#logging-into-a-log-analytics-workspace","title":"Logging into a Log Analytics workspace","text":"Logging of PSRule results into a workspace is done using the PSRule for Azure Monitor module. PSRule for Azure Monitor extends the PSRule pipeline to import results into the specified workspace.
Once configured, PSRule will log results into the PSRule_CL
custom log table of the chosen workspace.
Info
Integration between PSRule and Azure Monitor is done by means of a convention. Conventions extend the pipeline to be able to upload results after rules have run.
"},{"location":"setup/setup-azure-monitor-logs/#setting-environment-variables","title":"Setting environment variables","text":"PSRule for Azure Monitor requires a Log Analytics workspace to import results into. To configure the workspace to import results to the following environment variables must be set.
PSRULE_CONFIGURATION_MONITOR_WORKSPACE_ID
- The unique ID (GUID) for the workspace to import results.PSRULE_CONFIGURATION_MONITOR_WORKSPACE_KEY
- Either the primary or secondary key of the workspace.How to set these environment variables is covered in the next section for GitHub Actions and Azure Pipelines.
Tip
Both the workspace ID and keys can be found under the Agents management settings of the workspace.
"},{"location":"setup/setup-azure-monitor-logs/#configuring-your-pipeline","title":"Configuring your pipeline","text":"The convention that imports PSRule analysis results is not executed by default. To enable, reference the Monitor.LogAnalytics.Import
convention in your analysis pipeline.
GitHub Action
Import analysis results into Azure Monitor with GitHub Actions by:
PSRule.Monitor
module.Monitor.LogAnalytics.Import
convention.MONITOR_WORKSPACE_ID
and MONITOR_WORKSPACE_KEY
.Install the latest stable module versions.
- name: Analyze Azure template files\n uses: microsoft/ps-rule@v2.9.0\n with:\n modules: PSRule.Rules.Azure,PSRule.Monitor\n conventions: Monitor.LogAnalytics.Import\n env:\n # Define environment variables using GitHub encrypted secrets\n PSRULE_CONFIGURATION_MONITOR_WORKSPACE_ID: ${{ secrets.MONITOR_WORKSPACE_ID }}\n PSRULE_CONFIGURATION_MONITOR_WORKSPACE_KEY: ${{ secrets.MONITOR_WORKSPACE_KEY }}\n
Install the latest stable or pre-release module versions.
- name: Analyze Azure template files\n uses: microsoft/ps-rule@v2.9.0\n with:\n modules: PSRule.Rules.Azure,PSRule.Monitor\n conventions: Monitor.LogAnalytics.Import\n prerelease: true\n env:\n # Define environment variables using GitHub encrypted secrets\n PSRULE_CONFIGURATION_MONITOR_WORKSPACE_ID: ${{ secrets.MONITOR_WORKSPACE_ID }}\n PSRULE_CONFIGURATION_MONITOR_WORKSPACE_KEY: ${{ secrets.MONITOR_WORKSPACE_KEY }}\n
Important
Environment variables can be configured in the workflow or from a secret. To keep MONITOR_WORKSPACE_KEY
secure, use an encrypted secret.
Extension
Import analysis results into Azure Monitor with Azure Pipelines by:
ps-rule-assert
task in pipeline steps.PSRule.Monitor
module.Monitor.LogAnalytics.Import
convention.MONITORWORKSPACEID
and MONITORWORKSPACEKEY
.Install the latest stable module versions.
- task: ps-rule-assert@2\n displayName: Analyze Azure template files\n inputs:\n modules: PSRule.Rules.Azure,PSRule.Monitor\n conventions: Monitor.LogAnalytics.Import\n env:\n # Define environment variables within Azure Pipelines\n PSRULE_CONFIGURATION_MONITOR_WORKSPACE_ID: $(MONITORWORKSPACEID)\n PSRULE_CONFIGURATION_MONITOR_WORKSPACE_KEY: $(MONITORWORKSPACEKEY)\n
Install the latest stable or pre-release module versions.
- task: ps-rule-install@2\n displayName: Install PSRule for Azure (pre-release)\n inputs:\n module: PSRule.Rules.Azure\n prerelease: true\n\n- task: ps-rule-install@2\n displayName: Install PSRule for Azure Monitor (pre-release)\n inputs:\n module: PSRule.Monitor\n prerelease: true\n\n- task: ps-rule-assert@2\n displayName: Analyze Azure template files\n inputs:\n modules: PSRule.Rules.Azure,PSRule.Monitor\n conventions: Monitor.LogAnalytics.Import\n env:\n # Define environment variables within Azure Pipelines\n PSRULE_CONFIGURATION_MONITOR_WORKSPACE_ID: $(MONITORWORKSPACEID)\n PSRULE_CONFIGURATION_MONITOR_WORKSPACE_KEY: $(MONITORWORKSPACEKEY)\n
Important
Variables can be configured in YAML, on the pipeline, or referenced from a defined variable group. To keep MONITORWORKSPACEKEY
secure, use a variable group linked to an Azure Key Vault.
Continue reading for some sample resources you can try once this integration is setup Azure Monitor integration.
"},{"location":"setup/setup-azure-monitor-logs/#log-analytics-queries","title":"Log Analytics Queries","text":""},{"location":"setup/setup-azure-monitor-logs/#results-with-annotations","title":"Results with annotations","text":"Kusto// Show extended info\nPSRule_CL\n| where TimeGenerated > ago(30d)\n| extend Pillar = tostring(parse_json(Annotations_s).pillar)\n| extend Link = tostring(parse_json(Annotations_s).[\"online version\"])\n
"},{"location":"setup/setup-azure-monitor-logs/#summarize-results-by-run","title":"Summarize results by run","text":"Kusto// Group by run\nPSRule_CL\n| where TimeGenerated > ago(30d)\n| summarize Pass=countif(Outcome_s == \"Pass\"), Fail=countif(Outcome_s == \"Fail\") by RunId_s\n
"},{"location":"setup/setup-azure-monitor-logs/#querying-the-data","title":"Querying The Data","text":"Once the results have been published to the Log Analytics workspace, they can be queried by executing results against the PSRule_CL
table (under Custom Logs). For more information on how to write Log Analytics querys, review the Log Analytics tutortial.
Workbook
A sample Azure Monitor Workbook is available in the PSRule for Azure GitHub repository. This workbook can be imported directly into Azure Monitor and used as a foundation to build from. Review the Workbook creation tutorial for instructions on how to work with the sample Workbook.
"},{"location":"setup/setup-bicep/","title":"Setup Bicep","text":"To expand Azure resources for analysis from Bicep source files the Bicep CLI is required. The Bicep CLI is already installed on hosted runners and agents used by GitHub Actions and Azure Pipelines.
Abstract
This topic covers setting up support for analyzing Azure resources within Bicep source files.
"},{"location":"setup/setup-bicep/#installing-bicep-cli","title":"Installing Bicep CLI","text":"PSRule for Azure requires a minimum of Bicep CLI version 0.4.451. However the features you use within Bicep may require a newer version of the Bicep CLI.
You may need to install or upgrade the Bicep CLI in the following scenarios:
The Bicep CLI can be installed on MacOS, Linux, and Windows. For installation instructions see Setup your Bicep development environment.
Tip
When installing Bicep using the Azure CLI, Bicep is not added to the PATH
environment variable. To use PSRule for Azure with the Azure CLI set the PSRULE_AZURE_BICEP_USE_AZURE_CLI
to true
. Setting this environment variable is explained in the next section.
When expanding Bicep files, the path to the Bicep CLI binary is required. By default, the PATH
environment variable will be used to discover the binary path. When using this option, add the sub-directory containing the Bicep binary to the environment variable.
Alternatively, the path can be overridden by setting the PSRULE_AZURE_BICEP_PATH
environment variable. When setting PSRULE_AZURE_BICEP_PATH
specify the full path to the Bicep binary including the file name. File names used for Bicep binaries include bicep
, or bicep.exe
.
Example
Bashexport PSRULE_AZURE_BICEP_PATH='/usr/local/bin/bicep'\n
PowerShell$Env:PSRULE_AZURE_BICEP_PATH = '/usr/local/bin/bicep';\n
GitHub Actionsenv:\n PSRULE_AZURE_BICEP_PATH: '/usr/local/bin/bicep'\n
Azure Pipelinesvariables:\n- name: PSRULE_AZURE_BICEP_PATH\n value: '/usr/local/bin/bicep'\n
"},{"location":"setup/setup-bicep/#using-azure-cli","title":"Using Azure CLI","text":"By default, PSRule for Azure uses the Bicep CLI directly. An additional option is to use the Azure CLI to invoke the Bicep CLI. When using this option the required version of the CLI must be installed prior to using PSRule for Azure. This is explained in Setup your Bicep development environment.
To enable this option, set the PSRULE_AZURE_BICEP_USE_AZURE_CLI
environment variable to true
.
Example
Bashexport PSRULE_AZURE_BICEP_USE_AZURE_CLI=true\n
PowerShell$Env:PSRULE_AZURE_BICEP_USE_AZURE_CLI = 'true'\n
GitHub Actionsenv:\n PSRULE_AZURE_BICEP_USE_AZURE_CLI: true\n
Azure Pipelinesvariables:\n- name: PSRULE_AZURE_BICEP_USE_AZURE_CLI\n value: true\n
"},{"location":"setup/setup-bicep/#additional-arguments","title":"Additional arguments","text":"For configuration, additional arguments can be passed to the Bicep CLI. This is intended to improve forward compatibility with Bicep CLI.
To configure additional arguments, set the PSRULE_AZURE_BICEP_ARGS
environment variable.
Docs
PSRule for Azure can automatically expand Bicep source files. When enabled, PSRule for Azure automatically expands and analyzes Azure resource from .bicep
files.
To enabled this feature, set the Configuration.AZURE_BICEP_FILE_EXPANSION
to true
. This option can be set within the ps-rule.yaml
file.
configuration:\n # Enable automatic expansion of bicep source files.\n AZURE_BICEP_FILE_EXPANSION: true\n
Tip
If you deploy Bicep code using JSON parameter files this option does not need to be set. Set Configuration.AZURE_PARAMETER_FILE_EXPANSION
to true
instead. See Using parameter files and By metadata for more information.
Docs
In certain environments it may be necessary to increase the default timeout for building Bicep files. This can occur if your Bicep deployments are:
If you are experiencing timeout errors you can increase the default timeout of 5 seconds. To configure the timeout, set Configuration.AZURE_BICEP_FILE_EXPANSION_TIMEOUT
to the timeout in seconds.
configuration:\n # Enable automatic expansion of bicep source files.\n AZURE_BICEP_FILE_EXPANSION: true\n\n # Configure the timeout for bicep build to 15 seconds.\n AZURE_BICEP_FILE_EXPANSION_TIMEOUT: 15\n
"},{"location":"setup/setup-bicep/#checking-bicep-version","title":"Checking Bicep version","text":"v1.25.0
To use Bicep files with PSRule for Azure:
It may not always be clear which version of Bicep CLI is being used if you have multiple versions installed. Additionally, the version installed in your CI/ CD pipeline may not be the same as your local development environment.
You can enable checking the Bicep CLI version during initialization. To enable this feature, set the Configuration.AZURE_BICEP_CHECK_TOOL
option to true
. Additionally, you can set the minimum version required using the Configuration.AZURE_BICEP_MINIMUM_VERSION
option.
configuration:\n # Enable Bicep CLI checks.\n AZURE_BICEP_CHECK_TOOL: true\n\n # Optionally, configure the minimum version of the Bicep CLI.\n AZURE_BICEP_MINIMUM_VERSION: '0.16.2'\n
"},{"location":"setup/setup-bicep/#configuring-minimum-version","title":"Configuring minimum version","text":"v1.25.0
The Azure Bicep CLI is updated regularly, with new features and bug fixes. You must use a version of the Bicep CLI that supports the features you are using. If you attempt to use a feature that is not supported by the Bicep CLI, expansion will fail with a BCP error.
Tip
It may not always be clear which version of Bicep CLI is being used if you have multiple versions installed. Using the Bicep CLI via az bicep
is not the default, and you may need to set additional options to use it.
To ensure you are using the correct version of the Bicep CLI, you can configure the minimum version required. If an earlier version is detected, PSRule for Azure will generate an error. To configure the minimum version, set the Configuration.AZURE_BICEP_MINIMUM_VERSION
option. By default, the minimum version is set to 0.4.451
.
configuration:\n # Enable Bicep CLI checks.\n AZURE_BICEP_CHECK_TOOL: true\n\n # Configure the minimum version of the Bicep CLI.\n AZURE_BICEP_MINIMUM_VERSION: '0.16.2'\n
Important
The Configuration.AZURE_BICEP_CHECK_TOOL
must be set to true
for this option to take effect.
Tip
For troubleshooting Bicep compilation errors see Bicep compile errors.
"},{"location":"setup/setup-bicep/#recommended-content","title":"Recommended content","text":"To support analysis of in-flight resources, the configuration data must be exported from Azure. This spec documents this mode of operation.
"},{"location":"specs/inflight-export-spec/#requirements","title":"Requirements","text":"The requirements for this feature/ mode of operation include:
Additonally some non-function requirements include:
What's changed since v0.18.0:
Azure.GA_2020_12
baseline. #593Azure.GA_2020_09
as obsolete.Azure.AKS.Version
to 1.19.3. #590true
, false
, and null
template functions. #579createObject
template function. #580What's changed since pre-release v0.19.0-B2012008:
Azure.GA_2020_12
baseline. #593Azure.GA_2020_09
as obsolete.What's changed since pre-release v0.19.0-B2011008:
Azure.AKS.Version
to 1.19.3. #590What's changed since v0.18.0:
true
, false
, and null
template functions. #579createObject
template function. #580What's changed since v0.17.0:
Get-AzRuleTemplateLink
reports incorrect parameter with file path. #568What's changed since pre-release v0.18.0-B2011023:
What's changed since pre-release v0.18.0-B2011005:
Get-AzRuleTemplateLink
reports incorrect parameter with file path. #568What's changed since pre-release v0.18.0-B2010016:
What's changed since v0.17.0:
What's changed since v0.16.0:
maxmemory-reserved
setting. #502Azure.Storage.UseReplication
for additional use cases.resource-usage = 'azure-functions'
or resource-usage = 'azure-monitor'
. #534Azure.AKS.AzurePolicyAddOn
to GA rule set. #524Azure.AKS.PodSecurityPolicy
as this AKS feature is replaced by Azure Policy. #523providers
template function. #177dateTimeAdd
template function. #516What's changed since pre-release v0.17.0-B2010028:
What's changed since pre-release v0.17.0-B2010022:
maxmemory-reserved
setting. #502What's changed since pre-release v0.17.0-B2010017:
What's changed since pre-release v0.17.0-B2010006:
Azure.Storage.UseReplication
for additional use cases.resource-usage = 'azure-functions'
or resource-usage = 'azure-monitor'
. #534What's changed since pre-release v0.17.0-B2009009:
Azure.AKS.AzurePolicyAddOn
to GA rule set. #524Azure.AKS.PodSecurityPolicy
as this AKS feature is replaced by Azure Policy. #523What's changed since v0.16.0:
providers
template function. #177dateTimeAdd
template function. #516What's changed since v0.15.0:
Azure.GA_2020_09
baseline. #488Azure.GA_2020_06
as obsolete.Azure.AKS.Version
to 1.18.8. #5042019-04-01
schema. #495$Rule
properties. #491What's changed since pre-release v0.16.0-B2009033:
What's changed since pre-release v0.16.0-B2009024:
Azure.GA_2020_09
baseline. #488Azure.GA_2020_06
as obsolete.Azure.AKS.Version
to 1.18.8. #504What's changed since pre-release v0.16.0-B2009019:
What's changed since pre-release v0.16.0-B2009011:
2019-04-01
schema. #495What's changed since pre-release v0.16.0-B2009004:
$Rule
properties. #491What's changed since v0.15.0:
What's changed since v0.14.1:
Azure.AKS.Version
to 1.17.9. #452What's changed since pre-release v0.15.0-B2008034:
What's changed since pre-release v0.15.0-B2008034:
What's changed since pre-release v0.15.0-B2008026:
What's changed since v0.14.1:
Azure.AKS.Version
to 1.17.9. #452What's changed since v0.14.0:
What's changed since v0.13.0:
Azure.AKS.Version
to 1.17.7. #427What's changed since pre-release v0.14.0-B2007031:
What's changed since pre-release v0.14.0-B2007020:
What's changed since v0.13.0:
Azure.AKS.Version
to 1.17.7. #427What's changed since v0.12.1:
Azure.GA_2020_06
baseline. #399Azure.AKS.Version
to 1.16.9. #394What's changed since pre-release v0.13.0-B2006032:
Azure.GA_2020_06
baseline. #399Azure.AKS.Version
to 1.16.9. #394What's changed since v0.12.0:
What's changed since v0.11.0:
What's changed since pre-release v0.12.0-B2005026:
What's changed since v0.10.1:
Azure_
prefix.minAKSVersion
to Azure_AKSMinimumVersion
.azureAllowedRegions
to Azure_AllowedRegions
.What's changed since pre-release v0.11.0-B2004012:
Azure_
prefix.minAKSVersion
to Azure_AKSMinimumVersion
.azureAllowedRegions
to Azure_AllowedRegions
.What's changed since v0.10.0:
What's changed since v0.9.0:
Get-AzRuleTemplateLink
cmdlet to get metadata link to template files.Azure.AKS.Version
to 1.16.7. #330azureAllowedRegions
option. #328Export-AzRuleData
. #301What's changed since pre-release v0.10.0-B2003051:
Get-AzRuleTemplateLink
cmdlet to get metadata link to template files.azureAllowedRegions
option. #328Azure.AKS.Version
to 1.16.7. #330Export-AzRuleData
. #301What's changed since v0.8.0:
Azure.Storage.UseReplication
and Azure.Storage.SoftDelete
ignore cloud shell storage accounts.Az.Security
. #105Azure.VNET.UseNSGs
to exclude AzureFirewallSubnet
. #261What's changed since pre-release v0.9.0-B2002036:
Az.Security
. #105Azure.VNET.UseNSGs
to exclude AzureFirewallSubnet
. #261What's changed since v0.7.0:
Azure.AKS.Version
to 1.15.7. #247Azure.VNET.UseNSGs
to apply to subnet resources from templates. #246en
cultures.Azure.VirtualNetwork.*
to Azure.AppGW.*
.Azure.VirtualNetwork.*
to Azure.LB.*
.Azure.VirtualNetwork.*
to Azure.NSG.*
.Azure.VirtualNetwork.*
to Azure.VNET.*
.Azure.VirtualNetwork.*
to Azure.VM.*
.Azure.Storage.SecureTransferRequired
to Azure.Storage.SecureTransfer
.Azure.Resource.UseTags
applying to template and parameter files. #230What's changed since pre-release v0.8.0-B2001029:
Azure.VNET.UseNSGs
not populating subnet name in reason message. #256en
. #257Azure.VNET.UseNSGs
to apply to subnet resources from templates. #246Azure.AKS.Version
to 1.15.7. #247Azure.File.*
rules to Azure.Template.*
. #252Azure.Resource.UseTags
applying to template and parameter files. #230en
. #224Azure.VirtualNetwork.*
to Azure.AppGW.*
. #119Azure.VirtualNetwork.*
to Azure.LB.*
. #119Azure.VirtualNetwork.*
to Azure.NSG.*
. #119Azure.VirtualNetwork.*
to Azure.VNET.*
. #119Azure.VirtualNetwork.*
to Azure.VM.*
. #119Azure.Storage.SecureTransferRequired
to Azure.Storage.SecureTransfer
. #119Azure.AKS.Version
to 1.15.5. #217What's changed since v0.6.0:
Azure.AKS.Version
to check for node pool version. #191Azure.Subscription.*
to Azure.RBAC.*
.Azure.Subscription.*
to Azure.SecureCenter.*
.Azure.SubscriptionDefault
to Azure.Default
. #190What's changed since pre-release v0.7.0-B1912024:
Azure.AKS.Version
to check for node pool version. #191Azure.Subscription.*
to Azure.RBAC.*
. #119Azure.Subscription.*
to Azure.SecureCenter.*
. #119Azure.SubscriptionDefault
to Azure.Default
. #190What's changed since v0.5.0:
Export-AzTemplateRuleData
cmdlet to export templates. See cmdlet help for limitations.Azure.AKS.Version
to 1.14.8. #140Azure.Resource.UseTags
to exclude */providers/roleAssignments
. #155Azure.Resource.AllowedRegions
. #156*/providers/roleAssignments
, Microsoft.Authorization/*
and Microsoft.Consumption/*
.Azure.VirtualNetwork.NSGAssociated
for templates. #150Azure.VirtualNetwork.LateralTraversal
when destinationPortRanges
is used. #149What's changed since pre-release v0.6.0-B1911046:
Export-AzTemplateRuleData
cmdlet. #145deployment
function.Export-AzTemplateRuleData
does not return FileInfo objects. #162Export-AzTemplateRuleData
. #163Azure.Resource.UseTags
to exclude */providers/roleAssignments
. #155Azure.Resource.AllowedRegions
. #156*/providers/roleAssignments
, Microsoft.Authorization/*
and Microsoft.Consumption/*
.Azure.VirtualNetwork.NSGAssociated
for templates. #150Azure.VirtualNetwork.LateralTraversal
when destinationPortRanges
is used. #149Export-AzTemplateRuleData
cmdlet. #145array
, createArray
, coalesce
, intersection
, dataUri
and dataUriToString
functions.Azure.AKS.Version
to 1.14.8. #140Export-AzTemplateRuleData
cmdlet to export templates. See cmdlet help for limitations.What's changed since v0.4.0:
Azure.AKS.Version
to 1.14.6. #130Azure.VM.*
to improve output display. #119Azure.VirtualMachine.*
to Azure.VM.*
.What's changed since pre-release v0.5.0-B1910004:
Azure.AKS.Version
to 1.14.6. #130Azure.VirtualMachine.*
rules to Azure.VM.*
. #119What's changed since v0.3.0:
What's changed since pre-release v0.4.0-B190902:
What's changed since v0.2.0:
Azure.AppService.ARRAffinity
and Azure.AppService.UseHTTPS
now run against slots.Azure.AKS.Version
to 1.14.5. #109Azure.VirtualNetwork.LocalDNS
. #84Azure.VirtualNetwork.LocalDNS
. #89Microsoft.Sql/servers
. #114What's changed since pre-release v0.3.0-B190807:
Microsoft.Sql/servers
. #114Azure.AKS.Version
to 1.14.5. #109Azure.AppService.ARRAffinity
and Azure.AppService.UseHTTPS
now run against slots.Azure.VirtualNetwork.LocalDNS
. #84Azure.VirtualNetwork.LocalDNS
. #89Azure.AKS.Version
to 1.13.7. #83What's changed since v0.1.0:
Azure.AKS.UseRBAC
returns null. #60Azure.Storage.SoftDelete
and Azure.Storage.SecureTransferRequired
returns null. #64Recommend
keyword instead of Hint
alias. #71Azure.SQL.FirewallIPRange
, Azure.MySQL.FirewallIPRange
and Azure.PostgreSQL.FirewallIPRange
were added to check SQL, MySQL and PostgreSQL.-ResourceGroupName
and -Tag
parameters to Export-AzRuleData
cmdlet.What's changed since pre-release v0.2.0-B190715:
Azure.AKS.UseRBAC
returns null. #60Azure.Storage.SoftDelete
and Azure.Storage.SecureTransferRequired
returns null. #64Azure.SQL.FirewallIPRange
, Azure.MySQL.FirewallIPRange
and Azure.PostgreSQL.FirewallIPRange
were added to check SQL, MySQL and PostgreSQL.Recommend
keyword instead of Hint
alias. #71-ResourceGroupName
and -Tag
parameters to Export-AzRuleData
cmdlet.What's changed since pre-release v0.1.0-B190624:
Export-AzRuleData
and update filters. #28Export-AzRuleData
returns files generated by default. #27Export-AzRuleData
passes through objects resource objects to the pipeline. #25Export-AzRuleData
only exports data from current subscription context by default. #24-All
switch, or specifying specific subscriptions with the -Subscription
or -Tenant
parameters.See upgrade notes for helpful information when upgrading from previous versions.
Important notes:
Could not load file or assembly YamlDotNet
. See troubleshooting guide for a workaround to this issue.Azure_AKSMinimumVersion
is replaced with AZURE_AKS_CLUSTER_MINIMUM_VERSION
. If you have this option configured, please update it to AZURE_AKS_CLUSTER_MINIMUM_VERSION
. Support for Azure_AKSMinimumVersion
will be removed in v2. See upgrade notes for more information.Azure_AllowedRegions
is replaced with AZURE_RESOURCE_ALLOWED_LOCATIONS
. If you have this option configured, please update it to AZURE_RESOURCE_ALLOWED_LOCATIONS
. Support for Azure_AllowedRegions
will be removed in v2. See upgrade notes for more information.SupportsTag
PowerShell function has been replaced with the Azure.Resource.SupportsTags
selector. Update PowerShell rules to use the Azure.Resource.SupportsTags
selector instead. Support for the SupportsTag
function will be removed in v2. See upgrade notes for more information.What's changed since v1.34.2:
Azure.Pillar.CostOptimization
Azure.Pillar.OperationalExcellence
Azure.Pillar.PerformanceEfficiency
Azure.Pillar.Reliability
Azure.Pillar.Security
Azure.GA_2024_03
and Azure.Preview_2024_03
by @BernieWhite. #2781Azure.GA_2023_12
and Azure.Preview_2023_12
baselines as obsolete.Azure.AppService.NETVersion
to detect out of date .NET versions including .NET 5/6/7 by @BernieWhite. #27662024_03
.Azure.AppService.PHPVersion
to detect out of date PHP versions before 8.2 by @BernieWhite. #2768Azure.AppService.PHPVersion
check fails when phpVersion is null.2024_03
.Azure.AKS.Version
to use 1.27.9
as the minimum version by @BernieWhite. #2771Azure.Cognitive.*
have been renamed to Azure.AI.*
.Azure.LB.AvailabilityZone
when zone list is empty or null by @jtracey93. #2759What's changed since pre-release v1.35.0-B0116:
What's changed since pre-release v1.35.0-B0084:
Azure.GA_2024_03
and Azure.Preview_2024_03
by @BernieWhite. #2781Azure.GA_2023_12
and Azure.Preview_2023_12
baselines as obsolete.Azure.Cognitive.*
have been renamed to Azure.AI.*
.What's changed since pre-release v1.35.0-B0055:
What's changed since pre-release v1.35.0-B0030:
Azure.AppService.NETVersion
to detect out of date .NET versions including .NET 5/6/7 by @BernieWhite. #27662024_03
.Azure.AppService.PHPVersion
to detect out of date PHP versions before 8.2 by @BernieWhite. #2768Azure.AppService.PHPVersion
check fails when phpVersion is null.2024_03
.Azure.AKS.Version
to use 1.27.9
as the minimum version by @BernieWhite. #2771What's changed since pre-release v1.35.0-B0012:
Azure.LB.AvailabilityZone
when zone list is empty or null by @jtracey93. #2759What's changed since v1.34.2:
Azure.Pillar.CostOptimization
Azure.Pillar.OperationalExcellence
Azure.Pillar.PerformanceEfficiency
Azure.Pillar.Reliability
Azure.Pillar.Security
What's changed since v1.34.1:
What's changed since v1.34.0:
What's changed since v1.33.2:
AZURE_AKS_CLUSTER_USER_POOL_MINIMUM_NODES
to set the minimum number of user nodes.AZURE_AKS_CLUSTER_USER_POOL_EXCLUDED_FROM_MINIMUM_NODES
to exclude a specific node pool by name.Azure.AKS.MinNodeCount
the count nodes system node pools by @BernieWhite. #2683AZURE_AKS_CLUSTER_MINIMUM_SYSTEM_NODES
to set the minimum number of system nodes.Azure.FrontDoor.Logs
to cover premium and standard profiles instead of just classic by @BernieWhite. #2704Azure.FrontDoor.IsStandardOrPremium
.Azure.FrontDoor.IsClassic
.2024_03
.Azure.Defender.Storage.SensitiveData
to Azure.Defender.Storage.DataScan
.Azure.Defender.Storage.MalwareScan
to GA rule set by @BernieWhite. #2590Azure.Storage.DefenderCloud.MalwareScan
to Azure.Storage.Defender.MalwareScan
.Azure.Storage.DefenderCloud.SensitiveData
to Azure.Storage.Defender.DataScan
.Azure.Storage.Defender.MalwareScan
to GA rule set by @BernieWhite. #2590.bicepparam
file support to stable by @BernieWhite. #2682AZURE_BICEP_PARAMS_FILE_EXPANSION
to false
.What's changed since pre-release v1.34.0-B0077:
What's changed since pre-release v1.34.0-B0047:
Azure.Defender.Storage.SensitiveData
to Azure.Defender.Storage.DataScan
.Azure.Defender.Storage.MalwareScan
to GA rule set by @BernieWhite. #2590Azure.Storage.DefenderCloud.MalwareScan
to Azure.Storage.Defender.MalwareScan
.Azure.Storage.DefenderCloud.SensitiveData
to Azure.Storage.Defender.DataScan
.Azure.Storage.Defender.MalwareScan
to GA rule set by @BernieWhite. #2590What's changed since pre-release v1.34.0-B0022:
What's changed since v1.33.2:
AZURE_AKS_CLUSTER_USER_POOL_MINIMUM_NODES
to set the minimum number of user nodes.AZURE_AKS_CLUSTER_USER_POOL_EXCLUDED_FROM_MINIMUM_NODES
to exclude a specific node pool by name.Azure.AKS.MinNodeCount
the count nodes system node pools by @BernieWhite. #2683AZURE_AKS_CLUSTER_MINIMUM_SYSTEM_NODES
to set the minimum number of system nodes.Azure.FrontDoor.Logs
to cover premium and standard profiles instead of just classic by @BernieWhite. #2704Azure.FrontDoor.IsStandardOrPremium
.Azure.FrontDoor.IsClassic
.2024_03
..bicepparam
file support to stable by @BernieWhite. #2682AZURE_BICEP_PARAMS_FILE_EXPANSION
to false
.What's changed since v1.33.1:
Azure.Resource.AllowedRegions
raised during assertion call by @BernieWhite. #2687What's changed since v1.33.0:
Azure.AKS.AuthorizedIPs
is not valid for a private cluster by @BernieWhite. #2677What's changed since v1.32.1:
<Prefix>.PolicyBaseline.All
. i.e. Azure.PolicyBaseline.All
by default.Azure.AppGwWAF.RuleGroups
to use the rule sets by @BenjaminEngeset. #26291.0
.3.2
.Azure.Cognitive.ManagedIdentity
to configurations that require managed identities by @BernieWhite. #2559Azure.VM.UseHybridUseBenefit
are not enabled by default by @BernieWhite. #2493AZURE_VM_USE_HYBRID_USE_BENEFIT
option to true
.Azure.VNET.UseNSGs
by @BernieWhite. #2572AZURE_VNET_SUBNET_EXCLUDED_FROM_NSG
option.-Verbose
.-KeepDuplicates
parameter by @BernieWhite. #2482dateTimeAdd
may fail with different localization by @BernieWhite. #2631Azure.ACR.Usage
by @BernieWhite. #2494Azure.Template.TemplateFile
to support with languageVersion
2.0 template properties by @MrRoundRobin. #2660Azure.VM.DiskSizeAlignment
does not handle smaller sizes and ultra disks by @BernieWhite. #2656What's changed since pre-release v1.33.0-B0169:
What's changed since pre-release v1.33.0-B0126:
<Prefix>.PolicyBaseline.All
. i.e. Azure.PolicyBaseline.All
by default.-Verbose
.-KeepDuplicates
parameter by @BernieWhite. #2482Azure.ACR.Usage
by @BernieWhite. #2494What's changed since pre-release v1.33.0-B0088:
Azure.Template.TemplateFile
to support with languageVersion
2.0 template properties by @MrRoundRobin. #2660What's changed since pre-release v1.33.0-B0053:
Azure.VM.DiskSizeAlignment
does not handle smaller sizes and ultra disks by @BernieWhite. #2656What's changed since pre-release v1.33.0-B0023:
What's changed since v1.32.1:
Azure.AppGwWAF.RuleGroups
to use the rule sets by @BenjaminEngeset. #26291.0
.3.2
.Azure.Cognitive.ManagedIdentity
to configurations that require managed identities by @BernieWhite. #2559Azure.VM.UseHybridUseBenefit
are not enabled by default by @BernieWhite. #2493AZURE_VM_USE_HYBRID_USE_BENEFIT
option to true
.Azure.VNET.UseNSGs
by @BernieWhite. #2572AZURE_VNET_SUBNET_EXCLUDED_FROM_NSG
option.dateTimeAdd
may fail with different localization by @BernieWhite. #2631What's changed since v1.32.0:
What's changed since v1.31.3:
Azure.GA_2023_12
and Azure.Preview_2023_12
by @BernieWhite. #2580Azure.GA_2023_09
and Azure.Preview_2023_09
baselines as obsolete.Azure.AppConfig.GeoReplica
to GA rule set by @BernieWhite. #2592Azure.APIM.DefenderCloud
to GA rule set by @BernieWhite. #2591Azure.AKS.Version
to use latest stable version 1.27.7
by @BernieWhite. #2581Azure.Defender.Api
to GA rule set by @BernieWhite. #2591Azure.VM.NICAttached
to Azure.NIC.Attached
.Azure.VM.NICName
to Azure.NIC.Name
.Azure.VM.UniqueDns
to Azure.NIC.UniqueDns
.Azure.VM.NICAttached
by @BernieWhite. #2563Azure.Deployment.SecureParameter
by @BernieWhite. #2556What's changed since pre-release v1.32.0-B0099:
What's changed since pre-release v1.32.0-B0053:
Azure.GA_2023_12
and Azure.Preview_2023_12
by @BernieWhite. #2580Azure.GA_2023_09
and Azure.Preview_2023_09
baselines as obsolete.Azure.AppConfig.GeoReplica
to GA rule set by @BernieWhite. #2592Azure.APIM.DefenderCloud
to GA rule set by @BernieWhite. #2591Azure.AKS.Version
to use latest stable version 1.27.7
by @BernieWhite. #2581Azure.Defender.Api
to GA rule set by @BernieWhite. #2591What's changed since pre-release v1.32.0-B0021:
Azure.VM.NICAttached
to Azure.NIC.Attached
.Azure.VM.NICName
to Azure.NIC.Name
.Azure.VM.UniqueDns
to Azure.NIC.UniqueDns
.Azure.VM.NICAttached
by @BernieWhite. #2563What's changed since v1.31.3:
Azure.Deployment.SecureParameter
by @BernieWhite. #2556What's changed since v1.31.2:
What's changed since v1.31.1:
What's changed since v1.31.0:
Azure.Deployment.SecureParameter
by @BernieWhite. #2528AZURE_DEPLOYMENT_NONSENSITIVE_PARAMETER_NAMES
.What's changed since v1.30.3:
What's changed since pre-release v1.31.0-B0048:
What's changed since pre-release v1.31.0-B0020:
What's changed since v1.30.3:
What's changed since v1.30.2:
What's changed since v1.30.1:
What's changed since v1.30.0:
Azure.Resource.AllowedRegions
which was failing when no allowed regions were configured by @BernieWhite. #2461What's changed since v1.29.0:
Azure.GA_2023_09
and Azure.Preview_2023_09
by @BernieWhite. #2451Azure.GA_2023_06
and Azure.Preview_2023_06
baselines as obsolete.alert and deny
mode by @BenjaminEngeset. #2354Azure.AKS.Version
to use latest stable version 1.26.6
by @BernieWhite. #2404AZURE_AKS_CLUSTER_MINIMUM_VERSION
to configure the minimum version of the cluster.Azure.AKS.LocalAccounts
to GA rule set by @BernieWhite. #2448Azure.ContainerApp.DisableAffinity
to GA rule set by @BernieWhite. #2455Azure_AllowedRegions
option with AZURE_RESOURCE_ALLOWED_LOCATIONS
. #941Azure_AllowedRegions
is set it will be used instead of AZURE_RESOURCE_ALLOWED_LOCATIONS
.AZURE_RESOURCE_ALLOWED_LOCATIONS
is set, this value will be used.Azure_AllowedRegions
is set a warning will be generated until the configuration is removed.Azure_AllowedRegions
is deprecated and will be removed in v2.Azure.Storage.SecureTransfer
on new API versions by @BernieWhite. #2414Azure.VNET.LocalDNS
for DNS server addresses out of local scope by @BernieWhite. #2370AZURE_VNET_DNS_WITH_IDENTITY
to true
when using an Identity subscription for DNS.Azure.AKS.Version
by excluding node-image
channel by @BernieWhite. #2446What's changed since pre-release v1.30.0-B0127:
What's changed since pre-release v1.30.0-B0080:
Azure.GA_2023_09
and Azure.Preview_2023_09
by @BernieWhite. #2451Azure.GA_2023_06
and Azure.Preview_2023_06
baselines as obsolete.Azure.AKS.Version
to use latest stable version 1.26.6
by @BernieWhite. #2404AZURE_AKS_CLUSTER_MINIMUM_VERSION
to configure the minimum version of the cluster.Azure.AKS.LocalAccounts
to GA rule set by @BernieWhite. #2448Azure.ContainerApp.DisableAffinity
to GA rule set by @BernieWhite. #2455Azure.AKS.Version
by excluding node-image
channel by @BernieWhite. #2446What's changed since pre-release v1.30.0-B0047:
Azure_AllowedRegions
option with AZURE_RESOURCE_ALLOWED_LOCATIONS
. #941Azure_AllowedRegions
is set it will be used instead of AZURE_RESOURCE_ALLOWED_LOCATIONS
.AZURE_RESOURCE_ALLOWED_LOCATIONS
is set, this value will be used.Azure_AllowedRegions
is set a warning will be generated until the configuration is removed.Azure_AllowedRegions
is deprecated and will be removed in v2.Azure.Storage.SecureTransfer
on new API versions by @BernieWhite. #2414Azure.VNET.LocalDNS
for DNS server addresses out of local scope by @BernieWhite. #2370AZURE_VNET_DNS_WITH_IDENTITY
to true
when using an Identity subscription for DNS.What's changed since pre-release v1.30.0-B0026:
What's changed since pre-release v1.30.0-B0011:
What's changed since v1.29.0:
alert and deny
mode by @BenjaminEngeset. #2354What's changed since v1.28.2:
What's changed since pre-release v1.29.0-B0062:
What's changed since pre-release v1.29.0-B0036:
What's changed since pre-release v1.29.0-B0015:
What's changed since v1.28.2:
What's changed since v1.28.1:
What's changed since v1.28.0:
parseCidr
with /32
is not valid by @BernieWhite. #2336Azure.MariaDB.VNETRuleName
to allow for parent resources.Azure.MariaDB.FirewallRuleName
to allow for parent resources.What's changed since v1.27.3:
Azure.GA_2023_06
and Azure.Preview_2023_06
by @BernieWhite. #2310Azure.GA_2023_03
and Azure.Preview_2023_03
baselines as obsolete.Azure.AKS.PodIdentity
as pod identities has been replaced by workload identities by @BernieWhite. #2273tryGet
Bicep function.parseCidr
, cidrSubnet
, and cidrHost
.managementGroupResourceId
Bicep function by @BernieWhite. #2294coalesce
function by @BernieWhite. #2328What's changed since pre-release v1.28.0-B0213:
What's changed since pre-release v1.28.0-B0159:
tryGet
Bicep function.coalesce
function by @BernieWhite. #2328What's changed since pre-release v1.28.0-B0115:
Azure.GA_2023_06
and Azure.Preview_2023_06
by @BernieWhite. #2310Azure.GA_2023_03
and Azure.Preview_2023_03
baselines as obsolete.What's changed since pre-release v1.28.0-B0079:
parseCidr
, cidrSubnet
, and cidrHost
.What's changed since pre-release v1.28.0-B0045:
managementGroupResourceId
Bicep function by @BernieWhite. #2294What's changed since pre-release v1.28.0-B0024:
Azure.AKS.PodIdentity
as pod identities has been replaced by workload identities by @BernieWhite. #2273IsolatedV2
with Azure.AppService.MinPlan
by @BernieWhite. #2277What's changed since pre-release v1.28.0-B0010:
What's changed since v1.27.1:
What's changed since v1.27.2:
IsolatedV2
with Azure.AppService.MinPlan
by @BernieWhite. #2277What's changed since v1.27.1:
What's changed since v1.27.0:
What's changed since v1.26.1:
.bicepparam
files by @BernieWhite. #2132Standard
plan by @BenjaminEngeset. #2151Azure.APIM.EncryptValues
to check all API Management named values are encrypted with Key Vault secrets @BenjaminEngeset. #2146Azure.ContainerApp.Insecure
to GA rule set by @BernieWhite. #2174or
function evaluation by @BernieWhite. #2220Azure.MariaDB.Database
by @BernieWhite. #2191Azure.Defender.Api
documentation by @BenjaminEngeset. #2209Azure.AKS.UptimeSLA
with new pricing by @BenjaminEngeset. #2065 #2202What's changed since pre-release v1.27.0-B0186:
What's changed since pre-release v1.27.0-B0136:
What's changed since pre-release v1.27.0-B0091:
What's changed since pre-release v1.27.0-B0050:
.bicepparam
files by @BernieWhite. #2132or
function evaluation by @BernieWhite. #2220What's changed since pre-release v1.27.0-B0015:
Azure.MariaDB.Database
by @BernieWhite. #2191Azure.Defender.Api
documentation by @BenjaminEngeset. #2209Azure.AKS.UptimeSLA
with new pricing by @BenjaminEngeset. #2065 #2202What's changed since pre-release v1.27.0-B0003:
Standard
plan by @BenjaminEngeset. #2151Azure.ContainerApp.Insecure
to GA rule set by @BernieWhite. #2174What's changed since v1.26.1:
Azure.APIM.EncryptValues
to check all API Management named values are encrypted with Key Vault secrets @BenjaminEngeset. #2146What's changed since v1.26.0:
Azure.Resource.UseTags
for additional resources that don't support tags by @BernieWhite. #2129What's changed since v1.25.0:
Azure.GA_2023_03
and Azure.Preview_2023_03
by @BernieWhite. #2138Azure.GA_2022_12
and Azure.Preview_2022_12
baselines as obsolete.*
for any configuration option in CORS policies settings is not in use by @BenjaminEngeset. #2073Azure.AKS.Version
to use latest stable version 1.25.6
by @BernieWhite. #2136AZURE_AKS_CLUSTER_MINIMUM_VERSION
to configure the minimum version of the cluster.Azure.Deployment.Name
by @BernieWhite. #2109Azure.AppService.AlwaysOn
with Functions and Workflows by @BernieWhite. #943What's changed since pre-release v1.26.0-B0078:
What's changed since pre-release v1.26.0-B0040:
Azure.AppService.AlwaysOn
with Functions and Workflows by @BernieWhite. #943What's changed since pre-release v1.26.0-B0011:
Azure.GA_2023_03
and Azure.Preview_2023_03
by @BernieWhite. #2138Azure.GA_2022_12
and Azure.Preview_2022_12
baselines as obsolete.*
for any configuration option in CORS policies settings is not in use by @BenjaminEngeset. #2073Azure.AKS.Version
to use latest stable version 1.25.6
by @BernieWhite. #2136AZURE_AKS_CLUSTER_MINIMUM_VERSION
to configure the minimum version of the cluster.Azure.Deployment.Name
by @BernieWhite. #2109What's changed since v1.25.0:
What's changed since v1.25.0:
What's changed since v1.24.2:
Azure.MCSB.v1
which include rules aligned to the Microsoft Cloud Security Benchmark by @BernieWhite. #1634toObject
function by @BernieWhite. #2014AZURE_BICEP_CHECK_TOOL
to true
to check the Bicep CLI.AZURE_BICEP_MINIMUM_VERSION
to configure the minimum version.0.4.451
.What's changed since pre-release v1.25.0-B0100:
What's changed since pre-release v1.25.0-B0100:
What's changed since pre-release v1.25.0-B0065:
What's changed since pre-release v1.25.0-B0035:
toObject
function by @BernieWhite. #2014What's changed since pre-release v1.25.0-B0013:
AZURE_BICEP_CHECK_TOOL
to true
to check the Bicep CLI.AZURE_BICEP_MINIMUM_VERSION
to configure the minimum version.0.4.451
.What's changed since v1.24.2:
Azure.MCSB.v1
which include rules aligned to the Microsoft Cloud Security Benchmark by @BernieWhite. #1634This is a republish of v1.24.1 to fix a release issue. What's changed since v1.24.0:
What's changed since v1.24.0:
What's changed since v1.23.0:
Export-AzRuleData
to improve export performance by @BernieWhite. #1341Az.Resources
dependency.filter
, map
, reduce
, and sort
are supported.flatten
was previously added in v1.23.0.Export-AzRuleData
may not export all data if throttled by @BernieWhite. #1341apiVersion
comparison of requestContext
by @BernieWhite. #1654What's changed since pre-release v1.24.0-B0035:
What's changed since pre-release v1.24.0-B0013:
filter
, map
, reduce
, and sort
are supported.flatten
was previously added in v1.23.0.apiVersion
comparison of requestContext
by @BernieWhite. #1654What's changed since v1.23.0:
Export-AzRuleData
to improve export performance by @BernieWhite. #1341Az.Resources
dependency.Export-AzRuleData
may not export all data if throttled by @BernieWhite. #1341What's changed since v1.22.2:
Azure.GA_2022_12
and Azure.Preview_2022_12
by @BernieWhite. #1961Azure.GA_2022_09
and Azure.Preview_2022_09
baselines as obsolete.Azure.AKS.Version
to use latest stable version 1.25.4
by @BernieWhite. #1960AZURE_AKS_CLUSTER_MINIMUM_VERSION
to configure the minimum version of the cluster.flatten
function by @BernieWhite. #1536What's changed since pre-release v1.23.0-B0072:
What's changed since pre-release v1.23.0-B0046:
Azure.GA_2022_12
and Azure.Preview_2022_12
by @BernieWhite. #1961Azure.GA_2022_09
and Azure.Preview_2022_09
baselines as obsolete.Azure.AKS.Version
to use latest stable version 1.25.4
by @BernieWhite. #1960AZURE_AKS_CLUSTER_MINIMUM_VERSION
to configure the minimum version of the cluster.What's changed since pre-release v1.23.0-B0025:
Azure.Deployment.SecureValue
with reference
function expression by @BernieWhite. #1882What's changed since pre-release v1.23.0-B0009:
flatten
function by @BernieWhite. #1536What's changed since v1.22.1:
What's changed since v1.22.1:
Azure.Deployment.SecureValue
with reference
function expression by @BernieWhite. #1882What's changed since v1.22.0:
What's changed since v1.21.2:
'2021-08-01'
or newer by @BenjaminEngeset. #1819outer
and passing secure values by @ms-sambell. #1475requestContext
function by @BernieWhite. #1654Azure.AppService.WebProbe
with non-boolean value set by @BernieWhite. #1906Azure.Deployment.OutputSecretValue
by @BernieWhite. #1826 #1886What's changed since pre-release v1.22.0-B0203:
What's changed since pre-release v1.22.0-B0153:
Azure.AppService.WebProbe
with non-boolean value set by @BernieWhite. #1906What's changed since pre-release v1.22.0-B0106:
Azure.Deployment.OutputSecretValue
by @BernieWhite. #1826 #1886What's changed since pre-release v1.22.0-B0062:
requestContext
function by @BernieWhite. #1654What's changed since pre-release v1.22.0-B0026:
outer
and passing secure values by @ms-sambell. #1475What's changed since pre-release v1.22.0-B0011:
'2021-08-01'
or newer by @BenjaminEngeset. #1819What's changed since v1.21.0:
What's changed since v1.21.1:
What's changed since v1.21.0:
Azure.ACR.ContentTrust
when customer managed keys are enabled by @BernieWhite. #1810What's changed since v1.20.2:
AZURE_POLICY_IGNORE_LIST
configuration option.What's changed since pre-release v1.21.0-B0050:
What's changed since pre-release v1.21.0-B0027:
What's changed since pre-release v1.21.0-B0011:
What's changed since v1.20.1:
AZURE_POLICY_IGNORE_LIST
configuration option.What's changed since v1.20.1:
What's changed since v1.20.0:
What's changed since v1.19.2:
Azure.GA_2022_09
and Azure.Preview_2022_09
by @BernieWhite. #1738Azure.GA_2022_06
and Azure.Preview_2022_06
baselines as obsolete.Azure.SQL.ThreatDetection
to Azure.SQL.DefenderCloud
.Azure.SecurityCenter.Contact
to Azure.DefenderCloud.Contact
.Azure.SecurityCenter.Provisioning
to Azure.DefenderCloud.Provisioning
.Azure.AKS.Version
to use latest stable version 1.23.8
by @BernieWhite. #1627AZURE_AKS_CLUSTER_MINIMUM_VERSION
to configure the minimum version of the cluster.Azure.EventGrid.DisableLocalAuth
to GA rule set by @BernieWhite. #1628Azure.KeyVault.AutoRotationPolicy
to GA rule set by @BernieWhite. #1629name
and ref
properties for policy rules by @ArmaanMcleod. #1653AZURE_POLICY_RULE_PREFIX
or Export-AzPolicyAssignmentRuleData -RulePrefix
to override rule prefix.Azure.Deployment.AdminUsername
by @BernieWhite. #1631json()
and single quotes by @BernieWhite. #1656Azure.Deployment.AdminUsername
incorrectly fails with nested deployments by @BernieWhite. #1762Azure.FrontDoorWAF.Exclusions
reports exclusions when none are specified by @BernieWhite. #1751Azure.Deployment.AdminUsername
does not match the pattern by @BernieWhite. #1758What's changed since pre-release v1.20.0-B0477:
What's changed since pre-release v1.20.0-B0389:
name
and ref
properties for policy rules by @ArmaanMcleod. #1653AZURE_POLICY_RULE_PREFIX
or Export-AzPolicyAssignmentRuleData -RulePrefix
to override rule prefix.What's changed since pre-release v1.20.0-B0304:
Azure.Deployment.AdminUsername
incorrectly fails with nested deployments by @BernieWhite. #1762What's changed since pre-release v1.20.0-B0223:
Azure.FrontDoorWAF.Exclusions
reports exclusions when none are specified by @BernieWhite. #1751Azure.Deployment.AdminUsername
does not match the pattern by @BernieWhite. #1758What's changed since pre-release v1.20.0-B0148:
Azure.GA_2022_09
and Azure.Preview_2022_09
by @BernieWhite. #1738Azure.GA_2022_06
and Azure.Preview_2022_06
baselines as obsolete.What's changed since pre-release v1.20.0-B0085:
json()
and single quotes by @BernieWhite. #1656What's changed since pre-release v1.20.0-B0028:
Azure.SQL.ThreatDetection
to Azure.SQL.DefenderCloud
.Azure.SecurityCenter.Contact
to Azure.DefenderCloud.Contact
.Azure.SecurityCenter.Provisioning
to Azure.DefenderCloud.Provisioning
.What's changed since pre-release v1.20.0-B0004:
Azure.AKS.Version
to use latest stable version 1.23.8
by @BernieWhite. #1627AZURE_AKS_CLUSTER_MINIMUM_VERSION
to configure the minimum version of the cluster.Azure.EventGrid.DisableLocalAuth
to GA rule set by @BernieWhite. #1628Azure.KeyVault.AutoRotationPolicy
to GA rule set by @BernieWhite. #1629dateTimeAdd
errors handling utcNow
output by @BernieWhite. #1637Azure.Deployment.AdminUsername
by @BernieWhite. #1631What's changed since v1.19.1:
What's changed since v1.19.1:
dateTimeAdd
errors handling utcNow
output by @BernieWhite. #1637What's changed since v1.19.0:
Azure.VNET.UseNSGs
is missing exceptions by @BernieWhite. #1609RouteServerSubnet
and any subnet with a dedicated HSM delegation.What's changed since v1.18.1:
Azure.APIM.APIDescriptors
to warning from error.Azure.APIM.ProductDescriptors
to warning from error.Azure.Template.UseLocationParameter
to warning from error.Azure.Template.UseComments
to information from error.Azure.Template.UseDescriptions
to information from error.What's changed since pre-release v1.19.0-B0077:
What's changed since pre-release v1.19.0-B0042:
What's changed since pre-release v1.19.0-B0010:
What's changed since v1.18.1:
Azure.APIM.APIDescriptors
to warning from error.Azure.APIM.ProductDescriptors
to warning from error.Azure.Template.UseLocationParameter
to warning from error.Azure.Template.UseComments
to information from error.Azure.Template.UseDescriptions
to information from error.What's changed since v1.18.0:
Azure.APIM.HTTPBackend
reports failure when service URL is not defined by @BernieWhite. #1555Azure.SQL.AAD
failure with newer API by @BernieWhite. #1302What's changed since v1.17.1:
indexOf
, lastIndexOf
, and items
ARM functions by @BernieWhite. #1440join
ARM function by @BernieWhite. #1535Azure.SQL.TDE
is not required to enable Transparent Data Encryption for IaC by @BernieWhite. #1530What's changed since pre-release v1.18.0-B0027:
What's changed since pre-release v1.18.0-B0010:
indexOf
, lastIndexOf
, and items
ARM functions by @BernieWhite. #1440join
ARM function by @BernieWhite. #1535Azure.SQL.TDE
is not required to enable Transparent Data Encryption for IaC by @BernieWhite. #1530What's changed since pre-release v1.18.0-B0002:
What's changed since v1.17.1:
What's changed since v1.17.0:
What's changed since v1.16.1:
Azure.GA_2022_06
and Azure.Preview_2022_06
by @BernieWhite. #1499Azure.GA_2022_03
and Azure.Preview_2022_03
baselines as obsolete.What's changed since pre-release v1.17.0-B0064:
What's changed since pre-release v1.17.0-B0035:
What's changed since pre-release v1.17.0-B0014:
Azure.GA_2022_06
and Azure.Preview_2022_06
by @BernieWhite. #1499Azure.GA_2022_03
and Azure.Preview_2022_03
baselines as obsolete.What's changed since v1.16.1:
What's changed since v1.16.0:
Azure.AppGw.SSLPolicy
by @BernieWhite. #1469What's changed since v1.15.2:
Azure.PublicIP.AvailabilityZone
to exclude IP addresses for Azure Bastion by @BernieWhite. #1442resource-usage
tag set to azure-bastion
are excluded.dateTimeFromEpoch
and dateTimeToEpoch
ARM functions by @BernieWhite. #1451Azure.Template.UseVariables
does not accept function variables names by @BernieWhite. #1427AzurePowerShell
task by @BernieWhite. #1447Az.Accounts
and Az.Resources
from manifest. Pre-install these modules to use export cmdlets.What's changed since pre-release v1.16.0-B0072:
What's changed since pre-release v1.16.0-B0041:
AzurePowerShell
task by @BernieWhite. #1447Az.Accounts
and Az.Resources
from manifest. Pre-install these modules to use export cmdlets.What's changed since pre-release v1.16.0-B0017:
Azure.PublicIP.AvailabilityZone
to exclude IP addresses for Azure Bastion by @BernieWhite. #1442resource-usage
tag set to azure-bastion
are excluded.dateTimeFromEpoch
and dateTimeToEpoch
ARM functions by @BernieWhite. #1451What's changed since v1.15.2:
Azure.Template.UseVariables
does not accept function variables names by @BernieWhite. #1427What's changed since v1.15.1:
Azure.AppService.ManagedIdentity
does not accept both system and user assigned by @BernieWhite. #1415Azure.ADX.ManagedIdentity
Azure.APIM.ManagedIdentity
Azure.EventGrid.ManagedIdentity
Azure.Automation.ManagedIdentity
Azure.AppService.NETVersion
by @BernieWhite. #1414Azure.AppService.PHPVersion
.What's changed since v1.15.0:
dataCollectionRuleAssociations
from Azure.Resource.UseTags
by @BernieWhite. #1400What's changed since v1.14.3:
Azure.Resource.SupportsTags
selector by @BernieWhite. #1339SupportsTags
PowerShell function.SupportsTag
function will now result in a warning.SupportsTags
function will be removed in v2.Azure.AKS.Version
to use latest stable version 1.22.6
by @BernieWhite. #1386AZURE_AKS_CLUSTER_MINIMUM_VERSION
to configure the minimum version of the cluster.nodeps
manifest that does not include dependencies for Az modules by @BernieWhite. #1392What's changed since pre-release v1.15.0-B0053:
What's changed since pre-release v1.15.0-B0022:
Azure.Resource.SupportsTags
selector. #1339SupportsTags
PowerShell function.SupportsTag
function will now result in a warning.SupportsTags
function will be removed in v2.nodeps
manifest that does not include dependencies for Az modules. #1392What's changed since v1.14.3:
Azure.AKS.Version
to use latest stable version 1.22.6
. #1386AZURE_AKS_CLUSTER_MINIMUM_VERSION
to configure the minimum version of the cluster.What's changed since v1.14.2:
What's changed since v1.14.1:
What's changed since v1.14.0:
What's changed since v1.13.4:
reference()
function can be used to reference resources in template.Azure.GA_2022_03
and Azure.Preview_2022_03
. #1334Azure.GA_2021_12
and Azure.Preview_2021_12
baselines as obsolete.Export-AzPolicyAssignmentData
- Exports policy assignment data. #1266Export-AzPolicyAssignmentRuleData
- Exports JSON rules from policy assignment data. #1278Get-AzPolicyAssignmentDataSource
- Discovers policy assignment data. #1340Azure.AKS.Version
to use latest stable version 1.21.9
. #1318AZURE_AKS_CLUSTER_MINIMUM_VERSION
to configure the minimum version of the cluster.What's changed since pre-release v1.14.0-B2204013:
What's changed since pre-release v1.14.0-B2204007:
What's changed since pre-release v1.14.0-B2203117:
What's changed since pre-release v1.14.0-B2203088:
Export-AzPolicyAssignmentData
- Exports policy assignment data. #1266Export-AzPolicyAssignmentRuleData
- Exports JSON rules from policy assignment data. #1278Get-AzPolicyAssignmentDataSource
- Discovers policy assignment data. #1340What's changed since pre-release v1.14.0-B2203066:
Azure.GA_2022_03
and Azure.Preview_2022_03
. #1334Azure.GA_2021_12
and Azure.Preview_2021_12
baselines as obsolete.What's changed since v1.13.4:
reference()
function can be used to reference resources in template.Azure.AKS.Version
to use latest stable version 1.21.9
. #1318AZURE_AKS_CLUSTER_MINIMUM_VERSION
to configure the minimum version of the cluster.What's changed since v1.13.3:
Azure.ACR.Retention
and Azure.ACR.ContentTrust
are now only run against premium instances.What's changed since v1.13.2:
What's changed since v1.13.1:
What's changed since v1.13.0:
What's changed since v1.12.2:
What's changed since pre-release v1.13.0-B2202113:
What's changed since pre-release v1.13.0-B2202108:
What's changed since pre-release v1.13.0-B2202103:
What's changed since pre-release v1.13.0-B2202090:
What's changed since pre-release v1.13.0-B2202063:
What's changed since v1.12.2:
What's changed since v1.12.1:
What's changed since v1.12.0:
What's changed since v1.11.1:
Azure.AKS.Version
to use latest stable version 1.21.7
. #1188Azure.GA_2021_12
to previous version 1.20.5
.AZURE_AKS_CLUSTER_MINIMUM_VERSION
to configure the minimum version of the cluster.Azure.APIM.Protocols
Azure.APIM.Ciphers
Azure_AKSMinimumVersion
option with AZURE_AKS_CLUSTER_MINIMUM_VERSION
. #941Azure_AKSMinimumVersion
is set it will be used instead of AZURE_AKS_CLUSTER_MINIMUM_VERSION
.AZURE_AKS_CLUSTER_MINIMUM_VERSION
is set, this value will be used.Azure_AKSMinimumVersion
is set a warning will be generated until the configuration is removed.Azure_AKSMinimumVersion
is deprecated and will be removed in v2.What's changed since pre-release v1.12.0-B2201086:
What's changed since pre-release v1.12.0-B2201067:
What's changed since pre-release v1.12.0-B2201054:
What's changed since v1.11.1:
Azure.AKS.Version
to use latest stable version 1.21.7
. #1188Azure.GA_2021_12
to previous version 1.20.5
.AZURE_AKS_CLUSTER_MINIMUM_VERSION
to configure the minimum version of the cluster.Azure.APIM.Protocols
Azure.APIM.Ciphers
Azure_AKSMinimumVersion
option with AZURE_AKS_CLUSTER_MINIMUM_VERSION
. #941Azure_AKSMinimumVersion
is set it will be used instead of AZURE_AKS_CLUSTER_MINIMUM_VERSION
.AZURE_AKS_CLUSTER_MINIMUM_VERSION
is set, this value will be used.Azure_AKSMinimumVersion
is set a warning will be generated until the configuration is removed.Azure_AKSMinimumVersion
is deprecated and will be removed in v2.What's changed since v1.11.0:
Azure.AKS.CNISubnetSize
rule to use CNI selector. #1178What's changed since v1.10.4:
Azure.Preview_2021_09
.Azure.Preview_2021_12
.Azure.GA_2021_12
baseline. #1146Azure.GA_2021_09
as obsolete.Azure.Redis.AvailabilityZone
Azure.RedisEnterprise.Zones
Azure.AKS.AutoUpgrade
to GA rule set. #1130tenant()
. #1124managementGroup()
. #1125pickZones()
. #518Azure.LB.Name
Azure.NSG.Name
Azure.Firewall.Mode
Azure.Route.Name
Azure.VNET.Name
Azure.VNG.Name
Azure.VNG.ConnectionName
Azure.AppConfig.SKU
Azure.AppConfig.Name
Azure.AppInsights.Workspace
Azure.AppInsights.Name
Azure.Cosmos.AccountName
Azure.FrontDoor.State
Azure.FrontDoor.Name
Azure.FrontDoor.WAF.Mode
Azure.FrontDoor.WAF.Enabled
Azure.FrontDoor.WAF.Name
Azure.AKS.MinNodeCount
Azure.AKS.ManagedIdentity
Azure.AKS.StandardLB
Azure.AKS.AzurePolicyAddOn
Azure.AKS.ManagedAAD
Azure.AKS.AuthorizedIPs
Azure.AKS.LocalAccounts
Azure.AKS.AzureRBAC
What's changed since pre-release v1.11.0-B2112112:
What's changed since pre-release v1.11.0-B2112104:
Azure.Redis.AvailabilityZone
Azure.RedisEnterprise.Zones
What's changed since pre-release v1.11.0-B2112073:
Azure.AppConfig.SKU
Azure.AppConfig.Name
Azure.AppInsights.Workspace
Azure.AppInsights.Name
Azure.Cosmos.AccountName
Azure.FrontDoor.State
Azure.FrontDoor.Name
Azure.FrontDoor.WAF.Mode
Azure.FrontDoor.WAF.Enabled
Azure.FrontDoor.WAF.Name
Azure.AKS.MinNodeCount
Azure.AKS.ManagedIdentity
Azure.AKS.StandardLB
Azure.AKS.AzurePolicyAddOn
Azure.AKS.ManagedAAD
Azure.AKS.AuthorizedIPs
Azure.AKS.LocalAccounts
Azure.AKS.AzureRBAC
Azure.Preview_2021_12
. #1166What's changed since pre-release v1.11.0-B2112024:
Azure.Preview_2021_09
.Azure.Preview_2021_12
.Azure.GA_2021_12
baseline. #1146Azure.GA_2021_09
as obsolete.equals
parameter count mismatch. #1137What's changed since pre-release v1.11.0-B2111014:
Azure.AKS.AutoUpgrade
to GA rule set. #1130tenant()
. #1124managementGroup()
. #1125pickZones()
. #518Azure.Policy.WaiverExpiry
date conversion. #1118What's changed since v1.10.0:
Azure.LB.Name
Azure.NSG.Name
Azure.Firewall.Mode
Azure.Route.Name
Azure.VNET.Name
Azure.VNG.Name
Azure.VNG.ConnectionName
What's changed since v1.10.3:
What's changed since v1.10.2:
What's changed since v1.10.1:
equals
parameter count mismatch. #1137What's changed since v1.10.0:
Azure.Policy.WaiverExpiry
date conversion. #1118What's changed since v1.9.1:
What's changed since pre-release v1.10.0-B2111081:
What's changed since pre-release v1.10.0-B2111072:
What's changed since pre-release v1.10.0-B2111058:
What's changed since pre-release v1.10.0-B2111040:
What's changed since v1.9.1:
What's changed since v1.9.0:
Azure.VM.ASMinMembers
for template deployments. #1064What's changed since v1.8.1:
Azure.Template.DefineParameters
is ignored for AzOps generated templates.Azure.Template.UseLocationParameter
is ignored for AzOps generated templates.providers.json
monthly. #1041Azure.ACR.AdminUser
fails when adminUserEnabled
not set. #1014Azure.KeyVault.Logs
reports cannot index into a null array. #1024and
template function. #1026Azure.ACR.MinSKU
to work more reliably with templates. #1034What's changed since pre-release v1.9.0-B2110087:
What's changed since pre-release v1.9.0-B2110082:
What's changed since pre-release v1.9.0-B2110059:
providers.json
monthly. #1041What's changed since pre-release v1.9.0-B2110040:
Azure.ACR.MinSKU
to work more reliably with templates. #1034What's changed since pre-release v1.9.0-B2110025:
Azure.KeyVault.Logs
reports cannot index into a null array. #1024and
template function. #1026What's changed since pre-release v1.9.0-B2110014:
Azure.ACR.AdminUser
fails when adminUserEnabled
not set. #1014What's changed since pre-release v1.9.0-B2110009:
What's changed since pre-release v1.9.0-B2109027:
Azure.Template.UseLocationParameter
to only apply to templates deployed as RG scope #995createObject
when no parameters are specified. #1000What's changed since v1.8.0:
Azure.Template.DefineParameters
is ignored for AzOps generated templates.Azure.Template.UseLocationParameter
is ignored for AzOps generated templates.ToUpper
fails to convert character. #986What's changed since v1.8.0:
Azure.Template.UseLocationParameter
to only apply to templates deployed as RG scope #995createObject
when no parameters are specified. #1000ToUpper
fails to convert character. #986What's changed since v1.7.0:
Azure.GA_2021_09
baseline. #961Azure.GA_2021_06
as obsolete.Azure.Storage.MinTLS
. #971Azure.Storage.UseReplication
with large file storage. #965What's changed since pre-release v1.8.0-B2109060:
What's changed since pre-release v1.8.0-B2109060:
Azure.Storage.MinTLS
. #971Azure.Storage.UseReplication
with large file storage. #965What's changed since pre-release v1.8.0-B2109046:
Azure.GA_2021_09
baseline. #961Azure.GA_2021_06
as obsolete.What's changed since pre-release v1.8.0-B2109020:
What's changed since pre-release v1.8.0-B2108026:
What's changed since pre-release v1.8.0-B2108013:
What's changed since v1.7.0:
What's changed since v1.6.0:
AZURE_PARAMETER_FILE_METADATA_LINK
option to enable this rule./23
subnet is required.AZURE_AKS_CNI_MINIMUM_CLUSTER_SUBNET_SIZE
to change the default minimum subnet size.AzureFirewallManagementSubnet
from Azure.VNET.UseNSGs
. #869Azure.Template.ParameterValue
failing on empty value. #901What's changed since pre-release v1.7.0-B2108059:
What's changed since pre-release v1.7.0-B2108049:
Azure.Template.ParameterValue
failing on empty value. #901What's changed since pre-release v1.7.0-B2108040:
What's changed since pre-release v1.7.0-B2108020:
AZURE_PARAMETER_FILE_METADATA_LINK
option to enable this rule./23
subnet is required.AZURE_AKS_CNI_MINIMUM_CLUSTER_SUBNET_SIZE
to change the default minimum subnet size.What's changed since v1.6.0:
AzureFirewallManagementSubnet
from Azure.VNET.UseNSGs
. #869What's changed since v1.5.1:
AZURE_BICEP_FILE_EXPANSION
configuration to true
.What's changed since pre-release v1.6.0-B2108038:
What's changed since pre-release v1.6.0-B2108023:
What's changed since pre-release v1.6.0-B2107028:
AZURE_BICEP_FILE_EXPANSION
configuration to true
.What's changed since v1.5.1:
What's changed since v1.5.0:
What's changed since v1.4.1:
Azure.GA_2021_06
baseline. #822Azure.GA_2021_03
as obsolete.What's changed since pre-release v1.5.0-B2107002:
What's changed since pre-release v1.5.0-B2106018:
Azure.GA_2021_06
baseline. #822Azure.GA_2021_03
as obsolete.What's changed since v1.4.1:
What's changed since v1.4.0:
AZURE_PARAMETER_FILE_EXPANSION
configuration option.What's changed since v1.3.2:
Export-AzRuleTemplateData
.-Format File
.Azure.AKS.Version
to 1.20.5. #767What's changed since pre-release v1.4.0-B2105057:
What's changed since pre-release v1.4.0-B2105050:
Azure.AKS.Version
to 1.20.5. #767What's changed since pre-release v1.4.0-B2105044:
What's changed since pre-release v1.4.0-B2105027:
Export-AzRuleTemplateData
.-Format File
.What's changed since pre-release v1.4.0-B2105020:
What's changed since v1.3.2:
What's changed since v1.3.1:
What's changed since v1.3.0:
What's changed since v1.2.1:
Azure.Storage.UseEncryption
as Storage Service Encryption (SSE) is always on. #630Get-AzRuleTemplateLink
. #706azureAllowedRegions
. #737minAKSVersion
. #738What's changed since pre-release v1.3.0-B2104040:
What's changed since pre-release v1.3.0-B2104034:
What's changed since pre-release v1.3.0-B2104023:
azureAllowedRegions
. #737minAKSVersion
. #738What's changed since pre-release v1.3.0-B2104013:
What's changed since pre-release v1.3.0-B2103007:
What's changed since v1.2.0:
Azure.Storage.UseEncryption
as Storage Service Encryption (SSE) is always on. #630Get-AzRuleTemplateLink
. #706What's changed since v1.2.0:
What's changed since v1.1.4:
Azure.GA_2021_03
baseline. #673Azure.GA_2020_12
as obsolete.Azure.AKS.Version
to 1.19.7. #696What's changed since pre-release v1.2.0-B2103044:
What's changed since pre-release v1.2.0-B2103032:
Azure.GA_2021_03
baseline. #673Azure.GA_2020_12
as obsolete.Azure.AKS.Version
to 1.19.7. #696What's changed since pre-release v1.2.0-B2103024:
What's changed since v1.1.4:
What's changed since v1.1.3:
What's changed since v1.1.2:
What's changed since v1.1.1:
What's changed since v1.1.0:
What's changed since v1.0.0:
Export-AzRuleTemplateData
supports custom resource group and subscription. #651ResourceGroupName
parameter of Export-AzRuleTemplateData
has been renamed to ResourceGroup
.ResourceGroupName
on Export-AzRuleTemplateData
.minValue
and maxValue
constraints are valid. #637Get-AzRuleTemplateLink
discovers <templateName>.json
from <templateName>.parameters.json
.Azure.VM.ADE
to limit rule to exports only. #644if
condition values evaluation order. #652int
parameters with large values. #653createArray
function with no arguments. #667What's changed since pre-release v1.1.0-B2102034:
What's changed since pre-release v1.1.0-B2102023:
Get-AzRuleTemplateLink
discovers <templateName>.json
from <templateName>.parameters.json
.createArray
function with no arguments. #667What's changed since pre-release v1.1.0-B2102015:
Export-AzRuleTemplateData
supports custom resource group and subscription. #651ResourceGroupName
parameter of Export-AzRuleTemplateData
has been renamed to ResourceGroup
.ResourceGroupName
on Export-AzRuleTemplateData
.What's changed since pre-release v1.1.0-B2102010:
if
condition values evaluation order. #652int
parameters with large values. #653What's changed since pre-release v1.1.0-B2102001:
Azure.VM.ADE
to limit rule to exports only. #644What's changed since v1.0.0:
minValue
and maxValue
constraints are valid. #637What's changed since v0.19.0:
Azure.AKS.Version
to 1.19.6. #603Export-AzTemplateRuleData
to Export-AzRuleTemplateData
. #596Export-AzRuleTemplateData
aligns with prefix of other cmdlets.Export-AzTemplateRuleData
is now deprecated and will be removed in the next major version.Export-AzTemplateRuleData
to continue to be used.Export-AzTemplateRuleData
returns a deprecation warning.environment
template function. #517What's changed since pre-release v1.0.0-B2101028:
What's changed since pre-release v1.0.0-B2101016:
Export-AzTemplateRuleData
to Export-AzRuleTemplateData
. #596Export-AzRuleTemplateData
aligns with prefix of other cmdlets.Export-AzTemplateRuleData
is now deprecated and will be removed in the next major version.Export-AzTemplateRuleData
to continue to be used.Export-AzTemplateRuleData
returns a deprecation warning.What's changed since pre-release v1.0.0-B2101006:
Azure.FrontDoor.ProbePath
so the probe name is included. #617What's changed since v0.19.0:
Azure.AKS.Version
to 1.19.6. #603environment
template function. #517PSRule for Azure is a pre-built set of tests and documentation to help you configure Azure solutions. These tests allow you to check your Infrastructure as Code (IaC) before or after deployment to Azure. PSRule for Azure includes unit tests that check how Azure resources defined in ARM templates or Bicep code are configured.
"},{"location":"about/#why-use-psrule-for-azure","title":"Why use PSRule for Azure?","text":"PSRule for Azure helps you identify changes to improve the quality of solutions deployed on Azure. PSRule for Azure uses the principles of the Azure Well-Architected Framework (WAF) to:
If you want to write your own tests, you can do that too in your choice of YAML, JSON, or PowerShell. However with over 400 tests already built, you can identify and fix issues day one.
Get started with a sample repository
To get started with a sample repository, see PSRule for Azure Quick Start on GitHub.
"},{"location":"about/#introducing-psrule-for-azure","title":"Introducing PSRule for Azure","text":"An introduction to PSRule for Azure and how it relates to the Azure Well-Architected Framework. We also give an quick overview of baselines, handling exceptions, and reporting options.
"},{"location":"about/#who-uses-psrule-for-azure","title":"Who uses PSRule for Azure?","text":"Several first-party repositories use PSRule for Azure. Here's a few you may be familiar with:
The current state of Azure resources can be tested with PSRule for Azure, referred to as in-flight analysis. This is a two step process that works in high security environments with separation of roles.
Abstract
This topics covers how you can test the state of deployed Azure resources that have been exported.
Important
This step requires that you have already exported the state of deployed Azure resources. Before continuing, complete Exporting rule data for the resources that will be tested.
"},{"location":"analyzing-resources/#analyzing-exported-state","title":"Analyzing exported state","text":"The state of resources can be analyzed for exported state by using the Invoke-PSRule
PowerShell cmdlet.
For example:
Invoke-PSRule -InputPath 'out/' -Module 'PSRule.Rules.Azure';\n
To filter results to only failed rules, use Invoke-PSRule -Outcome Fail
. Passed, failed and error results are shown by default.
For example:
# Only show failed results\nInvoke-PSRule -InputPath 'out/' -Module 'PSRule.Rules.Azure' -Outcome Fail;\n
The output of this example is:
TargetName: storage\n\nRuleName Outcome Recommendation\n-------- ------- --------------\nAzure.Storage.UseReplication Fail Storage accounts not using GRS may be at risk\nAzure.Storage.SecureTransferRequ... Fail Storage accounts should only accept secure traffic\nAzure.Storage.SoftDelete Fail Enable soft delete on Storage Accounts\n
A summary of results can be displayed by using Invoke-PSRule -As Summary
.
For example:
# Display as summary results\nInvoke-PSRule -InputPath 'out/' -Module 'PSRule.Rules.Azure' -As Summary;\n
The output of this example is:
RuleName Pass Fail Outcome\n-------- ---- ---- -------\nAzure.ACR.MinSku 0 1 Fail\nAzure.AppService.PlanInstanceCount 0 1 Fail\nAzure.AppService.UseHTTPS 0 2 Fail\nAzure.Resource.UseTags 73 36 Fail\nAzure.SQL.ThreatDetection 0 1 Fail\nAzure.SQL.Auditing 0 1 Fail\nAzure.Storage.UseReplication 1 7 Fail\nAzure.Storage.SecureTransferRequ... 2 6 Fail\nAzure.Storage.SoftDelete 0 8 Fail\n
"},{"location":"analyzing-resources/#ignoring-rules","title":"Ignoring rules","text":"To prevent a rule executing you can either:
To exclude a rule, set Rule.Exclude
option within the ps-rule.yaml
file.
Docs
rule:\n exclude:\n # Ignore the following rules for all resources\n - Azure.VM.UseHybridUseBenefit\n - Azure.VM.Standalone\n
To suppress a rule, set Suppression
option within the ps-rule.yaml
file.
Docs
suppression:\n Azure.AKS.AuthorizedIPs:\n # Exclude the following externally managed AKS clusters\n - aks-cluster-prod-eus-001\n Azure.Storage.SoftDelete:\n # Exclude the following non-production storage accounts\n - storagedeveus6jo36t\n - storagedeveus1df278\n
Tip
Use comments within ps-rule.yaml
to describe the reason why rules are excluded or suppressed. Meaningful comments help during peer review within a Pull Request (PR). Also consider including a date if the exclusions or suppressions are temporary.
Docs
PSRule for Azure comes with many configuration options. The setup section explains in detail how to configure each option.
"},{"location":"creating-your-pipeline/","title":"Creating your pipeline","text":"Abstract
This topic covers how you can configuration continuous integration (CI) pipelines to tests Bicep and ARM templates automatically.
You can use PSRule for Azure to validate Azure resources throughout their lifecycle. By using validation within a continuous integration (CI) pipeline, any issues provide fast feedback.
Within the root directory of your infrastructure as code repository:
GitHub ActionsAzure PipelinesGeneric with PowerShellCreate a new GitHub Actions workflow by creating .github/workflows/analyze-arm.yaml
.
name: Analyze templates\non:\n push:\n branches:\n - main\n pull_request:\n branches:\n - main\njobs:\n analyze_arm:\n name: Analyze templates\n runs-on: ubuntu-latest\n steps:\n - name: Checkout\n uses: actions/checkout@v3\n\n # Analyze Azure resources using PSRule for Azure\n - name: Analyze Azure template files\n uses: microsoft/ps-rule@v2.9.0\n with:\n modules: 'PSRule.Rules.Azure'\n
Create a new Azure DevOps YAML pipeline by creating .azure-pipelines/analyze-arm.yaml
.
steps:\n\n# Analyze Azure resources using PSRule for Azure\n- task: ps-rule-assert@2\n displayName: Analyze Azure template files\n inputs:\n modules: 'PSRule.Rules.Azure'\n
Create a pipeline in any CI environment by using PowerShell.
# Analyze Azure resources using PSRule for Azure\n$modules = @('PSRule.Rules.Azure')\nInstall-Module -Name $modules -Scope CurrentUser -Force -ErrorAction Stop;\nAssert-PSRule -InputPath '.' -Module $modules -Format File -ErrorAction Stop;\n
This will automatically install compatible versions of all dependencies.
Tip
If this is your first time implementing PSRule for Azure on a live repository, you may want to consider setting continue on error. This will allow you to try out PSRule without preventing pull requests (PRs) from being merged.
"},{"location":"creating-your-pipeline/#parameters","title":"Parameters","text":"Several parameters are available to customize the behavior of the pipeline. In addition, many of these parameters are also available as configuration options configurable within ps-rule.yaml
.
Some of the most common parameters are listed below. For a full list of parameters see the readme for GitHub Actions or Azure Pipelines.
"},{"location":"creating-your-pipeline/#limiting-input-to-a-specific-path","title":"Limiting input to a specific path","text":"By default, PSRule will scan all files and folders within the repository or current working path. You can use the inputPath
parameter to limit the analysis to a specific file or directory path.
Tip
The inputPath
parameter only accepts a relative path. Both file and directory paths are supported. For example: azure/modules/
if you have a azure/modules/
directory in the root of your repository. Be careful not to specify a leading /
such as /azure/modules/
. On Linux /
is the root directory, which makes this a fully qualified path instead of a relative path.
# Analyze Azure resources using PSRule for Azure\n- name: Analyze Azure template files\n uses: microsoft/ps-rule@v2.9.0\n with:\n modules: 'PSRule.Rules.Azure'\n inputPath: azure/modules/\n
# Analyze Azure resources using PSRule for Azure\n- task: ps-rule-assert@2\n displayName: Analyze Azure template files\n inputs:\n modules: 'PSRule.Rules.Azure'\n inputPath: azure/modules/\n
# Analyze Azure resources using PSRule for Azure\n$modules = @('PSRule.Rules.Azure')\nInstall-Module -Name $modules -Scope CurrentUser -Force -ErrorAction Stop;\nAssert-PSRule -InputPath 'azure/modules/' -Module $modules -Format File -ErrorAction Stop;\n
"},{"location":"creating-your-pipeline/#configuring-a-baseline","title":"Configuring a baseline","text":"You can set the baseline
parameter to specify the name of a baseline to use. A baseline is a set of rules and configuration. PSRule for Azure ships with multiple baselines to choose from. See working with baselines for more information.
# Analyze Azure resources using PSRule for Azure\n- name: Analyze Azure template files\n uses: microsoft/ps-rule@v2.9.0\n with:\n modules: 'PSRule.Rules.Azure'\n baseline: Azure.GA_2023_09\n
# Analyze Azure resources using PSRule for Azure\n- task: ps-rule-assert@2\n displayName: Analyze Azure template files\n inputs:\n modules: 'PSRule.Rules.Azure'\n baseline: Azure.GA_2023_09\n
# Analyze Azure resources using PSRule for Azure\n$modules = @('PSRule.Rules.Azure')\nInstall-Module -Name $modules -Scope CurrentUser -Force -ErrorAction Stop;\nAssert-PSRule -InputPath '.' -Baseline 'Azure.GA_2023_09' -Module $modules -Format File -ErrorAction Stop;\n
"},{"location":"creating-your-pipeline/#continue-on-error","title":"Continue on error","text":"By default, PSRule breaks or stops the pipeline if any rules fail or errors occur. When adopting PSRule for Azure or a new baseline you may want to run PSRule without stopping the pipeline.
To do this, configure the PSRule for Azure step to continue on error.
GitHub ActionsAzure PipelinesGeneric with PowerShellSet the continue-on-error
property to true
.
# Analyze Azure resources using PSRule for Azure\n- name: Analyze Azure template files\n uses: microsoft/ps-rule@v2.9.0\n continue-on-error: true\n with:\n modules: 'PSRule.Rules.Azure'\n
Set the continueOnError
property to true
.
# Analyze Azure resources using PSRule for Azure\n- task: ps-rule-assert@2\n displayName: Analyze Azure template files\n continueOnError: true\n inputs:\n modules: 'PSRule.Rules.Azure'\n
Set the ErrorAction
parameter of Assert-PSRule
to Continue
.
# Analyze Azure resources using PSRule for Azure\n$modules = @('PSRule.Rules.Azure')\nInstall-Module -Name $modules -Scope CurrentUser -Force -ErrorAction Stop;\nAssert-PSRule -InputPath '.' -Module $modules -Format File -ErrorAction Continue;\n
"},{"location":"creating-your-pipeline/#adding-additional-modules","title":"Adding additional modules","text":"You can add additional modules to the modules
parameter by using comma (,
) separating each module name.
# Analyze Azure resources using PSRule for Azure\n- name: Analyze Azure template files\n uses: microsoft/ps-rule@v2.9.0\n with:\n modules: 'PSRule.Rules.Azure,PSRule.Monitor'\n
# Analyze Azure resources using PSRule for Azure\n- task: ps-rule-assert@2\n displayName: Analyze Azure template files\n inputs:\n modules: 'PSRule.Rules.Azure,PSRule.Monitor'\n
# Analyze Azure resources using PSRule for Azure\n$modules = @('PSRule.Rules.Azure', 'PSRule.Monitor')\nInstall-Module -Name $modules -Scope CurrentUser -Force -ErrorAction Stop;\nAssert-PSRule -InputPath '.' -Module $modules -Format File -ErrorAction Stop;\n
"},{"location":"creating-your-pipeline/#outputting-results","title":"Outputting results","text":"You can configure PSRule to output results into a file by using the outputFormat
and outputPath
parameters. For details on the formats that are supported see analysis output.
# Analyze Azure resources using PSRule for Azure\n- name: Analyze Azure template files\n uses: microsoft/ps-rule@v2.9.0\n with:\n modules: 'PSRule.Rules.Azure'\n outputFormat: Sarif\n outputPath: reports/ps-rule-results.sarif\n
# Analyze Azure resources using PSRule for Azure\n- task: ps-rule-assert@2\n displayName: Analyze Azure template files\n inputs:\n modules: 'PSRule.Rules.Azure'\n outputFormat: Sarif\n outputPath: reports/ps-rule-results.sarif\n
# Analyze Azure resources using PSRule for Azure\n$modules = @('PSRule.Rules.Azure')\nInstall-Module -Name $modules -Scope CurrentUser -Force -ErrorAction Stop;\nAssert-PSRule -InputPath '.' -OutputFormat 'Sarif' -OutputPath 'reports/ps-rule-results.sarif' -Module $modules -Format File -ErrorAction Stop;\n
"},{"location":"creating-your-pipeline/#configuration","title":"Configuration","text":"Configuration options for PSRule for Azure are set within the ps-rule.yaml
file. To set options, create a new file named ps-rule.yaml
in the root directory of your repository.
Tip
This file should be committed to your repository so it is available when your pipeline runs.
"},{"location":"creating-your-pipeline/#expand-template-parameter-files","title":"Expand template parameter files","text":"Docs
PSRule for Azure can automatically expand Azure template parameter files. When enabled, PSRule for Azure automatically resolves parameter and template file context at runtime.
To enabled this feature, set the Configuration.AZURE_PARAMETER_FILE_EXPANSION
option to true
. This option can be set within the ps-rule.yaml
file.
configuration:\n # Enable automatic expansion of Azure parameter files\n AZURE_PARAMETER_FILE_EXPANSION: true\n
"},{"location":"creating-your-pipeline/#expand-bicep-source-files","title":"Expand Bicep source files","text":"Docs
PSRule for Azure can automatically expand Bicep source files. When enabled, PSRule for Azure automatically expands and analyzes Azure resource from .bicep
files.
To enabled this feature, set the Configuration.AZURE_BICEP_FILE_EXPANSION
option to true
. This option can be set within the ps-rule.yaml
file.
configuration:\n # Enable automatic expansion of bicep source files\n AZURE_BICEP_FILE_EXPANSION: true\n
"},{"location":"creating-your-pipeline/#advanced-configuration","title":"Advanced configuration","text":"Docs
PSRule for Azure comes with many configuration options. The setup section explains in detail how to configure each option.
"},{"location":"creating-your-pipeline/#recommended-content","title":"Recommended content","text":"Using Bicep source
The following configuration options will be renamed in upcoming releases of PSRule for Azure. This is part of a ongoing effort to align the naming of configuration options across PSRule for Azure.
We plan to have all the old option names renamed and they will not longer work from v2. To upgrade use the new names instead. Until v2, the old option names are still work and will take precedence if new and old are configured.
New name Old name Available fromAZURE_AKS_CLUSTER_MINIMUM_VERSION
Azure_AKSMinimumVersion
v1.12.0 AZURE_AKS_POOL_MINIMUM_MAXPODS
Azure_AKSNodeMinimumMaxPods
TBA - not available AZURE_RESOURCE_ALLOWED_LOCATIONS
Azure_AllowedRegions
v1.30.0 AZURE_APIM_MINIMUM_CERTIFICATE_LIFETIME
Azure_MinimumCertificateLifetime
TBA - not available Note
Configuration options marked TBA are not available yet. Please use the old names until they are available. Check the change log and the upgrade notes for more information on a future release.
Important
New option names will work from the release specified by Available from. Configuring these options prior to that release will have no affect. For details on configuring these options see upgrade notes for details.
"},{"location":"deprecations/#realignment-of-rule-names-for-network-interfaces","title":"Realignment of rule names for network interfaces","text":"Orginally when many of the rules targeting network interfaces were created, network interfaces only applied to virtual machines. Today, network interfaces can be attached to different types of resources including:
To better reflect that network interfaces are not only related to VMs, the following rules have been renamed:
Azure.VM.NICAttached
to Azure.NIC.Attached
.Azure.VM.NICName
to Azure.NIC.Name
.Azure.VM.UniqueDns
to Azure.NIC.UniqueDns
.Aliases have been added to ensure any existing suppression and exclusion to these rules continues to work.
From v2.0.0 these aliases will no longer work.
To update your configuration, use the new rule names instead. Possible locations where the old rule names may be used include:
suppression
option defined within ps-rule.yaml
or by using New-PSRuleOption
.rule.exclude
or rule.include
option defined within ps-rule.yaml
or by using New-PSRuleOption
.rule.exclude
or rule.include
option defined within a custom baseline.PSRule for Azure supports analyzing resources contained within Azure Infrastructure as Code.
Abstract
This topic covers what source expansion is, why it's important, and how to use it within PSRule for Azure.
"},{"location":"expanding-source-files/#source-expansion","title":"Source expansion","text":"PSRule for Azure goes beyond linting Azure Bicep and template files for syntax. Source expansion performs context specific static analysis on Azure resources. Azure resources are analyzed before deployment as if they are deployed.
This provides some unique benefits such as:
reference
, list*
.Source expansion is supported with:
.bicep
extension are detected and expanded. See Using Bicep source for a detailed explanation of how to do this.Azure Bicep modules with tests \u2014 Reusable Bicep modules can be expanded with tests. See Using Bicep source for a detailed explanation of how to do this.
Currently the following limitations apply:
environment()
template function always returns values for Azure public cloud.reference()
function will return objects for resources within the same template. For resources that are not in the same template, a placeholder value is used instead.In addition, currently the following limitation apply to using Bicep source files:
Expansion of Bicep source files times out after 5 seconds by default. The timeout can be overridden by setting the AZURE_BICEP_FILE_EXPANSION_TIMEOUT option.
String parameters are commonly used to pass values such as a resource Id or location. PSRule for Azure provides additional support to allow parameters to be strongly typed. When a parameter is strongly typed, the value is checked against the type during expansion.
To configure a strong type for a parameter set the strongType
metadata property on the parameter. The strong type will be set to the resource type that the parameter will accept, such as Microsoft.OperationalInsights/workspaces
.
{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"workspaceId\": {\n \"type\": \"string\",\n \"metadata\": {\n \"description\": \"The resource identifier for a Log Analytics workspace.\",\n \"strongType\": \"Microsoft.OperationalInsights/workspaces\"\n }\n }\n }\n}\n
@metadata({\n strongType: 'Microsoft.OperationalInsights/workspaces'\n})\n@description('The resource identifier for a Log Analytics workspace.')\nparam workspaceId string\n
Strong type also supports the following non-resource type values:
location
- Specifies the parameter must contain any valid Azure location.Azure deployments support a number of scope functions can be used within Infrastructure as Code. When using PSRule for Azure, these functions have a default meaning that can be configured.
When configuring scope functions, only the properties you want to override has to be specified. Unspecified properties will inherit from the defaults.
"},{"location":"expanding-source-files/#subscription","title":"Subscription","text":"The subscription()
function will return the following unless overridden:
subscriptionId: 'ffffffff-ffff-ffff-ffff-ffffffffffff'\ndisplayName: 'PSRule Test Subscription'\nstate: 'NotDefined'\n
To override, configure AZURE_SUBSCRIPTION
.
The resourceGroup()
function will return the following unless overridden:
name: 'ps-rule-test-rg'\nlocation: 'eastus'\ntags: { }\nproperties:\n provisioningState: 'Succeeded'\n
To override, configure AZURE_RESOURCE_GROUP
.
The tenant()
function will return the following unless overridden:
countryCode: 'US'\ntenantId: 'ffffffff-ffff-ffff-ffff-ffffffffffff'\ndisplayName: 'PSRule'\n
To override, configure AZURE_TENANT
.
The managementGroup()
function will return the following unless overridden:
name: 'psrule-test'\nproperties:\n displyName: 'PSRule Test Management Group'\n
To override, configure AZURE_MANAGEMENT_GROUP
.
The current state of Azure resources can be tested with PSRule for Azure, referred to as in-flight analysis. This is a two step process that works in high security environments with separation of roles.
Abstract
This topics covers how you can export the current state of Azure resources deployed into a subscription. After the current state has been exported, offline analysis can be performed against the saved state.
Important
Before continuing, complete the steps from Installing locally. To export data from a subscription, Azure PowerShell modules must be installed. Exporting rule data can also be automated and scheduled with Azure Automation Service. However, for this scenario we will focus how to run this process interactively.
To perform analysis on Azure resources the current configuration state is exported to a JSON file format. The exported state is processed later during analysis.
What's not exported \u2014 Resource data such as:
The state of resources from the current Azure subscription will be exported by using the following commands:
# STEP 1: Authenticate to Azure, only required if not currently connected\nConnect-AzAccount;\n\n# STEP 2: Confirm the current subscription context\nGet-AzContext;\n\n# STEP 3: Exports Azure resources to JSON files\nExport-AzRuleData -OutputPath 'out/';\n
"},{"location":"export-rule-data/#additional-options","title":"Additional options","text":"By default, resource data for the current subscription context will be exported.
To export resource data for specific subscriptions use:
-Subscription
- to specify subscriptions by id or name.-Tenant
- to specify subscriptions within an Azure Active Directory Tenant by id.For example:
# Export data from two specific subscriptions\nExport-AzRuleData -Subscription 'Contoso Production', 'Contoso Non-production';\n
To export specific resource data use:
-ResourceGroupName
- to filter resources by Resource Group.-Tag
- to filter resources based on tag.For example:
# Export information from two resource groups within the current subscription context\nExport-AzRuleData -ResourceGroupName 'rg-app1-web', 'rg-app1-db';\n
To export resource data for all subscription contexts use:
-All
- to export resource data for all subscription contexts.For example:
# Export data from all subscription contexts\nExport-AzRuleData -All;\n
"},{"location":"faq/","title":"Frequently Asked Questions (FAQ)","text":"Continue reading for FAQ relating to PSRule for Azure. For general FAQ see PSRule - Frequently Asked Questions (FAQ), including:
Note
If you have a question that is not answered here, please join or start a discussion.
"},{"location":"faq/#what-is-a-rule","title":"What is a rule?","text":"A rule is a named set of checks and documentation. You can find the documentation for each rule under reference.
"},{"location":"faq/#what-is-a-baseline","title":"What is a baseline?","text":"A baseline combines rules and configuration. PSRule for Azure provides several baselines that can be referenced when running PSRule. Quarterly baselines provide a stable checkpoint of rules when you need to stagger adoption of new rules.
Continue reading working with baselines for a detailed breakdown.
"},{"location":"faq/#is-terraform-supported","title":"Is Terraform supported?","text":"Currently PSRule for Azure supports testing Azure resources from Infrastructure as Code (IaC) with:
Checking Terraform from HashiCorp Configuration Language (HCL) is not supported at this time. If this feature is important to you, please upvote \ud83d\udc4d the issue on GitHub.
What is supported? After resources are deployed to Azure, PSRule for Azure can be used to check the Azure resources in-flight.
This methods works for Azure resources regardless of how they are deployed. Use this method for analyzing resources deployed via the Azure Portal, Terraform, Pulumi, or other tools.
For instructions on how to do this see Exporting rule data.
"},{"location":"faq/#what-methods-are-supported-for-checking-resources","title":"What methods are supported for checking resources?","text":"PSRule for Azure supports two methods for analyzing Azure resources:
In-flight \u2014 After resources are deployed to an Azure subscription. Use in-flight analysis to:
PSRule for Azure covers common use cases that align to the Microsoft Azure Well-Architected Framework. Use of resource and resource group tags is recommended in the WAF, however implementation may vary. You may want to use PSRule to enforce tagging or something similar early in a DevOps pipeline.
We have a walk through scenario Enforcing custom tags to get you started.
"},{"location":"faq/#how-do-i-create-a-custom-rule-to-enforce-code-ownership","title":"How do I create a custom rule to enforce code ownership?","text":"GitHub, Azure DevOps, and other DevOps platforms may implement code ownership. This process involves assigning a team or an individual review and approval responsibility. In GitHub or Azure DevOps implementation, ownership is linked to the file path.
When a repository contains resources that different teams would approve how do you:
We have a walk through scenario Enforcing code ownership to get you started.
"},{"location":"faq/#do-you-have-sample-code","title":"Do you have sample code?","text":"In addition to the walk through scenarios, we have a quick start template here. The repository contains sample ARM templates, Bicep, and pipeline code to get you started.
In GitHub you can simply use the repository as a template for your own project.
"},{"location":"faq/#do-i-need-powershell-experience-to-start-using-psrule-for-azure","title":"Do I need PowerShell experience to start using PSRule for Azure?","text":"No. You can start using built-in rules and CI with Azure Pipelines or GitHub Actions. If we didn't tell you, you might not even know that PowerShell runs under the covers.
To perform local validation, some PowerShell setup is required but we step you through that. See How to install PSRule for Azure for details.
To start writing your own custom rules you can use YAML, JSON, or PowerShell. PowerShell experience is required for some scenarios. We have a walk through scenario Enforcing custom tags to get you started.
"},{"location":"faq/#what-permissions-do-i-need-to-export-rule-data","title":"What permissions do I need to export rule data?","text":"When exporting data for in-flight analysis, the default built-in Reader role to a subscription is required for:
Export-AzRuleData
.Export-AzRuleTemplateData
when online features are used.-ResourceGroupName
and -Subscription
parameter can be used; these require access Reader access.When exporting data for in-flight analysis, no access to Azure is required after data has been exported to JSON.
"},{"location":"faq/#should-i-continue-to-use-azure-advisor-defender-for-cloud-or-azure-policy","title":"Should I continue to use Azure Advisor, Defender for Cloud, or Azure Policy?","text":"Absolutely. PSRule for Azure does not replace Azure Advisor, Microsoft Defender for Cloud, or Azure Policy.
PSRule complements Azure Advisor, Microsoft Defender for Cloud, and Azure Policy features by:
PSRule for Azure annotates rules with three (3) severities which indicate how you should prioritize remediation. The following severities are defined:
Critical
\u2014 Consider addressing these first, ideally within the next thirty (30) days. Rules identified as critical often have high impact and are highly likely to affect your services.Important
\u2014 Consider addressing these next, ideally within the next sixty (60) days. Rules identified as important often have a significant impact and are likely to affect your services.Awareness
\u2014 Consider addressing these last, ideally within the next ninety (90) days. Rules identified as awareness often have a moderate or low impact to the operation of your services.Tip
Severities and suggested time frames are an indicator only. They may affect your environment, compliance, or security differently based on your specific requirements. If you feel the severity for a rule is broadly incorrect then please let as know. You can do this by joining or starting a discussion.
Additionally, PSRule for Azure uses three (3) rule levels. These levels determine how PSRule provides feedback about failing cases. The following levels are defined:
Error
\u2014 Rules defined as error will stop CI pipelines that are configured to break on error.Warning
\u2014 Rules defined as warning will not stop CI pipelines and will produce a warning.Information
\u2014 Rules defined as information will not stop CI pipelines.PSRule for Azure uses semantic versioning to declare breaking changes.
The latest module version can be installed from the PowerShell Gallery and NuGet. For a list of module changes please see the change log.
For more information on how we handles versioning and changes see Changes and versioning.
"},{"location":"faq/#traditional-unit-testing-vs-psrule-for-azure","title":"Traditional unit testing vs PSRule for Azure?","text":"You may already be using a unit test framework such as Pester to test infrastructure code. If you are, then you may have encountered the following challenges.
For a general PSRule/ Pester comparison see How is PSRule different to Pester?
"},{"location":"faq/#unit-testing-more-than-basic-json-structure","title":"Unit testing more than basic JSON structure","text":"Unit tests are unable to effectively test resources contained within Azure templates. Templates should be reusable, but this creates problems for testing when functions, conditions and copy loops are used. Template parameters could completely change the type, number of, or configuration of resources.
PSRule resolves templates to allow analysis of the resources that would be deployed based on provided parameters.
"},{"location":"faq/#standard-library-of-tests","title":"Standard library of tests","text":"When building unit tests for Azure resources, starting with an empty repository can be a daunting experience. While there are several open source repositories and samples around to get you started, you need to integrate these yourself.
PSRule for Azure is distributed as a PowerShell module using the PowerShell Gallery. Using a PowerShell module makes it easy to install and update. The built-in rules allow you starting testing resources quickly, with minimal integration.
For detailed examples see:
PSRule and PSRule for Azure currently do not collect any telemetry during installation or execution.
PowerShell (used by PSRule for Azure) does collect basic telemetry by default. Collection of telemetry in PowerShell and how to opt-out is explained in about_Telemetry.
"},{"location":"features/","title":"Features","text":""},{"location":"features/#learn-by-example","title":"Learn by example","text":"PSRule for Azure helps you quickly identify and fix issues to improve the quality of solutions deployed on Azure. Tests include documentation with official documentation references and examples. Use the Azure Bicep or template examples to adapt your solution to recommendations.
Note
Start exploring the list of rules included with PSRule for Azure.
"},{"location":"features/#framework-aligned","title":"Framework aligned","text":"PSRule for Azure is aligned to the Azure Well-Architected Framework (WAF). Tests called rules check the configuration of Azure resources against WAF principles. Rules exist across five (5) WAF pillars:
To help you align your Infrastructure as Code (IaC) to WAF principles, PSRule for Azure includes documentation. Included are examples, references to WAF and product documentation. This allows you to explore and learn the context of each WAF principle.
"},{"location":"features/#start-day-one","title":"Start day one","text":"PSRule for Azure includes over 400 rules for validating resources against configuration recommendations. Rules automatically detect and analyze resources from Azure IaC artifacts. This allows you to quickly light up unit testing of Azure resources from templates and Bicep deployments.
Use the built-in rules to start enforcing testing quickly. Then layer on your own rules as your organization's requirements mature. Custom rules can be implemented quickly and work side-by-side with built-in rules.
As new built-in rules are added and improved, download the latest version to start using them.
Tip
For detailed information on building custom rules see:
Azure resources can be validated throughout their lifecycle to support a DevOps culture. Start testing your Bicep and ARM templates from code by validating them offline before deployment.
Pre-flight validation can be integrated into a continuous integration (CI) pipeline as unit tests to:
Learn
You can learn more about Azure Bicep with the following links:
PSRule for Azure uses modern PowerShell libraries at its core, allowing it to go anywhere PowerShell can go. PSRule for Azure runs on MacOS, Linux, and Windows.
PowerShell makes it easy to integrate PSRule into popular CI systems. Run natively or in a container depending on your platform. PSRule has native extensions for:
Additionally, PSRule for Azure can be installed locally or within Azure Cloud Shell. For installation options see installation.
"},{"location":"install/","title":"How to install PSRule for Azure","text":"PSRule for Azure supports running within continuous integration (CI) systems or locally. It is shipped as a PowerShell module which makes it easy to install and distribute updates.
Task Options Run tests within CI pipelines With GitHub Actions or Azure Pipelines or PowerShell Run tests locally during development With Visual Studio Code and PowerShell Create custom tests for your organization With Visual Studio Code and PowerShellTip
PSRule for Azure provides native integration to popular CI systems such as GitHub Actions and Azure Pipelines. If you are using a different CI system you can use the local install to run on MacOS, Linux, and Windows worker nodes.
"},{"location":"install/#with-github-actions","title":"With GitHub Actions","text":"GitHub Action
Install and use PSRule for Azure with GitHub Actions by referencing the microsoft/ps-rule
action.
Install the latest stable version of PSRule for Azure.
GitHub Actions- name: Analyze Azure template files\n uses: microsoft/ps-rule@v2.9.0\n with:\n modules: 'PSRule.Rules.Azure'\n
Install the latest stable or pre-release version of PSRule for Azure.
GitHub Actions- name: Analyze Azure template files\n uses: microsoft/ps-rule@v2.9.0\n with:\n modules: 'PSRule.Rules.Azure'\n prerelease: true\n
This will automatically install compatible versions of all dependencies.
Note
For additional examples on commonly configured parameters see Creating your pipeline.
"},{"location":"install/#with-azure-pipelines","title":"With Azure Pipelines","text":"Extension
Install and use PSRule for Azure with Azure Pipeline by using extension tasks. Install the extension from the marketplace, then use the ps-rule-assert
task in pipeline steps.
Install the latest stable version of PSRule for Azure.
Azure Pipelines- task: ps-rule-assert@2\n displayName: Analyze Azure template files\n inputs:\n modules: 'PSRule.Rules.Azure'\n
Install the latest stable or pre-release version of PSRule for Azure.
Azure Pipelines- task: ps-rule-install@2\n displayName: Install PSRule for Azure (pre-release)\n inputs:\n module: PSRule.Rules.Azure\n prerelease: true\n\n- task: ps-rule-assert@2\n displayName: Analyze Azure template files\n inputs:\n modules: 'PSRule.Rules.Azure'\n
This will automatically install compatible versions of all dependencies.
Note
For additional examples on commonly configured parameters see Creating your pipeline.
"},{"location":"install/#with-visual-studio-code","title":"With Visual Studio Code","text":"Extension
An extension for Visual Studio Code is available. The Visual Studio Code extension includes a built-in task to test locally and configuration schemas.
To learn about Visual Studio Code support see the marketplace extension.
For best results, configure the PSRule.Rules.Azure
module using ps-rule.yaml
by setting requires
and include
options.
requires:\n PSRule.Rules.Azure: '>=1.29.0'\n\ninclude:\n module:\n - PSRule.Rules.Azure\n
Note
Currently the Visual Studio Code extension relies on PSRule for Azure installed by PowerShell.
"},{"location":"install/#with-powershell","title":"With PowerShell","text":"PSRule for Azure can be installed locally from the PowerShell Gallery using PowerShell. You can also use this option to install on CI workers that are not natively supported.
"},{"location":"install/#prerequisites","title":"Prerequisites","text":"Operating System Tool Installation Link Windows Windows PowerShell 5.1 with .NET Framework 4.7.2 or greater. link Windows, MacOS, Linux PowerShell version 7.2.x or greater. linkTo use PSRule for Azure, PSRule a separate PowerShell module must be installed. The required version will automatically be installed along-side PSRule for Azure.
Additionally, the exporting data from a subscription functionality requires the additional PowerShell modules:
Note
Azure PowerShell modules are not installed automatically when installing PSRule for Azure. This has been changed from v1.16.0 due to module dependency chains in Azure DevOps. In most cases these modules will be pre-installed on the CI worker. For private CI workers, consider pre-installing these modules in a previous step.
"},{"location":"install/#installing-powershell","title":"Installing PowerShell","text":"PowerShell 7.x can be installed on MacOS, Linux, and Windows but is not installed by default. For a list of platforms that PowerShell 7.2 is supported on and install instructions see Get PowerShell.
"},{"location":"install/#getting-the-modules","title":"Getting the modules","text":"Module
PSRule for Azure can be installed or updated from the PowerShell Gallery. Use the following command line examples from a PowerShell terminal to install or update PSRule for Azure.
For the current userFor all usersTo install PSRule for Azure for the current user use:
Install-Module -Name 'PSRule.Rules.Azure' -Repository PSGallery -Scope CurrentUser\n
To update PSRule for Azure for the current user use:
Update-Module -Name 'PSRule.Rules.Azure' -Scope CurrentUser\n
This will automatically install compatible versions of all dependencies.
To install PSRule for Azure for all users (requires admin/ root permissions) use:
Install-Module -Name 'PSRule.Rules.Azure' -Repository PSGallery -Scope AllUsers\n
To update PSRule for Azure for all users (requires admin/ root permissions) use:
Update-Module -Name 'PSRule.Rules.Azure' -Scope AllUsers\n
This will automatically install compatible versions of all dependencies.
"},{"location":"install/#pre-release-versions","title":"Pre-release versions","text":"To use a pre-release version of PSRule for Azure add the -AllowPrerelease
switch when calling Install-Module
, Update-Module
, or Save-Module
cmdlets.
Tip
To install pre-release module versions, the latest version of PowerShellGet may be required.
# Install the latest PowerShellGet version\nInstall-Module -Name PowerShellGet -Repository PSGallery -Scope CurrentUser -Force\n
Tip
To install a pre-release version of PSRule and PSRule for Azure, install each in separate steps.
For the current userFor all usersTo install PSRule for Azure for the current user use:
Install-Module -Name PowerShellGet -Repository PSGallery -Scope CurrentUser -Force\nInstall-Module -Name PSRule -Repository PSGallery -Scope CurrentUser -AllowPrerelease\nInstall-Module -Name PSRule.Rules.Azure -Repository PSGallery -Scope CurrentUser -AllowPrerelease\n
Open PowerShell with Run as administrator on Windows or sudo pwsh
on Linux.
To install PSRule for Azure for all users (requires admin/ root permissions) use:
Install-Module -Name PowerShellGet -Repository PSGallery -Scope CurrentUser -Force\nInstall-Module -Name PSRule -Repository PSGallery -Scope AllUsers -AllowPrerelease\nInstall-Module -Name PSRule.Rules.Azure -Repository PSGallery -Scope AllUsers -AllowPrerelease\n
"},{"location":"install/#building-from-source","title":"Building from source","text":"Source
PSRule for Azure is provided as open source on GitHub. To build PSRule for Azure from source code:
./build.ps1
from a PowerShell terminal in the cloned path.This build script will compile the module and documentation then output the result into out/modules/PSRule.Rules.Azure
.
build.ps1
script - .NET .NET SDK v7 is required. link - Bicep CLI PSRule depends on the Bicep CLI to expand Bicep modules to ARM link The following dependencies will be automatically installed if the required versions are not present:
These dependencies are only required for building and running tests for PSRule for Azure.
"},{"location":"install/#troubleshooting","title":"Troubleshooting","text":"If the ./build.ps1
script fails, you can start troubleshooting this by:
$PSVersionTable.PSVersion
dotnet --list-sdks
command in your terminal.If you are on a network that does not permit Internet access to the PowerShell Gallery, download the required PowerShell modules on an alternative device that has access. PowerShell provides the Save-Module
cmdlet that can be run from a PowerShell terminal to do this.
The following command lines can be used to download the required modules using a PowerShell terminal. After downloading the modules, copy the module directories to devices with restricted Internet access.
Runtime modulesDevelopment modulesTo save PSRule for Azure for offline use:
$modules = @('PSRule', 'PSRule.Rules.Azure', 'Az.Accounts', 'Az.Resources')\nSave-Module -Name $modules -Path '.\\modules'\n
This will save PSRule for Azure and all dependencies into the modules
sub-directory.
To save PSRule for Azure development module dependencies for offline use:
$modules = @('PSRule', 'Az.Accounts', 'Az.Resources', 'PlatyPS', 'Pester',\n 'PSScriptAnalyzer', 'PowerShellGet', 'PackageManagement', 'InvokeBuild')\nSave-Module -Name $modules -Repository PSGallery -Path '.\\modules';\n
This will save required developments dependencies into the modules
sub-directory.
The following tools also take advantage of PSRule for Azure.
"},{"location":"integrations/#azure-governance-visualizer","title":"Azure Governance Visualizer","text":"Docs \u00b7 v6_major_20220521_1
AzGovViz provides a convenient way to view your Azure governance and hierarchy. Additionally you can view recommendations from PSRule as you navigate to each level in your hierarchy.
You can include PSRule recommendations in AzGovViz output by adding the -DoPSRule
command-line switch. This and more is included in the documentation.
Docs \u00b7 v0.3.0
Template Analyzer scans Azure templates and Bicep code to ensure security and best practice checks are being followed before deployment.
By default, Template Analyzer will only include rules aligned to the Security Well-Architected Framework pillar. To include rules from other pillars, use the --include-non-security-rules
command-line switch.
Docs \u00b7 Public Preview
Microsoft Defender for DevOps (DfD) provides unified DevOps security management across multicloud and multiple-pipeline environments.
In this preview, DfD will include PSRule for Azure rules aligned to the Security Well-Architected Framework pillar.
"},{"location":"license-contributing/","title":"License and contributing","text":"PSRule for Azure is licensed with an MIT License, which means it's free to use and modify. But please check out the details.
We open source at Microsoft.
In addition to our team, we hope you will think about contributing too. Here is how you can get started:
Please read our contributing guidelines and code of conduct to learn how to contribute.
"},{"location":"related-projects/","title":"Related projects","text":"The PSRule project is distributed across multiple repositories. You can find out more by visiting each repository.
Name Description microsoft/PSRule Core engine responsible for running rules. microsoft/ps-rule GitHub continious integration using GitHub Actions. microsoft/PSRule-pipelines Azure DevOps continious integration using Azure Pipelines. microsoft/PSRule-vscode Support for running and authoring rules within Visual Studio Code. microsoft/PSRule.Monitor Support for logging PSRule analysis results to Azure Monitor. microsoft/PSRule.Rules.CAF A suite of rules to validate Azure resources against the Cloud Adoption Framework (CAF) using PSRule."},{"location":"samples/","title":"Samples","text":""},{"location":"samples/#quick-start-repository","title":"Quick Start repository","text":"Template
You can clone, download, or use as a template for your own repository. This repository contains the following samples for PSRule for Azure:
PSRule options \u2014 Example options for using PSRule for Azure.
Samples
A community collection of samples for PSRule. This repository includes samples for Azure as well as other use cases.
"},{"location":"support/","title":"Support","text":"This project uses GitHub Issues to track bugs and feature requests. Before logging an issue please see our troubleshooting guide.
Please search the existing issues before filing new issues to avoid duplicates.
Support for this project/ product is limited to the resources listed above.
"},{"location":"troubleshooting/","title":"Troubleshooting","text":"This article provides troubleshooting instructions for common errors.
"},{"location":"troubleshooting/#bicep-compile-errors","title":"Bicep compile errors","text":"When expanding Bicep source files you may get an error including a BCPnnn code similar to the following:
Error
Exception calling \"GetResources\" with \"3\" argument(s): \"Bicep (0.14.46) compilation of '' failed with: Error BCP057: The name \"storageAccountName\" does not exist in the current context.
This error is raised when Bicep fails to compile a source file. To resolve this issue:
az bicep
is not the default, and you may need to set additional options to use it.Tip
From PSRule for Azure v1.25.0 you can configure the minimum version of Bicep CLI required. If an earlier version is detected, PSRule for Azure will generate an error. See Configuring minimum version for details on how to configure this option.
"},{"location":"troubleshooting/#bicep-version","title":"Bicep version","text":"When expanding Bicep source files you may get an error relating to the Bicep version you have installed. For example if you attempt to use a Bicep feature that is not supported by the version used by PSRule for Azure.
Check the Bicep version reported by PSRule supports the Bicep features you are using.
PSRule for Azure uses the Bicep CLI installed on your machine or CI worker. By default, the Bicep CLI binary will be selected by your PATH
environment variable.
Optionally you can configure an alternative Bicep CLI binary to use by either:
true
.For more details on installing and configuring the Bicep CLI, see Setup Bicep.
"},{"location":"troubleshooting/#bicep-features","title":"Bicep features","text":"Generally PSRule for Azure plans to support any language features that are supported by the latest version of Bicep. New language features are often added behind an experimental feature flag for community feedback. Features flagged by Bicep as experimental may not be supported by PSRule for Azure immediately. PSRule for Azure will plan to add support as soon as possible after the feature flag is removed.
If you are using a Bicep feature that is not supported by PSRule for Azure, please join or start a discussion.
"},{"location":"troubleshooting/#bicep-compilation-timeout","title":"Bicep compilation timeout","text":"When expanding Bicep source files you may get an error similar to the following:
Error
Bicep (0.4.1124) compilation of 'C:\\temp\\deploy.bicep' failed with: Bicep compilation hasn't completed within the timeout window. This can be caused by errors or warnings. Check the Bicep output by running bicep build and addressing any issues.
This error is raised when Bicep takes longer then the timeout to build a source file. The default timeout is 5 seconds.
You can take steps to reduce your code complexity and reduce the time a build takes by:
module
calls.To increase the timeout value, set the AZURE_BICEP_FILE_EXPANSION_TIMEOUT
configuration option. See Bicep compilation timeout for details on how to configure this option.
There is a few common causes of this issue including:
inputType: repository
, which is the default value.inputType
set to inputPath
.inputPath
parameter. Setting the inputType
is not a requirement for using the inputPath
parameter. The inputPath
parameter can be used independently.-Format File
parameter.-InputPath
or -f
parameter followed by a file or directory path.Assert-PSRule -Module PSRule.Rules.Azure -Format File -f 'modules/'
.Note
If your pipeline is still not finding any Azure resources, please join or start a discussion.
"},{"location":"troubleshooting/#custom-rules-are-not-running","title":"Custom rules are not running","text":"There is a few common causes of this issue including:
.ps-rule/
directory. This directory is the root for your repository or the current working path by default. On case-sensitive file systems such as Linux, this directory name is case-sensitive. See Storing and naming rules for more information..Rule.ps1
, .Rule.yaml
, or .Rule.jsonc
suffix. On case-sensitive file systems such as Linux, this file suffix is case-sensitive. See Storing and naming rules for more information.-Type
parameter or type
properties in rules definitions, binding must be set. This is automatically configured for PSRule for Azure, however must be set in ps-rule.yaml
for custom rules. See binding type for more information.PSRule.Rules.Azure
must be run with any custom rules. See using templates and using Bicep source for details on how to enable expansion.true
. See Including custom rules for more information.Tip
You may be able to use git mv
to change the case of a file if it is committed to the repository incorrectly.
You may find while editing a .json
parameter file the root metadata
property is flagged with a warning.
Warning
The property 'metadata' is not allowed.
Azure parameter file{\n \"$schema\": \"https://schema.management.azure.com/schemas/2015-01-01/deploymentParameters.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"metadata\": {\n \"template\": \"./storage.template.json\"\n },\n \"parameters\": {\n }\n}\n
This doesn't affect the workings of the parameter file or deployment. The reason for the warning is that the metadata
property has not been added to the parameter file JSON schema. However, the top level metadata
property is ignored by Azure Resource Manager when deploying a template.
When running PSRule for Azure in Azure DevOps within the AzurePowerShell@5
task, you may see the following error.
Error
This module requires Az.Accounts version 2.8.0. An earlier version of Az.Accounts is imported in the current PowerShell session. Please open a new session before importing this module. This error could indicate that multiple incompatible versions of the Azure PowerShell cmdlets are installed on your system. Please see https://aka.ms/azps-version-error for troubleshooting information.
This error is raised by a chained dependency failure importing a newer version of Az.Accounts
. To avoid this issue attempt to install the exact versions of Az.Resources
. In the AzurePowerShell@5
task before installing PSRule.
Install-Module Az.Resources -RequiredVersion '5.6.0' -Force -Scope CurrentUser\n
From PSRule for Azure v1.16.0, Az.Accounts
and Az.Resources
are no longer installed as dependencies. When using export commands from PSRule, you may need to install these modules.
To install these modules, use the following PowerShell command:
Install-Module Az.Resources -Force -Scope CurrentUser\n
"},{"location":"troubleshooting/#could-not-load-file-or-assembly-yamldotnet","title":"Could not load file or assembly YamlDotNet","text":"PSRule >=1.3.0 uses an updated version of the YamlDotNet library. The PSRule for Azure <1.3.1 uses an older version of this library which may conflict.
To avoid this issue:
To install the latest module version of PSRule use the following commands:
Install-Module -Name PSRule.Rules.Azure -MinimumVersion 1.3.1 -Scope CurrentUser -Force;\n
For the PSRule GitHub Action, use >=1.4.0.
- name: Run PSRule analysis\n uses: microsoft/ps-rule@v2.9.0\n
"},{"location":"upgrade-notes/","title":"Upgrade notes","text":"This document contains notes to help upgrade from previous versions of PSRule for Azure.
"},{"location":"upgrade-notes/#upgrading-to-v200","title":"Upgrading to v2.0.0","text":"PSRule for Azure v2.0.0 is a planned future release. It's not yet available, but you can take these steps to proactively prepare for the release.
"},{"location":"upgrade-notes/#realigned-configuration-option-names","title":"Realigned configuration option names","text":"Several configuration options will be renamed in upcoming releases of PSRule for Azure. This is part of a ongoing effort to align the naming of configuration options across PSRule for Azure. For information on other options that will be renamed see deprecations.
You only need to take action if you have explicitly set old configuration option names.
The old option names may be set in:
ps-rule.yaml
.To locate any configurations, search for the old option names within your Infrastructure as Code repo.
New name Old name Available fromAZURE_AKS_CLUSTER_MINIMUM_VERSION
Azure_AKSMinimumVersion
v1.12.0 AZURE_RESOURCE_ALLOWED_LOCATIONS
Azure_AllowedRegions
v1.30.0 To update your configuration, use the new name instead.
Note
Environment variables are prefixed by PSRULE_CONFIGURATION_
and are case sensitive.
Set the AZURE_AKS_CLUSTER_MINIMUM_VERSION
option in ps-rule.yaml
.
# YAML: Set the AZURE_AKS_CLUSTER_MINIMUM_VERSION configuration option to 1.27.3\nconfiguration:\n AZURE_AKS_CLUSTER_MINIMUM_VERSION: 1.27.3\n
Set the PSRULE_CONFIGURATION_AZURE_AKS_CLUSTER_MINIMUM_VERSION
environment variable.
# Bash: Set the AZURE_AKS_CLUSTER_MINIMUM_VERSION configuration option to 1.27.3\nexport PSRULE_CONFIGURATION_AZURE_AKS_CLUSTER_MINIMUM_VERSION=\"1.27.3\"\n
Set the PSRULE_CONFIGURATION_AZURE_AKS_CLUSTER_MINIMUM_VERSION
environment variable.
# GitHub Actions: Set the AZURE_AKS_CLUSTER_MINIMUM_VERSION configuration option to 1.27.3\nenv:\n PSRULE_CONFIGURATION_AZURE_AKS_CLUSTER_MINIMUM_VERSION: '1.27.3'\n
Set the PSRULE_CONFIGURATION_AZURE_AKS_CLUSTER_MINIMUM_VERSION
environment variable.
# Azure Pipelines: Set the AZURE_AKS_CLUSTER_MINIMUM_VERSION configuration option to 1.27.3\nvariables:\n- name: PSRULE_CONFIGURATION_AZURE_AKS_CLUSTER_MINIMUM_VERSION\n value: '1.27.3'\n
"},{"location":"upgrade-notes/#realignment-of-rule-names-for-network-interfaces","title":"Realignment of rule names for network interfaces","text":"Orginally when many of the rules targeting network interfaces were created, network interfaces only applied to virtual machines. Today, network interfaces can be attached to different types of resources including:
To better reflect that network interfaces are not only related to VMs, the following rules have been renamed:
Azure.VM.NICAttached
to Azure.NIC.Attached
.Azure.VM.NICName
to Azure.NIC.Name
.Azure.VM.UniqueDns
to Azure.NIC.UniqueDns
.Aliases have been added to ensure any existing suppression and exclusion to these rules continues to work.
From v2.0.0 these aliases will no longer work.
To update your configuration, use the new rule names instead. Possible locations where the old rule names may be used include:
suppression
option defined within ps-rule.yaml
or by using New-PSRuleOption
.rule.exclude
or rule.include
option defined within ps-rule.yaml
or by using New-PSRuleOption
.rule.exclude
or rule.include
option defined within a custom baseline.The SupportsTags
function is a PowerShell function used for filtering rules. Previously you could use this function to only run a rule against resources that support tags. As of v1.15.0 this function has been deprecated for removal in the next major release v2.0.0.
From v2.0.0 the SupportsTags
function will not longer work.
The SupportsTags
function was previously only available for PowerShell rules and not well documented. Instead you can use the Azure.Resource.SupportsTags
selector introduced in v1.15.0. This selector supports the the same features but also supports YAML and JSON rules in addition to PowerShell.
To upgrade your PowerShell rules use the -With
parameter to set Azure.Resource.SupportsTags
. For example:
# Synopsis: Old rule using the SupportsTags function\nRule 'Local.MyRule' -If { (SupportsTags) } {\n # Rule logic goes here\n}\n\n# Synopsis: Rule updated using the Azure.Resource.SupportsTags selector\nRule 'Local.MyRule' -With 'Azure.Resource.SupportsTags' {\n # Rule logic goes here\n}\n
To read more about the selector, see the documentation.
"},{"location":"using-bicep/","title":"Using Bicep source","text":"PSRule for Azure discovers and analyzes Azure resources contained within Bicep files. To enable this feature, you need to:
Abstract
This topic covers how you can validate Azure resources within .bicep
files. To learn more about why this is important see Expanding source files.
To expand Bicep deployments configure ps-rule.yaml
with the AZURE_BICEP_FILE_EXPANSION
option.
# YAML: Enable expansion for Bicep source files.\nconfiguration:\n AZURE_BICEP_FILE_EXPANSION: true\n
Note
If you are using JSON parameter files exclusively, you do not need to set this option. Instead continue reading using parameter files.
"},{"location":"using-bicep/#setup-bicep","title":"Setup Bicep","text":"To expand Azure resources for analysis from Bicep source files the Bicep CLI is required. The Bicep CLI is already installed on hosted runners and agents used by GitHub Actions and Azure Pipelines. For details on how to configure Bicep for PSRule for Azure see Setup Bicep.
"},{"location":"using-bicep/#building-files","title":"Building files","text":"It's not necessary to build .bicep
files with bicep build
or az bicep build
. PSRule will automatically detect and build .bicep
files. You may choose to pre-build .bicep
files if the Bicep CLI is not available when PSRule is run.
Important
If using this method, follow using templates instead. Using bicep build
transpiles Bicep code into an Azure template .json
.
Bicep allows you to separate out complex details into separate files called modules. To expand resources, any parameters must be resolved.
Tip
If you are not familiar with the concept of expansion within PSRule for Azure see Expanding source files.
Two types of parameters exist, required (also called mandatory) and optional. An optional parameter is any parameter with a default value. Required parameters do not have a default value and must be specified.
Example modules/storage/main.bicep
// Required parameter\nparam name string\n\n// Optional parameters\nparam location string = resourceGroup().location\nparam sku string = 'Standard_LRS'\n
To specify required parameters for a module, create a deployment or test that references the module.
Example deploy.bicep
// Deploy storage account to production subscription\nmodule storageAccount './modules/storage/main.bicep' = {\n name: 'deploy-storage'\n params: {\n name: 'stpsrulebicep001'\n sku: 'Standard_GRS'\n }\n}\n
Example modules/storage/.tests/main.tests.bicep
// Test with only required parameters\nmodule test_required_params '../main.bicep' = {\n name: 'test_required_params'\n params: {\n name: 'sttest001'\n }\n}\n
"},{"location":"using-bicep/#configuring-path-exclusions","title":"Configuring path exclusions","text":"Unless configured, PSRule will discover all .bicep
files when expansion is enabled. Bicep module files with required parameters will not be able be expanded and should be excluded. Instead expand resources from deployments or tests.
To do this configure ps-rule.yaml
with the input.pathIgnore
option.
Example ps-rule.yaml
configuration:\n # Enable expansion for Bicep source files.\n AZURE_BICEP_FILE_EXPANSION: true\n\ninput:\n pathIgnore:\n # Exclude bicepconfig.json\n - 'bicepconfig.json'\n # Exclude module files\n - 'modules/**/*.bicep'\n # Include test files from modules\n - '!modules/**/*.tests.bicep'\n
Note
In this example, Bicep files such as deploy.bicep
in other directories will be expanded.
When using Bicep, you don't need to use parameter files. You can call .bicep
files directly from other .bicep
files with modules by using the module
keyword.
Alternatively, Bicep supports two options for parameter files:
.bicepparam
file to reference a Bicep module.Each option is described in more detail in the following sections.
"},{"location":"using-bicep/#using-json-parameter-files","title":"Using JSON parameter files","text":"You can choose to expand and test a Bicep module from JSON parameter files by metadata.
When using parameter files exclusively, the AZURE_BICEP_FILE_EXPANSION
configuration option does not need to be set. Instead set the AZURE_PARAMETER_FILE_EXPANSION
configuration option to true
. This option will discover Bicep files from parameter metadata.
Example ps-rule.yaml
configuration:\n # Enable expansion for Bicep module from parameter files.\n AZURE_PARAMETER_FILE_EXPANSION: true\n\ninput:\n pathIgnore:\n # Exclude bicepconfig.json\n - 'bicepconfig.json'\n # Exclude module files\n - 'modules/**/*.bicep'\n
Example template.parameters.json
{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentParameters.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"metadata\": {\n \"template\": \"./template.bicep\"\n },\n \"parameters\": {\n \"storageAccountName\": {\n \"value\": \"bicepstorage001\"\n },\n \"tags\": {\n \"value\": {\n \"env\": \"test\"\n }\n }\n }\n}\n
"},{"location":"using-bicep/#using-bicep-parameter-files","title":"Using Bicep parameter files","text":"v1.34.0
You can use .bicepparam
files to reference your Bicep modules as a method for providing parameters. Using the Bicep parameter file format, allows you to get many of the benefits of the Bicep language.
For example:
using 'main.bicep'\n\nparam storageAccountName = 'bicepstorage001'\nparam tags = {\n env: 'test'\n}\n
Learn
To learn more about Bicep parameter files see Create parameters files for Bicep deployment.
Note
To use Bicep parameter files you must use a minimum of Bicep CLI version 0.18.4. You can configure PSRule to check for the minimum Bicep version. See configuring minimum version for information on how to enable this check.
"},{"location":"using-bicep/#restoring-modules-from-a-private-registry","title":"Restoring modules from a private registry","text":"Bicep modules can be stored in a private registry. Storing modules in a private registry gives you a central location to reference modules across your organization.
To test Bicep deployments which uses modules stored in a private registry, these modules must be restored. The restore process automatically occurs when PSRule is run, however some additional steps are required to authenticate.
To prepare your registry for storing Bicep modules see Create private registry for Bicep modules.
To configure authentication for PSRule to a private registry:
bicepconfig.json
Some organizations may want to expose Bicep modules publicly. This can be configured by enabling anonymous pull access. To configure your registry see Make your container registry content publicly available.
Note
To use anonymous pull access to a registry you must use a minimum of Bicep CLI version 0.15.31. You can configure PSRule to check for the minimum Bicep version. See configuring minimum version for information on how to enable this check.
"},{"location":"using-bicep/#configure-bicepconfigjson","title":"Configurebicepconfig.json
","text":"To authenticate to a private registry, configure bicepconfig.json
by setting credentialPrecedence. This setting determines the order to find a credential to use when authenticating to the registry.
Use the following credential type based on your environment as the first value of the credentialPrecedence setting:
Environment
\u2014 Use environment variables to authenticate to the registry. This is the most common scenario for CI pipelines and works for cloud-hosted or self-hosted agents/ private runners.ManagedIdentity
\u2014 Use a managed identity to authenticate to the registry. This may be applicable for scenarios where you are using self-hosted agents or private runners. You must configure a System-Assigned managed identity for the Azure Virtual Machine or Virtual Machine Scale Set.Example bicepconfig.json
{\n \"credentialPrecedence\": [\n \"Environment\",\n \"AzureCLI\",\n ]\n}\n
Tip
The bicepconfig.json
configures the Bicep CLI. You should commit this file into a repository along with your Bicep code.
To access a private registry use an Entra ID identity which has been granted permissions to pull Bicep modules. When using Environment
credential type, see create a service principal that can access resources to create the identity. If you are using the ManagedIdentity
credential type, an identity is created for when you configure the managed identity.
After configuring the identity, grant access using the AcrPull
built-in RBAC role on the Azure Container Registry.
When using the Environment
credential type, environment variables should be set in the pipeline. Typically, the following three environment variables should be set:
AZURE_CLIENT_ID
\u2014 The Client ID (also called Application ID) of an App Registration in Azure AD. This will be represented as a GUID.AZURE_CLIENT_SECRET
\u2014 A valid secret that was generated for the App Registration.AZURE_TENANT_ID
\u2014 The Tenant ID that identifies your specific Azure AD tenant where your App Registration is created. This will be represented as a GUID.Note
The environment credential type also supports other environment variables that may be applicable to your environment. To see a list visit EnvironmentCredential Class.
GitHub ActionsAzure PipelinesConfigure the microsoft/ps-rule
action with Azure environment variables.
- name: Analyze Azure template files\n uses: microsoft/ps-rule@v2.9.0\n with:\n modules: PSRule.Rules.Azure,PSRule.Monitor\n conventions: Monitor.LogAnalytics.Import\n env:\n # Define environment variables using GitHub encrypted secrets\n AZURE_CLIENT_ID: ${{ secrets.BICEP_REGISTRY_CLIENTID }}\n AZURE_CLIENT_SECRET: ${{ secrets.BICEP_REGISTRY_CLIENTSECRET }}\n AZURE_TENANT_ID: ${{ secrets.BICEP_REGISTRY_TENANTID }}\n
Important
Environment variables can be configured in the workflow or from a secret. To keep BICEP_REGISTRY_CLIENTSECRET
secure, use an encrypted secret.
Configure the ps-rule-assert
task with Azure environment variables.
- task: ps-rule-assert@2\n displayName: Analyze Azure template files\n inputs:\n modules: 'PSRule.Rules.Azure'\n env:\n # Define environment variables within Azure Pipelines\n AZURE_CLIENT_ID: $(BICEPREGISTRYCLIENTID)\n AZURE_CLIENT_SECRET: $(BICEPREGISTRYCLIENTSECRET)\n AZURE_TENANT_ID: $(BICEPREGISTRYTENANTID)\n
Important
Variables can be configured in YAML, on the pipeline, or referenced from a defined variable group. To keep BICEPREGISTRYCLIENTSECRET
secure, use a variable group linked to an Azure Key Vault.
PSRule for Azure discovers and analyzes Azure resources contained within template and parameter files. To enable this feature, you need to:
Abstract
This topic covers how you can validate Azure resources within template .json
files. To learn more about why this is important see Expanding source files.
To expand parameter files configure ps-rule.yaml
with the AZURE_PARAMETER_FILE_EXPANSION
option.
# YAML: Enable expansion for template expansion.\nconfiguration:\n AZURE_PARAMETER_FILE_EXPANSION: true\n
"},{"location":"using-templates/#linking-templates","title":"Linking templates","text":"PSRule for Azure automatically detects parameter files and uses the following logic to link templates or Bicep modules.
Note
Metadata links take priority over naming convention. For details on both options continue reading.
Tip
Linking templates also applies to Bicep modules when you are using .json
parameter files.
A parameter file can be linked to an associated template or Bicep module by setting metadata. To link a template within a parameter file, set the metadata.template
property to the path of the template.
PSRule for Azure supports either:
./
.Tip
Referencing a path outside of the repository is blocked as this could lead to unintended exposure.
Relative to repositoryRelative to parameter fileThe following example shows linking to a template which is stored within a hierarchical template/
sub-directory.
Example
{\n \"$schema\": \"https://schema.management.azure.com/schemas/2015-01-01/deploymentParameters.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"metadata\": {\n \"template\": \"templates/storage/v1/template.json\"\n },\n \"parameters\": {\n }\n}\n
The following example shows linking to a template that is in the same directory as the parameter file.
Example
{\n \"$schema\": \"https://schema.management.azure.com/schemas/2015-01-01/deploymentParameters.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"metadata\": {\n \"template\": \"./storage.template.json\"\n },\n \"parameters\": {\n }\n}\n
Additional benefits you get by using metadata links include:
Get-AzRuleTemplateLink
cmdlet to list parameter file links.Tip
By default, metadata links are not required. By configuring the AZURE_PARAMETER_FILE_METADATA_LINK
option to true
, this can be enforced. When configured, PSRule for Azure will fail parameter files that do not contain a metadata link. For details on AZURE_PARAMETER_FILE_METADATA_LINK
see Configuring expansion.
Note
Bicep modules can also be expanded from parameter files. Instead of specifying a template path, you can specify the path to a Bicep file.
Note
You may find while editing a .json
parameter file the root metadata
property is flagged with a warning. For example Property metadata is not allowed.
. This doesn't affect the workings of the parameter file or deployment. If you like a detailed description continue reading Troubleshooting.
When metadata links are not set, PSRule will fallback to use a naming convention to link to template files.
Example
A parameter file named azuredeploy.parameters.json
links to the template file named azuredeploy.json
.
PSRule for Azure supports linking by naming convention when:
.parameters.json
linking to ARM templates or Bicep modules.azuredeploy.parameters.json
links to azuredeploy.json
or azuredeploy.bicep
..json
) is preferred. For example, azuredeploy.parameters.json
chooses azuredeploy.json
over azuredeploy.bicep
if both exist.The following is not currently supported:
<templateName>.param.json
..jsonc
.As PSRule evolves over time features and rules are added, updated, and removed. PSRule for Azure uses semantic versioning to declare breaking changes.
The latest module version can be installed from the PowerShell Gallery and NuGet. For a list of module changes please see the change log.
"},{"location":"versioning/#module-releases","title":"Module releases","text":""},{"location":"versioning/#stable-releases","title":"Stable releases","text":"Stable modules versions are identified by a version number (major.minor.patch
) such as 1.34.2
. A stable release is considered production ready and is recommended for general use. These versions are can be installed from the PowerShell Gallery or NuGet.
When using PSRule extensions in GitHub and Azure Pipelines, the latest stable version is automatically installed by default when an existing version is not already installed.
The version of PSRule and PSRule for Azure modules can be viewed by default in the output of each run.
"},{"location":"versioning/#pre-releases","title":"Pre-releases","text":"Pre-release module versions are created on major commits and can be installed from the PowerShell Gallery. Module versions and change log details for pre-releases will be removed as stable releases are made available.
You can identify a pre-release version by the pre-release suffix on the end of the version (major.minor.patch-prerelease
). For example, 1.35.0-B0055
.
To use a pre-release version you will need to install it specifically. To do this, insert a PowerShell step in your pipeline to install the module with the -AllowPrerelease
switch.
For example:
Install-Module -Name 'PSRule.Rules.Azure' -RequiredVersion '1.35.0-B0055' -AllowPrerelease -Force;\n
Important
Pre-release versions should be considered work in progress. These releases should not be used in production. We may introduce breaking changes between a pre-release as we work towards a stable version release.
"},{"location":"versioning/#experimental-features","title":"Experimental features","text":"From time to time we may ship experiential features. Experiential features are shipped so that customers can try them out and provide feedback. These features are generally marked experimental in the change log as these features ship. Experimental features may ship in stable releases, however to use them you may need to:
Important
Experimental features should be considered work in progress. These features may be incomplete and should not be used in production. We may introduce breaking changes for experimental features as we work towards a general release for the feature.
"},{"location":"versioning/#rule-lifecycle","title":"Rule lifecycle","text":"Common rules are added and updated on a regular basis. Occasionally rules are removed or deprecated.
The following information outlines how changes to rules are managed within PSRule for Azure.
2024_03
).Deprecation/ removal - occurs when checking for the conditions of the rule is no longer necessary or it no longer aligns. In these cases, the rule may be removed or if there is still some customer value it may be retained but not run by default. For example, the rule may not align to the Well-Architected Framework but is still useful for some customers. This is done by the means of a feature flag, by requiring a configuration value to be set. Check the rule documentation for details on any configuration requirements.
If you experience an issue with a feature or release please let us know by logging an issue as a bug.
"},{"location":"working-with-baselines/","title":"Working with baselines","text":"A baseline is a standard PSRule artifact that combines rules and configuration. PSRule for Azure provides several baselines that can be referenced when running PSRule.
Abstract
This topic covers how to use the baselines shipped with PSRule for Azure.
"},{"location":"working-with-baselines/#quarterly-baselines","title":"Quarterly baselines","text":"PSRule for Azure ships new rules on a monthly cadence. As new rules are added, existing pipelines that previously passed may fail based on additional requirements. It is generally expected that files committed to an integration branch such as main
continue to pass.
PSRule for Azure addresses this through quarterly baselines that provide:
Azure.GA_yyyy_mm
and Azure.Preview_yyyy_mm
based on the release year/ month.Considerations for adopting a quarterly baseline include:
Azure.GA_yyyy_mm
and preview features is named Azure.Preview_yyyy_mm
.Important
When using a quarterly baseline, by default PSRule will ignore custom/ standalone rules. To include custom rules, set the Rule.IncludeLocal
option to true
. This is described further in including custom rules.
Note
The preview quarterly baselines includes Azure features released under preview only. This is different from the Azure.Preview
baseline which contains GA and preview features.
Quarterly baselines don't address all cases where a previously passing pipeline may fail, specifically:
ps-rule.yaml
.v1.35.0
Pillar specific baselines includes rules aligned to a specific Microsoft Azure Well-Architected Framework pillar.
Use these baselines to focus on improvement aligned to a specific area of the Azure Well-Architected Framework. Only rules that related to GA Azure features are included in these baselines. These baselines are best used for ad-hoc scans.
The following baselines are available:
Azure.Pillar.CostOptimization
\u2014 A baseline that only includes cost optimization rules.Azure.Pillar.OperationalExcellence
\u2014 A baseline that only includes operational excellence rules.Azure.Pillar.PerformanceEfficiency
\u2014 A baseline that only includes performance efficiency rules.Azure.Pillar.Reliability
\u2014 A baseline that only includes reliability rules.Azure.Pillar.Security
\u2014 A baseline that only includes security rules.In additional to quarterly and pillar specific baselines, some additional baselines exist:
Azure.Default
\u2014 Includes rules for GA Azure features. This is the default baseline that is used when no baseline is specified. Rules for Azure features that are within the scope of a public or private preview are not included.Azure.Preview
\u2014 Includes all rules for GA and preview Azure features.Azure.All
\u2014 Includes all Azure rules shipped with PSRule for Azure. This is functionally the same as Azure.Preview
however intended for internal use only.Azure.MCSB.v1
\u2014 Includes rules related to Microsoft cloud security benchmark (MCSB) controls. This baseline is currently experimental and may change in future releases. You can learn more about MCSB within PSRule for Azure in the Microsoft cloud security benchmark (MCSB) topic.
To use a baseline within a CI pipeline specify the baseline by name. See reference for a list baselines shipped with PSRule for Azure.
GitHub ActionsAzure PipelinesPowerShellUpdate your GitHub Actions workflow by specifying baseline: <name_of_baseline>
.
# Analyze Azure resources using PSRule for Azure\n- name: Analyze Azure template files\n uses: microsoft/ps-rule@v2.9.0\n with:\n modules: 'PSRule.Rules.Azure'\n baseline: 'Azure.GA_2023_12'\n
Update your Azure DevOps YAML pipeline by specifying baseline: <name_of_baseline>
.
# Analyze Azure resources using PSRule for Azure\n- task: ps-rule-assert@2\n displayName: Analyze Azure template files\n inputs:\n modules: 'PSRule.Rules.Azure'\n baseline: 'Azure.GA_2023_12'\n
Update your PowerShell command-line with -Baseline <name_of_baseline>
.
Assert-PSRule -Format File -InputPath '.' -Module 'PSRule.Rules.Azure' -Baseline 'Azure.GA_2023_12'\n
With Invoke-PSRuleInvoke-PSRule -Format File -InputPath '.' -Module 'PSRule.Rules.Azure' -Baseline 'Azure.GA_2023_12'\n
"},{"location":"working-with-baselines/#creating-baselines","title":"Creating baselines","text":"To create your own baselines see the PSRule help topic about_PSRule_Baseline.
"},{"location":"working-with-baselines/#including-custom-rules","title":"Including custom rules","text":"v1.8.0
The quarterly baselines shipped with PSRule for Azure target a subset of rules for GA Azure features. When you specify a baseline, custom rules you create and store in .ps-rule/
will be ignored by default.
To change this behavior, set the Rule.IncludeLocal
option to true
. This option can be set in ps-rule.yaml
.
# YAML: Enable custom rules that don't exist in the baseline\nrule:\n includeLocal: true\n
"},{"location":"benchmark/results-v1.10.4/","title":"Results v1.10.4","text":"BenchmarkDotNet=v0.13.1, OS=Windows 10.0.22000\nIntel Core i7-1065G7 CPU 1.30GHz, 1 CPU, 8 logical and 4 physical cores\n.NET SDK=5.0.404\n [Host] : .NET Core 3.1.22 (CoreCLR 4.700.21.56803, CoreFX 4.700.21.57101), X64 RyuJIT\n DefaultJob : .NET Core 3.1.22 (CoreCLR 4.700.21.56803, CoreFX 4.700.21.57101), X64 RyuJIT\n
| Method | Mean | Error | StdDev | Gen 0 | Gen 1 | Allocated | |--------------------- |---------:|---------:|----------:|----------:|----------:|----------:| | Template | 74.25 ms | 4.140 ms | 12.206 ms | 6000.0000 | 1000.0000 | 27 MB | | PropertyCopyLoop | 47.84 ms | 0.936 ms | 1.615 ms | 4444.4444 | 222.2222 | 18 MB | | UserDefinedFunctions | 28.87 ms | 0.574 ms | 1.224 ms | 1500.0000 | 62.5000 | 6 MB |"},{"location":"benchmark/results-v1.11.0/","title":"Results v1.11.0","text":"BenchmarkDotNet=v0.13.1, OS=Windows 10.0.22000\nIntel Core i7-1065G7 CPU 1.30GHz, 1 CPU, 8 logical and 4 physical cores\n.NET SDK=5.0.404\n [Host] : .NET Core 3.1.22 (CoreCLR 4.700.21.56803, CoreFX 4.700.21.57101), X64 RyuJIT\n DefaultJob : .NET Core 3.1.22 (CoreCLR 4.700.21.56803, CoreFX 4.700.21.57101), X64 RyuJIT\n
| Method | Mean | Error | StdDev | Gen 0 | Gen 1 | Allocated | |--------------------- |---------:|---------:|---------:|----------:|----------:|----------:| | Template | 78.97 ms | 2.842 ms | 8.246 ms | 6000.0000 | 1000.0000 | 27 MB | | PropertyCopyLoop | 47.83 ms | 0.954 ms | 2.033 ms | 4400.0000 | 200.0000 | 18 MB | | UserDefinedFunctions | 29.42 ms | 0.587 ms | 1.172 ms | 1500.0000 | 62.5000 | 6 MB |"},{"location":"benchmark/results-v1.14.3/","title":"Results v1.14.3","text":"BenchmarkDotNet=v0.13.1, OS=Windows 10.0.22000\nIntel Core i7-1065G7 CPU 1.30GHz, 1 CPU, 8 logical and 4 physical cores\n.NET SDK=6.0.202\n [Host] : .NET Core 3.1.24 (CoreCLR 4.700.22.16002, CoreFX 4.700.22.17909), X64 RyuJIT\n DefaultJob : .NET Core 3.1.24 (CoreCLR 4.700.22.16002, CoreFX 4.700.22.17909), X64 RyuJIT\n
| Method | Mean | Error | StdDev | Gen 0 | Gen 1 | Allocated | |--------------------- |---------:|---------:|---------:|----------:|---------:|----------:| | Template | 80.07 ms | 2.250 ms | 6.598 ms | 6666.6667 | 666.6667 | 28 MB | | PropertyCopyLoop | 52.08 ms | 0.955 ms | 0.798 ms | 4500.0000 | 125.0000 | 18 MB | | UserDefinedFunctions | 35.51 ms | 0.705 ms | 1.635 ms | 1600.0000 | 66.6667 | 7 MB |"},{"location":"benchmark/results-v1.15.0/","title":"Results v1.15.0","text":"BenchmarkDotNet=v0.13.1, OS=Windows 10.0.22000\nIntel Core i7-1065G7 CPU 1.30GHz, 1 CPU, 8 logical and 4 physical cores\n.NET SDK=6.0.202\n [Host] : .NET Core 3.1.24 (CoreCLR 4.700.22.16002, CoreFX 4.700.22.17909), X64 RyuJIT\n DefaultJob : .NET Core 3.1.24 (CoreCLR 4.700.22.16002, CoreFX 4.700.22.17909), X64 RyuJIT\n
| Method | Mean | Error | StdDev | Median | Gen 0 | Gen 1 | Allocated | |----------------------- |----------------:|----------------:|----------------:|----------------:|----------:|----------:|-------------:| | Template | 58,758,457.6 ns | 1,368,418.79 ns | 3,859,649.48 ns | 57,989,600.0 ns | 6000.0000 | 2000.0000 | 28,881,656 B | | PropertyCopyLoop | 35,152,022.3 ns | 699,686.11 ns | 1,206,924.16 ns | 34,927,013.3 ns | 4466.6667 | 133.3333 | 19,040,308 B | | UserDefinedFunctions | 19,601,380.5 ns | 382,322.59 ns | 560,403.50 ns | 19,517,700.0 ns | 1562.5000 | 62.5000 | 6,821,540 B | | ResolvePolicyAliasPath | 2,194.6 ns | 42.05 ns | 84.93 ns | 2,154.7 ns | 0.2861 | - | 1,200 B | | GetResourceType | 293.9 ns | 1.82 ns | 1.52 ns | 293.9 ns | 0.0858 | - | 360 B |"},{"location":"benchmark/results-v1.34.2/","title":"Results v1.34.2","text":"BenchmarkDotNet v0.13.12, Windows 11 (10.0.22631.3155/23H2/2023Update/SunValley3)\nIntel Core i7-1065G7 CPU 1.30GHz, 1 CPU, 8 logical and 4 physical cores\n.NET SDK 8.0.200\n [Host] : .NET 7.0.16 (7.0.1624.6629), X64 RyuJIT AVX2\n DefaultJob : .NET 7.0.16 (7.0.1624.6629), X64 RyuJIT AVX2\n
| Method | Mean | Error | StdDev | Median | Gen0 | Gen1 | Allocated | |------------------------------------- |----------------:|----------------:|-----------------:|----------------:|----------:|----------:|-----------:| | Template | 91,883,381.6 ns | 3,632,849.07 ns | 10,597,191.25 ns | 89,313,550.0 ns | 8000.0000 | 2000.0000 | 35435008 B | | PropertyCopyLoop | 49,633,655.3 ns | 1,505,203.29 ns | 4,318,710.40 ns | 47,957,783.3 ns | 5500.0000 | 2666.6667 | 23333345 B | | UserDefinedFunctions | 29,551,473.2 ns | 677,400.84 ns | 1,910,621.08 ns | 29,457,092.2 ns | 2187.5000 | 62.5000 | 9336566 B | | ResolvePolicyAliasPath | 2,408.4 ns | 129.91 ns | 381.01 ns | 2,252.3 ns | 0.2861 | - | 1200 B | | GetResourceType | 297.3 ns | 9.93 ns | 28.18 ns | 287.5 ns | 0.0858 | - | 360 B | | CustomTypeDependencyGraph_GetOrdered | 876.7 ns | 17.50 ns | 31.55 ns | 878.1 ns | 0.1602 | - | 672 B |"},{"location":"benchmark/results-v1.35.0/","title":"Results v1.35.0","text":"BenchmarkDotNet v0.13.12, Windows 11 (10.0.22631.3155/23H2/2023Update/SunValley3)\nIntel Core i7-1065G7 CPU 1.30GHz, 1 CPU, 8 logical and 4 physical cores\n.NET SDK 8.0.200\n [Host] : .NET 7.0.16 (7.0.1624.6629), X64 RyuJIT AVX2\n DefaultJob : .NET 7.0.16 (7.0.1624.6629), X64 RyuJIT AVX2\n
| Method | Mean | Error | StdDev | Median | Gen0 | Gen1 | Gen2 | Allocated | |------------------------------------- |-----------------:|-----------------:|-----------------:|-----------------:|----------:|----------:|---------:|-----------:| | Template | 63,730,486.52 ns | 1,266,452.101 ns | 2,643,557.149 ns | 63,341,771.43 ns | 8285.7143 | 4142.8571 | 142.8571 | 35441751 B | | PropertyCopyLoop | 39,934,076.76 ns | 773,166.984 ns | 1,852,458.712 ns | 39,569,050.00 ns | 5400.0000 | 100.0000 | - | 23337248 B | | UserDefinedFunctions | 23,403,397.62 ns | 751,878.865 ns | 2,070,892.753 ns | 22,610,225.00 ns | 2156.2500 | 62.5000 | - | 9336567 B | | ResolvePolicyAliasPath | 2,284.19 ns | 70.184 ns | 197.956 ns | 2,275.12 ns | 0.2861 | - | - | 1200 B | | GetResourceType | 254.25 ns | 5.013 ns | 7.805 ns | 252.31 ns | 0.0858 | - | - | 360 B | | CustomTypeDependencyGraph_GetOrdered | 58.35 ns | 1.192 ns | 2.352 ns | 58.09 ns | 0.0401 | - | - | 168 B |"},{"location":"benchmark/results-v1.8.1/","title":"Results v1.8.1","text":"BenchmarkDotNet=v0.13.1, OS=Windows 10.0.22000\nIntel Core i7-1065G7 CPU 1.30GHz, 1 CPU, 8 logical and 4 physical cores\n.NET SDK=5.0.404\n [Host] : .NET Core 3.1.22 (CoreCLR 4.700.21.56803, CoreFX 4.700.21.57101), X64 RyuJIT\n DefaultJob : .NET Core 3.1.22 (CoreCLR 4.700.21.56803, CoreFX 4.700.21.57101), X64 RyuJIT\n
| Method | Mean | Error | StdDev | Gen 0 | Gen 1 | Allocated | |--------------------- |---------:|---------:|---------:|----------:|----------:|----------:| | Template | 49.11 ms | 1.871 ms | 5.307 ms | 5000.0000 | 1000.0000 | 21 MB | | PropertyCopyLoop | 42.65 ms | 0.815 ms | 1.001 ms | 3812.5000 | 125.0000 | 15 MB | | UserDefinedFunctions | 26.26 ms | 0.518 ms | 1.126 ms | 1125.0000 | 31.2500 | 5 MB |"},{"location":"benchmark/results-v1.9.1/","title":"Results v1.9.1","text":"BenchmarkDotNet=v0.13.1, OS=Windows 10.0.22000\nIntel Core i7-1065G7 CPU 1.30GHz, 1 CPU, 8 logical and 4 physical cores\n.NET SDK=5.0.404\n [Host] : .NET Core 3.1.22 (CoreCLR 4.700.21.56803, CoreFX 4.700.21.57101), X64 RyuJIT\n DefaultJob : .NET Core 3.1.22 (CoreCLR 4.700.21.56803, CoreFX 4.700.21.57101), X64 RyuJIT\n
| Method | Mean | Error | StdDev | Gen 0 | Gen 1 | Allocated | |--------------------- |---------:|---------:|---------:|----------:|---------:|----------:| | Template | 54.28 ms | 1.081 ms | 1.443 ms | 5333.3333 | 555.5556 | 21 MB | | PropertyCopyLoop | 42.15 ms | 0.823 ms | 0.881 ms | 3833.3333 | 166.6667 | 15 MB | | UserDefinedFunctions | 25.76 ms | 0.510 ms | 1.076 ms | 1125.0000 | 31.2500 | 5 MB |"},{"location":"commands/Export-AzPolicyAssignmentData/","title":"Export-AzPolicyAssignmentData","text":"Export policy assignment data.
"},{"location":"commands/Export-AzPolicyAssignmentData/#syntax","title":"SYNTAX","text":""},{"location":"commands/Export-AzPolicyAssignmentData/#default-default","title":"Default (Default)","text":"Export-AzPolicyAssignmentData [-OutputPath <String>] [-PassThru] [-WhatIf] [-Confirm] [<CommonParameters>]\n
"},{"location":"commands/Export-AzPolicyAssignmentData/#name","title":"Name","text":"Export-AzPolicyAssignmentData [-Name <String>] [-Scope <String>] [-PolicyDefinitionId <String>]\n [-OutputPath <String>] [-PassThru] [-WhatIf] [-Confirm] [<CommonParameters>]\n
"},{"location":"commands/Export-AzPolicyAssignmentData/#id","title":"Id","text":"Export-AzPolicyAssignmentData -Id <String> [-PolicyDefinitionId <String>] [-OutputPath <String>] [-PassThru]\n [-WhatIf] [-Confirm] [<CommonParameters>]\n
"},{"location":"commands/Export-AzPolicyAssignmentData/#includedescendent","title":"IncludeDescendent","text":"Export-AzPolicyAssignmentData [-Scope <String>] [-IncludeDescendent] [-OutputPath <String>] [-PassThru]\n [-WhatIf] [-Confirm] [<CommonParameters>]\n
"},{"location":"commands/Export-AzPolicyAssignmentData/#description","title":"Description","text":"This is an experimental cmdlet.
Export policy assignment data.
By default the current subscription context will be exported. i.e Get-AzContext
Policy assignment data will be exported to the current working directory by default as JSON files, one per subscription.
All output files include a .assignment.json
extension by default.
Export-AzPolicyAssignmentData\n
Directory: C:\\\n\n\nMode LastWriteTime Length Name\n---- ------------- ------ ----\n-a--- 26/03/2022 7:01 PM 740098 \ue60b 00000000-0000-0000-0000-000000000000.assignment.json\n
Export policy assignment data from current subscription context.
"},{"location":"commands/Export-AzPolicyAssignmentData/#example-2","title":"Example 2","text":"Export-AzPolicyAssignmentData -Name '000000000000000000000000' -Scope '/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/PolicyRG'\n
Directory: C:\\\n\n\nMode LastWriteTime Length Name\n---- ------------- ------ ----\n-a--- 26/03/2022 7:15 PM 4185 \ue60b 00000000-0000-0000-0000-000000000000.assignment.json\n
Export policy assignment with specific name and scope.
"},{"location":"commands/Export-AzPolicyAssignmentData/#example-3","title":"Example 3","text":"Export-AzPolicyAssignmentData -Id '/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/PolicyRG/providers/Microsoft.Authorization/policyAssignments/000000000000000000000000'\n
Directory: C:\\\n\n\nMode LastWriteTime Length Name\n---- ------------- ------ ----\n-a--- 26/03/2022 7:42 PM 4185 \ue60b 00000000-0000-0000-0000-00000000000.assignment.json\n
Export policy assignment with specific resource ID.
"},{"location":"commands/Export-AzPolicyAssignmentData/#parameters","title":"PARAMETERS","text":""},{"location":"commands/Export-AzPolicyAssignmentData/#-name","title":"-Name","text":"Specifies the name of the policy assignment.
Type: String\nParameter Sets: Name\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentData/#-id","title":"-Id","text":"Specifies the fully qualified resource ID for the policy assignment.
Type: String\nParameter Sets: Id\nAliases: AssignmentId\n\nRequired: True\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentData/#-scope","title":"-Scope","text":"Specifies the scope at which the policy is applied for the assignment.
Type: String\nParameter Sets: Name, IncludeDescendent\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentData/#-policydefinitionid","title":"-PolicyDefinitionId","text":"Specifies the ID of the policy definition of the policy assignment.
Type: String\nParameter Sets: Name, Id\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentData/#-includedescendent","title":"-IncludeDescendent","text":"Causes the list of returned policy assignments to include all assignments related to the given scope, including those from ancestor scopes and those from descendent scopes.
Type: SwitchParameter\nParameter Sets: IncludeDescendent\nAliases:\n\nRequired: True\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentData/#-outputpath","title":"-OutputPath","text":"The path to store generated JSON files containing policy assignment data.
Type: String\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: $PWD\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentData/#-passthru","title":"-PassThru","text":"By default, FileInfo objects are returned to the pipeline for each JSON file created. When -PassThru
is specified, JSON files are not created and Azure resource objects are returned to the pipeline instead.
Type: SwitchParameter\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentData/#commonparameters","title":"CommonParameters","text":"This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.
"},{"location":"commands/Export-AzPolicyAssignmentData/#inputs","title":"INPUTS","text":""},{"location":"commands/Export-AzPolicyAssignmentData/#none","title":"None","text":""},{"location":"commands/Export-AzPolicyAssignmentData/#outputs","title":"OUTPUTS","text":""},{"location":"commands/Export-AzPolicyAssignmentData/#systemiofileinfo","title":"System.IO.FileInfo","text":"Return FileInfo
for each of the output files created, one per subscription context. This is the default.
Return an object for each Azure resource, and configuration exported. This is returned when the -PassThru
switch is used.
Export JSON based rules from policy assignment data.
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#syntax","title":"SYNTAX","text":"Export-AzPolicyAssignmentRuleData [-Name <String>] -AssignmentFile <String>\n [-ResourceGroup <ResourceGroupReference>] [-Subscription <SubscriptionReference>] [-OutputPath <String>]\n [-RulePrefix <String>] [-PassThru] [-KeepDuplicates] [<CommonParameters>]\n
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#description","title":"Description","text":"This is an experimental cmdlet.
Export JSON based rules from policy assignment data.
Policy assignment data generated from Export-AzPolicyAssignmentData
is used to generate JSON rules.
By default this is an offline process, requiring no connectivity to Azure.
Policy definitions with the Disabled
effect are ignored.
The subscription()
function will return the following unless overridden:
The resourceGroup()
function will return the following unless overridden:
To override, set the AZURE_SUBSCRIPTION
and AZURE_RESOURCE_GROUP
in configuration.
The rule prefix Azure
is also applied to the policy names unless overridden with -RulePrefix
or AZURE_POLICY_RULE_PREFIX
in configuration.
Currently the following limitations apply:
field()
expressions are not expanded.value
cannot be expanded e.g. \"value\": \"[substring(field('name'), 0, 3)]\"
.Export-AzPolicyAssignmentRuleData -Name \"policy\" -AssignmentFile .\\00000000-0000-0000-0000-000000000000.assignment.json\n
Mode LastWriteTime Length Name\n---- ------------- ------ ----\n-a--- 26/03/2022 9:41 PM 361 \uf15b definitions-policy.Rule.jsonc\n
Export JSON rules to file in current working directory.
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#example-2","title":"Example 2","text":"$subscription = @{\n subscriptionId = 'nnnnnnnn-nnnn-nnnn-nnnn-nnnnnnnnnnnn'\n displayName = 'My Azure Subscription'\n tenantId = 'nnnnnnnn-nnnn-nnnn-nnnn-nnnnnnnnnnnn'\n}\n\nExport-AzPolicyAssignmentRuleData -Name \"policy\" -AssignmentFile .\\00000000-0000-0000-0000-000000000000.assignment.json -Subscription $subscription\n
Mode LastWriteTime Length Name\n---- ------------- ------ ----\n-a--- 26/03/2022 9:41 PM 361 \uf15b definitions-policy.Rule.jsonc\n
Export JSON rules to file in current working directory using a specific subscription.
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#example-3","title":"Example 3","text":"Get-AzPolicyAssignmentDataSource | Export-AzPolicyAssignmentRuleData\n
Mode LastWriteTime Length Name\n---- ------------- ------ ----\n-a--- 27/03/2022 11:26 AM 721 \uf15b definitions-export-1b474938.Rule.jsonc\n
Export JSON rules from the current working directory using discovered assignment sources in the current working directory.
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#parameters","title":"PARAMETERS","text":""},{"location":"commands/Export-AzPolicyAssignmentRuleData/#-name","title":"-Name","text":"The name of the assignment. If not specified export-<xxxxxxxx>
will be used as the name of the assignment.
Type: String\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#-assignmentfile","title":"-AssignmentFile","text":"The absolute or relative path to an assignment data file.
Type: String\nParameter Sets: (All)\nAliases:\n\nRequired: True\nPosition: Named\nDefault value: None\nAccept pipeline input: True (ByPropertyName)\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#-outputpath","title":"-OutputPath","text":"The path to store generated JSON files containing resources.
If this parameter is not specified, output will be written to the current working path. The file name definitions-<name>.Rule.jsonc
will be used when this parameter is not set or a directory is specified. Where <name>
is the name of the assignment specified by -Name
.
This parameter has no affect when -PassThru
is used.
Type: String\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: $PWD\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#-ruleprefix","title":"-RulePrefix","text":"By default, policy rule names use the Azure
prefix e.g. Azure.Policy.e749c2d003da
.
When -RulePrefix
is specified, the default prefix is overridden.
For example, with -RulePrefix 'CustomPolicyPrefix'
this would generate the policy rule name CustomPolicyPrefix.Policy.e749c2d003da
.
Type: String\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#-passthru","title":"-PassThru","text":"By default, FileInfo objects are returned to the pipeline for each JSON file created. When -PassThru
is specified, JSON files are not created and Azure resource objects are returned to the pipeline instead.
Type: SwitchParameter\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: False\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#-keepduplicates","title":"-KeepDuplicates","text":"Determines if Azure policy definitions that duplicate existing built-in rules are exported. By default, duplicates are not exported.
This only applies to built-in policy definitions.
Type: SwitchParameter\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: False\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#-resourcegroup","title":"-ResourceGroup","text":"A name or hashtable of the Resource Group in the assignment data file. This Resource Group specified here will be used to resolve the resourceGroup()
function.
When the name of Resource Group is specified, the Resource Group will be looked up and used during export. This requires an authenticated connection to Azure with permissions to read the specified Resource Group.
Alternately, a hashtable of a Resource Group object can be specified. This option does not require an authenticated Azure connection. The hashtable will override the defaults for any specified properties.
For more details see about_PSRule_Azure_Configuration.
Type: ResourceGroupReference\nParameter Sets: (All)\nAliases: ResourceGroupName\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#-subscription","title":"-Subscription","text":"The name or hashtable of the Subscription in the assignment data file. This subscription specified here will be used to resolve the subscription()
function.
When a subscription name is specified, the Subscription will be looked up and used during export. This requires an authenticated connection to Azure with permissions to read the specified Subscription.
Alternately, a hashtable of a Subscription object can be specified. This option does not require an authenticated Azure connection. The hashtable will override the defaults for any specified properties.
For more details see about_PSRule_Azure_Configuration.
Type: SubscriptionReference\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#commonparameters","title":"CommonParameters","text":"This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.
"},{"location":"commands/Export-AzPolicyAssignmentRuleData/#inputs","title":"INPUTS","text":""},{"location":"commands/Export-AzPolicyAssignmentRuleData/#systemstring","title":"System.String","text":""},{"location":"commands/Export-AzPolicyAssignmentRuleData/#outputs","title":"OUTPUTS","text":""},{"location":"commands/Export-AzPolicyAssignmentRuleData/#systemiofileinfo","title":"System.IO.FileInfo","text":""},{"location":"commands/Export-AzPolicyAssignmentRuleData/#systemobject","title":"System.Object","text":""},{"location":"commands/Export-AzPolicyAssignmentRuleData/#notes","title":"Notes","text":""},{"location":"commands/Export-AzPolicyAssignmentRuleData/#related-links","title":"RELATED LINKS","text":""},{"location":"commands/Export-AzRuleData/","title":"Export-AzRuleData","text":"Export resource configuration data from one or more Azure subscriptions.
"},{"location":"commands/Export-AzRuleData/#syntax","title":"SYNTAX","text":""},{"location":"commands/Export-AzRuleData/#default-default","title":"Default (Default)","text":"Export-AzRuleData [[-OutputPath] <String>] [-Subscription <String[]>] [-Tenant <String[]>]\n [-ResourceGroupName <String[]>] [-Tag <Hashtable>] [-PassThru] [-SkipDiscovery] [-ResourceId <String[]>]\n [-WhatIf] [-Confirm] [<CommonParameters>]\n
"},{"location":"commands/Export-AzRuleData/#all","title":"All","text":"Export-AzRuleData [[-OutputPath] <String>] [-ResourceGroupName <String[]>] [-Tag <Hashtable>] [-PassThru]\n [-All] [-WhatIf] [-Confirm] [<CommonParameters>]\n
"},{"location":"commands/Export-AzRuleData/#description","title":"Description","text":"Export resource configuration data from deployed resources in one or more Azure subscriptions.
If no filters are specified then the current subscription context will be exported. i.e. Get-AzContext
To export all subscriptions contexts use the -All
switch. When the -All
switch is used, all subscriptions contexts will be exported. i.e. Get-AzContext -ListAvailable
Resource data will be exported to the current working directory by default as JSON files, one per subscription.
"},{"location":"commands/Export-AzRuleData/#examples","title":"Examples","text":""},{"location":"commands/Export-AzRuleData/#example-1","title":"Example 1","text":"Export-AzRuleData\n
Directory: C:\\\n\nMode LastWriteTime Length Name\n---- ------------- ------ ----\n-a---- 1/07/2019 10:03 AM 7304948 00000000-0000-0000-0000-000000000001.json\n
Export resource configuration data from current subscription context.
"},{"location":"commands/Export-AzRuleData/#example-2","title":"Example 2","text":"Export-AzRuleData -Subscription 'Contoso Production', 'Contoso Non-production'\n
Directory: C:\\\n\nMode LastWriteTime Length Name\n---- ------------- ------ ----\n-a---- 1/07/2019 10:03 AM 7304948 00000000-0000-0000-0000-000000000001.json\n-a---- 1/07/2019 10:03 AM 7304948 00000000-0000-0000-0000-000000000002.json\n
Export resource configuration data from subscriptions by name.
"},{"location":"commands/Export-AzRuleData/#example-3","title":"Example 3","text":"Export-AzRuleData -ResourceGroupName 'rg-app1-web', 'rg-app1-db'\n
Directory: C:\\\n\nMode LastWriteTime Length Name\n---- ------------- ------ ----\n-a---- 1/07/2019 10:03 AM 7304948 00000000-0000-0000-0000-000000000001.json\n
Export resource configuration data from two resource groups within the current subscription context.
"},{"location":"commands/Export-AzRuleData/#parameters","title":"PARAMETERS","text":""},{"location":"commands/Export-AzRuleData/#-all","title":"-All","text":"By default, resources from the current subscription context are extracted. Use -All
to extract resource data for all subscription contexts instead.
Type: SwitchParameter\nParameter Sets: All\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleData/#-outputpath","title":"-OutputPath","text":"The path to store generated JSON files containing resources.
Type: String\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: 0\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleData/#-passthru","title":"-PassThru","text":"By default, FileInfo objects are returned to the pipeline for each JSON file created. When -PassThru
is specified, JSON files are not created and Azure resource objects are returned to the pipeline instead.
Type: SwitchParameter\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleData/#-resourcegroupname","title":"-ResourceGroupName","text":"Optionally filter resources by Resource Group name.
Type: String[]\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleData/#-subscription","title":"-Subscription","text":"Optionally filter resources by subscription, Id or Name.
Type: String[]\nParameter Sets: Default\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleData/#-tag","title":"-Tag","text":"Optionally filter resources based on tag.
Type: Hashtable\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleData/#-tenant","title":"-Tenant","text":"Optionally filter resources by a unique Tenant identifer.
Type: String[]\nParameter Sets: Default\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleData/#-resourceid","title":"-ResourceId","text":"A list of resource Ids to expand.
Type: String[]\nParameter Sets: Default\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: True (ByValue)\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleData/#-skipdiscovery","title":"-SkipDiscovery","text":"Determines if resource discovery is skipped. When skipped resources are expanded based on provided resource Ids.
Type: SwitchParameter\nParameter Sets: Default\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleData/#-confirm","title":"-Confirm","text":"Prompts you for confirmation before running the cmdlet.
Type: SwitchParameter\nParameter Sets: (All)\nAliases: cf\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleData/#-whatif","title":"-WhatIf","text":"Shows what would happen if the cmdlet runs. The cmdlet is not run.
Type: SwitchParameter\nParameter Sets: (All)\nAliases: wi\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleData/#commonparameters","title":"CommonParameters","text":"This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.
"},{"location":"commands/Export-AzRuleData/#inputs","title":"INPUTS","text":""},{"location":"commands/Export-AzRuleData/#none","title":"None","text":""},{"location":"commands/Export-AzRuleData/#outputs","title":"OUTPUTS","text":""},{"location":"commands/Export-AzRuleData/#systemiofileinfo","title":"System.IO.FileInfo","text":"Return FileInfo
for each of the output files created, one per subscription. This is the default.
Return an object for each Azure resource, and configuration exported. This is returned when the -PassThru
switch is used.
Export resource configuration data from Azure templates.
"},{"location":"commands/Export-AzRuleTemplateData/#syntax","title":"SYNTAX","text":""},{"location":"commands/Export-AzRuleTemplateData/#template-default","title":"Template (Default)","text":"Export-AzRuleTemplateData [[-Name] <String>] -TemplateFile <String> [-ParameterFile <String[]>]\n [-ResourceGroup <ResourceGroupReference>] [-Subscription <SubscriptionReference>] [-OutputPath <String>]\n [-PassThru] [<CommonParameters>]\n
"},{"location":"commands/Export-AzRuleTemplateData/#source","title":"Source","text":"Export-AzRuleTemplateData [[-Name] <String>] -SourceFile <String> [-ResourceGroup <ResourceGroupReference>]\n [-Subscription <SubscriptionReference>] [-OutputPath <String>] [-PassThru] [<CommonParameters>]\n
"},{"location":"commands/Export-AzRuleTemplateData/#description","title":"Description","text":"Export resource configuration data by merging Azure Resource Manager (ARM) template and parameter files. Template and parameters are merged by resolving template parameters, variables and functions.
This function does not check template files for strict compliance with Azure schemas.
By default this is an offline process, requiring no connectivity to Azure. Some functions that may be included in templates dynamically query Azure for current state. For these functions standard placeholder values are used by default. Functions that use placeholders include reference
, list*
.
The subscription()
function will return the following unless overridden:
The resourceGroup()
function will return the following unless overridden:
To override, set the AZURE_SUBSCRIPTION
and AZURE_RESOURCE_GROUP
in configuration.
Currently the following limitations apply:
environment
template function always returns values for Azure public cloud.reference()
function will return objects for resources within the same template. For resources that are not in the same template, a placeholder value is used instead.Export-AzRuleTemplateData -TemplateFile .\\template.json -ParameterFile .\\parameters.json;\n
Export resource configuration data based on merging a template and parameter file together.
"},{"location":"commands/Export-AzRuleTemplateData/#example-2","title":"Example 2","text":"Get-AzRuleTemplateLink | Export-AzRuleTemplateData;\n
Recursively scan the current working path and export linked templates.
"},{"location":"commands/Export-AzRuleTemplateData/#example-3","title":"Example 3","text":"$subscription = @{\n subscriptionId = 'nnnnnnnn-nnnn-nnnn-nnnn-nnnnnnnnnnnn'\n displayName = 'My Azure Subscription'\n tenantId = 'nnnnnnnn-nnnn-nnnn-nnnn-nnnnnnnnnnnn'\n}\nGet-AzRuleTemplateLink | Export-AzRuleTemplateData -Subscription $subscription;\n
Export linked templates from the current working path using a specific subscription.
"},{"location":"commands/Export-AzRuleTemplateData/#example-4","title":"Example 4","text":"$rg = @{\n name = 'my-test-rg'\n location = 'australiaeast'\n tags = @{\n env = 'prod'\n }\n}\nGet-AzRuleTemplateLink | Export-AzRuleTemplateData -ResourceGroup $rg;\n
Export linked templates from the current working path using a specific resource group.
"},{"location":"commands/Export-AzRuleTemplateData/#parameters","title":"PARAMETERS","text":""},{"location":"commands/Export-AzRuleTemplateData/#-name","title":"-Name","text":"The name of the deployment. If not specified export-<xxxxxxxx>
will be used as the name of the deployment.
This parameter is used by the deployment()
function and is also used to name the output file.
Type: String\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: 0\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleTemplateData/#-templatefile","title":"-TemplateFile","text":"The absolute or relative file path to an Azure Resource Manager template file.
Type: String\nParameter Sets: Template\nAliases:\n\nRequired: True\nPosition: Named\nDefault value: None\nAccept pipeline input: True (ByPropertyName)\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleTemplateData/#-parameterfile","title":"-ParameterFile","text":"The absolute or relative file path to one or more Azure Resource Manager template parameter files.
Type: String[]\nParameter Sets: Template\nAliases: TemplateParameterFile\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: True (ByPropertyName)\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleTemplateData/#-sourcefile","title":"-SourceFile","text":"The absolute or relative file path to a file of a Bicep file.
Type: String\nParameter Sets: Source\nAliases: f, FullName\n\nRequired: True\nPosition: Named\nDefault value: None\nAccept pipeline input: True (ByPropertyName)\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleTemplateData/#-outputpath","title":"-OutputPath","text":"The path to store generated JSON files containing resources.
If this parameter is not specified, output will be written to the current working path. The file name resources-<name>.json
will be used when this parameter is not set or a directory is specified. Where <name>
is the name of the deployment specified by -Name
.
This parameter has no affect when -PassThru
is used.
Type: String\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: $PWD\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleTemplateData/#-passthru","title":"-PassThru","text":"By default, FileInfo objects are returned to the pipeline for each JSON file created. When -PassThru
is specified, JSON files are not created and Azure resource objects are returned to the pipeline instead.
Type: SwitchParameter\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleTemplateData/#-resourcegroup","title":"-ResourceGroup","text":"A name or hashtable of the Resource Group where the deployment will occur. This Resource Group specified here will be used to resolve the resourceGroup()
function.
When the name of Resource Group is specified, the Resource Group will be looked up and used during export. This requires an authenticated connection to Azure with permissions to read the specified Resource Group.
Alternately, a hashtable of a Resource Group object can be specified. This option does not require an authenticated Azure connection. The hashtable will override the defaults for any specified properties.
For more details see about_PSRule_Azure_Configuration.
Type: ResourceGroupReference\nParameter Sets: (All)\nAliases: ResourceGroupName\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleTemplateData/#-subscription","title":"-Subscription","text":"The name or hashtable of the Subscription where the deployment will occur. This subscription specified here will be used to resolve the subscription()
function.
When a subscription name is specified, the Subscription will be looked up and used during export. This requires an authenticated connection to Azure with permissions to read the specified Subscription.
Alternately, a hashtable of a Subscription object can be specified. This option does not require an authenticated Azure connection. The hashtable will override the defaults for any specified properties.
For more details see about_PSRule_Azure_Configuration.
Type: SubscriptionReference\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Export-AzRuleTemplateData/#commonparameters","title":"CommonParameters","text":"This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.
"},{"location":"commands/Export-AzRuleTemplateData/#inputs","title":"INPUTS","text":""},{"location":"commands/Export-AzRuleTemplateData/#systemstring","title":"System.String","text":""},{"location":"commands/Export-AzRuleTemplateData/#systemstring_1","title":"System.String[]","text":""},{"location":"commands/Export-AzRuleTemplateData/#outputs","title":"OUTPUTS","text":""},{"location":"commands/Export-AzRuleTemplateData/#systemiofileinfo","title":"System.IO.FileInfo","text":""},{"location":"commands/Export-AzRuleTemplateData/#systemobject","title":"System.Object","text":""},{"location":"commands/Export-AzRuleTemplateData/#notes","title":"Notes","text":""},{"location":"commands/Export-AzRuleTemplateData/#related-links","title":"RELATED LINKS","text":""},{"location":"commands/Get-AzPolicyAssignmentDataSource/","title":"Get-AzPolicyAssignmentDataSource","text":"Get policy assignment sources.
"},{"location":"commands/Get-AzPolicyAssignmentDataSource/#syntax","title":"SYNTAX","text":"Get-AzPolicyAssignmentDataSource [-InputPath <String[]>] [[-Path] <String>] [<CommonParameters>]\n
"},{"location":"commands/Get-AzPolicyAssignmentDataSource/#description","title":"Description","text":"This is an experimental cmdlet.
Get policy assignment sources. By default *.assignment.json
sources are discovered from the current working directory.
Get-AzPolicyAssignmentDataSource\n
AssignmentFile\n--------------\nC:\\00000000-0000-0000-0000-000000000001.assignment.json\nC:\\Users\\user\\00000000-0000-0000-0000-000000000002.assignment.json\n
Gets policy assignment sources from any *.assignment.json
sources within any folder in the current working directory path.
A path or filter to search for assignment files within the path specified by -Path
. By default, files with *.assignment.json
suffix will be used.
When searching for assignment files all sub-directories will be scanned. To perform a shallow search, prefix input paths with ./
.
Type: String[]\nParameter Sets: (All)\nAliases: f, AssignmentFile, FullName\n\nRequired: False\nPosition: Named\nDefault value: '*.assignment.json'\nAccept pipeline input: True (ByPropertyName)\nAccept wildcard characters: True\n
"},{"location":"commands/Get-AzPolicyAssignmentDataSource/#-path","title":"-Path","text":"Sets the path to search for assignment files in. By default, this is the current working path.
Type: String\nParameter Sets: (All)\nAliases: p\n\nRequired: False\nPosition: 0\nDefault value: $PWD\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Get-AzPolicyAssignmentDataSource/#commonparameters","title":"CommonParameters","text":"This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.
"},{"location":"commands/Get-AzPolicyAssignmentDataSource/#inputs","title":"INPUTS","text":""},{"location":"commands/Get-AzPolicyAssignmentDataSource/#systemstring","title":"System.String[]","text":""},{"location":"commands/Get-AzPolicyAssignmentDataSource/#outputs","title":"OUTPUTS","text":""},{"location":"commands/Get-AzPolicyAssignmentDataSource/#psrulerulesazurepipelinepolicyassignmentsource","title":"PSRule.Rules.Azure.Pipeline.PolicyAssignmentSource","text":""},{"location":"commands/Get-AzPolicyAssignmentDataSource/#notes","title":"Notes","text":""},{"location":"commands/Get-AzPolicyAssignmentDataSource/#related-links","title":"RELATED LINKS","text":""},{"location":"commands/Get-AzRuleTemplateLink/","title":"Get-AzRuleTemplateLink","text":"Get a metadata link to a Azure template file.
"},{"location":"commands/Get-AzRuleTemplateLink/#syntax","title":"SYNTAX","text":"Get-AzRuleTemplateLink [[-InputPath] <String[]>] [-SkipUnlinked] [[-Path] <String>] [<CommonParameters>]\n
"},{"location":"commands/Get-AzRuleTemplateLink/#description","title":"Description","text":"Gets a link between an Azure Resource Manager (ARM) parameter file and its referenced template file. Parameter files reference a template file by defining metadata. Alternatively, template files are discovered by naming convention.
By default, when parameter files without a matching template are discovered an error is raised.
To reference a template, set the metadata.template
property to a file path. Referencing templates outside of the path specified with -Path
is not permitted.
To discover template files by naming convention:
.parameters.json
.<templateName>.parameters.json
.<templateName>.json
.For more information see the about_PSRule_Azure_Metadata_Link topic.
"},{"location":"commands/Get-AzRuleTemplateLink/#examples","title":"Examples","text":""},{"location":"commands/Get-AzRuleTemplateLink/#example-1","title":"Example 1","text":"Get-AzRuleTemplateLink\n
Get links from any *.parameters.json
files within any folder in the current working path.
A path or filter to search for parameter files within the path specified by -Path
. By default, files with *.parameters.json
suffix will be used.
When searching for parameter files all sub-directories will be scanned. To perform a shallow search, prefix input paths with ./
.
Type: String[]\nParameter Sets: (All)\nAliases: f, TemplateParameterFile, FullName\n\nRequired: False\nPosition: 1\nDefault value: '*.parameters.json'\nAccept pipeline input: True (ByPropertyName)\nAccept wildcard characters: True\n
"},{"location":"commands/Get-AzRuleTemplateLink/#-skipunlinked","title":"-SkipUnlinked","text":"Use this option to ignore parameter files that have no matching template. By default, when parameter files without a matching template are discovered an error is raised.
Type: SwitchParameter\nParameter Sets: (All)\nAliases:\n\nRequired: False\nPosition: Named\nDefault value: None\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Get-AzRuleTemplateLink/#-path","title":"-Path","text":"Sets the path to search for parameter files in. By default, this is the current working path.
Type: String\nParameter Sets: (All)\nAliases: p\n\nRequired: False\nPosition: 0\nDefault value: $PWD\nAccept pipeline input: False\nAccept wildcard characters: False\n
"},{"location":"commands/Get-AzRuleTemplateLink/#commonparameters","title":"CommonParameters","text":"This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.
"},{"location":"commands/Get-AzRuleTemplateLink/#inputs","title":"INPUTS","text":""},{"location":"commands/Get-AzRuleTemplateLink/#systemstring","title":"System.String[]","text":""},{"location":"commands/Get-AzRuleTemplateLink/#outputs","title":"OUTPUTS","text":""},{"location":"commands/Get-AzRuleTemplateLink/#psrulerulesazuredatametadataitemplatelink","title":"PSRule.Rules.Azure.Data.Metadata.ITemplateLink","text":""},{"location":"commands/Get-AzRuleTemplateLink/#notes","title":"Notes","text":""},{"location":"commands/Get-AzRuleTemplateLink/#related-links","title":"RELATED LINKS","text":"about_PSRule_Azure_Metadata_Link
"},{"location":"commands/PSRule.Rules.Azure/","title":"PSRule.Rules.Azure Module","text":""},{"location":"commands/PSRule.Rules.Azure/#description","title":"Description","text":"Validate Azure resources and infrastructure as code using PSRule.
"},{"location":"commands/PSRule.Rules.Azure/#psrule-cmdlets","title":"PSRule Cmdlets","text":""},{"location":"commands/PSRule.Rules.Azure/#export-azruledata","title":"Export-AzRuleData","text":"Export resource configuration data from one or more Azure subscriptions.
"},{"location":"commands/PSRule.Rules.Azure/#export-azruletemplatedata","title":"Export-AzRuleTemplateData","text":"Export resource configuration data from Azure templates.
"},{"location":"commands/PSRule.Rules.Azure/#get-azruletemplatelink","title":"Get-AzRuleTemplateLink","text":"Get a metadata link to a Azure template file.
"},{"location":"concepts/about_PSRule_Azure_Configuration/","title":"Configuration options","text":"Describes PSRule configuration options specific to PSRule for Azure.
"},{"location":"concepts/about_PSRule_Azure_Configuration/#description","title":"Description","text":"PSRule exposes configuration options that can be used to customize execution of PSRule.Rules.Azure
. This topic describes what configuration options are available.
PSRule configuration options can be specified by setting the configuration option in ps-rule.yaml
. Additionally, configuration options can be configured in a baseline or set at runtime. For details of setting configuration options see PSRule options.
The following configurations options are available for use:
AZURE_STORAGE_DEFENDER_PER_ACCOUNT
This configuration option determines the minimum version of Kubernetes for AKS clusters and node pools. Rules that check the Kubernetes version fail when the version is older than the version specified.
Syntax:
configuration:\n Azure_AKSMinimumVersion: string # A version string\n
Default:
# YAML: The default Azure_AKSMinimumVersion configuration option\nconfiguration:\n Azure_AKSMinimumVersion: 1.20.5\n
Example:
# YAML: Set the Azure_AKSMinimumVersion configuration option to 1.19.7\nconfiguration:\n Azure_AKSMinimumVersion: 1.19.7\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_aksnodeminimummaxpods","title":"Azure_AKSNodeMinimumMaxPods","text":"This configuration option determines the minimum allowed max pods setting per node pool. When an AKS cluster node pool is created, a maxPods
option is used to determine the maximum number of pods for each node in the node pool.
Syntax:
configuration:\n Azure_AKSNodeMinimumMaxPods: integer\n
Default:
# YAML: The default Azure_AKSNodeMinimumMaxPods configuration option\nconfiguration:\n Azure_AKSNodeMinimumMaxPods: 50\n
Example:
# YAML: Set the Azure_AKSNodeMinimumMaxPods configuration option to 30\nconfiguration:\n Azure_AKSNodeMinimumMaxPods: 30\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_allowedregions","title":"Azure_AllowedRegions","text":"This configuration option specifies a list of allowed locations that resources can be deployed to. Rules that check the location of Azure resources fail when a resource or resource group is created in a different region.
By default, Azure_AllowedRegions
is not configured. The rule Azure.Resource.AllowedRegions
is skipped when no allowed locations are configured.
Syntax:
configuration:\n Azure_AllowedRegions: array # An array of regions\n
Default:
# YAML: The default Azure_AllowedRegions configuration option\nconfiguration:\n Azure_AllowedRegions: []\n
Example:
# YAML: Set the Azure_AllowedRegions configuration option to Australia East, Australia South East\nconfiguration:\n Azure_AllowedRegions:\n - 'australiaeast'\n - 'australiasoutheast'\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_minimumcertificatelifetime","title":"Azure_MinimumCertificateLifetime","text":"This configuration option determines the minimum number of days allowed before certificate expiry. Rules that check certificate lifetime fail when the days remaining before expiry drop below this number.
Syntax:
configuration:\n Azure_MinimumCertificateLifetime: integer\n
Default:
# YAML: The default Azure_MinimumCertificateLifetime configuration option\nconfiguration:\n Azure_MinimumCertificateLifetime: 30\n
Example:
# YAML: Set the Azure_MinimumCertificateLifetime configuration option to 90\nconfiguration:\n Azure_MinimumCertificateLifetime: 90\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_parameter_file_expansion","title":"AZURE_PARAMETER_FILE_EXPANSION","text":"This configuration option determines if Azure template parameter files will automatically be expanded. By default, parameter files will not be automatically expanded.
Parameter files are expanded when PSRule cmdlets with the -Format File
parameter are used.
Syntax:
configuration:\n AZURE_PARAMETER_FILE_EXPANSION: bool\n
Default:
# YAML: The default AZURE_PARAMETER_FILE_EXPANSION configuration option\nconfiguration:\n AZURE_PARAMETER_FILE_EXPANSION: false\n
Example:
# YAML: Set the AZURE_PARAMETER_FILE_EXPANSION configuration option to enable expansion\nconfiguration:\n AZURE_PARAMETER_FILE_EXPANSION: true\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_policy_waiver_max_expiry","title":"AZURE_POLICY_WAIVER_MAX_EXPIRY","text":"This configuration option determines the maximum number of days in the future for a waiver policy exemption.
Syntax:
configuration:\n AZURE_POLICY_WAIVER_MAX_EXPIRY: integer\n
Default:
# YAML: The default AZURE_POLICY_WAIVER_MAX_EXPIRY configuration option\nconfiguration:\n AZURE_POLICY_WAIVER_MAX_EXPIRY: 366\n
Example:
# YAML: Set the AZURE_POLICY_WAIVER_MAX_EXPIRY configuration option to 90\nconfiguration:\n AZURE_POLICY_WAIVER_MAX_EXPIRY: 90\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_resource_group","title":"AZURE_RESOURCE_GROUP","text":"This configuration option sets the resource group object used by the resourceGroup()
function. Configure this option to change the resource group object when using exporting templates for analysis. Provided properties will override the default. Any properties that are not provided with use the defaults as specified below.
This configuration option will be ignored when -ResourceGroup
is used with Export-AzRuleTemplateData
.
Syntax:
configuration:\n AZURE_RESOURCE_GROUP:\n name: string\n location: string\n tags: object\n properties:\n provisioningState: string\n
Default:
# YAML: The default AZURE_RESOURCE_GROUP configuration option\nconfiguration:\n AZURE_RESOURCE_GROUP:\n name: 'ps-rule-test-rg'\n location: 'eastus'\n tags: { }\n properties:\n provisioningState: 'Succeeded'\n
Example:
# YAML: Override the location of the resource group object.\nconfiguration:\n AZURE_RESOURCE_GROUP:\n location: 'australiasoutheast'\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_subscription","title":"AZURE_SUBSCRIPTION","text":"This configuration option sets the subscription object used by the subscription()
function. Configure this option to change the subscription object when using exporting templates for analysis. Provided properties will override the default. Any properties that are not provided with use the defaults as specified below.
This configuration option will be ignored when -Subscription
is used with Export-AzRuleTemplateData
.
Syntax:
configuration:\n AZURE_SUBSCRIPTION:\n subscriptionId: string\n tenantId: string\n displayName: string\n state: string\n
Default:
# YAML: The default AZURE_SUBSCRIPTION configuration option\nconfiguration:\n AZURE_SUBSCRIPTION:\n subscriptionId: 'ffffffff-ffff-ffff-ffff-ffffffffffff'\n tenantId: 'ffffffff-ffff-ffff-ffff-ffffffffffff'\n displayName: 'PSRule Test Subscription'\n state: 'NotDefined'\n
Example:
# YAML: Override the display name of the subscription object\n AZURE_SUBSCRIPTION:\n displayName: 'My test subscription'\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_policy_ignore_list","title":"AZURE_POLICY_IGNORE_LIST","text":"This configuration option configures a custom list policy definitions to ignore when exporting policy to rules. In addition to the custom list, a built-in list of policies are ignored. The built-in list can be found here.
Configure this option to ignore policy definitions that:
Syntax:
configuration:\n AZURE_POLICY_IGNORE_LIST: array\n
Default:
# YAML: The default AZURE_POLICY_IGNORE_LIST configuration option\nconfiguration:\n AZURE_POLICY_IGNORE_LIST: []\n
Example:
# YAML: Add a custom policy definition to ignore\nconfiguration:\n AZURE_POLICY_IGNORE_LIST:\n - '/providers/Microsoft.Authorization/policyDefinitions/1f314764-cb73-4fc9-b863-8eca98ac36e9'\n - '/providers/Microsoft.Authorization/policyDefinitions/b54ed75b-3e1a-44ac-a333-05ba39b99ff0'\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_policy_rule_prefix","title":"AZURE_POLICY_RULE_PREFIX","text":"This configuration option sets the prefix for names of exported rules. Configure this option to change the prefix, which defaults to Azure
.
This configuration option will be ignored when -Prefix
is used with Export-AzPolicyAssignmentRuleData
.
Syntax:
configuration:\n AZURE_POLICY_RULE_PREFIX: string\n
Default:
# YAML: The default AZURE_POLICY_RULE_PREFIX configuration option\nconfiguration:\n AZURE_POLICY_RULE_PREFIX: 'Azure'\n
Example:
# YAML: Override the prefix of exported policy rules\n AZURE_POLICY_RULE_PREFIX: 'AzureCustomPrefix'\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_apim_min_api_version","title":"AZURE_APIM_MIN_API_VERSION","text":"This configuration option sets the minimum API version used for control plane API calls to API Management instances. Configure this option to change the minimum API version, which defaults to '2021-08-01'
.
Syntax:
configuration:\n AZURE_APIM_MIN_API_VERSION: string\n
Default:
# YAML: The default AZURE_APIM_MIN_API_VERSION configuration option\nconfiguration:\n AZURE_APIM_MIN_API_VERSION: '2021-08-01'\n
Example:
# YAML: Set the AZURE_APIM_MIN_API_VERSION configuration option to '2021-12-01-preview'\nconfiguration:\n AZURE_APIM_MIN_API_VERSION: '2021-12-01-preview'\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_cosmos_defender_per_account","title":"AZURE_COSMOS_DEFENDER_PER_ACCOUNT","text":"This configuration option enables validation for that each Cosmos DB account is associated with a Microsoft Defender for Cosmos DB resource level plan. Configure this option to enable the per account validation, which defaults to false
.
Syntax:
configuration:\n AZURE_COSMOS_DEFENDER_PER_ACCOUNT: boolean\n
Default:
# YAML: The default AZURE_COSMOS_DEFENDER_PER_ACCOUNT configuration option\nconfiguration:\n AZURE_COSMOS_DEFENDER_PER_ACCOUNT: false\n
Example:
# YAML: Set the AZURE_COSMOS_DEFENDER_PER_ACCOUNT configuration option to true\nconfiguration:\n AZURE_COSMOS_DEFENDER_PER_ACCOUNT: true\n
"},{"location":"concepts/about_PSRule_Azure_Configuration/#azure_storage_defender_per_account","title":"AZURE_STORAGE_DEFENDER_PER_ACCOUNT","text":"This configuration option enables validation for that each storage account is associated with a Microsoft Defender for Storage resource level plan. Configure this option to enable the per account validation, which defaults to false
.
Syntax:
configuration:\n AZURE_STORAGE_DEFENDER_PER_ACCOUNT: boolean\n
Default:
# YAML: The default AZURE_STORAGE_DEFENDER_PER_ACCOUNT configuration option\nconfiguration:\n AZURE_STORAGE_DEFENDER_PER_ACCOUNT: false\n
Example:
# YAML: Set the AZURE_STORAGE_DEFENDER_PER_ACCOUNT configuration option to true\nconfiguration:\n AZURE_STORAGE_DEFENDER_PER_ACCOUNT: true\n
"},{"location":"concepts/about_PSRule_Azure_Metadata_Link/","title":"PSRule_Azure_Metadata_Link","text":""},{"location":"concepts/about_PSRule_Azure_Metadata_Link/#about_psrule_azure_metadata_link","title":"about_PSRule_Azure_Metadata_Link","text":"Describes how Azure Resource Manager (ARM) parameter files reference a template file.
"},{"location":"concepts/about_PSRule_Azure_Metadata_Link/#description","title":"Description","text":"Azure Resource Manager (ARM) supports storing additional metadata within parameter files. PSRule uses this metadata to link template and parameter files together to improve unit testing of templates.
To reference a template within a parameter file:
metadata.template
property to the template../
. When ./
is not used, the template with is relative to the -Path
parameter.For example:
{\n \"$schema\": \"https://schema.management.azure.com/schemas/2015-01-01/deploymentParameters.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"metadata\": {\n \"template\": \"./Resources.Template.json\"\n },\n \"parameters\": {\n }\n}\n
"},{"location":"concepts/about_PSRule_Azure_Metadata_Link/#see-also","title":"SEE ALSO","text":"PSRule for Azure allows you to export your current Azure Policy assignments out as rules to enforce controls during development. This allows you to:
Abstract
This topic covers using policy as rules which allows you to use Azure Policy as rules to test Infrastructure as Code.
Experimental - Learn more
Policy as rules are a work in progress. As always if you find bugs/ errors or if something just doesn't work as your expect it to, please let us know. You can log a bug on GitHub or provide feedback here.
"},{"location":"concepts/policy-as-rules/#limitations","title":"Limitations","text":"This feature does not support:
Disabled
are ignored.Using policy as rules is a two step process:
Run Export-AzPolicyAssignmentData
to export assignments from Azure to an *.assignment.json
file.
Key points:
Az
PowerShell module and using Connect-AzAccount
.Set-AzContext
.Run Export-AzPolicyAssignmentRuleData
to convert assignments to rules. To run this command an -AssignmentFile
parameter with the path to the assignment JSON file generated in the previous step.
After the command completes a new file *.Rule.jsonc
should be generated containing generated rules.
PSRule for Azure allows you to:
Azure
. To change the prefix:-RulePrefix
parameter when running Export-AzPolicyAssignmentRuleData
. ORAZURE_POLICY_RULE_PREFIX
configuration option in ps-rule.yaml
.AZURE_POLICY_IGNORE_LIST
configuration option in ps-rule.yaml
. This option allows you to prevent specific policies from being exported as rules.For example:
ps-rule.yamlconfiguration:\n AZURE_POLICY_RULE_PREFIX: MyOrg\n AZURE_POLICY_IGNORE_LIST:\n - /providers/Microsoft.Authorization/policyDefinitions/1f314764-cb73-4fc9-b863-8eca98ac36e9\n - /providers/Microsoft.Authorization/policyDefinitions/b54ed75b-3e1a-44ac-a333-05ba39b99ff0\n
"},{"location":"concepts/policy-as-rules/#generated-baseline","title":"Generated baseline","text":"v1.33.0
When exporting policies, PSRule for Azure will automatically generate a baseline including any generated rules. By default, this baseline is called Azure.PolicyBaseline.All
. If you change the prefix of generated rules the baseline will be named <Prefix>.PolicyBaseline.All
.
See Using baselines for examples on how to use a baseline in a run.
"},{"location":"concepts/policy-as-rules/#duplicate-policies","title":"Duplicate policies","text":"v1.33.0
When exporting policies, you may encounter definitions that are duplicates of existing rules shipped with PSRule for Azure. By default, built-in Azure policies that are duplicates of existing rules are ignored. Additionally, PSRule for Azure will automatically switch in existing rules into the generated baseline.
Note
This only applies to built-in Azure policies that are duplicates of existing rules. Custom policies are not effected.
The list of built-in policies that are duplicates can be viewed here. If you believe a policy is missing from this list, please open an issue.
This allows you to:
To override this behavior use the -KeepDuplicates
parameter switch when running Export-AzPolicyAssignmentRuleData
.
By default, PSRule will attempt to read and test all files. You can configure options to:
Abstract
This topic covers how you can configure PSRule to ignore files, specific rules, or rules for special cases.
"},{"location":"concepts/suppression/#excluding-a-rule","title":"Excluding a rule","text":"Docs
You can exclude a rule to effectively disable the rule. When excluded, a rule is not used to test any Azure resources.
To exclude a rule, set the Rule.Exclude
option within the ps-rule.yaml
file.
rule:\n exclude:\n # Ignore the following rules for all resources\n - Azure.VM.UseHybridUseBenefit\n - Azure.VM.Standalone\n
"},{"location":"concepts/suppression/#suppress-a-rule-individually","title":"Suppress a rule individually","text":"Docs
You can suppress a rule to effectively skip or ignore a rule for a specific case or exception.
To suppress a rule, set Suppression
option within the ps-rule.yaml
file. PSRule allows you to specify the name of the rule and the name of the resources that will be suppressed.
suppression:\n Azure.Storage.SoftDelete:\n # Ignore soft delete on the following non-production storage accounts\n - storagedeveus6jo36t\n - storagedeveus1df278\n
Tip
Use comments within ps-rule.yaml
to describe the reason why rules are excluded or suppressed. Meaningful comments help during peer review within a Pull Request (PR). Also consider including a date if the exclusions or suppressions are temporary.
Docs
If you need to commonly suppress a rule for multiple resources you can use a Suppression Group. A Suppression Group allow you to define a condition for when a rule should be suppressed.
Example
For example, suppose you want to suppress the Azure.Storage.SoftDelete
rule for Storage Accounts based on a tag.
A Suppression Group can be defined within a .Rule.yaml
file within the .ps-rule/
sub-directory. Create this directory in your repository or current working path if it doesn't already exist.
---\n# Synopsis: Ignore soft delete for development storage accounts\napiVersion: github.com/microsoft/PSRule/v1\nkind: SuppressionGroup\nmetadata:\n name: Local.IgnoreNonProdStorage\nspec:\n rule:\n - Azure.Storage.SoftDelete\n if:\n field: tags.env\n equals: dev\n
Learn
To learn more, see suppression groups and expressions.
"},{"location":"concepts/suppression/#ignoring-files","title":"Ignoring files","text":"Docs
To exclude or ignore files from being processed, configure the Input.PathIgnore option. This option allows you to ignore files using a path spec.
To ignore files with common extensions, set the Input.PathIgnore
option within the ps-rule.yaml
file.
input:\n pathIgnore:\n # Exclude files with these extensions\n - '*.md'\n - '*.png'\n # Exclude specific configuration files\n - 'bicepconfig.json'\n
To ignore all files with some exceptions, set the Input.PathIgnore
option within the ps-rule.yaml
file.
input:\n pathIgnore:\n # Exclude all files\n - '*'\n # Only process deploy.bicep files\n - '!**/deploy.bicep'\n
Tip
Some common file exclusions are recommended for working with Azure Bicep source files. See Configuring path exclusions for details.
"},{"location":"customization/enforce-codeowners/","title":"Enforcing code ownership","text":"Abstract
The following scenario extends on existing code ownership features available in your tool of choice. This topic covers static analysis testing for the content (specific Azure resource) within file paths. This allows you to:
Pull requests (PRs) are a key concept within common Git workflows and DevOps culture to enforce peer review. Code ownership provides a mechanism to require one or more specific people review changes prior to merging a PR.
For Git repositories in GitHub and Azure Repos, code ownership is controlled based on file path. If a person or team owns a file or file path they are required to review the changes proposed in the PR. The specifics of how many approvals and if approval is optional vs required is controlled by branch protection/ policies.
In the context of Azure Infrastructure as Code (IaC) - Azure Bicep/ ARM templates, these changes may:
PSRule allows teams to layer on additional rules to ensure Azure resources fall within the paths expected by code ownership.
Info
Code ownership is implemented through CODEOWNERS in GitHub and required reviewers in Azure Repos.
"},{"location":"customization/enforce-codeowners/#creating-a-new-rule","title":"Creating a new rule","text":"Within the .ps-rule/
sub-directory create a new file called Org.Azure.Rule.ps1
. Use the following snippet to populate the rule file:
# Synopsis: Policy exemptions must be stored under designated paths for review.\nRule 'Org.Azure.Policy.Path' -Type 'Microsoft.Authorization/policyExemptions' {\n $Assert.WithinPath($PSRule.Source['Parameter'], '.', @(\n 'deployments/policy/'\n ));\n}\n
Some key points to call out with the rule snippet include:
Org.Azure.Policy.Path
. Each rule name must be unique.Microsoft.Authorization/policyExemptions
. i.e. Policy exemptions.$Assert.WithinPath
ensures the specifies path is within the deployments/policy/
sub-directory.$PSRule.Source
exposes the source path for the resource. PSRule for Azure exposes a Template
and Parameter
source for resources originating from a template.Tip
For recommendations on naming and storing rules see storing custom rules.
"},{"location":"customization/enforce-codeowners/#binding-type","title":"Binding type","text":"Rules packaged within PSRule for Azure will automatically detect Policy Exemptions by their type properties. Standalone rules will get their type binding configuration from ps-rule.yaml
instead.
To configure type binding:
ps-rule.yaml
file within the root of the repository.# Configure binding options\nbinding:\n targetType:\n - 'resourceType'\n - 'type'\n
Some key points to call out include:
targetType
allows rules to use the -Type
parameter. Our custom rule uses -Type 'Microsoft.Authorization/policyExemptions'
.resourceType
property if it exists, alternative it will use type
. If neither property exists, PSRule will use the object type.To test the custom rule within Visual Studio Code, see How to install PSRule for Azure. Alternatively you can test the rule manually by running the following from a PowerShell terminal.
PowerShellAssert-PSRule -Path '.ps-rule/' -Module 'PSRule.Rules.Azure' `\n -InputPath . -Format File\n
"},{"location":"customization/enforce-codeowners/#sample-code","title":"Sample code","text":"Grab the full sample code for each of these files from:
With PSRule, you can layer on custom rules with to implement organization specific requirements. These custom rules work side-by-side with PSRule for Azure.
Use of resource and resource group tags is recommended in the WAF, however implementations may vary. You may want to use PSRule to enforce tagging or something similar early in a DevOps pipeline.
Abstract
The following scenario shows how to create a custom rule to validate Resource Group tags. The scenario walks you through the process so that you can apply the same concepts for similar requirements.
"},{"location":"customization/enforce-custom-tags/#creating-a-new-rule","title":"Creating a new rule","text":"Within the .ps-rule
sub-directory create a new file called Org.Azure.Rule.ps1
. Use the following snippet to populate the rule file:
# Synopsis: Resource Groups must have all mandatory tags defined.\nRule 'Org.Azure.RG.Tags' -Type 'Microsoft.Resources/resourceGroups' {\n $hasTags = $Assert.HasField($TargetObject, 'Tags')\n if (!$hasTags.Result) {\n return $hasTags\n }\n\n # <Code for custom tags goes here>\n}\n
Some key points to call out with the rule snippet include:
Org.Azure.RG.Tags
. Each rule name must be unique.Microsoft.Resources/resourceGroups
. i.e. Resource Groups.$Assert.HasField
ensures that Resource Group has a tags property.$TargetObject
automatically exposes the current resource being processed.Tip
For recommendations on naming and storing rules see storing custom rules.
"},{"location":"customization/enforce-custom-tags/#adding-mandatory-tags","title":"Adding mandatory tags","text":"To require specific tags to be configured on Resource Groups append this code to the rule.
# Require tags be case-sensitive\n$Assert.HasField($TargetObject.tags, 'costCentre', <# case-sensitive #> $True)\n$Assert.HasField($TargetObject.tags, 'env', $True)\n
Some key points to call out include:
$Assert.HasField
assertions are case-sensitive which differs from the previous snippet.The updated rule should look like:
# Synopsis: Resource Groups must have all mandatory tags defined.\nRule 'Org.Azure.RG.Tags' -Type 'Microsoft.Resources/resourceGroups' {\n $hasTags = $Assert.HasField($TargetObject, 'Tags')\n if (!$hasTags.Result) {\n return $hasTags\n }\n\n # Require tags be case-sensitive\n $Assert.HasField($TargetObject.tags, 'costCentre', <# case-sensitive #> $True)\n $Assert.HasField($TargetObject.tags, 'env', $True)\n}\n
"},{"location":"customization/enforce-custom-tags/#limiting-tags-values","title":"Limiting tags values","text":"To require these tags to only accept allowed values, append this code to the rule.
<#\nThe costCentre tag must:\n- Start with a letter.\n- Be followed by a number between 10000-9999999999.\n#>\n$Assert.Match($TargetObject, 'tags.costCentre', '^([A-Z][1-9][0-9]{4,9})$', $True)\n\n# Require specific values for environment tag\n$Assert.In($TargetObject, 'tags.env', @(\n 'dev',\n 'prod',\n 'uat'\n), $True)\n
Some key points to call out include:
tags.costCentre
.The completed rule should look like:
# Synopsis: Resource Groups must have all mandatory tags defined.\nRule 'Org.Azure.RG.Tags' -Type 'Microsoft.Resources/resourceGroups' {\n $hasTags = $Assert.HasField($TargetObject, 'Tags')\n if (!$hasTags.Result) {\n return $hasTags\n }\n\n # Require tags be case-sensitive.\n $Assert.HasField($TargetObject.tags, 'costCentre', <# case-sensitive #> $True)\n $Assert.HasField($TargetObject.tags, 'env', $True)\n\n <#\n The costCentre tag must:\n - Start with a letter.\n - Be followed by a number between 10000-9999999999.\n #>\n $Assert.Match($TargetObject, 'tags.costCentre', '^([A-Z][1-9][0-9]{4,9})$', $True)\n\n # Require specific values for environment tag.\n $Assert.In($TargetObject, 'tags.env', @(\n 'dev',\n 'prod',\n 'uat'\n ), $True)\n}\n
"},{"location":"customization/enforce-custom-tags/#binding-type","title":"Binding type","text":"Rules packaged within PSRule for Azure will automatically detect Resource Groups by their type properties. Standalone rules will get their type binding configuration from ps-rule.yaml
instead.
To configure type binding:
ps-rule.yaml
file within the root of the repository.# Configure binding options\nbinding:\n targetType:\n - 'resourceType'\n - 'type'\n
Some key points to call out include:
targetType
allows rules to use the -Type
parameter. Our custom rule uses -Type 'Microsoft.Resources/resourceGroups'
.resourceType
property if it exists, alternative it will use type
. If neither property exists, PSRule will use the object type.To test the custom rule within Visual Studio Code, see How to install PSRule for Azure. Alternatively you can test the rule manually by running the following from a PowerShell terminal.
Assert-PSRule -Path '.ps-rule/' -Module 'PSRule.Rules.Azure' -InputPath . -Format File\n
"},{"location":"customization/enforce-custom-tags/#sample-code","title":"Sample code","text":"Grab the full sample code for each of these files from:
As discussed in Azure.NSG.LateralTraversal, outbound management traffic is expected from some subnets. Subnets that are expected allow outbound management traffic may include:
As a result, you may want to suppress the Azure.NSG.LateralTraversal rule on NSGs for these special cases.
Abstract
This topic provides an example you can use to configure PSRule to ignore special case NSGs.
"},{"location":"customization/permit-outbound-management/#create-a-suppression-group","title":"Create a suppression group","text":"Within the .ps-rule
sub-directory create a file called Org.Azure.Suppressions.Rule.yaml
. If the .ps-rule
sub-directory does not exist, create it in the root of your repository.
Use the following snippet to populate the suppression group:
---\n# Synopsis: Ignore NSG lateral movement for management subnet NSGs such as Azure Bastion.\napiVersion: github.com/microsoft/PSRule/v1\nkind: SuppressionGroup\nmetadata:\n name: Org.Azure.PermitOutboundManagement\nspec:\n rule:\n - PSRule.Rules.Azure\\Azure.NSG.LateralTraversal\n if:\n allOf:\n - type: '.'\n in:\n - Microsoft.Network/networkSecurityGroups\n\n # Suppress NSGs with bastion or management in thier name\n - name: '.'\n contains:\n - bastion\n - management\n
Some key points to call out with the suppression group snippet include:
Org.Azure.PermitOutboundManagement
. Each resource name must be unique.PSRule.Rules.Azure\\Azure.NSG.LateralTraversal
.Microsoft.Network/networkSecurityGroups
.bastion
or management
. The suppression group uses expressions to determine when a resource is suppressed. Update this condition to match your environment. For example, the following NSGs would be suppressed by this suppression group:nsg-bastion-prod-eus-001
nsg-hub-management-prod-001
Tip
Expressions can be combined within a suppression group using allOf
or anyOf
operators.
PSRule for Azure covers common use cases that align to the Microsoft Azure Well-Architected Framework (WAF). In addition to WAF alignment you may have a requirement to enforce organization specific rules.
For example:
PSRule allows custom rules to be layered on. These custom rules work side-by-side with PSRule for Azure.
"},{"location":"customization/storing-custom-rules/#using-a-standard-file-path","title":"Using a standard file path","text":"Rules can be standalone or packaged within a module. Standalone rules are ideal for a single project such as an Infrastructure as Code (IaC) repository. To reuse rules across multiple projects consider packaging these as a module.
The instructions for packaging rules in a module can be found here:
To store standalone rules we recommend that you:
.ps-rule
in the root of your repository. Use all lower-case in the sub-directory name. Put any custom rules within this sub-directory..Rule.ps1
.Note
Build pipelines are often case-sensitive or run on Linux-based systems. Using the casing rule above reduces confusion latter when you configure continuous integration (CI).
"},{"location":"customization/storing-custom-rules/#naming-rules","title":"Naming rules","text":"When running PSRule, rule names must be unique. PSRule for Azure uses the name prefix of Azure.
on all rules and resources included in the module.
Example
The following names are examples of rules included within PSRule for Azure:
Azure.AKS.Version
Azure.AKS.AuthorizedIPs
Azure.SQL.MinTLS
When naming custom rules we recommend that you:
Local.
or Org.
prefix for standalone rules.Invoke-PSRule
truncates longer names. PSRule supports longer rule names however if Invoke-PSRule
is called directly consider using Format-List
.Microsoft cloud security benchmark (MCSB) is a set of controls and recommendations that help improve the security of workloads on Azure and your multi-cloud environment. Controls from the MCSB are also mapped to industry frameworks, such as CIS, PCI-DSS, and NIST.
If you are new to MCSB or are looking for guidance on how to use it, please see the Introduction to the Microsoft cloud security benchmark.
"},{"location":"en/mcsb-v1/#microsoft-cloud-security-benchmark-v1","title":"Microsoft cloud security benchmark v1","text":"Is the latest version of the MCSB. Rules included within PSRule for Azure have been mapped to v1 so that you are able to understand the impact of the rules. This is particularly useful when you are looking to understand how to address a compliance requirement specific to your organization.
The following controls are included in the Microsoft cloud security benchmark v1:
Governance and Strategy (GS)
Experimental \u00b7 v1.25.0
To start using the MCSB v1 baseline with PSRule, configure the baseline parameter to use Azure.MCSB.v1
. View the list of rules associated with the MCSB v1 baseline.
Experimental - Learn more
MCSB baselines are a work in progress and subject to change. We hope to add more rules to the baseline in the future. Join or start a discussion to let us know how we can improve this feature going forward.
Note
It's important to note that the MCSB v1 baseline is subset of rules from the Well-Architected Framework. Not all rules for the Well-Architected Framework are included in MCSB. Using the MCSB v1 baseline is useful to understand alignment with the MCSB and other industry frameworks / standards. For a complete set of rules for the Well-Architected Framework, consider using a quarterly baseline.
"},{"location":"en/mcsb-v1/#recommended-content","title":"Recommended content","text":"Includes all Azure rules.
"},{"location":"en/baselines/Azure.All/#rules","title":"Rules","text":"The following rules are included within the Azure.All
baseline.
This baseline includes a total of 411 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.AnonymousAccess Disable anonymous pull access. Important Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.MinUserPoolNodes User node pools in an AKS cluster should have a minimum number of nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. Critical Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. Important Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppGwWAF.RuleGroups Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.NETVersion Configure applications to use newer .NET versions. Important Azure.AppService.PHPVersion Configure applications to use newer PHP runtime versions. Important Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Important Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Important Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. Important Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. Important Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.Databricks.PublicAccess Azure Databricks workspaces should disable public network access. Critical Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. Critical Azure.Databricks.SKU Ensure Databricks workspaces are non-trial SKUs for production workloads. Critical Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.Defender.Api Enable Microsoft Defender for APIs. Critical Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. Critical Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Azure.DevBox.ProjectLimit Limit the number of Dev Boxes a single user can create for a project. Important Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. Important Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. Critical Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). Critical Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. Critical Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. Critical Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. Important Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Important Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.Default/","title":"Azure.Default","text":"Default baseline for Azure rules.
"},{"location":"en/baselines/Azure.Default/#rules","title":"Rules","text":"The following rules are included within the Azure.Default
baseline.
This baseline includes a total of 402 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.MinUserPoolNodes User node pools in an AKS cluster should have a minimum number of nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. Critical Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. Important Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppGwWAF.RuleGroups Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.NETVersion Configure applications to use newer .NET versions. Important Azure.AppService.PHPVersion Configure applications to use newer PHP runtime versions. Important Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. Important Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. Important Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.Databricks.PublicAccess Azure Databricks workspaces should disable public network access. Critical Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. Critical Azure.Databricks.SKU Ensure Databricks workspaces are non-trial SKUs for production workloads. Critical Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.Defender.Api Enable Microsoft Defender for APIs. Critical Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. Critical Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Azure.DevBox.ProjectLimit Limit the number of Dev Boxes a single user can create for a project. Important Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. Important Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. Critical Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). Critical Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. Critical Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. Critical Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. Important Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.GA_2020_06/","title":"Azure.GA_2020_06","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released June 2020 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2020_06/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2020_06
baseline.
This baseline includes a total of 136 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important"},{"location":"en/baselines/Azure.GA_2020_09/","title":"Azure.GA_2020_09","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released September 2020 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2020_09/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2020_09
baseline.
This baseline includes a total of 152 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important"},{"location":"en/baselines/Azure.GA_2020_12/","title":"Azure.GA_2020_12","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released December 2020 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2020_12/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2020_12
baseline.
This baseline includes a total of 174 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important"},{"location":"en/baselines/Azure.GA_2021_03/","title":"Azure.GA_2021_03","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released March 2021 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2021_03/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2021_03
baseline.
This baseline includes a total of 189 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important"},{"location":"en/baselines/Azure.GA_2021_06/","title":"Azure.GA_2021_06","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released June 2021 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2021_06/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2021_06
baseline.
This baseline includes a total of 203 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important"},{"location":"en/baselines/Azure.GA_2021_09/","title":"Azure.GA_2021_09","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released September 2021 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2021_09/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2021_09
baseline.
This baseline includes a total of 222 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important"},{"location":"en/baselines/Azure.GA_2021_12/","title":"Azure.GA_2021_12","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released December 2021 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2021_12/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2021_12
baseline.
This baseline includes a total of 248 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness"},{"location":"en/baselines/Azure.GA_2022_03/","title":"Azure.GA_2022_03","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released March 2022 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2022_03/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2022_03
baseline.
This baseline includes a total of 264 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.GA_2022_06/","title":"Azure.GA_2022_06","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released June 2022 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2022_06/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2022_06
baseline.
This baseline includes a total of 268 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.GA_2022_09/","title":"Azure.GA_2022_09","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released September 2022 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2022_09/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2022_09
baseline.
This baseline includes a total of 299 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.GA_2022_12/","title":"Azure.GA_2022_12","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released December 2022 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2022_12/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2022_12
baseline.
This baseline includes a total of 337 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.GA_2023_03/","title":"Azure.GA_2023_03","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released March 2023 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2023_03/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2023_03
baseline.
This baseline includes a total of 357 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.GA_2023_06/","title":"Azure.GA_2023_06","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released June 2023 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2023_06/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2023_06
baseline.
This baseline includes a total of 372 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.GA_2023_09/","title":"Azure.GA_2023_09","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released September 2023 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2023_09/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2023_09
baseline.
This baseline includes a total of 383 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. Important Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. Important Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. Critical Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.GA_2023_12/","title":"Azure.GA_2023_12","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released December 2023 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2023_12/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2023_12
baseline.
This baseline includes a total of 392 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. Critical Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. Important Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. Important Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. Important Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. Critical Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.Defender.Api Enable Microsoft Defender for APIs. Critical Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. Critical Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. Critical Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). Critical Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. Critical Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. Critical Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. Important Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.GA_2024_03/","title":"Azure.GA_2024_03","text":"Include rules released March 2024 or prior for Azure GA features.
"},{"location":"en/baselines/Azure.GA_2024_03/#rules","title":"Rules","text":"The following rules are included within the Azure.GA_2024_03
baseline.
This baseline includes a total of 402 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.MinUserPoolNodes User node pools in an AKS cluster should have a minimum number of nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. Critical Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. Important Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppGwWAF.RuleGroups Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.NETVersion Configure applications to use newer .NET versions. Important Azure.AppService.PHPVersion Configure applications to use newer PHP runtime versions. Important Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. Important Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. Important Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.Databricks.PublicAccess Azure Databricks workspaces should disable public network access. Critical Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. Critical Azure.Databricks.SKU Ensure Databricks workspaces are non-trial SKUs for production workloads. Critical Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.Defender.Api Enable Microsoft Defender for APIs. Critical Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. Critical Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Azure.DevBox.ProjectLimit Limit the number of Dev Boxes a single user can create for a project. Important Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. Important Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. Critical Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). Critical Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. Critical Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. Critical Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. Important Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.MCSB.v1/","title":"Azure.MCSB.v1","text":"Experimental
This baseline is experimental and subject to change.
Microsoft Cloud Security Benchmark v1.
"},{"location":"en/baselines/Azure.MCSB.v1/#controls","title":"Controls","text":"The following rules are included within the Azure.MCSB.v1
baseline.
This baseline includes a total of 131 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. Critical Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.Defender.Api Enable Microsoft Defender for APIs. Critical Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. Important Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). Critical Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. Critical Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. Important Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important"},{"location":"en/baselines/Azure.Pillar.CostOptimization/","title":"Azure.Pillar.CostOptimization","text":"v1.35.0
Microsoft Azure Well-Architected Framework - Cost Optimization pillar specific baseline.
"},{"location":"en/baselines/Azure.Pillar.CostOptimization/#rules","title":"Rules","text":"The following rules are included within the Azure.Pillar.CostOptimization
baseline.
This baseline includes a total of 14 rules.
Name Synopsis Severity Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.DevBox.ProjectLimit Limit the number of Dev Boxes a single user can create for a project. Important Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness"},{"location":"en/baselines/Azure.Pillar.OperationalExcellence/","title":"Azure.Pillar.OperationalExcellence","text":"v1.35.0
Microsoft Azure Well-Architected Framework - Operational Excellence pillar specific baseline.
"},{"location":"en/baselines/Azure.Pillar.OperationalExcellence/#rules","title":"Rules","text":"The following rules are included within the Azure.Pillar.OperationalExcellence
baseline.
This baseline includes a total of 109 rules.
Name Synopsis Severity Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. Important Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness"},{"location":"en/baselines/Azure.Pillar.PerformanceEfficiency/","title":"Azure.Pillar.PerformanceEfficiency","text":"v1.35.0
Microsoft Azure Well-Architected Framework - Performance Efficiency pillar specific baseline.
"},{"location":"en/baselines/Azure.Pillar.PerformanceEfficiency/#rules","title":"Rules","text":"The following rules are included within the Azure.Pillar.PerformanceEfficiency
baseline.
This baseline includes a total of 18 rules.
Name Synopsis Severity Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. Important Azure.Databricks.SKU Ensure Databricks workspaces are non-trial SKUs for production workloads. Critical Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important"},{"location":"en/baselines/Azure.Pillar.Reliability/","title":"Azure.Pillar.Reliability","text":"v1.35.0
Microsoft Azure Well-Architected Framework - Reliability pillar specific baseline.
"},{"location":"en/baselines/Azure.Pillar.Reliability/#rules","title":"Rules","text":"The following rules are included within the Azure.Pillar.Reliability
baseline.
This baseline includes a total of 61 rules.
Name Synopsis Severity Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.MinUserPoolNodes User node pools in an AKS cluster should have a minimum number of nodes for failover and updates. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. Important Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.Pillar.Security/","title":"Azure.Pillar.Security","text":"v1.35.0
Microsoft Azure Well-Architected Framework - Security pillar specific baseline.
"},{"location":"en/baselines/Azure.Pillar.Security/#rules","title":"Rules","text":"The following rules are included within the Azure.Pillar.Security
baseline.
This baseline includes a total of 200 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. Critical Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppGwWAF.RuleGroups Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.NETVersion Configure applications to use newer .NET versions. Important Azure.AppService.PHPVersion Configure applications to use newer PHP runtime versions. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.Databricks.PublicAccess Azure Databricks workspaces should disable public network access. Critical Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. Critical Azure.Defender.Api Enable Microsoft Defender for APIs. Critical Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. Critical Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. Important Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). Critical Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. Critical Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. Critical Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. Important Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important"},{"location":"en/baselines/Azure.Preview/","title":"Azure.Preview","text":"Includes rules for Azure GA and preview features.
"},{"location":"en/baselines/Azure.Preview/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview
baseline.
This baseline includes a total of 411 rules.
Name Synopsis Severity Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Azure.ACR.AnonymousAccess Disable anonymous pull access. Important Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Azure.ACR.Name Container registry names should meet naming requirements. Awareness Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Azure.AKS.MinUserPoolNodes User node pools in an AKS cluster should have a minimum number of nodes for failover and updates. Important Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. Critical Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Azure.APIM.Name API Management service names should meet naming requirements. Awareness Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Azure.APIM.ProductApproval Configure products to require approval. Important Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Azure.APIM.ProductSubscription Configure products to require a subscription. Important Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. Important Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppGwWAF.RuleGroups Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Azure.AppService.NETVersion Configure applications to use newer .NET versions. Important Azure.AppService.PHPVersion Configure applications to use newer PHP runtime versions. Important Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Azure.AppService.WebProbe Configure and enable instance health probes. Important Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Important Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Important Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Azure.CDN.HTTP Enforce HTTPS for client connections. Important Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. Important Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. Important Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Azure.Databricks.PublicAccess Azure Databricks workspaces should disable public network access. Critical Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. Critical Azure.Databricks.SKU Ensure Databricks workspaces are non-trial SKUs for production workloads. Critical Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Azure.Defender.Api Enable Microsoft Defender for APIs. Critical Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. Critical Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Azure.DevBox.ProjectLimit Limit the number of Dev Boxes a single user can create for a project. Important Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. Important Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Azure.LB.Probe Use a specific probe for web protocols. Important Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. Critical Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). Critical Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. Critical Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. Critical Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. Important Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. Important Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Azure.Route.Name Route table names should meet naming requirements. Awareness Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Azure.Search.Name AI Search service names should meet naming requirements. Awareness Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Azure.Template.LocationType Location parameters should use a string value. Important Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Azure.Template.TemplateFile Use ARM template files that are valid. Important Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Important Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Azure.VM.PublicKey Linux virtual machines should use public keys. Important Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Azure.VNET.PeerState VNET peering connections must be connected. Important Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important"},{"location":"en/baselines/Azure.Preview_2021_09/","title":"Azure.Preview_2021_09","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released September 2021 or prior for Azure preview only features.
"},{"location":"en/baselines/Azure.Preview_2021_09/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview_2021_09
baseline.
This baseline includes a total of 2 rules.
Name Synopsis Severity Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important"},{"location":"en/baselines/Azure.Preview_2021_12/","title":"Azure.Preview_2021_12","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released December 2021 or prior for Azure preview only features.
"},{"location":"en/baselines/Azure.Preview_2021_12/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview_2021_12
baseline.
This baseline includes a total of 2 rules.
Name Synopsis Severity Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important"},{"location":"en/baselines/Azure.Preview_2022_03/","title":"Azure.Preview_2022_03","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released March 2022 or prior for Azure preview only features.
"},{"location":"en/baselines/Azure.Preview_2022_03/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview_2022_03
baseline.
This baseline includes a total of 2 rules.
Name Synopsis Severity Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important"},{"location":"en/baselines/Azure.Preview_2022_06/","title":"Azure.Preview_2022_06","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released June 2022 or prior for Azure preview only features.
"},{"location":"en/baselines/Azure.Preview_2022_06/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview_2022_06
baseline.
This baseline includes a total of 2 rules.
Name Synopsis Severity Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important"},{"location":"en/baselines/Azure.Preview_2022_09/","title":"Azure.Preview_2022_09","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released September 2022 or prior for Azure preview only features.
"},{"location":"en/baselines/Azure.Preview_2022_09/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview_2022_09
baseline.
This baseline includes a total of 3 rules.
Name Synopsis Severity Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important"},{"location":"en/baselines/Azure.Preview_2022_12/","title":"Azure.Preview_2022_12","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released December 2022 or prior for Azure preview only features.
"},{"location":"en/baselines/Azure.Preview_2022_12/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview_2022_12
baseline.
This baseline includes a total of 3 rules.
Name Synopsis Severity Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important"},{"location":"en/baselines/Azure.Preview_2023_03/","title":"Azure.Preview_2023_03","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released March 2023 or prior for Azure preview only features.
"},{"location":"en/baselines/Azure.Preview_2023_03/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview_2023_03
baseline.
This baseline includes a total of 3 rules.
Name Synopsis Severity Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important"},{"location":"en/baselines/Azure.Preview_2023_06/","title":"Azure.Preview_2023_06","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released June 2023 or prior for Azure preview only features.
"},{"location":"en/baselines/Azure.Preview_2023_06/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview_2023_06
baseline.
This baseline includes a total of 8 rules.
Name Synopsis Severity Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Important Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Important Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Important"},{"location":"en/baselines/Azure.Preview_2023_09/","title":"Azure.Preview_2023_09","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released September 2023 or prior for Azure preview only features.
"},{"location":"en/baselines/Azure.Preview_2023_09/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview_2023_09
baseline.
This baseline includes a total of 9 rules.
Name Synopsis Severity Azure.ACR.AnonymousAccess Disable anonymous pull access. Important Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Important Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Important Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Important"},{"location":"en/baselines/Azure.Preview_2023_12/","title":"Azure.Preview_2023_12","text":"Warning
This baseline is obsolete. Consider switching to a newer baseline.
Include rules released December 2023 or prior for Azure preview only features.
"},{"location":"en/baselines/Azure.Preview_2023_12/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview_2023_12
baseline.
This baseline includes a total of 9 rules.
Name Synopsis Severity Azure.ACR.AnonymousAccess Disable anonymous pull access. Important Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Important Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Important Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Important"},{"location":"en/baselines/Azure.Preview_2024_03/","title":"Azure.Preview_2024_03","text":"Include rules released March 2024 or prior for Azure preview only features.
"},{"location":"en/baselines/Azure.Preview_2024_03/#rules","title":"Rules","text":"The following rules are included within the Azure.Preview_2024_03
baseline.
This baseline includes a total of 9 rules.
Name Synopsis Severity Azure.ACR.AnonymousAccess Disable anonymous pull access. Important Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Important Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Important Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Important"},{"location":"en/rules/","title":"Reference","text":"The following rules and features are included in PSRule for Azure.
Info
The rule release indicates if the Azure feature is generally available (GA) or available under preview. Features provided under previews may have additional limits, availability restrictions, or terms. By default, PSRule for Azure will not provide recommendations that relate to preview features. To include rules for preview features see working with baselines.
"},{"location":"en/rules/#rules","title":"Rules","text":"The following rules are included in PSRule for Azure.
Reference Name Synopsis Release AZR-000001 Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. GA AZR-000002 Azure.ACR.ContainerScan Enable vulnerability scanning for container images. GA AZR-000003 Azure.ACR.ImageHealth Remove container images with known vulnerabilities. GA AZR-000004 Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. GA AZR-000005 Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. GA AZR-000006 Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. GA AZR-000007 Azure.ACR.Name Container registry names should meet naming requirements. GA AZR-000008 Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Preview AZR-000009 Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. GA AZR-000010 Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Preview AZR-000011 Azure.ADX.Usage Regularly remove unused resources to reduce costs. GA AZR-000012 Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. GA AZR-000013 Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. GA AZR-000014 Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. GA AZR-000015 Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. GA AZR-000016 Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. GA AZR-000017 Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. GA AZR-000018 Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. GA AZR-000019 Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. GA AZR-000020 Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. GA AZR-000021 Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. GA AZR-000022 Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. GA AZR-000023 Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. GA AZR-000024 Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. GA AZR-000025 Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. GA AZR-000026 Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. GA AZR-000027 Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. GA AZR-000028 Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. GA AZR-000029 Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. GA AZR-000030 Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. GA AZR-000031 Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. GA AZR-000032 Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. GA AZR-000033 Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. GA AZR-000034 Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. GA AZR-000035 Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. GA AZR-000036 Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. GA AZR-000038 Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. GA AZR-000039 Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. GA AZR-000040 Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. GA AZR-000041 Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. GA AZR-000042 Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. GA AZR-000043 Azure.APIM.APIDescriptors API Management APIs should have a display name and description. GA AZR-000044 Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. GA AZR-000045 Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. GA AZR-000046 Azure.APIM.ProductSubscription Configure products to require a subscription. GA AZR-000047 Azure.APIM.ProductApproval Configure products to require approval. GA AZR-000048 Azure.APIM.SampleProducts Remove starter and unlimited sample products. GA AZR-000049 Azure.APIM.ProductDescriptors API Management products should have a display name and description. GA AZR-000050 Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. GA AZR-000051 Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. GA AZR-000052 Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. GA AZR-000053 Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. GA AZR-000054 Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. GA AZR-000055 Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. GA AZR-000056 Azure.APIM.Name API Management service names should meet naming requirements. GA AZR-000057 Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. GA AZR-000058 Azure.AppConfig.Name App Configuration store names should meet naming requirements. GA AZR-000059 Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. GA AZR-000060 Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. GA AZR-000061 Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. GA AZR-000062 Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. GA AZR-000063 Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. GA AZR-000064 Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. GA AZR-000065 Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. GA AZR-000066 Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. GA AZR-000067 Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. GA AZR-000068 Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. GA AZR-000069 Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. GA AZR-000070 Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. GA AZR-000071 Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. GA AZR-000072 Azure.AppService.MinPlan Use at least a Standard App Service Plan. GA AZR-000073 Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. GA AZR-000074 Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. GA AZR-000075 Azure.AppService.NETVersion Configure applications to use newer .NET versions. GA AZR-000076 Azure.AppService.PHPVersion Configure applications to use newer PHP runtime versions. GA AZR-000077 Azure.AppService.AlwaysOn Configure Always On for App Service apps. GA AZR-000078 Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. GA AZR-000079 Azure.AppService.WebProbe Configure and enable instance health probes. GA AZR-000080 Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. GA AZR-000081 Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. GA AZR-000082 Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. GA AZR-000083 Azure.AppService.ARRAffinity Disable client affinity for stateless services. GA AZR-000084 Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. GA AZR-000085 Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. GA AZR-000086 Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. GA AZR-000087 Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). GA AZR-000088 Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. GA AZR-000089 Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. GA AZR-000090 Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. GA AZR-000091 Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. GA AZR-000092 Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. GA AZR-000093 Azure.CDN.HTTP Enforce HTTPS for client connections. GA AZR-000094 Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. GA AZR-000095 Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. GA AZR-000096 Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. GA AZR-000097 Azure.DataFactory.Version Consider migrating to DataFactory v2. GA AZR-000098 Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. GA AZR-000099 Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. GA AZR-000100 Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. GA AZR-000101 Azure.EventHub.Usage Regularly remove unused resources to reduce costs. GA AZR-000102 Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. GA AZR-000103 Azure.Firewall.Name Firewall names should meet naming requirements. GA AZR-000104 Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. GA AZR-000105 Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. GA AZR-000106 Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. GA AZR-000107 Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. GA AZR-000108 Azure.FrontDoor.Probe Use health probes to check the health of each backend. GA AZR-000109 Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. GA AZR-000110 Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. GA AZR-000111 Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. GA AZR-000112 Azure.FrontDoor.State Enable Azure Front Door Classic instance. GA AZR-000113 Azure.FrontDoor.Name Front Door names should meet naming requirements. GA AZR-000114 Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. GA AZR-000115 Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. GA AZR-000116 Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. GA AZR-000117 Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. GA AZR-000118 Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. GA AZR-000119 Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. GA AZR-000120 Azure.KeyVault.Name Key Vault names should meet naming requirements. GA AZR-000121 Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. GA AZR-000122 Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. GA AZR-000123 Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. GA AZR-000124 Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. GA AZR-000125 Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. GA AZR-000126 Azure.LB.Probe Use a specific probe for web protocols. GA AZR-000127 Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. GA AZR-000128 Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. GA AZR-000129 Azure.LB.Name Load Balancer names should meet naming requirements. GA AZR-000130 Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. GA AZR-000131 Azure.MySQL.UseSSL Enforce encrypted MySQL connections. GA AZR-000132 Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. GA AZR-000133 Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. GA AZR-000134 Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. GA AZR-000135 Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. GA AZR-000136 Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. GA AZR-000137 Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. GA AZR-000138 Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. GA AZR-000139 Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. GA AZR-000140 Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. GA AZR-000141 Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. GA AZR-000142 Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. GA AZR-000143 Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. GA AZR-000144 Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. GA AZR-000145 Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. GA AZR-000146 Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. GA AZR-000147 Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. GA AZR-000148 Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. GA AZR-000149 Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. GA AZR-000150 Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. GA AZR-000151 Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. GA AZR-000152 Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. GA AZR-000153 Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. GA AZR-000154 Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. GA AZR-000155 Azure.PublicIP.Name Public IP names should meet naming requirements. GA AZR-000156 Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. GA AZR-000157 Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. GA AZR-000158 Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. GA AZR-000159 Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. GA AZR-000160 Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. GA AZR-000161 Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. GA AZR-000162 Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. GA AZR-000163 Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. GA AZR-000164 Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. GA AZR-000165 Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. GA AZR-000166 Azure.Resource.UseTags Azure resources should be tagged using a standard convention. GA AZR-000167 Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. GA AZR-000168 Azure.ResourceGroup.Name Resource Group names should meet naming requirements. GA AZR-000169 Azure.Route.Name Route table names should meet naming requirements. GA AZR-000170 Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. GA AZR-000171 Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. GA AZR-000172 Azure.Search.SKU Use the basic and standard tiers for entry level workloads. GA AZR-000173 Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. GA AZR-000174 Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. GA AZR-000175 Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. GA AZR-000176 Azure.Search.Name AI Search service names should meet naming requirements. GA AZR-000177 Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. GA AZR-000178 Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. GA AZR-000179 Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. GA AZR-000180 Azure.SignalR.Name SignalR service instance names should meet naming requirements. GA AZR-000181 Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. GA AZR-000182 Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. GA AZR-000183 Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. GA AZR-000184 Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. GA AZR-000185 Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). GA AZR-000186 Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. GA AZR-000187 Azure.SQL.Auditing Enable auditing for Azure SQL logical server. GA AZR-000188 Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. GA AZR-000189 Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. GA AZR-000190 Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. GA AZR-000191 Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. GA AZR-000192 Azure.SQL.DBName Azure SQL Database names should meet naming requirements. GA AZR-000193 Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. GA AZR-000194 Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. GA AZR-000195 Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. GA AZR-000196 Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. GA AZR-000197 Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. GA AZR-000198 Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. GA AZR-000199 Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. GA AZR-000200 Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. GA AZR-000201 Azure.Storage.Name Storage Account names should meet naming requirements. GA AZR-000202 Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. GA AZR-000203 Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. GA AZR-000204 Azure.RBAC.LimitOwner Limit the number of subscription Owners. GA AZR-000205 Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. GA AZR-000206 Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). GA AZR-000207 Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. GA AZR-000208 Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. GA AZR-000209 Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. GA AZR-000210 Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. GA AZR-000211 Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. GA AZR-000212 Azure.Template.TemplateFile Use ARM template files that are valid. GA AZR-000213 Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. GA AZR-000214 Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. GA AZR-000215 Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. GA AZR-000216 Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. GA AZR-000217 Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. GA AZR-000218 Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. GA AZR-000219 Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. GA AZR-000220 Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. GA AZR-000221 Azure.Template.LocationType Location parameters should use a string value. GA AZR-000222 Azure.Template.ResourceLocation Template resource location should be an expression or global. GA AZR-000223 Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. GA AZR-000224 Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. GA AZR-000225 Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. GA AZR-000226 Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. GA AZR-000227 Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. GA AZR-000228 Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. GA AZR-000229 Azure.Template.ParameterFile Use ARM template parameter files that are valid. GA AZR-000230 Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. GA AZR-000231 Azure.Template.MetadataLink Configure a metadata link for each parameter file. GA AZR-000232 Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. GA AZR-000233 Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. GA AZR-000234 Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. GA AZR-000235 Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. GA AZR-000236 Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. GA AZR-000237 Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. GA AZR-000238 Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. GA AZR-000239 Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. GA AZR-000240 Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. GA AZR-000241 Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. GA AZR-000242 Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. GA AZR-000243 Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. GA AZR-000244 Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. GA AZR-000245 Azure.VM.PublicKey Linux virtual machines should use public keys. GA AZR-000246 Azure.VM.Agent Ensure the VM agent is provisioned automatically. GA AZR-000247 Azure.VM.Updates Ensure automatic updates are enabled at deployment. GA AZR-000248 Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. GA AZR-000249 Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. GA AZR-000250 Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. GA AZR-000251 Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. GA AZR-000252 Azure.VM.ADE Use Azure Disk Encryption (ADE). GA AZR-000253 Azure.VM.DiskName Managed Disk names should meet naming requirements. GA AZR-000254 Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. GA AZR-000255 Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). GA AZR-000256 Azure.VM.ASName Availability Set names should meet naming requirements. GA AZR-000257 Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. GA AZR-000258 Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. GA AZR-000259 Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. GA AZR-000260 Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. GA AZR-000261 Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. GA AZR-000262 Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. GA AZR-000263 Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. GA AZR-000264 Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. GA AZR-000265 Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. GA AZR-000266 Azure.VNET.PeerState VNET peering connections must be connected. GA AZR-000267 Azure.VNET.SubnetName Subnet names should meet naming requirements. GA AZR-000268 Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. GA AZR-000269 Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. GA AZR-000270 Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. GA AZR-000271 Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. GA AZR-000272 Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. GA AZR-000273 Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. GA AZR-000274 Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. GA AZR-000275 Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. GA AZR-000276 Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. GA AZR-000277 Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. GA AZR-000278 Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. GA AZR-000279 Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. GA AZR-000280 Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. GA AZR-000281 Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. GA AZR-000282 Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. GA AZR-000283 Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. GA AZR-000284 Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. GA AZR-000285 Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. GA AZR-000286 Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. GA AZR-000287 Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. GA AZR-000288 Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. GA AZR-000289 Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. GA AZR-000290 Azure.Defender.Containers Enable Microsoft Defender for Containers. GA AZR-000291 Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. GA AZR-000292 Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. GA AZR-000293 Azure.Defender.Servers Enable Microsoft Defender for Servers. GA AZR-000294 Azure.Defender.SQL Enable Microsoft Defender for SQL servers. GA AZR-000295 Azure.Defender.AppServices Enable Microsoft Defender for App Service. GA AZR-000296 Azure.Defender.Storage Enable Microsoft Defender for Storage. GA AZR-000297 Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. GA AZR-000298 Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. GA AZR-000299 Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. GA AZR-000300 Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. GA AZR-000301 Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. GA AZR-000302 Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. GA AZR-000303 Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. GA AZR-000304 Azure.AppGwWAF.RuleGroups Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. GA AZR-000305 Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. GA AZR-000306 Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. GA AZR-000307 Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. GA AZR-000308 Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. GA AZR-000309 Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. GA AZR-000310 Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Preview AZR-000311 Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. GA AZR-000312 Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. GA AZR-000313 Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. GA AZR-000314 Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. GA AZR-000315 Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. GA AZR-000316 Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. GA AZR-000317 Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. GA AZR-000318 Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. GA AZR-000319 Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. GA AZR-000320 Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. GA AZR-000321 Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. GA AZR-000322 Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. GA AZR-000323 Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. GA AZR-000324 Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. GA AZR-000325 Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. GA AZR-000326 Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. GA AZR-000327 Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. GA AZR-000328 Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. GA AZR-000329 Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. GA AZR-000330 Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. GA AZR-000331 Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. GA AZR-000332 Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. GA AZR-000333 Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. GA AZR-000334 Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. GA AZR-000335 Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. GA AZR-000336 Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. GA AZR-000337 Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. GA AZR-000338 Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. GA AZR-000339 Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. GA AZR-000340 Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. GA AZR-000341 Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. GA AZR-000342 Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. GA AZR-000343 Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. GA AZR-000344 Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. GA AZR-000345 Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. GA AZR-000346 Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. GA AZR-000347 Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. GA AZR-000348 Azure.AppGw.Name Application Gateways should meet naming requirements. GA AZR-000349 Azure.Bastion.Name Bastion hosts should meet naming requirements. GA AZR-000350 Azure.RSV.Name Recovery Services vaults should meet naming requirements. GA AZR-000351 Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. GA AZR-000352 Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. GA AZR-000353 Azure.Defender.Dns Enable Microsoft Defender for DNS. GA AZR-000354 Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). GA AZR-000355 Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. GA AZR-000356 Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. GA AZR-000357 Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. GA AZR-000358 Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. GA AZR-000359 Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. GA AZR-000360 Azure.ContainerApp.Name Container Apps should meet naming requirements. GA AZR-000361 Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. GA AZR-000362 Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. GA AZR-000363 Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. GA AZR-000364 Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. GA AZR-000365 Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. GA AZR-000366 Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. GA AZR-000367 Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. GA AZR-000368 Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. GA AZR-000369 Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. GA AZR-000370 Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. GA AZR-000371 Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. GA AZR-000372 Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. GA AZR-000373 Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Preview AZR-000374 Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Preview AZR-000375 Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Preview AZR-000376 Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. GA AZR-000377 Azure.Defender.Api Enable Microsoft Defender for APIs. GA AZR-000378 Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. GA AZR-000379 Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. GA AZR-000380 Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. GA AZR-000381 Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. GA AZR-000382 Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. GA AZR-000383 Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. GA AZR-000384 Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. GA AZR-000385 Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Preview AZR-000386 Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. GA AZR-000387 Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. GA AZR-000388 Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. GA AZR-000389 Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. GA AZR-000390 Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. GA AZR-000391 Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Preview AZR-000392 Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. GA AZR-000393 Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. GA AZR-000394 Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. GA AZR-000395 Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. GA AZR-000396 Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. GA AZR-000397 Azure.RSV.Immutable Ensure immutability is configured to protect backup data. GA AZR-000398 Azure.BV.Immutable Ensure immutability is configured to protect backup data. GA AZR-000399 Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. GA AZR-000400 Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. GA AZR-000401 Azure.ACR.AnonymousAccess Disable anonymous pull access. Preview AZR-000402 Azure.ACR.Firewall Limit network access of container registries to only trusted clients. GA AZR-000403 Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. GA AZR-000404 Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. GA AZR-000405 Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). GA AZR-000406 Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. GA AZR-000407 Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. GA AZR-000408 Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. GA AZR-000409 Azure.Databricks.SKU Ensure Databricks workspaces are non-trial SKUs for production workloads. GA AZR-000410 Azure.Databricks.PublicAccess Azure Databricks workspaces should disable public network access. GA AZR-000411 Azure.DevBox.ProjectLimit Limit the number of Dev Boxes a single user can create for a project. GA AZR-000412 Azure.AKS.MinUserPoolNodes User node pools in an AKS cluster should have a minimum number of nodes for failover and updates. GA"},{"location":"en/rules/Azure.ACR.AdminUser/","title":"Disable ACR admin user","text":"Azure.ACR.AdminUserAZR-000005ErrorSecurity \u00b7 Container Registry \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Use Entra ID identities instead of using the registry admin user.
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"en/rules/Azure.ACR.AdminUser/#description","title":"Description","text":"Azure Container Registry (ACR) includes a built-in local admin user account. The admin user account is a single user account with administrative access to the registry. This account provides single user access for early test and development. The admin user account is not intended for use with production container registries.
Instead of using the admin user account, consider using Entra ID (previously Azure AD) identities. Entra ID provides a centralized identity and authentication system for Azure. This provides a number of benefits including:
Consider disabling the admin user account and only use identity-based authentication for registry operations.
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"en/rules/Azure.ACR.AdminUser/#examples","title":"Examples","text":"","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"en/rules/Azure.ACR.AdminUser/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy registries that pass this rule:
properties.adminUserEnabled
to false
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2023-07-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"days\": 30,\n \"status\": \"enabled\"\n }\n }\n }\n}\n
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"en/rules/Azure.ACR.AdminUser/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy registries that pass this rule:
properties.adminUserEnabled
to false
.For example:
Azure Bicep snippetresource registry 'Microsoft.ContainerRegistry/registries@2023-07-01' = {\n name: name\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n days: 30\n status: 'enabled'\n }\n }\n }\n}\n
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"en/rules/Azure.ACR.AdminUser/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To configure registries that pass this rule:
Azure CLI snippetaz acr update -n '<name>' -g '<resource_group>' --admin-enabled false\n
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"en/rules/Azure.ACR.AdminUser/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To configure registries that pass this rule:
Azure PowerShell snippetUpdate-AzContainerRegistry -ResourceGroupName '<resource_group>' -Name '<name>' -DisableAdminUser\n
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"en/rules/Azure.ACR.AdminUser/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/dc921057-6b28-4fbe-9b83-f7bec05db6c2
./providers/Microsoft.Authorization/policyDefinitions/79fdfe03-ffcb-4e55-b4d0-b925b8241759
.Security \u00b7 Container Registry \u00b7 Rule \u00b7 Preview \u00b7 2023_09 \u00b7 Important
Disable anonymous pull access.
","tags":["Azure.ACR.AnonymousAccess","AZR-000401"]},{"location":"en/rules/Azure.ACR.AnonymousAccess/#description","title":"Description","text":"Azure Container Registry (ACR) allows you to pull or push content from an Azure container registry by being authenticated. However, it is possible to pull content from an Azure container registry by being unauthenticated (anonymous pull access).
By default, access to pull or push content from an Azure container registry is only available to authenticated users.
Generally speaking it is not a good practice to allow data-plane operations to unauthenticated users. However, anonymous pull access can be used in scenarios that do not require user authentication such as distributing public container images.
","tags":["Azure.ACR.AnonymousAccess","AZR-000401"]},{"location":"en/rules/Azure.ACR.AnonymousAccess/#recommendation","title":"Recommendation","text":"Consider disabling anonymous pull access in scenarios that require user authentication.
","tags":["Azure.ACR.AnonymousAccess","AZR-000401"]},{"location":"en/rules/Azure.ACR.AnonymousAccess/#examples","title":"Examples","text":"","tags":["Azure.ACR.AnonymousAccess","AZR-000401"]},{"location":"en/rules/Azure.ACR.AnonymousAccess/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy registries that pass this rule:
properties.anonymousPullEnabled
property to false
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2023-08-01-preview\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"anonymousPullEnabled\": false,\n \"policies\": {\n \"quarantinePolicy\": {\n \"status\": \"enabled\"\n },\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"days\": 30,\n \"status\": \"enabled\"\n },\n \"softDeletePolicy\": {\n \"retentionDays\": 90,\n \"status\": \"enabled\"\n }\n }\n }\n}\n
","tags":["Azure.ACR.AnonymousAccess","AZR-000401"]},{"location":"en/rules/Azure.ACR.AnonymousAccess/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy registries that pass this rule:
properties.anonymousPullEnabled
property to false
.For example:
Azure Bicep snippetresource registry 'Microsoft.ContainerRegistry/registries@2023-08-01-preview' = {\n name: name\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n anonymousPullEnabled: false\n policies: {\n quarantinePolicy: {\n status: 'enabled'\n }\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n days: 30\n status: 'enabled'\n }\n softDeletePolicy: {\n retentionDays: 90\n status: 'enabled'\n }\n }\n }\n}\n
","tags":["Azure.ACR.AnonymousAccess","AZR-000401"]},{"location":"en/rules/Azure.ACR.AnonymousAccess/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To configure registries that pass this rule:
Azure CLI snippetaz acr update -n '<name>' -g '<resource_group>' --anonymous-pull-enabled false\n
","tags":["Azure.ACR.AnonymousAccess","AZR-000401"]},{"location":"en/rules/Azure.ACR.AnonymousAccess/#notes","title":"Notes","text":"The anonymous pull access feature is currently in preview. Anonymous pull access is only available in the Standard
and Premium
service tiers.
Security \u00b7 Container Registry \u00b7 Rule \u00b7 2020_12 \u00b7 Critical
Enable vulnerability scanning for container images.
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"en/rules/Azure.ACR.ContainerScan/#description","title":"Description","text":"A potential risk with container-based workloads is un-patched security vulnerabilities in:
It is important to adopt a strategy to actively scan images for security vulnerabilities. One option for scanning container images is to use Microsoft Defender for container registries. Microsoft Defender for container registries scans each container image pushed to the registry.
Microsoft Defender for container registries scans images on push, import, and recently pulled images. Recently pulled images are scanned on a regular basis when they have been pulled within the last 30 days. When scanned, the container image is pulled and executed in an isolated sandbox for scanning. Any detected vulnerabilities are reported to Microsoft Defender for Cloud.
Container image vulnerability scanning with Microsoft Defender for container registries:
Consider using Microsoft Defender for Cloud to scan for security vulnerabilities in container images.
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"en/rules/Azure.ACR.ContainerScan/#examples","title":"Examples","text":"","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"en/rules/Azure.ACR.ContainerScan/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable container image scanning:
Standard
pricing tier for Microsoft Defender for container registries.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2018-06-01\",\n \"name\": \"ContainerRegistry\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"en/rules/Azure.ACR.ContainerScan/#configure-with-bicep","title":"Configure with Bicep","text":"To enable container image scanning:
Standard
pricing tier for Microsoft Defender for container registries.For example:
Azure Bicep snippetresource defenderForContainerRegistry 'Microsoft.Security/pricings@2018-06-01' = {\n name: 'ContainerRegistry'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"en/rules/Azure.ACR.ContainerScan/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz security pricing create -n 'ContainerRegistry' --tier 'standard'\n
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"en/rules/Azure.ACR.ContainerScan/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetSet-AzSecurityPricing -Name 'ContainerRegistry' -PricingTier 'Standard'\n
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"en/rules/Azure.ACR.ContainerScan/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"en/rules/Azure.ACR.ContainerScan/#links","title":"Links","text":"Security \u00b7 Container Registry \u00b7 Rule \u00b7 2020_12 \u00b7 Important
Use container images signed by a trusted image publisher.
","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"en/rules/Azure.ACR.ContentTrust/#description","title":"Description","text":"Azure Container Registry (ACR) content trust enables pushing and pulling of signed images. Signed images provides additional assurance that they have been built on a trusted source.
To enable content trust, the container registry must be using a Premium SKU.
Content trust is currently not supported in a registry that's encrypted with a customer-managed key. When using customer-managed keys, content trust can not be enabled.
","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"en/rules/Azure.ACR.ContentTrust/#recommendation","title":"Recommendation","text":"Consider enabling content trust on registries, clients, and sign container images.
","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"en/rules/Azure.ACR.ContentTrust/#examples","title":"Examples","text":"","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"en/rules/Azure.ACR.ContentTrust/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy registries that pass this rule:
properties.trustPolicy.status
to enabled
.properties.trustPolicy.type
to Notary
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2023-08-01-preview\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"days\": 30,\n \"status\": \"enabled\"\n }\n }\n }\n}\n
","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"en/rules/Azure.ACR.ContentTrust/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy registries that pass this rule:
properties.trustPolicy.status
to enabled
.properties.trustPolicy.type
to Notary
.For example:
Azure Bicep snippetresource registry 'Microsoft.ContainerRegistry/registries@2023-08-01-preview' = {\n name: name\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n days: 30\n status: 'enabled'\n }\n }\n }\n}\n
","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"en/rules/Azure.ACR.ContentTrust/#links","title":"Links","text":"Security \u00b7 Container Registry \u00b7 Rule \u00b7 2023_09 \u00b7 Important
Limit network access of container registries to only trusted clients.
","tags":["Azure.ACR.Firewall","AZR-000402"]},{"location":"en/rules/Azure.ACR.Firewall/#description","title":"Description","text":"Azure Container Registry (ACR) allows you to restrict network access to trusted clients and networks instead of any client.
Container registries using the Premium SKU can limit network access by setting firewall rules or using private endpoints. Firewall and private endpoints are not supported when using the Basic or Standard SKU.
In general, network access should be restricted to harden against unauthorized access or exfiltration attempts. However may not be required when publishing and distributing public container images to external parties.
","tags":["Azure.ACR.Firewall","AZR-000402"]},{"location":"en/rules/Azure.ACR.Firewall/#recommendation","title":"Recommendation","text":"Consider restricting network access to trusted clients to harden against unauthorized access or exfiltration attempts.
","tags":["Azure.ACR.Firewall","AZR-000402"]},{"location":"en/rules/Azure.ACR.Firewall/#examples","title":"Examples","text":"","tags":["Azure.ACR.Firewall","AZR-000402"]},{"location":"en/rules/Azure.ACR.Firewall/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Container Registries that pass this rule:
properties.publicNetworkAccess
property to Disabled
. ORproperties.networkRuleSet.defaultAction
property to Deny
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2023-01-01-preview\",\n \"name\": \"[parameters('registryName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"properties\": {\n \"publicNetworkAccess\": \"Enabled\",\n \"networkRuleBypassOptions\": \"AzureServices\",\n \"networkRuleSet\": {\n \"defaultAction\": \"Deny\",\n \"ipRules\": [\n {\n \"action\": \"Allow\",\n \"value\": \"_PublicIPv4Address_\"\n }\n ]\n }\n }\n}\n
","tags":["Azure.ACR.Firewall","AZR-000402"]},{"location":"en/rules/Azure.ACR.Firewall/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Container Registries that pass this rule:
properties.publicNetworkAccess
property to Disabled
. ORproperties.networkRuleSet.defaultAction
property to Deny
.For example:
Azure Bicep snippetresource acr 'Microsoft.ContainerRegistry/registries@2023-01-01-preview' = {\n name: registryName\n location: location\n sku: {\n name: 'Premium'\n }\n properties: {\n publicNetworkAccess: 'Enabled'\n networkRuleBypassOptions: 'AzureServices'\n networkRuleSet: {\n defaultAction: 'Deny'\n ipRules: [\n {\n action: 'Allow'\n value: '_PublicIPv4Address_'\n }\n ]\n }\n }\n}\n
","tags":["Azure.ACR.Firewall","AZR-000402"]},{"location":"en/rules/Azure.ACR.Firewall/#notes","title":"Notes","text":"Configuring firewall rules or using private endpoints is only available for the Premium SKU.
When used with Microsoft Defender for Containers, you must enable trusted Microsoft services for the vulnerability assessment feature to be able to scan the registry.
","tags":["Azure.ACR.Firewall","AZR-000402"]},{"location":"en/rules/Azure.ACR.Firewall/#links","title":"Links","text":"Reliability \u00b7 Container Registry \u00b7 Rule \u00b7 2020_12 \u00b7 Important
Use geo-replicated container registries to compliment a multi-region container deployments.
","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"en/rules/Azure.ACR.GeoReplica/#description","title":"Description","text":"A container registry is stored and maintained by default in a single region. Optionally geo-replication to one or more additional regions can be enabled.
Geo-replicating container registries provides the following benefits:
Consider using a geo-replicated container registry for multi-region deployments.
","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"en/rules/Azure.ACR.GeoReplica/#examples","title":"Examples","text":"","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"en/rules/Azure.ACR.GeoReplica/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable geo-replication for Container Registries that pass this rule:
sku.name
to Premium
(required for geo-replication).replications
child resource with location
set to the region to replicate to.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"metadata\": {\n \"_generator\": {\n \"name\": \"bicep\",\n \"version\": \"0.5.6.12127\",\n \"templateHash\": \"12610175857982700190\"\n }\n },\n \"parameters\": {\n \"acrName\": {\n \"type\": \"string\",\n \"defaultValue\": \"[format('acr{0}', uniqueString(resourceGroup().id))]\",\n \"maxLength\": 50,\n \"minLength\": 5,\n \"metadata\": {\n \"description\": \"Globally unique name of your Azure Container Registry\"\n }\n },\n \"acrAdminUserEnabled\": {\n \"type\": \"bool\",\n \"defaultValue\": false,\n \"metadata\": {\n \"description\": \"Enable admin user that has push / pull permission to the registry.\"\n }\n },\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"Location for registry home replica.\"\n }\n },\n \"acrSku\": {\n \"type\": \"string\",\n \"defaultValue\": \"Premium\",\n \"allowedValues\": [\n \"Premium\"\n ],\n \"metadata\": {\n \"description\": \"Tier of your Azure Container Registry. Geo-replication requires Premium SKU.\"\n }\n },\n \"acrReplicaLocation\": {\n \"type\": \"string\",\n \"metadata\": {\n \"description\": \"Short name for registry replica location.\"\n }\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2019-12-01-preview\",\n \"name\": \"[parameters('acrName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('acrSku')]\"\n },\n \"tags\": {\n \"displayName\": \"Container Registry\",\n \"container.registry\": \"[parameters('acrName')]\"\n },\n \"properties\": {\n \"adminUserEnabled\": \"[parameters('acrAdminUserEnabled')]\"\n }\n },\n {\n \"type\": \"Microsoft.ContainerRegistry/registries/replications\",\n \"apiVersion\": \"2019-12-01-preview\",\n \"name\": \"[format('{0}/{1}', parameters('acrName'), parameters('acrReplicaLocation'))]\",\n \"location\": \"[parameters('acrReplicaLocation')]\",\n \"properties\": {},\n \"dependsOn\": [\n \"[resourceId('Microsoft.ContainerRegistry/registries', parameters('acrName'))]\"\n ]\n }\n ],\n \"outputs\": {\n \"acrLoginServer\": {\n \"type\": \"string\",\n \"value\": \"[reference(resourceId('Microsoft.ContainerRegistry/registries', parameters('acrName'))).loginServer]\"\n }\n }\n}\n
","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"en/rules/Azure.ACR.GeoReplica/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Container Registries that pass this rule:
sku.name
to Premium
(required for geo-replication).replications
child resource with location
set to the region to replicate to.For example:
Azure Bicep snippetresource containerRegistry 'Microsoft.ContainerRegistry/registries@2019-12-01-preview' = {\n name: acrName\n location: location\n sku: {\n name: 'Premium'\n }\n tags: {\n displayName: 'Container Registry'\n 'container.registry': acrName\n }\n properties: {\n adminUserEnabled: acrAdminUserEnabled\n }\n}\n\nresource containerRegistryReplica 'Microsoft.ContainerRegistry/registries/replications@2019-12-01-preview' = {\n parent: containerRegistry\n name: '${acrReplicaLocation}'\n location: acrReplicaLocation\n properties: {\n }\n}\n
","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"en/rules/Azure.ACR.GeoReplica/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"en/rules/Azure.ACR.GeoReplica/#links","title":"Links","text":"Security \u00b7 Container Registry \u00b7 Rule \u00b7 2020_12 \u00b7 Critical
Remove container images with known vulnerabilities.
","tags":["Azure.ACR.ImageHealth","AZR-000003"]},{"location":"en/rules/Azure.ACR.ImageHealth/#description","title":"Description","text":"When Microsoft Defender for container registries is enabled, Microsoft Defender scans container images. Container images are scanned for known vulnerabilities and marked as healthy or unhealthy. Vulnerable container images should not be used.
","tags":["Azure.ACR.ImageHealth","AZR-000003"]},{"location":"en/rules/Azure.ACR.ImageHealth/#recommendation","title":"Recommendation","text":"Consider using removing container images with known vulnerabilities.
","tags":["Azure.ACR.ImageHealth","AZR-000003"]},{"location":"en/rules/Azure.ACR.ImageHealth/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.ACR.ImageHealth","AZR-000003"]},{"location":"en/rules/Azure.ACR.ImageHealth/#links","title":"Links","text":"Reliability \u00b7 Container Registry \u00b7 Rule \u00b7 2020_06 \u00b7 Important
ACR should use the Premium or Standard SKU for production deployments.
","tags":["Azure.ACR.MinSku","AZR-000006"]},{"location":"en/rules/Azure.ACR.MinSku/#description","title":"Description","text":"Azure Container Registry (ACR) provides a range of different service tiers (also known as SKUs). These service tiers provide different levels of performance and features.
Three service tiers are available: Basic, Standard, and Premium. Basic container registries are only recommended for non-production deployments. Use a minimum of Standard for production container registries.
The Premium SKU provides higher image throughput and included storage, and is required for:
Consider using the Premium Container Registry SKU for production deployments.
","tags":["Azure.ACR.MinSku","AZR-000006"]},{"location":"en/rules/Azure.ACR.MinSku/#examples","title":"Examples","text":"","tags":["Azure.ACR.MinSku","AZR-000006"]},{"location":"en/rules/Azure.ACR.MinSku/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy registries that pass this rule:
sku.name
property to Premium
or Standard
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2023-01-01-preview\",\n \"name\": \"[parameters('registryName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"quarantinePolicy\": {\n \"status\": \"enabled\"\n },\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"days\": 30,\n \"status\": \"enabled\"\n },\n \"softDeletePolicy\": {\n \"retentionDays\": 90,\n \"status\": \"enabled\"\n }\n }\n }\n}\n
","tags":["Azure.ACR.MinSku","AZR-000006"]},{"location":"en/rules/Azure.ACR.MinSku/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy registries that pass this rule:
sku.name
property to Premium
or Standard
.For example:
Azure Bicep snippetresource acr 'Microsoft.ContainerRegistry/registries@2023-01-01-preview' = {\n name: registryName\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n quarantinePolicy: {\n status: 'enabled'\n }\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n days: 30\n status: 'enabled'\n }\n softDeletePolicy: {\n retentionDays: 90\n status: 'enabled'\n }\n }\n }\n}\n
","tags":["Azure.ACR.MinSku","AZR-000006"]},{"location":"en/rules/Azure.ACR.MinSku/#links","title":"Links","text":"Operational Excellence \u00b7 Container Registry \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Container registry names should meet naming requirements.
","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"en/rules/Azure.ACR.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for container registry names are:
Consider using names that meet container registry naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"en/rules/Azure.ACR.Name/#examples","title":"Examples","text":"","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"en/rules/Azure.ACR.Name/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy registries that pass this rule, consider:
minLength
and maxLength
constraint for the resource name parameter.uniqueString()
function to generate a unique name.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"name\": {\n \"type\": \"string\",\n \"minLength\": 5,\n \"maxLength\": 50,\n \"metadata\": {\n \"description\": \"The name of the resource.\"\n }\n },\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"The location resources will be deployed.\"\n }\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2023-08-01-preview\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"days\": 30,\n \"status\": \"enabled\"\n }\n }\n }\n }\n ]\n}\n
","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"en/rules/Azure.ACR.Name/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy registries that pass this rule, consider:
minLength
and maxLength
constraint for the resource name parameter.uniqueString()
function to generate a unique name.For example:
Azure Bicep snippet@minLength(5)\n@maxLength(50)\n@sys.description('The name of the resource.')\nparam name string\n\n@sys.description('The location resources will be deployed.')\nparam location string = resourceGroup().location\n\nresource registry 'Microsoft.ContainerRegistry/registries@2023-08-01-preview' = {\n name: name\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n days: 30\n status: 'enabled'\n }\n }\n }\n}\n
","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"en/rules/Azure.ACR.Name/#notes","title":"Notes","text":"This rule does not check if container registry names are unique.
","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"en/rules/Azure.ACR.Name/#links","title":"Links","text":"Security \u00b7 Container Registry \u00b7 Rule \u00b7 Preview \u00b7 2020_12 \u00b7 Important
Enable container image quarantine, scan, and mark images as verified.
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"en/rules/Azure.ACR.Quarantine/#description","title":"Description","text":"Image quarantine is a configurable option for Azure Container Registry (ACR). When enabled, images pushed to the container registry are not available by default. Each image must be verified and marked as Passed
before it is available to pull.
To verify container images, integrate with an external security tool that supports this feature.
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"en/rules/Azure.ACR.Quarantine/#recommendation","title":"Recommendation","text":"Consider configuring a security tool to implement the image quarantine pattern. Enable image quarantine on the container registry to ensure each image is verified before use.
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"en/rules/Azure.ACR.Quarantine/#examples","title":"Examples","text":"","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"en/rules/Azure.ACR.Quarantine/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Container Registries that pass this rule:
properties.quarantinePolicy.status
to enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2023-01-01-preview\",\n \"name\": \"[parameters('registryName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"quarantinePolicy\": {\n \"status\": \"enabled\"\n },\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"days\": 30,\n \"status\": \"enabled\"\n },\n \"softDeletePolicy\": {\n \"retentionDays\": 90,\n \"status\": \"enabled\"\n }\n }\n }\n}\n
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"en/rules/Azure.ACR.Quarantine/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Container Registries that pass this rule:
properties.quarantinePolicy.status
to enabled
.For example:
Azure Bicep snippetresource acr 'Microsoft.ContainerRegistry/registries@2023-01-01-preview' = {\n name: registryName\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n quarantinePolicy: {\n status: 'enabled'\n }\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n days: 30\n status: 'enabled'\n }\n softDeletePolicy: {\n retentionDays: 90\n status: 'enabled'\n }\n }\n }\n}\n
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"en/rules/Azure.ACR.Quarantine/#notes","title":"Notes","text":"Image quarantine for Azure Container Registry is currently in preview.
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"en/rules/Azure.ACR.Quarantine/#links","title":"Links","text":"Cost Optimization \u00b7 Container Registry \u00b7 Rule \u00b7 Preview \u00b7 2020_12 \u00b7 Important
Use a retention policy to cleanup untagged manifests.
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"en/rules/Azure.ACR.Retention/#description","title":"Description","text":"Retention policy is a configurable option of Premium Azure Container Registry (ACR). When a retention policy is configured, untagged manifests in the registry are automatically deleted. A manifest is untagged when a more recent image is pushed using the same tag. i.e. latest.
The retention policy (in days) can be set to 0-365. The default is 7 days.
To configure a retention policy, the container registry must be using a Premium SKU.
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"en/rules/Azure.ACR.Retention/#recommendation","title":"Recommendation","text":"Consider enabling a retention policy for untagged manifests.
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"en/rules/Azure.ACR.Retention/#examples","title":"Examples","text":"","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"en/rules/Azure.ACR.Retention/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Container Registries that pass this rule:
properties.retentionPolicy.status
to enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2023-11-01-preview\",\n \"name\": \"[parameters('registryName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"quarantinePolicy\": {\n \"status\": \"enabled\"\n },\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"days\": 30,\n \"status\": \"enabled\"\n },\n \"softDeletePolicy\": {\n \"retentionDays\": 90,\n \"status\": \"enabled\"\n }\n }\n }\n}\n
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"en/rules/Azure.ACR.Retention/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Container Registries that pass this rule:
properties.retentionPolicy.status
to enabled
.For example:
Azure Bicep snippetresource acr 'Microsoft.ContainerRegistry/registries@2023-11-01-preview' = {\n name: registryName\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n quarantinePolicy: {\n status: 'enabled'\n }\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n days: 30\n status: 'enabled'\n }\n softDeletePolicy: {\n retentionDays: 90\n status: 'enabled'\n }\n }\n }\n}\n
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"en/rules/Azure.ACR.Retention/#notes","title":"Notes","text":"Retention policies for Azure Container Registry is currently in preview.
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"en/rules/Azure.ACR.Retention/#links","title":"Links","text":"Reliability \u00b7 Container Registry \u00b7 Rule \u00b7 Preview \u00b7 2022_09 \u00b7 Important
Azure Container Registries should have soft delete policy enabled.
","tags":["Azure.ACR.SoftDelete","AZR-000310"]},{"location":"en/rules/Azure.ACR.SoftDelete/#description","title":"Description","text":"Azure Container Registry (ACR) allows you to enable the soft delete policy to recover any accidentally deleted artifacts for a set retention period.
This feature is available in all the service tiers (also known as SKUs). For information about registry service tiers, see Azure Container Registry service tiers.
Once you enable the soft delete policy, ACR manages the deleted artifacts as the soft deleted artifacts with a set retention period. Thereby you have ability to list, filter, and restore the soft deleted artifacts. Once the retention period is complete, all the soft deleted artifacts are auto-purged.
Current preview limitations:
Azure Container Registries should have soft delete enabled to enable recovery of accidentally deleted artifacts.
","tags":["Azure.ACR.SoftDelete","AZR-000310"]},{"location":"en/rules/Azure.ACR.SoftDelete/#examples","title":"Examples","text":"","tags":["Azure.ACR.SoftDelete","AZR-000310"]},{"location":"en/rules/Azure.ACR.SoftDelete/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy an Azure Container Registry that pass this rule:
properties.policies.softDeletePolicy.status
property to enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2023-01-01-preview\",\n \"name\": \"[parameters('registryName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"quarantinePolicy\": {\n \"status\": \"enabled\"\n },\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"days\": 30,\n \"status\": \"enabled\"\n },\n \"softDeletePolicy\": {\n \"retentionDays\": 90,\n \"status\": \"enabled\"\n }\n }\n }\n}\n
","tags":["Azure.ACR.SoftDelete","AZR-000310"]},{"location":"en/rules/Azure.ACR.SoftDelete/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy an Azure Container Registry that pass this rule:
properties.policies.softDeletePolicy.status
property to enabled
.For example:
Azure Bicep snippetresource acr 'Microsoft.ContainerRegistry/registries@2023-01-01-preview' = {\n name: registryName\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n quarantinePolicy: {\n status: 'enabled'\n }\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n days: 30\n status: 'enabled'\n }\n softDeletePolicy: {\n retentionDays: 90\n status: 'enabled'\n }\n }\n }\n}\n
","tags":["Azure.ACR.SoftDelete","AZR-000310"]},{"location":"en/rules/Azure.ACR.SoftDelete/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz acr config soft-delete update -r '<name>' --days 90 --status enabled\n
","tags":["Azure.ACR.SoftDelete","AZR-000310"]},{"location":"en/rules/Azure.ACR.SoftDelete/#links","title":"Links","text":"Cost Optimization \u00b7 Container Registry \u00b7 Rule \u00b7 2020_12 \u00b7 Important
Regularly remove deprecated and unneeded images to reduce storage usage.
","tags":["Azure.ACR.Usage","AZR-000001"]},{"location":"en/rules/Azure.ACR.Usage/#description","title":"Description","text":"Each ACR SKU has an amount of included storage. When the amount of included storage is exceeded, additional storage costs per GiB are accrued.
It is good practice to regularly clean-up orphaned (or dangling) images. These images are a result of pushing updated images with the same tag.
","tags":["Azure.ACR.Usage","AZR-000001"]},{"location":"en/rules/Azure.ACR.Usage/#recommendation","title":"Recommendation","text":"Consider removing deprecated and unneeded images to reduce storage consumption. Also consider upgrading to the Premium SKU for Basic or Standard registries to increase included storage.
","tags":["Azure.ACR.Usage","AZR-000001"]},{"location":"en/rules/Azure.ACR.Usage/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.ACR.Usage","AZR-000001"]},{"location":"en/rules/Azure.ACR.Usage/#links","title":"Links","text":"Security \u00b7 Data Explorer \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Use disk encryption for Azure Data Explorer (ADX) clusters.
","tags":["Azure.ADX.DiskEncryption","AZR-000013"]},{"location":"en/rules/Azure.ADX.DiskEncryption/#description","title":"Description","text":"Azure storage is encrypted at rest, however computing resources can additionally use disk encryption. Disk encryption provides additional security for data at rest.
","tags":["Azure.ADX.DiskEncryption","AZR-000013"]},{"location":"en/rules/Azure.ADX.DiskEncryption/#recommendation","title":"Recommendation","text":"Consider enabling disk encryption on Azure Data Explorer clusters.
","tags":["Azure.ADX.DiskEncryption","AZR-000013"]},{"location":"en/rules/Azure.ADX.DiskEncryption/#examples","title":"Examples","text":"","tags":["Azure.ADX.DiskEncryption","AZR-000013"]},{"location":"en/rules/Azure.ADX.DiskEncryption/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy clusters that pass this rule:
properties.enableDiskEncryption
to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Kusto/clusters\",\n \"apiVersion\": \"2021-08-27\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_D11_v2\",\n \"tier\": \"Standard\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"enableDiskEncryption\": true\n }\n}\n
","tags":["Azure.ADX.DiskEncryption","AZR-000013"]},{"location":"en/rules/Azure.ADX.DiskEncryption/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy clusters that pass this rule:
properties.enableDiskEncryption
to true
.For example:
Azure Bicep snippetresource adx 'Microsoft.Kusto/clusters@2021-08-27' = {\n name: name\n location: location\n sku: {\n name: 'Standard_D11_v2'\n tier: 'Standard'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n enableDiskEncryption: true\n }\n}\n
","tags":["Azure.ADX.DiskEncryption","AZR-000013"]},{"location":"en/rules/Azure.ADX.DiskEncryption/#links","title":"Links","text":"Security \u00b7 Data Explorer \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Configure Data Explorer clusters to use managed identities to access Azure resources securely.
","tags":["Azure.ADX.ManagedIdentity","AZR-000012"]},{"location":"en/rules/Azure.ADX.ManagedIdentity/#description","title":"Description","text":"A managed identity allows your cluster to access other Azure AD-protected resources such as Azure Storage. The identity is managed by the Azure platform and doesn't require you to provision or rotate any secrets.
Using Azure managed identities have the following benefits:
Consider configuring a managed identity for each Azure Data Explorer cluster. Also consider using managed identities to authenticate to related Azure services.
","tags":["Azure.ADX.ManagedIdentity","AZR-000012"]},{"location":"en/rules/Azure.ADX.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.ADX.ManagedIdentity","AZR-000012"]},{"location":"en/rules/Azure.ADX.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy clusters that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Kusto/clusters\",\n \"apiVersion\": \"2021-08-27\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_D11_v2\",\n \"tier\": \"Standard\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"enableDiskEncryption\": true\n }\n}\n
","tags":["Azure.ADX.ManagedIdentity","AZR-000012"]},{"location":"en/rules/Azure.ADX.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy clusters that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource adx 'Microsoft.Kusto/clusters@2021-08-27' = {\n name: name\n location: location\n sku: {\n name: 'Standard_D11_v2'\n tier: 'Standard'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n enableDiskEncryption: true\n }\n}\n
","tags":["Azure.ADX.ManagedIdentity","AZR-000012"]},{"location":"en/rules/Azure.ADX.ManagedIdentity/#links","title":"Links","text":"Reliability \u00b7 Data Explorer \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters.
","tags":["Azure.ADX.SLA","AZR-000014"]},{"location":"en/rules/Azure.ADX.SLA/#description","title":"Description","text":"When choosing a SKU for an ADX cluster you should consider the SLA that is included in the SKU. ADX clusters offer a range of offerings. Development SKUs are designed for early non-production use and do not include any SLA.
","tags":["Azure.ADX.SLA","AZR-000014"]},{"location":"en/rules/Azure.ADX.SLA/#recommendation","title":"Recommendation","text":"Consider using a production ready SKU that includes a SLA.
","tags":["Azure.ADX.SLA","AZR-000014"]},{"location":"en/rules/Azure.ADX.SLA/#examples","title":"Examples","text":"","tags":["Azure.ADX.SLA","AZR-000014"]},{"location":"en/rules/Azure.ADX.SLA/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy clusters that pass this rule:
sku.tier
to Standard
.sku.name
to non-development SKU such as Standard_D11_v2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Kusto/clusters\",\n \"apiVersion\": \"2021-08-27\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_D11_v2\",\n \"tier\": \"Standard\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"enableDiskEncryption\": true\n }\n}\n
","tags":["Azure.ADX.SLA","AZR-000014"]},{"location":"en/rules/Azure.ADX.SLA/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy clusters that pass this rule:
sku.tier
to Standard
.sku.name
to non-development SKU such as Standard_D11_v2
.For example:
Azure Bicep snippetresource adx 'Microsoft.Kusto/clusters@2021-08-27' = {\n name: name\n location: location\n sku: {\n name: 'Standard_D11_v2'\n tier: 'Standard'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n enableDiskEncryption: true\n }\n}\n
","tags":["Azure.ADX.SLA","AZR-000014"]},{"location":"en/rules/Azure.ADX.SLA/#links","title":"Links","text":"Cost Optimization \u00b7 Data Explorer \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Regularly remove unused resources to reduce costs.
","tags":["Azure.ADX.Usage","AZR-000011"]},{"location":"en/rules/Azure.ADX.Usage/#description","title":"Description","text":"Billing starts for an Azure Data Explorer (ADX) cluster after it is provisioned. To store data in an ADX cluster, you must first create a database. Clusters without any databases are considered unused and can be removed to reduce costs and management overhead.
Additionally, ADX clusters on a paid tier can stopped. Stopping an ADX cluster de-allocates and removes compute resources. While in the stopped state, compute charges are not incurred. Any data stored in the cluster is persisted while the cluster is stopped.
","tags":["Azure.ADX.Usage","AZR-000011"]},{"location":"en/rules/Azure.ADX.Usage/#recommendation","title":"Recommendation","text":"Consider removing Data Explorer clusters that have no databases and are not used.
","tags":["Azure.ADX.Usage","AZR-000011"]},{"location":"en/rules/Azure.ADX.Usage/#notes","title":"Notes","text":"This rule applies when analyzing ADX clusters deployed (in-flight) and running within Azure. If the cluster is stopped, this rule is ignored.
","tags":["Azure.ADX.Usage","AZR-000011"]},{"location":"en/rules/Azure.ADX.Usage/#links","title":"Links","text":"Security \u00b7 Azure AI \u00b7 Rule \u00b7 2022_09 \u00b7 Important
Authenticate requests to Azure AI services with Entra ID identities.
","tags":["Azure.AI.DisableLocalAuth","AZR-000282"]},{"location":"en/rules/Azure.AI.DisableLocalAuth/#description","title":"Description","text":"To send requests to Azure AI service endpoints (previously known as Cognitive Services), each request must include an authentication header. Azure AI service endpoints supports authentication with keys or access tokens. Using an Entra ID access token instead of a cryptographic key has some additional security benefits.
With Entra ID authentication, an authorized identity is issued an OAuth2 access token issued by Entra ID. Using Entra ID as the identity provider centralizes identity management and auditing.
Once you decide to use Entra ID authentication, you can disable authentication using keys.
","tags":["Azure.AI.DisableLocalAuth","AZR-000282"]},{"location":"en/rules/Azure.AI.DisableLocalAuth/#recommendation","title":"Recommendation","text":"Consider only using Entra ID identities to authenticate requests to Azure AI service accounts. Once configured, disable authentication based on access keys.
","tags":["Azure.AI.DisableLocalAuth","AZR-000282"]},{"location":"en/rules/Azure.AI.DisableLocalAuth/#examples","title":"Examples","text":"","tags":["Azure.AI.DisableLocalAuth","AZR-000282"]},{"location":"en/rules/Azure.AI.DisableLocalAuth/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy accounts that pass this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.CognitiveServices/accounts\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"S0\"\n },\n \"kind\": \"CognitiveServices\",\n \"properties\": {\n \"publicNetworkAccess\": \"Disabled\",\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n },\n \"disableLocalAuth\": true\n }\n}\n
","tags":["Azure.AI.DisableLocalAuth","AZR-000282"]},{"location":"en/rules/Azure.AI.DisableLocalAuth/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy accounts that pass this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Bicep snippetresource account 'Microsoft.CognitiveServices/accounts@2023-05-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'S0'\n }\n kind: 'CognitiveServices'\n properties: {\n publicNetworkAccess: 'Disabled'\n networkAcls: {\n defaultAction: 'Deny'\n }\n disableLocalAuth: true\n }\n}\n
","tags":["Azure.AI.DisableLocalAuth","AZR-000282"]},{"location":"en/rules/Azure.AI.DisableLocalAuth/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/71ef260a-8f18-47b7-abcb-62d0673d94dc
/providers/Microsoft.Authorization/policyDefinitions/14de9e63-1b31-492e-a5a3-c3f7fd57f555
Security \u00b7 Azure AI \u00b7 Rule \u00b7 2022_09 \u00b7 Important
Configure managed identities to access Azure resources.
","tags":["Azure.AI.ManagedIdentity","AZR-000281"]},{"location":"en/rules/Azure.AI.ManagedIdentity/#description","title":"Description","text":"Azure AI services (previously known as Cognitive Services) must authenticate to Azure resources such storage accounts. To authenticate to Azure resources, Azure AI can use managed identities.
Using Azure managed identities have the following benefits:
Consider configuring a managed identity for each Azure AI services account.
","tags":["Azure.AI.ManagedIdentity","AZR-000281"]},{"location":"en/rules/Azure.AI.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.AI.ManagedIdentity","AZR-000281"]},{"location":"en/rules/Azure.AI.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy accounts that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.CognitiveServices/accounts\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"S0\"\n },\n \"kind\": \"TextAnalytics\",\n \"properties\": {\n \"publicNetworkAccess\": \"Disabled\",\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n },\n \"disableLocalAuth\": true\n }\n}\n
","tags":["Azure.AI.ManagedIdentity","AZR-000281"]},{"location":"en/rules/Azure.AI.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy accounts that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource language 'Microsoft.CognitiveServices/accounts@2023-05-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'S0'\n }\n kind: 'TextAnalytics'\n properties: {\n publicNetworkAccess: 'Disabled'\n networkAcls: {\n defaultAction: 'Deny'\n }\n disableLocalAuth: true\n }\n}\n
","tags":["Azure.AI.ManagedIdentity","AZR-000281"]},{"location":"en/rules/Azure.AI.ManagedIdentity/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/fe3fd216-4f83-4fc1-8984-2bbec80a3418
.Configuration of additional Azure resources is not required for all Azure AI services. This rule will run for the following Azure AI services:
TextAnalytics
- Language service.Security \u00b7 Azure AI \u00b7 Rule \u00b7 2022_09 \u00b7 Important
Use Private Endpoints to access Azure AI services accounts.
","tags":["Azure.AI.PrivateEndpoints","AZR-000283"]},{"location":"en/rules/Azure.AI.PrivateEndpoints/#description","title":"Description","text":"By default, a public endpoint is enabled for Azure AI services accounts (previously known as Cognitive Services). The public endpoint is used for all access except for requests that use a Private Endpoint. Access through the public endpoint can be disabled or restricted to authorized virtual networks.
Data exfiltration is an attack where an malicious actor does an unauthorized data transfer. Private Endpoints help prevent data exfiltration by an internal or external malicious actor. They do this by providing clear separation between public and private endpoints. As a result, broad access to public endpoints which could be operated by a malicious actor is not required.
","tags":["Azure.AI.PrivateEndpoints","AZR-000283"]},{"location":"en/rules/Azure.AI.PrivateEndpoints/#recommendation","title":"Recommendation","text":"Consider accessing Azure AI services accounts by Private Endpoints and disabling public endpoints.
","tags":["Azure.AI.PrivateEndpoints","AZR-000283"]},{"location":"en/rules/Azure.AI.PrivateEndpoints/#examples","title":"Examples","text":"","tags":["Azure.AI.PrivateEndpoints","AZR-000283"]},{"location":"en/rules/Azure.AI.PrivateEndpoints/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy accounts that pass this rule:
properties.publicNetworkAccess
property to Disabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.CognitiveServices/accounts\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"S0\"\n },\n \"kind\": \"CognitiveServices\",\n \"properties\": {\n \"publicNetworkAccess\": \"Disabled\",\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n },\n \"disableLocalAuth\": true\n }\n}\n
","tags":["Azure.AI.PrivateEndpoints","AZR-000283"]},{"location":"en/rules/Azure.AI.PrivateEndpoints/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy accounts that pass this rule:
properties.publicNetworkAccess
property to Disabled
.For example:
Azure Bicep snippetresource account 'Microsoft.CognitiveServices/accounts@2023-05-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'S0'\n }\n kind: 'CognitiveServices'\n properties: {\n publicNetworkAccess: 'Disabled'\n networkAcls: {\n defaultAction: 'Deny'\n }\n disableLocalAuth: true\n }\n}\n
","tags":["Azure.AI.PrivateEndpoints","AZR-000283"]},{"location":"en/rules/Azure.AI.PrivateEndpoints/#links","title":"Links","text":"Security \u00b7 Azure AI \u00b7 Rule \u00b7 2022_09 \u00b7 Important
Restrict access of Azure AI services to authorized virtual networks.
","tags":["Azure.AI.PublicAccess","AZR-000280"]},{"location":"en/rules/Azure.AI.PublicAccess/#description","title":"Description","text":"By default, public network access is enabled for a Azure AI service accounts (previously known as Cognitive Services). Service Endpoints and Private Link can be leveraged to restrict access to PaaS endpoints. When access is restricted, access by malicious actor is from an unauthorized virtual network is mitigated.
Configure service endpoints and private links where appropriate.
","tags":["Azure.AI.PublicAccess","AZR-000280"]},{"location":"en/rules/Azure.AI.PublicAccess/#recommendation","title":"Recommendation","text":"Consider configuring network access restrictions for Azure AI service accounts. Limit access to accounts so that access is permitted from authorized virtual networks only.
","tags":["Azure.AI.PublicAccess","AZR-000280"]},{"location":"en/rules/Azure.AI.PublicAccess/#examples","title":"Examples","text":"","tags":["Azure.AI.PublicAccess","AZR-000280"]},{"location":"en/rules/Azure.AI.PublicAccess/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy accounts that pass this rule:
properties.networkAcls.defaultAction
property to Deny
, orproperties.publicNetworkAccess
property to Disabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.CognitiveServices/accounts\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"S0\"\n },\n \"kind\": \"CognitiveServices\",\n \"properties\": {\n \"publicNetworkAccess\": \"Disabled\",\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n },\n \"disableLocalAuth\": true\n }\n}\n
","tags":["Azure.AI.PublicAccess","AZR-000280"]},{"location":"en/rules/Azure.AI.PublicAccess/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy accounts that pass this rule:
properties.networkAcls.defaultAction
property to Deny
, orproperties.publicNetworkAccess
property to Disabled
.For example:
Azure Bicep snippetresource account 'Microsoft.CognitiveServices/accounts@2023-05-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'S0'\n }\n kind: 'CognitiveServices'\n properties: {\n publicNetworkAccess: 'Disabled'\n networkAcls: {\n defaultAction: 'Deny'\n }\n disableLocalAuth: true\n }\n}\n
","tags":["Azure.AI.PublicAccess","AZR-000280"]},{"location":"en/rules/Azure.AI.PublicAccess/#links","title":"Links","text":"Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_09 \u00b7 Important
AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads.
","tags":["Azure.AKS.AuditLogs","AZR-000022"]},{"location":"en/rules/Azure.AKS.AuditLogs/#description","title":"Description","text":"To capture security-based audit logs from AKS clusters, the following diagnostic log categories should be enabled:
kube-audit
or kube-audit-admin
, or both.kube-audit
- Contains all audit log data for every audit event, including get, list, create, update, delete, patch, and post.kube-audit-admin
- Is a subset of the kube-audit
log category. kube-audit-admin
reduces the number of logs significantly by excluding the get and list audit events from the log.guard
- Contains logs for Azure Active Directory (AAD) authorization integration. For managed Azure AD, this includes token in and user info out. For Azure RBAC, this includes access reviews in and out.Consider configuring diagnostic settings to capture security-based audit logs from AKS clusters.
","tags":["Azure.AKS.AuditLogs","AZR-000022"]},{"location":"en/rules/Azure.AKS.AuditLogs/#examples","title":"Examples","text":"","tags":["Azure.AKS.AuditLogs","AZR-000022"]},{"location":"en/rules/Azure.AKS.AuditLogs/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
kube-audit
/kube-audit-admin
and guard
categories.For example:
Azure Template snippet{\n \"comments\": \"Azure Kubernetes Cluster\",\n \"apiVersion\": \"2020-12-01\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ],\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"location\": \"[parameters('location')]\",\n \"name\": \"[parameters('clusterName')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 32,\n \"count\": 3,\n \"minCount\": 3,\n \"maxCount\": 10,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D2s_v3\",\n \"osType\": \"Linux\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[variables('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\",\n \"scaleSetPriority\": \"Regular\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"Standard\",\n \"serviceCidr\": \"192.168.0.0/16\",\n \"dnsServiceIP\": \"192.168.0.4\",\n \"dockerBridgeCidr\": \"172.17.0.1/16\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true,\n \"config\": {\n \"version\": \"v2\"\n }\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"kubeDashboard\": {\n \"enabled\": false\n }\n }\n },\n \"resources\": [\n {\n \"apiVersion\": \"2016-09-01\",\n \"type\": \"Microsoft.ContainerService/managedClusters/providers/diagnosticSettings\",\n \"name\": \"[concat(parameters('clusterName'), '/Microsoft.Insights/service')]\",\n \"properties\": {\n \"workspaceId\": \"[parameters('workspaceId')]\",\n \"logs\": [\n {\n \"category\": \"kube-audit\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n },\n {\n \"category\": \"kube-audit-admin\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n },\n {\n \"category\": \"guard\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n }\n ],\n \"metrics\": []\n }\n }\n ]\n}\n
","tags":["Azure.AKS.AuditLogs","AZR-000022"]},{"location":"en/rules/Azure.AKS.AuditLogs/#links","title":"Links","text":"Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_06 \u00b7 Important
Restrict access to API server endpoints to authorized IP addresses.
","tags":["Azure.AKS.AuthorizedIPs","AZR-000030"]},{"location":"en/rules/Azure.AKS.AuthorizedIPs/#description","title":"Description","text":"In Kubernetes, the API server is the control plane of the cluster. Access to the API server is required by various cluster functions as well as all administrator activities.
All activities performed against the cluster require authorization. To improve cluster security, the API server can be restricted to a limited set of IP address ranges.
Restricting authorized IP addresses for the API server has the following limitations:
When configuring this feature, you must specify the IP address ranges that will be authorized. To allow only the outbound public IP of the Standard SKU load balancer, use 0.0.0.0/32
.
You should add these ranges to the allow list:
Consider restricting network traffic to the API server endpoints to trusted IP addresses.
","tags":["Azure.AKS.AuthorizedIPs","AZR-000030"]},{"location":"en/rules/Azure.AKS.AuthorizedIPs/#examples","title":"Examples","text":"","tags":["Azure.AKS.AuthorizedIPs","AZR-000030"]},{"location":"en/rules/Azure.AKS.AuthorizedIPs/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy clusters that pass this rule:
properties.apiServerAccessProfile.authorizedIPRanges
property to a list of authorized IP ranges.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-11-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": \"[variables('allPools')]\",\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\"\n },\n \"apiServerAccessProfile\": {\n \"authorizedIPRanges\": [\n \"0.0.0.0/32\"\n ]\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"oidcIssuerProfile\": {\n \"enabled\": true\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.AuthorizedIPs","AZR-000030"]},{"location":"en/rules/Azure.AKS.AuthorizedIPs/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy resource that pass this rule:
properties.apiServerAccessProfile.authorizedIPRanges
property to a list of authorized IP ranges.For example:
Azure Bicep snippetresource cluster 'Microsoft.ContainerService/managedClusters@2023-11-01' = {\n location: location\n name: name\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: allPools\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n }\n apiServerAccessProfile: {\n authorizedIPRanges: [\n '0.0.0.0/32'\n ]\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n oidcIssuerProfile: {\n enabled: true\n }\n addonProfiles: {\n azurepolicy: {\n enabled: true\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.AuthorizedIPs","AZR-000030"]},{"location":"en/rules/Azure.AKS.AuthorizedIPs/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz aks update -n '<name>' -g '<resource_group>' --api-server-authorized-ip-ranges '0.0.0.0/32'\n
","tags":["Azure.AKS.AuthorizedIPs","AZR-000030"]},{"location":"en/rules/Azure.AKS.AuthorizedIPs/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetSet-AzAksCluster -Name '<name>' -ResourceGroupName '<resource_group>' -ApiServerAccessAuthorizedIpRange '0.0.0.0/32'\n
","tags":["Azure.AKS.AuthorizedIPs","AZR-000030"]},{"location":"en/rules/Azure.AKS.AuthorizedIPs/#links","title":"Links","text":"Performance Efficiency \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_09 \u00b7 Important
Use autoscaling to scale clusters based on workload requirements.
","tags":["Azure.AKS.AutoScaling","AZR-000019"]},{"location":"en/rules/Azure.AKS.AutoScaling/#description","title":"Description","text":"In addition to perform manual scaling, AKS clusters support autoscaling. Autoscaling reduces manual intervention required to scale a cluster up/ down to keep up with changing workload requirements. Scaling is performed on a node pool, which is a group of nodes with the same configuration within a cluster.
Within AKS, the cluster autoscaler monitors pods and nodes in the cluster. When a pod cannot be scheduled due to resource constraints, the cluster autoscaler increases the number of nodes in the node pool. When a node is underutilized, the cluster autoscaler removes the node from the node pool. Scaling is performed within the range of minCount
and maxCount
properties set on the node pool.
In addition to performance efficiency, autoscaling can also help reduce costs when the cluster is underutilized enough to reduce the number of nodes.
When scaling an AKS cluster manually or with auto-scale, consider the following:
maxCount
nodes and nodes added during upgrades.minCount
and maxCount
nodes.Consider deploying AKS clusters with virtual machine scale sets node pools and enable autoscaling.
","tags":["Azure.AKS.AutoScaling","AZR-000019"]},{"location":"en/rules/Azure.AKS.AutoScaling/#examples","title":"Examples","text":"","tags":["Azure.AKS.AutoScaling","AZR-000019"]},{"location":"en/rules/Azure.AKS.AutoScaling/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
properties.agentPoolProfiles[*].enableAutoScaling
property to true
.properties.agentPoolProfiles[*].type
property to VirtualMachineScaleSets
.properties.agentPoolProfiles[*].minCount
and properties.agentPoolProfiles[*].maxCount
properties. The cluster autoscaler will adjust the number of nodes between (inclusive of) these values.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-11-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 5,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\"\n },\n {\n \"name\": \"user\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 20,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"User\",\n \"osDiskType\": \"Ephemeral\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\"\n },\n \"apiServerAccessProfile\": {\n \"authorizedIPRanges\": [\n \"0.0.0.0/32\"\n ]\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"oidcIssuerProfile\": {\n \"enabled\": true\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.AutoScaling","AZR-000019"]},{"location":"en/rules/Azure.AKS.AutoScaling/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
properties.agentPoolProfiles[*].enableAutoScaling
property to true
.properties.agentPoolProfiles[*].type
property to VirtualMachineScaleSets
.properties.agentPoolProfiles[*].minCount
and properties.agentPoolProfiles[*].maxCount
properties. The cluster autoscaler will adjust the number of nodes between (inclusive of) these values.For example:
Azure Bicep snippetresource clusterWithPools 'Microsoft.ContainerService/managedClusters@2023-11-01' = {\n location: location\n name: name\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: [\n {\n name: 'system'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 5\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'System'\n osDiskType: 'Ephemeral'\n }\n {\n name: 'user'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 20\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'User'\n osDiskType: 'Ephemeral'\n }\n ]\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n }\n apiServerAccessProfile: {\n authorizedIPRanges: [\n '0.0.0.0/32'\n ]\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n oidcIssuerProfile: {\n enabled: true\n }\n addonProfiles: {\n azurepolicy: {\n enabled: true\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.AutoScaling","AZR-000019"]},{"location":"en/rules/Azure.AKS.AutoScaling/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"","tags":["Azure.AKS.AutoScaling","AZR-000019"]},{"location":"en/rules/Azure.AKS.AutoScaling/#enable-cluster-autoscaler","title":"Enable cluster autoscaler","text":"Azure CLI snippetaz aks update \\\n --name '<name>' \\\n --resource-group '<resource_group>' \\\n --enable-cluster-autoscaler \\\n --min-count '<min_count>' \\\n --max-count '<max_count>'\n
","tags":["Azure.AKS.AutoScaling","AZR-000019"]},{"location":"en/rules/Azure.AKS.AutoScaling/#enable-cluster-nodepool-autoscaler","title":"Enable cluster nodepool autoscaler","text":"Azure CLI snippetaz aks nodepool update \\\n --name '<name>' \\\n --resource-group '<resource_group>' \\\n --cluster-name '<cluster_name>' \\\n --enable-cluster-autoscaler \\\n --min-count '<min_count>' \\\n --max-count '<max_count>'\n
","tags":["Azure.AKS.AutoScaling","AZR-000019"]},{"location":"en/rules/Azure.AKS.AutoScaling/#links","title":"Links","text":"Operational Excellence \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Configure AKS to automatically upgrade to newer supported AKS versions as they are made available.
","tags":["Azure.AKS.AutoUpgrade","AZR-000036"]},{"location":"en/rules/Azure.AKS.AutoUpgrade/#description","title":"Description","text":"In additional to performing manual upgrades, AKS supports auto-upgrades. Auto-upgrades reduces manual intervention required to maintain an AKS cluster.
To configure auto-upgrades select a release channel instead of the default none
. The following release channels are available:
none
- Disables auto-upgrades. The default setting.patch
- Automatically upgrade to the latest supported patch version of the current minor version.stable
- Automatically upgrade to the latest supported patch release of the recommended minor version. This is N-1 of the current AKS non-preview minor version.rapid
- Automatically upgrade to the latest supported patch of the latest support minor version.node-image
- Automatically upgrade to the latest node image version. Normally upgraded weekly.Consider enabling auto-upgrades for AKS clusters by setting an auto-upgrade channel.
","tags":["Azure.AKS.AutoUpgrade","AZR-000036"]},{"location":"en/rules/Azure.AKS.AutoUpgrade/#examples","title":"Examples","text":"","tags":["Azure.AKS.AutoUpgrade","AZR-000036"]},{"location":"en/rules/Azure.AKS.AutoUpgrade/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
properties.autoUpgradeProfile.upgradeChannel
to an upgrade channel such as stable
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2021-07-01\",\n \"name\": \"[parameters('clusterName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": \"[variables('allPools')]\",\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\",\n \"dockerBridgeCidr\": \"[variables('dockerBridgeCidr')]\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"addonProfiles\": {\n \"httpApplicationRouting\": {\n \"enabled\": false\n },\n \"azurepolicy\": {\n \"enabled\": true,\n \"config\": {\n \"version\": \"v2\"\n }\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"kubeDashboard\": {\n \"enabled\": false\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"tags\": \"[parameters('tags')]\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.AutoUpgrade","AZR-000036"]},{"location":"en/rules/Azure.AKS.AutoUpgrade/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
properties.autoUpgradeProfile.upgradeChannel
to an upgrade channel such as stable
.For example:
Azure Bicep snippetresource cluster 'Microsoft.ContainerService/managedClusters@2021-07-01' = {\n location: location\n name: clusterName\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: allPools\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n dockerBridgeCidr: dockerBridgeCidr\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n addonProfiles: {\n httpApplicationRouting: {\n enabled: false\n }\n azurepolicy: {\n enabled: true\n config: {\n version: 'v2'\n }\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n kubeDashboard: {\n enabled: false\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n tags: tags\n}\n
","tags":["Azure.AKS.AutoUpgrade","AZR-000036"]},{"location":"en/rules/Azure.AKS.AutoUpgrade/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz aks update -n '<name>' -g '<resource_group>' --auto-upgrade-channel 'stable'\n
","tags":["Azure.AKS.AutoUpgrade","AZR-000036"]},{"location":"en/rules/Azure.AKS.AutoUpgrade/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/5c345cdf-2049-47e0-b8fe-b0e96bc2df35
Reliability \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_09 \u00b7 Important
AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability.
","tags":["Azure.AKS.AvailabilityZone","AZR-000021"]},{"location":"en/rules/Azure.AKS.AvailabilityZone/#description","title":"Description","text":"AKS clusters using availability zones improve reliability and ensure availability during failure scenarios affecting a data center within a region. Nodes in one availability zone are physically separated from nodes defined in another availability zone. By spreading node pools across multiple zones, nodes in one node pool will continue running even if another zone has gone down.
","tags":["Azure.AKS.AvailabilityZone","AZR-000021"]},{"location":"en/rules/Azure.AKS.AvailabilityZone/#recommendation","title":"Recommendation","text":"Consider using availability zones for AKS clusters deployed with virtual machine scale sets.
","tags":["Azure.AKS.AvailabilityZone","AZR-000021"]},{"location":"en/rules/Azure.AKS.AvailabilityZone/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed to Azure using pre-flight and in-flight data.
This rule fails when \"availabilityZones\"
is null
, []
or not set when the AKS cluster is deployed to a virtual machine scale set and there are supported availability zones for the given region.
Configure AZURE_AKS_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
to set additional availability zones that need to be supported which are not in the existing providers for namespace Microsoft.Compute
and resource type virtualMachineScaleSets
.
# YAML: The default AZURE_AKS_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST configuration option\nconfiguration:\n AZURE_AKS_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST: []\n
","tags":["Azure.AKS.AvailabilityZone","AZR-000021"]},{"location":"en/rules/Azure.AKS.AvailabilityZone/#examples","title":"Examples","text":"","tags":["Azure.AKS.AvailabilityZone","AZR-000021"]},{"location":"en/rules/Azure.AKS.AvailabilityZone/#configure-with-azure-template","title":"Configure with Azure template","text":"To set availability zones for an AKS cluster:
properties.agentPoolProfiles[*].availabilityZones
to any or all of [\"1\", \"2\", \"3\"]
.properties.agentPoolProfiles[*].type
to VirtualMachineScaleSets
.For example:
Azure Template snippet{\n \"comments\": \"Azure Kubernetes Cluster\",\n \"apiVersion\": \"2020-12-01\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ],\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"location\": \"[parameters('location')]\",\n \"name\": \"[parameters('clusterName')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 32,\n \"count\": 3,\n \"minCount\": 3,\n \"maxCount\": 10,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D2s_v3\",\n \"osType\": \"Linux\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[variables('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\",\n \"scaleSetPriority\": \"Regular\",\n \"availabilityZones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"Standard\",\n \"serviceCidr\": \"192.168.0.0/16\",\n \"dnsServiceIP\": \"192.168.0.4\",\n \"dockerBridgeCidr\": \"172.17.0.1/16\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true,\n \"config\": {\n \"version\": \"v2\"\n }\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"kubeDashboard\": {\n \"enabled\": false\n }\n }\n }\n}\n
","tags":["Azure.AKS.AvailabilityZone","AZR-000021"]},{"location":"en/rules/Azure.AKS.AvailabilityZone/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"","tags":["Azure.AKS.AvailabilityZone","AZR-000021"]},{"location":"en/rules/Azure.AKS.AvailabilityZone/#create-aks-cluster-in-zone-1-2-and-3","title":"Create AKS Cluster in Zone 1, 2 and 3","text":"Azure CLI snippetaz aks create \\\n --resource-group '<resource_group>' \\\n --name '<cluster_name>' \\\n --generate-ssh-keys \\\n --vm-set-type VirtualMachineScaleSets \\\n --load-balancer-sku standard \\\n --node-count '<node_count>' \\\n --zones 1 2 3\n
","tags":["Azure.AKS.AvailabilityZone","AZR-000021"]},{"location":"en/rules/Azure.AKS.AvailabilityZone/#links","title":"Links","text":"Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_12 \u00b7 Important
Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes.
","tags":["Azure.AKS.AzurePolicyAddOn","AZR-000028"]},{"location":"en/rules/Azure.AKS.AzurePolicyAddOn/#description","title":"Description","text":"AKS clusters support integration with Azure Policy using an Open Policy Agent (OPA). Azure Policy integration is provided by an optional add-on that can be enabled on AKS clusters. Once enabled and Azure policies assigned, AKS clusters will enforce the configured constraints.
Examples of policies include:
Consider installing the Azure Policy Add-on for AKS clusters. Additionally, assign one or more Azure Policy definitions to security controls.
","tags":["Azure.AKS.AzurePolicyAddOn","AZR-000028"]},{"location":"en/rules/Azure.AKS.AzurePolicyAddOn/#examples","title":"Examples","text":"","tags":["Azure.AKS.AzurePolicyAddOn","AZR-000028"]},{"location":"en/rules/Azure.AKS.AzurePolicyAddOn/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
properties.addonProfiles.azurepolicy.enabled
to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2024-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 5,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\"\n },\n {\n \"name\": \"user\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 20,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"User\",\n \"osDiskType\": \"Ephemeral\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\"\n },\n \"apiServerAccessProfile\": {\n \"enablePrivateCluster\": true,\n \"enablePrivateClusterPublicFQDN\": false\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"oidcIssuerProfile\": {\n \"enabled\": true\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.AzurePolicyAddOn","AZR-000028"]},{"location":"en/rules/Azure.AKS.AzurePolicyAddOn/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
properties.addonProfiles.azurepolicy.enabled
to true
.For example:
Azure Bicep snippetresource privateCluster 'Microsoft.ContainerService/managedClusters@2024-01-01' = {\n location: location\n name: name\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: [\n {\n name: 'system'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 5\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'System'\n osDiskType: 'Ephemeral'\n }\n {\n name: 'user'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 20\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'User'\n osDiskType: 'Ephemeral'\n }\n ]\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n }\n apiServerAccessProfile: {\n enablePrivateCluster: true\n enablePrivateClusterPublicFQDN: false\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n oidcIssuerProfile: {\n enabled: true\n }\n addonProfiles: {\n azurepolicy: {\n enabled: true\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.AzurePolicyAddOn","AZR-000028"]},{"location":"en/rules/Azure.AKS.AzurePolicyAddOn/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/0a15ec92-a229-4763-bb14-0ea34a568f8d
/providers/Microsoft.Authorization/policyDefinitions/a8eff44f-8c92-45c3-a3fb-9880802d67a7
Azure Policy for AKS clusters is generally available (GA). Azure Policy for AKS Engine and Arc enabled Kubernetes are currently in preview.
","tags":["Azure.AKS.AzurePolicyAddOn","AZR-000028"]},{"location":"en/rules/Azure.AKS.AzurePolicyAddOn/#links","title":"Links","text":"Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_06 \u00b7 Important
Use Azure RBAC for Kubernetes Authorization with AKS clusters.
","tags":["Azure.AKS.AzureRBAC","AZR-000032"]},{"location":"en/rules/Azure.AKS.AzureRBAC/#description","title":"Description","text":"Azure Kubernetes Service (AKS) supports Role-based Access Control (RBAC). RBAC is supported using Kubernetes RBAC and optionally Azure RBAC.
Using authorization provided by Azure RBAC simplifies and centralizes authorization of Azure AD principals. Access to Kubernetes resource can be managed using Azure Resource Manager (ARM).
When Azure RBAC is enabled:
Consider using Azure RBAC for Kubernetes Authorization to centralize authorization of Azure AD principals.
","tags":["Azure.AKS.AzureRBAC","AZR-000032"]},{"location":"en/rules/Azure.AKS.AzureRBAC/#examples","title":"Examples","text":"","tags":["Azure.AKS.AzureRBAC","AZR-000032"]},{"location":"en/rules/Azure.AKS.AzureRBAC/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
properties.aadProfile.enableAzureRBAC
to true
.For example:
Azure Template snippet{\n \"comments\": \"Azure Kubernetes Cluster\",\n \"apiVersion\": \"2020-12-01\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ],\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"location\": \"[parameters('location')]\",\n \"name\": \"[parameters('clusterName')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 32,\n \"count\": 3,\n \"minCount\": 3,\n \"maxCount\": 10,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D2s_v3\",\n \"osType\": \"Linux\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[variables('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\",\n \"scaleSetPriority\": \"Regular\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"Standard\",\n \"serviceCidr\": \"192.168.0.0/16\",\n \"dnsServiceIP\": \"192.168.0.4\",\n \"dockerBridgeCidr\": \"172.17.0.1/16\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true,\n \"config\": {\n \"version\": \"v2\"\n }\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"kubeDashboard\": {\n \"enabled\": false\n }\n }\n }\n}\n
","tags":["Azure.AKS.AzureRBAC","AZR-000032"]},{"location":"en/rules/Azure.AKS.AzureRBAC/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz aks update -n '<name>' -g '<resource_group>' --enable-azure-rbac\n
","tags":["Azure.AKS.AzureRBAC","AZR-000032"]},{"location":"en/rules/Azure.AKS.AzureRBAC/#links","title":"Links","text":"Reliability \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_09 \u00b7 Important
AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues.
","tags":["Azure.AKS.CNISubnetSize","AZR-000020"]},{"location":"en/rules/Azure.AKS.CNISubnetSize/#description","title":"Description","text":"In addition to kubenet, AKS clusters support Azure Container Networking Interface (CNI). This enables every pod to be accessed directly from the subnet via an IP address. Each node supports a maximum number of pods, which are reserved as IP addresses. This approach requires more capacity planning ahead of time, and can result in IP address exhaustion or the need to rebuild AKS clusters into larger subnets as application workloads begin to grow.
","tags":["Azure.AKS.CNISubnetSize","AZR-000020"]},{"location":"en/rules/Azure.AKS.CNISubnetSize/#recommendation","title":"Recommendation","text":"Consider allocating a larger subnet (/23
or bigger) to your AKS cluster.
This rule applies when analyzing resources deployed to Azure using Export in-flight resource data.
","tags":["Azure.AKS.CNISubnetSize","AZR-000020"]},{"location":"en/rules/Azure.AKS.CNISubnetSize/#rule-configuration","title":"Rule configuration","text":"AZURE_AKS_CNI_MINIMUM_CLUSTER_SUBNET_SIZE
This rule fails when the CNI subnet size is smaller than /23
.
Configure AZURE_AKS_CNI_MINIMUM_CLUSTER_SUBNET_SIZE
to set the minimum AKS CNI cluster subnet size.
# YAML: The default AZURE_AKS_CNI_MINIMUM_CLUSTER_SUBNET_SIZE configuration option\nconfiguration:\n AZURE_AKS_CNI_MINIMUM_CLUSTER_SUBNET_SIZE: 23\n
","tags":["Azure.AKS.CNISubnetSize","AZR-000020"]},{"location":"en/rules/Azure.AKS.CNISubnetSize/#links","title":"Links","text":"Operational Excellence \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_09 \u00b7 Important
Enable Container insights to monitor AKS cluster workloads.
","tags":["Azure.AKS.ContainerInsights","AZR-000041"]},{"location":"en/rules/Azure.AKS.ContainerInsights/#description","title":"Description","text":"With Container insights, you can use performance charts and health status to monitor AKS clusters, nodes and pods. Container insights delivers quick, visual and actionable information: from the CPU and memory pressure of your nodes to the logs of individual Kubernetes pods.
","tags":["Azure.AKS.ContainerInsights","AZR-000041"]},{"location":"en/rules/Azure.AKS.ContainerInsights/#recommendation","title":"Recommendation","text":"Consider enabling Container insights for AKS clusters. Monitoring containers is critical, especially when running production AKS clusters at scale with multiple applications.
","tags":["Azure.AKS.ContainerInsights","AZR-000041"]},{"location":"en/rules/Azure.AKS.ContainerInsights/#examples","title":"Examples","text":"","tags":["Azure.AKS.ContainerInsights","AZR-000041"]},{"location":"en/rules/Azure.AKS.ContainerInsights/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Container insights for an AKS cluster:
properties.addonProfiles.omsAgent.enabled
to true
.properties.addonProfiles.omsAgent.config.logAnalyticsWorkspaceResourceID
.For example:
Azure Template snippet{\n \"comments\": \"Azure Kubernetes Cluster\",\n \"apiVersion\": \"2020-12-01\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ],\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"location\": \"[parameters('location')]\",\n \"name\": \"[parameters('clusterName')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 32,\n \"count\": 3,\n \"minCount\": 3,\n \"maxCount\": 10,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D2s_v3\",\n \"osType\": \"Linux\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[variables('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\",\n \"scaleSetPriority\": \"Regular\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"Standard\",\n \"serviceCidr\": \"192.168.0.0/16\",\n \"dnsServiceIP\": \"192.168.0.4\",\n \"dockerBridgeCidr\": \"172.17.0.1/16\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true,\n \"config\": {\n \"version\": \"v2\"\n }\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"kubeDashboard\": {\n \"enabled\": false\n }\n }\n }\n}\n
","tags":["Azure.AKS.ContainerInsights","AZR-000041"]},{"location":"en/rules/Azure.AKS.ContainerInsights/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"","tags":["Azure.AKS.ContainerInsights","AZR-000041"]},{"location":"en/rules/Azure.AKS.ContainerInsights/#enable-for-default-log-analytics-workspace","title":"Enable for default Log Analytics workspace","text":"Azure CLI snippetaz aks enable-addons \\\n --addons monitoring \\\n --name '<cluster_name>' \\\n --resource-group '<cluster_resource_group>'\n
","tags":["Azure.AKS.ContainerInsights","AZR-000041"]},{"location":"en/rules/Azure.AKS.ContainerInsights/#enable-for-an-existing-log-analytics-workspace","title":"Enable for an existing Log Analytics workspace","text":"Azure CLI snippetaz aks enable-addons \\\n --addons monitoring \\\n --name '<cluster_name>' \\\n --resource-group '<cluster_resource_group>' \\\n --workspace-resource-id '<workspace_id>'\n
","tags":["Azure.AKS.ContainerInsights","AZR-000041"]},{"location":"en/rules/Azure.AKS.ContainerInsights/#links","title":"Links","text":"Operational Excellence \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements.
","tags":["Azure.AKS.DNSPrefix","AZR-000040"]},{"location":"en/rules/Azure.AKS.DNSPrefix/#description","title":"Description","text":"The DNS prefix for AKS clusters has different requirements then the cluster name. The requirements for DNS prefixes are:
Consider using a DNS prefix that meets naming requirements.
","tags":["Azure.AKS.DNSPrefix","AZR-000040"]},{"location":"en/rules/Azure.AKS.DNSPrefix/#links","title":"Links","text":"Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2023_03 \u00b7 Important
Enable the Defender profile with Azure Kubernetes Service (AKS) cluster.
","tags":["Azure.AKS.DefenderProfile","AZR-000370"]},{"location":"en/rules/Azure.AKS.DefenderProfile/#description","title":"Description","text":"To collect and provide data plane protections of Microsoft Defender for Containers some additional daemon set and deployments needs to be deployed to the AKS clusters.
These components are installed when the Defender profile is enabled on the cluster.
The Defender profile deployed to each node provides the runtime protections and collects signals from nodes.
","tags":["Azure.AKS.DefenderProfile","AZR-000370"]},{"location":"en/rules/Azure.AKS.DefenderProfile/#recommendation","title":"Recommendation","text":"Consider enabling the Defender profile with Azure Kubernetes Service (AKS) cluster.
","tags":["Azure.AKS.DefenderProfile","AZR-000370"]},{"location":"en/rules/Azure.AKS.DefenderProfile/#examples","title":"Examples","text":"","tags":["Azure.AKS.DefenderProfile","AZR-000370"]},{"location":"en/rules/Azure.AKS.DefenderProfile/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable the Defender profile with Azure Kubernetes Service clusters:
properties.securityProfile.defender.securityMonitoring.enabled
to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-01-02-preview\",\n \"name\": \"[parameters('clusterName')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"securityProfile\": {\n \"defender\": {\n \"logAnalyticsWorkspaceResourceId\": \"[parameters('logAnalyticsWorkspaceResourceId')]\",\n \"securityMonitoring\": {\n \"enabled\": true\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.DefenderProfile","AZR-000370"]},{"location":"en/rules/Azure.AKS.DefenderProfile/#configure-with-bicep","title":"Configure with Bicep","text":"To enable the Defender profile with Azure Kubernetes Service clusters:
properties.securityProfile.defender.securityMonitoring.enabled
to true
.For example:
Azure Bicep snippetresource cluster 'Microsoft.ContainerService/managedClusters@2023-01-02-preview' = {\n location: location\n name: clusterName\n properties: {\n securityProfile: {\n defender: {\n logAnalyticsWorkspaceResourceId: logAnalyticsWorkspaceResourceId\n securityMonitoring: {\n enabled: true\n }\n }\n }\n } \n}\n
","tags":["Azure.AKS.DefenderProfile","AZR-000370"]},{"location":"en/rules/Azure.AKS.DefenderProfile/#notes","title":"Notes","text":"Outbound access so that the Defender profile can connect to Microsoft Defender for Cloud to send security data and events is required.
","tags":["Azure.AKS.DefenderProfile","AZR-000370"]},{"location":"en/rules/Azure.AKS.DefenderProfile/#links","title":"Links","text":"Performance Efficiency \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2022_09 \u00b7 Important
AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades.
","tags":["Azure.AKS.EphemeralOSDisk","AZR-000287"]},{"location":"en/rules/Azure.AKS.EphemeralOSDisk/#description","title":"Description","text":"By default, Azure automatically replicates the operating system disk for a virtual machine to Azure storage to avoid data loss if the VM needs to be relocated to another host. However, since containers aren't designed to have local state persisted, this behavior offers limited value while providing some drawbacks, including slower node provisioning and higher read/write latency.
By contrast, ephemeral OS disks are stored only on the host machine, just like a temporary disk. This provides lower read/write latency, along with faster node scaling and cluster upgrades.
Like the temporary disk, an ephemeral OS disk is included in the price of the virtual machine, so you incur no additional storage costs.
NB: When a user does not explicitly request managed disks for the OS, AKS will default to ephemeral OS if possible for a given node pool configuration. The rule is therefore configured with -Level Warning
as it can give inaccurate information.
When using ephemeral OS, the OS disk must fit in the VM cache. The sizes for VM cache are available in the Azure documentation in parentheses next to IO throughput (\"cache size in GiB\").
Examples:
AKS clusters should use ephemeral OS disks.
","tags":["Azure.AKS.EphemeralOSDisk","AZR-000287"]},{"location":"en/rules/Azure.AKS.EphemeralOSDisk/#examples","title":"Examples","text":"","tags":["Azure.AKS.EphemeralOSDisk","AZR-000287"]},{"location":"en/rules/Azure.AKS.EphemeralOSDisk/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy an AKS cluster that pass this rule:
properties.agentPoolProfiles.osDiskType
to Ephemeral
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2022-06-02-preview\",\n \"name\": \"[parameters('clusterName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Basic\",\n \"tier\": \"Paid\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"agentpool\",\n \"osDiskSizeGB\": 60,\n \"count\": \"[parameters('agentCount')]\",\n \"vmSize\": \"[parameters('agentVMSize')]\",\n \"osDiskType\": \"Ephemeral\",\n \"osType\": \"Linux\",\n \"mode\": \"System\"\n }\n ],\n \"linuxProfile\": {\n \"adminUsername\": \"[parameters('linuxAdminUsername')]\",\n \"ssh\": {\n \"publicKeys\": [\n {\n \"keyData\": \"[parameters('sshRSAPublicKey')]\"\n }\n ]\n }\n }\n }\n}\n
To deploy an AKS agent pool that pass this rule:
properties.osDiskType
to Ephemeral
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters/agentPools\",\n \"apiVersion\": \"2022-07-01\",\n \"name\": \"[format('{0}/{1}', parameters('clusterName'), variables('poolName'))]\",\n \"properties\": {\n \"count\": \"[variables('minCount')]\",\n \"vmSize\": \"[variables('vmSize')]\",\n \"osDiskSizeGB\": 60,\n \"osType\": \"Linux\",\n \"osDiskType\": \"Ephemeral\",\n \"maxPods\": 50,\n \"mode\": \"User\"\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ContainerService/managedClusters', parameters('clusterName'))]\"\n ]\n}\n
","tags":["Azure.AKS.EphemeralOSDisk","AZR-000287"]},{"location":"en/rules/Azure.AKS.EphemeralOSDisk/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy an AKS cluster that pass this rule:
properties.agentPoolProfiles.osDiskType
to Ephemeral
.For example:
Azure Bicep snippetresource aks 'Microsoft.ContainerService/managedClusters@2022-06-02-preview' = {\n name: clusterName\n location: location\n sku: {\n name: 'Basic'\n tier: 'Paid'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n dnsPrefix: dnsPrefix\n agentPoolProfiles: [\n {\n name: 'agentpool'\n osDiskSizeGB: 60\n count: agentCount\n vmSize: agentVMSize\n osDiskType: 'Ephemeral'\n osType: 'Linux'\n mode: 'System'\n }\n ]\n linuxProfile: {\n adminUsername: linuxAdminUsername\n ssh: {\n publicKeys: [\n {\n keyData: sshRSAPublicKey\n }\n ]\n }\n }\n }\n}\n
To deploy an AKS agent pool that pass this rule:
properties.osDiskType
to Ephemeral
.For example:
Azure Bicep snippetresource userPool 'Microsoft.ContainerService/managedClusters/agentPools@2022-07-01' = {\n parent: cluster\n name: poolName\n properties: {\n count: minCount\n vmSize: vmSize\n osDiskSizeGB: 60\n osType: 'Linux'\n osDiskType: 'Ephemeral'\n maxPods: 50\n mode: 'User'\n }\n}\n
","tags":["Azure.AKS.EphemeralOSDisk","AZR-000287"]},{"location":"en/rules/Azure.AKS.EphemeralOSDisk/#links","title":"Links","text":"Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Disable HTTP application routing add-on in AKS clusters.
","tags":["Azure.AKS.HttpAppRouting","AZR-000035"]},{"location":"en/rules/Azure.AKS.HttpAppRouting/#description","title":"Description","text":"The HTTP application routing add-on is designed to quickly expose HTTP endpoints to the public internet. This may be helpful in some limited scenarios, but should not be used in production.
When exposing application endpoints consider using an ingress controller that supports:
Azure provides a production ready ingress controller Application Gateway Ingress Controller (AGIC).
","tags":["Azure.AKS.HttpAppRouting","AZR-000035"]},{"location":"en/rules/Azure.AKS.HttpAppRouting/#recommendation","title":"Recommendation","text":"Consider disabling the HTTP application routing add-on in your AKS cluster. Also consider using Application Gateway Ingress Controller (AGIC) instead to protect application endpoints.
","tags":["Azure.AKS.HttpAppRouting","AZR-000035"]},{"location":"en/rules/Azure.AKS.HttpAppRouting/#examples","title":"Examples","text":"","tags":["Azure.AKS.HttpAppRouting","AZR-000035"]},{"location":"en/rules/Azure.AKS.HttpAppRouting/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
Properties.addonProfiles.httpApplicationRouting.enabled
to false
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2021-07-01\",\n \"name\": \"[parameters('clusterName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": \"[variables('allPools')]\",\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\",\n \"dockerBridgeCidr\": \"[variables('dockerBridgeCidr')]\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"addonProfiles\": {\n \"httpApplicationRouting\": {\n \"enabled\": false\n },\n \"azurepolicy\": {\n \"enabled\": true,\n \"config\": {\n \"version\": \"v2\"\n }\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"kubeDashboard\": {\n \"enabled\": false\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"tags\": \"[parameters('tags')]\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.HttpAppRouting","AZR-000035"]},{"location":"en/rules/Azure.AKS.HttpAppRouting/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
Properties.addonProfiles.httpApplicationRouting.enabled
to false
.For example:
Azure Bicep snippetresource cluster 'Microsoft.ContainerService/managedClusters@2021-07-01' = {\n location: location\n name: clusterName\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: allPools\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n dockerBridgeCidr: dockerBridgeCidr\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n addonProfiles: {\n httpApplicationRouting: {\n enabled: false\n }\n azurepolicy: {\n enabled: true\n config: {\n version: 'v2'\n }\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n kubeDashboard: {\n enabled: false\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n tags: tags\n}\n
","tags":["Azure.AKS.HttpAppRouting","AZR-000035"]},{"location":"en/rules/Azure.AKS.HttpAppRouting/#links","title":"Links","text":"Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2023_09 \u00b7 Important
Enforce named user accounts with RBAC assigned permissions.
","tags":["Azure.AKS.LocalAccounts","AZR-000031"]},{"location":"en/rules/Azure.AKS.LocalAccounts/#description","title":"Description","text":"AKS clusters support Role-based Access Control (RBAC) authorization. RBAC allows users, groups, and service accounts to be granted access to resources on an as needed basis. Actions performed by each identity can be logged for auditing with Kubernetes audit policies.
When a cluster is deployed, local accounts are enabled by default even when RBAC is enabled. These local accounts such as clusterAdmin
and clusterUser
are shared accounts that are not tied to an identity.
If local account credentials are used, Kubernetes auditing logs the local account instead of named accounts. Who performed an action cannot be determined from the audit logs, creating an audit log gap for privileged actions.
In an AKS cluster with local account disabled administrator will be unable to get the clusterAdmin credential. For example, using az aks get-credentials -g '<resource-group>' -n '<cluster-name>' --admin
will fail.
Consider enforcing usage of named accounts by disabling local Kubernetes account credentials. Also consider enforcing this setting using Azure Policy.
","tags":["Azure.AKS.LocalAccounts","AZR-000031"]},{"location":"en/rules/Azure.AKS.LocalAccounts/#examples","title":"Examples","text":"","tags":["Azure.AKS.LocalAccounts","AZR-000031"]},{"location":"en/rules/Azure.AKS.LocalAccounts/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
properties.disableLocalAccounts
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-07-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 5,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\"\n },\n {\n \"name\": \"user\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 20,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"User\",\n \"osDiskType\": \"Ephemeral\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"oidcIssuerProfile\": {\n \"enabled\": true\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.LocalAccounts","AZR-000031"]},{"location":"en/rules/Azure.AKS.LocalAccounts/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
properties.disableLocalAccounts
property to true
.For example:
Azure Bicep snippetresource clusterWithPools 'Microsoft.ContainerService/managedClusters@2023-07-01' = {\n location: location\n name: name\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: [\n {\n name: 'system'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 5\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'System'\n osDiskType: 'Ephemeral'\n }\n {\n name: 'user'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 20\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'User'\n osDiskType: 'Ephemeral'\n }\n ]\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n oidcIssuerProfile: {\n enabled: true\n }\n addonProfiles: {\n azurepolicy: {\n enabled: true\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.LocalAccounts","AZR-000031"]},{"location":"en/rules/Azure.AKS.LocalAccounts/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz aks update -n '<name>' -g '<resource_group>' --enable-aad --aad-admin-group-object-ids '<aad-group-id>' --disable-local\n
","tags":["Azure.AKS.LocalAccounts","AZR-000031"]},{"location":"en/rules/Azure.AKS.LocalAccounts/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/993c2fcd-2b29-49d2-9eb0-df2c3a730c32
Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_06 \u00b7 Important
Use AKS-managed Azure AD to simplify authorization and improve security.
","tags":["Azure.AKS.ManagedAAD","AZR-000029"]},{"location":"en/rules/Azure.AKS.ManagedAAD/#description","title":"Description","text":"AKS-managed integration provides an easy way to use Azure AD authorization for AKS. Previous Azure AD integration with AKS required app registration and management within Azure AD.
","tags":["Azure.AKS.ManagedAAD","AZR-000029"]},{"location":"en/rules/Azure.AKS.ManagedAAD/#recommendation","title":"Recommendation","text":"Consider configuring AKS-managed Azure AD integration for AKS clusters.
","tags":["Azure.AKS.ManagedAAD","AZR-000029"]},{"location":"en/rules/Azure.AKS.ManagedAAD/#examples","title":"Examples","text":"","tags":["Azure.AKS.ManagedAAD","AZR-000029"]},{"location":"en/rules/Azure.AKS.ManagedAAD/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
properties.aadProfile.managed
to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2021-10-01\",\n \"name\": \"[parameters('clusterName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": \"[variables('allPools')]\",\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\",\n \"dockerBridgeCidr\": \"[variables('dockerBridgeCidr')]\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"addonProfiles\": {\n \"httpApplicationRouting\": {\n \"enabled\": false\n },\n \"azurepolicy\": {\n \"enabled\": true,\n \"config\": {\n \"version\": \"v2\"\n }\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"kubeDashboard\": {\n \"enabled\": false\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n },\n \"podIdentityProfile\": {\n \"enabled\": true\n }\n },\n \"tags\": \"[parameters('tags')]\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.ManagedAAD","AZR-000029"]},{"location":"en/rules/Azure.AKS.ManagedAAD/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
properties.aadProfile.managed
to true
.For example:
Azure Bicep snippetresource cluster 'Microsoft.ContainerService/managedClusters@2021-10-01' = {\n location: location\n name: clusterName\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: allPools\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n dockerBridgeCidr: dockerBridgeCidr\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n addonProfiles: {\n httpApplicationRouting: {\n enabled: false\n }\n azurepolicy: {\n enabled: true\n config: {\n version: 'v2'\n }\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n kubeDashboard: {\n enabled: false\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n podIdentityProfile: {\n enabled: true\n }\n }\n tags: tags\n}\n
","tags":["Azure.AKS.ManagedAAD","AZR-000029"]},{"location":"en/rules/Azure.AKS.ManagedAAD/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz aks update -n '<name>' -g '<resource_group>' --enable-aad --aad-admin-group-object-ids '<group_id>'\n
","tags":["Azure.AKS.ManagedAAD","AZR-000029"]},{"location":"en/rules/Azure.AKS.ManagedAAD/#links","title":"Links","text":"Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Configure AKS clusters to use managed identities for managing cluster infrastructure.
","tags":["Azure.AKS.ManagedIdentity","AZR-000025"]},{"location":"en/rules/Azure.AKS.ManagedIdentity/#description","title":"Description","text":"During the lifecycle of an AKS cluster, the control plane configures a number of Azure resources. This includes node pools, networking, storage and other supporting services.
When making calls against the Azure REST APIs, an identity must be used to authenticate requests. The type of identity the control plane will use is configurable at cluster creation. Either a service principal or system-assigned managed identity can be used.
By default, the service principal credentials are valid for one year. Service principal credentials must be rotated before expiry to prevent issues. You can update or rotate the service principal credentials at any time.
Using a system-assigned managed identity abstracts the process of managing a service principal. The managed identity is automatically created/ removed with the cluster. Managed identities also reduce maintenance (and improve security) by automatically rotating credentials.
Separately, applications within an AKS cluster may use managed identities with AAD Pod Identity.
","tags":["Azure.AKS.ManagedIdentity","AZR-000025"]},{"location":"en/rules/Azure.AKS.ManagedIdentity/#recommendation","title":"Recommendation","text":"Consider using managed identities during AKS cluster creation. Additionally, consider redeploying the AKS cluster with managed identities instead of service principals.
","tags":["Azure.AKS.ManagedIdentity","AZR-000025"]},{"location":"en/rules/Azure.AKS.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.AKS.ManagedIdentity","AZR-000025"]},{"location":"en/rules/Azure.AKS.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-11-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 5,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\"\n },\n {\n \"name\": \"user\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 20,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"User\",\n \"osDiskType\": \"Ephemeral\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\"\n },\n \"apiServerAccessProfile\": {\n \"authorizedIPRanges\": [\n \"0.0.0.0/32\"\n ]\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"oidcIssuerProfile\": {\n \"enabled\": true\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.ManagedIdentity","AZR-000025"]},{"location":"en/rules/Azure.AKS.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource clusterWithPools 'Microsoft.ContainerService/managedClusters@2023-11-01' = {\n location: location\n name: name\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: [\n {\n name: 'system'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 5\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'System'\n osDiskType: 'Ephemeral'\n }\n {\n name: 'user'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 20\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'User'\n osDiskType: 'Ephemeral'\n }\n ]\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n }\n apiServerAccessProfile: {\n authorizedIPRanges: [\n '0.0.0.0/32'\n ]\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n oidcIssuerProfile: {\n enabled: true\n }\n addonProfiles: {\n azurepolicy: {\n enabled: true\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.ManagedIdentity","AZR-000025"]},{"location":"en/rules/Azure.AKS.ManagedIdentity/#notes","title":"Notes","text":"Managed identities can only be configured during initial cluster creation. Existing AKS clusters must be redeployed to enable managed identities.
","tags":["Azure.AKS.ManagedIdentity","AZR-000025"]},{"location":"en/rules/Azure.AKS.ManagedIdentity/#links","title":"Links","text":"Reliability \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
AKS clusters should have minimum number of system nodes for failover and updates.
","tags":["Azure.AKS.MinNodeCount","AZR-000024"]},{"location":"en/rules/Azure.AKS.MinNodeCount/#description","title":"Description","text":"Azure Kubernetes (AKS) clusters support multiple nodes and node pools. Each node is a virtual machine (VM) that runs Kubernetes components and a container runtime. A node pool is a grouping of nodes that run the same configuration. Application or system pods can be scheduled to run across multiple nodes to ensure resiliency and high availability. AKS supports configuring one or more system node pools, and zero or more user node pools.
System node pools are intended for pods that perform important management and infrastructure functions for cluster operation. This includes CoreDNS, konnectivity, and Azure Policy to name a few. The number of pods that are scheduled to run on system node pools varies based on the configuration of your cluster.
User node pools are intended for application pods. In general, schedule application workloads to run on user node pools to avoid disrupting the operation of system pods.
A minimum number of nodes in each node pool should be maintained to ensure resiliency during node failures or disruptions. Also consider how your nodes are distributed across availability zones when deploying to a supported region. Understanding that adding new nodes to a node pool can take time.
For example, in a three-node node pool:
For example, in a 2x two-node node pool:
1
, 2
. AKS will automatically spread the nodes across the two availability zones as it scales out.1
fails, 50% capacity on the remaining nodes in availability zone 2
will continue to run pods.1
will be rescheduled to run pending enough capacity.Consider configuring AKS clusters with at least three (3) agent nodes in system node pools.
","tags":["Azure.AKS.MinNodeCount","AZR-000024"]},{"location":"en/rules/Azure.AKS.MinNodeCount/#examples","title":"Examples","text":"","tags":["Azure.AKS.MinNodeCount","AZR-000024"]},{"location":"en/rules/Azure.AKS.MinNodeCount/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
To deploy AKS clusters that pass this rule:
properties.agentPoolProfiles
:minCount
property to at least 3
for node pools with auto-scale. ORcount
property to at least 3
for node pools without auto-scale. OR3
across all pools. For example, two node pools with minCount
set to 2
totalling 4 nodes.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-11-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 5,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\"\n },\n {\n \"name\": \"user\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 20,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"User\",\n \"osDiskType\": \"Ephemeral\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\"\n },\n \"apiServerAccessProfile\": {\n \"authorizedIPRanges\": [\n \"0.0.0.0/32\"\n ]\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"oidcIssuerProfile\": {\n \"enabled\": true\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.MinNodeCount","AZR-000024"]},{"location":"en/rules/Azure.AKS.MinNodeCount/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
properties.agentPoolProfiles
:minCount
property to at least 3
for node pools with auto-scale. ORcount
property to at least 3
for node pools without auto-scale. OR3
across all pools. For example, two node pools with minCount
set to 2
totalling 4 nodes.For example:
Azure Bicep snippetresource clusterWithPools 'Microsoft.ContainerService/managedClusters@2023-11-01' = {\n location: location\n name: name\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: [\n {\n name: 'system'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 5\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'System'\n osDiskType: 'Ephemeral'\n }\n {\n name: 'user'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 20\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'User'\n osDiskType: 'Ephemeral'\n }\n ]\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n }\n apiServerAccessProfile: {\n authorizedIPRanges: [\n '0.0.0.0/32'\n ]\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n oidcIssuerProfile: {\n enabled: true\n }\n addonProfiles: {\n azurepolicy: {\n enabled: true\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.MinNodeCount","AZR-000024"]},{"location":"en/rules/Azure.AKS.MinNodeCount/#notes","title":"Notes","text":"","tags":["Azure.AKS.MinNodeCount","AZR-000024"]},{"location":"en/rules/Azure.AKS.MinNodeCount/#rule-configuration","title":"Rule configuration","text":"AZURE_AKS_CLUSTER_MINIMUM_SYSTEM_NODES
This rule fails by default if you have less than three (3) nodes in the cluster across all system node pools. To change the default, set the AZURE_AKS_CLUSTER_MINIMUM_SYSTEM_NODES
configuration option.
Reliability \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2024_03 \u00b7 Important
User node pools in an AKS cluster should have a minimum number of nodes for failover and updates.
","tags":["Azure.AKS.MinUserPoolNodes","AZR-000412"]},{"location":"en/rules/Azure.AKS.MinUserPoolNodes/#description","title":"Description","text":"Azure Kubernetes (AKS) clusters support multiple nodes and node pools. Each node is a virtual machine (VM) that runs Kubernetes components and a container runtime. A node pool is a grouping of nodes that run the same configuration. Application or system pods can be scheduled to run across multiple nodes to ensure resiliency and high availability. AKS supports configuring one or more system node pools, and zero or more user node pools.
User node pools are intended for application pods.
A minimum number of nodes in each node pool should be maintained to ensure resiliency during node failures or disruptions. Resiliency in application pods is also dependent on the number of replicas and the distribution of pods across nodes. Application pods may be configured to use specific node pools based on access features such as GPU or access to storage.
Also consider how your nodes are distributed across availability zones when deploying to a supported region. Understanding that adding new nodes to a node pool can take time.
","tags":["Azure.AKS.MinUserPoolNodes","AZR-000412"]},{"location":"en/rules/Azure.AKS.MinUserPoolNodes/#recommendation","title":"Recommendation","text":"Consider configuring AKS clusters with at least three (3) agent nodes in each user node pools.
","tags":["Azure.AKS.MinUserPoolNodes","AZR-000412"]},{"location":"en/rules/Azure.AKS.MinUserPoolNodes/#examples","title":"Examples","text":"","tags":["Azure.AKS.MinUserPoolNodes","AZR-000412"]},{"location":"en/rules/Azure.AKS.MinUserPoolNodes/#configure-with-azure-template","title":"Configure with Azure template","text":"properties.agentPoolProfiles
:minCount
property to at least 3
for node pools with auto-scale. ORcount
property to at least 3
for node pools without auto-scale.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-11-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 5,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\"\n },\n {\n \"name\": \"user\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 20,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"User\",\n \"osDiskType\": \"Ephemeral\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\"\n },\n \"apiServerAccessProfile\": {\n \"authorizedIPRanges\": [\n \"0.0.0.0/32\"\n ]\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"oidcIssuerProfile\": {\n \"enabled\": true\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.MinUserPoolNodes","AZR-000412"]},{"location":"en/rules/Azure.AKS.MinUserPoolNodes/#configure-with-bicep","title":"Configure with Bicep","text":"properties.agentPoolProfiles
:minCount
property to at least 3
for node pools with auto-scale. ORcount
property to at least 3
for node pools without auto-scale.For example:
Azure Bicep snippetresource clusterWithPools 'Microsoft.ContainerService/managedClusters@2023-11-01' = {\n location: location\n name: name\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: [\n {\n name: 'system'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 5\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'System'\n osDiskType: 'Ephemeral'\n }\n {\n name: 'user'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 20\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'User'\n osDiskType: 'Ephemeral'\n }\n ]\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n }\n apiServerAccessProfile: {\n authorizedIPRanges: [\n '0.0.0.0/32'\n ]\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n oidcIssuerProfile: {\n enabled: true\n }\n addonProfiles: {\n azurepolicy: {\n enabled: true\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.MinUserPoolNodes","AZR-000412"]},{"location":"en/rules/Azure.AKS.MinUserPoolNodes/#notes","title":"Notes","text":"Node pools that are configured for spot instances are excluded from this rule. Spot instances can be used for burst capacity but do not provide a guarantee of availability.
","tags":["Azure.AKS.MinUserPoolNodes","AZR-000412"]},{"location":"en/rules/Azure.AKS.MinUserPoolNodes/#rule-configuration","title":"Rule configuration","text":"AZURE_AKS_CLUSTER_USER_POOL_MINIMUM_NODES
This rule fails by default if you have less than three (3) nodes in each user node pool. To change the default, set the AZURE_AKS_CLUSTER_USER_POOL_MINIMUM_NODES
configuration option.
AZURE_AKS_CLUSTER_USER_POOL_EXCLUDED_FROM_MINIMUM_NODES
To exclude a specific user node pool by name from this rule, set the AZURE_AKS_CLUSTER_USER_POOL_EXCLUDED_FROM_MINIMUM_NODES
configuration option.
Operational Excellence \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Azure Kubernetes Service (AKS) cluster names should meet naming requirements.
","tags":["Azure.AKS.Name","AZR-000039"]},{"location":"en/rules/Azure.AKS.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for AKS cluster names are:
Consider using names that meet AKS cluster naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.AKS.Name","AZR-000039"]},{"location":"en/rules/Azure.AKS.Name/#notes","title":"Notes","text":"This rule does not check if cluster names are unique.
Cluster DNS prefix has different naming requirements then cluster name. The requirements for DNS prefixes are:
Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Deploy AKS clusters with Network Policies enabled.
","tags":["Azure.AKS.NetworkPolicy","AZR-000027"]},{"location":"en/rules/Azure.AKS.NetworkPolicy/#description","title":"Description","text":"AKS clusters provides a platform to host containerized workloads. The running of these applications or services is orchestrated by Kubernetes. Workloads may elastic scale or change network addressing.
By default, all pods in an AKS cluster can send and receive traffic without limitations. Network Policy defines access policies for limiting network communication of pods. Using Network Policies allows network controls to be applied with the context of the workload.
For improved security, define network policy rules to control the flow of traffic. For example, only permit backend components to receive traffic from frontend components.
To use Network Policy it must be enabled at cluster deployment time. AKS supports two implementations of network policies, Azure Network Policies and Calico Network Policies. Azure Network Policies are supported by Azure support and engineering teams.
","tags":["Azure.AKS.NetworkPolicy","AZR-000027"]},{"location":"en/rules/Azure.AKS.NetworkPolicy/#recommendation","title":"Recommendation","text":"Consider deploying AKS clusters with network policy enabled to extend network segmentation into clusters.
","tags":["Azure.AKS.NetworkPolicy","AZR-000027"]},{"location":"en/rules/Azure.AKS.NetworkPolicy/#examples","title":"Examples","text":"","tags":["Azure.AKS.NetworkPolicy","AZR-000027"]},{"location":"en/rules/Azure.AKS.NetworkPolicy/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
properties.networkProfile.networkPolicy
to azure
or calico
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-11-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 5,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\"\n },\n {\n \"name\": \"user\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 20,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"User\",\n \"osDiskType\": \"Ephemeral\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\"\n },\n \"apiServerAccessProfile\": {\n \"authorizedIPRanges\": [\n \"0.0.0.0/32\"\n ]\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"oidcIssuerProfile\": {\n \"enabled\": true\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.NetworkPolicy","AZR-000027"]},{"location":"en/rules/Azure.AKS.NetworkPolicy/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
properties.networkProfile.networkPolicy
to azure
or calico
.For example:
Azure Bicep snippetresource clusterWithPools 'Microsoft.ContainerService/managedClusters@2023-11-01' = {\n location: location\n name: name\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: [\n {\n name: 'system'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 5\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'System'\n osDiskType: 'Ephemeral'\n }\n {\n name: 'user'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 20\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'User'\n osDiskType: 'Ephemeral'\n }\n ]\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n }\n apiServerAccessProfile: {\n authorizedIPRanges: [\n '0.0.0.0/32'\n ]\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n oidcIssuerProfile: {\n enabled: true\n }\n addonProfiles: {\n azurepolicy: {\n enabled: true\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.NetworkPolicy","AZR-000027"]},{"location":"en/rules/Azure.AKS.NetworkPolicy/#notes","title":"Notes","text":"Network Policy can only be set during initial cluster creation. Existing AKS clusters must be redeployed to enable Network Policy.
","tags":["Azure.AKS.NetworkPolicy","AZR-000027"]},{"location":"en/rules/Azure.AKS.NetworkPolicy/#links","title":"Links","text":"Performance Efficiency \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods.
","tags":["Azure.AKS.NodeMinPods","AZR-000018"]},{"location":"en/rules/Azure.AKS.NodeMinPods/#description","title":"Description","text":"Node pools within a Azure Kubernetes Cluster (AKS) support between 30 and 250 pods per node. The maximum number of pods for nodes within a node pool is set at creation time.
When deploying AKS clusters with kubernet networking the default maximum number of pods is 110. For Azure CNI AKS clusters, the default maximum number of pods is 30.
In many environments, deploying DaemonSets for monitoring and management tools can exhaust the CNI default.
When you are using Azure CNI, ensure that there is enough IP address space in the node pool subnet. Each pod and host requires at least one IP address. Additionally, other resources such as load balancers will consuming additional IP addresses based on configuration. The node pools subnet should have enough IP address space to accommodate the maxCount
nodes and nodes added during upgrades.
Consider deploying node pools with a minimum number of pods per node.
","tags":["Azure.AKS.NodeMinPods","AZR-000018"]},{"location":"en/rules/Azure.AKS.NodeMinPods/#examples","title":"Examples","text":"","tags":["Azure.AKS.NodeMinPods","AZR-000018"]},{"location":"en/rules/Azure.AKS.NodeMinPods/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy clusters that pass this rule:
properties.agentPoolProfiles[].maxPods
property to at least 50
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-11-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 5,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\"\n },\n {\n \"name\": \"user\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 20,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"User\",\n \"osDiskType\": \"Ephemeral\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\"\n },\n \"apiServerAccessProfile\": {\n \"authorizedIPRanges\": [\n \"0.0.0.0/32\"\n ]\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"oidcIssuerProfile\": {\n \"enabled\": true\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.NodeMinPods","AZR-000018"]},{"location":"en/rules/Azure.AKS.NodeMinPods/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy clusters that pass this rule:
properties.agentPoolProfiles[].maxPods
property to at least 50
.For example:
Azure Bicep snippetresource clusterWithPools 'Microsoft.ContainerService/managedClusters@2023-11-01' = {\n location: location\n name: name\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: [\n {\n name: 'system'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 5\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'System'\n osDiskType: 'Ephemeral'\n }\n {\n name: 'user'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 20\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'User'\n osDiskType: 'Ephemeral'\n }\n ]\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n }\n apiServerAccessProfile: {\n authorizedIPRanges: [\n '0.0.0.0/32'\n ]\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n oidcIssuerProfile: {\n enabled: true\n }\n addonProfiles: {\n azurepolicy: {\n enabled: true\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.NodeMinPods","AZR-000018"]},{"location":"en/rules/Azure.AKS.NodeMinPods/#notes","title":"Notes","text":"","tags":["Azure.AKS.NodeMinPods","AZR-000018"]},{"location":"en/rules/Azure.AKS.NodeMinPods/#rule-configuration","title":"Rule configuration","text":"Azure_AKSNodeMinimumMaxPods
By default, this rule fails when node pools have maxPods
set to less than 50. To configure this rule override the Azure_AKSNodeMinimumMaxPods
configuration value with the minimum maxPods.
Operational Excellence \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_09 \u00b7 Important
AKS clusters should collect platform diagnostic logs to monitor the state of workloads.
","tags":["Azure.AKS.PlatformLogs","AZR-000023"]},{"location":"en/rules/Azure.AKS.PlatformLogs/#description","title":"Description","text":"To capture platform logs from AKS clusters, the following diagnostic log/metric categories should be enabled:
cluster-autoscaler
kube-apiserver
kube-controller-manager
kube-scheduler
AllMetrics
Consider configuring diagnostic settings to capture platform logs from AKS clusters.
","tags":["Azure.AKS.PlatformLogs","AZR-000023"]},{"location":"en/rules/Azure.AKS.PlatformLogs/#notes","title":"Notes","text":"Configure AZURE_AKS_ENABLED_PLATFORM_LOG_CATEGORIES_LIST
to enable selective log categories. By default all log categories are selected, as shown below.
# YAML: The default AZURE_AKS_ENABLED_PLATFORM_LOG_CATEGORIES_LIST configuration option\nconfiguration:\n AZURE_AKS_ENABLED_PLATFORM_LOG_CATEGORIES_LIST: ['cluster-autoscaler', 'kube-apiserver', 'kube-controller-manager', 'kube-scheduler', 'AllMetrics']\n
","tags":["Azure.AKS.PlatformLogs","AZR-000023"]},{"location":"en/rules/Azure.AKS.PlatformLogs/#examples","title":"Examples","text":"","tags":["Azure.AKS.PlatformLogs","AZR-000023"]},{"location":"en/rules/Azure.AKS.PlatformLogs/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
cluster-autoscaler
, kube-apiserver
, kube-controller-manager
, kube-scheduler
and AllMetrics
categories.For example:
Azure Template snippet{\n \"comments\": \"Azure Kubernetes Cluster\",\n \"apiVersion\": \"2020-12-01\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ],\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"location\": \"[parameters('location')]\",\n \"name\": \"[parameters('clusterName')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 32,\n \"count\": 3,\n \"minCount\": 3,\n \"maxCount\": 10,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D2s_v3\",\n \"osType\": \"Linux\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[variables('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\",\n \"scaleSetPriority\": \"Regular\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"Standard\",\n \"serviceCidr\": \"192.168.0.0/16\",\n \"dnsServiceIP\": \"192.168.0.4\",\n \"dockerBridgeCidr\": \"172.17.0.1/16\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true,\n \"config\": {\n \"version\": \"v2\"\n }\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"kubeDashboard\": {\n \"enabled\": false\n }\n }\n },\n \"resources\": [\n {\n \"apiVersion\": \"2016-09-01\",\n \"type\": \"Microsoft.ContainerService/managedClusters/providers/diagnosticSettings\",\n \"name\": \"[concat(parameters('clusterName'), '/Microsoft.Insights/service')]\",\n \"properties\": {\n \"workspaceId\": \"[parameters('workspaceId')]\",\n \"logs\": [\n {\n \"category\": \"kube-apiserver\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n },\n {\n \"category\": \"kube-controller-manager\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n },\n {\n \"category\": \"kube-scheduler\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n },\n {\n \"category\": \"cluster-autoscaler\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n }\n ],\n \"metrics\": [\n {\n \"category\": \"AllMetrics\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n }\n ]\n }\n }\n ]\n}\n
","tags":["Azure.AKS.PlatformLogs","AZR-000023"]},{"location":"en/rules/Azure.AKS.PlatformLogs/#links","title":"Links","text":"Performance Efficiency \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Deploy AKS clusters with nodes pools based on VM scale sets.
","tags":["Azure.AKS.PoolScaleSet","AZR-000017"]},{"location":"en/rules/Azure.AKS.PoolScaleSet/#description","title":"Description","text":"When deploying AKS clusters, Azure node pool VMs can be deployed using Availability Sets or VM Scale Sets. New AKS clusters default to VM scale set node pools.
Deploying AKS clusters with scale set node pools is required for some cluster features such as multiple node pools and cluster autoscaler.
","tags":["Azure.AKS.PoolScaleSet","AZR-000017"]},{"location":"en/rules/Azure.AKS.PoolScaleSet/#recommendation","title":"Recommendation","text":"Multiple node pools and the cluster autoscaler can be used to improve the scalability and performance of a cluster while minimizing cost.
Using VM scale sets is a deployment time configuration. Consider redeploying the AKS cluster with VM Scale Sets instead of Availability Sets.
","tags":["Azure.AKS.PoolScaleSet","AZR-000017"]},{"location":"en/rules/Azure.AKS.PoolScaleSet/#examples","title":"Examples","text":"","tags":["Azure.AKS.PoolScaleSet","AZR-000017"]},{"location":"en/rules/Azure.AKS.PoolScaleSet/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy clusters that pass this rule:
properties.agentPoolProfiles[].type
property to VirtualMachineScaleSets
for each node pool.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"system\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 5,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"System\",\n \"osDiskType\": \"Ephemeral\"\n },\n {\n \"name\": \"user\",\n \"osDiskSizeGB\": 0,\n \"minCount\": 3,\n \"maxCount\": 20,\n \"enableAutoScaling\": true,\n \"maxPods\": 50,\n \"vmSize\": \"Standard_D4s_v5\",\n \"type\": \"VirtualMachineScaleSets\",\n \"vnetSubnetID\": \"[parameters('clusterSubnetId')]\",\n \"mode\": \"User\",\n \"osDiskType\": \"Ephemeral\"\n }\n ],\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"oidcIssuerProfile\": {\n \"enabled\": true\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"identity\"\n ]\n}\n
","tags":["Azure.AKS.PoolScaleSet","AZR-000017"]},{"location":"en/rules/Azure.AKS.PoolScaleSet/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy clusters that pass this rule:
properties.agentPoolProfiles[].type
property to VirtualMachineScaleSets
for each node pool.For example:
Azure Bicep snippetresource clusterWithPools 'Microsoft.ContainerService/managedClusters@2023-04-01' = {\n location: location\n name: name\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: [\n {\n name: 'system'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 5\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'System'\n osDiskType: 'Ephemeral'\n }\n {\n name: 'user'\n osDiskSizeGB: 0\n minCount: 3\n maxCount: 20\n enableAutoScaling: true\n maxPods: 50\n vmSize: 'Standard_D4s_v5'\n type: 'VirtualMachineScaleSets'\n vnetSubnetID: clusterSubnetId\n mode: 'User'\n osDiskType: 'Ephemeral'\n }\n ]\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n oidcIssuerProfile: {\n enabled: true\n }\n addonProfiles: {\n azurepolicy: {\n enabled: true\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.PoolScaleSet","AZR-000017"]},{"location":"en/rules/Azure.AKS.PoolScaleSet/#links","title":"Links","text":"Reliability \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
AKS node pools should match Kubernetes control plane version.
","tags":["Azure.AKS.PoolVersion","AZR-000016"]},{"location":"en/rules/Azure.AKS.PoolVersion/#description","title":"Description","text":"AKS supports multiple node pools. In a multi-node pool configuration, it is possible that the control plane and node pools could be running a different version of Kubernetes.
Different versions of Kubernetes between the control plane and node pools is intended as a short term option to allow rolling upgrades. For general operation, the control plane and node pool Kubernetes versions should match.
","tags":["Azure.AKS.PoolVersion","AZR-000016"]},{"location":"en/rules/Azure.AKS.PoolVersion/#recommendation","title":"Recommendation","text":"Consider upgrading node pools to match AKS control plan version.
","tags":["Azure.AKS.PoolVersion","AZR-000016"]},{"location":"en/rules/Azure.AKS.PoolVersion/#links","title":"Links","text":"Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault.
","tags":["Azure.AKS.SecretStore","AZR-000033"]},{"location":"en/rules/Azure.AKS.SecretStore/#description","title":"Description","text":"AKS clusters may need to store and retrieve secrets, keys, and certificates. The Secrets Store CSI Driver provides cluster support to integrate with Key Vault. When enabled and configured secrets, keys, and certificates can be securely accessed from a pod.
The Secrets Store CSI Driver can automatically refresh secrets and keys periodically from Key Vault. To enable this feature, enable Secrets Store CSI Driver autorotation.
Avoid storing secrets to access Azure resources. Use a Managed Identity when possible instead of cryptographic keys or a regular service principal.
","tags":["Azure.AKS.SecretStore","AZR-000033"]},{"location":"en/rules/Azure.AKS.SecretStore/#recommendation","title":"Recommendation","text":"Consider deploying AKS clusters with the Secrets Store CSI Driver and store Secrets in Key Vault.
","tags":["Azure.AKS.SecretStore","AZR-000033"]},{"location":"en/rules/Azure.AKS.SecretStore/#examples","title":"Examples","text":"","tags":["Azure.AKS.SecretStore","AZR-000033"]},{"location":"en/rules/Azure.AKS.SecretStore/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
Properties.addonProfiles.azureKeyvaultSecretsProvider.enabled
to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2021-07-01\",\n \"name\": \"[parameters('clusterName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": \"[variables('allPools')]\",\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\",\n \"dockerBridgeCidr\": \"[variables('dockerBridgeCidr')]\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"addonProfiles\": {\n \"httpApplicationRouting\": {\n \"enabled\": false\n },\n \"azurepolicy\": {\n \"enabled\": true,\n \"config\": {\n \"version\": \"v2\"\n }\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"kubeDashboard\": {\n \"enabled\": false\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"tags\": \"[parameters('tags')]\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.SecretStore","AZR-000033"]},{"location":"en/rules/Azure.AKS.SecretStore/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
Properties.addonProfiles.azureKeyvaultSecretsProvider.enabled
to true
.For example:
Azure Bicep snippetresource cluster 'Microsoft.ContainerService/managedClusters@2021-07-01' = {\n location: location\n name: clusterName\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: allPools\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n dockerBridgeCidr: dockerBridgeCidr\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n addonProfiles: {\n httpApplicationRouting: {\n enabled: false\n }\n azurepolicy: {\n enabled: true\n config: {\n version: 'v2'\n }\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n kubeDashboard: {\n enabled: false\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n tags: tags\n}\n
","tags":["Azure.AKS.SecretStore","AZR-000033"]},{"location":"en/rules/Azure.AKS.SecretStore/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz aks enable-addons --addons azure-keyvault-secrets-provider -n '<name>' -g '<resource_group>'\n
","tags":["Azure.AKS.SecretStore","AZR-000033"]},{"location":"en/rules/Azure.AKS.SecretStore/#links","title":"Links","text":"Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters.
","tags":["Azure.AKS.SecretStoreRotation","AZR-000034"]},{"location":"en/rules/Azure.AKS.SecretStoreRotation/#description","title":"Description","text":"AKS clusters may need to store and retrieve secrets, keys, and certificates. The Secrets Store CSI Driver provides cluster support to integrate with Key Vault. When enabled and configured secrets, keys, and certificates can be securely accessed from a pod.
When secrets are updated in Key Vault, pods may need to be restarted to pick up the new secrets. Enabling autorotation with the Secrets Store CSI Driver, automatically refreshed pods with new secrets. It does this by periodically polling for updates to the secrets in Key Vault. The default interval is every 2 minutes.
The Secrets Store CSI Driver does not automatically change secrets in Key Vault. Updating the secrets in Key Vault must be done by an external process, such as an Azure Function.
","tags":["Azure.AKS.SecretStoreRotation","AZR-000034"]},{"location":"en/rules/Azure.AKS.SecretStoreRotation/#recommendation","title":"Recommendation","text":"Consider enabling autorotation of Secrets Store CSI Driver secrets for AKS clusters.
","tags":["Azure.AKS.SecretStoreRotation","AZR-000034"]},{"location":"en/rules/Azure.AKS.SecretStoreRotation/#examples","title":"Examples","text":"","tags":["Azure.AKS.SecretStoreRotation","AZR-000034"]},{"location":"en/rules/Azure.AKS.SecretStoreRotation/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
Properties.addonProfiles.azureKeyvaultSecretsProvider.config.enableSecretRotation
to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2021-07-01\",\n \"name\": \"[parameters('clusterName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": \"[variables('allPools')]\",\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\",\n \"dockerBridgeCidr\": \"[variables('dockerBridgeCidr')]\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"addonProfiles\": {\n \"httpApplicationRouting\": {\n \"enabled\": false\n },\n \"azurepolicy\": {\n \"enabled\": true,\n \"config\": {\n \"version\": \"v2\"\n }\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"kubeDashboard\": {\n \"enabled\": false\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"tags\": \"[parameters('tags')]\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.SecretStoreRotation","AZR-000034"]},{"location":"en/rules/Azure.AKS.SecretStoreRotation/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
Properties.addonProfiles.azureKeyvaultSecretsProvider.config.enableSecretRotation
to true
.For example:
Azure Bicep snippetresource cluster 'Microsoft.ContainerService/managedClusters@2021-07-01' = {\n location: location\n name: clusterName\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: allPools\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n dockerBridgeCidr: dockerBridgeCidr\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n addonProfiles: {\n httpApplicationRouting: {\n enabled: false\n }\n azurepolicy: {\n enabled: true\n config: {\n version: 'v2'\n }\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n kubeDashboard: {\n enabled: false\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n tags: tags\n}\n
","tags":["Azure.AKS.SecretStoreRotation","AZR-000034"]},{"location":"en/rules/Azure.AKS.SecretStoreRotation/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz aks update --enable-secret-rotation -n '<name>' -g '<resource_group>'\n
","tags":["Azure.AKS.SecretStoreRotation","AZR-000034"]},{"location":"en/rules/Azure.AKS.SecretStoreRotation/#links","title":"Links","text":"Performance Efficiency \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU.
","tags":["Azure.AKS.StandardLB","AZR-000026"]},{"location":"en/rules/Azure.AKS.StandardLB/#description","title":"Description","text":"When deploying an AKS cluster, either a Standard or Basic load balancer SKU can be configured. A Standard load balancer SKU is required for several AKS features including:
These features improve the scalability and reliability of the cluster.
AKS clusters can not be updated to use a Standard load balancer SKU after deployment. For switch to an Standard load balancer SKU, the cluster must be redeployed.
","tags":["Azure.AKS.StandardLB","AZR-000026"]},{"location":"en/rules/Azure.AKS.StandardLB/#recommendation","title":"Recommendation","text":"Consider using Standard load balancer SKU during AKS cluster creation. Additionally, consider redeploying the AKS clusters with a Standard load balancer SKU configured.
","tags":["Azure.AKS.StandardLB","AZR-000026"]},{"location":"en/rules/Azure.AKS.StandardLB/#examples","title":"Examples","text":"","tags":["Azure.AKS.StandardLB","AZR-000026"]},{"location":"en/rules/Azure.AKS.StandardLB/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy clusters that pass this rule:
properties.networkProfile.loadBalancerSku
property to standard
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"[parameters('kubernetesVersion')]\",\n \"disableLocalAccounts\": true,\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": \"[variables('allPools')]\",\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"oidcIssuerProfile\": {\n \"enabled\": true\n },\n \"addonProfiles\": {\n \"azurepolicy\": {\n \"enabled\": true\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"identity\"\n ]\n}\n
","tags":["Azure.AKS.StandardLB","AZR-000026"]},{"location":"en/rules/Azure.AKS.StandardLB/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy clusters that pass this rule:
properties.networkProfile.loadBalancerSku
property to standard
.For example:
Azure Bicep snippetresource cluster 'Microsoft.ContainerService/managedClusters@2023-04-01' = {\n location: location\n name: name\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: kubernetesVersion\n disableLocalAccounts: true\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: allPools\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n oidcIssuerProfile: {\n enabled: true\n }\n addonProfiles: {\n azurepolicy: {\n enabled: true\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n }\n}\n
","tags":["Azure.AKS.StandardLB","AZR-000026"]},{"location":"en/rules/Azure.AKS.StandardLB/#links","title":"Links","text":"AKS clusters should have Uptime SLA enabled for a financially backed SLA.
"},{"location":"en/rules/Azure.AKS.UptimeSLA/#description","title":"Description","text":"Azure Kubernetes Service (AKS) offers two pricing tiers for cluster management.
The Standard
tier is suitable for financially backed SLA scenarios as it enables Uptime SLA by default on the cluster.
Benefits:
Consider enabling Uptime SLA for a financially backed SLA.
"},{"location":"en/rules/Azure.AKS.UptimeSLA/#examples","title":"Examples","text":""},{"location":"en/rules/Azure.AKS.UptimeSLA/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy an AKS cluster that pass this rule:
sku.tier
to Standard
.For example:
{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-02-01\",\n \"name\": \"[parameters('clusterName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Basic\",\n \"tier\": \"Standard\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": [\n {\n \"name\": \"agentpool\",\n \"osDiskSizeGB\": \"[parameters('osDiskSizeGB')]\",\n \"count\": \"[parameters('agentCount')]\",\n \"vmSize\": \"[parameters('agentVMSize')]\",\n \"osType\": \"Linux\",\n \"mode\": \"System\"\n }\n ],\n \"linuxProfile\": {\n \"adminUsername\": \"[parameters('linuxAdminUsername')]\",\n \"ssh\": {\n \"publicKeys\": [\n {\n \"keyData\": \"[parameters('sshRSAPublicKey')]\"\n }\n ]\n }\n }\n }\n}\n
"},{"location":"en/rules/Azure.AKS.UptimeSLA/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy an AKS cluster that pass this rule:
sku.tier
to Standard
.For example:
resource aks 'Microsoft.ContainerService/managedClusters@2023-02-01' = {\n name: clusterName\n location: location\n sku: {\n name: 'Basic'\n tier: 'Standard'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n dnsPrefix: dnsPrefix\n agentPoolProfiles: [\n {\n name: 'agentpool'\n osDiskSizeGB: osDiskSizeGB\n count: agentCount\n vmSize: agentVMSize\n osType: 'Linux'\n mode: 'System'\n }\n ]\n linuxProfile: {\n adminUsername: linuxAdminUsername\n ssh: {\n publicKeys: [\n {\n keyData: sshRSAPublicKey\n }\n ]\n }\n }\n }\n}\n
"},{"location":"en/rules/Azure.AKS.UptimeSLA/#notes","title":"Notes","text":"Basic
and Paid
are removed in the 2023-02-01
and 2023-02-02 Preview
API version, and this will be a breaking change in API versions 2023-02-01
and 2023-02-02 Preview
or newer.
Security \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Deploy AKS cluster with role-based access control (RBAC) enabled.
","tags":["Azure.AKS.UseRBAC","AZR-000038"]},{"location":"en/rules/Azure.AKS.UseRBAC/#description","title":"Description","text":"AKS supports granting access to cluster resources using role-based access control (RBAC). Additionally Azure Active Directory (AAD) integration with AKS allows, RBAC to be granted based on AAD user or group.
","tags":["Azure.AKS.UseRBAC","AZR-000038"]},{"location":"en/rules/Azure.AKS.UseRBAC/#recommendation","title":"Recommendation","text":"Azure AD integration with AKS provides granular access control for Kubernetes resources using RBAC.
RBAC is a deployment time configuration. Consider redeploying the AKS cluster with RBAC enabled.
","tags":["Azure.AKS.UseRBAC","AZR-000038"]},{"location":"en/rules/Azure.AKS.UseRBAC/#links","title":"Links","text":"Reliability \u00b7 Azure Kubernetes Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
AKS control plane and nodes pools should use a current stable release.
","tags":["Azure.AKS.Version","AZR-000015"]},{"location":"en/rules/Azure.AKS.Version/#description","title":"Description","text":"The AKS Kubernetes support policy provides support for the latest generally available (GA) three minor versions (N-2). This version support policy is based on the Kubernetes community support policy, who maintain the Kubernetes project. As the Kubernetes releases new minor versions, the old minor versions are deprecated and eventually removed from support.
When your cluster or cluster nodes are running a version that is no longer supported, you may:
Additionally, AKS provides Platform Support for subset of components following an N-3.
AKS supports a feature called cluster auto-upgrade, which can be used to reduce operational overhead of upgrading your cluster. This feature allows you to configure your cluster to automatically upgrade to the latest supported minor version of Kubernetes. When you enable cluster auto-upgrade, the control plane and node pools are upgraded to the latest supported minor version. Two channels are available for cluster auto-upgrade that maintain Kubernetes minor versions stable
and rapid
. For details on the differences between the two channels, see the references below.
You are able to define a planned maintenance window to schedule and control upgrades to your cluster. Use the Planned Maintenance window to schedule upgrades to your cluster during times of low business impact. Alternatively, consider using blue / green clusters.
","tags":["Azure.AKS.Version","AZR-000015"]},{"location":"en/rules/Azure.AKS.Version/#recommendation","title":"Recommendation","text":"Consider upgrading AKS control plane and nodes pools to the latest stable version of Kubernetes. Also consider enabling cluster auto-upgrade within a maintenance window to minimize operational overhead of cluster upgrades.
","tags":["Azure.AKS.Version","AZR-000015"]},{"location":"en/rules/Azure.AKS.Version/#examples","title":"Examples","text":"","tags":["Azure.AKS.Version","AZR-000015"]},{"location":"en/rules/Azure.AKS.Version/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AKS clusters that pass this rule:
properties.autoUpgradeProfile.upgradeChannel
to rapid
or stable
. ORproperties.kubernetesVersion
to a newer stable version.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerService/managedClusters\",\n \"apiVersion\": \"2023-07-01\",\n \"name\": \"[parameters('clusterName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName')))]\": {}\n }\n },\n \"properties\": {\n \"kubernetesVersion\": \"1.27.9\",\n \"enableRBAC\": true,\n \"dnsPrefix\": \"[parameters('dnsPrefix')]\",\n \"agentPoolProfiles\": \"[variables('allPools')]\",\n \"aadProfile\": {\n \"managed\": true,\n \"enableAzureRBAC\": true,\n \"adminGroupObjectIDs\": \"[parameters('clusterAdmins')]\",\n \"tenantID\": \"[subscription().tenantId]\"\n },\n \"networkProfile\": {\n \"networkPlugin\": \"azure\",\n \"networkPolicy\": \"azure\",\n \"loadBalancerSku\": \"standard\",\n \"serviceCidr\": \"[variables('serviceCidr')]\",\n \"dnsServiceIP\": \"[variables('dnsServiceIP')]\",\n \"dockerBridgeCidr\": \"[variables('dockerBridgeCidr')]\"\n },\n \"autoUpgradeProfile\": {\n \"upgradeChannel\": \"stable\"\n },\n \"addonProfiles\": {\n \"httpApplicationRouting\": {\n \"enabled\": false\n },\n \"azurepolicy\": {\n \"enabled\": true,\n \"config\": {\n \"version\": \"v2\"\n }\n },\n \"omsagent\": {\n \"enabled\": true,\n \"config\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('workspaceId')]\"\n }\n },\n \"kubeDashboard\": {\n \"enabled\": false\n },\n \"azureKeyvaultSecretsProvider\": {\n \"enabled\": true,\n \"config\": {\n \"enableSecretRotation\": \"true\"\n }\n }\n },\n \"podIdentityProfile\": {\n \"enabled\": true\n }\n },\n \"tags\": \"[parameters('tags')]\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', parameters('identityName'))]\"\n ]\n}\n
","tags":["Azure.AKS.Version","AZR-000015"]},{"location":"en/rules/Azure.AKS.Version/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AKS clusters that pass this rule:
properties.autoUpgradeProfile.upgradeChannel
to rapid
or stable
. ORproperties.kubernetesVersion
to a newer stable version.For example:
Azure Bicep snippetresource cluster 'Microsoft.ContainerService/managedClusters@2023-07-01' = {\n location: location\n name: clusterName\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n kubernetesVersion: '1.27.9'\n enableRBAC: true\n dnsPrefix: dnsPrefix\n agentPoolProfiles: allPools\n aadProfile: {\n managed: true\n enableAzureRBAC: true\n adminGroupObjectIDs: clusterAdmins\n tenantID: subscription().tenantId\n }\n networkProfile: {\n networkPlugin: 'azure'\n networkPolicy: 'azure'\n loadBalancerSku: 'standard'\n serviceCidr: serviceCidr\n dnsServiceIP: dnsServiceIP\n dockerBridgeCidr: dockerBridgeCidr\n }\n autoUpgradeProfile: {\n upgradeChannel: 'stable'\n }\n addonProfiles: {\n httpApplicationRouting: {\n enabled: false\n }\n azurepolicy: {\n enabled: true\n config: {\n version: 'v2'\n }\n }\n omsagent: {\n enabled: true\n config: {\n logAnalyticsWorkspaceResourceID: workspaceId\n }\n }\n kubeDashboard: {\n enabled: false\n }\n azureKeyvaultSecretsProvider: {\n enabled: true\n config: {\n enableSecretRotation: 'true'\n }\n }\n }\n podIdentityProfile: {\n enabled: true\n }\n }\n tags: tags\n}\n
","tags":["Azure.AKS.Version","AZR-000015"]},{"location":"en/rules/Azure.AKS.Version/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz aks update -n '<name>' -g '<resource_group>' --auto-upgrade-channel 'stable'\n
Azure CLI snippetaz aks upgrade -n '<name>' -g '<resource_group>' --kubernetes-version '1.27.9'\n
","tags":["Azure.AKS.Version","AZR-000015"]},{"location":"en/rules/Azure.AKS.Version/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetSet-AzAksCluster -Name '<name>' -ResourceGroupName '<resource_group>' -KubernetesVersion '1.27.9'\n
","tags":["Azure.AKS.Version","AZR-000015"]},{"location":"en/rules/Azure.AKS.Version/#notes","title":"Notes","text":"A list of available Kubernetes versions can be found using the az aks get-versions -o table --location <location>
CLI command.
If you must maintain AKS clusters for longer then the community support period, consider switching to Long Term Support (LTS). AKS LTS provides support for a specific Kubernetes version for a longer period of time. The first LTS release is 1.27.
","tags":["Azure.AKS.Version","AZR-000015"]},{"location":"en/rules/Azure.AKS.Version/#rule-configuration","title":"Rule configuration","text":"AZURE_AKS_CLUSTER_MINIMUM_VERSION
To configure this rule override the AZURE_AKS_CLUSTER_MINIMUM_VERSION
configuration value with the minimum Kubernetes version.
Operational Excellence \u00b7 API Management \u00b7 Rule \u00b7 2020_09 \u00b7 Awareness
API Management APIs should have a display name and description.
","tags":["Azure.APIM.APIDescriptors","AZR-000043"]},{"location":"en/rules/Azure.APIM.APIDescriptors/#description","title":"Description","text":"Each API created in API Management can have a display name and description set. Using easy to understand descriptions and metadata greatly assist identification for management and usage.
During monitoring from service provider and consumer perspectives:
This information is visible within the developer portal and exported OpenAPI definitions.
","tags":["Azure.APIM.APIDescriptors","AZR-000043"]},{"location":"en/rules/Azure.APIM.APIDescriptors/#recommendation","title":"Recommendation","text":"Consider using display name and description fields on APIs to convey intended purpose and usage. Display name and description fields should be human readable and easy to understand.
","tags":["Azure.APIM.APIDescriptors","AZR-000043"]},{"location":"en/rules/Azure.APIM.APIDescriptors/#examples","title":"Examples","text":"","tags":["Azure.APIM.APIDescriptors","AZR-000043"]},{"location":"en/rules/Azure.APIM.APIDescriptors/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management APIs that pass this rule:
properties.displayName
with a human readable name.properties.description
with an description of the APIs purpose.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service/apis\",\n \"apiVersion\": \"2021-08-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'echo-v1')]\",\n \"properties\": {\n \"displayName\": \"Echo API\",\n \"description\": \"An echo API service.\",\n \"type\": \"http\",\n \"path\": \"echo\",\n \"serviceUrl\": \"https://echo.contoso.com\",\n \"protocols\": [\n \"https\"\n ],\n \"apiVersion\": \"v1\",\n \"apiVersionSetId\": \"[resourceId('Microsoft.ApiManagement/service/apiVersionSets', parameters('name'), 'echo')]\",\n \"subscriptionRequired\": true\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ApiManagement/service', parameters('name'))]\",\n \"[resourceId('Microsoft.ApiManagement/service/apiVersionSets', parameters('name'), 'echo')]\"\n ]\n}\n
","tags":["Azure.APIM.APIDescriptors","AZR-000043"]},{"location":"en/rules/Azure.APIM.APIDescriptors/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management APIs that pass this rule:
properties.displayName
with a human readable name.properties.description
with an description of the APIs purpose.For example:
Azure Bicep snippetresource api 'Microsoft.ApiManagement/service/apis@2021-08-01' = {\n parent: service\n name: 'echo-v1'\n properties: {\n displayName: 'Echo API'\n description: 'An echo API service.'\n type: 'http'\n path: 'echo'\n serviceUrl: 'https://echo.contoso.com'\n protocols: [\n 'https'\n ]\n apiVersion: 'v1'\n apiVersionSetId: version.id\n subscriptionRequired: true\n }\n}\n
","tags":["Azure.APIM.APIDescriptors","AZR-000043"]},{"location":"en/rules/Azure.APIM.APIDescriptors/#links","title":"Links","text":"Reliability \u00b7 API Management \u00b7 Rule \u00b7 2021_12 \u00b7 Important
API management services deployed with Premium SKU should use availability zones in supported regions for high availability.
","tags":["Azure.APIM.AvailabilityZone","AZR-000052"]},{"location":"en/rules/Azure.APIM.AvailabilityZone/#description","title":"Description","text":"API management services using availability zones improve reliability and ensure availability during failure scenarios affecting a data center within a region. With zone redundancy, the gateway and the control plane of your API Management instance (Management API, developer portal, Git configuration) are replicated across data centers in physically separated zones, making it resilient to a zone failure.
","tags":["Azure.APIM.AvailabilityZone","AZR-000052"]},{"location":"en/rules/Azure.APIM.AvailabilityZone/#recommendation","title":"Recommendation","text":"Consider using availability zones for API management services deployed with Premium SKU.
","tags":["Azure.APIM.AvailabilityZone","AZR-000052"]},{"location":"en/rules/Azure.APIM.AvailabilityZone/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed to Azure using pre-flight and in-flight data.
This rule fails when \"zones\"
is null
, []
or less than two zones when API management service is deployed with Premium SKU and there are supported availability zones for the given region.
Configure AZURE_APIM_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
to set additional availability zones that need to be supported which are not in the existing providers for namespace Microsoft.ApiManagement
and resource type services
.
# YAML: The default AZURE_APIM_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST configuration option\nconfiguration:\n AZURE_APIM_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST: []\n
","tags":["Azure.APIM.AvailabilityZone","AZR-000052"]},{"location":"en/rules/Azure.APIM.AvailabilityZone/#examples","title":"Examples","text":"","tags":["Azure.APIM.AvailabilityZone","AZR-000052"]},{"location":"en/rules/Azure.APIM.AvailabilityZone/#configure-with-azure-template","title":"Configure with Azure template","text":"To set availability zones for a API management service
zones
to a minimum of two zones from [\"1\", \"2\", \"3\"]
, ensuring the number of zones match sku.capacity
.properties.additionalLocations[*].zones
to a minimum of two zones from [\"1\", \"2\", \"3\"]
, ensuring the number of zones match properties.additionalLocations[*].sku.capacity
. sku.name
and/or properties.additionalLocations[*].sku.name
to Premium
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service\",\n \"apiVersion\": \"2021-01-01-preview\",\n \"name\": \"[parameters('service_api_mgmt_test2_name')]\",\n \"location\": \"Australia East\",\n \"sku\": {\n \"name\": \"Premium\",\n \"capacity\": 3\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ],\n \"properties\": {\n \"publisherEmail\": \"john.doe@contoso.com\",\n \"publisherName\": \"contoso\",\n \"notificationSenderEmail\": \"apimgmt-noreply@mail.windowsazure.com\",\n \"hostnameConfigurations\": [\n {\n \"type\": \"Proxy\",\n \"hostName\": \"[concat(parameters('service_api_mgmt_test2_name'), '.azure-api.net')]\",\n \"negotiateClientCertificate\": false,\n \"defaultSslBinding\": true,\n \"certificateSource\": \"BuiltIn\"\n }\n ],\n \"additionalLocations\": [\n {\n \"location\": \"East US\",\n \"sku\": {\n \"name\": \"Premium\",\n \"capacity\": 3\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ],\n \"disableGateway\": false\n }\n ],\n \"customProperties\": {\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168\": \"false\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11\": \"false\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10\": \"false\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30\": \"false\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11\": \"false\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10\": \"false\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30\": \"false\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2\": \"false\"\n },\n \"virtualNetworkType\": \"None\",\n \"disableGateway\": false,\n \"apiVersionConstraint\": {}\n }\n}\n
","tags":["Azure.APIM.AvailabilityZone","AZR-000052"]},{"location":"en/rules/Azure.APIM.AvailabilityZone/#configure-with-bicep","title":"Configure with Bicep","text":"To set availability zones for a API management service
zones
to a minimum of two zones from [\"1\", \"2\", \"3\"]
, ensuring the number of zones match sku.capacity
.properties.additionalLocations[*].zones
to a minimum of two zones from [\"1\", \"2\", \"3\"]
, ensuring the number of zones match properties.additionalLocations[*].sku.capacity
. sku.name
and/or properties.additionalLocations[*].sku.name
to Premium
.For example:
Azure Bicep snippetresource service_api_mgmt_test2_name_resource 'Microsoft.ApiManagement/service@2021-01-01-preview' = {\n name: service_api_mgmt_test2_name\n location: 'Australia East'\n sku: {\n name: 'Premium'\n capacity: 3\n }\n zones: [\n '1',\n '2',\n '3'\n ]\n properties: {\n publisherEmail: 'john.doe@contoso.com'\n publisherName: 'contoso'\n notificationSenderEmail: 'apimgmt-noreply@mail.windowsazure.com'\n hostnameConfigurations: [\n {\n type: 'Proxy'\n hostName: '${service_api_mgmt_test2_name}.azure-api.net'\n negotiateClientCertificate: false\n defaultSslBinding: true\n certificateSource: 'BuiltIn'\n }\n ]\n additionalLocations: [\n {\n location: 'East US'\n sku: {\n name: 'Premium'\n capacity: 1\n }\n zones: [\n '1'\n ]\n disableGateway: false\n }\n ]\n customProperties: {\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168': 'false'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11': 'false'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10': 'false'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30': 'false'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11': 'false'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10': 'false'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30': 'false'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2': 'false'\n }\n virtualNetworkType: 'None'\n disableGateway: false\n apiVersionConstraint: {}\n }\n}\n
","tags":["Azure.APIM.AvailabilityZone","AZR-000052"]},{"location":"en/rules/Azure.APIM.AvailabilityZone/#links","title":"Links","text":"Security \u00b7 API Management \u00b7 Rule \u00b7 2023_03 \u00b7 Important
Avoid using wildcard for any configuration option in CORS policies.
","tags":["Azure.APIM.CORSPolicy","AZR-000365"]},{"location":"en/rules/Azure.APIM.CORSPolicy/#description","title":"Description","text":"The API Management cors
policy adds cross-origin resource sharing (CORS) support to an operation or APIs.
CORS is not a security feature. CORS is a W3C standard that allows a server to relax the same-origin policy enforced by modern browsers. CORS uses HTTP headers that allows API Management (and other HTTP servers) to indicate any allowed origins.
Using wildcard (*
) in any policy is overly permissive and may reduce the effectiveness of browser same-origin policy enforcement.
Consider configuring the CORS policy by specifying explicit values for each property.
","tags":["Azure.APIM.CORSPolicy","AZR-000365"]},{"location":"en/rules/Azure.APIM.CORSPolicy/#examples","title":"Examples","text":"","tags":["Azure.APIM.CORSPolicy","AZR-000365"]},{"location":"en/rules/Azure.APIM.CORSPolicy/#configure-api-management-policy","title":"Configure API Management policy","text":"To deploy API Management CORS policies that pass this rule:
cors
policies provide the exact values for all propeties.cors
policy including:allowed-origins
allowed-methods
allowed-headers
expose-headers
For example a global scoped policy:
API Management policy<policies>\n <inbound>\n <cors allow-credentials=\"true\">\n <allowed-origins>\n <origin>https://contoso.developer.azure-api.net</origin>\n <origin>https://developer.contoso.com</origin>\n </allowed-origins>\n <allowed-methods preflight-result-max-age=\"300\">\n <method>GET</method>\n <method>PUT</method>\n <method>POST</method>\n <method>PATCH</method>\n <method>HEAD</method>\n <method>DELETE</method>\n <method>OPTIONS</method>\n </allowed-methods>\n <allowed-headers>\n <header>Content-Type</header>\n <header>Cache-Control</header>\n <header>Authorization</header>\n </allowed-headers>\n </cors>\n </inbound>\n <backend>\n <forward-request />\n </backend>\n <outbound />\n <on-error />\n</policies>\n
","tags":["Azure.APIM.CORSPolicy","AZR-000365"]},{"location":"en/rules/Azure.APIM.CORSPolicy/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management CORS policies that pass this rule:
*
for any CORS policy element in properties.value
property. Instead provide exact values.For example a global scoped policy:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service/policies\",\n \"apiVersion\": \"2022-08-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'policy')]\",\n \"properties\": {\n \"value\": \"<policies><inbound><cors allow-credentials=\\\"true\\\"><allowed-origins><origin>https://contoso.developer.azure-api.net</origin><origin>https://developer.contoso.com</origin></allowed-origins><allowed-methods preflight-result-max-age=\\\"300\\\"><method>GET</method><method>PUT</method><method>POST</method><method>PATCH</method><method>HEAD</method><method>DELETE</method><method>OPTIONS</method></allowed-methods><allowed-headers><header>Content-Type</header><header>Cache-Control</header><header>Authorization</header></allowed-headers></cors></inbound><backend><forward-request /></backend><outbound /><on-error /></policies>\",\n \"format\": \"xml\"\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ApiManagement/service', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.APIM.CORSPolicy","AZR-000365"]},{"location":"en/rules/Azure.APIM.CORSPolicy/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management CORS policies that pass this rule:
*
for any CORS policy element in properties.value
property. Instead provide exact values.For example a global scoped policy:
Azure Bicep snippetresource globalPolicy 'Microsoft.ApiManagement/service/policies@2022-08-01' = {\n parent: service\n name: 'policy'\n properties: {\n value: '<policies><inbound><cors allow-credentials=\"true\"><allowed-origins><origin>https://contoso.developer.azure-api.net</origin><origin>https://developer.contoso.com</origin></allowed-origins><allowed-methods preflight-result-max-age=\"300\"><method>GET</method><method>PUT</method><method>POST</method><method>PATCH</method><method>HEAD</method><method>DELETE</method><method>OPTIONS</method></allowed-methods><allowed-headers><header>Content-Type</header><header>Cache-Control</header><header>Authorization</header></allowed-headers></cors></inbound><backend><forward-request /></backend><outbound /><on-error /></policies>'\n format: 'xml'\n }\n}\n
","tags":["Azure.APIM.CORSPolicy","AZR-000365"]},{"location":"en/rules/Azure.APIM.CORSPolicy/#notes","title":"Notes","text":"The rule only checks against rawxml
and xml
policy formatted content.
When using Azure Bicep, the policy XML can be loaded from an external file by using the loadTextContent
function.
Operational Excellence \u00b7 API Management \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Renew certificates used for custom domain bindings.
","tags":["Azure.APIM.CertificateExpiry","AZR-000051"]},{"location":"en/rules/Azure.APIM.CertificateExpiry/#description","title":"Description","text":"When custom domains are configured within an API Management service. A certificate must be assigned to allow traffic to be transmitted using TLS.
Each certificate has an expiry date, after which the certificate is not valid. After expiry, client connections to the API Management service will reject the certificate.
","tags":["Azure.APIM.CertificateExpiry","AZR-000051"]},{"location":"en/rules/Azure.APIM.CertificateExpiry/#recommendation","title":"Recommendation","text":"Consider renewing certificates before expiry to prevent service issues.
","tags":["Azure.APIM.CertificateExpiry","AZR-000051"]},{"location":"en/rules/Azure.APIM.CertificateExpiry/#notes","title":"Notes","text":"By default, this rule fails when certificates have less than 30 days remaining before expiry.
To configure this rule:
Azure_MinimumCertificateLifetime
configuration value with the minimum number of days until expiry.Security \u00b7 API Management \u00b7 Rule \u00b7 2022_03 \u00b7 Critical
API Management should not accept weak or deprecated ciphers for client or backend communication.
","tags":["Azure.APIM.Ciphers","AZR-000055"]},{"location":"en/rules/Azure.APIM.Ciphers/#description","title":"Description","text":"API Management provides support for weak or deprecated ciphers. These older versions are provided for compatibility with clients and backends but are not consider secure. These many of these ciphers are enabled by default and need to be set to 'False'
.
The following ciphers are considered weak or deprecated:
TripleDes168
TLS_RSA_WITH_AES_128_CBC_SHA
TLS_RSA_WITH_AES_256_CBC_SHA
TLS_RSA_WITH_AES_128_CBC_SHA256
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
TLS_RSA_WITH_AES_256_CBC_SHA256
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
TLS_RSA_WITH_AES_128_GCM_SHA256
Consider disabling weak or deprecated ciphers from API Management Services. Also consider disabling weak or deprecated protocols.
","tags":["Azure.APIM.Ciphers","AZR-000055"]},{"location":"en/rules/Azure.APIM.Ciphers/#examples","title":"Examples","text":"","tags":["Azure.APIM.Ciphers","AZR-000055"]},{"location":"en/rules/Azure.APIM.Ciphers/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management Services that pass this rule:
\"False\"
(as a string) within the properties.customProperties
property:Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256
For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service\",\n \"apiVersion\": \"2021-08-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\",\n \"capacity\": 1\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"publisherEmail\": \"[parameters('publisherEmail')]\",\n \"publisherName\": \"[parameters('publisherName')]\",\n \"customProperties\": {\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2\": \"True\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256\": \"False\"\n },\n \"apiVersionConstraint\": {\n \"minApiVersion\": \"2021-08-01\"\n }\n }\n}\n
","tags":["Azure.APIM.Ciphers","AZR-000055"]},{"location":"en/rules/Azure.APIM.Ciphers/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management Services that pass this rule:
'False'
(as a string) within the properties.customProperties
property:Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256
For example:
Azure Bicep snippetresource service 'Microsoft.ApiManagement/service@2021-08-01' = {\n name: name\n location: location\n sku: {\n name: 'Premium'\n capacity: 1\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n publisherEmail: publisherEmail\n publisherName: publisherName\n customProperties: {\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2': 'True'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256': 'False'\n }\n apiVersionConstraint: {\n minApiVersion: '2021-08-01'\n }\n }\n}\n
","tags":["Azure.APIM.Ciphers","AZR-000055"]},{"location":"en/rules/Azure.APIM.Ciphers/#links","title":"Links","text":"Security \u00b7 API Management \u00b7 Rule \u00b7 2023_12 \u00b7 Critical
APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs.
","tags":["Azure.APIM.DefenderCloud","AZR-000387"]},{"location":"en/rules/Azure.APIM.DefenderCloud/#description","title":"Description","text":"Microsoft Defender for APIs provides additional security for APIs published in Azure API Management. Protection is provided by analyzing onboarded APIs.
Which allows Microsoft Defender for Cloud to produce security findings. These security findings includes API recommendations and runtime threats.
The inventory and security findings for onboarded APIs is reviewed in the Defender for Cloud API Security dashboard. Defender for APIs can be enabled together with the Defender CSPM plan, offering further capabilities.
To use Microsoft Defender for APIs:
Consider onboarding APIs published in Azure API Management to Microsoft Defender for APIs.
","tags":["Azure.APIM.DefenderCloud","AZR-000387"]},{"location":"en/rules/Azure.APIM.DefenderCloud/#examples","title":"Examples","text":"","tags":["Azure.APIM.DefenderCloud","AZR-000387"]},{"location":"en/rules/Azure.APIM.DefenderCloud/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management APIs that pass this rule:
Microsoft.Security/apiCollections
sub-resource (extension resource).name
property to the name as the API.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/apiCollections\",\n \"apiVersion\": \"2022-11-20-preview\",\n \"scope\": \"[format('Microsoft.ApiManagement/service/{0}', parameters('apiManagementServiceName'))]\",\n \"name\": \"[parameters('apiName')]\"\n}\n
","tags":["Azure.APIM.DefenderCloud","AZR-000387"]},{"location":"en/rules/Azure.APIM.DefenderCloud/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management APIs that pass this rule:
Microsoft.Security/apiCollections
sub-resource (extension resource).name
property to the name as the API.For example:
Azure Bicep snippetresource apiManagementService 'Microsoft.ApiManagement/service@2022-08-01' existing = {\n name: apiManagementServiceName\n}\n\nresource onboardDefender 'Microsoft.Security/apiCollections@2022-11-20-preview' = {\n name: apiName\n scope: apiManagementService\n}\n
","tags":["Azure.APIM.DefenderCloud","AZR-000387"]},{"location":"en/rules/Azure.APIM.DefenderCloud/#notes","title":"Notes","text":"Microsoft Defender for APIs has the following limitations:
This rule may currently generate false positive results for APIs only hosted on self-hosted gateways or managed using workspaces.
","tags":["Azure.APIM.DefenderCloud","AZR-000387"]},{"location":"en/rules/Azure.APIM.DefenderCloud/#links","title":"Links","text":"Security \u00b7 API Management \u00b7 Rule \u00b7 2023_06 \u00b7 Important
Encrypt all API Management named values with Key Vault secrets.
","tags":["Azure.APIM.EncryptValues","AZR-000045"]},{"location":"en/rules/Azure.APIM.EncryptValues/#description","title":"Description","text":"Named values can be used to manage constant string values and secrets across all API configurations and policies.
Named values are a global collection of name/value pairs in each API Management instance, which may contain sensitive information.
Secret values can be stored either as encrypted strings in API Management (custom secrets) or by referencing secrets in Azure Key Vault.
All secrets in Key Vault are stored encrypted.
Using Key Vault secrets is recommended because it helps improve API Management security by:
Consider encrypting all API Management named values with Key Vault secrets.
","tags":["Azure.APIM.EncryptValues","AZR-000045"]},{"location":"en/rules/Azure.APIM.EncryptValues/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management named values that pass this rule:
properties.keyVault.secretIdentifier
property.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service/namedValues\",\n \"apiVersion\": \"2022-08-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), parameters('namedValue'))]\",\n \"properties\": {\n \"displayName\": \"[parameters('namedValue')]\",\n \"keyVault\": {\n \"identityClientId\": null,\n \"secretIdentifier\": \"[format('https://myVault.vault.azure.net/secrets/{0}', parameters('namedValue'))]\"\n },\n \"tags\": []\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ApiManagement/service', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.APIM.EncryptValues","AZR-000045"]},{"location":"en/rules/Azure.APIM.EncryptValues/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management named values that pass this rule:
properties.keyVault.secretIdentifier
property.For example:
Azure Bicep snippetresource apimNamedValue 'Microsoft.ApiManagement/service/namedValues@2022-08-01' = {\n name: namedValue\n parent: apim\n properties: {\n displayName: namedValue\n keyVault: {\n identityClientId: null\n secretIdentifier: 'https://myVault.vault.azure.net/secrets/${namedValue}'\n }\n tags: []\n }\n}\n
","tags":["Azure.APIM.EncryptValues","AZR-000045"]},{"location":"en/rules/Azure.APIM.EncryptValues/#notes","title":"Notes","text":"Using Key Vault secrets requires a system-assigned or user-assigned managed identity assigned to the API Management instance. The identity needs permissions to get and list secrets from the Key Vault. Also make sure to read the Prerequisites for key vault integration
section in links.
Security \u00b7 API Management \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Use HTTPS for communication to backend services.
","tags":["Azure.APIM.HTTPBackend","AZR-000044"]},{"location":"en/rules/Azure.APIM.HTTPBackend/#description","title":"Description","text":"When API Management connects to the backend API it can use HTTP or HTTPS. When using HTTP, sensitive information may be exposed to an untrusted party.
Additionally, when configuring backends:
Consider configuring only backend services configured with HTTPS-based URLs.
","tags":["Azure.APIM.HTTPBackend","AZR-000044"]},{"location":"en/rules/Azure.APIM.HTTPBackend/#examples","title":"Examples","text":"","tags":["Azure.APIM.HTTPBackend","AZR-000044"]},{"location":"en/rules/Azure.APIM.HTTPBackend/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy APIs that pass this rule:
properties.serviceUrl
property to a URL that starts with https://
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service/apis\",\n \"apiVersion\": \"2021-08-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'echo-v1')]\",\n \"properties\": {\n \"displayName\": \"Echo API\",\n \"description\": \"An echo API service.\",\n \"path\": \"echo\",\n \"serviceUrl\": \"https://echo.contoso.com\",\n \"protocols\": [\n \"https\"\n ],\n \"apiVersion\": \"v1\",\n \"apiVersionSetId\": \"[resourceId('Microsoft.ApiManagement/service/apiVersionSets', parameters('name'), 'echo')]\",\n \"subscriptionRequired\": true\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ApiManagement/service', parameters('name'))]\",\n \"[resourceId('Microsoft.ApiManagement/service/apiVersionSets', parameters('name'), 'echo')]\"\n ]\n}\n
To deploy API backends that pass this rule:
properties.url
property to a URL that starts with https://
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service/backends\",\n \"apiVersion\": \"2021-08-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'echo')]\",\n \"properties\": {\n \"title\": \"echo\",\n \"description\": \"A backend service for the Each API.\",\n \"protocol\": \"http\",\n \"url\": \"https://echo.contoso.com\"\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ApiManagement/service', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.APIM.HTTPBackend","AZR-000044"]},{"location":"en/rules/Azure.APIM.HTTPBackend/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy APIs that pass this rule:
properties.serviceUrl
property to a URL that starts with https://
.For example:
Azure Bicep snippetresource api 'Microsoft.ApiManagement/service/apis@2021-08-01' = {\n parent: service\n name: 'echo-v1'\n properties: {\n displayName: 'Echo API'\n description: 'An echo API service.'\n path: 'echo'\n serviceUrl: 'https://echo.contoso.com'\n protocols: [\n 'https'\n ]\n apiVersion: 'v1'\n apiVersionSetId: version.id\n subscriptionRequired: true\n }\n}\n
To deploy API backends that pass this rule:
properties.url
property to a URL that starts with https://
.For example:
Azure Bicep snippetresource backend 'Microsoft.ApiManagement/service/backends@2021-08-01' = {\n parent: service\n name: 'echo'\n properties: {\n title: 'echo'\n description: 'A backend service for the Each API.'\n protocol: 'http'\n url: 'https://echo.contoso.com'\n }\n}\n
","tags":["Azure.APIM.HTTPBackend","AZR-000044"]},{"location":"en/rules/Azure.APIM.HTTPBackend/#links","title":"Links","text":"Security \u00b7 API Management \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Enforce HTTPS for communication to API clients.
","tags":["Azure.APIM.HTTPEndpoint","AZR-000042"]},{"location":"en/rules/Azure.APIM.HTTPEndpoint/#description","title":"Description","text":"When an client connects to API Management it can use HTTP or HTTPS. Each API can be configured to accept connection for HTTP and/ or HTTPS. When using HTTP, sensitive information may be exposed to an untrusted party.
","tags":["Azure.APIM.HTTPEndpoint","AZR-000042"]},{"location":"en/rules/Azure.APIM.HTTPEndpoint/#recommendation","title":"Recommendation","text":"Consider setting the each API to only accept HTTPS connections. In the portal, this is done by configuring the HTTPS URL scheme.
","tags":["Azure.APIM.HTTPEndpoint","AZR-000042"]},{"location":"en/rules/Azure.APIM.HTTPEndpoint/#links","title":"Links","text":"Security \u00b7 API Management \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Configure managed identities to access Azure resources.
","tags":["Azure.APIM.ManagedIdentity","AZR-000053"]},{"location":"en/rules/Azure.APIM.ManagedIdentity/#description","title":"Description","text":"API Management must authenticate to access Azure resources such as Key Vault. Use Key Vault to store certificates and secrets used within API Management.
","tags":["Azure.APIM.ManagedIdentity","AZR-000053"]},{"location":"en/rules/Azure.APIM.ManagedIdentity/#recommendation","title":"Recommendation","text":"Consider configuring a managed identity for each API Management instance. Also consider using managed identities to authenticate to related Azure services.
","tags":["Azure.APIM.ManagedIdentity","AZR-000053"]},{"location":"en/rules/Azure.APIM.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.APIM.ManagedIdentity","AZR-000053"]},{"location":"en/rules/Azure.APIM.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management services that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service\",\n \"apiVersion\": \"2021-08-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\",\n \"capacity\": 1\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"publisherEmail\": \"[parameters('publisherEmail')]\",\n \"publisherName\": \"[parameters('publisherName')]\",\n \"customProperties\": {\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2\": \"True\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256\": \"False\"\n },\n \"apiVersionConstraint\": {\n \"minApiVersion\": \"2021-08-01\"\n }\n }\n}\n
","tags":["Azure.APIM.ManagedIdentity","AZR-000053"]},{"location":"en/rules/Azure.APIM.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management services that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource service 'Microsoft.ApiManagement/service@2021-08-01' = {\n name: name\n location: location\n sku: {\n name: 'Premium'\n capacity: 1\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n publisherEmail: publisherEmail\n publisherName: publisherName\n customProperties: {\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2': 'True'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256': 'False'\n }\n apiVersionConstraint: {\n minApiVersion: '2021-08-01'\n }\n }\n}\n
","tags":["Azure.APIM.ManagedIdentity","AZR-000053"]},{"location":"en/rules/Azure.APIM.ManagedIdentity/#links","title":"Links","text":"Operational Excellence \u00b7 API Management \u00b7 Rule \u00b7 2022_12 \u00b7 Important
API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer.
","tags":["Azure.APIM.MinAPIVersion","AZR-000321"]},{"location":"en/rules/Azure.APIM.MinAPIVersion/#description","title":"Description","text":"On 30 September 2023, all API versions prior to 2021-08-01 will be retired and API calls using those API versions will fail. This means you'll no longer be able to create or manage your API Management services using your existing templates, tools, scripts, and programs until they've been updated. Data operations (such as accessing the APIs or Products configured on Azure API Management) will be unaffected by this update, including after 30 September 2023.
From now through 30 September 2023, you can continue to use the templates, tools, and programs without impact. You can transition to API version 2021-08-01 or later at any point prior to 30 September 2023.
","tags":["Azure.APIM.MinAPIVersion","AZR-000321"]},{"location":"en/rules/Azure.APIM.MinAPIVersion/#recommendation","title":"Recommendation","text":"Limit control plane API calls to API Management with version '2021-08-01' or newer.
","tags":["Azure.APIM.MinAPIVersion","AZR-000321"]},{"location":"en/rules/Azure.APIM.MinAPIVersion/#examples","title":"Examples","text":"","tags":["Azure.APIM.MinAPIVersion","AZR-000321"]},{"location":"en/rules/Azure.APIM.MinAPIVersion/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management services that pass this rule:
apiVersion
property to '2021-08-01'
or newer.properties.apiVersionConstraint.minApiVersion
property to '2021-08-01'
or newer.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service\",\n \"apiVersion\": \"2021-08-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\",\n \"capacity\": 1\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"publisherEmail\": \"[parameters('publisherEmail')]\",\n \"publisherName\": \"[parameters('publisherName')]\",\n \"customProperties\": {\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2\": \"True\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256\": \"False\"\n },\n \"apiVersionConstraint\": {\n \"minApiVersion\": \"2021-08-01\"\n }\n }\n}\n
","tags":["Azure.APIM.MinAPIVersion","AZR-000321"]},{"location":"en/rules/Azure.APIM.MinAPIVersion/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management services that pass this rule:
Microsoft.ApiManagement/service@2021-08-01
or newer.properties.apiVersionConstraint.minApiVersion
property to '2021-08-01'
or newer.For example:
Azure Bicep snippetresource service 'Microsoft.ApiManagement/service@2021-08-01' = {\n name: name\n location: location\n sku: {\n name: 'Premium'\n capacity: 1\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n publisherEmail: publisherEmail\n publisherName: publisherName\n customProperties: {\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2': 'True'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256': 'False'\n }\n apiVersionConstraint: {\n minApiVersion: '2021-08-01'\n }\n }\n}\n
","tags":["Azure.APIM.MinAPIVersion","AZR-000321"]},{"location":"en/rules/Azure.APIM.MinAPIVersion/#notes","title":"Notes","text":"This rule fails:
properties.apiVersionConstraint.minApiVersion
property is not configured.properties.apiVersionConstraint.minApiVersion
property value is less than the default value 2021-08-01
and no configuration option property value is set to overwrite the default value.properties.apiVersionConstraint.minApiVersion
property value is less than the configuration option property value specified.Important Currently, depending on how you delete an API Management instance, the instance is either soft-deleted and recoverable during a retention period, or it's permanently deleted:
Configure AZURE_APIM_MIN_API_VERSION
to set the minimum API version used for control plane API calls to the API Management instance.
# YAML: The default AZURE_APIM_MIN_API_VERSION configuration option\nconfiguration:\n AZURE_APIM_MIN_API_VERSION: '2021-08-01'\n
","tags":["Azure.APIM.MinAPIVersion","AZR-000321"]},{"location":"en/rules/Azure.APIM.MinAPIVersion/#links","title":"Links","text":"Reliability \u00b7 API Management \u00b7 Rule \u00b7 2022_12 \u00b7 Important
API Management instances should use multi-region deployment to improve service availability.
","tags":["Azure.APIM.MultiRegion","AZR-000340"]},{"location":"en/rules/Azure.APIM.MultiRegion/#description","title":"Description","text":"Azure API Management supports multi-region deployment. Multi-region deployment provides availability of the API gateway in more than one region and provides service availability if one region goes offline.
This feature is currently only available for the Premium tier of API Management.
","tags":["Azure.APIM.MultiRegion","AZR-000340"]},{"location":"en/rules/Azure.APIM.MultiRegion/#recommendation","title":"Recommendation","text":"Consider deploying an API Management service across multiple regions to improve service availability.
","tags":["Azure.APIM.MultiRegion","AZR-000340"]},{"location":"en/rules/Azure.APIM.MultiRegion/#examples","title":"Examples","text":"","tags":["Azure.APIM.MultiRegion","AZR-000340"]},{"location":"en/rules/Azure.APIM.MultiRegion/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management instances that pass this rule:
properties.additionalLocations
property.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service\",\n \"apiVersion\": \"2021-12-01-preview\",\n \"name\": \"[parameters('apiManagementServiceName')]\",\n \"location\": \"eastus\",\n \"sku\": {\n \"name\": \"Premium\",\n \"capacity\": 1\n },\n \"properties\": {\n \"additionalLocations\": [\n {\n \"location\": \"westeurope\",\n \"sku\": {\n \"name\": \"Premium\",\n \"capacity\": 1\n },\n \"disableGateway\": false\n }\n ]\n }\n}\n
","tags":["Azure.APIM.MultiRegion","AZR-000340"]},{"location":"en/rules/Azure.APIM.MultiRegion/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management instances that pass this rule:
properties.additionalLocations
property.For example:
Azure Bicep snippetresource apiManagementService 'Microsoft.ApiManagement/service@2021-12-01-preview' = {\n name: apiManagementServiceName\n location: 'eastus'\n sku: {\n name: 'Premium'\n capacity: 1\n }\n properties: {\n additionalLocations: [\n {\n location: 'westeurope'\n sku: {\n name: 'Premium'\n capacity: 1\n }\n disableGateway: false\n }\n ]\n }\n}\n
","tags":["Azure.APIM.MultiRegion","AZR-000340"]},{"location":"en/rules/Azure.APIM.MultiRegion/#notes","title":"Notes","text":"This rule is only applicable for API Management instances configured with a Premium tier.
It is recommended to configure zone redundancy if the region supports it.
Virtual network settings must be configured in the added region, if networking is configured in the existing region or regions. The rule does not take this into consideration.
","tags":["Azure.APIM.MultiRegion","AZR-000340"]},{"location":"en/rules/Azure.APIM.MultiRegion/#links","title":"Links","text":"Reliability \u00b7 API Management \u00b7 Rule \u00b7 2022_12 \u00b7 Important
API Management instances should have multi-region deployment gateways enabled.
","tags":["Azure.APIM.MultiRegionGateway","AZR-000341"]},{"location":"en/rules/Azure.APIM.MultiRegionGateway/#description","title":"Description","text":"Azure API Management supports multi-region deployment. Deploy API Management in multiple locations to:
API gateways can be disabled to enabled you to test failover of your API workloads to another region. When disabled, an API gateway will not route API traffic. You should reenable API gateways after you have concluded failover testing to ensure that the API gateway is available for failover if another region becomes unavailable.
If a region goes offline, API requests are automatically routed around the failed region to the next closest gateway.
","tags":["Azure.APIM.MultiRegionGateway","AZR-000341"]},{"location":"en/rules/Azure.APIM.MultiRegionGateway/#recommendation","title":"Recommendation","text":"Consider enabling each regional API gateway location for multi-region redundancy.
","tags":["Azure.APIM.MultiRegionGateway","AZR-000341"]},{"location":"en/rules/Azure.APIM.MultiRegionGateway/#examples","title":"Examples","text":"","tags":["Azure.APIM.MultiRegionGateway","AZR-000341"]},{"location":"en/rules/Azure.APIM.MultiRegionGateway/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management instances that pass this rule:
properties.additionalLocations.disableGateway
property to false
for each additional location.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service\",\n \"apiVersion\": \"2021-12-01-preview\",\n \"name\": \"[parameters('apiManagementServiceName')]\",\n \"location\": \"eastus\",\n \"sku\": {\n \"name\": \"Premium\",\n \"capacity\": 1\n },\n \"properties\": {\n \"additionalLocations\": [\n {\n \"location\": \"westeurope\",\n \"sku\": {\n \"name\": \"Premium\",\n \"capacity\": 1\n },\n \"disableGateway\": false\n }\n ]\n }\n}\n
","tags":["Azure.APIM.MultiRegionGateway","AZR-000341"]},{"location":"en/rules/Azure.APIM.MultiRegionGateway/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management instances that pass this rule:
properties.additionalLocations.disableGateway
property to false
for each additional location.For example:
Azure Bicep snippetresource apiManagementService 'Microsoft.ApiManagement/service@2021-12-01-preview' = {\n name: apiManagementServiceName\n location: 'eastus'\n sku: {\n name: 'Premium'\n capacity: 1\n }\n properties: {\n additionalLocations: [\n {\n location: 'westeurope'\n sku: {\n name: 'Premium'\n capacity: 1\n }\n disableGateway: false\n }\n ]\n }\n}\n
","tags":["Azure.APIM.MultiRegionGateway","AZR-000341"]},{"location":"en/rules/Azure.APIM.MultiRegionGateway/#links","title":"Links","text":"Operational Excellence \u00b7 API Management \u00b7 Rule \u00b7 2020_09 \u00b7 Awareness
API Management service names should meet naming requirements.
","tags":["Azure.APIM.Name","AZR-000056"]},{"location":"en/rules/Azure.APIM.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for API Management service names are:
Consider using names that meet API Management naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.APIM.Name","AZR-000056"]},{"location":"en/rules/Azure.APIM.Name/#examples","title":"Examples","text":"","tags":["Azure.APIM.Name","AZR-000056"]},{"location":"en/rules/Azure.APIM.Name/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy services that pass this rule, consider:
minLength
and maxLength
constraint for the resource name parameter.uniqueString()
function to generate a unique name.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"name\": {\n \"type\": \"string\",\n \"minLength\": 1,\n \"maxLength\": 50,\n \"metadata\": {\n \"description\": \"The name of the resource.\"\n }\n },\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"The location resources will be deployed.\"\n }\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.ApiManagement/service\",\n \"apiVersion\": \"2022-08-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\",\n \"capacity\": 1\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"publisherEmail\": \"[parameters('publisherEmail')]\",\n \"publisherName\": \"[parameters('publisherName')]\",\n \"customProperties\": {\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2\": \"True\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256\": \"False\"\n },\n \"apiVersionConstraint\": {\n \"minApiVersion\": \"2021-08-01\"\n }\n },\n \"metadata\": {\n \"description\": \"An example API Management service.\"\n }\n }\n ]\n}\n
","tags":["Azure.APIM.Name","AZR-000056"]},{"location":"en/rules/Azure.APIM.Name/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy services that pass this rule, consider:
minLength
and maxLength
constraint for the resource name parameter.uniqueString()
function to generate a unique name.For example:
Azure Bicep snippet@minLength(1)\n@maxLength(50)\n@sys.description('The name of the resource.')\nparam name string\n\n@sys.description('The location resources will be deployed.')\nparam location string = resourceGroup().location\n\nresource service 'Microsoft.ApiManagement/service@2022-08-01' = {\n name: name\n location: location\n sku: {\n name: 'Premium'\n capacity: 1\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n publisherEmail: publisherEmail\n publisherName: publisherName\n customProperties: {\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2': 'True'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256': 'False'\n }\n apiVersionConstraint: {\n minApiVersion: '2021-08-01'\n }\n }\n}\n
","tags":["Azure.APIM.Name","AZR-000056"]},{"location":"en/rules/Azure.APIM.Name/#notes","title":"Notes","text":"This rule does not check if API Management service names are unique.
","tags":["Azure.APIM.Name","AZR-000056"]},{"location":"en/rules/Azure.APIM.Name/#links","title":"Links","text":"Security \u00b7 API Management \u00b7 Rule \u00b7 2023_06 \u00b7 Important
Base element for any policy element in a section should be configured.
","tags":["Azure.APIM.PolicyBase","AZR-000371"]},{"location":"en/rules/Azure.APIM.PolicyBase/#description","title":"Description","text":"Determine the policy evaluation order by placement of the base (<base />
) element in each section in the policy definition at each scope.
API Management supports the following scopes Global (all API), Workspace, Product, API, or Operation.
The base element inherits the policies configured in that section at the next broader (parent) scope. Otherwise inherited security or other controls may not apply. The base element can be placed before or after any policy element in a section, depending on the wanted evaluation order. However, if security controls are defined in inherited scopes it may decrease the effectiveness of these controls. For most cases, unless otherwise specified in the policy reference (such as cors
) the base element should be specified as the first element in each section.
A specific exception is at the Global scope. The Global scope does not need the base element because this is the peak scope from which all others inherit.
","tags":["Azure.APIM.PolicyBase","AZR-000371"]},{"location":"en/rules/Azure.APIM.PolicyBase/#recommendation","title":"Recommendation","text":"Consider configuring the base element for any policy element in a section.
","tags":["Azure.APIM.PolicyBase","AZR-000371"]},{"location":"en/rules/Azure.APIM.PolicyBase/#examples","title":"Examples","text":"","tags":["Azure.APIM.PolicyBase","AZR-000371"]},{"location":"en/rules/Azure.APIM.PolicyBase/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management policies that pass this rule:
properties.value
property.For example an API policy:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service/apis/policies\",\n \"apiVersion\": \"2021-08-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'policy')]\",\n \"properties\": {\n \"value\": \"<policies><inbound><base /><ip-filter action=\\\"allow\\\"><address-range from=\\\"10.1.0.1\\\" to=\\\"10.1.0.255\\\" /></ip-filter></inbound><backend><base /></backend><outbound><base /></outbound><on-error><base /></on-error></policies>\",\n \"format\": \"xml\"\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ApiManagement/service/apis', parameters('name'))]\"\n ],\n}\n
","tags":["Azure.APIM.PolicyBase","AZR-000371"]},{"location":"en/rules/Azure.APIM.PolicyBase/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management policies that pass this rule:
properties.value
property.For example an API policy:
Azure Bicep snippetresource apiName_policy 'Microsoft.ApiManagement/service/apis/policies@2021-08-01' = {\n parent: api\n name: 'policy'\n properties: {\n value: '<policies><inbound><base /><ip-filter action=\\\"allow\\\"><address-range from=\\\"10.1.0.1\\\" to=\\\"10.1.0.255\\\" /></ip-filter></inbound><backend><base /></backend><outbound><base /></outbound><on-error><base /></on-error></policies>'\n format: 'xml'\n }\n}\n
","tags":["Azure.APIM.PolicyBase","AZR-000371"]},{"location":"en/rules/Azure.APIM.PolicyBase/#notes","title":"Notes","text":"The rule only checks against rawxml
and xml
policy formatted content. Global policies are excluded since they don't benefit from the base element.
Security \u00b7 API Management \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Configure products to require approval.
","tags":["Azure.APIM.ProductApproval","AZR-000047"]},{"location":"en/rules/Azure.APIM.ProductApproval/#description","title":"Description","text":"When publishing APIs through Azure API Management (APIM), APIs can optionally be assigned to products. Products are a grouping and management construct within API Management. API Management uses products:
Requiring subscriptions on products and requiring approval is an optional security control within API Management. However, for authorizing access to APIs it is recommended to use stronger forms of authorization such as OAuth 2.0.
Using subscriptions and approval on products helps by:
If a product does not require subscriptions (called an open product):
If a product requires subscriptions, but does not require approval:
Consider configuring all API Management products to require approval.
","tags":["Azure.APIM.ProductApproval","AZR-000047"]},{"location":"en/rules/Azure.APIM.ProductApproval/#examples","title":"Examples","text":"","tags":["Azure.APIM.ProductApproval","AZR-000047"]},{"location":"en/rules/Azure.APIM.ProductApproval/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management Products that pass this rule:
properties.approvalRequired
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service/products\",\n \"apiVersion\": \"2022-08-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'echo')]\",\n \"properties\": {\n \"displayName\": \"Echo\",\n \"description\": \"Echo API services for Contoso.\",\n \"approvalRequired\": true,\n \"subscriptionRequired\": true\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ApiManagement/service', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.APIM.ProductApproval","AZR-000047"]},{"location":"en/rules/Azure.APIM.ProductApproval/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management Products that pass this rule:
properties.approvalRequired
property to true
.For example:
Azure Bicep snippetresource product 'Microsoft.ApiManagement/service/products@2022-08-01' = {\n parent: service\n name: 'echo'\n properties: {\n displayName: 'Echo'\n description: 'Echo API services for Contoso.'\n approvalRequired: true\n subscriptionRequired: true\n }\n}\n
","tags":["Azure.APIM.ProductApproval","AZR-000047"]},{"location":"en/rules/Azure.APIM.ProductApproval/#links","title":"Links","text":"API Management products should have a display name and description.
"},{"location":"en/rules/Azure.APIM.ProductDescriptors/#description","title":"Description","text":"Each product created in API Management can have a display name and description set. Using easy to understand descriptions and metadata greatly assists identification for management and usage.
During monitoring from service provider perspective:
This information is visible within the developer portal. Accurate information can be used to assist developers in understanding the purpose of a product.
"},{"location":"en/rules/Azure.APIM.ProductDescriptors/#recommendation","title":"Recommendation","text":"Consider using display name and description fields on products to convey intended purpose and usage. Display name and description fields should be human readable and easy to understand.
"},{"location":"en/rules/Azure.APIM.ProductDescriptors/#examples","title":"Examples","text":""},{"location":"en/rules/Azure.APIM.ProductDescriptors/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management Products that pass this rule:
properties.displayName
with a human readable name.properties.description
with an description of the APIs purpose.For example:
{\n \"type\": \"Microsoft.ApiManagement/service/products\",\n \"apiVersion\": \"2022-08-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'echo')]\",\n \"properties\": {\n \"displayName\": \"Echo\",\n \"description\": \"Echo API services for Contoso.\",\n \"approvalRequired\": true,\n \"subscriptionRequired\": true\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ApiManagement/service', parameters('name'))]\"\n ]\n}\n
"},{"location":"en/rules/Azure.APIM.ProductDescriptors/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management Products that pass this rule:
properties.displayName
with a human readable name.properties.description
with an description of the APIs purpose.For example:
resource product 'Microsoft.ApiManagement/service/products@2022-08-01' = {\n parent: service\n name: 'echo'\n properties: {\n displayName: 'Echo'\n description: 'Echo API services for Contoso.'\n approvalRequired: true\n subscriptionRequired: true\n }\n}\n
"},{"location":"en/rules/Azure.APIM.ProductDescriptors/#links","title":"Links","text":"Security \u00b7 API Management \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Configure products to require a subscription.
","tags":["Azure.APIM.ProductSubscription","AZR-000046"]},{"location":"en/rules/Azure.APIM.ProductSubscription/#description","title":"Description","text":"When publishing APIs through Azure API Management (APIM), APIs can optionally be assigned to products. Products are a grouping and management construct within API Management. API Management uses products:
Requiring subscriptions on products and requiring approval is an optional security control within API Management. However, for authorizing access to APIs it is recommended to use stronger forms of authorization such as OAuth 2.0.
Using subscriptions and approval on products helps by:
If a product does not require subscriptions (called an open product):
If a product requires subscriptions, but does not require approval:
Consider configuring all API Management products to require a subscription.
","tags":["Azure.APIM.ProductSubscription","AZR-000046"]},{"location":"en/rules/Azure.APIM.ProductSubscription/#examples","title":"Examples","text":"","tags":["Azure.APIM.ProductSubscription","AZR-000046"]},{"location":"en/rules/Azure.APIM.ProductSubscription/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management Products that pass this rule:
properties.subscriptionRequired
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service/products\",\n \"apiVersion\": \"2022-08-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'echo')]\",\n \"properties\": {\n \"displayName\": \"Echo\",\n \"description\": \"Echo API services for Contoso.\",\n \"approvalRequired\": true,\n \"subscriptionRequired\": true\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ApiManagement/service', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.APIM.ProductSubscription","AZR-000046"]},{"location":"en/rules/Azure.APIM.ProductSubscription/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management Products that pass this rule:
properties.subscriptionRequired
property to true
.For example:
Azure Bicep snippetresource product 'Microsoft.ApiManagement/service/products@2022-08-01' = {\n parent: service\n name: 'echo'\n properties: {\n displayName: 'Echo'\n description: 'Echo API services for Contoso.'\n approvalRequired: true\n subscriptionRequired: true\n }\n}\n
","tags":["Azure.APIM.ProductSubscription","AZR-000046"]},{"location":"en/rules/Azure.APIM.ProductSubscription/#links","title":"Links","text":"Operational Excellence \u00b7 API Management \u00b7 Rule \u00b7 2020_09 \u00b7 Important
Set legal terms for each product registered in API Management.
","tags":["Azure.APIM.ProductTerms","AZR-000050"]},{"location":"en/rules/Azure.APIM.ProductTerms/#description","title":"Description","text":"Within API Management a product is created to publish one or more APIs. For each product legal terms can be specified. When set, developers using the developer portal are required to accept the terms to subscribe to a product. Use these terms to set expectations on acceptable use of the included APIs.
Acceptance of legal terms is bypassed when an administrator creates a subscription.
","tags":["Azure.APIM.ProductTerms","AZR-000050"]},{"location":"en/rules/Azure.APIM.ProductTerms/#recommendation","title":"Recommendation","text":"Consider configuring legal terms for all products to declare acceptable use of included APIs.
","tags":["Azure.APIM.ProductTerms","AZR-000050"]},{"location":"en/rules/Azure.APIM.ProductTerms/#links","title":"Links","text":"Security \u00b7 API Management \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
API Management should only accept a minimum of TLS 1.2 for client and backend communication.
","tags":["Azure.APIM.Protocols","AZR-000054"]},{"location":"en/rules/Azure.APIM.Protocols/#description","title":"Description","text":"API Management provides support for older TLS/ SSL protocols, which are disabled by default. These older versions are provided for compatibility but are not consider secure.
The following protocols are considered weak or deprecated:
SSL 3.0
TLS 1.0
TLS 1.1
Consider configuring the minimum supported TLS version to be 1.2. Also consider disabling weak or deprecated ciphers.
","tags":["Azure.APIM.Protocols","AZR-000054"]},{"location":"en/rules/Azure.APIM.Protocols/#examples","title":"Examples","text":"","tags":["Azure.APIM.Protocols","AZR-000054"]},{"location":"en/rules/Azure.APIM.Protocols/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy API Management Services that pass this rule:
\"False\"
(as a string) within the properties.customProperties
property:Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30
For example:
Azure Template snippet{\n \"type\": \"Microsoft.ApiManagement/service\",\n \"apiVersion\": \"2021-08-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\",\n \"capacity\": 1\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"publisherEmail\": \"[parameters('publisherEmail')]\",\n \"publisherName\": \"[parameters('publisherName')]\",\n \"customProperties\": {\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2\": \"True\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA\": \"False\",\n \"Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256\": \"False\"\n },\n \"apiVersionConstraint\": {\n \"minApiVersion\": \"2021-08-01\"\n }\n }\n}\n
","tags":["Azure.APIM.Protocols","AZR-000054"]},{"location":"en/rules/Azure.APIM.Protocols/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy API Management Services that pass this rule:
'False'
(as a string) within the properties.customProperties
property:Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11
Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30
For example:
Azure Bicep snippetresource service 'Microsoft.ApiManagement/service@2021-08-01' = {\n name: name\n location: location\n sku: {\n name: 'Premium'\n capacity: 1\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n publisherEmail: publisherEmail\n publisherName: publisherName\n customProperties: {\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Ssl30': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Ssl30': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2': 'True'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_256_CBC_SHA256': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA': 'False'\n 'Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_GCM_SHA256': 'False'\n }\n apiVersionConstraint: {\n minApiVersion: '2021-08-01'\n }\n }\n}\n
","tags":["Azure.APIM.Protocols","AZR-000054"]},{"location":"en/rules/Azure.APIM.Protocols/#links","title":"Links","text":"Operational Excellence \u00b7 API Management \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Remove starter and unlimited sample products.
","tags":["Azure.APIM.SampleProducts","AZR-000048"]},{"location":"en/rules/Azure.APIM.SampleProducts/#description","title":"Description","text":"API Management includes two sample products Starter and Unlimited. Accidentally adding APIs to these sample products may expose APIs more than intended.
","tags":["Azure.APIM.SampleProducts","AZR-000048"]},{"location":"en/rules/Azure.APIM.SampleProducts/#recommendation","title":"Recommendation","text":"Consider removing starter and unlimited sample products from API Management.
","tags":["Azure.APIM.SampleProducts","AZR-000048"]},{"location":"en/rules/Azure.APIM.SampleProducts/#links","title":"Links","text":"Operational Excellence \u00b7 App Service Environment \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2.
","tags":["Azure.ASE.MigrateV3","AZR-000319"]},{"location":"en/rules/Azure.ASE.MigrateV3/#description","title":"Description","text":"The classic App Service Environment version 1 (ASEv1) and version 2 (ASEv2) will be retired on August 31, 2024. To avoid service disruption, migrate to App Service Environment version 3 (ASEv3). App Service Environment v3 has advantages and feature differences that provide enhanced support for your workloads and can reduce overall costs.
App Service Environment v3 differs from earlier versions in the following ways:
A few features that were available in earlier versions of App Service Environment aren't available in App Service Environment v3. For example, you can no longer do the following:
Classic App Service Environments should migrate to App Service Environment v3.
","tags":["Azure.ASE.MigrateV3","AZR-000319"]},{"location":"en/rules/Azure.ASE.MigrateV3/#examples","title":"Examples","text":"","tags":["Azure.ASE.MigrateV3","AZR-000319"]},{"location":"en/rules/Azure.ASE.MigrateV3/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy app service environments pass this rule:
kind
to 'ASEV3'
.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"metadata\": {\n \"_generator\": {\n \"name\": \"bicep\",\n \"version\": \"0.11.1.770\",\n \"templateHash\": \"13381170219553357893\"\n }\n },\n \"parameters\": {\n \"aseName\": {\n \"type\": \"string\",\n \"defaultValue\": \"001-ase\",\n \"metadata\": {\n \"description\": \"Name of the App Service Environment\"\n }\n },\n \"virtualNetworkName\": {\n \"type\": \"string\",\n \"defaultValue\": \"ase-001-vnet\",\n \"metadata\": {\n \"description\": \"The name of the vnet\"\n }\n },\n \"vnetResourceGroupName\": {\n \"type\": \"string\",\n \"defaultValue\": \"ase-001-rg\",\n \"metadata\": {\n \"description\": \"The resource group name that contains the vnet\"\n }\n },\n \"subnetName\": {\n \"type\": \"string\",\n \"defaultValue\": \"ase-001-sn\",\n \"metadata\": {\n \"description\": \"Subnet name that will contain the App Service Environment\"\n }\n },\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"Location for the resources\"\n }\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Web/hostingEnvironments\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"[parameters('aseName')]\",\n \"location\": \"[parameters('location')]\",\n \"kind\": \"ASEV3\",\n \"tags\": {\n \"displayName\": \"App Service Environment\",\n \"usage\": \"Hosting awesome applications\",\n \"owner\": \"Platform\"\n },\n \"properties\": {\n \"virtualNetwork\": {\n \"id\": \"[extensionResourceId(format('/subscriptions/{0}/resourceGroups/{1}', subscription().subscriptionId, parameters('vnetResourceGroupName')), 'Microsoft.Network/virtualNetworks/subnets', parameters('virtualNetworkName'), parameters('subnetName'))]\"\n }\n }\n }\n ]\n}\n
","tags":["Azure.ASE.MigrateV3","AZR-000319"]},{"location":"en/rules/Azure.ASE.MigrateV3/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy app service environments pass this rule:
kind
to 'ASEV3'
.For example:
Azure Bicep snippet@description('Name of the App Service Environment')\nparam aseName string = '001-ase'\n\n@description('The name of the vnet')\nparam virtualNetworkName string = 'ase-001-vnet'\n\n@description('The resource group name that contains the vnet')\nparam vnetResourceGroupName string = 'ase-001-rg'\n\n@description('Subnet name that will contain the App Service Environment')\nparam subnetName string = 'ase-001-sn'\n\n@description('Location for the resources')\nparam location string = resourceGroup().location\n\nresource virtualNetwork 'Microsoft.Network/virtualNetworks@2022-05-01' existing = {\n scope: resourceGroup(vnetResourceGroupName)\n name: virtualNetworkName\n}\n\nresource subnet 'Microsoft.Network/virtualNetworks/subnets@2022-05-01' existing = {\n parent: virtualNetwork\n name: subnetName\n}\n\nresource hostingEnvironment 'Microsoft.Web/hostingEnvironments@2022-03-01' = {\n name: aseName\n location: location\n kind: 'ASEV3'\n tags: {\n displayName: 'App Service Environment'\n usage: 'Hosting awesome applications'\n owner: 'Platform'\n }\n properties: {\n virtualNetwork: {\n id: subnet.id\n }\n }\n}\n
","tags":["Azure.ASE.MigrateV3","AZR-000319"]},{"location":"en/rules/Azure.ASE.MigrateV3/#links","title":"Links","text":"Operational Excellence \u00b7 Application Security Group \u00b7 Rule \u00b7 2021_12 \u00b7 Awareness
Application Security Group (ASG) names should meet naming requirements.
","tags":["Azure.ASG.Name","AZR-000085"]},{"location":"en/rules/Azure.ASG.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for ASG names are:
Consider using names that meet Application Security Group naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.ASG.Name","AZR-000085"]},{"location":"en/rules/Azure.ASG.Name/#examples","title":"Examples","text":"","tags":["Azure.ASG.Name","AZR-000085"]},{"location":"en/rules/Azure.ASG.Name/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Application Security Groups that pass this rule:
name
to a value that meets the requirements.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/applicationSecurityGroups\",\n \"apiVersion\": \"2022-01-01\",\n \"name\": \"[parameters('asgName')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {}\n}\n
","tags":["Azure.ASG.Name","AZR-000085"]},{"location":"en/rules/Azure.ASG.Name/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Application Security Groups that pass this rule:
name
to a value that meets the requirements.For example:
Azure Bicep snippetresource asg 'Microsoft.Network/applicationSecurityGroups@2022-01-01' = {\n name: asgName\n location:location\n properties: {}\n}\n
","tags":["Azure.ASG.Name","AZR-000085"]},{"location":"en/rules/Azure.ASG.Name/#notes","title":"Notes","text":"This rule does not check if ASG names are unique.
","tags":["Azure.ASG.Name","AZR-000085"]},{"location":"en/rules/Azure.ASG.Name/#links","title":"Links","text":"Security \u00b7 App Configuration \u00b7 Rule \u00b7 2022_09 \u00b7 Important
Ensure app configuration store audit diagnostic logs are enabled.
","tags":["Azure.AppConfig.AuditLogs","AZR-000311"]},{"location":"en/rules/Azure.AppConfig.AuditLogs/#description","title":"Description","text":"To capture logs that record interactions with data or the settings of the app configuration store, diagnostic settings must be configured.
When configuring diagnostic settings, enable one of the following:
Audit
category.audit
category group.allLogs
category group.Management operations for App Configuration Store are captured automatically within Azure Activity Logs.
","tags":["Azure.AppConfig.AuditLogs","AZR-000311"]},{"location":"en/rules/Azure.AppConfig.AuditLogs/#recommendation","title":"Recommendation","text":"Consider configuring diagnostic settings to record interactions with data or the settings of the App Configuration Store.
","tags":["Azure.AppConfig.AuditLogs","AZR-000311"]},{"location":"en/rules/Azure.AppConfig.AuditLogs/#examples","title":"Examples","text":"","tags":["Azure.AppConfig.AuditLogs","AZR-000311"]},{"location":"en/rules/Azure.AppConfig.AuditLogs/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy an App Configuration Store that pass this rule:
Audit
category or audit
category group or allLogs
category group.For example:
Azure Template snippet{\n \"parameters\": {\n \"name\": {\n \"type\": \"string\",\n \"metadata\": {\n \"description\": \"The name of the App Configuration Store.\"\n }\n },\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"The location resources will be deployed.\"\n }\n },\n \"workspaceId\": {\n \"type\": \"string\",\n \"metadata\": {\n \"description\": \"The resource id of the Log Analytics workspace to send diagnostic logs to.\"\n }\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.AppConfiguration/configurationStores\",\n \"apiVersion\": \"2022-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"enablePurgeProtection\": true\n }\n },\n {\n \"type\": \"Microsoft.Insights/diagnosticSettings\",\n \"apiVersion\": \"2021-05-01-preview\",\n \"scope\": \"[format('Microsoft.AppConfiguration/configurationStores/{0}', parameters('name'))]\",\n \"name\": \"[format('{0}-diagnostic', parameters('name'))]\",\n \"properties\": {\n \"logs\": [\n {\n \"categoryGroup\": \"audit\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 90,\n \"enabled\": true\n }\n }\n ],\n \"workspaceId\": \"[parameters('workspaceId')]\"\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.AppConfiguration/configurationStores', parameters('name'))]\"\n ]\n }\n ]\n}\n
","tags":["Azure.AppConfig.AuditLogs","AZR-000311"]},{"location":"en/rules/Azure.AppConfig.AuditLogs/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy an App Configuration Store that pass this rule:
Audit
category or audit
category group or allLogs
category group.For example:
Azure Bicep snippetresource store 'Microsoft.AppConfiguration/configurationStores@2023-03-01' = {\n name: name\n location: location\n sku: {\n name: 'standard'\n }\n properties: {\n disableLocalAuth: true\n enablePurgeProtection: true\n publicNetworkAccess: 'Disabled'\n }\n}\n\nresource diagnostic 'Microsoft.Insights/diagnosticSettings@2021-05-01-preview' = {\n scope: store\n name: '${name}-diagnostic'\n properties: {\n logs: [\n {\n categoryGroup: 'audit'\n enabled: true\n retentionPolicy: {\n days: 90\n enabled: true\n }\n }\n ]\n workspaceId: workspaceId\n }\n}\n
","tags":["Azure.AppConfig.AuditLogs","AZR-000311"]},{"location":"en/rules/Azure.AppConfig.AuditLogs/#configure-with-bicep-public-registry","title":"Configure with Bicep Public Registry","text":"To deploy an App Configuration Store that pass this rule:
diagnosticSettingsProperties.logs
parameter.Audit
category or audit
category group or allLogs
category group.For example:
Azure Bicep snippetmodule store 'br/public:app/app-configuration:1.1.1' = {\n name: 'store'\n params: {\n skuName: 'Standard'\n disableLocalAuth: true\n enablePurgeProtection: true\n publicNetworkAccess: 'Disabled'\n diagnosticSettingsProperties: {\n diagnosticReceivers: {\n workspaceId: workspaceId\n }\n logs: [\n {\n categoryGroup: 'audit'\n enabled: true\n retentionPolicy: {\n days: 90\n enabled: true\n }\n }\n ]\n }\n }\n}\n
","tags":["Azure.AppConfig.AuditLogs","AZR-000311"]},{"location":"en/rules/Azure.AppConfig.AuditLogs/#links","title":"Links","text":"Security \u00b7 App Configuration \u00b7 Rule \u00b7 2022_09 \u00b7 Important
Authenticate App Configuration clients with Entra ID identities.
","tags":["Azure.AppConfig.DisableLocalAuth","AZR-000291"]},{"location":"en/rules/Azure.AppConfig.DisableLocalAuth/#description","title":"Description","text":"Every request to an Azure App Configuration resource must be authenticated. App Configuration supports authenticating requests using either Entra ID (previously Azure AD) identities or access keys. Using Entra ID identities:
To require clients to use Entra ID to authenticate requests, you can disable the usage of access keys for an Azure App Configuration resource.
When you disable access key authentication for an Azure App Configuration resource, any existing access keys for that resource are deleted. Any subsequent requests to the resource using the previously existing access keys will be rejected. Only requests that are authenticated using Entra ID will succeed.
","tags":["Azure.AppConfig.DisableLocalAuth","AZR-000291"]},{"location":"en/rules/Azure.AppConfig.DisableLocalAuth/#recommendation","title":"Recommendation","text":"Consider only using Entra ID identities to access App Configuration data. Then disable authentication based on access keys or SAS tokens.
","tags":["Azure.AppConfig.DisableLocalAuth","AZR-000291"]},{"location":"en/rules/Azure.AppConfig.DisableLocalAuth/#examples","title":"Examples","text":"","tags":["Azure.AppConfig.DisableLocalAuth","AZR-000291"]},{"location":"en/rules/Azure.AppConfig.DisableLocalAuth/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy configuration stores that pass this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.AppConfiguration/configurationStores\",\n \"apiVersion\": \"2023-03-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"enablePurgeProtection\": true,\n \"publicNetworkAccess\": \"Disabled\"\n }\n}\n
","tags":["Azure.AppConfig.DisableLocalAuth","AZR-000291"]},{"location":"en/rules/Azure.AppConfig.DisableLocalAuth/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy configuration stores that pass this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Bicep snippetresource store 'Microsoft.AppConfiguration/configurationStores@2023-03-01' = {\n name: name\n location: location\n sku: {\n name: 'standard'\n }\n properties: {\n disableLocalAuth: true\n enablePurgeProtection: true\n publicNetworkAccess: 'Disabled'\n }\n}\n
","tags":["Azure.AppConfig.DisableLocalAuth","AZR-000291"]},{"location":"en/rules/Azure.AppConfig.DisableLocalAuth/#configure-with-bicep-public-registry","title":"Configure with Bicep Public Registry","text":"To deploy App Configuration Stores that pass this rule:
params.disableLocalAuth
parameter to true
.For example:
Azure Bicep snippetmodule br_public_store 'br/public:app/app-configuration:1.1.2' = {\n name: 'store'\n params: {\n skuName: 'Standard'\n disableLocalAuth: true\n enablePurgeProtection: true\n publicNetworkAccess: 'Disabled'\n replicas: [\n {\n name: 'eastus'\n location: 'eastus'\n }\n ]\n }\n}\n
","tags":["Azure.AppConfig.DisableLocalAuth","AZR-000291"]},{"location":"en/rules/Azure.AppConfig.DisableLocalAuth/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
Name Resource App Configuration stores should have local authentication methods disabled/providers/Microsoft.Authorization/policyDefinitions/b08ab3ca-1062-4db3-8803-eec9cae605d6
Configure App Configuration stores to disable local authentication methods /providers/Microsoft.Authorization/policyDefinitions/72bc14af-4ab8-43af-b4e4-38e7983f9a1f
","tags":["Azure.AppConfig.DisableLocalAuth","AZR-000291"]},{"location":"en/rules/Azure.AppConfig.DisableLocalAuth/#links","title":"Links","text":"Reliability \u00b7 App Configuration \u00b7 Rule \u00b7 2023_12 \u00b7 Important
Replicate app configuration store across all points of presence for an application.
","tags":["Azure.AppConfig.GeoReplica","AZR-000312"]},{"location":"en/rules/Azure.AppConfig.GeoReplica/#description","title":"Description","text":"By default, an app configuration store is stored and maintained in a single region.
The app configuration geo-replication feature allows you to replicate your configuration store to additional regions. Each new replica will be in a different region with a new endpoint for your applications to send requests to. The original endpoint of your configuration store is called the origin. The origin can't be removed, but otherwise behaves like any replica.
Replicating your configuration store adds the following benefits:
When considering where to place replicas, consider the following; where does the application run from?
Consider replicating app configuration stores to improve resiliency to region outages.
","tags":["Azure.AppConfig.GeoReplica","AZR-000312"]},{"location":"en/rules/Azure.AppConfig.GeoReplica/#examples","title":"Examples","text":"","tags":["Azure.AppConfig.GeoReplica","AZR-000312"]},{"location":"en/rules/Azure.AppConfig.GeoReplica/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy App Configuration Stores that pass this rule:
sku.name
to Standard
(required for geo-replication).location
on replica sub-resource to a different location than the app configuration store.For example:
Azure Template snippet{\n \"resources\": [\n {\n \"type\": \"Microsoft.AppConfiguration/configurationStores\",\n \"apiVersion\": \"2023-03-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"enablePurgeProtection\": true,\n \"publicNetworkAccess\": \"Disabled\"\n }\n },\n {\n \"type\": \"Microsoft.AppConfiguration/configurationStores/replicas\",\n \"apiVersion\": \"2023-03-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), parameters('replicaName'))]\",\n \"location\": \"[parameters('replicaLocation')]\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.AppConfiguration/configurationStores', parameters('name'))]\"\n ]\n }\n ]\n}\n
","tags":["Azure.AppConfig.GeoReplica","AZR-000312"]},{"location":"en/rules/Azure.AppConfig.GeoReplica/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Configuration Stores that pass this rule:
sku.name
to Standard
(required for geo-replication).location
on replica sub-resource to a different location than the app configuration store.For example:
Azure Bicep snippetresource store 'Microsoft.AppConfiguration/configurationStores@2023-03-01' = {\n name: name\n location: location\n sku: {\n name: 'standard'\n }\n properties: {\n disableLocalAuth: true\n enablePurgeProtection: true\n publicNetworkAccess: 'Disabled'\n }\n}\n\nresource replica 'Microsoft.AppConfiguration/configurationStores/replicas@2023-03-01' = {\n parent: store\n name: replicaName\n location: replicaLocation\n}\n
","tags":["Azure.AppConfig.GeoReplica","AZR-000312"]},{"location":"en/rules/Azure.AppConfig.GeoReplica/#configure-with-bicep-public-registry","title":"Configure with Bicep Public Registry","text":"To deploy App Configuration Stores that pass this rule:
params.skuName
to Standard
(required for geo-replication).params.replicas
to an array of objects.location
on each replica to a different location than the app configuration store.For example:
Azure Bicep snippetmodule br_public_store 'br/public:app/app-configuration:1.1.2' = {\n name: 'store'\n params: {\n skuName: 'Standard'\n disableLocalAuth: true\n enablePurgeProtection: true\n publicNetworkAccess: 'Disabled'\n replicas: [\n {\n name: 'eastus'\n location: 'eastus'\n }\n ]\n }\n}\n
","tags":["Azure.AppConfig.GeoReplica","AZR-000312"]},{"location":"en/rules/Azure.AppConfig.GeoReplica/#links","title":"Links","text":"Operational Excellence \u00b7 App Configuration \u00b7 Rule \u00b7 2020_12 \u00b7 Awareness
App Configuration store names should meet naming requirements.
","tags":["Azure.AppConfig.Name","AZR-000058"]},{"location":"en/rules/Azure.AppConfig.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for App Configuration store names are:
Consider using names that meet App Configuration store naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.AppConfig.Name","AZR-000058"]},{"location":"en/rules/Azure.AppConfig.Name/#examples","title":"Examples","text":"","tags":["Azure.AppConfig.Name","AZR-000058"]},{"location":"en/rules/Azure.AppConfig.Name/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy configuration stores that pass this rule:
name
to a value that meets the requirements.For example:
Azure Template snippet{\n \"type\": \"Microsoft.AppConfiguration/configurationStores\",\n \"apiVersion\": \"2022-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"enablePurgeProtection\": true\n }\n}\n
","tags":["Azure.AppConfig.Name","AZR-000058"]},{"location":"en/rules/Azure.AppConfig.Name/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy configuration stores that pass this rule:
name
to a value that meets the requirements.For example:
Azure Bicep snippetresource store 'Microsoft.AppConfiguration/configurationStores@2022-05-01' = {\n name: name\n location: location\n sku: {\n name: 'standard'\n }\n properties: {\n disableLocalAuth: true\n enablePurgeProtection: true\n }\n}\n
","tags":["Azure.AppConfig.Name","AZR-000058"]},{"location":"en/rules/Azure.AppConfig.Name/#configure-with-bicep-public-registry","title":"Configure with Bicep Public Registry","text":"To deploy App Configuration Stores that pass this rule:
params.name
to a value that meets the requirements.For example:
Azure Bicep snippetmodule br_public_store 'br/public:app/app-configuration:1.1.2' = {\n name: 'store'\n params: {\n skuName: 'Standard'\n disableLocalAuth: true\n enablePurgeProtection: true\n publicNetworkAccess: 'Disabled'\n replicas: [\n {\n name: 'eastus'\n location: 'eastus'\n }\n ]\n }\n}\n
","tags":["Azure.AppConfig.Name","AZR-000058"]},{"location":"en/rules/Azure.AppConfig.Name/#notes","title":"Notes","text":"This rule does not check if App Configuration store names are unique.
","tags":["Azure.AppConfig.Name","AZR-000058"]},{"location":"en/rules/Azure.AppConfig.Name/#links","title":"Links","text":"Reliability \u00b7 App Configuration \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Consider purge protection for app configuration store to ensure store cannot be purged in the retention period.
","tags":["Azure.AppConfig.PurgeProtect","AZR-000313"]},{"location":"en/rules/Azure.AppConfig.PurgeProtect/#description","title":"Description","text":"With purge protection enabled, soft deleted stores can't be purged in the retention period. If disabled, the soft deleted store can be purged before the retention period expires. Once purge protection is enabled on a store, it can't be disabled.
Purge protection is only available for configuration stores that use the standard SKU.
","tags":["Azure.AppConfig.PurgeProtect","AZR-000313"]},{"location":"en/rules/Azure.AppConfig.PurgeProtect/#recommendation","title":"Recommendation","text":"Consider enabling purge protection for app configuration stores.
","tags":["Azure.AppConfig.PurgeProtect","AZR-000313"]},{"location":"en/rules/Azure.AppConfig.PurgeProtect/#examples","title":"Examples","text":"","tags":["Azure.AppConfig.PurgeProtect","AZR-000313"]},{"location":"en/rules/Azure.AppConfig.PurgeProtect/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy App Configuration Stores that pass this rule:
properties.enablePurgeProtection
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.AppConfiguration/configurationStores\",\n \"apiVersion\": \"2023-03-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"enablePurgeProtection\": true,\n \"publicNetworkAccess\": \"Disabled\"\n }\n}\n
","tags":["Azure.AppConfig.PurgeProtect","AZR-000313"]},{"location":"en/rules/Azure.AppConfig.PurgeProtect/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Configuration Stores that pass this rule:
properties.enablePurgeProtection
property to true
.For example:
Azure Bicep snippetresource store 'Microsoft.AppConfiguration/configurationStores@2023-03-01' = {\n name: name\n location: location\n sku: {\n name: 'standard'\n }\n properties: {\n disableLocalAuth: true\n enablePurgeProtection: true\n publicNetworkAccess: 'Disabled'\n }\n}\n
","tags":["Azure.AppConfig.PurgeProtect","AZR-000313"]},{"location":"en/rules/Azure.AppConfig.PurgeProtect/#configure-with-bicep-public-registry","title":"Configure with Bicep Public Registry","text":"To deploy App Configuration Stores that pass this rule:
params.enablePurgeProtection
parameter to true
.For example:
Azure Bicep snippetmodule br_public_store 'br/public:app/app-configuration:1.1.2' = {\n name: 'store'\n params: {\n skuName: 'Standard'\n disableLocalAuth: true\n enablePurgeProtection: true\n publicNetworkAccess: 'Disabled'\n replicas: [\n {\n name: 'eastus'\n location: 'eastus'\n }\n ]\n }\n}\n
","tags":["Azure.AppConfig.PurgeProtect","AZR-000313"]},{"location":"en/rules/Azure.AppConfig.PurgeProtect/#links","title":"Links","text":"Reliability \u00b7 App Configuration \u00b7 Rule \u00b7 2020_12 \u00b7 Important
App Configuration should use a minimum size of Standard.
","tags":["Azure.AppConfig.SKU","AZR-000057"]},{"location":"en/rules/Azure.AppConfig.SKU/#description","title":"Description","text":"App Configuration is offered in two different SKUs; Free, and Standard. Standard includes additional features, increases scalability, and 99.9% SLA. The Free SKU does not include a SLA.
","tags":["Azure.AppConfig.SKU","AZR-000057"]},{"location":"en/rules/Azure.AppConfig.SKU/#recommendation","title":"Recommendation","text":"Consider upgrading App Configuration instances to Standard. Free instances are intended only for early development and testing scenarios.
","tags":["Azure.AppConfig.SKU","AZR-000057"]},{"location":"en/rules/Azure.AppConfig.SKU/#examples","title":"Examples","text":"","tags":["Azure.AppConfig.SKU","AZR-000057"]},{"location":"en/rules/Azure.AppConfig.SKU/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy configuration stores that pass this rule:
sku.name
property to standard
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.AppConfiguration/configurationStores\",\n \"apiVersion\": \"2023-03-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"enablePurgeProtection\": true,\n \"publicNetworkAccess\": \"Disabled\"\n }\n}\n
","tags":["Azure.AppConfig.SKU","AZR-000057"]},{"location":"en/rules/Azure.AppConfig.SKU/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy configuration stores that pass this rule:
sku.name
property to standard
.For example:
Azure Bicep snippetresource store 'Microsoft.AppConfiguration/configurationStores@2023-03-01' = {\n name: name\n location: location\n sku: {\n name: 'standard'\n }\n properties: {\n disableLocalAuth: true\n enablePurgeProtection: true\n publicNetworkAccess: 'Disabled'\n }\n}\n
","tags":["Azure.AppConfig.SKU","AZR-000057"]},{"location":"en/rules/Azure.AppConfig.SKU/#configure-with-bicep-public-registry","title":"Configure with Bicep Public Registry","text":"To deploy App Configuration Stores that pass this rule:
params.skuName
parameter to Standard
.For example:
Azure Bicep snippetmodule br_public_store 'br/public:app/app-configuration:1.1.2' = {\n name: 'store'\n params: {\n skuName: 'Standard'\n disableLocalAuth: true\n enablePurgeProtection: true\n publicNetworkAccess: 'Disabled'\n replicas: [\n {\n name: 'eastus'\n location: 'eastus'\n }\n ]\n }\n}\n
","tags":["Azure.AppConfig.SKU","AZR-000057"]},{"location":"en/rules/Azure.AppConfig.SKU/#links","title":"Links","text":"Reliability \u00b7 Application Gateway \u00b7 Rule \u00b7 2021_09 \u00b7 Important
Application gateways should use availability zones in supported regions for high availability.
","tags":["Azure.AppGw.AvailabilityZone","AZR-000060"]},{"location":"en/rules/Azure.AppGw.AvailabilityZone/#description","title":"Description","text":"Application gateways using availability zones improve reliability and ensure availability during failure scenarios affecting a data center within a region. A zone redundant Application gateway or Web Application Firewall (WAF) deployment can spread across multiple availability zones, which ensures the application gateway will continue running even if another zone has gone down. Backend pools for applications can be similarly distributed across availability zones.
","tags":["Azure.AppGw.AvailabilityZone","AZR-000060"]},{"location":"en/rules/Azure.AppGw.AvailabilityZone/#recommendation","title":"Recommendation","text":"Consider using availability zones for Application gateways deployed with V2 SKU (Standard_v2, WAF_v2).
","tags":["Azure.AppGw.AvailabilityZone","AZR-000060"]},{"location":"en/rules/Azure.AppGw.AvailabilityZone/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed to Azure using pre-flight and in-flight data.
This rule fails when \"zones\"
is null
, []
or not set when the Application gateway is deployed with V2 SKU (Standard_v2, WAF_v2) and there are supported availability zones for the given region.
Configure AZURE_APPGW_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
to set additional availability zones that need to be supported which are not in the existing providers for namespace Microsoft.Network
and resource type applicationGateways
.
# YAML: The default AZURE_APPGW_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST configuration option\nconfiguration:\n AZURE_APPGW_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST: []\n
","tags":["Azure.AppGw.AvailabilityZone","AZR-000060"]},{"location":"en/rules/Azure.AppGw.AvailabilityZone/#examples","title":"Examples","text":"","tags":["Azure.AppGw.AvailabilityZone","AZR-000060"]},{"location":"en/rules/Azure.AppGw.AvailabilityZone/#configure-with-azure-template","title":"Configure with Azure template","text":"To set availability zones for an Application gateway
zones
to any or all of [\"1\", \"2\", \"3\"]
.properties.sku.name
and properties.sku.tier
to Standard_v2
or WAF_v2
.For example:
Azure Template snippet {\n \"name\": \"appGw-001\",\n \"type\": \"Microsoft.Network/applicationGateways\",\n \"apiVersion\": \"2019-09-01\",\n \"location\": \"[resourceGroup().location]\",\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ],\n \"tags\": {},\n \"properties\": {\n \"sku\": {\n \"name\": \"WAF_v2\",\n \"tier\": \"WAF_v2\"\n },\n \"autoscaleConfiguration\": {\n \"minCapacity\": 2,\n \"maxCapacity\": 3\n }\n }\n }\n
","tags":["Azure.AppGw.AvailabilityZone","AZR-000060"]},{"location":"en/rules/Azure.AppGw.AvailabilityZone/#configure-with-bicep","title":"Configure with Bicep","text":"To set availability zones for an Application gateway
zones
to any or all of [\"1\", \"2\", \"3\"]
.properties.sku.name
and properties.sku.tier
to Standard_v2
or WAF_v2
.For example:
Azure Bicep snippetresource name_resource 'Microsoft.Network/applicationGateways@2019-09-01' = {\n name: 'appGw-001'\n location: location\n zones: [\n '1'\n '2'\n '3'\n ]\n tags: {}\n properties: {\n sku: {\n name: 'WAF_v2'\n tier: 'WAF_v2'\n }\n autoscaleConfiguration: {\n minCapacity: 2\n maxCapacity: 3\n }\n }\n}\n
","tags":["Azure.AppGw.AvailabilityZone","AZR-000060"]},{"location":"en/rules/Azure.AppGw.AvailabilityZone/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"","tags":["Azure.AppGw.AvailabilityZone","AZR-000060"]},{"location":"en/rules/Azure.AppGw.AvailabilityZone/#create-wafv2-application-gateway-in-zone-1-2-and-3","title":"Create WAFv2 Application Gateway in Zone 1, 2 and 3","text":"Azure CLI snippetaz network application-gateway create \\\n --name '<application_gateway_name>' \\\n --location '<location>' \\\n --resource-group '<resource_group>' \\\n --capacity '<capacity>' \\\n --sku WAF_v2 \\\n --public-ip-address '<public_ip_address>' \\\n --vnet-name '<virtual_network_name>' \\\n --subnet '<subnet_name>' \\\n --zones 1 2 3 \\\n --servers '<address_1>' '<address_2>'\n
","tags":["Azure.AppGw.AvailabilityZone","AZR-000060"]},{"location":"en/rules/Azure.AppGw.AvailabilityZone/#links","title":"Links","text":"Operational Excellence \u00b7 Application Gateway \u00b7 Rule \u00b7 2023_06 \u00b7 Important
Use a Application Gateway v2 SKU.
","tags":["Azure.AppGw.MigrateV2","AZR-000376"]},{"location":"en/rules/Azure.AppGw.MigrateV2/#description","title":"Description","text":"The Application Gateway v1 SKUs (Standard and WAF) will be retired on April 28, 2026. To avoid service disruption, migrate to Application Gateway v2 SKUs.
The v2 SKUs offers performance enhancements, security controls and adds support for critical new features like autoscaling, zone redundancy, support for static VIPs, header rewrite, key vault integration, mutual authentication (mTLS), Azure Kubernetes Service ingress controller and private link.
","tags":["Azure.AppGw.MigrateV2","AZR-000376"]},{"location":"en/rules/Azure.AppGw.MigrateV2/#recommendation","title":"Recommendation","text":"Migrate deprecated v1 Application Gateways to a v2 SKU before retirement to avoid service disruption.
","tags":["Azure.AppGw.MigrateV2","AZR-000376"]},{"location":"en/rules/Azure.AppGw.MigrateV2/#examples","title":"Examples","text":"","tags":["Azure.AppGw.MigrateV2","AZR-000376"]},{"location":"en/rules/Azure.AppGw.MigrateV2/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Application Gateways that pass this rule:
properties.sku.tier
or properties.sku.name
to Standard_v2
(Application Gateway) or WAF_v2
(Web Application Firewall).For example:
Azure Template snippet{\n \"name\": \"[parameters('name')]\",\n \"type\": \"Microsoft.Network/applicationGateways\",\n \"apiVersion\": \"2022-07-01\",\n \"location\": \"[resourceGroup().location]\",\n \"properties\": {\n \"sku\": {\n \"capacity\": 2,\n \"name\": \"WAF_v2\",\n \"tier\": \"WAF_v2\"\n }\n }\n}\n
","tags":["Azure.AppGw.MigrateV2","AZR-000376"]},{"location":"en/rules/Azure.AppGw.MigrateV2/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Application Gateways that pass this rule:
properties.sku.tier
or properties.sku.name
to Standard_v2
(Application Gateway) or WAF_v2
(Web Application Firewall).For example:
Azure Bicep snippetresource appGw 'Microsoft.Network/applicationGateways@2022-07-01' = {\n name: \n location: location\n properties: {\n sku: {\n capacity: 2\n name: 'WAF_v2'\n tier: 'WAF_v2'\n }\n }\n}\n
","tags":["Azure.AppGw.MigrateV2","AZR-000376"]},{"location":"en/rules/Azure.AppGw.MigrateV2/#notes","title":"Notes","text":"This rule is applicable for both Application Gateways and Application Gateways with Web Application Firewall (WAF).
Not all existing features under the v1 SKUs are supported in the v2 SKUs. The v2 SKUs are not currently available in all regions.
","tags":["Azure.AppGw.MigrateV2","AZR-000376"]},{"location":"en/rules/Azure.AppGw.MigrateV2/#links","title":"Links","text":"Reliability \u00b7 Application Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Application Gateways should use a minimum of two instances.
","tags":["Azure.AppGw.MinInstance","AZR-000061"]},{"location":"en/rules/Azure.AppGw.MinInstance/#description","title":"Description","text":"Application Gateways should use two or more instances to be covered by the Service Level Agreement (SLA). By having two or more instances this allows the App Gateway to meet high availability requirements and reduce downtime.
","tags":["Azure.AppGw.MinInstance","AZR-000061"]},{"location":"en/rules/Azure.AppGw.MinInstance/#recommendation","title":"Recommendation","text":"When using Application Gateway v1 or v2 with auto-scaling disabled, specify the number of instances to be two or more. When auto-scaling is enabled with Application Gateway v2, configure the minimum number of instances to be two or more.
","tags":["Azure.AppGw.MinInstance","AZR-000061"]},{"location":"en/rules/Azure.AppGw.MinInstance/#examples","title":"Examples","text":"","tags":["Azure.AppGw.MinInstance","AZR-000061"]},{"location":"en/rules/Azure.AppGw.MinInstance/#configure-with-azure-template","title":"Configure with Azure template","text":"To set capacity for an Application gateway
Autoscaling:
autoscaleConfiguration.minCapacity
to any or all of 2
.Manual Scaling:
sku.capacitiy
to 2
or more.For example:
Azure Template snippet{\n \"name\": \"appGw-001\",\n \"type\": \"Microsoft.Network/applicationGateways\",\n \"apiVersion\": \"2019-09-01\",\n \"location\": \"[resourceGroup().location]\",\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ],\n \"properties\": {\n \"sku\": {\n \"capacity\": 2, // Manual Scale\n \"name\": \"WAF_v2\",\n \"tier\": \"WAF_v2\"\n },\n \"autoscaleConfiguration\": { //Autoscale\n \"minCapacity\": 2,\n \"maxCapacity\": 3\n },\n \"webApplicationFirewallConfiguration\": {\n \"enabled\": true,\n \"firewallMode\": \"Detection\",\n \"ruleSetType\": \"OWASP\",\n \"ruleSetVersion\": \"3.0\"\n }\n }\n}\n
","tags":["Azure.AppGw.MinInstance","AZR-000061"]},{"location":"en/rules/Azure.AppGw.MinInstance/#configure-with-bicep","title":"Configure with Bicep","text":"To set capacity for an Application gateway
Autoscaling:
autoscaleConfiguration.minCapacity
to any or all of 2
.Manual Scaling:
sku.capacitiy
to 2
or more.For example:
Azure Bicep snippetresource name_resource 'Microsoft.Network/applicationGateways@2019-09-01' = {\n name: 'appGw-001'\n location: location\n zones: [\n '1'\n '2'\n '3'\n ]\n properties: {\n sku: {\n capacity: 2 // Manual scale\n name: 'WAF_v2'\n tier: 'WAF_v2'\n }\n autoscaleConfiguration: { // Autoscale\n minCapacity: 1\n maxCapacity: 2\n }\n webApplicationFirewallConfiguration: {\n enabled: true\n firewallMode: 'Detection'\n ruleSetType: 'OWASP'\n ruleSetVersion: '3.0'\n }\n }\n}\n
","tags":["Azure.AppGw.MinInstance","AZR-000061"]},{"location":"en/rules/Azure.AppGw.MinInstance/#links","title":"Links","text":"Operational Excellence \u00b7 Application Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Application Gateway should use a minimum instance size of Medium.
","tags":["Azure.AppGw.MinSku","AZR-000062"]},{"location":"en/rules/Azure.AppGw.MinSku/#description","title":"Description","text":"An Application Gateway is offered in different versions v1 and v2. When deploying an Application Gateway v1, three different instance sizes are available: Small, Medium and Large.
Application Gateway v2, Standard_v2 and WAF_v2 SKUs don't offer different instance sizes.
","tags":["Azure.AppGw.MinSku","AZR-000062"]},{"location":"en/rules/Azure.AppGw.MinSku/#recommendation","title":"Recommendation","text":"Application Gateways using v1 SKUs should be deployed with an instance size of Medium or Large. Small instance sizes are intended for development and testing scenarios.
","tags":["Azure.AppGw.MinSku","AZR-000062"]},{"location":"en/rules/Azure.AppGw.MinSku/#examples","title":"Examples","text":"","tags":["Azure.AppGw.MinSku","AZR-000062"]},{"location":"en/rules/Azure.AppGw.MinSku/#configure-with-azure-template","title":"Configure with Azure template","text":"To set the instance size for an Application Gateway V1:
properties.sku.name
to Standard_Medium
or Standard_Large
.For example:
Azure Template snippet{\n\n \"name\": \"appGw-001\",\n \"type\": \"Microsoft.Network/applicationGateways\",\n \"apiVersion\": \"2019-09-01\",\n \"location\": \"[resourceGroup().location]\",\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ],\n \"tags\": {},\n \"properties\": {\n \"sku\": {\n \"capacity\": 2,\n \"name\": \"Standard_Large\",\n \"tier\": \"Standard\"\n },\n \"enableHttp2\": false\n }\n\n}\n
","tags":["Azure.AppGw.MinSku","AZR-000062"]},{"location":"en/rules/Azure.AppGw.MinSku/#configure-with-bicep","title":"Configure with Bicep","text":"To set the instance size for an Application Gateway V1:
properties.sku.name
to Standard_Medium
or Standard_Large
.For example:
Azure Bicep snippetresource name_resource 'Microsoft.Network/applicationGateways@2019-09-01' = {\n name: 'appGw-001'\n location: location\n zones: [\n '1'\n '2'\n '3'\n ]\n tags: {}\n properties: {\n sku: {\n capacity: 2\n name: 'Standard_Large'\n tier: 'Standard'\n }\n enableHttp2: false\n }\n}\n
","tags":["Azure.AppGw.MinSku","AZR-000062"]},{"location":"en/rules/Azure.AppGw.MinSku/#links","title":"Links","text":"Operational Excellence \u00b7 Application Gateway \u00b7 Rule \u00b7 2022_12 \u00b7 Awareness
Application Gateways should meet naming requirements.
","tags":["Azure.AppGw.Name","AZR-000348"]},{"location":"en/rules/Azure.AppGw.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Application Gateway names are:
Consider using names that meet Application Gateway naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.AppGw.Name","AZR-000348"]},{"location":"en/rules/Azure.AppGw.Name/#notes","title":"Notes","text":"This rule does not check if Application Gateways names are unique.
","tags":["Azure.AppGw.Name","AZR-000348"]},{"location":"en/rules/Azure.AppGw.Name/#links","title":"Links","text":"Security \u00b7 Application Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules.
","tags":["Azure.AppGw.OWASP","AZR-000067"]},{"location":"en/rules/Azure.AppGw.OWASP/#description","title":"Description","text":"Application Gateways deployed with WAF features support configuration of OWASP rule sets for detection and / or prevention of malicious attacks. Two rule set versions are available; OWASP 2.x and OWASP 3.x.
","tags":["Azure.AppGw.OWASP","AZR-000067"]},{"location":"en/rules/Azure.AppGw.OWASP/#recommendation","title":"Recommendation","text":"Consider configuring Application Gateways to use OWASP 3.x rules instead of 2.x rule set versions.
","tags":["Azure.AppGw.OWASP","AZR-000067"]},{"location":"en/rules/Azure.AppGw.OWASP/#examples","title":"Examples","text":"","tags":["Azure.AppGw.OWASP","AZR-000067"]},{"location":"en/rules/Azure.AppGw.OWASP/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Application Gateways that pass this rule:
properties.webApplicationFirewallConfiguration.ruleSetType
property to OWASP
.properties.webApplicationFirewallConfiguration.ruleSetVersion
property to a minimum of 3.2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/applicationGateways\",\n \"apiVersion\": \"2020-11-01\",\n \"name\": \"appGw-001\",\n \"location\": \"[resourceGroup().location]\",\n \"properties\": {\n \"sku\": {\n \"name\": \"WAF_v2\",\n \"tier\": \"WAF_v2\"\n },\n \"webApplicationFirewallConfiguration\": {\n \"enabled\": true,\n \"firewallMode\": \"Prevention\",\n \"ruleSetType\": \"OWASP\",\n \"ruleSetVersion\": \"3.2\",\n \"disabledRuleGroups\": [],\n \"requestBodyCheck\": true,\n \"maxRequestBodySizeInKb\": 128,\n \"fileUploadLimitInMb\": 100\n }\n }\n}\n
","tags":["Azure.AppGw.OWASP","AZR-000067"]},{"location":"en/rules/Azure.AppGw.OWASP/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Application Gateways that pass this rule:
properties.webApplicationFirewallConfiguration.ruleSetType
property to OWASP
.properties.webApplicationFirewallConfiguration.ruleSetVersion
property to a minimum of 3.2
.For example:
Azure Bicep snippetresource appGw 'Microsoft.Network/applicationGateways@2021-02-01' = {\n name: 'appGw-001'\n location: location\n properties: {\n sku: {\n name: 'WAF_v2'\n tier: 'WAF_v2'\n }\n webApplicationFirewallConfiguration: {\n enabled: true\n firewallMode: 'Prevention'\n ruleSetType: 'OWASP'\n ruleSetVersion: '3.2'\n }\n }\n}\n
","tags":["Azure.AppGw.OWASP","AZR-000067"]},{"location":"en/rules/Azure.AppGw.OWASP/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz network application-gateway waf-config set --enabled true --rule-set-type OWASP --rule-set-version '3.2' -n '<name>' -g '<resource_group>'\n
","tags":["Azure.AppGw.OWASP","AZR-000067"]},{"location":"en/rules/Azure.AppGw.OWASP/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippet$AppGw = Get-AzApplicationGateway -Name '<name>' -ResourceGroupName '<resource_group>'\nSet-AzApplicationGatewayWebApplicationFirewallConfiguration -ApplicationGateway $AppGw -Enabled $True -FirewallMode 'Prevention' -RuleSetType 'OWASP' -RuleSetVersion '3.2'\n
","tags":["Azure.AppGw.OWASP","AZR-000067"]},{"location":"en/rules/Azure.AppGw.OWASP/#links","title":"Links","text":"Security \u00b7 Application Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Internet exposed Application Gateways should use prevention mode to protect backend resources.
","tags":["Azure.AppGw.Prevention","AZR-000065"]},{"location":"en/rules/Azure.AppGw.Prevention/#description","title":"Description","text":"Application Gateways with Web Application Firewall (WAF) enabled support two modes of operation:
Consider switching Internet exposed Application Gateways to use prevention mode to protect backend resources.
","tags":["Azure.AppGw.Prevention","AZR-000065"]},{"location":"en/rules/Azure.AppGw.Prevention/#examples","title":"Examples","text":"","tags":["Azure.AppGw.Prevention","AZR-000065"]},{"location":"en/rules/Azure.AppGw.Prevention/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Application Gateways that pass this rule:
properties.webApplicationFirewallConfiguration.firewallMode
property to Prevention
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/applicationGateways\",\n \"apiVersion\": \"2020-11-01\",\n \"name\": \"appGw-001\",\n \"location\": \"[resourceGroup().location]\",\n \"properties\": {\n \"sku\": {\n \"name\": \"WAF_v2\",\n \"tier\": \"WAF_v2\"\n },\n \"webApplicationFirewallConfiguration\": {\n \"enabled\": true,\n \"firewallMode\": \"Prevention\",\n \"ruleSetType\": \"OWASP\",\n \"ruleSetVersion\": \"3.2\",\n \"disabledRuleGroups\": [],\n \"requestBodyCheck\": true,\n \"maxRequestBodySizeInKb\": 128,\n \"fileUploadLimitInMb\": 100\n }\n }\n}\n
","tags":["Azure.AppGw.Prevention","AZR-000065"]},{"location":"en/rules/Azure.AppGw.Prevention/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Application Gateways that pass this rule:
properties.webApplicationFirewallConfiguration.firewallMode
property to Prevention
.For example:
Azure Bicep snippetresource name_resource 'Microsoft.Network/applicationGateways@2019-09-01' = {\n name: 'appGw-001'\n location: location\n properties: {\n sku: {\n name: 'WAF_v2'\n tier: 'WAF_v2'\n }\n webApplicationFirewallConfiguration: {\n enabled: true\n firewallMode: 'Prevention'\n ruleSetType: 'OWASP'\n ruleSetVersion: '3.2'\n disabledRuleGroups: []\n requestBodyCheck: true\n maxRequestBodySizeInKb: 128\n fileUploadLimitInMb: 100\n }\n }\n}\n
","tags":["Azure.AppGw.Prevention","AZR-000065"]},{"location":"en/rules/Azure.AppGw.Prevention/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz network application-gateway waf-config set --enabled true --firewall-mode Prevention -n '<name>' -g '<resource_group>'\n
","tags":["Azure.AppGw.Prevention","AZR-000065"]},{"location":"en/rules/Azure.AppGw.Prevention/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippet$AppGw = Get-AzApplicationGateway -Name '<name>' -ResourceGroupName '<resource_group>'\nSet-AzApplicationGatewayWebApplicationFirewallConfiguration -ApplicationGateway $AppGw -Enabled $True -FirewallMode 'Prevention'\n
","tags":["Azure.AppGw.Prevention","AZR-000065"]},{"location":"en/rules/Azure.AppGw.Prevention/#links","title":"Links","text":"Security \u00b7 Application Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Application Gateway should only accept a minimum of TLS 1.2.
","tags":["Azure.AppGw.SSLPolicy","AZR-000064"]},{"location":"en/rules/Azure.AppGw.SSLPolicy/#description","title":"Description","text":"The minimum version of TLS that Application Gateways accept is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Azure lets you disable outdated protocols and require connections to use a minimum of TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 is accepted.
Application Gateway should only accept a minimum of TLS 1.2 to ensure secure connections.
","tags":["Azure.AppGw.SSLPolicy","AZR-000064"]},{"location":"en/rules/Azure.AppGw.SSLPolicy/#recommendation","title":"Recommendation","text":"Consider configuring Application Gateways to accept a minimum of TLS 1.2.
","tags":["Azure.AppGw.SSLPolicy","AZR-000064"]},{"location":"en/rules/Azure.AppGw.SSLPolicy/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Application Gateways that pass this rule use a predefined or custom policy:
properties.sslPolicy.policyType
property to Custom
.properties.sslPolicy.minProtocolVersion
property to TLSv1_2
.properties.sslPolicy.cipherSuites
property to a list of supported ciphers. For example:TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
properties.sslPolicy.policyType
property to Predefined
.properties.sslPolicy.policyName
property to a supported predefined policy such as AppGwSslPolicy20220101S
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/applicationGateways\",\n \"apiVersion\": \"2023-09-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ],\n \"properties\": {\n \"sku\": {\n \"name\": \"WAF_v2\",\n \"tier\": \"WAF_v2\"\n },\n \"sslPolicy\": {\n \"policyType\": \"Custom\",\n \"minProtocolVersion\": \"TLSv1_2\",\n \"cipherSuites\": [\n \"TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384\",\n \"TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256\",\n \"TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384\",\n \"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256\"\n ]\n }\n }\n}\n
","tags":["Azure.AppGw.SSLPolicy","AZR-000064"]},{"location":"en/rules/Azure.AppGw.SSLPolicy/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Application Gateways that pass this rule use a predefined or custom policy:
properties.sslPolicy.policyType
property to Custom
.properties.sslPolicy.minProtocolVersion
property to TLSv1_2
.properties.sslPolicy.cipherSuites
property to a list of supported ciphers. For example:TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
properties.sslPolicy.policyType
property to Predefined
.properties.sslPolicy.policyName
property to a supported predefined policy such as AppGwSslPolicy20220101S
.For example:
Azure Bicep snippetresource app_gw 'Microsoft.Network/applicationGateways@2023-09-01' = {\n name: name\n location: location\n zones: [\n '1'\n '2'\n '3'\n ]\n properties: {\n sku: {\n name: 'WAF_v2'\n tier: 'WAF_v2'\n }\n sslPolicy: {\n policyType: 'Custom'\n minProtocolVersion: 'TLSv1_2'\n cipherSuites: [\n 'TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384'\n 'TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256'\n 'TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384'\n 'TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256'\n ]\n }\n }\n}\n
","tags":["Azure.AppGw.SSLPolicy","AZR-000064"]},{"location":"en/rules/Azure.AppGw.SSLPolicy/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippet$gw = Get-AzApplicationGateway -Name '<name>' -ResourceGroupName '<resource_group>'\nSet-AzApplicationGatewaySslPolicy -ApplicationGateway $gw -PolicyType Custom -MinProtocolVersion TLSv1_2 -CipherSuite 'TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384', 'TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256', 'TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384', 'TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256'\n
","tags":["Azure.AppGw.SSLPolicy","AZR-000064"]},{"location":"en/rules/Azure.AppGw.SSLPolicy/#links","title":"Links","text":"Security \u00b7 Application Gateway \u00b7 Rule \u00b7 2021_09 \u00b7 Critical
Application Gateways should only expose frontend HTTP endpoints over HTTPS.
","tags":["Azure.AppGw.UseHTTPS","AZR-000059"]},{"location":"en/rules/Azure.AppGw.UseHTTPS/#description","title":"Description","text":"Application Gateways support HTTP and HTTPS endpoints for backend and frontend traffic. When using frontend HTTP (80
) endpoints, traffic between client and Application Gateway is not encrypted.
Unencrypted communication could allow disclosure of information to an un-trusted party.
","tags":["Azure.AppGw.UseHTTPS","AZR-000059"]},{"location":"en/rules/Azure.AppGw.UseHTTPS/#recommendation","title":"Recommendation","text":"Consider configuring Application Gateways to only expose HTTPS endpoints. For client applications such as progressive web apps, consider redirecting HTTP traffic to HTTPS.
","tags":["Azure.AppGw.UseHTTPS","AZR-000059"]},{"location":"en/rules/Azure.AppGw.UseHTTPS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Application Gateways that pass this rule:
properties.frontendPorts.properties.port
property to 443
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/applicationGateways\",\n \"apiVersion\": \"2023-09-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ],\n \"properties\": {\n \"sku\": {\n \"name\": \"WAF_v2\",\n \"tier\": \"WAF_v2\"\n },\n \"sslPolicy\": {\n \"policyType\": \"Custom\",\n \"minProtocolVersion\": \"TLSv1_2\",\n \"cipherSuites\": [\n \"TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384\",\n \"TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256\",\n \"TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384\",\n \"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256\"\n ]\n },\n \"frontendPorts\": [\n {\n \"name\": \"https\",\n \"properties\": {\n \"Port\": 443\n }\n }\n ]\n }\n}\n
","tags":["Azure.AppGw.UseHTTPS","AZR-000059"]},{"location":"en/rules/Azure.AppGw.UseHTTPS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Application Gateways that pass this rule:
properties.frontendPorts.properties.port
property to 443
.For example:
Azure Bicep snippetresource app_gw 'Microsoft.Network/applicationGateways@2023-09-01' = {\n name: name\n location: location\n zones: [\n '1'\n '2'\n '3'\n ]\n properties: {\n sku: {\n name: 'WAF_v2'\n tier: 'WAF_v2'\n }\n sslPolicy: {\n policyType: 'Custom'\n minProtocolVersion: 'TLSv1_2'\n cipherSuites: [\n 'TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384'\n 'TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256'\n 'TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384'\n 'TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256'\n ]\n }\n frontendPorts: [\n {\n name: 'https'\n properties: {\n Port: 443\n }\n }\n ]\n }\n}\n
","tags":["Azure.AppGw.UseHTTPS","AZR-000059"]},{"location":"en/rules/Azure.AppGw.UseHTTPS/#links","title":"Links","text":"Security \u00b7 Application Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Internet accessible Application Gateways should use protect endpoints with WAF.
","tags":["Azure.AppGw.UseWAF","AZR-000063"]},{"location":"en/rules/Azure.AppGw.UseWAF/#description","title":"Description","text":"Application Gateway endpoints can optionally be configured with a Web Application Firewall (WAF) policy. When configured, every incoming request is filtered by the WAF policy.
To use a WAF policy, the Application Gateway must be deployed with a Web Application Firewall SKU.
","tags":["Azure.AppGw.UseWAF","AZR-000063"]},{"location":"en/rules/Azure.AppGw.UseWAF/#recommendation","title":"Recommendation","text":"Consider deploying Application Gateways with a WAF SKU to protect against common attacks.
","tags":["Azure.AppGw.UseWAF","AZR-000063"]},{"location":"en/rules/Azure.AppGw.UseWAF/#examples","title":"Examples","text":"","tags":["Azure.AppGw.UseWAF","AZR-000063"]},{"location":"en/rules/Azure.AppGw.UseWAF/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Application Gateways that pass this rule:
WAF
or WAF_v2
SKU.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/applicationGateways\",\n \"apiVersion\": \"2020-11-01\",\n \"name\": \"appGw-001\",\n \"location\": \"[resourceGroup().location]\",\n \"properties\": {\n \"sku\": {\n \"name\": \"WAF_v2\",\n \"tier\": \"WAF_v2\"\n },\n \"webApplicationFirewallConfiguration\": {\n \"enabled\": true,\n \"firewallMode\": \"Prevention\",\n \"ruleSetType\": \"OWASP\",\n \"ruleSetVersion\": \"3.2\",\n \"disabledRuleGroups\": [],\n \"requestBodyCheck\": true,\n \"maxRequestBodySizeInKb\": 128,\n \"fileUploadLimitInMb\": 100\n }\n }\n}\n
","tags":["Azure.AppGw.UseWAF","AZR-000063"]},{"location":"en/rules/Azure.AppGw.UseWAF/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Application Gateways that pass this rule:
WAF
or WAF_v2
SKU.For example:
Azure Bicep snippetresource appGw 'Microsoft.Network/applicationGateways@2021-02-01' = {\n name: 'appGw-001'\n location: location\n properties: {\n sku: {\n name: 'WAF_v2'\n tier: 'WAF_v2'\n }\n webApplicationFirewallConfiguration: {\n enabled: true\n firewallMode: 'Prevention'\n ruleSetType: 'OWASP'\n ruleSetVersion: '3.2'\n }\n }\n}\n
","tags":["Azure.AppGw.UseWAF","AZR-000063"]},{"location":"en/rules/Azure.AppGw.UseWAF/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz network application-gateway update --sku WAF_v2 -n '<name>' -g '<resource_group>'\n
","tags":["Azure.AppGw.UseWAF","AZR-000063"]},{"location":"en/rules/Azure.AppGw.UseWAF/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippet$AppGw = Get-AzApplicationGateway -Name '<name>' -ResourceGroupName '<resource_group>'\n$AppGw = Set-AzApplicationGatewaySku -ApplicationGateway $AppGw -Name 'WAF_v2' -Tier 'WAF_v2'\n
","tags":["Azure.AppGw.UseWAF","AZR-000063"]},{"location":"en/rules/Azure.AppGw.UseWAF/#links","title":"Links","text":"Security \u00b7 Application Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources.
","tags":["Azure.AppGw.WAFEnabled","AZR-000066"]},{"location":"en/rules/Azure.AppGw.WAFEnabled/#description","title":"Description","text":"Security features of Application Gateways deployed with WAF may be toggled on or off.
When WAF is disabled network traffic is still processed by the Application Gateway however detection and/ or prevention of malicious attacks does not occur.
To protect backend resources from potentially malicious network traffic, WAF must be enabled.
","tags":["Azure.AppGw.WAFEnabled","AZR-000066"]},{"location":"en/rules/Azure.AppGw.WAFEnabled/#recommendation","title":"Recommendation","text":"Consider enabling WAF for Application Gateway instances connected to un-trusted or low-trust networks such as the Internet.
","tags":["Azure.AppGw.WAFEnabled","AZR-000066"]},{"location":"en/rules/Azure.AppGw.WAFEnabled/#examples","title":"Examples","text":"","tags":["Azure.AppGw.WAFEnabled","AZR-000066"]},{"location":"en/rules/Azure.AppGw.WAFEnabled/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Application Gateways that pass this rule:
properties.webApplicationFirewallConfiguration.enabled
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/applicationGateways\",\n \"apiVersion\": \"2020-11-01\",\n \"name\": \"appGw-001\",\n \"location\": \"[resourceGroup().location]\",\n \"properties\": {\n \"sku\": {\n \"name\": \"WAF_v2\",\n \"tier\": \"WAF_v2\"\n },\n \"webApplicationFirewallConfiguration\": {\n \"enabled\": true,\n \"firewallMode\": \"Prevention\",\n \"ruleSetType\": \"OWASP\",\n \"ruleSetVersion\": \"3.2\",\n \"disabledRuleGroups\": [],\n \"requestBodyCheck\": true,\n \"maxRequestBodySizeInKb\": 128,\n \"fileUploadLimitInMb\": 100\n }\n }\n}\n
","tags":["Azure.AppGw.WAFEnabled","AZR-000066"]},{"location":"en/rules/Azure.AppGw.WAFEnabled/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Application Gateways that pass this rule:
properties.webApplicationFirewallConfiguration.enabled
property to true
.For example:
Azure Bicep snippetresource appGw 'Microsoft.Network/applicationGateways@2021-02-01' = {\n name: 'appGw-001'\n location: location\n properties: {\n sku: {\n name: 'WAF_v2'\n tier: 'WAF_v2'\n }\n webApplicationFirewallConfiguration: {\n enabled: true\n firewallMode: 'Prevention'\n ruleSetType: 'OWASP'\n ruleSetVersion: '3.2'\n }\n }\n}\n
","tags":["Azure.AppGw.WAFEnabled","AZR-000066"]},{"location":"en/rules/Azure.AppGw.WAFEnabled/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz network application-gateway waf-config set --enabled true -n '<name>' -g '<resource_group>'\n
","tags":["Azure.AppGw.WAFEnabled","AZR-000066"]},{"location":"en/rules/Azure.AppGw.WAFEnabled/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippet$AppGw = Get-AzApplicationGateway -Name '<name>' -ResourceGroupName '<resource_group>'\nSet-AzApplicationGatewayWebApplicationFirewallConfiguration -ApplicationGateway $AppGw -Enabled $True -FirewallMode 'Prevention'\n
","tags":["Azure.AppGw.WAFEnabled","AZR-000066"]},{"location":"en/rules/Azure.AppGw.WAFEnabled/#links","title":"Links","text":"Security \u00b7 Application Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Application Gateway Web Application Firewall (WAF) should have all rules enabled.
","tags":["Azure.AppGw.WAFRules","AZR-000068"]},{"location":"en/rules/Azure.AppGw.WAFRules/#description","title":"Description","text":"Application Gateway instances with WAF allow OWASP detection/ prevention rules to be toggled on or off. All OWASP rules are turned on by default.
When OWASP rules are turned off, the protection they provide is disabled.
","tags":["Azure.AppGw.WAFRules","AZR-000068"]},{"location":"en/rules/Azure.AppGw.WAFRules/#recommendation","title":"Recommendation","text":"Consider enabling all OWASP rules within Application Gateway instances.
Before disabling OWASP rules, ensure that the backend workload has alternative protections in-place. Alternatively consider updating application code to use safe web standards.
","tags":["Azure.AppGw.WAFRules","AZR-000068"]},{"location":"en/rules/Azure.AppGw.WAFRules/#examples","title":"Examples","text":"","tags":["Azure.AppGw.WAFRules","AZR-000068"]},{"location":"en/rules/Azure.AppGw.WAFRules/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Application Gateways that pass this rule:
properties.webApplicationFirewallConfiguration.disabledRuleGroups.ruleGroupName
property to $ruleName
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/applicationGateways\",\n \"apiVersion\": \"2020-11-01\",\n \"name\": \"appGw-001\",\n \"location\": \"[resourceGroup().location]\",\n \"properties\": {\n \"sku\": {\n \"name\": \"WAF_v2\",\n \"tier\": \"WAF_v2\"\n },\n \"webApplicationFirewallConfiguration\": {\n \"enabled\": true,\n \"firewallMode\": \"Prevention\",\n \"ruleSetType\": \"OWASP\",\n \"ruleSetVersion\": \"3.2\",\n \"disabledRuleGroups\": [\n {\n \"ruleGroupName\": \"exampleRule\",\n \"rules\": []\n }\n ],\n \"requestBodyCheck\": true,\n \"maxRequestBodySizeInKb\": 128,\n \"fileUploadLimitInMb\": 100\n }\n }\n}\n
","tags":["Azure.AppGw.WAFRules","AZR-000068"]},{"location":"en/rules/Azure.AppGw.WAFRules/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Application Gateways that pass this rule:
properties.webApplicationFirewallConfiguration.enabled
property to true
.For example:
Azure Bicep snippetresource appGw 'Microsoft.Network/applicationGateways@2021-02-01' = {\n name: 'appGw-001'\n location: location\n properties: {\n sku: {\n name: 'WAF_v2'\n tier: 'WAF_v2'\n }\n webApplicationFirewallConfiguration: {\n enabled: true\n firewallMode: 'Prevention'\n ruleSetType: 'OWASP'\n ruleSetVersion: '3.2'\n disabledRuleGroups: [\n {\n ruleGroupName: 'exampleRule',\n rules: []\n }\n ]\n }\n }\n}\n
","tags":["Azure.AppGw.WAFRules","AZR-000068"]},{"location":"en/rules/Azure.AppGw.WAFRules/#links","title":"Links","text":"Security \u00b7 Application Gateway \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources.
","tags":["Azure.AppGwWAF.Enabled","AZR-000309"]},{"location":"en/rules/Azure.AppGwWAF.Enabled/#description","title":"Description","text":"Security features of Application Gateways deployed with WAF may be toggled on or off.
When WAF is disabled network traffic is still processed by the Application Gateway however detection and/ or prevention of malicious attacks does not occur.
To protect backend resources from potentially malicious network traffic, WAF must be enabled.
","tags":["Azure.AppGwWAF.Enabled","AZR-000309"]},{"location":"en/rules/Azure.AppGwWAF.Enabled/#recommendation","title":"Recommendation","text":"Consider enabling WAF for Application Gateway instances connected to un-trusted or low-trust networks such as the Internet.
","tags":["Azure.AppGwWAF.Enabled","AZR-000309"]},{"location":"en/rules/Azure.AppGwWAF.Enabled/#examples","title":"Examples","text":"","tags":["Azure.AppGwWAF.Enabled","AZR-000309"]},{"location":"en/rules/Azure.AppGwWAF.Enabled/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Application Gateways that pass this rule:
properties.policySettings.state
property to Enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies\",\n \"apiVersion\": \"2022-01-01\",\n \"name\": \"agwwaf\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"managedRules\": {\n \"managedRuleSets\": [\n {\n \"ruleSetType\": \"OWASP\",\n \"ruleSetVersion\": \"3.2\"\n },\n {\n \"ruleSetType\": \"Microsoft_BotManagerRuleSet\",\n \"ruleSetVersion\": \"0.1\"\n }\n ]\n },\n \"policySettings\": {\n \"state\": \"Enabled\",\n \"mode\": \"Prevention\"\n }\n }\n}\n
","tags":["Azure.AppGwWAF.Enabled","AZR-000309"]},{"location":"en/rules/Azure.AppGwWAF.Enabled/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Application Gateways that pass this rule:
properties.policySettings.state
property to Enabled
.For example:
Azure Bicep snippetresource waf 'Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies@2022-01-01' = {\n name: 'agwwaf'\n location: location\n properties: {\n managedRules: {\n managedRuleSets: [\n {\n ruleSetType: 'OWASP'\n ruleSetVersion: '3.2'\n }\n {\n ruleSetType: 'Microsoft_BotManagerRuleSet'\n ruleSetVersion: '0.1'\n }\n ]\n }\n policySettings: {\n state: 'Enabled'\n mode: 'Prevention'\n }\n }\n}\n
","tags":["Azure.AppGwWAF.Enabled","AZR-000309"]},{"location":"en/rules/Azure.AppGwWAF.Enabled/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz network application-gateway waf-config set --enabled true -n '<name>' -g '<resource_group>'\n
","tags":["Azure.AppGwWAF.Enabled","AZR-000309"]},{"location":"en/rules/Azure.AppGwWAF.Enabled/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippet$AppGw = Get-AzApplicationGateway -Name '<name>' -ResourceGroupName '<resource_group>'\nSet-AzApplicationGatewayWebApplicationFirewallConfiguration -ApplicationGateway $AppGw -Enabled $True -FirewallMode 'Prevention'\n
","tags":["Azure.AppGwWAF.Enabled","AZR-000309"]},{"location":"en/rules/Azure.AppGwWAF.Enabled/#links","title":"Links","text":"Security \u00b7 Application Gateway \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Application Gateway Web Application Firewall (WAF) should have all rules enabled.
","tags":["Azure.AppGwWAF.Exclusions","AZR-000303"]},{"location":"en/rules/Azure.AppGwWAF.Exclusions/#description","title":"Description","text":"Application Gateway instances with WAF allow OWASP detection/ prevention rules to be toggled on or off. All OWASP rules are turned on by default.
When OWASP rules are turned off, the protection they provide is disabled.
","tags":["Azure.AppGwWAF.Exclusions","AZR-000303"]},{"location":"en/rules/Azure.AppGwWAF.Exclusions/#recommendation","title":"Recommendation","text":"Consider enabling all OWASP rules within Application Gateway instances.
Before disabling OWASP rules, ensure that the backend workload has alternative protections in-place. Alternatively consider updating application code to use safe web standards.
","tags":["Azure.AppGwWAF.Exclusions","AZR-000303"]},{"location":"en/rules/Azure.AppGwWAF.Exclusions/#links","title":"Links","text":"Security \u00b7 Application Gateway \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources.
","tags":["Azure.AppGwWAF.PreventionMode","AZR-000302"]},{"location":"en/rules/Azure.AppGwWAF.PreventionMode/#description","title":"Description","text":"Application Gateway WAF policies support two modes of operation, detection and prevention. By default, prevention is configured.
Consider setting Application Gateway WAF policy to use protection mode.
","tags":["Azure.AppGwWAF.PreventionMode","AZR-000302"]},{"location":"en/rules/Azure.AppGwWAF.PreventionMode/#links","title":"Links","text":"Security \u00b7 Application Gateway \u00b7 Rule \u00b7 2024_03 \u00b7 Critical
Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources.
","tags":["Azure.AppGwWAF.RuleGroups","AZR-000304"]},{"location":"en/rules/Azure.AppGwWAF.RuleGroups/#description","title":"Description","text":"Application Gateway WAF policies support two main Rule Groups.
Consider configuring Application Gateway WAF policy to use the recommended rule sets.
","tags":["Azure.AppGwWAF.RuleGroups","AZR-000304"]},{"location":"en/rules/Azure.AppGwWAF.RuleGroups/#links","title":"Links","text":"Operational Excellence \u00b7 Application Insights \u00b7 Rule \u00b7 2021_06 \u00b7 Awareness
Azure Application Insights resources names should meet naming requirements.
","tags":["Azure.AppInsights.Name","AZR-000070"]},{"location":"en/rules/Azure.AppInsights.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Application Insights resource names are:
Consider using names that meet Application Insights resource naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.AppInsights.Name","AZR-000070"]},{"location":"en/rules/Azure.AppInsights.Name/#notes","title":"Notes","text":"This rule does not check if Application Insights resource names are unique.
","tags":["Azure.AppInsights.Name","AZR-000070"]},{"location":"en/rules/Azure.AppInsights.Name/#links","title":"Links","text":"Operational Excellence \u00b7 Application Insights \u00b7 Rule \u00b7 2021_06 \u00b7 Important
Configure Application Insights resources to store data in workspaces.
","tags":["Azure.AppInsights.Workspace","AZR-000069"]},{"location":"en/rules/Azure.AppInsights.Workspace/#description","title":"Description","text":"Application Insights (App Insights) can be deployed as either classic or workspace-based resources. When configured as workspace-based, telemetry is sent from App Insights to a common Log Analytics workspace.
Using a Log Analytics workspace for App Insights:
App Insights resources can be configured as workspace-based either during or after initial deployment.
","tags":["Azure.AppInsights.Workspace","AZR-000069"]},{"location":"en/rules/Azure.AppInsights.Workspace/#recommendation","title":"Recommendation","text":"Consider using workspace-based Application Insights resources to collect telemetry in shared storage.
","tags":["Azure.AppInsights.Workspace","AZR-000069"]},{"location":"en/rules/Azure.AppInsights.Workspace/#examples","title":"Examples","text":"","tags":["Azure.AppInsights.Workspace","AZR-000069"]},{"location":"en/rules/Azure.AppInsights.Workspace/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Application Insights resources that pass this rule:
properties.WorkspaceResourceId
property to a valid Log Analytics workspace.For example:
Azure Template snippet{\n \"type\": \"microsoft.insights/components\",\n \"apiVersion\": \"2020-02-02\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"kind\": \"web\",\n \"properties\": {\n \"Application_Type\": \"web\",\n \"Flow_Type\": \"Redfield\",\n \"Request_Source\": \"IbizaAIExtension\",\n \"WorkspaceResourceId\": \"[parameters('workspaceId')]\"\n }\n}\n
","tags":["Azure.AppInsights.Workspace","AZR-000069"]},{"location":"en/rules/Azure.AppInsights.Workspace/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Application Insights resources that pass this rule:
properties.WorkspaceResourceId
property to a valid Log Analytics workspace.For example:
Azure Bicep snippetresource appInsights 'Microsoft.Insights/components@2020-02-02' = {\n name: name\n location: location\n kind: 'web'\n properties: {\n Application_Type: 'web'\n Flow_Type: 'Redfield'\n Request_Source: 'IbizaAIExtension'\n WorkspaceResourceId: workspaceId\n }\n}\n
","tags":["Azure.AppInsights.Workspace","AZR-000069"]},{"location":"en/rules/Azure.AppInsights.Workspace/#links","title":"Links","text":"Performance Efficiency \u00b7 App Service \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Disable client affinity for stateless services.
","tags":["Azure.AppService.ARRAffinity","AZR-000083"]},{"location":"en/rules/Azure.AppService.ARRAffinity/#description","title":"Description","text":"Azure App Service apps use Application Request Routing (ARR) by default. ARR uses a cookie to route subsequent client requests back to the same instance when an app is scaled to two or more instances. This benefits stateful applications, which may hold session information in instance memory.
For stateless applications, disabling ARR allows Azure App Service more evenly distribute load.
","tags":["Azure.AppService.ARRAffinity","AZR-000083"]},{"location":"en/rules/Azure.AppService.ARRAffinity/#recommendation","title":"Recommendation","text":"Azure App Service sites make use of Application Request Routing (ARR) by default. Consider disabling ARR affinity for stateless applications.
","tags":["Azure.AppService.ARRAffinity","AZR-000083"]},{"location":"en/rules/Azure.AppService.ARRAffinity/#links","title":"Links","text":"Reliability \u00b7 App Service \u00b7 Rule \u00b7 2020_12 \u00b7 Important
Configure Always On for App Service apps.
","tags":["Azure.AppService.AlwaysOn","AZR-000077"]},{"location":"en/rules/Azure.AppService.AlwaysOn/#description","title":"Description","text":"Azure App Service apps are automatically unloaded when there's no traffic. Unloading apps reduces resource consumption when apps share a single App Services Plan. After an app have been unloaded, the next web request will trigger a cold start of the app. A cold start of the app can cause request timeouts.
Web apps using continuous WebJobs or WebJobs triggered with a CRON expression must use always on to start.
","tags":["Azure.AppService.AlwaysOn","AZR-000077"]},{"location":"en/rules/Azure.AppService.AlwaysOn/#recommendation","title":"Recommendation","text":"Consider enabling Always On for each App Services app.
","tags":["Azure.AppService.AlwaysOn","AZR-000077"]},{"location":"en/rules/Azure.AppService.AlwaysOn/#examples","title":"Examples","text":"","tags":["Azure.AppService.AlwaysOn","AZR-000077"]},{"location":"en/rules/Azure.AppService.AlwaysOn/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy App Services that pass this rule:
properties.siteConfig.alwaysOn
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/sites\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"kind\": \"web\",\n \"properties\": {\n \"serverFarmId\": \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\",\n \"httpsOnly\": true,\n \"siteConfig\": {\n \"alwaysOn\": true,\n \"minTlsVersion\": \"1.2\",\n \"ftpsState\": \"Disabled\",\n \"remoteDebuggingEnabled\": false,\n \"http20Enabled\": true,\n \"netFrameworkVersion\": \"v8.0\",\n \"healthCheckPath\": \"/healthz\",\n \"metadata\": [\n {\n \"name\": \"CURRENT_STACK\",\n \"value\": \"dotnet\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\"\n ]\n}\n
","tags":["Azure.AppService.AlwaysOn","AZR-000077"]},{"location":"en/rules/Azure.AppService.AlwaysOn/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Services that pass this rule:
properties.siteConfig.alwaysOn
property to true
.For example:
Azure Bicep snippetresource web 'Microsoft.Web/sites@2023-01-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n kind: 'web'\n properties: {\n serverFarmId: plan.id\n httpsOnly: true\n siteConfig: {\n alwaysOn: true\n minTlsVersion: '1.2'\n ftpsState: 'Disabled'\n remoteDebuggingEnabled: false\n http20Enabled: true\n netFrameworkVersion: 'v8.0'\n healthCheckPath: '/healthz'\n metadata: [\n {\n name: 'CURRENT_STACK'\n value: 'dotnet'\n }\n ]\n }\n }\n}\n
","tags":["Azure.AppService.AlwaysOn","AZR-000077"]},{"location":"en/rules/Azure.AppService.AlwaysOn/#notes","title":"Notes","text":"The Always On feature of App Service is not applicable to Azure Functions and Standard Logic Apps under most circumstances. To reduce false positives, this rule ignores apps based on Azure Functions and Standard Logic Apps.
When running in a Consumption Plan or Premium Plan you should not enable Always On. On a Consumption plan the platform activates function apps automatically. On a Premium plan the platform keeps your desired number of pre-warmed instances always on automatically.
","tags":["Azure.AppService.AlwaysOn","AZR-000077"]},{"location":"en/rules/Azure.AppService.AlwaysOn/#links","title":"Links","text":"Performance Efficiency \u00b7 App Service \u00b7 Rule \u00b7 2020_12 \u00b7 Awareness
Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency.
","tags":["Azure.AppService.HTTP2","AZR-000078"]},{"location":"en/rules/Azure.AppService.HTTP2/#description","title":"Description","text":"Azure App Service has native support for HTTP/2, but by default it is disabled. HTTP/2 offers a number of improvements over HTTP/1.1, including:
Consider using HTTP/2 for Azure Services apps to improve protocol efficiency.
","tags":["Azure.AppService.HTTP2","AZR-000078"]},{"location":"en/rules/Azure.AppService.HTTP2/#examples","title":"Examples","text":"","tags":["Azure.AppService.HTTP2","AZR-000078"]},{"location":"en/rules/Azure.AppService.HTTP2/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy App Services that pass this rule:
properties.siteConfig.http20Enabled
to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/sites\",\n \"apiVersion\": \"2021-02-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"kind\": \"web\",\n \"properties\": {\n \"serverFarmId\": \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\",\n \"httpsOnly\": true,\n \"siteConfig\": {\n \"alwaysOn\": true,\n \"minTlsVersion\": \"1.2\",\n \"ftpsState\": \"FtpsOnly\",\n \"remoteDebuggingEnabled\": false,\n \"http20Enabled\": true\n }\n },\n \"tags\": \"[parameters('tags')]\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\"\n ]\n}\n
","tags":["Azure.AppService.HTTP2","AZR-000078"]},{"location":"en/rules/Azure.AppService.HTTP2/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Services that pass this rule:
properties.siteConfig.http20Enabled
to true
.For example:
Azure Bicep snippetresource webApp 'Microsoft.Web/sites@2021-02-01' = {\n name: name\n location: location\n kind: 'web'\n properties: {\n serverFarmId: appPlan.id\n httpsOnly: true\n siteConfig: {\n alwaysOn: true\n minTlsVersion: '1.2'\n ftpsState: 'FtpsOnly'\n remoteDebuggingEnabled: false\n http20Enabled: true\n }\n }\n tags: tags\n}\n
","tags":["Azure.AppService.HTTP2","AZR-000078"]},{"location":"en/rules/Azure.AppService.HTTP2/#links","title":"Links","text":"Security \u00b7 App Service \u00b7 Rule \u00b7 2020_12 \u00b7 Important
Configure managed identities to access Azure resources.
","tags":["Azure.AppService.ManagedIdentity","AZR-000082"]},{"location":"en/rules/Azure.AppService.ManagedIdentity/#description","title":"Description","text":"Azure App Service apps must authenticate to Azure resources such as Azure SQL Databases. App Service can use managed identities to authenticate to Azure resource without storing credentials.
Using Azure managed identities have the following benefits:
Consider configuring a managed identity for each App Service app. Also consider using managed identities to authenticate to related Azure services.
","tags":["Azure.AppService.ManagedIdentity","AZR-000082"]},{"location":"en/rules/Azure.AppService.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.AppService.ManagedIdentity","AZR-000082"]},{"location":"en/rules/Azure.AppService.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy App Services that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/sites\",\n \"apiVersion\": \"2021-02-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"kind\": \"web\",\n \"properties\": {\n \"serverFarmId\": \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\",\n \"httpsOnly\": true,\n \"siteConfig\": {\n \"alwaysOn\": true,\n \"minTlsVersion\": \"1.2\",\n \"ftpsState\": \"FtpsOnly\",\n \"remoteDebuggingEnabled\": false,\n \"http20Enabled\": true\n }\n },\n \"tags\": \"[parameters('tags')]\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\"\n ]\n}\n
","tags":["Azure.AppService.ManagedIdentity","AZR-000082"]},{"location":"en/rules/Azure.AppService.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Services that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource webApp 'Microsoft.Web/sites@2021-02-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n kind: 'web'\n properties: {\n serverFarmId: plan.id\n httpsOnly: true\n siteConfig: {\n alwaysOn: true\n minTlsVersion: '1.2'\n ftpsState: 'FtpsOnly'\n remoteDebuggingEnabled: false\n http20Enabled: true\n }\n }\n tags: tags\n}\n
","tags":["Azure.AppService.ManagedIdentity","AZR-000082"]},{"location":"en/rules/Azure.AppService.ManagedIdentity/#links","title":"Links","text":"Performance Efficiency \u00b7 App Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use at least a Standard App Service Plan.
","tags":["Azure.AppService.MinPlan","AZR-000072"]},{"location":"en/rules/Azure.AppService.MinPlan/#description","title":"Description","text":"Azure App Services provide a range of different plans that can be used to scale your application. Each plan provides different levels of performance and features.
To get you started a number of entry level plans are available. The Free
, Shared
, and Basic
plans can be used for limited testing and development. However these plans are not suitable for production use. Production workloads are best suited to standard and premium plans with PremiumV3
the newest plan.
This rule does not apply to consumption or elastic App Services Plans used for Azure Functions.
","tags":["Azure.AppService.MinPlan","AZR-000072"]},{"location":"en/rules/Azure.AppService.MinPlan/#recommendation","title":"Recommendation","text":"Consider using a standard or premium plan for hosting apps on Azure App Service.
","tags":["Azure.AppService.MinPlan","AZR-000072"]},{"location":"en/rules/Azure.AppService.MinPlan/#examples","title":"Examples","text":"","tags":["Azure.AppService.MinPlan","AZR-000072"]},{"location":"en/rules/Azure.AppService.MinPlan/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy App Services Plans that pass this rule:
sku.tier
to a plan equal to or greater than Standard
. For example: PremiumV3
, PremiumV2
, Premium
, Standard
For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/serverfarms\",\n \"apiVersion\": \"2022-09-01\",\n \"name\": \"[parameters('planName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"S1\",\n \"tier\": \"Standard\",\n \"capacity\": 2\n }\n}\n
","tags":["Azure.AppService.MinPlan","AZR-000072"]},{"location":"en/rules/Azure.AppService.MinPlan/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Services Plans that pass this rule:
sku.tier
to a plan equal to or greater than Standard
. For example: PremiumV3
, PremiumV2
, Premium
, Standard
For example:
Azure Bicep snippetresource plan 'Microsoft.Web/serverfarms@2022-09-01' = {\n name: planName\n location: location\n sku: {\n name: 'S1'\n tier: 'Standard'\n capacity: 2\n }\n}\n
","tags":["Azure.AppService.MinPlan","AZR-000072"]},{"location":"en/rules/Azure.AppService.MinPlan/#links","title":"Links","text":"Security \u00b7 App Service \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
App Service should reject TLS versions older than 1.2.
","tags":["Azure.AppService.MinTLS","AZR-000073"]},{"location":"en/rules/Azure.AppService.MinTLS/#description","title":"Description","text":"The minimum version of TLS that Azure App Service accepts is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
App Service lets you disable outdated protocols and enforce TLS 1.2. By default, a minimum of TLS 1.2 is enforced.
","tags":["Azure.AppService.MinTLS","AZR-000073"]},{"location":"en/rules/Azure.AppService.MinTLS/#recommendation","title":"Recommendation","text":"Consider configuring the minimum supported TLS version to be 1.2. Also consider using Azure Policy to audit or enforce this configuration.
","tags":["Azure.AppService.MinTLS","AZR-000073"]},{"location":"en/rules/Azure.AppService.MinTLS/#examples","title":"Examples","text":"","tags":["Azure.AppService.MinTLS","AZR-000073"]},{"location":"en/rules/Azure.AppService.MinTLS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy App Services that pass this rule:
properties.siteConfig.minTlsVersion
property to 1.2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/sites\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"kind\": \"web\",\n \"properties\": {\n \"serverFarmId\": \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\",\n \"httpsOnly\": true,\n \"siteConfig\": {\n \"alwaysOn\": true,\n \"minTlsVersion\": \"1.2\",\n \"ftpsState\": \"Disabled\",\n \"remoteDebuggingEnabled\": false,\n \"http20Enabled\": true,\n \"netFrameworkVersion\": \"v8.0\",\n \"healthCheckPath\": \"/healthz\",\n \"metadata\": [\n {\n \"name\": \"CURRENT_STACK\",\n \"value\": \"dotnet\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\"\n ]\n}\n
","tags":["Azure.AppService.MinTLS","AZR-000073"]},{"location":"en/rules/Azure.AppService.MinTLS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Services that pass this rule:
properties.siteConfig.minTlsVersion
property to 1.2
.For example:
Azure Bicep snippetresource web 'Microsoft.Web/sites@2023-01-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n kind: 'web'\n properties: {\n serverFarmId: plan.id\n httpsOnly: true\n siteConfig: {\n alwaysOn: true\n minTlsVersion: '1.2'\n ftpsState: 'Disabled'\n remoteDebuggingEnabled: false\n http20Enabled: true\n netFrameworkVersion: 'v8.0'\n healthCheckPath: '/healthz'\n metadata: [\n {\n name: 'CURRENT_STACK'\n value: 'dotnet'\n }\n ]\n }\n }\n}\n
","tags":["Azure.AppService.MinTLS","AZR-000073"]},{"location":"en/rules/Azure.AppService.MinTLS/#links","title":"Links","text":"Security \u00b7 App Service \u00b7 Rule \u00b7 2024_03 \u00b7 Important
Configure applications to use newer .NET versions.
","tags":["Azure.AppService.NETVersion","AZR-000075"]},{"location":"en/rules/Azure.AppService.NETVersion/#description","title":"Description","text":"Within a App Service app, the version of .NET used to run application/ site code is configurable.
Overtime, a specific version of .NET may become outdated and no longer supported by Microsoft. This can lead to security vulnerabilities or are simply not able to use the latest security features.
.NET 6.0 and .NET 7.0 are approaching end of support.
","tags":["Azure.AppService.NETVersion","AZR-000075"]},{"location":"en/rules/Azure.AppService.NETVersion/#recommendation","title":"Recommendation","text":"Consider updating the site to use a newer .NET version such as v8.0
.
To deploy App Services that pass this rule:
properties.siteConfig.netFrameworkVersion
property to v4.0
or v8.0
.properties.siteConfig.linuxFxVersion
property to DOTNET|8.0
. .NET Framework is not supported on Linux-based plans.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/sites\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"kind\": \"web\",\n \"properties\": {\n \"serverFarmId\": \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\",\n \"httpsOnly\": true,\n \"siteConfig\": {\n \"alwaysOn\": true,\n \"minTlsVersion\": \"1.2\",\n \"ftpsState\": \"Disabled\",\n \"remoteDebuggingEnabled\": false,\n \"http20Enabled\": true,\n \"netFrameworkVersion\": \"v8.0\",\n \"healthCheckPath\": \"/healthz\",\n \"metadata\": [\n {\n \"name\": \"CURRENT_STACK\",\n \"value\": \"dotnet\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\"\n ]\n}\n
","tags":["Azure.AppService.NETVersion","AZR-000075"]},{"location":"en/rules/Azure.AppService.NETVersion/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Services that pass this rule:
properties.siteConfig.netFrameworkVersion
property to v4.0
or v8.0
.properties.siteConfig.linuxFxVersion
property to DOTNET|8.0
. .NET Framework is not supported on Linux-based plans.For example:
Azure Bicep snippetresource web 'Microsoft.Web/sites@2023-01-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n kind: 'web'\n properties: {\n serverFarmId: plan.id\n httpsOnly: true\n siteConfig: {\n alwaysOn: true\n minTlsVersion: '1.2'\n ftpsState: 'Disabled'\n remoteDebuggingEnabled: false\n http20Enabled: true\n netFrameworkVersion: 'v8.0'\n healthCheckPath: '/healthz'\n metadata: [\n {\n name: 'CURRENT_STACK'\n value: 'dotnet'\n }\n ]\n }\n }\n}\n
","tags":["Azure.AppService.NETVersion","AZR-000075"]},{"location":"en/rules/Azure.AppService.NETVersion/#_1","title":"Azure.AppService.NETVersion","text":"","tags":["Azure.AppService.NETVersion","AZR-000075"]},{"location":"en/rules/Azure.AppService.NETVersion/#links","title":"Links","text":"Security \u00b7 App Service \u00b7 Rule \u00b7 2024_03 \u00b7 Important
Configure applications to use newer PHP runtime versions.
","tags":["Azure.AppService.PHPVersion","AZR-000076"]},{"location":"en/rules/Azure.AppService.PHPVersion/#description","title":"Description","text":"Within a App Service app, the version of PHP runtime used to run application/ site code is configurable.
Overtime, a specific version of PHP may become outdated and no longer supported by Microsoft in Azure App Service. This can lead to security vulnerabilities or are simply not able to use the latest security features.
PHP 8.0 and 8.1 are approaching end of support.
","tags":["Azure.AppService.PHPVersion","AZR-000076"]},{"location":"en/rules/Azure.AppService.PHPVersion/#recommendation","title":"Recommendation","text":"Consider updating the site to use a newer PHP runtime version such as 8.2
.
To deploy App Services that pass this rule:
properties.siteConfig.linuxFxVersion
to a minimum of PHP|8.2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/sites\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"kind\": \"web\",\n \"properties\": {\n \"serverFarmId\": \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\",\n \"httpsOnly\": true,\n \"clientAffinityEnabled\": false,\n \"siteConfig\": {\n \"alwaysOn\": true,\n \"minTlsVersion\": \"1.2\",\n \"ftpsState\": \"Disabled\",\n \"http20Enabled\": true,\n \"healthCheckPath\": \"/healthz\",\n \"linuxFxVersion\": \"PHP|8.2\"\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\"\n ]\n}\n
","tags":["Azure.AppService.PHPVersion","AZR-000076"]},{"location":"en/rules/Azure.AppService.PHPVersion/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Services that pass this rule:
properties.siteConfig.linuxFxVersion
to a minimum of PHP|8.2
.For example:
Azure Bicep snippetresource php 'Microsoft.Web/sites@2023-01-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n kind: 'web'\n properties: {\n serverFarmId: plan.id\n httpsOnly: true\n clientAffinityEnabled: false\n siteConfig: {\n alwaysOn: true\n minTlsVersion: '1.2'\n ftpsState: 'Disabled'\n http20Enabled: true\n healthCheckPath: '/healthz'\n linuxFxVersion: 'PHP|8.2'\n }\n }\n}\n
","tags":["Azure.AppService.PHPVersion","AZR-000076"]},{"location":"en/rules/Azure.AppService.PHPVersion/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/7261b898-8a84-4db8-9e04-18527132abb3
/providers/Microsoft.Authorization/policyDefinitions/f466b2a6-823d-470d-8ea5-b031e72d79ae
From November 2022 - PHP is only supported on Linux-based plans.
","tags":["Azure.AppService.PHPVersion","AZR-000076"]},{"location":"en/rules/Azure.AppService.PHPVersion/#links","title":"Links","text":"Reliability \u00b7 App Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
App Service Plan should use a minimum number of instances for failover.
","tags":["Azure.AppService.PlanInstanceCount","AZR-000071"]},{"location":"en/rules/Azure.AppService.PlanInstanceCount/#description","title":"Description","text":"App Services Plans provides a configurable number of instances that will run apps. When a single instance is configured your app may be temporarily unavailable during unplanned interruptions. In most circumstances, Azure will self heal faulty app service instances automatically. However during this time there may interruptions to your workload.
This rule does not apply to consumption or elastic App Services Plans.
","tags":["Azure.AppService.PlanInstanceCount","AZR-000071"]},{"location":"en/rules/Azure.AppService.PlanInstanceCount/#recommendation","title":"Recommendation","text":"Consider using an App Service Plan with at least two (2) instances.
","tags":["Azure.AppService.PlanInstanceCount","AZR-000071"]},{"location":"en/rules/Azure.AppService.PlanInstanceCount/#examples","title":"Examples","text":"","tags":["Azure.AppService.PlanInstanceCount","AZR-000071"]},{"location":"en/rules/Azure.AppService.PlanInstanceCount/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy App Services Plans that pass this rule:
sku.capacity
to 2
or more.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/serverfarms\",\n \"apiVersion\": \"2021-01-15\",\n \"name\": \"[parameters('planName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"S1\",\n \"tier\": \"Standard\",\n \"capacity\": 2\n }\n}\n
","tags":["Azure.AppService.PlanInstanceCount","AZR-000071"]},{"location":"en/rules/Azure.AppService.PlanInstanceCount/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Services Plans that pass this rule:
sku.capacity
to 2
or more.For example:
Azure Bicep snippetresource appPlan 'Microsoft.Web/serverfarms@2021-01-15' = {\n name: planName\n location: location\n sku: {\n name: 'S1'\n tier: 'Standard'\n capacity: 2\n }\n}\n
","tags":["Azure.AppService.PlanInstanceCount","AZR-000071"]},{"location":"en/rules/Azure.AppService.PlanInstanceCount/#links","title":"Links","text":"Security \u00b7 App Service \u00b7 Rule \u00b7 2020_12 \u00b7 Important
Disable remote debugging on App Service apps when not in use.
","tags":["Azure.AppService.RemoteDebug","AZR-000074"]},{"location":"en/rules/Azure.AppService.RemoteDebug/#description","title":"Description","text":"Remote debugging can be enabled on apps running within Azure App Services.
To enable remote debugging, App Service allows connectivity to additional ports. While access to remote debugging ports is authenticated, the attack service for an app is increased.
","tags":["Azure.AppService.RemoteDebug","AZR-000074"]},{"location":"en/rules/Azure.AppService.RemoteDebug/#recommendation","title":"Recommendation","text":"Consider disabling remote debugging when not in use.
","tags":["Azure.AppService.RemoteDebug","AZR-000074"]},{"location":"en/rules/Azure.AppService.RemoteDebug/#examples","title":"Examples","text":"","tags":["Azure.AppService.RemoteDebug","AZR-000074"]},{"location":"en/rules/Azure.AppService.RemoteDebug/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy App Services that pass this rule:
properties.siteConfig.remoteDebuggingEnabled
property to false
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/sites\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"kind\": \"web\",\n \"properties\": {\n \"serverFarmId\": \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\",\n \"httpsOnly\": true,\n \"siteConfig\": {\n \"alwaysOn\": true,\n \"minTlsVersion\": \"1.2\",\n \"ftpsState\": \"Disabled\",\n \"remoteDebuggingEnabled\": false,\n \"http20Enabled\": true,\n \"netFrameworkVersion\": \"v8.0\",\n \"healthCheckPath\": \"/healthz\",\n \"metadata\": [\n {\n \"name\": \"CURRENT_STACK\",\n \"value\": \"dotnet\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\"\n ]\n}\n
","tags":["Azure.AppService.RemoteDebug","AZR-000074"]},{"location":"en/rules/Azure.AppService.RemoteDebug/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Services that pass this rule:
properties.siteConfig.remoteDebuggingEnabled
property to false
.For example:
Azure Bicep snippetresource web 'Microsoft.Web/sites@2023-01-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n kind: 'web'\n properties: {\n serverFarmId: plan.id\n httpsOnly: true\n siteConfig: {\n alwaysOn: true\n minTlsVersion: '1.2'\n ftpsState: 'Disabled'\n remoteDebuggingEnabled: false\n http20Enabled: true\n netFrameworkVersion: 'v8.0'\n healthCheckPath: '/healthz'\n metadata: [\n {\n name: 'CURRENT_STACK'\n value: 'dotnet'\n }\n ]\n }\n }\n}\n
","tags":["Azure.AppService.RemoteDebug","AZR-000074"]},{"location":"en/rules/Azure.AppService.RemoteDebug/#links","title":"Links","text":"Security \u00b7 App Service \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Azure App Service apps should only accept encrypted connections.
","tags":["Azure.AppService.UseHTTPS","AZR-000084"]},{"location":"en/rules/Azure.AppService.UseHTTPS/#description","title":"Description","text":"Azure App Service apps are configured by default to accept encrypted and unencrypted connections. HTTP connections can be automatically redirected to use HTTPS when the HTTPS Only setting is enabled.
Unencrypted communication to App Service apps could allow disclosure of information to an untrusted party.
","tags":["Azure.AppService.UseHTTPS","AZR-000084"]},{"location":"en/rules/Azure.AppService.UseHTTPS/#recommendation","title":"Recommendation","text":"When access using unencrypted HTTP connection is not required consider enabling HTTPS Only. Also consider using Azure Policy to audit or enforce this configuration.
","tags":["Azure.AppService.UseHTTPS","AZR-000084"]},{"location":"en/rules/Azure.AppService.UseHTTPS/#examples","title":"Examples","text":"","tags":["Azure.AppService.UseHTTPS","AZR-000084"]},{"location":"en/rules/Azure.AppService.UseHTTPS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy App Services that pass this rule:
properties.httpsOnly
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/sites\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"kind\": \"web\",\n \"properties\": {\n \"serverFarmId\": \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\",\n \"httpsOnly\": true,\n \"siteConfig\": {\n \"alwaysOn\": true,\n \"minTlsVersion\": \"1.2\",\n \"ftpsState\": \"Disabled\",\n \"remoteDebuggingEnabled\": false,\n \"http20Enabled\": true,\n \"netFrameworkVersion\": \"v8.0\",\n \"healthCheckPath\": \"/healthz\",\n \"metadata\": [\n {\n \"name\": \"CURRENT_STACK\",\n \"value\": \"dotnet\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\"\n ]\n}\n
","tags":["Azure.AppService.UseHTTPS","AZR-000084"]},{"location":"en/rules/Azure.AppService.UseHTTPS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy App Services that pass this rule:
properties.httpsOnly
property to true
.For example:
Azure Bicep snippetresource web 'Microsoft.Web/sites@2023-01-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n kind: 'web'\n properties: {\n serverFarmId: plan.id\n httpsOnly: true\n siteConfig: {\n alwaysOn: true\n minTlsVersion: '1.2'\n ftpsState: 'Disabled'\n remoteDebuggingEnabled: false\n http20Enabled: true\n netFrameworkVersion: 'v8.0'\n healthCheckPath: '/healthz'\n metadata: [\n {\n name: 'CURRENT_STACK'\n value: 'dotnet'\n }\n ]\n }\n }\n}\n
","tags":["Azure.AppService.UseHTTPS","AZR-000084"]},{"location":"en/rules/Azure.AppService.UseHTTPS/#links","title":"Links","text":"Reliability \u00b7 App Service \u00b7 Rule \u00b7 2022_06 \u00b7 Important
Configure and enable instance health probes.
","tags":["Azure.AppService.WebProbe","AZR-000079"]},{"location":"en/rules/Azure.AppService.WebProbe/#description","title":"Description","text":"Azure App Service monitors a specific path for each web app instance to determine health status. The monitored path should implement functional checks to determine if the app is performing correctly. The checks should include dependencies including those that may not be regularly called.
Regular checks of the monitored path allow Azure App Service to route traffic based on availability.
","tags":["Azure.AppService.WebProbe","AZR-000079"]},{"location":"en/rules/Azure.AppService.WebProbe/#recommendation","title":"Recommendation","text":"Consider configuring a health probe to monitor instance availability.
","tags":["Azure.AppService.WebProbe","AZR-000079"]},{"location":"en/rules/Azure.AppService.WebProbe/#examples","title":"Examples","text":"","tags":["Azure.AppService.WebProbe","AZR-000079"]},{"location":"en/rules/Azure.AppService.WebProbe/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Web Apps that pass this rule:
properties.siteConfig.healthCheckPath
property to a valid application path such as /healthz
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/sites\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"kind\": \"web\",\n \"properties\": {\n \"serverFarmId\": \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\",\n \"httpsOnly\": true,\n \"siteConfig\": {\n \"alwaysOn\": true,\n \"minTlsVersion\": \"1.2\",\n \"ftpsState\": \"Disabled\",\n \"remoteDebuggingEnabled\": false,\n \"http20Enabled\": true,\n \"netFrameworkVersion\": \"v8.0\",\n \"healthCheckPath\": \"/healthz\",\n \"metadata\": [\n {\n \"name\": \"CURRENT_STACK\",\n \"value\": \"dotnet\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\"\n ]\n}\n
","tags":["Azure.AppService.WebProbe","AZR-000079"]},{"location":"en/rules/Azure.AppService.WebProbe/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Web Apps that pass this rule:
properties.siteConfig.healthCheckPath
property to a valid application path such as /healthz
.For example:
Azure Bicep snippetresource web 'Microsoft.Web/sites@2023-01-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n kind: 'web'\n properties: {\n serverFarmId: plan.id\n httpsOnly: true\n siteConfig: {\n alwaysOn: true\n minTlsVersion: '1.2'\n ftpsState: 'Disabled'\n remoteDebuggingEnabled: false\n http20Enabled: true\n netFrameworkVersion: 'v8.0'\n healthCheckPath: '/healthz'\n metadata: [\n {\n name: 'CURRENT_STACK'\n value: 'dotnet'\n }\n ]\n }\n }\n}\n
","tags":["Azure.AppService.WebProbe","AZR-000079"]},{"location":"en/rules/Azure.AppService.WebProbe/#links","title":"Links","text":"Reliability \u00b7 App Service \u00b7 Rule \u00b7 2022_06 \u00b7 Important
Configure a dedicated path for health probe requests.
","tags":["Azure.AppService.WebProbePath","AZR-000080"]},{"location":"en/rules/Azure.AppService.WebProbePath/#description","title":"Description","text":"Azure App Service monitors a specific path for each web app instance to determine health status. The monitored path should implement functional checks to determine if the app is performing correctly. The checks should include dependencies including those that may not be regularly called.
Regular checks of the monitored path allow Azure App Service to route traffic based on availability.
","tags":["Azure.AppService.WebProbePath","AZR-000080"]},{"location":"en/rules/Azure.AppService.WebProbePath/#recommendation","title":"Recommendation","text":"Consider using a dedicated health probe endpoint that implements functional checks.
","tags":["Azure.AppService.WebProbePath","AZR-000080"]},{"location":"en/rules/Azure.AppService.WebProbePath/#examples","title":"Examples","text":"","tags":["Azure.AppService.WebProbePath","AZR-000080"]},{"location":"en/rules/Azure.AppService.WebProbePath/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Web Apps that pass this rule:
properties.siteConfig.healthCheckPath
property to a dedicated application path such as /healthz
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/sites\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"kind\": \"web\",\n \"properties\": {\n \"serverFarmId\": \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\",\n \"httpsOnly\": true,\n \"siteConfig\": {\n \"alwaysOn\": true,\n \"minTlsVersion\": \"1.2\",\n \"ftpsState\": \"Disabled\",\n \"remoteDebuggingEnabled\": false,\n \"http20Enabled\": true,\n \"netFrameworkVersion\": \"v8.0\",\n \"healthCheckPath\": \"/healthz\",\n \"metadata\": [\n {\n \"name\": \"CURRENT_STACK\",\n \"value\": \"dotnet\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\"\n ]\n}\n
","tags":["Azure.AppService.WebProbePath","AZR-000080"]},{"location":"en/rules/Azure.AppService.WebProbePath/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Web Apps that pass this rule:
properties.siteConfig.healthCheckPath
property to a dedicated application path such as /healthz
.For example:
Azure Bicep snippetresource web 'Microsoft.Web/sites@2023-01-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n kind: 'web'\n properties: {\n serverFarmId: plan.id\n httpsOnly: true\n siteConfig: {\n alwaysOn: true\n minTlsVersion: '1.2'\n ftpsState: 'Disabled'\n remoteDebuggingEnabled: false\n http20Enabled: true\n netFrameworkVersion: 'v8.0'\n healthCheckPath: '/healthz'\n metadata: [\n {\n name: 'CURRENT_STACK'\n value: 'dotnet'\n }\n ]\n }\n }\n}\n
","tags":["Azure.AppService.WebProbePath","AZR-000080"]},{"location":"en/rules/Azure.AppService.WebProbePath/#links","title":"Links","text":"Security \u00b7 App Service \u00b7 Rule \u00b7 2022_06 \u00b7 Important
Web apps should disable insecure FTP and configure SFTP when required.
","tags":["Azure.AppService.WebSecureFtp","AZR-000081"]},{"location":"en/rules/Azure.AppService.WebSecureFtp/#description","title":"Description","text":"Azure App Service supports configuration of FTP and SFTP for uploading site content. By default, both FTP and SFTP are enabled. In many circumstances, use of FTP or SFTP is not required for automated deployments.
When interactive deployments are required consider using SFTP instead of FTP. Use of FTP alone is not sufficient to prevent disclosure of sensitive information that may be transferred.
","tags":["Azure.AppService.WebSecureFtp","AZR-000081"]},{"location":"en/rules/Azure.AppService.WebSecureFtp/#recommendation","title":"Recommendation","text":"Consider disabling insecure FTP and configure SFTP only when required. Also consider using Azure Policy to audit or enforce this configuration.
","tags":["Azure.AppService.WebSecureFtp","AZR-000081"]},{"location":"en/rules/Azure.AppService.WebSecureFtp/#examples","title":"Examples","text":"","tags":["Azure.AppService.WebSecureFtp","AZR-000081"]},{"location":"en/rules/Azure.AppService.WebSecureFtp/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Web Apps that pass this rule:
properties.siteConfig.ftpsState
property to FtpsOnly
or Disabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Web/sites\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"kind\": \"web\",\n \"properties\": {\n \"serverFarmId\": \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\",\n \"httpsOnly\": true,\n \"siteConfig\": {\n \"alwaysOn\": true,\n \"minTlsVersion\": \"1.2\",\n \"ftpsState\": \"Disabled\",\n \"remoteDebuggingEnabled\": false,\n \"http20Enabled\": true,\n \"netFrameworkVersion\": \"v8.0\",\n \"healthCheckPath\": \"/healthz\",\n \"metadata\": [\n {\n \"name\": \"CURRENT_STACK\",\n \"value\": \"dotnet\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Web/serverfarms', parameters('planName'))]\"\n ]\n}\n
","tags":["Azure.AppService.WebSecureFtp","AZR-000081"]},{"location":"en/rules/Azure.AppService.WebSecureFtp/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Web Apps that pass this rule:
properties.siteConfig.ftpsState
property to FtpsOnly
or Disabled
.For example:
Azure Bicep snippetresource web 'Microsoft.Web/sites@2023-01-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n kind: 'web'\n properties: {\n serverFarmId: plan.id\n httpsOnly: true\n siteConfig: {\n alwaysOn: true\n minTlsVersion: '1.2'\n ftpsState: 'Disabled'\n remoteDebuggingEnabled: false\n http20Enabled: true\n netFrameworkVersion: 'v8.0'\n healthCheckPath: '/healthz'\n metadata: [\n {\n name: 'CURRENT_STACK'\n value: 'dotnet'\n }\n ]\n }\n }\n}\n
","tags":["Azure.AppService.WebSecureFtp","AZR-000081"]},{"location":"en/rules/Azure.AppService.WebSecureFtp/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/4d24b6d4-5e53-4a4f-a7f4-618fa573ee4b
/providers/Microsoft.Authorization/policyDefinitions/c285a320-8830-4665-9cc7-bbd05fc7c5c0
/providers/Microsoft.Authorization/policyDefinitions/399b2637-a50f-4f95-96f8-3a145476eb15
/providers/Microsoft.Authorization/policyDefinitions/e1a09430-221d-4d4c-a337-1edb5a1fa9bb
/providers/Microsoft.Authorization/policyDefinitions/9a1b8c48-453a-4044-86c3-d8bfd823e4f5
Security \u00b7 Arc \u00b7 Rule \u00b7 Preview \u00b7 2023_06 \u00b7 Important
Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters.
","tags":["Azure.Arc.Kubernetes.Defender","AZR-000373"]},{"location":"en/rules/Azure.Arc.Kubernetes.Defender/#description","title":"Description","text":"Defender for Containers relies on the Defender extension for several features.
To collect and provide data plane protections of Microsoft Defender for Containers, the extension must be deployed to the Arc connected Kubernetes cluster. The extension will deploy some additional daemon set and deployments to the cluster.
","tags":["Azure.Arc.Kubernetes.Defender","AZR-000373"]},{"location":"en/rules/Azure.Arc.Kubernetes.Defender/#recommendation","title":"Recommendation","text":"Consider deploying the Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters.
","tags":["Azure.Arc.Kubernetes.Defender","AZR-000373"]},{"location":"en/rules/Azure.Arc.Kubernetes.Defender/#examples","title":"Examples","text":"","tags":["Azure.Arc.Kubernetes.Defender","AZR-000373"]},{"location":"en/rules/Azure.Arc.Kubernetes.Defender/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Arc-enabled Kubernetes clusters that pass this rule:
Microsoft.KubernetesConfiguration/extensions
sub-resource (extension resource).properties.extensionType
property to microsoft.azuredefender.kubernetes
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.KubernetesConfiguration/extensions\",\n \"apiVersion\": \"2022-11-01\",\n \"scope\": \"[format('Microsoft.Kubernetes/connectedClusters/{0}', parameters('name'))]\",\n \"name\": \"microsoft.azuredefender.kubernetes\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"extensionType\": \"microsoft.azuredefender.kubernetes\",\n \"configurationSettings\": {\n \"logAnalyticsWorkspaceResourceID\": \"[parameters('logAnalyticsWorkspaceResourceID')]\",\n \"auditLogPath\": \"/var/log/kube-apiserver/audit.log\"\n },\n \"configurationProtectedSettings\": {\n \"omsagent.secret.wsid\": \"[parameters('wsid')]\",\n \"omsagent.secret.key\": \"[parameters('key')]\"\n },\n \"autoUpgradeMinorVersion\": true,\n \"releaseTrain\": \"Stable\",\n \"scope\": {\n \"cluster\": {\n \"releaseNamespace\": \"azuredefender\"\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Kubernetes/connectedClusters', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.Arc.Kubernetes.Defender","AZR-000373"]},{"location":"en/rules/Azure.Arc.Kubernetes.Defender/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Arc-enabled Kubernetes clusters that pass this rule:
Microsoft.KubernetesConfiguration/extensions
sub-resource (extension resource).properties.extensionType
property to microsoft.azuredefender.kubernetes
.For example:
Azure Bicep snippetresource defenderExtension 'Microsoft.KubernetesConfiguration/extensions@2022-11-01' = {\n name: 'microsoft.azuredefender.kubernetes'\n scope: arcKubernetesCluster\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n extensionType: 'microsoft.azuredefender.kubernetes'\n configurationSettings: {\n logAnalyticsWorkspaceResourceID: logAnalyticsWorkspaceResourceID\n auditLogPath: '/var/log/kube-apiserver/audit.log'\n }\n configurationProtectedSettings: {\n 'omsagent.secret.wsid': wsid\n 'omsagent.secret.key': key\n }\n autoUpgradeMinorVersion: true\n releaseTrain: 'Stable'\n scope: {\n cluster: {\n releaseNamespace: 'azuredefender'\n }\n }\n }\n}\n
","tags":["Azure.Arc.Kubernetes.Defender","AZR-000373"]},{"location":"en/rules/Azure.Arc.Kubernetes.Defender/#links","title":"Links","text":"Operational Excellence \u00b7 Arc \u00b7 Rule \u00b7 Preview \u00b7 2023_06 \u00b7 Important
Use a maintenance configuration for Arc-enabled servers.
","tags":["Azure.Arc.Server.MaintenanceConfig","AZR-000374"]},{"location":"en/rules/Azure.Arc.Server.MaintenanceConfig/#description","title":"Description","text":"Arc-enabled servers can be attached to a maintenance configuration which allows customer managed assessments and updates for machine patches within the guest operating system.
","tags":["Azure.Arc.Server.MaintenanceConfig","AZR-000374"]},{"location":"en/rules/Azure.Arc.Server.MaintenanceConfig/#recommendation","title":"Recommendation","text":"Consider automatically managing and applying operating system updates with a maintenance configuration.
","tags":["Azure.Arc.Server.MaintenanceConfig","AZR-000374"]},{"location":"en/rules/Azure.Arc.Server.MaintenanceConfig/#examples","title":"Examples","text":"","tags":["Azure.Arc.Server.MaintenanceConfig","AZR-000374"]},{"location":"en/rules/Azure.Arc.Server.MaintenanceConfig/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Arc-enabled servers that pass this rule:
Microsoft.Maintenance/configurationAssignments
sub-resource (extension resource).properties.maintenanceConfigurationId
property to the linked maintenance configuration resource Id.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Maintenance/configurationAssignments\",\n \"apiVersion\": \"2022-11-01-preview\",\n \"name\": \"[parameters('assignmentName')]\",\n \"location\": \"[parameters('location')]\",\n \"scope\": \"[format('Microsoft.HybridCompute/machines/{0}', parameters('name'))]\",\n \"properties\": {\n \"maintenanceConfigurationId\": \"[parameters('maintenanceConfigurationId')]\"\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.HybridCompute/machines', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.Arc.Server.MaintenanceConfig","AZR-000374"]},{"location":"en/rules/Azure.Arc.Server.MaintenanceConfig/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Arc-enabled servers that pass this rule:
Microsoft.Maintenance/configurationAssignments
sub-resource (extension resource).properties.maintenanceConfigurationId
property to the linked maintenance configuration resource Id.For example:
Azure Bicep snippetresource config 'Microsoft.Maintenance/configurationAssignments@2022-11-01-preview' = {\n name: assignmentName\n location: location\n scope: arcServer\n properties: {\n maintenanceConfigurationId: maintenanceConfigurationId\n }\n}\n
","tags":["Azure.Arc.Server.MaintenanceConfig","AZR-000374"]},{"location":"en/rules/Azure.Arc.Server.MaintenanceConfig/#notes","title":"Notes","text":"Operating system updates with Update Managment center is a preview feature. Not all regions or operating systems are supported, check out the LINKS
section for supported regions. Update management center doesn't support driver updates.
Security \u00b7 Automation Account \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Ensure automation account audit diagnostic logs are enabled.
","tags":["Azure.Automation.AuditLogs","AZR-000088"]},{"location":"en/rules/Azure.Automation.AuditLogs/#description","title":"Description","text":"To capture logs that record interactions with data or the settings of the automation account, diagnostic settings must be configured.
When configuring diagnostic settings, enabled one of the following:
AuditEvent
category.audit
category group.allLogs
category group.Management operations for Automation Account is captured automatically within Azure Activity Logs.
","tags":["Azure.Automation.AuditLogs","AZR-000088"]},{"location":"en/rules/Azure.Automation.AuditLogs/#recommendation","title":"Recommendation","text":"Consider configuring diagnostic settings to record interactions with data or the settings of the Automation Account.
","tags":["Azure.Automation.AuditLogs","AZR-000088"]},{"location":"en/rules/Azure.Automation.AuditLogs/#examples","title":"Examples","text":"","tags":["Azure.Automation.AuditLogs","AZR-000088"]},{"location":"en/rules/Azure.Automation.AuditLogs/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Automation accounts that pass this rule:
AuditEvent
category or audit
category group or allLogs
category group.For example:
Azure Template snippet{\n \"parameters\": {\n \"automationAccountName\": {\n \"defaultValue\": \"automation-account1\",\n \"type\": \"String\"\n },\n \"location\": {\n \"type\": \"String\"\n },\n \"workspaceId\": {\n \"type\": \"String\"\n }\n },\n \"variables\": {},\n \"resources\": [\n {\n \"type\": \"Microsoft.Automation/automationAccounts\",\n \"apiVersion\": \"2021-06-22\",\n \"name\": \"[parameters('automationAccountName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"disableLocalAuth\": false,\n \"sku\": {\n \"name\": \"Basic\"\n },\n \"encryption\": {\n \"keySource\": \"Microsoft.Automation\",\n \"identity\": {}\n }\n }\n },\n {\n \"comments\": \"Enable monitoring of Automation Account operations.\",\n \"type\": \"Microsoft.Insights/diagnosticSettings\",\n \"name\": \"[concat(parameters('automationAccountName'), '/Microsoft.Insights/service')]\",\n \"apiVersion\": \"2021-05-01-preview\",\n \"dependsOn\": [\n \"[concat('Microsoft.Automation/automationAccounts/', parameters('automationAccountName'))]\"\n ],\n \"properties\": {\n \"workspaceId\": \"[parameters('workspaceId')]\",\n \"logs\": [\n {\n \"category\": \"AuditEvent\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n }\n ]\n }\n }\n ]\n}\n
","tags":["Azure.Automation.AuditLogs","AZR-000088"]},{"location":"en/rules/Azure.Automation.AuditLogs/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Automation accounts that pass this rule:
AuditEvent
category or audit
category group or allLogs
category group.For example:
Azure Bicep snippetparam automationAccountName string = 'automation-account1'\nparam location string\nparam workspaceId string\n\nresource automationAccountResource 'Microsoft.Automation/automationAccounts@2021-06-22' = {\n name: automationAccountName\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n disableLocalAuth: false\n sku: {\n name: 'Basic'\n }\n encryption: {\n keySource: 'Microsoft.Automation'\n identity: {}\n }\n }\n}\n\nresource automationAccountName_Microsoft_Insights_service 'Microsoft.Insights/diagnosticSettings@2021-05-01-preview' = {\n name: 'diagnosticSettings'\n properties: {\n workspaceId: workspaceId\n logs: [\n {\n category: 'AuditEvent'\n enabled: true\n retentionPolicy: {\n days: 0\n enabled: false\n }\n }\n ]\n }\n dependsOn: [\n automationAccountResource\n ]\n}\n
","tags":["Azure.Automation.AuditLogs","AZR-000088"]},{"location":"en/rules/Azure.Automation.AuditLogs/#links","title":"Links","text":"Security \u00b7 Automation Account \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Azure Automation variables should be encrypted.
","tags":["Azure.Automation.EncryptVariables","AZR-000086"]},{"location":"en/rules/Azure.Automation.EncryptVariables/#description","title":"Description","text":"Azure Automation allows configuration properties to be saved as variables. Variables are a key/ value pairs, which may contain sensitive information.
When variables are encrypted they can only be access from within the runbook context. Variables not encrypted are visible to anyone with read permissions.
","tags":["Azure.Automation.EncryptVariables","AZR-000086"]},{"location":"en/rules/Azure.Automation.EncryptVariables/#recommendation","title":"Recommendation","text":"Consider encrypting all automation account variables.
Additionally consider, using Key Vault to store secrets. Key Vault improves security by tightly controlling access to secrets and improving management controls.
","tags":["Azure.Automation.EncryptVariables","AZR-000086"]},{"location":"en/rules/Azure.Automation.EncryptVariables/#links","title":"Links","text":"Security \u00b7 Automation Account \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Ensure Managed Identity is used for authentication.
","tags":["Azure.Automation.ManagedIdentity","AZR-000090"]},{"location":"en/rules/Azure.Automation.ManagedIdentity/#description","title":"Description","text":"Azure automation can use Managed Identities to authenticate to Azure resources without storing credentials.
Using managed identities have the following benefits:
Consider configure a managed identity for each Automation Account.
","tags":["Azure.Automation.ManagedIdentity","AZR-000090"]},{"location":"en/rules/Azure.Automation.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.Automation.ManagedIdentity","AZR-000090"]},{"location":"en/rules/Azure.Automation.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Automation Accounts that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Automation/automationAccounts\",\n \"apiVersion\": \"2021-06-22\",\n \"name\": \"[parameters('automation_account_name')]\",\n \"location\": \"australiaeast\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"disableLocalAuth\": false,\n \"sku\": {\n \"name\": \"Basic\"\n },\n \"encryption\": {\n \"keySource\": \"Microsoft.Automation\",\n \"identity\": {}\n }\n }\n}\n
","tags":["Azure.Automation.ManagedIdentity","AZR-000090"]},{"location":"en/rules/Azure.Automation.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Automation Accounts that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource automation_account_name_resource 'Microsoft.Automation/automationAccounts@2021-06-22' = {\n name: automation_account_name\n location: 'australiaeast'\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n disableLocalAuth: false\n sku: {\n name: 'Basic'\n }\n encryption: {\n keySource: 'Microsoft.Automation'\n identity: {}\n }\n }\n}\n
","tags":["Azure.Automation.ManagedIdentity","AZR-000090"]},{"location":"en/rules/Azure.Automation.ManagedIdentity/#links","title":"Links","text":"Operational Excellence \u00b7 Automation Account \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Ensure automation account platform diagnostic logs are enabled.
","tags":["Azure.Automation.PlatformLogs","AZR-000089"]},{"location":"en/rules/Azure.Automation.PlatformLogs/#description","title":"Description","text":"To capture platform logs from Automation Accounts, the following diagnostic log categories should be enabled:
We can also enable all the above with the allLogs
category group.
To capture metric log categories, th following must be enabled as well:
Consider configuring diagnostic settings to capture platform logs from Automation accounts.
","tags":["Azure.Automation.PlatformLogs","AZR-000089"]},{"location":"en/rules/Azure.Automation.PlatformLogs/#notes","title":"Notes","text":"Configure AZURE_AUTOMATIONACCOUNT_ENABLED_PLATFORM_LOG_CATEGORIES_LIST
to enable selective log categories. By default all log categories are selected, as shown below.
# YAML: The default AZURE_AUTOMATIONACCOUNT_ENABLED_PLATFORM_LOG_CATEGORIES_LIST configuration option\nconfiguration:\n AZURE_AUTOMATIONACCOUNT_ENABLED_PLATFORM_LOG_CATEGORIES_LIST: ['JobLogs', 'JobStreams', 'DscNodeStatus', 'AllMetrics']\n
","tags":["Azure.Automation.PlatformLogs","AZR-000089"]},{"location":"en/rules/Azure.Automation.PlatformLogs/#examples","title":"Examples","text":"","tags":["Azure.Automation.PlatformLogs","AZR-000089"]},{"location":"en/rules/Azure.Automation.PlatformLogs/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Automation accounts that pass this rule:
JobLogs
, JobStreams
, DSCNodeStatus
and AllMetrics
categories.For example:
Azure Template snippet{\n \"parameters\": {\n \"automationAccountName\": {\n \"defaultValue\": \"automation-account1\",\n \"type\": \"String\"\n },\n \"location\": {\n \"type\": \"String\"\n },\n \"workspaceId\": {\n \"type\": \"String\"\n }\n },\n \"variables\": {},\n \"resources\": [\n {\n \"type\": \"Microsoft.Automation/automationAccounts\",\n \"apiVersion\": \"2021-06-22\",\n \"name\": \"[parameters('automationAccountName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"disableLocalAuth\": false,\n \"sku\": {\n \"name\": \"Basic\"\n },\n \"encryption\": {\n \"keySource\": \"Microsoft.Automation\",\n \"identity\": {}\n }\n }\n },\n {\n \"comments\": \"Enable monitoring of Automation Account operations.\",\n \"type\": \"Microsoft.Insights/diagnosticSettings\",\n \"name\": \"[concat(parameters('automationAccountName'), '/Microsoft.Insights/service')]\",\n \"apiVersion\": \"2021-05-01-preview\",\n \"dependsOn\": [\n \"[concat('Microsoft.Automation/automationAccounts/', parameters('automationAccountName'))]\"\n ],\n \"properties\": {\n \"workspaceId\": \"[parameters('workspaceId')]\",\n \"logs\": [\n {\n \"category\": \"JobLogs\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n },\n {\n \"category\": \"JobStreams\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n },\n {\n \"category\": \"DSCNodeStatus\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n }\n ],\n \"metrics\": [\n {\n \"category\": \"AllMetrics\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n }\n ]\n }\n }\n ]\n}\n
","tags":["Azure.Automation.PlatformLogs","AZR-000089"]},{"location":"en/rules/Azure.Automation.PlatformLogs/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Automation accounts that pass this rule:
JobLogs
, JobStreams
, DSCNodeStatus
and AllMetrics
categories.For example:
Azure Bicep snippetparam automationAccountName string = 'automation-account1'\nparam location string\nparam workspaceId string\n\nresource automationAccountResource 'Microsoft.Automation/automationAccounts@2021-06-22' = {\n name: automationAccountName\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n disableLocalAuth: false\n sku: {\n name: 'Basic'\n }\n encryption: {\n keySource: 'Microsoft.Automation'\n identity: {}\n }\n }\n}\n\nresource automationAccountName_Microsoft_Insights_service 'Microsoft.Insights/diagnosticSettings@2021-05-01-preview' = {\n name: 'diagnosticSettings'\n properties: {\n workspaceId: workspaceId\n logs: [\n {\n category: 'JobLogs'\n enabled: true\n retentionPolicy: {\n days: 0\n enabled: false\n }\n },\n {\n category: 'JobStreams'\n enabled: true\n retentionPolicy: {\n days: 0\n enabled: false\n }\n },\n {\n category: 'DSCNodeStatus'\n enabled: true\n retentionPolicy: {\n days: 0\n enabled: false\n }\n }\n ]\n metrics: [\n {\n category: 'AllMetrics'\n enabled: true\n retentionPolicy: {\n days: 0\n enabled: false\n }\n }\n ]\n }\n dependsOn: [\n automationAccountResource\n ]\n}\n
","tags":["Azure.Automation.PlatformLogs","AZR-000089"]},{"location":"en/rules/Azure.Automation.PlatformLogs/#links","title":"Links","text":"Security \u00b7 Automation Account \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Do not create webhooks with an expiry time greater than 1 year (default).
","tags":["Azure.Automation.WebHookExpiry","AZR-000087"]},{"location":"en/rules/Azure.Automation.WebHookExpiry/#description","title":"Description","text":"Do not create webhooks with an expiry time greater than 1 year (default).
","tags":["Azure.Automation.WebHookExpiry","AZR-000087"]},{"location":"en/rules/Azure.Automation.WebHookExpiry/#recommendation","title":"Recommendation","text":"An expiry time of 1 year is the default for webhook creation. Webhooks should be programmatically rotated at regular intervals - Microsoft recommends setting a shorter time than the default of 1 year. If authentication is required for a webhook consider implementing a pre-shared key in the header - or using an Azure Function.
","tags":["Azure.Automation.WebHookExpiry","AZR-000087"]},{"location":"en/rules/Azure.BV.Immutable/","title":"Immutability","text":"Azure.BV.ImmutableAZR-000398ErrorSecurity \u00b7 Backup Vault \u00b7 Rule \u00b7 2023_09 \u00b7 Important
Ensure immutability is configured to protect backup data.
","tags":["Azure.BV.Immutable","AZR-000398"]},{"location":"en/rules/Azure.BV.Immutable/#description","title":"Description","text":"Immutability is supported for Backup vaults by configuring the Immutable vault setting.
Immutable vault helps protecting backup data by blocking any operations that could lead to loss of recovery points. Additionally, locking the Immutable vault setting makes it irreversible to prevent any malicious actors from disabling immutability and deleting backups.
For example, an malicious attack may attempt to remove data or delete vaults to prevent recovery to a known good state.
The Immutable vault setting is not enabled per default.
","tags":["Azure.BV.Immutable","AZR-000398"]},{"location":"en/rules/Azure.BV.Immutable/#recommendation","title":"Recommendation","text":"Consider configuring immutability to protect backup data from accidental or malicious deletion.
","tags":["Azure.BV.Immutable","AZR-000398"]},{"location":"en/rules/Azure.BV.Immutable/#examples","title":"Examples","text":"","tags":["Azure.BV.Immutable","AZR-000398"]},{"location":"en/rules/Azure.BV.Immutable/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Backup vaults that pass this rule:
properties.securitySettings.immutabilitySettings.state
to Unlocked
or Locked
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DataProtection/backupVaults\",\n \"apiVersion\": \"2022-11-01-preview\",\n \"name\": \"[parameters('vaultName')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"securitySettings\": {\n \"immutabilitySettings\": {\n \"state\": \"Locked\"\n }\n }\n }\n}\n
","tags":["Azure.BV.Immutable","AZR-000398"]},{"location":"en/rules/Azure.BV.Immutable/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Backup vaults that pass this rule:
properties.securitySettings.immutabilitySettings.state
to Unlocked
or Locked
.For example:
Azure Bicep snippetresource backupVault 'Microsoft.DataProtection/backupVaults@2022-11-01-preview' = {\n name: vaultName\n location: location\n properties: {\n securitySettings: {\n immutabilitySettings: {\n state: 'Locked'\n }\n }\n }\n}\n
","tags":["Azure.BV.Immutable","AZR-000398"]},{"location":"en/rules/Azure.BV.Immutable/#notes","title":"Notes","text":"Note that immutability locking Locked
is irreversible, so ensure to take a well-informed decision when opting to lock. For example, for vaults containing production workloads consider using Locked
. For cases where you are creating and destroying backups and vaults on a regulary basis such as temporary environments consider Unlocked
.
Operational Excellence \u00b7 Bastion \u00b7 Rule \u00b7 2022_12 \u00b7 Awareness
Bastion hosts should meet naming requirements.
","tags":["Azure.Bastion.Name","AZR-000349"]},{"location":"en/rules/Azure.Bastion.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Bastion host names are:
Consider using names that meet Bastion host naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.Bastion.Name","AZR-000349"]},{"location":"en/rules/Azure.Bastion.Name/#notes","title":"Notes","text":"This rule does not check if Bastion host names are unique.
","tags":["Azure.Bastion.Name","AZR-000349"]},{"location":"en/rules/Azure.Bastion.Name/#links","title":"Links","text":"Operational Excellence \u00b7 Content Delivery Network \u00b7 Rule \u00b7 2020_09 \u00b7 Awareness
Azure CDN Endpoint names should meet naming requirements.
","tags":["Azure.CDN.EndpointName","AZR-000091"]},{"location":"en/rules/Azure.CDN.EndpointName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for CDN endpoint names are:
Consider using names that meet CDN endpoint naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.CDN.EndpointName","AZR-000091"]},{"location":"en/rules/Azure.CDN.EndpointName/#notes","title":"Notes","text":"This rule does not check if CDN endpoint names are unique.
","tags":["Azure.CDN.EndpointName","AZR-000091"]},{"location":"en/rules/Azure.CDN.EndpointName/#links","title":"Links","text":"Security \u00b7 Content Delivery Network \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Enforce HTTPS for client connections.
","tags":["Azure.CDN.HTTP","AZR-000093"]},{"location":"en/rules/Azure.CDN.HTTP/#description","title":"Description","text":"When a client connect to CDN content it can use HTTP or HTTPS. Support for both HTTP and HTTPS is enabled by default. When using HTTP, sensitive information may be exposed to an untrusted party.
","tags":["Azure.CDN.HTTP","AZR-000093"]},{"location":"en/rules/Azure.CDN.HTTP/#recommendation","title":"Recommendation","text":"Consider disabling HTTP support on the CDN endpoint origin.
","tags":["Azure.CDN.HTTP","AZR-000093"]},{"location":"en/rules/Azure.CDN.HTTP/#links","title":"Links","text":"Security \u00b7 Content Delivery Network \u00b7 Rule \u00b7 2020_09 \u00b7 Important
Azure CDN endpoints should reject TLS versions older than 1.2.
","tags":["Azure.CDN.MinTLS","AZR-000092"]},{"location":"en/rules/Azure.CDN.MinTLS/#description","title":"Description","text":"The minimum version of TLS that Azure CDN endpoints accept is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Azure lets you disable outdated protocols and require connections to use a minimum of TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 is accepted.
To configure the minimum TLS version, a custom domain must be configured.
","tags":["Azure.CDN.MinTLS","AZR-000092"]},{"location":"en/rules/Azure.CDN.MinTLS/#recommendation","title":"Recommendation","text":"Consider configuring a custom domain and setting the minimum supported TLS version to be 1.2.
","tags":["Azure.CDN.MinTLS","AZR-000092"]},{"location":"en/rules/Azure.CDN.MinTLS/#links","title":"Links","text":"Performance Efficiency \u00b7 Front Door \u00b7 Rule \u00b7 2022_09 \u00b7 Important
Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities.
","tags":["Azure.CDN.UseFrontDoor","AZR-000286"]},{"location":"en/rules/Azure.CDN.UseFrontDoor/#description","title":"Description","text":"Using a CDN is a good way to minimize the load on your application, and maximize availability and performance.
Standard content delivery network (CDN) capability includes the ability to cache files closer to end users to speed up delivery of static files. However, with dynamic web applications, caching that content in edge locations isn't possible because the server generates the content in response to user behavior. Speeding up the delivery of such content is more complex than traditional edge caching and requires an end-to-end solution that finely tunes each element along the entire data path from inception to delivery. With Azure CDN dynamic site acceleration (DSA) optimization, the performance of web pages with dynamic content is measurably improved.
Azure Front Door Standard or Premium SKU offers modern cloud Content Delivery Network (CDN). These SKUs in particular provides fast, reliable, and secure access between users and dynamic web content across the globe.
","tags":["Azure.CDN.UseFrontDoor","AZR-000286"]},{"location":"en/rules/Azure.CDN.UseFrontDoor/#recommendation","title":"Recommendation","text":"Consider using Front Door Standard or Premium SKU to improve performance.
","tags":["Azure.CDN.UseFrontDoor","AZR-000286"]},{"location":"en/rules/Azure.CDN.UseFrontDoor/#examples","title":"Examples","text":"","tags":["Azure.CDN.UseFrontDoor","AZR-000286"]},{"location":"en/rules/Azure.CDN.UseFrontDoor/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy an front door profile that pass this rule:
sku.name
to Standard_AzureFrontDoor
or Premium_AzureFrontDoor
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cdn/profiles\",\n \"apiVersion\": \"2022-05-01-preview\",\n \"name\": \"myFrontDoor\",\n \"location\": \"global\",\n \"sku\": {\n \"name\": \"Standard_AzureFrontDoor\"\n }\n}\n
","tags":["Azure.CDN.UseFrontDoor","AZR-000286"]},{"location":"en/rules/Azure.CDN.UseFrontDoor/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy an front door profile that pass this rule:
sku.name
to Standard_AzureFrontDoor
or Premium_AzureFrontDoor
.For example:
Azure Bicep snippetresource frontDoorProfile 'Microsoft.Cdn/profiles@2021-06-01' = {\n name: 'myFrontDoor'\n location: 'global'\n sku: {\n name: 'Standard_AzureFrontDoor'\n }\n}\n
","tags":["Azure.CDN.UseFrontDoor","AZR-000286"]},{"location":"en/rules/Azure.CDN.UseFrontDoor/#links","title":"Links","text":"Operational Excellence \u00b7 Container App \u00b7 Rule \u00b7 2023_09 \u00b7 Important
Migrate from retired API version to a supported version.
","tags":["Azure.ContainerApp.APIVersion","AZR-000400"]},{"location":"en/rules/Azure.ContainerApp.APIVersion/#description","title":"Description","text":"The API Azure Container Apps control plane API versions 2022-06-01-preview
and 2022-11-01-preview
are on the retirement path and will be retired on the November 16, 2023.
This means you'll no longer be able to create or manage your Azure Container Apps using your existing templates, tools, scripts and programs until they've been updated to a supported API version.
","tags":["Azure.ContainerApp.APIVersion","AZR-000400"]},{"location":"en/rules/Azure.ContainerApp.APIVersion/#recommendation","title":"Recommendation","text":"Consider migrating from a retired API version to a supported version.
","tags":["Azure.ContainerApp.APIVersion","AZR-000400"]},{"location":"en/rules/Azure.ContainerApp.APIVersion/#examples","title":"Examples","text":"","tags":["Azure.ContainerApp.APIVersion","AZR-000400"]},{"location":"en/rules/Azure.ContainerApp.APIVersion/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Container Apps that pass this rule:
apiVersion
to a supported version.For example:
Azure Template snippet{\n \"type\": \"Microsoft.App/containerApps\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('appName')]\",\n \"location\": \"[parameters('location')]\"\n}\n
","tags":["Azure.ContainerApp.APIVersion","AZR-000400"]},{"location":"en/rules/Azure.ContainerApp.APIVersion/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Container Apps that pass this rule:
apiVersion
to a supported version.For example:
Azure Bicep snippetresource containerApp 'Microsoft.App/containerApps@2023-05-01' = {\n name: appName\n location: location\n}\n
","tags":["Azure.ContainerApp.APIVersion","AZR-000400"]},{"location":"en/rules/Azure.ContainerApp.APIVersion/#links","title":"Links","text":"Performance Efficiency \u00b7 Container App \u00b7 Rule \u00b7 2023_09 \u00b7 Important
Disable session affinity to prevent unbalanced distribution.
","tags":["Azure.ContainerApp.DisableAffinity","AZR-000378"]},{"location":"en/rules/Azure.ContainerApp.DisableAffinity/#description","title":"Description","text":"Container apps allows you to configure session affinity (sticky sessions). When enabled, this feature route requests from the same client to the same replica. This feature might be useful for stateful applications that require a consistent connection to the same replica.
However, for stateless applications there is drawbacks to using session affinity. As connections are opened and closed, a subset of replicas might become overloaded with requests, while others are dormant. This can lead to: poor performance and resource utilization; less predictable scaling.
","tags":["Azure.ContainerApp.DisableAffinity","AZR-000378"]},{"location":"en/rules/Azure.ContainerApp.DisableAffinity/#recommendation","title":"Recommendation","text":"Consider using stateful application design and disabling session affinity to evenly distribute requests across each replica.
","tags":["Azure.ContainerApp.DisableAffinity","AZR-000378"]},{"location":"en/rules/Azure.ContainerApp.DisableAffinity/#examples","title":"Examples","text":"","tags":["Azure.ContainerApp.DisableAffinity","AZR-000378"]},{"location":"en/rules/Azure.ContainerApp.DisableAffinity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Container Apps that pass this rule:
properties.configuration.ingress.stickySessions.affinity
to none
or don't specify the property at all.For example:
Azure Template snippet{\n \"type\": \"Microsoft.App/containerApps\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('appName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"environmentId\": \"[resourceId('Microsoft.App/managedEnvironments', parameters('envName'))]\",\n \"template\": {\n \"revisionSuffix\": \"[parameters('revision')]\",\n \"containers\": \"[variables('containers')]\"\n },\n \"configuration\": {\n \"ingress\": {\n \"allowInsecure\": false,\n \"stickySessions\": {\n \"affinity\": \"none\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.App/managedEnvironments', parameters('envName'))]\"\n ]\n}\n
","tags":["Azure.ContainerApp.DisableAffinity","AZR-000378"]},{"location":"en/rules/Azure.ContainerApp.DisableAffinity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Container Apps that pass this rule:
properties.configuration.ingress.stickySessions.affinity
to none
or don't specify the property at all.For example:
Azure Bicep snippetresource containerApp 'Microsoft.App/containerApps@2023-05-01' = {\n name: appName\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n environmentId: containerEnv.id\n template: {\n revisionSuffix: revision\n containers: containers\n }\n configuration: {\n ingress: {\n allowInsecure: false\n stickySessions: {\n affinity: 'none'\n }\n }\n }\n }\n}\n
","tags":["Azure.ContainerApp.DisableAffinity","AZR-000378"]},{"location":"en/rules/Azure.ContainerApp.DisableAffinity/#notes","title":"Notes","text":"This rule may generate false positive results for stateful applications.
","tags":["Azure.ContainerApp.DisableAffinity","AZR-000378"]},{"location":"en/rules/Azure.ContainerApp.DisableAffinity/#links","title":"Links","text":"Security \u00b7 Container App \u00b7 Rule \u00b7 2023_03 \u00b7 Important
Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment.
","tags":["Azure.ContainerApp.ExternalIngress","AZR-000362"]},{"location":"en/rules/Azure.ContainerApp.ExternalIngress/#description","title":"Description","text":"Container apps allows you to expose your container app to the Internet, your VNET, or to other container apps within the same environment by enabling ingress.
When inbound access to the app is required, configure the ingress. Applications that do batch processing or consume events may not require ingress to be enabled.
When external ingress is configured, communication outside the container apps environment is enabled from your private VNET or the Internet. To restrict communication to a private VNET your Container App Environment must be deployed on a custom VNET with an Internal load balancer.
If communication outside your Container Apps Environment is not required, disable external ingress.
","tags":["Azure.ContainerApp.ExternalIngress","AZR-000362"]},{"location":"en/rules/Azure.ContainerApp.ExternalIngress/#recommendation","title":"Recommendation","text":"Consider disabling external ingress.
","tags":["Azure.ContainerApp.ExternalIngress","AZR-000362"]},{"location":"en/rules/Azure.ContainerApp.ExternalIngress/#examples","title":"Examples","text":"","tags":["Azure.ContainerApp.ExternalIngress","AZR-000362"]},{"location":"en/rules/Azure.ContainerApp.ExternalIngress/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Container Apps that pass this rule:
properties.configuration.ingress.external
to false
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.App/containerApps\",\n \"apiVersion\": \"2022-10-01\",\n \"name\": \"[parameters('appName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\",\n \"userAssignedIdentities\": {}\n },\n \"properties\": {\n \"environmentId\": \"[parameters('environmentId')]\",\n \"template\": {\n \"revisionSuffix\": \"\",\n \"containers\": \"[variables('containers')]\"\n },\n \"configuration\": {\n \"ingress\": {\n \"external\": false\n }\n }\n }\n}\n
","tags":["Azure.ContainerApp.ExternalIngress","AZR-000362"]},{"location":"en/rules/Azure.ContainerApp.ExternalIngress/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Container Apps that pass this rule:
properties.configuration.ingress.external
to false
.For example:
Azure Bicep snippetresource containerApp 'Microsoft.App/containerApps@2022-10-01' = {\n name: appName\n location: location\n identity: {\n type: 'SystemAssigned'\n userAssignedIdentities: {}\n }\n properties: {\n environmentId: environmentId\n template: {\n revisionSuffix: ''\n containers: containers\n }\n configuration: {\n ingress: {\n external: false\n }\n }\n }\n}\n
","tags":["Azure.ContainerApp.ExternalIngress","AZR-000362"]},{"location":"en/rules/Azure.ContainerApp.ExternalIngress/#notes","title":"Notes","text":"This rule is skipped by default because there are common cases where external ingress is required. If you don't need external ingress, enable this rule by:
AZURE_CONTAINERAPPS_RESTRICT_INGRESS
configuration option to true
.Security \u00b7 Container App \u00b7 Rule \u00b7 2023_06 \u00b7 Important
Ensure insecure inbound traffic is not permitted to the container app.
","tags":["Azure.ContainerApp.Insecure","AZR-000094"]},{"location":"en/rules/Azure.ContainerApp.Insecure/#description","title":"Description","text":"Container Apps by default will automatically redirect any HTTP requests to HTTPS. In this default configuration any inbound requests will occur over a minimum of TLS 1.2. This secure by default behavior can be overridden by allowing insecure HTTP traffic.
Unencrypted communication to Container Apps could allow disclosure of information to an untrusted party.
","tags":["Azure.ContainerApp.Insecure","AZR-000094"]},{"location":"en/rules/Azure.ContainerApp.Insecure/#recommendation","title":"Recommendation","text":"Consider disabling insecure traffic and require all inbound traffic to be over TLS 1.2.
","tags":["Azure.ContainerApp.Insecure","AZR-000094"]},{"location":"en/rules/Azure.ContainerApp.Insecure/#examples","title":"Examples","text":"","tags":["Azure.ContainerApp.Insecure","AZR-000094"]},{"location":"en/rules/Azure.ContainerApp.Insecure/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy resource that pass this rule:
properties.configuration.ingress.allowInsecure
to false
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.App/containerApps\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('appName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"environmentId\": \"[resourceId('Microsoft.App/managedEnvironments', parameters('envName'))]\",\n \"template\": {\n \"revisionSuffix\": \"[parameters('revision')]\",\n \"containers\": \"[variables('containers')]\"\n },\n \"configuration\": {\n \"ingress\": {\n \"allowInsecure\": false,\n \"stickySessions\": {\n \"affinity\": \"none\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.App/managedEnvironments', parameters('envName'))]\"\n ]\n}\n
","tags":["Azure.ContainerApp.Insecure","AZR-000094"]},{"location":"en/rules/Azure.ContainerApp.Insecure/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy resource that pass this rule:
properties.configuration.ingress.allowInsecure
to false
.For example:
Azure Bicep snippetresource containerApp 'Microsoft.App/containerApps@2023-05-01' = {\n name: appName\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n environmentId: containerEnv.id\n template: {\n revisionSuffix: revision\n containers: containers\n }\n configuration: {\n ingress: {\n allowInsecure: false\n stickySessions: {\n affinity: 'none'\n }\n }\n }\n }\n}\n
","tags":["Azure.ContainerApp.Insecure","AZR-000094"]},{"location":"en/rules/Azure.ContainerApp.Insecure/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/0e80e269-43a4-4ae9-b5bc-178126b8a5cb
Security \u00b7 Container App \u00b7 Rule \u00b7 2023_03 \u00b7 Important
Ensure managed identity is used for authentication.
","tags":["Azure.ContainerApp.ManagedIdentity","AZR-000361"]},{"location":"en/rules/Azure.ContainerApp.ManagedIdentity/#description","title":"Description","text":"Using managed identities have the following benefits:
Consider configure a managed identity for each container app.
","tags":["Azure.ContainerApp.ManagedIdentity","AZR-000361"]},{"location":"en/rules/Azure.ContainerApp.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.ContainerApp.ManagedIdentity","AZR-000361"]},{"location":"en/rules/Azure.ContainerApp.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Container Apps that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
or SystemAssigned,UserAssigned
.identity.type
is UserAssigned
or SystemAssigned,UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.App/containerApps\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('appName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"environmentId\": \"[resourceId('Microsoft.App/managedEnvironments', parameters('envName'))]\",\n \"template\": {\n \"revisionSuffix\": \"[parameters('revision')]\",\n \"containers\": \"[variables('containers')]\"\n },\n \"configuration\": {\n \"ingress\": {\n \"allowInsecure\": false,\n \"stickySessions\": {\n \"affinity\": \"none\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.App/managedEnvironments', parameters('envName'))]\"\n ]\n}\n
","tags":["Azure.ContainerApp.ManagedIdentity","AZR-000361"]},{"location":"en/rules/Azure.ContainerApp.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Container Apps that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
or SystemAssigned,UserAssigned
.identity.type
is UserAssigned
or SystemAssigned,UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource containerApp 'Microsoft.App/containerApps@2023-05-01' = {\n name: appName\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n environmentId: containerEnv.id\n template: {\n revisionSuffix: revision\n containers: containers\n }\n configuration: {\n ingress: {\n allowInsecure: false\n stickySessions: {\n affinity: 'none'\n }\n }\n }\n }\n}\n
","tags":["Azure.ContainerApp.ManagedIdentity","AZR-000361"]},{"location":"en/rules/Azure.ContainerApp.ManagedIdentity/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/b874ab2d-72dd-47f1-8cb5-4a306478a4e7
Using managed identities in scale rules isn't supported. Init containers can't access managed identities.
","tags":["Azure.ContainerApp.ManagedIdentity","AZR-000361"]},{"location":"en/rules/Azure.ContainerApp.ManagedIdentity/#links","title":"Links","text":"Operational Excellence \u00b7 Container App \u00b7 Rule \u00b7 2023_03 \u00b7 Awareness
Container Apps should meet naming requirements.
","tags":["Azure.ContainerApp.Name","AZR-000360"]},{"location":"en/rules/Azure.ContainerApp.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for container app names are:
Consider using container app names thas meets naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.ContainerApp.Name","AZR-000360"]},{"location":"en/rules/Azure.ContainerApp.Name/#notes","title":"Notes","text":"This rule does not check if container app names are unique.
","tags":["Azure.ContainerApp.Name","AZR-000360"]},{"location":"en/rules/Azure.ContainerApp.Name/#links","title":"Links","text":"Security \u00b7 Container App \u00b7 Rule \u00b7 2023_03 \u00b7 Important
Ensure public network access for Container Apps environment is disabled.
","tags":["Azure.ContainerApp.PublicAccess","AZR-000363"]},{"location":"en/rules/Azure.ContainerApp.PublicAccess/#description","title":"Description","text":"Container apps environments allows you to expose your container app to the Internet.
Container apps environments deployed as external resources are available for public requests. External environments are deployed with a virtual IP on an external, public facing IP address.
Disable public network access to improve security by exposing the Container Apps environment through an internal load balancer.
This removes the need for a public IP address and prevents internet access to all Container Apps within the environment.
To provide secure access, instead consider using an Application Gateway or Azure Front Door premium in front of your Container Apps on your private VNET.
","tags":["Azure.ContainerApp.PublicAccess","AZR-000363"]},{"location":"en/rules/Azure.ContainerApp.PublicAccess/#recommendation","title":"Recommendation","text":"Consider disabling public network access.
","tags":["Azure.ContainerApp.PublicAccess","AZR-000363"]},{"location":"en/rules/Azure.ContainerApp.PublicAccess/#examples","title":"Examples","text":"","tags":["Azure.ContainerApp.PublicAccess","AZR-000363"]},{"location":"en/rules/Azure.ContainerApp.PublicAccess/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Container Apps environments that pass this rule:
properties.vnetConfiguration.infrastructureSubnetId
with the resource Id of a subnet.properties.vnetConfiguration.internal
to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.App/containerApps\",\n \"apiVersion\": \"2022-10-01\",\n \"name\": \"[parameters('envName')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"vnetConfiguration\": {\n \"dockerBridgeCidr\": \"[parameters('dockerBridgeCidr')]\",\n \"infrastructureSubnetId\": \"[parameters('infrastructureSubnetId')]\",\n \"internal\": true,\n \"outboundSettings\": {},\n \"platformReservedCidr\": \"[parameters('platformReservedCidr')]\",\n \"platformReservedDnsIP\": \"[parameters('platformReservedDnsIP')]\",\n }\n }\n}\n
","tags":["Azure.ContainerApp.PublicAccess","AZR-000363"]},{"location":"en/rules/Azure.ContainerApp.PublicAccess/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Container Apps environments that pass this rule:
properties.vnetConfiguration.infrastructureSubnetId
with the resource Id of a subnet.properties.vnetConfiguration.internal
to true
.For example:
Azure Bicep snippetresource containerAppEnv 'Microsoft.App/managedEnvironments@2022-10-01' = {\n name: envName\n location: location\n properties: {\n vnetConfiguration: {\n dockerBridgeCidr: dockerBridgeCidr\n infrastructureSubnetId: infrastructureSubnetId\n internal: true\n outboundSettings: {}\n platformReservedCidr: platformReservedCidr\n platformReservedDnsIP: platformReservedDnsIP\n }\n }\n}\n
","tags":["Azure.ContainerApp.PublicAccess","AZR-000363"]},{"location":"en/rules/Azure.ContainerApp.PublicAccess/#links","title":"Links","text":"Security \u00b7 Container App \u00b7 Rule \u00b7 2023_06 \u00b7 Important
IP ingress restrictions mode should be set to allow action for all rules defined.
","tags":["Azure.ContainerApp.RestrictIngress","AZR-000380"]},{"location":"en/rules/Azure.ContainerApp.RestrictIngress/#description","title":"Description","text":"Container apps supports restricting inbound traffic by IP addresses.
This allows container apps to restrict inbound HTTP or TCP traffic by allowing or denying access to a specific list of IP address ranges.
However, configuring a rule with the Deny
action leads to traffic being denied from the IPv4 address or range, but allows all other traffic.
Instead by configuring a rule or multiple rules with the Allow
action traffic is allowed from the IPv4 address or range, but denies all other traffic.
When no IP restriction rules are defined, all inbound traffic is allowed.
IP ingress restrictions mode can be used for container apps within external and internal environments, but internal ones are limited to private addresses only, where external ones supports both public and private addresses.
","tags":["Azure.ContainerApp.RestrictIngress","AZR-000380"]},{"location":"en/rules/Azure.ContainerApp.RestrictIngress/#recommendation","title":"Recommendation","text":"Consider configuring IP restrictions to limit ingress traffic to allowed IP addresses.
","tags":["Azure.ContainerApp.RestrictIngress","AZR-000380"]},{"location":"en/rules/Azure.ContainerApp.RestrictIngress/#examples","title":"Examples","text":"","tags":["Azure.ContainerApp.RestrictIngress","AZR-000380"]},{"location":"en/rules/Azure.ContainerApp.RestrictIngress/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Container Apps that pass this rule:
properties.configuration.ingress.ipSecurityRestrictions
.properties.configuration.ingress.ipSecurityRestrictions
to action Allow
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.App/containerApps\",\n \"apiVersion\": \"2022-11-01-preview\",\n \"name\": \"[parameters('appName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\",\n \"userAssignedIdentities\": {}\n },\n \"properties\": {\n \"environmentId\": \"[parameters('environmentId')]\",\n \"template\": {\n \"revisionSuffix\": \"\",\n \"containers\": \"[variables('containers')]\"\n },\n \"configuration\": {\n \"ingress\": {\n \"external\": false,\n \"ipSecurityRestrictions\": [\n {\n \"action\": \"Allow\",\n \"description\": \"ClientIPAddress_1\",\n \"ipAddressRange\": \"10.1.1.1/32\",\n \"name\": \"ClientIPAddress_1\"\n },\n {\n \"action\": \"Allow\",\n \"description\": \"ClientIPAddress_2\",\n \"ipAddressRange\": \"10.1.2.1/32\",\n \"name\": \"ClientIPAddress_2\"\n }\n ]\n }\n }\n }\n}\n
","tags":["Azure.ContainerApp.RestrictIngress","AZR-000380"]},{"location":"en/rules/Azure.ContainerApp.RestrictIngress/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Container Apps that pass this rule:
properties.configuration.ingress.ipSecurityRestrictions
.properties.configuration.ingress.ipSecurityRestrictions
to action Allow
.For example:
Azure Bicep snippetresource containerApp 'Microsoft.App/containerApps@2022-11-01-preview' = {\n name: appName\n location: location\n identity: {\n type: 'SystemAssigned'\n userAssignedIdentities: {}\n }\n properties: {\n environmentId: environmentId\n template: {\n revisionSuffix: ''\n containers: containers\n }\n configuration: {\n ingress: {\n external: false\n ipSecurityRestrictions: [\n {\n action: 'Allow'\n description: 'ClientIPAddress_1'\n ipAddressRange: '10.1.1.1/32'\n name: 'ClientIPAddress_1'\n }\n {\n action: 'Allow'\n description: 'ClientIPAddress_2'\n ipAddressRange: '10.1.2.1/32'\n name: 'ClientIPAddress_2'\n }\n ]\n }\n }\n }\n}\n
","tags":["Azure.ContainerApp.RestrictIngress","AZR-000380"]},{"location":"en/rules/Azure.ContainerApp.RestrictIngress/#notes","title":"Notes","text":"All rules must be the same type. It is not supported to combine allow rules and deny rules. If no rules are defined at all, the rule will not pass as it expects at least one allow rule to be configured.
","tags":["Azure.ContainerApp.RestrictIngress","AZR-000380"]},{"location":"en/rules/Azure.ContainerApp.RestrictIngress/#links","title":"Links","text":"Reliability \u00b7 Container App \u00b7 Rule \u00b7 2023_03 \u00b7 Awareness
Use of Azure Files volume mounts to persistent storage container data.
","tags":["Azure.ContainerApp.Storage","AZR-000364"]},{"location":"en/rules/Azure.ContainerApp.Storage/#description","title":"Description","text":"Container apps allows you to use different types of storage. This can be achieved by using volume mounts.
There are considerations to be taken, whether persistent storage is suitable for your app or if non-persistent storage is suitable. Apps may require no storage.
By default all files created inside a container are stored on a writable container layer.
Some considerations when using container file system storage:
Usage examples for this can be a stateless web API or a single page application (that just calls APIs).
Some considerations when using storage volume mounts:
Usage examples for this can be a main app container that write log files that are processed by a sidecar container or writing files to a file share to make data accessible by other systems.
","tags":["Azure.ContainerApp.Storage","AZR-000364"]},{"location":"en/rules/Azure.ContainerApp.Storage/#recommendation","title":"Recommendation","text":"Consider using Azure File volume mounts to persistent storage across containers and replicas.
","tags":["Azure.ContainerApp.Storage","AZR-000364"]},{"location":"en/rules/Azure.ContainerApp.Storage/#examples","title":"Examples","text":"","tags":["Azure.ContainerApp.Storage","AZR-000364"]},{"location":"en/rules/Azure.ContainerApp.Storage/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Container Apps that pass this rule:
properties.template.volumes
array to define a volume or several volumes.storageType
of AzureFile
.properties.template.containers.volumeMounts
array.For example with an Azure Files volume:
Azure Template snippet{\n \"type\": \"Microsoft.App/containerApps\",\n \"apiVersion\": \"2022-10-01\",\n \"name\": \"[parameters('appName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\",\n \"userAssignedIdentities\": {}\n },\n \"properties\": {\n \"environmentId\": \"[parameters('environmentId')]\",\n \"template\": {\n \"revisionSuffix\": \"\",\n \"containers\": [\n {\n \"image\": \"mcr.microsoft.com/azuredocs/containerapps-helloworld:latest\",\n \"name\": \"simple-hello-world-container\",\n \"resources\": {\n \"cpu\": \"[json('.25')]\",\n \"memory\": \".5Gi\"\n },\n \"volumeMounts\": [\n {\n \"mountPath\": \"/myfiles\",\n \"volumeName\": \"azure-files-volume\"\n }\n ]\n }\n ],\n \"scale\": {\n \"minReplicas\": 1,\n \"maxReplicas\": 3\n },\n \"volumes\": [\n {\n \"name\": \"azure-files-volume\",\n \"storageType\": \"AzureFile\",\n \"storageName\": \"myazurefiles\"\n }\n ]\n }\n }\n}\n
","tags":["Azure.ContainerApp.Storage","AZR-000364"]},{"location":"en/rules/Azure.ContainerApp.Storage/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Container Apps that pass this rule:
properties.template.volumes
array to define a volume or several volumes.storageType
of AzureFile
.properties.template.containers.volumeMounts
array.For example with an Azure Files volume:
Azure Bicep snippetresource containerApp 'Microsoft.App/containerApps@2022-10-01' = {\n name: appName\n location: location\n identity: {\n type: 'SystemAssigned'\n userAssignedIdentities: {}\n }\n properties: {\n environmentId: environmentId\n template: {\n revisionSuffix: ''\n containers: [\n {\n image: 'mcr.microsoft.com/azuredocs/containerapps-helloworld:latest'\n name: 'simple-hello-world-container'\n resources: {\n cpu: json('.25')\n memory: '.5Gi'\n }\n volumeMounts: [\n {\n mountPath: '/myfiles'\n volumeName: 'azure-files-volume'\n }\n ]\n }\n ]\n scale: {\n minReplicas: 1\n maxReplicas: 3\n }\n volumes: [\n {\n name: 'azure-files-volume'\n storageType: 'AzureFile'\n storageName: 'myazurefiles'\n }\n ]\n }\n }\n}\n
","tags":["Azure.ContainerApp.Storage","AZR-000364"]},{"location":"en/rules/Azure.ContainerApp.Storage/#notes","title":"Notes","text":"To enable Azure Files storage, a storage definition must be defined in the Container Apps Environment.
","tags":["Azure.ContainerApp.Storage","AZR-000364"]},{"location":"en/rules/Azure.ContainerApp.Storage/#links","title":"Links","text":"Operational Excellence \u00b7 Cosmos DB \u00b7 Rule \u00b7 2021_09 \u00b7 Awareness
Cosmos DB account names should meet naming requirements.
","tags":["Azure.Cosmos.AccountName","AZR-000096"]},{"location":"en/rules/Azure.Cosmos.AccountName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Cosmos DB account names are:
Consider using names that meet Cosmos DB account naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.Cosmos.AccountName","AZR-000096"]},{"location":"en/rules/Azure.Cosmos.AccountName/#notes","title":"Notes","text":"This rule does not check if Cosmos DB account names are unique.
","tags":["Azure.Cosmos.AccountName","AZR-000096"]},{"location":"en/rules/Azure.Cosmos.AccountName/#links","title":"Links","text":"Security \u00b7 Cosmos DB \u00b7 Rule \u00b7 2023_06 \u00b7 Critical
Enable Microsoft Defender for Azure Cosmos DB.
","tags":["Azure.Cosmos.DefenderCloud","AZR-000382"]},{"location":"en/rules/Azure.Cosmos.DefenderCloud/#description","title":"Description","text":"Microsoft Defender for Azure Cosmos DB provides additional security insight for Azure Cosmos DB accounts.
Protection is provided by analyzing onboarded Cosmos DB accounts for unusual and potentially harmful attempts to access or exploit the accounts. Which allows Microsoft Defender for Cloud to produce security alerts that are triggered when anomalies in activity occur.
Security alerts for onboarded Cosmos DB accounts shows up in Defender for Cloud with details of the suspicious activity and recommendations on how to investigate and remediate the threats.
Microsoft Defender for Cosmos DB can be enabled at the resource level, but the general recommandation is to enable it at the subscription level and by doing so ensures all Cosmos DB accounts in the subscription will be protected, including future ones. However, enabling it at resource level can be done to protect a specific Azure Cosmos DB account.
","tags":["Azure.Cosmos.DefenderCloud","AZR-000382"]},{"location":"en/rules/Azure.Cosmos.DefenderCloud/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for Azure Cosmos DB to provide additional security insights for Azure Cosmos DB accounts.
","tags":["Azure.Cosmos.DefenderCloud","AZR-000382"]},{"location":"en/rules/Azure.Cosmos.DefenderCloud/#examples","title":"Examples","text":"","tags":["Azure.Cosmos.DefenderCloud","AZR-000382"]},{"location":"en/rules/Azure.Cosmos.DefenderCloud/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Microsoft Defender for Azure Cosmos DB accounts:
Microsoft.DBforMySQL/servers/securityAlertPolicies
sub-resource (extension resource).properties.isEnabled
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/advancedThreatProtectionSettings\",\n \"apiVersion\": \"2019-01-01\",\n \"scope\": \"[format('Microsoft.DocumentDB/databaseAccounts/{0}', parameters('accountName'))]\",\n \"name\": \"current\",\n \"properties\": {\n \"isEnabled\": true\n },\n \"dependsOn\": [\n \"cosmosDbAccount\"\n ]\n}\n
","tags":["Azure.Cosmos.DefenderCloud","AZR-000382"]},{"location":"en/rules/Azure.Cosmos.DefenderCloud/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Microsoft Defender for Azure Cosmos DB accounts:
Microsoft.DBforMySQL/servers/securityAlertPolicies
sub-resource (extension resource).properties.isEnabled
property to true
.For example:
Azure Bicep snippetresource defenderForCosmosDb 'Microsoft.Security/advancedThreatProtectionSettings@2019-01-01' = {\n scope: cosmosDbAccount\n name: 'current'\n properties: {\n isEnabled: true\n }\n}\n
","tags":["Azure.Cosmos.DefenderCloud","AZR-000382"]},{"location":"en/rules/Azure.Cosmos.DefenderCloud/#notes","title":"Notes","text":"Microsoft Defender for Azure Cosmos DB is currently available only for the NoSQL API. When Microsoft Defender for Cosmos DB is enabled at the subscription level, the resource level enablement has no effect as it will be handled by the plan at the subscription level.
","tags":["Azure.Cosmos.DefenderCloud","AZR-000382"]},{"location":"en/rules/Azure.Cosmos.DefenderCloud/#links","title":"Links","text":"Security \u00b7 Cosmos DB \u00b7 Rule \u00b7 2021_09 \u00b7 Important
Use Azure AD identities for management place operations in Azure Cosmos DB.
","tags":["Azure.Cosmos.DisableMetadataWrite","AZR-000095"]},{"location":"en/rules/Azure.Cosmos.DisableMetadataWrite/#description","title":"Description","text":"Cosmos DB provides two authorization options for interacting with the database:
Resource management operations include management of databases, indexes, and containers. By default, keys are permitted to perform resource management operations. You can restrict these operations to Azure Resource Manager (ARM) calls only.
","tags":["Azure.Cosmos.DisableMetadataWrite","AZR-000095"]},{"location":"en/rules/Azure.Cosmos.DisableMetadataWrite/#recommendation","title":"Recommendation","text":"Consider limiting key and resource tokens to data plane operations only. Use Azure AD identities for authorizing account and resource management operations.
","tags":["Azure.Cosmos.DisableMetadataWrite","AZR-000095"]},{"location":"en/rules/Azure.Cosmos.DisableMetadataWrite/#examples","title":"Examples","text":"","tags":["Azure.Cosmos.DisableMetadataWrite","AZR-000095"]},{"location":"en/rules/Azure.Cosmos.DisableMetadataWrite/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Cosmos DB accounts that pass this rule:
Properties.disableKeyBasedMetadataWriteAccess
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DocumentDB/databaseAccounts\",\n \"apiVersion\": \"2021-06-15\",\n \"name\": \"[parameters('dbAccountName')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"consistencyPolicy\": {\n \"defaultConsistencyLevel\": \"Session\"\n },\n \"databaseAccountOfferType\": \"Standard\",\n \"locations\": [\n {\n \"locationName\": \"[parameters('location')]\",\n \"failoverPriority\": 0,\n \"isZoneRedundant\": false\n }\n ],\n \"disableKeyBasedMetadataWriteAccess\": true\n }\n}\n
","tags":["Azure.Cosmos.DisableMetadataWrite","AZR-000095"]},{"location":"en/rules/Azure.Cosmos.DisableMetadataWrite/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Cosmos DB accounts that pass this rule:
Properties.disableKeyBasedMetadataWriteAccess
property to true
.For example:
Azure Bicep snippetresource dbAccount 'Microsoft.DocumentDB/databaseAccounts@2021-06-15' = {\n name: dbAccountName\n location: location\n properties: {\n consistencyPolicy: {\n defaultConsistencyLevel: 'Session'\n }\n databaseAccountOfferType: 'Standard'\n locations: [\n {\n locationName: location\n failoverPriority: 0\n isZoneRedundant: false\n }\n ]\n disableKeyBasedMetadataWriteAccess: true\n }\n}\n
","tags":["Azure.Cosmos.DisableMetadataWrite","AZR-000095"]},{"location":"en/rules/Azure.Cosmos.DisableMetadataWrite/#links","title":"Links","text":"Operational Excellence \u00b7 Data Factory \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Consider migrating to DataFactory v2.
","tags":["Azure.DataFactory.Version","AZR-000097"]},{"location":"en/rules/Azure.DataFactory.Version/#description","title":"Description","text":"Consider migrating to DataFactory v2.
","tags":["Azure.DataFactory.Version","AZR-000097"]},{"location":"en/rules/Azure.DataFactory.Version/#recommendation","title":"Recommendation","text":"Consider migrating to DataFactory v2.
","tags":["Azure.DataFactory.Version","AZR-000097"]},{"location":"en/rules/Azure.Databricks.PublicAccess/","title":"Azure Databricks workspaces should disable public network access","text":"Azure.Databricks.PublicAccessAZR-000410ErrorSecurity \u00b7 Databricks \u00b7 Rule \u00b7 2024_03 \u00b7 Critical
Azure Databricks workspaces should disable public network access.
","tags":["Azure.Databricks.PublicAccess","AZR-000410"]},{"location":"en/rules/Azure.Databricks.PublicAccess/#description","title":"Description","text":"Disabling public network access improves security by ensuring that the resource isn't exposed on the public internet. You can control exposure of your resources by creating private endpoints instead.
","tags":["Azure.Databricks.PublicAccess","AZR-000410"]},{"location":"en/rules/Azure.Databricks.PublicAccess/#recommendation","title":"Recommendation","text":"Consider configuring Databricks workspaces to disable public network access, using private endpoints to control connectivity.
","tags":["Azure.Databricks.PublicAccess","AZR-000410"]},{"location":"en/rules/Azure.Databricks.PublicAccess/#examples","title":"Examples","text":"","tags":["Azure.Databricks.PublicAccess","AZR-000410"]},{"location":"en/rules/Azure.Databricks.PublicAccess/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy workspaces that pass this rule:
properties.publicNetworkAccess
property to Disabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Databricks/workspaces\",\n \"apiVersion\": \"2023-02-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"managedResourceGroupId\": \"[subscriptionResourceId('Microsoft.Resources/resourceGroups', 'example-mg')]\",\n \"publicNetworkAccess\": \"Disabled\",\n \"parameters\": {\n \"enableNoPublicIp\": {\n \"value\": true\n }\n }\n }\n}\n
","tags":["Azure.Databricks.PublicAccess","AZR-000410"]},{"location":"en/rules/Azure.Databricks.PublicAccess/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy workspaces that pass this rule:
properties.publicNetworkAccess
property to Disabled
.For example:
Azure Bicep snippetresource databricks 'Microsoft.Databricks/workspaces@2023-02-01' = {\n name: name\n location: location\n sku: {\n name: 'standard'\n }\n properties: {\n managedResourceGroupId: managedRg.id\n publicNetworkAccess: 'Disabled'\n parameters: {\n enableNoPublicIp: {\n value: true\n }\n }\n }\n}\n
","tags":["Azure.Databricks.PublicAccess","AZR-000410"]},{"location":"en/rules/Azure.Databricks.PublicAccess/#links","title":"Links","text":"Performance Efficiency \u00b7 Databricks \u00b7 Rule \u00b7 2024_03 \u00b7 Critical
Ensure Databricks workspaces are non-trial SKUs for production workloads.
","tags":["Azure.Databricks.SKU","AZR-000409"]},{"location":"en/rules/Azure.Databricks.SKU/#description","title":"Description","text":"An Azure Databricks workspace has three available SKU types to support the compute demands of a workspace.
The Trial SKU is a time-bound offer which has feature and compute limitations, making it unsuitable for production workloads. NB - The Trial SKU is a strong candidate for non-production or innovation workloads which can accept the tiers constraints.
","tags":["Azure.Databricks.SKU","AZR-000409"]},{"location":"en/rules/Azure.Databricks.SKU/#recommendation","title":"Recommendation","text":"Consider configuring Databricks workspaces to use either Standard or Premium tiers, dependant on the workload demands and non-functional requirements (NFRs).
","tags":["Azure.Databricks.SKU","AZR-000409"]},{"location":"en/rules/Azure.Databricks.SKU/#examples","title":"Examples","text":"","tags":["Azure.Databricks.SKU","AZR-000409"]},{"location":"en/rules/Azure.Databricks.SKU/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy workspaces that pass this rule:
sku.name
to a a non-trial tier, i.e. standard
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Databricks/workspaces\",\n \"apiVersion\": \"2023-02-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"managedResourceGroupId\": \"[subscriptionResourceId('Microsoft.Resources/resourceGroups', 'example-mg')]\",\n \"publicNetworkAccess\": \"Disabled\",\n \"parameters\": {\n \"enableNoPublicIp\": {\n \"value\": true\n }\n }\n }\n}\n
","tags":["Azure.Databricks.SKU","AZR-000409"]},{"location":"en/rules/Azure.Databricks.SKU/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy workspaces that pass this rule:
sku.name
to a a non-trial tier, i.e. standard
.For example:
Azure Bicep snippetresource databricks 'Microsoft.Databricks/workspaces@2023-02-01' = {\n name: name\n location: location\n sku: {\n name: 'standard'\n }\n properties: {\n managedResourceGroupId: managedRg.id\n publicNetworkAccess: 'Disabled'\n parameters: {\n enableNoPublicIp: {\n value: true\n }\n }\n }\n}\n
","tags":["Azure.Databricks.SKU","AZR-000409"]},{"location":"en/rules/Azure.Databricks.SKU/#links","title":"Links","text":"Security \u00b7 Databricks \u00b7 Rule \u00b7 2023_09 \u00b7 Critical
Use Databricks workspaces configured for secure cluster connectivity.
","tags":["Azure.Databricks.SecureConnectivity","AZR-000393"]},{"location":"en/rules/Azure.Databricks.SecureConnectivity/#description","title":"Description","text":"An Azure Databricks workspace uses one or more runtime clusters to execute data processing workloads.
When configuring Databricks workspaces, runtime clusters can be configured with or without public IP addresses. Secure cluster connectivity is used when a Databricks workspace is deployed without public IP addresses. Use secure cluster connectivity to simplify security and administration of Databricks networking within Azure.
With secure cluster connectivity enabled:
Consider configuring Databricks workspaces to use secure cluster connectivity.
","tags":["Azure.Databricks.SecureConnectivity","AZR-000393"]},{"location":"en/rules/Azure.Databricks.SecureConnectivity/#examples","title":"Examples","text":"","tags":["Azure.Databricks.SecureConnectivity","AZR-000393"]},{"location":"en/rules/Azure.Databricks.SecureConnectivity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy workspaces that pass this rule:
properties.parameters.enableNoPublicIp.value
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Databricks/workspaces\",\n \"apiVersion\": \"2023-02-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"managedResourceGroupId\": \"[subscriptionResourceId('Microsoft.Resources/resourceGroups', 'example-mg')]\",\n \"publicNetworkAccess\": \"Disabled\",\n \"parameters\": {\n \"enableNoPublicIp\": {\n \"value\": true\n }\n }\n }\n}\n
","tags":["Azure.Databricks.SecureConnectivity","AZR-000393"]},{"location":"en/rules/Azure.Databricks.SecureConnectivity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy workspaces that pass this rule:
properties.parameters.enableNoPublicIp.value
property to true
.For example:
Azure Bicep snippetresource databricks 'Microsoft.Databricks/workspaces@2023-02-01' = {\n name: name\n location: location\n sku: {\n name: 'standard'\n }\n properties: {\n managedResourceGroupId: managedRg.id\n publicNetworkAccess: 'Disabled'\n parameters: {\n enableNoPublicIp: {\n value: true\n }\n }\n }\n}\n
","tags":["Azure.Databricks.SecureConnectivity","AZR-000393"]},{"location":"en/rules/Azure.Databricks.SecureConnectivity/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2023_12 \u00b7 Critical
Enable Microsoft Defender for APIs.
","tags":["Azure.Defender.Api","AZR-000377"]},{"location":"en/rules/Azure.Defender.Api/#description","title":"Description","text":"Microsoft Defender for APIs provides additional security for APIs published in Azure API Management.
Protection is provided by analyzing onboarded APIs. Which allows Microsoft Defender for Cloud to produce security findings.
The inventory and security findings for onboarded APIs is reviewed in the Defender for Cloud API Security dashboard.
These security findings includes API recommendations and runtime threats.
Defender for APIs can be enabled together with the Defender CSPM plan, offering further capabilities.
Microsoft Defender for APIs can be enabled at the subscription level.
","tags":["Azure.Defender.Api","AZR-000377"]},{"location":"en/rules/Azure.Defender.Api/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for APIs to provide additional security for APIs published in Azure API Management.
","tags":["Azure.Defender.Api","AZR-000377"]},{"location":"en/rules/Azure.Defender.Api/#examples","title":"Examples","text":"","tags":["Azure.Defender.Api","AZR-000377"]},{"location":"en/rules/Azure.Defender.Api/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy and enable Defender for APIs configurations that pass this rule:
properties.pricingTier
property to to Standard
.properties.subPlan
property to a plan such as P1
. Other plans are available, currently these are: P1
, P2
, P3
, P4
, and P5
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"Api\",\n \"properties\": {\n \"subPlan\": \"P1\",\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.Defender.Api","AZR-000377"]},{"location":"en/rules/Azure.Defender.Api/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy and enable Defender for APIs configurations that pass this rule:
properties.pricingTier
property to to Standard
.properties.subPlan
property to a plan such as P1
. Other plans are available, currently these are: P1
, P2
, P3
, P4
, and P5
.For example:
Azure Bicep snippetresource defenderForApi 'Microsoft.Security/pricings@2023-01-01' = {\n name: 'Api'\n properties: {\n subPlan: 'P1'\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.Defender.Api","AZR-000377"]},{"location":"en/rules/Azure.Defender.Api/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To enable Microsoft Defender for APIs:
Standard
pricing tier for Microsoft Defender for APIs.For example:
Azure CLI snippetaz security pricing create -n Api --tier standard --subplan P1\n
","tags":["Azure.Defender.Api","AZR-000377"]},{"location":"en/rules/Azure.Defender.Api/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To enable Microsoft Defender for APIs:
Standard
pricing tier for Microsoft Defender for APIs.For example:
Azure PowerShell snippetSet-AzSecurityPricing -Name 'Api' -PricingTier 'Standard' -SubPlan 'P1'\n
","tags":["Azure.Defender.Api","AZR-000377"]},{"location":"en/rules/Azure.Defender.Api/#notes","title":"Notes","text":"Currently only REST APIs published in Azure API Management is supported. Not all regions are supported.
","tags":["Azure.Defender.Api","AZR-000377"]},{"location":"en/rules/Azure.Defender.Api/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Enable Microsoft Defender for App Service.
","tags":["Azure.Defender.AppServices","AZR-000295"]},{"location":"en/rules/Azure.Defender.AppServices/#description","title":"Description","text":"Many attacks are performed first by probing web applications to find and exploit weaknesses. It is crucial to secure your applications, even while running in PaaS services like App Service.
Microsoft Defender for App Service identifies attacks over App Service thanks to cloud scale data analysis. It offers:
The solution is particularly efficient as it can can identify attack methodologies applying to multiple targets. The log data and the infrastructure together are used to enhance Defender for App Service globally.
","tags":["Azure.Defender.AppServices","AZR-000295"]},{"location":"en/rules/Azure.Defender.AppServices/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for App Service to protect your web apps and APIs.
","tags":["Azure.Defender.AppServices","AZR-000295"]},{"location":"en/rules/Azure.Defender.AppServices/#examples","title":"Examples","text":"","tags":["Azure.Defender.AppServices","AZR-000295"]},{"location":"en/rules/Azure.Defender.AppServices/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Defender for App Service:
Standard
pricing tier for Microsoft Defender for App Service.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"AppServices\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.Defender.AppServices","AZR-000295"]},{"location":"en/rules/Azure.Defender.AppServices/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Defender for App Service:
Standard
pricing tier for Microsoft Defender for App Service.For example:
Azure Bicep snippetresource defenderForAppService 'Microsoft.Security/pricings@2022-03-01' = {\n name: 'AppServices'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.Defender.AppServices","AZR-000295"]},{"location":"en/rules/Azure.Defender.AppServices/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz security pricing create -n 'AppServices' --tier 'standard'\n
","tags":["Azure.Defender.AppServices","AZR-000295"]},{"location":"en/rules/Azure.Defender.AppServices/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetSet-AzSecurityPricing -Name 'AppServices' -PricingTier 'Standard'\n
","tags":["Azure.Defender.AppServices","AZR-000295"]},{"location":"en/rules/Azure.Defender.AppServices/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.Defender.AppServices","AZR-000295"]},{"location":"en/rules/Azure.Defender.AppServices/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2023_03 \u00b7 Critical
Enable Microsoft Defender for Azure Resource Manager (ARM).
","tags":["Azure.Defender.Arm","AZR-000354"]},{"location":"en/rules/Azure.Defender.Arm/#description","title":"Description","text":"Microsoft Defender for ARM provides additional protection for control plane activities. It does this by detecting suspicious activities such as disabling security features or attempts at lateral movement.
Protection is provided by analyzing telemetry from Azure Resource Manager operations. Which allows Microsoft Defender for Cloud to detect anomalous activities regardless of the tool used to perform the operation. For example: Azure CLI, Azure Portal, PowerShell, REST API, Terraform, etc.
When anomalous activities occur, Microsoft Defender for ARM shows alerts to relevant members of your organization. These alerts include the details of the suspicious activity and recommendations on how to investigate and remediate threats.
Microsoft Defender for ARM can be enabled at the subscription level.
","tags":["Azure.Defender.Arm","AZR-000354"]},{"location":"en/rules/Azure.Defender.Arm/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for Resource Manager to provide additional protection to control plane activities.
","tags":["Azure.Defender.Arm","AZR-000354"]},{"location":"en/rules/Azure.Defender.Arm/#examples","title":"Examples","text":"","tags":["Azure.Defender.Arm","AZR-000354"]},{"location":"en/rules/Azure.Defender.Arm/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Microsoft Defender for Resource Manager:
Standard
pricing tier for Microsoft Defender for Resource Manager.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"Arm\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.Defender.Arm","AZR-000354"]},{"location":"en/rules/Azure.Defender.Arm/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Microsoft Defender for Resource Manager:
Standard
pricing tier for Microsoft Defender for Resource Manager.For example:
Azure Bicep snippetresource defenderForArm 'Microsoft.Security/pricings@2022-03-01' = {\n name: 'Arm'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.Defender.Arm","AZR-000354"]},{"location":"en/rules/Azure.Defender.Arm/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To enable Microsoft Defender for Resource Manager:
Standard
pricing tier for Microsoft Defender for Resource Manager.For example:
Azure CLI snippetaz security pricing create -n 'Arm' --tier 'standard'\n
","tags":["Azure.Defender.Arm","AZR-000354"]},{"location":"en/rules/Azure.Defender.Arm/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To enable Microsoft Defender for Resource Manager:
Standard
pricing tier for Microsoft Defender for Resource Manager.For example:
Azure PowerShell snippetSet-AzSecurityPricing -Name 'Arm' -PricingTier 'Standard'\n
","tags":["Azure.Defender.Arm","AZR-000354"]},{"location":"en/rules/Azure.Defender.Arm/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.Defender.Arm","AZR-000354"]},{"location":"en/rules/Azure.Defender.Arm/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Enable Microsoft Defender for Containers.
","tags":["Azure.Defender.Containers","AZR-000290"]},{"location":"en/rules/Azure.Defender.Containers/#description","title":"Description","text":"Container-based workloads should be carefully monitored the following three core security aspects:
It is important to adopt a strategy to actively perform those three aspects. One option for doing so is to use Microsoft Defender for Containers.
Defender for Cloud continuously assesses the configurations of your clusters. If any misconfigurations is found, it generates security recommendations. The recommendations available in the Recommendations page allow you to investigate and remediate issues.
Defender for Containers also provides real-time threat protection for your containerized environments. If any suspicious activities is detected, Defender for Container generates an alert. Threat protection at the cluster level is provided by the Defender agent and analysis of the Kubernetes audit logs.
Defender for Containers scans images on push, import, and recently pulled images. Recently pulled images are scanned on a regular basis when they have been pulled within the last 30 days. When scanned, the container image is pulled and executed in an isolated sandbox for scanning. Any detected vulnerabilities are reported to Microsoft Defender for Cloud.
","tags":["Azure.Defender.Containers","AZR-000290"]},{"location":"en/rules/Azure.Defender.Containers/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for Containers to protect your container-based workloads.
","tags":["Azure.Defender.Containers","AZR-000290"]},{"location":"en/rules/Azure.Defender.Containers/#examples","title":"Examples","text":"","tags":["Azure.Defender.Containers","AZR-000290"]},{"location":"en/rules/Azure.Defender.Containers/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Microsoft Defender for Containers:
Standard
pricing tier for Microsoft Defender for Containers.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"Containers\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.Defender.Containers","AZR-000290"]},{"location":"en/rules/Azure.Defender.Containers/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Microsoft Defender for Containers:
Standard
pricing tier for Microsoft Defender for Containers.For example:
Azure Bicep snippetresource defenderForContainers 'Microsoft.Security/pricings@2022-03-01' = {\n name: 'Containers'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.Defender.Containers","AZR-000290"]},{"location":"en/rules/Azure.Defender.Containers/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To enable Microsoft Defender for Containers:
Standard
pricing tier for Microsoft Defender for Containers.For example:
Azure CLI snippetaz security pricing create -n 'Containers' --tier 'standard'\n
","tags":["Azure.Defender.Containers","AZR-000290"]},{"location":"en/rules/Azure.Defender.Containers/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To enable Microsoft Defender for Containers:
Standard
pricing tier for Microsoft Defender for Containers.For example:
Azure PowerShell snippetSet-AzSecurityPricing -Name 'Containers' -PricingTier 'Standard'\n
","tags":["Azure.Defender.Containers","AZR-000290"]},{"location":"en/rules/Azure.Defender.Containers/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.Defender.Containers","AZR-000290"]},{"location":"en/rules/Azure.Defender.Containers/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2023_06 \u00b7 Critical
Enable Microsoft Defender for Azure Cosmos DB.
","tags":["Azure.Defender.CosmosDb","AZR-000379"]},{"location":"en/rules/Azure.Defender.CosmosDb/#description","title":"Description","text":"Microsoft Defender for Azure Cosmos DB provides additional security insight for Azure Cosmos DB accounts.
Protection is provided by analyzing onboarded Cosmos DB accounts for unusual and potentially harmful attempts to access or exploit the accounts. Which allows Microsoft Defender for Cloud to produce security alerts that are triggered when anomalies in activity occur.
Security alerts for onboarded Cosmos DB accounts shows up in Defender for Cloud with details of the suspicious activity and recommendations on how to investigate and remediate the threats.
Microsoft Defender for Cosmos DB can be enabled at the subscription level and by doing so ensures all Cosmos DB accounts in the subscription will be protected, including future ones.
","tags":["Azure.Defender.CosmosDb","AZR-000379"]},{"location":"en/rules/Azure.Defender.CosmosDb/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for Azure Cosmos DB to provide additional security insights for Azure Cosmos DB accounts.
","tags":["Azure.Defender.CosmosDb","AZR-000379"]},{"location":"en/rules/Azure.Defender.CosmosDb/#examples","title":"Examples","text":"","tags":["Azure.Defender.CosmosDb","AZR-000379"]},{"location":"en/rules/Azure.Defender.CosmosDb/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Microsoft Defender for Azure Cosmos DB accounts:
Standard
pricing tier for Microsoft Defender for Azure Cosmos DB.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"CosmosDbs\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.Defender.CosmosDb","AZR-000379"]},{"location":"en/rules/Azure.Defender.CosmosDb/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Microsoft Defender for Azure Cosmos DB accounts:
Standard
pricing tier for Microsoft Defender for Azure Cosmos DB.For example:
Azure Bicep snippetresource defenderForCosmosDb 'Microsoft.Security/pricings@2022-03-01' = {\n name: 'CosmosDbs'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.Defender.CosmosDb","AZR-000379"]},{"location":"en/rules/Azure.Defender.CosmosDb/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To enable Microsoft Defender for Azure Cosmos DB accounts:
Standard
pricing tier for Microsoft Defender for Azure Cosmos DB.For example:
Azure CLI snippetaz security pricing create -n 'CosmosDbs' --tier 'standard'\n
","tags":["Azure.Defender.CosmosDb","AZR-000379"]},{"location":"en/rules/Azure.Defender.CosmosDb/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To enable Microsoft Defender for Azure Cosmos DB accounts:
Standard
pricing tier for Microsoft Defender for Azure Cosmos DB.For example:
Azure PowerShell snippetSet-AzSecurityPricing -Name 'CosmosDbs' -PricingTier 'Standard'\n
","tags":["Azure.Defender.CosmosDb","AZR-000379"]},{"location":"en/rules/Azure.Defender.CosmosDb/#notes","title":"Notes","text":"Microsoft Defender for Azure Cosmos DB is currently available only for the NoSQL API.
","tags":["Azure.Defender.CosmosDb","AZR-000379"]},{"location":"en/rules/Azure.Defender.CosmosDb/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2023_06 \u00b7 Critical
Enable Microsoft Defender Cloud Security Posture Management Standard plan.
","tags":["Azure.Defender.Cspm","AZR-000372"]},{"location":"en/rules/Azure.Defender.Cspm/#description","title":"Description","text":"Microsoft Defender Cloud Security Posture Management (CSPM) provides additional visibility across cloud environments to quickly detect configuration errors and remediate them through automation. It does this by keeping constant eye on the security state of your cloud resources in different environments.
By enabling the Defender Cloud CSPM Standard plan, Microsoft Defender provides advanced posture management capabilities such as:
Microsoft Defender Cloud Security Posture Management (CSPM) can be enabled at the subscription level.
","tags":["Azure.Defender.Cspm","AZR-000372"]},{"location":"en/rules/Azure.Defender.Cspm/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender Cloud Security Posture Management (CSPM) Standard plan to provide additional visibility across cloud environments.
","tags":["Azure.Defender.Cspm","AZR-000372"]},{"location":"en/rules/Azure.Defender.Cspm/#examples","title":"Examples","text":"","tags":["Azure.Defender.Cspm","AZR-000372"]},{"location":"en/rules/Azure.Defender.Cspm/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Microsoft Defender Cloud Security Posture Management Standard plan:
Standard
pricing tier for Microsoft Defender Cloud Security Posture Management.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"CloudPosture\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.Defender.Cspm","AZR-000372"]},{"location":"en/rules/Azure.Defender.Cspm/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Microsoft Defender Cloud Security Posture Management Standard plan:
Standard
pricing tier for Microsoft Defender Cloud Security Posture Management.For example:
Azure Bicep snippetresource defenderCspm 'Microsoft.Security/pricings@2022-03-01' = {\n name: 'CloudPosture'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.Defender.Cspm","AZR-000372"]},{"location":"en/rules/Azure.Defender.Cspm/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"TTo enable Microsoft Defender Cloud Security Posture Management Standard plan:
Standard
pricing tier for Microsoft Defender Cloud Security Posture Management.For example:
Azure CLI snippetaz security pricing create -n 'CloudPosture' --tier 'standard'\n
","tags":["Azure.Defender.Cspm","AZR-000372"]},{"location":"en/rules/Azure.Defender.Cspm/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To enable Microsoft Defender Cloud Security Posture Management Standard plan:
Standard
pricing tier for Microsoft Defender Cloud Security Posture Management.For example:
Azure PowerShell snippetSet-AzSecurityPricing -Name 'CloudPosture' -PricingTier 'Standard'\n
","tags":["Azure.Defender.Cspm","AZR-000372"]},{"location":"en/rules/Azure.Defender.Cspm/#notes","title":"Notes","text":"This rule applies when analyzing resources before deployed (pre-flight) and deployed (in-flight) to Azure.
","tags":["Azure.Defender.Cspm","AZR-000372"]},{"location":"en/rules/Azure.Defender.Cspm/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2023_03 \u00b7 Critical
Enable Microsoft Defender for DNS.
","tags":["Azure.Defender.Dns","AZR-000353"]},{"location":"en/rules/Azure.Defender.Dns/#description","title":"Description","text":"Microsoft Defender for DNS provides additional protection for virtual networks and resources. It does this by monitoring Azure-provided DNS for suspicious and anomalous activity. By analyzing telemetry for DNS, Microsoft Defender for DNS can detect and alert on persistent threats such as:
Microsoft Defender for DNS can be enabled at the subscription level.
","tags":["Azure.Defender.Dns","AZR-000353"]},{"location":"en/rules/Azure.Defender.Dns/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for DNS to provide additional protection to virtual network and resources.
","tags":["Azure.Defender.Dns","AZR-000353"]},{"location":"en/rules/Azure.Defender.Dns/#examples","title":"Examples","text":"","tags":["Azure.Defender.Dns","AZR-000353"]},{"location":"en/rules/Azure.Defender.Dns/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Microsoft Defender for DNS:
Standard
pricing tier for Microsoft Defender for DNS.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"Dns\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.Defender.Dns","AZR-000353"]},{"location":"en/rules/Azure.Defender.Dns/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Microsoft Defender for DNS:
Standard
pricing tier for Microsoft Defender for DNS.For example:
Azure Bicep snippetresource defenderForDns 'Microsoft.Security/pricings@2022-03-01' = {\n name: 'Dns'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.Defender.Dns","AZR-000353"]},{"location":"en/rules/Azure.Defender.Dns/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To enable Microsoft Defender for DNS:
Standard
pricing tier for Microsoft Defender for DNS.For example:
Azure CLI snippetaz security pricing create -n 'Dns' --tier 'standard'\n
","tags":["Azure.Defender.Dns","AZR-000353"]},{"location":"en/rules/Azure.Defender.Dns/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To enable Microsoft Defender for DNS:
Standard
pricing tier for Microsoft Defender for DNS.For example:
Azure PowerShell snippetSet-AzSecurityPricing -Name 'Dns' -PricingTier 'Standard'\n
","tags":["Azure.Defender.Dns","AZR-000353"]},{"location":"en/rules/Azure.Defender.Dns/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.Defender.Dns","AZR-000353"]},{"location":"en/rules/Azure.Defender.Dns/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2023_03 \u00b7 Critical
Enable Microsoft Defender for Key Vault.
","tags":["Azure.Defender.KeyVault","AZR-000352"]},{"location":"en/rules/Azure.Defender.KeyVault/#description","title":"Description","text":"Microsoft Defender for Key Vault provides additional protection for keys and secrets stored in Key Vaults. It does this by detecting unusual and potentially harmful attempts to access or exploit Key Vault accounts. This protection is provided by analyzing telemetry from Key Vault and Microsoft Defender for Cloud.
When anomalous activities occur, Defender for Key Vault shows alerts to relevant members of your organization. These alerts include the details of the suspicious activity and recommendations on how to investigate and remediate threats.
Microsoft Defender for Key Vault can be enabled at the subscription level for all Key Vaults in the subscription. Azure Policy can be used to automatically enable Microsoft Defender for Key Vault a subscription.
","tags":["Azure.Defender.KeyVault","AZR-000352"]},{"location":"en/rules/Azure.Defender.KeyVault/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for Key Vault to provide additional protection to Key Vaults.
","tags":["Azure.Defender.KeyVault","AZR-000352"]},{"location":"en/rules/Azure.Defender.KeyVault/#examples","title":"Examples","text":"","tags":["Azure.Defender.KeyVault","AZR-000352"]},{"location":"en/rules/Azure.Defender.KeyVault/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Microsoft Defender for Key Vault:
Standard
pricing tier for Microsoft Defender for Key Vault.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"KeyVaults\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.Defender.KeyVault","AZR-000352"]},{"location":"en/rules/Azure.Defender.KeyVault/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Microsoft Defender for Key Vault:
Standard
pricing tier for Microsoft Defender for Key Vault.For example:
Azure Bicep snippetresource defenderForKeyVaults 'Microsoft.Security/pricings@2022-03-01' = {\n name: 'KeyVaults'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.Defender.KeyVault","AZR-000352"]},{"location":"en/rules/Azure.Defender.KeyVault/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To enable Microsoft Defender for Key Vault:
Standard
pricing tier for Microsoft Defender for Key Vault.For example:
Azure CLI snippetaz security pricing create -n 'KeyVaults' --tier 'standard'\n
","tags":["Azure.Defender.KeyVault","AZR-000352"]},{"location":"en/rules/Azure.Defender.KeyVault/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To enable Microsoft Defender for Key Vault:
Standard
pricing tier for Microsoft Defender for Key Vault.For example:
Azure PowerShell snippetSet-AzSecurityPricing -Name 'KeyVaults' -PricingTier 'Standard'\n
","tags":["Azure.Defender.KeyVault","AZR-000352"]},{"location":"en/rules/Azure.Defender.KeyVault/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.Defender.KeyVault","AZR-000352"]},{"location":"en/rules/Azure.Defender.KeyVault/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2023_06 \u00b7 Critical
Enable Microsoft Defender for open-source relational databases.
","tags":["Azure.Defender.OssRdb","AZR-000381"]},{"location":"en/rules/Azure.Defender.OssRdb/#description","title":"Description","text":"Microsoft Defender for open-source relational databases provides additional security for open-source relational databases.
The following open-source relational databases are supported:
Protection is provided by analyzing onboarded databases for unusual and potentially harmful attempts to access or exploit databases. Which allows Microsoft Defender for Cloud to produce security alerts that are triggered when anomalies in activity occur.
Security alerts for onboarded databases shows up in Defender for Cloud with details of the suspicious activity and recommendations on how to investigate and remediate the threats.
Microsoft Defender for open-source relational databases can be enabled at the subscription level and by doing so ensures all supported databases in the subscription will be protected, including future ones.
","tags":["Azure.Defender.OssRdb","AZR-000381"]},{"location":"en/rules/Azure.Defender.OssRdb/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for for open-source relational databases to provide additional security for open-source relational databases.
","tags":["Azure.Defender.OssRdb","AZR-000381"]},{"location":"en/rules/Azure.Defender.OssRdb/#examples","title":"Examples","text":"","tags":["Azure.Defender.OssRdb","AZR-000381"]},{"location":"en/rules/Azure.Defender.OssRdb/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Microsoft Defender for open-source relational databases:
Standard
pricing tier for Microsoft Defender for open-source relational databases.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"OpenSourceRelationalDatabases\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.Defender.OssRdb","AZR-000381"]},{"location":"en/rules/Azure.Defender.OssRdb/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Microsoft Defender for open-source relational databases:
Standard
pricing tier for Microsoft Defender for open-source relational databases.For example:
Azure Bicep snippetresource defenderForOssRdb 'Microsoft.Security/pricings@2022-03-01' = {\n name: 'OpenSourceRelationalDatabases'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.Defender.OssRdb","AZR-000381"]},{"location":"en/rules/Azure.Defender.OssRdb/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To enable Microsoft Defender for open-source relational databases:
Standard
pricing tier for Microsoft Defender for open-source relational databases.For example:
Azure CLI snippetaz security pricing create -n 'OpenSourceRelationalDatabases' --tier 'standard'\n
","tags":["Azure.Defender.OssRdb","AZR-000381"]},{"location":"en/rules/Azure.Defender.OssRdb/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To enable Microsoft Defender for open-source relational databases:
Standard
pricing tier for Microsoft Defender for open-source relational databases.For example:
Azure PowerShell snippetSet-AzSecurityPricing -Name 'OpenSourceRelationalDatabases' -PricingTier 'Standard'\n
","tags":["Azure.Defender.OssRdb","AZR-000381"]},{"location":"en/rules/Azure.Defender.OssRdb/#notes","title":"Notes","text":"Microsoft Defender for open-source relational databases is currently available only for the single server deployment model for PostgreSQL and the single server deployment model for MySQL. For PostgreSQL, MySQL and MariaDB General Purpose
and Memory Optimized
tiers are required in order to be protected.
Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Enable Microsoft Defender for SQL servers.
","tags":["Azure.Defender.SQL","AZR-000294"]},{"location":"en/rules/Azure.Defender.SQL/#description","title":"Description","text":"SQL databases are used to store critical and strategic assets for your company and should be carefully secured. Microsoft Defender for SQL represents a single go-to location to manage security capabilities.
Enabling Defender for SQL automatically enables the following advanced SQL security capabilities:
When enable at subscription level, all databases in Azure SQL Database and Azure SQL Managed Instance are protected.
","tags":["Azure.Defender.SQL","AZR-000294"]},{"location":"en/rules/Azure.Defender.SQL/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for SQL to protect your SQL databases.
","tags":["Azure.Defender.SQL","AZR-000294"]},{"location":"en/rules/Azure.Defender.SQL/#examples","title":"Examples","text":"","tags":["Azure.Defender.SQL","AZR-000294"]},{"location":"en/rules/Azure.Defender.SQL/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Microsoft Defender for SQL:
Standard
pricing tier for Microsoft Defender for SQL.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"SqlServers\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.Defender.SQL","AZR-000294"]},{"location":"en/rules/Azure.Defender.SQL/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Microsoft Defender for SQL:
Standard
pricing tier for Microsoft Defender for SQL.For example:
Azure Bicep snippetresource defenderForSQL 'Microsoft.Security/pricings@2022-03-01' = {\n name: 'SqlServers'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.Defender.SQL","AZR-000294"]},{"location":"en/rules/Azure.Defender.SQL/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To enable Microsoft Defender for SQL:
Standard
pricing tier for Microsoft Defender for SQL.For example:
Azure CLI snippetaz security pricing create -n 'SqlServers' --tier 'standard'\n
","tags":["Azure.Defender.SQL","AZR-000294"]},{"location":"en/rules/Azure.Defender.SQL/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To enable Microsoft Defender for SQL:
Standard
pricing tier for Microsoft Defender for SQL.For example:
Azure PowerShell snippetSet-AzSecurityPricing -Name 'SqlServers' -PricingTier 'Standard'\n
","tags":["Azure.Defender.SQL","AZR-000294"]},{"location":"en/rules/Azure.Defender.SQL/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.Defender.SQL","AZR-000294"]},{"location":"en/rules/Azure.Defender.SQL/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Enable Microsoft Defender for SQL servers on machines.
","tags":["Azure.Defender.SQLOnVM","AZR-000297"]},{"location":"en/rules/Azure.Defender.SQLOnVM/#description","title":"Description","text":"SQL databases are used to store critical and strategic assets for your company and should be carefully secured. Microsoft Defender for SQL Servers on machines represents a single go-to location to manage security capabilities.
Enabling Defender for SQL automatically enables vulnerability Assessment for your SQL databases hosted in a VM. It discovers, tracks, and provides guidance to remediate potential database vulnerabilities.
Enabling at subscription level doesn't protect all your SQL servers. A Log Analytics agent must be deployed on the machine and the Log Analytics workspace must have Defender for SQL enabled.
","tags":["Azure.Defender.SQLOnVM","AZR-000297"]},{"location":"en/rules/Azure.Defender.SQLOnVM/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for SQL Servers on machines to protect your SQL servers running on VMs.
","tags":["Azure.Defender.SQLOnVM","AZR-000297"]},{"location":"en/rules/Azure.Defender.SQLOnVM/#examples","title":"Examples","text":"","tags":["Azure.Defender.SQLOnVM","AZR-000297"]},{"location":"en/rules/Azure.Defender.SQLOnVM/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Defender for SQL servers on machines:
Standard
pricing tier for Microsoft Defender for SQL servers on machines.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"SqlServerVirtualMachines\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.Defender.SQLOnVM","AZR-000297"]},{"location":"en/rules/Azure.Defender.SQLOnVM/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Defender for SQL servers on machines:
Standard
pricing tier for Microsoft Defender for SQL servers on machines.For example:
Azure Bicep snippetresource defenderForSQLOnVM 'Microsoft.Security/pricings@2022-03-01' = {\n name: 'SqlServerVirtualMachines'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.Defender.SQLOnVM","AZR-000297"]},{"location":"en/rules/Azure.Defender.SQLOnVM/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz security pricing create -n 'SqlServerVirtualMachines' --tier 'standard'\n
","tags":["Azure.Defender.SQLOnVM","AZR-000297"]},{"location":"en/rules/Azure.Defender.SQLOnVM/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetSet-AzSecurityPricing -Name 'SqlServerVirtualMachines' -PricingTier 'Standard'\n
","tags":["Azure.Defender.SQLOnVM","AZR-000297"]},{"location":"en/rules/Azure.Defender.SQLOnVM/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.Defender.SQLOnVM","AZR-000297"]},{"location":"en/rules/Azure.Defender.SQLOnVM/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Enable Microsoft Defender for Servers.
","tags":["Azure.Defender.Servers","AZR-000293"]},{"location":"en/rules/Azure.Defender.Servers/#description","title":"Description","text":"Microsoft Defender for Servers automatically deploys an agent into your Windows and Linux machines to protect them.
With the unified integration of Microsoft Defender for Endpoint (MDE) you benefit from features like:
Consider using Microsoft Defender for Servers P2 to protect your virtual machines.
","tags":["Azure.Defender.Servers","AZR-000293"]},{"location":"en/rules/Azure.Defender.Servers/#examples","title":"Examples","text":"","tags":["Azure.Defender.Servers","AZR-000293"]},{"location":"en/rules/Azure.Defender.Servers/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Defender for Servers:
Standard
pricing tier for Microsoft Defender for Servers and set the P2
sub plan.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"VirtualMachines\",\n \"properties\": {\n \"pricingTier\": \"Standard\",\n \"subPlan\": \"P2\"\n }\n}\n
","tags":["Azure.Defender.Servers","AZR-000293"]},{"location":"en/rules/Azure.Defender.Servers/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Defender for Servers:
Standard
pricing tier for Microsoft Defender for Servers and set the P2
sub plan.For example:
Azure Bicep snippetresource defenderForServers 'Microsoft.Security/pricings@2022-03-01' = {\n name: 'VirtualMachines'\n properties: {\n pricingTier: 'Standard',\n subPlan: 'P2'\n }\n}\n
","tags":["Azure.Defender.Servers","AZR-000293"]},{"location":"en/rules/Azure.Defender.Servers/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz security pricing create -n 'VirtualMachines' --tier 'standard'\n
","tags":["Azure.Defender.Servers","AZR-000293"]},{"location":"en/rules/Azure.Defender.Servers/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetSet-AzSecurityPricing -Name 'VirtualMachines' -PricingTier 'Standard'\n
","tags":["Azure.Defender.Servers","AZR-000293"]},{"location":"en/rules/Azure.Defender.Servers/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.Defender.Servers","AZR-000293"]},{"location":"en/rules/Azure.Defender.Servers/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 Preview \u00b7 2023_06 \u00b7 Critical
Enable sensitive data threat detection in Microsoft Defender for Storage.
","tags":["Azure.Defender.Storage.DataScan","AZR-000385"]},{"location":"en/rules/Azure.Defender.Storage.DataScan/#description","title":"Description","text":"Sensitive data threat detection is an additional security feature for Microsoft Defender for Storage. When enabled Defender for Storage provides alerts when sensitive data is discovered.
The sensitive data threat detection capability helps teams:
When enabling sensitive data threat detection, the sensitive data categories include built-in sensitive information types (SITs) in the default list of Microsoft Purview. It is possible to customize the Data Sensitivity Discovery for a organization, by creating custom sensitive information types (SITs).
Sensitive data threat detection in Microsoft Defender for Storage can be enabled at the subscription level and by doing so ensures all storage accounts in the subscription will be protected, including future ones.
","tags":["Azure.Defender.Storage.DataScan","AZR-000385"]},{"location":"en/rules/Azure.Defender.Storage.DataScan/#recommendation","title":"Recommendation","text":"Consider using sensitive data threat detection in Microsoft Defender for Storage for all storage accounts in the subscription.
","tags":["Azure.Defender.Storage.DataScan","AZR-000385"]},{"location":"en/rules/Azure.Defender.Storage.DataScan/#examples","title":"Examples","text":"","tags":["Azure.Defender.Storage.DataScan","AZR-000385"]},{"location":"en/rules/Azure.Defender.Storage.DataScan/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable sensitive data threat detection in Microsoft Defender for Storage:
properties.pricingTier
property to Standard
.properties.subPlan
property to DefenderForStorageV2
.SensitiveDataDiscovery
extension.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2024-01-01\",\n \"name\": \"StorageAccounts\",\n \"properties\": {\n \"pricingTier\": \"Standard\",\n \"subPlan\": \"DefenderForStorageV2\",\n \"extensions\": [\n {\n \"name\": \"OnUploadMalwareScanning\",\n \"isEnabled\": \"True\",\n \"additionalExtensionProperties\": {\n \"CapGBPerMonthPerStorageAccount\": \"5000\"\n }\n },\n {\n \"name\": \"SensitiveDataDiscovery\",\n \"isEnabled\": \"True\"\n }\n ]\n }\n}\n
","tags":["Azure.Defender.Storage.DataScan","AZR-000385"]},{"location":"en/rules/Azure.Defender.Storage.DataScan/#configure-with-bicep","title":"Configure with Bicep","text":"To enable sensitive data threat detection in Microsoft Defender for Storage:
properties.pricingTier
property to Standard
.properties.subPlan
property to DefenderForStorageV2
.SensitiveDataDiscovery
extension.For example:
Azure Bicep snippetresource defenderForStorage 'Microsoft.Security/pricings@2024-01-01' = {\n name: 'StorageAccounts'\n properties: {\n pricingTier: 'Standard'\n subPlan: 'DefenderForStorageV2'\n extensions: [\n {\n name: 'OnUploadMalwareScanning'\n isEnabled: 'True'\n additionalExtensionProperties: {\n CapGBPerMonthPerStorageAccount: '5000'\n }\n }\n {\n name: 'SensitiveDataDiscovery'\n isEnabled: 'True'\n }\n ]\n }\n}\n
","tags":["Azure.Defender.Storage.DataScan","AZR-000385"]},{"location":"en/rules/Azure.Defender.Storage.DataScan/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/640d2586-54d2-465f-877f-9ffc1d2109f4
/providers/Microsoft.Authorization/policyDefinitions/cfdc5972-75b3-4418-8ae1-7f5c36839390
This feature is currently in preview.
Sensitive data threat detection is only available in the DefenderForStorageV2
sub plan for Defender for Storage, which offers new features that aren't included in the classic plan.
Not all services and blob types within storage accounts are currently supported. See limitations for more information.
","tags":["Azure.Defender.Storage.DataScan","AZR-000385"]},{"location":"en/rules/Azure.Defender.Storage.DataScan/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2024_03 \u00b7 Critical
Enable Malware Scanning in Microsoft Defender for Storage.
","tags":["Azure.Defender.Storage.MalwareScan","AZR-000383"]},{"location":"en/rules/Azure.Defender.Storage.MalwareScan/#description","title":"Description","text":"Microsoft Defender for Storage provides additional security for storage accounts. One of the features in the Defender for Storage service is malware scanning that is powered by Microsoft Defender Antivirus.
Content uploaded to cloud storage could be malware. Storage accounts can be an entry point and distribution point for malware in the organization. To protect organizations from this threat, content in cloud storage must be scanned for malware before it's accessed.
Malware scanning in Defender for Storage helps protect storage accounts from malicious content by, performing a malware scan on uploaded content in near real time. When the malware scan identifies a malicious file, detailed Microsoft Defenders for Cloud security alerts are generated.
Malware Scanning in Microsoft Defender for Storage can be enabled at the subscription level. This ensures all storage accounts in the subscription will be protected, including future ones.
This can be helpful:
Consider using malware scanning in Microsoft Defender for Storage for all storage accounts in the subscription.
","tags":["Azure.Defender.Storage.MalwareScan","AZR-000383"]},{"location":"en/rules/Azure.Defender.Storage.MalwareScan/#examples","title":"Examples","text":"","tags":["Azure.Defender.Storage.MalwareScan","AZR-000383"]},{"location":"en/rules/Azure.Defender.Storage.MalwareScan/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable malware scanning in Microsoft Defender for Storage:
properties.pricingTier
property to Standard
.properties.subPlan
property to DefenderForStorageV2
.OnUploadMalwareScanning
extension.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2024-01-01\",\n \"name\": \"StorageAccounts\",\n \"properties\": {\n \"pricingTier\": \"Standard\",\n \"subPlan\": \"DefenderForStorageV2\",\n \"extensions\": [\n {\n \"name\": \"OnUploadMalwareScanning\",\n \"isEnabled\": \"True\",\n \"additionalExtensionProperties\": {\n \"CapGBPerMonthPerStorageAccount\": \"5000\"\n }\n },\n {\n \"name\": \"SensitiveDataDiscovery\",\n \"isEnabled\": \"True\"\n }\n ]\n }\n}\n
","tags":["Azure.Defender.Storage.MalwareScan","AZR-000383"]},{"location":"en/rules/Azure.Defender.Storage.MalwareScan/#configure-with-bicep","title":"Configure with Bicep","text":"To enable malware scanning in Microsoft Defender for Storage:
properties.pricingTier
property to Standard
.properties.subPlan
property to DefenderForStorageV2
.OnUploadMalwareScanning
extension.For example:
Azure Bicep snippetresource defenderForStorage 'Microsoft.Security/pricings@2024-01-01' = {\n name: 'StorageAccounts'\n properties: {\n pricingTier: 'Standard'\n subPlan: 'DefenderForStorageV2'\n extensions: [\n {\n name: 'OnUploadMalwareScanning'\n isEnabled: 'True'\n additionalExtensionProperties: {\n CapGBPerMonthPerStorageAccount: '5000'\n }\n }\n {\n name: 'SensitiveDataDiscovery'\n isEnabled: 'True'\n }\n ]\n }\n}\n
","tags":["Azure.Defender.Storage.MalwareScan","AZR-000383"]},{"location":"en/rules/Azure.Defender.Storage.MalwareScan/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/640d2586-54d2-465f-877f-9ffc1d2109f4
/providers/Microsoft.Authorization/policyDefinitions/cfdc5972-75b3-4418-8ae1-7f5c36839390
Malware scanning is only available in the DefenderForStorageV2
sub plan for Defender for Storage, which offers new features that aren't included in the classic plan.
Not all services and blob types within storage accounts are currently supported. See limitations for more information.
","tags":["Azure.Defender.Storage.MalwareScan","AZR-000383"]},{"location":"en/rules/Azure.Defender.Storage.MalwareScan/#links","title":"Links","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2023_06 \u00b7 Critical
Enable Microsoft Defender for Storage.
","tags":["Azure.Defender.Storage","AZR-000296"]},{"location":"en/rules/Azure.Defender.Storage/#description","title":"Description","text":"Microsoft Defender for Storage provides additional security for storage accounts.
Protection is provided by the following which allows Microsoft Defender for Cloud to discover and mitigate potential threats:
Security findings for on-boarded storage accounts shows up in Defender for Cloud with details of the security threats with contextual information.
Defender for Storage can be enabled at the subscription level. This ensures all storage accounts in the subscription will be protected, including future ones.
","tags":["Azure.Defender.Storage","AZR-000296"]},{"location":"en/rules/Azure.Defender.Storage/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for Storage to protect your data hosted in storage accounts.
","tags":["Azure.Defender.Storage","AZR-000296"]},{"location":"en/rules/Azure.Defender.Storage/#examples","title":"Examples","text":"","tags":["Azure.Defender.Storage","AZR-000296"]},{"location":"en/rules/Azure.Defender.Storage/#configure-with-azure-template","title":"Configure with Azure template","text":"To enable Defender for Storage:
properties.pricingTier
property to Standard
.properties.subPlan
property to DefenderForStorageV2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2024-01-01\",\n \"name\": \"StorageAccounts\",\n \"properties\": {\n \"pricingTier\": \"Standard\",\n \"subPlan\": \"DefenderForStorageV2\",\n \"extensions\": [\n {\n \"name\": \"OnUploadMalwareScanning\",\n \"isEnabled\": \"True\",\n \"additionalExtensionProperties\": {\n \"CapGBPerMonthPerStorageAccount\": \"5000\"\n }\n },\n {\n \"name\": \"SensitiveDataDiscovery\",\n \"isEnabled\": \"True\"\n }\n ]\n }\n}\n
","tags":["Azure.Defender.Storage","AZR-000296"]},{"location":"en/rules/Azure.Defender.Storage/#configure-with-bicep","title":"Configure with Bicep","text":"To enable Defender for Storage:
properties.pricingTier
property to Standard
.properties.subPlan
property to DefenderForStorageV2
.For example:
Azure Bicep snippetresource defenderForStorage 'Microsoft.Security/pricings@2024-01-01' = {\n name: 'StorageAccounts'\n properties: {\n pricingTier: 'Standard'\n subPlan: 'DefenderForStorageV2'\n extensions: [\n {\n name: 'OnUploadMalwareScanning'\n isEnabled: 'True'\n additionalExtensionProperties: {\n CapGBPerMonthPerStorageAccount: '5000'\n }\n }\n {\n name: 'SensitiveDataDiscovery'\n isEnabled: 'True'\n }\n ]\n }\n}\n
","tags":["Azure.Defender.Storage","AZR-000296"]},{"location":"en/rules/Azure.Defender.Storage/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetSet-AzSecurityPricing -Name 'StorageAccounts' -PricingTier 'Standard' -SubPlan 'DefenderForStorageV2'\n
","tags":["Azure.Defender.Storage","AZR-000296"]},{"location":"en/rules/Azure.Defender.Storage/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/640d2586-54d2-465f-877f-9ffc1d2109f4
/providers/Microsoft.Authorization/policyDefinitions/cfdc5972-75b3-4418-8ae1-7f5c36839390
The DefenderForStorageV2
sub plan represents the new Defender for Storage plan which offers several new benefits that aren't included in the classic plan. The new plan includes more advanced capabilities that can help improve the security of the data and help prevent malicious file uploads, sensitive data exfiltration, and data corruption.
Currently only the Blob Storage
, Azure Files
and Azure Data Lake Storage Gen2
service is supported by Defender for Storage.
Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Microsoft Defender for Cloud email and phone contact details should be set.
","tags":["Azure.DefenderCloud.Contact","AZR-000209"]},{"location":"en/rules/Azure.DefenderCloud.Contact/#description","title":"Description","text":"Security contact details configured in Microsoft Defender for Cloud are used by Microsoft to notify you in response to certain security events.
","tags":["Azure.DefenderCloud.Contact","AZR-000209"]},{"location":"en/rules/Azure.DefenderCloud.Contact/#recommendation","title":"Recommendation","text":"Consider configuring Microsoft Defender for Cloud email and phone contact details.
","tags":["Azure.DefenderCloud.Contact","AZR-000209"]},{"location":"en/rules/Azure.DefenderCloud.Contact/#link","title":"LINK","text":"Security \u00b7 Microsoft Defender for Cloud \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Enable auto-provisioning on to improve Microsoft Defender for Cloud insights.
","tags":["Azure.DefenderCloud.Provisioning","AZR-000210"]},{"location":"en/rules/Azure.DefenderCloud.Provisioning/#description","title":"Description","text":"Select resources such as virtual machines (VMs) and VM scale sets require an agent to be installed to collect additional information from the operating system (OS). This information is used to identify missing security updates and additional threats.
By turning auto-provisioning on, Microsoft Defender for Cloud automatically deploys an Azure Monitor agent to VMs on a regular basis.
","tags":["Azure.DefenderCloud.Provisioning","AZR-000210"]},{"location":"en/rules/Azure.DefenderCloud.Provisioning/#recommendation","title":"Recommendation","text":"Consider enabling auto-provisioning to improve Azure Microsoft Defender for Cloud VM insights.
","tags":["Azure.DefenderCloud.Provisioning","AZR-000210"]},{"location":"en/rules/Azure.DefenderCloud.Provisioning/#links","title":"Links","text":"Security \u00b7 Deployment \u00b7 Rule \u00b7 2022_09 \u00b7 Awareness
Use secure parameters for sensitive resource properties.
","tags":["Azure.Deployment.AdminUsername","AZR-000284"]},{"location":"en/rules/Azure.Deployment.AdminUsername/#description","title":"Description","text":"Resource properties can be configured using a hardcoded value or Azure Bicep/ template expressions. When specifying sensitive values use secure parameters such as secureString
or secureObject
.
Sensitive values that use deterministic expressions such as hardcodes string literals or variables are not secure.
","tags":["Azure.Deployment.AdminUsername","AZR-000284"]},{"location":"en/rules/Azure.Deployment.AdminUsername/#recommendation","title":"Recommendation","text":"Sensitive properties should be passed as parameters. Avoid using deterministic values for sensitive properties.
","tags":["Azure.Deployment.AdminUsername","AZR-000284"]},{"location":"en/rules/Azure.Deployment.AdminUsername/#examples","title":"Examples","text":"","tags":["Azure.Deployment.AdminUsername","AZR-000284"]},{"location":"en/rules/Azure.Deployment.AdminUsername/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy resources that pass this rule:
For example:
Azure Template snippet{\n \"type\": \"Microsoft.Compute/virtualMachines\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"zones\": [\n \"1\"\n ],\n \"properties\": {\n \"hardwareProfile\": {\n \"vmSize\": \"Standard_D2s_v3\"\n },\n \"osProfile\": {\n \"computerName\": \"[parameters('name')]\",\n \"adminUsername\": \"[parameters('adminUsername')]\",\n \"adminPassword\": \"[parameters('adminPassword')]\"\n },\n \"storageProfile\": {\n \"imageReference\": {\n \"publisher\": \"MicrosoftWindowsServer\",\n \"offer\": \"WindowsServer\",\n \"sku\": \"[parameters('sku')]\",\n \"version\": \"latest\"\n },\n \"osDisk\": {\n \"name\": \"[format('{0}-disk0', parameters('name'))]\",\n \"caching\": \"ReadWrite\",\n \"createOption\": \"FromImage\",\n \"managedDisk\": {\n \"storageAccountType\": \"Premium_LRS\"\n }\n }\n },\n \"licenseType\": \"Windows_Server\",\n \"networkProfile\": {\n \"networkInterfaces\": [\n {\n \"id\": \"[resourceId('Microsoft.Network/networkInterfaces', format('{0}-nic0', parameters('name')))]\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Network/networkInterfaces', format('{0}-nic0', parameters('name')))]\"\n ]\n}\n
","tags":["Azure.Deployment.AdminUsername","AZR-000284"]},{"location":"en/rules/Azure.Deployment.AdminUsername/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy resources that pass this rule:
For example:
Azure Bicep snippet@secure()\n@description('The name of the local administrator account.')\nparam adminUsername string\n\n@secure()\n@description('A password for the local administrator account.')\nparam adminPassword string\n\nresource vm1 'Microsoft.Compute/virtualMachines@2022-03-01' = {\n name: name\n location: location\n zones: [\n '1'\n ]\n properties: {\n hardwareProfile: {\n vmSize: 'Standard_D2s_v3'\n }\n osProfile: {\n computerName: name\n adminUsername: adminUsername\n adminPassword: adminPassword\n }\n storageProfile: {\n imageReference: {\n publisher: 'MicrosoftWindowsServer'\n offer: 'WindowsServer'\n sku: sku\n version: 'latest'\n }\n osDisk: {\n name: '${name}-disk0'\n caching: 'ReadWrite'\n createOption: 'FromImage'\n managedDisk: {\n storageAccountType: 'Premium_LRS'\n }\n }\n }\n licenseType: 'Windows_Server'\n networkProfile: {\n networkInterfaces: [\n {\n id: nic.id\n }\n ]\n }\n }\n}\n
","tags":["Azure.Deployment.AdminUsername","AZR-000284"]},{"location":"en/rules/Azure.Deployment.AdminUsername/#notes","title":"Notes","text":"Configure AZURE_DEPLOYMENT_SENSITIVE_PROPERTY_NAMES
to specify sensitive property names. By default, the following values are used:
adminUsername
administratorLogin
administratorLoginPassword
Operational Excellence \u00b7 Deployment \u00b7 Rule \u00b7 2023_03 \u00b7 Awareness
Nested deployments should meet naming requirements of deployments.
","tags":["Azure.Deployment.Name","AZR-000359"]},{"location":"en/rules/Azure.Deployment.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Azure deployments names are:
Consider using nested deployment names thas meets naming requirements of deployments. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.Deployment.Name","AZR-000359"]},{"location":"en/rules/Azure.Deployment.Name/#notes","title":"Notes","text":"This rule does not check if nested deployment names are unique.
","tags":["Azure.Deployment.Name","AZR-000359"]},{"location":"en/rules/Azure.Deployment.Name/#links","title":"Links","text":"Security \u00b7 Deployment \u00b7 Rule \u00b7 2022_12 \u00b7 Critical
Do not use Outer deployments when references SecureString or SecureObject parameters.
","tags":["Azure.Deployment.OuterSecret","AZR-000331"]},{"location":"en/rules/Azure.Deployment.OuterSecret/#description","title":"Description","text":"Template child deployments can be scoped as either outer
or inner
. When using outer
scope evaluated deployments, parameters from the parent template are used directly within nested templates instead of enforcing secureString
and secureObject
types.
When passing secure values to nested deployments always use inner
scope deployments to ensure secure values are not logging. Bicep modules always use inner
scope evaluated deployments.
Consider using inner
deployments to prevent secure values from being exposed.
Nested Deployments within an ARM template need the property expressionEvaluationOptions.Scope
to be set to inner
.
{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"adminUsername\": {\n \"type\": \"securestring\",\n \"defaultValue\": \"admin\"\n }\n },\n \"resources\": [\n {\n \"name\": \"nestedDeployment-A\",\n \"type\": \"Microsoft.Resources/deployments\",\n \"apiVersion\": \"2020-10-01\",\n \"properties\": {\n \"expressionEvaluationOptions\": {\n \"scope\": \"inner\"\n },\n \"mode\": \"Incremental\",\n \"template\": {\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"adminUsername\": {\n \"type\": \"securestring\",\n \"defaultValue\": \"password\"\n }\n },\n \"variables\": {},\n \"resources\": [\n {\n \"apiVersion\": \"2019-12-01\",\n \"type\": \"Microsoft.Compute/virtualMachines\",\n \"name\": \"vm-example\",\n \"location\": \"australiaeast\",\n \"properties\": {\n \"osProfile\": {\n \"computerName\": \"vm-example\",\n \"adminUsername\": \"[parameters('adminUsername')]\"\n }\n }\n }\n ]\n }\n }\n }\n ]\n}\n
","tags":["Azure.Deployment.OuterSecret","AZR-000331"]},{"location":"en/rules/Azure.Deployment.OuterSecret/#configure-with-bicep","title":"Configure with Bicep","text":"Bicep templates will do this by default when performing nested deployments.
","tags":["Azure.Deployment.OuterSecret","AZR-000331"]},{"location":"en/rules/Azure.Deployment.OuterSecret/#links","title":"Links","text":"Security \u00b7 Deployment \u00b7 Rule \u00b7 2022_06 \u00b7 Critical
Avoid outputting sensitive deployment values.
","tags":["Azure.Deployment.OutputSecretValue","AZR-000279"]},{"location":"en/rules/Azure.Deployment.OutputSecretValue/#description","title":"Description","text":"Don't include any values in an ARM template or Bicep output that could potentially expose secrets. The output from a template is stored in the deployment history, so a malicious user could find that information.
Examples of secrets are:
secureString
or secureObject
type.list*
functions such as listKeys
.Consider removing any output values that return secret values in code.
","tags":["Azure.Deployment.OutputSecretValue","AZR-000279"]},{"location":"en/rules/Azure.Deployment.OutputSecretValue/#examples","title":"Examples","text":"","tags":["Azure.Deployment.OutputSecretValue","AZR-000279"]},{"location":"en/rules/Azure.Deployment.OutputSecretValue/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy securely pass secrets within Infrastructure as Code:
secureString
or secureObject
type.Example using secureString
type:
{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"adminPassword\": {\n \"type\": \"secureString\",\n \"metadata\": {\n \"description\": \"Local administrator password for virtual machine.\"\n }\n }\n },\n \"resources\": []\n}\n
The following example fails because it returns a secret:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"adminPassword\": {\n \"type\": \"secureString\",\n \"metadata\": {\n \"description\": \"Local administrator password for virtual machine.\"\n }\n }\n },\n \"resources\": [],\n \"outputs\": {\n \"accountPassword\": {\n \"type\": \"string\",\n \"value\": \"[parameters('adminPassword')]\"\n }\n }\n}\n
","tags":["Azure.Deployment.OutputSecretValue","AZR-000279"]},{"location":"en/rules/Azure.Deployment.OutputSecretValue/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy securely pass secrets within Infrastructure as Code:
@secure()
annotation.Example using @secure()
annotation:
@secure()\n@description('Local administrator password for virtual machine.')\nparam adminPassword string\n
The following example fails because it returns a secret:
Azure Bicep snippetoutput accountPassword string = adminPassword\n
","tags":["Azure.Deployment.OutputSecretValue","AZR-000279"]},{"location":"en/rules/Azure.Deployment.OutputSecretValue/#links","title":"Links","text":"Security \u00b7 Deployment \u00b7 Rule \u00b7 2023_12 \u00b7 Critical
Use secure parameters for any parameter that contains sensitive information.
","tags":["Azure.Deployment.SecureParameter","AZR-000408"]},{"location":"en/rules/Azure.Deployment.SecureParameter/#description","title":"Description","text":"Azure Bicep and Azure Resource Manager (ARM) templates can be used to deploy resources to Azure. When deploying Azure resources, sensitive values such as passwords, certificates, and keys should be passed as secure parameters. Secure parameters use the secureString
or secureObject
type.
Parameters that do not use secure types are recorded in logs and deployment history. These values can be retrieved by anyone with access to the deployment history.
","tags":["Azure.Deployment.SecureParameter","AZR-000408"]},{"location":"en/rules/Azure.Deployment.SecureParameter/#recommendation","title":"Recommendation","text":"Consider using secure parameters for parameters that contain sensitive information.
","tags":["Azure.Deployment.SecureParameter","AZR-000408"]},{"location":"en/rules/Azure.Deployment.SecureParameter/#examples","title":"Examples","text":"","tags":["Azure.Deployment.SecureParameter","AZR-000408"]},{"location":"en/rules/Azure.Deployment.SecureParameter/#configure-with-azure-template","title":"Configure with Azure template","text":"To configure deployments that pass this rule:
secureString
or secureObject
.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"secret\": {\n \"type\": \"secureString\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.KeyVault/vaults/secrets\",\n \"apiVersion\": \"2022-07-01\",\n \"name\": \"keyvault/good\",\n \"properties\": {\n \"value\": \"[parameters('secret')]\"\n }\n }\n ]\n}\n
","tags":["Azure.Deployment.SecureParameter","AZR-000408"]},{"location":"en/rules/Azure.Deployment.SecureParameter/#configure-with-bicep","title":"Configure with Bicep","text":"To configure deployments that pass this rule:
@secure()
attribute on sensitive parameters.For example:
Azure Bicep snippet@secure()\nparam secret string\n\nresource goodSecret 'Microsoft.KeyVault/vaults/secrets@2022-07-01' = {\n parent: vault\n name: 'good'\n properties: {\n value: secret\n }\n}\n
","tags":["Azure.Deployment.SecureParameter","AZR-000408"]},{"location":"en/rules/Azure.Deployment.SecureParameter/#notes","title":"Notes","text":"This rule uses a heuristics to determine if a parameter should use a secure type:
int
or bool
are ignored regardless of how they are named.password
, secret
, or token
will be considered sensitive.passwordlength
, secretname
, secreturl
, secreturi
, secretrotation
, secretinterval
, secretprovider
, secretsprovider
, secretref
, secretid
, disablepassword
, sync*passwords
, or tokenname
.key
or keys
will be considered sensitive.publickey
or publickeys
.If you identify a parameter that is not sensitive, and is incorrectly flagged by this rule, you can override the rule. To override this rule:
AZURE_DEPLOYMENT_NONSENSITIVE_PARAMETER_NAMES
configuration value to identify parameters that are not sensitive.Security \u00b7 Deployment \u00b7 Rule \u00b7 2022_12 \u00b7 Critical
Use secure parameters for setting properties of resources that contain sensitive information.
","tags":["Azure.Deployment.SecureValue","AZR-000316"]},{"location":"en/rules/Azure.Deployment.SecureValue/#description","title":"Description","text":"Azure Bicep and Azure Resource Manager (ARM) templates can be used to deploy resources to Azure. When deploying Azure resources, sensitive values such as passwords, certificates, and keys should be passed as secure parameters. Secure parameters use the secureString
or secureObject
type.
Parameters that do not use secure types are recorded in logs and deployment history. These values can be retrieved by anyone with access to the deployment history.
","tags":["Azure.Deployment.SecureValue","AZR-000316"]},{"location":"en/rules/Azure.Deployment.SecureValue/#recommendation","title":"Recommendation","text":"Consider using secure parameters for sensitive resource properties.
","tags":["Azure.Deployment.SecureValue","AZR-000316"]},{"location":"en/rules/Azure.Deployment.SecureValue/#examples","title":"Examples","text":"","tags":["Azure.Deployment.SecureValue","AZR-000316"]},{"location":"en/rules/Azure.Deployment.SecureValue/#configure-with-azure-template","title":"Configure with Azure template","text":"To configure deployments that pass this rule:
secureString
or secureObject
.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"secret\": {\n \"type\": \"secureString\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.KeyVault/vaults/secrets\",\n \"apiVersion\": \"2022-07-01\",\n \"name\": \"keyvault/good\",\n \"properties\": {\n \"value\": \"[parameters('secret')]\"\n }\n }\n ]\n}\n
","tags":["Azure.Deployment.SecureValue","AZR-000316"]},{"location":"en/rules/Azure.Deployment.SecureValue/#configure-with-bicep","title":"Configure with Bicep","text":"To configure deployments that pass this rule:
@secure()
attribute on parameters used to set sensitive resource properties.For example:
Azure Bicep snippet@secure()\nparam secret string\n\nresource goodSecret 'Microsoft.KeyVault/vaults/secrets@2022-07-01' = {\n name: 'keyvault/good'\n properties: {\n value: secret\n }\n}\n
","tags":["Azure.Deployment.SecureValue","AZR-000316"]},{"location":"en/rules/Azure.Deployment.SecureValue/#notes","title":"Notes","text":"This rule checks the following resource type properties:
Microsoft.KeyVault/vaults/secrets
:properties.value
Microsoft.Compute/virtualMachineScaleSets
:properties.virtualMachineProfile.osProfile.adminPassword
Cost Optimization \u00b7 Dev Box \u00b7 Rule \u00b7 2024_03 \u00b7 Important
Limit the number of Dev Boxes a single user can create for a project.
","tags":["Azure.DevBox.ProjectLimit","AZR-000411"]},{"location":"en/rules/Azure.DevBox.ProjectLimit/#description","title":"Description","text":"Microsoft Dev Box is a service that allows users to create and manage a developer workstation in the cloud (Dev Boxes). Dev Boxes are virtual machines with specifications and configuration designed for developers. Each Dev Box is billed based on usage to a capped amount per month.
Dev Box Projects are used to manage Dev Boxes. By default, a single user can create multiple Dev Boxes for a single Dev Box Project. This can lead to unexpected costs.
Organizations should consider how many Dev Boxes are required for a single user and set reasonable limits.
","tags":["Azure.DevBox.ProjectLimit","AZR-000411"]},{"location":"en/rules/Azure.DevBox.ProjectLimit/#recommendation","title":"Recommendation","text":"Consider limiting the number of Dev Boxes a single user can create for any projects. Additional consider, configuring budgets and alerts to monitor cost exceptions.
","tags":["Azure.DevBox.ProjectLimit","AZR-000411"]},{"location":"en/rules/Azure.DevBox.ProjectLimit/#examples","title":"Examples","text":"","tags":["Azure.DevBox.ProjectLimit","AZR-000411"]},{"location":"en/rules/Azure.DevBox.ProjectLimit/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Dev Box Projects that pass this rule:
properties.maxDevBoxesPerUser
property to limit the number of Dev Box a single user can create. E.g. 2
For example:
Azure Template snippet{\n \"type\": \"Microsoft.DevCenter/projects\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"devCenterId\": \"[resourceId('Microsoft.DevCenter/devcenters', parameters('name'))]\",\n \"maxDevBoxesPerUser\": 2\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.DevCenter/devcenters', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.DevBox.ProjectLimit","AZR-000411"]},{"location":"en/rules/Azure.DevBox.ProjectLimit/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Dev Box Projects that pass this rule:
properties.maxDevBoxesPerUser
property to limit the number of Dev Box a single user can create. E.g. 2
For example:
Azure Bicep snippetresource project 'Microsoft.DevCenter/projects@2023-04-01' = {\n name: name\n location: location\n properties: {\n devCenterId: center.id\n maxDevBoxesPerUser: 2\n }\n}\n
","tags":["Azure.DevBox.ProjectLimit","AZR-000411"]},{"location":"en/rules/Azure.DevBox.ProjectLimit/#notes","title":"Notes","text":"The properties.maxDevBoxesPerUser
property does not limit the number of Dev Boxes a user can create across multiple projects.
Security \u00b7 Event Grid \u00b7 Rule \u00b7 2022_09 \u00b7 Important
Authenticate publishing clients with Azure AD identities.
","tags":["Azure.EventGrid.DisableLocalAuth","AZR-000100"]},{"location":"en/rules/Azure.EventGrid.DisableLocalAuth/#description","title":"Description","text":"To publish events to Event Grid access keys, SAS tokens, or Azure AD identities can be used. With Azure AD authentication, the identity is validated against the Microsoft Identity Platform. Using Azure AD identities centralizes identity management and auditing.
Once you decide to use Azure AD authentication, you can disable authentication using keys or SAS tokens.
","tags":["Azure.EventGrid.DisableLocalAuth","AZR-000100"]},{"location":"en/rules/Azure.EventGrid.DisableLocalAuth/#recommendation","title":"Recommendation","text":"Consider only using Azure AD identities to publish events to Event Grid. Then disable authentication based on access keys or SAS tokens.
","tags":["Azure.EventGrid.DisableLocalAuth","AZR-000100"]},{"location":"en/rules/Azure.EventGrid.DisableLocalAuth/#examples","title":"Examples","text":"","tags":["Azure.EventGrid.DisableLocalAuth","AZR-000100"]},{"location":"en/rules/Azure.EventGrid.DisableLocalAuth/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Event Grid Topics that pass this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.EventGrid/topics\",\n \"apiVersion\": \"2022-06-15\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"publicNetworkAccess\": \"Disabled\",\n \"inputSchema\": \"CloudEventSchemaV1_0\"\n }\n}\n
","tags":["Azure.EventGrid.DisableLocalAuth","AZR-000100"]},{"location":"en/rules/Azure.EventGrid.DisableLocalAuth/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Event Grid Topics that pass this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Bicep snippetresource eventGrid 'Microsoft.EventGrid/topics@2022-06-15' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n disableLocalAuth: true\n publicNetworkAccess: 'Disabled'\n inputSchema: 'CloudEventSchemaV1_0'\n }\n}\n
","tags":["Azure.EventGrid.DisableLocalAuth","AZR-000100"]},{"location":"en/rules/Azure.EventGrid.DisableLocalAuth/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
Security \u00b7 Event Grid \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Use managed identities to deliver Event Grid Topic events.
","tags":["Azure.EventGrid.ManagedIdentity","AZR-000099"]},{"location":"en/rules/Azure.EventGrid.ManagedIdentity/#description","title":"Description","text":"When delivering events you can use Managed Identities to authenticate event delivery. You can enable either system-assigned identity or user-assigned identity but not both. You can have at most two user-assigned identities assigned to a topic or domain.
","tags":["Azure.EventGrid.ManagedIdentity","AZR-000099"]},{"location":"en/rules/Azure.EventGrid.ManagedIdentity/#recommendation","title":"Recommendation","text":"Consider configuring a managed identity for each Event Grid Topic.
","tags":["Azure.EventGrid.ManagedIdentity","AZR-000099"]},{"location":"en/rules/Azure.EventGrid.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.EventGrid.ManagedIdentity","AZR-000099"]},{"location":"en/rules/Azure.EventGrid.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Event Grid Topics that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.EventGrid/topics\",\n \"apiVersion\": \"2022-06-15\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"publicNetworkAccess\": \"Disabled\",\n \"inputSchema\": \"CloudEventSchemaV1_0\"\n }\n}\n
","tags":["Azure.EventGrid.ManagedIdentity","AZR-000099"]},{"location":"en/rules/Azure.EventGrid.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Event Grid Topics that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource eventGrid 'Microsoft.EventGrid/topics@2022-06-15' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n disableLocalAuth: true\n publicNetworkAccess: 'Disabled'\n inputSchema: 'CloudEventSchemaV1_0'\n }\n}\n
","tags":["Azure.EventGrid.ManagedIdentity","AZR-000099"]},{"location":"en/rules/Azure.EventGrid.ManagedIdentity/#links","title":"Links","text":"Security \u00b7 Event Grid \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Use Private Endpoints to access Event Grid topics and domains.
","tags":["Azure.EventGrid.TopicPublicAccess","AZR-000098"]},{"location":"en/rules/Azure.EventGrid.TopicPublicAccess/#description","title":"Description","text":"By default, public network access is enabled for an Event Grid topic or domain. To allow access via private endpoints only, disable public network access.
","tags":["Azure.EventGrid.TopicPublicAccess","AZR-000098"]},{"location":"en/rules/Azure.EventGrid.TopicPublicAccess/#recommendation","title":"Recommendation","text":"Consider using Private Endpoints to access Event Grid topics and domains. To limit access to Event Grid topics and domains, disable public access.
","tags":["Azure.EventGrid.TopicPublicAccess","AZR-000098"]},{"location":"en/rules/Azure.EventGrid.TopicPublicAccess/#examples","title":"Examples","text":"","tags":["Azure.EventGrid.TopicPublicAccess","AZR-000098"]},{"location":"en/rules/Azure.EventGrid.TopicPublicAccess/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Event Grid Topics that pass this rule:
properties.publicNetworkAccess
property to Disabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.EventGrid/topics\",\n \"apiVersion\": \"2022-06-15\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"publicNetworkAccess\": \"Disabled\",\n \"inputSchema\": \"CloudEventSchemaV1_0\"\n }\n}\n
","tags":["Azure.EventGrid.TopicPublicAccess","AZR-000098"]},{"location":"en/rules/Azure.EventGrid.TopicPublicAccess/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Event Grid Topics that pass this rule:
properties.publicNetworkAccess
property to Disabled
.For example:
Azure Bicep snippetresource eventGrid 'Microsoft.EventGrid/topics@2022-06-15' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n disableLocalAuth: true\n publicNetworkAccess: 'Disabled'\n inputSchema: 'CloudEventSchemaV1_0'\n }\n}\n
","tags":["Azure.EventGrid.TopicPublicAccess","AZR-000098"]},{"location":"en/rules/Azure.EventGrid.TopicPublicAccess/#links","title":"Links","text":"Security \u00b7 Event Hub \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Authenticate Event Hub publishers and consumers with Entra ID identities.
","tags":["Azure.EventHub.DisableLocalAuth","AZR-000102"]},{"location":"en/rules/Azure.EventHub.DisableLocalAuth/#description","title":"Description","text":"To publish or consume events from Event Hubs cryptographic keys, or Entra ID (previously Azure AD) identities can be used. Cryptographic keys include Shared Access Policy keys or Shared Access Signature (SAS) tokens. With Entra ID authentication, the identity is validated against Azure AD. Using Entra ID identities centralizes identity management and auditing.
Once you decide to use Entra ID authentication, you can disable authentication using keys or SAS tokens.
","tags":["Azure.EventHub.DisableLocalAuth","AZR-000102"]},{"location":"en/rules/Azure.EventHub.DisableLocalAuth/#recommendation","title":"Recommendation","text":"Consider only using Entra ID identities to publish or consume events from Event Hub. Then disable authentication based on access keys or SAS tokens.
","tags":["Azure.EventHub.DisableLocalAuth","AZR-000102"]},{"location":"en/rules/Azure.EventHub.DisableLocalAuth/#examples","title":"Examples","text":"","tags":["Azure.EventHub.DisableLocalAuth","AZR-000102"]},{"location":"en/rules/Azure.EventHub.DisableLocalAuth/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Event Hub namespaces that pass this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.EventHub/namespaces\",\n \"apiVersion\": \"2024-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"Standard\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"minimumTlsVersion\": \"1.2\",\n \"publicNetworkAccess\": \"Disabled\",\n \"isAutoInflateEnabled\": true,\n \"maximumThroughputUnits\": 10,\n \"zoneRedundant\": true\n }\n}\n
","tags":["Azure.EventHub.DisableLocalAuth","AZR-000102"]},{"location":"en/rules/Azure.EventHub.DisableLocalAuth/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Event Hub namespaces that pass this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Bicep snippetresource ns 'Microsoft.EventHub/namespaces@2024-01-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'Standard'\n }\n properties: {\n disableLocalAuth: true\n minimumTlsVersion: '1.2'\n publicNetworkAccess: 'Disabled'\n isAutoInflateEnabled: true\n maximumThroughputUnits: 10\n zoneRedundant: true\n }\n}\n
","tags":["Azure.EventHub.DisableLocalAuth","AZR-000102"]},{"location":"en/rules/Azure.EventHub.DisableLocalAuth/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
Security \u00b7 Event Hub \u00b7 Rule \u00b7 2023_03 \u00b7 Critical
Event Hub namespaces should reject TLS versions older than 1.2.
","tags":["Azure.EventHub.MinTLS","AZR-000356"]},{"location":"en/rules/Azure.EventHub.MinTLS/#description","title":"Description","text":"The minimum version of TLS that Event Hub namespaces accept is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Azure lets you disable outdated protocols and require connections to use a minimum of TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 is accepted.
","tags":["Azure.EventHub.MinTLS","AZR-000356"]},{"location":"en/rules/Azure.EventHub.MinTLS/#recommendation","title":"Recommendation","text":"Configure the minimum supported TLS version to be 1.2.
","tags":["Azure.EventHub.MinTLS","AZR-000356"]},{"location":"en/rules/Azure.EventHub.MinTLS/#examples","title":"Examples","text":"","tags":["Azure.EventHub.MinTLS","AZR-000356"]},{"location":"en/rules/Azure.EventHub.MinTLS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Event Hub namespaces that pass this rule:
properties.minimumTlsVersion
property to 1.2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.EventHub/namespaces\",\n \"apiVersion\": \"2024-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"Standard\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"minimumTlsVersion\": \"1.2\",\n \"publicNetworkAccess\": \"Disabled\",\n \"isAutoInflateEnabled\": true,\n \"maximumThroughputUnits\": 10,\n \"zoneRedundant\": true\n }\n}\n
","tags":["Azure.EventHub.MinTLS","AZR-000356"]},{"location":"en/rules/Azure.EventHub.MinTLS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Event Hub namespaces that pass this rule:
properties.minimumTlsVersion
property to 1.2
.For example:
Azure Bicep snippetresource ns 'Microsoft.EventHub/namespaces@2024-01-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'Standard'\n }\n properties: {\n disableLocalAuth: true\n minimumTlsVersion: '1.2'\n publicNetworkAccess: 'Disabled'\n isAutoInflateEnabled: true\n maximumThroughputUnits: 10\n zoneRedundant: true\n }\n}\n
","tags":["Azure.EventHub.MinTLS","AZR-000356"]},{"location":"en/rules/Azure.EventHub.MinTLS/#links","title":"Links","text":"Cost Optimization \u00b7 Event Hub \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Regularly remove unused resources to reduce costs.
","tags":["Azure.EventHub.Usage","AZR-000101"]},{"location":"en/rules/Azure.EventHub.Usage/#description","title":"Description","text":"Billing starts for an Event Hub namespace after it is provisioned. To receive events in a Event Hub namespace, you must first create an Event Hub. Namespaces without any Event Hubs are considered unused.
","tags":["Azure.EventHub.Usage","AZR-000101"]},{"location":"en/rules/Azure.EventHub.Usage/#recommendation","title":"Recommendation","text":"Consider removing Event Hub namespaces that are not used.
","tags":["Azure.EventHub.Usage","AZR-000101"]},{"location":"en/rules/Azure.EventHub.Usage/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.EventHub.Usage","AZR-000101"]},{"location":"en/rules/Azure.EventHub.Usage/#links","title":"Links","text":"Security \u00b7 Firewall \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls.
","tags":["Azure.Firewall.Mode","AZR-000105"]},{"location":"en/rules/Azure.Firewall.Mode/#description","title":"Description","text":"Threat intelligence-based filtering can optionally be enabled on Azure Firewall. When enabled, Azure Firewall alerts and deny traffic to/ from known malicious IP addresses and domains.
By default, Azure Firewall alerts on triggered threat intelligence rules.
Specifically, this rule only applies using an Azure Firewall in classic management mode. If the Azure Firewall is connected to a Secured Virtual Hub this rule will not apply.
Classic managed Azure Firewalls are standalone. Alternatively you can manage Azure Firewalls at scale through Firewall Manager by using policy. When using firewall policies, threat intelligence is configured centrally instead of on each firewall.
","tags":["Azure.Firewall.Mode","AZR-000105"]},{"location":"en/rules/Azure.Firewall.Mode/#recommendation","title":"Recommendation","text":"Consider configuring Azure Firewall to alert and deny IP addresses and domains detected as malicious. Alternatively, consider using firewall policies to manage Azure Firewalls at scale.
","tags":["Azure.Firewall.Mode","AZR-000105"]},{"location":"en/rules/Azure.Firewall.Mode/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Firewalls that pass this rule:
properties.threatIntelMode
to Deny
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/azureFirewalls\",\n \"apiVersion\": \"2021-05-01\",\n \"name\": \"[format('{0}_classic', parameters('name'))]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"sku\": {\n \"name\": \"AZFW_VNet\"\n },\n \"threatIntelMode\": \"Deny\"\n }\n}\n
","tags":["Azure.Firewall.Mode","AZR-000105"]},{"location":"en/rules/Azure.Firewall.Mode/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Firewalls that pass this rule:
properties.threatIntelMode
to Deny
.For example:
Azure Bicep snippetresource firewall_classic 'Microsoft.Network/azureFirewalls@2021-05-01' = {\n name: '${name}_classic'\n location: location\n properties: {\n sku: {\n name: 'AZFW_VNet'\n }\n threatIntelMode: 'Deny'\n }\n}\n
","tags":["Azure.Firewall.Mode","AZR-000105"]},{"location":"en/rules/Azure.Firewall.Mode/#links","title":"Links","text":"Operational Excellence \u00b7 Firewall \u00b7 Rule \u00b7 2021_12 \u00b7 Awareness
Firewall names should meet naming requirements.
","tags":["Azure.Firewall.Name","AZR-000103"]},{"location":"en/rules/Azure.Firewall.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Firewall names are:
Consider using names that meet Firewall naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.Firewall.Name","AZR-000103"]},{"location":"en/rules/Azure.Firewall.Name/#examples","title":"Examples","text":"","tags":["Azure.Firewall.Name","AZR-000103"]},{"location":"en/rules/Azure.Firewall.Name/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy firewalls that pass this rule:
name
property to align to resource naming requirements.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/azureFirewalls\",\n \"apiVersion\": \"2023-02-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"sku\": {\n \"name\": \"AZFW_VNet\",\n \"tier\": \"Premium\"\n },\n \"firewallPolicy\": {\n \"id\": \"[resourceId('Microsoft.Network/firewallPolicies', format('{0}_policy', parameters('name')))]\"\n }\n },\n \"dependsOn\": [\n \"firewall_policy\"\n ]\n}\n
","tags":["Azure.Firewall.Name","AZR-000103"]},{"location":"en/rules/Azure.Firewall.Name/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy firewalls that pass this rule:
name
property to align to resource naming requirements.For example:
Azure Bicep snippetresource firewall 'Microsoft.Network/azureFirewalls@2023-02-01' = {\n name: name\n location: location\n properties: {\n sku: {\n name: 'AZFW_VNet'\n tier: 'Premium'\n }\n firewallPolicy: {\n id: firewall_policy.id\n }\n }\n}\n
","tags":["Azure.Firewall.Name","AZR-000103"]},{"location":"en/rules/Azure.Firewall.Name/#notes","title":"Notes","text":"This rule does not check if Firewall names are unique.
","tags":["Azure.Firewall.Name","AZR-000103"]},{"location":"en/rules/Azure.Firewall.Name/#links","title":"Links","text":"Security \u00b7 Firewall \u00b7 Rule \u00b7 2023_09 \u00b7 Critical
Deny high confidence malicious IP addresses, domains and URLs.
","tags":["Azure.Firewall.PolicyMode","AZR-000399"]},{"location":"en/rules/Azure.Firewall.PolicyMode/#description","title":"Description","text":"Threat intelligence-based filtering can optionally be enabled on Azure Firewall, by associating one or more policies with threat intelligence-based filtering configured.
When configured, Azure Firewall alerts and deny traffic to/from known malicious IP addresses, domains and URLs.
By default, threat intelligence-based filtering is enabled and in alert
mode on each policy unless otherwise is specified.
By configuring threat intelligence-based filtering in alert and deny
mode, threat intelligence-based filtering may deny traffic before any configured rules are processed.
Consider configuring Azure Firewall to alert and deny IP addresses, domains and URLs detected as malicious.
","tags":["Azure.Firewall.PolicyMode","AZR-000399"]},{"location":"en/rules/Azure.Firewall.PolicyMode/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Firewall polices that pass this rule:
properties.threatIntelMode
to Deny
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/firewallPolicies\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"sku\": {\n \"tier\": \"Premium\"\n },\n \"threatIntelMode\": \"Deny\"\n }\n}\n
","tags":["Azure.Firewall.PolicyMode","AZR-000399"]},{"location":"en/rules/Azure.Firewall.PolicyMode/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Firewall polices that pass this rule:
properties.threatIntelMode
to Deny
.For example:
Azure Bicep snippetresource firewallPolicy 'Microsoft.Network/firewallPolicies@2023-04-01' = {\n name: name\n location: location\n properties: {\n sku: {\n tier: 'Premium'\n }\n threatIntelMode: 'Deny'\n }\n}\n
","tags":["Azure.Firewall.PolicyMode","AZR-000399"]},{"location":"en/rules/Azure.Firewall.PolicyMode/#notes","title":"Notes","text":"Azure Firewall Premium SKU is required for associating standalone resource firewall policies. Only Standard and Premium firewall policies supports threat intelligence-based filtering in alert and deny
mode.
In order to take advantage of URL filtering with HTTPS
traffic included in threat intelligence-based filtering, TLS inspection must be configured first.
Operational Excellence \u00b7 Firewall \u00b7 Rule \u00b7 2021_12 \u00b7 Awareness
Firewall policy names should meet naming requirements.
","tags":["Azure.Firewall.PolicyName","AZR-000104"]},{"location":"en/rules/Azure.Firewall.PolicyName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Firewall policy names are:
Consider using names that meet Firewall policy naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.Firewall.PolicyName","AZR-000104"]},{"location":"en/rules/Azure.Firewall.PolicyName/#notes","title":"Notes","text":"This rule does not check if Firewall policy names are unique.
","tags":["Azure.Firewall.PolicyName","AZR-000104"]},{"location":"en/rules/Azure.Firewall.PolicyName/#links","title":"Links","text":"Security \u00b7 Front Door \u00b7 Rule \u00b7 2024_03 \u00b7 Important
Audit and monitor access through Azure Front Door profiles.
","tags":["Azure.FrontDoor.Logs","AZR-000107"]},{"location":"en/rules/Azure.FrontDoor.Logs/#description","title":"Description","text":"Azure Front Door (AFD) supports logging network access to resources through the service. This includes access logs and web application firewall logs. Capturing these logs can help detect and respond to security threats as part of a security monitoring strategy. Additionally, many compliance standards require logging and monitoring of network access.
Like all security monitoring, it is only effective if the logs are reviewed and correlated with other security events. Microsoft Sentinel can be used to analyze and correlate logs, or third-party solutions can be used.
To capture network access events through Front Door, diagnostic settings must be configured. When configuring diagnostics settings enable collection of the following logs:
FrontdoorAccessLog
- Can be used to monitor network activity and access through Front Door.FrontdoorWebApplicationFirewallLog
- Can be used to detect potential attacks, or false positive detections. This log will be empty if a WAF policy is not configured.Management operations for Front Door is captured automatically within Azure Activity Logs.
","tags":["Azure.FrontDoor.Logs","AZR-000107"]},{"location":"en/rules/Azure.FrontDoor.Logs/#recommendation","title":"Recommendation","text":"Consider configuring diagnostics setting to log network activity and access through Azure Front Door (AFD). Also consider correlating logs with other security events to detect and respond to security threats.
","tags":["Azure.FrontDoor.Logs","AZR-000107"]},{"location":"en/rules/Azure.FrontDoor.Logs/#examples","title":"Examples","text":"","tags":["Azure.FrontDoor.Logs","AZR-000107"]},{"location":"en/rules/Azure.FrontDoor.Logs/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Front Door Premium/ Standard profiles that passes this rule:
FrontdoorAccessLog
category.FrontdoorWebApplicationFirewallLog
category if a WAF policy is configured.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Insights/diagnosticSettings\",\n \"apiVersion\": \"2021-05-01-preview\",\n \"scope\": \"[format('Microsoft.Cdn/profiles/{0}', parameters('name'))]\",\n \"name\": \"audit\",\n \"properties\": {\n \"workspaceId\": \"[parameters('workspaceId')]\",\n \"logs\": [\n {\n \"category\": \"FrontdoorAccessLog\",\n \"enabled\": true\n },\n {\n \"category\": \"FrontdoorWebApplicationFirewallLog\",\n \"enabled\": true\n }\n ]\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Cdn/profiles', parameters('name'))]\"\n ]\n}\n
To deploy Azure Front Door Classic profiles that passes this rule:
FrontdoorAccessLog
category.FrontdoorWebApplicationFirewallLog
category if a WAF policy is configured.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Insights/diagnosticSettings\",\n \"apiVersion\": \"2021-05-01-preview\",\n \"scope\": \"[format('Microsoft.Network/frontDoors/{0}', parameters('name'))]\",\n \"name\": \"audit\",\n \"properties\": {\n \"workspaceId\": \"[parameters('workspaceId')]\",\n \"logs\": [\n {\n \"category\": \"FrontdoorAccessLog\",\n \"enabled\": true\n },\n {\n \"category\": \"FrontdoorWebApplicationFirewallLog\",\n \"enabled\": true\n }\n ]\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Network/frontDoors', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.FrontDoor.Logs","AZR-000107"]},{"location":"en/rules/Azure.FrontDoor.Logs/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Front Door Premium/ Standard profiles that passes this rule:
FrontdoorAccessLog
category.FrontdoorWebApplicationFirewallLog
category.For example:
Azure Bicep snippetresource audit 'Microsoft.Insights/diagnosticSettings@2021-05-01-preview' = {\n name: 'audit'\n scope: afd_profile\n properties: {\n workspaceId: workspaceId\n logs: [\n {\n category: 'FrontdoorAccessLog'\n enabled: true\n }\n {\n category: 'FrontdoorWebApplicationFirewallLog'\n enabled: true\n }\n ]\n }\n}\n
To deploy Azure Front Door Classic profiles that passes this rule:
FrontdoorAccessLog
category.FrontdoorWebApplicationFirewallLog
category.For example:
Azure Bicep snippetresource audit_classic 'Microsoft.Insights/diagnosticSettings@2021-05-01-preview' = {\n name: 'audit'\n scope: afd_classic\n properties: {\n workspaceId: workspaceId\n logs: [\n {\n category: 'FrontdoorAccessLog'\n enabled: true\n }\n {\n category: 'FrontdoorWebApplicationFirewallLog'\n enabled: true\n }\n ]\n }\n}\n
","tags":["Azure.FrontDoor.Logs","AZR-000107"]},{"location":"en/rules/Azure.FrontDoor.Logs/#notes","title":"Notes","text":"This rule applies to Azure Front Door Premium/ Standard/ Classic profiles.
","tags":["Azure.FrontDoor.Logs","AZR-000107"]},{"location":"en/rules/Azure.FrontDoor.Logs/#links","title":"Links","text":"Security \u00b7 Front Door \u00b7 Rule \u00b7 2023_09 \u00b7 Important
Ensure Front Door uses a managed identity to authorize access to Azure resources.
","tags":["Azure.FrontDoor.ManagedIdentity","AZR-000396"]},{"location":"en/rules/Azure.FrontDoor.ManagedIdentity/#description","title":"Description","text":"When configuring a Standard or Premium SKU with a custom domain using bring your own certificate (BYOC) access to a Key Vault is required. Standard and Premium Front Door profiles support two methods for authorizing access to Azure resources:
205478c0-bd83-4e1b-a9d6-db63a3e1e1c8
.d4631ece-daab-479b-be77-ccb713491fc0
.The multi-tenant app registration has a number of challenges:
Using an managed identity allows access to Key Vault to be granted using RBAC on an individual basis.
","tags":["Azure.FrontDoor.ManagedIdentity","AZR-000396"]},{"location":"en/rules/Azure.FrontDoor.ManagedIdentity/#recommendation","title":"Recommendation","text":"Consider configure a managed identity to allow support for Azure AD authentication.
","tags":["Azure.FrontDoor.ManagedIdentity","AZR-000396"]},{"location":"en/rules/Azure.FrontDoor.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.FrontDoor.ManagedIdentity","AZR-000396"]},{"location":"en/rules/Azure.FrontDoor.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Front Door instances that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
or SystemAssigned,UserAssigned
.identity.type
is UserAssigned
or SystemAssigned,UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cdn/profiles\",\n \"apiVersion\": \"2022-11-01-preview\",\n \"name\": \"myFrontDoor\",\n \"location\": \"global\",\n \"sku\": {\n \"name\": \"Standard_AzureFrontDoor\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\",\n \"userAssignedIdentities\": {}\n }\n}\n
","tags":["Azure.FrontDoor.ManagedIdentity","AZR-000396"]},{"location":"en/rules/Azure.FrontDoor.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Front Door instances that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
or SystemAssigned,UserAssigned
.identity.type
is UserAssigned
or SystemAssigned,UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource frontDoorProfile 'Microsoft.Cdn/profiles@2022-11-01-preview' = {\n name: 'myFrontDoor'\n location: 'global'\n sku: {\n name: 'Standard_AzureFrontDoor'\n }\n identity: {\n type: 'SystemAssigned'\n userAssignedIdentities: {}\n }\n}\n
","tags":["Azure.FrontDoor.ManagedIdentity","AZR-000396"]},{"location":"en/rules/Azure.FrontDoor.ManagedIdentity/#notes","title":"Notes","text":"Currently Azure Front Door only supports authentication using an Entra ID (Azure AD) to Key Vault. To use a managed identity, the Standard or Premium SKU is required. Managed identities are not supported with the Classic SKU.
If you only use Azure Front Door (AFD) managed certificates for custom domains, a managed identity is not required.
","tags":["Azure.FrontDoor.ManagedIdentity","AZR-000396"]},{"location":"en/rules/Azure.FrontDoor.ManagedIdentity/#links","title":"Links","text":"Security \u00b7 Front Door \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Front Door Classic instances should reject TLS versions older than 1.2.
","tags":["Azure.FrontDoor.MinTLS","AZR-000106"]},{"location":"en/rules/Azure.FrontDoor.MinTLS/#description","title":"Description","text":"The minimum version of TLS that Azure Front Door accepts is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Front Door lets you disable outdated protocols and enforce TLS 1.2. By default, a minimum of TLS 1.2 is enforced.
","tags":["Azure.FrontDoor.MinTLS","AZR-000106"]},{"location":"en/rules/Azure.FrontDoor.MinTLS/#recommendation","title":"Recommendation","text":"Consider configuring the minimum supported TLS version to be 1.2 for each endpoint. This applies to Azure Front Door Classic instances only.
","tags":["Azure.FrontDoor.MinTLS","AZR-000106"]},{"location":"en/rules/Azure.FrontDoor.MinTLS/#examples","title":"Examples","text":"","tags":["Azure.FrontDoor.MinTLS","AZR-000106"]},{"location":"en/rules/Azure.FrontDoor.MinTLS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy a Front Door resource that passes this rule:
properties.frontendEndpoints[*].properties.customHttpsConfiguration.minimumTlsVersion
property to 1.2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/frontDoors\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"global\",\n \"properties\": {\n \"enabledState\": \"Enabled\",\n \"frontendEndpoints\": [\n {\n \"name\": \"[variables('frontEndEndpointName')]\",\n \"properties\": {\n \"hostName\": \"[format('{0}.azurefd.net', parameters('name'))]\",\n \"sessionAffinityEnabledState\": \"Disabled\",\n \"customHttpsConfiguration\": {\n \"minimumTlsVersion\": \"1.2\"\n }\n }\n }\n ],\n \"loadBalancingSettings\": \"[variables('loadBalancingSettings')]\",\n \"backendPools\": \"[variables('backendPools')]\",\n \"healthProbeSettings\": \"[variables('healthProbeSettings')]\",\n \"routingRules\": \"[variables('routingRules')]\"\n }\n}\n
","tags":["Azure.FrontDoor.MinTLS","AZR-000106"]},{"location":"en/rules/Azure.FrontDoor.MinTLS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy a Front Door resource that passes this rule:
properties.frontendEndpoints[*].properties.customHttpsConfiguration.minimumTlsVersion
property to 1.2
.For example:
Azure Bicep snippetresource afd_classic 'Microsoft.Network/frontDoors@2021-06-01' = {\n name: name\n location: 'global'\n properties: {\n enabledState: 'Enabled'\n frontendEndpoints: [\n {\n name: frontEndEndpointName\n properties: {\n hostName: '${name}.azurefd.net'\n sessionAffinityEnabledState: 'Disabled'\n customHttpsConfiguration: {\n minimumTlsVersion: '1.2'\n }\n }\n }\n ]\n loadBalancingSettings: loadBalancingSettings\n backendPools: backendPools\n healthProbeSettings: healthProbeSettings\n routingRules: routingRules\n }\n}\n
","tags":["Azure.FrontDoor.MinTLS","AZR-000106"]},{"location":"en/rules/Azure.FrontDoor.MinTLS/#links","title":"Links","text":"Operational Excellence \u00b7 Front Door \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Front Door names should meet naming requirements.
","tags":["Azure.FrontDoor.Name","AZR-000113"]},{"location":"en/rules/Azure.FrontDoor.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Front Door names are:
Consider using names that meet Front Door naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.FrontDoor.Name","AZR-000113"]},{"location":"en/rules/Azure.FrontDoor.Name/#notes","title":"Notes","text":"This rule does not check if Front Door names are unique.
","tags":["Azure.FrontDoor.Name","AZR-000113"]},{"location":"en/rules/Azure.FrontDoor.Name/#links","title":"Links","text":"Reliability \u00b7 Front Door \u00b7 Rule \u00b7 2021_03 \u00b7 Important
Use health probes to check the health of each backend.
","tags":["Azure.FrontDoor.Probe","AZR-000108"]},{"location":"en/rules/Azure.FrontDoor.Probe/#description","title":"Description","text":"The health and performance of an application can degrade over time. Degradation might not be noticeable until the application fails.
Azure Front Door can use periodic health probes against backend endpoints to determine health status. When one or more backend in a pool is healthy traffic is routed to healthy endpoints only. If all endpoints in a pool is unhealthy Front Door sends the request to any enabled endpoint.
Health probes allow Front Door to select a backend endpoint able to respond to the request.
","tags":["Azure.FrontDoor.Probe","AZR-000108"]},{"location":"en/rules/Azure.FrontDoor.Probe/#recommendation","title":"Recommendation","text":"Consider configuring and enabling a health probe for each Front Door backend.
","tags":["Azure.FrontDoor.Probe","AZR-000108"]},{"location":"en/rules/Azure.FrontDoor.Probe/#examples","title":"Examples","text":"","tags":["Azure.FrontDoor.Probe","AZR-000108"]},{"location":"en/rules/Azure.FrontDoor.Probe/#configure-with-azure-template","title":"Configure with Azure template","text":"Premium / StandardClassicTo deploy a Front Door resource that passes this rule:
properties.healthProbeSettings
property of the originGroups
sub-resource.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cdn/profiles\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"Global\",\n \"sku\": {\n \"name\": \"Premium_AzureFrontDoor\"\n }\n},\n{\n \"type\": \"Microsoft.Cdn/profiles/originGroups\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), parameters('name'))]\",\n \"properties\": {\n \"loadBalancingSettings\": {\n \"sampleSize\": 4,\n \"successfulSamplesRequired\": 3\n },\n \"healthProbeSettings\": {\n \"probePath\": \"/healthz\",\n \"probeRequestType\": \"HEAD\",\n \"probeProtocol\": \"Http\",\n \"probeIntervalInSeconds\": 100\n }\n },\n \"dependsOn\": [\n \"[parameters('name')]\"\n ]\n}\n
To deploy a Front Door resource that passes this rule:
properties.healthProbeSettings[*].properties.enabledState
property to Enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/frontDoors\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"global\",\n \"properties\": {\n \"enabledState\": \"Enabled\",\n \"frontendEndpoints\": \"[variables('frontendEndpoints')]\",\n \"loadBalancingSettings\": \"[variables('loadBalancingSettings')]\",\n \"backendPools\": \"[variables('backendPools')]\",\n \"healthProbeSettings\": [\n {\n \"name\": \"[variables('healthProbeSettingsName')]\",\n \"properties\": {\n \"enabledState\": \"Enabled\",\n \"path\": \"/healthz\",\n \"protocol\": \"Http\",\n \"intervalInSeconds\": 120,\n \"healthProbeMethod\": \"HEAD\"\n }\n }\n ],\n \"routingRules\": \"[variables('routingRules')]\"\n }\n}\n
","tags":["Azure.FrontDoor.Probe","AZR-000108"]},{"location":"en/rules/Azure.FrontDoor.Probe/#configure-with-bicep","title":"Configure with Bicep","text":"Premium / StandardClassic To deploy a Front Door resource that passes this rule:
properties.healthProbeSettings
property of the originGroups
sub-resource.For example:
Azure Bicep snippetresource afd_premium 'Microsoft.Cdn/profiles@2021-06-01' = {\n name: name\n location: 'Global'\n sku: {\n name: 'Premium_AzureFrontDoor'\n }\n}\n\nresource frontDoorOriginGroup 'Microsoft.Cdn/profiles/originGroups@2021-06-01' = {\n name: name\n parent: afd_premium\n properties: {\n loadBalancingSettings: {\n sampleSize: 4\n successfulSamplesRequired: 3\n }\n healthProbeSettings: {\n probePath: '/healthz'\n probeRequestType: 'HEAD'\n probeProtocol: 'Http'\n probeIntervalInSeconds: 100\n }\n }\n}\n
To deploy a Front Door resource that passes this rule:
properties.healthProbeSettings[*].properties.enabledState
property to Enabled
.For example:
Azure Bicep snippetresource afd_classic 'Microsoft.Network/frontDoors@2021-06-01' = {\n name: name\n location: 'global'\n properties: {\n enabledState: 'Enabled'\n frontendEndpoints: frontendEndpoints\n loadBalancingSettings: loadBalancingSettings\n backendPools: backendPools\n healthProbeSettings: [\n {\n name: healthProbeSettingsName\n properties: {\n enabledState: 'Enabled'\n path: '/healthz'\n protocol: 'Http'\n intervalInSeconds: 120\n healthProbeMethod: 'HEAD'\n }\n }\n ]\n routingRules: routingRules\n }\n}\n
","tags":["Azure.FrontDoor.Probe","AZR-000108"]},{"location":"en/rules/Azure.FrontDoor.Probe/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz network front-door probe update --front-door-name '<front_door>' -n '<probe_name>' -g '<resource_group>' --enabled 'Enabled' --path '/healthz'\n
","tags":["Azure.FrontDoor.Probe","AZR-000108"]},{"location":"en/rules/Azure.FrontDoor.Probe/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippet$probeSetting = New-AzFrontDoorHealthProbeSettingObject -Name '<probe_name>' -EnabledState 'Enabled' -Path '/healthz'\nSet-AzFrontDoor -Name '<front_door>' -ResourceGroupName '<resource_group>' -HealthProbeSetting $probeSetting\n
","tags":["Azure.FrontDoor.Probe","AZR-000108"]},{"location":"en/rules/Azure.FrontDoor.Probe/#links","title":"Links","text":"Reliability \u00b7 Front Door \u00b7 Rule \u00b7 2021_03 \u00b7 Important
Configure health probes to use HEAD
requests to reduce performance overhead.
Azure Front Door supports sending HEAD
or GET
requests for health probes to backend endpoints. HTTP HEAD
requests are identical to GET
requests except that the server does not send a response body. As a result, HEAD
request typically have a lower performance impact then GET
request.
By eliminating a response body:
Consider configuring health probes to query backend health endpoints using HEAD
requests to reduce performance overhead.
To deploy a Front Door resource that passes this rule:
properties.healthProbeSettings.probeRequestType
property to HEAD
of the originGroups
sub-resource.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cdn/profiles\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"Global\",\n \"sku\": {\n \"name\": \"Premium_AzureFrontDoor\"\n }\n},\n{\n \"type\": \"Microsoft.Cdn/profiles/originGroups\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), parameters('name'))]\",\n \"properties\": {\n \"loadBalancingSettings\": {\n \"sampleSize\": 4,\n \"successfulSamplesRequired\": 3\n },\n \"healthProbeSettings\": {\n \"probePath\": \"/healthz\",\n \"probeRequestType\": \"HEAD\",\n \"probeProtocol\": \"Http\",\n \"probeIntervalInSeconds\": 100\n }\n },\n \"dependsOn\": [\n \"[parameters('name')]\"\n ]\n}\n
To deploy a Front Door resource that passes this rule:
properties.healthProbeSettings[*].properties.healthProbeMethod
property to HEAD
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/frontDoors\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"global\",\n \"properties\": {\n \"enabledState\": \"Enabled\",\n \"frontendEndpoints\": \"[variables('frontendEndpoints')]\",\n \"loadBalancingSettings\": \"[variables('loadBalancingSettings')]\",\n \"backendPools\": \"[variables('backendPools')]\",\n \"healthProbeSettings\": [\n {\n \"name\": \"[variables('healthProbeSettingsName')]\",\n \"properties\": {\n \"enabledState\": \"Enabled\",\n \"path\": \"/healthz\",\n \"protocol\": \"Http\",\n \"intervalInSeconds\": 120,\n \"healthProbeMethod\": \"HEAD\"\n }\n }\n ],\n \"routingRules\": \"[variables('routingRules')]\"\n }\n}\n
","tags":["Azure.FrontDoor.ProbeMethod","AZR-000109"]},{"location":"en/rules/Azure.FrontDoor.ProbeMethod/#configure-with-bicep","title":"Configure with Bicep","text":"Premium / StandardClassic To deploy a Front Door resource that passes this rule:
properties.healthProbeSettings.probeRequestType
property to HEAD
of the originGroups
sub-resource.For example:
Azure Bicep snippetresource afd_premium 'Microsoft.Cdn/profiles@2021-06-01' = {\n name: name\n location: 'Global'\n sku: {\n name: 'Premium_AzureFrontDoor'\n }\n}\n\nresource frontDoorOriginGroup 'Microsoft.Cdn/profiles/originGroups@2021-06-01' = {\n name: name\n parent: afd_premium\n properties: {\n loadBalancingSettings: {\n sampleSize: 4\n successfulSamplesRequired: 3\n }\n healthProbeSettings: {\n probePath: '/healthz'\n probeRequestType: 'HEAD'\n probeProtocol: 'Http'\n probeIntervalInSeconds: 100\n }\n }\n}\n
To deploy a Front Door resource that passes this rule:
properties.healthProbeSettings[*].properties.healthProbeMethod
property to HEAD
.For example:
Azure Bicep snippetresource afd_classic 'Microsoft.Network/frontDoors@2021-06-01' = {\n name: name\n location: 'global'\n properties: {\n enabledState: 'Enabled'\n frontendEndpoints: frontendEndpoints\n loadBalancingSettings: loadBalancingSettings\n backendPools: backendPools\n healthProbeSettings: [\n {\n name: healthProbeSettingsName\n properties: {\n enabledState: 'Enabled'\n path: '/healthz'\n protocol: 'Http'\n intervalInSeconds: 120\n healthProbeMethod: 'HEAD'\n }\n }\n ]\n routingRules: routingRules\n }\n}\n
","tags":["Azure.FrontDoor.ProbeMethod","AZR-000109"]},{"location":"en/rules/Azure.FrontDoor.ProbeMethod/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz network front-door probe update --front-door-name '<front_door>' -n '<probe_name>' -g '<resource_group>' --probeMethod 'HEAD' --path '/healthz'\n
","tags":["Azure.FrontDoor.ProbeMethod","AZR-000109"]},{"location":"en/rules/Azure.FrontDoor.ProbeMethod/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippet$probeSetting = New-AzFrontDoorHealthProbeSettingObject -Name '<probe_name>' -HealthProbeMethod 'HEAD' -Path '/healthz'\nSet-AzFrontDoor -Name '<front_door>' -ResourceGroupName '<resource_group>' -HealthProbeSetting $probeSetting\n
","tags":["Azure.FrontDoor.ProbeMethod","AZR-000109"]},{"location":"en/rules/Azure.FrontDoor.ProbeMethod/#links","title":"Links","text":"Reliability \u00b7 Front Door \u00b7 Rule \u00b7 2021_03 \u00b7 Important
Configure a dedicated path for health probe requests.
","tags":["Azure.FrontDoor.ProbePath","AZR-000110"]},{"location":"en/rules/Azure.FrontDoor.ProbePath/#description","title":"Description","text":"Azure Front Door monitors a specific path for each backend to determine health status. The monitored path should implement functional checks to determine if the backend is performing correctly. The checks should include dependencies including those that may not be regularly called.
Regular checks of the monitored path allow Front Door to make load balancing decisions based on status.
","tags":["Azure.FrontDoor.ProbePath","AZR-000110"]},{"location":"en/rules/Azure.FrontDoor.ProbePath/#recommendation","title":"Recommendation","text":"Consider using a dedicated health probe endpoint that implements functional checks.
","tags":["Azure.FrontDoor.ProbePath","AZR-000110"]},{"location":"en/rules/Azure.FrontDoor.ProbePath/#examples","title":"Examples","text":"","tags":["Azure.FrontDoor.ProbePath","AZR-000110"]},{"location":"en/rules/Azure.FrontDoor.ProbePath/#configure-with-azure-template","title":"Configure with Azure template","text":"Premium / StandardClassicTo deploy a Front Door resource that passes this rule:
properties.healthProbeSettings.probePath
property to a dedicated path of the originGroups
sub-resource.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cdn/profiles\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"Global\",\n \"sku\": {\n \"name\": \"Premium_AzureFrontDoor\"\n }\n},\n{\n \"type\": \"Microsoft.Cdn/profiles/originGroups\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), parameters('name'))]\",\n \"properties\": {\n \"loadBalancingSettings\": {\n \"sampleSize\": 4,\n \"successfulSamplesRequired\": 3\n },\n \"healthProbeSettings\": {\n \"probePath\": \"/healthz\",\n \"probeRequestType\": \"HEAD\",\n \"probeProtocol\": \"Http\",\n \"probeIntervalInSeconds\": 100\n }\n },\n \"dependsOn\": [\n \"[parameters('name')]\"\n ]\n}\n
To deploy a Front Door resource that passes this rule:
properties.healthProbeSettings[*].properties.path
property to a dedicated path.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/frontDoors\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"global\",\n \"properties\": {\n \"enabledState\": \"Enabled\",\n \"frontendEndpoints\": \"[variables('frontendEndpoints')]\",\n \"loadBalancingSettings\": \"[variables('loadBalancingSettings')]\",\n \"backendPools\": \"[variables('backendPools')]\",\n \"healthProbeSettings\": [\n {\n \"name\": \"[variables('healthProbeSettingsName')]\",\n \"properties\": {\n \"enabledState\": \"Enabled\",\n \"path\": \"/healthz\",\n \"protocol\": \"Http\",\n \"intervalInSeconds\": 120,\n \"healthProbeMethod\": \"HEAD\"\n }\n }\n ],\n \"routingRules\": \"[variables('routingRules')]\"\n }\n}\n
","tags":["Azure.FrontDoor.ProbePath","AZR-000110"]},{"location":"en/rules/Azure.FrontDoor.ProbePath/#configure-with-bicep","title":"Configure with Bicep","text":"Premium / StandardClassic To deploy a Front Door resource that passes this rule:
properties.healthProbeSettings.probePath
property to a dedicated path of the originGroups
sub-resource.For example:
Azure Bicep snippetresource afd_premium 'Microsoft.Cdn/profiles@2021-06-01' = {\n name: name\n location: 'Global'\n sku: {\n name: 'Premium_AzureFrontDoor'\n }\n}\n\nresource frontDoorOriginGroup 'Microsoft.Cdn/profiles/originGroups@2021-06-01' = {\n name: name\n parent: afd_premium\n properties: {\n loadBalancingSettings: {\n sampleSize: 4\n successfulSamplesRequired: 3\n }\n healthProbeSettings: {\n probePath: '/healthz'\n probeRequestType: 'HEAD'\n probeProtocol: 'Http'\n probeIntervalInSeconds: 100\n }\n }\n}\n
To deploy a Front Door resource that passes this rule:
properties.healthProbeSettings[*].properties.path
property to a dedicated path.For example:
Azure Bicep snippetresource afd_classic 'Microsoft.Network/frontDoors@2021-06-01' = {\n name: name\n location: 'global'\n properties: {\n enabledState: 'Enabled'\n frontendEndpoints: frontendEndpoints\n loadBalancingSettings: loadBalancingSettings\n backendPools: backendPools\n healthProbeSettings: [\n {\n name: healthProbeSettingsName\n properties: {\n enabledState: 'Enabled'\n path: '/healthz'\n protocol: 'Http'\n intervalInSeconds: 120\n healthProbeMethod: 'HEAD'\n }\n }\n ]\n routingRules: routingRules\n }\n}\n
","tags":["Azure.FrontDoor.ProbePath","AZR-000110"]},{"location":"en/rules/Azure.FrontDoor.ProbePath/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz network front-door probe update --front-door-name '<front_door>' -n '<probe_name>' -g '<resource_group>' --path '/healthz'\n
","tags":["Azure.FrontDoor.ProbePath","AZR-000110"]},{"location":"en/rules/Azure.FrontDoor.ProbePath/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippet$probeSetting = New-AzFrontDoorHealthProbeSettingObject -Name '<probe_name>' -Path '/healthz'\nSet-AzFrontDoor -Name '<front_door>' -ResourceGroupName '<resource_group>' -HealthProbeSetting $probeSetting\n
","tags":["Azure.FrontDoor.ProbePath","AZR-000110"]},{"location":"en/rules/Azure.FrontDoor.ProbePath/#links","title":"Links","text":"Cost Optimization \u00b7 Front Door \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Enable Azure Front Door Classic instance.
","tags":["Azure.FrontDoor.State","AZR-000112"]},{"location":"en/rules/Azure.FrontDoor.State/#description","title":"Description","text":"The operational state of a Front Door Classic instance is configurable, either enabled or disabled. By default, a Front Door is enabled.
Optionally, a Front Door Classic instance may be disabled to temporarily prevent traffic being processed.
","tags":["Azure.FrontDoor.State","AZR-000112"]},{"location":"en/rules/Azure.FrontDoor.State/#recommendation","title":"Recommendation","text":"Consider enabling the Front Door service or remove the instance if it is no longer required. This applies to Azure Front Door Classic instances only.
","tags":["Azure.FrontDoor.State","AZR-000112"]},{"location":"en/rules/Azure.FrontDoor.State/#examples","title":"Examples","text":"","tags":["Azure.FrontDoor.State","AZR-000112"]},{"location":"en/rules/Azure.FrontDoor.State/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy a Front Door resource that passes this rule:
properties.enabledState
property to Enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/frontDoors\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"global\",\n \"properties\": {\n \"enabledState\": \"Enabled\",\n \"frontendEndpoints\": \"[variables('frontendEndpoints')]\",\n \"loadBalancingSettings\": \"[variables('loadBalancingSettings')]\",\n \"backendPools\": \"[variables('backendPools')]\",\n \"healthProbeSettings\": \"[variables('healthProbeSettings')]\",\n \"routingRules\": \"[variables('routingRules')]\"\n }\n}\n
","tags":["Azure.FrontDoor.State","AZR-000112"]},{"location":"en/rules/Azure.FrontDoor.State/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy a Front Door resource that passes this rule:
properties.enabledState
property to Enabled
.For example:
Azure Bicep snippetresource afd_classic 'Microsoft.Network/frontDoors@2021-06-01' = {\n name: name\n location: 'global'\n properties: {\n enabledState: 'Enabled'\n frontendEndpoints: frontendEndpoints\n loadBalancingSettings: loadBalancingSettings\n backendPools: backendPools\n healthProbeSettings: healthProbeSettings\n routingRules: routingRules\n }\n}\n
","tags":["Azure.FrontDoor.State","AZR-000112"]},{"location":"en/rules/Azure.FrontDoor.State/#links","title":"Links","text":"Performance Efficiency \u00b7 Front Door \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Use caching to reduce retrieving contents from origins.
","tags":["Azure.FrontDoor.UseCaching","AZR-000320"]},{"location":"en/rules/Azure.FrontDoor.UseCaching/#description","title":"Description","text":"Azure Front Door delivers large files without a cap on file size. Front Door uses a technique called object chunking. When a large file is requested, Front Door retrieves smaller pieces of the file from the backend. After receiving a full or byte-range file request, the Front Door environment requests the file from the backend in chunks of 8 MB.
After the chunk arrives at the Front Door environment, it's cached and immediately served to the user. Front Door then pre-fetches the next chunk in parallel. This pre-fetch ensures that the content stays one chunk ahead of the user, which reduces latency. This process continues until the entire file gets downloaded (if requested) or the client closes the connection.
For more information on the byte-range request, read RFC 7233. Front Door caches any chunks as they're received so the entire file doesn't need to be cached on the Front Door cache. Ensuing requests for the file or byte ranges are served from the cache. If the chunks aren't all cached, pre-fetching is used to request chunks from the backend. This optimization relies on the backend's ability to support byte-range requests. If the backend doesn't support byte-range requests, this optimization isn't effective.
","tags":["Azure.FrontDoor.UseCaching","AZR-000320"]},{"location":"en/rules/Azure.FrontDoor.UseCaching/#recommendation","title":"Recommendation","text":"Use caching to reduce retrieving contents from origins and improve overall performance.
","tags":["Azure.FrontDoor.UseCaching","AZR-000320"]},{"location":"en/rules/Azure.FrontDoor.UseCaching/#examples","title":"Examples","text":"","tags":["Azure.FrontDoor.UseCaching","AZR-000320"]},{"location":"en/rules/Azure.FrontDoor.UseCaching/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy front door instances pass this rule:
properties.routingRules.properties.routeConfiguration.cacheConfiguration
.Important The rule checks also for rule sets (child resources) that are overwriting the cache configuration from routing rules. Check the link Routing architecture overview
for more information around this.
For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/frontDoors\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[parameters('frontDoorName')]\",\n \"location\": \"global\",\n \"properties\": {\n \"enabledState\": \"Enabled\",\n \"frontendEndpoints\": [\n {\n \"name\": \"[variables('frontEndEndpointName')]\",\n \"properties\": {\n \"hostName\": \"[format('{0}.azurefd.net', parameters('frontDoorName'))]\",\n \"sessionAffinityEnabledState\": \"Disabled\"\n }\n }\n ],\n \"loadBalancingSettings\": [\n {\n \"name\": \"[variables('loadBalancingSettingsName')]\",\n \"properties\": {\n \"sampleSize\": 4,\n \"successfulSamplesRequired\": 2\n }\n }\n ],\n \"healthProbeSettings\": [\n {\n \"name\": \"[variables('healthProbeSettingsName')]\",\n \"properties\": {\n \"path\": \"/\",\n \"protocol\": \"Http\",\n \"intervalInSeconds\": 120\n }\n }\n ],\n \"backendPools\": [\n {\n \"name\": \"[variables('backendPoolName')]\",\n \"properties\": {\n \"backends\": [\n {\n \"address\": \"[parameters('backendAddress')]\",\n \"backendHostHeader\": \"[parameters('backendAddress')]\",\n \"httpPort\": 80,\n \"httpsPort\": 443,\n \"weight\": 50,\n \"priority\": 1,\n \"enabledState\": \"Enabled\"\n }\n ],\n \"loadBalancingSettings\": {\n \"id\": \"[resourceId('Microsoft.Network/frontDoors/loadBalancingSettings', parameters('frontDoorName'), variables('loadBalancingSettingsName'))]\"\n },\n \"healthProbeSettings\": {\n \"id\": \"[resourceId('Microsoft.Network/frontDoors/healthProbeSettings', parameters('frontDoorName'), variables('healthProbeSettingsName'))]\"\n }\n }\n }\n ],\n \"routingRules\": [\n {\n \"name\": \"[variables('routingRuleName')]\",\n \"properties\": {\n \"frontendEndpoints\": [\n {\n \"id\": \"[resourceId('Microsoft.Network/frontDoors/frontEndEndpoints', parameters('frontDoorName'), variables('frontEndEndpointName'))]\"\n }\n ],\n \"acceptedProtocols\": [\n \"Http\",\n \"Https\"\n ],\n \"patternsToMatch\": [\n \"/*\"\n ],\n \"routeConfiguration\": {\n \"@odata.type\": \"#Microsoft.Azure.FrontDoor.Models.FrontdoorForwardingConfiguration\",\n \"cacheConfiguration\": {\n \"cacheDuration\": \"P12DT1H\",\n \"dynamicCompression\": \"Disabled\",\n \"queryParameters\": \"customerId\",\n \"queryParameterStripDirective\": \"StripAll\"\n },\n \"forwardingProtocol\": \"MatchRequest\",\n \"backendPool\": {\n \"id\": \"[resourceId('Microsoft.Network/frontDoors/backEndPools', parameters('frontDoorName'), variables('backendPoolName'))]\"\n }\n },\n \"enabledState\": \"Enabled\"\n }\n }\n ]\n }\n}\n
","tags":["Azure.FrontDoor.UseCaching","AZR-000320"]},{"location":"en/rules/Azure.FrontDoor.UseCaching/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy front door instances pass this rule:
properties.routingRules.properties.routeConfiguration.cacheConfiguration
.Important The rule checks also for rule sets (child resources) that are overwriting the cache configuration from routing rules. Check the link Routing architecture overview
for more information around this.
For example:
Azure Bicep snippet@description('The name of the Front Door profile.')\nparam frontDoorName string\n\n@description('The hostname of the backend. Must be an IP address or FQDN.')\nparam backendAddress string\n\nvar frontEndEndpointName = 'frontEndEndpoint'\nvar loadBalancingSettingsName = 'loadBalancingSettings'\nvar healthProbeSettingsName = 'healthProbeSettings'\nvar routingRuleName = 'routingRule'\nvar backendPoolName = 'backendPool'\n\nresource frontDoor 'Microsoft.Network/frontDoors@2021-06-01' = {\n name: frontDoorName\n location: 'global'\n properties: {\n enabledState: 'Enabled'\n\n frontendEndpoints: [\n {\n name: frontEndEndpointName\n properties: {\n hostName: '${frontDoorName}.azurefd.net'\n sessionAffinityEnabledState: 'Disabled'\n }\n }\n ]\n\n loadBalancingSettings: [\n {\n name: loadBalancingSettingsName\n properties: {\n sampleSize: 4\n successfulSamplesRequired: 2\n }\n }\n ]\n\n healthProbeSettings: [\n {\n name: healthProbeSettingsName\n properties: {\n path: '/'\n protocol: 'Http'\n intervalInSeconds: 120\n }\n }\n ]\n\n backendPools: [\n {\n name: backendPoolName\n properties: {\n backends: [\n {\n address: backendAddress\n backendHostHeader: backendAddress\n httpPort: 80\n httpsPort: 443\n weight: 50\n priority: 1\n enabledState: 'Enabled'\n }\n ]\n loadBalancingSettings: {\n id: resourceId('Microsoft.Network/frontDoors/loadBalancingSettings', frontDoorName, loadBalancingSettingsName)\n }\n healthProbeSettings: {\n id: resourceId('Microsoft.Network/frontDoors/healthProbeSettings', frontDoorName, healthProbeSettingsName)\n }\n }\n }\n ]\n\n routingRules: [\n {\n name: routingRuleName\n properties: {\n frontendEndpoints: [\n {\n id: resourceId('Microsoft.Network/frontDoors/frontEndEndpoints', frontDoorName, frontEndEndpointName)\n }\n ]\n acceptedProtocols: [\n 'Http'\n 'Https'\n ]\n patternsToMatch: [\n '/*'\n ]\n routeConfiguration: {\n '@odata.type': '#Microsoft.Azure.FrontDoor.Models.FrontdoorForwardingConfiguration'\n cacheConfiguration: {\n cacheDuration: 'P12DT1H'\n dynamicCompression: 'Disabled'\n queryParameters: 'customerId'\n queryParameterStripDirective: 'StripAll'\n }\n forwardingProtocol: 'MatchRequest'\n backendPool: {\n id: resourceId('Microsoft.Network/frontDoors/backEndPools', frontDoorName, backendPoolName)\n }\n }\n enabledState: 'Enabled'\n }\n }\n ]\n }\n}\n
","tags":["Azure.FrontDoor.UseCaching","AZR-000320"]},{"location":"en/rules/Azure.FrontDoor.UseCaching/#notes","title":"Notes","text":"This rule only applies to Azure Front Door Classic profiles (Microsoft.Network/frontDoors
).
Security \u00b7 Front Door \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Enable Web Application Firewall (WAF) policies on each Front Door endpoint.
","tags":["Azure.FrontDoor.UseWAF","AZR-000111"]},{"location":"en/rules/Azure.FrontDoor.UseWAF/#description","title":"Description","text":"Front Door endpoints can optionally be configured with a WAF policy. When configured, every incoming request through Front Door is filtered by the WAF policy.
","tags":["Azure.FrontDoor.UseWAF","AZR-000111"]},{"location":"en/rules/Azure.FrontDoor.UseWAF/#recommendation","title":"Recommendation","text":"Consider enabling a WAF policy on each Front Door endpoint.
","tags":["Azure.FrontDoor.UseWAF","AZR-000111"]},{"location":"en/rules/Azure.FrontDoor.UseWAF/#links","title":"Links","text":"Security \u00b7 Front Door \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources.
","tags":["Azure.FrontDoor.WAF.Enabled","AZR-000115"]},{"location":"en/rules/Azure.FrontDoor.WAF.Enabled/#description","title":"Description","text":"The operational state of a Front Door WAF policy instance is configurable, either enabled or disabled. By default, a WAF policy is enabled.
When disabled, incoming requests bypass the WAF policy and are sent to back ends based on routing rules.
","tags":["Azure.FrontDoor.WAF.Enabled","AZR-000115"]},{"location":"en/rules/Azure.FrontDoor.WAF.Enabled/#recommendation","title":"Recommendation","text":"Consider enabling WAF policy.
","tags":["Azure.FrontDoor.WAF.Enabled","AZR-000115"]},{"location":"en/rules/Azure.FrontDoor.WAF.Enabled/#links","title":"Links","text":"Security \u00b7 Front Door \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources.
","tags":["Azure.FrontDoor.WAF.Mode","AZR-000114"]},{"location":"en/rules/Azure.FrontDoor.WAF.Mode/#description","title":"Description","text":"Front Door WAF policies support two modes of operation, detection and prevention. By default, prevention is configured.
Consider setting Front Door WAF policy to use protection mode.
","tags":["Azure.FrontDoor.WAF.Mode","AZR-000114"]},{"location":"en/rules/Azure.FrontDoor.WAF.Mode/#links","title":"Links","text":"Operational Excellence \u00b7 Front Door \u00b7 Rule \u00b7 2020_12 \u00b7 Awareness
Front Door WAF policy names should meet naming requirements.
","tags":["Azure.FrontDoor.WAF.Name","AZR-000116"]},{"location":"en/rules/Azure.FrontDoor.WAF.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Front Door Web Application Firewall (WAF) policy names are:
Consider using names that meet Front Door WAF policy naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.FrontDoor.WAF.Name","AZR-000116"]},{"location":"en/rules/Azure.FrontDoor.WAF.Name/#notes","title":"Notes","text":"This rule does not check if Front Door WAF policy names are unique.
","tags":["Azure.FrontDoor.WAF.Name","AZR-000116"]},{"location":"en/rules/Azure.FrontDoor.WAF.Name/#links","title":"Links","text":"Security \u00b7 Front Door \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources.
","tags":["Azure.FrontDoorWAF.Enabled","AZR-000305"]},{"location":"en/rules/Azure.FrontDoorWAF.Enabled/#description","title":"Description","text":"The operational state of a Front Door WAF policy instance is configurable, either enabled or disabled. By default, a WAF policy is enabled.
When disabled, incoming requests bypass the WAF policy and are sent to back ends based on routing rules.
","tags":["Azure.FrontDoorWAF.Enabled","AZR-000305"]},{"location":"en/rules/Azure.FrontDoorWAF.Enabled/#recommendation","title":"Recommendation","text":"Consider enabling WAF policy.
","tags":["Azure.FrontDoorWAF.Enabled","AZR-000305"]},{"location":"en/rules/Azure.FrontDoorWAF.Enabled/#examples","title":"Examples","text":"","tags":["Azure.FrontDoorWAF.Enabled","AZR-000305"]},{"location":"en/rules/Azure.FrontDoorWAF.Enabled/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy WAF policies that pass this rule:
properties.policySettings.enabledState
property to Enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/FrontDoorWebApplicationFirewallPolicies\",\n \"apiVersion\": \"2022-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"Global\",\n \"sku\": {\n \"name\": \"Premium_AzureFrontDoor\"\n },\n \"properties\": {\n \"managedRules\": {\n \"managedRuleSets\": [\n {\n \"ruleSetType\": \"Microsoft_DefaultRuleSet\",\n \"ruleSetVersion\": \"2.0\",\n \"ruleSetAction\": \"Block\",\n \"exclusions\": [],\n \"ruleGroupOverrides\": []\n },\n {\n \"ruleSetType\": \"Microsoft_BotManagerRuleSet\",\n \"ruleSetVersion\": \"1.0\",\n \"ruleSetAction\": \"Block\",\n \"exclusions\": [],\n \"ruleGroupOverrides\": []\n }\n ]\n },\n \"policySettings\": {\n \"enabledState\": \"Enabled\",\n \"mode\": \"Prevention\"\n }\n }\n}\n
","tags":["Azure.FrontDoorWAF.Enabled","AZR-000305"]},{"location":"en/rules/Azure.FrontDoorWAF.Enabled/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy WAF policies that pass this rule:
properties.policySettings.enabledState
property to Enabled
.For example:
Azure Bicep snippetresource waf 'Microsoft.Network/FrontDoorWebApplicationFirewallPolicies@2022-05-01' = {\n name: name\n location: 'Global'\n sku: {\n name: 'Premium_AzureFrontDoor'\n }\n properties: {\n managedRules: {\n managedRuleSets: [\n {\n ruleSetType: 'Microsoft_DefaultRuleSet'\n ruleSetVersion: '2.0'\n ruleSetAction: 'Block'\n exclusions: []\n ruleGroupOverrides: []\n }\n {\n ruleSetType: 'Microsoft_BotManagerRuleSet'\n ruleSetVersion: '1.0'\n ruleSetAction: 'Block'\n exclusions: []\n ruleGroupOverrides: []\n }\n ]\n }\n policySettings: {\n enabledState: 'Enabled'\n mode: 'Prevention'\n }\n }\n}\n
","tags":["Azure.FrontDoorWAF.Enabled","AZR-000305"]},{"location":"en/rules/Azure.FrontDoorWAF.Enabled/#links","title":"Links","text":"Security \u00b7 Front Door \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions.
","tags":["Azure.FrontDoorWAF.Exclusions","AZR-000307"]},{"location":"en/rules/Azure.FrontDoorWAF.Exclusions/#description","title":"Description","text":"Front Door WAF supports exclusions lists.
Sometimes Web Application Firewall (WAF) might block a request that you want to allow for your application. WAF exclusion lists allow you to omit certain request attributes from a WAF evaluation. However, it should be allowed and only used as a last resort.
","tags":["Azure.FrontDoorWAF.Exclusions","AZR-000307"]},{"location":"en/rules/Azure.FrontDoorWAF.Exclusions/#recommendation","title":"Recommendation","text":"Avoid configuring Front Door WAF rule exclusions.
","tags":["Azure.FrontDoorWAF.Exclusions","AZR-000307"]},{"location":"en/rules/Azure.FrontDoorWAF.Exclusions/#examples","title":"Examples","text":"","tags":["Azure.FrontDoorWAF.Exclusions","AZR-000307"]},{"location":"en/rules/Azure.FrontDoorWAF.Exclusions/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy WAF policies that pass this rule:
exclusions
property for each managed rule group to an empty array. ORexclusions
property for each managed rule group.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/FrontDoorWebApplicationFirewallPolicies\",\n \"apiVersion\": \"2022-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"Global\",\n \"sku\": {\n \"name\": \"Premium_AzureFrontDoor\"\n },\n \"properties\": {\n \"managedRules\": {\n \"managedRuleSets\": [\n {\n \"ruleSetType\": \"Microsoft_DefaultRuleSet\",\n \"ruleSetVersion\": \"2.0\",\n \"ruleSetAction\": \"Block\",\n \"exclusions\": [],\n \"ruleGroupOverrides\": []\n },\n {\n \"ruleSetType\": \"Microsoft_BotManagerRuleSet\",\n \"ruleSetVersion\": \"1.0\",\n \"ruleSetAction\": \"Block\",\n \"exclusions\": [],\n \"ruleGroupOverrides\": []\n }\n ]\n },\n \"policySettings\": {\n \"enabledState\": \"Enabled\",\n \"mode\": \"Prevention\"\n }\n }\n}\n
","tags":["Azure.FrontDoorWAF.Exclusions","AZR-000307"]},{"location":"en/rules/Azure.FrontDoorWAF.Exclusions/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy WAF policies that pass this rule:
exclusions
property for each managed rule group to an empty array. ORexclusions
property for each managed rule group.For example:
Azure Bicep snippetresource waf 'Microsoft.Network/FrontDoorWebApplicationFirewallPolicies@2022-05-01' = {\n name: name\n location: 'Global'\n sku: {\n name: 'Premium_AzureFrontDoor'\n }\n properties: {\n managedRules: {\n managedRuleSets: [\n {\n ruleSetType: 'Microsoft_DefaultRuleSet'\n ruleSetVersion: '2.0'\n ruleSetAction: 'Block'\n exclusions: []\n ruleGroupOverrides: []\n }\n {\n ruleSetType: 'Microsoft_BotManagerRuleSet'\n ruleSetVersion: '1.0'\n ruleSetAction: 'Block'\n exclusions: []\n ruleGroupOverrides: []\n }\n ]\n }\n policySettings: {\n enabledState: 'Enabled'\n mode: 'Prevention'\n }\n }\n}\n
","tags":["Azure.FrontDoorWAF.Exclusions","AZR-000307"]},{"location":"en/rules/Azure.FrontDoorWAF.Exclusions/#links","title":"Links","text":"Security \u00b7 Front Door \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources.
","tags":["Azure.FrontDoorWAF.PreventionMode","AZR-000306"]},{"location":"en/rules/Azure.FrontDoorWAF.PreventionMode/#description","title":"Description","text":"Front Door WAF policies support two modes of operation, detection and prevention. By default, prevention is configured.
Consider setting Front Door WAF policy to use protection mode.
","tags":["Azure.FrontDoorWAF.PreventionMode","AZR-000306"]},{"location":"en/rules/Azure.FrontDoorWAF.PreventionMode/#examples","title":"Examples","text":"","tags":["Azure.FrontDoorWAF.PreventionMode","AZR-000306"]},{"location":"en/rules/Azure.FrontDoorWAF.PreventionMode/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy WAF policies that pass this rule:
properties.policySettings.mode
property to Prevention
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/FrontDoorWebApplicationFirewallPolicies\",\n \"apiVersion\": \"2022-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"Global\",\n \"sku\": {\n \"name\": \"Premium_AzureFrontDoor\"\n },\n \"properties\": {\n \"managedRules\": {\n \"managedRuleSets\": [\n {\n \"ruleSetType\": \"Microsoft_DefaultRuleSet\",\n \"ruleSetVersion\": \"2.0\",\n \"ruleSetAction\": \"Block\",\n \"exclusions\": [],\n \"ruleGroupOverrides\": []\n },\n {\n \"ruleSetType\": \"Microsoft_BotManagerRuleSet\",\n \"ruleSetVersion\": \"1.0\",\n \"ruleSetAction\": \"Block\",\n \"exclusions\": [],\n \"ruleGroupOverrides\": []\n }\n ]\n },\n \"policySettings\": {\n \"enabledState\": \"Enabled\",\n \"mode\": \"Prevention\"\n }\n }\n}\n
","tags":["Azure.FrontDoorWAF.PreventionMode","AZR-000306"]},{"location":"en/rules/Azure.FrontDoorWAF.PreventionMode/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy WAF policies that pass this rule:
properties.policySettings.mode
property to Prevention
.For example:
Azure Bicep snippetresource waf 'Microsoft.Network/FrontDoorWebApplicationFirewallPolicies@2022-05-01' = {\n name: name\n location: 'Global'\n sku: {\n name: 'Premium_AzureFrontDoor'\n }\n properties: {\n managedRules: {\n managedRuleSets: [\n {\n ruleSetType: 'Microsoft_DefaultRuleSet'\n ruleSetVersion: '2.0'\n ruleSetAction: 'Block'\n exclusions: []\n ruleGroupOverrides: []\n }\n {\n ruleSetType: 'Microsoft_BotManagerRuleSet'\n ruleSetVersion: '1.0'\n ruleSetAction: 'Block'\n exclusions: []\n ruleGroupOverrides: []\n }\n ]\n }\n policySettings: {\n enabledState: 'Enabled'\n mode: 'Prevention'\n }\n }\n}\n
","tags":["Azure.FrontDoorWAF.PreventionMode","AZR-000306"]},{"location":"en/rules/Azure.FrontDoorWAF.PreventionMode/#links","title":"Links","text":"Security \u00b7 Front Door \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources.
","tags":["Azure.FrontDoorWAF.RuleGroups","AZR-000308"]},{"location":"en/rules/Azure.FrontDoorWAF.RuleGroups/#description","title":"Description","text":"Front Door WAF policies support two main Rule Groups.
Consider configuring Front Door WAF policy to use the recommended rule sets.
","tags":["Azure.FrontDoorWAF.RuleGroups","AZR-000308"]},{"location":"en/rules/Azure.FrontDoorWAF.RuleGroups/#examples","title":"Examples","text":"","tags":["Azure.FrontDoorWAF.RuleGroups","AZR-000308"]},{"location":"en/rules/Azure.FrontDoorWAF.RuleGroups/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy WAF policies that pass this rule:
Microsoft_DefaultRuleSet
rule set to the properties.managedRules.managedRuleSets
property.2.0
or greater.Microsoft_BotManagerRuleSet
rule set to the properties.managedRules.managedRuleSets
property.1.0
or greater.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/FrontDoorWebApplicationFirewallPolicies\",\n \"apiVersion\": \"2022-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"Global\",\n \"sku\": {\n \"name\": \"Premium_AzureFrontDoor\"\n },\n \"properties\": {\n \"managedRules\": {\n \"managedRuleSets\": [\n {\n \"ruleSetType\": \"Microsoft_DefaultRuleSet\",\n \"ruleSetVersion\": \"2.0\",\n \"ruleSetAction\": \"Block\",\n \"exclusions\": [],\n \"ruleGroupOverrides\": []\n },\n {\n \"ruleSetType\": \"Microsoft_BotManagerRuleSet\",\n \"ruleSetVersion\": \"1.0\",\n \"ruleSetAction\": \"Block\",\n \"exclusions\": [],\n \"ruleGroupOverrides\": []\n }\n ]\n },\n \"policySettings\": {\n \"enabledState\": \"Enabled\",\n \"mode\": \"Prevention\"\n }\n }\n}\n
","tags":["Azure.FrontDoorWAF.RuleGroups","AZR-000308"]},{"location":"en/rules/Azure.FrontDoorWAF.RuleGroups/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy WAF policies that pass this rule:
Microsoft_DefaultRuleSet
rule set to the properties.managedRules.managedRuleSets
property.2.0
or greater.Microsoft_BotManagerRuleSet
rule set to the properties.managedRules.managedRuleSets
property.1.0
or greater.For example:
Azure Bicep snippetresource waf 'Microsoft.Network/FrontDoorWebApplicationFirewallPolicies@2022-05-01' = {\n name: name\n location: 'Global'\n sku: {\n name: 'Premium_AzureFrontDoor'\n }\n properties: {\n managedRules: {\n managedRuleSets: [\n {\n ruleSetType: 'Microsoft_DefaultRuleSet'\n ruleSetVersion: '2.0'\n ruleSetAction: 'Block'\n exclusions: []\n ruleGroupOverrides: []\n }\n {\n ruleSetType: 'Microsoft_BotManagerRuleSet'\n ruleSetVersion: '1.0'\n ruleSetAction: 'Block'\n exclusions: []\n ruleGroupOverrides: []\n }\n ]\n }\n policySettings: {\n enabledState: 'Enabled'\n mode: 'Prevention'\n }\n }\n}\n
","tags":["Azure.FrontDoorWAF.RuleGroups","AZR-000308"]},{"location":"en/rules/Azure.FrontDoorWAF.RuleGroups/#links","title":"Links","text":"Operational Excellence \u00b7 User Assigned Managed Identity \u00b7 Rule \u00b7 2021_12 \u00b7 Awareness
Managed Identity names should meet naming requirements.
","tags":["Azure.Identity.UserAssignedName","AZR-000117"]},{"location":"en/rules/Azure.Identity.UserAssignedName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Managed Identity names are:
Consider using names that meet Managed Identity naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.Identity.UserAssignedName","AZR-000117"]},{"location":"en/rules/Azure.Identity.UserAssignedName/#notes","title":"Notes","text":"This rule does not check if Managed Identity names are unique.
","tags":["Azure.Identity.UserAssignedName","AZR-000117"]},{"location":"en/rules/Azure.Identity.UserAssignedName/#links","title":"Links","text":"Security \u00b7 IoT Hub \u00b7 Rule \u00b7 2023_03 \u00b7 Critical
IoT Hubs should reject TLS versions older than 1.2.
","tags":["Azure.IoTHub.MinTLS","AZR-000357"]},{"location":"en/rules/Azure.IoTHub.MinTLS/#description","title":"Description","text":"The minimum version of TLS that IoT Hubs accept is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Azure lets you disable outdated protocols and require connections to use a minimum of TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 is accepted.
","tags":["Azure.IoTHub.MinTLS","AZR-000357"]},{"location":"en/rules/Azure.IoTHub.MinTLS/#recommendation","title":"Recommendation","text":"Configure the minimum supported TLS version to be 1.2.
","tags":["Azure.IoTHub.MinTLS","AZR-000357"]},{"location":"en/rules/Azure.IoTHub.MinTLS/#examples","title":"Examples","text":"","tags":["Azure.IoTHub.MinTLS","AZR-000357"]},{"location":"en/rules/Azure.IoTHub.MinTLS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy IoT Hubs that pass this rule:
properties.minTlsVersion
property to 1.2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Devices/IotHubs\",\n \"apiVersion\": \"2022-04-30-preview\",\n \"name\": \"[parameters('iotHubName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"S1\",\n \"capacity\": 1,\n },\n \"properties\": {\n \"minimumTlsVersion\": \"1.2\",\n }\n}\n
","tags":["Azure.IoTHub.MinTLS","AZR-000357"]},{"location":"en/rules/Azure.IoTHub.MinTLS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy IoT Hubs that pass this rule:
properties.minTlsVersion
property to 1.2
.For example:
Azure Bicep snippetresource IoTHub 'Microsoft.Devices/IotHubs@2022-04-30-preview' = {\n name: iotHubName\n location: location\n sku: {\n name: 'S1'\n capacity: 1\n }\n properties: {\n minTlsVersion: '1.2'\n }\n}\n
","tags":["Azure.IoTHub.MinTLS","AZR-000357"]},{"location":"en/rules/Azure.IoTHub.MinTLS/#notes","title":"Notes","text":"The minimum TLS version feature is currently only supported in these regions: - East US - South Central US - West US 2 - US Gov Arizona - US Gov Virginia
The minTlsVersion
property is read-only and cannot be changed once your IoT Hub resource is created. It is therefore important to properly test and validate that all oT devices and services are compatible with TLS 1.2 and the recommended ciphers in advance.
Security \u00b7 Key Vault \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use the principal of least privilege when assigning access to Key Vault.
","tags":["Azure.KeyVault.AccessPolicy","AZR-000118"]},{"location":"en/rules/Azure.KeyVault.AccessPolicy/#description","title":"Description","text":"Key Vault is a service designed to securely store sensitive items such as secrets, keys and certificates. Access Policies determine the permissions user accounts, groups or applications have to Key Vaults items.
The ability for applications and administrators to get, set and list within a Key Vault is commonly required. However should only be assigned to security principals that require access. The purge permission should be rarely assigned.
","tags":["Azure.KeyVault.AccessPolicy","AZR-000118"]},{"location":"en/rules/Azure.KeyVault.AccessPolicy/#recommendation","title":"Recommendation","text":"Consider assigning access to Key Vault data based on the principle of least privilege.
","tags":["Azure.KeyVault.AccessPolicy","AZR-000118"]},{"location":"en/rules/Azure.KeyVault.AccessPolicy/#examples","title":"Examples","text":"","tags":["Azure.KeyVault.AccessPolicy","AZR-000118"]},{"location":"en/rules/Azure.KeyVault.AccessPolicy/#azure-templates","title":"Azure templates","text":"To deploy Key Vaults that pass this rule:
purge
and all
permissions for Key Vault objects. Use specific permissions such as get
and set
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.KeyVault/vaults\",\n \"apiVersion\": \"2022-07-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"sku\": {\n \"family\": \"A\",\n \"name\": \"premium\"\n },\n \"tenantId\": \"[tenant().tenantId]\",\n \"softDeleteRetentionInDays\": 90,\n \"enableSoftDelete\": true,\n \"enablePurgeProtection\": true,\n \"accessPolicies\": [\n {\n \"objectId\": \"[parameters('objectId')]\",\n \"permissions\": {\n \"secrets\": [\n \"get\",\n \"list\",\n \"set\"\n ]\n },\n \"tenantId\": \"[tenant().tenantId]\"\n }\n ]\n }\n}\n
","tags":["Azure.KeyVault.AccessPolicy","AZR-000118"]},{"location":"en/rules/Azure.KeyVault.AccessPolicy/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Key Vaults that pass this rule:
purge
and all
permissions for Key Vault objects. Use specific permissions such as get
and set
.For example:
Azure Bicep snippetresource vault 'Microsoft.KeyVault/vaults@2022-07-01' = {\n name: name\n location: location\n properties: {\n sku: {\n family: 'A'\n name: 'premium'\n }\n tenantId: tenant().tenantId\n softDeleteRetentionInDays: 90\n enableSoftDelete: true\n enablePurgeProtection: true\n accessPolicies: [\n {\n objectId: objectId\n permissions: {\n secrets: [\n 'get'\n 'list'\n 'set'\n ]\n }\n tenantId: tenant().tenantId\n }\n ]\n }\n}\n
","tags":["Azure.KeyVault.AccessPolicy","AZR-000118"]},{"location":"en/rules/Azure.KeyVault.AccessPolicy/#links","title":"Links","text":"Security \u00b7 Key Vault \u00b7 Rule \u00b7 2022_09 \u00b7 Important
Key Vault keys should have auto-rotation enabled.
","tags":["Azure.KeyVault.AutoRotationPolicy","AZR-000123"]},{"location":"en/rules/Azure.KeyVault.AutoRotationPolicy/#description","title":"Description","text":"Automated key rotation in Key Vault allows users to configure Key Vault to automatically generate a new key version at a specified frequency.
Key rotation is often a cause of many application outages. It's critical that the rotation of keys be scheduled and automated to ensure effectiveness.
","tags":["Azure.KeyVault.AutoRotationPolicy","AZR-000123"]},{"location":"en/rules/Azure.KeyVault.AutoRotationPolicy/#recommendation","title":"Recommendation","text":"Consider enabling auto-rotation on Key Vault keys.
","tags":["Azure.KeyVault.AutoRotationPolicy","AZR-000123"]},{"location":"en/rules/Azure.KeyVault.AutoRotationPolicy/#examples","title":"Examples","text":"","tags":["Azure.KeyVault.AutoRotationPolicy","AZR-000123"]},{"location":"en/rules/Azure.KeyVault.AutoRotationPolicy/#configure-with-azure-template","title":"Configure with Azure template","text":"To set auto-rotation for a key:
properties.rotationPolicy.lifetimeActions[*].action.type
to Rotate
.properties.rotationPolicy.lifetimeActions[*].trigger.timeAfterCreate
to the time duration after key creation to rotate.For example:
Azure Template snippet{\n \"type\": \"Microsoft.KeyVault/vaults/keys\",\n \"apiVersion\": \"2021-06-01-preview\",\n \"name\": \"[concat(parameters('vaultName'), '/', 'key1')]\",\n \"properties\": {\n \"keyOps\": [\n \"sign\",\n \"verify\",\n \"wrapKey\",\n \"unwrapKey\",\n \"encrypt\",\n \"decrypt\"\n ],\n \"keySize\": 2048,\n \"kty\": \"RSA\",\n \"rotationPolicy\": {\n \"lifetimeActions\": [\n {\n \"action\": {\n \"type\": \"Rotate\"\n },\n \"trigger\": {\n \"timeAfterCreate\": \"P18D\"\n }\n },\n {\n \"action\": {\n \"type\": \"Notify\"\n },\n \"trigger\": {\n \"timeAfterCreate\": \"P30D\"\n }\n }\n ]\n }\n }\n}\n
","tags":["Azure.KeyVault.AutoRotationPolicy","AZR-000123"]},{"location":"en/rules/Azure.KeyVault.AutoRotationPolicy/#configure-with-bicep","title":"Configure with Bicep","text":"To set auto-rotation for a key:
properties.rotationPolicy.lifetimeActions[*].action.type
to Rotate
.properties.rotationPolicy.lifetimeActions[*].trigger.timeAfterCreate
to the time duration after key creation to rotate.For example:
Azure Bicep snippetresource vaultName_key1 'Microsoft.KeyVault/vaults/keys@2021-06-01-preview' = {\n parent: vaultName_resource\n name: 'key1'\n properties: {\n keyOps: [\n 'sign'\n 'verify'\n 'wrapKey'\n 'unwrapKey'\n 'encrypt'\n 'decrypt'\n ]\n keySize: 2048\n kty: 'RSA'\n rotationPolicy: {\n lifetimeActions: [\n {\n action: {\n type: 'rotate'\n }\n trigger: {\n timeAfterCreate: 'P18D'\n }\n }\n {\n action: {\n type: 'notify'\n }\n trigger: {\n timeAfterCreate: 'P30D'\n }\n }\n ]\n }\n }\n}\n
","tags":["Azure.KeyVault.AutoRotationPolicy","AZR-000123"]},{"location":"en/rules/Azure.KeyVault.AutoRotationPolicy/#links","title":"Links","text":"Security \u00b7 Key Vault \u00b7 Rule \u00b7 2023_03 \u00b7 Important
Key Vault should only accept explicitly allowed traffic.
","tags":["Azure.KeyVault.Firewall","AZR-000355"]},{"location":"en/rules/Azure.KeyVault.Firewall/#description","title":"Description","text":"By default, Key Vault accept connections from clients on any network. To limit access to selected networks, you must first change the default action.
After changing the default action from Allow
to Deny
, configure one or more rules to allow traffic. Traffic can be allowed from:
If any of the following options are enabled you must also enable Allow trusted Microsoft services to bypass this firewall:
enabledForDeployment
- Azure Virtual Machines for deployment.enabledForDiskEncryption
- Azure Disk Encryption for volume encryption.enabledForTemplateDeployment
- Azure Resource Manager for template deployment.Consider configuring Key Vault firewall to restrict network access to permitted clients only. Also consider enforcing this setting using Azure Policy.
","tags":["Azure.KeyVault.Firewall","AZR-000355"]},{"location":"en/rules/Azure.KeyVault.Firewall/#examples","title":"Examples","text":"","tags":["Azure.KeyVault.Firewall","AZR-000355"]},{"location":"en/rules/Azure.KeyVault.Firewall/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Key Vaults that pass this rule:
properties.networkAcls.defaultAction
property to Deny
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.KeyVault/vaults\",\n \"apiVersion\": \"2023-02-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"sku\": {\n \"family\": \"A\",\n \"name\": \"premium\"\n },\n \"tenantId\": \"[tenant().tenantId]\",\n \"softDeleteRetentionInDays\": 90,\n \"enableSoftDelete\": true,\n \"enablePurgeProtection\": true,\n \"enableRbacAuthorization\": true,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\",\n \"bypass\": \"AzureServices\"\n }\n }\n}\n
","tags":["Azure.KeyVault.Firewall","AZR-000355"]},{"location":"en/rules/Azure.KeyVault.Firewall/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Key Vaults that pass this rule:
properties.networkAcls.defaultAction
property to Deny
.For example:
Azure Bicep snippetresource vault 'Microsoft.KeyVault/vaults@2023-02-01' = {\n name: name\n location: location\n properties: {\n sku: {\n family: 'A'\n name: 'premium'\n }\n tenantId: tenant().tenantId\n softDeleteRetentionInDays: 90\n enableSoftDelete: true\n enablePurgeProtection: true\n enableRbacAuthorization: true\n networkAcls: {\n defaultAction: 'Deny'\n bypass: 'AzureServices'\n }\n }\n}\n
","tags":["Azure.KeyVault.Firewall","AZR-000355"]},{"location":"en/rules/Azure.KeyVault.Firewall/#links","title":"Links","text":"Operational Excellence \u00b7 Key Vault \u00b7 Rule \u00b7 2021_03 \u00b7 Awareness
Key Vault Key names should meet naming requirements.
","tags":["Azure.KeyVault.KeyName","AZR-000122"]},{"location":"en/rules/Azure.KeyVault.KeyName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Key Vault Key names are:
Consider using key names that meet Key Vault naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.KeyVault.KeyName","AZR-000122"]},{"location":"en/rules/Azure.KeyVault.KeyName/#notes","title":"Notes","text":"This rule does not check if Key names are unique.
","tags":["Azure.KeyVault.KeyName","AZR-000122"]},{"location":"en/rules/Azure.KeyVault.KeyName/#links","title":"Links","text":"Security \u00b7 Key Vault \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Ensure audit diagnostics logs are enabled to audit Key Vault access.
","tags":["Azure.KeyVault.Logs","AZR-000119"]},{"location":"en/rules/Azure.KeyVault.Logs/#description","title":"Description","text":"To capture logs that record interactions with data or the settings of key vault, diagnostic settings must be configured.
When configuring diagnostics settings, enable one of the following:
AuditEvent
category.audit
category group.allLogs
category group.Management operations for Key Vault is captured automatically within Azure Activity Logs.
","tags":["Azure.KeyVault.Logs","AZR-000119"]},{"location":"en/rules/Azure.KeyVault.Logs/#recommendation","title":"Recommendation","text":"Configure audit diagnostics logs to audit Key Vault access.
","tags":["Azure.KeyVault.Logs","AZR-000119"]},{"location":"en/rules/Azure.KeyVault.Logs/#examples","title":"Examples","text":"","tags":["Azure.KeyVault.Logs","AZR-000119"]},{"location":"en/rules/Azure.KeyVault.Logs/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy key vaults that pass this rule:
AuditEvent
category or audit
category group or allLogs
category group.For example:
Azure Template snippet{\n \"type\": \"Microsoft.KeyVault/vaults\",\n \"apiVersion\": \"2023-02-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"sku\": {\n \"family\": \"A\",\n \"name\": \"premium\"\n },\n \"tenantId\": \"[tenant().tenantId]\",\n \"softDeleteRetentionInDays\": 90,\n \"enableSoftDelete\": true,\n \"enablePurgeProtection\": true,\n \"enableRbacAuthorization\": true,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\",\n \"bypass\": \"AzureServices\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Insights/diagnosticSettings\",\n \"apiVersion\": \"2021-05-01-preview\",\n \"scope\": \"[format('Microsoft.KeyVault/vaults/{0}', parameters('name'))]\",\n \"name\": \"logs\",\n \"properties\": {\n \"workspaceId\": \"[parameters('workspaceId')]\",\n \"logs\": [\n {\n \"category\": \"AuditEvent\",\n \"enabled\": true\n }\n ]\n },\n \"dependsOn\": [\n \"[parameters('name')]\"\n ]\n }\n ]\n}\n
","tags":["Azure.KeyVault.Logs","AZR-000119"]},{"location":"en/rules/Azure.KeyVault.Logs/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy key vaults that pass this rule:
AuditEvent
category or audit
category group or allLogs
category group.For example:
Azure Bicep snippetresource vault 'Microsoft.KeyVault/vaults@2023-02-01' = {\n name: name\n location: location\n properties: {\n sku: {\n family: 'A'\n name: 'premium'\n }\n tenantId: tenant().tenantId\n softDeleteRetentionInDays: 90\n enableSoftDelete: true\n enablePurgeProtection: true\n enableRbacAuthorization: true\n networkAcls: {\n defaultAction: 'Deny'\n bypass: 'AzureServices'\n }\n }\n}\n\nresource logs 'Microsoft.Insights/diagnosticSettings@2021-05-01-preview' = {\n name: 'logs'\n scope: vault\n properties: {\n workspaceId: workspaceId\n logs: [\n {\n category: 'AuditEvent'\n enabled: true\n }\n ]\n }\n}\n
","tags":["Azure.KeyVault.Logs","AZR-000119"]},{"location":"en/rules/Azure.KeyVault.Logs/#links","title":"Links","text":"Operational Excellence \u00b7 Key Vault \u00b7 Rule \u00b7 2021_03 \u00b7 Awareness
Key Vault names should meet naming requirements.
","tags":["Azure.KeyVault.Name","AZR-000120"]},{"location":"en/rules/Azure.KeyVault.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Key Vault names are:
Consider using names that meet Key Vault naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.KeyVault.Name","AZR-000120"]},{"location":"en/rules/Azure.KeyVault.Name/#notes","title":"Notes","text":"This rule does not check if Key Vault names are unique.
","tags":["Azure.KeyVault.Name","AZR-000120"]},{"location":"en/rules/Azure.KeyVault.Name/#links","title":"Links","text":"Reliability \u00b7 Key Vault \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items.
","tags":["Azure.KeyVault.PurgeProtect","AZR-000125"]},{"location":"en/rules/Azure.KeyVault.PurgeProtect/#description","title":"Description","text":"Purge Protection is a feature of Key Vault that prevents purging of vaults and vault items. When soft delete is configured without purge protection, deleted vaults and vault items can be purged. Purging deletes the vault and/ or vault items immediately, and is irreversible.
When purge protection is enabled, vaults and vault items can no longer be purged. Deleted vaults and vault items will be recoverable until the configured retention period. By default, the retention period is 90 days.
Purge protection is not enabled by default.
","tags":["Azure.KeyVault.PurgeProtect","AZR-000125"]},{"location":"en/rules/Azure.KeyVault.PurgeProtect/#recommendation","title":"Recommendation","text":"Consider enabling purge protection on Key Vaults to enforce retention of vaults and vault items for up to 90 days.
","tags":["Azure.KeyVault.PurgeProtect","AZR-000125"]},{"location":"en/rules/Azure.KeyVault.PurgeProtect/#examples","title":"Examples","text":"","tags":["Azure.KeyVault.PurgeProtect","AZR-000125"]},{"location":"en/rules/Azure.KeyVault.PurgeProtect/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Key Vaults that pass this rule:
properties.enablePurgeProtection
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.KeyVault/vaults\",\n \"apiVersion\": \"2023-07-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"sku\": {\n \"family\": \"A\",\n \"name\": \"premium\"\n },\n \"tenantId\": \"[tenant().tenantId]\",\n \"softDeleteRetentionInDays\": 90,\n \"enableSoftDelete\": true,\n \"enablePurgeProtection\": true,\n \"enableRbacAuthorization\": true,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\",\n \"bypass\": \"AzureServices\"\n }\n }\n}\n
","tags":["Azure.KeyVault.PurgeProtect","AZR-000125"]},{"location":"en/rules/Azure.KeyVault.PurgeProtect/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Key Vaults that pass this rule:
properties.enablePurgeProtection
property to true
.For example:
Azure Bicep snippetresource vault 'Microsoft.KeyVault/vaults@2023-07-01' = {\n name: name\n location: location\n properties: {\n sku: {\n family: 'A'\n name: 'premium'\n }\n tenantId: tenant().tenantId\n softDeleteRetentionInDays: 90\n enableSoftDelete: true\n enablePurgeProtection: true\n enableRbacAuthorization: true\n networkAcls: {\n defaultAction: 'Deny'\n bypass: 'AzureServices'\n }\n }\n}\n
","tags":["Azure.KeyVault.PurgeProtect","AZR-000125"]},{"location":"en/rules/Azure.KeyVault.PurgeProtect/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz keyvault update -n '<name>' -g '<resource_group>' --enable-purge-protection\n
","tags":["Azure.KeyVault.PurgeProtect","AZR-000125"]},{"location":"en/rules/Azure.KeyVault.PurgeProtect/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetUpdate-AzKeyVault -ResourceGroupName '<resource_group>' -Name '<name>' -EnablePurgeProtection\n
","tags":["Azure.KeyVault.PurgeProtect","AZR-000125"]},{"location":"en/rules/Azure.KeyVault.PurgeProtect/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
Security \u00b7 Key Vault \u00b7 Rule \u00b7 2023_06 \u00b7 Awareness
Key Vaults should use Azure RBAC as the authorization system for the data plane.
","tags":["Azure.KeyVault.RBAC","AZR-000388"]},{"location":"en/rules/Azure.KeyVault.RBAC/#description","title":"Description","text":"Azure RBAC is the recommended authorization system for the Azure Key Vault data plane.
Azure RBAC allows users to manage key, secrets, and certificates permissions. It provides one place to manage all permissions across all Key Vaults.
Azure RBAC for Key Vault also allows users to have separate permissions on individual keys, secrets, and certificates.
The Azure RBAC permission model is not enabled by default.
","tags":["Azure.KeyVault.RBAC","AZR-000388"]},{"location":"en/rules/Azure.KeyVault.RBAC/#recommendation","title":"Recommendation","text":"Consider using Azure RBAC as the authorization system on Key Vaults for the data plane.
","tags":["Azure.KeyVault.RBAC","AZR-000388"]},{"location":"en/rules/Azure.KeyVault.RBAC/#examples","title":"Examples","text":"","tags":["Azure.KeyVault.RBAC","AZR-000388"]},{"location":"en/rules/Azure.KeyVault.RBAC/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Key Vaults that pass this rule:
properties.enableRbacAuthorization
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.KeyVault/vaults\",\n \"apiVersion\": \"2023-07-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"sku\": {\n \"family\": \"A\",\n \"name\": \"premium\"\n },\n \"tenantId\": \"[tenant().tenantId]\",\n \"softDeleteRetentionInDays\": 90,\n \"enableSoftDelete\": true,\n \"enablePurgeProtection\": true,\n \"enableRbacAuthorization\": true,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\",\n \"bypass\": \"AzureServices\"\n }\n }\n}\n
","tags":["Azure.KeyVault.RBAC","AZR-000388"]},{"location":"en/rules/Azure.KeyVault.RBAC/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Key Vaults that pass this rule:
properties.enableRbacAuthorization
property to true
.For example:
Azure Bicep snippetresource vault 'Microsoft.KeyVault/vaults@2023-07-01' = {\n name: name\n location: location\n properties: {\n sku: {\n family: 'A'\n name: 'premium'\n }\n tenantId: tenant().tenantId\n softDeleteRetentionInDays: 90\n enableSoftDelete: true\n enablePurgeProtection: true\n enableRbacAuthorization: true\n networkAcls: {\n defaultAction: 'Deny'\n bypass: 'AzureServices'\n }\n }\n}\n
","tags":["Azure.KeyVault.RBAC","AZR-000388"]},{"location":"en/rules/Azure.KeyVault.RBAC/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz keyvault update -n '<name>' -g '<resource_group>' --enable-rbac-authorization\n
","tags":["Azure.KeyVault.RBAC","AZR-000388"]},{"location":"en/rules/Azure.KeyVault.RBAC/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetUpdate-AzKeyVault -ResourceGroupName '<resource_group>' -Name '<name>' -EnableRbacAuthorization\n
","tags":["Azure.KeyVault.RBAC","AZR-000388"]},{"location":"en/rules/Azure.KeyVault.RBAC/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
The RBAC permission model may not be suitable for all use cases. If this rule is not suitable for your use case, you can exclude or suppress the rule. For information about limitations see Azure role-based access control vs. access policies in the LINKS
section.
Operational Excellence \u00b7 Key Vault \u00b7 Rule \u00b7 2021_03 \u00b7 Awareness
Key Vault Secret names should meet naming requirements.
","tags":["Azure.KeyVault.SecretName","AZR-000121"]},{"location":"en/rules/Azure.KeyVault.SecretName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Key Vault Secret names are:
Consider using secret names that meet Key Vault naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.KeyVault.SecretName","AZR-000121"]},{"location":"en/rules/Azure.KeyVault.SecretName/#notes","title":"Notes","text":"This rule does not check if Secret names are unique.
","tags":["Azure.KeyVault.SecretName","AZR-000121"]},{"location":"en/rules/Azure.KeyVault.SecretName/#links","title":"Links","text":"Reliability \u00b7 Key Vault \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion.
","tags":["Azure.KeyVault.SoftDelete","AZR-000124"]},{"location":"en/rules/Azure.KeyVault.SoftDelete/#description","title":"Description","text":"Soft Delete is a feature of Key Vault that retains Key Vaults and Key Vault items after initial deletion. A soft deleted vault or vault item can be restored within the configured retention period.
By default, new Key Vaults created through the portal will have soft delete for 90 days configured.
Once enabled, soft delete can not be disabled. When soft delete is enabled, it is possible to purge soft deleted vaults and vault items.
","tags":["Azure.KeyVault.SoftDelete","AZR-000124"]},{"location":"en/rules/Azure.KeyVault.SoftDelete/#recommendation","title":"Recommendation","text":"Consider enabling soft delete on Key Vaults to enable recovery of vaults and vault items.
","tags":["Azure.KeyVault.SoftDelete","AZR-000124"]},{"location":"en/rules/Azure.KeyVault.SoftDelete/#examples","title":"Examples","text":"","tags":["Azure.KeyVault.SoftDelete","AZR-000124"]},{"location":"en/rules/Azure.KeyVault.SoftDelete/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Key Vaults that pass this rule:
properties.enableSoftDelete
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.KeyVault/vaults\",\n \"apiVersion\": \"2023-07-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"sku\": {\n \"family\": \"A\",\n \"name\": \"premium\"\n },\n \"tenantId\": \"[tenant().tenantId]\",\n \"softDeleteRetentionInDays\": 90,\n \"enableSoftDelete\": true,\n \"enablePurgeProtection\": true,\n \"enableRbacAuthorization\": true,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\",\n \"bypass\": \"AzureServices\"\n }\n }\n}\n
","tags":["Azure.KeyVault.SoftDelete","AZR-000124"]},{"location":"en/rules/Azure.KeyVault.SoftDelete/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Key Vaults that pass this rule:
properties.enableSoftDelete
property to true
.For example:
Azure Bicep snippetresource vault 'Microsoft.KeyVault/vaults@2023-07-01' = {\n name: name\n location: location\n properties: {\n sku: {\n family: 'A'\n name: 'premium'\n }\n tenantId: tenant().tenantId\n softDeleteRetentionInDays: 90\n enableSoftDelete: true\n enablePurgeProtection: true\n enableRbacAuthorization: true\n networkAcls: {\n defaultAction: 'Deny'\n bypass: 'AzureServices'\n }\n }\n}\n
","tags":["Azure.KeyVault.SoftDelete","AZR-000124"]},{"location":"en/rules/Azure.KeyVault.SoftDelete/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz keyvault update -n '<name>' -g '<resource_group>' --retention-days 90\n
","tags":["Azure.KeyVault.SoftDelete","AZR-000124"]},{"location":"en/rules/Azure.KeyVault.SoftDelete/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
Reliability \u00b7 Load Balancer \u00b7 Rule \u00b7 2021_09 \u00b7 Important
Load balancers deployed with Standard SKU should be zone-redundant for high availability.
","tags":["Azure.LB.AvailabilityZone","AZR-000127"]},{"location":"en/rules/Azure.LB.AvailabilityZone/#description","title":"Description","text":"Load balancers using availability zones improve reliability and ensure availability during failure scenarios affecting a data center within a region. A single zone redundant frontend IP address will survive zone failure. The frontend IP may be used to reach all (non-impacted) backend pool members no matter the zone. One or more availability zones can fail and the data path survives as long as one zone in the region remains healthy.
","tags":["Azure.LB.AvailabilityZone","AZR-000127"]},{"location":"en/rules/Azure.LB.AvailabilityZone/#recommendation","title":"Recommendation","text":"Consider using zone-redundant load balancers deployed with Standard SKU.
","tags":["Azure.LB.AvailabilityZone","AZR-000127"]},{"location":"en/rules/Azure.LB.AvailabilityZone/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed to Azure using pre-flight and in-flight data.
This rule fails when \"zones\"
is constrained to a single(zonal) zone or is not configured, and passes when set to [\"1\", \"2\", \"3\"]
.
To configure zone-redundancy for a load balancer.
sku.name
to Standard
.properties.frontendIPConfigurations[*].zones
to [\"1\", \"2\", \"3\"]
.For example:
Azure Template snippet{\n \"apiVersion\": \"2020-07-01\",\n \"name\": \"[parameters('name')]\",\n \"type\": \"Microsoft.Network/loadBalancers\",\n \"location\": \"[parameters('location')]\",\n \"dependsOn\": [],\n \"tags\": {},\n \"properties\": {\n \"frontendIPConfigurations\": [\n {\n \"name\": \"frontend-ip-config\",\n \"properties\": {\n \"privateIPAddress\": null,\n \"privateIPAddressVersion\": \"IPv4\",\n \"privateIPAllocationMethod\": \"Dynamic\",\n \"subnet\": {\n \"id\": \"/subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/resourceGroups/lb-rg/providers/Microsoft.Network/virtualNetworks/lb-vnet/subnets/default\"\n }\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n }\n ],\n \"backendAddressPools\": [],\n \"probes\": [],\n \"loadBalancingRules\": [],\n \"inboundNatRules\": [],\n \"outboundRules\": []\n },\n \"sku\": {\n \"name\": \"[parameters('sku')]\",\n \"tier\": \"[parameters('tier')]\"\n }\n}\n
","tags":["Azure.LB.AvailabilityZone","AZR-000127"]},{"location":"en/rules/Azure.LB.AvailabilityZone/#configure-with-bicep","title":"Configure with Bicep","text":"To configure zone-redundancy for a load balancer.
sku.name
to Standard
.properties.frontendIPConfigurations[*].zones
to ['1', '2', '3']
.For example:
Azure Bicep snippetresource lb_001 'Microsoft.Network/loadBalancers@2021-02-01' = {\n name: lbName\n location: location\n sku: {\n name: 'Standard'\n }\n properties: {\n frontendIPConfigurations: [\n {\n name: 'frontendIPConfig'\n properties: {\n privateIPAllocationMethod: 'Dynamic'\n subnet: {\n id: vnet.properties.subnets[1].id\n }\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n }\n ]\n }\n}\n
","tags":["Azure.LB.AvailabilityZone","AZR-000127"]},{"location":"en/rules/Azure.LB.AvailabilityZone/#links","title":"Links","text":"Operational Excellence \u00b7 Load Balancer \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Load Balancer names should meet naming requirements.
","tags":["Azure.LB.Name","AZR-000129"]},{"location":"en/rules/Azure.LB.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Load Balancer names are:
Consider using names that meet Load Balancer naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.LB.Name","AZR-000129"]},{"location":"en/rules/Azure.LB.Name/#notes","title":"Notes","text":"This rule does not check if Load Balancer names are unique.
","tags":["Azure.LB.Name","AZR-000129"]},{"location":"en/rules/Azure.LB.Name/#links","title":"Links","text":"Reliability \u00b7 Load Balancer \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use a specific probe for web protocols.
","tags":["Azure.LB.Probe","AZR-000126"]},{"location":"en/rules/Azure.LB.Probe/#description","title":"Description","text":"A load balancer probe can be configured as TCP/ HTTP or HTTPS.
","tags":["Azure.LB.Probe","AZR-000126"]},{"location":"en/rules/Azure.LB.Probe/#recommendation","title":"Recommendation","text":"Consider using a dedicated health check endpoint for HTTP or HTTPS health probes.
","tags":["Azure.LB.Probe","AZR-000126"]},{"location":"en/rules/Azure.LB.Probe/#links","title":"Links","text":"Reliability \u00b7 Load Balancer \u00b7 Rule \u00b7 2021_09 \u00b7 Important
Load balancers should be deployed with Standard SKU for production workloads.
","tags":["Azure.LB.StandardSKU","AZR-000128"]},{"location":"en/rules/Azure.LB.StandardSKU/#description","title":"Description","text":"Standard Load Balancer enables you to scale your applications and create high availability for small scale deployments to large and complex multi-zone architectures. It supports inbound as well as outbound connections, provides low latency and high throughput, and scales up to millions of flows for all TCP and UDP applications. It enables Availability Zones with zone-redundant and zonal front ends as well as cross-zone load balancing for public and internal scenarios. You can scale Network Virtual Appliance scenarios and make them more resilient by using internal HA Ports load balancing rules. It also provides new diagnostics insights with multi-dimensional metrics in Azure Monitor.
","tags":["Azure.LB.StandardSKU","AZR-000128"]},{"location":"en/rules/Azure.LB.StandardSKU/#recommendation","title":"Recommendation","text":"Consider using Standard SKU for load balancers deployed in production.
","tags":["Azure.LB.StandardSKU","AZR-000128"]},{"location":"en/rules/Azure.LB.StandardSKU/#examples","title":"Examples","text":"","tags":["Azure.LB.StandardSKU","AZR-000128"]},{"location":"en/rules/Azure.LB.StandardSKU/#configure-with-azure-template","title":"Configure with Azure template","text":"To configure Standard SKU for a load balancer.
sku.name
to Standard
.For example:
Azure Template snippet{\n \"apiVersion\": \"2020-07-01\",\n \"name\": \"[parameters('name')]\",\n \"type\": \"Microsoft.Network/loadBalancers\",\n \"location\": \"[parameters('location')]\",\n \"dependsOn\": [],\n \"tags\": {},\n \"properties\": {\n \"frontendIPConfigurations\": [\n {\n \"name\": \"frontend-ip-config\",\n \"properties\": {\n \"privateIPAddress\": null,\n \"privateIPAddressVersion\": \"IPv4\",\n \"privateIPAllocationMethod\": \"Dynamic\",\n \"subnet\": {\n \"id\": \"/subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/resourceGroups/lb-rg/providers/Microsoft.Network/virtualNetworks/lb-vnet/subnets/default\"\n }\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n }\n ],\n \"backendAddressPools\": [],\n \"probes\": [],\n \"loadBalancingRules\": [],\n \"inboundNatRules\": [],\n \"outboundRules\": []\n },\n \"sku\": {\n \"name\": \"Standard\",\n \"tier\": \"[parameters('tier')]\"\n }\n}\n
","tags":["Azure.LB.StandardSKU","AZR-000128"]},{"location":"en/rules/Azure.LB.StandardSKU/#configure-with-bicep","title":"Configure with Bicep","text":"To configure Standard SKU for a load balancer.
sku.name
to Standard
.For example:
Azure Bicep snippetresource lb_001 'Microsoft.Network/loadBalancers@2021-02-01' = {\n name: lbName\n location: location\n sku: {\n name: 'Standard'\n }\n properties: {\n frontendIPConfigurations: [\n {\n name: 'frontendIPConfig'\n properties: {\n privateIPAllocationMethod: 'Dynamic'\n subnet: {\n id: vnet.properties.subnets[1].id\n }\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n }\n ]\n }\n}\n
","tags":["Azure.LB.StandardSKU","AZR-000128"]},{"location":"en/rules/Azure.LB.StandardSKU/#links","title":"Links","text":"Security \u00b7 Logic App \u00b7 Rule \u00b7 2020_12 \u00b7 Critical
Limit HTTP request trigger access to trusted IP addresses.
","tags":["Azure.LogicApp.LimitHTTPTrigger","AZR-000130"]},{"location":"en/rules/Azure.LogicApp.LimitHTTPTrigger/#description","title":"Description","text":"When a Logic App uses a HTTP request trigger by default any source IP address can trigger the workflow. Logic Apps can be configured to limit the IP addresses that are accepted to trigger the workflow.
","tags":["Azure.LogicApp.LimitHTTPTrigger","AZR-000130"]},{"location":"en/rules/Azure.LogicApp.LimitHTTPTrigger/#recommendation","title":"Recommendation","text":"Consider limiting Logic Apps with HTTP request triggers to trusted IP addresses.
","tags":["Azure.LogicApp.LimitHTTPTrigger","AZR-000130"]},{"location":"en/rules/Azure.LogicApp.LimitHTTPTrigger/#links","title":"Links","text":"Cost Optimization \u00b7 Machine Learning \u00b7 Rule \u00b7 2023_12 \u00b7 Critical
Configure an idle shutdown timeout for Machine Learning compute instances.
","tags":["Azure.ML.ComputeIdleShutdown","AZR-000403"]},{"location":"en/rules/Azure.ML.ComputeIdleShutdown/#description","title":"Description","text":"Machine Learning uses compute instances as a training or inference compute for development and testing. It's similar to a virtual machine on the cloud.
To avoid getting charged for a compute instance that is switched on but not being actively used, you can configure when to automatically shutdown compute instances due to inactivity.
","tags":["Azure.ML.ComputeIdleShutdown","AZR-000403"]},{"location":"en/rules/Azure.ML.ComputeIdleShutdown/#recommendation","title":"Recommendation","text":"Consider configuring ML - Compute Instances to automatically shutdown after a period of inactivity to optimize compute costs.
","tags":["Azure.ML.ComputeIdleShutdown","AZR-000403"]},{"location":"en/rules/Azure.ML.ComputeIdleShutdown/#examples","title":"Examples","text":"","tags":["Azure.ML.ComputeIdleShutdown","AZR-000403"]},{"location":"en/rules/Azure.ML.ComputeIdleShutdown/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy compute instances that passes this rule:
properties.properties.idleTimeBeforeShutdown
property with a ISO 8601 formatted string. i.e. For an idle shutdown time of 15 minutes use PT15M
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.MachineLearningServices/workspaces/computes\",\n \"apiVersion\": \"2023-06-01-preview\",\n \"name\": \"[format('{0}/{1}', parameters('name'), parameters('name'))]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"computeType\": \"ComputeInstance\",\n \"disableLocalAuth\": true,\n \"properties\": {\n \"vmSize\": \"[parameters('vmSize')]\",\n \"idleTimeBeforeShutdown\": \"PT15M\"\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.MachineLearningServices/workspaces', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.ML.ComputeIdleShutdown","AZR-000403"]},{"location":"en/rules/Azure.ML.ComputeIdleShutdown/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy compute instances that passes this rule:
properties.properties.idleTimeBeforeShutdown
property with a ISO 8601 formatted string. i.e. For an idle shutdown time of 15 minutes use PT15M
.For example:
Azure Bicep snippetresource compute_instance 'Microsoft.MachineLearningServices/workspaces/computes@2023-06-01-preview' = {\n parent: workspace\n name: name\n location: location\n properties: {\n computeType: 'ComputeInstance'\n disableLocalAuth: true\n properties: {\n vmSize: vmSize\n idleTimeBeforeShutdown: 'PT15M'\n }\n }\n}\n
","tags":["Azure.ML.ComputeIdleShutdown","AZR-000403"]},{"location":"en/rules/Azure.ML.ComputeIdleShutdown/#links","title":"Links","text":"Security \u00b7 Machine Learning \u00b7 Rule \u00b7 2023_12 \u00b7 Critical
Azure Machine Learning Computes should be hosted in a virtual network (VNet).
","tags":["Azure.ML.ComputeVnet","AZR-000405"]},{"location":"en/rules/Azure.ML.ComputeVnet/#description","title":"Description","text":"When using Azure Machine Learning (ML), you can configure compute instances to be private or accessible from the public Internet. By default, the ML compute is configured to be accessible from the public Internet.
ML compute can be deployed into an virtual network (VNet) to provide private connectivity, enhanaced security, and isolation. Using a VNet reduces the attack surface for your solution, and the chances of data exfiltration. Additionally, network controls such as Network Security Groups (NSGs) can be used to further restrict access.
","tags":["Azure.ML.ComputeVnet","AZR-000405"]},{"location":"en/rules/Azure.ML.ComputeVnet/#recommendation","title":"Recommendation","text":"Consider using ML - compute hosted in a VNet to provide private connectivity, enhanaced security, and isolation.
","tags":["Azure.ML.ComputeVnet","AZR-000405"]},{"location":"en/rules/Azure.ML.ComputeVnet/#examples","title":"Examples","text":"","tags":["Azure.ML.ComputeVnet","AZR-000405"]},{"location":"en/rules/Azure.ML.ComputeVnet/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy an ML - compute that passes this rule:
properties.properties.subnet.id
property with a resource Id of a specific VNET subnet.For example:
Azure Template snippet{\n \"type\": \"Microsoft.MachineLearningServices/workspaces/computes\",\n \"apiVersion\": \"2023-06-01-preview\",\n \"name\": \"[format('{0}/{1}', parameters('name'), parameters('name'))]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"computeType\": \"ComputeInstance\",\n \"disableLocalAuth\": true,\n \"properties\": {\n \"vmSize\": \"[parameters('vmSize')]\",\n \"idleTimeBeforeShutdown\": \"PT15M\",\n \"subnet\": {\n \"id\": \"[resourceId('Microsoft.Network/virtualNetworks/subnets', split('vnet/subnet', '/')[0], split('vnet/subnet', '/')[1])]\"\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.MachineLearningServices/workspaces', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.ML.ComputeVnet","AZR-000405"]},{"location":"en/rules/Azure.ML.ComputeVnet/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy an ML - compute that passes this rule:
properties.properties.subnet.id
property with a resource Id of a specific VNET subnet.For example:
Azure Bicep snippetresource compute_instance 'Microsoft.MachineLearningServices/workspaces/computes@2023-06-01-preview' = {\n parent: workspace\n name: name\n location: location\n properties: {\n computeType: 'ComputeInstance'\n disableLocalAuth: true\n properties: {\n vmSize: vmSize\n idleTimeBeforeShutdown: 'PT15M'\n subnet: {\n id: subnet.id\n }\n }\n }\n}\n
","tags":["Azure.ML.ComputeVnet","AZR-000405"]},{"location":"en/rules/Azure.ML.ComputeVnet/#links","title":"Links","text":"Security \u00b7 Machine Learning \u00b7 Rule \u00b7 2023_12 \u00b7 Critical
Azure Machine Learning compute resources should have local authentication methods disabled.
","tags":["Azure.ML.DisableLocalAuth","AZR-000404"]},{"location":"en/rules/Azure.ML.DisableLocalAuth/#description","title":"Description","text":"Azure Machine Learning (ML) compute can have local authenication enabled or disabled. When enabled local authentication methods must be managed and audited separately.
Disabling local authentication ensures that Entra ID (previously Azure Active Directory) is used exclusively for authentication. Using Entra ID, provides consistency as a single authoritative source which:
Consider disabling local authentication on ML - Compute as part of a broader security strategy.
","tags":["Azure.ML.DisableLocalAuth","AZR-000404"]},{"location":"en/rules/Azure.ML.DisableLocalAuth/#examples","title":"Examples","text":"","tags":["Azure.ML.DisableLocalAuth","AZR-000404"]},{"location":"en/rules/Azure.ML.DisableLocalAuth/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy ML - compute that passes this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.MachineLearningServices/workspaces/computes\",\n \"apiVersion\": \"2023-06-01-preview\",\n \"name\": \"[format('{0}/{1}', parameters('name'), parameters('name'))]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"computeType\": \"ComputeInstance\",\n \"disableLocalAuth\": true,\n \"properties\": {\n \"vmSize\": \"[parameters('vmSize')]\",\n \"idleTimeBeforeShutdown\": \"PT15M\"\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.MachineLearningServices/workspaces', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.ML.DisableLocalAuth","AZR-000404"]},{"location":"en/rules/Azure.ML.DisableLocalAuth/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy ML - compute that passes this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Bicep snippetresource compute_instance 'Microsoft.MachineLearningServices/workspaces/computes@2023-06-01-preview' = {\n parent: workspace\n name: name\n location: location\n properties: {\n computeType: 'ComputeInstance'\n disableLocalAuth: true\n properties: {\n vmSize: vmSize\n idleTimeBeforeShutdown: 'PT15M'\n subnet: {\n id: subnet.id\n }\n }\n }\n}\n
","tags":["Azure.ML.DisableLocalAuth","AZR-000404"]},{"location":"en/rules/Azure.ML.DisableLocalAuth/#links","title":"Links","text":"Security \u00b7 Machine Learning \u00b7 Rule \u00b7 2023_12 \u00b7 Critical
Disable public network access from a Azure Machine Learning workspace.
","tags":["Azure.ML.PublicAccess","AZR-000406"]},{"location":"en/rules/Azure.ML.PublicAccess/#description","title":"Description","text":"Disabling public network access improves security by ensuring that the Machine Learning Workspaces aren't exposed on the public internet. You can control exposure of your workspaces by creating private endpoints instead. By default, a public endpoint is enabled for Machine Learning workspaces. The public endpoint is used for all access except for requests that use a Private Endpoint. Access through the public endpoint can be disabled or restricted to authorized virtual networks.
Data exfiltration is an attack where an malicious actor does an unauthorized data transfer. Private Endpoints help control exposure of a workspace to data exfiltration by an internal or external malicious actor. They do this by providing clear separation between public and private endpoints. As a result, broad access to public endpoints which could be operated by a malicious actor are not required.
","tags":["Azure.ML.PublicAccess","AZR-000406"]},{"location":"en/rules/Azure.ML.PublicAccess/#recommendation","title":"Recommendation","text":"Consider disabling access from public endpoints by setting the publicNetworkAccess
property to Disabled
as part of a broader security strategy.
To deploy an ML - Workspace that passes this rule:
properties.publicNetworkAccess
property to Disabled
.properties.allowPublicAccessWhenBehindVnet
property is defined remove the property. Switch to using the properties.publicNetworkAccess
property instead. Configuring both properties is not required.For example:
Azure Template snippet{\n \"type\": \"Microsoft.MachineLearningServices/workspaces\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"basic\",\n \"tier\": \"basic\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"friendlyName\": \"[parameters('name')]\",\n \"keyVault\": \"[resourceId('Microsoft.KeyVault/vaults', parameters('KeyVaultName'))]\",\n \"storageAccount\": \"[resourceId('Microsoft.Storage/storageAccounts', parameters('StorageAccountName'))]\",\n \"applicationInsights\": \"[resourceId('Microsoft.Insights/components', parameters('AppInsightsName'))]\",\n \"containerRegistry\": \"[resourceId('Microsoft.ContainerRegistry/registries', parameters('ContainerRegistryName'))]\",\n \"publicNetworkAccess\": \"Disabled\"\n }\n}\n
","tags":["Azure.ML.PublicAccess","AZR-000406"]},{"location":"en/rules/Azure.ML.PublicAccess/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy an ML - Workspace that passes this rule:
properties.publicNetworkAccess
property to Disabled
.properties.allowPublicAccessWhenBehindVnet
property is defined remove the property. Switch to using the properties.publicNetworkAccess
property instead. Configuring both properties is not required.For example:
Azure Bicep snippetresource workspace 'Microsoft.MachineLearningServices/workspaces@2023-04-01' = {\n name: name\n location: location\n sku: {\n name: 'basic'\n tier: 'basic'\n }\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n friendlyName: friendlyName\n keyVault: keyVault.id\n storageAccount: storageAccount.id\n applicationInsights: appInsights.id\n containerRegistry: containerRegistry.id\n publicNetworkAccess: 'Disabled'\n primaryUserAssignedIdentity: identity.id\n }\n}\n
","tags":["Azure.ML.PublicAccess","AZR-000406"]},{"location":"en/rules/Azure.ML.PublicAccess/#links","title":"Links","text":"Security \u00b7 Machine Learning \u00b7 Rule \u00b7 2023_12 \u00b7 Important
ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity.
","tags":["Azure.ML.UserManagedIdentity","AZR-000407"]},{"location":"en/rules/Azure.ML.UserManagedIdentity/#description","title":"Description","text":"Manange access to Azure ML workspace and associated resources, Azure Container Registry, KeyVault, Storage, and App Insights using user-assigned managed identity. By default, system-assigned managed identity is used by Azure ML workspace to access the associated resources. User-assigned managed identity allows you to create the identity as an Azure resource and maintain the life cycle of that identity.
","tags":["Azure.ML.UserManagedIdentity","AZR-000407"]},{"location":"en/rules/Azure.ML.UserManagedIdentity/#recommendation","title":"Recommendation","text":"Consider using a User-Assigned Managed Identity, as part of a broader security and lifecycle management strategy.
","tags":["Azure.ML.UserManagedIdentity","AZR-000407"]},{"location":"en/rules/Azure.ML.UserManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.ML.UserManagedIdentity","AZR-000407"]},{"location":"en/rules/Azure.ML.UserManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy an ML - Workspace that passes this rule:
identity.type
property to UserAssigned
.identity.userAssignedIdentities
.properties.primaryUserAssignedIdentity
property value to the User-Assigned Managed Identity.For example:
Azure Template snippet{\n \"type\": \"Microsoft.MachineLearningServices/workspaces\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"basic\",\n \"tier\": \"basic\"\n },\n \"identity\": {\n \"type\": \"UserAssigned\",\n \"userAssignedIdentities\": {\n \"[format('{0}', resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', 'example'))]\": {}\n }\n },\n \"properties\": {\n \"friendlyName\": \"[parameters('friendlyName')]\",\n \"keyVault\": \"[resourceId('Microsoft.KeyVault/vaults', 'example')]\",\n \"storageAccount\": \"[resourceId('Microsoft.Storage/storageAccounts', 'example')]\",\n \"applicationInsights\": \"[resourceId('Microsoft.Insights/components', 'example')]\",\n \"containerRegistry\": \"[resourceId('Microsoft.ContainerRegistry/registries', 'example')]\",\n \"publicNetworkAccess\": \"Disabled\",\n \"primaryUserAssignedIdentity\": \"[resourceId('Microsoft.ManagedIdentity/userAssignedIdentities', 'example')]\"\n }\n}\n
","tags":["Azure.ML.UserManagedIdentity","AZR-000407"]},{"location":"en/rules/Azure.ML.UserManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy an ML - Workspace that passes this rule:
identity.type
property to UserAssigned
.identity.userAssignedIdentities
.properties.primaryUserAssignedIdentity
property value to the User-Assigned Managed Identity.For example:
Azure Bicep snippetresource workspace 'Microsoft.MachineLearningServices/workspaces@2023-04-01' = {\n name: name\n location: location\n sku: {\n name: 'basic'\n tier: 'basic'\n }\n identity: {\n type: 'UserAssigned'\n userAssignedIdentities: {\n '${identity.id}': {}\n }\n }\n properties: {\n friendlyName: friendlyName\n keyVault: keyVault.id\n storageAccount: storageAccount.id\n applicationInsights: appInsights.id\n containerRegistry: containerRegistry.id\n publicNetworkAccess: 'Disabled'\n primaryUserAssignedIdentity: identity.id\n }\n}\n
","tags":["Azure.ML.UserManagedIdentity","AZR-000407"]},{"location":"en/rules/Azure.ML.UserManagedIdentity/#links","title":"Links","text":"Security \u00b7 Azure Database for MariaDB \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Determine if access from Azure services is required.
","tags":["Azure.MariaDB.AllowAzureAccess","AZR-000342"]},{"location":"en/rules/Azure.MariaDB.AllowAzureAccess/#description","title":"Description","text":"Allow access to Azure services, permits any Azure service including other Azure customers, network based-access to databases on the same Azure Database for MariaDB server instance. If network based access is permitted, authentication is still required.
Enabling access from Azure services is useful in certain cases where fixed outgoing IP addresses isn't available for the services.
","tags":["Azure.MariaDB.AllowAzureAccess","AZR-000342"]},{"location":"en/rules/Azure.MariaDB.AllowAzureAccess/#recommendation","title":"Recommendation","text":"Where fixed outgoing IP addresses are available for the Azure services, configure IP or virtual network based firewall rules instead of using Allow access to Azure services.
Determine if access from Azure services is required for the services connecting to the hosted databases.
","tags":["Azure.MariaDB.AllowAzureAccess","AZR-000342"]},{"location":"en/rules/Azure.MariaDB.AllowAzureAccess/#examples","title":"Examples","text":"","tags":["Azure.MariaDB.AllowAzureAccess","AZR-000342"]},{"location":"en/rules/Azure.MariaDB.AllowAzureAccess/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for MariaDB Servers that pass this rule:
Microsoft.DBforMariaDB servers/firewallRules
sub-resource (child resource).properties.startIpAddress
and properties.endIpAddress
property to a valid IPv4 address format.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMariaDB/servers\",\n \"apiVersion\": \"2018-06-01\",\n \"name\": \"[parameters('serverName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('skuName')]\",\n \"tier\": \"[parameters('skuTier')]\",\n \"capacity\": \"[parameters('skuCapacity')]\",\n \"size\": \"[format('{0}', parameters('skuSizeMB'))]\",\n \"family\": \"[parameters('skuFamily')]\"\n },\n \"properties\": {\n \"createMode\": \"Default\",\n \"version\": \"[parameters('mariadbVersion')]\",\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"storageProfile\": {\n \"storageMB\": \"[parameters('skuSizeMB')]\",\n \"backupRetentionDays\": \"[parameters('backupRetentionDays')]\",\n \"geoRedundantBackup\": \"[parameters('geoRedundantBackup')]\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.DBforMariaDB/servers/firewallRules\",\n \"apiVersion\": \"2018-06-01\",\n \"name\": \"MariaDbServer001/FunctionApp\",\n \"properties\": {\n \"startIpAddress\": \"20.67.176.40\",\n \"endIpAddress\": \"20.67.176.40\"\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.DBforMariaDB/servers', parameters('serverName'))]\"\n ]\n }\n ]\n}\n
","tags":["Azure.MariaDB.AllowAzureAccess","AZR-000342"]},{"location":"en/rules/Azure.MariaDB.AllowAzureAccess/#configure-with-bicep","title":"Configure with Bicep","text":"Microsoft.DBforMariaDB servers/firewallRules
sub-resource (child resource).properties.startIpAddress
and properties.endIpAddress
property to a valid IPv4 address format.For example:
Azure Bicep snippetresource mariaDbServer 'Microsoft.DBforMariaDB/servers@2018-06-01' = {\n name: serverName\n location: location\n sku: {\n name: skuName\n tier: skuTier\n capacity: skuCapacity\n size: '${skuSizeMB}' \n family: skuFamily\n }\n properties: {\n createMode: 'Default'\n version: mariadbVersion\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n storageProfile: {\n storageMB: skuSizeMB\n backupRetentionDays: backupRetentionDays\n geoRedundantBackup: geoRedundantBackup\n }\n }\n}\n\nresource mariaDbServerFirewallRule 'Microsoft.DBforMariaDB/servers/firewallRules@2018-06-01' = {\n name: 'MariaDbServer001/FunctionApp'\n parent: mariaDbServer\n properties: {\n startIpAddress: '20.67.176.40'\n endIpAddress: '20.67.176.40'\n }\n}\n
","tags":["Azure.MariaDB.AllowAzureAccess","AZR-000342"]},{"location":"en/rules/Azure.MariaDB.AllowAzureAccess/#links","title":"Links","text":"Operational Excellence \u00b7 Azure Database for MariaDB \u00b7 Rule \u00b7 2022_12 \u00b7 Awareness
Azure Database for MariaDB databases should meet naming requirements.
","tags":["Azure.MariaDB.DatabaseName","AZR-000337"]},{"location":"en/rules/Azure.MariaDB.DatabaseName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Azure Database for MariaDB database names are:
Consider using names that meet Azure Database for MariaDB database naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.MariaDB.DatabaseName","AZR-000337"]},{"location":"en/rules/Azure.MariaDB.DatabaseName/#notes","title":"Notes","text":"This rule does not check if Azure Database for MariaDB database names are unique.
","tags":["Azure.MariaDB.DatabaseName","AZR-000337"]},{"location":"en/rules/Azure.MariaDB.DatabaseName/#links","title":"Links","text":"Security \u00b7 Azure Database for MariaDB \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Enable Microsoft Defender for Cloud for Azure Database for MariaDB.
","tags":["Azure.MariaDB.DefenderCloud","AZR-000330"]},{"location":"en/rules/Azure.MariaDB.DefenderCloud/#description","title":"Description","text":"Defender for Cloud detects anomalous activities indicating unusual and potentially harmful attempts to access or exploit databases.
","tags":["Azure.MariaDB.DefenderCloud","AZR-000330"]},{"location":"en/rules/Azure.MariaDB.DefenderCloud/#recommendation","title":"Recommendation","text":"Enable Microsoft Defender for Cloud for Azure Database for MariaDB.
","tags":["Azure.MariaDB.DefenderCloud","AZR-000330"]},{"location":"en/rules/Azure.MariaDB.DefenderCloud/#examples","title":"Examples","text":"","tags":["Azure.MariaDB.DefenderCloud","AZR-000330"]},{"location":"en/rules/Azure.MariaDB.DefenderCloud/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for MariaDB Servers that pass this rule:
Microsoft.DBforMariaDB/servers/securityAlertPolicies
sub-resource (child resource).properties.state
property to Enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMariaDB/servers\",\n \"apiVersion\": \"2018-06-01\",\n \"name\": \"[parameters('serverName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('skuName')]\",\n \"tier\": \"GeneralPurpose\",\n \"capacity\": \"[parameters('SkuCapacity')]\",\n \"size\": \"[format('{0}', parameters('skuSizeMB'))]\",\n \"family\": \"[parameters('skuFamily')]\"\n },\n \"properties\": {\n \"createMode\": \"Default\",\n \"version\": \"[parameters('mariadbVersion')]\",\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"storageProfile\": {\n \"storageMB\": \"[parameters('skuSizeMB')]\",\n \"backupRetentionDays\": 7,\n \"geoRedundantBackup\": \"Enabled\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.DBforMariaDB/servers/securityAlertPolicies\",\n \"apiVersion\": \"2018-06-01\",\n \"name\": \"Default\",\n \"dependsOn\": [\"[parameters('serverName')]\"],\n \"properties\": {\n \"emailAccountAdmins\": true,\n \"emailAddresses\": [\"soc@contoso.com\"],\n \"retentionDays\": 14,\n \"state\": \"Enabled\",\n \"storageAccountAccessKey\": \"account-key\",\n \"storageEndpoint\": \"https://contoso.blob.core.windows.net\"\n }\n }\n ]\n}\n
","tags":["Azure.MariaDB.DefenderCloud","AZR-000330"]},{"location":"en/rules/Azure.MariaDB.DefenderCloud/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for MariaDB Servers that pass this rule:
Microsoft.DBforMariaDB/servers/securityAlertPolicies
sub-resource (child resource).properties.state
property to Enabled
.For example:
Azure Bicep snippetresource mariaDbServer 'Microsoft.DBforMariaDB/servers@2018-06-01' = {\n name: serverName\n location: location\n sku: {\n name: skuName\n tier: 'GeneralPurpose'\n capacity: skuCapacity\n size: '${skuSizeMB}' \n family: skuFamily\n }\n properties: {\n createMode: 'Default'\n version: mariadbVersion\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n storageProfile: {\n storageMB: skuSizeMB\n backupRetentionDays: 7\n geoRedundantBackup: 'Enabled'\n }\n }\n}\n\nresource mariaDbDefender 'Microsoft.DBforMariaDB/servers/securityAlertPolicies@2018-06-01' = {\n name: 'Default'\n parent: MariaDbServer\n properties: {\n emailAccountAdmins: true\n emailAddresses: ['soc@contoso.com']\n retentionDays: 14\n state: 'Enabled'\n storageAccountAccessKey: 'account-key'\n storageEndpoint: 'https://contoso.blob.core.windows.net'\n }\n}\n
","tags":["Azure.MariaDB.DefenderCloud","AZR-000330"]},{"location":"en/rules/Azure.MariaDB.DefenderCloud/#links","title":"Links","text":"Security \u00b7 Azure Database for MariaDB \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Determine if there is an excessive number of permitted IP addresses.
","tags":["Azure.MariaDB.FirewallIPRange","AZR-000344"]},{"location":"en/rules/Azure.MariaDB.FirewallIPRange/#description","title":"Description","text":"Typically the number of IP address rules permitted through the firewall is minimal, with management connectivity from on-premises and cloud application connectivity.
Server-level firewall permitted IP addresses apply to all databases on the Azure Database for MariaDB server.
","tags":["Azure.MariaDB.FirewallIPRange","AZR-000344"]},{"location":"en/rules/Azure.MariaDB.FirewallIPRange/#recommendation","title":"Recommendation","text":"Review the number of Azure for MariaDB server firewall permitted public IP addresses configured. Consider to removing IP addresses that are no longer needed.
","tags":["Azure.MariaDB.FirewallIPRange","AZR-000344"]},{"location":"en/rules/Azure.MariaDB.FirewallIPRange/#notes","title":"Notes","text":"This rule fails when the number of configured public IP addresses exceeds ten (10).
","tags":["Azure.MariaDB.FirewallIPRange","AZR-000344"]},{"location":"en/rules/Azure.MariaDB.FirewallIPRange/#links","title":"Links","text":"Security \u00b7 Azure Database for MariaDB \u00b7 Rule \u00b7 2022_12 \u00b7 Awareness
Determine if there is an excessive number of firewall rules.
","tags":["Azure.MariaDB.FirewallRuleCount","AZR-000343"]},{"location":"en/rules/Azure.MariaDB.FirewallRuleCount/#description","title":"Description","text":"Typically the number of firewall rules required is minimal, with management connectivity from on-premises and cloud application connectivity.
Server-level firewall rules apply to all databases on the Azure Database for MariaDB server.
","tags":["Azure.MariaDB.FirewallRuleCount","AZR-000343"]},{"location":"en/rules/Azure.MariaDB.FirewallRuleCount/#recommendation","title":"Recommendation","text":"Review the number of Azure for MariaDB server firewall rules configured. Consider to removing rules that are no longer needed.
","tags":["Azure.MariaDB.FirewallRuleCount","AZR-000343"]},{"location":"en/rules/Azure.MariaDB.FirewallRuleCount/#notes","title":"Notes","text":"This rule fails when the number of configured firewall rules exceeds ten (10).
","tags":["Azure.MariaDB.FirewallRuleCount","AZR-000343"]},{"location":"en/rules/Azure.MariaDB.FirewallRuleCount/#links","title":"Links","text":"Operational Excellence \u00b7 Azure Database for MariaDB \u00b7 Rule \u00b7 2022_12 \u00b7 Awareness
Azure Database for MariaDB firewall rules should meet naming requirements.
","tags":["Azure.MariaDB.FirewallRuleName","AZR-000338"]},{"location":"en/rules/Azure.MariaDB.FirewallRuleName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Azure Database for MariaDB firewall rule names are:
Consider using names that meet Azure Database for MariaDB firewall rule naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.MariaDB.FirewallRuleName","AZR-000338"]},{"location":"en/rules/Azure.MariaDB.FirewallRuleName/#notes","title":"Notes","text":"This rule does not check if Azure Database for MariaDB firewall rule names are unique.
","tags":["Azure.MariaDB.FirewallRuleName","AZR-000338"]},{"location":"en/rules/Azure.MariaDB.FirewallRuleName/#links","title":"Links","text":"Reliability \u00b7 Azure Database for MariaDB \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Azure Database for MariaDB should store backups in a geo-redundant storage.
","tags":["Azure.MariaDB.GeoRedundantBackup","AZR-000329"]},{"location":"en/rules/Azure.MariaDB.GeoRedundantBackup/#description","title":"Description","text":"Geo-redundant backup helps to protect your Azure Database for MariaDB Servers against outages impacting backup storage in the primary region and allows you to restore your server to the geo-paired region in the event of a disaster.
When the backups are stored in geo-redundant backup storage, they are not only stored within the region in which your server is hosted, but are also replicated to a paired data center.
Check out the NOTES
and the LINKS
section for more details about geo-redundant backup.
Configure geo-redundant backup for Azure Database for MariaDB.
","tags":["Azure.MariaDB.GeoRedundantBackup","AZR-000329"]},{"location":"en/rules/Azure.MariaDB.GeoRedundantBackup/#examples","title":"Examples","text":"","tags":["Azure.MariaDB.GeoRedundantBackup","AZR-000329"]},{"location":"en/rules/Azure.MariaDB.GeoRedundantBackup/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for MariaDB Servers that pass this rule:
properties.storageProfile.geoRedundantBackup
property to Enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMariaDB/servers\",\n \"apiVersion\": \"2018-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('sku')]\",\n \"tier\": \"GeneralPurpose\",\n \"capacity\": \"[parameters('skuCapacity')]\",\n \"size\": \"[format('{0}', parameters('skuSizeMB'))]\",\n \"family\": \"Gen5\"\n },\n \"properties\": {\n \"sslEnforcement\": \"Enabled\",\n \"minimalTlsVersion\": \"TLS1_2\",\n \"createMode\": \"Default\",\n \"version\": \"10.3\",\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"publicNetworkAccess\": \"Disabled\",\n \"storageProfile\": {\n \"storageMB\": \"[parameters('skuSizeMB')]\",\n \"backupRetentionDays\": 7,\n \"geoRedundantBackup\": \"Enabled\"\n }\n }\n}\n
","tags":["Azure.MariaDB.GeoRedundantBackup","AZR-000329"]},{"location":"en/rules/Azure.MariaDB.GeoRedundantBackup/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for MariaDB Servers that pass this rule:
properties.storageProfile.geoRedundantBackup
property to Enabled
.For example:
Azure Bicep snippetresource server 'Microsoft.DBforMariaDB/servers@2018-06-01' = {\n name: name\n location: location\n sku: {\n name: sku\n tier: 'GeneralPurpose'\n capacity: skuCapacity\n size: '${skuSizeMB}'\n family: 'Gen5'\n }\n properties: {\n sslEnforcement: 'Enabled'\n minimalTlsVersion: 'TLS1_2'\n createMode: 'Default'\n version: '10.3'\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n publicNetworkAccess: 'Disabled'\n storageProfile: {\n storageMB: skuSizeMB\n backupRetentionDays: 7\n geoRedundantBackup: 'Enabled'\n }\n }\n}\n
","tags":["Azure.MariaDB.GeoRedundantBackup","AZR-000329"]},{"location":"en/rules/Azure.MariaDB.GeoRedundantBackup/#notes","title":"Notes","text":"This rule is only applicable for Azure Database for Maria DB Servers with General Purpose
and Memory Optimized
tiers. The Basic
tier does not support geo-redundant backup storage.
Security \u00b7 Azure Database for MariaDB \u00b7 Rule \u00b7 2022_12 \u00b7 Critical
Azure Database for MariaDB servers should reject TLS versions older than 1.2.
","tags":["Azure.MariaDB.MinTLS","AZR-000335"]},{"location":"en/rules/Azure.MariaDB.MinTLS/#description","title":"Description","text":"The minimum version of TLS that Azure Database for MariaDB servers accept is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Azure lets you disable outdated protocols and require connections to use a minimum of TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 is accepted.
","tags":["Azure.MariaDB.MinTLS","AZR-000335"]},{"location":"en/rules/Azure.MariaDB.MinTLS/#recommendation","title":"Recommendation","text":"Configure the minimum supported TLS version to be 1.2.
","tags":["Azure.MariaDB.MinTLS","AZR-000335"]},{"location":"en/rules/Azure.MariaDB.MinTLS/#examples","title":"Examples","text":"","tags":["Azure.MariaDB.MinTLS","AZR-000335"]},{"location":"en/rules/Azure.MariaDB.MinTLS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for MariaDB Servers that pass this rule:
properties.minimalTlsVersion
property to TLS1_2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMariaDB/servers\",\n \"apiVersion\": \"2018-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('sku')]\",\n \"tier\": \"GeneralPurpose\",\n \"capacity\": \"[parameters('skuCapacity')]\",\n \"size\": \"[format('{0}', parameters('skuSizeMB'))]\",\n \"family\": \"Gen5\"\n },\n \"properties\": {\n \"sslEnforcement\": \"Enabled\",\n \"minimalTlsVersion\": \"TLS1_2\",\n \"createMode\": \"Default\",\n \"version\": \"10.3\",\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"publicNetworkAccess\": \"Disabled\",\n \"storageProfile\": {\n \"storageMB\": \"[parameters('skuSizeMB')]\",\n \"backupRetentionDays\": 7,\n \"geoRedundantBackup\": \"Enabled\"\n }\n }\n}\n
","tags":["Azure.MariaDB.MinTLS","AZR-000335"]},{"location":"en/rules/Azure.MariaDB.MinTLS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for MariaDB Servers that pass this rule:
properties.minimalTlsVersion
property to TLS1_2
.For example:
Azure Bicep snippetresource server 'Microsoft.DBforMariaDB/servers@2018-06-01' = {\n name: name\n location: location\n sku: {\n name: sku\n tier: 'GeneralPurpose'\n capacity: skuCapacity\n size: '${skuSizeMB}'\n family: 'Gen5'\n }\n properties: {\n sslEnforcement: 'Enabled'\n minimalTlsVersion: 'TLS1_2'\n createMode: 'Default'\n version: '10.3'\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n publicNetworkAccess: 'Disabled'\n storageProfile: {\n storageMB: skuSizeMB\n backupRetentionDays: 7\n geoRedundantBackup: 'Enabled'\n }\n }\n}\n
","tags":["Azure.MariaDB.MinTLS","AZR-000335"]},{"location":"en/rules/Azure.MariaDB.MinTLS/#links","title":"Links","text":"Operational Excellence \u00b7 Azure Database for MariaDB \u00b7 Rule \u00b7 2022_12 \u00b7 Awareness
Azure Database for MariaDB servers should meet naming requirements.
","tags":["Azure.MariaDB.ServerName","AZR-000336"]},{"location":"en/rules/Azure.MariaDB.ServerName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Azure Database for MariaDB server names are:
Consider using names that meet Azure Database for MariaDB server naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.MariaDB.ServerName","AZR-000336"]},{"location":"en/rules/Azure.MariaDB.ServerName/#examples","title":"Examples","text":"","tags":["Azure.MariaDB.ServerName","AZR-000336"]},{"location":"en/rules/Azure.MariaDB.ServerName/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy servers that pass this rule:
name
property to align to resource naming requirements.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMariaDB/servers\",\n \"apiVersion\": \"2018-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('sku')]\",\n \"tier\": \"GeneralPurpose\",\n \"capacity\": \"[parameters('skuCapacity')]\",\n \"size\": \"[format('{0}', parameters('skuSizeMB'))]\",\n \"family\": \"Gen5\"\n },\n \"properties\": {\n \"sslEnforcement\": \"Enabled\",\n \"minimalTlsVersion\": \"TLS1_2\",\n \"createMode\": \"Default\",\n \"version\": \"10.3\",\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"publicNetworkAccess\": \"Disabled\",\n \"storageProfile\": {\n \"storageMB\": \"[parameters('skuSizeMB')]\",\n \"backupRetentionDays\": 7,\n \"geoRedundantBackup\": \"Enabled\"\n }\n }\n}\n
","tags":["Azure.MariaDB.ServerName","AZR-000336"]},{"location":"en/rules/Azure.MariaDB.ServerName/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy servers that pass this rule:
name
property to align to resource naming requirements.For example:
Azure Bicep snippetresource server 'Microsoft.DBforMariaDB/servers@2018-06-01' = {\n name: name\n location: location\n sku: {\n name: sku\n tier: 'GeneralPurpose'\n capacity: skuCapacity\n size: '${skuSizeMB}'\n family: 'Gen5'\n }\n properties: {\n sslEnforcement: 'Enabled'\n minimalTlsVersion: 'TLS1_2'\n createMode: 'Default'\n version: '10.3'\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n publicNetworkAccess: 'Disabled'\n storageProfile: {\n storageMB: skuSizeMB\n backupRetentionDays: 7\n geoRedundantBackup: 'Enabled'\n }\n }\n}\n
","tags":["Azure.MariaDB.ServerName","AZR-000336"]},{"location":"en/rules/Azure.MariaDB.ServerName/#notes","title":"Notes","text":"This rule does not check if Azure Database for MariaDB server names are unique.
","tags":["Azure.MariaDB.ServerName","AZR-000336"]},{"location":"en/rules/Azure.MariaDB.ServerName/#links","title":"Links","text":"Security \u00b7 Azure Database for MariaDB \u00b7 Rule \u00b7 2022_12 \u00b7 Critical
Azure Database for MariaDB servers should only accept encrypted connections.
","tags":["Azure.MariaDB.UseSSL","AZR-000334"]},{"location":"en/rules/Azure.MariaDB.UseSSL/#description","title":"Description","text":"Azure Database for MariaDB is configured to only accept encrypted connections by default. When the setting enforce SSL connections is disabled, encrypted and unencrypted connections are permitted. This does not indicate that unencrypted connections are being used.
Unencrypted communication to MariaDB server instances could allow disclosure of information to an untrusted party.
","tags":["Azure.MariaDB.UseSSL","AZR-000334"]},{"location":"en/rules/Azure.MariaDB.UseSSL/#recommendation","title":"Recommendation","text":"Azure Database for MariaDB should be configured to only accept encrypted connections. Unless explicitly required, consider enabling enforce SSL connections.
Also consider using Azure Policy to audit or enforce this configuration.
","tags":["Azure.MariaDB.UseSSL","AZR-000334"]},{"location":"en/rules/Azure.MariaDB.UseSSL/#examples","title":"Examples","text":"","tags":["Azure.MariaDB.UseSSL","AZR-000334"]},{"location":"en/rules/Azure.MariaDB.UseSSL/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for MariaDB Servers that pass this rule:
properties.sslEnforcement
property to Enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMariaDB/servers\",\n \"apiVersion\": \"2018-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('sku')]\",\n \"tier\": \"GeneralPurpose\",\n \"capacity\": \"[parameters('skuCapacity')]\",\n \"size\": \"[format('{0}', parameters('skuSizeMB'))]\",\n \"family\": \"Gen5\"\n },\n \"properties\": {\n \"sslEnforcement\": \"Enabled\",\n \"minimalTlsVersion\": \"TLS1_2\",\n \"createMode\": \"Default\",\n \"version\": \"10.3\",\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"publicNetworkAccess\": \"Disabled\",\n \"storageProfile\": {\n \"storageMB\": \"[parameters('skuSizeMB')]\",\n \"backupRetentionDays\": 7,\n \"geoRedundantBackup\": \"Enabled\"\n }\n }\n}\n
","tags":["Azure.MariaDB.UseSSL","AZR-000334"]},{"location":"en/rules/Azure.MariaDB.UseSSL/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for MariaDB Servers that pass this rule:
properties.sslEnforcement
property to Enabled
.For example:
Azure Bicep snippetresource server 'Microsoft.DBforMariaDB/servers@2018-06-01' = {\n name: name\n location: location\n sku: {\n name: sku\n tier: 'GeneralPurpose'\n capacity: skuCapacity\n size: '${skuSizeMB}'\n family: 'Gen5'\n }\n properties: {\n sslEnforcement: 'Enabled'\n minimalTlsVersion: 'TLS1_2'\n createMode: 'Default'\n version: '10.3'\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n publicNetworkAccess: 'Disabled'\n storageProfile: {\n storageMB: skuSizeMB\n backupRetentionDays: 7\n geoRedundantBackup: 'Enabled'\n }\n }\n}\n
","tags":["Azure.MariaDB.UseSSL","AZR-000334"]},{"location":"en/rules/Azure.MariaDB.UseSSL/#links","title":"Links","text":"Operational Excellence \u00b7 Azure Database for MariaDB \u00b7 Rule \u00b7 2022_12 \u00b7 Awareness
Azure Database for MariaDB VNET rules should meet naming requirements.
","tags":["Azure.MariaDB.VNETRuleName","AZR-000339"]},{"location":"en/rules/Azure.MariaDB.VNETRuleName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Azure Database for MariaDB VNET rule names are:
Consider using names that meet Azure Database for MariaDB VNET rule naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.MariaDB.VNETRuleName","AZR-000339"]},{"location":"en/rules/Azure.MariaDB.VNETRuleName/#notes","title":"Notes","text":"This rule does not check if Azure Database for MariaDB VNET rule names are unique.
","tags":["Azure.MariaDB.VNETRuleName","AZR-000339"]},{"location":"en/rules/Azure.MariaDB.VNETRuleName/#links","title":"Links","text":"Operational Excellence \u00b7 Monitor \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Configure Service Health alerts to notify administrators.
","tags":["Azure.Monitor.ServiceHealth","AZR-000211"]},{"location":"en/rules/Azure.Monitor.ServiceHealth/#description","title":"Description","text":"Azure provides events and can alert administrators when one of the following occurs in your subscriptions:
Consider configuring an alert to notify administrators when services you are using are potentially impacted.
","tags":["Azure.Monitor.ServiceHealth","AZR-000211"]},{"location":"en/rules/Azure.Monitor.ServiceHealth/#links","title":"Links","text":"Security \u00b7 Azure Database for MySQL \u00b7 Rule \u00b7 2023_06 \u00b7 Critical
Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases.
","tags":["Azure.MySQL.AAD","AZR-000392"]},{"location":"en/rules/Azure.MySQL.AAD/#description","title":"Description","text":"Azure Database for MySQL offer two authentication models, Azure Active Directory (AAD) and MySQL logins. AAD authentication supports centialized identity management in addition to modern password protections. Some of the benefits of AAD authentication over MySQL authentication including:
It is also possible to disable MySQL authentication entirely for the flexible server deployment model.
","tags":["Azure.MySQL.AAD","AZR-000392"]},{"location":"en/rules/Azure.MySQL.AAD/#recommendation","title":"Recommendation","text":"Consider using Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Additionally, consider disabling MySQL authentication.
","tags":["Azure.MySQL.AAD","AZR-000392"]},{"location":"en/rules/Azure.MySQL.AAD/#examples","title":"Examples","text":"","tags":["Azure.MySQL.AAD","AZR-000392"]},{"location":"en/rules/Azure.MySQL.AAD/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for MySQL flexible servers that pass this rule:
Microsoft.DBforMySQL/flexibleServers/administrators
sub-resource.properties.administratorType
to ActiveDirectory
.properties.identityResourceId
to the resource ID of the user-assigned identity used for AAD authentication.properties.login
to the AAD administrator login object name.properties.sid
to the object ID GUID of the AAD administrator user, group, or application.properties.tenantId
to the tenant ID of the AAD administrator user, group, or application.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMySQL/flexibleServers/administrators\",\n \"apiVersion\": \"2022-12-01-preview\",\n \"name\": \"[format('{0}/{1}', parameters('serverName'), 'activeDirectory')]\",\n \"properties\": {\n \"administratorType\": \"ActiveDirectory\",\n \"identityResourceId\": \"[parameters('identityResourceId')]\",\n \"login\": \"[parameters('login')]\",\n \"sid\": \"[parameters('sid')]\",\n \"tenantId\": \"[parameters('tenantId')]\"\n\n },\n \"dependsOn\": [\n \"mySqlFlexibleServer\"\n ]\n}\n
To deploy Azure Database for MySQL single servers that pass this rule:
Microsoft.DBforMySQL/servers/administrators
sub-resource.properties.administratorType
to ActiveDirectory
.properties.login
to the AAD administrator login object name.properties.sid
to the object ID GUID of the AAD administrator user, group, or application.properties.tenantId
to the tenant ID of the AAD administrator user, group, or application.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMySQL/servers/administrators\",\n \"apiVersion\": \"2017-12-01\",\n \"name\": \"[format('{0}/{1}', parameters('serverName'), 'activeDirectory')]\",\n \"properties\": {\n \"administratorType\": \"ActiveDirectory\",\n \"login\": \"[parameters('login')]\",\n \"sid\": \"[parameters('sid')]\",\n \"tenantId\": \"[parameters('tenantId')]\"\n },\n \"dependsOn\": [\n \"mySqlSingleServer\"\n ]\n}\n
","tags":["Azure.MySQL.AAD","AZR-000392"]},{"location":"en/rules/Azure.MySQL.AAD/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for MySQL flexible servers that pass this rule:
Microsoft.DBforMySQL/flexibleServers/administrators
sub-resource.properties.administratorType
to ActiveDirectory
.properties.identityResourceId
to the resource ID of the user-assigned identity used for AAD authentication.properties.login
to the AAD administrator login object name.properties.sid
to the object ID GUID of the AAD administrator user, group, or application.properties.tenantId
to the tenant ID of the AAD administrator user, group, or application.For example:
Azure Bicep snippetresource aadAdmin 'Microsoft.DBforMySQL/flexibleServers/administrators@2021-12-01-preview' = {\n name: 'activeDirectory'\n parent: mySqlFlexibleServer\n properties: {\n administratorType: 'ActiveDirectory'\n identityResourceId: identityResourceId\n login: login\n sid: sid\n tenantId: tenantId\n }\n}\n
To deploy Azure Database for MySQL single servers that pass this rule:
Microsoft.DBforMySQL/servers/administrators
sub-resource.properties.administratorType
to ActiveDirectory
.properties.login
to the AAD administrator login object name.properties.sid
to the object ID GUID of the AAD administrator user, group, or application.properties.tenantId
to the tenant ID of the AAD administrator user, group, or application.For example:
Azure Bicep snippetresource aadAdmin 'Microsoft.DBforMySQL/servers/administrators@2017-12-01' = {\n name: 'activeDirectory'\n parent: mySqlSingleServer\n properties: {\n administratorType: 'ActiveDirectory'\n login: login\n sid: sid\n tenantId: tenantId\n }\n}\n
","tags":["Azure.MySQL.AAD","AZR-000392"]},{"location":"en/rules/Azure.MySQL.AAD/#notes","title":"Notes","text":"For the flexible server deployment model a user-assigned identity is required in order to use AAD-authentication. The single server deployment model does not support enforcing AAD-authentication only.
","tags":["Azure.MySQL.AAD","AZR-000392"]},{"location":"en/rules/Azure.MySQL.AAD/#links","title":"Links","text":"Security \u00b7 Azure Database for MySQL \u00b7 Rule \u00b7 2023_09 \u00b7 Important
Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases.
","tags":["Azure.MySQL.AADOnly","AZR-000394"]},{"location":"en/rules/Azure.MySQL.AADOnly/#description","title":"Description","text":"Azure Database for MySQL supports authentication with MySQL logins and Azure AD authentication.
By default, authentication with MySQL logins is enabled. MySQL logins are unable to provide sufficient protection for identities. Azure AD authentication provides strong protection controls including conditional access, identity governance, and privileged identity management.
Once you decide to use Azure AD authentication, you can disable authentication with MySQL logins.
Azure AD-only authentication is only supported for the flexible server deployment model with MySQL 5.7 and newer.
","tags":["Azure.MySQL.AADOnly","AZR-000394"]},{"location":"en/rules/Azure.MySQL.AADOnly/#recommendation","title":"Recommendation","text":"Consider using Azure AD-only authentication. Also consider using Azure Policy for Azure AD-only authentication with Azure Database for MySQL.
","tags":["Azure.MySQL.AADOnly","AZR-000394"]},{"location":"en/rules/Azure.MySQL.AADOnly/#examples","title":"Examples","text":"","tags":["Azure.MySQL.AADOnly","AZR-000394"]},{"location":"en/rules/Azure.MySQL.AADOnly/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for MySQL flexible servers that pass this rule:
Microsoft.DBforMySQL/flexibleServers/configurations
sub-resource.name
to aad_auth_only
.properties.value
to ON
.properties.source
to user-override
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMySQL/flexibleServers/configurations\",\n \"apiVersion\": \"2022-01-01\",\n \"name\": \"[format('{0}/{1}', parameters('serverName'), 'aad_auth_only')]\",\n \"properties\": {\n \"value\": \"ON\",\n \"source\": \"user-override\"\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.DBforMySQL/flexibleServers', parameters('serverName'))]\"\n ]\n}\n
","tags":["Azure.MySQL.AADOnly","AZR-000394"]},{"location":"en/rules/Azure.MySQL.AADOnly/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for MySQL flexible servers that pass this rule:
Microsoft.DBforMySQL/flexibleServers/configurations
sub-resource.name
to aad_auth_only
.properties.value
to ON
.properties.source
to user-override
.For example:
Azure Bicep snippetresource aadOnly 'Microsoft.DBforMySQL/flexibleServers/configurations@2022-01-01' = {\n name: 'aad_auth_only'\n parent: mySqlFlexibleServer\n properties: {\n value: 'ON'\n source: 'user-override'\n }\n}\n
","tags":["Azure.MySQL.AADOnly","AZR-000394"]},{"location":"en/rules/Azure.MySQL.AADOnly/#notes","title":"Notes","text":"The Azure AD admin must be set before enabling Azure AD-only authentication. Azure AD-only authentication is only suppored for the flexible server deployment model.
","tags":["Azure.MySQL.AADOnly","AZR-000394"]},{"location":"en/rules/Azure.MySQL.AADOnly/#links","title":"Links","text":"Security \u00b7 Azure Database for MySQL \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Determine if access from Azure services is required.
","tags":["Azure.MySQL.AllowAzureAccess","AZR-000134"]},{"location":"en/rules/Azure.MySQL.AllowAzureAccess/#description","title":"Description","text":"Allow access to Azure services, permits any Azure service including other Azure customers, network based-access to databases on the same MySQL server instance. If network based access is permitted, authentication is still required.
Enabling access from Azure Services is useful in certain cases for serverless PaaS workloads where configuring a stable IP address is not possible. For example Azure Functions, Container Instances and Logic Apps.
","tags":["Azure.MySQL.AllowAzureAccess","AZR-000134"]},{"location":"en/rules/Azure.MySQL.AllowAzureAccess/#recommendation","title":"Recommendation","text":"Where a stable IP addresses are able to be configured, configure IP or virtual network based firewall rules instead of using Allow access to Azure services.
Determine if access from Azure services is required for the services connecting to the hosted databases.
","tags":["Azure.MySQL.AllowAzureAccess","AZR-000134"]},{"location":"en/rules/Azure.MySQL.AllowAzureAccess/#links","title":"Links","text":"Security \u00b7 Azure Database for MySQL \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Enable Microsoft Defender for Cloud for Azure Database for MySQL.
","tags":["Azure.MySQL.DefenderCloud","AZR-000328"]},{"location":"en/rules/Azure.MySQL.DefenderCloud/#description","title":"Description","text":"Defender for Cloud detects anomalous activities indicating unusual and potentially harmful attempts to access or exploit databases.
","tags":["Azure.MySQL.DefenderCloud","AZR-000328"]},{"location":"en/rules/Azure.MySQL.DefenderCloud/#recommendation","title":"Recommendation","text":"Enable Microsoft Defender for Cloud for Azure Database for MySQL.
","tags":["Azure.MySQL.DefenderCloud","AZR-000328"]},{"location":"en/rules/Azure.MySQL.DefenderCloud/#examples","title":"Examples","text":"","tags":["Azure.MySQL.DefenderCloud","AZR-000328"]},{"location":"en/rules/Azure.MySQL.DefenderCloud/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for MySQL Single Servers that pass this rule:
Microsoft.DBforMySQL/servers/securityAlertPolicies
sub-resource (child resource).properties.state
property to Enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMySQL/servers\",\n \"apiVersion\": \"2017-12-01\",\n \"name\": \"[parameters('serverName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('skuName')]\",\n \"tier\": \"GeneralPurpose\",\n \"capacity\": \"[parameters('skuCapacity')]\",\n \"size\": \"[format('{0}', parameters('SkuSizeMB'))]\",\n \"family\": \"[parameters('skuFamily')]\"\n },\n \"properties\": {\n \"createMode\": \"Default\",\n \"version\": \"[parameters('mysqlVersion')]\",\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"storageProfile\": {\n \"storageMB\": \"[parameters('SkuSizeMB')]\",\n \"backupRetentionDays\": 7,\n \"geoRedundantBackup\": \"Enabled\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.DBforMySQL/servers/securityAlertPolicies\",\n \"apiVersion\": \"2017-12-01\",\n \"name\": \"Default\",\n \"dependsOn\": [\"[parameters('serverName')]\"],\n \"properties\": {\n \"emailAccountAdmins\": true,\n \"emailAddresses\": [\"soc@contoso.com\"],\n \"retentionDays\": 14,\n \"state\": \"Enabled\",\n \"storageAccountAccessKey\": \"account-key\",\n \"storageEndpoint\": \"https://contoso.blob.core.windows.net\"\n }\n }\n ]\n}\n
","tags":["Azure.MySQL.DefenderCloud","AZR-000328"]},{"location":"en/rules/Azure.MySQL.DefenderCloud/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for MySQL Single Servers that pass this rule:
Microsoft.DBforMySQL/servers/securityAlertPolicies
sub-resource (child resource).properties.state
property to Enabled
.For example:
Azure Bicep snippetresource mysqlDbServer 'Microsoft.DBforMySQL/servers@2017-12-01' = {\n name: serverName\n location: location\n sku: {\n name: skuName\n tier: 'GeneralPurpose'\n capacity: skuCapacity\n size: '${SkuSizeMB}'\n family: skuFamily\n }\n properties: {\n createMode: 'Default'\n version: mysqlVersion\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n storageProfile: {\n storageMB: SkuSizeMB\n backupRetentionDays: 7\n geoRedundantBackup: 'Enabled'\n }\n }\n}\n\nresource mysqlDefender 'Microsoft.DBforMySQL/servers/securityAlertPolicies@2017-12-01' = {\n name: 'Default'\n parent: mysqlDbServer\n properties: {\n emailAccountAdmins: true\n emailAddresses: ['soc@contoso.com']\n retentionDays: 14\n state: 'Enabled'\n storageAccountAccessKey: 'account-key'\n storageEndpoint: 'https://contoso.blob.core.windows.net'\n }\n}\n
","tags":["Azure.MySQL.DefenderCloud","AZR-000328"]},{"location":"en/rules/Azure.MySQL.DefenderCloud/#notes","title":"Notes","text":"This rule is only applicable for the Azure Database for MySQL Single Server deployment model.
Azure Database for MySQL Flexible Server deployment model does not currently support Microsoft Defender for Cloud.
","tags":["Azure.MySQL.DefenderCloud","AZR-000328"]},{"location":"en/rules/Azure.MySQL.DefenderCloud/#links","title":"Links","text":"Security \u00b7 Azure Database for MySQL \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Determine if there is an excessive number of permitted IP addresses.
","tags":["Azure.MySQL.FirewallIPRange","AZR-000135"]},{"location":"en/rules/Azure.MySQL.FirewallIPRange/#description","title":"Description","text":"Typically the number of IP address rules permitted through the firewall is minimal, with management connectivity from on-premises and cloud application connectivity the most common.
","tags":["Azure.MySQL.FirewallIPRange","AZR-000135"]},{"location":"en/rules/Azure.MySQL.FirewallIPRange/#recommendation","title":"Recommendation","text":"The MySQL server has greater then ten (10) public IP addresses that are permitted network access. Some rules may not be needed or can be reduced.
","tags":["Azure.MySQL.FirewallIPRange","AZR-000135"]},{"location":"en/rules/Azure.MySQL.FirewallIPRange/#links","title":"Links","text":"Security \u00b7 Azure Database for MySQL \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Determine if there is an excessive number of firewall rules.
","tags":["Azure.MySQL.FirewallRuleCount","AZR-000133"]},{"location":"en/rules/Azure.MySQL.FirewallRuleCount/#description","title":"Description","text":"Typically the number of firewall rules required is minimal, with management connectivity from on-premises and cloud application connectivity the most common.
","tags":["Azure.MySQL.FirewallRuleCount","AZR-000133"]},{"location":"en/rules/Azure.MySQL.FirewallRuleCount/#recommendation","title":"Recommendation","text":"The MySQL server has greater then ten (10) firewall rules. Some rules may not be needed.
","tags":["Azure.MySQL.FirewallRuleCount","AZR-000133"]},{"location":"en/rules/Azure.MySQL.FirewallRuleCount/#links","title":"Links","text":"Reliability \u00b7 Azure Database for MySQL \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Azure Database for MySQL should store backups in a geo-redundant storage.
","tags":["Azure.MySQL.GeoRedundantBackup","AZR-000323"]},{"location":"en/rules/Azure.MySQL.GeoRedundantBackup/#description","title":"Description","text":"Geo-redundant backup helps to protect your Azure Database for MySQL Servers against outages impacting backup storage in the primary region and allows you to restore your server to the geo-paired region in the event of a disaster.
When the backups are stored in geo-redundant backup storage, they are not only stored within the region in which your server is hosted, but are also replicated to a paired data center. Both the Azure Database for MySQL Flexible Server and the Azure Database for MySQL Single Server deployment model supports geo-redundant backup.
For the flexible deployment model the geo-redundant backup is supported for all tiers, but for the single deployment model either General Purpose
or Memory Optimized
tier is required.
Check out the NOTES
section for more details about geo-redundant backup for each of the deployment models.
Configure geo-redundant backup for Azure Database for MySQL.
","tags":["Azure.MySQL.GeoRedundantBackup","AZR-000323"]},{"location":"en/rules/Azure.MySQL.GeoRedundantBackup/#examples","title":"Examples","text":"","tags":["Azure.MySQL.GeoRedundantBackup","AZR-000323"]},{"location":"en/rules/Azure.MySQL.GeoRedundantBackup/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for MySQL Flexible Servers that pass this rule:
properties.backup.geoRedundantBackup
property to the value 'Enabled'
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMySQL/flexibleServers\",\n \"apiVersion\": \"2021-12-01-preview\",\n \"name\": \"[parameters('serverName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_D16as\",\n \"tier\": \"GeneralPurpose\"\n },\n \"properties\": {\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"storage\": {\n \"autoGrow\": \"Enabled\",\n \"iops\": \"[parameters('StorageIops')]\",\n \"storageSizeGB\": \"[parameters('StorageSizeGB')]\"\n },\n \"createMode\": \"Default\",\n \"version\": \"[parameters('mysqlVersion')]\",\n \"backup\": {\n \"backupRetentionDays\": 7,\n \"geoRedundantBackup\": \"Enabled\"\n },\n \"highAvailability\": {\n \"mode\": \"Disabled\"\n }\n }\n}\n
To deploy Azure Database for MySQL Single Servers that pass this rule:
properties.storageProfile.geoRedundantBackup
property to the value 'Enabled'
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforMySQL/servers\",\n \"apiVersion\": \"2017-12-01\",\n \"name\": \"[parameters('serverName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('skuName')]\",\n \"tier\": \"GeneralPurpose\",\n \"capacity\": \"[parameters('skuCapacity')]\",\n \"size\": \"[format('{0}', parameters('SkuSizeMB'))]\",\n \"family\": \"[parameters('skuFamily')]\"\n },\n \"properties\": {\n \"createMode\": \"Default\",\n \"version\": \"[parameters('mysqlVersion')]\",\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"storageProfile\": {\n \"storageMB\": \"[parameters('SkuSizeMB')]\",\n \"backupRetentionDays\": 7,\n \"geoRedundantBackup\": \"Enabled\"\n }\n }\n}\n
","tags":["Azure.MySQL.GeoRedundantBackup","AZR-000323"]},{"location":"en/rules/Azure.MySQL.GeoRedundantBackup/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for MySQL Flexible Servers that pass this rule:
properties.backup.geoRedundantBackup
property to the value 'Enabled'
.For example:
Azure Bicep snippetresource mysqlDbServer 'Microsoft.DBforMySQL/flexibleServers@2021-12-01-preview' = {\n name: serverName\n location: location\n sku: {\n name: 'Standard_D16as'\n tier: 'GeneralPurpose'\n }\n properties: {\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n storage: {\n autoGrow: 'Enabled'\n iops: StorageIops\n storageSizeGB: StorageSizeGB\n }\n createMode: 'Default'\n version: mysqlVersion\n backup: {\n backupRetentionDays: 7\n geoRedundantBackup: 'Enabled'\n }\n highAvailability: {\n mode: 'Disabled'\n }\n }\n}\n
To deploy Azure Database for MySQL Single Servers that pass this rule:
properties.storageProfile.geoRedundantBackup
property to the value 'Enabled'
.For example:
Azure Bicep snippetresource mysqlDbServer 'Microsoft.DBforMySQL/servers@2017-12-01' = {\n name: serverName\n location: location\n sku: {\n name: skuName\n tier: 'GeneralPurpose'\n capacity: skuCapacity\n size: '${SkuSizeMB}'\n family: skuFamily\n }\n properties: {\n createMode: 'Default'\n version: mysqlVersion\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n storageProfile: {\n storageMB: SkuSizeMB\n backupRetentionDays: 7\n geoRedundantBackup: 'Enabled'\n }\n }\n}\n
","tags":["Azure.MySQL.GeoRedundantBackup","AZR-000323"]},{"location":"en/rules/Azure.MySQL.GeoRedundantBackup/#notes","title":"Notes","text":"This rule is applicable for both the Azure Database for MySQL Flexible Server deployment model and the Azure Database for MySQL Single Server deployment model.
For the Single Server deployment model, it runs only against 'General Purpose'
and 'Memory Optimized'
tiers. The 'Basic'
tier does not support geo-redundant backup storage.
Security \u00b7 Azure Database for MySQL \u00b7 Rule \u00b7 2020_09 \u00b7 Critical
MySQL DB servers should reject TLS versions older than 1.2.
","tags":["Azure.MySQL.MinTLS","AZR-000132"]},{"location":"en/rules/Azure.MySQL.MinTLS/#description","title":"Description","text":"The minimum version of TLS that MySQL DB servers accept is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Azure lets you disable outdated protocols and require connections to use a minimum of TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 is accepted.
","tags":["Azure.MySQL.MinTLS","AZR-000132"]},{"location":"en/rules/Azure.MySQL.MinTLS/#recommendation","title":"Recommendation","text":"Consider configuring the minimum supported TLS version to be 1.2.
","tags":["Azure.MySQL.MinTLS","AZR-000132"]},{"location":"en/rules/Azure.MySQL.MinTLS/#links","title":"Links","text":"Operational Excellence \u00b7 Azure Database for MySQL \u00b7 Rule \u00b7 2020_12 \u00b7 Awareness
Azure MySQL DB server names should meet naming requirements.
","tags":["Azure.MySQL.ServerName","AZR-000136"]},{"location":"en/rules/Azure.MySQL.ServerName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for MySQL DB server names are:
Consider using names that meet Azure MySQL DB server naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.MySQL.ServerName","AZR-000136"]},{"location":"en/rules/Azure.MySQL.ServerName/#notes","title":"Notes","text":"This rule does not check if Azure MySQL DB server names are unique.
","tags":["Azure.MySQL.ServerName","AZR-000136"]},{"location":"en/rules/Azure.MySQL.ServerName/#links","title":"Links","text":"Reliability \u00b7 Azure Database for MySQL \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Use Azure Database for MySQL Flexible Server deployment model.
","tags":["Azure.MySQL.UseFlexible","AZR-000325"]},{"location":"en/rules/Azure.MySQL.UseFlexible/#description","title":"Description","text":"Azure Database for MySQL Single Server is on the retirement path. Upgrade to Azure Database for MySQL Flexible Server.
Azure Database for MySQL Flexible Server provides additional options for resilience and scalability above the Single Server deployment model.
","tags":["Azure.MySQL.UseFlexible","AZR-000325"]},{"location":"en/rules/Azure.MySQL.UseFlexible/#recommendation","title":"Recommendation","text":"Consider migrating to Azure Database for MySQL Flexible Server deployment model.
","tags":["Azure.MySQL.UseFlexible","AZR-000325"]},{"location":"en/rules/Azure.MySQL.UseFlexible/#links","title":"Links","text":"Security \u00b7 Azure Database for MySQL \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Enforce encrypted MySQL connections.
","tags":["Azure.MySQL.UseSSL","AZR-000131"]},{"location":"en/rules/Azure.MySQL.UseSSL/#description","title":"Description","text":"Azure Database for MySQL is configured to only accept encrypted connections by default. When the setting enforce SSL connections is disabled, encrypted and unencrypted connections are permitted. This does not indicate that unencrypted connections are being used.
Unencrypted communication to MySQL server instances could allow disclosure of information to an untrusted party.
","tags":["Azure.MySQL.UseSSL","AZR-000131"]},{"location":"en/rules/Azure.MySQL.UseSSL/#recommendation","title":"Recommendation","text":"Azure Database for MySQL should be configured to only accept encrypted connections. Unless explicitly required, consider enabling enforce SSL connections.
Also consider using Azure Policy to audit or enforce this configuration.
","tags":["Azure.MySQL.UseSSL","AZR-000131"]},{"location":"en/rules/Azure.MySQL.UseSSL/#links","title":"Links","text":"Cost Optimization \u00b7 Network Interface \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Network interfaces (NICs) that are not used should be removed.
","tags":["Azure.NIC.Attached","AZR-000257"]},{"location":"en/rules/Azure.NIC.Attached/#description","title":"Description","text":"Network interfaces (NICs) are used to attach services to a virtual network (VNET). Each NIC is deployed as a separate resource, however they are intended to be used with a related service. A NIC that is not attached to a related service performs no purpose.
Keeping unused resources in code or deployed in Azure can lead to confusion and distract attention away from active resources. Avoid unnecessary complexity that can increase the time required to develop, test, and maintain the workload.
Example of services that use NICs include:
Consider removing network interfaces that are not required to keep deployments lean and focus personnel time on active resources. Also consider using Resource Groups to help manage the lifecycle of related resources together.
","tags":["Azure.NIC.Attached","AZR-000257"]},{"location":"en/rules/Azure.NIC.Attached/#links","title":"Links","text":"Operational Excellence \u00b7 Network Interface \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Network Interface (NIC) names should meet naming requirements.
","tags":["Azure.NIC.Name","AZR-000259"]},{"location":"en/rules/Azure.NIC.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Network Interface names are:
Consider using names that meet Network Interface naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.NIC.Name","AZR-000259"]},{"location":"en/rules/Azure.NIC.Name/#examples","title":"Examples","text":"","tags":["Azure.NIC.Name","AZR-000259"]},{"location":"en/rules/Azure.NIC.Name/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy network interfaces that pass this rule:
minLength
and maxLength
constraint for the resource name parameter.uniqueString()
function to generate a unique name.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"The location resources will be deployed.\"\n }\n },\n \"subnetId\": {\n \"type\": \"string\",\n \"metadata\": {\n \"description\": \"A reference to the VNET subnet where the VM will be deployed.\"\n }\n },\n \"nicName\": {\n \"type\": \"string\",\n \"minLength\": 1,\n \"maxLength\": 80,\n \"metadata\": {\n \"description\": \"The name of the resource.\"\n }\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Network/networkInterfaces\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('nicName')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"ipConfigurations\": [\n {\n \"name\": \"ipconfig-1\",\n \"properties\": {\n \"privateIPAllocationMethod\": \"Dynamic\",\n \"subnet\": {\n \"id\": \"[parameters('subnetId')]\"\n }\n }\n }\n ]\n }\n }\n ]\n}\n
","tags":["Azure.NIC.Name","AZR-000259"]},{"location":"en/rules/Azure.NIC.Name/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy network interfaces that pass this rule:
minLength
and maxLength
constraint for the resource name parameter.uniqueString()
function to generate a unique name.For example:
Azure Bicep snippet@minLength(1)\n@maxLength(80)\n@sys.description('The name of the resource.')\nparam nicName string\n\nresource nic 'Microsoft.Network/networkInterfaces@2023-05-01' = {\n name: nicName\n location: location\n properties: {\n ipConfigurations: [\n {\n name: 'ipconfig-1'\n properties: {\n privateIPAllocationMethod: 'Dynamic'\n subnet: {\n id: subnetId\n }\n }\n }\n ]\n }\n}\n
","tags":["Azure.NIC.Name","AZR-000259"]},{"location":"en/rules/Azure.NIC.Name/#notes","title":"Notes","text":"This rule does not check if Network Interface names are unique.
","tags":["Azure.NIC.Name","AZR-000259"]},{"location":"en/rules/Azure.NIC.Name/#links","title":"Links","text":"Operational Excellence \u00b7 Network Interface \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Network interfaces (NICs) should inherit DNS from virtual networks.
","tags":["Azure.NIC.UniqueDns","AZR-000258"]},{"location":"en/rules/Azure.NIC.UniqueDns/#description","title":"Description","text":"By default Virtual machine (VM) NICs automatically use a DNS configuration inherited from the virtual network they connect to. Optionally, DNS servers can be overridden on a per NIC basis with a custom configuration.
Using network interfaces with individual DNS server settings may increase management overhead and complexity.
","tags":["Azure.NIC.UniqueDns","AZR-000258"]},{"location":"en/rules/Azure.NIC.UniqueDns/#recommendation","title":"Recommendation","text":"Consider updating NIC DNS server settings to inherit from virtual network.
","tags":["Azure.NIC.UniqueDns","AZR-000258"]},{"location":"en/rules/Azure.NIC.UniqueDns/#links","title":"Links","text":"Operational Excellence \u00b7 Network Security Group \u00b7 Rule \u00b7 2022_09 \u00b7 Awareness
AKS Network Security Group (NSG) should not have custom rules.
","tags":["Azure.NSG.AKSRules","AZR-000292"]},{"location":"en/rules/Azure.NSG.AKSRules/#description","title":"Description","text":"AKS manages the Network Security Group (NSG) allocated to the cluster. There should be no custom rules added as it may cause conflicts, break the AKS cluster or have an unexpected result.
","tags":["Azure.NSG.AKSRules","AZR-000292"]},{"location":"en/rules/Azure.NSG.AKSRules/#recommendation","title":"Recommendation","text":"Do not create custom Network Security Group (NSG) rules for an AKS managed NSG.
","tags":["Azure.NSG.AKSRules","AZR-000292"]},{"location":"en/rules/Azure.NSG.AKSRules/#links","title":"Links","text":"Security \u00b7 Network Security Group \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source.
","tags":["Azure.NSG.AnyInboundSource","AZR-000137"]},{"location":"en/rules/Azure.NSG.AnyInboundSource/#description","title":"Description","text":"NSGs filter network traffic for Azure services connected to a virtual network subnet. In addition to the built-in security rules, a number of custom rules may be defined. Custom security rules can be defined that allow or deny inbound or outbound communication.
When defining custom rules, avoid using rules that allow any as the inbound source. The intent of custom rules that allow any inbound source may not be clearly understood by support teams. Additionally, custom rules with any inbound source may expose services if a public IP address is attached.
When inbound network traffic from the Internet is intended also consider the following:
Consider updating inbound rules to use a specified source such as an IP range, application security group, or service tag. If inbound access from Internet-based sources is intended, consider using the service tag Internet
.
To deploy Network Security Groups that pass this rule:
sourceAddressPrefix
or sourceAddressPrefixes
property to a value other then *
for inbound allow rules.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/networkSecurityGroups\",\n \"apiVersion\": \"2023-09-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"securityRules\": [\n {\n \"name\": \"AllowLoadBalancerHealthInbound\",\n \"properties\": {\n \"description\": \"Allow inbound Azure Load Balancer health check.\",\n \"access\": \"Allow\",\n \"direction\": \"Inbound\",\n \"priority\": 100,\n \"protocol\": \"*\",\n \"sourcePortRange\": \"*\",\n \"sourceAddressPrefix\": \"AzureLoadBalancer\",\n \"destinationPortRange\": \"*\",\n \"destinationAddressPrefix\": \"*\"\n }\n },\n {\n \"name\": \"AllowApplicationInbound\",\n \"properties\": {\n \"description\": \"Allow internal web traffic into application.\",\n \"access\": \"Allow\",\n \"direction\": \"Inbound\",\n \"priority\": 300,\n \"protocol\": \"Tcp\",\n \"sourcePortRange\": \"*\",\n \"sourceAddressPrefix\": \"10.0.0.0/8\",\n \"destinationPortRange\": \"443\",\n \"destinationAddressPrefix\": \"VirtualNetwork\"\n }\n },\n {\n \"name\": \"DenyAllInbound\",\n \"properties\": {\n \"description\": \"Deny all other inbound traffic.\",\n \"access\": \"Deny\",\n \"direction\": \"Inbound\",\n \"priority\": 4000,\n \"protocol\": \"*\",\n \"sourcePortRange\": \"*\",\n \"sourceAddressPrefix\": \"*\",\n \"destinationPortRange\": \"*\",\n \"destinationAddressPrefix\": \"*\"\n }\n },\n {\n \"name\": \"DenyTraversalOutbound\",\n \"properties\": {\n \"description\": \"Deny outbound double hop traversal.\",\n \"access\": \"Deny\",\n \"direction\": \"Outbound\",\n \"priority\": 200,\n \"protocol\": \"Tcp\",\n \"sourcePortRange\": \"*\",\n \"sourceAddressPrefix\": \"VirtualNetwork\",\n \"destinationAddressPrefix\": \"*\",\n \"destinationPortRanges\": [\n \"3389\",\n \"22\"\n ]\n }\n }\n ]\n }\n}\n
To create an Application Security Group, use the Microsoft.Network/applicationSecurityGroups
resource. For example:
{\n \"type\": \"Microsoft.Network/applicationSecurityGroups\",\n \"apiVersion\": \"2023-09-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {}\n}\n
","tags":["Azure.NSG.AnyInboundSource","AZR-000137"]},{"location":"en/rules/Azure.NSG.AnyInboundSource/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Network Security Groups that pass this rule:
sourceAddressPrefix
or sourceAddressPrefixes
property to a value other then *
for inbound allow rules.For example:
Azure Bicep snippetresource nsg 'Microsoft.Network/networkSecurityGroups@2023-09-01' = {\n name: name\n location: location\n properties: {\n securityRules: [\n {\n name: 'AllowLoadBalancerHealthInbound'\n properties: {\n description: 'Allow inbound Azure Load Balancer health check.'\n access: 'Allow'\n direction: 'Inbound'\n priority: 100\n protocol: '*'\n sourcePortRange: '*'\n sourceAddressPrefix: 'AzureLoadBalancer'\n destinationPortRange: '*'\n destinationAddressPrefix: '*'\n }\n }\n {\n name: 'AllowApplicationInbound'\n properties: {\n description: 'Allow internal web traffic into application.'\n access: 'Allow'\n direction: 'Inbound'\n priority: 300\n protocol: 'Tcp'\n sourcePortRange: '*'\n sourceAddressPrefix: '10.0.0.0/8'\n destinationPortRange: '443'\n destinationAddressPrefix: 'VirtualNetwork'\n }\n }\n {\n name: 'DenyAllInbound'\n properties: {\n description: 'Deny all other inbound traffic.'\n access: 'Deny'\n direction: 'Inbound'\n priority: 4000\n protocol: '*'\n sourcePortRange: '*'\n sourceAddressPrefix: '*'\n destinationPortRange: '*'\n destinationAddressPrefix: '*'\n }\n }\n {\n name: 'DenyTraversalOutbound'\n properties: {\n description: 'Deny outbound double hop traversal.'\n access: 'Deny'\n direction: 'Outbound'\n priority: 200\n protocol: 'Tcp'\n sourcePortRange: '*'\n sourceAddressPrefix: 'VirtualNetwork'\n destinationAddressPrefix: '*'\n destinationPortRanges: [\n '3389'\n '22'\n ]\n }\n }\n ]\n }\n}\n
To create an Application Security Group, use the Microsoft.Network/applicationSecurityGroups
resource. For example:
resource asg 'Microsoft.Network/applicationSecurityGroups@2023-09-01' = {\n name: name\n location: location\n properties: {}\n}\n
","tags":["Azure.NSG.AnyInboundSource","AZR-000137"]},{"location":"en/rules/Azure.NSG.AnyInboundSource/#links","title":"Links","text":"Operational Excellence \u00b7 Network Security Group \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Network Security Groups (NSGs) should be associated to a subnet or network interface.
","tags":["Azure.NSG.Associated","AZR-000140"]},{"location":"en/rules/Azure.NSG.Associated/#description","title":"Description","text":"NSGs are basic stateful firewalls that are deployed as separate resources within your subscriptions. Each NSG can be associated to one or more network interfaces or subnets. NSGs that are not associated with a network interface or subnet perform no purpose and add to administration overhead.
","tags":["Azure.NSG.Associated","AZR-000140"]},{"location":"en/rules/Azure.NSG.Associated/#recommendation","title":"Recommendation","text":"Consider cleaning up NSGs that are not required to reduce technical debt. Also consider using Resource Groups to help manage the lifecycle of related resources together. Apply tags to all resources to help identify resources that are attached to specific workloads
To find orphaned NSG's run the following Azure CLI command
Azure CLI snippetaz network nsg list -g $rgName --query \"[?(subnets==null) && (networkInterfaces==null)].id\" -o tsv\n
","tags":["Azure.NSG.Associated","AZR-000140"]},{"location":"en/rules/Azure.NSG.Associated/#links","title":"Links","text":"Operational Excellence \u00b7 Network Security Group \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Avoid denying all inbound traffic.
","tags":["Azure.NSG.DenyAllInbound","AZR-000138"]},{"location":"en/rules/Azure.NSG.DenyAllInbound/#description","title":"Description","text":"Network Security Groups (NSGs) are configured to block all inbound network traffic by default. Blocking all inbound traffic will fail load balancer health probes and other required traffic.
When using a custom deny all inbound rule, also add rules to allow permitted traffic. To permit network traffic, add a custom allow rule with a lower priority number then the deny all rule. Rules with a lower priority number will be processed first. 100 is the lowest priority number.
","tags":["Azure.NSG.DenyAllInbound","AZR-000138"]},{"location":"en/rules/Azure.NSG.DenyAllInbound/#recommendation","title":"Recommendation","text":"Consider using a higher priority number for deny all rules to allow permitted traffic rules to be added. Consider enabling Flow Logs on all critical subnets in your subscription as an auditability and security best practice.
","tags":["Azure.NSG.DenyAllInbound","AZR-000138"]},{"location":"en/rules/Azure.NSG.DenyAllInbound/#examples","title":"Examples","text":"","tags":["Azure.NSG.DenyAllInbound","AZR-000138"]},{"location":"en/rules/Azure.NSG.DenyAllInbound/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Network Security Groups that pass this rule:
For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/networkSecurityGroups\",\n \"apiVersion\": \"2022-01-01\",\n \"name\": \"[parameters('nsgName')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"securityRules\": [\n {\n \"name\": \"AllowLoadBalancerHealthInbound\",\n \"properties\": {\n \"description\": \"Allow inbound Azure Load Balancer health check.\",\n \"access\": \"Allow\",\n \"direction\": \"Inbound\",\n \"priority\": 100,\n \"protocol\": \"*\",\n \"sourcePortRange\": \"*\",\n \"sourceAddressPrefix\": \"AzureLoadBalancer\",\n \"destinationPortRange\": \"*\",\n \"destinationAddressPrefix\": \"*\"\n }\n },\n {\n \"name\": \"AllowApplicationInbound\",\n \"properties\": {\n \"description\": \"Allow internal web traffic into application.\",\n \"access\": \"Allow\",\n \"direction\": \"Inbound\",\n \"priority\": 300,\n \"protocol\": \"Tcp\",\n \"sourcePortRange\": \"*\",\n \"sourceAddressPrefix\": \"10.0.0.0/8\",\n \"destinationPortRange\": \"443\",\n \"destinationAddressPrefix\": \"VirtualNetwork\"\n }\n },\n {\n \"name\": \"DenyAllInbound\",\n \"properties\": {\n \"description\": \"Deny all other inbound traffic.\",\n \"access\": \"Deny\",\n \"direction\": \"Inbound\",\n \"priority\": 4000,\n \"protocol\": \"*\",\n \"sourcePortRange\": \"*\",\n \"sourceAddressPrefix\": \"*\",\n \"destinationPortRange\": \"*\",\n \"destinationAddressPrefix\": \"*\"\n }\n },\n {\n \"name\": \"DenyTraversalOutbound\",\n \"properties\": {\n \"description\": \"Deny outbound double hop traversal.\",\n \"access\": \"Deny\",\n \"direction\": \"Outbound\",\n \"priority\": 200,\n \"protocol\": \"Tcp\",\n \"sourcePortRange\": \"*\",\n \"sourceAddressPrefix\": \"VirtualNetwork\",\n \"destinationAddressPrefix\": \"*\",\n \"destinationPortRanges\": [\n \"3389\",\n \"22\"\n ]\n }\n }\n ]\n }\n}\n
","tags":["Azure.NSG.DenyAllInbound","AZR-000138"]},{"location":"en/rules/Azure.NSG.DenyAllInbound/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Network Security Groups that pass this rule:
For example:
Azure Bicep snippetresource nsg 'Microsoft.Network/networkSecurityGroups@2022-01-01' = {\n name: nsgName\n location: location\n properties: {\n securityRules: [\n {\n name: 'AllowLoadBalancerHealthInbound'\n properties: {\n description: 'Allow inbound Azure Load Balancer health check.'\n access: 'Allow'\n direction: 'Inbound'\n priority: 100\n protocol: '*'\n sourcePortRange: '*'\n sourceAddressPrefix: 'AzureLoadBalancer'\n destinationPortRange: '*'\n destinationAddressPrefix: '*'\n }\n }\n {\n name: 'AllowApplicationInbound'\n properties: {\n description: 'Allow internal web traffic into application.'\n access: 'Allow'\n direction: 'Inbound'\n priority: 300\n protocol: 'Tcp'\n sourcePortRange: '*'\n sourceAddressPrefix: '10.0.0.0/8'\n destinationPortRange: '443'\n destinationAddressPrefix: 'VirtualNetwork'\n }\n }\n {\n name: 'DenyAllInbound'\n properties: {\n description: 'Deny all other inbound traffic.'\n access: 'Deny'\n direction: 'Inbound'\n priority: 4000\n protocol: '*'\n sourcePortRange: '*'\n sourceAddressPrefix: '*'\n destinationPortRange: '*'\n destinationAddressPrefix: '*'\n }\n }\n {\n name: 'DenyTraversalOutbound'\n properties: {\n description: 'Deny outbound double hop traversal.'\n access: 'Deny'\n direction: 'Outbound'\n priority: 200\n protocol: 'Tcp'\n sourcePortRange: '*'\n sourceAddressPrefix: 'VirtualNetwork'\n destinationAddressPrefix: '*'\n destinationPortRanges: [\n '3389'\n '22'\n ]\n }\n }\n ]\n }\n}\n
","tags":["Azure.NSG.DenyAllInbound","AZR-000138"]},{"location":"en/rules/Azure.NSG.DenyAllInbound/#links","title":"Links","text":"Security \u00b7 Network Security Group \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Deny outbound management connections from non-management hosts.
","tags":["Azure.NSG.LateralTraversal","AZR-000139"]},{"location":"en/rules/Azure.NSG.LateralTraversal/#description","title":"Description","text":"Network Security Groups (NSGs) are basic stateful firewalls that provide network isolation and security. NSGs allow or deny network traffic to and from Azure resources in an Azure virtual network. i.e. Traffic between VMs on the same or different subnet can be restricted. NSGs do this by enforcing ordered access rules for all traffic in or out services attached to a subnet.
This micro-segmentation approach provides a control to reduce lateral movement between services.
Typically, a subset of trusted hosts such as privileged access workstations (PAWs), bastion hosts, or jump boxes will be used for management. Management protocols originating from application workload hosts should be blocked.
For example:
This helps improve security in two ways:
Consider configuring NSGs rules to block common outbound management traffic from non-management hosts.
","tags":["Azure.NSG.LateralTraversal","AZR-000139"]},{"location":"en/rules/Azure.NSG.LateralTraversal/#notes","title":"Notes","text":"Specifically this rule checks if either 3389 (RDP) or 22 (SSH) has been blocked for outbound traffic.
To suppress this rule for NSGs protecting subnets expected to allow outbound management traffic see Permit outbound management.
","tags":["Azure.NSG.LateralTraversal","AZR-000139"]},{"location":"en/rules/Azure.NSG.LateralTraversal/#examples","title":"Examples","text":"","tags":["Azure.NSG.LateralTraversal","AZR-000139"]},{"location":"en/rules/Azure.NSG.LateralTraversal/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy NSGs that pass this rule:
For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/networkSecurityGroups\",\n \"name\": \"[parameters('nsgName')]\",\n \"apiVersion\": \"2019-04-01\",\n \"location\": \"[resourceGroup().location]\",\n \"properties\": {\n \"securityRules\": [\n {\n \"name\": \"deny-hop-outbound\",\n \"properties\": {\n \"protocol\": \"*\",\n \"sourcePortRange\": \"*\",\n \"destinationPortRanges\": [\n \"3389\",\n \"22\"\n ],\n \"access\": \"Deny\",\n \"priority\": 200,\n \"direction\": \"Outbound\",\n \"sourceAddressPrefix\": \"VirtualNetwork\",\n \"destinationAddressPrefix\": \"*\"\n }\n }\n ]\n }\n}\n
","tags":["Azure.NSG.LateralTraversal","AZR-000139"]},{"location":"en/rules/Azure.NSG.LateralTraversal/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy NSGs that pass this rule:
For example:
Azure Bicep snippetresource nsg 'Microsoft.Network/networkSecurityGroups@2021-02-01' = {\n name: 'nsg-001'\n properties: {\n securityRules: [\n {\n name: 'deny-hop-outbound'\n properties: {\n priority: 200\n access: 'Deny'\n protocol: 'Tcp'\n direction: 'Outbound'\n sourceAddressPrefix: 'VirtualNetwork'\n destinationAddressPrefix: '*'\n destinationPortRanges: [\n '3389'\n '22'\n ]\n }\n }\n ]\n }\n}\n
","tags":["Azure.NSG.LateralTraversal","AZR-000139"]},{"location":"en/rules/Azure.NSG.LateralTraversal/#links","title":"Links","text":"Operational Excellence \u00b7 Network Security Group \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Network Security Group (NSG) names should meet naming requirements.
","tags":["Azure.NSG.Name","AZR-000141"]},{"location":"en/rules/Azure.NSG.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for NSG names are:
Consider using names that meet Network Security Group naming requirements. Additionally consider naming resources with a standard naming convention. If creating resources using CI/CD pipelines consider programmatically Generating Cloud Resource Names using PowerShell or Bicep
","tags":["Azure.NSG.Name","AZR-000141"]},{"location":"en/rules/Azure.NSG.Name/#notes","title":"Notes","text":"This rule does not check if NSG names are unique.
","tags":["Azure.NSG.Name","AZR-000141"]},{"location":"en/rules/Azure.NSG.Name/#links","title":"Links","text":"Operational Excellence \u00b7 Policy \u00b7 Rule \u00b7 2021_06 \u00b7 Awareness
Policy assignments should use assignedBy
metadata.
When using the Azure Portal, policy assignment automatically set the assignedBy
metadata. This metadata field is intended to indicate the person or team assigning the policy to a resource scope.
When automating policy management, it may be helpful to identify assignments managed by code.
","tags":["Azure.Policy.AssignmentAssignedBy","AZR-000144"]},{"location":"en/rules/Azure.Policy.AssignmentAssignedBy/#recommendation","title":"Recommendation","text":"Consider setting assignedBy
metadata for each policy assignment.
To deploy policy assignments that pass this rule:
properties.metadata.assignedBy
property with a valid value.For example:
Azure Template snippet{\n \"comments\": \"Initiative assignment\",\n \"name\": \"assignment-001\",\n \"type\": \"Microsoft.Authorization/policyAssignments\",\n \"apiVersion\": \"2019-06-01\",\n \"properties\": {\n \"displayName\": \"Assignment 001\",\n \"description\": \"An example policy assignment.\",\n \"metadata\": {\n \"assignedBy\": \"DevOps pipeline\"\n },\n \"enforcementMode\": \"Default\"\n }\n}\n
","tags":["Azure.Policy.AssignmentAssignedBy","AZR-000144"]},{"location":"en/rules/Azure.Policy.AssignmentAssignedBy/#links","title":"Links","text":"Operational Excellence \u00b7 Policy \u00b7 Rule \u00b7 2021_06 \u00b7 Awareness
Policy assignments should use a display name and description.
","tags":["Azure.Policy.AssignmentDescriptors","AZR-000143"]},{"location":"en/rules/Azure.Policy.AssignmentDescriptors/#description","title":"Description","text":"Policy assignments can be configured with a display name and description. Use these additional properties to clearly convey the intent of the policy assignment.
","tags":["Azure.Policy.AssignmentDescriptors","AZR-000143"]},{"location":"en/rules/Azure.Policy.AssignmentDescriptors/#recommendation","title":"Recommendation","text":"Consider setting a display name and description for each policy assignment.
","tags":["Azure.Policy.AssignmentDescriptors","AZR-000143"]},{"location":"en/rules/Azure.Policy.AssignmentDescriptors/#examples","title":"Examples","text":"","tags":["Azure.Policy.AssignmentDescriptors","AZR-000143"]},{"location":"en/rules/Azure.Policy.AssignmentDescriptors/#azure-templates","title":"Azure templates","text":"To deploy policy assignments that pass this rule:
properties.displayName
property with a valid value.properties.description
property with a valid value.For example:
Azure Template snippet{\n \"comments\": \"Initiative assignment\",\n \"name\": \"assignment-001\",\n \"type\": \"Microsoft.Authorization/policyAssignments\",\n \"apiVersion\": \"2019-06-01\",\n \"properties\": {\n \"displayName\": \"Assignment 001\",\n \"description\": \"An example policy assignment.\",\n \"metadata\": {\n \"assignedBy\": \"DevOps pipeline\"\n },\n \"enforcementMode\": \"Default\"\n }\n}\n
","tags":["Azure.Policy.AssignmentDescriptors","AZR-000143"]},{"location":"en/rules/Azure.Policy.AssignmentDescriptors/#links","title":"Links","text":"Operational Excellence \u00b7 Policy \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Policy and initiative definitions should use a display name, description, and category.
","tags":["Azure.Policy.Descriptors","AZR-000142"]},{"location":"en/rules/Azure.Policy.Descriptors/#description","title":"Description","text":"Policy and initiative definitions can be configured with a display name, description, and category. Use these additional properties to clearly convey the purpose when creating custom definitions.
","tags":["Azure.Policy.Descriptors","AZR-000142"]},{"location":"en/rules/Azure.Policy.Descriptors/#recommendation","title":"Recommendation","text":"Consider setting a display name, description and category for each policy and initiatives definition.
","tags":["Azure.Policy.Descriptors","AZR-000142"]},{"location":"en/rules/Azure.Policy.Descriptors/#examples","title":"Examples","text":"","tags":["Azure.Policy.Descriptors","AZR-000142"]},{"location":"en/rules/Azure.Policy.Descriptors/#azure-templates","title":"Azure templates","text":"To deploy initiative and policy definitions that pass this rule:
properties.displayName
property with a valid value.properties.description
property with a valid value.properties.metadata.category
property with a valid value.For example:
Azure Template snippet{\n \"comments\": \"Initiative definition\",\n \"name\": \"initiative-001\",\n \"type\": \"Microsoft.Authorization/policySetDefinitions\",\n \"apiVersion\": \"2019-06-01\",\n \"properties\": {\n \"policyType\": \"Custom\",\n \"displayName\": \"Initiative 001\",\n \"description\": \"An example initiative.\",\n \"metadata\": {\n \"category\": \"Security\"\n },\n \"policyDefinitions\": []\n }\n}\n
","tags":["Azure.Policy.Descriptors","AZR-000142"]},{"location":"en/rules/Azure.Policy.Descriptors/#links","title":"Links","text":"Operational Excellence \u00b7 Policy \u00b7 Rule \u00b7 2021_06 \u00b7 Awareness
Policy exemptions should use a display name and description.
","tags":["Azure.Policy.ExemptionDescriptors","AZR-000145"]},{"location":"en/rules/Azure.Policy.ExemptionDescriptors/#description","title":"Description","text":"Policy assignments can be configured with a display name and description. Use these additional properties to clearly convey the reason for the policy exemption. Additionally, consider providing a link or reference to track exemption conditions and approval.
","tags":["Azure.Policy.ExemptionDescriptors","AZR-000145"]},{"location":"en/rules/Azure.Policy.ExemptionDescriptors/#recommendation","title":"Recommendation","text":"Consider setting a display name and description for each policy exemption.
","tags":["Azure.Policy.ExemptionDescriptors","AZR-000145"]},{"location":"en/rules/Azure.Policy.ExemptionDescriptors/#examples","title":"Examples","text":"","tags":["Azure.Policy.ExemptionDescriptors","AZR-000145"]},{"location":"en/rules/Azure.Policy.ExemptionDescriptors/#azure-templates","title":"Azure templates","text":"To deploy policy exemptions that pass this rule:
properties.displayName
property with a valid value.properties.description
property with a valid value.For example:
Azure Template snippet{\n \"comments\": \"An example exemption.\",\n \"name\": \"exemption-001\",\n \"type\": \"Microsoft.Authorization/policyExemptions\",\n \"apiVersion\": \"2020-07-01-preview\",\n \"properties\": {\n \"policyAssignmentId\": \"<assignment_id>\",\n \"policyDefinitionReferenceIds\": [],\n \"exemptionCategory\": \"Waiver\",\n \"expiresOn\": \"2021-04-27T14:00:00Z\",\n \"displayName\": \"Exemption 001\",\n \"description\": \"An example exemption.\",\n \"metadata\": {\n \"requestedBy\": \"Apps team\",\n \"approvedBy\": \"Security team\",\n \"createdBy\": \"DevOps pipeline\"\n }\n }\n}\n
","tags":["Azure.Policy.ExemptionDescriptors","AZR-000145"]},{"location":"en/rules/Azure.Policy.ExemptionDescriptors/#links","title":"Links","text":"Operational Excellence \u00b7 Policy \u00b7 Rule \u00b7 2021_06 \u00b7 Awareness
Configure policy waiver exemptions to expire.
","tags":["Azure.Policy.WaiverExpiry","AZR-000146"]},{"location":"en/rules/Azure.Policy.WaiverExpiry/#description","title":"Description","text":"Azure Policy waiver exemptions are intended to be temporary acceptance of a non-compliance state. Use the Mitigated
category when the issue intent has been met through an another method.
Consider configuring an expiry for policy exemption waivers within the maximum threshold.
","tags":["Azure.Policy.WaiverExpiry","AZR-000146"]},{"location":"en/rules/Azure.Policy.WaiverExpiry/#examples","title":"Examples","text":"","tags":["Azure.Policy.WaiverExpiry","AZR-000146"]},{"location":"en/rules/Azure.Policy.WaiverExpiry/#azure-templates","title":"Azure templates","text":"To deploy policy assignments that pass this rule:
properties.expiresOn
property with a valid date earlier than the maximum number of days.For example:
Azure Template snippet{\n \"comments\": \"An example exemption.\",\n \"name\": \"exemption-001\",\n \"type\": \"Microsoft.Authorization/policyExemptions\",\n \"apiVersion\": \"2020-07-01-preview\",\n \"properties\": {\n \"policyAssignmentId\": \"<assignment_id>\",\n \"policyDefinitionReferenceIds\": [],\n \"exemptionCategory\": \"Waiver\",\n \"expiresOn\": \"2021-04-27T14:00:00Z\",\n \"displayName\": \"Exemption 001\",\n \"description\": \"An example exemption.\",\n \"metadata\": {\n \"requestedBy\": \"Apps team\",\n \"approvedBy\": \"Security team\",\n \"createdBy\": \"DevOps pipeline\"\n }\n }\n}\n
","tags":["Azure.Policy.WaiverExpiry","AZR-000146"]},{"location":"en/rules/Azure.Policy.WaiverExpiry/#notes","title":"Notes","text":"This rule fails:
Configure AZURE_POLICY_WAIVER_MAX_EXPIRY
to set the maximum expiry date threshold.
# YAML: The default AZURE_POLICY_WAIVER_MAX_EXPIRY configuration option\nconfiguration:\n AZURE_POLICY_WAIVER_MAX_EXPIRY: 366\n
","tags":["Azure.Policy.WaiverExpiry","AZR-000146"]},{"location":"en/rules/Azure.Policy.WaiverExpiry/#links","title":"Links","text":"Security \u00b7 Azure Database for PostgreSQL \u00b7 Rule \u00b7 2023_06 \u00b7 Critical
Use Entra ID authentication with Azure Database for PostgreSQL databases.
","tags":["Azure.PostgreSQL.AAD","AZR-000389"]},{"location":"en/rules/Azure.PostgreSQL.AAD/#description","title":"Description","text":"Azure Database for PostgreSQL offer two authentication models, Entra ID (previously knows as Azure AD) and PostgreSQL logins. Entra ID authentication supports centralized identity management in addition to modern password protections. Some of the benefits of Entra ID authentication over PostgreSQL authentication including:
It is also possible to disable PostgreSQL authentication entirely for the flexible server deployment model.
","tags":["Azure.PostgreSQL.AAD","AZR-000389"]},{"location":"en/rules/Azure.PostgreSQL.AAD/#recommendation","title":"Recommendation","text":"Consider using Entra ID authentication with Azure Database for PostgreSQL databases. Additionally, consider disabling PostgreSQL authentication.
","tags":["Azure.PostgreSQL.AAD","AZR-000389"]},{"location":"en/rules/Azure.PostgreSQL.AAD/#examples","title":"Examples","text":"","tags":["Azure.PostgreSQL.AAD","AZR-000389"]},{"location":"en/rules/Azure.PostgreSQL.AAD/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for PostgreSQL flexible servers that pass this rule:
Microsoft.DBforPostgreSQL/flexibleServers/administrators
sub-resource.properties.principalName
to the user principal name of the Entra ID administrator user, group, or application.properties.principalType
to the principal type used to represent the type of Entra ID administrator.properties.tenantId
to the tenant ID of the Entra ID administrator user, group, or application.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforPostgreSQL/flexibleServers/administrators\",\n \"apiVersion\": \"2022-12-01\",\n \"name\": \"[format('{0}/{1}', parameters('serverName'), parameters('name'))]\",\n \"properties\": {\n \"principalName\": \"[parameters('principalName')]\",\n \"principalType\": \"[parameters('principalType')]\",\n \"tenantId\": \"[parameters('tenantId')]\"\n },\n \"dependsOn\": [\n \"postgreSqlFlexibleServer\"\n ]\n}\n
To deploy Azure Database for PostgreSQL single servers that pass this rule:
Microsoft.DBforPostgreSQL/servers/administrators
sub-resource.properties.administratorType
to ActiveDirectory
.properties.login
to the Entra ID administrator login object name.properties.sid
to the object ID GUID of the Entra ID administrator user, group, or application.properties.tenantId
to the tenant ID of the Entra ID administrator user, group, or application.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforPostgreSQL/servers/administrators\",\n \"apiVersion\": \"2017-12-01\",\n \"name\": \"[format('{0}/{1}', parameters('serverName'), 'activeDirectory')]\",\n \"properties\": {\n \"administratorType\": \"ActiveDirectory\",\n \"login\": \"[parameters('login')]\",\n \"sid\": \"[parameters('sid')]\",\n \"tenantId\": \"[parameters('tenantId')]\"\n },\n \"dependsOn\": [\n \"postgreSqlSingleServer\"\n ]\n}\n
","tags":["Azure.PostgreSQL.AAD","AZR-000389"]},{"location":"en/rules/Azure.PostgreSQL.AAD/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for PostgreSQL flexible servers that pass this rule:
Microsoft.DBforPostgreSQL/flexibleServers/administrators
sub-resource.properties.principalName
to the user principal name of the Entra ID administrator user, group, or application.properties.principalType
to the principal type used to represent the type of Entra ID administrator.properties.tenantId
to the tenant ID of the Entra ID administrator user, group, or application.For example:
Azure Bicep snippetresource aadAdmin 'Microsoft.DBforPostgreSQL/flexibleServers/administrators@2022-12-01' = {\n name: name\n parent: postgreSqlFlexibleServer\n properties: {\n principalName: principalName\n principalType: principalType\n tenantId: tenantId\n }\n}\n
To deploy Azure Database for PostgreSQL single servers that pass this rule:
Microsoft.DBforPostgreSQL/servers/administrators
sub-resource.properties.administratorType
to ActiveDirectory
.properties.login
to the Entra ID administrator login object name.properties.sid
to the object ID GUID of the Entra ID administrator user, group, or application.properties.tenantId
to the tenant ID of the Entra ID administrator user, group, or application.For example:
Azure Bicep snippetresource aadAdmin 'Microsoft.DBforPostgreSQL/servers/administrators@2017-12-01' = {\n name: 'activeDirectory'\n parent: postgreSqlSingleServer\n properties: {\n administratorType: 'ActiveDirectory'\n login: login\n sid: sid\n tenantId: tenantId\n }\n}\n
","tags":["Azure.PostgreSQL.AAD","AZR-000389"]},{"location":"en/rules/Azure.PostgreSQL.AAD/#notes","title":"Notes","text":"The single server deployment model is limited to:
Security \u00b7 Azure Database for PostgreSQL \u00b7 Rule \u00b7 2023_06 \u00b7 Important
Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases.
","tags":["Azure.PostgreSQL.AADOnly","AZR-000390"]},{"location":"en/rules/Azure.PostgreSQL.AADOnly/#description","title":"Description","text":"Azure Database for PostgreSQL supports authentication with PostgreSQL logins and Azure AD authentication.
By default, authentication with PostgreSQL logins is enabled. PostgreSQL logins are unable to provide sufficient protection for identities. Azure AD authentication provides strong protection controls including conditional access, identity governance, and privileged identity management.
Once you decide to use Azure AD authentication, you can disable authentication with PostgreSQL logins.
Azure AD-only authentication is only supported for the flexible server deployment model.
","tags":["Azure.PostgreSQL.AADOnly","AZR-000390"]},{"location":"en/rules/Azure.PostgreSQL.AADOnly/#recommendation","title":"Recommendation","text":"Consider using Azure AD-only authentication. Also consider using Azure Policy for Azure AD-only authentication with Azure Database for PostgreSQL.
","tags":["Azure.PostgreSQL.AADOnly","AZR-000390"]},{"location":"en/rules/Azure.PostgreSQL.AADOnly/#examples","title":"Examples","text":"","tags":["Azure.PostgreSQL.AADOnly","AZR-000390"]},{"location":"en/rules/Azure.PostgreSQL.AADOnly/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for PostgreSQL flexible servers that pass this rule:
properties.authConfig.activeDirectoryAuth
property to true
.properties.authConfig.passwordAuth
property to false
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforPostgreSQL/flexibleServers\",\n \"apiVersion\": \"2022-12-01\",\n \"name\": \"[parameters('serverName')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"authConfig\": {\n \"activeDirectoryAuth\": \"Enabled\",\n \"passwordAuth\": \"Disabled\",\n \"tenantId\": \"[parameters('tenantId')]\"\n }\n }\n}\n
","tags":["Azure.PostgreSQL.AADOnly","AZR-000390"]},{"location":"en/rules/Azure.PostgreSQL.AADOnly/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for PostgreSQL flexible servers that pass this rule:
properties.authConfig.activeDirectoryAuth
property to true
.properties.authConfig.passwordAuth
property to false
.For example:
Azure Bicep snippetresource postgreSqlFlexibleServer 'Microsoft.DBforPostgreSQL/flexibleServers@2022-12-01' = {\n name: serverName\n location: location\n properties: {\n authConfig: {\n activeDirectoryAuth: 'Enabled'\n passwordAuth: 'Disabled'\n tenantId: tenantId\n }\n }\n}\n
","tags":["Azure.PostgreSQL.AADOnly","AZR-000390"]},{"location":"en/rules/Azure.PostgreSQL.AADOnly/#notes","title":"Notes","text":"The Azure AD admin must be set before enabling Azure AD-only authentication. Azure AD-only authentication is only suppored for the flexible server deployment model.
","tags":["Azure.PostgreSQL.AADOnly","AZR-000390"]},{"location":"en/rules/Azure.PostgreSQL.AADOnly/#links","title":"Links","text":"Security \u00b7 Azure Database for PostgreSQL \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Determine if access from Azure services is required.
","tags":["Azure.PostgreSQL.AllowAzureAccess","AZR-000150"]},{"location":"en/rules/Azure.PostgreSQL.AllowAzureAccess/#description","title":"Description","text":"Allow access to Azure services, permits any Azure service including other Azure customers, network based-access to databases on the same PostgreSQL server instance. If network based access is permitted, authentication is still required.
Enabling access from Azure Services is useful in certain cases for serverless PaaS workloads where configuring a stable IP address is not possible. For example Azure Functions, Container Instances and Logic Apps.
","tags":["Azure.PostgreSQL.AllowAzureAccess","AZR-000150"]},{"location":"en/rules/Azure.PostgreSQL.AllowAzureAccess/#recommendation","title":"Recommendation","text":"Where a stable IP addresses are able to be configured, configure IP or virtual network based firewall rules instead of using Allow access to Azure services.
Determine if access from Azure services is required for the services connecting to the hosted databases.
","tags":["Azure.PostgreSQL.AllowAzureAccess","AZR-000150"]},{"location":"en/rules/Azure.PostgreSQL.AllowAzureAccess/#links","title":"Links","text":"Security \u00b7 Azure Database for PostgreSQL \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL.
","tags":["Azure.PostgreSQL.DefenderCloud","AZR-000327"]},{"location":"en/rules/Azure.PostgreSQL.DefenderCloud/#description","title":"Description","text":"Defender for Cloud detects anomalous activities indicating unusual and potentially harmful attempts to access or exploit databases.
","tags":["Azure.PostgreSQL.DefenderCloud","AZR-000327"]},{"location":"en/rules/Azure.PostgreSQL.DefenderCloud/#recommendation","title":"Recommendation","text":"Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL.
","tags":["Azure.PostgreSQL.DefenderCloud","AZR-000327"]},{"location":"en/rules/Azure.PostgreSQL.DefenderCloud/#examples","title":"Examples","text":"","tags":["Azure.PostgreSQL.DefenderCloud","AZR-000327"]},{"location":"en/rules/Azure.PostgreSQL.DefenderCloud/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for PostgreSQL Single Servers that pass this rule:
Microsoft.DBforPostgreSQL/servers/securityAlertPolicies
sub-resource (child resource).properties.state
property to Enabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforPostgreSQL/servers\",\n \"apiVersion\": \"2017-12-01\",\n \"name\": \"[parameters('serverName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('skuName')]\",\n \"tier\": \"GeneralPurpose\",\n \"capacity\": \"[parameters('SkuCapacity')]\",\n \"size\": \"[format('{0}', parameters('skuSizeMB'))]\",\n \"family\": \"[parameters('skuFamily')]\"\n },\n \"properties\": {\n \"createMode\": \"Default\",\n \"version\": \"[parameters('postgresqlVersion')]\",\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"storageProfile\": {\n \"storageMB\": \"[parameters('skuSizeMB')]\",\n \"backupRetentionDays\": 7,\n \"geoRedundantBackup\": \"Enabled\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.DBforPostgreSQL/servers/securityAlertPolicies\",\n \"apiVersion\": \"2017-12-01\",\n \"name\": \"Default\",\n \"dependsOn\": [\"[parameters('serverName')]\"],\n \"properties\": {\n \"emailAccountAdmins\": true,\n \"emailAddresses\": [\"soc@contoso.com\"],\n \"retentionDays\": 14,\n \"state\": \"Enabled\",\n \"storageAccountAccessKey\": \"account-key\",\n \"storageEndpoint\": \"https://contoso.blob.core.windows.net\"\n }\n }\n ]\n}\n
","tags":["Azure.PostgreSQL.DefenderCloud","AZR-000327"]},{"location":"en/rules/Azure.PostgreSQL.DefenderCloud/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for PostgreSQL Single Servers that pass this rule:
Microsoft.DBforPostgreSQL/servers/securityAlertPolicies
sub-resource (child resource).properties.state
property to Enabled
.For example:
Azure Bicep snippetresource postgresqlDbServer 'Microsoft.DBforPostgreSQL/servers@2017-12-01' = {\n name: serverName\n location: location\n sku: {\n name: skuName\n tier: 'GeneralPurpose'\n capacity: skuCapacity\n size: '${skuSizeMB}'\n family: skuFamily\n }\n properties: {\n createMode: 'Default'\n version: postgresqlVersion\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n storageProfile: {\n storageMB: SkuSizeMB\n backupRetentionDays: 7\n geoRedundantBackup: 'Enabled'\n }\n }\n}\n\nresource postgresqlDefender 'Microsoft.DBforPostgreSQL/servers/securityAlertPolicies@2017-12-01' = {\n name: 'Default'\n parent: postgresqlDbServer\n properties: {\n emailAccountAdmins: true\n emailAddresses: ['soc@contoso.com']\n retentionDays: 14\n state: 'Enabled'\n storageAccountAccessKey: 'account-key'\n storageEndpoint: 'https://contoso.blob.core.windows.net'\n }\n}\n
","tags":["Azure.PostgreSQL.DefenderCloud","AZR-000327"]},{"location":"en/rules/Azure.PostgreSQL.DefenderCloud/#notes","title":"Notes","text":"This rule is only applicable for the Azure Database for PostgreSQL Single Server deployment model.
Azure Database for PostgreSQL Flexible Server deployment model does not currently support Microsoft Defender for Cloud.
","tags":["Azure.PostgreSQL.DefenderCloud","AZR-000327"]},{"location":"en/rules/Azure.PostgreSQL.DefenderCloud/#links","title":"Links","text":"Security \u00b7 Azure Database for PostgreSQL \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Determine if there is an excessive number of permitted IP addresses.
","tags":["Azure.PostgreSQL.FirewallIPRange","AZR-000151"]},{"location":"en/rules/Azure.PostgreSQL.FirewallIPRange/#description","title":"Description","text":"Typically the number of IP address rules permitted through the firewall is minimal, with management connectivity from on-premises and cloud application connectivity the most common.
","tags":["Azure.PostgreSQL.FirewallIPRange","AZR-000151"]},{"location":"en/rules/Azure.PostgreSQL.FirewallIPRange/#recommendation","title":"Recommendation","text":"The PostgreSQL server has greater then ten (10) public IP addresses that are permitted network access. Some rules may not be needed or can be reduced.
","tags":["Azure.PostgreSQL.FirewallIPRange","AZR-000151"]},{"location":"en/rules/Azure.PostgreSQL.FirewallIPRange/#links","title":"Links","text":"Security \u00b7 Azure Database for PostgreSQL \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Determine if there is an excessive number of firewall rules.
","tags":["Azure.PostgreSQL.FirewallRuleCount","AZR-000149"]},{"location":"en/rules/Azure.PostgreSQL.FirewallRuleCount/#description","title":"Description","text":"Typically the number of firewall rules required is minimal, with management connectivity from on-premises and cloud application connectivity the most common.
","tags":["Azure.PostgreSQL.FirewallRuleCount","AZR-000149"]},{"location":"en/rules/Azure.PostgreSQL.FirewallRuleCount/#recommendation","title":"Recommendation","text":"The PostgreSQL server has greater then ten (10) firewall rules. Some rules may not be needed.
","tags":["Azure.PostgreSQL.FirewallRuleCount","AZR-000149"]},{"location":"en/rules/Azure.PostgreSQL.FirewallRuleCount/#links","title":"Links","text":"Reliability \u00b7 Azure Database for PostgreSQL \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Azure Database for PostgreSQL should store backups in a geo-redundant storage.
","tags":["Azure.PostgreSQL.GeoRedundantBackup","AZR-000326"]},{"location":"en/rules/Azure.PostgreSQL.GeoRedundantBackup/#description","title":"Description","text":"Geo-redundant backup helps to protect your Azure Database for PostgreSQL Servers against outages impacting backup storage in the primary region and allows you to restore your server to the geo-paired region in the event of a disaster.
When the backups are stored in geo-redundant backup storage, they are not only stored within the region in which your server is hosted, but are also replicated to a paired data center. Both the Azure Database for PostgreSQL Flexible Server and the Azure Database for PostgreSQL Single Server deployment model supports geo-redundant backup.
For the flexible deployment model the geo-redundant backup is supported for all tiers, but for the single deployment model either General Purpose
or Memory Optimized
tier is required.
Check out the NOTES
and the LINKS
section for more details about geo-redundant backup for each of the deployment models.
Configure geo-redundant backup for Azure Database for PostgreSQL.
","tags":["Azure.PostgreSQL.GeoRedundantBackup","AZR-000326"]},{"location":"en/rules/Azure.PostgreSQL.GeoRedundantBackup/#examples","title":"Examples","text":"","tags":["Azure.PostgreSQL.GeoRedundantBackup","AZR-000326"]},{"location":"en/rules/Azure.PostgreSQL.GeoRedundantBackup/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Azure Database for PostgreSQL Flexible Servers that pass this rule:
properties.backup.geoRedundantBackup
property to the value 'Enabled'
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforPostgreSQL/flexibleServers\",\n \"apiVersion\": \"2022-01-20-preview\",\n \"name\": \"[parameters('serverName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_D16as\",\n \"tier\": \"GeneralPurpose\"\n },\n \"properties\": {\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"storage\": {\n \"storageSizeGB\": \"[parameters('StorageSizeGB')]\"\n },\n \"createMode\": \"Default\",\n \"version\": \"[parameters('postgresqlVersion')]\",\n \"backup\": {\n \"backupRetentionDays\": 7,\n \"geoRedundantBackup\": \"Enabled\"\n },\n \"highAvailability\": {\n \"mode\": \"Disabled\"\n }\n }\n}\n
To deploy Azure Database for PostgreSQL Single Servers that pass this rule:
properties.storageProfile.geoRedundantBackup
property to the value 'Enabled'
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.DBforPostgreSQL/servers\",\n \"apiVersion\": \"2017-12-01\",\n \"name\": \"[parameters('serverName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('skuName')]\",\n \"tier\": \"GeneralPurpose\",\n \"capacity\": \"[parameters('SkuCapacity')]\",\n \"size\": \"[format('{0}', parameters('skuSizeMB'))]\",\n \"family\": \"[parameters('skuFamily')]\"\n },\n \"properties\": {\n \"createMode\": \"Default\",\n \"version\": \"[parameters('postgresqlVersion')]\",\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"storageProfile\": {\n \"storageMB\": \"[parameters('skuSizeMB')]\",\n \"backupRetentionDays\": 7,\n \"geoRedundantBackup\": \"Enabled\"\n }\n }\n}\n
","tags":["Azure.PostgreSQL.GeoRedundantBackup","AZR-000326"]},{"location":"en/rules/Azure.PostgreSQL.GeoRedundantBackup/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Azure Database for PostgreSQL Flexible Servers that pass this rule:
properties.backup.geoRedundantBackup
property to the value 'Enabled'
.For example:
Azure Bicep snippetresource postgresqlDbServer 'Microsoft.DBforPostgreSQL/flexibleServers@2022-01-20-preview' = {\n name: serverName\n location: location\n sku: {\n name: 'Standard_D16as'\n tier: 'GeneralPurpose'\n }\n properties: {\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n storage: {\n storageSizeGB: StorageSizeGB\n }\n createMode: 'Default'\n version: postgresqlVersion\n backup: {\n backupRetentionDays: 7\n geoRedundantBackup: 'Enabled'\n }\n highAvailability: {\n mode: 'Disabled'\n }\n }\n}\n
To deploy Azure Database for PostgreSQL Single Servers that pass this rule:
properties.storageProfile.geoRedundantBackup
property to the value 'Enabled'
.For example:
Azure Bicep snippetresource postgresqlDbServer 'Microsoft.DBforPostgreSQL/servers@2017-12-01' = {\n name: serverName\n location: location\n sku: {\n name: skuName\n tier: 'GeneralPurpose'\n capacity: skuCapacity\n size: '${skuSizeMB}'\n family: skuFamily\n }\n properties: {\n createMode: 'Default'\n version: postgresqlVersion\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n storageProfile: {\n storageMB: SkuSizeMB\n backupRetentionDays: 7\n geoRedundantBackup: 'Enabled'\n }\n }\n}\n
","tags":["Azure.PostgreSQL.GeoRedundantBackup","AZR-000326"]},{"location":"en/rules/Azure.PostgreSQL.GeoRedundantBackup/#notes","title":"Notes","text":"This rule is applicable for both the Azure Database for PostgreSQL Flexible Server deployment model and the Azure Database for PostgreSQL Single Server deployment model.
For the Single Server deployment model, it runs only against 'General Purpose'
and 'Memory Optimized'
tiers. The 'Basic'
tier does not support geo-redundant backup storage.
Security \u00b7 Azure Database for PostgreSQL \u00b7 Rule \u00b7 2020_09 \u00b7 Critical
PostgreSQL DB servers should reject TLS versions older than 1.2.
","tags":["Azure.PostgreSQL.MinTLS","AZR-000148"]},{"location":"en/rules/Azure.PostgreSQL.MinTLS/#description","title":"Description","text":"The minimum version of TLS that PostgreSQL DB servers accept is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Azure lets you disable outdated protocols and require connections to use a minimum of TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 is accepted.
","tags":["Azure.PostgreSQL.MinTLS","AZR-000148"]},{"location":"en/rules/Azure.PostgreSQL.MinTLS/#recommendation","title":"Recommendation","text":"Consider configuring the minimum supported TLS version to be 1.2.
","tags":["Azure.PostgreSQL.MinTLS","AZR-000148"]},{"location":"en/rules/Azure.PostgreSQL.MinTLS/#links","title":"Links","text":"Operational Excellence \u00b7 Azure Database for PostgreSQL \u00b7 Rule \u00b7 2020_12 \u00b7 Awareness
Azure PostgreSQL DB server names should meet naming requirements.
","tags":["Azure.PostgreSQL.ServerName","AZR-000152"]},{"location":"en/rules/Azure.PostgreSQL.ServerName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for PostgreSQL DB server names are:
Consider using names that meet Azure PostgreSQL DB server naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.PostgreSQL.ServerName","AZR-000152"]},{"location":"en/rules/Azure.PostgreSQL.ServerName/#notes","title":"Notes","text":"This rule does not check if Azure PostgreSQL DB server names are unique.
","tags":["Azure.PostgreSQL.ServerName","AZR-000152"]},{"location":"en/rules/Azure.PostgreSQL.ServerName/#links","title":"Links","text":"Security \u00b7 Azure Database for PostgreSQL \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Enforce encrypted PostgreSQL connections.
","tags":["Azure.PostgreSQL.UseSSL","AZR-000147"]},{"location":"en/rules/Azure.PostgreSQL.UseSSL/#description","title":"Description","text":"Azure Database for PostgreSQL is configured to only accept encrypted connections by default. When the setting enforce SSL connections is disabled, encrypted and unencrypted connections are permitted. This does not indicate that unencrypted connections are being used.
Unencrypted communication to PostgreSQL server instances could allow disclosure of information to an untrusted party.
","tags":["Azure.PostgreSQL.UseSSL","AZR-000147"]},{"location":"en/rules/Azure.PostgreSQL.UseSSL/#recommendation","title":"Recommendation","text":"Azure Database for PostgreSQL should be configured to only accept encrypted connections. Unless explicitly required, consider enabling enforce SSL connections.
Also consider using Azure Policy to audit or enforce this configuration.
","tags":["Azure.PostgreSQL.UseSSL","AZR-000147"]},{"location":"en/rules/Azure.PostgreSQL.UseSSL/#links","title":"Links","text":"Operational Excellence \u00b7 Private Endpoint \u00b7 Rule \u00b7 2021_12 \u00b7 Awareness
Private Endpoint names should meet naming requirements.
","tags":["Azure.PrivateEndpoint.Name","AZR-000153"]},{"location":"en/rules/Azure.PrivateEndpoint.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Private Endpoint names are:
Consider using names that meet Private Endpoint naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.PrivateEndpoint.Name","AZR-000153"]},{"location":"en/rules/Azure.PrivateEndpoint.Name/#notes","title":"Notes","text":"This rule does not check if Private Endpoint names are unique.
","tags":["Azure.PrivateEndpoint.Name","AZR-000153"]},{"location":"en/rules/Azure.PrivateEndpoint.Name/#links","title":"Links","text":"Reliability \u00b7 Public IP address \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability.
","tags":["Azure.PublicIP.AvailabilityZone","AZR-000157"]},{"location":"en/rules/Azure.PublicIP.AvailabilityZone/#description","title":"Description","text":"Public IP addresses using availability zones improve reliability and ensure availability during failure scenarios affecting a data center within a region. A zone redundant Public IP address can spread across multiple availability zones, which ensures the Public IP address will continue running even if another zone has gone down. Furthermore, this ensures Public Standard Load balancer frontend IPs using a zone-redundant Public IP address can survive zone failure.
","tags":["Azure.PublicIP.AvailabilityZone","AZR-000157"]},{"location":"en/rules/Azure.PublicIP.AvailabilityZone/#recommendation","title":"Recommendation","text":"Consider using zone-redundant Public IP addresses deployed with Standard SKU.
","tags":["Azure.PublicIP.AvailabilityZone","AZR-000157"]},{"location":"en/rules/Azure.PublicIP.AvailabilityZone/#examples","title":"Examples","text":"","tags":["Azure.PublicIP.AvailabilityZone","AZR-000157"]},{"location":"en/rules/Azure.PublicIP.AvailabilityZone/#configure-with-azure-template","title":"Configure with Azure template","text":"To configure zone-redundancy for a Public IP address.
sku.name
to Standard
.zones
to [\"1\", \"2\", \"3\"]
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/publicIPAddresses\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard\",\n \"tier\": \"Regional\"\n },\n \"properties\": {\n \"publicIPAddressVersion\": \"IPv4\",\n \"publicIPAllocationMethod\": \"Static\",\n \"idleTimeoutInMinutes\": 4\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n}\n
","tags":["Azure.PublicIP.AvailabilityZone","AZR-000157"]},{"location":"en/rules/Azure.PublicIP.AvailabilityZone/#configure-with-bicep","title":"Configure with Bicep","text":"To configure zone-redundancy for a Public IP address.
sku.name
to Standard
.zones
to ['1', '2', '3']
.For example:
Azure Bicep snippetresource pip 'Microsoft.Network/publicIPAddresses@2023-05-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard'\n tier: 'Regional'\n }\n properties: {\n publicIPAddressVersion: 'IPv4'\n publicIPAllocationMethod: 'Static'\n idleTimeoutInMinutes: 4\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n}\n
","tags":["Azure.PublicIP.AvailabilityZone","AZR-000157"]},{"location":"en/rules/Azure.PublicIP.AvailabilityZone/#notes","title":"Notes","text":"This rule is not applicable for public IP addresses used for Azure Bastion. Azure Bastion does not currently support Availability Zones. Public IP addresses with the following tags are automatically excluded from this rule:
resource-usage
tag set to azure-bastion
.This rule fails when \"zones\"
is constrained to a single(zonal) zone, or set to null
, []
when there are supported availability zones for the given region.
This rule passes if no zones exist for a given region or \"zones\"
is set to [\"1\", \"2\", \"3\"]
.
Configure AZURE_PUBLICIP_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
to set additional availability zones that need to be supported which are not in the existing providers for namespace Microsoft.Network
and resource type publicIpAddresses
.
# YAML: The default AZURE_PUBLICIP_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST configuration option\nconfiguration:\n AZURE_PUBLICIP_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST: []\n
","tags":["Azure.PublicIP.AvailabilityZone","AZR-000157"]},{"location":"en/rules/Azure.PublicIP.AvailabilityZone/#links","title":"Links","text":"Operational Excellence \u00b7 Public IP address \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Public IP domain name labels should meet naming requirements.
","tags":["Azure.PublicIP.DNSLabel","AZR-000156"]},{"location":"en/rules/Azure.PublicIP.DNSLabel/#description","title":"Description","text":"When configuring Azure Public IP addresses domain name labels must meet naming requirements. The requirements for Public IP domain name labels are:
Consider using domain name labels that meet Public IP naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.PublicIP.DNSLabel","AZR-000156"]},{"location":"en/rules/Azure.PublicIP.DNSLabel/#notes","title":"Notes","text":"This rule does not check if Public IP domain name labels are unique.
","tags":["Azure.PublicIP.DNSLabel","AZR-000156"]},{"location":"en/rules/Azure.PublicIP.DNSLabel/#links","title":"Links","text":"Cost Optimization \u00b7 Public IP address \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Public IP addresses should be attached or cleaned up if not in use.
","tags":["Azure.PublicIP.IsAttached","AZR-000154"]},{"location":"en/rules/Azure.PublicIP.IsAttached/#description","title":"Description","text":"Unattached static Public IP address are charged when not in use.
","tags":["Azure.PublicIP.IsAttached","AZR-000154"]},{"location":"en/rules/Azure.PublicIP.IsAttached/#recommendation","title":"Recommendation","text":"Consider removing Public IP addresses that are no used.
","tags":["Azure.PublicIP.IsAttached","AZR-000154"]},{"location":"en/rules/Azure.PublicIP.IsAttached/#notes","title":"Notes","text":"This rule applies when analyzing public IP addresses (in-flight) running within Azure.
","tags":["Azure.PublicIP.IsAttached","AZR-000154"]},{"location":"en/rules/Azure.PublicIP.IsAttached/#links","title":"Links","text":"Operational Excellence \u00b7 Public IP address \u00b7 Rule \u00b7 2023_09 \u00b7 Important
Use the Standard SKU for Public IP addresses as the Basic SKU will be retired.
","tags":["Azure.PublicIP.MigrateStandard","AZR-000395"]},{"location":"en/rules/Azure.PublicIP.MigrateStandard/#description","title":"Description","text":"The Basic SKU for Public IP addresses will be retired on September 30, 2025. To avoid service disruption, migrate to Standard SKU for Public IP addresses.
The Standard SKU additionally offers security by default and supports redundancy.
","tags":["Azure.PublicIP.MigrateStandard","AZR-000395"]},{"location":"en/rules/Azure.PublicIP.MigrateStandard/#recommendation","title":"Recommendation","text":"Migrate Basic SKU for Public IP addresses to the Standard SKU before retirement to avoid service disruption.
","tags":["Azure.PublicIP.MigrateStandard","AZR-000395"]},{"location":"en/rules/Azure.PublicIP.MigrateStandard/#examples","title":"Examples","text":"","tags":["Azure.PublicIP.MigrateStandard","AZR-000395"]},{"location":"en/rules/Azure.PublicIP.MigrateStandard/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Public IP addresses that pass this rule:
sku.name
to Standard
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/publicIPAddresses\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard\",\n \"tier\": \"Regional\"\n },\n \"properties\": {\n \"publicIPAddressVersion\": \"IPv4\",\n \"publicIPAllocationMethod\": \"Static\",\n \"idleTimeoutInMinutes\": 4\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n}\n
","tags":["Azure.PublicIP.MigrateStandard","AZR-000395"]},{"location":"en/rules/Azure.PublicIP.MigrateStandard/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Public IP addresses that pass this rule:
sku.name
to Standard
.For example:
Azure Bicep snippetresource pip 'Microsoft.Network/publicIPAddresses@2023-05-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard'\n tier: 'Regional'\n }\n properties: {\n publicIPAddressVersion: 'IPv4'\n publicIPAllocationMethod: 'Static'\n idleTimeoutInMinutes: 4\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n}\n
","tags":["Azure.PublicIP.MigrateStandard","AZR-000395"]},{"location":"en/rules/Azure.PublicIP.MigrateStandard/#links","title":"Links","text":"Operational Excellence \u00b7 Public IP address \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Public IP names should meet naming requirements.
","tags":["Azure.PublicIP.Name","AZR-000155"]},{"location":"en/rules/Azure.PublicIP.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Public IP names are:
Consider using names that meet Public IP naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.PublicIP.Name","AZR-000155"]},{"location":"en/rules/Azure.PublicIP.Name/#examples","title":"Examples","text":"","tags":["Azure.PublicIP.Name","AZR-000155"]},{"location":"en/rules/Azure.PublicIP.Name/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy public IPs that pass this rule, consider:
minLength
and maxLength
constraint for the resource name parameter.uniqueString()
function to generate a unique name.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"name\": {\n \"type\": \"string\",\n \"minLength\": 1,\n \"maxLength\": 80,\n \"metadata\": {\n \"description\": \"The name of the resource.\"\n }\n },\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"The location resources will be deployed.\"\n }\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Network/publicIPAddresses\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard\",\n \"tier\": \"Regional\"\n },\n \"properties\": {\n \"publicIPAddressVersion\": \"IPv4\",\n \"publicIPAllocationMethod\": \"Static\",\n \"idleTimeoutInMinutes\": 4\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n }\n ]\n}\n
","tags":["Azure.PublicIP.Name","AZR-000155"]},{"location":"en/rules/Azure.PublicIP.Name/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy public IPs that pass this rule, consider:
minLength
and maxLength
constraint for the resource name parameter.uniqueString()
function to generate a unique name.For example:
Azure Bicep snippet@minLength(1)\n@maxLength(80)\n@sys.description('The name of the resource.')\nparam name string\n\n@sys.description('The location resources will be deployed.')\nparam location string = resourceGroup().location\n\nresource pip 'Microsoft.Network/publicIPAddresses@2023-05-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard'\n tier: 'Regional'\n }\n properties: {\n publicIPAddressVersion: 'IPv4'\n publicIPAllocationMethod: 'Static'\n idleTimeoutInMinutes: 4\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n}\n
","tags":["Azure.PublicIP.Name","AZR-000155"]},{"location":"en/rules/Azure.PublicIP.Name/#notes","title":"Notes","text":"This rule does not check if Public IP names are unique.
","tags":["Azure.PublicIP.Name","AZR-000155"]},{"location":"en/rules/Azure.PublicIP.Name/#links","title":"Links","text":"Reliability \u00b7 Public IP address \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Public IP addresses should be deployed with Standard SKU for production workloads.
","tags":["Azure.PublicIP.StandardSKU","AZR-000158"]},{"location":"en/rules/Azure.PublicIP.StandardSKU/#description","title":"Description","text":"Public IP addresses allow Internet resources to communicate inbound to Azure resources. Currently two SKUs are supported: Basic and Standard.
However, the Basic SKU for Public IP addresses will be retired on September 30, 2025.
The Standard SKU additionally offers security and redundancy improvements over the Basic SKU. Including:
Consider using Standard SKU for Public IP addresses deployed in production.
","tags":["Azure.PublicIP.StandardSKU","AZR-000158"]},{"location":"en/rules/Azure.PublicIP.StandardSKU/#examples","title":"Examples","text":"","tags":["Azure.PublicIP.StandardSKU","AZR-000158"]},{"location":"en/rules/Azure.PublicIP.StandardSKU/#configure-with-azure-template","title":"Configure with Azure template","text":"To configure Standard SKU for a Public IP address.
sku.name
to Standard
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/publicIPAddresses\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard\",\n \"tier\": \"Regional\"\n },\n \"properties\": {\n \"publicIPAddressVersion\": \"IPv4\",\n \"publicIPAllocationMethod\": \"Static\",\n \"idleTimeoutInMinutes\": 4\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n}\n
","tags":["Azure.PublicIP.StandardSKU","AZR-000158"]},{"location":"en/rules/Azure.PublicIP.StandardSKU/#configure-with-bicep","title":"Configure with Bicep","text":"To configure Standard SKU for a Public IP address.
sku.name
to Standard
.For example:
For example:
Azure Bicep snippetresource pip 'Microsoft.Network/publicIPAddresses@2023-05-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard'\n tier: 'Regional'\n }\n properties: {\n publicIPAddressVersion: 'IPv4'\n publicIPAllocationMethod: 'Static'\n idleTimeoutInMinutes: 4\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n}\n
","tags":["Azure.PublicIP.StandardSKU","AZR-000158"]},{"location":"en/rules/Azure.PublicIP.StandardSKU/#links","title":"Links","text":"Security \u00b7 Subscription \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Delegate access to manage Azure resources using role-based access control (RBAC).
","tags":["Azure.RBAC.CoAdministrator","AZR-000206"]},{"location":"en/rules/Azure.RBAC.CoAdministrator/#description","title":"Description","text":"Use of Co-administrator is intended to support management of resources deployed using the Classic deployment model. Resources deployed in the Resource Manager model do not require delegation of Co-administrators.
Azure RBAC provides greater flexibility and control providing over 100 built-in roles. Additionally RBAC works with advanced advanced security features like Privileged Identity Management (PIM).
","tags":["Azure.RBAC.CoAdministrator","AZR-000206"]},{"location":"en/rules/Azure.RBAC.CoAdministrator/#recommendation","title":"Recommendation","text":"Consider delegating access to manage Azure resources using RBAC instead of classic Co-administrator roles. Limit delegation of Co-administrator roles only to subscription that contain resources deployed in the Classic deployment model.
","tags":["Azure.RBAC.CoAdministrator","AZR-000206"]},{"location":"en/rules/Azure.RBAC.CoAdministrator/#links","title":"Links","text":"Security \u00b7 Subscription \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Limit Role-Base Access Control (RBAC) inheritance from Management Groups.
","tags":["Azure.RBAC.LimitMGDelegation","AZR-000205"]},{"location":"en/rules/Azure.RBAC.LimitMGDelegation/#description","title":"Description","text":"RBAC in Azure inherits from management group to subscription to resource group to resource. Management group RBAC assignments have broad impact.
","tags":["Azure.RBAC.LimitMGDelegation","AZR-000205"]},{"location":"en/rules/Azure.RBAC.LimitMGDelegation/#recommendation","title":"Recommendation","text":"Consider limiting the number of assignment inherited from Management Groups by scoping permission to individual Resource Group.
Azure Blueprints can be used to rollout standard RBAC assignments to common resources. Additionally RBAC assignments can be deployed using Azure Resource Manager templates.
","tags":["Azure.RBAC.LimitMGDelegation","AZR-000205"]},{"location":"en/rules/Azure.RBAC.LimitOwner/","title":"Limit use of subscription scoped Owner role","text":"Azure.RBAC.LimitOwnerAZR-000204ErrorSecurity \u00b7 Subscription \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Limit the number of subscription Owners.
","tags":["Azure.RBAC.LimitOwner","AZR-000204"]},{"location":"en/rules/Azure.RBAC.LimitOwner/#description","title":"Description","text":"Azure provides a flexible delegation model using Role-Base Access Control (RBAC). RBAC allows administrators to grant fine grained permissions using roles to Azure resources. Over 100 built-in roles exist, and custom roles can be created to perform specific tasks. Permissions can be scoped to management group, subscription, resource group or individual resources.
The Owner role provides the ability to create, delete, update and configure permissions for any resource. When assigned at the subscription scope, these permissions apply to the whole subscription and all resources in the subscription.
","tags":["Azure.RBAC.LimitOwner","AZR-000204"]},{"location":"en/rules/Azure.RBAC.LimitOwner/#recommendation","title":"Recommendation","text":"Consider limiting the number of subscription Owners by using a more specific role or scoping Owner permission to a Resource Group.
","tags":["Azure.RBAC.LimitOwner","AZR-000204"]},{"location":"en/rules/Azure.RBAC.LimitOwner/#links","title":"Links","text":"Security \u00b7 Subscription \u00b7 Rule \u00b7 2020_09 \u00b7 Important
Use just-in-time (JiT) activation of roles instead of persistent role assignment.
","tags":["Azure.RBAC.PIM","AZR-000208"]},{"location":"en/rules/Azure.RBAC.PIM/#description","title":"Description","text":"PIM helps manage the impact of identity compromise or misuse of permissions by reducing persistent access. With PIM, eligible identities can activate time-bound role assignments on an as needed basis (just-in-time). Activation typically occurs before a schedule change or management operation.
PIM is an Azure Active Directory (AD) feature included in Azure AD Premium P2.
","tags":["Azure.RBAC.PIM","AZR-000208"]},{"location":"en/rules/Azure.RBAC.PIM/#recommendation","title":"Recommendation","text":"Consider using Privileged Identity Management (PIM) to activate privileged roles on an as needed basis.
","tags":["Azure.RBAC.PIM","AZR-000208"]},{"location":"en/rules/Azure.RBAC.PIM/#links","title":"Links","text":"Security \u00b7 Subscription \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use groups for assigning permissions instead of individual user accounts.
","tags":["Azure.RBAC.UseGroups","AZR-000203"]},{"location":"en/rules/Azure.RBAC.UseGroups/#description","title":"Description","text":"Granting access with individual user accounts can bypass existing on-premises identity management tools and processes.
","tags":["Azure.RBAC.UseGroups","AZR-000203"]},{"location":"en/rules/Azure.RBAC.UseGroups/#recommendation","title":"Recommendation","text":"Consider using groups for assigning permissions instead of individual user accounts.
","tags":["Azure.RBAC.UseGroups","AZR-000203"]},{"location":"en/rules/Azure.RBAC.UseGroups/#links","title":"Links","text":"Security \u00b7 Subscription \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use RBAC assignments on resource groups instead of individual resources.
","tags":["Azure.RBAC.UseRGDelegation","AZR-000207"]},{"location":"en/rules/Azure.RBAC.UseRGDelegation/#description","title":"Description","text":"Azure provides a flexible delegation model using RBAC that allows administrators to grant fine grained permissions using roles to Azure resources. Permissions can be scoped to management group, subscription, resource group or individual resources.
","tags":["Azure.RBAC.UseRGDelegation","AZR-000207"]},{"location":"en/rules/Azure.RBAC.UseRGDelegation/#recommendation","title":"Recommendation","text":"Consider using RBAC assignments on resource groups instead of individual resources.
","tags":["Azure.RBAC.UseRGDelegation","AZR-000207"]},{"location":"en/rules/Azure.RBAC.UseRGDelegation/#links","title":"Links","text":"Security \u00b7 Recovery Services Vault \u00b7 Rule \u00b7 2023_09 \u00b7 Important
Ensure immutability is configured to protect backup data.
","tags":["Azure.RSV.Immutable","AZR-000397"]},{"location":"en/rules/Azure.RSV.Immutable/#description","title":"Description","text":"Immutability is supported for Recovery Services vaults by configuring the Immutable vault setting.
Immutable vault helps protecting backup data by blocking any operations that could lead to loss of recovery points. Additionally, locking the Immutable vault setting makes it irreversible to prevent any malicious actors from disabling immutability and deleting backups.
For example, an malicious attack may attempt to remove data or delete vaults to prevent recovery to a known good state.
The Immutable vault setting is not enabled per default.
","tags":["Azure.RSV.Immutable","AZR-000397"]},{"location":"en/rules/Azure.RSV.Immutable/#recommendation","title":"Recommendation","text":"Consider configuring immutability to protect backup data from accidental or malicious deletion.
","tags":["Azure.RSV.Immutable","AZR-000397"]},{"location":"en/rules/Azure.RSV.Immutable/#examples","title":"Examples","text":"","tags":["Azure.RSV.Immutable","AZR-000397"]},{"location":"en/rules/Azure.RSV.Immutable/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Recovery Services vaults that pass this rule:
properties.securitySettings.immutabilitySettings.state
to Unlocked
or Locked
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.RecoveryServices/vaults\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('vaultName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('skuName')]\",\n \"tier\": \"[parameters('skuTier')]\"\n },\n \"properties\": {\n \"securitySettings\": {\n \"immutabilitySettings\": {\n \"state\": \"Locked\"\n }\n }\n }\n}\n
","tags":["Azure.RSV.Immutable","AZR-000397"]},{"location":"en/rules/Azure.RSV.Immutable/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Recovery Services vaults that pass this rule:
properties.securitySettings.immutabilitySettings.state
to Unlocked
or Locked
.For example:
Azure Bicep snippetresource recoveryServicesVault 'Microsoft.RecoveryServices/vaults@2023-01-01' = {\n name: vaultName\n location: location\n sku: {\n name: skuName\n tier: skuTier\n }\n properties: {\n securitySettings: {\n immutabilitySettings: {\n state: 'Locked'\n }\n }\n }\n}\n
","tags":["Azure.RSV.Immutable","AZR-000397"]},{"location":"en/rules/Azure.RSV.Immutable/#notes","title":"Notes","text":"Note that immutability locking Locked
is irreversible, so ensure to take a well-informed decision when opting to lock. For example, for vaults containing production workloads consider using Locked
. For cases where you are creating and destroying backups and vaults on a regulary basis such as temporary environments consider Unlocked
.
Operational Excellence \u00b7 Recovery Services Vault \u00b7 Rule \u00b7 2022_12 \u00b7 Awareness
Recovery Services vaults should meet naming requirements.
","tags":["Azure.RSV.Name","AZR-000350"]},{"location":"en/rules/Azure.RSV.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Recovery Services vault names are:
Consider using names that meet Recovery Services vault naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.RSV.Name","AZR-000350"]},{"location":"en/rules/Azure.RSV.Name/#notes","title":"Notes","text":"This rule does not check if Recovery Services vault names are unique.
","tags":["Azure.RSV.Name","AZR-000350"]},{"location":"en/rules/Azure.RSV.Name/#links","title":"Links","text":"Reliability \u00b7 Recovery Services Vault \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Recovery Services Vaults (RSV) without replication alerts configured may be at risk.
","tags":["Azure.RSV.ReplicationAlert","AZR-000171"]},{"location":"en/rules/Azure.RSV.ReplicationAlert/#description","title":"Description","text":"Recovery Services Vaults (RSV) can be used to replicate virtual machines between Azure Regions. Alerts can be configured to send notifications when replication issues occur.
The replication alerts can be configured for:
Configure replication alerts for Recovery Service Vaults that are performing replication tasks.
","tags":["Azure.RSV.ReplicationAlert","AZR-000171"]},{"location":"en/rules/Azure.RSV.ReplicationAlert/#examples","title":"Examples","text":"","tags":["Azure.RSV.ReplicationAlert","AZR-000171"]},{"location":"en/rules/Azure.RSV.ReplicationAlert/#configure-with-azure-template","title":"Configure with Azure template","text":"By default a Recovery Services vaults does not have replication alerts setup. To define a replication alert via ARM templates either configure the sendToOwners
or CustomerEmailAddress
properties:
properties.sendToOwners
to Send
.properties.customEmailAddresses
to [ \"example@email.com\" ]
For example:
Azure Template snippet{\n \"type\": \"Microsoft.RecoveryServices/vaults/replicationAlertSettings\",\n \"apiVersion\": \"2021-08-01\",\n \"name\": \"replicationAlert\",\n \"properties\": {\n \"sendToOwners\": \"Send\",\n \"customEmailAddresses\": [\n \"example@email.com\"\n ],\n \"locale\": \"en-US\"\n }\n}\n
","tags":["Azure.RSV.ReplicationAlert","AZR-000171"]},{"location":"en/rules/Azure.RSV.ReplicationAlert/#configure-with-bicep","title":"Configure with Bicep","text":"By default a Recovery Services vaults does not have replication alerts setup. To define a replication alert via a Bicep either configure the sendToOwners
or CustomerEmailAddress
properties:
properties.sendToOwners
to Send
.properties.customEmailAddresses
to [ \"example@email.com\" ]
For example:
Azure Bicep snippetresource testRecoveryServices 'Microsoft.RecoveryServices/vaults/replicationAlertSettings@2021-08-01' = {\n name: 'replicationAlert'\n parent: resourceSymbolicName\n properties: {\n sendToOwners: 'Sender'\n customEmailAddresses: [\n 'example@email.com'\n ]\n locale: 'en-US'\n }\n}\n
","tags":["Azure.RSV.ReplicationAlert","AZR-000171"]},{"location":"en/rules/Azure.RSV.ReplicationAlert/#notes","title":"Notes","text":"With the locale
property you can define the locale for the email notification.
Reliability \u00b7 Recovery Services Vault \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk.
","tags":["Azure.RSV.StorageType","AZR-000170"]},{"location":"en/rules/Azure.RSV.StorageType/#description","title":"Description","text":"Recovery Services Vaults can be configured with several different durability options. Azure provides a number of geo-replicated options for storage including; Geo-redundant storage and read access geo-zone-redundant storage. The default storage type used will be Geo-redundant Geo-zone-redundant storage is only available in supported regions.
The following geo-replicated options are available for recovery services vaults:
GeoRedundant
ReadAccessGeoZoneRedundant
Consider using GeoRedundant for recovery services vaults that contain data.
","tags":["Azure.RSV.StorageType","AZR-000170"]},{"location":"en/rules/Azure.RSV.StorageType/#examples","title":"Examples","text":"","tags":["Azure.RSV.StorageType","AZR-000170"]},{"location":"en/rules/Azure.RSV.StorageType/#configure-with-azure-template","title":"Configure with Azure template","text":"The default storage type used by Recovery Services vaults is Geo-redundant. However if you're defining the backup config in an ARM template:
properties.storageType
to either GeoRedundant
or ReadAccessGeoZoneRedundant
. For example:{\n \"type\": \"Microsoft.RecoveryServices/vaults/backupconfig\",\n \"apiVersion\": \"2021-10-01\",\n \"name\": \"vaultconfig-a\",\n \"location\": \"australiaeast\",\n \"tags\": {},\n \"properties\": {\n \"storageType\": \"GeoRedundant\"\n }\n}\n
","tags":["Azure.RSV.StorageType","AZR-000170"]},{"location":"en/rules/Azure.RSV.StorageType/#configure-with-bicep","title":"Configure with Bicep","text":"The default storage type used by Recovery Services vaults is Geo-redundant. However if you're defining the backup config via Bicep:
properties.storageType
to either GeoRedundant
or ReadAccessGeoZoneRedundant
.For example:
Azure Bicep snippetresource testRecoveryServices 'Microsoft.RecoveryServices/vaults/backupconfig@2021-10-01' = {\n name: 'vaultconfig'\n location: 'string'\n parent: resourceSymbolicName\n properties: {\n storageType: 'GeoRedundant'\n }\n}\n
","tags":["Azure.RSV.StorageType","AZR-000170"]},{"location":"en/rules/Azure.RSV.StorageType/#links","title":"Links","text":"Reliability \u00b7 Azure Cache for Redis \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Premium Redis cache should be deployed with availability zones for high availability.
","tags":["Azure.Redis.AvailabilityZone","AZR-000161"]},{"location":"en/rules/Azure.Redis.AvailabilityZone/#description","title":"Description","text":"Redis Cache using availability zones improve reliability and ensure availability during failure scenarios affecting a data center within a region. Nodes in one availability zone are physically separated from nodes defined in another availability zone. By spreading node pools across multiple zones, nodes in one node pool will continue running even if another zone has gone down.
","tags":["Azure.Redis.AvailabilityZone","AZR-000161"]},{"location":"en/rules/Azure.Redis.AvailabilityZone/#recommendation","title":"Recommendation","text":"Consider using availability zones for Premium Redis Cache deployed in supported regions.
","tags":["Azure.Redis.AvailabilityZone","AZR-000161"]},{"location":"en/rules/Azure.Redis.AvailabilityZone/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed to Azure using pre-flight and in-flight data.
This rule fails when \"zones\"
is null
, []
or less than two zones are used when there are availability zones for the given region.
This rule fails when cache is not zone redundant(1, 2 and 3) when there are availability zones for the given region.
Configure AZURE_REDISCACHE_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
to set additional availability zones that need to be supported which are not in the existing providers for namespace Microsoft.Cache
and resource type Redis
.
# YAML: The default AZURE_REDISCACHE_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST configuration option\nconfiguration:\n AZURE_REDISCACHE_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST: []\n
","tags":["Azure.Redis.AvailabilityZone","AZR-000161"]},{"location":"en/rules/Azure.Redis.AvailabilityZone/#examples","title":"Examples","text":"","tags":["Azure.Redis.AvailabilityZone","AZR-000161"]},{"location":"en/rules/Azure.Redis.AvailabilityZone/#configure-with-azure-template","title":"Configure with Azure template","text":"To set availability zones for Premium SKU Redis Cache:
zones
to a minimum of two zones from [\"1\", \"2\", \"3\"]
.Properties.replicasPerMaster
to number of zones - 1, to ensure you have at least as many nodes as zones you are replicating to.Properties.sku.name
to Premium
.Properties.sku.family
to P
.Properties.sku.capacity
to one of [1, 2, 3, 4, 5]
, depending on the SKU you picked:P1
- 6 GBP2
- 13 GBP3
- 26 GBP4
- 53 GBP5
- 120 GBFor example:
Azure Template snippet{\n \"type\": \"Microsoft.Cache/redis\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"minimumTlsVersion\": \"1.2\",\n \"redisVersion\": \"latest\",\n \"sku\": {\n \"name\": \"Premium\",\n \"family\": \"P\",\n \"capacity\": 1\n },\n \"redisConfiguration\": {\n \"maxmemory-reserved\": \"615\"\n },\n \"enableNonSslPort\": false\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n}\n
","tags":["Azure.Redis.AvailabilityZone","AZR-000161"]},{"location":"en/rules/Azure.Redis.AvailabilityZone/#configure-with-bicep","title":"Configure with Bicep","text":"To set availability zones for Premium SKU Redis Cache:
zones
to a minimum of two zones from [\"1\", \"2\", \"3\"]
.Properties.replicasPerMaster
to number of zones - 1, to ensure you have at least as many nodes as zones you are replicating to.Properties.sku.name
to Premium
.Properties.sku.family
to P
.Properties.sku.capacity
to one of [1, 2, 3, 4, 5]
, depending on the SKU you picked:P1
- 6 GBP2
- 13 GBP3
- 26 GBP4
- 53 GBP5
- 120 GBFor example:
Azure Bicep snippetresource cache 'Microsoft.Cache/redis@2023-04-01' = {\n name: name\n location: location\n properties: {\n minimumTlsVersion: '1.2'\n redisVersion: 'latest'\n sku: {\n name: 'Premium'\n family: 'P'\n capacity: 1\n }\n redisConfiguration: {\n 'maxmemory-reserved': '615'\n }\n enableNonSslPort: false\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n}\n
","tags":["Azure.Redis.AvailabilityZone","AZR-000161"]},{"location":"en/rules/Azure.Redis.AvailabilityZone/#links","title":"Links","text":"Security \u00b7 Azure Cache for Redis \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Determine if there is an excessive number of permitted IP addresses for the Redis cache.
","tags":["Azure.Redis.FirewallIPRange","AZR-000300"]},{"location":"en/rules/Azure.Redis.FirewallIPRange/#description","title":"Description","text":"When using Azure Cache for Redis, injected into a VNET you are able to create firewall rules to limit access to the cache. Each firewall rules specifies a range of IP addresses that are allowed to access the cache.
If no firewall rules are set and public access is not disabled, then all IP addresses are allowed to access the cache. By default, the cache is configured to allow access from all IP addresses.
Consider using private endpoints to limit access to the cache. If this is not possible, use firewall rules to limit access to the cache. However, avoid using overly permissive firewall rules that are:
The Redis cache has greater than ten (10) public IP addresses that are permitted network access. Some rules may not be needed or can be reduced.
","tags":["Azure.Redis.FirewallIPRange","AZR-000300"]},{"location":"en/rules/Azure.Redis.FirewallIPRange/#examples","title":"Examples","text":"","tags":["Azure.Redis.FirewallIPRange","AZR-000300"]},{"location":"en/rules/Azure.Redis.FirewallIPRange/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy caches that pass this rule:
properties.startIP
property to the start of the IP address range.properties.endIP
property to the end of the IP address range.{\n \"type\": \"Microsoft.Cache/redis/firewallRules\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'allow-on-premises')]\",\n \"properties\": {\n \"startIP\": \"10.0.1.1\",\n \"endIP\": \"10.0.1.31\"\n },\n \"dependsOn\": [\n \"cache\"\n ]\n}\n
","tags":["Azure.Redis.FirewallIPRange","AZR-000300"]},{"location":"en/rules/Azure.Redis.FirewallIPRange/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy caches that pass this rule:
properties.startIP
property to the start of the IP address range.properties.endIP
property to the end of the IP address range.resource rule 'Microsoft.Cache/redis/firewallRules@2023-04-01' = {\n parent: cache\n name: 'allow-on-premises'\n properties: {\n startIP: '10.0.1.1'\n endIP: '10.0.1.31'\n }\n}\n
","tags":["Azure.Redis.FirewallIPRange","AZR-000300"]},{"location":"en/rules/Azure.Redis.FirewallIPRange/#notes","title":"Notes","text":"This rule is not applicable when Redis is configured to allow private connectivity by setting properties.publicNetworkAccess
to Disabled
. Firewall rules can be used with VNET injected caches, but not private endpoints.
Security \u00b7 Azure Cache for Redis \u00b7 Rule \u00b7 2022_09 \u00b7 Awareness
Determine if there is an excessive number of firewall rules for the Redis cache.
","tags":["Azure.Redis.FirewallRuleCount","AZR-000299"]},{"location":"en/rules/Azure.Redis.FirewallRuleCount/#description","title":"Description","text":"When using Azure Cache for Redis, injected into a VNET you are able to create firewall rules to limit access to the cache. Each firewall rules specifies a range of IP addresses that are allowed to access the cache.
If no firewall rules are set and public access is not disabled, then all IP addresses are allowed to access the cache. By default, the cache is configured to allow access from all IP addresses.
Consider using private endpoints to limit access to the cache. If this is not possible, use firewall rules to limit access to the cache. However, avoid using overly permissive firewall rules that are:
The Redis cache has more than ten (10) firewall rules. Some rules may not be needed.
","tags":["Azure.Redis.FirewallRuleCount","AZR-000299"]},{"location":"en/rules/Azure.Redis.FirewallRuleCount/#examples","title":"Examples","text":"","tags":["Azure.Redis.FirewallRuleCount","AZR-000299"]},{"location":"en/rules/Azure.Redis.FirewallRuleCount/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy caches that pass this rule:
properties.startIP
property to the start of the IP address range.properties.endIP
property to the end of the IP address range.{\n \"type\": \"Microsoft.Cache/redis/firewallRules\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'allow-on-premises')]\",\n \"properties\": {\n \"startIP\": \"10.0.1.1\",\n \"endIP\": \"10.0.1.31\"\n },\n \"dependsOn\": [\n \"cache\"\n ]\n}\n
","tags":["Azure.Redis.FirewallRuleCount","AZR-000299"]},{"location":"en/rules/Azure.Redis.FirewallRuleCount/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy caches that pass this rule:
properties.startIP
property to the start of the IP address range.properties.endIP
property to the end of the IP address range.resource rule 'Microsoft.Cache/redis/firewallRules@2023-04-01' = {\n parent: cache\n name: 'allow-on-premises'\n properties: {\n startIP: '10.0.1.1'\n endIP: '10.0.1.31'\n }\n}\n
","tags":["Azure.Redis.FirewallRuleCount","AZR-000299"]},{"location":"en/rules/Azure.Redis.FirewallRuleCount/#notes","title":"Notes","text":"This rule is not applicable when Redis is configured to allow private connectivity by setting properties.publicNetworkAccess
to Disabled
. Firewall rules can be used with VNet injected caches, but not private endpoints.
Performance Efficiency \u00b7 Azure Cache for Redis \u00b7 Rule \u00b7 2020_12 \u00b7 Important
Configure maxmemory-reserved
to reserve memory for non-cache operations.
Azure Cache for Redis supports configuration of the maxmemory-reserved
setting. The maxmemory-reserved
setting configures the amount of memory reserved for non-cache operations. Non-cache operations include background tasks, eviction, and compaction.
By reserving memory for these operations, you prevent Redis cache from using all available memory for cache. If enough memory is not reserved for these operations it can lead to performance degradation and instability.
Setting this value allows you to have a more consistent experience when your load varies. This value should be set higher for workloads that are write heavy.
When memory reserved by maxmemory-reserved
, it is unavailable for storage of cached data.
Consider configuring maxmemory-reserved
to at least 10% of available cache memory.
To deploy caches that pass this rule:
properties.redisConfiguration.maxmemory-reserved
property to at least 10% of the cache memory.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cache/redis\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"minimumTlsVersion\": \"1.2\",\n \"redisVersion\": \"latest\",\n \"sku\": {\n \"name\": \"Premium\",\n \"family\": \"P\",\n \"capacity\": 1\n },\n \"redisConfiguration\": {\n \"maxmemory-reserved\": \"615\"\n },\n \"enableNonSslPort\": false\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n}\n
","tags":["Azure.Redis.MaxMemoryReserved","AZR-000160"]},{"location":"en/rules/Azure.Redis.MaxMemoryReserved/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy caches that pass this rule:
properties.redisConfiguration.maxmemory-reserved
property to at least 10% of the cache memory.For example:
Azure Bicep snippetresource cache 'Microsoft.Cache/redis@2023-04-01' = {\n name: name\n location: location\n properties: {\n minimumTlsVersion: '1.2'\n redisVersion: 'latest'\n sku: {\n name: 'Premium'\n family: 'P'\n capacity: 1\n }\n redisConfiguration: {\n 'maxmemory-reserved': '615'\n }\n enableNonSslPort: false\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n}\n
","tags":["Azure.Redis.MaxMemoryReserved","AZR-000160"]},{"location":"en/rules/Azure.Redis.MaxMemoryReserved/#links","title":"Links","text":"Performance Efficiency \u00b7 Azure Cache for Redis \u00b7 Rule \u00b7 2020_12 \u00b7 Important
Use Azure Cache for Redis instances of at least Standard C1.
","tags":["Azure.Redis.MinSKU","AZR-000159"]},{"location":"en/rules/Azure.Redis.MinSKU/#description","title":"Description","text":"Azure Cache for Redis supports a range of different scale options. Basic tier or Standard C0 caches are not suitable for production workloads.
Consider using a minimum of a Standard C1 instance for production workloads.
","tags":["Azure.Redis.MinSKU","AZR-000159"]},{"location":"en/rules/Azure.Redis.MinSKU/#examples","title":"Examples","text":"","tags":["Azure.Redis.MinSKU","AZR-000159"]},{"location":"en/rules/Azure.Redis.MinSKU/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy caches that pass this rule:
properties.sku.name
property to Premium
or Standard
.properties.sku.family
property to P
or C
.properties.sku.capacity
property to a capacity valid for the SKU 1
or higher.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cache/redis\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"minimumTlsVersion\": \"1.2\",\n \"redisVersion\": \"latest\",\n \"sku\": {\n \"name\": \"Premium\",\n \"family\": \"P\",\n \"capacity\": 1\n },\n \"redisConfiguration\": {\n \"maxmemory-reserved\": \"615\"\n },\n \"enableNonSslPort\": false\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n}\n
","tags":["Azure.Redis.MinSKU","AZR-000159"]},{"location":"en/rules/Azure.Redis.MinSKU/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy caches that pass this rule:
properties.sku.name
property to Premium
or Standard
.properties.sku.family
property to P
or C
.properties.sku.capacity
property to a capacity valid for the SKU 1
or higher.For example:
Azure Bicep snippetresource cache 'Microsoft.Cache/redis@2023-04-01' = {\n name: name\n location: location\n properties: {\n minimumTlsVersion: '1.2'\n redisVersion: 'latest'\n sku: {\n name: 'Premium'\n family: 'P'\n capacity: 1\n }\n redisConfiguration: {\n 'maxmemory-reserved': '615'\n }\n enableNonSslPort: false\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n}\n
","tags":["Azure.Redis.MinSKU","AZR-000159"]},{"location":"en/rules/Azure.Redis.MinSKU/#links","title":"Links","text":"Security \u00b7 Azure Cache for Redis \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Redis Cache should reject TLS versions older than 1.2.
","tags":["Azure.Redis.MinTLS","AZR-000164"]},{"location":"en/rules/Azure.Redis.MinTLS/#description","title":"Description","text":"The minimum version of TLS that Redis Cache accepts is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Azure lets you disable outdated protocols and require connections to use a minimum of TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 is accepted.
","tags":["Azure.Redis.MinTLS","AZR-000164"]},{"location":"en/rules/Azure.Redis.MinTLS/#recommendation","title":"Recommendation","text":"Consider configuring the minimum supported TLS version to be 1.2. Support for TLS 1.0/ 1.1 version will be removed.
","tags":["Azure.Redis.MinTLS","AZR-000164"]},{"location":"en/rules/Azure.Redis.MinTLS/#examples","title":"Examples","text":"","tags":["Azure.Redis.MinTLS","AZR-000164"]},{"location":"en/rules/Azure.Redis.MinTLS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy caches that pass this rule:
properties.minimumTlsVersion
property to a minimum of 1.2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cache/redis\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"minimumTlsVersion\": \"1.2\",\n \"redisVersion\": \"latest\",\n \"sku\": {\n \"name\": \"Premium\",\n \"family\": \"P\",\n \"capacity\": 1\n },\n \"redisConfiguration\": {\n \"maxmemory-reserved\": \"615\"\n },\n \"enableNonSslPort\": false\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n}\n
","tags":["Azure.Redis.MinTLS","AZR-000164"]},{"location":"en/rules/Azure.Redis.MinTLS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy caches that pass this rule:
properties.minimumTlsVersion
property to a minimum of 1.2
.For example:
Azure Bicep snippetresource cache 'Microsoft.Cache/redis@2023-04-01' = {\n name: name\n location: location\n properties: {\n minimumTlsVersion: '1.2'\n redisVersion: 'latest'\n sku: {\n name: 'Premium'\n family: 'P'\n capacity: 1\n }\n redisConfiguration: {\n 'maxmemory-reserved': '615'\n }\n enableNonSslPort: false\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n}\n
","tags":["Azure.Redis.MinTLS","AZR-000164"]},{"location":"en/rules/Azure.Redis.MinTLS/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To deploy caches that pass this rule:
--set
parameter.For example:
Azure CLI snippetaz redis update -n '<name>' -g '<resource_group>' --set minimumTlsVersion=1.2\n
","tags":["Azure.Redis.MinTLS","AZR-000164"]},{"location":"en/rules/Azure.Redis.MinTLS/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To deploy caches that pass this rule:
-MinimumTlsVersion
parameter.For example:
Azure PowerShell snippetSet-AzRedisCache -Name '<name>' -MinimumTlsVersion '1.2'\n
","tags":["Azure.Redis.MinTLS","AZR-000164"]},{"location":"en/rules/Azure.Redis.MinTLS/#links","title":"Links","text":"Security \u00b7 Azure Cache for Redis \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Azure Cache for Redis should only accept secure connections.
","tags":["Azure.Redis.NonSslPort","AZR-000163"]},{"location":"en/rules/Azure.Redis.NonSslPort/#description","title":"Description","text":"Azure Cache for Redis can be configured to accept encrypted and unencrypted connections. By default, only encrypted communication is accepted. To accept unencrypted connections, the non-SSL port must be enabled. Using the non-SSL port for Azure Redis cache allows unencrypted communication to Redis cache.
Unencrypted communication can potentially allow disclosure of sensitive information to an untrusted party.
","tags":["Azure.Redis.NonSslPort","AZR-000163"]},{"location":"en/rules/Azure.Redis.NonSslPort/#recommendation","title":"Recommendation","text":"Consider only using secure connections to Redis cache by enabling SSL and disabling the non-SSL port.
","tags":["Azure.Redis.NonSslPort","AZR-000163"]},{"location":"en/rules/Azure.Redis.NonSslPort/#examples","title":"Examples","text":"","tags":["Azure.Redis.NonSslPort","AZR-000163"]},{"location":"en/rules/Azure.Redis.NonSslPort/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy caches that pass this rule:
properties.enableNonSslPort
property to false
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cache/redis\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"minimumTlsVersion\": \"1.2\",\n \"redisVersion\": \"latest\",\n \"sku\": {\n \"name\": \"Premium\",\n \"family\": \"P\",\n \"capacity\": 1\n },\n \"redisConfiguration\": {\n \"maxmemory-reserved\": \"615\"\n },\n \"enableNonSslPort\": false\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n}\n
","tags":["Azure.Redis.NonSslPort","AZR-000163"]},{"location":"en/rules/Azure.Redis.NonSslPort/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy caches that pass this rule:
properties.enableNonSslPort
property to false
.For example:
Azure Bicep snippetresource cache 'Microsoft.Cache/redis@2023-04-01' = {\n name: name\n location: location\n properties: {\n minimumTlsVersion: '1.2'\n redisVersion: 'latest'\n sku: {\n name: 'Premium'\n family: 'P'\n capacity: 1\n }\n redisConfiguration: {\n 'maxmemory-reserved': '615'\n }\n enableNonSslPort: false\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n}\n
","tags":["Azure.Redis.NonSslPort","AZR-000163"]},{"location":"en/rules/Azure.Redis.NonSslPort/#links","title":"Links","text":"Security \u00b7 Azure Cache for Redis \u00b7 Rule \u00b7 2022_03 \u00b7 Critical
Redis cache should disable public network access.
","tags":["Azure.Redis.PublicNetworkAccess","AZR-000165"]},{"location":"en/rules/Azure.Redis.PublicNetworkAccess/#description","title":"Description","text":"When using Azure Cache for Redis, you can configure the cache to be private or accessible from the public Internet. By default, the cache is configured to be accessible from the public Internet.
To limit network access to the cache you can use firewall rules or private endpoints. Using private endpoints with Azure Cache for Redis is the recommend approach for most scenarios.
Use private endpoints to improve the security posture of your Redis cache and reduce the risk of data breaches.
A private endpoint provides secure and private connectivity to Redis instances by:
If you are using VNET injection, it is recommended to migrate to private endpoints.
","tags":["Azure.Redis.PublicNetworkAccess","AZR-000165"]},{"location":"en/rules/Azure.Redis.PublicNetworkAccess/#recommendation","title":"Recommendation","text":"Consider using private endpoints to limit network connectivity to the cache and help reduce data exfiltration risks.
","tags":["Azure.Redis.PublicNetworkAccess","AZR-000165"]},{"location":"en/rules/Azure.Redis.PublicNetworkAccess/#examples","title":"Examples","text":"","tags":["Azure.Redis.PublicNetworkAccess","AZR-000165"]},{"location":"en/rules/Azure.Redis.PublicNetworkAccess/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy caches that pass this rule:
properties.publicNetworkAccess
property to Disabled
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cache/redis\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"minimumTlsVersion\": \"1.2\",\n \"redisVersion\": \"latest\",\n \"sku\": {\n \"name\": \"Premium\",\n \"family\": \"P\",\n \"capacity\": 1\n },\n \"redisConfiguration\": {\n \"maxmemory-reserved\": \"615\"\n },\n \"enableNonSslPort\": false,\n \"publicNetworkAccess\": \"Disabled\"\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n}\n
","tags":["Azure.Redis.PublicNetworkAccess","AZR-000165"]},{"location":"en/rules/Azure.Redis.PublicNetworkAccess/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy caches that pass this rule:
properties.publicNetworkAccess
property to Disabled
.For example:
Azure Bicep snippetresource cache 'Microsoft.Cache/redis@2023-04-01' = {\n name: name\n location: location\n properties: {\n minimumTlsVersion: '1.2'\n redisVersion: 'latest'\n sku: {\n name: 'Premium'\n family: 'P'\n capacity: 1\n }\n redisConfiguration: {\n 'maxmemory-reserved': '615'\n }\n enableNonSslPort: false\n publicNetworkAccess: 'Disabled'\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n}\n
","tags":["Azure.Redis.PublicNetworkAccess","AZR-000165"]},{"location":"en/rules/Azure.Redis.PublicNetworkAccess/#links","title":"Links","text":"Reliability \u00b7 Azure Cache for Redis \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Azure Cache for Redis should use the latest supported version of Redis.
","tags":["Azure.Redis.Version","AZR-000347"]},{"location":"en/rules/Azure.Redis.Version/#description","title":"Description","text":"Azure Cache for Redis supports Redis 6. Redis 6 brings new security features and better performance.
Version 4 for Azure Cache for Redis instances will be retired on June 30, 3023.
","tags":["Azure.Redis.Version","AZR-000347"]},{"location":"en/rules/Azure.Redis.Version/#recommendation","title":"Recommendation","text":"Consider upgrading Redis version for Azure Cache for Redis to the latest supported version (>=6.0).
","tags":["Azure.Redis.Version","AZR-000347"]},{"location":"en/rules/Azure.Redis.Version/#examples","title":"Examples","text":"","tags":["Azure.Redis.Version","AZR-000347"]},{"location":"en/rules/Azure.Redis.Version/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy caches that pass this rule:
properties.redisVersion
property to latest
or 6
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cache/redis\",\n \"apiVersion\": \"2023-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"minimumTlsVersion\": \"1.2\",\n \"redisVersion\": \"latest\",\n \"sku\": {\n \"name\": \"Premium\",\n \"family\": \"P\",\n \"capacity\": 1\n },\n \"redisConfiguration\": {\n \"maxmemory-reserved\": \"615\"\n },\n \"enableNonSslPort\": false\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ]\n}\n
","tags":["Azure.Redis.Version","AZR-000347"]},{"location":"en/rules/Azure.Redis.Version/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy caches that pass this rule:
properties.redisVersion
property to latest
or 6
.For example:
Azure Bicep snippetresource cache 'Microsoft.Cache/redis@2023-04-01' = {\n name: name\n location: location\n properties: {\n minimumTlsVersion: '1.2'\n redisVersion: 'latest'\n sku: {\n name: 'Premium'\n family: 'P'\n capacity: 1\n }\n redisConfiguration: {\n 'maxmemory-reserved': '615'\n }\n enableNonSslPort: false\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n}\n
","tags":["Azure.Redis.Version","AZR-000347"]},{"location":"en/rules/Azure.Redis.Version/#notes","title":"Notes","text":"This rule is only applicable for Azure Cache for Redis (OSS Redis) offering.
","tags":["Azure.Redis.Version","AZR-000347"]},{"location":"en/rules/Azure.Redis.Version/#links","title":"Links","text":"Security \u00b7 Azure Cache for Redis Enterprise \u00b7 Rule \u00b7 2022_09 \u00b7 Critical
Redis Cache should reject TLS versions older than 1.2.
","tags":["Azure.RedisEnterprise.MinTLS","AZR-000301"]},{"location":"en/rules/Azure.RedisEnterprise.MinTLS/#description","title":"Description","text":"The minimum version of TLS that Redis Cache accepts is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Azure lets you disable outdated protocols and require connections to use a minimum of TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 is accepted.
","tags":["Azure.RedisEnterprise.MinTLS","AZR-000301"]},{"location":"en/rules/Azure.RedisEnterprise.MinTLS/#recommendation","title":"Recommendation","text":"Consider configuring the minimum supported TLS version to be 1.2. Support for TLS 1.0/ 1.1 version will be removed.
","tags":["Azure.RedisEnterprise.MinTLS","AZR-000301"]},{"location":"en/rules/Azure.RedisEnterprise.MinTLS/#examples","title":"Examples","text":"","tags":["Azure.RedisEnterprise.MinTLS","AZR-000301"]},{"location":"en/rules/Azure.RedisEnterprise.MinTLS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy caches that pass this rule:
properties.minimumTlsVersion
property to 1.2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Cache/redisEnterprise\",\n \"apiVersion\": \"2022-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Enterprise_E10\"\n },\n \"properties\": {\n \"minimumTlsVersion\": \"1.2\"\n }\n}\n
","tags":["Azure.RedisEnterprise.MinTLS","AZR-000301"]},{"location":"en/rules/Azure.RedisEnterprise.MinTLS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy caches that pass this rule:
properties.minimumTlsVersion
property to 1.2
.For example:
Azure Bicep snippetresource cache 'Microsoft.Cache/redisEnterprise@2022-01-01' = {\n name: name\n location: location\n sku: {\n name: 'Enterprise_E10'\n }\n properties: {\n minimumTlsVersion: '1.2'\n }\n}\n
","tags":["Azure.RedisEnterprise.MinTLS","AZR-000301"]},{"location":"en/rules/Azure.RedisEnterprise.MinTLS/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To deploy caches that pass this rule:
--set
parameter.For example:
Azure CLI snippetaz redis update -n '<name>' -g '<resource_group>' --set minimumTlsVersion=1.2\n
","tags":["Azure.RedisEnterprise.MinTLS","AZR-000301"]},{"location":"en/rules/Azure.RedisEnterprise.MinTLS/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To deploy caches that pass this rule:
-MinimumTlsVersion
parameter.For example:
Azure PowerShell snippetSet-AzRedisCache -Name '<name>' -MinimumTlsVersion '1.2'\n
","tags":["Azure.RedisEnterprise.MinTLS","AZR-000301"]},{"location":"en/rules/Azure.RedisEnterprise.MinTLS/#links","title":"Links","text":"Reliability \u00b7 Azure Cache for Redis Enterprise \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Enterprise Redis cache should be zone-redundant for high availability.
","tags":["Azure.RedisEnterprise.Zones","AZR-000162"]},{"location":"en/rules/Azure.RedisEnterprise.Zones/#description","title":"Description","text":"Redis Cache using availability zones improve reliability and ensure availability during failure scenarios affecting a data center within a region. Nodes in one availability zone are physically separated from nodes defined in another availability zone. By spreading node pools across multiple zones, nodes in one node pool will continue running even if another zone has gone down.
","tags":["Azure.RedisEnterprise.Zones","AZR-000162"]},{"location":"en/rules/Azure.RedisEnterprise.Zones/#recommendation","title":"Recommendation","text":"Consider using availability zones for Enterprise Redis Cache deployed in supported regions.
","tags":["Azure.RedisEnterprise.Zones","AZR-000162"]},{"location":"en/rules/Azure.RedisEnterprise.Zones/#notes","title":"Notes","text":"This rule fails when cache is not zone redundant(1, 2 and 3) when there are availability zones for the given region.
Configure AZURE_REDISENTERPRISECACHE_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
to set additional availability zones that need to be supported which are not in the existing providers for namespace Microsoft.Cache
and resource type redisEnterprise
.
# YAML: The default AZURE_REDISENTERPRISECACHE_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST configuration option\nconfiguration:\n AZURE_REDISENTERPRISECACHE_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST: []\n
","tags":["Azure.RedisEnterprise.Zones","AZR-000162"]},{"location":"en/rules/Azure.RedisEnterprise.Zones/#examples","title":"Examples","text":"","tags":["Azure.RedisEnterprise.Zones","AZR-000162"]},{"location":"en/rules/Azure.RedisEnterprise.Zones/#configure-with-azure-template","title":"Configure with Azure template","text":"To set availability zones for Enterprise SKU Redis Cache:
zones
to [\"1\", \"2\", \"3\"]
or zone-redundancy.Properties.sku.name
to one of:Enterprise_E10
- 12 GBEnterprise_E20
- 25 GBEnterprise_E50
- 50 GBEnterprise_E100
- 100 GBEnterpriseFlash_F300
- 345 GBEnterpriseFlash_F700
- 715 GBEnterpriseFlash_F1500
- 1455 GBProperties.sku.capacity
to:[2, 4, 6, 8, 10]
if using Enterprise_E10
, Enterprise_E20
, Enterprise_E50
or Enterprise_E100
.3
or 9
if using EnterpriseFlash_F300
, EnterpriseFlash_F700
, EnterpriseFlash_F1500
.For example:
Azure Template snippet{\n \"name\": \"testrediscache\",\n \"type\": \"Microsoft.Cache/redisEnterprise\",\n \"apiVersion\": \"2021-02-01-preview\",\n \"properties\": {},\n \"location\": \"australiaeast\",\n \"dependsOn\": [],\n \"sku\": {\n \"name\": \"EnterpriseFlash_F700\",\n \"capacity\": 3\n },\n \"zones\": [\n \"1\",\n \"2\",\n \"3\"\n ],\n \"tags\": {},\n \"resources\": [\n {\n \"name\": \"testrediscache/default\",\n \"type\": \"Microsoft.Cache/redisEnterprise/databases\",\n \"apiVersion\": \"2021-02-01-preview\",\n \"properties\": {\n \"clientProtocol\": \"Encrypted\",\n \"evictionPolicy\": \"NoEviction\",\n \"clusteringPolicy\": \"OSSCluster\",\n \"persistence\": {\n \"aofEnabled\": false,\n \"rdbEnabled\": false\n }\n },\n \"dependsOn\": [\n \"Microsoft.Cache/redisEnterprise/testrediscache\"\n ],\n \"tags\": {}\n }\n ]\n}\n
","tags":["Azure.RedisEnterprise.Zones","AZR-000162"]},{"location":"en/rules/Azure.RedisEnterprise.Zones/#configure-with-bicep","title":"Configure with Bicep","text":"To set availability zones for Enterprise SKU Redis Cache:
zones
to [\"1\", \"2\", \"3\"]
or zone-redundancy.Properties.sku.name
to one of:Enterprise_E10
- 12 GBEnterprise_E20
- 25 GBEnterprise_E50
- 50 GBEnterprise_E100
- 100 GBEnterpriseFlash_F300
- 345 GBEnterpriseFlash_F700
- 715 GBEnterpriseFlash_F1500
- 1455 GBProperties.sku.capacity
to:[2, 4, 6, 8, 10]
if using Enterprise_E10
, Enterprise_E20
, Enterprise_E50
or Enterprise_E100
.3
or 9
if using EnterpriseFlash_F300
, EnterpriseFlash_F700
, EnterpriseFlash_F1500
.For example:
Azure Bicep snippetresource testrediscache 'Microsoft.Cache/redisEnterprise@2021-02-01-preview' = {\n name: 'testrediscache'\n properties: {}\n location: 'australiaeast'\n sku: {\n name: 'EnterpriseFlash_F700'\n capacity: 3\n }\n zones: [\n '1'\n '2'\n '3'\n ]\n tags: {}\n dependsOn: []\n}\n\nresource testrediscache_default 'Microsoft.Cache/redisEnterprise/databases@2021-02-01-preview' = {\n parent: testrediscache\n name: 'default'\n properties: {\n clientProtocol: 'Encrypted'\n evictionPolicy: 'NoEviction'\n clusteringPolicy: 'OSSCluster'\n persistence: {\n aofEnabled: false\n rdbEnabled: false\n }\n }\n tags: {}\n}\n
","tags":["Azure.RedisEnterprise.Zones","AZR-000162"]},{"location":"en/rules/Azure.RedisEnterprise.Zones/#links","title":"Links","text":"Security \u00b7 All resources \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Resources should be deployed to allowed regions.
","tags":["Azure.Resource.AllowedRegions","AZR-000167"]},{"location":"en/rules/Azure.Resource.AllowedRegions/#description","title":"Description","text":"Azure supports deployment to many locations around the world called regions. Many organizations have requirements that limit where data can be stored or processed. This is commonly known as data residency.
Most Azure resources must be deployed to a specific region. To align with your organizational requirements, you may choose to limit the regions that resources can be deployed to.
Some resources, particularly those related to preview services or features, may not be available in all regions.
","tags":["Azure.Resource.AllowedRegions","AZR-000167"]},{"location":"en/rules/Azure.Resource.AllowedRegions/#recommendation","title":"Recommendation","text":"Consider deploying resources to allowed regions to align with your organizational requirements. Also consider using Azure Policy to enforce allowed regions at runtime.
","tags":["Azure.Resource.AllowedRegions","AZR-000167"]},{"location":"en/rules/Azure.Resource.AllowedRegions/#examples","title":"Examples","text":"","tags":["Azure.Resource.AllowedRegions","AZR-000167"]},{"location":"en/rules/Azure.Resource.AllowedRegions/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy resources that pass this rule:
location
property to an allowed region. ORFor example:
Azure Template snippet{\n \"type\": \"Microsoft.Storage/storageAccounts\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_GRS\"\n },\n \"kind\": \"StorageV2\",\n \"properties\": {\n \"allowBlobPublicAccess\": false,\n \"supportsHttpsTrafficOnly\": true,\n \"minimumTlsVersion\": \"TLS1_2\",\n \"accessTier\": \"Hot\",\n \"allowSharedKeyAccess\": false,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n }\n }\n}\n
","tags":["Azure.Resource.AllowedRegions","AZR-000167"]},{"location":"en/rules/Azure.Resource.AllowedRegions/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy resources that pass this rule:
location
property to an allowed region. ORFor example:
Azure Bicep snippet@sys.description('The location resources will be deployed.')\nparam location string = resourceGroup().location\n\nresource storageAccount 'Microsoft.Storage/storageAccounts@2023-01-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard_GRS'\n }\n kind: 'StorageV2'\n properties: {\n allowBlobPublicAccess: false\n supportsHttpsTrafficOnly: true\n minimumTlsVersion: 'TLS1_2'\n accessTier: 'Hot'\n allowSharedKeyAccess: false\n networkAcls: {\n defaultAction: 'Deny'\n }\n }\n}\n
","tags":["Azure.Resource.AllowedRegions","AZR-000167"]},{"location":"en/rules/Azure.Resource.AllowedRegions/#notes","title":"Notes","text":"This rule requires one or more allowed regions to be configured. By default, all regions are allowed.
","tags":["Azure.Resource.AllowedRegions","AZR-000167"]},{"location":"en/rules/Azure.Resource.AllowedRegions/#rule-configuration","title":"Rule configuration","text":"AZURE_RESOURCE_ALLOWED_LOCATIONS
To configure this rule set the AZURE_RESOURCE_ALLOWED_LOCATIONS
configuration value to a set of allowed regions.
For example:
configuration:\n AZURE_RESOURCE_ALLOWED_LOCATIONS:\n - australiaeast\n - australiasoutheast\n
If you configure this AZURE_RESOURCE_ALLOWED_LOCATIONS
configuration value, also consider setting AZURE_RESOURCE_GROUP
the configuration value to when resources use the location of the resource group.
For example:
configuration:\n AZURE_RESOURCE_GROUP:\n location: australiaeast\n
","tags":["Azure.Resource.AllowedRegions","AZR-000167"]},{"location":"en/rules/Azure.Resource.AllowedRegions/#links","title":"Links","text":"Cost Optimization \u00b7 All resources \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Azure resources should be tagged using a standard convention.
","tags":["Azure.Resource.UseTags","AZR-000166"]},{"location":"en/rules/Azure.Resource.UseTags/#description","title":"Description","text":"Azure Resource Manager (ARM) supports a flexible tagging model that allows each resource to be tagged. Tags are additional metadata that improves identification of resources and aids lifecycle management.
Azure stores tags as name/ value pairs such as environment = production
or costCode = 349921
.
A well defined tagging approach improves the management, billing, and automation operations of resources. When planning tags, identify information that is meaningful to business and technical staff.
Azure provides several built-in policies to managed tags. Using these policies help enforce a tagging standard can reduce overall management Resource tags can be inherited from subscriptions or resource groups using Azure Policy.
","tags":["Azure.Resource.UseTags","AZR-000166"]},{"location":"en/rules/Azure.Resource.UseTags/#recommendation","title":"Recommendation","text":"Consider tagging resources using a standard convention. Identify mandatory and optional tags then tag all resources and resource groups using this standard.
Also consider using Azure Policy to enforce mandatory tags.
","tags":["Azure.Resource.UseTags","AZR-000166"]},{"location":"en/rules/Azure.Resource.UseTags/#examples","title":"Examples","text":"","tags":["Azure.Resource.UseTags","AZR-000166"]},{"location":"en/rules/Azure.Resource.UseTags/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy resource that pass this rule:
tags
property tags that align to your tagging standard.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Resources/resourceGroups\",\n \"apiVersion\": \"2022-09-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"tags\": {\n \"environment\": \"production\",\n \"costCode\": \"349921\"\n }\n}\n
","tags":["Azure.Resource.UseTags","AZR-000166"]},{"location":"en/rules/Azure.Resource.UseTags/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy resource that pass this rule:
tags
property tags that align to your tagging standard.For example:
Azure Bicep snippetresource rg 'Microsoft.Resources/resourceGroups@2022-09-01' = {\n name: name\n location: location\n tags: {\n environment: 'production'\n costCode: '349921'\n }\n}\n
","tags":["Azure.Resource.UseTags","AZR-000166"]},{"location":"en/rules/Azure.Resource.UseTags/#notes","title":"Notes","text":"Azure Policy includes several built-in policies to enforce tagging such as:
If you find resources that incorrectly report they should be tagged, please let us know by opening an issue.
","tags":["Azure.Resource.UseTags","AZR-000166"]},{"location":"en/rules/Azure.Resource.UseTags/#links","title":"Links","text":"Operational Excellence \u00b7 Resource Group \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Resource Group names should meet naming requirements.
","tags":["Azure.ResourceGroup.Name","AZR-000168"]},{"location":"en/rules/Azure.ResourceGroup.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Resource Group names are:
Consider using names that meet Resource Group naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.ResourceGroup.Name","AZR-000168"]},{"location":"en/rules/Azure.ResourceGroup.Name/#notes","title":"Notes","text":"This rule does not check if Resource Group names are unique.
","tags":["Azure.ResourceGroup.Name","AZR-000168"]},{"location":"en/rules/Azure.ResourceGroup.Name/#links","title":"Links","text":"Operational Excellence \u00b7 Route table \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Route table names should meet naming requirements.
","tags":["Azure.Route.Name","AZR-000169"]},{"location":"en/rules/Azure.Route.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Route table names are:
Consider using names that meet Route table naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.Route.Name","AZR-000169"]},{"location":"en/rules/Azure.Route.Name/#notes","title":"Notes","text":"This rule does not check if Route table names are unique.
","tags":["Azure.Route.Name","AZR-000169"]},{"location":"en/rules/Azure.Route.Name/#links","title":"Links","text":"Security \u00b7 SQL Database \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Use Entra ID authentication with Azure SQL databases.
","tags":["Azure.SQL.AAD","AZR-000188"]},{"location":"en/rules/Azure.SQL.AAD/#description","title":"Description","text":"Azure SQL Database offer two authentication models, Entra ID (previously known as Azure AD) and SQL authentication. Entra ID authentication supports centralized identity management in addition to modern password protections. Some of the benefits of Entra ID authentication over SQL authentication including:
It is also possible to disable SQL authentication entirely and only use Entra ID authentication.
","tags":["Azure.SQL.AAD","AZR-000188"]},{"location":"en/rules/Azure.SQL.AAD/#recommendation","title":"Recommendation","text":"Consider using Entra ID authentication with SQL databases. Additionally, consider disabling SQL authentication.
","tags":["Azure.SQL.AAD","AZR-000188"]},{"location":"en/rules/Azure.SQL.AAD/#examples","title":"Examples","text":"","tags":["Azure.SQL.AAD","AZR-000188"]},{"location":"en/rules/Azure.SQL.AAD/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy logical SQL Servers that pass this rule:
properties.administrators.administratorType
to ActiveDirectory
.properties.administrators.login
to the administrator login object name.properties.administrators.sid
to the object ID GUID of the administrator user, group, or application.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Sql/servers\",\n \"apiVersion\": \"2022-11-01-preview\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"publicNetworkAccess\": \"Disabled\",\n \"minimalTlsVersion\": \"1.2\",\n \"administrators\": {\n \"azureADOnlyAuthentication\": true,\n \"administratorType\": \"ActiveDirectory\",\n \"login\": \"[parameters('adminLogin')]\",\n \"principalType\": \"Group\",\n \"sid\": \"[parameters('adminPrincipalId')]\",\n \"tenantId\": \"[tenant().tenantId]\"\n }\n }\n}\n
Alternatively, you can configure the Microsoft.Sql/servers/administrators
sub-resource. To deploy Microsoft.Sql/servers/administrators
sub-resources that pass this rule:
properties.administratorType
to ActiveDirectory
.properties.login
to the administrator login object name.properties.sid
to the object ID GUID of the administrator user, group, or application.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Sql/servers/administrators\",\n \"apiVersion\": \"2022-02-01-preview\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'ActiveDirectory')]\",\n \"properties\": {\n \"administratorType\": \"ActiveDirectory\",\n \"login\": \"[parameters('adminLogin')]\",\n \"sid\": \"[parameters('adminPrincipalId')]\"\n },\n \"dependsOn\": [\n \"server\"\n ]\n}\n
","tags":["Azure.SQL.AAD","AZR-000188"]},{"location":"en/rules/Azure.SQL.AAD/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy logical SQL Servers that pass this rule:
properties.administrators.administratorType
to ActiveDirectory
.properties.administrators.login
to the administrator login object name.properties.administrators.sid
to the object ID GUID of the administrator user, group, or application.For example:
Azure Bicep snippetresource server 'Microsoft.Sql/servers@2022-11-01-preview' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n publicNetworkAccess: 'Disabled'\n minimalTlsVersion: '1.2'\n administrators: {\n azureADOnlyAuthentication: true\n administratorType: 'ActiveDirectory'\n login: adminLogin\n principalType: 'Group'\n sid: adminPrincipalId\n tenantId: tenant().tenantId\n }\n }\n}\n
Alternatively, you can configure the Microsoft.Sql/servers/administrators
sub-resource. To deploy Microsoft.Sql/servers/administrators
sub-resources that pass this rule:
properties.administratorType
to ActiveDirectory
.properties.login
to the administrator login object name.properties.sid
to the object ID GUID of the administrator user, group, or application.For example:
Azure Bicep snippetresource sqlAdministrator 'Microsoft.Sql/servers/administrators@2022-02-01-preview' = {\n parent: server\n name: 'ActiveDirectory'\n properties: {\n administratorType: 'ActiveDirectory'\n login: adminLogin\n sid: adminPrincipalId\n }\n}\n
","tags":["Azure.SQL.AAD","AZR-000188"]},{"location":"en/rules/Azure.SQL.AAD/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz sql server ad-admin create -s '<server_name>' -g '<resource_group>' -u '<user_name>' -i '<object_id>'\n
","tags":["Azure.SQL.AAD","AZR-000188"]},{"location":"en/rules/Azure.SQL.AAD/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetSet-AzSqlServerActiveDirectoryAdministrator -ResourceGroupName '<resource_group>' -ServerName '<server_name>' -DisplayName '<user_name>'\n
","tags":["Azure.SQL.AAD","AZR-000188"]},{"location":"en/rules/Azure.SQL.AAD/#notes","title":"Notes","text":"In newer API versions the properties.administrators
property can be configured. Entra ID authentication can also be configured using the Microsoft.Sql/servers/administrators
sub-resource.
If both the properties.administrators
property and Microsoft.Sql/servers/administrators
are set, the sub-resource will override the property.
Security \u00b7 SQL Database \u00b7 Rule \u00b7 2023_03 \u00b7 Important
Ensure Azure AD-only authentication is enabled with Azure SQL Database.
","tags":["Azure.SQL.AADOnly","AZR-000369"]},{"location":"en/rules/Azure.SQL.AADOnly/#description","title":"Description","text":"Azure SQL Database supports authentication with SQL logins and Azure AD authentication. By default, authentication with SQL logins is enabled. SQL logins are unable to provide sufficient protection for identities.
Azure AD authentication provides:
Additionally you can disable SQL authentication entirely, by enabling Azure AD-only authentication.
Some features may have limitations when using Azure AD-only authentication is enabled, including:
Continue reading Limitations for Azure AD-only authentication in SQL Database.
","tags":["Azure.SQL.AADOnly","AZR-000369"]},{"location":"en/rules/Azure.SQL.AADOnly/#recommendation","title":"Recommendation","text":"Consider using Azure AD-only authentication. Also consider using Azure Policy for Azure AD-only authentication with SQL Database.
","tags":["Azure.SQL.AADOnly","AZR-000369"]},{"location":"en/rules/Azure.SQL.AADOnly/#examples","title":"Examples","text":"Azure AD-only authentication can be enabled in two different ways.
","tags":["Azure.SQL.AADOnly","AZR-000369"]},{"location":"en/rules/Azure.SQL.AADOnly/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy SQL Logical Servers that pass this rule:
properties.administrators.azureADOnlyAuthentication
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Sql/servers\",\n \"apiVersion\": \"2022-05-01-preview\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\",\n \"userAssignedIdentities\": {}\n },\n \"properties\": {\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"administrators\": {\n \"administratorType\": \"ActiveDirectory\",\n \"azureADOnlyAuthentication\": true,\n \"login\": \"[parameters('login')]\",\n \"principalType\": \"[parameters('principalType')]\",\n \"sid\": \"[parameters('sid')]\",\n \"tenantId\": \"[parameters('tenantId')]\"\n }\n }\n}\n
Alternatively, you can configure the Microsoft.Sql/servers/azureADOnlyAuthentications
sub-resource. To deploy Microsoft.Sql/servers/azureADOnlyAuthentications
sub-resources that pass this rule:
properties.azureADOnlyAuthentication
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Sql/servers/azureADOnlyAuthentications\",\n \"apiVersion\": \"2022-05-01-preview\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'Default')]\",\n \"properties\": {\n \"azureADOnlyAuthentication\": true\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Sql/servers', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.SQL.AADOnly","AZR-000369"]},{"location":"en/rules/Azure.SQL.AADOnly/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy SQL Logical Servers that pass this rule:
properties.administrators.azureADOnlyAuthentication
property to true
.For example:
Azure Bicep snippetresource logicalServer 'Microsoft.Sql/servers@2022-05-01-preview' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n userAssignedIdentities: {}\n }\n properties: {\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n administrators: {\n administratorType: 'ActiveDirectory'\n azureADOnlyAuthentication: true\n login: login\n principalType: principalType\n sid: sid\n tenantId: tenantId\n }\n }\n}\n
Alternatively, you can configure the Microsoft.Sql/servers/azureADOnlyAuthentications
sub-resource. To deploy Microsoft.Sql/servers/azureADOnlyAuthentications
sub-resources that pass this rule:
properties.azureADOnlyAuthentication
property to true
.For example:
Azure Bicep snippetresource aadOnly 'Microsoft.Sql/servers/azureADOnlyAuthentications@2022-05-01-preview' = {\n name: 'Default'\n parent: logicalServer\n properties: {\n azureADOnlyAuthentication: true\n }\n}\n
","tags":["Azure.SQL.AADOnly","AZR-000369"]},{"location":"en/rules/Azure.SQL.AADOnly/#notes","title":"Notes","text":"The Azure AD admin must be set before enabling Azure AD-only authentication. A managed identity is required if an Azure AD service principal (Azure AD application) oversees creating and managing Azure AD users, groups, or applications in the logical server.
","tags":["Azure.SQL.AADOnly","AZR-000369"]},{"location":"en/rules/Azure.SQL.AADOnly/#links","title":"Links","text":"Security \u00b7 SQL Database \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Determine if access from Azure services is required.
","tags":["Azure.SQL.AllowAzureAccess","AZR-000184"]},{"location":"en/rules/Azure.SQL.AllowAzureAccess/#description","title":"Description","text":"Allow access to Azure services, permits any Azure service network based access to databases. Network based access it not limited to a single customer, all Azure IP addresses are permitted. Network access can also be allowed/ blocked on individual databases, which takes precedence over server firewall rules.
If network based access is permitted, authentication is still required.
Enabling access from Azure Services is useful in certain cases for on demand PaaS workloads where configuring a stable IP address is not possible. For example Azure Functions, Container Instances and Logic Apps.
","tags":["Azure.SQL.AllowAzureAccess","AZR-000184"]},{"location":"en/rules/Azure.SQL.AllowAzureAccess/#recommendation","title":"Recommendation","text":"Consider using a stable IP address or configure virtual network based firewall rules. Determine if access from Azure services is required for the services connecting to the hosted databases.
","tags":["Azure.SQL.AllowAzureAccess","AZR-000184"]},{"location":"en/rules/Azure.SQL.AllowAzureAccess/#links","title":"Links","text":"Security \u00b7 SQL Database \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Enable auditing for Azure SQL logical server.
","tags":["Azure.SQL.Auditing","AZR-000187"]},{"location":"en/rules/Azure.SQL.Auditing/#description","title":"Description","text":"Auditing for Azure SQL Database tracks database events and writes them to an audit log. Audit logs help you find suspicious events, unusual activity, and trends.
","tags":["Azure.SQL.Auditing","AZR-000187"]},{"location":"en/rules/Azure.SQL.Auditing/#recommendation","title":"Recommendation","text":"Consider enabling auditing for each SQL Database logical server and review reports on a regular basis.
","tags":["Azure.SQL.Auditing","AZR-000187"]},{"location":"en/rules/Azure.SQL.Auditing/#examples","title":"Examples","text":"","tags":["Azure.SQL.Auditing","AZR-000187"]},{"location":"en/rules/Azure.SQL.Auditing/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy logical servers that pass this rule:
Microsoft.Sql/servers/auditingSettings
sub-resource with each logical server.properties.state
property to Enabled
for the Microsoft.Sql/servers/auditingSettings
sub-resource.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Sql/servers/auditingSettings\",\n \"apiVersion\": \"2022-08-01-preview\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'default')]\",\n \"properties\": {\n \"isAzureMonitorTargetEnabled\": true,\n \"state\": \"Enabled\",\n \"retentionDays\": 7,\n \"auditActionsAndGroups\": [\n \"SUCCESSFUL_DATABASE_AUTHENTICATION_GROUP\",\n \"FAILED_DATABASE_AUTHENTICATION_GROUP\",\n \"BATCH_COMPLETED_GROUP\"\n ]\n },\n \"dependsOn\": [\n \"server\"\n ]\n}\n
","tags":["Azure.SQL.Auditing","AZR-000187"]},{"location":"en/rules/Azure.SQL.Auditing/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy logical servers that pass this rule:
Microsoft.Sql/servers/auditingSettings
sub-resource with each logical server.properties.state
property to Enabled
for the Microsoft.Sql/servers/auditingSettings
sub-resource.For example:
Azure Bicep snippetresource server 'Microsoft.Sql/servers@2022-11-01-preview' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n publicNetworkAccess: 'Disabled'\n minimalTlsVersion: '1.2'\n administrators: {\n azureADOnlyAuthentication: true\n administratorType: 'ActiveDirectory'\n login: adminLogin\n principalType: 'Group'\n sid: adminPrincipalId\n tenantId: tenant().tenantId\n }\n }\n}\n\nresource sqlAuditSettings 'Microsoft.Sql/servers/auditingSettings@2022-08-01-preview' = {\n name: 'default'\n parent: server\n properties: {\n isAzureMonitorTargetEnabled: true\n state: 'Enabled'\n retentionDays: 7\n auditActionsAndGroups: [\n 'SUCCESSFUL_DATABASE_AUTHENTICATION_GROUP'\n 'FAILED_DATABASE_AUTHENTICATION_GROUP'\n 'BATCH_COMPLETED_GROUP'\n ]\n }\n}\n
","tags":["Azure.SQL.Auditing","AZR-000187"]},{"location":"en/rules/Azure.SQL.Auditing/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz sql server audit-policy update -g '<resource_group>' -n '<server_name>' --state Enabled --bsts Enabled --storage-account '<storage_account_name>'\n
","tags":["Azure.SQL.Auditing","AZR-000187"]},{"location":"en/rules/Azure.SQL.Auditing/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetSet-AzSqlServerAudit -ResourceGroupName '<resource_group>' -ServerName '<server_name>' -BlobStorageTargetState Enabled -StorageAccountResourceId '<storage_resource_id>'\n
","tags":["Azure.SQL.Auditing","AZR-000187"]},{"location":"en/rules/Azure.SQL.Auditing/#links","title":"Links","text":"Operational Excellence \u00b7 SQL Database \u00b7 Rule \u00b7 2020_12 \u00b7 Awareness
Azure SQL Database names should meet naming requirements.
","tags":["Azure.SQL.DBName","AZR-000192"]},{"location":"en/rules/Azure.SQL.DBName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for SQL Database names are:
<>*%&:\\/?
The following reserved database names can not be used:
master
model
tempdb
Consider using names that meet Azure SQL Database naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.SQL.DBName","AZR-000192"]},{"location":"en/rules/Azure.SQL.DBName/#notes","title":"Notes","text":"This rule does not check if Azure SQL Database names are unique.
","tags":["Azure.SQL.DBName","AZR-000192"]},{"location":"en/rules/Azure.SQL.DBName/#links","title":"Links","text":"Security \u00b7 SQL Database \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Enable Microsoft Defender for Azure SQL logical server.
","tags":["Azure.SQL.DefenderCloud","AZR-000186"]},{"location":"en/rules/Azure.SQL.DefenderCloud/#description","title":"Description","text":"Enable Microsoft Defender for Azure SQL logical server.
","tags":["Azure.SQL.DefenderCloud","AZR-000186"]},{"location":"en/rules/Azure.SQL.DefenderCloud/#recommendation","title":"Recommendation","text":"Consider enabling Advanced Data Security and configuring Microsoft Defender for SQL logical servers.
","tags":["Azure.SQL.DefenderCloud","AZR-000186"]},{"location":"en/rules/Azure.SQL.DefenderCloud/#examples","title":"Examples","text":"","tags":["Azure.SQL.DefenderCloud","AZR-000186"]},{"location":"en/rules/Azure.SQL.DefenderCloud/#configure-with-azure-template","title":"Configure with Azure template","text":"Azure Template snippet{\n \"comments\": \"Create or update an Azure SQL logical server.\",\n \"type\": \"Microsoft.Sql/servers\",\n \"apiVersion\": \"2019-06-01-preview\",\n \"name\": \"[parameters('serverName')]\",\n \"location\": \"[parameters('location')]\",\n \"tags\": \"[parameters('tags')]\",\n \"kind\": \"v12.0\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"administratorLogin\": \"[parameters('adminUsername')]\",\n \"version\": \"12.0\",\n \"publicNetworkAccess\": \"[if(parameters('allowPublicAccess'), 'Enabled', 'Disabled')]\",\n \"administratorLoginPassword\": \"[parameters('adminPassword')]\",\n \"minimalTLSVersion\": \"1.2\"\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Sql/servers/securityAlertPolicies\",\n \"apiVersion\": \"2020-02-02-preview\",\n \"name\": \"[concat(parameters('serverName'), '/Default')]\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.Sql/servers', parameters('serverName'))]\"\n ],\n \"properties\": {\n \"state\": \"Enabled\"\n }\n }\n ]\n}\n
","tags":["Azure.SQL.DefenderCloud","AZR-000186"]},{"location":"en/rules/Azure.SQL.DefenderCloud/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetSet-AzSqlDatabaseThreatDetectionPolicy -ResourceGroupName '<resource_group>' -ServerName '<server_name>' -DatabaseName '<database>' -StorageAccountName '<account_name>' -NotificationRecipientsEmails '<email>' -EmailAdmins $False\n
","tags":["Azure.SQL.DefenderCloud","AZR-000186"]},{"location":"en/rules/Azure.SQL.DefenderCloud/#links","title":"Links","text":"Operational Excellence \u00b7 SQL Database \u00b7 Rule \u00b7 2020_12 \u00b7 Awareness
Azure SQL failover group names should meet naming requirements.
","tags":["Azure.SQL.FGName","AZR-000193"]},{"location":"en/rules/Azure.SQL.FGName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for SQL failover group names are:
Consider using names that meet Azure SQL failover group naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.SQL.FGName","AZR-000193"]},{"location":"en/rules/Azure.SQL.FGName/#notes","title":"Notes","text":"This rule does not check if Azure SQL failover group names are unique.
","tags":["Azure.SQL.FGName","AZR-000193"]},{"location":"en/rules/Azure.SQL.FGName/#links","title":"Links","text":"Security \u00b7 SQL Database \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range).
","tags":["Azure.SQL.FirewallIPRange","AZR-000185"]},{"location":"en/rules/Azure.SQL.FirewallIPRange/#description","title":"Description","text":"Typically the number of IP address rules permitted through the firewall is minimal, with management connectivity from on-premises and cloud application connectivity the most common. This rule assesses the combined IP addresses from each Allowed IP firewall entry to check that the total allowed addresses is less than (10).
","tags":["Azure.SQL.FirewallIPRange","AZR-000185"]},{"location":"en/rules/Azure.SQL.FirewallIPRange/#recommendation","title":"Recommendation","text":"Reduce the size or count of the IP ranges set in the Firewall rules so that the total Allowed IPs are less than (10).
","tags":["Azure.SQL.FirewallIPRange","AZR-000185"]},{"location":"en/rules/Azure.SQL.FirewallIPRange/#example","title":"Example","text":"","tags":["Azure.SQL.FirewallIPRange","AZR-000185"]},{"location":"en/rules/Azure.SQL.FirewallIPRange/#links","title":"Links","text":"Security \u00b7 SQL Database \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Determine if there is an excessive number of firewall rules.
","tags":["Azure.SQL.FirewallRuleCount","AZR-000183"]},{"location":"en/rules/Azure.SQL.FirewallRuleCount/#description","title":"Description","text":"Typically the number of firewall rules required is minimal, with management connectivity from on-premises and cloud application connectivity the most common.
","tags":["Azure.SQL.FirewallRuleCount","AZR-000183"]},{"location":"en/rules/Azure.SQL.FirewallRuleCount/#recommendation","title":"Recommendation","text":"The logical SQL Server has greater then ten (10) firewall rules. Some rules may not be needed.
","tags":["Azure.SQL.FirewallRuleCount","AZR-000183"]},{"location":"en/rules/Azure.SQL.FirewallRuleCount/#links","title":"Links","text":"Security \u00b7 SQL Database \u00b7 Rule \u00b7 2020_09 \u00b7 Critical
Azure SQL Database servers should reject TLS versions older than 1.2.
","tags":["Azure.SQL.MinTLS","AZR-000189"]},{"location":"en/rules/Azure.SQL.MinTLS/#description","title":"Description","text":"The minimum version of TLS that Azure SQL Database servers accept is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Azure lets you disable outdated protocols and require connections to use a minimum of TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 is accepted.
","tags":["Azure.SQL.MinTLS","AZR-000189"]},{"location":"en/rules/Azure.SQL.MinTLS/#recommendation","title":"Recommendation","text":"Consider configuring the minimum supported TLS version to be 1.2.
","tags":["Azure.SQL.MinTLS","AZR-000189"]},{"location":"en/rules/Azure.SQL.MinTLS/#examples","title":"Examples","text":"","tags":["Azure.SQL.MinTLS","AZR-000189"]},{"location":"en/rules/Azure.SQL.MinTLS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy logical SQL Servers that pass this rule:
properties.minimalTlsVersion
to 1.2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Sql/servers\",\n \"apiVersion\": \"2022-11-01-preview\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"publicNetworkAccess\": \"Disabled\",\n \"minimalTlsVersion\": \"1.2\",\n \"administrators\": {\n \"azureADOnlyAuthentication\": true,\n \"administratorType\": \"ActiveDirectory\",\n \"login\": \"[parameters('adminLogin')]\",\n \"principalType\": \"Group\",\n \"sid\": \"[parameters('adminPrincipalId')]\",\n \"tenantId\": \"[tenant().tenantId]\"\n }\n }\n}\n
","tags":["Azure.SQL.MinTLS","AZR-000189"]},{"location":"en/rules/Azure.SQL.MinTLS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy logical SQL Servers that pass this rule:
properties.minimalTlsVersion
to 1.2
.For example:
Azure Bicep snippetresource server 'Microsoft.Sql/servers@2022-11-01-preview' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n publicNetworkAccess: 'Disabled'\n minimalTlsVersion: '1.2'\n administrators: {\n azureADOnlyAuthentication: true\n administratorType: 'ActiveDirectory'\n login: adminLogin\n principalType: 'Group'\n sid: adminPrincipalId\n tenantId: tenant().tenantId\n }\n }\n}\n
","tags":["Azure.SQL.MinTLS","AZR-000189"]},{"location":"en/rules/Azure.SQL.MinTLS/#links","title":"Links","text":"Operational Excellence \u00b7 SQL Database \u00b7 Rule \u00b7 2020_12 \u00b7 Awareness
Azure SQL logical server names should meet naming requirements.
","tags":["Azure.SQL.ServerName","AZR-000190"]},{"location":"en/rules/Azure.SQL.ServerName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for SQL logical server names are:
Consider using names that meet Azure SQL logical server naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.SQL.ServerName","AZR-000190"]},{"location":"en/rules/Azure.SQL.ServerName/#notes","title":"Notes","text":"This rule does not check if Azure SQL logical server names are unique.
","tags":["Azure.SQL.ServerName","AZR-000190"]},{"location":"en/rules/Azure.SQL.ServerName/#links","title":"Links","text":"Security \u00b7 SQL Database \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Use Transparent Data Encryption (TDE) with Azure SQL Database.
","tags":["Azure.SQL.TDE","AZR-000191"]},{"location":"en/rules/Azure.SQL.TDE/#description","title":"Description","text":"TDE helps protect Azure SQL Databases against malicious offline access by encrypting data at rest. SQL Databases perform real-time encryption and decryption of the database, backups, and log files. Encryption is perform at rest without requiring changes to the application.
","tags":["Azure.SQL.TDE","AZR-000191"]},{"location":"en/rules/Azure.SQL.TDE/#recommendation","title":"Recommendation","text":"Consider enable Transparent Data Encryption (TDE) for Azure SQL Databases to perform encryption at rest.
","tags":["Azure.SQL.TDE","AZR-000191"]},{"location":"en/rules/Azure.SQL.TDE/#examples","title":"Examples","text":"","tags":["Azure.SQL.TDE","AZR-000191"]},{"location":"en/rules/Azure.SQL.TDE/#configure-with-azure-template","title":"Configure with Azure template","text":"Azure Template snippet{\n \"type\": \"Microsoft.Sql/servers/databases\",\n \"apiVersion\": \"2020-08-01-preview\",\n \"name\": \"[variables('dbName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('sku')]\"\n },\n \"kind\": \"v12.0,user\",\n \"properties\": {\n \"collation\": \"SQL_Latin1_General_CP1_CI_AS\",\n \"maxSizeBytes\": \"[mul(parameters('maxSizeMB'), 1048576)]\",\n \"catalogCollation\": \"SQL_Latin1_General_CP1_CI_AS\",\n \"zoneRedundant\": false,\n \"readScale\": \"Disabled\",\n \"storageAccountType\": \"GRS\"\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Sql/servers/databases/transparentDataEncryption\",\n \"apiVersion\": \"2014-04-01\",\n \"name\": \"[concat(variables('dbName'), '/current')]\",\n \"location\": \"[parameters('location')]\",\n \"dependsOn\": [\n \"[resourceId('Microsoft.Sql/servers/databases', parameters('serverName'), parameters('databaseName'))]\"\n ],\n \"properties\": {\n \"status\": \"Enabled\"\n }\n }\n ]\n}\n
","tags":["Azure.SQL.TDE","AZR-000191"]},{"location":"en/rules/Azure.SQL.TDE/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz sql db tde set --status Enabled -s '<server_name>' -d '<database>' -g '<resource_group>'\n
","tags":["Azure.SQL.TDE","AZR-000191"]},{"location":"en/rules/Azure.SQL.TDE/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetSet-AzSqlDatabaseTransparentDataEncryption -ResourceGroupName '<resource_group>' -ServerName '<server_name>' -DatabaseName '<database>' -State Enabled\n
","tags":["Azure.SQL.TDE","AZR-000191"]},{"location":"en/rules/Azure.SQL.TDE/#links","title":"Links","text":"Security \u00b7 SQL Managed Instance \u00b7 Rule \u00b7 2023_03 \u00b7 Critical
Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance.
","tags":["Azure.SQLMI.AAD","AZR-000368"]},{"location":"en/rules/Azure.SQLMI.AAD/#description","title":"Description","text":"Azure SQL Managed Instance supports authentication with SQL logins and Azure AD authentication.
By default, authentication with SQL logins is enabled. SQL logins are unable to provide sufficient protection for identities. Azure AD authentication provides strong protection controls including conditional access, identity governance, and privileged identity management.
Using Azure AD authentication requires an Azure AD administrator provisioned, if a instance does not have an Azure AD administrator, then Azure AD logins and users receive a Cannot connect
to instance error.
Once you decide to use Azure AD authentication, you can disable authentication with SQL logins.
","tags":["Azure.SQLMI.AAD","AZR-000368"]},{"location":"en/rules/Azure.SQLMI.AAD/#recommendation","title":"Recommendation","text":"Consider using Azure Active Directory (AAD) authentication with SQL Managed Instance. Additionally, consider disabling SQL authentication.
","tags":["Azure.SQLMI.AAD","AZR-000368"]},{"location":"en/rules/Azure.SQLMI.AAD/#examples","title":"Examples","text":"An Azure AD administrator can be provisioned in two different ways.
","tags":["Azure.SQLMI.AAD","AZR-000368"]},{"location":"en/rules/Azure.SQLMI.AAD/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy SQL Managed Instances that pass this rule:
properties.administrators.administratorType
to ActiveDirectory
.properties.administrators.login
to the administrator login object name.properties.administrators.sid
to the object ID GUID of the administrator user, group, or application.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Sql/managedInstances\",\n \"apiVersion\": \"2022-05-01-preview\",\n \"name\": \"[parameters('managedInstanceName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\",\n \"userAssignedIdentities\": {}\n },\n \"properties\": {\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"administrators\": {\n \"administratorType\": \"ActiveDirectory\",\n \"azureADOnlyAuthentication\": true,\n \"login\": \"[parameters('login')]\",\n \"principalType\": \"[parameters('principalType')]\",\n \"sid\": \"[parameters('sid')]\",\n \"tenantId\": \"[parameters('tenantId')]\"\n }\n }\n}\n
Alternatively, you can configure the Microsoft.Sql/managedInstances/administrators
sub-resource. To deploy Microsoft.Sql/managedInstances/administrators
sub-resources that pass this rule:
properties.administratorType
to ActiveDirectory
.properties.login
to the administrator login object name.properties.sid
to the object ID GUID of the administrator user, group, or application.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Sql/managedInstances/administrators\",\n \"apiVersion\": \"2022-05-01-preview\",\n \"name\": \"[format('{0}/{1}', parameters('managedInstanceName'), 'ActiveDirectory')]\",\n \"properties\": {\n \"administratorType\": \"ActiveDirectory\",\n \"login\": \"[parameters('login')]\",\n \"sid\": \"[parameters('sid')]\"\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Sql/managedInstances', parameters('managedInstanceName'))]\"\n ]\n}\n
","tags":["Azure.SQLMI.AAD","AZR-000368"]},{"location":"en/rules/Azure.SQLMI.AAD/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy SQL Managed Instances that pass this rule:
properties.administrators.administratorType
to ActiveDirectory
.properties.administrators.login
to the administrator login object name.properties.administrators.sid
to the object ID GUID of the administrator user, group, or application.For example:
Azure Bicep snippetresource managedInstance 'Microsoft.Sql/managedInstances@2022-05-01-preview' = {\n name: managedInstanceName\n location: location\n identity: {\n type: 'SystemAssigned'\n userAssignedIdentities: {}\n }\n properties: {\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n administrators: {\n administratorType: 'ActiveDirectory'\n azureADOnlyAuthentication: true\n login: login\n principalType: principalType\n sid: sid\n tenantId: tenantId\n }\n }\n}\n
Alternatively, you can configure the Microsoft.Sql/managedInstances/administrators
sub-resource. To deploy Microsoft.Sql/managedInstances/administrators
sub-resources that pass this rule:
properties.administratorType
to ActiveDirectory
.properties.login
to the administrator login object name.properties.sid
to the object ID GUID of the administrator user, group, or application.For example:
Azure Bicep snippetresource sqlAdministrator 'Microsoft.Sql/managedInstances//administrators@2022-05-01-preview' = {\n parent: managedInstance\n name: 'ActiveDirectory'\n properties: {\n administratorType: 'ActiveDirectory'\n login: login\n sid: sid\n }\n}\n
","tags":["Azure.SQLMI.AAD","AZR-000368"]},{"location":"en/rules/Azure.SQLMI.AAD/#notes","title":"Notes","text":"If both the properties.administrators
property and Microsoft.Sql/managedInstances/administrators
are set, the sub-resoure will override the property.
Managed identity is required to allow support for Azure AD authentication in SQL Managed Instance.
","tags":["Azure.SQLMI.AAD","AZR-000368"]},{"location":"en/rules/Azure.SQLMI.AAD/#links","title":"Links","text":"Security \u00b7 SQL Managed Instance \u00b7 Rule \u00b7 2023_03 \u00b7 Important
Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance.
","tags":["Azure.SQLMI.AADOnly","AZR-000366"]},{"location":"en/rules/Azure.SQLMI.AADOnly/#description","title":"Description","text":"Azure SQL Managed Instance supports authentication with SQL logins and Azure AD authentication.
By default, authentication with SQL logins is enabled. SQL logins are unable to provide sufficient protection for identities. Azure AD authentication provides strong protection controls including conditional access, identity governance, and privileged identity management.
Once you decide to use Azure AD authentication, you can disable authentication with SQL logins.
","tags":["Azure.SQLMI.AADOnly","AZR-000366"]},{"location":"en/rules/Azure.SQLMI.AADOnly/#recommendation","title":"Recommendation","text":"Consider using Azure AD-only authentication. Also consider using Azure Policy for Azure AD-only authentication with SQL Managed Instance.
","tags":["Azure.SQLMI.AADOnly","AZR-000366"]},{"location":"en/rules/Azure.SQLMI.AADOnly/#examples","title":"Examples","text":"Azure AD-only authentication can be enabled in two different ways.
","tags":["Azure.SQLMI.AADOnly","AZR-000366"]},{"location":"en/rules/Azure.SQLMI.AADOnly/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy SQL Managed Instances that pass this rule:
properties.administrators.azureADOnlyAuthentication
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Sql/managedInstances\",\n \"apiVersion\": \"2022-05-01-preview\",\n \"name\": \"[parameters('managedInstanceName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\",\n \"userAssignedIdentities\": {}\n },\n \"properties\": {\n \"administratorLogin\": \"[parameters('administratorLogin')]\",\n \"administratorLoginPassword\": \"[parameters('administratorLoginPassword')]\",\n \"administrators\": {\n \"administratorType\": \"ActiveDirectory\",\n \"azureADOnlyAuthentication\": true,\n \"login\": \"[parameters('login')]\",\n \"principalType\": \"[parameters('principalType')]\",\n \"sid\": \"[parameters('sid')]\",\n \"tenantId\": \"[parameters('tenantId')]\"\n }\n }\n}\n
Alternatively, you can configure the Microsoft.Sql/managedInstances/azureADOnlyAuthentications
sub-resource. To deploy Microsoft.Sql/managedInstances/azureADOnlyAuthentications
sub-resources that pass this rule:
properties.azureADOnlyAuthentication
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Sql/managedInstances/azureADOnlyAuthentications\",\n \"apiVersion\": \"2022-05-01-preview\",\n \"name\": \"[format('{0}/{1}', parameters('managedInstanceName'), 'Default')]\",\n \"properties\": {\n \"azureADOnlyAuthentication\": true\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Sql/managedInstances', parameters('managedInstanceName'))]\"\n ]\n}\n
","tags":["Azure.SQLMI.AADOnly","AZR-000366"]},{"location":"en/rules/Azure.SQLMI.AADOnly/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy SQL Managed Instances that pass this rule:
properties.administrators.azureADOnlyAuthentication
property to true
.For example:
Azure Bicep snippetresource managedInstance 'Microsoft.Sql/managedInstances@2022-05-01-preview' = {\n name: managedInstanceName\n location: location\n identity: {\n type: 'SystemAssigned'\n userAssignedIdentities: {}\n }\n properties: {\n administratorLogin: administratorLogin\n administratorLoginPassword: administratorLoginPassword\n administrators: {\n administratorType: 'ActiveDirectory'\n azureADOnlyAuthentication: true\n login: login\n principalType: principalType\n sid: sid\n tenantId: tenantId\n }\n }\n}\n
Alternatively, you can configure the Microsoft.Sql/managedInstances/azureADOnlyAuthentications
sub-resource. To deploy Microsoft.Sql/managedInstances/azureADOnlyAuthentications
sub-resources that pass this rule:
properties.azureADOnlyAuthentication
property to true
.For example:
Azure Bicep snippetresource aadOnly 'Microsoft.Sql/managedInstances/azureADOnlyAuthentications@2022-05-01-preview' = {\n name: 'Default'\n parent: managedInstance\n properties: {\n azureADOnlyAuthentication: true\n }\n}\n
","tags":["Azure.SQLMI.AADOnly","AZR-000366"]},{"location":"en/rules/Azure.SQLMI.AADOnly/#notes","title":"Notes","text":"The Azure AD admin must be set before enabling Azure AD-only authentication. Managed identity is required to allow support for Azure AD authentication in SQL Managed Instance.
","tags":["Azure.SQLMI.AADOnly","AZR-000366"]},{"location":"en/rules/Azure.SQLMI.AADOnly/#links","title":"Links","text":"Security \u00b7 SQL Managed Instance \u00b7 Rule \u00b7 2023_03 \u00b7 Important
Ensure managed identity is used to allow support for Azure AD authentication.
","tags":["Azure.SQLMI.ManagedIdentity","AZR-000367"]},{"location":"en/rules/Azure.SQLMI.ManagedIdentity/#description","title":"Description","text":"A managed identity is required for allowing support for Azure AD authentication in SQL Managed Instance.
You must enable the instance identity (SMI or UMI) to allow support for Azure AD authentication in SQL Managed Instance.
Additionally, a managed identity is required for transparent data encryption with customer-managed key.
","tags":["Azure.SQLMI.ManagedIdentity","AZR-000367"]},{"location":"en/rules/Azure.SQLMI.ManagedIdentity/#recommendation","title":"Recommendation","text":"Consider configure a managed identity to allow support for Azure AD authentication.
","tags":["Azure.SQLMI.ManagedIdentity","AZR-000367"]},{"location":"en/rules/Azure.SQLMI.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.SQLMI.ManagedIdentity","AZR-000367"]},{"location":"en/rules/Azure.SQLMI.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy SQL Managed Instances that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
or SystemAssigned,UserAssigned
.identity.type
is UserAssigned
or SystemAssigned,UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Sql/managedInstances\",\n \"apiVersion\": \"2022-05-01-preview\",\n \"name\": \"[parameters('managedInstanceName')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\",\n \"userAssignedIdentities\": {}\n },\n \"properties\": {}\n}\n
","tags":["Azure.SQLMI.ManagedIdentity","AZR-000367"]},{"location":"en/rules/Azure.SQLMI.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy SQL Managed Instances that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
or SystemAssigned,UserAssigned
.identity.type
is UserAssigned
or SystemAssigned,UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource managedInstance 'Microsoft.Sql/managedInstances@2022-05-01-preview' = {\n name: appName\n location: location\n name: managedInstanceName\n location: location\n identity: {\n type: 'SystemAssigned'\n userAssignedIdentities: {}\n }\n properties: {}\n}\n
","tags":["Azure.SQLMI.ManagedIdentity","AZR-000367"]},{"location":"en/rules/Azure.SQLMI.ManagedIdentity/#notes","title":"Notes","text":"To grant permissions to access Microsoft Graph through an SMI or a UMI, you need to use PowerShell. You can't grant these permissions by using the Azure portal.
","tags":["Azure.SQLMI.ManagedIdentity","AZR-000367"]},{"location":"en/rules/Azure.SQLMI.ManagedIdentity/#links","title":"Links","text":"Operational Excellence \u00b7 SQL Managed Instance \u00b7 Rule \u00b7 2020_12 \u00b7 Awareness
SQL Managed Instance names should meet naming requirements.
","tags":["Azure.SQLMI.Name","AZR-000194"]},{"location":"en/rules/Azure.SQLMI.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for SQL Managed Instance names are:
Consider using names that meet SQL Managed Instance naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.SQLMI.Name","AZR-000194"]},{"location":"en/rules/Azure.SQLMI.Name/#notes","title":"Notes","text":"This rule does not check if SQL Managed Instance names are unique.
","tags":["Azure.SQLMI.Name","AZR-000194"]},{"location":"en/rules/Azure.SQLMI.Name/#links","title":"Links","text":"Reliability \u00b7 AI Search \u00b7 Rule \u00b7 2021_06 \u00b7 Important
Use a minimum of 3 replicas to receive an SLA for query and index updates.
","tags":["Azure.Search.IndexSLA","AZR-000174"]},{"location":"en/rules/Azure.Search.IndexSLA/#description","title":"Description","text":"AI Search (Previously known as Cognitive Search) services support indexing and querying. Indexing is the process of loading content into the service to make it searchable. Querying is the process where a client searches for content by sending queries to the index.
AI Search supports a configurable number of replicas. Having multiple replicas allows queries and index updates to load balance across multiple replicas.
To receive a Service Level Agreement (SLA) for Search index updates a minimum of 3 replicas is required.
","tags":["Azure.Search.IndexSLA","AZR-000174"]},{"location":"en/rules/Azure.Search.IndexSLA/#recommendation","title":"Recommendation","text":"Consider increasing the number of replicas to a minimum of 3 to receive an SLA on index update requests.
","tags":["Azure.Search.IndexSLA","AZR-000174"]},{"location":"en/rules/Azure.Search.IndexSLA/#examples","title":"Examples","text":"","tags":["Azure.Search.IndexSLA","AZR-000174"]},{"location":"en/rules/Azure.Search.IndexSLA/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AI Search services that pass this rule:
properties.replicaCount
property to a minimum of 3
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Search/searchServices\",\n \"apiVersion\": \"2022-09-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"replicaCount\": 3,\n \"partitionCount\": 1,\n \"hostingMode\": \"default\"\n }\n}\n
","tags":["Azure.Search.IndexSLA","AZR-000174"]},{"location":"en/rules/Azure.Search.IndexSLA/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AI Search services that pass this rule:
properties.replicaCount
property to a minimum of 3
.For example:
Azure Bicep snippetresource search 'Microsoft.Search/searchServices@2022-09-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'standard'\n }\n properties: {\n replicaCount: 3\n partitionCount: 1\n hostingMode: 'default'\n }\n}\n
","tags":["Azure.Search.IndexSLA","AZR-000174"]},{"location":"en/rules/Azure.Search.IndexSLA/#links","title":"Links","text":"Security \u00b7 AI Search \u00b7 Rule \u00b7 2021_06 \u00b7 Important
Configure managed identities to access Azure resources.
","tags":["Azure.Search.ManagedIdentity","AZR-000175"]},{"location":"en/rules/Azure.Search.ManagedIdentity/#description","title":"Description","text":"AI Search (Previously known as Cognitive Search) may require connection to other Azure resources. Connections to Azure resources are required to use some features including indexing and customer managed-keys. AI Search can use managed identities to authenticate to Azure resources without storing credentials.
Using Azure managed identities have the following benefits:
Consider configuring a managed identity for each AI Search service. Also consider using managed identities to authenticate to related Azure services.
","tags":["Azure.Search.ManagedIdentity","AZR-000175"]},{"location":"en/rules/Azure.Search.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.Search.ManagedIdentity","AZR-000175"]},{"location":"en/rules/Azure.Search.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AI Search services that pass this rule:
identity.type
property to SystemAssigned
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Search/searchServices\",\n \"apiVersion\": \"2022-09-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"replicaCount\": 3,\n \"partitionCount\": 1,\n \"hostingMode\": \"default\"\n }\n}\n
","tags":["Azure.Search.ManagedIdentity","AZR-000175"]},{"location":"en/rules/Azure.Search.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AI Search Search services that pass this rule:
identity.type
property to SystemAssigned
.For example:
Azure Bicep snippetresource search 'Microsoft.Search/searchServices@2022-09-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'standard'\n }\n properties: {\n replicaCount: 3\n partitionCount: 1\n hostingMode: 'default'\n }\n}\n
","tags":["Azure.Search.ManagedIdentity","AZR-000175"]},{"location":"en/rules/Azure.Search.ManagedIdentity/#links","title":"Links","text":"Operational Excellence \u00b7 AI Search \u00b7 Rule \u00b7 2021_06 \u00b7 Awareness
AI Search service names should meet naming requirements.
","tags":["Azure.Search.Name","AZR-000176"]},{"location":"en/rules/Azure.Search.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for AI Search (Previously known as Cognitive Search) service names are:
Consider using names that meet Azure AI Search service naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.Search.Name","AZR-000176"]},{"location":"en/rules/Azure.Search.Name/#notes","title":"Notes","text":"This rule does not check if Azure AI Search service names are unique.
","tags":["Azure.Search.Name","AZR-000176"]},{"location":"en/rules/Azure.Search.Name/#links","title":"Links","text":"Reliability \u00b7 AI Search \u00b7 Rule \u00b7 2021_06 \u00b7 Important
Use a minimum of 2 replicas to receive an SLA for index queries.
","tags":["Azure.Search.QuerySLA","AZR-000173"]},{"location":"en/rules/Azure.Search.QuerySLA/#description","title":"Description","text":"AI Search (Previously known as Cognitive Search) services support indexing and querying. Indexing is the process of loading content into the service to make it searchable. Querying is the process where a client searches for content by sending queries to the index.
AI Search supports a configurable number of replicas. Having multiple replicas allows queries and index updates to load balance across multiple replicas.
To receive a Service Level Agreement (SLA) for Search index queries a minimum of 2 replicas is required.
","tags":["Azure.Search.QuerySLA","AZR-000173"]},{"location":"en/rules/Azure.Search.QuerySLA/#recommendation","title":"Recommendation","text":"Consider increasing the number of replicas to a minimum of 2 to receive an SLA on index query requests.
","tags":["Azure.Search.QuerySLA","AZR-000173"]},{"location":"en/rules/Azure.Search.QuerySLA/#examples","title":"Examples","text":"","tags":["Azure.Search.QuerySLA","AZR-000173"]},{"location":"en/rules/Azure.Search.QuerySLA/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AI Search services that pass this rule:
properties.replicaCount
property to a minimum of 2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Search/searchServices\",\n \"apiVersion\": \"2022-09-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"replicaCount\": 3,\n \"partitionCount\": 1,\n \"hostingMode\": \"default\"\n }\n}\n
","tags":["Azure.Search.QuerySLA","AZR-000173"]},{"location":"en/rules/Azure.Search.QuerySLA/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AI Search services that pass this rule:
properties.replicaCount
property to a minimum of 2
.For example:
Azure Bicep snippetresource search 'Microsoft.Search/searchServices@2022-09-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'standard'\n }\n properties: {\n replicaCount: 3\n partitionCount: 1\n hostingMode: 'default'\n }\n}\n
","tags":["Azure.Search.QuerySLA","AZR-000173"]},{"location":"en/rules/Azure.Search.QuerySLA/#links","title":"Links","text":"Performance Efficiency \u00b7 AI Search \u00b7 Rule \u00b7 2021_06 \u00b7 Critical
Use the basic and standard tiers for entry level workloads.
","tags":["Azure.Search.SKU","AZR-000172"]},{"location":"en/rules/Azure.Search.SKU/#description","title":"Description","text":"AI Search (Previously known as Cognitive Search) services using the Free tier run on resources shared across multiple subscribers. The Free tier is only suggested for limited small scale tests such as running code samples or tutorials.
Running more demanding workloads on the Free tier may experience unpredictable performance or issues.
To select a tier for your workload, estimate and test your required capacity.
","tags":["Azure.Search.SKU","AZR-000172"]},{"location":"en/rules/Azure.Search.SKU/#recommendation","title":"Recommendation","text":"Consider deploying AI Search services using basic or higher tier.
","tags":["Azure.Search.SKU","AZR-000172"]},{"location":"en/rules/Azure.Search.SKU/#examples","title":"Examples","text":"","tags":["Azure.Search.SKU","AZR-000172"]},{"location":"en/rules/Azure.Search.SKU/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy AI Search services that pass this rule:
sku.name
to a minimum of basic
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Search/searchServices\",\n \"apiVersion\": \"2022-09-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"standard\"\n },\n \"properties\": {\n \"replicaCount\": 3,\n \"partitionCount\": 1,\n \"hostingMode\": \"default\"\n }\n}\n
","tags":["Azure.Search.SKU","AZR-000172"]},{"location":"en/rules/Azure.Search.SKU/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy AI Search services that pass this rule:
sku.name
to a minimum of basic
.For example:
Azure Bicep snippetresource search 'Microsoft.Search/searchServices@2022-09-01' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'standard'\n }\n properties: {\n replicaCount: 3\n partitionCount: 1\n hostingMode: 'default'\n }\n}\n
","tags":["Azure.Search.SKU","AZR-000172"]},{"location":"en/rules/Azure.Search.SKU/#links","title":"Links","text":"Security \u00b7 Service Bus \u00b7 Rule \u00b7 2023_03 \u00b7 Important
Ensure namespaces audit diagnostic logs are enabled.
","tags":["Azure.ServiceBus.AuditLogs","AZR-000358"]},{"location":"en/rules/Azure.ServiceBus.AuditLogs/#description","title":"Description","text":"To capture logs that record data plane access operations (such as send or receive messages) in the service bus, diagnostic settings must be configured.
When configuring diagnostic settings, enabled one of the following:
RuntimeAuditLogs
category.audit
category group.allLogs
category group.Management operations for Service Bus is captured automatically within Azure Activity Logs.
","tags":["Azure.ServiceBus.AuditLogs","AZR-000358"]},{"location":"en/rules/Azure.ServiceBus.AuditLogs/#recommendation","title":"Recommendation","text":"Consider configuring diagnostic settings to record interactions with data of the Service Bus.
","tags":["Azure.ServiceBus.AuditLogs","AZR-000358"]},{"location":"en/rules/Azure.ServiceBus.AuditLogs/#examples","title":"Examples","text":"","tags":["Azure.ServiceBus.AuditLogs","AZR-000358"]},{"location":"en/rules/Azure.ServiceBus.AuditLogs/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Service Bus namespaces that pass this rule:
RuntimeAuditLogs
category or audit
category group or allLogs
category group.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ServiceBus/namespaces\",\n \"apiVersion\": \"2022-10-01-preview\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"minimumTlsVersion\": \"1.2\"\n }\n},\n{\n \"type\": \"Microsoft.Insights/diagnosticSettings\",\n \"apiVersion\": \"2021-05-01-preview\",\n \"scope\": \"[format('Microsoft.ServiceBus/namespaces/{0}', parameters('name'))]\",\n \"name\": \"[parameters('diagName')]\",\n \"properties\": {\n \"workspaceId\": \"[parameters('workspaceId')]\",\n \"logs\": [\n {\n \"category\": \"RuntimeAuditLogs\",\n \"enabled\": true,\n \"retentionPolicy\": {\n \"days\": 0,\n \"enabled\": false\n }\n }\n ]\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.ServiceBus/namespaces', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.ServiceBus.AuditLogs","AZR-000358"]},{"location":"en/rules/Azure.ServiceBus.AuditLogs/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Service Bus namespaces that pass this rule:
RuntimeAuditLogs
category or audit
category group or allLogs
category group.For example:
Azure Bicep snippetresource ns 'Microsoft.ServiceBus/namespaces@2022-10-01-preview' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'Premium'\n }\n properties: {\n disableLocalAuth: true\n minimumTlsVersion: '1.2'\n }\n}\n\nresource nsDiagnosticSettings 'Microsoft.Insights/diagnosticSettings@2021-05-01-preview' = {\n name: diagName\n properties: {\n workspaceId: workspaceId\n logs: [\n {\n category: 'RuntimeAuditLogs'\n enabled: true\n retentionPolicy: {\n days: 0\n enabled: false\n }\n }\n ]\n }\n scope: ns\n}\n
","tags":["Azure.ServiceBus.AuditLogs","AZR-000358"]},{"location":"en/rules/Azure.ServiceBus.AuditLogs/#notes","title":"Notes","text":"This rule only applies to premium tier Service Bus instances. Runtime audit logs are currently available only in the Premium
tier.
Security \u00b7 Service Bus \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Authenticate Service Bus publishers and consumers with Entra ID identities.
","tags":["Azure.ServiceBus.DisableLocalAuth","AZR-000178"]},{"location":"en/rules/Azure.ServiceBus.DisableLocalAuth/#description","title":"Description","text":"To publish or consume messages from Service Bus cryptographic keys, or Entra ID identities can be used. Cryptographic keys include Shared Access Policy keys or Shared Access Signature (SAS) tokens. With Entra ID authentication, the identity is validated against Entra ID. Using Entra ID identities centralizes identity management and auditing.
Once you decide to use Entra ID authentication, you can disable authentication using keys or SAS tokens.
","tags":["Azure.ServiceBus.DisableLocalAuth","AZR-000178"]},{"location":"en/rules/Azure.ServiceBus.DisableLocalAuth/#recommendation","title":"Recommendation","text":"Consider only using Entra ID identities to publish or consume messages from Service Bus. Then disable authentication based on access keys or SAS tokens.
","tags":["Azure.ServiceBus.DisableLocalAuth","AZR-000178"]},{"location":"en/rules/Azure.ServiceBus.DisableLocalAuth/#examples","title":"Examples","text":"","tags":["Azure.ServiceBus.DisableLocalAuth","AZR-000178"]},{"location":"en/rules/Azure.ServiceBus.DisableLocalAuth/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy namespaces that pass this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ServiceBus/namespaces\",\n \"apiVersion\": \"2022-10-01-preview\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"Standard\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"minimumTlsVersion\": \"1.2\"\n }\n}\n
","tags":["Azure.ServiceBus.DisableLocalAuth","AZR-000178"]},{"location":"en/rules/Azure.ServiceBus.DisableLocalAuth/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy namespaces that pass this rule:
properties.disableLocalAuth
property to true
.For example:
Azure Bicep snippetresource ns 'Microsoft.ServiceBus/namespaces@2022-10-01-preview' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'Standard'\n }\n properties: {\n disableLocalAuth: true\n minimumTlsVersion: '1.2'\n }\n}\n
","tags":["Azure.ServiceBus.DisableLocalAuth","AZR-000178"]},{"location":"en/rules/Azure.ServiceBus.DisableLocalAuth/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/cfb11c26-f069-4c14-8e36-56c394dae5af
/providers/Microsoft.Authorization/policyDefinitions/910711a6-8aa2-4f15-ae62-1e5b2ed3ef9e
Security \u00b7 Service Bus \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Service Bus namespaces should reject TLS versions older than 1.2.
","tags":["Azure.ServiceBus.MinTLS","AZR-000315"]},{"location":"en/rules/Azure.ServiceBus.MinTLS/#description","title":"Description","text":"Clients connect to Azure Service Bus to send and receive messages over a Transport Layer Security (TLS) encrypted connection. The minimum version of TLS that Service Bus accepts is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS. Additionally, support for TLS 1.0 and 1.1 are on a deprecation path across Azure services.
Azure lets you disable outdated protocols and require connections to use a minimum of TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 are accepted.
When clients connect using an older version of TLS that is disabled, the connection will fail.
","tags":["Azure.ServiceBus.MinTLS","AZR-000315"]},{"location":"en/rules/Azure.ServiceBus.MinTLS/#recommendation","title":"Recommendation","text":"Consider configuring the minimum supported TLS version for Service Bus clients to be 1.2. Support for TLS 1.0/ 1.1 version will be removed.
","tags":["Azure.ServiceBus.MinTLS","AZR-000315"]},{"location":"en/rules/Azure.ServiceBus.MinTLS/#examples","title":"Examples","text":"","tags":["Azure.ServiceBus.MinTLS","AZR-000315"]},{"location":"en/rules/Azure.ServiceBus.MinTLS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy namespaces that pass this rule:
properties.minimumTlsVersion
property to 1.2
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.ServiceBus/namespaces\",\n \"apiVersion\": \"2022-10-01-preview\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"sku\": {\n \"name\": \"Standard\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"minimumTlsVersion\": \"1.2\"\n }\n}\n
","tags":["Azure.ServiceBus.MinTLS","AZR-000315"]},{"location":"en/rules/Azure.ServiceBus.MinTLS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy namespaces that pass this rule:
properties.minimumTlsVersion
property to 1.2
.For example:
Azure Bicep snippetresource ns 'Microsoft.ServiceBus/namespaces@2022-10-01-preview' = {\n name: name\n location: location\n identity: {\n type: 'SystemAssigned'\n }\n sku: {\n name: 'Standard'\n }\n properties: {\n disableLocalAuth: true\n minimumTlsVersion: '1.2'\n }\n}\n
","tags":["Azure.ServiceBus.MinTLS","AZR-000315"]},{"location":"en/rules/Azure.ServiceBus.MinTLS/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz servicebus namespace update -n '<name>' -g '<resource_group>' --minimum-tls-version '1.2'\n
","tags":["Azure.ServiceBus.MinTLS","AZR-000315"]},{"location":"en/rules/Azure.ServiceBus.MinTLS/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippet$ns = Get-AzServiceBusNamespace -Name '<name>' -ResourceGroupName '<resource_group>'\nSet-AzServiceBusNamespace -InputObject $ns -MinimumTlsVersion '1.2'\n
","tags":["Azure.ServiceBus.MinTLS","AZR-000315"]},{"location":"en/rules/Azure.ServiceBus.MinTLS/#links","title":"Links","text":"Cost Optimization \u00b7 Service Bus \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Regularly remove unused resources to reduce costs.
","tags":["Azure.ServiceBus.Usage","AZR-000177"]},{"location":"en/rules/Azure.ServiceBus.Usage/#description","title":"Description","text":"Billing starts for a Standard or Premium Service Bus namespace after it is provisioned. To to receive messages you must first create at least one queue or topic. Namespaces without any queues or topics are considered unused.
","tags":["Azure.ServiceBus.Usage","AZR-000177"]},{"location":"en/rules/Azure.ServiceBus.Usage/#recommendation","title":"Recommendation","text":"Consider removing Service Bus namespaces that are not used.
","tags":["Azure.ServiceBus.Usage","AZR-000177"]},{"location":"en/rules/Azure.ServiceBus.Usage/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.ServiceBus.Usage","AZR-000177"]},{"location":"en/rules/Azure.ServiceBus.Usage/#links","title":"Links","text":"Security \u00b7 Service Fabric \u00b7 Rule \u00b7 2021_03 \u00b7 Critical
Use Azure Active Directory (AAD) client authentication for Service Fabric clusters.
","tags":["Azure.ServiceFabric.AAD","AZR-000179"]},{"location":"en/rules/Azure.ServiceFabric.AAD/#description","title":"Description","text":"When deploying Service Fabric clusters on Azure, AAD can optionally be used to secure management endpoints. If configured, client authentication (client-to-node security) uses AAD. Additionally Azure Role-based Access Control (RBAC) can be used to delegate cluster access.
For Service Fabric clusters running on Azure, AAD is recommended to secure access to management endpoints.
","tags":["Azure.ServiceFabric.AAD","AZR-000179"]},{"location":"en/rules/Azure.ServiceFabric.AAD/#recommendation","title":"Recommendation","text":"Consider enabling Azure Active Directory (AAD) client authentication for Service Fabric clusters.
","tags":["Azure.ServiceFabric.AAD","AZR-000179"]},{"location":"en/rules/Azure.ServiceFabric.AAD/#notes","title":"Notes","text":"For Linux clusters, AAD authentication must be configured at cluster creation time. Windows cluster can be updated to support AAD authentication after initial deployment.
","tags":["Azure.ServiceFabric.AAD","AZR-000179"]},{"location":"en/rules/Azure.ServiceFabric.AAD/#links","title":"Links","text":"Security \u00b7 SignalR Service \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Configure SignalR Services to use managed identities to access Azure resources securely.
","tags":["Azure.SignalR.ManagedIdentity","AZR-000181"]},{"location":"en/rules/Azure.SignalR.ManagedIdentity/#description","title":"Description","text":"A managed identity allows your service to access other Azure AD-protected resources such as Azure Functions. The identity is managed by the Azure platform and doesn't require you to provision or rotate any secrets.
Using Azure managed identities have the following benefits:
Consider configuring a managed identity for each SignalR Service. Also consider using managed identities to authenticate to related Azure services.
","tags":["Azure.SignalR.ManagedIdentity","AZR-000181"]},{"location":"en/rules/Azure.SignalR.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.SignalR.ManagedIdentity","AZR-000181"]},{"location":"en/rules/Azure.SignalR.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy services that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.SignalRService/signalR\",\n \"apiVersion\": \"2021-10-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"kind\": \"SignalR\",\n \"sku\": {\n \"name\": \"Standard_S1\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"features\": [\n {\n \"flag\": \"ServiceMode\",\n \"value\": \"Serverless\"\n }\n ]\n }\n}\n
","tags":["Azure.SignalR.ManagedIdentity","AZR-000181"]},{"location":"en/rules/Azure.SignalR.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy services that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource service 'Microsoft.SignalRService/signalR@2021-10-01' = {\n name: name\n location: location\n kind: 'SignalR'\n sku: {\n name: 'Standard_S1'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n disableLocalAuth: true\n features: [\n {\n flag: 'ServiceMode'\n value: 'Serverless'\n }\n ]\n }\n}\n
","tags":["Azure.SignalR.ManagedIdentity","AZR-000181"]},{"location":"en/rules/Azure.SignalR.ManagedIdentity/#links","title":"Links","text":"Operational Excellence \u00b7 SignalR Service \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
SignalR service instance names should meet naming requirements.
","tags":["Azure.SignalR.Name","AZR-000180"]},{"location":"en/rules/Azure.SignalR.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for SignalR service names are:
Consider using names that meet SignalR service naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.SignalR.Name","AZR-000180"]},{"location":"en/rules/Azure.SignalR.Name/#notes","title":"Notes","text":"This rule does not check if SignalR service names are unique.
","tags":["Azure.SignalR.Name","AZR-000180"]},{"location":"en/rules/Azure.SignalR.Name/#links","title":"Links","text":"Reliability \u00b7 SignalR Service \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Use SKUs that include an SLA when configuring SignalR Services.
","tags":["Azure.SignalR.SLA","AZR-000182"]},{"location":"en/rules/Azure.SignalR.SLA/#description","title":"Description","text":"When choosing a SKU for a SignalR Service you should consider the SLA that is included in the SKU. SignalR Services offer a range of SKU offerings:
Free
- Are designed for early non-production use and do not include any SLA.Standard
- Are designed for production use and include an SLA.Premium
- Are designed for production use and include an SLA. Additional, Premium SKUs support increased resilience with Availablity Zones.Consider using a Standard or Premium SKU that includes an SLA.
","tags":["Azure.SignalR.SLA","AZR-000182"]},{"location":"en/rules/Azure.SignalR.SLA/#examples","title":"Examples","text":"","tags":["Azure.SignalR.SLA","AZR-000182"]},{"location":"en/rules/Azure.SignalR.SLA/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy services that pass this rule:
sku.name
to Standard_S1
or Premium_P1
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.SignalRService/signalR\",\n \"apiVersion\": \"2021-10-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"kind\": \"SignalR\",\n \"sku\": {\n \"name\": \"Standard_S1\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"disableLocalAuth\": true,\n \"features\": [\n {\n \"flag\": \"ServiceMode\",\n \"value\": \"Serverless\"\n }\n ]\n }\n}\n
","tags":["Azure.SignalR.SLA","AZR-000182"]},{"location":"en/rules/Azure.SignalR.SLA/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy services that pass this rule:
sku.name
to Standard_S1
or Premium_P1
.For example:
Azure Bicep snippetresource service 'Microsoft.SignalRService/signalR@2021-10-01' = {\n name: name\n location: location\n kind: 'SignalR'\n sku: {\n name: 'Standard_S1'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n disableLocalAuth: true\n features: [\n {\n flag: 'ServiceMode'\n value: 'Serverless'\n }\n ]\n }\n}\n
","tags":["Azure.SignalR.SLA","AZR-000182"]},{"location":"en/rules/Azure.SignalR.SLA/#links","title":"Links","text":"Security \u00b7 Storage Account \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use containers configured with a private access type that requires authorization.
","tags":["Azure.Storage.BlobAccessType","AZR-000199"]},{"location":"en/rules/Azure.Storage.BlobAccessType/#description","title":"Description","text":"Azure Storage Account blob containers use the Private access type by default. Additional access types Blob and Container provide anonymous access to blobs without authorization. Blob and Container access types are not intended for access to customer data. When authorization is required, clients must use cryptographic keys or identity-based tokens to authenticate.
Blob and Container access types are designed for public access scenarios. For example, storage of web assets like .css and .js files used in public websites.
","tags":["Azure.Storage.BlobAccessType","AZR-000199"]},{"location":"en/rules/Azure.Storage.BlobAccessType/#recommendation","title":"Recommendation","text":"To provide secure access to data always use the Private access type (default). Also consider, disabling public access for the storage account.
","tags":["Azure.Storage.BlobAccessType","AZR-000199"]},{"location":"en/rules/Azure.Storage.BlobAccessType/#examples","title":"Examples","text":"","tags":["Azure.Storage.BlobAccessType","AZR-000199"]},{"location":"en/rules/Azure.Storage.BlobAccessType/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Storage Account blob containers that pass this rule:
properties.publicAccess
property to None
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Storage/storageAccounts/blobServices/containers\",\n \"apiVersion\": \"2021-06-01\",\n \"name\": \"[format('{0}/{1}/{2}', parameters('name'), 'default', variables('containerName'))]\",\n \"properties\": {\n \"publicAccess\": \"None\"\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Storage/storageAccounts/blobServices', parameters('name'), 'default')]\",\n \"[resourceId('Microsoft.Storage/storageAccounts', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.Storage.BlobAccessType","AZR-000199"]},{"location":"en/rules/Azure.Storage.BlobAccessType/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Storage Account blob containers that pass this rule:
properties.publicAccess
property to None
.For example:
Azure Bicep snippetresource container 'Microsoft.Storage/storageAccounts/blobServices/containers@2021-06-01' = {\n parent: blobService\n name: containerName\n properties: {\n publicAccess: 'None'\n }\n}\n
","tags":["Azure.Storage.BlobAccessType","AZR-000199"]},{"location":"en/rules/Azure.Storage.BlobAccessType/#links","title":"Links","text":"Security \u00b7 Storage Account \u00b7 Rule \u00b7 2020_09 \u00b7 Important
Storage Accounts should only accept authorized requests.
","tags":["Azure.Storage.BlobPublicAccess","AZR-000198"]},{"location":"en/rules/Azure.Storage.BlobPublicAccess/#description","title":"Description","text":"Blob containers in Azure Storage Accounts can be configured for private or anonymous public access. By default, containers are private and only accessible with a credential or access token. When a container is configured with an access type other than private, anonymous access is permitted.
Anonymous access to blobs or containers can be restricted by setting allowBlobPublicAccess
to false
. This enhanced security setting for a storage account overrides the individual settings for blob containers. When you disallow public access for a storage account, blobs are no longer accessible anonymously.
Consider disallowing anonymous access to storage account blobs unless specifically required. Also consider enforcing this setting using Azure Policy.
","tags":["Azure.Storage.BlobPublicAccess","AZR-000198"]},{"location":"en/rules/Azure.Storage.BlobPublicAccess/#examples","title":"Examples","text":"","tags":["Azure.Storage.BlobPublicAccess","AZR-000198"]},{"location":"en/rules/Azure.Storage.BlobPublicAccess/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Storage Accounts that pass this rule:
properties.allowBlobPublicAccess
property to false
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Storage/storageAccounts\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_GRS\"\n },\n \"kind\": \"StorageV2\",\n \"properties\": {\n \"allowBlobPublicAccess\": false,\n \"supportsHttpsTrafficOnly\": true,\n \"minimumTlsVersion\": \"TLS1_2\",\n \"accessTier\": \"Hot\",\n \"allowSharedKeyAccess\": false,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n }\n }\n}\n
","tags":["Azure.Storage.BlobPublicAccess","AZR-000198"]},{"location":"en/rules/Azure.Storage.BlobPublicAccess/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Storage Accounts that pass this rule:
properties.allowBlobPublicAccess
property to false
.For example:
Azure Bicep snippetresource storageAccount 'Microsoft.Storage/storageAccounts@2023-01-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard_GRS'\n }\n kind: 'StorageV2'\n properties: {\n allowBlobPublicAccess: false\n supportsHttpsTrafficOnly: true\n minimumTlsVersion: 'TLS1_2'\n accessTier: 'Hot'\n allowSharedKeyAccess: false\n networkAcls: {\n defaultAction: 'Deny'\n }\n }\n}\n
","tags":["Azure.Storage.BlobPublicAccess","AZR-000198"]},{"location":"en/rules/Azure.Storage.BlobPublicAccess/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/13502221-8df0-4414-9937-de9c5c4e396b
Reliability \u00b7 Storage Account \u00b7 Rule \u00b7 2022_09 \u00b7 Important
Enable container soft delete on Storage Accounts.
","tags":["Azure.Storage.ContainerSoftDelete","AZR-000289"]},{"location":"en/rules/Azure.Storage.ContainerSoftDelete/#description","title":"Description","text":"Container soft delete protects your data from being accidentally or erroneously modified or deleted. When container soft delete is enabled for a storage account, a container and its contents may be recovered after it has been deleted, within a retention period that you specify.
Blob container soft delete should be considered part of the strategy to protect and retain data. Also consider:
Blob containers can be configured to retain deleted containers for a period of time between 1 and 365 days.
","tags":["Azure.Storage.ContainerSoftDelete","AZR-000289"]},{"location":"en/rules/Azure.Storage.ContainerSoftDelete/#recommendation","title":"Recommendation","text":"Consider enabling container soft delete on storage accounts to protect blob containers from accidental deletion or modification.
","tags":["Azure.Storage.ContainerSoftDelete","AZR-000289"]},{"location":"en/rules/Azure.Storage.ContainerSoftDelete/#examples","title":"Examples","text":"","tags":["Azure.Storage.ContainerSoftDelete","AZR-000289"]},{"location":"en/rules/Azure.Storage.ContainerSoftDelete/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Storage Accounts that pass this rule:
properties.containerDeleteRetentionPolicy.enabled
property to true
on the blob services sub-resource.properties.containerDeleteRetentionPolicy.days
property to the number of days to retain blobs.{\n \"type\": \"Microsoft.Storage/storageAccounts\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_GRS\"\n },\n \"kind\": \"StorageV2\",\n \"properties\": {\n \"allowBlobPublicAccess\": false,\n \"supportsHttpsTrafficOnly\": true,\n \"minimumTlsVersion\": \"TLS1_2\",\n \"accessTier\": \"Hot\",\n \"allowSharedKeyAccess\": false,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Storage/storageAccounts/blobServices\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'default')]\",\n \"properties\": {\n \"deleteRetentionPolicy\": {\n \"enabled\": true,\n \"days\": 7\n },\n \"containerDeleteRetentionPolicy\": {\n \"enabled\": true,\n \"days\": 7\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Storage/storageAccounts', parameters('name'))]\"\n ]\n }\n ]\n}\n
","tags":["Azure.Storage.ContainerSoftDelete","AZR-000289"]},{"location":"en/rules/Azure.Storage.ContainerSoftDelete/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Storage Accounts that pass this rule:
properties.containerDeleteRetentionPolicy.enabled
property to true
on the blob services sub-resource.properties.containerDeleteRetentionPolicy.days
property to the number of days to retain blobs.For example:
Azure Bicep snippetresource storageAccount 'Microsoft.Storage/storageAccounts@2023-01-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard_GRS'\n }\n kind: 'StorageV2'\n properties: {\n allowBlobPublicAccess: false\n supportsHttpsTrafficOnly: true\n minimumTlsVersion: 'TLS1_2'\n accessTier: 'Hot'\n allowSharedKeyAccess: false\n networkAcls: {\n defaultAction: 'Deny'\n }\n }\n}\n\nresource blobService 'Microsoft.Storage/storageAccounts/blobServices@2023-01-01' = {\n parent: storageAccount\n name: 'default'\n properties: {\n deleteRetentionPolicy: {\n enabled: true\n days: 7\n }\n containerDeleteRetentionPolicy: {\n enabled: true\n days: 7\n }\n }\n}\n
","tags":["Azure.Storage.ContainerSoftDelete","AZR-000289"]},{"location":"en/rules/Azure.Storage.ContainerSoftDelete/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz storage account blob-service-properties update --enable-container-delete-retention true --container-delete-retention-days 7 -n '<name>' -g '<resource_group>'\n
","tags":["Azure.Storage.ContainerSoftDelete","AZR-000289"]},{"location":"en/rules/Azure.Storage.ContainerSoftDelete/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetEnable-AzStorageContainerDeleteRetentionPolicy -ResourceGroupName '<resource_group>' -StorageAccountName '<name>' -RetentionDays 7\n
","tags":["Azure.Storage.ContainerSoftDelete","AZR-000289"]},{"location":"en/rules/Azure.Storage.ContainerSoftDelete/#notes","title":"Notes","text":"Cloud Shell storage with the tag ms-resource-usage = 'azure-cloud-shell'
is excluded. Storage accounts used for Cloud Shell are not intended to store data.
Storage accounts with:
FileStorage
storage account do not support blob soft delete.Security \u00b7 Storage Account \u00b7 Rule \u00b7 Preview \u00b7 2023_06 \u00b7 Critical
Enable sensitive data threat detection in Microsoft Defender for Storage.
","tags":["Azure.Storage.Defender.DataScan","AZR-000391"]},{"location":"en/rules/Azure.Storage.Defender.DataScan/#description","title":"Description","text":"Sensitive data threat detection is an additional security feature for Microsoft Defender for Storage. When enabled Defender for Storage provides alerts when sensitive data is discovered.
The sensitive data threat detection capability helps teams:
When enabling sensitive data threat detection, the sensitive data categories include built-in sensitive information types (SITs) in the default list of Microsoft Purview. It is possible to customize the Data Sensitivity Discovery for a organization, by creating custom sensitive information types (SITs).
Sensitive data threat detection in Microsoft Defender for Storage can be enabled at the subscription level and by doing so ensures all storage accounts in the subscription will be protected, including future ones.
When overriding sensitive data threat detection on individual Storage Account it is possible to configure custom sensitive data threat detection settings that differ from the settings configured at the subscription level.
","tags":["Azure.Storage.Defender.DataScan","AZR-000391"]},{"location":"en/rules/Azure.Storage.Defender.DataScan/#recommendation","title":"Recommendation","text":"Consider enabling sensitive data threat detection using Microsoft Defender for Storage on the Storage Account. Additionally, consider enabling sensitive data threat detection for all Storage Accounts within a subscription.
","tags":["Azure.Storage.Defender.DataScan","AZR-000391"]},{"location":"en/rules/Azure.Storage.Defender.DataScan/#examples","title":"Examples","text":"","tags":["Azure.Storage.Defender.DataScan","AZR-000391"]},{"location":"en/rules/Azure.Storage.Defender.DataScan/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Storage Accounts that pass this rule:
Microsoft.Security/DefenderForStorageSettings
sub-resource (extension resource).properties.sensitiveDataDiscovery.isEnabled
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/defenderForStorageSettings\",\n \"apiVersion\": \"2022-12-01-preview\",\n \"scope\": \"[format('Microsoft.Storage/storageAccounts/{0}', parameters('name'))]\",\n \"name\": \"current\",\n \"properties\": {\n \"isEnabled\": true,\n \"malwareScanning\": {\n \"onUpload\": {\n \"isEnabled\": true,\n \"capGBPerMonth\": 5000\n }\n },\n \"sensitiveDataDiscovery\": {\n \"isEnabled\": true\n },\n \"overrideSubscriptionLevelSettings\": false\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Storage/storageAccounts', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.Storage.Defender.DataScan","AZR-000391"]},{"location":"en/rules/Azure.Storage.Defender.DataScan/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Storage Accounts that pass this rule:
Microsoft.Security/DefenderForStorageSettings
sub-resource (extension resource).properties.sensitiveDataDiscovery.isEnabled
property to true
.For example:
Azure Bicep snippetresource defenderForStorageSettings 'Microsoft.Security/defenderForStorageSettings@2022-12-01-preview' = {\n name: 'current'\n scope: storageAccount\n properties: {\n isEnabled: true\n malwareScanning: {\n onUpload: {\n isEnabled: true\n capGBPerMonth: 5000\n }\n }\n sensitiveDataDiscovery: {\n isEnabled: true\n }\n overrideSubscriptionLevelSettings: false\n }\n}\n
","tags":["Azure.Storage.Defender.DataScan","AZR-000391"]},{"location":"en/rules/Azure.Storage.Defender.DataScan/#notes","title":"Notes","text":"This feature is currently in preview.
The following limitations currently apply for Microsoft Defender for Storage:
properties.overrideSubscriptionLevelSettings
property to true
.Security \u00b7 Storage Account \u00b7 Rule \u00b7 2024_03 \u00b7 Critical
Enable Malware Scanning in Microsoft Defender for Storage.
","tags":["Azure.Storage.Defender.MalwareScan","AZR-000384"]},{"location":"en/rules/Azure.Storage.Defender.MalwareScan/#description","title":"Description","text":"Microsoft Defender for Storage provides additional security for storage accounts.
One of the features in the Defender for Storage service is malware scanning that is powered by Microsoft Defender Antivirus.
Content uploaded to cloud storage could be malware. Storage accounts can be a malware entry point into the organization and a malware distribution point. To protect organizations from this threat, content in cloud storage must be scanned for malware before it's accessed.
Malware Scanning in Defender for Storage helps protect storage accounts from malicious content by performing a full malware scan on uploaded content in near real time.
This can be helpful when:
When the malware scan identifies a malicious file, detailed Microsoft Defenders for Cloud security alerts are generated.
Malware Scanning in Microsoft Defender for Storage can be enabled at the resource level. However, the general recommendation is to enable it at the subscription level and by doing so ensures all storage accounts in the subscription will be protected, including future ones. Defender for Storage settings on each storage account is inherited by the subscription level settings.
It is also worth to mention that the resource level enablement can be useful when:
Consider enabling Malware Scanning using Microsoft Defender for Storage on the Storage Account. Alternatively, enable Malware Scanning for all Storage Accounts within a subscription.
","tags":["Azure.Storage.Defender.MalwareScan","AZR-000384"]},{"location":"en/rules/Azure.Storage.Defender.MalwareScan/#examples","title":"Examples","text":"","tags":["Azure.Storage.Defender.MalwareScan","AZR-000384"]},{"location":"en/rules/Azure.Storage.Defender.MalwareScan/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Storage Accounts that pass this rule:
Microsoft.Security/DefenderForStorageSettings
sub-resource (extension resource).properties.malwareScanning.onUpload.isEnabled
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/defenderForStorageSettings\",\n \"apiVersion\": \"2022-12-01-preview\",\n \"scope\": \"[format('Microsoft.Storage/storageAccounts/{0}', parameters('name'))]\",\n \"name\": \"current\",\n \"properties\": {\n \"isEnabled\": true,\n \"malwareScanning\": {\n \"onUpload\": {\n \"isEnabled\": true,\n \"capGBPerMonth\": 5000\n }\n },\n \"sensitiveDataDiscovery\": {\n \"isEnabled\": true\n },\n \"overrideSubscriptionLevelSettings\": false\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Storage/storageAccounts', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.Storage.Defender.MalwareScan","AZR-000384"]},{"location":"en/rules/Azure.Storage.Defender.MalwareScan/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Storage Accounts that pass this rule:
Microsoft.Security/DefenderForStorageSettings
sub-resource (extension resource).properties.malwareScanning.onUpload.isEnabled
property to true
.For example:
Azure Bicep snippetresource defenderForStorageSettings 'Microsoft.Security/defenderForStorageSettings@2022-12-01-preview' = {\n name: 'current'\n scope: storageAccount\n properties: {\n isEnabled: true\n malwareScanning: {\n onUpload: {\n isEnabled: true\n capGBPerMonth: 5000\n }\n }\n sensitiveDataDiscovery: {\n isEnabled: true\n }\n overrideSubscriptionLevelSettings: false\n }\n}\n
","tags":["Azure.Storage.Defender.MalwareScan","AZR-000384"]},{"location":"en/rules/Azure.Storage.Defender.MalwareScan/#notes","title":"Notes","text":"Not all services within storage accounts are currently supported.
overrideSubscriptionLevelSettings
value is false
, the resource level enablement will be ignored and the subscription level (plan) will still be used.overrideSubscriptionLevelSettings
value is true
, the resource level enablement will be honored and a dedicated plan will be configured for the storage account.Security \u00b7 Storage Account \u00b7 Rule \u00b7 2023_06 \u00b7 Critical
Enable Microsoft Defender for Storage for storage accounts.
","tags":["Azure.Storage.DefenderCloud","AZR-000386"]},{"location":"en/rules/Azure.Storage.DefenderCloud/#description","title":"Description","text":"Microsoft Defender for Storage analyzes data and control plane logs from protected Storage Accounts. Which allows Microsoft Defender for Cloud to surface findings with details of the security threats and contextual information.
Additionally, Microsoft Defender for Storage provides security extensions to analyze data stored within Storage Accounts:
Microsoft Defender for Storage can be enabled on a per subscription or per resource basis. Enabling at the subscription level is recommended because it protects current and future Storage Accounts. However, enabling at the resource level may be preferred for specific Storage Account to apply custom settings.
","tags":["Azure.Storage.DefenderCloud","AZR-000386"]},{"location":"en/rules/Azure.Storage.DefenderCloud/#recommendation","title":"Recommendation","text":"Consider using Microsoft Defender for Storage to protect your data hosted in storage accounts. Additionally, consider using Microsoft Defender for Storage to protect all storage accounts within a subscription.
","tags":["Azure.Storage.DefenderCloud","AZR-000386"]},{"location":"en/rules/Azure.Storage.DefenderCloud/#examples","title":"Examples","text":"","tags":["Azure.Storage.DefenderCloud","AZR-000386"]},{"location":"en/rules/Azure.Storage.DefenderCloud/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy storage accounts that pass this rule:
Microsoft.Security/DefenderForStorageSettings
sub-resource (extension resource).properties.isEnabled
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Security/defenderForStorageSettings\",\n \"apiVersion\": \"2022-12-01-preview\",\n \"scope\": \"[format('Microsoft.Storage/storageAccounts/{0}', parameters('name'))]\",\n \"name\": \"current\",\n \"properties\": {\n \"isEnabled\": true,\n \"malwareScanning\": {\n \"onUpload\": {\n \"isEnabled\": true,\n \"capGBPerMonth\": 5000\n }\n },\n \"sensitiveDataDiscovery\": {\n \"isEnabled\": true\n },\n \"overrideSubscriptionLevelSettings\": false\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Storage/storageAccounts', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.Storage.DefenderCloud","AZR-000386"]},{"location":"en/rules/Azure.Storage.DefenderCloud/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy storage accounts that pass this rule:
Microsoft.Security/DefenderForStorageSettings
sub-resource (extension resource).properties.isEnabled
property to true
.For example:
Azure Bicep snippetresource defenderForStorageSettings 'Microsoft.Security/defenderForStorageSettings@2022-12-01-preview' = {\n name: 'current'\n scope: storageAccount\n properties: {\n isEnabled: true\n malwareScanning: {\n onUpload: {\n isEnabled: true\n capGBPerMonth: 5000\n }\n }\n sensitiveDataDiscovery: {\n isEnabled: true\n }\n overrideSubscriptionLevelSettings: false\n }\n}\n
","tags":["Azure.Storage.DefenderCloud","AZR-000386"]},{"location":"en/rules/Azure.Storage.DefenderCloud/#notes","title":"Notes","text":"The following limitations currently apply for Microsoft Defender for Storage:
Blob Storage
, Azure Files
and Azure Data Lake Storage Gen2
. Other storage types are not supported.properties.overrideSubscriptionLevelSettings
property to true
.AZURE_STORAGE_DEFENDER_PER_ACCOUNT
This rule is not processed by default because configuration at the subscription level is recommended. To enable this rule, set the AZURE_STORAGE_DEFENDER_PER_ACCOUNT
configuration value to true
.
Reliability \u00b7 Storage Account \u00b7 Rule \u00b7 2022_09 \u00b7 Important
","tags":["Azure.Storage.FileShareSoftDelete","AZR-000298"]},{"location":"en/rules/Azure.Storage.FileShareSoftDelete/#synopsis","title":"Synopsis","text":"Enable soft delete on Storage Accounts file shares.
","tags":["Azure.Storage.FileShareSoftDelete","AZR-000298"]},{"location":"en/rules/Azure.Storage.FileShareSoftDelete/#description","title":"Description","text":"Soft delete for Azure Files protects your shares from being accidentally deleted. This feature does not protect against individual files being deleted or modified. When soft delete is enabled for a Azure Files on a Storage Account, a share and its contents may be recovered after it has been deleted, within a retention period that you specify.
Soft delete on file shares should be considered part of the strategy to protect and retain data for Azure Files. Also consider:
Storage Accounts can be configured to retain deleted share for a period of time between 1 and 365 days.
","tags":["Azure.Storage.FileShareSoftDelete","AZR-000298"]},{"location":"en/rules/Azure.Storage.FileShareSoftDelete/#recommendation","title":"Recommendation","text":"Consider enabling soft delete on Azure Files to protect against accidental deletion of shares.
","tags":["Azure.Storage.FileShareSoftDelete","AZR-000298"]},{"location":"en/rules/Azure.Storage.FileShareSoftDelete/#examples","title":"Examples","text":"","tags":["Azure.Storage.FileShareSoftDelete","AZR-000298"]},{"location":"en/rules/Azure.Storage.FileShareSoftDelete/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Storage Accounts that pass this rule:
properties.deleteRetentionPolicy.enabled
property to true
on the fileServices
sub-resourceproperties.deleteRetentionPolicy.days
property to the number of days to retain files.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Storage/storageAccounts/fileServices\",\n \"apiVersion\": \"2022-05-01\",\n \"name\": \"default\",\n \"properties\": {\n \"shareDeleteRetentionPolicy\": {\n \"days\": \"7\",\n \"enabled\": \"true\"\n }\n }\n}\n
","tags":["Azure.Storage.FileShareSoftDelete","AZR-000298"]},{"location":"en/rules/Azure.Storage.FileShareSoftDelete/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Storage Accounts that pass this rule:
properties.deleteRetentionPolicy.enabled
property to true
on the fileServices
sub-resourceproperties.deleteRetentionPolicy.days
property to the number of days to retain files.For example:
Azure Bicep snippetresource fileServices 'Microsoft.Storage/storageAccounts/fileServices@2023-01-01' = {\n parent: storageAccount\n name: 'default'\n properties: {\n shareDeleteRetentionPolicy: {\n enabled: true\n days: 7\n }\n }\n}\n
","tags":["Azure.Storage.FileShareSoftDelete","AZR-000298"]},{"location":"en/rules/Azure.Storage.FileShareSoftDelete/#notes","title":"Notes","text":"Cloud Shell storage with the tag ms-resource-usage = 'azure-cloud-shell'
is excluded. Storage accounts used for Cloud Shell are not intended to store data.
Security \u00b7 Storage Account \u00b7 Rule \u00b7 2021_09 \u00b7 Important
Storage Accounts should only accept explicitly allowed traffic.
","tags":["Azure.Storage.Firewall","AZR-000202"]},{"location":"en/rules/Azure.Storage.Firewall/#description","title":"Description","text":"By default, storage accounts accept connections from clients on any network. To limit access to selected networks, you must first change the default action.
After changing the default action from Allow
to Deny
, configure one or more rules to allow traffic. Traffic can be allowed from:
Consider configuring storage firewall to restrict network access to permitted clients only. Also consider enforcing this setting using Azure Policy.
","tags":["Azure.Storage.Firewall","AZR-000202"]},{"location":"en/rules/Azure.Storage.Firewall/#examples","title":"Examples","text":"","tags":["Azure.Storage.Firewall","AZR-000202"]},{"location":"en/rules/Azure.Storage.Firewall/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Storage Accounts that pass this rule:
properties.networkAcls.defaultAction
property to Deny
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Storage/storageAccounts\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_GRS\"\n },\n \"kind\": \"StorageV2\",\n \"properties\": {\n \"allowBlobPublicAccess\": false,\n \"supportsHttpsTrafficOnly\": true,\n \"minimumTlsVersion\": \"TLS1_2\",\n \"accessTier\": \"Hot\",\n \"allowSharedKeyAccess\": false,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n }\n }\n}\n
","tags":["Azure.Storage.Firewall","AZR-000202"]},{"location":"en/rules/Azure.Storage.Firewall/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Storage Accounts that pass this rule:
properties.networkAcls.defaultAction
property to Deny
.For example:
Azure Bicep snippetresource storageAccount 'Microsoft.Storage/storageAccounts@2023-01-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard_GRS'\n }\n kind: 'StorageV2'\n properties: {\n allowBlobPublicAccess: false\n supportsHttpsTrafficOnly: true\n minimumTlsVersion: 'TLS1_2'\n accessTier: 'Hot'\n allowSharedKeyAccess: false\n networkAcls: {\n defaultAction: 'Deny'\n }\n }\n}\n
","tags":["Azure.Storage.Firewall","AZR-000202"]},{"location":"en/rules/Azure.Storage.Firewall/#notes","title":"Notes","text":"Cloud Shell storage with the tag ms-resource-usage = 'azure-cloud-shell'
is excluded. Azure storage firewall is not supported for Cloud Shell storage accounts.
Security \u00b7 Storage Account \u00b7 Rule \u00b7 2020_09 \u00b7 Critical
Storage Accounts should reject TLS versions older than 1.2.
","tags":["Azure.Storage.MinTLS","AZR-000200"]},{"location":"en/rules/Azure.Storage.MinTLS/#description","title":"Description","text":"The minimum version of TLS that Azure Storage Accounts accept for blob storage is configurable. Older TLS versions are no longer considered secure by industry standards, such as PCI DSS.
Storage Accounts lets you disable outdated protocols and enforce TLS 1.2. By default, TLS 1.0, TLS 1.1, and TLS 1.2 is accepted.
","tags":["Azure.Storage.MinTLS","AZR-000200"]},{"location":"en/rules/Azure.Storage.MinTLS/#recommendation","title":"Recommendation","text":"Consider configuring the minimum supported TLS version to be 1.2. Also consider enforcing this setting using Azure Policy.
","tags":["Azure.Storage.MinTLS","AZR-000200"]},{"location":"en/rules/Azure.Storage.MinTLS/#examples","title":"Examples","text":"","tags":["Azure.Storage.MinTLS","AZR-000200"]},{"location":"en/rules/Azure.Storage.MinTLS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Storage Accounts that pass this rule:
properties.minimumTlsVersion
property to TLS1_2
or newer.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Storage/storageAccounts\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_GRS\"\n },\n \"kind\": \"StorageV2\",\n \"properties\": {\n \"allowBlobPublicAccess\": false,\n \"supportsHttpsTrafficOnly\": true,\n \"minimumTlsVersion\": \"TLS1_2\",\n \"accessTier\": \"Hot\",\n \"allowSharedKeyAccess\": false,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n }\n }\n}\n
","tags":["Azure.Storage.MinTLS","AZR-000200"]},{"location":"en/rules/Azure.Storage.MinTLS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Storage Accounts that pass this rule:
properties.minimumTlsVersion
property to TLS1_2
or newer.For example:
Azure Bicep snippetresource storageAccount 'Microsoft.Storage/storageAccounts@2023-01-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard_GRS'\n }\n kind: 'StorageV2'\n properties: {\n allowBlobPublicAccess: false\n supportsHttpsTrafficOnly: true\n minimumTlsVersion: 'TLS1_2'\n accessTier: 'Hot'\n allowSharedKeyAccess: false\n networkAcls: {\n defaultAction: 'Deny'\n }\n }\n}\n
","tags":["Azure.Storage.MinTLS","AZR-000200"]},{"location":"en/rules/Azure.Storage.MinTLS/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/fe83a0eb-a853-422d-aac2-1bffd182c5d0
Operational Excellence \u00b7 Storage Account \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Storage Account names should meet naming requirements.
","tags":["Azure.Storage.Name","AZR-000201"]},{"location":"en/rules/Azure.Storage.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Storage Account names are:
Consider using names that meet Storage Account naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.Storage.Name","AZR-000201"]},{"location":"en/rules/Azure.Storage.Name/#notes","title":"Notes","text":"This rule does not check if Storage Account names are unique.
","tags":["Azure.Storage.Name","AZR-000201"]},{"location":"en/rules/Azure.Storage.Name/#links","title":"Links","text":"Security \u00b7 Storage Account \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Storage accounts should only accept encrypted connections.
","tags":["Azure.Storage.SecureTransfer","AZR-000196"]},{"location":"en/rules/Azure.Storage.SecureTransfer/#description","title":"Description","text":"Azure Storage Accounts can be configured to allow unencrypted connections. Unencrypted communication could allow disclosure of information to an un-trusted party. Storage Accounts can be configured to require encrypted connections.
To do this set the Secure transfer required option. When secure transfer required is enabled, attempts to connect to storage using HTTP or unencrypted SMB connections are rejected.
Storage Accounts that are deployed with a newer API version will have this option enabled by default. However, this does not prevent the option from being disabled.
","tags":["Azure.Storage.SecureTransfer","AZR-000196"]},{"location":"en/rules/Azure.Storage.SecureTransfer/#recommendation","title":"Recommendation","text":"Storage accounts should only accept secure traffic. Consider only accepting encrypted connections by setting the Secure transfer required option. Also consider using Azure Policy to audit or enforce this configuration.
","tags":["Azure.Storage.SecureTransfer","AZR-000196"]},{"location":"en/rules/Azure.Storage.SecureTransfer/#examples","title":"Examples","text":"","tags":["Azure.Storage.SecureTransfer","AZR-000196"]},{"location":"en/rules/Azure.Storage.SecureTransfer/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Storage Accounts that pass this rule:
properties.supportsHttpsTrafficOnly
property to true
.properties.supportsHttpsTrafficOnly
property ORproperties.supportsHttpsTrafficOnly
property to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Storage/storageAccounts\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_GRS\"\n },\n \"kind\": \"StorageV2\",\n \"properties\": {\n \"allowBlobPublicAccess\": false,\n \"supportsHttpsTrafficOnly\": true,\n \"minimumTlsVersion\": \"TLS1_2\",\n \"accessTier\": \"Hot\",\n \"allowSharedKeyAccess\": false,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n }\n }\n}\n
","tags":["Azure.Storage.SecureTransfer","AZR-000196"]},{"location":"en/rules/Azure.Storage.SecureTransfer/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Storage Accounts that pass this rule:
properties.supportsHttpsTrafficOnly
property to true
.properties.supportsHttpsTrafficOnly
property ORproperties.supportsHttpsTrafficOnly
property to true
.For example:
Azure Bicep snippetresource storageAccount 'Microsoft.Storage/storageAccounts@2023-01-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard_GRS'\n }\n kind: 'StorageV2'\n properties: {\n allowBlobPublicAccess: false\n supportsHttpsTrafficOnly: true\n minimumTlsVersion: 'TLS1_2'\n accessTier: 'Hot'\n allowSharedKeyAccess: false\n networkAcls: {\n defaultAction: 'Deny'\n }\n }\n}\n
","tags":["Azure.Storage.SecureTransfer","AZR-000196"]},{"location":"en/rules/Azure.Storage.SecureTransfer/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/404c3081-a854-4457-ae30-26a93ef643f9
/providers/Microsoft.Authorization/policyDefinitions/f81e3117-0093-4b17-8a60-82363134f0eb
Reliability \u00b7 Storage Account \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Enable blob soft delete on Storage Accounts.
","tags":["Azure.Storage.SoftDelete","AZR-000197"]},{"location":"en/rules/Azure.Storage.SoftDelete/#description","title":"Description","text":"Soft delete provides an easy way to recover deleted or modified blob data stored within Storage Accounts. When soft delete is enabled, deleted blobs are kept and can be restored within the configured interval.
Blob soft delete should be considered part of the strategy to protect and retain data. Also consider:
Blobs can be configured to retain deleted blobs for a period of time between 1 and 365 days.
","tags":["Azure.Storage.SoftDelete","AZR-000197"]},{"location":"en/rules/Azure.Storage.SoftDelete/#recommendation","title":"Recommendation","text":"Consider enabling soft delete on storage accounts to protect blobs from accidental deletion or modification.
","tags":["Azure.Storage.SoftDelete","AZR-000197"]},{"location":"en/rules/Azure.Storage.SoftDelete/#examples","title":"Examples","text":"","tags":["Azure.Storage.SoftDelete","AZR-000197"]},{"location":"en/rules/Azure.Storage.SoftDelete/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Storage Accounts that pass this rule:
properties.deleteRetentionPolicy.enabled
property to true
on the blob services sub-resource.properties.deleteRetentionPolicy.days
property to the number of days to retain blobs.{\n \"type\": \"Microsoft.Storage/storageAccounts\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_GRS\"\n },\n \"kind\": \"StorageV2\",\n \"properties\": {\n \"allowBlobPublicAccess\": false,\n \"supportsHttpsTrafficOnly\": true,\n \"minimumTlsVersion\": \"TLS1_2\",\n \"accessTier\": \"Hot\",\n \"allowSharedKeyAccess\": false,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Storage/storageAccounts/blobServices\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'default')]\",\n \"properties\": {\n \"deleteRetentionPolicy\": {\n \"enabled\": true,\n \"days\": 7\n },\n \"containerDeleteRetentionPolicy\": {\n \"enabled\": true,\n \"days\": 7\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Storage/storageAccounts', parameters('name'))]\"\n ]\n }\n ]\n}\n
","tags":["Azure.Storage.SoftDelete","AZR-000197"]},{"location":"en/rules/Azure.Storage.SoftDelete/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Storage Accounts that pass this rule:
properties.deleteRetentionPolicy.enabled
property to true
on the blob services sub-resource.properties.deleteRetentionPolicy.days
property to the number of days to retain blobs.For example:
Azure Bicep snippetresource storageAccount 'Microsoft.Storage/storageAccounts@2023-01-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard_GRS'\n }\n kind: 'StorageV2'\n properties: {\n allowBlobPublicAccess: false\n supportsHttpsTrafficOnly: true\n minimumTlsVersion: 'TLS1_2'\n accessTier: 'Hot'\n allowSharedKeyAccess: false\n networkAcls: {\n defaultAction: 'Deny'\n }\n }\n}\n\nresource blobService 'Microsoft.Storage/storageAccounts/blobServices@2023-01-01' = {\n parent: storageAccount\n name: 'default'\n properties: {\n deleteRetentionPolicy: {\n enabled: true\n days: 7\n }\n containerDeleteRetentionPolicy: {\n enabled: true\n days: 7\n }\n }\n}\n
","tags":["Azure.Storage.SoftDelete","AZR-000197"]},{"location":"en/rules/Azure.Storage.SoftDelete/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz storage account blob-service-properties update --enable-delete-retention true --delete-retention-days 7 -n '<name>' -g '<resource_group>'\n
","tags":["Azure.Storage.SoftDelete","AZR-000197"]},{"location":"en/rules/Azure.Storage.SoftDelete/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippetEnable-AzStorageBlobDeleteRetentionPolicy -ResourceGroupName '<resource_group>' -AccountName '<name>' -RetentionDays 7\n
","tags":["Azure.Storage.SoftDelete","AZR-000197"]},{"location":"en/rules/Azure.Storage.SoftDelete/#notes","title":"Notes","text":"Cloud Shell storage with the tag ms-resource-usage = 'azure-cloud-shell'
is excluded. Storage accounts used for Cloud Shell are not intended to store data.
Storage accounts with:
FileStorage
storage account do not support blob soft delete.Reliability \u00b7 Storage Account \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Storage Accounts not using geo-replicated storage (GRS) may be at risk.
","tags":["Azure.Storage.UseReplication","AZR-000195"]},{"location":"en/rules/Azure.Storage.UseReplication/#description","title":"Description","text":"Storage Accounts can be configured with several different durability options. Azure provides a number of geo-replicated options including; Geo-redundant storage and geo-zone-redundant storage. Geo-zone-redundant storage is only available in supported regions.
The following geo-replicated options are available within Azure:
Standard_GRS
Standard_RAGRS
Standard_GZRS
Standard_RAGZRS
Consider using GRS for storage accounts that contain data.
","tags":["Azure.Storage.UseReplication","AZR-000195"]},{"location":"en/rules/Azure.Storage.UseReplication/#examples","title":"Examples","text":"","tags":["Azure.Storage.UseReplication","AZR-000195"]},{"location":"en/rules/Azure.Storage.UseReplication/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Storage Accounts that pass this rule:
sku.name
property to a geo-replicated SKU. Such as Standard_GRS
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Storage/storageAccounts\",\n \"apiVersion\": \"2023-01-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_GRS\"\n },\n \"kind\": \"StorageV2\",\n \"properties\": {\n \"allowBlobPublicAccess\": false,\n \"supportsHttpsTrafficOnly\": true,\n \"minimumTlsVersion\": \"TLS1_2\",\n \"accessTier\": \"Hot\",\n \"allowSharedKeyAccess\": false,\n \"networkAcls\": {\n \"defaultAction\": \"Deny\"\n }\n }\n}\n
","tags":["Azure.Storage.UseReplication","AZR-000195"]},{"location":"en/rules/Azure.Storage.UseReplication/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Storage Accounts that pass this rule:
sku.name
property to a geo-replicated SKU. Such as Standard_GRS
.For example:
Azure Bicep snippetresource storageAccount 'Microsoft.Storage/storageAccounts@2023-01-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard_GRS'\n }\n kind: 'StorageV2'\n properties: {\n allowBlobPublicAccess: false\n supportsHttpsTrafficOnly: true\n minimumTlsVersion: 'TLS1_2'\n accessTier: 'Hot'\n allowSharedKeyAccess: false\n networkAcls: {\n defaultAction: 'Deny'\n }\n }\n}\n
","tags":["Azure.Storage.UseReplication","AZR-000195"]},{"location":"en/rules/Azure.Storage.UseReplication/#notes","title":"Notes","text":"This rule is not applicable for premium storage accounts. Storage Accounts with the following tags are automatically excluded from this rule:
ms-resource-usage = 'azure-cloud-shell'
- Storage Accounts used for Cloud Shell are not intended to store data. This tag is applied by Azure to Cloud Shell Storage Accounts by default.resource-usage = 'azure-functions'
- Storage Accounts used for Azure Functions. This tag can be optionally configured.resource-usage = 'azure-monitor'
- Storage Accounts used by Azure Monitor are intended for diagnostic logs. This tag can be optionally configured.Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_03 \u00b7 Awareness
Use default deployment detail level for nested deployments.
","tags":["Azure.Template.DebugDeployment","AZR-000225"]},{"location":"en/rules/Azure.Template.DebugDeployment/#description","title":"Description","text":"When creating Azure template, nested deployments can be created with debugging settings enabled. Deployment debugging detail is intended for troubleshooting deployments during development. Debugging settings may log sensitive values. Use caution when using this setting to debug of nested deployments.
To reduce nested deployment detail, remove or configure the properties.debugSetting.detailLevel
property to none
for nested deployments.
Consider disabling debugging of nested deployments before release.
","tags":["Azure.Template.DebugDeployment","AZR-000225"]},{"location":"en/rules/Azure.Template.DebugDeployment/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_03 \u00b7 Awareness
Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters.
","tags":["Azure.Template.DefineParameters","AZR-000218"]},{"location":"en/rules/Azure.Template.DefineParameters/#description","title":"Description","text":"Azure templates support parameters, which are inputs you can specify when deploying the template resources. Each template can support up to 256 parameters.
When defining template parameters:
defaultValue
.Consider defining a minimal number of parameters to make the template reusable.
","tags":["Azure.Template.DefineParameters","AZR-000218"]},{"location":"en/rules/Azure.Template.DefineParameters/#examples","title":"Examples","text":"","tags":["Azure.Template.DefineParameters","AZR-000218"]},{"location":"en/rules/Azure.Template.DefineParameters/#configure-with-azure-template","title":"Configure with Azure template","text":"To author templates that pass this rule:
For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"metadata\": {\n \"name\": \"Managed Identity\",\n \"description\": \"Create or update a Managed Identity.\"\n },\n \"parameters\": {\n \"identityName\": {\n \"type\": \"string\",\n \"metadata\": {\n \"description\": \"The name of the Managed Identity.\"\n }\n },\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"The Azure region to deploy to.\",\n \"example\": \"eastus\"\n }\n },\n \"tags\": {\n \"type\": \"object\",\n \"metadata\": {\n \"description\": \"Tags to apply to the resource.\",\n \"example\": {\n \"service\": \"app1\",\n \"env\": \"prod\"\n }\n }\n }\n },\n \"variables\": {\n \"tenantId\": \"[subscription().tenantId]\"\n },\n \"resources\": [\n {\n \"comments\": \"Create or update a Managed Identity\",\n \"type\": \"Microsoft.ManagedIdentity/userAssignedIdentities\",\n \"apiVersion\": \"2018-11-30\",\n \"name\": \"[parameters('identityName')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"tenantId\": \"[variables('tenantId')]\"\n },\n \"tags\": \"[parameters('tags')]\"\n }\n ]\n}\n
","tags":["Azure.Template.DefineParameters","AZR-000218"]},{"location":"en/rules/Azure.Template.DefineParameters/#notes","title":"Notes","text":"This rule is not applicable and ignored for templates generated with Bicep, PSArm and AzOps. Generated templates from these tools may not require any parameters to be set.
","tags":["Azure.Template.DefineParameters","AZR-000218"]},{"location":"en/rules/Azure.Template.DefineParameters/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_12 \u00b7 Awareness
Template expressions should not exceed the maximum length.
","tags":["Azure.Template.ExpressionLength","AZR-000228"]},{"location":"en/rules/Azure.Template.ExpressionLength/#description","title":"Description","text":"Extremely long expressions may be difficult to read and debug. Avoid using expressions that exceed 24,576 characters in length.
","tags":["Azure.Template.ExpressionLength","AZR-000228"]},{"location":"en/rules/Azure.Template.ExpressionLength/#recommendation","title":"Recommendation","text":"Consider updating the expression to reduce complexity and length.
","tags":["Azure.Template.ExpressionLength","AZR-000228"]},{"location":"en/rules/Azure.Template.ExpressionLength/#notes","title":"Notes","text":"This rule is not applicable and ignored for templates generated with Bicep, PSArm, and AzOps. Generated templates from these tools may not require any parameters to be set.
","tags":["Azure.Template.ExpressionLength","AZR-000228"]},{"location":"en/rules/Azure.Template.ExpressionLength/#links","title":"Links","text":"Reliability \u00b7 All resources \u00b7 Rule \u00b7 2021_03 \u00b7 Awareness
Set the default value for the location parameter within an ARM template to resource group location.
","tags":["Azure.Template.LocationDefault","AZR-000220"]},{"location":"en/rules/Azure.Template.LocationDefault/#description","title":"Description","text":"In the event of a regional outage in the resource group location, you will be unable to control resources inside that resource group, regardless of what region those resources are actually in. Resources for regional services should be deployed into a resource group on the same region.
When authoring templates, the resource group location should be the default resource location. This approach minimizes the number of times users are asked to provide location information.
","tags":["Azure.Template.LocationDefault","AZR-000220"]},{"location":"en/rules/Azure.Template.LocationDefault/#recommendation","title":"Recommendation","text":"Consider updating the location
parameter to use [resourceGroup().location]
as the default value.
To author templates that pass this rule:
location
parameter is specified, it should be set to [resourceGroup().location]
.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"The location resources will be deployed.\"\n }\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Network/networkSecurityGroups\",\n \"apiVersion\": \"2021-02-01\",\n \"name\": \"nsg-001\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"securityRules\": [\n {\n \"name\": \"deny-hop-outbound\",\n \"properties\": {\n \"priority\": 200,\n \"access\": \"Deny\",\n \"protocol\": \"Tcp\",\n \"direction\": \"Outbound\",\n \"sourceAddressPrefix\": \"VirtualNetwork\",\n \"destinationAddressPrefix\": \"*\",\n \"destinationPortRanges\": [\n \"3389\",\n \"22\"\n ]\n }\n }\n ]\n }\n }\n ]\n}\n
","tags":["Azure.Template.LocationDefault","AZR-000220"]},{"location":"en/rules/Azure.Template.LocationDefault/#configure-with-bicep","title":"Configure with Bicep","text":"To author bicep source files that pass this rule:
location
parameter is specified, it should be set to resourceGroup().location
.For example:
Azure Bicep snippet@description('The location resources will be deployed.')\nparam location string = resourceGroup().location\n
","tags":["Azure.Template.LocationDefault","AZR-000220"]},{"location":"en/rules/Azure.Template.LocationDefault/#notes","title":"Notes","text":"This rule ignores templates using tenant, Management Group, and Subscription deployment schemas. Deployment to these scopes does not occur against a resource group.
","tags":["Azure.Template.LocationDefault","AZR-000220"]},{"location":"en/rules/Azure.Template.LocationDefault/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_03 \u00b7 Important
Location parameters should use a string value.
","tags":["Azure.Template.LocationType","AZR-000221"]},{"location":"en/rules/Azure.Template.LocationType/#description","title":"Description","text":"The template parameter location
is a standard parameter recommended for deployment templates. The location
parameter is a intended for specifying the deployment location of the primary resource. When including location parameters in templates use the type string
.
Additionally, the template may include other resources. Use the location
parameter value for resources that are likely to be in the same location. This approach minimizes the number of times users are asked to provide location information.
Consider updating the location
parameter to be of type string
.
To author templates that pass this rule:
location
parameter is specified, it should be set to a string
type.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"The location resources will be deployed.\"\n }\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Network/networkSecurityGroups\",\n \"apiVersion\": \"2021-02-01\",\n \"name\": \"nsg-001\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"securityRules\": [\n {\n \"name\": \"deny-hop-outbound\",\n \"properties\": {\n \"priority\": 200,\n \"access\": \"Deny\",\n \"protocol\": \"Tcp\",\n \"direction\": \"Outbound\",\n \"sourceAddressPrefix\": \"VirtualNetwork\",\n \"destinationAddressPrefix\": \"*\",\n \"destinationPortRanges\": [\n \"3389\",\n \"22\"\n ]\n }\n }\n ]\n }\n }\n ]\n}\n
","tags":["Azure.Template.LocationType","AZR-000221"]},{"location":"en/rules/Azure.Template.LocationType/#configure-with-bicep","title":"Configure with Bicep","text":"To author bicep source files that pass this rule:
location
parameter is specified, it should be set to a string
type.For example:
Azure Bicep snippet@description('The location resources will be deployed.')\nparam location string = resourceGroup().location\n
","tags":["Azure.Template.LocationType","AZR-000221"]},{"location":"en/rules/Azure.Template.LocationType/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_09 \u00b7 Important
Configure a metadata link for each parameter file.
","tags":["Azure.Template.MetadataLink","AZR-000231"]},{"location":"en/rules/Azure.Template.MetadataLink/#description","title":"Description","text":"A parameter file can include an additional metadata. This metadata provides additional context for use of the parameter file.
PSRule for Azure uses the metadata.template
property within parameter files to store a metadata link. A metadata link, is an explicit association between a parameter file it's intended template file.
This rule is disabled by default but can be enabled by configuring AZURE_PARAMETER_FILE_METADATA_LINK
. Enable this rule to ensure that each parameter file has a metadata link to a valid template file.
Consider setting metadata for each parameter file linking to the deployment template.
","tags":["Azure.Template.MetadataLink","AZR-000231"]},{"location":"en/rules/Azure.Template.MetadataLink/#examples","title":"Examples","text":"","tags":["Azure.Template.MetadataLink","AZR-000231"]},{"location":"en/rules/Azure.Template.MetadataLink/#configure-parameter-file","title":"Configure parameter file","text":"To create parameter files that pass this rule:
metadata.template
property to a valid template file path.For example:
Azure Template snippet{\n \"$schema\": \"http://schema.management.azure.com/schemas/2015-01-01/deploymentParameters.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"metadata\": {\n \"template\": \"templates/storage/v1/template.json\"\n },\n \"parameters\": {\n \"storageAccountName\": {\n \"value\": \"...\"\n }\n }\n}\n
","tags":["Azure.Template.MetadataLink","AZR-000231"]},{"location":"en/rules/Azure.Template.MetadataLink/#notes","title":"Notes","text":"Enable this rule by setting the AZURE_PARAMETER_FILE_METADATA_LINK
option to true
.
Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_03 \u00b7 Important
Set the parameter default value to a value of the same type.
","tags":["Azure.Template.ParameterDataTypes","AZR-000226"]},{"location":"en/rules/Azure.Template.ParameterDataTypes/#description","title":"Description","text":"Azure Resource Manager (ARM) template support parameters with a range of types, including:
bool
int
string
array
object
secureString
secureObject
When including a defaultValue
, the default value should match the same type at the type
property. For example:
{\n \"boolParam\": {\n \"type\": \"bool\",\n \"defaultValue\": false\n },\n \"intParam\": {\n \"type\": \"int\",\n \"defaultValue\": 5\n },\n \"stringParam\": {\n \"type\": \"string\",\n \"defaultValue\": \"test-rg\"\n },\n \"arrayParam\": {\n \"type\": \"array\",\n \"defaultValue\": [ 1, 2, 3 ]\n },\n \"objectParam\": {\n \"type\": \"object\",\n \"defaultValue\": {\n \"one\": \"a\",\n \"two\": \"b\"\n }\n }\n}\n
","tags":["Azure.Template.ParameterDataTypes","AZR-000226"]},{"location":"en/rules/Azure.Template.ParameterDataTypes/#recommendation","title":"Recommendation","text":"Consider updating the parameter default value to a value of the same type.
","tags":["Azure.Template.ParameterDataTypes","AZR-000226"]},{"location":"en/rules/Azure.Template.ParameterDataTypes/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use ARM template parameter files that are valid.
","tags":["Azure.Template.ParameterFile","AZR-000229"]},{"location":"en/rules/Azure.Template.ParameterFile/#description","title":"Description","text":"Azure Resource Manager (ARM) template parameter files have a pre-defined structure. ARM template parameter files require $schema
, contentVersion
and parameters
sections to be defined. If any of these sections are missing, ARM will not accept the parameter file.
Consider reviewing the requirements for this file. Also consider using Visual Studio Code to assist with authoring these files.
","tags":["Azure.Template.ParameterFile","AZR-000229"]},{"location":"en/rules/Azure.Template.ParameterFile/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2020_09 \u00b7 Awareness
Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter.
","tags":["Azure.Template.ParameterMetadata","AZR-000215"]},{"location":"en/rules/Azure.Template.ParameterMetadata/#description","title":"Description","text":"ARM templates supports an additional metadata description to be added to each parameter. The parameter description is visible in Azure when using portal deployment pages. Additionally, descriptions provide context for people editing template and parameter files.
For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"storageAccountType\": {\n \"type\": \"string\",\n \"metadata\": {\n \"description\": \"The type of the new storage account created to store the VM disks.\"\n }\n }\n }\n}\n
","tags":["Azure.Template.ParameterMetadata","AZR-000215"]},{"location":"en/rules/Azure.Template.ParameterMetadata/#recommendation","title":"Recommendation","text":"Consider defining a metadata description for each template parameter.
","tags":["Azure.Template.ParameterMetadata","AZR-000215"]},{"location":"en/rules/Azure.Template.ParameterMetadata/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_03 \u00b7 Important
Template parameters minValue
and maxValue
constraints must be valid.
When defining Azure template parameters the minValue
or maxValue
constraints can be added to parameters. These constraints are only valid for parameters using the int
type. When configuring minValue
and maxValue
an integer must be used.
Consider updating parameter definitions using minValue
or maxValue
. When using minValue
or maxValue
these values must be integers and only apply to int
parameters.
Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_09 \u00b7 Awareness
Use an Azure template parameter file schema with the https scheme.
","tags":["Azure.Template.ParameterScheme","AZR-000230"]},{"location":"en/rules/Azure.Template.ParameterScheme/#description","title":"Description","text":"JSON schemas are used to validate the structure of Azure template parameter files. The JSON schema specification permits schemas to use https or http schemes. When using referencing schemas served by schema.management.azure.com
the http scheme redirects to https.
While http://schema.management.azure.com/schemas/2019-04-01/deploymentParameters.json#
points to a file. All supported Azure template parameter schemas use the https scheme.
Consider using a schema with the https scheme.
","tags":["Azure.Template.ParameterScheme","AZR-000230"]},{"location":"en/rules/Azure.Template.ParameterScheme/#examples","title":"Examples","text":"","tags":["Azure.Template.ParameterScheme","AZR-000230"]},{"location":"en/rules/Azure.Template.ParameterScheme/#configure-with-azure-template","title":"Configure with Azure template","text":"To define Azure template parameter files that pass this rule:
https://
URI prefix, such as https://schema.management.azure.com/schemas/2019-04-01/deploymentParameters.json#
.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentParameters.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": { }\n}\n
","tags":["Azure.Template.ParameterScheme","AZR-000230"]},{"location":"en/rules/Azure.Template.ParameterScheme/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_12 \u00b7 Awareness
Set the parameter value to a value that matches the specified strong type.
","tags":["Azure.Template.ParameterStrongType","AZR-000227"]},{"location":"en/rules/Azure.Template.ParameterStrongType/#description","title":"Description","text":"Template string parameters can optionally specify a strong type. When parameter files are expanded, if the parameter value does not match the type this rule fails. Support is provided by PSRule for Azure for the following types:
Microsoft.OperationalInsights/workspaces
. If a resource type is specified the parameter value must be a resource id of that type.location
as the strong type. If location
is specified, the parameter value must be a valid Azure location.Consider updating the parameter value to a value that matches the specifed strong type.
","tags":["Azure.Template.ParameterStrongType","AZR-000227"]},{"location":"en/rules/Azure.Template.ParameterStrongType/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_09 \u00b7 Awareness
Specify a value for each parameter in template parameter files.
","tags":["Azure.Template.ParameterValue","AZR-000232"]},{"location":"en/rules/Azure.Template.ParameterValue/#description","title":"Description","text":"When defining a template parameter file:
Consider defining a value for each parameter in the template parameter file.
","tags":["Azure.Template.ParameterValue","AZR-000232"]},{"location":"en/rules/Azure.Template.ParameterValue/#examples","title":"Examples","text":"","tags":["Azure.Template.ParameterValue","AZR-000232"]},{"location":"en/rules/Azure.Template.ParameterValue/#configure-with-azure-template","title":"Configure with Azure template","text":"To define Azure template parameter files that pass this rule:
For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentParameters.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"parameter1\": {\n \"value\": \"value1\"\n },\n \"parameter2\": {\n \"value\": []\n }\n }\n}\n
","tags":["Azure.Template.ParameterValue","AZR-000232"]},{"location":"en/rules/Azure.Template.ParameterValue/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_03 \u00b7 Awareness
Template resource location should be an expression or global
.
The template parameter location
is a standard parameter recommended for deployment templates. The location
parameter is a intended for specifying the deployment location of the primary resource.
When defining a resource that requires a location, use the location
parameter. For example:
{\n \"type\": \"Microsoft.Network/virtualNetworks\",\n \"name\": \"[parameters('VNETName')]\",\n \"apiVersion\": \"2020-06-01\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {}\n}\n
Additionally, the template may include other resources. Use the location
parameter value for resources that are likely to be in the same location. This approach minimizes the number of times users are asked to provide location information. For resources that aren't available in all locations, use a separate parameter.
For non-regional resources such as Front Door and DNS Zones specify a literal location global
.
Consider updating the resource location
property to use [parameters('location)]
.
Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2020_09 \u00b7 Awareness
Each Azure Resource Manager (ARM) template file should deploy at least one resource.
","tags":["Azure.Template.Resources","AZR-000216"]},{"location":"en/rules/Azure.Template.Resources/#description","title":"Description","text":"An ARM template file is used to create or update one or more Azure resources. The resources
property of an ARM template includes a definition of the resources to deploy.
Consider removing Azure template files that do not deploy any resources.
","tags":["Azure.Template.Resources","AZR-000216"]},{"location":"en/rules/Azure.Template.Resources/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use ARM template files that are valid.
","tags":["Azure.Template.TemplateFile","AZR-000212"]},{"location":"en/rules/Azure.Template.TemplateFile/#description","title":"Description","text":"Azure Resource Manager (ARM) template files have a pre-defined structure. ARM templates require $schema
, contentVersion
and resources
sections to be defined. If any of these sections are missing, ARM will not accept the template.
Consider reviewing the requirements for this file. Also consider using Visual Studio Code to assist with authoring these files.
","tags":["Azure.Template.TemplateFile","AZR-000212"]},{"location":"en/rules/Azure.Template.TemplateFile/#examples","title":"Examples","text":"","tags":["Azure.Template.TemplateFile","AZR-000212"]},{"location":"en/rules/Azure.Template.TemplateFile/#configure-with-azure-template","title":"Configure with Azure template","text":"To define Azure template files that pass this rule:
$schema
, contentVersion
and resources
properties.languageVersion
, definitions
, metadata
, parameters
, functions
, variables
, and outputs
properties.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": { },\n \"variables\": { },\n \"resources\": [ ]\n}\n
","tags":["Azure.Template.TemplateFile","AZR-000212"]},{"location":"en/rules/Azure.Template.TemplateFile/#notes","title":"Notes","text":"This rule is not applicable to Azure Bicep files as they have a different structure. If you are running analysis over pre-built Bicep files and they generate a rule failure, please raise an issue.
","tags":["Azure.Template.TemplateFile","AZR-000212"]},{"location":"en/rules/Azure.Template.TemplateFile/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_09 \u00b7 Awareness
Use a more recent version of the Azure template schema.
","tags":["Azure.Template.TemplateSchema","AZR-000213"]},{"location":"en/rules/Azure.Template.TemplateSchema/#description","title":"Description","text":"The JSON schemas used to define Azure templates are versioned. When defining templates use templates with a supported schema.
The following template schemas are deprecated:
https://schema.management.azure.com/schemas/2015-01-01/deploymentTemplate.json#
Consider using a more recent schema version for Azure template files.
","tags":["Azure.Template.TemplateSchema","AZR-000213"]},{"location":"en/rules/Azure.Template.TemplateSchema/#examples","title":"Examples","text":"","tags":["Azure.Template.TemplateSchema","AZR-000213"]},{"location":"en/rules/Azure.Template.TemplateSchema/#configure-with-azure-template","title":"Configure with Azure template","text":"To define Azure template files that pass this rule:
https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#
https://schema.management.azure.com/schemas/2018-05-01/subscriptionDeploymentTemplate.json#
https://schema.management.azure.com/schemas/2019-08-01/tenantDeploymentTemplate.json#
https://schema.management.azure.com/schemas/2019-08-01/managementGroupDeploymentTemplate.json#
For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": { },\n \"functions\": [],\n \"resources\": [ ]\n}\n
","tags":["Azure.Template.TemplateSchema","AZR-000213"]},{"location":"en/rules/Azure.Template.TemplateSchema/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_09 \u00b7 Awareness
Use an Azure template file schema with the https scheme.
","tags":["Azure.Template.TemplateScheme","AZR-000214"]},{"location":"en/rules/Azure.Template.TemplateScheme/#description","title":"Description","text":"JSON schemas are used to validate the structure of Azure template files. The JSON schema specification permits schemas to use https or http schemes. When using referencing schemas served by schema.management.azure.com
the http scheme redirects to https.
While http://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#
points to a file. All supported Azure template schemas use the https scheme.
Consider using a schema with the https scheme.
","tags":["Azure.Template.TemplateScheme","AZR-000214"]},{"location":"en/rules/Azure.Template.TemplateScheme/#examples","title":"Examples","text":"","tags":["Azure.Template.TemplateScheme","AZR-000214"]},{"location":"en/rules/Azure.Template.TemplateScheme/#configure-with-azure-template","title":"Configure with Azure template","text":"To define Azure template files that pass this rule:
https://
URI prefix, such as https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#
.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": { },\n \"functions\": [],\n \"resources\": [ ]\n}\n
","tags":["Azure.Template.TemplateScheme","AZR-000214"]},{"location":"en/rules/Azure.Template.TemplateScheme/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_12 \u00b7 Awareness
Use comments for each resource in ARM template to communicate purpose.
","tags":["Azure.Template.UseComments","AZR-000234"]},{"location":"en/rules/Azure.Template.UseComments/#description","title":"Description","text":"ARM templates can optionally include comments in resources. This helps other contributors understand the purpose of the resource.
","tags":["Azure.Template.UseComments","AZR-000234"]},{"location":"en/rules/Azure.Template.UseComments/#recommendation","title":"Recommendation","text":"Specify comments for each resource in the template.
","tags":["Azure.Template.UseComments","AZR-000234"]},{"location":"en/rules/Azure.Template.UseComments/#examples","title":"Examples","text":"","tags":["Azure.Template.UseComments","AZR-000234"]},{"location":"en/rules/Azure.Template.UseComments/#configure-with-azure-template","title":"Configure with Azure template","text":"To define Azure template files that pass this rule:
comments
for each resource in the template.For example:
Azure Template snippet\"resources\": [\n {\n \"name\": \"[variables('storageAccountName')]\",\n \"type\": \"Microsoft.Storage/storageAccounts\",\n \"apiVersion\": \"2019-06-01\",\n \"location\": \"[resourceGroup().location]\",\n \"comments\": \"This storage account is used to store the VM disks.\",\n ...\n }\n]\n
","tags":["Azure.Template.UseComments","AZR-000234"]},{"location":"en/rules/Azure.Template.UseComments/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_12 \u00b7 Awareness
Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose.
","tags":["Azure.Template.UseDescriptions","AZR-000235"]},{"location":"en/rules/Azure.Template.UseDescriptions/#description","title":"Description","text":"Generated templates can optionally include descriptions in resources. This helps other contributors understand the purpose of the resource.
","tags":["Azure.Template.UseDescriptions","AZR-000235"]},{"location":"en/rules/Azure.Template.UseDescriptions/#recommendation","title":"Recommendation","text":"Specify descriptions for each resource in the template.
","tags":["Azure.Template.UseDescriptions","AZR-000235"]},{"location":"en/rules/Azure.Template.UseDescriptions/#examples","title":"Examples","text":"","tags":["Azure.Template.UseDescriptions","AZR-000235"]},{"location":"en/rules/Azure.Template.UseDescriptions/#configure-with-bicep","title":"Configure with Bicep","text":"To define Bicep template files that pass this rule:
@description()
or @sys.description()
decorator for each resource in the template.For example:
Azure Bicep snippet// An example container registry\n@description('abc')\nresource acr 'Microsoft.ContainerRegistry/registries@2021-06-01-preview' = {\n name: registryName\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n quarantinePolicy: {\n status: 'enabled'\n }\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n status: 'enabled'\n days: 30\n }\n }\n }\n}\n
","tags":["Azure.Template.UseDescriptions","AZR-000235"]},{"location":"en/rules/Azure.Template.UseDescriptions/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_03 \u00b7 Awareness
Template should reference a location parameter to specify resource location.
","tags":["Azure.Template.UseLocationParameter","AZR-000223"]},{"location":"en/rules/Azure.Template.UseLocationParameter/#description","title":"Description","text":"The template parameter location
is a standard parameter recommended for deployment templates. The location
parameter is a intended for specifying the deployment location of the primary resource.
When defining a resource that requires a location, use the location
parameter. For example:
{\n \"type\": \"Microsoft.Network/virtualNetworks\",\n \"name\": \"[parameters('VNETName')]\",\n \"apiVersion\": \"2020-06-01\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {}\n}\n
Additionally, the template may include other resources. Use the location
parameter value for resources that are likely to be in the same location. This approach minimizes the number of times users are asked to provide location information. For resources that aren't available in all locations, use a separate parameter.
Consider using parameters('location)
instead of resourceGroup().location
. Using a location parameter enabled users of the template to specify the location of deployed resources.
To author templates that pass this rule:
location
.[parameters('location')]
.For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"metadata\": {\n \"name\": \"Managed Identity\",\n \"description\": \"Create or update a Managed Identity.\"\n },\n \"parameters\": {\n \"identityName\": {\n \"type\": \"string\",\n \"metadata\": {\n \"description\": \"The name of the Managed Identity.\"\n }\n },\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"The Azure region to deploy to.\",\n \"example\": \"eastus\"\n }\n },\n \"tags\": {\n \"type\": \"object\",\n \"metadata\": {\n \"description\": \"Tags to apply to the resource.\",\n \"example\": {\n \"service\": \"app1\",\n \"env\": \"prod\"\n }\n }\n }\n },\n \"variables\": {\n \"tenantId\": \"[subscription().tenantId]\"\n },\n \"resources\": [\n {\n \"comments\": \"Create or update a Managed Identity\",\n \"type\": \"Microsoft.ManagedIdentity/userAssignedIdentities\",\n \"apiVersion\": \"2018-11-30\",\n \"name\": \"[parameters('identityName')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"tenantId\": \"[variables('tenantId')]\"\n },\n \"tags\": \"[parameters('tags')]\"\n }\n ]\n}\n
","tags":["Azure.Template.UseLocationParameter","AZR-000223"]},{"location":"en/rules/Azure.Template.UseLocationParameter/#notes","title":"Notes","text":"This rule is not applicable and ignored for templates generated with Bicep, PSArm, and AzOps. Generated templates from these tools may not require any parameters to be set.
","tags":["Azure.Template.UseLocationParameter","AZR-000223"]},{"location":"en/rules/Azure.Template.UseLocationParameter/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2020_09 \u00b7 Awareness
Each Azure Resource Manager (ARM) template parameter should be used or removed from template files.
","tags":["Azure.Template.UseParameters","AZR-000217"]},{"location":"en/rules/Azure.Template.UseParameters/#description","title":"Description","text":"ARM templates can optionally define parameters that can be reused throughout the template. Parameters that are not used may make template use more complex for no benefit.
","tags":["Azure.Template.UseParameters","AZR-000217"]},{"location":"en/rules/Azure.Template.UseParameters/#recommendation","title":"Recommendation","text":"Consider removing unused parameters from Azure template files.
","tags":["Azure.Template.UseParameters","AZR-000217"]},{"location":"en/rules/Azure.Template.UseParameters/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2020_09 \u00b7 Awareness
Each Azure Resource Manager (ARM) template variable should be used or removed from template files.
","tags":["Azure.Template.UseVariables","AZR-000219"]},{"location":"en/rules/Azure.Template.UseVariables/#description","title":"Description","text":"ARM templates can optionally define variables that can be reused throughout the template. Variables that are not used may add template complexity for no benefit.
","tags":["Azure.Template.UseVariables","AZR-000219"]},{"location":"en/rules/Azure.Template.UseVariables/#recommendation","title":"Recommendation","text":"Consider removing unused variables from Azure template files.
","tags":["Azure.Template.UseVariables","AZR-000219"]},{"location":"en/rules/Azure.Template.UseVariables/#links","title":"Links","text":"Operational Excellence \u00b7 All resources \u00b7 Rule \u00b7 2021_09 \u00b7 Awareness
Use a valid secret reference within parameter files.
","tags":["Azure.Template.ValidSecretRef","AZR-000233"]},{"location":"en/rules/Azure.Template.ValidSecretRef/#description","title":"Description","text":"When referencing secrets in a template parameter file:
Check the secret value Key Vault reference is valid.
","tags":["Azure.Template.ValidSecretRef","AZR-000233"]},{"location":"en/rules/Azure.Template.ValidSecretRef/#examples","title":"Examples","text":"","tags":["Azure.Template.ValidSecretRef","AZR-000233"]},{"location":"en/rules/Azure.Template.ValidSecretRef/#configure-with-azure-template","title":"Configure with Azure template","text":"To define Azure template parameter files that pass this rule:
For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentParameters.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"gatewayName\": {\n \"value\": \"gateway-A\"\n },\n \"sku\": {\n \"value\": \"VpnGw1\"\n },\n \"subnetId\": {\n \"value\": \"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/virtualNetworks/vnet-A/subnets/GatewaySubnet\"\n },\n \"sharedKey\": {\n \"reference\": {\n \"keyVault\": {\n \"id\": \"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.KeyVault/vaults/kv-001\"\n },\n \"secretName\": \"valid-secret\"\n }\n }\n }\n}\n
","tags":["Azure.Template.ValidSecretRef","AZR-000233"]},{"location":"en/rules/Azure.Template.ValidSecretRef/#links","title":"Links","text":"Reliability \u00b7 Traffic Manager \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Traffic Manager should use at lest two enabled endpoints.
","tags":["Azure.TrafficManager.Endpoints","AZR-000236"]},{"location":"en/rules/Azure.TrafficManager.Endpoints/#description","title":"Description","text":"Traffic Manager is a DNS service that enables you to distribute traffic to improve availability and responsiveness. Traffic is distributed across endpoints, which can be located in different availability zones and regions.
When only one enabled endpoint exists, routing for high availability and/ or responsiveness is not possible.
","tags":["Azure.TrafficManager.Endpoints","AZR-000236"]},{"location":"en/rules/Azure.TrafficManager.Endpoints/#recommendation","title":"Recommendation","text":"Consider adding additional endpoints or enabling disabled endpoints. Also consider, using endpoints deployed across different regions to provide high availability.
","tags":["Azure.TrafficManager.Endpoints","AZR-000236"]},{"location":"en/rules/Azure.TrafficManager.Endpoints/#links","title":"Links","text":"Security \u00b7 Traffic Manager \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Monitor Traffic Manager web-based endpoints with HTTPS.
","tags":["Azure.TrafficManager.Protocol","AZR-000237"]},{"location":"en/rules/Azure.TrafficManager.Protocol/#description","title":"Description","text":"Traffic Manager can use TCP, HTTP or HTTPS to monitor endpoint health. For web-based endpoints use HTTPS.
If TCP is used, Traffic Manager only checks that it can open a TCP port on the endpoint. This alone does not indicate that the endpoint is operational and ready to receive requests. Additionally when using HTTP and HTTPS, Traffic Manager check HTTP response codes.
If HTTP is used, Traffic Manager will send unencrypted health checks to the endpoint. HTTPS-based health checks additionally check if a certificate is present, but do not validate if the certificate is valid.
","tags":["Azure.TrafficManager.Protocol","AZR-000237"]},{"location":"en/rules/Azure.TrafficManager.Protocol/#recommendation","title":"Recommendation","text":"Consider using HTTPS to monitor web-based endpoint health. HTTPS-based monitoring improves security and increases accuracy of health probes.
","tags":["Azure.TrafficManager.Protocol","AZR-000237"]},{"location":"en/rules/Azure.TrafficManager.Protocol/#examples","title":"Examples","text":"","tags":["Azure.TrafficManager.Protocol","AZR-000237"]},{"location":"en/rules/Azure.TrafficManager.Protocol/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Traffic Manager profiles that pass this rule:
properties.monitorConfig.protocol
property to HTTPS
for HTTP-based endpoints.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/trafficmanagerprofiles\",\n \"apiVersion\": \"2022-04-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"global\",\n \"properties\": {\n \"endpoints\": \"[parameters('endpoints')]\",\n \"trafficRoutingMethod\": \"Performance\",\n \"monitorConfig\": {\n \"protocol\": \"HTTPS\",\n \"port\": 443,\n \"intervalInSeconds\": 30,\n \"timeoutInSeconds\": 5,\n \"toleratedNumberOfFailures\": 3,\n \"path\": \"/healthz\"\n }\n }\n}\n
","tags":["Azure.TrafficManager.Protocol","AZR-000237"]},{"location":"en/rules/Azure.TrafficManager.Protocol/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Traffic Manager profiles that pass this rule:
properties.monitorConfig.protocol
property to HTTPS
for HTTP-based endpoints.For example:
Azure Bicep snippetresource profile 'Microsoft.Network/trafficmanagerprofiles@2022-04-01' = {\n name: name\n location: 'global'\n properties: {\n endpoints: endpoints\n trafficRoutingMethod: 'Performance'\n monitorConfig: {\n protocol: 'HTTPS'\n port: 443\n intervalInSeconds: 30\n timeoutInSeconds: 5\n toleratedNumberOfFailures: 3\n path: '/healthz'\n }\n }\n}\n
","tags":["Azure.TrafficManager.Protocol","AZR-000237"]},{"location":"en/rules/Azure.TrafficManager.Protocol/#links","title":"Links","text":"Security \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use Azure Disk Encryption (ADE).
","tags":["Azure.VM.ADE","AZR-000252"]},{"location":"en/rules/Azure.VM.ADE/#description","title":"Description","text":"Virtual machines (VMs) can be encrypted using ADE to protect disks with full disk encryption. Storage Service Encryption (SSE) is encryption as rest for Managed Disks and Storage Accounts. SSE automatically decrypts storage as it is read. Full disk encryption varies from SSE by decrypting disks on read within the operating system.
ADE protects disk decryption keys within Key Vault.
","tags":["Azure.VM.ADE","AZR-000252"]},{"location":"en/rules/Azure.VM.ADE/#recommendation","title":"Recommendation","text":"Consider using Azure Disk Encryption (ADE) to protect VM disks from being downloaded and accessed offline.
","tags":["Azure.VM.ADE","AZR-000252"]},{"location":"en/rules/Azure.VM.ADE/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Machine \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Use Azure Monitor Agent for collecting monitoring data from VMs.
","tags":["Azure.VM.AMA","AZR-000345"]},{"location":"en/rules/Azure.VM.AMA/#description","title":"Description","text":"Azure Monitor is the platform capability for monitoring and observability in Azure. Azure Monitor collects monitoring telemetry from a variety of on-premises, multi-cloud, and Azure sources.
To monitor Windows and Linux operating systems the Azure Monitor Agent (AMA) is deployed. Once the AMA the agent is deployed, collected data gets delivered to Azure Monitor, where is can be used for:
For Azure virtual machines (VMs), virtual machine scale sets (VMSS), and Azure Arc enabled servers the monitoring agent is deployed as an extension. The extension also supports modern management capabilities such as Azure Policy, automatic updates, and deployment as Infrastructure as Code.
The AMA replaces Azure Monitor's legacy monitoring agents.
","tags":["Azure.VM.AMA","AZR-000345"]},{"location":"en/rules/Azure.VM.AMA/#recommendation","title":"Recommendation","text":"Consider monitoring virtual machines (VMs) with the Azure Monitor Agent.
","tags":["Azure.VM.AMA","AZR-000345"]},{"location":"en/rules/Azure.VM.AMA/#examples","title":"Examples","text":"","tags":["Azure.VM.AMA","AZR-000345"]},{"location":"en/rules/Azure.VM.AMA/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy virtual machines that pass this rule:
Microsoft.Compute/virtualMachines/extensions
.properties.publisher
to Microsoft.Azure.Monitor
.properties.type
to AzureMonitorWindowsAgent
(Windows) or AzureMonitorLinuxAgent
(Linux).For example:
Azure Template snippet{\n \"type\": \"Microsoft.Compute/virtualMachines/extensions\",\n \"apiVersion\": \"2023-09-01\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'AzureMonitorWindowsAgent')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"publisher\": \"Microsoft.Azure.Monitor\",\n \"type\": \"AzureMonitorWindowsAgent\",\n \"typeHandlerVersion\": \"1.0\",\n \"autoUpgradeMinorVersion\": true,\n \"enableAutomaticUpgrade\": true,\n \"settings\": {\n \"authentication\": {\n \"managedIdentity\": {\n \"identifier-name\": \"mi_res_id\",\n \"identifier-value\": \"[parameters('amaIdentityId')]\"\n }\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Compute/virtualMachines', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.VM.AMA","AZR-000345"]},{"location":"en/rules/Azure.VM.AMA/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy virtual machines that pass this rule:
Microsoft.Compute/virtualMachines/extensions
.properties.publisher
to Microsoft.Azure.Monitor
.properties.type
to AzureMonitorWindowsAgent
(Windows) or AzureMonitorLinuxAgent
(Linux).For example:
Azure Bicep snippetresource windowsAgent 'Microsoft.Compute/virtualMachines/extensions@2023-09-01' = {\n parent: vm\n name: 'AzureMonitorWindowsAgent'\n location: location\n properties: {\n publisher: 'Microsoft.Azure.Monitor'\n type: 'AzureMonitorWindowsAgent'\n typeHandlerVersion: '1.0'\n autoUpgradeMinorVersion: true\n enableAutomaticUpgrade: true\n settings: {\n authentication: {\n managedIdentity: {\n 'identifier-name': 'mi_res_id'\n 'identifier-value': amaIdentityId\n }\n }\n }\n }\n}\n
","tags":["Azure.VM.AMA","AZR-000345"]},{"location":"en/rules/Azure.VM.AMA/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"To configure virtual machine using a user-assigned identity:
Microsoft.Compute/virtualMachines/extensions
.--name
parameter to AzureMonitorWindowsAgent
(Windows) or AzureMonitorLinuxAgent
(Linux).For example:
Azure CLI snippetaz vm extension set --name 'AzureMonitorWindowsAgent' --publisher Microsoft.Azure.Monitor --ids '<vm-resource-id>' --enable-auto-upgrade true --settings '{\"authentication\":{\"managedIdentity\":{\"identifier-name\":\"mi_res_id\",\"identifier-value\":\"/subscriptions/<my-subscription-id>/resourceGroups/<my-resource-group>/providers/Microsoft.ManagedIdentity/userAssignedIdentities/<my-user-assigned-identity>\"}}}'\n
","tags":["Azure.VM.AMA","AZR-000345"]},{"location":"en/rules/Azure.VM.AMA/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"To configure virtual machine using a user-assigned identity:
Microsoft.Compute/virtualMachines/extensions
.-ExtensionType
parameter to AzureMonitorWindowsAgent
(Windows) or AzureMonitorLinuxAgent
(Linux).For example:
Azure PowerShell snippetSet-AzVMExtension -Name AzureMonitorWindowsAgent -ExtensionType 'AzureMonitorWindowsAgent' -Publisher Microsoft.Azure.Monitor -ResourceGroupName '<resource-group-name>' -VMName '<virtual-machine-name>' -Location '<location>' -TypeHandlerVersion '1.0' -EnableAutomaticUpgrade $true -SettingString '{\"authentication\":{\"managedIdentity\":{\"identifier-name\":\"mi_res_id\",\"identifier-value\":\"/subscriptions/<my-subscription-id>/resourceGroups/<my-resource-group>/providers/Microsoft.ManagedIdentity/userAssignedIdentities/<my-user-assigned-identity>\"}}}'\n
","tags":["Azure.VM.AMA","AZR-000345"]},{"location":"en/rules/Azure.VM.AMA/#notes","title":"Notes","text":"Deploying Azure Monitor Agent (AMA) extension alone does not include all configuration needed. Additionally data collection rules and associations are required to specify what data is collected and where it is sent.
","tags":["Azure.VM.AMA","AZR-000345"]},{"location":"en/rules/Azure.VM.AMA/#links","title":"Links","text":"Reliability \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use availability sets aligned with managed disks fault domains.
","tags":["Azure.VM.ASAlignment","AZR-000254"]},{"location":"en/rules/Azure.VM.ASAlignment/#description","title":"Description","text":"Availability sets can be configured to align with managed disk fault domains. When aligned, the fault domain for storage is co-located with compute. Aligned availability sets help prevent compute and storage from a single VM spanning multiple fault domains.
","tags":["Azure.VM.ASAlignment","AZR-000254"]},{"location":"en/rules/Azure.VM.ASAlignment/#recommendation","title":"Recommendation","text":"Consider deploying VMs with managed disks into aligned availability sets.
","tags":["Azure.VM.ASAlignment","AZR-000254"]},{"location":"en/rules/Azure.VM.ASAlignment/#links","title":"Links","text":"Reliability \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Availability sets should be deployed with at least two virtual machines (VMs).
","tags":["Azure.VM.ASMinMembers","AZR-000255"]},{"location":"en/rules/Azure.VM.ASMinMembers/#description","title":"Description","text":"An availability set is a logical grouping of VMs that allows Azure to optimize the placement of VMs. Azure uses this grouping to separate VMs within the availablity set across fault and update domains. Each VM in your availability set is assigned an update domain and a fault domain. VMs in different update and fault domains is mapped to different underlying physical hardware. The reason for doing this is to improve reliability by removing some single points of failure.
Deploy two or more VMs within an availability set to provide for a highly available application. There is no cost for the Availability Set itself, you only pay for each VM instance that you create.
","tags":["Azure.VM.ASMinMembers","AZR-000255"]},{"location":"en/rules/Azure.VM.ASMinMembers/#recommendation","title":"Recommendation","text":"Consider deploying at least two VMs within an availability set to gain availability benefits.
","tags":["Azure.VM.ASMinMembers","AZR-000255"]},{"location":"en/rules/Azure.VM.ASMinMembers/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed to Azure (in-flight).
","tags":["Azure.VM.ASMinMembers","AZR-000255"]},{"location":"en/rules/Azure.VM.ASMinMembers/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Availability Set names should meet naming requirements.
","tags":["Azure.VM.ASName","AZR-000256"]},{"location":"en/rules/Azure.VM.ASName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Availability Set names are:
Consider using names that meet Availability Set naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.VM.ASName","AZR-000256"]},{"location":"en/rules/Azure.VM.ASName/#notes","title":"Notes","text":"This rule does not check if Availability Set names are unique.
","tags":["Azure.VM.ASName","AZR-000256"]},{"location":"en/rules/Azure.VM.ASName/#links","title":"Links","text":"Performance Efficiency \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use accelerated networking for supported operating systems and VM types.
","tags":["Azure.VM.AcceleratedNetworking","AZR-000244"]},{"location":"en/rules/Azure.VM.AcceleratedNetworking/#description","title":"Description","text":"Enabling accelerated networking for a virtual machine (VM) greatly improves networking performance. Accelerated networking work by enabling single root I/O virtualization (SR-IOV) to a VM. SR-IOV reduces latency, jitter, and CPU utilization network demanding workloads.
Accelerated networking is available for supported operating systems and VM types.
","tags":["Azure.VM.AcceleratedNetworking","AZR-000244"]},{"location":"en/rules/Azure.VM.AcceleratedNetworking/#recommendation","title":"Recommendation","text":"Consider enabling accelerated networking for supported operating systems and VM types.
","tags":["Azure.VM.AcceleratedNetworking","AZR-000244"]},{"location":"en/rules/Azure.VM.AcceleratedNetworking/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Ensure the VM agent is provisioned automatically.
","tags":["Azure.VM.Agent","AZR-000246"]},{"location":"en/rules/Azure.VM.Agent/#description","title":"Description","text":"The virtual machine (VM) agent is required for most functionality that interacts with the guest operating system.
VM extensions help reduce management overhead by providing an entry point to bootstrap monitoring and configuration of the guest operating system. The VM agent is required to use any VM extensions.
","tags":["Azure.VM.Agent","AZR-000246"]},{"location":"en/rules/Azure.VM.Agent/#recommendation","title":"Recommendation","text":"Automatically provision the VM agent for all supported operating systems, this is the default.
","tags":["Azure.VM.Agent","AZR-000246"]},{"location":"en/rules/Azure.VM.BasicSku/","title":"Avoid Basic VM SKU","text":"Azure.VM.BasicSkuAZR-000241ErrorOperational Excellence \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Virtual machines (VMs) should not use Basic sizes.
","tags":["Azure.VM.BasicSku","AZR-000241"]},{"location":"en/rules/Azure.VM.BasicSku/#description","title":"Description","text":"VMs can be deployed in Basic or Standard sizes. Basic VM sizes are suitable only for entry level development scenarios.
","tags":["Azure.VM.BasicSku","AZR-000241"]},{"location":"en/rules/Azure.VM.BasicSku/#recommendation","title":"Recommendation","text":"Basic VM sizes are not suitable for production workloads or intensive development workloads. Consider migration to an alternative Standard VM size.
","tags":["Azure.VM.BasicSku","AZR-000241"]},{"location":"en/rules/Azure.VM.BasicSku/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Virtual Machine (VM) computer name should meet naming requirements.
","tags":["Azure.VM.ComputerName","AZR-000249"]},{"location":"en/rules/Azure.VM.ComputerName/#description","title":"Description","text":"When configuring Azure VMs the assigned computer name must meet operation system (OS) requirements.
The requirements for Windows VMs are:
The requirements for Linux VMs are:
Consider using computer names that meet OS naming requirements. Additionally, consider using computer names that match the VM resource name.
","tags":["Azure.VM.ComputerName","AZR-000249"]},{"location":"en/rules/Azure.VM.ComputerName/#notes","title":"Notes","text":"VM resource names have different naming restrictions. See Azure.VM.Name
for details.
Cost Optimization \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Managed disks should be attached to virtual machines or removed.
","tags":["Azure.VM.DiskAttached","AZR-000250"]},{"location":"en/rules/Azure.VM.DiskAttached/#description","title":"Description","text":"Unattached managed disks are charged but not in use. Unattached managed disks still consume storage and are charged on their size.
","tags":["Azure.VM.DiskAttached","AZR-000250"]},{"location":"en/rules/Azure.VM.DiskAttached/#recommendation","title":"Recommendation","text":"Consider removing managed disks that are no longer required to reduce complexity and costs.
","tags":["Azure.VM.DiskAttached","AZR-000250"]},{"location":"en/rules/Azure.VM.DiskAttached/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.VM.DiskAttached","AZR-000250"]},{"location":"en/rules/Azure.VM.DiskAttached/#links","title":"Links","text":"Performance Efficiency \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Check disk caching is configured correctly for the workload.
","tags":["Azure.VM.DiskCaching","AZR-000242"]},{"location":"en/rules/Azure.VM.DiskCaching/#description","title":"Description","text":"Check disk caching is configured correctly for the workload.
","tags":["Azure.VM.DiskCaching","AZR-000242"]},{"location":"en/rules/Azure.VM.DiskCaching/#recommendation","title":"Recommendation","text":"Check disk caching is configured correctly for the workload.
","tags":["Azure.VM.DiskCaching","AZR-000242"]},{"location":"en/rules/Azure.VM.DiskName/","title":"Use valid Managed Disk names","text":"Azure.VM.DiskNameAZR-000253ErrorOperational Excellence \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Managed Disk names should meet naming requirements.
","tags":["Azure.VM.DiskName","AZR-000253"]},{"location":"en/rules/Azure.VM.DiskName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Managed Disk names are:
Consider using names that meet Managed Disk naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.VM.DiskName","AZR-000253"]},{"location":"en/rules/Azure.VM.DiskName/#notes","title":"Notes","text":"This rule does not check if Managed Disk names are unique.
","tags":["Azure.VM.DiskName","AZR-000253"]},{"location":"en/rules/Azure.VM.DiskName/#links","title":"Links","text":"Cost Optimization \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Align to the Managed Disk billing increments to improve cost efficiency.
","tags":["Azure.VM.DiskSizeAlignment","AZR-000251"]},{"location":"en/rules/Azure.VM.DiskSizeAlignment/#description","title":"Description","text":"Azure managed disks are billed based on predefined size increments. The billing increments are based on the disk storage type. These include:
Premium SSD
- 4/ 8/ 16/ 32/ 64/ 128/ 256/ 512/ 1024/ 2048/ 4096/ 8192/ 16384/ 32768 GiB.Standard SSD
- 4/ 8/ 16/ 32/ 64/ 128/ 256/ 512/ 1024/ 2048/ 4096/ 8192/ 16384/ 32768 GiB.Standard HDD
- 32/ 64/ 128/ 256/ 512/ 1024/ 2048/ 4096/ 8192/ 16384/ 32768 GiB.Ultra SSD
- 4/ 8/ 16/ 32/ 64/ 128/ 256/ 512 GiB, then 1 TiB increments to 64 TiB.If you provision a disk that is not aligned to the billing model, you will be billed for the next increment. For example, if a disk is provisioned at 33 GiB, the disk is billed as 64 GiB.
","tags":["Azure.VM.DiskSizeAlignment","AZR-000251"]},{"location":"en/rules/Azure.VM.DiskSizeAlignment/#recommendation","title":"Recommendation","text":"Consider aligning provisioned disk sizes to the billing increments for Managed Disks to improve cost efficiency.
","tags":["Azure.VM.DiskSizeAlignment","AZR-000251"]},{"location":"en/rules/Azure.VM.DiskSizeAlignment/#examples","title":"Examples","text":"","tags":["Azure.VM.DiskSizeAlignment","AZR-000251"]},{"location":"en/rules/Azure.VM.DiskSizeAlignment/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy managed disks that pass this rule:
properties.diskSizeGB
property to a value that aligns to the billing model of the disk storage type. E.g. 32
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Compute/disks\",\n \"apiVersion\": \"2023-04-02\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium_ZRS\"\n },\n \"properties\": {\n \"creationData\": {\n \"createOption\": \"Empty\"\n },\n \"diskSizeGB\": 32\n }\n}\n
","tags":["Azure.VM.DiskSizeAlignment","AZR-000251"]},{"location":"en/rules/Azure.VM.DiskSizeAlignment/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy managed disks that pass this rule:
properties.diskSizeGB
property to a value that aligns to the billing model of the disk storage type. E.g. 32
.For example:
Azure Bicep snippetresource dataDisk 'Microsoft.Compute/disks@2023-04-02' = {\n name: name\n location: location\n sku: {\n name: 'Premium_ZRS'\n }\n properties: {\n creationData: {\n createOption: 'Empty'\n }\n diskSizeGB: 32\n }\n}\n
","tags":["Azure.VM.DiskSizeAlignment","AZR-000251"]},{"location":"en/rules/Azure.VM.DiskSizeAlignment/#notes","title":"Notes","text":"This rule has the following limitations:
Operational Excellence \u00b7 Virtual Machine \u00b7 Rule \u00b7 Preview \u00b7 2023_06 \u00b7 Important
Use a maintenance configuration for virtual machines.
","tags":["Azure.VM.MaintenanceConfig","AZR-000375"]},{"location":"en/rules/Azure.VM.MaintenanceConfig/#description","title":"Description","text":"Virtual machines can be attached to a maintenance configuration which allows customer managed assessments and updates for machine patches within the guest operating system.
","tags":["Azure.VM.MaintenanceConfig","AZR-000375"]},{"location":"en/rules/Azure.VM.MaintenanceConfig/#recommendation","title":"Recommendation","text":"Consider automatically managing and applying operating system updates by associating a maintenance configuration.
","tags":["Azure.VM.MaintenanceConfig","AZR-000375"]},{"location":"en/rules/Azure.VM.MaintenanceConfig/#examples","title":"Examples","text":"","tags":["Azure.VM.MaintenanceConfig","AZR-000375"]},{"location":"en/rules/Azure.VM.MaintenanceConfig/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy virtual machines that pass this rule:
Microsoft.Maintenance/configurationAssignments
sub-resource (extension resource).properties.maintenanceConfigurationId
property to the linked maintenance configuration resource Id.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Maintenance/configurationAssignments\",\n \"apiVersion\": \"2022-11-01-preview\",\n \"name\": \"[parameters('assignmentName')]\",\n \"location\": \"[parameters('location')]\",\n \"scope\": \"[format('Microsoft.Compute/virtualMachines/{0}', parameters('name'))]\",\n \"properties\": {\n \"maintenanceConfigurationId\": \"[parameters('maintenanceConfigurationId')]\"\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Compute/virtualMachines', parameters('name'))]\"\n ]\n}\n
","tags":["Azure.VM.MaintenanceConfig","AZR-000375"]},{"location":"en/rules/Azure.VM.MaintenanceConfig/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy virtual machines that pass this rule:
Microsoft.Maintenance/configurationAssignments
sub-resource (extension resource).properties.maintenanceConfigurationId
property to the linked maintenance configuration resource Id.For example:
Azure Bicep snippetresource config 'Microsoft.Maintenance/configurationAssignments@2022-11-01-preview' = {\n name: assignmentName\n location: location\n scope: vm\n properties: {\n maintenanceConfigurationId: maintenanceConfigurationId\n }\n}\n
","tags":["Azure.VM.MaintenanceConfig","AZR-000375"]},{"location":"en/rules/Azure.VM.MaintenanceConfig/#notes","title":"Notes","text":"Operating system updates with Update Management center is a preview feature. Not all operating systems are supported, check out the LINKS
section for more information. Update management center doesn't support driver updates.
Operational Excellence \u00b7 Virtual Machine \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Use Azure Monitor Agent as replacement for Log Analytics Agent.
","tags":["Azure.VM.MigrateAMA","AZR-000317"]},{"location":"en/rules/Azure.VM.MigrateAMA/#description","title":"Description","text":"The legacy Log Analytics agent will be retired on August 31, 2024. Before that date, you'll need to start using the Azure Monitor agent to monitor your VMs and servers in Azure. The Azure Monitor agent provdes the following benefits over legacy agents:
Virtual Machines should migrate to Azure Monitor Agent.
","tags":["Azure.VM.MigrateAMA","AZR-000317"]},{"location":"en/rules/Azure.VM.MigrateAMA/#examples","title":"Examples","text":"","tags":["Azure.VM.MigrateAMA","AZR-000317"]},{"location":"en/rules/Azure.VM.MigrateAMA/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy virtual machines that pass this rule:
properties.publisher
to 'Microsoft.Azure.Monitor'
.properties.type
to 'AzureMonitorWindowsAgent'
(Windows) or 'AzureMonitorLinuxAgent'
(Linux).For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"vmName\": {\n \"type\": \"string\"\n },\n \"location\": {\n \"type\": \"string\"\n },\n \"userAssignedManagedIdentity\": {\n \"type\": \"string\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Compute/virtualMachines/extensions\",\n \"apiVersion\": \"2022-08-01\",\n \"name\": \"[format('{0}/AzureMonitorWindowsAgent', parameters('vmName'))]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"publisher\": \"Microsoft.Azure.Monitor\",\n \"type\": \"AzureMonitorWindowsAgent\",\n \"typeHandlerVersion\": \"1.0\",\n \"settings\": {\n \"authentication\": {\n \"managedIdentity\": {\n \"identifier-name\": \"mi_res_id\",\n \"identifier-value\": \"[parameters('userAssignedManagedIdentity')]\"\n }\n }\n },\n \"autoUpgradeMinorVersion\": true,\n \"enableAutomaticUpgrade\": true\n }\n }\n ]\n}\n
","tags":["Azure.VM.MigrateAMA","AZR-000317"]},{"location":"en/rules/Azure.VM.MigrateAMA/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy virtual machines that pass this rule:
properties.publisher
to 'Microsoft.Azure.Monitor'
.properties.type
to 'AzureMonitorWindowsAgent'
(Windows) or 'AzureMonitorLinuxAgent'
(Linux).For example:
Azure Bicep snippetparam vmName string\nparam location string\nparam userAssignedManagedIdentity string\n\nresource windowsAgent 'Microsoft.Compute/virtualMachines/extensions@2022-08-01' = {\n name: '${vmName}/AzureMonitorWindowsAgent'\n location: location\n properties: {\n publisher: 'Microsoft.Azure.Monitor'\n type: 'AzureMonitorWindowsAgent'\n typeHandlerVersion: '1.0'\n autoUpgradeMinorVersion: true\n enableAutomaticUpgrade: true\n settings: {\n authentication: {\n managedIdentity: {\n identifier-name: 'mi_res_id'\n identifier-value: userAssignedManagedIdentity\n }\n }\n }\n }\n}\n
","tags":["Azure.VM.MigrateAMA","AZR-000317"]},{"location":"en/rules/Azure.VM.MigrateAMA/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Virtual Machine (VM) names should meet naming requirements.
","tags":["Azure.VM.Name","AZR-000248"]},{"location":"en/rules/Azure.VM.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for VM names are:
Consider using names that meet VM resource name requirements. Additionally, consider using a resource name that meeting OS naming requirements.
","tags":["Azure.VM.Name","AZR-000248"]},{"location":"en/rules/Azure.VM.Name/#notes","title":"Notes","text":"This rule does not check if VM names are unique. Additionally, VM computer names have additional restrictions. See Azure.VM.ComputerName
for details.
Operational Excellence \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Proximity Placement Group (PPG) names should meet naming requirements.
","tags":["Azure.VM.PPGName","AZR-000260"]},{"location":"en/rules/Azure.VM.PPGName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for placement groups names are:
Consider using names that meet Proximity Placement Group naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.VM.PPGName","AZR-000260"]},{"location":"en/rules/Azure.VM.PPGName/#notes","title":"Notes","text":"This rule does not check if Proximity Placement Group names are unique.
","tags":["Azure.VM.PPGName","AZR-000260"]},{"location":"en/rules/Azure.VM.PPGName/#links","title":"Links","text":"Cost Optimization \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Virtual machines (VMs) should not use expired promotional SKU.
","tags":["Azure.VM.PromoSku","AZR-000240"]},{"location":"en/rules/Azure.VM.PromoSku/#description","title":"Description","text":"Some VM sizes may offer promotional rates that can be used by deploying VMs with a designated SKU. Promotional rates expire, and while this does not cause interruption to running VMs, the rate that VMs are billed at returns to the original price.
Promo SKUs are not eligible for savings from reserved instances. Expired promo SKUs may confuse billing reconciliation when the promotional period expires.
VMs should not use expired promo SKU.
","tags":["Azure.VM.PromoSku","AZR-000240"]},{"location":"en/rules/Azure.VM.PromoSku/#recommendation","title":"Recommendation","text":"Consider moving from promotional SKUs to SKUs eligible for reserved instances for VMs with an extended life cycle. Alternatively, consider moving from promotional SKUs to the regular SKU once the promotional period has expired.
","tags":["Azure.VM.PromoSku","AZR-000240"]},{"location":"en/rules/Azure.VM.PromoSku/#links","title":"Links","text":"Security \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Linux virtual machines should use public keys.
","tags":["Azure.VM.PublicKey","AZR-000245"]},{"location":"en/rules/Azure.VM.PublicKey/#description","title":"Description","text":"Linux virtual machines support either password or public key based authentication for the default administrator account.
","tags":["Azure.VM.PublicKey","AZR-000245"]},{"location":"en/rules/Azure.VM.PublicKey/#recommendation","title":"Recommendation","text":"Consider using public key based authentication instead of passwords.
","tags":["Azure.VM.PublicKey","AZR-000245"]},{"location":"en/rules/Azure.VM.SQLServerDisk/","title":"Configure Premium disks or above","text":"Azure.VM.SQLServerDiskAZR-000324ErrorPerformance Efficiency \u00b7 Virtual Machine \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Use Premium SSD disks or greater for data and log files for production SQL Server workloads.
","tags":["Azure.VM.SQLServerDisk","AZR-000324"]},{"location":"en/rules/Azure.VM.SQLServerDisk/#description","title":"Description","text":"Use premium SSD disks or greater for data and log files for production SQL Server workloads.
This is an advanced topic with many considerations, so we highly suggest to follow the LINKS
section for more around this with aligned and up-to-date documentation.
Configure Premium SSD disks or greater for data and log files for production SQL Server workloads.
","tags":["Azure.VM.SQLServerDisk","AZR-000324"]},{"location":"en/rules/Azure.VM.SQLServerDisk/#examples","title":"Examples","text":"","tags":["Azure.VM.SQLServerDisk","AZR-000324"]},{"location":"en/rules/Azure.VM.SQLServerDisk/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Virtual Machines that pass this rule:
properties.storageProfile.osDisk.managedDisk.storageAccountType
property to Premium_LRS
or greater.properties.storageProfile.dataDisks
to use Premium_LRS
or greater by setting the property managedDisk.storageAccountType
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Compute/virtualMachines\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"[parameters('virtualMachineName')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"hardwareProfile\": {\n \"vmSize\": \"[parameters('virtualMachineSize')]\"\n },\n \"storageProfile\": {\n \"osDisk\": {\n \"createOption\": \"FromImage\",\n \"managedDisk\": {\n \"storageAccountType\": \"Premium_LRS\"\n },\n \"diskSizeGB\": 127\n },\n \"imageReference\": {\n \"publisher\": \"MicrosoftSQLServer\",\n \"offer\": \"SQL2019-WS2019\",\n \"sku\": \"Enterprise\",\n \"version\": \"latest\"\n },\n \"dataDisks\": [\n {\n \"lun\": 0,\n \"caching\": \"ReadOnly\",\n \"createOption\": \"Empty\",\n \"writeAcceleratorEnabled\": false,\n \"managedDisk\": {\n \"storageAccountType\": \"UltraSSD_LRS\"\n },\n \"diskSizeGB\": 1023\n }\n ]\n },\n \"networkProfile\": {\n \"networkInterfaces\": [\n {\n \"id\": \"[resourceId('Microsoft.Network/networkInterfaces', variables('networkInterfaceName'))]\"\n }\n ]\n },\n \"osProfile\": {\n \"computerName\": \"[parameters('virtualMachineName')]\",\n \"adminUsername\": \"[parameters('adminUsername')]\",\n \"adminPassword\": \"[parameters('adminPassword')]\",\n \"windowsConfiguration\": {\n \"enableAutomaticUpdates\": true,\n \"provisionVMAgent\": true\n }\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Network/networkInterfaces', variables('networkInterfaceName'))]\"\n ]\n}\n
","tags":["Azure.VM.SQLServerDisk","AZR-000324"]},{"location":"en/rules/Azure.VM.SQLServerDisk/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Virtual Machines that pass this rule:
properties.storageProfile.osDisk.managedDisk.storageAccountType
property to Premium_LRS
or greater.properties.storageProfile.dataDisks
to use Premium_LRS
or greater by setting the property managedDisk.storageAccountType
.For example:
Azure Bicep snippetresource virtualMachine 'Microsoft.Compute/virtualMachines@2022-03-01' = {\n name: virtualMachineName\n location: location\n properties: {\n hardwareProfile: {\n vmSize: virtualMachineSize\n }\n storageProfile: {\n osDisk: {\n createOption: 'FromImage'\n managedDisk: {\n storageAccountType: 'Premium_LRS'\n }\n diskSizeGB: 127\n }\n imageReference: {\n publisher: 'MicrosoftSQLServer'\n offer: 'SQL2019-WS2019'\n sku: 'Enterprise'\n version: 'latest'\n }\n dataDisks: [\n {\n lun: 0\n caching: 'ReadOnly'\n createOption: 'Empty'\n writeAcceleratorEnabled: false\n managedDisk: {\n storageAccountType: 'UltraSSD_LRS'\n }\n diskSizeGB: 1023\n }\n ]\n }\n networkProfile: {\n networkInterfaces: [\n {\n id: networkInterface.id\n }\n ]\n }\n osProfile: {\n computerName: virtualMachineName\n adminUsername: adminUsername\n adminPassword: adminPassword\n windowsConfiguration: {\n enableAutomaticUpdates: true\n provisionVMAgent: true\n }\n }\n }\n}\n
","tags":["Azure.VM.SQLServerDisk","AZR-000324"]},{"location":"en/rules/Azure.VM.SQLServerDisk/#notes","title":"Notes","text":"This rule is only applicable for OS disk and data disks configured with the property properties.storageProfile.osDisk.managedDisk.storageAccountType
and the property properties.storageProfile.dataDisks.managedDisk.storageAccountType
.
Resources declarations can therefore pass the rule which are using not using Premium disks or above.
","tags":["Azure.VM.SQLServerDisk","AZR-000324"]},{"location":"en/rules/Azure.VM.SQLServerDisk/#links","title":"Links","text":"Security \u00b7 Virtual Machine \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Custom Script Extensions scripts that reference secret values must use the protectedSettings.
","tags":["Azure.VM.ScriptExtensions","AZR-000332"]},{"location":"en/rules/Azure.VM.ScriptExtensions/#description","title":"Description","text":"Virtual Machines support the ability to execute custom scripts on launch. This can be configured via user data and custom script extensions. When the template is rendered, anything in the settings section will be rendered in clear text. To ensure they're kept secret, use the protectedSettings section instead.
","tags":["Azure.VM.ScriptExtensions","AZR-000332"]},{"location":"en/rules/Azure.VM.ScriptExtensions/#recommendation","title":"Recommendation","text":"Consider specifying secure values within protectedSettings
to avoid exposing secrets during extension deployments.
To deploy VM extensions that pass this rule:
properties.protectedSettings
.{\n \"type\": \"Microsoft.Compute/virtualMachines/extensions\",\n \"name\": \"installcustomscript\",\n \"apiVersion\": \"2015-06-15\",\n \"location\": \"australiaeast\",\n \"properties\": {\n \"publisher\": \"Microsoft.Azure.Extensions\",\n \"type\": \"CustomScript\",\n \"typeHandlerVersion\": \"2.0\",\n \"autoUpgradeMinorVersion\": true,\n \"protectedSettings\": {\n \"commandToExecute\": \"Write-Output 'hello-world'\"\n }\n }\n}\n
","tags":["Azure.VM.ScriptExtensions","AZR-000332"]},{"location":"en/rules/Azure.VM.ScriptExtensions/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy VM extensions that pass this rule:
properties.protectedSettings
.resource script 'Microsoft.Compute/virtualMachines/extensions@2015-06-15' = {\n name: 'installcustomscript'\n location: location\n properties: {\n publisher: 'Microsoft.Azure.Extensions'\n type: 'CustomScript'\n typeHandlerVersion: '2.0'\n autoUpgradeMinorVersion: true\n protectedSettings: {\n commandToExecute: 'Write-Output \"hello-world\"'\n }\n }\n}\n
","tags":["Azure.VM.ScriptExtensions","AZR-000332"]},{"location":"en/rules/Azure.VM.ScriptExtensions/#links","title":"Links","text":"Cost Optimization \u00b7 Virtual Machine \u00b7 Rule \u00b7 2023_03 \u00b7 Important
Azure VMs should be running or in a deallocated state.
","tags":["Azure.VM.ShouldNotBeStopped","AZR-000351"]},{"location":"en/rules/Azure.VM.ShouldNotBeStopped/#description","title":"Description","text":"Azure Virtual Machines in a stopped state are still billed hourly for compute usage. Therefor VMs should generally be in a deallocated or running state.
","tags":["Azure.VM.ShouldNotBeStopped","AZR-000351"]},{"location":"en/rules/Azure.VM.ShouldNotBeStopped/#recommendation","title":"Recommendation","text":"Consider fully de-allocating VMs instead of stopping VMs to reduce cost.
","tags":["Azure.VM.ShouldNotBeStopped","AZR-000351"]},{"location":"en/rules/Azure.VM.ShouldNotBeStopped/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed (in-flight) to Azure.
","tags":["Azure.VM.ShouldNotBeStopped","AZR-000351"]},{"location":"en/rules/Azure.VM.ShouldNotBeStopped/#links","title":"Links","text":"Reliability \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use VM features to increase reliability and improve covered SLA for VM configurations.
","tags":["Azure.VM.Standalone","AZR-000239"]},{"location":"en/rules/Azure.VM.Standalone/#description","title":"Description","text":"All VM configurations within Azure offer an SLA. However, the SLA provided and the overall availability of the system varies depending on the configuration.
First, consider performing a Failure Mode Analysis (FMA) of the system. A FMA is the process of analyzing the system to determine the possible failure points.
For Virtual Machines (VMs), running a single instance is often a single point of failure. In many but not all cases, the number of VMs can be increased to add redundancy to the system. Taking advantage of some of the features of Azure can further increase the availability of the system.
Consider using availability zones/ sets or only premium/ ultra disks to improve SLA.
","tags":["Azure.VM.Standalone","AZR-000239"]},{"location":"en/rules/Azure.VM.Standalone/#examples","title":"Examples","text":"","tags":["Azure.VM.Standalone","AZR-000239"]},{"location":"en/rules/Azure.VM.Standalone/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy VMs that pass this rule with on of the following:
properties.availabilitySet.id
in code.zones
with 1
, 2
, or 3
in code.storageAccountType
as Premium_LRS
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Compute/virtualMachines\",\n \"apiVersion\": \"2022-03-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"zones\": [\n \"1\"\n ],\n \"properties\": {\n \"hardwareProfile\": {\n \"vmSize\": \"Standard_D2s_v3\"\n },\n \"osProfile\": {\n \"computerName\": \"[parameters('name')]\",\n \"adminUsername\": \"[parameters('adminUsername')]\",\n \"adminPassword\": \"[parameters('adminPassword')]\"\n },\n \"storageProfile\": {\n \"imageReference\": {\n \"publisher\": \"MicrosoftWindowsServer\",\n \"offer\": \"WindowsServer\",\n \"sku\": \"[parameters('sku')]\",\n \"version\": \"latest\"\n },\n \"osDisk\": {\n \"name\": \"[format('{0}-disk0', parameters('name'))]\",\n \"caching\": \"ReadWrite\",\n \"createOption\": \"FromImage\",\n \"managedDisk\": {\n \"storageAccountType\": \"Premium_LRS\"\n }\n }\n },\n \"licenseType\": \"Windows_Server\",\n \"networkProfile\": {\n \"networkInterfaces\": [\n {\n \"id\": \"[resourceId('Microsoft.Network/networkInterfaces', format('{0}-nic0', parameters('name')))]\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Network/networkInterfaces', format('{0}-nic0', parameters('name')))]\"\n ]\n}\n
","tags":["Azure.VM.Standalone","AZR-000239"]},{"location":"en/rules/Azure.VM.Standalone/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy VMs that pass this rule with on of the following:
properties.availabilitySet.id
in code.zones
with 1
, 2
, or 3
in code.storageAccountType
as Premium_LRS
.For example:
Azure Bicep snippetresource vm1 'Microsoft.Compute/virtualMachines@2022-03-01' = {\n name: name\n location: location\n zones: [\n '1'\n ]\n properties: {\n hardwareProfile: {\n vmSize: 'Standard_D2s_v3'\n }\n osProfile: {\n computerName: name\n adminUsername: adminUsername\n adminPassword: adminPassword\n }\n storageProfile: {\n imageReference: {\n publisher: 'MicrosoftWindowsServer'\n offer: 'WindowsServer'\n sku: sku\n version: 'latest'\n }\n osDisk: {\n name: '${name}-disk0'\n caching: 'ReadWrite'\n createOption: 'FromImage'\n managedDisk: {\n storageAccountType: 'Premium_LRS'\n }\n }\n }\n licenseType: 'Windows_Server'\n networkProfile: {\n networkInterfaces: [\n {\n id: nic.id\n }\n ]\n }\n }\n}\n
","tags":["Azure.VM.Standalone","AZR-000239"]},{"location":"en/rules/Azure.VM.Standalone/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Ensure automatic updates are enabled at deployment.
","tags":["Azure.VM.Updates","AZR-000247"]},{"location":"en/rules/Azure.VM.Updates/#description","title":"Description","text":"Window virtual machines (VMs) have automatic updates turned on at deployment time by default. The option can be enabled/ disabled at deployment time or updated for VM scale sets.
Enabling this option does not prevent automatic updates being disabled or reconfigured within the operating system after deployment.
","tags":["Azure.VM.Updates","AZR-000247"]},{"location":"en/rules/Azure.VM.Updates/#recommendation","title":"Recommendation","text":"Enable automatic updates at deployment time, then reconfigure as required to meet patch management requirements.
","tags":["Azure.VM.Updates","AZR-000247"]},{"location":"en/rules/Azure.VM.UseHybridUseBenefit/","title":"Use Azure Hybrid Benefit","text":"Azure.VM.UseHybridUseBenefitAZR-000243ErrorCost Optimization \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads.
","tags":["Azure.VM.UseHybridUseBenefit","AZR-000243"]},{"location":"en/rules/Azure.VM.UseHybridUseBenefit/#description","title":"Description","text":"The running cost of Virtual machine (VM) workloads in Azure is composed of several components, including:
Azure Hybrid Benefit is a licensing benefit that helps you to reduce your overall cost of ownership. With Azure Hybrid Benefit you to use your existing on-premises licenses to pay a reduced rate on Azure.
When Azure Hybrid Benefit enabled on supported VM images:
For additional information on Azure Hybrid Benefit, see the Azure Hybrid Benefit FAQ.
","tags":["Azure.VM.UseHybridUseBenefit","AZR-000243"]},{"location":"en/rules/Azure.VM.UseHybridUseBenefit/#recommendation","title":"Recommendation","text":"Consider using Azure Hybrid Benefit for eligible virtual machine (VM) workloads.
","tags":["Azure.VM.UseHybridUseBenefit","AZR-000243"]},{"location":"en/rules/Azure.VM.UseHybridUseBenefit/#examples","title":"Examples","text":"","tags":["Azure.VM.UseHybridUseBenefit","AZR-000243"]},{"location":"en/rules/Azure.VM.UseHybridUseBenefit/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy VMs that pass this rule:
properties.licenseType
property to one of the following:Windows_Server
Windows_Client
For example:
Azure Template snippet{\n \"type\": \"Microsoft.Compute/virtualMachines\",\n \"apiVersion\": \"2023-09-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"zones\": [\n \"1\"\n ],\n \"properties\": {\n \"hardwareProfile\": {\n \"vmSize\": \"Standard_D2s_v3\"\n },\n \"osProfile\": {\n \"computerName\": \"[parameters('name')]\",\n \"adminUsername\": \"[parameters('adminUsername')]\",\n \"adminPassword\": \"[parameters('adminPassword')]\"\n },\n \"storageProfile\": {\n \"imageReference\": {\n \"publisher\": \"MicrosoftWindowsServer\",\n \"offer\": \"WindowsServer\",\n \"sku\": \"[parameters('sku')]\",\n \"version\": \"latest\"\n },\n \"osDisk\": {\n \"name\": \"[format('{0}-disk0', parameters('name'))]\",\n \"caching\": \"ReadWrite\",\n \"createOption\": \"FromImage\",\n \"managedDisk\": {\n \"storageAccountType\": \"Premium_LRS\"\n }\n }\n },\n \"licenseType\": \"Windows_Server\",\n \"networkProfile\": {\n \"networkInterfaces\": [\n {\n \"id\": \"[resourceId('Microsoft.Network/networkInterfaces', parameters('nicName'))]\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Network/networkInterfaces', parameters('nicName'))]\"\n ]\n}\n
","tags":["Azure.VM.UseHybridUseBenefit","AZR-000243"]},{"location":"en/rules/Azure.VM.UseHybridUseBenefit/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy VMs that pass this rule:
properties.licenseType
property to one of the following:Windows_Server
Windows_Client
For example:
Azure Bicep snippetresource vm_with_benefit 'Microsoft.Compute/virtualMachines@2023-09-01' = {\n name: name\n location: location\n zones: [\n '1'\n ]\n properties: {\n hardwareProfile: {\n vmSize: 'Standard_D2s_v3'\n }\n osProfile: {\n computerName: name\n adminUsername: adminUsername\n adminPassword: adminPassword\n }\n storageProfile: {\n imageReference: {\n publisher: 'MicrosoftWindowsServer'\n offer: 'WindowsServer'\n sku: sku\n version: 'latest'\n }\n osDisk: {\n name: '${name}-disk0'\n caching: 'ReadWrite'\n createOption: 'FromImage'\n managedDisk: {\n storageAccountType: 'Premium_LRS'\n }\n }\n }\n licenseType: 'Windows_Server'\n networkProfile: {\n networkInterfaces: [\n {\n id: nic.id\n }\n ]\n }\n }\n}\n
","tags":["Azure.VM.UseHybridUseBenefit","AZR-000243"]},{"location":"en/rules/Azure.VM.UseHybridUseBenefit/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz vm update -n '<name>' -g '<resource_group>' --set licenseType=Windows_Server\n
","tags":["Azure.VM.UseHybridUseBenefit","AZR-000243"]},{"location":"en/rules/Azure.VM.UseHybridUseBenefit/#notes","title":"Notes","text":"This rule is not processed by default. To enable this rule, set the AZURE_VM_USE_AZURE_HYBRID_BENEFIT
configuration value to true
.
For example:
ps-rule.yamlconfiguration:\n AZURE_VM_USE_AZURE_HYBRID_BENEFIT: true\n
The following limitations currently apply:
Reliability \u00b7 Virtual Machine \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Virtual machines (VMs) should use managed disks.
","tags":["Azure.VM.UseManagedDisks","AZR-000238"]},{"location":"en/rules/Azure.VM.UseManagedDisks/#description","title":"Description","text":"VMs can be configured with un-managed or managed disks. Un-managed disks, are .vhd
files stored on a Storage Account that you manage as files. Managed disks are the successor to un-managed disks and improve durability and availability of VMs by the following:
Additionally, managed disks provide the following benefits:
Consider using managed disks for virtual machine (VM) storage.
","tags":["Azure.VM.UseManagedDisks","AZR-000238"]},{"location":"en/rules/Azure.VM.UseManagedDisks/#examples","title":"Examples","text":"","tags":["Azure.VM.UseManagedDisks","AZR-000238"]},{"location":"en/rules/Azure.VM.UseManagedDisks/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy VMs that pass this rule:
properties.storageProfile.osDisk.managedDisk.storageAccountType
property to valid storage type.properties.storageProfile.osDisk.createOption
property to FromImage
.properties.storageProfile.osDisk.createOption
property to Attach
.properties.storageProfile.osDisk.managedDisk.id
property to the resource ID of an existing disk resource.properties.storageProfile.dataDisks[*].managedDisk.storageAccountType
property to valid storage type.properties.storageProfile.dataDisks[*].createOption
property to Empty
or FromImage
.properties.storageProfile.dataDisks[*].managedDisk.id
property to the resource ID of an existing disk resource.properties.storageProfile.dataDisks[*].createOption
property to Attach
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Compute/virtualMachines\",\n \"apiVersion\": \"2023-09-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"zones\": [\n \"1\"\n ],\n \"properties\": {\n \"hardwareProfile\": {\n \"vmSize\": \"Standard_D2s_v3\"\n },\n \"osProfile\": {\n \"computerName\": \"[parameters('name')]\",\n \"adminUsername\": \"[parameters('adminUsername')]\",\n \"adminPassword\": \"[parameters('adminPassword')]\"\n },\n \"storageProfile\": {\n \"imageReference\": {\n \"publisher\": \"MicrosoftWindowsServer\",\n \"offer\": \"WindowsServer\",\n \"sku\": \"[parameters('sku')]\",\n \"version\": \"latest\"\n },\n \"osDisk\": {\n \"name\": \"[format('{0}-disk0', parameters('name'))]\",\n \"caching\": \"ReadWrite\",\n \"createOption\": \"FromImage\",\n \"managedDisk\": {\n \"storageAccountType\": \"Premium_LRS\"\n }\n },\n \"dataDisks\": [\n {\n \"createOption\": \"Attach\",\n \"lun\": 0,\n \"managedDisk\": {\n \"id\": \"[parameters('dataDiskId')]\"\n }\n }\n ]\n },\n \"networkProfile\": {\n \"networkInterfaces\": [\n {\n \"id\": \"[resourceId('Microsoft.Network/networkInterfaces', parameters('nicName'))]\"\n }\n ]\n }\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Network/networkInterfaces', parameters('nicName'))]\"\n ]\n}\n
","tags":["Azure.VM.UseManagedDisks","AZR-000238"]},{"location":"en/rules/Azure.VM.UseManagedDisks/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy VMs that pass this rule:
properties.storageProfile.osDisk.managedDisk.storageAccountType
property to valid storage type.properties.storageProfile.osDisk.createOption
property to FromImage
.properties.storageProfile.osDisk.createOption
property to Attach
.properties.storageProfile.osDisk.managedDisk.id
property to the resource ID of an existing disk resource.properties.storageProfile.dataDisks[*].managedDisk.storageAccountType
property to valid storage type.properties.storageProfile.dataDisks[*].createOption
property to Empty
or FromImage
.properties.storageProfile.dataDisks[*].managedDisk.id
property to the resource ID of an existing disk resource.properties.storageProfile.dataDisks[*].createOption
property to Attach
.For example:
Azure Bicep snippetresource vm 'Microsoft.Compute/virtualMachines@2023-09-01' = {\n name: name\n location: location\n zones: [\n '1'\n ]\n properties: {\n hardwareProfile: {\n vmSize: 'Standard_D2s_v3'\n }\n osProfile: {\n computerName: name\n adminUsername: adminUsername\n adminPassword: adminPassword\n }\n storageProfile: {\n imageReference: {\n publisher: 'MicrosoftWindowsServer'\n offer: 'WindowsServer'\n sku: sku\n version: 'latest'\n }\n osDisk: {\n name: '${name}-disk0'\n caching: 'ReadWrite'\n createOption: 'FromImage'\n managedDisk: {\n storageAccountType: 'Premium_LRS'\n }\n }\n dataDisks: [\n {\n createOption: 'Attach'\n lun: 0\n managedDisk: {\n id: dataDiskId\n }\n }\n ]\n }\n networkProfile: {\n networkInterfaces: [\n {\n id: nic.id\n }\n ]\n }\n }\n}\n
","tags":["Azure.VM.UseManagedDisks","AZR-000238"]},{"location":"en/rules/Azure.VM.UseManagedDisks/#configure-with-azure-policy","title":"Configure with Azure Policy","text":"To address this issue at runtime use the following policies:
/providers/Microsoft.Authorization/policyDefinitions/06a78e20-9358-41c9-923c-fb736d382a4d
.Operational Excellence \u00b7 Virtual Machine Scale Sets \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Use Azure Monitor Agent for collecting monitoring data from VM scale sets.
","tags":["Azure.VMSS.AMA","AZR-000346"]},{"location":"en/rules/Azure.VMSS.AMA/#description","title":"Description","text":"Azure Monitor Agent (AMA) collects monitoring data from the guest operating system of virtual machine scale sets (VMSS) instances. Data collected gets delivered to Azure Monitor for use by features, insights and other services, such as Microsoft Defender for Cloud.
Azure Monitor Agent replaces all of Azure Monitor's legacy monitoring agents.
","tags":["Azure.VMSS.AMA","AZR-000346"]},{"location":"en/rules/Azure.VMSS.AMA/#recommendation","title":"Recommendation","text":"Consider monitoring Virtual Machine Scale Sets instances using the Azure Monitor Agent.
","tags":["Azure.VMSS.AMA","AZR-000346"]},{"location":"en/rules/Azure.VMSS.AMA/#examples","title":"Examples","text":"","tags":["Azure.VMSS.AMA","AZR-000346"]},{"location":"en/rules/Azure.VMSS.AMA/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy virtual machine scale sets that pass this rule:
properties.virtualMachineProfile.extensionProfile.extensions.properties.publisher
to Microsoft.Azure.Monitor
.properties.virtualMachineProfile.extensionProfile.extensions.properties.type
to AzureMonitorWindowsAgent
(Windows) or AzureMonitorLinuxAgent
(Linux).For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"vmssName\": {\n \"type\": \"string\",\n \"defaultValue\": \"vmss-01\"\n },\n \"location\": {\n \"type\": \"string\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Compute/virtualMachineScaleSets\",\n \"apiVersion\": \"2022-08-01\",\n \"name\": \"[parameters('vmssName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"b2ms\",\n \"tier\": \"Standard\",\n \"capacity\": 1\n },\n \"properties\": {\n \"overprovision\": true,\n \"upgradePolicy\": {\n \"mode\": \"Automatic\"\n },\n \"singlePlacementGroup\": true,\n \"platformFaultDomainCount\": 3,\n \"virtualMachineProfile\": {\n \"extensionProfile\": {\n \"extensions\": [\n {\n \"name\": \"[format('{0}/AzureMonitorLinuxAgent', parameters('vmssName'))]\",\n \"properties\": {\n \"autoUpgradeMinorVersion\": true,\n \"enableAutomaticUpgrade\": true,\n \"publisher\": \"Microsoft.Azure.Monitor\",\n \"type\": \"AzureMonitorLinuxAgent\",\n \"typeHandlerVersion\": \"1.21\"\n }\n }\n ]\n },\n \"storageProfile\": {\n \"osDisk\": {\n \"caching\": \"ReadWrite\",\n \"createOption\": \"FromImage\"\n },\n \"imageReference\": {\n \"publisher\": \"microsoft-aks\",\n \"offer\": \"aks\",\n \"sku\": \"aks-ubuntu-1804-202208\",\n \"version\": \"2022.08.29\"\n }\n },\n \"osProfile\": {\n \"adminUsername\": \"azureuser\",\n \"computerNamePrefix\": \"vmss-01\",\n \"linuxConfiguration\": {\n \"disablePasswordAuthentication\": true\n },\n \"provisionVMAgent\": true,\n \"ssh\": {\n \"publicKeys\": [\n {\n \"path\": \"/home/azureuser/.ssh/authorized_keys\"\n }\n ]\n }\n },\n \"networkProfile\": {\n \"networkInterfaceConfigurations\": [\n {\n \"name\": \"vmss-001\",\n \"properties\": {\n \"primary\": true,\n \"enableAcceleratedNetworking\": true,\n \"networkSecurityGroup\": {\n \"id\": \"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/networkSecurityGroups/nsg-001\"\n },\n \"ipConfigurations\": [\n {\n \"name\": \"ipconfig1\",\n \"properties\": {\n \"primary\": true,\n \"subnet\": {\n \"id\": \"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/virtualNetworks/vnet-001/subnets/subnet-001\"\n },\n \"privateIPAddressVersion\": \"IPv4\",\n \"loadBalancerBackendAddressPools\": [\n {\n \"id\": \"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/loadBalancers/kubernetes/backendAddressPools/kubernetes\"\n }\n ]\n }\n }\n ]\n }\n }\n ]\n }\n }\n }\n }\n ]\n}\n
To deploy virtual machine scale sets with a extension sub resource that pass this rule:
Microsoft.Compute/virtualMachines/extensions
.properties.publisher
to Microsoft.Azure.Monitor
.properties.type
to AzureMonitorWindowsAgent
(Windows) or AzureMonitorLinuxAgent
(Linux).For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"vmssName\": {\n \"type\": \"string\"\n },\n \"location\": {\n \"type\": \"string\"\n },\n \"userAssignedManagedIdentity\": {\n \"type\": \"string\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Compute/virtualMachineScaleSets/extensions\",\n \"apiVersion\": \"2022-08-01\",\n \"name\": \"[format('{0}/AzureMonitorLinuxAgent', parameters('vmssName'))]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"publisher\": \"Microsoft.Azure.Monitor\",\n \"type\": \"AzureMonitorLinuxAgent\",\n \"typeHandlerVersion\": \"1.21\",\n \"settings\": {\n \"authentication\": {\n \"managedIdentity\": {\n \"identifier-name\": \"mi_res_id\",\n \"identifier-value\": \"[parameters('userAssignedManagedIdentity')]\"\n }\n }\n },\n \"autoUpgradeMinorVersion\": true,\n \"enableAutomaticUpgrade\": true\n }\n }\n ]\n}\n
","tags":["Azure.VMSS.AMA","AZR-000346"]},{"location":"en/rules/Azure.VMSS.AMA/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy virtual machine scale sets that pass this rule:
properties.virtualMachineProfile.extensionProfile.extensions.properties.publisher
to Microsoft.Azure.Monitor
.properties.virtualMachineProfile.extensionProfile.extensions.properties.type
to AzureMonitorWindowsAgent
(Windows) or AzureMonitorLinuxAgent
(Linux).For example:
Azure Bicep snippetparam vmssName string = 'vmss-01'\nparam location string\n\nresource vmScaleSet 'Microsoft.Compute/virtualMachineScaleSets@2022-08-01' = {\n name: vmssName\n location: location\n sku: {\n name: 'b2ms'\n tier: 'Standard'\n capacity: 1\n }\n properties: {\n overprovision: true\n upgradePolicy: {\n mode: 'Automatic'\n }\n singlePlacementGroup: true\n platformFaultDomainCount: 3\n virtualMachineProfile: {\n extensionProfile: {\n extensions: [\n {\n name: '${vmssName}/AzureMonitorLinuxAgent'\n\n properties: {\n autoUpgradeMinorVersion: true\n enableAutomaticUpgrade: true\n publisher: 'Microsoft.Azure.Monitor'\n type: 'AzureMonitorLinuxAgent'\n typeHandlerVersion: '1.21'\n }\n }\n ]\n }\n storageProfile: {\n osDisk: {\n caching: 'ReadWrite'\n createOption: 'FromImage'\n }\n imageReference: {\n publisher: 'microsoft-aks'\n offer: 'aks'\n sku: 'aks-ubuntu-1804-202208'\n version: '2022.08.29'\n }\n }\n osProfile: {\n adminUsername: 'azureuser'\n computerNamePrefix: 'vmss-01'\n linuxConfiguration: {\n disablePasswordAuthentication: true\n }\n provisionVMAgent: true\n ssh: {\n publicKeys: [\n {\n path: '/home/azureuser/.ssh/authorized_keys'\n }\n ]\n }\n }\n networkProfile: {\n networkInterfaceConfigurations: [\n {\n name: 'vmss-001'\n properties: {\n primary: true\n enableAcceleratedNetworking: true\n networkSecurityGroup: {\n id: '/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/networkSecurityGroups/nsg-001'\n }\n ipConfigurations: [\n {\n name: 'ipconfig1'\n properties: {\n primary: true\n subnet: {\n id: '/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/virtualNetworks/vnet-001/subnets/subnet-001'\n }\n privateIPAddressVersion: 'IPv4'\n loadBalancerBackendAddressPools: [\n {\n id: '/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/loadBalancers/kubernetes/backendAddressPools/kubernetes'\n }\n ]\n }\n }\n ]\n }\n }\n ]\n }\n }\n }\n}\n
To deploy virtual machine scale sets with a extension sub resource that pass this rule:
Microsoft.Compute/virtualMachines/extensions
.properties.publisher
to Microsoft.Azure.Monitor
.properties.type
to AzureMonitorWindowsAgent
(Windows) or AzureMonitorLinuxAgent
(Linux).For example:
Azure Bicep snippetparam vmssName string\nparam location string\nparam userAssignedManagedIdentity string\n\nresource linuxAgent 'Microsoft.Compute/virtualMachineScaleSets/extensions@2022-08-01' = {\n name: '${vmssName}/AzureMonitorLinuxAgent'\n location: location\n properties: {\n publisher: 'Microsoft.Azure.Monitor'\n type: 'AzureMonitorLinuxAgent'\n typeHandlerVersion: '1.21'\n autoUpgradeMinorVersion: true\n enableAutomaticUpgrade: true\n settings: {\n authentication: {\n managedIdentity: {\n identifier-name: 'mi_res_id'\n identifier-value: userAssignedManagedIdentity\n }\n }\n }\n }\n}\n
","tags":["Azure.VMSS.AMA","AZR-000346"]},{"location":"en/rules/Azure.VMSS.AMA/#notes","title":"Notes","text":"The Azure Monitor Agent (AMA) itself does not include all configuration needed, additionally data collection rules and associations are required.
","tags":["Azure.VMSS.AMA","AZR-000346"]},{"location":"en/rules/Azure.VMSS.AMA/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Machine Scale Sets \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Virtual Machine Scale Set (VMSS) computer name should meet naming requirements.
","tags":["Azure.VMSS.ComputerName","AZR-000262"]},{"location":"en/rules/Azure.VMSS.ComputerName/#description","title":"Description","text":"When configuring Azure VMSS the assigned computer name prefix must meet operation system (OS) requirements.
The requirements for Windows VM instances are:
The requirements for Linux VM instances are:
Consider using computer names that meet OS naming requirements. Additionally, consider using computer names that match the VMSS resource name.
","tags":["Azure.VMSS.ComputerName","AZR-000262"]},{"location":"en/rules/Azure.VMSS.ComputerName/#notes","title":"Notes","text":"VMSS resource names have different naming restrictions. See Azure.VMSS.Name
for details.
Operational Excellence \u00b7 Virtual Machine Scale Sets \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Use Azure Monitor Agent as replacement for Log Analytics Agent.
","tags":["Azure.VMSS.MigrateAMA","AZR-000318"]},{"location":"en/rules/Azure.VMSS.MigrateAMA/#description","title":"Description","text":"The legacy Log Analytics agent will be retired on August 31, 2024. Before that date, you'll need to start using the Azure Monitor agent to monitor your virtual machine scale sets. The Azure Monitor agent provdes the following benefits over legacy agents:
Virtual Machine Scale Sets should migrate to Azure Monitor Agent.
","tags":["Azure.VMSS.MigrateAMA","AZR-000318"]},{"location":"en/rules/Azure.VMSS.MigrateAMA/#examples","title":"Examples","text":"","tags":["Azure.VMSS.MigrateAMA","AZR-000318"]},{"location":"en/rules/Azure.VMSS.MigrateAMA/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy virtual machine scale sets that pass this rule:
properties.virtualMachineProfile.extensionProfile.extensions.properties.publisher
to 'Microsoft.Azure.Monitor'
.properties.virtualMachineProfile.extensionProfile.extensions.properties.type
to 'AzureMonitorWindowsAgent'
(Windows) or 'AzureMonitorLinuxAgent'
(Linux).For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"vmssName\": {\n \"type\": \"string\",\n \"defaultValue\": \"vmss-01\"\n },\n \"location\": {\n \"type\": \"string\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Compute/virtualMachineScaleSets\",\n \"apiVersion\": \"2022-08-01\",\n \"name\": \"[parameters('vmssName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"b2ms\",\n \"tier\": \"Standard\",\n \"capacity\": 1\n },\n \"properties\": {\n \"overprovision\": true,\n \"upgradePolicy\": {\n \"mode\": \"Automatic\"\n },\n \"singlePlacementGroup\": true,\n \"platformFaultDomainCount\": 3,\n \"virtualMachineProfile\": {\n \"extensionProfile\": {\n \"extensions\": [\n {\n \"name\": \"[format('{0}/AzureMonitorLinuxAgent', parameters('vmssName'))]\",\n \"properties\": {\n \"autoUpgradeMinorVersion\": true,\n \"enableAutomaticUpgrade\": true,\n \"publisher\": \"Microsoft.Azure.Monitor\",\n \"type\": \"AzureMonitorLinuxAgent\",\n \"typeHandlerVersion\": \"1.21\"\n }\n }\n ]\n },\n \"storageProfile\": {\n \"osDisk\": {\n \"caching\": \"ReadWrite\",\n \"createOption\": \"FromImage\"\n },\n \"imageReference\": {\n \"publisher\": \"microsoft-aks\",\n \"offer\": \"aks\",\n \"sku\": \"aks-ubuntu-1804-202208\",\n \"version\": \"2022.08.29\"\n }\n },\n \"osProfile\": {\n \"adminUsername\": \"azureuser\",\n \"computerNamePrefix\": \"vmss-01\",\n \"linuxConfiguration\": {\n \"disablePasswordAuthentication\": true\n },\n \"provisionVMAgent\": true,\n \"ssh\": {\n \"publicKeys\": [\n {\n \"path\": \"/home/azureuser/.ssh/authorized_keys\"\n }\n ]\n }\n },\n \"networkProfile\": {\n \"networkInterfaceConfigurations\": [\n {\n \"name\": \"vmss-001\",\n \"properties\": {\n \"primary\": true,\n \"enableAcceleratedNetworking\": true,\n \"networkSecurityGroup\": {\n \"id\": \"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/networkSecurityGroups/nsg-001\"\n },\n \"ipConfigurations\": [\n {\n \"name\": \"ipconfig1\",\n \"properties\": {\n \"primary\": true,\n \"subnet\": {\n \"id\": \"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/virtualNetworks/vnet-001/subnets/subnet-001\"\n },\n \"privateIPAddressVersion\": \"IPv4\",\n \"loadBalancerBackendAddressPools\": [\n {\n \"id\": \"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/loadBalancers/kubernetes/backendAddressPools/kubernetes\"\n }\n ]\n }\n }\n ]\n }\n }\n ]\n }\n }\n }\n }\n ]\n}\n
To deploy virtual machine scale sets with a extension sub resource that pass this rule:
properties.publisher
to 'Microsoft.Azure.Monitor'
.properties.type
to 'AzureMonitorWindowsAgent'
(Windows) or 'AzureMonitorLinuxAgent'
(Linux).For example:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"vmssName\": {\n \"type\": \"string\"\n },\n \"location\": {\n \"type\": \"string\"\n },\n \"userAssignedManagedIdentity\": {\n \"type\": \"string\"\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.Compute/virtualMachineScaleSets/extensions\",\n \"apiVersion\": \"2022-08-01\",\n \"name\": \"[format('{0}/AzureMonitorLinuxAgent', parameters('vmssName'))]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"publisher\": \"Microsoft.Azure.Monitor\",\n \"type\": \"AzureMonitorLinuxAgent\",\n \"typeHandlerVersion\": \"1.21\",\n \"settings\": {\n \"authentication\": {\n \"managedIdentity\": {\n \"identifier-name\": \"mi_res_id\",\n \"identifier-value\": \"[parameters('userAssignedManagedIdentity')]\"\n }\n }\n },\n \"autoUpgradeMinorVersion\": true,\n \"enableAutomaticUpgrade\": true\n }\n }\n ]\n}\n
","tags":["Azure.VMSS.MigrateAMA","AZR-000318"]},{"location":"en/rules/Azure.VMSS.MigrateAMA/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy virtual machine scale sets that pass this rule:
properties.virtualMachineProfile.extensionProfile.extensions.properties.publisher
to 'Microsoft.Azure.Monitor'
.properties.virtualMachineProfile.extensionProfile.extensions.properties.type
to 'AzureMonitorWindowsAgent'
(Windows) or 'AzureMonitorLinuxAgent'
(Linux).For example:
Azure Bicep snippetparam vmssName string = 'vmss-01'\nparam location string\n\nresource vmScaleSet 'Microsoft.Compute/virtualMachineScaleSets@2022-08-01' = {\n name: vmssName\n location: location\n sku: {\n name: 'b2ms'\n tier: 'Standard'\n capacity: 1\n }\n properties: {\n overprovision: true\n upgradePolicy: {\n mode: 'Automatic'\n }\n singlePlacementGroup: true\n platformFaultDomainCount: 3\n virtualMachineProfile: {\n extensionProfile: {\n extensions: [\n {\n name: '${vmssName}/AzureMonitorLinuxAgent'\n\n properties: {\n autoUpgradeMinorVersion: true\n enableAutomaticUpgrade: true\n publisher: 'Microsoft.Azure.Monitor'\n type: 'AzureMonitorLinuxAgent'\n typeHandlerVersion: '1.21'\n }\n }\n ]\n }\n storageProfile: {\n osDisk: {\n caching: 'ReadWrite'\n createOption: 'FromImage'\n }\n imageReference: {\n publisher: 'microsoft-aks'\n offer: 'aks'\n sku: 'aks-ubuntu-1804-202208'\n version: '2022.08.29'\n }\n }\n osProfile: {\n adminUsername: 'azureuser'\n computerNamePrefix: 'vmss-01'\n linuxConfiguration: {\n disablePasswordAuthentication: true\n }\n provisionVMAgent: true\n ssh: {\n publicKeys: [\n {\n path: '/home/azureuser/.ssh/authorized_keys'\n }\n ]\n }\n }\n networkProfile: {\n networkInterfaceConfigurations: [\n {\n name: 'vmss-001'\n properties: {\n primary: true\n enableAcceleratedNetworking: true\n networkSecurityGroup: {\n id: '/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/networkSecurityGroups/nsg-001'\n }\n ipConfigurations: [\n {\n name: 'ipconfig1'\n properties: {\n primary: true\n subnet: {\n id: '/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/virtualNetworks/vnet-001/subnets/subnet-001'\n }\n privateIPAddressVersion: 'IPv4'\n loadBalancerBackendAddressPools: [\n {\n id: '/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/loadBalancers/kubernetes/backendAddressPools/kubernetes'\n }\n ]\n }\n }\n ]\n }\n }\n ]\n }\n }\n }\n}\n
To deploy virtual machine scale sets with a extension sub resource that pass this rule:
properties.publisher
to 'Microsoft.Azure.Monitor'
.properties.type
to 'AzureMonitorWindowsAgent'
(Windows) or 'AzureMonitorLinuxAgent'
(Linux).For example:
Azure Bicep snippetparam vmssName string\nparam location string\nparam userAssignedManagedIdentity string\n\nresource linuxAgent 'Microsoft.Compute/virtualMachineScaleSets/extensions@2022-08-01' = {\n name: '${vmssName}/AzureMonitorLinuxAgent'\n location: location\n properties: {\n publisher: 'Microsoft.Azure.Monitor'\n type: 'AzureMonitorLinuxAgent'\n typeHandlerVersion: '1.21'\n autoUpgradeMinorVersion: true\n enableAutomaticUpgrade: true\n settings: {\n authentication: {\n managedIdentity: {\n identifier-name: 'mi_res_id'\n identifier-value: userAssignedManagedIdentity\n }\n }\n }\n }\n}\n
","tags":["Azure.VMSS.MigrateAMA","AZR-000318"]},{"location":"en/rules/Azure.VMSS.MigrateAMA/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Machine Scale Sets \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Virtual Machine Scale Set (VMSS) names should meet naming requirements.
","tags":["Azure.VMSS.Name","AZR-000261"]},{"location":"en/rules/Azure.VMSS.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for VMSS names are:
Consider using names that meet VMSS resource name requirements. Additionally, consider using a resource name that meeting OS naming requirements.
","tags":["Azure.VMSS.Name","AZR-000261"]},{"location":"en/rules/Azure.VMSS.Name/#notes","title":"Notes","text":"This rule does not check if VMSS names are unique. Additionally, VMSS computer names have additional restrictions. See Azure.VMSS.ComputerName
for details.
Security \u00b7 Virtual Machine Scale Sets \u00b7 Rule \u00b7 2022_09 \u00b7 Important
Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities.
","tags":["Azure.VMSS.PublicKey","AZR-000288"]},{"location":"en/rules/Azure.VMSS.PublicKey/#description","title":"Description","text":"Linux virtual machine scale sets should have password authentication disabled to help with eliminating password-based attacks.
A common tactic observed used by adversaries against customers running Linux Virtual Machines (VMs) in Azure is password-based attacks.
","tags":["Azure.VMSS.PublicKey","AZR-000288"]},{"location":"en/rules/Azure.VMSS.PublicKey/#recommendation","title":"Recommendation","text":"Linux virtual machine scale sets should have password authentication disabled and instead use SSH keys.
","tags":["Azure.VMSS.PublicKey","AZR-000288"]},{"location":"en/rules/Azure.VMSS.PublicKey/#examples","title":"Examples","text":"","tags":["Azure.VMSS.PublicKey","AZR-000288"]},{"location":"en/rules/Azure.VMSS.PublicKey/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy an virtual machine scale set that pass this rule:
properties.virtualMachineProfile.OsProfile.linuxConfiguration.disablePasswordAuthentication
to true
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Compute/virtualMachineScaleSets\",\n \"apiVersion\": \"2021-11-01\",\n \"name\": \"vmss-01\",\n \"location\": \"[resourceGroup().location]\",\n \"sku\": {\n \"name\": \"b2ms\",\n \"tier\": \"Standard\",\n \"capacity\": 1\n },\n \"properties\": {\n \"overprovision\": true,\n \"upgradePolicy\": {\n \"mode\": \"Automatic\"\n },\n \"singlePlacementGroup\": true,\n \"platformFaultDomainCount\": 3,\n \"virtualMachineProfile\": {\n \"storageProfile\": {\n \"osDisk\": {\n \"caching\": \"ReadWrite\",\n \"createOption\": \"FromImage\"\n },\n \"imageReference\": {\n \"publisher\": \"microsoft-aks\",\n \"offer\": \"aks\",\n \"sku\": \"aks-ubuntu-1804-202208\",\n \"version\": \"2022.08.29\"\n }\n },\n \"osProfile\": {\n \"adminUsername\": \"azureuser\",\n \"computerNamePrefix\": \"vmss-01\",\n \"linuxConfiguration\": {\n \"disablePasswordAuthentication\": true\n },\n \"provisionVMAgent\": true,\n \"ssh\": {\n \"publicKeys\": [\n {\n \"path\": \"/home/azureuser/.ssh/authorized_keys\"\n }\n ]\n }\n },\n \"networkProfile\": {\n \"networkInterfaceConfigurations\": [\n {\n \"name\": \"vmss-001\",\n \"properties\": {\n \"primary\": true,\n \"enableAcceleratedNetworking\": true,\n \"networkSecurityGroup\": {\n \"id\": \"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/networkSecurityGroups/nsg-001\"\n },\n \"ipConfigurations\": [\n {\n \"name\": \"ipconfig1\",\n \"properties\": {\n \"primary\": true,\n \"subnet\": {\n \"id\": \"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/virtualNetworks/vnet-001/subnets/subnet-001\"\n },\n \"privateIPAddressVersion\": \"IPv4\",\n \"loadBalancerBackendAddressPools\": [\n {\n \"id\": \"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/loadBalancers/kubernetes/backendAddressPools/kubernetes\"\n }\n ]\n }\n }\n ]\n }\n }\n ]\n }\n }\n }\n }\n
","tags":["Azure.VMSS.PublicKey","AZR-000288"]},{"location":"en/rules/Azure.VMSS.PublicKey/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy an virtual machine scale set that pass this rule:
properties.virtualMachineProfile.OsProfile.linuxConfiguration.disablePasswordAuthentication
to true
.For example:
Azure Bicep snippetresource vmScaleSet 'Microsoft.Compute/virtualMachineScaleSets@2021-11-01' = {\n name: 'vmss-01'\n location: resourceGroup().location\n sku: {\n name: 'b2ms'\n tier: 'Standard'\n capacity: 1\n }\n properties: {\n overprovision: true\n upgradePolicy: {\n mode: 'Automatic'\n }\n singlePlacementGroup: true\n platformFaultDomainCount: 3\n virtualMachineProfile: {\n storageProfile: {\n osDisk: {\n caching: 'ReadWrite'\n createOption: 'FromImage'\n }\n imageReference: {\n publisher: 'microsoft-aks'\n offer: 'aks'\n sku: 'aks-ubuntu-1804-202208'\n version: '2022.08.29'\n } \n }\n osProfile: {\n adminUsername: 'azureuser'\n computerNamePrefix: 'vmss-01'\n linuxConfiguration: {\n disablePasswordAuthentication: true\n }\n provisionVMAgent: true\n ssh: {\n publicKeys: [\n {\n path: '/home/azureuser/.ssh/authorized_keys'\n }\n ]\n }\n }\n networkProfile: {\n networkInterfaceConfigurations: [\n {\n name: 'vmss-001'\n properties: {\n primary: true\n enableAcceleratedNetworking: true\n networkSecurityGroup: {\n id: '/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/networkSecurityGroups/nsg-001'\n }\n ipConfigurations: [\n {\n name: 'ipconfig1'\n properties: {\n primary: true\n subnet: {\n id: '/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/virtualNetworks/vnet-001/subnets/subnet-001'\n }\n privateIPAddressVersion: 'IPv4'\n loadBalancerBackendAddressPools: [\n {\n id: '/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/test-rg/providers/Microsoft.Network/loadBalancers/kubernetes/backendAddressPools/kubernetes'\n }\n ]\n }\n }\n ]\n }\n }\n ]\n }\n }\n }\n}\n
","tags":["Azure.VMSS.PublicKey","AZR-000288"]},{"location":"en/rules/Azure.VMSS.PublicKey/#links","title":"Links","text":"Security \u00b7 Virtual Machine Scale Sets \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Custom Script Extensions scripts that reference secret values must use the protectedSettings.
","tags":["Azure.VMSS.ScriptExtensions","AZR-000333"]},{"location":"en/rules/Azure.VMSS.ScriptExtensions/#description","title":"Description","text":"Virtual Machines Scale Sets support the ability to execute custom scripts on launch. This can be configured via user data and custom script extensions. When the template is rendered, anything in the settings section will be rendered in clear text. To ensure they're kept secret, use the protectedSettings section instead.
","tags":["Azure.VMSS.ScriptExtensions","AZR-000333"]},{"location":"en/rules/Azure.VMSS.ScriptExtensions/#recommendation","title":"Recommendation","text":"Consider specifying secure values within properties.extensionProfile.extensions.protectedSettings
to avoid exposing secrets during extension deployments.
To deploy VMSS extensions that pass this rule:
properties.extensionProfile.extensions.protectedSettings
\"extensionProfile\": {\n \"extensions\": [\n {\n \"name\": \"customScript\",\n \"properties\": {\n \"publisher\": \"Microsoft.Compute\",\n \"protectedSettings\": {\n \"commandToExecute\": \"Write-Output 'example'\"\n },\n \"typeHandlerVersion\": \"1.8\",\n \"autoUpgradeMinorVersion\": true,\n \"type\": \"CustomScriptExtension\"\n }\n }\n ]\n}\n
","tags":["Azure.VMSS.ScriptExtensions","AZR-000333"]},{"location":"en/rules/Azure.VMSS.ScriptExtensions/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy VMSS extensions that pass this rule:
properties.extensionProfile.extensions.protectedSettings
extensionProfile: {\n extensions: [\n {\n name: 'customScript'\n properties: {\n publisher: 'Microsoft.Compute'\n protectedSettings: {\n commandToExecute: 'Write-Output \"example\"'\n },\n typeHandlerVersion: '1.8'\n autoUpgradeMinorVersion: true\n type: 'CustomScriptExtension'\n }\n }\n ]\n}\n
","tags":["Azure.VMSS.ScriptExtensions","AZR-000333"]},{"location":"en/rules/Azure.VMSS.ScriptExtensions/#links","title":"Links","text":"Reliability \u00b7 Virtual Network \u00b7 Rule \u00b7 2022_12 \u00b7 Important
VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs.
","tags":["Azure.VNET.BastionSubnet","AZR-000314"]},{"location":"en/rules/Azure.VNET.BastionSubnet/#description","title":"Description","text":"Azure Bastion lets you securely connect to a virtual machine using your browser or native SSH/RDP client on Windows workstations or the Azure portal. An Azure Bastion host is deployed inside an Azure Virtual Network and can access virtual machines in the virtual network (VNet), or virtual machines in peered VNets.
Azure Bastion is a fully managed service that provides more secure and seamless Remote Desktop Protocol (RDP) and Secure Shell Protocol (SSH) access to virtual machines (VMs), without any exposure through public IP addresses.
This is a recommended pattern for virtual machine remote access.
Adding Azure Bastion in your configuration adds the following benefits:
Consider an Azure Bastion Subnet to allow for out of band remote access to VMs and provide an extra layer of control.
","tags":["Azure.VNET.BastionSubnet","AZR-000314"]},{"location":"en/rules/Azure.VNET.BastionSubnet/#examples","title":"Examples","text":"","tags":["Azure.VNET.BastionSubnet","AZR-000314"]},{"location":"en/rules/Azure.VNET.BastionSubnet/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Virtual Networks that pass this rule:
AzureBastionSubnet
defined in properties.subnets
.For example:
Azure Template snippet{\n \"apiVersion\": \"2023-05-01\",\n \"type\": \"Microsoft.Network/virtualNetworks\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"addressSpace\": {\n \"addressPrefixes\": [\"10.0.0.0/16\"]\n },\n \"subnets\": [\n {\n \"name\": \"GatewaySubnet\",\n \"properties\": {\n \"addressPrefix\": \"10.0.0.0/27\"\n }\n },\n {\n \"name\": \"AzureBastionSubnet\",\n \"properties\": {\n \"addressPrefix\": \"10.0.1.64/26\"\n }\n }\n ]\n }\n}\n
To deploy Virtual Networks with a subnet sub-resource that pass this rule:
AzureBastionSubnet
sub-resource.For example:
Azure Template snippet{\n \"apiVersion\": \"2023-05-01\",\n \"type\": \"Microsoft.Network/virtualNetworks/subnets\",\n \"name\": \"[format('{0}/{1}', parameters('name'), 'AzureBastionSubnet')]\",\n \"properties\": {\n \"addressPrefix\": \"10.0.1.64/26\"\n },\n \"dependsOn\": [\"[resourceId('Microsoft.Network/virtualNetworks', parameters('name'))]\"]\n}\n
","tags":["Azure.VNET.BastionSubnet","AZR-000314"]},{"location":"en/rules/Azure.VNET.BastionSubnet/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Virtual Networks that pass this rule:
AzureBastionSubnet
defined in properties.subnets
.For example:
Azure Bicep snippetresource vnet 'Microsoft.Network/virtualNetworks@2023-05-01' = {\n name: name\n location: location\n properties: {\n addressSpace: {\n addressPrefixes: [\n '10.0.0.0/16'\n ]\n }\n subnets: [\n {\n name: 'GatewaySubnet'\n properties: {\n addressPrefix: '10.0.0.0/27'\n }\n }\n {\n name: 'AzureBastionSubnet'\n properties: {\n addressPrefix: '10.0.1.64/26'\n }\n }\n ]\n }\n}\n
To deploy Virtual Networks with a subnet sub-resource that pass this rule:
AzureBastionSubnet
sub-resource.For example:
Azure Bicep snippetresource bastionSubnet 'Microsoft.Network/virtualNetworks/subnets@2023-05-01' = {\n name: 'AzureBastionSubnet'\n parent: vnet\n properties: {\n addressPrefix: '10.0.1.64/26'\n }\n}\n
","tags":["Azure.VNET.BastionSubnet","AZR-000314"]},{"location":"en/rules/Azure.VNET.BastionSubnet/#links","title":"Links","text":"Security \u00b7 Virtual Network \u00b7 Rule \u00b7 2022_12 \u00b7 Important
Use Azure Firewall to filter network traffic to and from Azure resources.
","tags":["Azure.VNET.FirewallSubnet","AZR-000322"]},{"location":"en/rules/Azure.VNET.FirewallSubnet/#description","title":"Description","text":"Network segmentation is a key component of a secure network architecture. Azure provides several features that work together to provide strong network segmentation controls.
Azure Firewall is a cloud native stateful Firewall as a service. It can be used to perform deep packet inspection on both east-west and north-south traffic. Firewalls rules can be defined as policies and centrally managed.
Some key advantages that Azure Firewall has over traditional solutions include:
For guidance on defining your network topology in Azure see Cloud Adoption Framework (CAF).
","tags":["Azure.VNET.FirewallSubnet","AZR-000322"]},{"location":"en/rules/Azure.VNET.FirewallSubnet/#recommendation","title":"Recommendation","text":"Consider deploying an Azure Firewall within hub networks to filter traffic between VNETs and on-premises networks.
","tags":["Azure.VNET.FirewallSubnet","AZR-000322"]},{"location":"en/rules/Azure.VNET.FirewallSubnet/#examples","title":"Examples","text":"","tags":["Azure.VNET.FirewallSubnet","AZR-000322"]},{"location":"en/rules/Azure.VNET.FirewallSubnet/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Virtual Networks that pass this rule:
AzureFirewallSubnet
defined in properties.subnets
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/virtualNetworks\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"addressSpace\": {\n \"addressPrefixes\": [\n \"10.0.0.0/16\"\n ]\n },\n \"subnets\": [\n {\n \"name\": \"GatewaySubnet\",\n \"properties\": {\n \"addressPrefix\": \"10.0.0.0/27\"\n }\n },\n {\n \"name\": \"AzureFirewallSubnet\",\n \"properties\": {\n \"addressPrefix\": \"10.0.1.0/26\"\n }\n }\n ]\n }\n}\n
","tags":["Azure.VNET.FirewallSubnet","AZR-000322"]},{"location":"en/rules/Azure.VNET.FirewallSubnet/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Virtual Networks that pass this rule:
AzureFirewallSubnet
defined in properties.subnets
.For example:
Azure Bicep snippetresource vnet 'Microsoft.Network/virtualNetworks@2023-05-01' = {\n name: name\n location: location\n properties: {\n addressSpace: {\n addressPrefixes: [\n '10.0.0.0/16'\n ]\n }\n subnets: [\n {\n name: 'GatewaySubnet'\n properties: {\n addressPrefix: '10.0.0.0/27'\n }\n }\n {\n name: 'AzureFirewallSubnet'\n properties: {\n addressPrefix: '10.0.1.0/26'\n }\n }\n ]\n }\n}\n
","tags":["Azure.VNET.FirewallSubnet","AZR-000322"]},{"location":"en/rules/Azure.VNET.FirewallSubnet/#links","title":"Links","text":"Reliability \u00b7 Virtual Network \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Virtual networks (VNETs) should use DNS servers deployed within the same Azure region.
","tags":["Azure.VNET.LocalDNS","AZR-000265"]},{"location":"en/rules/Azure.VNET.LocalDNS/#description","title":"Description","text":"Virtual networks allow one or more custom DNS servers to be specified. These DNS servers are inherited by connected services such as virtual machines.
When configuring custom DNS server IP addresses, these servers must be accessible for name resolution to occur. Connectivity between services may be impacted if DNS server IP addresses are temporarily or permanently unavailable.
Avoid taking a dependency on external DNS servers for local communication such as those deployed on-premises. This can be achieved by using DNS services deployed into the same Azure region.
Where possible consider deploying:
Alternatively, redundant virtual machines (VMs) can be deployed into Azure to perform DNS resolution.
","tags":["Azure.VNET.LocalDNS","AZR-000265"]},{"location":"en/rules/Azure.VNET.LocalDNS/#recommendation","title":"Recommendation","text":"Consider deploying redundant DNS services within a connected Azure VNET.
","tags":["Azure.VNET.LocalDNS","AZR-000265"]},{"location":"en/rules/Azure.VNET.LocalDNS/#examples","title":"Examples","text":"","tags":["Azure.VNET.LocalDNS","AZR-000265"]},{"location":"en/rules/Azure.VNET.LocalDNS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Virtual Networks that pass this rule:
properties.dhcpOptions.dnsServers
to an IP address within the same or peered network within Azure. ORFor example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/virtualNetworks\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"addressSpace\": {\n \"addressPrefixes\": [\n \"10.0.0.0/16\"\n ]\n },\n \"dhcpOptions\": {\n \"dnsServers\": [\n \"10.0.1.4\",\n \"10.0.1.5\"\n ]\n }\n }\n}\n
","tags":["Azure.VNET.LocalDNS","AZR-000265"]},{"location":"en/rules/Azure.VNET.LocalDNS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Virtual Networks that pass this rule:
properties.dhcpOptions.dnsServers
to an IP address within the same or peered network within Azure. ORFor example:
Azure Bicep snippetresource vnet 'Microsoft.Network/virtualNetworks@2023-05-01' = {\n name: name\n location: location\n properties: {\n addressSpace: {\n addressPrefixes: [\n '10.0.0.0/16'\n ]\n }\n dhcpOptions: {\n dnsServers: [\n '10.0.1.4'\n '10.0.1.5'\n ]\n }\n }\n}\n
","tags":["Azure.VNET.LocalDNS","AZR-000265"]},{"location":"en/rules/Azure.VNET.LocalDNS/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed to Azure (in-flight).
When deploying Active Directory Domain Services (ADDS) within Azure, you may decide to:
When you do this, this rule may report a false positive by default. If you are using this configuration, we recommend you set the configuration option AZURE_VNET_DNS_WITH_IDENTITY
to true
.
For example:
configuration:\n AZURE_VNET_DNS_WITH_IDENTITY: true\n
","tags":["Azure.VNET.LocalDNS","AZR-000265"]},{"location":"en/rules/Azure.VNET.LocalDNS/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Network \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Virtual Network (VNET) names should meet naming requirements.
","tags":["Azure.VNET.Name","AZR-000268"]},{"location":"en/rules/Azure.VNET.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Virtual Network names are:
Consider using names that meet Virtual Network naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.VNET.Name","AZR-000268"]},{"location":"en/rules/Azure.VNET.Name/#notes","title":"Notes","text":"This rule does not check if Virtual Network names are unique.
","tags":["Azure.VNET.Name","AZR-000268"]},{"location":"en/rules/Azure.VNET.Name/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Network \u00b7 Rule \u00b7 2020_06 \u00b7 Important
VNET peering connections must be connected.
","tags":["Azure.VNET.PeerState","AZR-000266"]},{"location":"en/rules/Azure.VNET.PeerState/#description","title":"Description","text":"When peering virtual networks, a peering connection must be established from both virtual networks. Only once both peering connections are in the Connected state will traffic be allowed to flow between the virtual networks.
Connections in the Initiated
or Disconnected
state should be investigated to determine if the connection is required. When the connection is no longer required, it should be removed to prevent confusion during management and monitoring operations.
Most customers will use a hub and spoke topology to connect virtual networks. For guidance on defining your network topology in Azure see Cloud Adoption Framework (CAF).
","tags":["Azure.VNET.PeerState","AZR-000266"]},{"location":"en/rules/Azure.VNET.PeerState/#recommendation","title":"Recommendation","text":"Consider removing peering connections that are not longer required or complete peering connections.
","tags":["Azure.VNET.PeerState","AZR-000266"]},{"location":"en/rules/Azure.VNET.PeerState/#examples","title":"Examples","text":"","tags":["Azure.VNET.PeerState","AZR-000266"]},{"location":"en/rules/Azure.VNET.PeerState/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy virtual networks that pass this rule:
For example a peering connection from a spoke to a hub:
Azure Template snippet{\n \"type\": \"Microsoft.Network/virtualNetworks/virtualNetworkPeerings\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[format('{0}/{1}', parameters('spokeName'), format('peer-to-{0}', parameters('hubName')))]\",\n \"properties\": {\n \"remoteVirtualNetwork\": {\n \"id\": \"[resourceId('Microsoft.Network/virtualNetworks', parameters('hubName'))]\"\n },\n \"allowVirtualNetworkAccess\": true,\n \"allowForwardedTraffic\": true,\n \"allowGatewayTransit\": false,\n \"useRemoteGateways\": true\n }\n}\n
For example a peering connection from a hub to a spoke:
Azure Template snippet{\n \"type\": \"Microsoft.Network/virtualNetworks/virtualNetworkPeerings\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[format('{0}/{1}', parameters('hubName'), format('peer-to-{0}', parameters('spokeName')))]\",\n \"properties\": {\n \"remoteVirtualNetwork\": {\n \"id\": \"[resourceId('Microsoft.Network/virtualNetworks', parameters('spokeName'))]\"\n },\n \"allowVirtualNetworkAccess\": true,\n \"allowForwardedTraffic\": false,\n \"allowGatewayTransit\": true,\n \"useRemoteGateways\": false\n }\n}\n
","tags":["Azure.VNET.PeerState","AZR-000266"]},{"location":"en/rules/Azure.VNET.PeerState/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy virtual networks that pass this rule:
For example a peering connection from a spoke to a hub:
Azure Bicep snippetresource toHub 'Microsoft.Network/virtualNetworks/virtualNetworkPeerings@2023-05-01' = {\n parent: spoke\n name: 'peer-to-${hub.name}'\n properties: {\n remoteVirtualNetwork: {\n id: hub.id\n }\n allowVirtualNetworkAccess: true\n allowForwardedTraffic: true\n allowGatewayTransit: false\n useRemoteGateways: true\n }\n}\n
For example a peering connection from a hub to a spoke:
Azure Bicep snippetresource toSpoke 'Microsoft.Network/virtualNetworks/virtualNetworkPeerings@2023-05-01' = {\n parent: hub\n name: 'peer-to-${spoke.name}'\n properties: {\n remoteVirtualNetwork: {\n id: spoke.id\n }\n allowVirtualNetworkAccess: true\n allowForwardedTraffic: false\n allowGatewayTransit: true\n useRemoteGateways: false\n }\n}\n
","tags":["Azure.VNET.PeerState","AZR-000266"]},{"location":"en/rules/Azure.VNET.PeerState/#notes","title":"Notes","text":"This rule applies when analyzing resources deployed to Azure (in-flight).
","tags":["Azure.VNET.PeerState","AZR-000266"]},{"location":"en/rules/Azure.VNET.PeerState/#links","title":"Links","text":"Reliability \u00b7 Virtual Network \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Virtual networks (VNETs) should have at least two DNS servers assigned.
","tags":["Azure.VNET.SingleDNS","AZR-000264"]},{"location":"en/rules/Azure.VNET.SingleDNS/#description","title":"Description","text":"Virtual networks (VNETs) should have at least two (2) DNS servers assigned. Using a single DNS server may indicate a single point of failure where the DNS IP address is not load balanced.
","tags":["Azure.VNET.SingleDNS","AZR-000264"]},{"location":"en/rules/Azure.VNET.SingleDNS/#recommendation","title":"Recommendation","text":"Virtual networks should have at least two (2) DNS servers set when not using Azure-provided DNS.
","tags":["Azure.VNET.SingleDNS","AZR-000264"]},{"location":"en/rules/Azure.VNET.SingleDNS/#examples","title":"Examples","text":"","tags":["Azure.VNET.SingleDNS","AZR-000264"]},{"location":"en/rules/Azure.VNET.SingleDNS/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy Virtual Networks that pass this rule:
properties.dhcpOptions.dnsServers
to at least two DNS server addresses. ORFor example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/virtualNetworks\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"addressSpace\": {\n \"addressPrefixes\": [\n \"10.0.0.0/16\"\n ]\n },\n \"dhcpOptions\": {\n \"dnsServers\": [\n \"10.0.1.4\",\n \"10.0.1.5\"\n ]\n }\n }\n}\n
","tags":["Azure.VNET.SingleDNS","AZR-000264"]},{"location":"en/rules/Azure.VNET.SingleDNS/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy Virtual Networks that pass this rule:
properties.dhcpOptions.dnsServers
to at least two DNS server addresses. ORFor example:
Azure Bicep snippetresource vnet 'Microsoft.Network/virtualNetworks@2023-05-01' = {\n name: name\n location: location\n properties: {\n addressSpace: {\n addressPrefixes: [\n '10.0.0.0/16'\n ]\n }\n dhcpOptions: {\n dnsServers: [\n '10.0.1.4'\n '10.0.1.5'\n ]\n }\n }\n}\n
","tags":["Azure.VNET.SingleDNS","AZR-000264"]},{"location":"en/rules/Azure.VNET.SingleDNS/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Network \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Subnet names should meet naming requirements.
","tags":["Azure.VNET.SubnetName","AZR-000267"]},{"location":"en/rules/Azure.VNET.SubnetName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for Route table names are:
Consider using names that meet subnet naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.VNET.SubnetName","AZR-000267"]},{"location":"en/rules/Azure.VNET.SubnetName/#notes","title":"Notes","text":"This rule does not check if subnet names are unique.
","tags":["Azure.VNET.SubnetName","AZR-000267"]},{"location":"en/rules/Azure.VNET.SubnetName/#links","title":"Links","text":"Security \u00b7 Virtual Network \u00b7 Rule \u00b7 2020_06 \u00b7 Critical
Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned.
","tags":["Azure.VNET.UseNSGs","AZR-000263"]},{"location":"en/rules/Azure.VNET.UseNSGs/#description","title":"Description","text":"Each VNET subnet should have a network security group (NSG) assigned. NSGs are basic stateful firewalls that provide network isolation and security within a VNET. A key benefit of NSGS is that they provide network segmentation between and within a subnet.
NSGs can be assigned to a virtual machine network interface or a subnet. When assigning NSGs to a subnet, all network traffic within the subnet is subject to the NSG rules.
There is a small subset of special purpose subnets that do not support NSGs. These subnets are:
GatewaySubnet
- used for hybrid connectivity with VPN and ExpressRoute gateways.AzureFirewallSubnet
and AzureFirewallManagementSubnet
- are for Azure Firewall. Azure Firewall includes an intrinsic NSG that is not directly manageable or visible.RouteServerSubnet
- used by managed routing provided by Azure Route Server.Microsoft.HardwareSecurityModules/dedicatedHSMs
.Consider assigning a network security group (NSG) to each virtual network subnet.
","tags":["Azure.VNET.UseNSGs","AZR-000263"]},{"location":"en/rules/Azure.VNET.UseNSGs/#examples","title":"Examples","text":"","tags":["Azure.VNET.UseNSGs","AZR-000263"]},{"location":"en/rules/Azure.VNET.UseNSGs/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy virtual networks subnets that pass this rule:
properties.networkSecurityGroup.id
property for each supported subnet to a NSG resource id.For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/virtualNetworks\",\n \"apiVersion\": \"2023-05-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"addressSpace\": {\n \"addressPrefixes\": [\n \"10.0.0.0/16\"\n ]\n },\n \"dhcpOptions\": {\n \"dnsServers\": [\n \"10.0.1.4\",\n \"10.0.1.5\"\n ]\n },\n \"subnets\": [\n {\n \"name\": \"GatewaySubnet\",\n \"properties\": {\n \"addressPrefix\": \"10.0.0.0/24\"\n }\n },\n {\n \"name\": \"snet-001\",\n \"properties\": {\n \"addressPrefix\": \"10.0.1.0/24\",\n \"networkSecurityGroup\": {\n \"id\": \"[resourceId('Microsoft.Network/networkSecurityGroups', parameters('nsgName'))]\"\n }\n }\n }\n ]\n },\n \"dependsOn\": [\n \"[resourceId('Microsoft.Network/networkSecurityGroups', parameters('nsgName'))]\"\n ]\n}\n
","tags":["Azure.VNET.UseNSGs","AZR-000263"]},{"location":"en/rules/Azure.VNET.UseNSGs/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy virtual network subnets that pass this rule:
properties.networkSecurityGroup.id
property for each supported subnet to a NSG resource id.For example:
Azure Bicep snippetresource vnet 'Microsoft.Network/virtualNetworks@2023-05-01' = {\n name: name\n location: location\n properties: {\n addressSpace: {\n addressPrefixes: [\n '10.0.0.0/16'\n ]\n }\n dhcpOptions: {\n dnsServers: [\n '10.0.1.4'\n '10.0.1.5'\n ]\n }\n subnets: [\n {\n name: 'GatewaySubnet'\n properties: {\n addressPrefix: '10.0.0.0/24'\n }\n }\n {\n name: 'snet-001'\n properties: {\n addressPrefix: '10.0.1.0/24'\n networkSecurityGroup: {\n id: nsg.id\n }\n }\n }\n ]\n }\n}\n
","tags":["Azure.VNET.UseNSGs","AZR-000263"]},{"location":"en/rules/Azure.VNET.UseNSGs/#configure-with-azure-cli","title":"Configure with Azure CLI","text":"Azure CLI snippetaz network vnet subnet update -n '<subnet>' -g '<resource_group>' --vnet-name '<vnet_name>' --network-security-group '<nsg_name>`\n
","tags":["Azure.VNET.UseNSGs","AZR-000263"]},{"location":"en/rules/Azure.VNET.UseNSGs/#configure-with-azure-powershell","title":"Configure with Azure PowerShell","text":"Azure PowerShell snippet$vnet = Get-AzVirtualNetwork -Name '<vnet_name>' -ResourceGroupName '<resource_group>'\n$nsg = Get-AzNetworkSecurityGroup -Name '<nsg_name>' -ResourceGroupName '<resource_group>'\nSet-AzVirtualNetworkSubnetConfig -Name '<subnet>' -VirtualNetwork $vnet -AddressPrefix '10.0.1.0/24' -NetworkSecurityGroup $nsg\n
","tags":["Azure.VNET.UseNSGs","AZR-000263"]},{"location":"en/rules/Azure.VNET.UseNSGs/#notes","title":"Notes","text":"If you identify a false postive for an Azure service that does not support NSGs, please open an issue to help us improve this rule.
To exclude subnets that are specific to your environment, use the AZURE_VNET_SUBNET_EXCLUDED_FROM_NSG
configuration option. Any subnet names specified by this option will be ignored by this rule.
For example:
configuration:\n AZURE_VNET_SUBNET_EXCLUDED_FROM_NSG:\n - subnet-1\n - subnet-2\n
","tags":["Azure.VNET.UseNSGs","AZR-000263"]},{"location":"en/rules/Azure.VNET.UseNSGs/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Network Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Virtual Network Gateway (VNG) connection names should meet naming requirements.
","tags":["Azure.VNG.ConnectionName","AZR-000275"]},{"location":"en/rules/Azure.VNG.ConnectionName/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for connection names are:
Consider using names that meet connection naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.VNG.ConnectionName","AZR-000275"]},{"location":"en/rules/Azure.VNG.ConnectionName/#notes","title":"Notes","text":"This rule does not check if connection names are unique.
","tags":["Azure.VNG.ConnectionName","AZR-000275"]},{"location":"en/rules/Azure.VNG.ConnectionName/#links","title":"Links","text":"Reliability \u00b7 Virtual Network Gateway \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type.
","tags":["Azure.VNG.ERAvailabilityZoneSKU","AZR-000273"]},{"location":"en/rules/Azure.VNG.ERAvailabilityZoneSKU/#description","title":"Description","text":"ExpressRoute gateways can be deployed in Availability Zones with the following SKUs:
This brings resiliency, scalability, and higher availability to ExpressRoute gateways. Deploying ExpressRoute gateways in Azure Availability Zones physically and logically separates gateways within a region, while protecting your on-premises network connectivity to Azure from zone-level failures.
","tags":["Azure.VNG.ERAvailabilityZoneSKU","AZR-000273"]},{"location":"en/rules/Azure.VNG.ERAvailabilityZoneSKU/#recommendation","title":"Recommendation","text":"Consider deploying ExpressRoute gateways with an availability zone SKU to improve reliability of virtual network gateways.
","tags":["Azure.VNG.ERAvailabilityZoneSKU","AZR-000273"]},{"location":"en/rules/Azure.VNG.ERAvailabilityZoneSKU/#notes","title":"Notes","text":"ExpressRoute gateway availability zones are managed via Public IP addresses, and are flagged separately under the Azure.PublicIP.AvailabilityZone
rule.
To configure an AZ SKU for an ExpressRoute gateway:
properties.gatewayType
to 'ExpressRoute'
properties.sku.name
and properties.sku.tier
to one of the following AZ SKUs:'ErGw1AZ'
'ErGw2AZ'
'ErGw3AZ'
For example:
Azure Template snippet{\n \"apiVersion\": \"2020-11-01\",\n \"name\": \"[parameters('name')]\",\n \"type\": \"Microsoft.Network/virtualNetworkGateways\",\n \"location\": \"[parameters('location')]\",\n \"dependsOn\": [\n \"[concat('Microsoft.Network/publicIPAddresses/', parameters('newPublicIpAddressName'))]\"\n ],\n \"tags\": {},\n \"properties\": {\n \"gatewayType\": \"ExpressRoute\",\n \"ipConfigurations\": [\n {\n \"name\": \"default\",\n \"properties\": {\n \"privateIPAllocationMethod\": \"Dynamic\",\n \"subnet\": {\n \"id\": \"[parameters('subnetId')]\"\n },\n \"publicIpAddress\": {\n \"id\": \"[resourceId('vpn-rg', 'Microsoft.Network/publicIPAddresses', parameters('newPublicIpAddressName'))]\"\n }\n }\n }\n ],\n \"vpnType\": \"[parameters('vpnType')]\",\n \"vpnGatewayGeneration\": \"[parameters('vpnGatewayGeneration')]\",\n \"sku\": {\n \"name\": \"ErGw1AZ\",\n \"tier\": \"ErGw1AZ\"\n }\n }\n}\n
","tags":["Azure.VNG.ERAvailabilityZoneSKU","AZR-000273"]},{"location":"en/rules/Azure.VNG.ERAvailabilityZoneSKU/#configure-with-bicep","title":"Configure with Bicep","text":"To configure an AZ SKU for an ExpressRoute gateway:
properties.gatewayType
to 'ExpressRoute'
properties.sku.name
and properties.sku.tier
to one of the following AZ SKUs:'ErGw1AZ'
'ErGw2AZ'
'ErGw3AZ'
For example:
Azure Bicep snippetresource name_resource 'Microsoft.Network/virtualNetworkGateways@2020-11-01' = {\n name: name\n location: location\n tags: {}\n properties: {\n gatewayType: 'ExpressRoute'\n ipConfigurations: [\n {\n name: 'default'\n properties: {\n privateIPAllocationMethod: 'Dynamic'\n subnet: {\n id: subnetId\n }\n publicIPAddress: {\n id: resourceId('vpn-rg', 'Microsoft.Network/publicIPAddresses', newPublicIpAddressName)\n }\n }\n }\n ]\n vpnType: vpnType\n vpnGatewayGeneration: vpnGatewayGeneration\n sku: {\n name: 'ErGw1AZ'\n tier: 'ErGw1AZ'\n }\n }\n dependsOn: [\n newPublicIpAddressName_resource\n ]\n}\n
","tags":["Azure.VNG.ERAvailabilityZoneSKU","AZR-000273"]},{"location":"en/rules/Azure.VNG.ERAvailabilityZoneSKU/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Network Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways.
","tags":["Azure.VNG.ERLegacySKU","AZR-000271"]},{"location":"en/rules/Azure.VNG.ERLegacySKU/#description","title":"Description","text":"When deploying a ER gateway a number of options are available including SKU/ size. The gateway SKU affects the reliance and performance of the underlying gateway instances. Previously the following SKUs were available however have been depreciated.
Consider redeploying ER gateways using new SKUs to improve reliability and performance of gateways.
","tags":["Azure.VNG.ERLegacySKU","AZR-000271"]},{"location":"en/rules/Azure.VNG.ERLegacySKU/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual Network Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Awareness
Virtual Network Gateway (VNG) names should meet naming requirements.
","tags":["Azure.VNG.Name","AZR-000274"]},{"location":"en/rules/Azure.VNG.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for VNG names are:
Consider using names that meet Virtual Network Gateway (VNG) naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.VNG.Name","AZR-000274"]},{"location":"en/rules/Azure.VNG.Name/#notes","title":"Notes","text":"This rule does not check if VNG names are unique.
","tags":["Azure.VNG.Name","AZR-000274"]},{"location":"en/rules/Azure.VNG.Name/#links","title":"Links","text":"Reliability \u00b7 Virtual Network Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime.
","tags":["Azure.VNG.VPNActiveActive","AZR-000270"]},{"location":"en/rules/Azure.VNG.VPNActiveActive/#description","title":"Description","text":"VPN Gateways can be configured as either Active-Passive or Active-Active for Site-to-Site (S2S) connections. When deploying VPN gateways, Azure deploys two instances for high-availability (HA).
When using an Active-Passive configuration, one instance is designated a standby for failover.
Gateways configured to use an Active-Active configuration:
Consider using Active-Active VPN gateways to reduce connectivity downtime during HA failover.
","tags":["Azure.VNG.VPNActiveActive","AZR-000270"]},{"location":"en/rules/Azure.VNG.VPNActiveActive/#notes","title":"Notes","text":"Azure provisions a single instance for Basic (legacy) VPN gateways. As a result, Basic VPN gateways do not support Active-Active connections. To use Active-Active VPN connections, migrate to a gateway configured as VpnGw1 or higher SKU.
","tags":["Azure.VNG.VPNActiveActive","AZR-000270"]},{"location":"en/rules/Azure.VNG.VPNActiveActive/#links","title":"Links","text":"Reliability \u00b7 Virtual Network Gateway \u00b7 Rule \u00b7 2021_12 \u00b7 Important
Use availability zone SKU for virtual network gateways deployed with VPN gateway type.
","tags":["Azure.VNG.VPNAvailabilityZoneSKU","AZR-000272"]},{"location":"en/rules/Azure.VNG.VPNAvailabilityZoneSKU/#description","title":"Description","text":"VPN gateways can be deployed in Availability Zones with the following SKUs:
This brings resiliency, scalability, and higher availability to VPN gateways. Deploying VPN gateways in Azure Availability Zones physically and logically separates gateways within a region, while protecting your on-premises network connectivity to Azure from zone-level failures.
","tags":["Azure.VNG.VPNAvailabilityZoneSKU","AZR-000272"]},{"location":"en/rules/Azure.VNG.VPNAvailabilityZoneSKU/#recommendation","title":"Recommendation","text":"Consider deploying VPN gateways with an availability zone SKU to improve reliability of virtual network gateways.
","tags":["Azure.VNG.VPNAvailabilityZoneSKU","AZR-000272"]},{"location":"en/rules/Azure.VNG.VPNAvailabilityZoneSKU/#examples","title":"Examples","text":"","tags":["Azure.VNG.VPNAvailabilityZoneSKU","AZR-000272"]},{"location":"en/rules/Azure.VNG.VPNAvailabilityZoneSKU/#configure-with-azure-template","title":"Configure with Azure template","text":"To configure an AZ SKU for a VPN gateway:
properties.gatewayType
to 'Vpn'
properties.sku.name
and properties.sku.tier
to one of the following AZ SKUs:'VpnGw1AZ'
'VpnGw2AZ'
'VpnGw3AZ'
'VpnGw4AZ'
'VpnGw5AZ'
For example:
Azure Template snippet{\n \"type\": \"Microsoft.Network/virtualNetworkGateways\",\n \"apiVersion\": \"2023-06-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"properties\": {\n \"gatewayType\": \"Vpn\",\n \"ipConfigurations\": [\n {\n \"name\": \"default\",\n \"properties\": {\n \"privateIPAllocationMethod\": \"Dynamic\",\n \"subnet\": {\n \"id\": \"[parameters('subnetId')]\"\n },\n \"publicIPAddress\": {\n \"id\": \"[parameters('pipId')]\"\n }\n }\n }\n ],\n \"vpnType\": \"RouteBased\",\n \"vpnGatewayGeneration\": \"Generation2\",\n \"sku\": {\n \"name\": \"VpnGw1AZ\",\n \"tier\": \"VpnGw1AZ\"\n }\n }\n}\n
","tags":["Azure.VNG.VPNAvailabilityZoneSKU","AZR-000272"]},{"location":"en/rules/Azure.VNG.VPNAvailabilityZoneSKU/#configure-with-bicep","title":"Configure with Bicep","text":"To configure an AZ SKU for a VPN gateway:
properties.gatewayType
to 'Vpn'
properties.sku.name
and properties.sku.tier
to one of the following AZ SKUs:'VpnGw1AZ'
'VpnGw2AZ'
'VpnGw3AZ'
'VpnGw4AZ'
'VpnGw5AZ'
For example:
Azure Bicep snippetresource vng 'Microsoft.Network/virtualNetworkGateways@2023-06-01' = {\n name: name\n location: location\n properties: {\n gatewayType: 'Vpn'\n ipConfigurations: [\n {\n name: 'default'\n properties: {\n privateIPAllocationMethod: 'Dynamic'\n subnet: {\n id: subnetId\n }\n publicIPAddress: {\n id: pipId\n }\n }\n }\n ]\n vpnType: 'RouteBased'\n vpnGatewayGeneration: 'Generation2'\n sku: {\n name: 'VpnGw1AZ'\n tier: 'VpnGw1AZ'\n }\n }\n}\n
","tags":["Azure.VNG.VPNAvailabilityZoneSKU","AZR-000272"]},{"location":"en/rules/Azure.VNG.VPNAvailabilityZoneSKU/#notes","title":"Notes","text":"VPN gateway availability zones are managed via Public IP addresses, and are flagged separately under the Azure.PublicIP.AvailabilityZone
rule.
Operational Excellence \u00b7 Virtual Network Gateway \u00b7 Rule \u00b7 2020_06 \u00b7 Important
Migrate from legacy SKUs to improve reliability and performance of VPN gateways.
","tags":["Azure.VNG.VPNLegacySKU","AZR-000269"]},{"location":"en/rules/Azure.VNG.VPNLegacySKU/#description","title":"Description","text":"When deploying a VPN gateway a number of options are available including SKU/ size. The gateway SKU affects the reliance and performance of the underlying gateway instances. Previously the following SKUs were available however have been depreciated.
Consider redeploying VPN gateways using new SKUs to improve reliability and performance of gateways.
","tags":["Azure.VNG.VPNLegacySKU","AZR-000269"]},{"location":"en/rules/Azure.VNG.VPNLegacySKU/#links","title":"Links","text":"Security \u00b7 Web PubSub Service \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Configure Web PubSub Services to use managed identities to access Azure resources securely.
","tags":["Azure.WebPubSub.ManagedIdentity","AZR-000277"]},{"location":"en/rules/Azure.WebPubSub.ManagedIdentity/#description","title":"Description","text":"A managed identity allows your service to access other Azure AD-protected resources such as Azure Functions. The identity is managed by the Azure platform and doesn't require you to provision or rotate any secrets.
Using Azure managed identities have the following benefits:
Consider configuring a managed identity for each Web PubSub Service. Also consider using managed identities to authenticate to related Azure services.
","tags":["Azure.WebPubSub.ManagedIdentity","AZR-000277"]},{"location":"en/rules/Azure.WebPubSub.ManagedIdentity/#examples","title":"Examples","text":"","tags":["Azure.WebPubSub.ManagedIdentity","AZR-000277"]},{"location":"en/rules/Azure.WebPubSub.ManagedIdentity/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy services that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.SignalRService/webPubSub\",\n \"apiVersion\": \"2023-02-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_S1\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"disableLocalAuth\": true\n }\n}\n
","tags":["Azure.WebPubSub.ManagedIdentity","AZR-000277"]},{"location":"en/rules/Azure.WebPubSub.ManagedIdentity/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy services that pass this rule:
identity.type
to SystemAssigned
or UserAssigned
.identity.type
is UserAssigned
, reference the identity with identity.userAssignedIdentities
.For example:
Azure Bicep snippetresource service 'Microsoft.SignalRService/webPubSub@2023-02-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard_S1'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n disableLocalAuth: true\n }\n}\n
","tags":["Azure.WebPubSub.ManagedIdentity","AZR-000277"]},{"location":"en/rules/Azure.WebPubSub.ManagedIdentity/#links","title":"Links","text":"Reliability \u00b7 Web PubSub Service \u00b7 Rule \u00b7 2022_03 \u00b7 Important
Use SKUs that include an SLA when configuring Web PubSub Services.
","tags":["Azure.WebPubSub.SLA","AZR-000278"]},{"location":"en/rules/Azure.WebPubSub.SLA/#description","title":"Description","text":"When choosing a SKU for a Web PubSub Service you should consider the SLA that is included in the SKU. Web PubSub Services offer a range of SKU offerings:
Free
- Are designed for early non-production use and do not include any SLA.Standard
- Are designed for production use and include an SLA.Consider using a Standard SKU that includes an SLA.
","tags":["Azure.WebPubSub.SLA","AZR-000278"]},{"location":"en/rules/Azure.WebPubSub.SLA/#examples","title":"Examples","text":"","tags":["Azure.WebPubSub.SLA","AZR-000278"]},{"location":"en/rules/Azure.WebPubSub.SLA/#configure-with-azure-template","title":"Configure with Azure template","text":"To deploy services that pass this rule:
sku.name
to Standard_S1
.For example:
Azure Template snippet{\n \"type\": \"Microsoft.SignalRService/webPubSub\",\n \"apiVersion\": \"2021-10-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Standard_S1\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"disableLocalAuth\": true\n }\n}\n
","tags":["Azure.WebPubSub.SLA","AZR-000278"]},{"location":"en/rules/Azure.WebPubSub.SLA/#configure-with-bicep","title":"Configure with Bicep","text":"To deploy services that pass this rule:
sku.name
to Standard_S1
.For example:
Azure Bicep snippetresource service 'Microsoft.SignalRService/webPubSub@2021-10-01' = {\n name: name\n location: location\n sku: {\n name: 'Standard_S1'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n disableLocalAuth: true\n }\n}\n
","tags":["Azure.WebPubSub.SLA","AZR-000278"]},{"location":"en/rules/Azure.WebPubSub.SLA/#links","title":"Links","text":"Operational Excellence \u00b7 Virtual WAN \u00b7 Rule \u00b7 2021_12 \u00b7 Awareness
Virtual WAN (vWAN) names should meet naming requirements.
","tags":["Azure.vWAN.Name","AZR-000276"]},{"location":"en/rules/Azure.vWAN.Name/#description","title":"Description","text":"When naming Azure resources, resource names must meet service requirements. The requirements for vWAN names are:
Consider using names that meet Virtual WAN (vWAN) naming requirements. Additionally consider naming resources with a standard naming convention.
","tags":["Azure.vWAN.Name","AZR-000276"]},{"location":"en/rules/Azure.vWAN.Name/#notes","title":"Notes","text":"This rule does not check if vWAN names are unique.
","tags":["Azure.vWAN.Name","AZR-000276"]},{"location":"en/rules/Azure.vWAN.Name/#links","title":"Links","text":"PSRule for Azure includes the following rules across five pillars of the Microsoft Azure Well-Architected Framework.
"},{"location":"en/rules/module/#cost-optimization","title":"Cost Optimization","text":""},{"location":"en/rules/module/#co03-cost-data-and-reporting","title":"CO:03 Cost data and reporting","text":"Name Synopsis Severity Level Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Error"},{"location":"en/rules/module/#co04-spending-guardrails","title":"CO:04 Spending guardrails","text":"Name Synopsis Severity Level Azure.DevBox.ProjectLimit Limit the number of Dev Boxes a single user can create for a project. Important Error"},{"location":"en/rules/module/#co05-rate-optimization","title":"CO:05 Rate optimization","text":"Name Synopsis Severity Level Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Error Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Error"},{"location":"en/rules/module/#co06-usage-and-billing-increments","title":"CO:06 Usage and billing increments","text":"Name Synopsis Severity Level Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. Critical Error Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Error"},{"location":"en/rules/module/#co07-component-costs","title":"CO:07 Component costs","text":"Name Synopsis Severity Level Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Error Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Error Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Error"},{"location":"en/rules/module/#co10-data-costs","title":"CO:10 Data costs","text":"Name Synopsis Severity Level Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Error"},{"location":"en/rules/module/#co13-personnel-time","title":"CO:13 Personnel time","text":"Name Synopsis Severity Level Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Error"},{"location":"en/rules/module/#co14-consolidation","title":"CO:14 Consolidation","text":"Name Synopsis Severity Level Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Error Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Error Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Error Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Error Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Error"},{"location":"en/rules/module/#operational-excellence","title":"Operational Excellence","text":""},{"location":"en/rules/module/#configuration","title":"Configuration","text":"Name Synopsis Severity Level Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Error Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Error Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Error"},{"location":"en/rules/module/#deployment","title":"Deployment","text":"Name Synopsis Severity Level Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Error Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Error Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Error Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Error Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Error Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Error Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Error Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Error Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Error"},{"location":"en/rules/module/#infrastructure-provisioning","title":"Infrastructure provisioning","text":"Name Synopsis Severity Level Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Error Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Error"},{"location":"en/rules/module/#instrumentation","title":"Instrumentation","text":"Name Synopsis Severity Level Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Warning"},{"location":"en/rules/module/#monitor","title":"Monitor","text":"Name Synopsis Severity Level Azure.VNET.PeerState VNET peering connections must be connected. Important Error"},{"location":"en/rules/module/#monitoring","title":"Monitoring","text":"Name Synopsis Severity Level Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Error Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Error Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Error Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Error Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Error Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Error Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Error"},{"location":"en/rules/module/#oe04-continuous-integration","title":"OE:04 Continuous integration","text":"Name Synopsis Severity Level Azure.ACR.Name Container registry names should meet naming requirements. Awareness Error Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Error Azure.APIM.Name API Management service names should meet naming requirements. Awareness Error Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Error Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Error Azure.Search.Name AI Search service names should meet naming requirements. Awareness Error Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Error Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Error Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Error Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Error"},{"location":"en/rules/module/#oe04-tools-and-processes","title":"OE:04 Tools and processes","text":"Name Synopsis Severity Level Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Warning"},{"location":"en/rules/module/#oe05-infrastructure-as-code","title":"OE:05 Infrastructure as code","text":"Name Synopsis Severity Level Azure.Template.TemplateFile Use ARM template files that are valid. Important Error Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Error"},{"location":"en/rules/module/#oe07-monitoring-system","title":"OE:07 Monitoring system","text":"Name Synopsis Severity Level Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Error Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Error"},{"location":"en/rules/module/#oe09-task-automation","title":"OE:09 Task automation","text":"Name Synopsis Severity Level Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Error"},{"location":"en/rules/module/#principles","title":"Principles","text":"Name Synopsis Severity Level Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Error"},{"location":"en/rules/module/#release-engineering","title":"Release engineering","text":"Name Synopsis Severity Level Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Error Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Error Azure.Template.LocationType Location parameters should use a string value. Important Error Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Error Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Error Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Error Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Error Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Error Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Error Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Warning Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Error Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Error"},{"location":"en/rules/module/#repeatable-infrastructure","title":"Repeatable infrastructure","text":"Name Synopsis Severity Level Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Error Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Error Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Error Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Error Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Important Error Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Error Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Error Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Error Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. Important Error Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Error Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Error Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Error Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Error Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Error Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Error Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Error Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Error Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Error Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Error Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Error Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Error Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Error Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Error Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Error Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Error Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Error Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Error Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Error Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Error Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Error Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Error Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Error Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Error Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Error Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Error Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Error Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. Important Error Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Error Azure.Route.Name Route table names should meet naming requirements. Awareness Error Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Error Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Error Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Error Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Error Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Error Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Error Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Error Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Error Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Error Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Error Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Error Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Error Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Error Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Information Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Information Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Error Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Error Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Error Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Important Error Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Error Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Error Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Error Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Error Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Error Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Error"},{"location":"en/rules/module/#tagging-and-resource-naming","title":"Tagging and resource naming","text":"Name Synopsis Severity Level Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Error"},{"location":"en/rules/module/#performance-efficiency","title":"Performance Efficiency","text":""},{"location":"en/rules/module/#application-capacity","title":"Application capacity","text":"Name Synopsis Severity Level Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Error Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Error Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Error"},{"location":"en/rules/module/#application-design","title":"Application design","text":"Name Synopsis Severity Level Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Error Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Error"},{"location":"en/rules/module/#application-scalability","title":"Application scalability","text":"Name Synopsis Severity Level Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Error Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Error"},{"location":"en/rules/module/#design-for-performance","title":"Design for performance","text":"Name Synopsis Severity Level Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Error"},{"location":"en/rules/module/#design-for-performance-efficiency","title":"Design for performance efficiency","text":"Name Synopsis Severity Level Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. Important Error"},{"location":"en/rules/module/#pe02-capacity-planning","title":"PE:02 Capacity planning","text":"Name Synopsis Severity Level Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Error"},{"location":"en/rules/module/#pe03-selecting-services","title":"PE:03 Selecting services","text":"Name Synopsis Severity Level Azure.Databricks.SKU Ensure Databricks workspaces are non-trial SKUs for production workloads. Critical Error"},{"location":"en/rules/module/#pe05-scaling-and-partitioning","title":"PE:05 Scaling and partitioning","text":"Name Synopsis Severity Level Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Error Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Error"},{"location":"en/rules/module/#pe08-data-performance","title":"PE:08 Data performance","text":"Name Synopsis Severity Level Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Error"},{"location":"en/rules/module/#performance","title":"Performance","text":"Name Synopsis Severity Level Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Error Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Error"},{"location":"en/rules/module/#performance-efficiency-checklist","title":"Performance efficiency checklist","text":"Name Synopsis Severity Level Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Warning Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Error"},{"location":"en/rules/module/#reliability","title":"Reliability","text":""},{"location":"en/rules/module/#application-design_1","title":"Application design","text":"Name Synopsis Severity Level Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Error"},{"location":"en/rules/module/#availability","title":"Availability","text":"Name Synopsis Severity Level Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Error Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Error"},{"location":"en/rules/module/#best-practices","title":"Best practices","text":"Name Synopsis Severity Level Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Error"},{"location":"en/rules/module/#data-management","title":"Data management","text":"Name Synopsis Severity Level Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Error Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important Error Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Error Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Error Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Error Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Error"},{"location":"en/rules/module/#design","title":"Design","text":"Name Synopsis Severity Level Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Error Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Error Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Error Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Error Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Error Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Error Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Error Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Error Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Error Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Error"},{"location":"en/rules/module/#health-modeling","title":"Health modeling","text":"Name Synopsis Severity Level Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Error Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Error Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Error"},{"location":"en/rules/module/#load-balancing-and-failover","title":"Load balancing and failover","text":"Name Synopsis Severity Level Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Error Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Error"},{"location":"en/rules/module/#re01-simplicity-and-efficiency","title":"RE:01 Simplicity and efficiency","text":"Name Synopsis Severity Level Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Error"},{"location":"en/rules/module/#re04-target-metrics","title":"RE:04 Target metrics","text":"Name Synopsis Severity Level Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Error Azure.AppService.WebProbe Configure and enable instance health probes. Important Error Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Error Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Error"},{"location":"en/rules/module/#re05-redundancy","title":"RE:05 Redundancy","text":"Name Synopsis Severity Level Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Error Azure.AKS.MinUserPoolNodes User node pools in an AKS cluster should have a minimum number of nodes for failover and updates. Important Error Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. Important Error Azure.LB.Probe Use a specific probe for web protocols. Important Error Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Warning Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Error Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Error Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Error"},{"location":"en/rules/module/#re05-regions-and-availability-zones","title":"RE:05 Regions and availability zones","text":"Name Synopsis Severity Level Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Error"},{"location":"en/rules/module/#re06-data-partitioning","title":"RE:06 Data partitioning","text":"Name Synopsis Severity Level Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Error Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Error"},{"location":"en/rules/module/#re07-self-preservation","title":"RE:07 Self-preservation","text":"Name Synopsis Severity Level Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Error Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Error"},{"location":"en/rules/module/#reliability-design-principles","title":"Reliability design principles","text":"Name Synopsis Severity Level Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Error"},{"location":"en/rules/module/#requirements","title":"Requirements","text":"Name Synopsis Severity Level Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Error Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Error Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Error Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Error Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Error Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Error Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Error Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Error Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important Error"},{"location":"en/rules/module/#resiliency-and-dependencies","title":"Resiliency and dependencies","text":"Name Synopsis Severity Level Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Error Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Error Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Error Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Error Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Error"},{"location":"en/rules/module/#resource-deployment","title":"Resource deployment","text":"Name Synopsis Severity Level Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Error"},{"location":"en/rules/module/#scalability","title":"Scalability","text":"Name Synopsis Severity Level Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Error"},{"location":"en/rules/module/#target-and-non-functional-requirements","title":"Target and non-functional requirements","text":"Name Synopsis Severity Level Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Error Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Error Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Error"},{"location":"en/rules/module/#security","title":"Security","text":""},{"location":"en/rules/module/#application-endpoints","title":"Application endpoints","text":"Name Synopsis Severity Level Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Error Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Error Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Error Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Error Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Error Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Error Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Error Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Error"},{"location":"en/rules/module/#authentication","title":"Authentication","text":"Name Synopsis Severity Level Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Error Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Error Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Error Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. Critical Error Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Error Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Error Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Error Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Error Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Error"},{"location":"en/rules/module/#authorization","title":"Authorization","text":"Name Synopsis Severity Level Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Error"},{"location":"en/rules/module/#azure-resources","title":"Azure resources","text":"Name Synopsis Severity Level Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Error Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Error Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Error Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Error"},{"location":"en/rules/module/#connectivity","title":"Connectivity","text":"Name Synopsis Severity Level Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). Critical Error Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. Critical Error Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Error Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Error Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Error"},{"location":"en/rules/module/#data-protection","title":"Data protection","text":"Name Synopsis Severity Level Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Error Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Error Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Error Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Error Azure.CDN.HTTP Enforce HTTPS for client connections. Important Error Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Error Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Error Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Error Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Error Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Error Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Error"},{"location":"en/rules/module/#design_1","title":"Design","text":"Name Synopsis Severity Level Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Error Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Error"},{"location":"en/rules/module/#encryption","title":"Encryption","text":"Name Synopsis Severity Level Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Error Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Error Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Error Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Error Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Error Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Error Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Error Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Error Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Error Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Error Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Error Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Error"},{"location":"en/rules/module/#identity-and-access-management","title":"Identity and access management","text":"Name Synopsis Severity Level Azure.ACR.AnonymousAccess Disable anonymous pull access. Important Error Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Error Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Error Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Error Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Error Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Error Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. Important Error Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Error Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Error Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Error Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Error Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Error Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Error Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Error Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Error Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Error Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Error Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Error Azure.VM.PublicKey Linux virtual machines should use public keys. Important Error Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Error"},{"location":"en/rules/module/#infrastructure-provisioning_1","title":"Infrastructure provisioning","text":"Name Synopsis Severity Level Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Error Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Error Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Error Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. Critical Error Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Error"},{"location":"en/rules/module/#key-and-secret-management","title":"Key and secret management","text":"Name Synopsis Severity Level Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Error Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Error Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Error"},{"location":"en/rules/module/#monitor_1","title":"Monitor","text":"Name Synopsis Severity Level Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Error Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Error Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Error"},{"location":"en/rules/module/#network-security-and-containment","title":"Network security and containment","text":"Name Synopsis Severity Level Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Error Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Error Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Error Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Error Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Error Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Error Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.AppGwWAF.RuleGroups Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Error Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Error Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Error Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Error Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Error Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Error Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Error Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Error Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error"},{"location":"en/rules/module/#network-segmentation","title":"Network segmentation","text":"Name Synopsis Severity Level Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Error Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Error"},{"location":"en/rules/module/#review-and-remediate","title":"Review and remediate","text":"Name Synopsis Severity Level Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Error"},{"location":"en/rules/module/#se01-security-baseline","title":"SE:01 Security baseline","text":"Name Synopsis Severity Level Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Error"},{"location":"en/rules/module/#se02-secured-development-lifecycle","title":"SE:02 Secured development lifecycle","text":"Name Synopsis Severity Level Azure.AppService.NETVersion Configure applications to use newer .NET versions. Important Error Azure.AppService.PHPVersion Configure applications to use newer PHP runtime versions. Important Error"},{"location":"en/rules/module/#se04-segmentation","title":"SE:04 Segmentation","text":"Name Synopsis Severity Level Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Error"},{"location":"en/rules/module/#se05-identity-and-access-management","title":"SE:05 Identity and access management","text":"Name Synopsis Severity Level Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Error Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Error Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Error Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Error Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.APIM.ProductApproval Configure products to require approval. Important Error Azure.APIM.ProductSubscription Configure products to require a subscription. Important Error Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Error Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Error Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Error Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Error Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Error Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Warning Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Error Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Error Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Error Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Error Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Error"},{"location":"en/rules/module/#se06-network-controls","title":"SE:06 Network controls","text":"Name Synopsis Severity Level Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Error Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Error Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Error Azure.Databricks.PublicAccess Azure Databricks workspaces should disable public network access. Critical Error Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. Critical Error Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Error Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Error Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Error"},{"location":"en/rules/module/#se07-encryption","title":"SE:07 Encryption","text":"Name Synopsis Severity Level Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Error Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Error Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Error Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Error Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Error Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Error Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Error Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Error Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Error Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Error Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Error Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Error Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Error"},{"location":"en/rules/module/#se08-hardening-resources","title":"SE:08 Hardening resources","text":"Name Synopsis Severity Level Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Error Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Error"},{"location":"en/rules/module/#se10-monitoring-and-threat-detection","title":"SE:10 Monitoring and threat detection","text":"Name Synopsis Severity Level Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. Critical Error Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Error Azure.Defender.Api Enable Microsoft Defender for APIs. Critical Error Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Error Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Error Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Error Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. Important Error Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Error Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Error Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Error Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Error"},{"location":"en/rules/module/#secrets","title":"Secrets","text":"Name Synopsis Severity Level Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Error Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Error"},{"location":"en/rules/module/#security-design-principles","title":"Security design principles","text":"Name Synopsis Severity Level Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Error Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Error"},{"location":"en/rules/module/#security-operations","title":"Security operations","text":"Name Synopsis Severity Level Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Important Error Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Error Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Error Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Error Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Error Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Error Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Error Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Error Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Error Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Error Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Error Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Error Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Error Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Error Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Error Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Error Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Error"},{"location":"en/rules/module/#virtual-machine","title":"Virtual Machine","text":"Name Synopsis Severity Level Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Error"},{"location":"en/rules/resource/","title":"Rules by resource type","text":"PSRule for Azure includes the following rules organized by resource type.
"},{"location":"en/rules/resource/#ai-search","title":"AI Search","text":"Name Synopsis Severity Level Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Error Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.Search.Name AI Search service names should meet naming requirements. Awareness Error Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Error Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Error"},{"location":"en/rules/resource/#all-resources","title":"All resources","text":"Name Synopsis Severity Level Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Error Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Error Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Error Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Error Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Error Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Error Azure.Template.LocationType Location parameters should use a string value. Important Error Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Error Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Error Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Error Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Error Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Error Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Error Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Error Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Error Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Error Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Error Azure.Template.TemplateFile Use ARM template files that are valid. Important Error Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Error Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Error Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Information Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Information Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Warning Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Error Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Error Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Error"},{"location":"en/rules/resource/#api-management","title":"API Management","text":"Name Synopsis Severity Level Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Warning Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Error Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Error Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Error Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Error Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. Critical Error Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Error Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Error Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Error Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Error Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Error Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Error Azure.APIM.Name API Management service names should meet naming requirements. Awareness Error Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Error Azure.APIM.ProductApproval Configure products to require approval. Important Error Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Warning Azure.APIM.ProductSubscription Configure products to require a subscription. Important Error Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Error Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Error Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Error"},{"location":"en/rules/resource/#app-configuration","title":"App Configuration","text":"Name Synopsis Severity Level Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Error Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Error Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. Important Error Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Error Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Error Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Error"},{"location":"en/rules/resource/#app-service","title":"App Service","text":"Name Synopsis Severity Level Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Error Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Error Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Error Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Error Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Error Azure.AppService.NETVersion Configure applications to use newer .NET versions. Important Error Azure.AppService.PHPVersion Configure applications to use newer PHP runtime versions. Important Error Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Error Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Error Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Error Azure.AppService.WebProbe Configure and enable instance health probes. Important Error Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Error Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Error"},{"location":"en/rules/resource/#app-service-environment","title":"App Service Environment","text":"Name Synopsis Severity Level Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Error"},{"location":"en/rules/resource/#application-gateway","title":"Application Gateway","text":"Name Synopsis Severity Level Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Error Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Error Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Error Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Error Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Error Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Error Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Error Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Error Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Error Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Error Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Error Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Error Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Error Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Error Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.AppGwWAF.RuleGroups Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Error"},{"location":"en/rules/resource/#application-insights","title":"Application Insights","text":"Name Synopsis Severity Level Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Error Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Error"},{"location":"en/rules/resource/#application-security-group","title":"Application Security Group","text":"Name Synopsis Severity Level Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Error"},{"location":"en/rules/resource/#arc","title":"Arc","text":"Name Synopsis Severity Level Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Important Error Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Important Error"},{"location":"en/rules/resource/#automation-account","title":"Automation Account","text":"Name Synopsis Severity Level Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Error Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Error Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Error Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Error Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Error"},{"location":"en/rules/resource/#azure-ai","title":"Azure AI","text":"Name Synopsis Severity Level Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Error Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Error Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Error"},{"location":"en/rules/resource/#azure-cache-for-redis","title":"Azure Cache for Redis","text":"Name Synopsis Severity Level Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Error Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Error Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Error Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Error Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Error Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Error Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Error Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Error Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Error"},{"location":"en/rules/resource/#azure-cache-for-redis-enterprise","title":"Azure Cache for Redis Enterprise","text":"Name Synopsis Severity Level Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Error Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Error"},{"location":"en/rules/resource/#azure-database-for-mariadb","title":"Azure Database for MariaDB","text":"Name Synopsis Severity Level Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Error Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Error Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Error Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Error Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Error Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Error Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Error Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Error"},{"location":"en/rules/resource/#azure-database-for-mysql","title":"Azure Database for MySQL","text":"Name Synopsis Severity Level Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Error Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Error Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Error Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Error Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Error Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Error Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Warning Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Error"},{"location":"en/rules/resource/#azure-database-for-postgresql","title":"Azure Database for PostgreSQL","text":"Name Synopsis Severity Level Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Error Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Error Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Error Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Error Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Error Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Error Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Error"},{"location":"en/rules/resource/#azure-kubernetes-service","title":"Azure Kubernetes Service","text":"Name Synopsis Severity Level Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Error Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Error Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Error Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Error Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Error Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Error Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Error Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Error Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Error Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Error Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Error Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Warning Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Error Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Error Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Error Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Error Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Error Azure.AKS.MinUserPoolNodes User node pools in an AKS cluster should have a minimum number of nodes for failover and updates. Important Error Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Error Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Error Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Error Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Error Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Error Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Error Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Error Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Error Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Error Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Error Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Error Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Error"},{"location":"en/rules/resource/#backup-vault","title":"Backup Vault","text":"Name Synopsis Severity Level Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Error"},{"location":"en/rules/resource/#bastion","title":"Bastion","text":"Name Synopsis Severity Level Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Error"},{"location":"en/rules/resource/#container-app","title":"Container App","text":"Name Synopsis Severity Level Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. Important Error Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. Important Error Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Error Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Error Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Error Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Error Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Error Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Error Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Error"},{"location":"en/rules/resource/#container-registry","title":"Container Registry","text":"Name Synopsis Severity Level Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Error Azure.ACR.AnonymousAccess Disable anonymous pull access. Important Error Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Error Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Error Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Error Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Error Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Error Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Error Azure.ACR.Name Container registry names should meet naming requirements. Awareness Error Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Error Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Error Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important Error Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Error"},{"location":"en/rules/resource/#content-delivery-network","title":"Content Delivery Network","text":"Name Synopsis Severity Level Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Error Azure.CDN.HTTP Enforce HTTPS for client connections. Important Error Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Error"},{"location":"en/rules/resource/#cosmos-db","title":"Cosmos DB","text":"Name Synopsis Severity Level Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Error Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Error Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Error"},{"location":"en/rules/resource/#data-explorer","title":"Data Explorer","text":"Name Synopsis Severity Level Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Error Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Error Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Error Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Error"},{"location":"en/rules/resource/#data-factory","title":"Data Factory","text":"Name Synopsis Severity Level Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Error"},{"location":"en/rules/resource/#databricks","title":"Databricks","text":"Name Synopsis Severity Level Azure.Databricks.PublicAccess Azure Databricks workspaces should disable public network access. Critical Error Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. Critical Error Azure.Databricks.SKU Ensure Databricks workspaces are non-trial SKUs for production workloads. Critical Error"},{"location":"en/rules/resource/#deployment","title":"Deployment","text":"Name Synopsis Severity Level Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Error Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Error Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Error Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Error Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. Critical Error Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Error"},{"location":"en/rules/resource/#dev-box","title":"Dev Box","text":"Name Synopsis Severity Level Azure.DevBox.ProjectLimit Limit the number of Dev Boxes a single user can create for a project. Important Error"},{"location":"en/rules/resource/#event-grid","title":"Event Grid","text":"Name Synopsis Severity Level Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Error Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Error Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Error"},{"location":"en/rules/resource/#event-hub","title":"Event Hub","text":"Name Synopsis Severity Level Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Error Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Error Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Error"},{"location":"en/rules/resource/#firewall","title":"Firewall","text":"Name Synopsis Severity Level Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Error Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Error Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Error Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Error"},{"location":"en/rules/resource/#front-door","title":"Front Door","text":"Name Synopsis Severity Level Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Error Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. Important Error Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Error Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Error Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Error Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Error Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Error Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Error Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Error Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Error Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Error Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Error Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Error Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Error Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Error Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error"},{"location":"en/rules/resource/#iot-hub","title":"IoT Hub","text":"Name Synopsis Severity Level Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Error"},{"location":"en/rules/resource/#key-vault","title":"Key Vault","text":"Name Synopsis Severity Level Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Error Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Error Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Error Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Error Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Error Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Error Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Error Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Warning Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Error Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Error"},{"location":"en/rules/resource/#load-balancer","title":"Load Balancer","text":"Name Synopsis Severity Level Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Error Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Error Azure.LB.Probe Use a specific probe for web protocols. Important Error Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Error"},{"location":"en/rules/resource/#logic-app","title":"Logic App","text":"Name Synopsis Severity Level Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Error"},{"location":"en/rules/resource/#machine-learning","title":"Machine Learning","text":"Name Synopsis Severity Level Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. Critical Error Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). Critical Error Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. Critical Error Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. Critical Error Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. Important Error"},{"location":"en/rules/resource/#microsoft-defender-for-cloud","title":"Microsoft Defender for Cloud","text":"Name Synopsis Severity Level Azure.Defender.Api Enable Microsoft Defender for APIs. Critical Error Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Error Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Error Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Error Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Error Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Error Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Error Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Error Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Error Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Error Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Error Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Error Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Error Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Error Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Error Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Error Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Error"},{"location":"en/rules/resource/#monitor","title":"Monitor","text":"Name Synopsis Severity Level Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Error"},{"location":"en/rules/resource/#network-interface","title":"Network Interface","text":"Name Synopsis Severity Level Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Error Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Error Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Error"},{"location":"en/rules/resource/#network-security-group","title":"Network Security Group","text":"Name Synopsis Severity Level Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Error Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Error Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Error Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Error Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Error Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Error"},{"location":"en/rules/resource/#policy","title":"Policy","text":"Name Synopsis Severity Level Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Error Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Error Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Error Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Error Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Error"},{"location":"en/rules/resource/#private-endpoint","title":"Private Endpoint","text":"Name Synopsis Severity Level Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Error"},{"location":"en/rules/resource/#public-ip-address","title":"Public IP address","text":"Name Synopsis Severity Level Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Error Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Error Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Error Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. Important Error Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Error Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Error"},{"location":"en/rules/resource/#recovery-services-vault","title":"Recovery Services Vault","text":"Name Synopsis Severity Level Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Error Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Error Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Error Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Error"},{"location":"en/rules/resource/#resource-group","title":"Resource Group","text":"Name Synopsis Severity Level Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Error"},{"location":"en/rules/resource/#route-table","title":"Route table","text":"Name Synopsis Severity Level Azure.Route.Name Route table names should meet naming requirements. Awareness Error"},{"location":"en/rules/resource/#service-bus","title":"Service Bus","text":"Name Synopsis Severity Level Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Error Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Error Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Error Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Error"},{"location":"en/rules/resource/#service-fabric","title":"Service Fabric","text":"Name Synopsis Severity Level Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Error"},{"location":"en/rules/resource/#signalr-service","title":"SignalR Service","text":"Name Synopsis Severity Level Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Error Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Error Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Error"},{"location":"en/rules/resource/#sql-database","title":"SQL Database","text":"Name Synopsis Severity Level Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Error Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Error Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Error Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Error Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Error Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Error Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Error Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Error Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Error Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Error"},{"location":"en/rules/resource/#sql-managed-instance","title":"SQL Managed Instance","text":"Name Synopsis Severity Level Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Error Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Error Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Error Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Error"},{"location":"en/rules/resource/#storage-account","title":"Storage Account","text":"Name Synopsis Severity Level Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Error Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Error Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Error Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Error Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Error Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Error Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Error Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Error Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Error Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Error Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Error Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Error Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Error"},{"location":"en/rules/resource/#subscription","title":"Subscription","text":"Name Synopsis Severity Level Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Error Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Error Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Error Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Error Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Error Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Error"},{"location":"en/rules/resource/#traffic-manager","title":"Traffic Manager","text":"Name Synopsis Severity Level Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Error Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Error"},{"location":"en/rules/resource/#user-assigned-managed-identity","title":"User Assigned Managed Identity","text":"Name Synopsis Severity Level Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Error"},{"location":"en/rules/resource/#virtual-machine","title":"Virtual Machine","text":"Name Synopsis Severity Level Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Error Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Error Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Error Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Error Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Error Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Error Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Error Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Error Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Error Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Error Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Error Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Error Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Error Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Important Error Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Error Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Error Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Error Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Error Azure.VM.PublicKey Linux virtual machines should use public keys. Important Error Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Error Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Error Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Error Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Error Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Error Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Error Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Error"},{"location":"en/rules/resource/#virtual-machine-scale-sets","title":"Virtual Machine Scale Sets","text":"Name Synopsis Severity Level Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Error Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Error Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Error Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Error Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Error Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Error"},{"location":"en/rules/resource/#virtual-network","title":"Virtual Network","text":"Name Synopsis Severity Level Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Error Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Error Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Error Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Error Azure.VNET.PeerState VNET peering connections must be connected. Important Error Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Error Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Error Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Error"},{"location":"en/rules/resource/#virtual-network-gateway","title":"Virtual Network Gateway","text":"Name Synopsis Severity Level Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Error Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Error Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Error Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Error Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Error Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Error Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Error"},{"location":"en/rules/resource/#virtual-wan","title":"Virtual WAN","text":"Name Synopsis Severity Level Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Error"},{"location":"en/rules/resource/#web-pubsub-service","title":"Web PubSub Service","text":"Name Synopsis Severity Level Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Error Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important Error"},{"location":"en/selectors/Azure.AppService.IsAPIApp/","title":"Azure.AppService.IsAPIApp","text":"Azure App Services API apps.
"},{"location":"en/selectors/Azure.AppService.IsAPIApp/#description","title":"Description","text":"Use this selector to filter rules to only run against API apps.
"},{"location":"en/selectors/Azure.AppService.IsAPIApp/#examples","title":"Examples","text":""},{"location":"en/selectors/Azure.AppService.IsAPIApp/#configure-with-yaml-based-rules","title":"Configure with YAML-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.AppService.IsAPIApp
.---\n# Synopsis: An example rule.\napiVersion: github.com/microsoft/PSRule/v1\nkind: Rule\nmetadata:\n name: Local.MyRule\nspec:\n with:\n - PSRule.Rules.Azure\\Azure.AppService.IsAPIApp\n condition:\n # Rule logic goes here\n
"},{"location":"en/selectors/Azure.AppService.IsAPIApp/#configure-with-json-based-rules","title":"Configure with JSON-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.AppService.IsAPIApp
.{\n // Synopsis: An example rule.\n \"apiVersion\": \"github.com/microsoft/PSRule/v1\",\n \"kind\": \"Rule\",\n \"metadata\": {\n \"name\": \"Local.MyRule\"\n },\n \"spec\": {\n \"with\": [\n \"PSRule.Rules.Azure\\\\Azure.AppService.IsAPIApp\"\n ],\n \"condition\": {\n // Rule logic goes here\n }\n }\n}\n
"},{"location":"en/selectors/Azure.AppService.IsAPIApp/#configure-with-powershell-based-rules","title":"Configure with PowerShell-based rules","text":"-With
parameter to set PSRule.Rules.Azure\\Azure.AppService.IsAPIApp
.# Synopsis: An example rule.\nRule 'Local.MyRule' -With 'PSRule.Rules.Azure\\Azure.AppService.IsAPIApp' {\n # Rule logic goes here\n}\n
"},{"location":"en/selectors/Azure.AppService.IsFunctionApp/","title":"Azure.AppService.IsFunctionApp","text":"Azure App Services function apps.
"},{"location":"en/selectors/Azure.AppService.IsFunctionApp/#description","title":"Description","text":"Use this selector to filter rules to only run against Azure Functions apps.
"},{"location":"en/selectors/Azure.AppService.IsFunctionApp/#examples","title":"Examples","text":""},{"location":"en/selectors/Azure.AppService.IsFunctionApp/#configure-with-yaml-based-rules","title":"Configure with YAML-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.AppService.IsFunctionApp
.---\n# Synopsis: An example rule.\napiVersion: github.com/microsoft/PSRule/v1\nkind: Rule\nmetadata:\n name: Local.MyRule\nspec:\n with:\n - PSRule.Rules.Azure\\Azure.AppService.IsFunctionApp\n condition:\n # Rule logic goes here\n
"},{"location":"en/selectors/Azure.AppService.IsFunctionApp/#configure-with-json-based-rules","title":"Configure with JSON-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.AppService.IsFunctionApp
.{\n // Synopsis: An example rule.\n \"apiVersion\": \"github.com/microsoft/PSRule/v1\",\n \"kind\": \"Rule\",\n \"metadata\": {\n \"name\": \"Local.MyRule\"\n },\n \"spec\": {\n \"with\": [\n \"PSRule.Rules.Azure\\\\Azure.AppService.IsFunctionApp\"\n ],\n \"condition\": {\n // Rule logic goes here\n }\n }\n}\n
"},{"location":"en/selectors/Azure.AppService.IsFunctionApp/#configure-with-powershell-based-rules","title":"Configure with PowerShell-based rules","text":"-With
parameter to set PSRule.Rules.Azure\\Azure.AppService.IsFunctionApp
.# Synopsis: An example rule.\nRule 'Local.MyRule' -With 'PSRule.Rules.Azure\\Azure.AppService.IsFunctionApp' {\n # Rule logic goes here\n}\n
"},{"location":"en/selectors/Azure.AppService.IsLogicApp/","title":"Azure.AppService.IsLogicApp","text":"Single tenanted Logic Apps.
"},{"location":"en/selectors/Azure.AppService.IsLogicApp/#description","title":"Description","text":"Use this selector to filter rules to only run against Logic Apps with the Standard SKU.
"},{"location":"en/selectors/Azure.AppService.IsLogicApp/#examples","title":"Examples","text":""},{"location":"en/selectors/Azure.AppService.IsLogicApp/#configure-with-yaml-based-rules","title":"Configure with YAML-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.AppService.IsLogicApp
.---\n# Synopsis: An example rule.\napiVersion: github.com/microsoft/PSRule/v1\nkind: Rule\nmetadata:\n name: Local.MyRule\nspec:\n with:\n - PSRule.Rules.Azure\\Azure.AppService.IsLogicApp\n condition:\n # Rule logic goes here\n
"},{"location":"en/selectors/Azure.AppService.IsLogicApp/#configure-with-json-based-rules","title":"Configure with JSON-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.AppService.IsLogicApp
.{\n // Synopsis: An example rule.\n \"apiVersion\": \"github.com/microsoft/PSRule/v1\",\n \"kind\": \"Rule\",\n \"metadata\": {\n \"name\": \"Local.MyRule\"\n },\n \"spec\": {\n \"with\": [\n \"PSRule.Rules.Azure\\\\Azure.AppService.IsLogicApp\"\n ],\n \"condition\": {\n // Rule logic goes here\n }\n }\n}\n
"},{"location":"en/selectors/Azure.AppService.IsLogicApp/#configure-with-powershell-based-rules","title":"Configure with PowerShell-based rules","text":"-With
parameter to set PSRule.Rules.Azure\\Azure.AppService.IsLogicApp
.# Synopsis: An example rule.\nRule 'Local.MyRule' -With 'PSRule.Rules.Azure\\Azure.AppService.IsLogicApp' {\n # Rule logic goes here\n}\n
"},{"location":"en/selectors/Azure.AppService.IsWebApp/","title":"Azure.AppService.IsWebApp","text":"Azure App Services web apps.
"},{"location":"en/selectors/Azure.AppService.IsWebApp/#description","title":"Description","text":"Use this selector to filter rules to only run against web apps.
"},{"location":"en/selectors/Azure.AppService.IsWebApp/#examples","title":"Examples","text":""},{"location":"en/selectors/Azure.AppService.IsWebApp/#configure-with-yaml-based-rules","title":"Configure with YAML-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.AppService.IsWebApp
.---\n# Synopsis: An example rule.\napiVersion: github.com/microsoft/PSRule/v1\nkind: Rule\nmetadata:\n name: Local.MyRule\nspec:\n with:\n - PSRule.Rules.Azure\\Azure.AppService.IsWebApp\n condition:\n # Rule logic goes here\n
"},{"location":"en/selectors/Azure.AppService.IsWebApp/#configure-with-json-based-rules","title":"Configure with JSON-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.AppService.IsWebApp
.{\n // Synopsis: An example rule.\n \"apiVersion\": \"github.com/microsoft/PSRule/v1\",\n \"kind\": \"Rule\",\n \"metadata\": {\n \"name\": \"Local.MyRule\"\n },\n \"spec\": {\n \"with\": [\n \"PSRule.Rules.Azure\\\\Azure.AppService.IsWebApp\"\n ],\n \"condition\": {\n // Rule logic goes here\n }\n }\n}\n
"},{"location":"en/selectors/Azure.AppService.IsWebApp/#configure-with-powershell-based-rules","title":"Configure with PowerShell-based rules","text":"-With
parameter to set PSRule.Rules.Azure\\Azure.AppService.IsWebApp
.# Synopsis: An example rule.\nRule 'Local.MyRule' -With 'PSRule.Rules.Azure\\Azure.AppService.IsWebApp' {\n # Rule logic goes here\n}\n
"},{"location":"en/selectors/Azure.FrontDoor.IsClassic/","title":"AAzure.FrontDoor.IsClassic","text":"Azure Front Door profiles using the Classic SKU.
"},{"location":"en/selectors/Azure.FrontDoor.IsClassic/#description","title":"Description","text":"Use this selector to filter rules to only run against Azure Front Door profiles using the Classic SKU.
"},{"location":"en/selectors/Azure.FrontDoor.IsClassic/#examples","title":"Examples","text":""},{"location":"en/selectors/Azure.FrontDoor.IsClassic/#configure-with-yaml-based-rules","title":"Configure with YAML-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.FrontDoor.IsClassic
.---\n# Synopsis: An example rule.\napiVersion: github.com/microsoft/PSRule/v1\nkind: Rule\nmetadata:\n name: Local.MyRule\nspec:\n with:\n - PSRule.Rules.Azure\\Azure.FrontDoor.IsClassic\n condition:\n # Rule logic goes here\n
"},{"location":"en/selectors/Azure.FrontDoor.IsClassic/#configure-with-json-based-rules","title":"Configure with JSON-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.FrontDoor.IsClassic
.{\n // Synopsis: An example rule.\n \"apiVersion\": \"github.com/microsoft/PSRule/v1\",\n \"kind\": \"Rule\",\n \"metadata\": {\n \"name\": \"Local.MyRule\"\n },\n \"spec\": {\n \"with\": [\n \"PSRule.Rules.Azure\\\\Azure.FrontDoor.IsClassic\"\n ],\n \"condition\": {\n // Rule logic goes here\n }\n }\n}\n
"},{"location":"en/selectors/Azure.FrontDoor.IsClassic/#configure-with-powershell-based-rules","title":"Configure with PowerShell-based rules","text":"-With
parameter to set PSRule.Rules.Azure\\Azure.FrontDoor.IsClassic
.# Synopsis: An example rule.\nRule 'Local.MyRule' -With 'PSRule.Rules.Azure\\Azure.FrontDoor.IsClassic' {\n # Rule logic goes here\n}\n
"},{"location":"en/selectors/Azure.FrontDoor.IsStandardOrPremium/","title":"Azure.FrontDoor.IsStandardOrPremium","text":"Azure Front Door profiles using the Standard or Premium SKU.
"},{"location":"en/selectors/Azure.FrontDoor.IsStandardOrPremium/#description","title":"Description","text":"Use this selector to filter rules to only run against Azure Front Door profiles using the Standard or Premium SKU.
"},{"location":"en/selectors/Azure.FrontDoor.IsStandardOrPremium/#examples","title":"Examples","text":""},{"location":"en/selectors/Azure.FrontDoor.IsStandardOrPremium/#configure-with-yaml-based-rules","title":"Configure with YAML-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.FrontDoor.IsStandardOrPremium
.---\n# Synopsis: An example rule.\napiVersion: github.com/microsoft/PSRule/v1\nkind: Rule\nmetadata:\n name: Local.MyRule\nspec:\n with:\n - PSRule.Rules.Azure\\Azure.FrontDoor.IsStandardOrPremium\n condition:\n # Rule logic goes here\n
"},{"location":"en/selectors/Azure.FrontDoor.IsStandardOrPremium/#configure-with-json-based-rules","title":"Configure with JSON-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.FrontDoor.IsStandardOrPremium
.{\n // Synopsis: An example rule.\n \"apiVersion\": \"github.com/microsoft/PSRule/v1\",\n \"kind\": \"Rule\",\n \"metadata\": {\n \"name\": \"Local.MyRule\"\n },\n \"spec\": {\n \"with\": [\n \"PSRule.Rules.Azure\\\\Azure.FrontDoor.IsStandardOrPremium\"\n ],\n \"condition\": {\n // Rule logic goes here\n }\n }\n}\n
"},{"location":"en/selectors/Azure.FrontDoor.IsStandardOrPremium/#configure-with-powershell-based-rules","title":"Configure with PowerShell-based rules","text":"-With
parameter to set PSRule.Rules.Azure\\Azure.FrontDoor.IsStandardOrPremium
.# Synopsis: An example rule.\nRule 'Local.MyRule' -With 'PSRule.Rules.Azure\\Azure.FrontDoor.IsStandardOrPremium' {\n # Rule logic goes here\n}\n
"},{"location":"en/selectors/Azure.Resource.SupportsTags/","title":"Azure.Resource.SupportsTags","text":"Resources that supports tags.
"},{"location":"en/selectors/Azure.Resource.SupportsTags/#description","title":"Description","text":"Use this selector to filter rules to only run against resources that support tags.
"},{"location":"en/selectors/Azure.Resource.SupportsTags/#examples","title":"Examples","text":""},{"location":"en/selectors/Azure.Resource.SupportsTags/#configure-with-yaml-based-rules","title":"Configure with YAML-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.Resource.SupportsTags
.---\n# Synopsis: An example rule.\napiVersion: github.com/microsoft/PSRule/v1\nkind: Rule\nmetadata:\n name: Local.MyRule\nspec:\n with:\n - PSRule.Rules.Azure\\Azure.Resource.SupportsTags\n condition:\n # Rule logic goes here\n
"},{"location":"en/selectors/Azure.Resource.SupportsTags/#configure-with-json-based-rules","title":"Configure with JSON-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.Resource.SupportsTags
.{\n // Synopsis: An example rule.\n \"apiVersion\": \"github.com/microsoft/PSRule/v1\",\n \"kind\": \"Rule\",\n \"metadata\": {\n \"name\": \"Local.MyRule\"\n },\n \"spec\": {\n \"with\": [\n \"PSRule.Rules.Azure\\\\Azure.Resource.SupportsTags\"\n ],\n \"condition\": {\n // Rule logic goes here\n }\n }\n}\n
"},{"location":"en/selectors/Azure.Resource.SupportsTags/#configure-with-powershell-based-rules","title":"Configure with PowerShell-based rules","text":"-With
parameter to set PSRule.Rules.Azure\\Azure.Resource.SupportsTags
.# Synopsis: An example rule.\nRule 'Local.MyRule' -With 'PSRule.Rules.Azure\\Azure.Resource.SupportsTags' {\n # Rule logic goes here\n}\n
"},{"location":"en/selectors/Azure.ServiceBus.IsPremium/","title":"Azure.ServiceBus.IsPremium","text":"Azure Service Bus premium namespaces.
"},{"location":"en/selectors/Azure.ServiceBus.IsPremium/#description","title":"Description","text":"Use this selector to filter rules to only run against premium Service Bus namespaces.
"},{"location":"en/selectors/Azure.ServiceBus.IsPremium/#examples","title":"Examples","text":""},{"location":"en/selectors/Azure.ServiceBus.IsPremium/#configure-with-yaml-based-rules","title":"Configure with YAML-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.ServiceBus.IsPremium
.---\n# Synopsis: An example rule.\napiVersion: github.com/microsoft/PSRule/v1\nkind: Rule\nmetadata:\n name: Local.MyRule\nspec:\n with:\n - PSRule.Rules.Azure\\Azure.ServiceBus.IsPremium\n condition:\n # Rule logic goes here\n
"},{"location":"en/selectors/Azure.ServiceBus.IsPremium/#configure-with-json-based-rules","title":"Configure with JSON-based rules","text":"with
property to set PSRule.Rules.Azure\\Azure.ServiceBus.IsPremium
.{\n // Synopsis: An example rule.\n \"apiVersion\": \"github.com/microsoft/PSRule/v1\",\n \"kind\": \"Rule\",\n \"metadata\": {\n \"name\": \"Local.MyRule\"\n },\n \"spec\": {\n \"with\": [\n \"PSRule.Rules.Azure\\\\Azure.ServiceBus.IsPremium\"\n ],\n \"condition\": {\n // Rule logic goes here\n }\n }\n}\n
"},{"location":"en/selectors/Azure.ServiceBus.IsPremium/#configure-with-powershell-based-rules","title":"Configure with PowerShell-based rules","text":"-With
parameter to set PSRule.Rules.Azure\\Azure.ServiceBus.IsPremium
.# Synopsis: An example rule.\nRule 'Local.MyRule' -With 'PSRule.Rules.Azure\\Azure.ServiceBus.IsPremium' {\n # Rule logic goes here\n}\n
"},{"location":"es/asb-v3/","title":"Azure Security Benchmark","text":"Azure Security Benchmark (ASB) es un conjunto de controles y recomendaciones que ayudan a mejorar la seguridad de las cargas de trabajo en Azure. Los controles del ASB tambi\u00e9n se asignan a los marcos de la industria, como CIS, PCI-DSS y NIST. Si esta es su primera introduccion a ASB o esta busecano por ayudo a como utilizarlo, refiera a la Introducci\u00f3n a Azure Security Benchmark
"},{"location":"es/asb-v3/#azure-security-benchmark-v3","title":"Azure Security Benchmark v3","text":"Esta es la versi\u00f3n mas reciente del ASB. Las reglas incluidas en PSRule para Azure se han asignado a v3 para que pueda comprender el impacto de las reglas. Esto es particularmente \u00fatil cuando busca comprender c\u00f3mo abordar un requisito de cumplimiento espec\u00edfico de su organizaci\u00f3n.
Los siguientes controles est\u00e1n incluidos en Azure Security Benchmark v3:
Gobernanza y estrategia (GS)
The following rules and features are included in PSRule for Azure.
Info
The rule release indicates if the Azure feature is generally available (GA) or available under preview. Features provided under previews may have additional limits, availability restrictions, or terms. By default, PSRule for Azure will not provide recommendations that relate to preview features. To include rules for preview features see working with baselines.
"},{"location":"es/rules/#rules","title":"Rules","text":"The following rules are included in PSRule for Azure.
Reference Name Synopsis Release AZR-000001 Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. GA AZR-000002 Azure.ACR.ContainerScan Enable vulnerability scanning for container images. GA AZR-000003 Azure.ACR.ImageHealth Remove container images with known vulnerabilities. GA AZR-000004 Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. GA AZR-000005 Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. GA AZR-000006 Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. GA AZR-000007 Azure.ACR.Name Container registry names should meet naming requirements. GA AZR-000008 Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Preview AZR-000009 Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. GA AZR-000010 Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Preview AZR-000011 Azure.ADX.Usage Regularly remove unused resources to reduce costs. GA AZR-000012 Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. GA AZR-000013 Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. GA AZR-000014 Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. GA AZR-000015 Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. GA AZR-000016 Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. GA AZR-000017 Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. GA AZR-000018 Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. GA AZR-000019 Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. GA AZR-000020 Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. GA AZR-000021 Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. GA AZR-000022 Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. GA AZR-000023 Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. GA AZR-000024 Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. GA AZR-000025 Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. GA AZR-000026 Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. GA AZR-000027 Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. GA AZR-000028 Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. GA AZR-000029 Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. GA AZR-000030 Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. GA AZR-000031 Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. GA AZR-000032 Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. GA AZR-000033 Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. GA AZR-000034 Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. GA AZR-000035 Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. GA AZR-000036 Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. GA AZR-000038 Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. GA AZR-000039 Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. GA AZR-000040 Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. GA AZR-000041 Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. GA AZR-000042 Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. GA AZR-000043 Azure.APIM.APIDescriptors API Management APIs should have a display name and description. GA AZR-000044 Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. GA AZR-000045 Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. GA AZR-000046 Azure.APIM.ProductSubscription Configure products to require a subscription. GA AZR-000047 Azure.APIM.ProductApproval Configure products to require approval. GA AZR-000048 Azure.APIM.SampleProducts Remove starter and unlimited sample products. GA AZR-000049 Azure.APIM.ProductDescriptors API Management products should have a display name and description. GA AZR-000050 Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. GA AZR-000051 Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. GA AZR-000052 Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. GA AZR-000053 Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. GA AZR-000054 Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. GA AZR-000055 Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. GA AZR-000056 Azure.APIM.Name API Management service names should meet naming requirements. GA AZR-000057 Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. GA AZR-000058 Azure.AppConfig.Name App Configuration store names should meet naming requirements. GA AZR-000059 Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. GA AZR-000060 Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. GA AZR-000061 Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. GA AZR-000062 Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. GA AZR-000063 Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. GA AZR-000064 Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. GA AZR-000065 Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. GA AZR-000066 Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. GA AZR-000067 Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. GA AZR-000068 Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. GA AZR-000069 Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. GA AZR-000070 Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. GA AZR-000071 Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. GA AZR-000072 Azure.AppService.MinPlan Use at least a Standard App Service Plan. GA AZR-000073 Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. GA AZR-000074 Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. GA AZR-000075 Azure.AppService.NETVersion Configure applications to use newer .NET versions. GA AZR-000076 Azure.AppService.PHPVersion Configure applications to use newer PHP runtime versions. GA AZR-000077 Azure.AppService.AlwaysOn Configure Always On for App Service apps. GA AZR-000078 Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. GA AZR-000079 Azure.AppService.WebProbe Configure and enable instance health probes. GA AZR-000080 Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. GA AZR-000081 Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. GA AZR-000082 Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. GA AZR-000083 Azure.AppService.ARRAffinity Disable client affinity for stateless services. GA AZR-000084 Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. GA AZR-000085 Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. GA AZR-000086 Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. GA AZR-000087 Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). GA AZR-000088 Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. GA AZR-000089 Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. GA AZR-000090 Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. GA AZR-000091 Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. GA AZR-000092 Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. GA AZR-000093 Azure.CDN.HTTP Enforce HTTPS for client connections. GA AZR-000094 Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. GA AZR-000095 Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. GA AZR-000096 Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. GA AZR-000097 Azure.DataFactory.Version Consider migrating to DataFactory v2. GA AZR-000098 Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. GA AZR-000099 Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. GA AZR-000100 Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. GA AZR-000101 Azure.EventHub.Usage Regularly remove unused resources to reduce costs. GA AZR-000102 Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. GA AZR-000103 Azure.Firewall.Name Firewall names should meet naming requirements. GA AZR-000104 Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. GA AZR-000105 Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. GA AZR-000106 Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. GA AZR-000107 Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. GA AZR-000108 Azure.FrontDoor.Probe Use health probes to check the health of each backend. GA AZR-000109 Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. GA AZR-000110 Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. GA AZR-000111 Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. GA AZR-000112 Azure.FrontDoor.State Enable Azure Front Door Classic instance. GA AZR-000113 Azure.FrontDoor.Name Front Door names should meet naming requirements. GA AZR-000114 Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. GA AZR-000115 Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. GA AZR-000116 Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. GA AZR-000117 Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. GA AZR-000118 Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. GA AZR-000119 Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. GA AZR-000120 Azure.KeyVault.Name Key Vault names should meet naming requirements. GA AZR-000121 Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. GA AZR-000122 Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. GA AZR-000123 Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. GA AZR-000124 Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. GA AZR-000125 Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. GA AZR-000126 Azure.LB.Probe Use a specific probe for web protocols. GA AZR-000127 Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. GA AZR-000128 Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. GA AZR-000129 Azure.LB.Name Load Balancer names should meet naming requirements. GA AZR-000130 Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. GA AZR-000131 Azure.MySQL.UseSSL Enforce encrypted MySQL connections. GA AZR-000132 Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. GA AZR-000133 Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. GA AZR-000134 Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. GA AZR-000135 Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. GA AZR-000136 Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. GA AZR-000137 Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. GA AZR-000138 Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. GA AZR-000139 Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. GA AZR-000140 Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. GA AZR-000141 Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. GA AZR-000142 Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. GA AZR-000143 Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. GA AZR-000144 Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. GA AZR-000145 Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. GA AZR-000146 Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. GA AZR-000147 Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. GA AZR-000148 Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. GA AZR-000149 Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. GA AZR-000150 Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. GA AZR-000151 Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. GA AZR-000152 Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. GA AZR-000153 Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. GA AZR-000154 Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. GA AZR-000155 Azure.PublicIP.Name Public IP names should meet naming requirements. GA AZR-000156 Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. GA AZR-000157 Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. GA AZR-000158 Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. GA AZR-000159 Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. GA AZR-000160 Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. GA AZR-000161 Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. GA AZR-000162 Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. GA AZR-000163 Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. GA AZR-000164 Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. GA AZR-000165 Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. GA AZR-000166 Azure.Resource.UseTags Azure resources should be tagged using a standard convention. GA AZR-000167 Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. GA AZR-000168 Azure.ResourceGroup.Name Resource Group names should meet naming requirements. GA AZR-000169 Azure.Route.Name Route table names should meet naming requirements. GA AZR-000170 Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. GA AZR-000171 Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. GA AZR-000172 Azure.Search.SKU Use the basic and standard tiers for entry level workloads. GA AZR-000173 Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. GA AZR-000174 Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. GA AZR-000175 Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. GA AZR-000176 Azure.Search.Name AI Search service names should meet naming requirements. GA AZR-000177 Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. GA AZR-000178 Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. GA AZR-000179 Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. GA AZR-000180 Azure.SignalR.Name SignalR service instance names should meet naming requirements. GA AZR-000181 Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. GA AZR-000182 Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. GA AZR-000183 Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. GA AZR-000184 Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. GA AZR-000185 Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). GA AZR-000186 Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. GA AZR-000187 Azure.SQL.Auditing Enable auditing for Azure SQL logical server. GA AZR-000188 Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. GA AZR-000189 Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. GA AZR-000190 Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. GA AZR-000191 Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. GA AZR-000192 Azure.SQL.DBName Azure SQL Database names should meet naming requirements. GA AZR-000193 Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. GA AZR-000194 Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. GA AZR-000195 Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. GA AZR-000196 Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. GA AZR-000197 Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. GA AZR-000198 Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. GA AZR-000199 Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. GA AZR-000200 Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. GA AZR-000201 Azure.Storage.Name Storage Account names should meet naming requirements. GA AZR-000202 Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. GA AZR-000203 Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. GA AZR-000204 Azure.RBAC.LimitOwner Limit the number of subscription Owners. GA AZR-000205 Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. GA AZR-000206 Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). GA AZR-000207 Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. GA AZR-000208 Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. GA AZR-000209 Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. GA AZR-000210 Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. GA AZR-000211 Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. GA AZR-000212 Azure.Template.TemplateFile Use ARM template files that are valid. GA AZR-000213 Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. GA AZR-000214 Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. GA AZR-000215 Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. GA AZR-000216 Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. GA AZR-000217 Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. GA AZR-000218 Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. GA AZR-000219 Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. GA AZR-000220 Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. GA AZR-000221 Azure.Template.LocationType Location parameters should use a string value. GA AZR-000222 Azure.Template.ResourceLocation Template resource location should be an expression or global. GA AZR-000223 Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. GA AZR-000224 Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. GA AZR-000225 Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. GA AZR-000226 Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. GA AZR-000227 Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. GA AZR-000228 Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. GA AZR-000229 Azure.Template.ParameterFile Use ARM template parameter files that are valid. GA AZR-000230 Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. GA AZR-000231 Azure.Template.MetadataLink Configure a metadata link for each parameter file. GA AZR-000232 Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. GA AZR-000233 Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. GA AZR-000234 Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. GA AZR-000235 Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. GA AZR-000236 Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. GA AZR-000237 Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. GA AZR-000238 Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. GA AZR-000239 Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. GA AZR-000240 Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. GA AZR-000241 Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. GA AZR-000242 Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. GA AZR-000243 Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. GA AZR-000244 Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. GA AZR-000245 Azure.VM.PublicKey Linux virtual machines should use public keys. GA AZR-000246 Azure.VM.Agent Ensure the VM agent is provisioned automatically. GA AZR-000247 Azure.VM.Updates Ensure automatic updates are enabled at deployment. GA AZR-000248 Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. GA AZR-000249 Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. GA AZR-000250 Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. GA AZR-000251 Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. GA AZR-000252 Azure.VM.ADE Use Azure Disk Encryption (ADE). GA AZR-000253 Azure.VM.DiskName Managed Disk names should meet naming requirements. GA AZR-000254 Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. GA AZR-000255 Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). GA AZR-000256 Azure.VM.ASName Availability Set names should meet naming requirements. GA AZR-000257 Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. GA AZR-000258 Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. GA AZR-000259 Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. GA AZR-000260 Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. GA AZR-000261 Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. GA AZR-000262 Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. GA AZR-000263 Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. GA AZR-000264 Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. GA AZR-000265 Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. GA AZR-000266 Azure.VNET.PeerState VNET peering connections must be connected. GA AZR-000267 Azure.VNET.SubnetName Subnet names should meet naming requirements. GA AZR-000268 Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. GA AZR-000269 Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. GA AZR-000270 Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. GA AZR-000271 Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. GA AZR-000272 Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. GA AZR-000273 Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. GA AZR-000274 Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. GA AZR-000275 Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. GA AZR-000276 Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. GA AZR-000277 Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. GA AZR-000278 Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. GA AZR-000279 Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. GA AZR-000280 Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. GA AZR-000281 Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. GA AZR-000282 Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. GA AZR-000283 Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. GA AZR-000284 Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. GA AZR-000285 Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. GA AZR-000286 Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. GA AZR-000287 Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. GA AZR-000288 Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. GA AZR-000289 Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. GA AZR-000290 Azure.Defender.Containers Enable Microsoft Defender for Containers. GA AZR-000291 Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. GA AZR-000292 Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. GA AZR-000293 Azure.Defender.Servers Enable Microsoft Defender for Servers. GA AZR-000294 Azure.Defender.SQL Enable Microsoft Defender for SQL servers. GA AZR-000295 Azure.Defender.AppServices Enable Microsoft Defender for App Service. GA AZR-000296 Azure.Defender.Storage Enable Microsoft Defender for Storage. GA AZR-000297 Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. GA AZR-000298 Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. GA AZR-000299 Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. GA AZR-000300 Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. GA AZR-000301 Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. GA AZR-000302 Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. GA AZR-000303 Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. GA AZR-000304 Azure.AppGwWAF.RuleGroups Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. GA AZR-000305 Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. GA AZR-000306 Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. GA AZR-000307 Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. GA AZR-000308 Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. GA AZR-000309 Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. GA AZR-000310 Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Preview AZR-000311 Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. GA AZR-000312 Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. GA AZR-000313 Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. GA AZR-000314 Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. GA AZR-000315 Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. GA AZR-000316 Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. GA AZR-000317 Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. GA AZR-000318 Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. GA AZR-000319 Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. GA AZR-000320 Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. GA AZR-000321 Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. GA AZR-000322 Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. GA AZR-000323 Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. GA AZR-000324 Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. GA AZR-000325 Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. GA AZR-000326 Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. GA AZR-000327 Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. GA AZR-000328 Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. GA AZR-000329 Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. GA AZR-000330 Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. GA AZR-000331 Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. GA AZR-000332 Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. GA AZR-000333 Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. GA AZR-000334 Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. GA AZR-000335 Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. GA AZR-000336 Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. GA AZR-000337 Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. GA AZR-000338 Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. GA AZR-000339 Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. GA AZR-000340 Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. GA AZR-000341 Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. GA AZR-000342 Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. GA AZR-000343 Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. GA AZR-000344 Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. GA AZR-000345 Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. GA AZR-000346 Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. GA AZR-000347 Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. GA AZR-000348 Azure.AppGw.Name Application Gateways should meet naming requirements. GA AZR-000349 Azure.Bastion.Name Bastion hosts should meet naming requirements. GA AZR-000350 Azure.RSV.Name Recovery Services vaults should meet naming requirements. GA AZR-000351 Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. GA AZR-000352 Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. GA AZR-000353 Azure.Defender.Dns Enable Microsoft Defender for DNS. GA AZR-000354 Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). GA AZR-000355 Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. GA AZR-000356 Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. GA AZR-000357 Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. GA AZR-000358 Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. GA AZR-000359 Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. GA AZR-000360 Azure.ContainerApp.Name Container Apps should meet naming requirements. GA AZR-000361 Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. GA AZR-000362 Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. GA AZR-000363 Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. GA AZR-000364 Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. GA AZR-000365 Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. GA AZR-000366 Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. GA AZR-000367 Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. GA AZR-000368 Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. GA AZR-000369 Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. GA AZR-000370 Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. GA AZR-000371 Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. GA AZR-000372 Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. GA AZR-000373 Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Preview AZR-000374 Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Preview AZR-000375 Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Preview AZR-000376 Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. GA AZR-000377 Azure.Defender.Api Enable Microsoft Defender for APIs. GA AZR-000378 Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. GA AZR-000379 Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. GA AZR-000380 Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. GA AZR-000381 Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. GA AZR-000382 Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. GA AZR-000383 Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. GA AZR-000384 Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. GA AZR-000385 Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Preview AZR-000386 Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. GA AZR-000387 Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. GA AZR-000388 Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. GA AZR-000389 Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. GA AZR-000390 Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. GA AZR-000391 Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Preview AZR-000392 Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. GA AZR-000393 Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. GA AZR-000394 Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. GA AZR-000395 Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. GA AZR-000396 Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. GA AZR-000397 Azure.RSV.Immutable Ensure immutability is configured to protect backup data. GA AZR-000398 Azure.BV.Immutable Ensure immutability is configured to protect backup data. GA AZR-000399 Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. GA AZR-000400 Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. GA AZR-000401 Azure.ACR.AnonymousAccess Disable anonymous pull access. Preview AZR-000402 Azure.ACR.Firewall Limit network access of container registries to only trusted clients. GA AZR-000403 Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. GA AZR-000404 Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. GA AZR-000405 Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). GA AZR-000406 Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. GA AZR-000407 Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. GA AZR-000408 Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. GA AZR-000409 Azure.Databricks.SKU Ensure Databricks workspaces are non-trial SKUs for production workloads. GA AZR-000410 Azure.Databricks.PublicAccess Azure Databricks workspaces should disable public network access. GA AZR-000411 Azure.DevBox.ProjectLimit Limit the number of Dev Boxes a single user can create for a project. GA AZR-000412 Azure.AKS.MinUserPoolNodes User node pools in an AKS cluster should have a minimum number of nodes for failover and updates. GA"},{"location":"es/rules/Azure.ACR.AdminUser/","title":"Deshabilitar el usuario adminstrador para ACR","text":"Azure.ACR.AdminUserAZR-000005ErrorSeguridad \u00b7 Container Registry \u00b7 Rule \u00b7 2020_06 \u00b7 Critico
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"es/rules/Azure.ACR.AdminUser/#sinopsis","title":"Sinopsis","text":"Usar identidades de Azure AD en lugar de usar el usuario administrador del registro.
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"es/rules/Azure.ACR.AdminUser/#descripcion","title":"Descripci\u00f3n","text":"Azure Container Registry (ACR) incluye una cuenta de usuario administrador incorporada. La cuenta de usuario administrador es una cuenta de usuario \u00fanica con acceso administrativo al registro. Esta cuenta proporciona acceso de usuario \u00fanico para pruebas y desarrollo tempranos. La cuenta de usuario administrador no est\u00e1 dise\u00f1ada para usarse con registros de contenedores de producci\u00f3n.
En su lugar, utilice el control de acceso basado en roles (RBAC). RBAC se puede usar para delegar permisos de registro a una identidad de Azure AD (AAD).
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"es/rules/Azure.ACR.AdminUser/#recomendacion","title":"Recomendaci\u00f3n","text":"Considere deshabilitar la cuenta de usuario administrador y solo use la autenticaci\u00f3n basada en identidad para las operaciones de registro.
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"es/rules/Azure.ACR.AdminUser/#ejemplos","title":"Ejemplos","text":"","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"es/rules/Azure.ACR.AdminUser/#configurar-con-plantilla-de-arm","title":"Configurar con plantilla de ARM","text":"Para implementar Container Registries, pasa la siguiente regla:
properties.adminUserEnabled
a false
.Por ejemplo:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2023-07-01\",\n \"name\": \"[parameters('name')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"days\": 30,\n \"status\": \"enabled\"\n }\n }\n }\n}\n
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"es/rules/Azure.ACR.AdminUser/#configurar-con-bicep","title":"Configurar con Bicep","text":"Para implementar Container Registries, pasa la siguiente regla:
properties.adminUserEnabled
a false
.Por ejemplo:
Azure Bicep snippetresource registry 'Microsoft.ContainerRegistry/registries@2023-07-01' = {\n name: name\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n days: 30\n status: 'enabled'\n }\n }\n }\n}\n
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"es/rules/Azure.ACR.AdminUser/#configurar-con-azure-cli","title":"Configurar con Azure CLI","text":"Azure CLI snippetaz acr update -n '<name>' -g '<resource_group>' --admin-enabled false\n
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"es/rules/Azure.ACR.AdminUser/#configurar-con-azure-powershell","title":"Configurar con Azure PowerShell","text":"Azure PowerShell snippetUpdate-AzContainerRegistry -ResourceGroupName '<resource_group>' -Name '<name>' -DisableAdminUser\n
","tags":["Azure.ACR.AdminUser","AZR-000005"]},{"location":"es/rules/Azure.ACR.AdminUser/#enlaces","title":"Enlaces","text":"Seguridad \u00b7 Container Registry \u00b7 Rule \u00b7 2020_12 \u00b7 Critico
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"es/rules/Azure.ACR.ContainerScan/#sinopsis","title":"Sinopsis","text":"Habilite el an\u00e1lisis de vulnerabilidades para im\u00e1genes de contenedores.
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"es/rules/Azure.ACR.ContainerScan/#descripcion","title":"Descripci\u00f3n","text":"Un riesgo potencial con las cargas de trabajo basadas en contenedores son las vulnerabilidades de seguridad sin parches en:
Es importante adoptar una estrategia para escanear activamente las im\u00e1genes en busca de vulnerabilidades de seguridad. Una opci\u00f3n para escanear im\u00e1genes de contenedores es usar Microsoft Defender para registros de contenedores. Microsoft Defender para registros de contenedores analiza cada imagen de contenedor enviada al registro.
Microsoft Defender para registros de contenedores analiza im\u00e1genes en im\u00e1genes insertadas, importadas y extra\u00eddas recientemente. Las im\u00e1genes extra\u00eddas recientemente se escanean peri\u00f3dicamente cuando se extrajeron en los \u00faltimos 30 d\u00edas. Cualquier vulnerabilidad detectada se informa a Microsoft Defender for Cloud.
Escaneo de vulnerabilidades de im\u00e1genes de contenedores con Microsoft Defender para registros de contenedores:
Considere usar Microsoft Defender para la nube para buscar vulnerabilidades de seguridad en im\u00e1genes de contenedores.
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"es/rules/Azure.ACR.ContainerScan/#ejemplos","title":"Ejemplos","text":"","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"es/rules/Azure.ACR.ContainerScan/#configurar-con-plantilla-de-arm","title":"Configurar con plantilla de ARM","text":"Para habilitar el escaneo de im\u00e1genes de contenedores:
pricingTier
a Standard
para Microsoft Defender para container registries.Por ejemplo:
Azure Template snippet{\n \"type\": \"Microsoft.Security/pricings\",\n \"apiVersion\": \"2018-06-01\",\n \"name\": \"ContainerRegistry\",\n \"properties\": {\n \"pricingTier\": \"Standard\"\n }\n}\n
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"es/rules/Azure.ACR.ContainerScan/#configurar-con-bicep","title":"Configurar con Bicep","text":"Para habilitar el escaneo de im\u00e1genes de contenedores:
pricingTier
a Standard
para Microsoft Defender para container registries.Por ejemplo:
Azure Bicep snippetresource defenderForContainerRegistry 'Microsoft.Security/pricings@2018-06-01' = {\n name: 'ContainerRegistry'\n properties: {\n pricingTier: 'Standard'\n }\n}\n
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"es/rules/Azure.ACR.ContainerScan/#configurar-con-azure-cli","title":"Configurar con Azure CLI","text":"Azure CLI snippetaz security pricing create -n 'ContainerRegistry' --tier 'standard'\n
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"es/rules/Azure.ACR.ContainerScan/#configurar-con-azure-powershell","title":"Configurar con Azure PowerShell","text":"Azure PowerShell snippetSet-AzSecurityPricing -Name 'ContainerRegistry' -PricingTier 'Standard'\n
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"es/rules/Azure.ACR.ContainerScan/#notas","title":"Notas","text":"Esta regla se aplica cuando se analizan los recursos implementados en Azure.
","tags":["Azure.ACR.ContainerScan","AZR-000002"]},{"location":"es/rules/Azure.ACR.ContainerScan/#enlaces","title":"Enlaces","text":"Seguridad \u00b7 Container Registry \u00b7 Rule \u00b7 2020_12 \u00b7 Importante
","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"es/rules/Azure.ACR.ContentTrust/#sinopsis","title":"Sinopsis","text":"Utilica im\u00e1genes de contenedores firmadas por un publicador de im\u00e1genes de confianza. Use container images signed by a trusted image publisher.
","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"es/rules/Azure.ACR.ContentTrust/#descripcion","title":"Descripci\u00f3n","text":"La confianza en el contenido de Azure Container Registry (ACR) permite insertar y extraer im\u00e1genes firmadas. Las im\u00e1genes firmadas brindan una garant\u00eda adicional de que se han creado en una fuente confiable. Para habilitar la confianza en el contenido, el registro del contenedor debe usar una SKU Premium.
","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"es/rules/Azure.ACR.ContentTrust/#recomendacion","title":"Recomendaci\u00f3n","text":"Considere habilitar la confianza en el contenido en registros, clientes e im\u00e1genes de contenedores de firmas.
","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"es/rules/Azure.ACR.ContentTrust/#ejemplos","title":"Ejemplos","text":"","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"es/rules/Azure.ACR.ContentTrust/#configurar-con-plantilla-de-arm","title":"Configurar con plantilla de ARM","text":"Para implementar resgistros de contenedores que superen esta regla:
properties.trustPolicy.status
a enabled
.properties.trustPolicy.type
a Notary
.Por ejemplo:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2021-06-01-preview\",\n \"name\": \"[parameters('registryName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"quarantinePolicy\": {\n \"status\": \"enabled\"\n },\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"status\": \"enabled\",\n \"days\": 30\n }\n }\n }\n}\n
","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"es/rules/Azure.ACR.ContentTrust/#configurar-con-bicep","title":"Configurar con Bicep","text":"Para implementar resgistros de contenedores que superen esta regla:
properties.trustPolicy.status
a enabled
.properties.trustPolicy.type
a Notary
.Por ejemplo:
Azure Bicep snippetresource acr 'Microsoft.ContainerRegistry/registries@2021-06-01-preview' = {\n name: registryName\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n quarantinePolicy: {\n status: 'enabled'\n }\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n status: 'enabled'\n days: 30\n }\n }\n }\n}\n
","tags":["Azure.ACR.ContentTrust","AZR-000009"]},{"location":"es/rules/Azure.ACR.ContentTrust/#enlaces","title":"Enlaces","text":"Confiabilidad \u00b7 Container Registry \u00b7 Rule \u00b7 2020_12 \u00b7 Importante
","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"es/rules/Azure.ACR.GeoReplica/#sinopsis","title":"Sinopsis","text":"Utilice registros de contenedores replicados geogr\u00e1ficamente para complementar las implementaciones de contenedores en varias regiones.
","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"es/rules/Azure.ACR.GeoReplica/#descripcion","title":"Descripci\u00f3n","text":"Un registro de contenedor se almacena y mantiene de forma predeterminada en una sola regi\u00f3n. Opcionalmente, se puede habilitar la replicaci\u00f3n geogr\u00e1fica en una o m\u00e1s regiones adicionales.
Los registros de contenedores de replicaci\u00f3n geogr\u00e1fica brindan los siguientes beneficios:
Considere usar un registro de contenedor replicado geogr\u00e1ficamente para implementaciones en varias regiones.
","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"es/rules/Azure.ACR.GeoReplica/#ejemplos","title":"Ejemplos","text":"","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"es/rules/Azure.ACR.GeoReplica/#configurar-con-plantilla-de-arm","title":"Configurar con plantilla de ARM","text":"Para habilitar la replicaci\u00f3n geogr\u00e1fica para registros de contenedores que pasan esta regla:
sku.name
a Premium
(necesario para la replicaci\u00f3n geogr\u00e1fica).replications
con location
establecida en la regi\u00f3n para replicar.Por ejemplo:
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"metadata\": {\n \"_generator\": {\n \"name\": \"bicep\",\n \"version\": \"0.5.6.12127\",\n \"templateHash\": \"12610175857982700190\"\n }\n },\n \"parameters\": {\n \"acrName\": {\n \"type\": \"string\",\n \"defaultValue\": \"[format('acr{0}', uniqueString(resourceGroup().id))]\",\n \"maxLength\": 50,\n \"minLength\": 5,\n \"metadata\": {\n \"description\": \"Globally unique name of your Azure Container Registry\"\n }\n },\n \"acrAdminUserEnabled\": {\n \"type\": \"bool\",\n \"defaultValue\": false,\n \"metadata\": {\n \"description\": \"Enable admin user that has push / pull permission to the registry.\"\n }\n },\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"Location for registry home replica.\"\n }\n },\n \"acrSku\": {\n \"type\": \"string\",\n \"defaultValue\": \"Premium\",\n \"allowedValues\": [\"Premium\"],\n \"metadata\": {\n \"description\": \"Tier of your Azure Container Registry. Geo-replication requires Premium SKU.\"\n }\n },\n \"acrReplicaLocation\": {\n \"type\": \"string\",\n \"metadata\": {\n \"description\": \"Short name for registry replica location.\"\n }\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2019-12-01-preview\",\n \"name\": \"[parameters('acrName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('acrSku')]\"\n },\n \"tags\": {\n \"displayName\": \"Container Registry\",\n \"container.registry\": \"[parameters('acrName')]\"\n },\n \"properties\": {\n \"adminUserEnabled\": \"[parameters('acrAdminUserEnabled')]\"\n }\n },\n {\n \"type\": \"Microsoft.ContainerRegistry/registries/replications\",\n \"apiVersion\": \"2019-12-01-preview\",\n \"name\": \"[format('{0}/{1}', parameters('acrName'), parameters('acrReplicaLocation'))]\",\n \"location\": \"[parameters('acrReplicaLocation')]\",\n \"properties\": {},\n \"dependsOn\": [\n \"[resourceId('Microsoft.ContainerRegistry/registries', parameters('acrName'))]\"\n ]\n }\n ],\n \"outputs\": {\n \"acrLoginServer\": {\n \"type\": \"string\",\n \"value\": \"[reference(resourceId('Microsoft.ContainerRegistry/registries', parameters('acrName'))).loginServer]\"\n }\n }\n}\n
","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"es/rules/Azure.ACR.GeoReplica/#configurar-con-bicep","title":"Configurar con Bicep","text":"Para habilitar la replicaci\u00f3n geogr\u00e1fica para registros de contenedores que pasan esta regla:
sku.name
a Premium
(necesario para la replicaci\u00f3n geogr\u00e1fica).replications
con location
establecida en la regi\u00f3n para replicar.Por ejemplo:
Azure Bicep snippetresource containerRegistry 'Microsoft.ContainerRegistry/registries@2019-12-01-preview' = {\n name: acrName\n location: location\n sku: {\n name: 'Premium'\n }\n tags: {\n displayName: 'Container Registry'\n 'container.registry': acrName\n }\n properties: {\n adminUserEnabled: acrAdminUserEnabled\n }\n}\n\nresource containerRegistryReplica 'Microsoft.ContainerRegistry/registries/replications@2019-12-01-preview' = {\n parent: containerRegistry\n name: '${acrReplicaLocation}'\n location: acrReplicaLocation\n properties: {\n }\n}\n
","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"es/rules/Azure.ACR.GeoReplica/#notas","title":"Notas","text":"Esta regla se aplica cuando se analizan los recursos implementados en Azure.
","tags":["Azure.ACR.GeoReplica","AZR-000004"]},{"location":"es/rules/Azure.ACR.GeoReplica/#elaces","title":"Elaces","text":"Seguridad \u00b7 Container Registry \u00b7 Rule \u00b7 2020_12 \u00b7 Critico
","tags":["Azure.ACR.ImageHealth","AZR-000003"]},{"location":"es/rules/Azure.ACR.ImageHealth/#sinopsis","title":"Sinopsis","text":"Eliminar im\u00e1genes de contenedores con vulnerabilidades conocidas.
","tags":["Azure.ACR.ImageHealth","AZR-000003"]},{"location":"es/rules/Azure.ACR.ImageHealth/#descripcion","title":"Descripci\u00f3n","text":"Cuando Microsoft Defender para registros de contenedores est\u00e1 habilitado, Microsoft Defender analiza las im\u00e1genes de contenedores. Las im\u00e1genes de contenedores se escanean en busca de vulnerabilidades conocidas y se marcan como saludables o no saludables. No se deben utilizar im\u00e1genes de contenedores vulnerables.
","tags":["Azure.ACR.ImageHealth","AZR-000003"]},{"location":"es/rules/Azure.ACR.ImageHealth/#recomendacion","title":"Recomendaci\u00f3n","text":"Considere usar la eliminaci\u00f3n de im\u00e1genes de contenedores con vulnerabilidades conocidas.
","tags":["Azure.ACR.ImageHealth","AZR-000003"]},{"location":"es/rules/Azure.ACR.ImageHealth/#notas","title":"Notas","text":"Esta regla se aplica cuando se analizan los recursos implementados en Azure.
","tags":["Azure.ACR.ImageHealth","AZR-000003"]},{"location":"es/rules/Azure.ACR.ImageHealth/#enlaces","title":"Enlaces","text":"Confiabilidad \u00b7 Container Registry \u00b7 Rule \u00b7 2020_06 \u00b7 Importante
","tags":["Azure.ACR.MinSku","AZR-000006"]},{"location":"es/rules/Azure.ACR.MinSku/#sinopsis","title":"Sinopsis","text":"ACR debe usar el SKU Premium o Est\u00e1ndar para las implementaciones de producci\u00f3n.
","tags":["Azure.ACR.MinSku","AZR-000006"]},{"location":"es/rules/Azure.ACR.MinSku/#descripcion","title":"Descripci\u00f3n","text":"Azure Container Registry (ACR) proporciona una gama de diferentes niveles de servicio (tambi\u00e9n conocidos como SKU). Estos niveles de servicio proporcionan diferentes niveles de rendimiento y caracter\u00edsticas.
Hay tres niveles de servicio disponibles: B\u00e1sico, Est\u00e1ndar y Premium. Los registros de contenedores b\u00e1sicos solo se recomiendan para implementaciones que no sean de producci\u00f3n. Utilice un m\u00ednimo de Est\u00e1ndar para registros de contenedores de producci\u00f3n.
El SKU Premium proporciona un mayor rendimiento de im\u00e1genes y almacenamiento incluido, y es necesario para:
Considere usar el SKU de Premium de registros de contenedores para implementaciones de producci\u00f3n.
","tags":["Azure.ACR.MinSku","AZR-000006"]},{"location":"es/rules/Azure.ACR.MinSku/#ejemplos","title":"Ejemplos","text":"","tags":["Azure.ACR.MinSku","AZR-000006"]},{"location":"es/rules/Azure.ACR.MinSku/#configurar-con-plantilla-de-arm","title":"Configurar con plantilla de ARM","text":"Para implementar registros de contenedores que superen esta regla:
sku.name
a Premium
o Standard
.Por ejemplo:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2021-06-01-preview\",\n \"name\": \"[parameters('registryName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"quarantinePolicy\": {\n \"status\": \"enabled\"\n },\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"status\": \"enabled\",\n \"days\": 30\n }\n }\n }\n}\n
","tags":["Azure.ACR.MinSku","AZR-000006"]},{"location":"es/rules/Azure.ACR.MinSku/#configurar-con-bicep","title":"Configurar con Bicep","text":"Para implementar registros de contenedores que superen esta regla:
sku.name
a Premium
o Standard
.Por ejemplo:
Azure Bicep snippetresource acr 'Microsoft.ContainerRegistry/registries@2021-06-01-preview' = {\n name: registryName\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n quarantinePolicy: {\n status: 'enabled'\n }\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n status: 'enabled'\n days: 30\n }\n }\n }\n}\n
","tags":["Azure.ACR.MinSku","AZR-000006"]},{"location":"es/rules/Azure.ACR.MinSku/#elaces","title":"Elaces","text":"Excelencia operativa \u00b7 Container Registry \u00b7 Rule \u00b7 2020_06 \u00b7 Consciente
","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"es/rules/Azure.ACR.Name/#sinopsis","title":"Sinopsis","text":"Los nombres de registro de contenedores deben cumplir con los requisitos de denominaci\u00f3n.
","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"es/rules/Azure.ACR.Name/#descripcion","title":"Descripci\u00f3n","text":"Al nombrar los recursos de Azure, los nombres de los recursos deben cumplir con los requisitos del servicio. Los requisitos para los nombres de registro de contenedores son:
Considere usar nombres que cumplan con los requisitos de nombres del registro de contenedores. Adem\u00e1s, considere nombrar recursos con una convenci\u00f3n de nomenclatura est\u00e1ndar.
","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"es/rules/Azure.ACR.Name/#ejemplos","title":"Ejemplos","text":"","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"es/rules/Azure.ACR.Name/#configurar-con-plantilla-de-arm","title":"Configurar con plantilla de ARM","text":"Puede asegurarse de que el par\u00e1metro acrName
cumpla con los requisitos de nomenclatura utilizando las propiedades de los par\u00e1metros MinLength
y maxLength
. Tambi\u00e9n puede usar una funci\u00f3n uniqueString()
para asegurarse de que el nombre sea globalmente \u00fanico.
Por ejemplo
Azure Template snippet{\n \"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"parameters\": {\n \"acrName\": {\n \"type\": \"string\",\n \"defaultValue\": \"[format('acr{0}', uniqueString(resourceGroup().id))]\",\n \"maxLength\": 50,\n \"minLength\": 5,\n \"metadata\": {\n \"description\": \"Globally unique name of your Azure Container Registry\"\n }\n },\n \"location\": {\n \"type\": \"string\",\n \"defaultValue\": \"[resourceGroup().location]\",\n \"metadata\": {\n \"description\": \"Location for registry home replica.\"\n }\n },\n \"acrSku\": {\n \"type\": \"string\",\n \"defaultValue\": \"Premium\",\n \"allowedValues\": [\n \"Standard\"\n \"Premium\"\n ],\n \"metadata\": {\n \"description\": \"Tier of your Azure Container Registry.\"\n }\n }\n },\n \"resources\": [\n {\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2019-12-01-preview\",\n \"name\": \"[parameters('acrName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"[parameters('acrSku')]\"\n },\n \"tags\": {\n \"displayName\": \"Container Registry\",\n \"container.registry\": \"[parameters('acrName')]\"\n }\n }\n ],\n \"outputs\": {\n \"acrLoginServer\": {\n \"type\": \"string\",\n \"value\": \"[reference(resourceId('Microsoft.ContainerRegistry/registries', parameters('acrName'))).loginServer]\"\n }\n }\n}\n
","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"es/rules/Azure.ACR.Name/#configurar-con-bicep","title":"Configurar con Bicep","text":"Puede asegurarse de que el par\u00e1metro acrName
cumpla con los requisitos de nomenclatura utilizando las propiedades de los par\u00e1metros MinLength
y maxLength
. Tambi\u00e9n puede usar una funci\u00f3n uniqueString()
para asegurarse de que el nombre sea globalmente \u00fanico.
Por ejemplo:
Azure Bicep snippet@description('Globally unique name of your Azure Container Registry')\n@minLength(5)\n@maxLength(50)\nparam acrName string = 'acr${uniqueString(resourceGroup().id)}'\n\n@description('Location for registry home replica.')\nparam location string = resourceGroup().location\n\n@description('Tier of your Azure Container Registry. Geo-replication requires Premium SKU.')\n@allowed([\n 'Standard'\n 'Premium'\n])\nparam acrSku string = 'Premium'\n\nresource containerRegistry 'Microsoft.ContainerRegistry/registries@2019-12-01-preview' = {\n name: acrName\n location: location\n sku: {\n name: acrSku\n }\n tags: {\n displayName: 'Container Registry'\n 'container.registry': acrName\n }\n}\n\noutput acrLoginServer string = containerRegistry.properties.loginServer\n
","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"es/rules/Azure.ACR.Name/#notas","title":"Notas","text":"Esta regla no comprueba si los nombres de registro de contenedores son \u00fanicos.
","tags":["Azure.ACR.Name","AZR-000007"]},{"location":"es/rules/Azure.ACR.Name/#enlaces","title":"Enlaces","text":"Seguridad \u00b7 Container Registry \u00b7 Rule \u00b7 Preview \u00b7 2020_12 \u00b7 Importante
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"es/rules/Azure.ACR.Quarantine/#sinopsis","title":"Sinopsis","text":"Habilite la cuarentena de im\u00e1genes de contenedores, escanee y marque im\u00e1genes como verificadas.
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"es/rules/Azure.ACR.Quarantine/#descripcion","title":"Descripci\u00f3n","text":"La cuarentena de im\u00e1genes es una opci\u00f3n configurable para Azure Container Registry (ACR). Cuando est\u00e1 habilitado, las im\u00e1genes enviadas al registro del contenedor no est\u00e1n disponibles de forma predeterminada. Cada imagen debe verificarse y marcarse como Aprobada
antes de que est\u00e9 disponible para extraer.
Para verificar im\u00e1genes de contenedores, integre con una herramienta de seguridad externa que admita esta funci\u00f3n.
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"es/rules/Azure.ACR.Quarantine/#recomendacion","title":"Recomendaci\u00f3n","text":"Considere configurar una herramienta de seguridad para implementar el patr\u00f3n de cuarentena de im\u00e1genes. Habilite la cuarentena de im\u00e1genes en el registro de contenedores para garantizar que cada imagen se verifique antes de su uso.
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"es/rules/Azure.ACR.Quarantine/#ejemplos","title":"Ejemplos","text":"","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"es/rules/Azure.ACR.Quarantine/#configurar-con-plantilla-de-arm","title":"Configurar con plantilla de ARM","text":"Para implementar registros de contenedores que superen esta regla:
properties.quarantinePolicy.status
a enabled
.Por ejemplo:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2021-06-01-preview\",\n \"name\": \"[parameters('registryName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"quarantinePolicy\": {\n \"status\": \"enabled\"\n },\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"status\": \"enabled\",\n \"days\": 30\n }\n }\n }\n}\n
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"es/rules/Azure.ACR.Quarantine/#configurar-con-bicep","title":"Configurar con Bicep","text":"Para implementar registros de contenedores que superen esta regla:
properties.quarantinePolicy.status
a enabled
.Por ejemplo:
Azure Bicep snippetresource acr 'Microsoft.ContainerRegistry/registries@2021-06-01-preview' = {\n name: registryName\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n quarantinePolicy: {\n status: 'enabled'\n }\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n status: 'enabled'\n days: 30\n }\n }\n }\n}\n
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"es/rules/Azure.ACR.Quarantine/#notas","title":"Notas","text":"La cuarentena de im\u00e1genes para Azure Container Registry se encuentra actualmente en versi\u00f3n preliminar.
","tags":["Azure.ACR.Quarantine","AZR-000008"]},{"location":"es/rules/Azure.ACR.Quarantine/#enlaces","title":"Enlaces","text":"Optimizaci\u00f3n de costos \u00b7 Container Registry \u00b7 Rule \u00b7 Preview \u00b7 2020_12 \u00b7 Importante
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"es/rules/Azure.ACR.Retention/#sinopsis","title":"Sinopsis","text":"Use una directiva de retenci\u00f3n para limpiar los manifiestos sin etiquetar.
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"es/rules/Azure.ACR.Retention/#descripcion","title":"Descripci\u00f3n","text":"La directiva de retenci\u00f3n es una opci\u00f3n configurable de Premium Azure Container Registry (ACR). Cuando se configura una directiva de retenci\u00f3n, los manifiestos sin etiquetar en el registro se eliminan autom\u00e1ticamente. Un manifiesto no est\u00e1 etiquetado cuando se env\u00eda una imagen m\u00e1s reciente con la misma etiqueta. es decir, lo \u00faltimo.
La directiva de retenci\u00f3n (en d\u00edas) se puede establecer en 0-365. El valor predeterminado es 7 d\u00edas.
Para configurar una directiva de retenci\u00f3n, el registro del contenedor debe usar una SKU Premium.
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"es/rules/Azure.ACR.Retention/#recomendacion","title":"Recomendaci\u00f3n","text":"Considere habilitar una directiva de retenci\u00f3n para manifiestos sin etiquetar.
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"es/rules/Azure.ACR.Retention/#ejemplos","title":"Ejemplos","text":"","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"es/rules/Azure.ACR.Retention/#configurar-con-plantilla-de-arm","title":"Configurar con plantilla de ARM","text":"Para implementar registros de contenedores que superen esta regla:
properties.retentionPolicy.status
a enabled
.Por ejemplo:
Azure Template snippet{\n \"type\": \"Microsoft.ContainerRegistry/registries\",\n \"apiVersion\": \"2021-06-01-preview\",\n \"name\": \"[parameters('registryName')]\",\n \"location\": \"[parameters('location')]\",\n \"sku\": {\n \"name\": \"Premium\"\n },\n \"identity\": {\n \"type\": \"SystemAssigned\"\n },\n \"properties\": {\n \"adminUserEnabled\": false,\n \"policies\": {\n \"quarantinePolicy\": {\n \"status\": \"enabled\"\n },\n \"trustPolicy\": {\n \"status\": \"enabled\",\n \"type\": \"Notary\"\n },\n \"retentionPolicy\": {\n \"status\": \"enabled\",\n \"days\": 30\n }\n }\n }\n}\n
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"es/rules/Azure.ACR.Retention/#configurar-con-bicep","title":"Configurar con Bicep","text":"Para implementar registros de contenedores que superen esta regla:
properties.retentionPolicy.status
a enabled
.Por ejemplo:
Azure Bicep snippetresource acr 'Microsoft.ContainerRegistry/registries@2021-06-01-preview' = {\n name: registryName\n location: location\n sku: {\n name: 'Premium'\n }\n identity: {\n type: 'SystemAssigned'\n }\n properties: {\n adminUserEnabled: false\n policies: {\n quarantinePolicy: {\n status: 'enabled'\n }\n trustPolicy: {\n status: 'enabled'\n type: 'Notary'\n }\n retentionPolicy: {\n status: 'enabled'\n days: 30\n }\n }\n }\n}\n
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"es/rules/Azure.ACR.Retention/#notas","title":"Notas","text":"Las directivas de retenci\u00f3n para Azure Container Registry est\u00e1n actualmente en versi\u00f3n preliminar.
","tags":["Azure.ACR.Retention","AZR-000010"]},{"location":"es/rules/Azure.ACR.Retention/#enlaces","title":"Enlaces","text":"Optimizaci\u00f3n de costos \u00b7 Container Registry \u00b7 Rule \u00b7 2020_12 \u00b7 Importante
","tags":["Azure.ACR.Usage","AZR-000001"]},{"location":"es/rules/Azure.ACR.Usage/#sinopsis","title":"Sinopsis","text":"Elimine peri\u00f3dicamente las im\u00e1genes obsoletas e innecesarias para reducir el uso del almacenamiento.
","tags":["Azure.ACR.Usage","AZR-000001"]},{"location":"es/rules/Azure.ACR.Usage/#descripcion","title":"Descripci\u00f3n","text":"Cada SKU de ACR tiene una cantidad de almacenamiento incluido. Cuando se excede la cantidad de almacenamiento incluido, se acumulan costos de almacenamiento adicionales por GiB.
Es una buena pr\u00e1ctica limpiar regularmente las im\u00e1genes hu\u00e9rfanas. Estas im\u00e1genes son el resultado de enviar im\u00e1genes actualizadas con la misma etiqueta.
","tags":["Azure.ACR.Usage","AZR-000001"]},{"location":"es/rules/Azure.ACR.Usage/#recomendacion","title":"Recomendaci\u00f3n","text":"Considere eliminar las im\u00e1genes obsoletas e innecesarias para reducir el consumo de almacenamiento. Tambi\u00e9n considere actualizar a Premium SKU para registros b\u00e1sicos o est\u00e1ndar para aumentar el almacenamiento incluido.
","tags":["Azure.ACR.Usage","AZR-000001"]},{"location":"es/rules/Azure.ACR.Usage/#notas","title":"Notas","text":"Esta regla se aplica cuando se analizan los recursos implementados en Azure.
","tags":["Azure.ACR.Usage","AZR-000001"]},{"location":"es/rules/Azure.ACR.Usage/#enlaces","title":"Enlaces","text":"PSRule for Azure includes the following rules across five pillars of the Microsoft Azure Well-Architected Framework.
"},{"location":"es/rules/module/#cost-optimization","title":"Cost Optimization","text":""},{"location":"es/rules/module/#co03-cost-data-and-reporting","title":"CO:03 Cost data and reporting","text":"Name Synopsis Severity Level Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Error"},{"location":"es/rules/module/#co04-spending-guardrails","title":"CO:04 Spending guardrails","text":"Name Synopsis Severity Level Azure.DevBox.ProjectLimit Limit the number of Dev Boxes a single user can create for a project. Important Error"},{"location":"es/rules/module/#co05-rate-optimization","title":"CO:05 Rate optimization","text":"Name Synopsis Severity Level Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Error Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Error"},{"location":"es/rules/module/#co06-usage-and-billing-increments","title":"CO:06 Usage and billing increments","text":"Name Synopsis Severity Level Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. Critical Error Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Error"},{"location":"es/rules/module/#co07-component-costs","title":"CO:07 Component costs","text":"Name Synopsis Severity Level Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Error Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Error Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Error"},{"location":"es/rules/module/#co10-data-costs","title":"CO:10 Data costs","text":"Name Synopsis Severity Level Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Error"},{"location":"es/rules/module/#co13-personnel-time","title":"CO:13 Personnel time","text":"Name Synopsis Severity Level Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Error"},{"location":"es/rules/module/#co14-consolidation","title":"CO:14 Consolidation","text":"Name Synopsis Severity Level Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Error Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Error Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Error Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Error Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Error"},{"location":"es/rules/module/#operational-excellence","title":"Operational Excellence","text":""},{"location":"es/rules/module/#configuration","title":"Configuration","text":"Name Synopsis Severity Level Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Error Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Error Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Error"},{"location":"es/rules/module/#deployment","title":"Deployment","text":"Name Synopsis Severity Level Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Error Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Error Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Error Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Error Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Error Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Error Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Error Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Error Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Error"},{"location":"es/rules/module/#infrastructure-provisioning","title":"Infrastructure provisioning","text":"Name Synopsis Severity Level Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Error Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Error"},{"location":"es/rules/module/#instrumentation","title":"Instrumentation","text":"Name Synopsis Severity Level Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Warning"},{"location":"es/rules/module/#monitor","title":"Monitor","text":"Name Synopsis Severity Level Azure.VNET.PeerState VNET peering connections must be connected. Important Error"},{"location":"es/rules/module/#monitoring","title":"Monitoring","text":"Name Synopsis Severity Level Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Error Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Error Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Error Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Error Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Error Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Error Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Error"},{"location":"es/rules/module/#oe04-continuous-integration","title":"OE:04 Continuous integration","text":"Name Synopsis Severity Level Azure.ACR.Name Container registry names should meet naming requirements. Awareness Error Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Error Azure.APIM.Name API Management service names should meet naming requirements. Awareness Error Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Error Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Error Azure.Search.Name AI Search service names should meet naming requirements. Awareness Error Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Error Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Error Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Error Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Error"},{"location":"es/rules/module/#oe04-tools-and-processes","title":"OE:04 Tools and processes","text":"Name Synopsis Severity Level Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Warning"},{"location":"es/rules/module/#oe05-infrastructure-as-code","title":"OE:05 Infrastructure as code","text":"Name Synopsis Severity Level Azure.Template.TemplateFile Use ARM template files that are valid. Important Error Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Error"},{"location":"es/rules/module/#oe07-monitoring-system","title":"OE:07 Monitoring system","text":"Name Synopsis Severity Level Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Error Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Error"},{"location":"es/rules/module/#oe09-task-automation","title":"OE:09 Task automation","text":"Name Synopsis Severity Level Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Error"},{"location":"es/rules/module/#principles","title":"Principles","text":"Name Synopsis Severity Level Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Error"},{"location":"es/rules/module/#release-engineering","title":"Release engineering","text":"Name Synopsis Severity Level Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Error Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Error Azure.Template.LocationType Location parameters should use a string value. Important Error Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Error Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Error Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Error Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Error Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Error Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Error Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Warning Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Error Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Error"},{"location":"es/rules/module/#repeatable-infrastructure","title":"Repeatable infrastructure","text":"Name Synopsis Severity Level Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Error Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Error Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Error Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Error Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Important Error Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Error Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Error Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Error Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. Important Error Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Error Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Error Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Error Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Error Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Error Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Error Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Error Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Error Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Error Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Error Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Error Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Error Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Error Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Error Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Error Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Error Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Error Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Error Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Error Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Error Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Error Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Error Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Error Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Error Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Error Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Error Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Error Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. Important Error Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Error Azure.Route.Name Route table names should meet naming requirements. Awareness Error Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Error Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Error Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Error Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Error Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Error Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Error Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Error Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Error Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Error Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Error Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Error Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Error Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Error Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Information Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Information Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Error Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Error Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Error Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Important Error Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Error Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Error Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Error Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Error Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Error Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Error"},{"location":"es/rules/module/#tagging-and-resource-naming","title":"Tagging and resource naming","text":"Name Synopsis Severity Level Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Error"},{"location":"es/rules/module/#performance-efficiency","title":"Performance Efficiency","text":""},{"location":"es/rules/module/#application-capacity","title":"Application capacity","text":"Name Synopsis Severity Level Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Error Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Error Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Error"},{"location":"es/rules/module/#application-design","title":"Application design","text":"Name Synopsis Severity Level Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Error Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Error"},{"location":"es/rules/module/#application-scalability","title":"Application scalability","text":"Name Synopsis Severity Level Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Error Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Error"},{"location":"es/rules/module/#design-for-performance","title":"Design for performance","text":"Name Synopsis Severity Level Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Error"},{"location":"es/rules/module/#design-for-performance-efficiency","title":"Design for performance efficiency","text":"Name Synopsis Severity Level Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. Important Error"},{"location":"es/rules/module/#pe02-capacity-planning","title":"PE:02 Capacity planning","text":"Name Synopsis Severity Level Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Error"},{"location":"es/rules/module/#pe03-selecting-services","title":"PE:03 Selecting services","text":"Name Synopsis Severity Level Azure.Databricks.SKU Ensure Databricks workspaces are non-trial SKUs for production workloads. Critical Error"},{"location":"es/rules/module/#pe05-scaling-and-partitioning","title":"PE:05 Scaling and partitioning","text":"Name Synopsis Severity Level Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Error Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Error"},{"location":"es/rules/module/#pe08-data-performance","title":"PE:08 Data performance","text":"Name Synopsis Severity Level Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Error"},{"location":"es/rules/module/#performance","title":"Performance","text":"Name Synopsis Severity Level Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Error Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Error"},{"location":"es/rules/module/#performance-efficiency-checklist","title":"Performance efficiency checklist","text":"Name Synopsis Severity Level Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Warning Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Error"},{"location":"es/rules/module/#reliability","title":"Reliability","text":""},{"location":"es/rules/module/#application-design_1","title":"Application design","text":"Name Synopsis Severity Level Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Error"},{"location":"es/rules/module/#availability","title":"Availability","text":"Name Synopsis Severity Level Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Error Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Error"},{"location":"es/rules/module/#best-practices","title":"Best practices","text":"Name Synopsis Severity Level Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Error"},{"location":"es/rules/module/#data-management","title":"Data management","text":"Name Synopsis Severity Level Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Error Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important Error Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Error Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Error Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Error Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Error"},{"location":"es/rules/module/#design","title":"Design","text":"Name Synopsis Severity Level Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Error Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Error Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Error Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Error Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Error Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Error Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Error Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Error Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Error Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Error"},{"location":"es/rules/module/#health-modeling","title":"Health modeling","text":"Name Synopsis Severity Level Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Error Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Error Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Error"},{"location":"es/rules/module/#load-balancing-and-failover","title":"Load balancing and failover","text":"Name Synopsis Severity Level Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Error Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Error"},{"location":"es/rules/module/#re01-simplicity-and-efficiency","title":"RE:01 Simplicity and efficiency","text":"Name Synopsis Severity Level Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Error"},{"location":"es/rules/module/#re04-target-metrics","title":"RE:04 Target metrics","text":"Name Synopsis Severity Level Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Error Azure.AppService.WebProbe Configure and enable instance health probes. Important Error Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Error Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Error"},{"location":"es/rules/module/#re05-redundancy","title":"RE:05 Redundancy","text":"Name Synopsis Severity Level Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Error Azure.AKS.MinUserPoolNodes User node pools in an AKS cluster should have a minimum number of nodes for failover and updates. Important Error Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. Important Error Azure.LB.Probe Use a specific probe for web protocols. Important Error Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Warning Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Error Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Error Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Error"},{"location":"es/rules/module/#re05-regions-and-availability-zones","title":"RE:05 Regions and availability zones","text":"Name Synopsis Severity Level Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Error"},{"location":"es/rules/module/#re06-data-partitioning","title":"RE:06 Data partitioning","text":"Name Synopsis Severity Level Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Error Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Error"},{"location":"es/rules/module/#re07-self-preservation","title":"RE:07 Self-preservation","text":"Name Synopsis Severity Level Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Error Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Error"},{"location":"es/rules/module/#reliability-design-principles","title":"Reliability design principles","text":"Name Synopsis Severity Level Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Error"},{"location":"es/rules/module/#requirements","title":"Requirements","text":"Name Synopsis Severity Level Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Error Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Error Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Error Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Error Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Error Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Error Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Error Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Error Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important Error"},{"location":"es/rules/module/#resiliency-and-dependencies","title":"Resiliency and dependencies","text":"Name Synopsis Severity Level Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Error Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Error Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Error Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Error Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Error"},{"location":"es/rules/module/#resource-deployment","title":"Resource deployment","text":"Name Synopsis Severity Level Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Error"},{"location":"es/rules/module/#scalability","title":"Scalability","text":"Name Synopsis Severity Level Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Error"},{"location":"es/rules/module/#target-and-non-functional-requirements","title":"Target and non-functional requirements","text":"Name Synopsis Severity Level Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Error Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Error Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Error"},{"location":"es/rules/module/#security","title":"Security","text":""},{"location":"es/rules/module/#application-endpoints","title":"Application endpoints","text":"Name Synopsis Severity Level Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Error Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Error Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Error Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Error Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Error Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Error Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Error Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Error"},{"location":"es/rules/module/#authentication","title":"Authentication","text":"Name Synopsis Severity Level Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Error Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Error Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Error Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. Critical Error Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Error Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Error Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Error Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Error Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Error"},{"location":"es/rules/module/#authorization","title":"Authorization","text":"Name Synopsis Severity Level Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Error"},{"location":"es/rules/module/#azure-resources","title":"Azure resources","text":"Name Synopsis Severity Level Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Error Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Error Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Error Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Error"},{"location":"es/rules/module/#connectivity","title":"Connectivity","text":"Name Synopsis Severity Level Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). Critical Error Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. Critical Error Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Error Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Error Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Error"},{"location":"es/rules/module/#data-protection","title":"Data protection","text":"Name Synopsis Severity Level Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Error Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Error Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Error Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Error Azure.CDN.HTTP Enforce HTTPS for client connections. Important Error Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Error Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Error Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Error Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Error Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Error Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Error"},{"location":"es/rules/module/#design_1","title":"Design","text":"Name Synopsis Severity Level Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Error Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Error"},{"location":"es/rules/module/#encryption","title":"Encryption","text":"Name Synopsis Severity Level Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Error Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Error Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Error Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Error Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Error Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Error Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Error Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Error Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Error Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Error Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Error Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Error"},{"location":"es/rules/module/#identity-and-access-management","title":"Identity and access management","text":"Name Synopsis Severity Level Azure.ACR.AnonymousAccess Disable anonymous pull access. Important Error Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Error Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Error Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Error Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Error Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Error Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. Important Error Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Error Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Error Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Error Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Error Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Error Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Error Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Error Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Error Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Error Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Error Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Error Azure.VM.PublicKey Linux virtual machines should use public keys. Important Error Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Error"},{"location":"es/rules/module/#infrastructure-provisioning_1","title":"Infrastructure provisioning","text":"Name Synopsis Severity Level Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Error Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Error Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Error Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. Critical Error Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Error"},{"location":"es/rules/module/#key-and-secret-management","title":"Key and secret management","text":"Name Synopsis Severity Level Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Error Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Error Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Error"},{"location":"es/rules/module/#monitor_1","title":"Monitor","text":"Name Synopsis Severity Level Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Error Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Error Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Error"},{"location":"es/rules/module/#network-security-and-containment","title":"Network security and containment","text":"Name Synopsis Severity Level Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Error Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Error Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Error Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Error Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Error Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Error Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.AppGwWAF.RuleGroups Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Error Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Error Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Error Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Error Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Error Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Error Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Error Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Error Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error"},{"location":"es/rules/module/#network-segmentation","title":"Network segmentation","text":"Name Synopsis Severity Level Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Error Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Error"},{"location":"es/rules/module/#review-and-remediate","title":"Review and remediate","text":"Name Synopsis Severity Level Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Error"},{"location":"es/rules/module/#se01-security-baseline","title":"SE:01 Security baseline","text":"Name Synopsis Severity Level Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Error"},{"location":"es/rules/module/#se02-secured-development-lifecycle","title":"SE:02 Secured development lifecycle","text":"Name Synopsis Severity Level Azure.AppService.NETVersion Configure applications to use newer .NET versions. Important Error Azure.AppService.PHPVersion Configure applications to use newer PHP runtime versions. Important Error"},{"location":"es/rules/module/#se04-segmentation","title":"SE:04 Segmentation","text":"Name Synopsis Severity Level Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Error"},{"location":"es/rules/module/#se05-identity-and-access-management","title":"SE:05 Identity and access management","text":"Name Synopsis Severity Level Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Error Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Error Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Error Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Error Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.APIM.ProductApproval Configure products to require approval. Important Error Azure.APIM.ProductSubscription Configure products to require a subscription. Important Error Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Error Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Error Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Error Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Error Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Error Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Warning Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Error Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Error Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Error Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Error Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Error"},{"location":"es/rules/module/#se06-network-controls","title":"SE:06 Network controls","text":"Name Synopsis Severity Level Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Error Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Error Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Error Azure.Databricks.PublicAccess Azure Databricks workspaces should disable public network access. Critical Error Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. Critical Error Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Error Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Error Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Error"},{"location":"es/rules/module/#se07-encryption","title":"SE:07 Encryption","text":"Name Synopsis Severity Level Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Error Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Error Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Error Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Error Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Error Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Error Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Error Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Error Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Error Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Error Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Error Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Error Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Error"},{"location":"es/rules/module/#se08-hardening-resources","title":"SE:08 Hardening resources","text":"Name Synopsis Severity Level Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Error Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Error"},{"location":"es/rules/module/#se10-monitoring-and-threat-detection","title":"SE:10 Monitoring and threat detection","text":"Name Synopsis Severity Level Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. Critical Error Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Error Azure.Defender.Api Enable Microsoft Defender for APIs. Critical Error Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Error Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Error Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Error Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. Important Error Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Error Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Error Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Error Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Error"},{"location":"es/rules/module/#secrets","title":"Secrets","text":"Name Synopsis Severity Level Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Error Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Error"},{"location":"es/rules/module/#security-design-principles","title":"Security design principles","text":"Name Synopsis Severity Level Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Error Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Error"},{"location":"es/rules/module/#security-operations","title":"Security operations","text":"Name Synopsis Severity Level Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Important Error Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Error Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Error Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Error Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Error Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Error Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Error Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Error Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Error Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Error Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Error Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Error Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Error Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Error Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Error Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Error Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Error"},{"location":"es/rules/module/#virtual-machine","title":"Virtual Machine","text":"Name Synopsis Severity Level Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Error"},{"location":"es/rules/resource/","title":"Rules by resource type","text":"PSRule for Azure includes the following rules organized by resource type.
"},{"location":"es/rules/resource/#ai-search","title":"AI Search","text":"Name Synopsis Severity Level Azure.Search.IndexSLA Use a minimum of 3 replicas to receive an SLA for query and index updates. Important Error Azure.Search.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.Search.Name AI Search service names should meet naming requirements. Awareness Error Azure.Search.QuerySLA Use a minimum of 2 replicas to receive an SLA for index queries. Important Error Azure.Search.SKU Use the basic and standard tiers for entry level workloads. Critical Error"},{"location":"es/rules/resource/#all-resources","title":"All resources","text":"Name Synopsis Severity Level Azure.Resource.AllowedRegions Resources should be deployed to allowed regions. Important Error Azure.Resource.UseTags Azure resources should be tagged using a standard convention. Awareness Error Azure.Template.DebugDeployment Use default deployment detail level for nested deployments. Awareness Error Azure.Template.DefineParameters Each Azure Resource Manager (ARM) template file should contain a minimal number of parameters. Awareness Error Azure.Template.ExpressionLength Template expressions should not exceed the maximum length. Awareness Error Azure.Template.LocationDefault Set the default value for the location parameter within an ARM template to resource group location. Awareness Error Azure.Template.LocationType Location parameters should use a string value. Important Error Azure.Template.MetadataLink Configure a metadata link for each parameter file. Important Error Azure.Template.ParameterDataTypes Set the parameter default value to a value of the same type. Important Error Azure.Template.ParameterFile Use ARM template parameter files that are valid. Important Error Azure.Template.ParameterMetadata Set metadata descriptions in Azure Resource Manager (ARM) template for each parameter. Awareness Error Azure.Template.ParameterMinMaxValue Template parameters minValue and maxValue constraints must be valid. Important Error Azure.Template.ParameterScheme Use an Azure template parameter file schema with the https scheme. Awareness Error Azure.Template.ParameterStrongType Set the parameter value to a value that matches the specified strong type. Awareness Error Azure.Template.ParameterValue Specify a value for each parameter in template parameter files. Awareness Error Azure.Template.ResourceLocation Template resource location should be an expression or global. Awareness Error Azure.Template.Resources Each Azure Resource Manager (ARM) template file should deploy at least one resource. Awareness Error Azure.Template.TemplateFile Use ARM template files that are valid. Important Error Azure.Template.TemplateSchema Use a more recent version of the Azure template schema. Awareness Error Azure.Template.TemplateScheme Use an Azure template file schema with the https scheme. Awareness Error Azure.Template.UseComments Use comments for each resource in ARM template to communicate purpose. Awareness Information Azure.Template.UseDescriptions Use descriptions for each resource in generated template(bicep, psarm, AzOps) to communicate purpose. Awareness Information Azure.Template.UseLocationParameter Template should reference a location parameter to specify resource location. Awareness Warning Azure.Template.UseParameters Each Azure Resource Manager (ARM) template parameter should be used or removed from template files. Awareness Error Azure.Template.UseVariables Each Azure Resource Manager (ARM) template variable should be used or removed from template files. Awareness Error Azure.Template.ValidSecretRef Use a valid secret reference within parameter files. Awareness Error"},{"location":"es/rules/resource/#api-management","title":"API Management","text":"Name Synopsis Severity Level Azure.APIM.APIDescriptors API Management APIs should have a display name and description. Awareness Warning Azure.APIM.AvailabilityZone API management services deployed with Premium SKU should use availability zones in supported regions for high availability. Important Error Azure.APIM.CertificateExpiry Renew certificates used for custom domain bindings. Important Error Azure.APIM.Ciphers API Management should not accept weak or deprecated ciphers for client or backend communication. Critical Error Azure.APIM.CORSPolicy Avoid using wildcard for any configuration option in CORS policies. Important Error Azure.APIM.DefenderCloud APIs published in Azure API Management should be onboarded to Microsoft Defender for APIs. Critical Error Azure.APIM.EncryptValues Encrypt all API Management named values with Key Vault secrets. Important Error Azure.APIM.HTTPBackend Use HTTPS for communication to backend services. Critical Error Azure.APIM.HTTPEndpoint Enforce HTTPS for communication to API clients. Important Error Azure.APIM.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.APIM.MinAPIVersion API Management instances should limit control plane API calls to API Management with version '2021-08-01' or newer. Important Error Azure.APIM.MultiRegion API Management instances should use multi-region deployment to improve service availability. Important Error Azure.APIM.MultiRegionGateway API Management instances should have multi-region deployment gateways enabled. Important Error Azure.APIM.Name API Management service names should meet naming requirements. Awareness Error Azure.APIM.PolicyBase Base element for any policy element in a section should be configured. Important Error Azure.APIM.ProductApproval Configure products to require approval. Important Error Azure.APIM.ProductDescriptors API Management products should have a display name and description. Awareness Warning Azure.APIM.ProductSubscription Configure products to require a subscription. Important Error Azure.APIM.ProductTerms Set legal terms for each product registered in API Management. Important Error Azure.APIM.Protocols API Management should only accept a minimum of TLS 1.2 for client and backend communication. Critical Error Azure.APIM.SampleProducts Remove starter and unlimited sample products. Awareness Error"},{"location":"es/rules/resource/#app-configuration","title":"App Configuration","text":"Name Synopsis Severity Level Azure.AppConfig.AuditLogs Ensure app configuration store audit diagnostic logs are enabled. Important Error Azure.AppConfig.DisableLocalAuth Authenticate App Configuration clients with Entra ID identities. Important Error Azure.AppConfig.GeoReplica Replicate app configuration store across all points of presence for an application. Important Error Azure.AppConfig.Name App Configuration store names should meet naming requirements. Awareness Error Azure.AppConfig.PurgeProtect Consider purge protection for app configuration store to ensure store cannot be purged in the retention period. Important Error Azure.AppConfig.SKU App Configuration should use a minimum size of Standard. Important Error"},{"location":"es/rules/resource/#app-service","title":"App Service","text":"Name Synopsis Severity Level Azure.AppService.AlwaysOn Configure Always On for App Service apps. Important Error Azure.AppService.ARRAffinity Disable client affinity for stateless services. Awareness Error Azure.AppService.HTTP2 Use HTTP/2 instead of HTTP/1.x to improve protocol efficiency. Awareness Error Azure.AppService.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.AppService.MinPlan Use at least a Standard App Service Plan. Important Error Azure.AppService.MinTLS App Service should reject TLS versions older than 1.2. Critical Error Azure.AppService.NETVersion Configure applications to use newer .NET versions. Important Error Azure.AppService.PHPVersion Configure applications to use newer PHP runtime versions. Important Error Azure.AppService.PlanInstanceCount App Service Plan should use a minimum number of instances for failover. Important Error Azure.AppService.RemoteDebug Disable remote debugging on App Service apps when not in use. Important Error Azure.AppService.UseHTTPS Azure App Service apps should only accept encrypted connections. Important Error Azure.AppService.WebProbe Configure and enable instance health probes. Important Error Azure.AppService.WebProbePath Configure a dedicated path for health probe requests. Important Error Azure.AppService.WebSecureFtp Web apps should disable insecure FTP and configure SFTP when required. Important Error"},{"location":"es/rules/resource/#app-service-environment","title":"App Service Environment","text":"Name Synopsis Severity Level Azure.ASE.MigrateV3 Use ASEv3 as replacement for the classic app service environment versions ASEv1 and ASEv2. Important Error"},{"location":"es/rules/resource/#application-gateway","title":"Application Gateway","text":"Name Synopsis Severity Level Azure.AppGw.AvailabilityZone Application gateways should use availability zones in supported regions for high availability. Important Error Azure.AppGw.MigrateV2 Use a Application Gateway v2 SKU. Important Error Azure.AppGw.MinInstance Application Gateways should use a minimum of two instances. Important Error Azure.AppGw.MinSku Application Gateway should use a minimum instance size of Medium. Important Error Azure.AppGw.Name Application Gateways should meet naming requirements. Awareness Error Azure.AppGw.OWASP Application Gateway Web Application Firewall (WAF) should use OWASP 3.x rules. Important Error Azure.AppGw.Prevention Internet exposed Application Gateways should use prevention mode to protect backend resources. Critical Error Azure.AppGw.SSLPolicy Application Gateway should only accept a minimum of TLS 1.2. Critical Error Azure.AppGw.UseHTTPS Application Gateways should only expose frontend HTTP endpoints over HTTPS. Critical Error Azure.AppGw.UseWAF Internet accessible Application Gateways should use protect endpoints with WAF. Critical Error Azure.AppGw.WAFEnabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Error Azure.AppGw.WAFRules Application Gateway Web Application Firewall (WAF) should have all rules enabled. Important Error Azure.AppGwWAF.Enabled Application Gateway Web Application Firewall (WAF) must be enabled to protect backend resources. Critical Error Azure.AppGwWAF.Exclusions Application Gateway Web Application Firewall (WAF) should have all rules enabled. Critical Error Azure.AppGwWAF.PreventionMode Use protection mode in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.AppGwWAF.RuleGroups Use recommended rule groups in Application Gateway Web Application Firewall (WAF) policies to protect back end resources. Critical Error"},{"location":"es/rules/resource/#application-insights","title":"Application Insights","text":"Name Synopsis Severity Level Azure.AppInsights.Name Azure Application Insights resources names should meet naming requirements. Awareness Error Azure.AppInsights.Workspace Configure Application Insights resources to store data in workspaces. Important Error"},{"location":"es/rules/resource/#application-security-group","title":"Application Security Group","text":"Name Synopsis Severity Level Azure.ASG.Name Application Security Group (ASG) names should meet naming requirements. Awareness Error"},{"location":"es/rules/resource/#arc","title":"Arc","text":"Name Synopsis Severity Level Azure.Arc.Kubernetes.Defender Deploy Microsoft Defender for Containers extension for Arc-enabled Kubernetes clusters. Important Error Azure.Arc.Server.MaintenanceConfig Use a maintenance configuration for Arc-enabled servers. Important Error"},{"location":"es/rules/resource/#automation-account","title":"Automation Account","text":"Name Synopsis Severity Level Azure.Automation.AuditLogs Ensure automation account audit diagnostic logs are enabled. Important Error Azure.Automation.EncryptVariables Azure Automation variables should be encrypted. Important Error Azure.Automation.ManagedIdentity Ensure Managed Identity is used for authentication. Important Error Azure.Automation.PlatformLogs Ensure automation account platform diagnostic logs are enabled. Important Error Azure.Automation.WebHookExpiry Do not create webhooks with an expiry time greater than 1 year (default). Awareness Error"},{"location":"es/rules/resource/#azure-ai","title":"Azure AI","text":"Name Synopsis Severity Level Azure.AI.DisableLocalAuth Authenticate requests to Azure AI services with Entra ID identities. Important Error Azure.AI.ManagedIdentity Configure managed identities to access Azure resources. Important Error Azure.AI.PrivateEndpoints Use Private Endpoints to access Azure AI services accounts. Important Error Azure.AI.PublicAccess Restrict access of Azure AI services to authorized virtual networks. Important Error"},{"location":"es/rules/resource/#azure-cache-for-redis","title":"Azure Cache for Redis","text":"Name Synopsis Severity Level Azure.Redis.AvailabilityZone Premium Redis cache should be deployed with availability zones for high availability. Important Error Azure.Redis.FirewallIPRange Determine if there is an excessive number of permitted IP addresses for the Redis cache. Critical Error Azure.Redis.FirewallRuleCount Determine if there is an excessive number of firewall rules for the Redis cache. Awareness Error Azure.Redis.MaxMemoryReserved Configure maxmemory-reserved to reserve memory for non-cache operations. Important Error Azure.Redis.MinSKU Use Azure Cache for Redis instances of at least Standard C1. Important Error Azure.Redis.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Error Azure.Redis.NonSslPort Azure Cache for Redis should only accept secure connections. Critical Error Azure.Redis.PublicNetworkAccess Redis cache should disable public network access. Critical Error Azure.Redis.Version Azure Cache for Redis should use the latest supported version of Redis. Important Error"},{"location":"es/rules/resource/#azure-cache-for-redis-enterprise","title":"Azure Cache for Redis Enterprise","text":"Name Synopsis Severity Level Azure.RedisEnterprise.MinTLS Redis Cache should reject TLS versions older than 1.2. Critical Error Azure.RedisEnterprise.Zones Enterprise Redis cache should be zone-redundant for high availability. Important Error"},{"location":"es/rules/resource/#azure-database-for-mariadb","title":"Azure Database for MariaDB","text":"Name Synopsis Severity Level Azure.MariaDB.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.MariaDB.DatabaseName Azure Database for MariaDB databases should meet naming requirements. Awareness Error Azure.MariaDB.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MariaDB. Important Error Azure.MariaDB.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.MariaDB.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.MariaDB.FirewallRuleName Azure Database for MariaDB firewall rules should meet naming requirements. Awareness Error Azure.MariaDB.GeoRedundantBackup Azure Database for MariaDB should store backups in a geo-redundant storage. Important Error Azure.MariaDB.MinTLS Azure Database for MariaDB servers should reject TLS versions older than 1.2. Critical Error Azure.MariaDB.ServerName Azure Database for MariaDB servers should meet naming requirements. Awareness Error Azure.MariaDB.UseSSL Azure Database for MariaDB servers should only accept encrypted connections. Critical Error Azure.MariaDB.VNETRuleName Azure Database for MariaDB VNET rules should meet naming requirements. Awareness Error"},{"location":"es/rules/resource/#azure-database-for-mysql","title":"Azure Database for MySQL","text":"Name Synopsis Severity Level Azure.MySQL.AAD Use Azure Active Directory (AAD) authentication with Azure Database for MySQL databases. Critical Error Azure.MySQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for MySQL databases. Important Error Azure.MySQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.MySQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for MySQL. Important Error Azure.MySQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.MySQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.MySQL.GeoRedundantBackup Azure Database for MySQL should store backups in a geo-redundant storage. Important Error Azure.MySQL.MinTLS MySQL DB servers should reject TLS versions older than 1.2. Critical Error Azure.MySQL.ServerName Azure MySQL DB server names should meet naming requirements. Awareness Error Azure.MySQL.UseFlexible Use Azure Database for MySQL Flexible Server deployment model. Important Warning Azure.MySQL.UseSSL Enforce encrypted MySQL connections. Critical Error"},{"location":"es/rules/resource/#azure-database-for-postgresql","title":"Azure Database for PostgreSQL","text":"Name Synopsis Severity Level Azure.PostgreSQL.AAD Use Entra ID authentication with Azure Database for PostgreSQL databases. Critical Error Azure.PostgreSQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure Database for PostgreSQL databases. Important Error Azure.PostgreSQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.PostgreSQL.DefenderCloud Enable Microsoft Defender for Cloud for Azure Database for PostgreSQL. Important Error Azure.PostgreSQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses. Important Error Azure.PostgreSQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.PostgreSQL.GeoRedundantBackup Azure Database for PostgreSQL should store backups in a geo-redundant storage. Important Error Azure.PostgreSQL.MinTLS PostgreSQL DB servers should reject TLS versions older than 1.2. Critical Error Azure.PostgreSQL.ServerName Azure PostgreSQL DB server names should meet naming requirements. Awareness Error Azure.PostgreSQL.UseSSL Enforce encrypted PostgreSQL connections. Critical Error"},{"location":"es/rules/resource/#azure-kubernetes-service","title":"Azure Kubernetes Service","text":"Name Synopsis Severity Level Azure.AKS.AuditLogs AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads. Important Error Azure.AKS.AuthorizedIPs Restrict access to API server endpoints to authorized IP addresses. Important Error Azure.AKS.AutoScaling Use autoscaling to scale clusters based on workload requirements. Important Error Azure.AKS.AutoUpgrade Configure AKS to automatically upgrade to newer supported AKS versions as they are made available. Important Error Azure.AKS.AvailabilityZone AKS clusters deployed with virtual machine scale sets should use availability zones in supported regions for high availability. Important Error Azure.AKS.AzurePolicyAddOn Configure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes. Important Error Azure.AKS.AzureRBAC Use Azure RBAC for Kubernetes Authorization with AKS clusters. Important Error Azure.AKS.CNISubnetSize AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues. Important Error Azure.AKS.ContainerInsights Enable Container insights to monitor AKS cluster workloads. Important Error Azure.AKS.DefenderProfile Enable the Defender profile with Azure Kubernetes Service (AKS) cluster. Important Error Azure.AKS.DNSPrefix Azure Kubernetes Service (AKS) cluster DNS prefix should meet naming requirements. Awareness Error Azure.AKS.EphemeralOSDisk AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades. Important Warning Azure.AKS.HttpAppRouting Disable HTTP application routing add-on in AKS clusters. Important Error Azure.AKS.LocalAccounts Enforce named user accounts with RBAC assigned permissions. Important Error Azure.AKS.ManagedAAD Use AKS-managed Azure AD to simplify authorization and improve security. Important Error Azure.AKS.ManagedIdentity Configure AKS clusters to use managed identities for managing cluster infrastructure. Important Error Azure.AKS.MinNodeCount AKS clusters should have minimum number of system nodes for failover and updates. Important Error Azure.AKS.MinUserPoolNodes User node pools in an AKS cluster should have a minimum number of nodes for failover and updates. Important Error Azure.AKS.Name Azure Kubernetes Service (AKS) cluster names should meet naming requirements. Awareness Error Azure.AKS.NetworkPolicy Deploy AKS clusters with Network Policies enabled. Important Error Azure.AKS.NodeMinPods Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods. Important Error Azure.AKS.PlatformLogs AKS clusters should collect platform diagnostic logs to monitor the state of workloads. Important Error Azure.AKS.PoolScaleSet Deploy AKS clusters with nodes pools based on VM scale sets. Important Error Azure.AKS.PoolVersion AKS node pools should match Kubernetes control plane version. Important Error Azure.AKS.SecretStore Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault. Important Error Azure.AKS.SecretStoreRotation Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters. Important Error Azure.AKS.StandardLB Azure Kubernetes Clusters (AKS) should use a Standard load balancer SKU. Important Error Azure.AKS.UptimeSLA AKS clusters should have Uptime SLA enabled for a financially backed SLA. Important Error Azure.AKS.UseRBAC Deploy AKS cluster with role-based access control (RBAC) enabled. Important Error Azure.AKS.Version AKS control plane and nodes pools should use a current stable release. Important Error"},{"location":"es/rules/resource/#backup-vault","title":"Backup Vault","text":"Name Synopsis Severity Level Azure.BV.Immutable Ensure immutability is configured to protect backup data. Important Error"},{"location":"es/rules/resource/#bastion","title":"Bastion","text":"Name Synopsis Severity Level Azure.Bastion.Name Bastion hosts should meet naming requirements. Awareness Error"},{"location":"es/rules/resource/#container-app","title":"Container App","text":"Name Synopsis Severity Level Azure.ContainerApp.APIVersion Migrate from retired API version to a supported version. Important Error Azure.ContainerApp.DisableAffinity Disable session affinity to prevent unbalanced distribution. Important Error Azure.ContainerApp.ExternalIngress Limit inbound communication for Container Apps is limited to callers within the Container Apps Environment. Important Error Azure.ContainerApp.Insecure Ensure insecure inbound traffic is not permitted to the container app. Important Error Azure.ContainerApp.ManagedIdentity Ensure managed identity is used for authentication. Important Error Azure.ContainerApp.Name Container Apps should meet naming requirements. Awareness Error Azure.ContainerApp.PublicAccess Ensure public network access for Container Apps environment is disabled. Important Error Azure.ContainerApp.RestrictIngress IP ingress restrictions mode should be set to allow action for all rules defined. Important Error Azure.ContainerApp.Storage Use of Azure Files volume mounts to persistent storage container data. Awareness Error"},{"location":"es/rules/resource/#container-registry","title":"Container Registry","text":"Name Synopsis Severity Level Azure.ACR.AdminUser Use Entra ID identities instead of using the registry admin user. Critical Error Azure.ACR.AnonymousAccess Disable anonymous pull access. Important Error Azure.ACR.ContainerScan Enable vulnerability scanning for container images. Critical Error Azure.ACR.ContentTrust Use container images signed by a trusted image publisher. Important Error Azure.ACR.Firewall Limit network access of container registries to only trusted clients. Important Error Azure.ACR.GeoReplica Use geo-replicated container registries to compliment a multi-region container deployments. Important Error Azure.ACR.ImageHealth Remove container images with known vulnerabilities. Critical Error Azure.ACR.MinSku ACR should use the Premium or Standard SKU for production deployments. Important Error Azure.ACR.Name Container registry names should meet naming requirements. Awareness Error Azure.ACR.Quarantine Enable container image quarantine, scan, and mark images as verified. Important Error Azure.ACR.Retention Use a retention policy to cleanup untagged manifests. Important Error Azure.ACR.SoftDelete Azure Container Registries should have soft delete policy enabled. Important Error Azure.ACR.Usage Regularly remove deprecated and unneeded images to reduce storage usage. Important Error"},{"location":"es/rules/resource/#content-delivery-network","title":"Content Delivery Network","text":"Name Synopsis Severity Level Azure.CDN.EndpointName Azure CDN Endpoint names should meet naming requirements. Awareness Error Azure.CDN.HTTP Enforce HTTPS for client connections. Important Error Azure.CDN.MinTLS Azure CDN endpoints should reject TLS versions older than 1.2. Important Error"},{"location":"es/rules/resource/#cosmos-db","title":"Cosmos DB","text":"Name Synopsis Severity Level Azure.Cosmos.AccountName Cosmos DB account names should meet naming requirements. Awareness Error Azure.Cosmos.DefenderCloud Enable Microsoft Defender for Azure Cosmos DB. Critical Error Azure.Cosmos.DisableMetadataWrite Use Azure AD identities for management place operations in Azure Cosmos DB. Important Error"},{"location":"es/rules/resource/#data-explorer","title":"Data Explorer","text":"Name Synopsis Severity Level Azure.ADX.DiskEncryption Use disk encryption for Azure Data Explorer (ADX) clusters. Important Error Azure.ADX.ManagedIdentity Configure Data Explorer clusters to use managed identities to access Azure resources securely. Important Error Azure.ADX.SLA Use SKUs that include an SLA when configuring Azure Data Explorer (ADX) clusters. Important Error Azure.ADX.Usage Regularly remove unused resources to reduce costs. Important Error"},{"location":"es/rules/resource/#data-factory","title":"Data Factory","text":"Name Synopsis Severity Level Azure.DataFactory.Version Consider migrating to DataFactory v2. Awareness Error"},{"location":"es/rules/resource/#databricks","title":"Databricks","text":"Name Synopsis Severity Level Azure.Databricks.PublicAccess Azure Databricks workspaces should disable public network access. Critical Error Azure.Databricks.SecureConnectivity Use Databricks workspaces configured for secure cluster connectivity. Critical Error Azure.Databricks.SKU Ensure Databricks workspaces are non-trial SKUs for production workloads. Critical Error"},{"location":"es/rules/resource/#deployment","title":"Deployment","text":"Name Synopsis Severity Level Azure.Deployment.AdminUsername Use secure parameters for sensitive resource properties. Awareness Error Azure.Deployment.Name Nested deployments should meet naming requirements of deployments. Awareness Error Azure.Deployment.OuterSecret Do not use Outer deployments when references SecureString or SecureObject parameters. Critical Error Azure.Deployment.OutputSecretValue Avoid outputting sensitive deployment values. Critical Error Azure.Deployment.SecureParameter Use secure parameters for any parameter that contains sensitive information. Critical Error Azure.Deployment.SecureValue Use secure parameters for setting properties of resources that contain sensitive information. Critical Error"},{"location":"es/rules/resource/#dev-box","title":"Dev Box","text":"Name Synopsis Severity Level Azure.DevBox.ProjectLimit Limit the number of Dev Boxes a single user can create for a project. Important Error"},{"location":"es/rules/resource/#event-grid","title":"Event Grid","text":"Name Synopsis Severity Level Azure.EventGrid.DisableLocalAuth Authenticate publishing clients with Azure AD identities. Important Error Azure.EventGrid.ManagedIdentity Use managed identities to deliver Event Grid Topic events. Important Error Azure.EventGrid.TopicPublicAccess Use Private Endpoints to access Event Grid topics and domains. Important Error"},{"location":"es/rules/resource/#event-hub","title":"Event Hub","text":"Name Synopsis Severity Level Azure.EventHub.DisableLocalAuth Authenticate Event Hub publishers and consumers with Entra ID identities. Important Error Azure.EventHub.MinTLS Event Hub namespaces should reject TLS versions older than 1.2. Critical Error Azure.EventHub.Usage Regularly remove unused resources to reduce costs. Important Error"},{"location":"es/rules/resource/#firewall","title":"Firewall","text":"Name Synopsis Severity Level Azure.Firewall.Mode Deny high confidence malicious IP addresses and domains on classic managed Azure Firewalls. Critical Error Azure.Firewall.Name Firewall names should meet naming requirements. Awareness Error Azure.Firewall.PolicyMode Deny high confidence malicious IP addresses, domains and URLs. Critical Error Azure.Firewall.PolicyName Firewall policy names should meet naming requirements. Awareness Error"},{"location":"es/rules/resource/#front-door","title":"Front Door","text":"Name Synopsis Severity Level Azure.CDN.UseFrontDoor Use Azure Front Door Standard or Premium SKU to improve the performance of web pages with dynamic content and overall capabilities. Important Error Azure.FrontDoor.Logs Audit and monitor access through Azure Front Door profiles. Important Error Azure.FrontDoor.ManagedIdentity Ensure Front Door uses a managed identity to authorize access to Azure resources. Important Error Azure.FrontDoor.MinTLS Front Door Classic instances should reject TLS versions older than 1.2. Critical Error Azure.FrontDoor.Name Front Door names should meet naming requirements. Awareness Error Azure.FrontDoor.Probe Use health probes to check the health of each backend. Important Error Azure.FrontDoor.ProbeMethod Configure health probes to use HEAD requests to reduce performance overhead. Important Error Azure.FrontDoor.ProbePath Configure a dedicated path for health probe requests. Important Error Azure.FrontDoor.State Enable Azure Front Door Classic instance. Important Error Azure.FrontDoor.UseCaching Use caching to reduce retrieving contents from origins. Important Error Azure.FrontDoor.UseWAF Enable Web Application Firewall (WAF) policies on each Front Door endpoint. Critical Error Azure.FrontDoor.WAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Error Azure.FrontDoor.WAF.Mode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.FrontDoor.WAF.Name Front Door WAF policy names should meet naming requirements. Awareness Error Azure.FrontDoorWAF.Enabled Front Door Web Application Firewall (WAF) policy must be enabled to protect back end resources. Critical Error Azure.FrontDoorWAF.Exclusions Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions. Critical Error Azure.FrontDoorWAF.PreventionMode Use protection mode in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error Azure.FrontDoorWAF.RuleGroups Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Critical Error"},{"location":"es/rules/resource/#iot-hub","title":"IoT Hub","text":"Name Synopsis Severity Level Azure.IoTHub.MinTLS IoT Hubs should reject TLS versions older than 1.2. Critical Error"},{"location":"es/rules/resource/#key-vault","title":"Key Vault","text":"Name Synopsis Severity Level Azure.KeyVault.AccessPolicy Use the principal of least privilege when assigning access to Key Vault. Important Error Azure.KeyVault.AutoRotationPolicy Key Vault keys should have auto-rotation enabled. Important Error Azure.KeyVault.Firewall Key Vault should only accept explicitly allowed traffic. Important Error Azure.KeyVault.KeyName Key Vault Key names should meet naming requirements. Awareness Error Azure.KeyVault.Logs Ensure audit diagnostics logs are enabled to audit Key Vault access. Important Error Azure.KeyVault.Name Key Vault names should meet naming requirements. Awareness Error Azure.KeyVault.PurgeProtect Enable Purge Protection on Key Vaults to prevent early purge of vaults and vault items. Important Error Azure.KeyVault.RBAC Key Vaults should use Azure RBAC as the authorization system for the data plane. Awareness Warning Azure.KeyVault.SecretName Key Vault Secret names should meet naming requirements. Awareness Error Azure.KeyVault.SoftDelete Enable Soft Delete on Key Vaults to protect vaults and vault items from accidental deletion. Important Error"},{"location":"es/rules/resource/#load-balancer","title":"Load Balancer","text":"Name Synopsis Severity Level Azure.LB.AvailabilityZone Load balancers deployed with Standard SKU should be zone-redundant for high availability. Important Error Azure.LB.Name Load Balancer names should meet naming requirements. Awareness Error Azure.LB.Probe Use a specific probe for web protocols. Important Error Azure.LB.StandardSKU Load balancers should be deployed with Standard SKU for production workloads. Important Error"},{"location":"es/rules/resource/#logic-app","title":"Logic App","text":"Name Synopsis Severity Level Azure.LogicApp.LimitHTTPTrigger Limit HTTP request trigger access to trusted IP addresses. Critical Error"},{"location":"es/rules/resource/#machine-learning","title":"Machine Learning","text":"Name Synopsis Severity Level Azure.ML.ComputeIdleShutdown Configure an idle shutdown timeout for Machine Learning compute instances. Critical Error Azure.ML.ComputeVnet Azure Machine Learning Computes should be hosted in a virtual network (VNet). Critical Error Azure.ML.DisableLocalAuth Azure Machine Learning compute resources should have local authentication methods disabled. Critical Error Azure.ML.PublicAccess Disable public network access from a Azure Machine Learning workspace. Critical Error Azure.ML.UserManagedIdentity ML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity. Important Error"},{"location":"es/rules/resource/#microsoft-defender-for-cloud","title":"Microsoft Defender for Cloud","text":"Name Synopsis Severity Level Azure.Defender.Api Enable Microsoft Defender for APIs. Critical Error Azure.Defender.AppServices Enable Microsoft Defender for App Service. Critical Error Azure.Defender.Arm Enable Microsoft Defender for Azure Resource Manager (ARM). Critical Error Azure.Defender.Containers Enable Microsoft Defender for Containers. Critical Error Azure.Defender.CosmosDb Enable Microsoft Defender for Azure Cosmos DB. Critical Error Azure.Defender.Cspm Enable Microsoft Defender Cloud Security Posture Management Standard plan. Critical Error Azure.Defender.Dns Enable Microsoft Defender for DNS. Critical Error Azure.Defender.KeyVault Enable Microsoft Defender for Key Vault. Critical Error Azure.Defender.OssRdb Enable Microsoft Defender for open-source relational databases. Critical Error Azure.Defender.Servers Enable Microsoft Defender for Servers. Critical Error Azure.Defender.SQL Enable Microsoft Defender for SQL servers. Critical Error Azure.Defender.SQLOnVM Enable Microsoft Defender for SQL servers on machines. Critical Error Azure.Defender.Storage Enable Microsoft Defender for Storage. Critical Error Azure.Defender.Storage.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Error Azure.Defender.Storage.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Error Azure.DefenderCloud.Contact Microsoft Defender for Cloud email and phone contact details should be set. Important Error Azure.DefenderCloud.Provisioning Enable auto-provisioning on to improve Microsoft Defender for Cloud insights. Important Error"},{"location":"es/rules/resource/#monitor","title":"Monitor","text":"Name Synopsis Severity Level Azure.Monitor.ServiceHealth Configure Service Health alerts to notify administrators. Important Error"},{"location":"es/rules/resource/#network-interface","title":"Network Interface","text":"Name Synopsis Severity Level Azure.NIC.Attached Network interfaces (NICs) that are not used should be removed. Awareness Error Azure.NIC.Name Network Interface (NIC) names should meet naming requirements. Awareness Error Azure.NIC.UniqueDns Network interfaces (NICs) should inherit DNS from virtual networks. Awareness Error"},{"location":"es/rules/resource/#network-security-group","title":"Network Security Group","text":"Name Synopsis Severity Level Azure.NSG.AKSRules AKS Network Security Group (NSG) should not have custom rules. Awareness Error Azure.NSG.AnyInboundSource Network security groups (NSGs) should avoid rules that allow \"any\" as an inbound source. Critical Error Azure.NSG.Associated Network Security Groups (NSGs) should be associated to a subnet or network interface. Awareness Error Azure.NSG.DenyAllInbound Avoid denying all inbound traffic. Important Error Azure.NSG.LateralTraversal Deny outbound management connections from non-management hosts. Important Error Azure.NSG.Name Network Security Group (NSG) names should meet naming requirements. Awareness Error"},{"location":"es/rules/resource/#policy","title":"Policy","text":"Name Synopsis Severity Level Azure.Policy.AssignmentAssignedBy Policy assignments should use assignedBy metadata. Awareness Error Azure.Policy.AssignmentDescriptors Policy assignments should use a display name and description. Awareness Error Azure.Policy.Descriptors Policy and initiative definitions should use a display name, description, and category. Awareness Error Azure.Policy.ExemptionDescriptors Policy exemptions should use a display name and description. Awareness Error Azure.Policy.WaiverExpiry Configure policy waiver exemptions to expire. Awareness Error"},{"location":"es/rules/resource/#private-endpoint","title":"Private Endpoint","text":"Name Synopsis Severity Level Azure.PrivateEndpoint.Name Private Endpoint names should meet naming requirements. Awareness Error"},{"location":"es/rules/resource/#public-ip-address","title":"Public IP address","text":"Name Synopsis Severity Level Azure.PublicIP.AvailabilityZone Public IP addresses deployed with Standard SKU should use availability zones in supported regions for high availability. Important Error Azure.PublicIP.DNSLabel Public IP domain name labels should meet naming requirements. Awareness Error Azure.PublicIP.IsAttached Public IP addresses should be attached or cleaned up if not in use. Important Error Azure.PublicIP.MigrateStandard Use the Standard SKU for Public IP addresses as the Basic SKU will be retired. Important Error Azure.PublicIP.Name Public IP names should meet naming requirements. Awareness Error Azure.PublicIP.StandardSKU Public IP addresses should be deployed with Standard SKU for production workloads. Important Error"},{"location":"es/rules/resource/#recovery-services-vault","title":"Recovery Services Vault","text":"Name Synopsis Severity Level Azure.RSV.Immutable Ensure immutability is configured to protect backup data. Important Error Azure.RSV.Name Recovery Services vaults should meet naming requirements. Awareness Error Azure.RSV.ReplicationAlert Recovery Services Vaults (RSV) without replication alerts configured may be at risk. Important Error Azure.RSV.StorageType Recovery Services Vaults (RSV) not using geo-replicated storage (GRS) may be at risk. Important Error"},{"location":"es/rules/resource/#resource-group","title":"Resource Group","text":"Name Synopsis Severity Level Azure.ResourceGroup.Name Resource Group names should meet naming requirements. Awareness Error"},{"location":"es/rules/resource/#route-table","title":"Route table","text":"Name Synopsis Severity Level Azure.Route.Name Route table names should meet naming requirements. Awareness Error"},{"location":"es/rules/resource/#service-bus","title":"Service Bus","text":"Name Synopsis Severity Level Azure.ServiceBus.AuditLogs Ensure namespaces audit diagnostic logs are enabled. Important Error Azure.ServiceBus.DisableLocalAuth Authenticate Service Bus publishers and consumers with Entra ID identities. Important Error Azure.ServiceBus.MinTLS Service Bus namespaces should reject TLS versions older than 1.2. Important Error Azure.ServiceBus.Usage Regularly remove unused resources to reduce costs. Important Error"},{"location":"es/rules/resource/#service-fabric","title":"Service Fabric","text":"Name Synopsis Severity Level Azure.ServiceFabric.AAD Use Azure Active Directory (AAD) client authentication for Service Fabric clusters. Critical Error"},{"location":"es/rules/resource/#signalr-service","title":"SignalR Service","text":"Name Synopsis Severity Level Azure.SignalR.ManagedIdentity Configure SignalR Services to use managed identities to access Azure resources securely. Important Error Azure.SignalR.Name SignalR service instance names should meet naming requirements. Awareness Error Azure.SignalR.SLA Use SKUs that include an SLA when configuring SignalR Services. Important Error"},{"location":"es/rules/resource/#sql-database","title":"SQL Database","text":"Name Synopsis Severity Level Azure.SQL.AAD Use Entra ID authentication with Azure SQL databases. Critical Error Azure.SQL.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Database. Important Error Azure.SQL.AllowAzureAccess Determine if access from Azure services is required. Important Error Azure.SQL.Auditing Enable auditing for Azure SQL logical server. Important Error Azure.SQL.DBName Azure SQL Database names should meet naming requirements. Awareness Error Azure.SQL.DefenderCloud Enable Microsoft Defender for Azure SQL logical server. Important Error Azure.SQL.FGName Azure SQL failover group names should meet naming requirements. Awareness Error Azure.SQL.FirewallIPRange Determine if there is an excessive number of permitted IP addresses set in the allowed IP list (CIDR range). Important Error Azure.SQL.FirewallRuleCount Determine if there is an excessive number of firewall rules. Awareness Error Azure.SQL.MinTLS Azure SQL Database servers should reject TLS versions older than 1.2. Critical Error Azure.SQL.ServerName Azure SQL logical server names should meet naming requirements. Awareness Error Azure.SQL.TDE Use Transparent Data Encryption (TDE) with Azure SQL Database. Critical Error"},{"location":"es/rules/resource/#sql-managed-instance","title":"SQL Managed Instance","text":"Name Synopsis Severity Level Azure.SQLMI.AAD Use Azure Active Directory (AAD) authentication with Azure SQL Managed Instance. Critical Error Azure.SQLMI.AADOnly Ensure Azure AD-only authentication is enabled with Azure SQL Managed Instance. Important Error Azure.SQLMI.ManagedIdentity Ensure managed identity is used to allow support for Azure AD authentication. Important Error Azure.SQLMI.Name SQL Managed Instance names should meet naming requirements. Awareness Error"},{"location":"es/rules/resource/#storage-account","title":"Storage Account","text":"Name Synopsis Severity Level Azure.Storage.BlobAccessType Use containers configured with a private access type that requires authorization. Important Error Azure.Storage.BlobPublicAccess Storage Accounts should only accept authorized requests. Important Error Azure.Storage.ContainerSoftDelete Enable container soft delete on Storage Accounts. Important Error Azure.Storage.Defender.DataScan Enable sensitive data threat detection in Microsoft Defender for Storage. Critical Error Azure.Storage.Defender.MalwareScan Enable Malware Scanning in Microsoft Defender for Storage. Critical Error Azure.Storage.DefenderCloud Enable Microsoft Defender for Storage for storage accounts. Critical Error Azure.Storage.FileShareSoftDelete Enable soft delete on Storage Accounts file shares. Important Error Azure.Storage.Firewall Storage Accounts should only accept explicitly allowed traffic. Important Error Azure.Storage.MinTLS Storage Accounts should reject TLS versions older than 1.2. Critical Error Azure.Storage.Name Storage Account names should meet naming requirements. Awareness Error Azure.Storage.SecureTransfer Storage accounts should only accept encrypted connections. Important Error Azure.Storage.SoftDelete Enable blob soft delete on Storage Accounts. Important Error Azure.Storage.UseReplication Storage Accounts not using geo-replicated storage (GRS) may be at risk. Important Error"},{"location":"es/rules/resource/#subscription","title":"Subscription","text":"Name Synopsis Severity Level Azure.RBAC.CoAdministrator Delegate access to manage Azure resources using role-based access control (RBAC). Important Error Azure.RBAC.LimitMGDelegation Limit Role-Base Access Control (RBAC) inheritance from Management Groups. Important Error Azure.RBAC.LimitOwner Limit the number of subscription Owners. Important Error Azure.RBAC.PIM Use just-in-time (JiT) activation of roles instead of persistent role assignment. Important Error Azure.RBAC.UseGroups Use groups for assigning permissions instead of individual user accounts. Important Error Azure.RBAC.UseRGDelegation Use RBAC assignments on resource groups instead of individual resources. Important Error"},{"location":"es/rules/resource/#traffic-manager","title":"Traffic Manager","text":"Name Synopsis Severity Level Azure.TrafficManager.Endpoints Traffic Manager should use at lest two enabled endpoints. Important Error Azure.TrafficManager.Protocol Monitor Traffic Manager web-based endpoints with HTTPS. Important Error"},{"location":"es/rules/resource/#user-assigned-managed-identity","title":"User Assigned Managed Identity","text":"Name Synopsis Severity Level Azure.Identity.UserAssignedName Managed Identity names should meet naming requirements. Awareness Error"},{"location":"es/rules/resource/#virtual-machine","title":"Virtual Machine","text":"Name Synopsis Severity Level Azure.VM.AcceleratedNetworking Use accelerated networking for supported operating systems and VM types. Important Error Azure.VM.ADE Use Azure Disk Encryption (ADE). Important Error Azure.VM.Agent Ensure the VM agent is provisioned automatically. Important Error Azure.VM.AMA Use Azure Monitor Agent for collecting monitoring data from VMs. Important Error Azure.VM.ASAlignment Use availability sets aligned with managed disks fault domains. Important Error Azure.VM.ASMinMembers Availability sets should be deployed with at least two virtual machines (VMs). Important Error Azure.VM.ASName Availability Set names should meet naming requirements. Awareness Error Azure.VM.BasicSku Virtual machines (VMs) should not use Basic sizes. Important Error Azure.VM.ComputerName Virtual Machine (VM) computer name should meet naming requirements. Awareness Error Azure.VM.DiskAttached Managed disks should be attached to virtual machines or removed. Important Error Azure.VM.DiskCaching Check disk caching is configured correctly for the workload. Important Error Azure.VM.DiskName Managed Disk names should meet naming requirements. Awareness Error Azure.VM.DiskSizeAlignment Align to the Managed Disk billing increments to improve cost efficiency. Awareness Error Azure.VM.MaintenanceConfig Use a maintenance configuration for virtual machines. Important Error Azure.VM.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Error Azure.VM.Name Virtual Machine (VM) names should meet naming requirements. Awareness Error Azure.VM.PPGName Proximity Placement Group (PPG) names should meet naming requirements. Awareness Error Azure.VM.PromoSku Virtual machines (VMs) should not use expired promotional SKU. Awareness Error Azure.VM.PublicKey Linux virtual machines should use public keys. Important Error Azure.VM.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Error Azure.VM.ShouldNotBeStopped Azure VMs should be running or in a deallocated state. Important Error Azure.VM.SQLServerDisk Use Premium SSD disks or greater for data and log files for production SQL Server workloads. Important Error Azure.VM.Standalone Use VM features to increase reliability and improve covered SLA for VM configurations. Important Error Azure.VM.Updates Ensure automatic updates are enabled at deployment. Important Error Azure.VM.UseHybridUseBenefit Use Azure Hybrid Benefit for applicable virtual machine (VM) workloads. Awareness Error Azure.VM.UseManagedDisks Virtual machines (VMs) should use managed disks. Important Error"},{"location":"es/rules/resource/#virtual-machine-scale-sets","title":"Virtual Machine Scale Sets","text":"Name Synopsis Severity Level Azure.VMSS.AMA Use Azure Monitor Agent for collecting monitoring data from VM scale sets. Important Error Azure.VMSS.ComputerName Virtual Machine Scale Set (VMSS) computer name should meet naming requirements. Awareness Error Azure.VMSS.MigrateAMA Use Azure Monitor Agent as replacement for Log Analytics Agent. Important Error Azure.VMSS.Name Virtual Machine Scale Set (VMSS) names should meet naming requirements. Awareness Error Azure.VMSS.PublicKey Use SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities. Important Error Azure.VMSS.ScriptExtensions Custom Script Extensions scripts that reference secret values must use the protectedSettings. Important Error"},{"location":"es/rules/resource/#virtual-network","title":"Virtual Network","text":"Name Synopsis Severity Level Azure.VNET.BastionSubnet VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs. Important Error Azure.VNET.FirewallSubnet Use Azure Firewall to filter network traffic to and from Azure resources. Important Error Azure.VNET.LocalDNS Virtual networks (VNETs) should use DNS servers deployed within the same Azure region. Important Error Azure.VNET.Name Virtual Network (VNET) names should meet naming requirements. Awareness Error Azure.VNET.PeerState VNET peering connections must be connected. Important Error Azure.VNET.SingleDNS Virtual networks (VNETs) should have at least two DNS servers assigned. Important Error Azure.VNET.SubnetName Subnet names should meet naming requirements. Awareness Error Azure.VNET.UseNSGs Virtual network (VNET) subnets should have Network Security Groups (NSGs) assigned. Critical Error"},{"location":"es/rules/resource/#virtual-network-gateway","title":"Virtual Network Gateway","text":"Name Synopsis Severity Level Azure.VNG.ConnectionName Virtual Network Gateway (VNG) connection names should meet naming requirements. Awareness Error Azure.VNG.ERAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with ExpressRoute gateway type. Important Error Azure.VNG.ERLegacySKU Migrate from legacy SKUs to improve reliability and performance of ExpressRoute (ER) gateways. Important Error Azure.VNG.Name Virtual Network Gateway (VNG) names should meet naming requirements. Awareness Error Azure.VNG.VPNActiveActive Use VPN gateways configured to operate in an Active-Active configuration to reduce connectivity downtime. Important Error Azure.VNG.VPNAvailabilityZoneSKU Use availability zone SKU for virtual network gateways deployed with VPN gateway type. Important Error Azure.VNG.VPNLegacySKU Migrate from legacy SKUs to improve reliability and performance of VPN gateways. Important Error"},{"location":"es/rules/resource/#virtual-wan","title":"Virtual WAN","text":"Name Synopsis Severity Level Azure.vWAN.Name Virtual WAN (vWAN) names should meet naming requirements. Awareness Error"},{"location":"es/rules/resource/#web-pubsub-service","title":"Web PubSub Service","text":"Name Synopsis Severity Level Azure.WebPubSub.ManagedIdentity Configure Web PubSub Services to use managed identities to access Azure resources securely. Important Error Azure.WebPubSub.SLA Use SKUs that include an SLA when configuring Web PubSub Services. Important Error"},{"location":"learn/learn-video-series/","title":"Learn PSRule for Azure series","text":""},{"location":"learn/learn-video-series/#introducing-psrule-for-azure","title":"Introducing PSRule for Azure","text":"An introduction to PSRule for Azure and how it relates to the Azure Well-Architected Framework. We also give an quick overview of baselines, handling exceptions, and reporting options.
"},{"location":"learn/learn-video-series/#getting-started-using-github","title":"Getting started using GitHub","text":"Getting started with PSRule for Azure using GitHub. We create a GitHub Actions workflow, enabled expansion, and iterate on Bicep code.
"},{"location":"learn/official/","title":"Official learning","text":""},{"location":"learn/official/#blog-posts","title":"Blog posts","text":""},{"location":"learn/official/#2022","title":"2022","text":"PSRule for Azure is licensed with an MIT License, which means it's free to use and modify. But please check out the details.
We open source at Microsoft.
In addition to our team, we hope you will think about contributing too. Here is how you can get started:
Please read our contributing guidelines and code of conduct to learn how to contribute.
"},{"location":"license-contributing/hackathons/","title":"Past hackathons","text":""},{"location":"license-contributing/hackathons/#microsoft-global-hackathon-2022","title":"Microsoft Global Hackathon 2022","text":"Thanks to the team who made the following contributions during the hackathon:
Azure.SQL.ThreatDetection
to Azure.SQL.DefenderCloud
.Azure.SecurityCenter.Contact
to Azure.DefenderCloud.Contact
.Azure.SecurityCenter.Provisioning
to Azure.DefenderCloud.Provisioning
.PSRule for Azure contains documentation ranging from conceptual, code examples, to recommendations. All of this documentation is written in markdown, open source, and available for you to contribute to.
Some of the documentation that you might like to improve includes:
docs/en/rules/
).docs/customization/
and docs/scenarios/
).docs/commands/
and docs/concepts/
).Abstract
This topic covers contributing documentation in PSRule for Azure.
"},{"location":"license-contributing/writing-documentation/#rule-help","title":"Rule help","text":"PSRule for Azure includes recommendations and expanded documentation with each rule. The recommendations are written in markdown and consumed by PSRule during analysis. This allows us to present easy to read web documentation without writing it separately for anaylsis.
As a result, PSRule does require rule documentation to be structured in a standard way. Also we have standards about the metadata we required to ensure there is consistency across documentation.
Some key points for writing rule help:
Please read our contributing guidelines and code of conduct to learn how to contribute.
"},{"location":"quickstarts/test-bicep-with-github/","title":"Test a Bicep deployment with GitHub Actions","text":"Bicep supports using a parameter file to deploy a module to Azure.
Abstract
Learn how to setup your GitHub repository to automatically test Bicep deployments referenced using .bicepparam
files.
This quickstart assumes you have already:
Installed an editor or IDE locally to edit your repository files. For more information, see Visual Studio Code.
If you don't already have a Bicep deployment in your repository, add a sample deployment.
deployments
.deployments
folder, create a new file called dev.bicepparam
.deployments
folder, create a new file called main.bicep
.using 'main.bicep'\n\nparam environment = 'dev'\nparam name = 'kv-example-001'\nparam defaultAction = 'Deny'\nparam workspaceId = '/subscriptions/00000000-0000-0000-0000-000000000000/resourcegroups/rg-test/providers/microsoft.operationalinsights/workspaces/workspace-001'\n
Example deployment module deployments/main.biceptargetScope = 'resourceGroup'\n\nparam name string\nparam location string = resourceGroup().location\n\n@allowed([\n 'Allow'\n 'Deny'\n])\nparam defaultAction string = 'Deny'\nparam environment string\nparam workspaceId string = ''\n\nresource vault 'Microsoft.KeyVault/vaults@2023-02-01' = {\n name: name\n location: location\n properties: {\n sku: {\n family: 'A'\n name: 'standard'\n }\n tenantId: tenant().tenantId\n enableSoftDelete: true\n enablePurgeProtection: true\n enableRbacAuthorization: true\n networkAcls: {\n defaultAction: defaultAction\n }\n }\n tags: {\n env: environment\n }\n}\n\n@sys.description('Configure auditing for Key Vault.')\nresource logs 'Microsoft.Insights/diagnosticSettings@2021-05-01-preview' = if (!empty(workspaceId)) {\n name: 'service'\n scope: vault\n properties: {\n workspaceId: workspaceId\n logs: [\n {\n category: 'AuditEvent'\n enabled: true\n }\n ]\n }\n}\n
You can also find a copy of these files in the quickstart sample repository.
"},{"location":"quickstarts/test-bicep-with-github/#create-an-options-file","title":"Create an options file","text":"PSRule can be configured using a default YAML options file called ps-rule.yaml
. Many of configuration options you are likely to want to use can be set using this file. Options in this file will automatically be detected by other PSRule commands and tools.
ps-rule.yaml
.#\n# PSRule configuration\n#\n\n# Please see the documentation for all configuration options:\n# https://aka.ms/ps-rule-azure/options\n\n# Require a minimum version of PSRule for Azure.\nrequires:\n PSRule.Rules.Azure: '>=1.34.0' # (1)\n\n# Automatically use rules for Azure.\ninclude:\n module:\n - PSRule.Rules.Azure # (2)\n\n# Ignore all files except .bicepparam files.\ninput:\n pathIgnore:\n - '**' # (3)\n - '!**/*.bicepparam' # (4)\n
.bicepparam
files.GitHub Actions are configured using a YAML file called a workflow. A workflow is made up of one or more jobs and steps.
.github/workflows
..github/workflows
folder, create a new file called analysis.yaml
.#\n# Analyze repository with PSRule\n#\n\n# For PSRule documentation see:\n# https://aka.ms/ps-rule\n# https://aka.ms/ps-rule-azure\n\n# For action details see:\n# https://aka.ms/ps-rule-action\n\nname: Analyze repository\n\n# Run analysis for main or PRs against main\non:\n push:\n branches:\n - main\n pull_request:\n branches:\n - main\n\njobs:\n analyze:\n name: Analyze repository\n runs-on: ubuntu-latest\n steps:\n\n - name: Checkout\n uses: actions/checkout@v4\n\n - name: Run PSRule analysis\n uses: microsoft/ps-rule@v2.9.0 # (1)\n with:\n modules: PSRule.Rules.Azure # (2)\n
main
branch in GitHub. For more information, see Creating a pull request.Navigate to the Actions tab in your repository to check the status of the workflow.
Enforcing custom tags
Azure Resource Manager (ARM) templates are a JSON-based file structure. ARM templates are typically not static, they include parameters, functions and conditions. Depending on the parameters provided to a template, resources may differ significantly.
Important resource properties that should be validated are often variables, parameters or deployed conditionally. Under these circumstances, to correctly validate resources in a template, parameters must be resolved.
The following scenario shows how PSRule can be used to validate Azure resource templates within an Azure Pipeline.
This scenario covers the following:
PSRule includes an extension that can be installed from the Visual Studio Marketplace. Once installed, Azure Pipelines tasks are available to install PSRule modules and run analysis.
"},{"location":"scenarios/azure-pipelines-ci/azure-pipelines-ci/#linking-parameter-files-to-templates","title":"Linking parameter files to templates","text":"ARM template parameter files allows parameters for a deployment to be saved and checked into source control. PSRule can automatically resolve ARM templates from parameter files by using a metadata link.
To link a parameter file to an ARM template add the metadata.template
property within a parameter file.
For example:
{\n \"$schema\": \"https://schema.management.azure.com/schemas/2015-01-01/deploymentParameters.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"metadata\": {\n \"template\": \"./azuredeploy.json\"\n },\n \"parameters\": {\n \"vnetName\": {\n \"value\": \"vnet-001\"\n },\n \"addressPrefix\": {\n \"value\": [\n \"10.1.0.0/24\"\n ]\n }\n }\n}\n
In the example parameter file azuredeploy.parameters.json
is linked to the template azuredeploy.json
. The prefix of ./
indicates that the template file is in a relative path to the parameter file. If ./
is not included, PSRule will look for the template relative to the working directory.
For example:
{\n \"$schema\": \"https://schema.management.azure.com/schemas/2015-01-01/deploymentParameters.json#\",\n \"contentVersion\": \"1.0.0.0\",\n \"metadata\": {\n \"template\": \"templates/vnet-hub/v1/template.json\"\n },\n \"parameters\": {\n \"vnetName\": {\n \"value\": \"vnet-001\"\n },\n \"addressPrefix\": {\n \"value\": [\n \"10.1.0.0/24\"\n ]\n }\n }\n}\n
"},{"location":"scenarios/azure-pipelines-ci/azure-pipelines-ci/#creating-a-yaml-pipeline","title":"Creating a YAML pipeline","text":"Azure Pipelines supports defining pipelines in YAML. PSRule uses a number of configurable task steps to install modules, export data and perform analysis.
"},{"location":"scenarios/azure-pipelines-ci/azure-pipelines-ci/#installing-azure-rules","title":"Installing Azure rules","text":"To install the module containing Azure rules use the ps-rule-install
YAML task.
# Install PSRule.Rules.Azure from the PowerShell Gallery.\n- task: ps-rule-install@2\n inputs:\n module: PSRule.Rules.Azure # Install PSRule.Rules.Azure from the PowerShell Gallery.\n
"},{"location":"scenarios/azure-pipelines-ci/azure-pipelines-ci/#exporting-resource-data-for-analysis","title":"Exporting resource data for analysis","text":"PSRule provides a pre-built cmdlets for finding template files within a path and exporting resource data.
Get-AzRuleTemplateLink
finds linked templates from parameter files. By default, parameter files with the *.parameters.json
extension are discovered. Files are found recursively from the current working path.Export-AzRuleTemplateData
exports resource data from template files.To generate data for analysis use a PowerShell YAML task to export resource data from linked templates.
# Export resource data from parameter files within the current working directory.\n- powershell: Get-AzRuleTemplateLink | Export-AzRuleTemplateData -OutputPath out/templates/;\n displayName: 'Export template data'\n
If parameter files are located in a specific sub-directory the path can be updated as follows.
# Export resource data from parameter files in the deployments/ sub-directory.\n- powershell: Get-AzRuleTemplateLink ./deployments/ | Export-AzRuleTemplateData -OutputPath out/templates/;\n displayName: 'Export template data'\n
If parameter files do not use the file extension .parameters.json
input path can be set.
# Export resource data from parameter files ending in *.json instead of default *.parameters.json.\n- powershell: Get-AzRuleTemplateLink -InputPath *.json | Export-AzRuleTemplateData -OutputPath out/templates/;\n displayName: 'Export template data'\n
In both cases, resource data for analysis is exported to out/templates/
.
To validate exported resources use the ps-rule-assert
YAML task. The following task uses previously exported resource data for analysis.
# Run analysis from JSON files using the `PSRule.Rules.Azure` module and custom rules from `.ps-rule/`.\n- task: ps-rule-assert@2\n inputs:\n inputType: inputPath\n inputPath: 'out/templates/*.json' # Read exported resource data from 'out/templates/'.\n modules: 'PSRule.Rules.Azure' # Analyze objects using the rules within the PSRule.Rules.Azure PowerShell module.\n # Optionally, also analyze objects using custom rules from '.ps-rule/'.\n source: '.ps-rule/'\n # Optionally, save results to an NUnit report.\n outputFormat: NUnit3\n outputPath: reports/ps-rule-resources.xml\n
In the example:
out/templates/
..ps-rule/
these are also evaluated.NUnit is a popular unit test framework for .NET. PSRule supports publishing validation results in the NUnit format. With Azure DevOps, an NUnit report can be published using Publish Test Results task.
An example YAML snippet is included below:
# Publish NUnit report as test results\n- task: PublishTestResults@2\n displayName: 'Publish PSRule results'\n inputs:\n testRunTitle: 'PSRule' # The title to use for the test run.\n testRunner: NUnit # Import report using the NUnit format.\n testResultsFiles: 'reports/ps-rule-results.xml' # The previously saved NUnit report.\n condition: succeededOrFailed() # Run this task if previous steps succeeded of failed.\n
"},{"location":"scenarios/azure-pipelines-ci/azure-pipelines-ci/#complete-example","title":"Complete example","text":"Putting each of these steps together.
"},{"location":"scenarios/azure-pipelines-ci/azure-pipelines-ci/#azure-devops-pipeline","title":"Azure DevOps Pipeline","text":"#\n# PSRule with Azure Pipelines\n#\n\ntrigger:\n- main\n\npool:\n vmImage: 'ubuntu-latest'\n\nsteps:\n\n# Install PSRule.Rules.Azure from the PowerShell Gallery\n- task: ps-rule-install@2\n inputs:\n module: PSRule.Rules.Azure # Install PSRule.Rules.Azure from the PowerShell Gallery.\n\n# Export resource data from parameter files within the current working directory.\n- powershell: Get-AzRuleTemplateLink | Export-AzRuleTemplateData -OutputPath out/templates/;\n displayName: 'Export template data'\n\n# Run analysis from JSON files using the `PSRule.Rules.Azure` module and custom rules from `.ps-rule/`.\n- task: ps-rule-assert@2\n inputs:\n inputType: inputPath\n inputPath: 'out/templates/*.json' # Read exported resource data from 'out/templates/'.\n modules: 'PSRule.Rules.Azure' # Analyze objects using the rules within the PSRule.Rules.Azure PowerShell module.\n # Optionally, also analyze objects using custom rules from '.ps-rule/'.\n source: '.ps-rule/'\n # Optionally, save results to an NUnit report.\n outputFormat: NUnit3\n outputPath: reports/ps-rule-resources.xml\n\n# Publish NUnit report as test results\n- task: PublishTestResults@2\n displayName: 'Publish PSRule results'\n inputs:\n testRunTitle: 'PSRule' # The title to use for the test run.\n testRunner: NUnit # Import report using the NUnit format.\n testResultsFiles: 'reports/ps-rule-*.xml' # Use previously saved NUnit reports.\n mergeTestResults: true # Merge multiple reports.\n condition: succeededOrFailed() # Run this task if previous steps succeeded of failed.\n
"},{"location":"scenarios/azure-pipelines-ci/azure-pipelines-ci/#more-information","title":"More information","text":"Azure Resource Manager (ARM) templates are a JSON-based file structure. ARM templates are typically not static, they include parameters, functions and conditions. Depending on the parameters provided to a template, resources may differ significantly.
Important resource properties that should be validated are often variables, parameters or deployed conditionally. Under these circumstances, to correctly validate resources in a template, parameters must be resolved.
The following scenario shows how to validate Azure resources from templates using a generic pipeline. The examples provided can be integrated into a continuous integration (CI) pipeline able to run PowerShell.
For integrating into Azure DevOps see Validate Azure resources from templates with Azure Pipelines.
This scenario covers the following:
Typically, PSRule is not pre-installed on CI worker nodes and must be installed within the pipeline. PSRule PowerShell modules need to be installed prior to calling PSRule cmdlets.
If your CI pipeline runs on a persistent virtual machine that you control, consider pre-installing PSRule. The following examples focus on installing PSRule dynamically during execution of the pipeline. Which is suitable for cloud-based CI worker nodes.
To install PSRule within a CI pipeline, execute the Install-Module
PowerShell cmdlet.
Depending on your environment, the CI worker process may not have administrative permissions. To install modules into the current context running the CI pipeline use -Scope CurrentUser
. The PowerShell Gallery is not a trusted source by default. Use the -Force
switch to suppress a prompt to install modules from PowerShell Gallery.
For example:
$Null = Install-Module -Name PSRule.Rules.Azure -Scope CurrentUser -Force;\n
Installing PSRule.Rules.Azure
also installs the base PSRule
module and associated Azure dependencies. The PSRule.Rules.Azure
module includes cmdlets and pre-built rules for validating Azure resources. Using the pre-built rules is completely optional.
In some cases, installing NuGet and PowerShellGet may be required to connect to the PowerShell Gallery. The NuGet package provider can be installed using the Install-PackageProvider
PowerShell cmdlet.
$Null = Install-PackageProvider -Name NuGet -Scope CurrentUser -Force;\n
The example below includes both steps together with checks:
if ($Null -eq (Get-PackageProvider -Name NuGet -ErrorAction SilentlyContinue)) {\n $Null = Install-PackageProvider -Name NuGet -Scope CurrentUser -Force;\n}\n\nif ($Null -eq (Get-InstalledModule -Name PowerShellGet -MinimumVersion 2.2.1 -ErrorAction Ignore)) {\n Install-Module PowerShellGet -MinimumVersion 2.2.1 -Scope CurrentUser -Force -AllowClobber;\n}\n\nif ($Null -eq (Get-InstalledModule -Name PSRule.Rules.Azure -MinimumVersion '0.12.1' -ErrorAction SilentlyContinue)) {\n $Null = Install-Module -Name PSRule.Rules.Azure -Scope CurrentUser -MinimumVersion '0.12.1' -Force;\n}\n
Add -AllowPrerelease
to install pre-release versions. See the change log for the latest version.
In PSRule, the Export-AzRuleTemplateData
cmdlet resolves a template and returns a resultant set of resources. The resultant set of resources can then be validated.
No connectivity to Azure is required by default when calling Export-AzRuleTemplateData
.
To run Export-AzRuleTemplateData
two key parameters are required:
-TemplateFile
- An absolute or relative path to the template JSON file.-ParameterFile
- An absolute or relative path to one or more parameter JSON files.The -ParameterFile
parameter is optional when all parameters defined in the template have defaultValue
set.
Optionally the following parameters can be used:
-Name
- The name of the deployment. If not specified a default name of export-<xxxxxxxx>
will be used.-OutputPath
- An absolute or relative path where the resultant resources will be written to JSON. If not specified the current working path be used.-ResourceGroup
- The name of a resource group where the deployment is intended to be run. If not specified placeholder values will be used.-Subscription
- The name or subscription Id of a subscription where the deployment is intended to be run. If not specified placeholder values will be used.See cmdlet help for a full list of parameters.
If -OutputPath
is a directory or is not set, the output file will be automatically named resources-<name>.json
.
For example:
Export-AzRuleTemplateData -TemplateFile .\\template.json -ParameterFile .\\parameters.json;\n
Multiple parameter files that map to the same template can be supplied in a single cmdlet call. Additional templates can be exported by calling Export-AzRuleTemplateData
multiple times.
A number of functions that can be used within Azure templates retrieve information from Azure. Some examples include reference
, subscription
, resourceGroup
, list*
.
The default for Export-AzRuleTemplateData
is to operate without requiring authenticated connectivity to Azure. As a result, functions that retrieve information from Azure use placeholders such as {{Subscription.SubscriptionId}}
.
To provide a real value for subscription
and resourceGroup
use the -Subscription
and -ResourceGroup
parameters. When using -Subscription
and -ResourceGroup
the subscription and resource group must already exist. Additionally the context running the cmdlet must have at least read access (i.e. Reader
).
It is currently not possible to provide a real value for reference
and list*
, only placeholders will be used.
Key Vault references in parameter files use placeholders instead of the real value to prevent accidental exposure of secrets.
"},{"location":"scenarios/azure-template-ci/azure-template-ci/#validating-exported-resources","title":"Validating exported resources","text":"To validate exported resources use Invoke-PSRule
, Assert-PSRule
or Test-PSRuleTarget
. In a CI pipeline, Assert-PSRule
is recommended. Assert-PSRule
outputs preformatted results ideal for use within a CI pipeline.
Use Assert-PSRule
with the resolved resource output as an input using -InputPath
.
In the following example, resources from .\\resources.json
are validated against pre-built rules:
Assert-PSRule -InputPath .\\resources-export-*.json -Module PSRule.Rules.Azure;\n
Example output:
-> vnet-001 : Microsoft.Network/virtualNetworks\n\n [PASS] Azure.Resource.UseTags\n [PASS] Azure.VirtualNetwork.UseNSGs\n [PASS] Azure.VirtualNetwork.SingleDNS\n [PASS] Azure.VirtualNetwork.LocalDNS\n\n -> vnet-001/subnet2 : Microsoft.Network/virtualNetworks/subnets\n\n [FAIL] Azure.Resource.UseTags\n
To process multiple input files a wildcard *
can be used.
Assert-PSRule -InputPath .\\out\\*.json -Module PSRule.Rules.Azure;\n
"},{"location":"scenarios/azure-template-ci/azure-template-ci/#formatting-output","title":"Formatting output","text":"When executing a CI pipeline, feedback on any validation failures is important. The Assert-PSRule
cmdlet provides easy to read formatted output instead of PowerShell objects.
Additionally, Assert-PSRule
supports styling formatted output for Azure Pipelines and GitHub Actions. Use the -Style AzurePipelines
or -Style GitHubActions
parameter to style output.
For example:
Assert-PSRule -InputPath .\\out\\*.json -Style AzurePipelines -Module PSRule.Rules.Azure;\n
"},{"location":"scenarios/azure-template-ci/azure-template-ci/#failing-the-pipeline","title":"Failing the pipeline","text":"When using PSRule within a CI pipeline, a failed rule should stop the pipeline. When using Assert-PSRule
if any rules fail, an error will be generated.
Assert-PSRule : One or more rules reported failure.\nAt line:1 char:1\n+ Assert-PSRule -Module PSRule.Rules.Azure -InputPath .\\out\\tests\\Resou ...\n+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n+ CategoryInfo : InvalidData: (:) [Assert-PSRule], FailPipelineException\n+ FullyQualifiedErrorId : PSRule.Fail,Assert-PSRule\n
A single PowerShell error is typically enough to stop a CI pipeline. If you are using a different configuration additionally -ErrorAction Stop
can be used.
For example:
Assert-PSRule -Module PSRule.Rules.Azure -InputPath .\\out\\*.json -ErrorAction Stop;\n
"},{"location":"scenarios/azure-template-ci/azure-template-ci/#generating-nunit-output","title":"Generating NUnit output","text":"NUnit is a popular unit test framework for .NET. NUnit generates a test report format that is widely interpreted by CI systems. While PSRule does not use NUnit directly, it support outputting validation results in the NUnit3 format. Using a common format allows integration with any system that supports the NUnit3 for publishing test results.
To generate an NUnit report:
-OutputFormat NUnit3
parameter.-OutputPath
parameter to specify the path of the report file to write.Assert-PSRule -OutputFormat NUnit3 -OutputPath .\\reports\\rule-report.xml -Module PSRule.Rules.Azure -InputPath .\\out\\*.json;\n
The output path will be created if it does not exist.
"},{"location":"scenarios/azure-template-ci/azure-template-ci/#complete-example","title":"Complete example","text":"Putting each of these steps together.
"},{"location":"scenarios/azure-template-ci/azure-template-ci/#install-dependencies","title":"Install dependencies","text":"# Install dependencies for connecting to PowerShell Gallery\nif ($Null -eq (Get-PackageProvider -Name NuGet -ErrorAction Ignore)) {\n Install-PackageProvider -Name NuGet -Force -Scope CurrentUser;\n}\n\nif ($Null -eq (Get-InstalledModule -Name PowerShellGet -MinimumVersion 2.2.1 -ErrorAction Ignore)) {\n Install-Module PowerShellGet -MinimumVersion 2.2.1 -Scope CurrentUser -Force -AllowClobber;\n}\n
"},{"location":"scenarios/azure-template-ci/azure-template-ci/#validate-templates","title":"Validate templates","text":"# Install PSRule.Rules.Azure module\nif ($Null -eq (Get-InstalledModule -Name PSRule.Rules.Azure -MinimumVersion '0.12.1' -ErrorAction SilentlyContinue)) {\n $Null = Install-Module -Name PSRule.Rules.Azure -Scope CurrentUser -MinimumVersion '0.12.1' -Force;\n}\n\n# Resolve resources\nExport-AzRuleTemplateData -TemplateFile .\\template.json -ParameterFile .\\parameters.json -OutputPath out/;\n\n# Validate resources\n$assertParams = @{\n InputPath = 'out/*.json'\n Module = 'PSRule.Rules.Azure'\n Style = 'AzurePipelines'\n OutputFormat = 'NUnit3'\n OutputPath = 'reports/rule-report.xml'\n}\nAssert-PSRule @assertParams;\n
"},{"location":"scenarios/azure-template-ci/azure-template-ci/#additional-options","title":"Additional options","text":""},{"location":"scenarios/azure-template-ci/azure-template-ci/#using-invoke-build","title":"Using Invoke-Build","text":"Invoke-Build
is a build automation cmdlet that can be installed from the PowerShell Gallery by installing the InvokeBuild module. Within Invoke-Build, each build process is broken into tasks.
The following example shows an example of using PSRule.Rules.Azure with InvokeBuild tasks.
# Synopsis: Install PSRule modules\ntask InstallPSRule {\n if ($Null -eq (Get-InstalledModule -Name PSRule.Rules.Azure -MinimumVersion '0.12.1' -ErrorAction SilentlyContinue)) {\n $Null = Install-Module -Name PSRule.Rules.Azure -Scope CurrentUser -MinimumVersion '0.12.1' -Force;\n }\n}\n\n# Synopsis: Run validation\ntask ValidateTemplate InstallPSRule, {\n # Resolve resources\n Export-AzRuleTemplateData -TemplateFile .\\template.json -ParameterFile .\\parameters.json -OutputPath out/;\n\n # Validate resources\n $assertParams = @{\n InputPath = 'out/*.json'\n Module = 'PSRule.Rules.Azure'\n Style = 'AzurePipelines'\n OutputFormat = 'NUnit3'\n OutputPath = 'reports/rule-report.xml'\n }\n Assert-PSRule @assertParams;\n}\n\n# Synopsis: Run all build tasks\ntask Build ValidateTemplate\n
Invoke-Build Build;\n
"},{"location":"scenarios/azure-template-ci/azure-template-ci/#calling-from-pester","title":"Calling from Pester","text":"Pester is a unit test framework for PowerShell that can be installed from the PowerShell Gallery.
Typically, Pester unit tests are built for a particular pipeline. PSRule can complement Pester unit tests by providing dynamic and sharable rules that are easy to reuse. By using -If
or -Type
pre-conditions, rules can dynamically provide validation for a range of use cases.
When calling PSRule from Pester use Invoke-PSRule
instead of Assert-PSRule
. Invoke-PSRule
returns validation result objects that can be tested by Pester Should
conditions.
Additionally, the Logging.RuleFail
option can be included to generate an error message for each failing rule.
For example:
Describe 'Azure' {\n Context 'Resource templates' {\n It 'Use content rules' {\n Export-AzRuleTemplateData -TemplateFile .\\template.json -ParameterFile .\\parameters.json -OutputPath .\\out\\resources.json;\n\n # Validate resources\n $invokeParams = @{\n InputPath = 'out/*.json'\n Module = 'PSRule.Rules.Azure'\n OutputFormat = 'NUnit3'\n OutputPath = 'reports/rule-report.xml'\n Option = (New-PSRuleOption -LoggingRuleFail Error)\n }\n Invoke-PSRule @invokeParams -Outcome Fail,Error | Should -BeNullOrEmpty;\n }\n }\n}\n
"},{"location":"scenarios/azure-template-ci/azure-template-ci/#more-information","title":"More information","text":"PSRule for Azure can automatically resolve Azure resource context at runtime from infrastructure code. This feature can be enabled by using the following configuration options.
"},{"location":"setup/configuring-expansion/#configuration","title":"Configuration","text":"Tip
Each of these configuration options are set within the ps-rule.yaml
file. To learn how to set configuration options see Configuring options.
v1.4.1
This configuration option determines if Azure template parameter files will automatically be expanded. By default, parameter files will not be automatically expanded. When enabled, PSRule will discover and expand JSON parameter files for Azure templates or Bicep modules.
Parameter files are expanded when PSRule cmdlets with the -Format File
parameter are used.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_PARAMETER_FILE_EXPANSION: bool\n
Default:
ps-rule.yaml# YAML: The default AZURE_PARAMETER_FILE_EXPANSION configuration option\nconfiguration:\n AZURE_PARAMETER_FILE_EXPANSION: false\n
Example:
ps-rule.yaml# YAML: Set the AZURE_PARAMETER_FILE_EXPANSION configuration option to enable expansion\nconfiguration:\n AZURE_PARAMETER_FILE_EXPANSION: true\n
"},{"location":"setup/configuring-expansion/#bicep-source-expansion","title":"Bicep source expansion","text":"v1.11.0
This configuration option determines if Azure Bicep source files will automatically be expanded. By default, Bicep files will not be automatically expanded.
Bicep files are expanded when PSRule cmdlets with the -Format File
parameter are used.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_BICEP_FILE_EXPANSION: bool\n
Default:
ps-rule.yaml# YAML: The default AZURE_BICEP_FILE_EXPANSION configuration option\nconfiguration:\n AZURE_BICEP_FILE_EXPANSION: false\n
Example:
ps-rule.yaml# YAML: Set the AZURE_BICEP_FILE_EXPANSION configuration option to enable expansion\nconfiguration:\n AZURE_BICEP_FILE_EXPANSION: true\n
"},{"location":"setup/configuring-expansion/#bicep-parameter-expansion","title":"Bicep parameter expansion","text":"v1.34.0
This configuration option determines if Azure Bicep parameter files (.bicepparam
) are expanded. By default, Bicep parameter files will be automatically expanded.
Bicep files are expanded when PSRule cmdlets with the -Format File
parameter are used.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_BICEP_PARAMS_FILE_EXPANSION: bool\n
Default:
ps-rule.yaml# YAML: The default AZURE_BICEP_PARAMS_FILE_EXPANSION configuration option\nconfiguration:\n AZURE_BICEP_PARAMS_FILE_EXPANSION: true\n
Example:
ps-rule.yaml# YAML: Set the AZURE_BICEP_PARAMS_FILE_EXPANSION configuration option to enable expansion\nconfiguration:\n AZURE_BICEP_PARAMS_FILE_EXPANSION: false\n
"},{"location":"setup/configuring-expansion/#bicep-compilation-timeout","title":"Bicep compilation timeout","text":"v1.13.3
This configuration option determines the maximum time to spend building a single Bicep source file. The timeout is configured in seconds.
When a timeout occurs, PSRule for Azure stops the build and returns an error. Any resources contained within Bicep source files that exceeded the timeout are not analyzed.
The default timeout is 5 seconds, however the timeout can be set to an integer between 1
and 120
.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_BICEP_FILE_EXPANSION_TIMEOUT: int\n
Default:
ps-rule.yaml# YAML: The default AZURE_BICEP_FILE_EXPANSION_TIMEOUT configuration option\nconfiguration:\n AZURE_BICEP_FILE_EXPANSION_TIMEOUT: 5\n
Example:
ps-rule.yaml# YAML: Set the AZURE_BICEP_FILE_EXPANSION_TIMEOUT configuration option to enable expansion\nconfiguration:\n AZURE_BICEP_FILE_EXPANSION_TIMEOUT: 15\n
"},{"location":"setup/configuring-expansion/#require-template-metadata-link","title":"Require template metadata link","text":"v1.7.0
This configuration option determines if Azure template parameter files require a metadata link. When configured to true
, the Azure.Template.MetadataLink
rule is enabled. Any Azure template parameter files that do not include a metadata link will report a fail for this rule.
The rule Azure.Template.MetadataLink
is not enabled by default. Additionally, when enabled this rule can still be excluded or suppressed like all other rules.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_PARAMETER_FILE_METADATA_LINK: bool\n
Default:
ps-rule.yaml# YAML: The default AZURE_PARAMETER_FILE_METADATA_LINK configuration option\nconfiguration:\n AZURE_PARAMETER_FILE_METADATA_LINK: false\n
Example:
ps-rule.yaml# YAML: Set the AZURE_PARAMETER_FILE_METADATA_LINK configuration option to enable expansion\nconfiguration:\n AZURE_PARAMETER_FILE_METADATA_LINK: true\n
"},{"location":"setup/configuring-expansion/#deployment-properties","title":"Deployment properties","text":"v1.17.0
This configuration option sets the deployment object use by the deployment()
function. Configure this option to change the details of the deployment when exporting templates for analysis. Provided properties will override the default. Any properties that are not provided with use the defaults as specified below.
This configuration option applies to the parent deployment. Nested deployments will use any properties configured within code. Additionally, this configuration option will be ignore when -Name
is used with Export-AzRuleTemplateData
.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_DEPLOYMENT:\n name: string\n
Default:
ps-rule.yaml# YAML: The default AZURE_DEPLOYMENT configuration option\nconfiguration:\n AZURE_DEPLOYMENT:\n name: 'ps-rule-test-deployment'\n
Example:
ps-rule.yaml# YAML: Override the name of the deployment object.\nconfiguration:\n AZURE_DEPLOYMENT:\n name: 'deploy-web-application'\n
"},{"location":"setup/configuring-expansion/#deployment-resource-group","title":"Deployment resource group","text":"v1.1.0
This configuration option sets the resource group object used by the resourceGroup()
function. Configure this option to change the resource group object when using exporting templates for analysis. Provided properties will override the default. Any properties that are not provided with use the defaults as specified below.
This configuration option will be ignored when -ResourceGroup
is used with Export-AzRuleTemplateData
.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_RESOURCE_GROUP:\n name: string\n location: string\n tags: object\n properties:\n provisioningState: string\n
Default:
ps-rule.yaml# YAML: The default AZURE_RESOURCE_GROUP configuration option\nconfiguration:\n AZURE_RESOURCE_GROUP:\n name: 'ps-rule-test-rg'\n location: 'eastus'\n tags: { }\n properties:\n provisioningState: 'Succeeded'\n
Example:
ps-rule.yaml# YAML: Override the location of the resource group object.\nconfiguration:\n AZURE_RESOURCE_GROUP:\n location: 'australiasoutheast'\n
"},{"location":"setup/configuring-expansion/#deployment-subscription","title":"Deployment subscription","text":"v1.1.0
This configuration option sets the subscription object used by the subscription()
function. Configure this option to change the subscription object when using exporting templates for analysis. Provided properties will override the default. Any properties that are not provided with use the defaults as specified below.
This configuration option will be ignored when -Subscription
is used with Export-AzRuleTemplateData
.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_SUBSCRIPTION:\n subscriptionId: string\n displayName: string\n state: string\n
Default:
ps-rule.yaml# YAML: The default AZURE_SUBSCRIPTION configuration option\nconfiguration:\n AZURE_SUBSCRIPTION:\n subscriptionId: 'ffffffff-ffff-ffff-ffff-ffffffffffff'\n displayName: 'PSRule Test Subscription'\n state: 'NotDefined'\n
Example:
ps-rule.yaml# YAML: Override the display name of the subscription object\nconfiguration:\n AZURE_SUBSCRIPTION:\n displayName: 'My test subscription'\n
"},{"location":"setup/configuring-expansion/#deployment-tenant","title":"Deployment tenant","text":"v1.11.0
This configuration option sets the tenant object used by the tenant()
function. Configure this option to change the tenant object when using exporting templates for analysis. Provided properties will override the default. Any properties that are not provided with use the defaults as specified below.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_TENANT:\n countryCode: string\n tenantId: string\n displayName: string\n
Default:
ps-rule.yaml# YAML: The default AZURE_TENANT configuration option\nconfiguration:\n AZURE_TENANT:\n countryCode: 'US'\n tenantId: 'ffffffff-ffff-ffff-ffff-ffffffffffff'\n displayName: 'PSRule'\n
Example:
ps-rule.yaml# YAML: Override the display name of the tenant object\nconfiguration:\n AZURE_TENANT:\n displayName: 'Contoso'\n
"},{"location":"setup/configuring-expansion/#deployment-management-group","title":"Deployment management group","text":"v1.11.0
This configuration option sets the management group object used by the managementGroup()
function. Configure this option to change the management group object when using exporting templates for analysis. Provided properties will override the default. Any properties that are not provided with use the defaults as specified below.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_MANAGEMENT_GROUP:\n name: string\n properties:\n displayName: string\n
Default:
ps-rule.yaml# YAML: The default AZURE_MANAGEMENT_GROUP configuration option\nconfiguration:\n AZURE_MANAGEMENT_GROUP:\n name: 'psrule-test'\n properties:\n displyName: 'PSRule Test Management Group'\n
Example:
ps-rule.yaml# YAML: Override the display name of the management group object\nconfiguration:\n AZURE_MANAGEMENT_GROUP:\n properties:\n displayName: 'My test management group'\n
"},{"location":"setup/configuring-expansion/#required-parameter-defaults","title":"Required parameter defaults","text":"v1.13.0
This configuration option allows a fallback value to be configured for required parameters. When a parameter value is not provided and a default is not set, the fallback value will be used.
Configure this option when you are providing a set of common parameters dynamically during a pipeline. In this scenario, it may not make sense to add the parameters to a parameter file or Bicep deployment.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_PARAMETER_DEFAULTS:\n <parameter>: <value>\n
Default:
ps-rule.yaml# YAML: The default AZURE_PARAMETER_DEFAULTS configuration option\nconfiguration:\n AZURE_PARAMETER_DEFAULTS: { }\n
Example:
ps-rule.yaml# YAML: Set fallback values for adminPassword and workspaceId parameters.\nconfiguration:\n AZURE_PARAMETER_DEFAULTS:\n adminPassword: $CREDENTIAL_PLACEHOLDER$\n workspaceId: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.OperationalInsights/workspaces/{workspaceName}\n
"},{"location":"setup/configuring-expansion/#excluding-files","title":"Excluding files","text":"Template or Bicep source files can be excluded from being processed by PSRule and expansion. To exclude a file, configure the input.pathIgnore
option by providing a path spec to ignore.
Syntax:
ps-rule.yamlinput:\n pathIgnore:\n - string\n - string\n
Default:
ps-rule.yaml# YAML: The default input.pathIgnore option\ninput:\n pathIgnore: []\n
Example:
ps-rule.yaml# YAML: Exclude a file from being processed by PSRule and expansion\ninput:\n pathIgnore:\n - 'out/'\n - 'modules/**/*.bicep'\n
"},{"location":"setup/configuring-options/","title":"Configuring options","text":"PSRule for Azure comes with many configuration options. Additionally, the PSRule engine includes several options that apply to all rules. You can visit the about_PSRule_Options topic to read about general PSRule options.
"},{"location":"setup/configuring-options/#setting-options","title":"Setting options","text":"Configuration options are set within the ps-rule.yaml
file. PSRule will automatically find this file within the current working directory. To set options, create a new file named ps-rule.yaml
in the root directory of your repository.
For configuring pre-flight analysis, create a ps-rule.yaml
in your current working directory.
Tip
This file should be committed to your repository so it is available when your pipeline runs.
Note
Use all lowercase characters ps-rule.yaml
to name the file. On case-sensitive file systems, a file with uppercase characters may not be found.
Configuration can be combined as indented keys. Use comments to add context.
Example ps-rule.yaml
requires:\n # Require a minimum of PSRule for Azure v1.34.2\n PSRule.Rules.Azure: '>=1.34.2'\n\nconfiguration:\n # Enable expansion of Azure Template files.\n AZURE_PARAMETER_FILE_EXPANSION: true\n\n # Enable expansion of Azure Bicep files.\n AZURE_BICEP_FILE_EXPANSION: true\n\n # Configure the timeout for bicep build to 15 seconds.\n AZURE_BICEP_FILE_EXPANSION_TIMEOUT: 15\n\n # Enable Bicep CLI checks.\n AZURE_BICEP_CHECK_TOOL: true\n\n # Optionally, configure the minimum version of the Bicep CLI.\n AZURE_BICEP_MINIMUM_VERSION: '0.16.2'\n\n # Configure the minimum AKS cluster version.\n AZURE_AKS_CLUSTER_MINIMUM_VERSION: '1.27.9'\n\nrule:\n # Enable custom rules that don't exist in the baseline\n includeLocal: true\n exclude:\n # Ignore the following rules for all resources\n - Azure.VM.UseHybridUseBenefit\n - Azure.VM.Standalone\n\nsuppression:\n Azure.AKS.AuthorizedIPs:\n # Exclude the following externally managed AKS clusters\n - aks-cluster-prod-eus-001\n Azure.Storage.SoftDelete:\n # Exclude the following non-production storage accounts\n - storagedeveus6jo36t\n - storagedeveus1df278\n
Tip
YAML can be a bit particular about indenting. If something is not working, double check that you have consistent spacing in your options file. We recommend using two (2) spaces to indent.
"},{"location":"setup/configuring-options/#setting-environment-variables","title":"Setting environment variables","text":"In addition to ps-rule.yaml
, most options can be set using environment variables. When configuring environment variables we recommend that all capital letters are used. This is because environment variables are case-sensitive on some operating systems.
PSRule environment variables use a consistent naming pattern of PSRULE_<PARENT>_<NAME>
. Where <PARENT>
is the parent class and <NAME>
is the specific option.
When setting environment variables:
PSRULE_OUTPUT_FORMAT
could be set to Yaml
.true
, false
, 1
, or 0
and are not case-sensitive. For example PSRULE_CONFIGURATION_AZURE_BICEP_FILE_EXPANSION
could be set to true
.PSRULE_RULE_EXCLUDE
could be set to 'Azure.VM.UseHybridUseBenefit;Azure.VM.Standalone'
.env:\n PSRULE_CONFIGURATION_AZURE_BICEP_FILE_EXPANSION: true\n PSRULE_OUTPUT_FORMAT: Yaml\n PSRULE_RULE_EXCLUDE: 'Azure.VM.UseHybridUseBenefit;Azure.VM.Standalone'\n
variables:\n- name: PSRULE_CONFIGURATION_AZURE_BICEP_FILE_EXPANSION\n value: true\n- name: PSRULE_OUTPUT_FORMAT\n value: Yaml\n- name: PSRULE_RULE_EXCLUDE\n value: 'Azure.VM.UseHybridUseBenefit;Azure.VM.Standalone'\n
$Env:PSRULE_CONFIGURATION_AZURE_BICEP_FILE_EXPANSION = 'true'\n$Env:PSRULE_OUTPUT_FORMAT = 'Yaml'\n$Env:PSRULE_RULE_EXCLUDE = 'Azure.VM.UseHybridUseBenefit;Azure.VM.Standalone'\n
export PSRULE_CONFIGURATION_AZURE_BICEP_FILE_EXPANSION=true\nexport PSRULE_OUTPUT_FORMAT=Yaml\nexport PSRULE_RULE_EXCLUDE='Azure.VM.UseHybridUseBenefit;Azure.VM.Standalone'\n
"},{"location":"setup/configuring-rules/","title":"Configuring rule defaults","text":"PSRule for Azure include several rules that can be configured. Setting these values overrides the default configuration with organization specific values.
To use a configuration option, you must use the minimum version specified. Earlier versions of PSRule for Azure will ignore the configuration option.
Tip
Each of these configuration options are set within the ps-rule.yaml
file. To learn how to set configuration options see Configuring options.
v1.34.0 Azure.AKS.MinNodeCount
This configuration option determines the minimum number of nodes in an AKS clusters across all system node pools.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_AKS_CLUSTER_MINIMUM_SYSTEM_NODES: integer\n
Default:
ps-rule.yaml# YAML: The default AZURE_AKS_CLUSTER_MINIMUM_SYSTEM_NODES configuration option\nconfiguration:\n AZURE_AKS_CLUSTER_MINIMUM_SYSTEM_NODES: 3\n
Example:
ps-rule.yaml# YAML: Set the AZURE_AKS_CLUSTER_MINIMUM_SYSTEM_NODES configuration option to 2\nconfiguration:\n AZURE_AKS_CLUSTER_MINIMUM_SYSTEM_NODES: 2\n
"},{"location":"setup/configuring-rules/#azure_aks_cluster_minimum_version","title":"AZURE_AKS_CLUSTER_MINIMUM_VERSION","text":"v1.12.0 Azure.AKS.Version
This configuration option determines the minimum version of Kubernetes for AKS clusters and node pools. Rules that check the Kubernetes version fail when the version is older than the version specified.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_AKS_CLUSTER_MINIMUM_VERSION: string # A version string\n
Default:
ps-rule.yaml# YAML: The default AZURE_AKS_CLUSTER_MINIMUM_VERSION configuration option\nconfiguration:\n AZURE_AKS_CLUSTER_MINIMUM_VERSION: 1.27.9\n
Example:
ps-rule.yaml# YAML: Set the AZURE_AKS_CLUSTER_MINIMUM_VERSION configuration option to 1.22.4\nconfiguration:\n AZURE_AKS_CLUSTER_MINIMUM_VERSION: 1.22.4\n
"},{"location":"setup/configuring-rules/#azure_aks_cni_minimum_cluster_subnet_size","title":"AZURE_AKS_CNI_MINIMUM_CLUSTER_SUBNET_SIZE","text":"v1.7.0 Azure.AKS.CNISubnetSize
This configuration option determines the minimum subnet size for Azure AKS CNI.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_AKS_CNI_MINIMUM_CLUSTER_SUBNET_SIZE: integer\n
Default:
ps-rule.yaml# YAML: The default AZURE_AKS_CNI_MINIMUM_CLUSTER_SUBNET_SIZE configuration option\nconfiguration:\n AZURE_AKS_CNI_MINIMUM_CLUSTER_SUBNET_SIZE: 23\n
Example:
ps-rule.yaml# YAML: Set the AZURE_AKS_CNI_MINIMUM_CLUSTER_SUBNET_SIZE configuration option to 26\nconfiguration:\n AZURE_AKS_CNI_MINIMUM_CLUSTER_SUBNET_SIZE: 26\n
"},{"location":"setup/configuring-rules/#azure_aks_additional_region_availability_zone_list","title":"AZURE_AKS_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST","text":"This configuration option adds availability zones that are not included in the existing providers. You can use this option to add availability zones that are not included in the default list.
The following providers are supported:
Microsoft.Compute/virtualMachineScaleSets
Microsoft.Network/applicationGateways
Microsoft.Network/publicIPAddresses
Microsoft.ApiManagement/service
Microsoft.Cache/Redis
Microsoft.Cache/redisEnterprise
The following rules and configuration options are supported:
Azure.AKS.AvailabilityZone
- AZURE_AKS_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
Azure.AppGw.AvailabilityZone
- AZURE_APPGW_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
Azure.PublicIP.AvailabilityZone
- AZURE_PUBLICIP_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
Azure.APIM.AvailabilityZone
- AZURE_APIM_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
Azure.Redis.AvailabilityZone
- AZURE_REDISCACHE_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
Azure.RedisEnterprise.Zones
- AZURE_REDISENTERPRISECACHE_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST
Syntax:
ps-rule.yamlconfiguration:\n AZURE_AKS_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST: array\n
Default:
ps-rule.yaml# YAML: The default AZURE_AKS_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST configuration option\nconfiguration:\n AZURE_AKS_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST: []\n
Example:
ps-rule.yaml# YAML: Set the AZURE_AKS_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST configuration option to Antarctica North and Antarctica South, with zones 1, 2, 3.\nconfiguration:\n AZURE_AKS_ADDITIONAL_REGION_AVAILABILITY_ZONE_LIST:\n - location: Antarctica North\n zones:\n - '1'\n - '2'\n - '3'\n - location: Antarctica South\n zones:\n - '1'\n - '2'\n - '3'\n
The above example, both these forms of location are accepted:
Antarctica North
or antarcticanorth
Antarctica South
or antarcticasouth
The rules normalize these location formats so either is accepted in the configuration.
Note
The above are examples for illustration purpose only. At the time of writing, Antarctica North
and Antarctica South
are fictional locations. If they do in the future exist, use this option add them prior to PSRule for Azure support. The above shows examples specific to Azure.AKS.AvailabilityZone
, but behavior is consistent across all supported rules.
This configuration option sets selective platform diagnostic categories to report on being enabled.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_AKS_ENABLED_PLATFORM_LOG_CATEGORIES_LIST: array\n
Default:
ps-rule.yaml# YAML: The default AZURE_AKS_ENABLED_PLATFORM_LOG_CATEGORIES_LIST configuration option\nconfiguration:\n AZURE_AKS_ENABLED_PLATFORM_LOG_CATEGORIES_LIST:\n - cluster-autoscaler\n - kube-apiserver\n - kube-controller-manager\n - kube-scheduler\n - AllMetrics\n
Example:
# YAML: Set the AZURE_AKS_ENABLED_PLATFORM_LOG_CATEGORIES_LIST configuration option to cluster-autoscaler and AllMetrics categories only.\nconfiguration:\n AZURE_AKS_ENABLED_PLATFORM_LOG_CATEGORIES_LIST:\n - cluster-autoscaler\n - AllMetrics\n
"},{"location":"setup/configuring-rules/#azure_automationaccount_enabled_platform_log_categories_list","title":"AZURE_AUTOMATIONACCOUNT_ENABLED_PLATFORM_LOG_CATEGORIES_LIST","text":"This configuration option sets selective platform diagnostic categories to report on being enabled.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_AUTOMATIONACCOUNT_ENABLED_PLATFORM_LOG_CATEGORIES_LIST: array\n
Default:
ps-rule.yaml# YAML: The default AZURE_AUTOMATIONACCOUNT_ENABLED_PLATFORM_LOG_CATEGORIES_LIST configuration option\nconfiguration:\n AZURE_AUTOMATIONACCOUNT_ENABLED_PLATFORM_LOG_CATEGORIES_LIST:\n - JobLogs\n - JobStreams\n - DscNodeStatus\n - AllMetrics\n
Example:
ps-rule.yaml# YAML: Set the AZURE_AUTOMATIONACCOUNT_ENABLED_PLATFORM_LOG_CATEGORIES_LIST configuration option to JobLogs and AllMetrics categories only.\nconfiguration:\n AZURE_AUTOMATIONACCOUNT_ENABLED_PLATFORM_LOG_CATEGORIES_LIST:\n - JobLogs\n - AllMetrics\n
"},{"location":"setup/configuring-rules/#set-the-minimum-maxpods-for-a-node-pool","title":"Set the minimum MaxPods for a node pool","text":"v1.0.0
This configuration option determines the minimum allowed max pods setting per node pool. When an AKS cluster node pool is created, a maxPods
option is used to determine the maximum number of pods for each node in the node pool.
Depending on your workloads it may make sense to change this option:
Syntax:
ps-rule.yamlconfiguration:\n Azure_AKSNodeMinimumMaxPods: integer\n
Default:
ps-rule.yaml# YAML: The default Azure_AKSNodeMinimumMaxPods configuration option\nconfiguration:\n Azure_AKSNodeMinimumMaxPods: 50\n
Example:
ps-rule.yaml# YAML: Set the Azure_AKSNodeMinimumMaxPods configuration option to 30\nconfiguration:\n Azure_AKSNodeMinimumMaxPods: 30\n
"},{"location":"setup/configuring-rules/#azure_aks_cluster_user_pool_minimum_nodes","title":"AZURE_AKS_CLUSTER_USER_POOL_MINIMUM_NODES","text":"v1.34.0 Azure.AKS.MinUserPoolNodes
This configuration option determines the minimum number of nodes in each user node pool for an AKS clusters.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_AKS_CLUSTER_USER_POOL_MINIMUM_NODES: integer\n
Default:
ps-rule.yaml# YAML: The default AZURE_AKS_CLUSTER_USER_POOL_MINIMUM_NODES configuration option\nconfiguration:\n AZURE_AKS_CLUSTER_USER_POOL_MINIMUM_NODES: 3\n
Example:
ps-rule.yaml# YAML: Set the AZURE_AKS_CLUSTER_USER_POOL_MINIMUM_NODES configuration option to 2\nconfiguration:\n AZURE_AKS_CLUSTER_USER_POOL_MINIMUM_NODES: 2\n
"},{"location":"setup/configuring-rules/#azure_aks_cluster_user_pool_excluded_from_minimum_nodes","title":"AZURE_AKS_CLUSTER_USER_POOL_EXCLUDED_FROM_MINIMUM_NODES","text":"v1.34.0 Azure.AKS.MinUserPoolNodes
This configuration option excludes specific user node pools by name from requiring a minimum number of nodes. By default, no user node pools are configured to be excluded.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_AKS_CLUSTER_USER_POOL_EXCLUDED_FROM_MINIMUM_NODES: array\n
Default:
ps-rule.yaml# YAML: The default AZURE_AKS_CLUSTER_USER_POOL_EXCLUDED_FROM_MINIMUM_NODES configuration option\nconfiguration:\n AZURE_AKS_CLUSTER_USER_POOL_EXCLUDED_FROM_MINIMUM_NODES: []\n
Example:
ps-rule.yaml# YAML: Set the AZURE_AKS_CLUSTER_USER_POOL_EXCLUDED_FROM_MINIMUM_NODES configuration option to exclude nodepool2\nconfiguration:\n AZURE_AKS_CLUSTER_USER_POOL_EXCLUDED_FROM_MINIMUM_NODES:\n - nodepool2\n
"},{"location":"setup/configuring-rules/#azure_apim_min_api_version","title":"AZURE_APIM_MIN_API_VERSION","text":"v1.22.0 Azure.APIM.MinAPIVersion
This configuration option sets the minimum API version used for control plane API calls to API Management instances. Configure this option to change the minimum API version, which defaults to '2021-08-01'
.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_APIM_MIN_API_VERSION: string\n
Default:
ps-rule.yaml# YAML: The default AZURE_APIM_MIN_API_VERSION configuration option\nconfiguration:\n AZURE_APIM_MIN_API_VERSION: '2021-08-01'\n
Example:
ps-rule.yaml# YAML: Set the AZURE_APIM_MIN_API_VERSION configuration option to '2021-12-01-preview'\nconfiguration:\n AZURE_APIM_MIN_API_VERSION: '2021-12-01-preview'\n
"},{"location":"setup/configuring-rules/#azure_containerapps_restrict_ingress","title":"AZURE_CONTAINERAPPS_RESTRICT_INGRESS","text":"This configuration specifies whether if external ingress should be enabled or disabled.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_CONTAINERAPPS_RESTRICT_INGRESS: boolean\n
Default:
ps-rule.yaml# YAML: The default AZURE_CONTAINERAPPS_RESTRICT_INGRESS configuration option\nconfiguration:\n AZURE_CONTAINERAPPS_RESTRICT_INGRESS: false\n
Example:
ps-rule.yaml# YAML: Set the AZURE_CONTAINERAPPS_RESTRICT_INGRESS configuration option to enabled\nconfiguration:\n AZURE_CONTAINERAPPS_RESTRICT_INGRESS: true\n
"},{"location":"setup/configuring-rules/#azure_cosmos_defender_per_account","title":"AZURE_COSMOS_DEFENDER_PER_ACCOUNT","text":"This configuration option enables validation for that each Cosmos DB account is associated with a Microsoft Defender for Cosmos DB resource level plan. Configure this option to enable the per account validation, which defaults to false
.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_COSMOS_DEFENDER_PER_ACCOUNT: boolean\n
Default:
ps-rule.yaml# YAML: The default AZURE_COSMOS_DEFENDER_PER_ACCOUNT configuration option\nconfiguration:\n AZURE_COSMOS_DEFENDER_PER_ACCOUNT: false\n
Example:
ps-rule.yaml# YAML: Set the AZURE_COSMOS_DEFENDER_PER_ACCOUNT configuration option to true\nconfiguration:\n AZURE_COSMOS_DEFENDER_PER_ACCOUNT: true\n
"},{"location":"setup/configuring-rules/#azure_deployment_nonsensitive_parameter_names","title":"AZURE_DEPLOYMENT_NONSENSITIVE_PARAMETER_NAMES","text":"v1.31.1 Azure.Deployment.SecureParameter
This configuration overrides the default list of parameter names that are considered sensitive. By setting this configuration option, any parameters names specified are not considered sensitive.
By default, AZURE_DEPLOYMENT_NONSENSITIVE_PARAMETER_NAMES
is not configured.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_DEPLOYMENT_NONSENSITIVE_PARAMETER_NAMES: array\n
Default:
ps-rule.yaml# YAML: The default AZURE_DEPLOYMENT_NONSENSITIVE_PARAMETER_NAMES configuration option\nconfiguration:\n AZURE_DEPLOYMENT_NONSENSITIVE_PARAMETER_NAMES: []\n
Example:
ps-rule.yaml# YAML: Set the AZURE_DEPLOYMENT_NONSENSITIVE_PARAMETER_NAMES configuration option to enabled\nconfiguration:\n AZURE_DEPLOYMENT_NONSENSITIVE_PARAMETER_NAMES:\n - notSecret\n
"},{"location":"setup/configuring-rules/#azure_deployment_sensitive_property_names","title":"AZURE_DEPLOYMENT_SENSITIVE_PROPERTY_NAMES","text":"v1.20.0 Azure.Deployment.AdminUsername
This configuration identifies potentially sensitive properties that should not use hardcoded values. By setting this configuration option, properties with the specified names will generate a failure when a hardcoded value is detected.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_DEPLOYMENT_SENSITIVE_PROPERTY_NAMES: array\n
Default:
ps-rule.yaml# YAML: The default AZURE_DEPLOYMENT_SENSITIVE_PROPERTY_NAMES configuration option\nconfiguration:\n AZURE_DEPLOYMENT_SENSITIVE_PROPERTY_NAMES:\n - adminUsername\n - administratorLogin\n - administratorLoginPassword\n
Example:
ps-rule.yaml# YAML: Set the AZURE_DEPLOYMENT_SENSITIVE_PROPERTY_NAMES configuration option to enabled\nconfiguration:\n AZURE_DEPLOYMENT_SENSITIVE_PROPERTY_NAMES:\n - adminUsername\n - administratorLogin\n - administratorLoginPassword\n - loginName\n
"},{"location":"setup/configuring-rules/#azure_resource_allowed_locations","title":"AZURE_RESOURCE_ALLOWED_LOCATIONS","text":"v1.30.0 Azure.Resource.AllowedRegions
This configuration option specifies a list of allowed locations that resources can be deployed to. Rules that check the location of Azure resources fail when a resource or resource group is created in a different region.
By default, AZURE_RESOURCE_ALLOWED_LOCATIONS
is not configured.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_RESOURCE_ALLOWED_LOCATIONS: array # An array of regions\n
Default:
# YAML: The default Azure_AllowedRegions configuration option\nconfiguration:\n AZURE_RESOURCE_ALLOWED_LOCATIONS: []\n
Example:
ps-rule.yaml# YAML: Set the AZURE_RESOURCE_ALLOWED_LOCATIONS configuration option to Australia East, Australia South East\nconfiguration:\n AZURE_RESOURCE_ALLOWED_LOCATIONS:\n - australiaeast\n - australiasoutheast\n
If you configure the AZURE_RESOURCE_ALLOWED_LOCATIONS
configuration value, also consider setting AZURE_RESOURCE_GROUP
the configuration value to when resources use the location of the resource group.
For example:
ps-rule.yamlconfiguration:\n AZURE_RESOURCE_GROUP:\n location: australiaeast\n
"},{"location":"setup/configuring-rules/#azure_minimumcertificatelifetime","title":"Azure_MinimumCertificateLifetime","text":"This configuration option determines the minimum number of days allowed before certificate expiry. Rules that check certificate lifetime fail when the days remaining before expiry drop below this number.
Syntax:
ps-rule.yamlconfiguration:\n Azure_MinimumCertificateLifetime: integer\n
Default:
# YAML: The default Azure_MinimumCertificateLifetime configuration option\nconfiguration:\n Azure_MinimumCertificateLifetime: 30\n
Example:
ps-rule.yaml# YAML: Set the Azure_MinimumCertificateLifetime configuration option to 90\nconfiguration:\n Azure_MinimumCertificateLifetime: 90\n
"},{"location":"setup/configuring-rules/#azure_linux_os_offers","title":"AZURE_LINUX_OS_OFFERS","text":"v1.20.0
This configurations specifies names of offers corresponding to the Linux OS. It's mostly intended to be used when analyzing templates that use private Linux offerings. Rules that check if a VM or VMSS has Linux OS also validate against the values set by this configuration.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_LINUX_OS_OFFERS: array # An array of offer names\n
Default:
# YAML: The default AZURE_LINUX_OS_OFFERS configuration option\nconfiguration:\n AZURE_LINUX_OS_OFFERS: []\n
Example:
ps-rule.yaml# YAML: Set the AZURE_LINUX_OS_OFFERS configuration option to aLinuxOffer, anotherLinuxOffer\nconfiguration:\n AZURE_LINUX_OS_OFFERS:\n - 'aLinuxOffer'\n - 'anotherLinuxOffer'\n
"},{"location":"setup/configuring-rules/#azure_policy_ignore_list","title":"AZURE_POLICY_IGNORE_LIST","text":"v1.21.0
This configuration option configures a custom list policy definitions to ignore when exporting policy to rules. In addition to the custom list, a built-in list of policies are ignored. The built-in list can be found here.
Configure this option to ignore policy definitions that:
Syntax:
ps-rule.yamlconfiguration:\n AZURE_POLICY_IGNORE_LIST: array\n
Default:
ps-rule.yaml# YAML: The default AZURE_POLICY_IGNORE_LIST configuration option\nconfiguration:\n AZURE_POLICY_IGNORE_LIST: []\n
Example:
ps-rule.yaml# YAML: Add a custom policy definition to ignore\n AZURE_POLICY_IGNORE_LIST:\n - '/providers/Microsoft.Authorization/policyDefinitions/1f314764-cb73-4fc9-b863-8eca98ac36e9'\n - '/providers/Microsoft.Authorization/policyDefinitions/b54ed75b-3e1a-44ac-a333-05ba39b99ff0'\n
"},{"location":"setup/configuring-rules/#azure_policy_rule_prefix","title":"AZURE_POLICY_RULE_PREFIX","text":"This configuration option sets the prefix for names of exported rules. Configure this option to change the prefix, which defaults to Azure
.
This configuration option will be ignored when -Prefix
is used with Export-AzPolicyAssignmentRuleData
.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_POLICY_RULE_PREFIX: string\n
Default:
ps-rule.yaml# YAML: The default AZURE_POLICY_RULE_PREFIX configuration option\nconfiguration:\n AZURE_POLICY_RULE_PREFIX: Azure\n
Example:
ps-rule.yaml# YAML: Override the prefix of exported policy rules\n AZURE_POLICY_RULE_PREFIX: AzureCustomPrefix\n
"},{"location":"setup/configuring-rules/#azure_policy_waiver_max_expiry","title":"AZURE_POLICY_WAIVER_MAX_EXPIRY","text":"This configuration option determines the maximum number of days in the future for a waiver policy exemption.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_POLICY_WAIVER_MAX_EXPIRY: integer\n
Default:
ps-rule.yaml# YAML: The default AZURE_POLICY_WAIVER_MAX_EXPIRY configuration option\nconfiguration:\n AZURE_POLICY_WAIVER_MAX_EXPIRY: 366\n
Example:
ps-rule.yaml# YAML: Set the AZURE_POLICY_WAIVER_MAX_EXPIRY configuration option to 90\nconfiguration:\n AZURE_POLICY_WAIVER_MAX_EXPIRY: 90\n
"},{"location":"setup/configuring-rules/#azure_storage_defender_per_account","title":"AZURE_STORAGE_DEFENDER_PER_ACCOUNT","text":"v1.27.0 Azure.Storage.DefenderCloud
This configuration option enables validation that storage accounts are associated with a resource level Microsoft Defender for Storage plan. By default, this option is set to false
because configuration at the subscription level is recommended. Configure this option to enable the per account validation, which defaults to false
.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_STORAGE_DEFENDER_PER_ACCOUNT: boolean\n
Default:
# YAML: The default AZURE_STORAGE_DEFENDER_PER_ACCOUNT configuration option\nconfiguration:\n AZURE_STORAGE_DEFENDER_PER_ACCOUNT: false\n
Example:
ps-rule.yaml# YAML: Set the AZURE_STORAGE_DEFENDER_PER_ACCOUNT configuration option to true\nconfiguration:\n AZURE_STORAGE_DEFENDER_PER_ACCOUNT: true\n
"},{"location":"setup/configuring-rules/#azure_vm_use_azure_hybrid_benefit","title":"AZURE_VM_USE_AZURE_HYBRID_BENEFIT","text":"v1.33.0 Azure.VM.UseHybridUseBenefit
This configuration option determines whether to check for Azure Hybrid Benefit (AHB) when deploying Windows VMs. When enabled, rules that check for AHB fail when the VM is not configured to use AHB.
To use AHB, you must separately have eligible licenses, such as Windows Server or SQL Server.
By default, this configuration option is set to false
.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_VM_USE_AZURE_HYBRID_BENEFIT: boolean\n
Default:
ps-rule.yamlconfiguration:\n AZURE_VM_USE_AZURE_HYBRID_BENEFIT: false\n
Example:
ps-rule.yaml# Set the configuration option to enabled.\nconfiguration:\n AZURE_VNET_DNS_WITH_IDENTITY: true\n
"},{"location":"setup/configuring-rules/#azure_vnet_dns_with_identity","title":"AZURE_VNET_DNS_WITH_IDENTITY","text":"v1.30.0 Azure.VNET.LocalDNS
Set this configuration option to true
when DNS is deployed within the Identity subscription to avoid false positives.
When deploying Active Directory Domain Services (ADDS) within Azure, you may decide to:
If you are using this configuration, we recommend you set the configuration option AZURE_VNET_DNS_WITH_IDENTITY
to true
. By default, this configuration option is set to false
.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_VNET_DNS_WITH_IDENTITY: boolean\n
Default:
ps-rule.yamlconfiguration:\n AZURE_VNET_DNS_WITH_IDENTITY: false\n
Example:
ps-rule.yaml# Set the configuration option to enabled.\nconfiguration:\n AZURE_VNET_DNS_WITH_IDENTITY: true\n
"},{"location":"setup/configuring-rules/#azure_vnet_subnet_excluded_from_nsg","title":"AZURE_VNET_SUBNET_EXCLUDED_FROM_NSG","text":"v1.33.0 Azure.VNET.UseNSGs
This configuration option excludes subnets from requiring a Network Security Group (NSG). You can use this configuration option to exclude subnets that are specific to your environment. To configure this option, specify a list of subnet names to exclude.
Syntax:
ps-rule.yamlconfiguration:\n AZURE_VNET_SUBNET_EXCLUDED_FROM_NSG: array\n
Default:
ps-rule.yamlconfiguration:\n AZURE_VNET_SUBNET_EXCLUDED_FROM_NSG: []\n
Example:
ps-rule.yaml# Configure two customs subnets to be excluded from NSG checks.\nconfiguration:\n AZURE_VNET_SUBNET_EXCLUDED_FROM_NSG:\n - subnet-1\n - subnet-2\n
"},{"location":"setup/setup-azure-monitor-logs/","title":"Setup Azure Monitor logs","text":"When analyzing Azure resources, you may want to capture the results of each analysis run. Azure Monitor provides a central storage location for log data through Log Analytics workspaces. Centrally storing PSRule results enables the following scenarios:
Abstract
This topic covers setting up PSRule to log rule results into a Log Analytics workspace.
"},{"location":"setup/setup-azure-monitor-logs/#logging-into-a-log-analytics-workspace","title":"Logging into a Log Analytics workspace","text":"Logging of PSRule results into a workspace is done using the PSRule for Azure Monitor module. PSRule for Azure Monitor extends the PSRule pipeline to import results into the specified workspace.
Once configured, PSRule will log results into the PSRule_CL
custom log table of the chosen workspace.
Info
Integration between PSRule and Azure Monitor is done by means of a convention. Conventions extend the pipeline to be able to upload results after rules have run.
"},{"location":"setup/setup-azure-monitor-logs/#setting-environment-variables","title":"Setting environment variables","text":"PSRule for Azure Monitor requires a Log Analytics workspace to import results into. To configure the workspace to import results to the following environment variables must be set.
PSRULE_CONFIGURATION_MONITOR_WORKSPACE_ID
- The unique ID (GUID) for the workspace to import results.PSRULE_CONFIGURATION_MONITOR_WORKSPACE_KEY
- Either the primary or secondary key of the workspace.How to set these environment variables is covered in the next section for GitHub Actions and Azure Pipelines.
Tip
Both the workspace ID and keys can be found under the Agents management settings of the workspace.
"},{"location":"setup/setup-azure-monitor-logs/#configuring-your-pipeline","title":"Configuring your pipeline","text":"The convention that imports PSRule analysis results is not executed by default. To enable, reference the Monitor.LogAnalytics.Import
convention in your analysis pipeline.
GitHub Action
Import analysis results into Azure Monitor with GitHub Actions by:
PSRule.Monitor
module.Monitor.LogAnalytics.Import
convention.MONITOR_WORKSPACE_ID
and MONITOR_WORKSPACE_KEY
.Install the latest stable module versions.
- name: Analyze Azure template files\n uses: microsoft/ps-rule@v2.9.0\n with:\n modules: PSRule.Rules.Azure,PSRule.Monitor\n conventions: Monitor.LogAnalytics.Import\n env:\n # Define environment variables using GitHub encrypted secrets\n PSRULE_CONFIGURATION_MONITOR_WORKSPACE_ID: ${{ secrets.MONITOR_WORKSPACE_ID }}\n PSRULE_CONFIGURATION_MONITOR_WORKSPACE_KEY: ${{ secrets.MONITOR_WORKSPACE_KEY }}\n
Install the latest stable or pre-release module versions.
- name: Analyze Azure template files\n uses: microsoft/ps-rule@v2.9.0\n with:\n modules: PSRule.Rules.Azure,PSRule.Monitor\n conventions: Monitor.LogAnalytics.Import\n prerelease: true\n env:\n # Define environment variables using GitHub encrypted secrets\n PSRULE_CONFIGURATION_MONITOR_WORKSPACE_ID: ${{ secrets.MONITOR_WORKSPACE_ID }}\n PSRULE_CONFIGURATION_MONITOR_WORKSPACE_KEY: ${{ secrets.MONITOR_WORKSPACE_KEY }}\n
Important
Environment variables can be configured in the workflow or from a secret. To keep MONITOR_WORKSPACE_KEY
secure, use an encrypted secret.
Extension
Import analysis results into Azure Monitor with Azure Pipelines by:
ps-rule-assert
task in pipeline steps.PSRule.Monitor
module.Monitor.LogAnalytics.Import
convention.MONITORWORKSPACEID
and MONITORWORKSPACEKEY
.Install the latest stable module versions.
- task: ps-rule-assert@2\n displayName: Analyze Azure template files\n inputs:\n modules: PSRule.Rules.Azure,PSRule.Monitor\n conventions: Monitor.LogAnalytics.Import\n env:\n # Define environment variables within Azure Pipelines\n PSRULE_CONFIGURATION_MONITOR_WORKSPACE_ID: $(MONITORWORKSPACEID)\n PSRULE_CONFIGURATION_MONITOR_WORKSPACE_KEY: $(MONITORWORKSPACEKEY)\n
Install the latest stable or pre-release module versions.
- task: ps-rule-install@2\n displayName: Install PSRule for Azure (pre-release)\n inputs:\n module: PSRule.Rules.Azure\n prerelease: true\n\n- task: ps-rule-install@2\n displayName: Install PSRule for Azure Monitor (pre-release)\n inputs:\n module: PSRule.Monitor\n prerelease: true\n\n- task: ps-rule-assert@2\n displayName: Analyze Azure template files\n inputs:\n modules: PSRule.Rules.Azure,PSRule.Monitor\n conventions: Monitor.LogAnalytics.Import\n env:\n # Define environment variables within Azure Pipelines\n PSRULE_CONFIGURATION_MONITOR_WORKSPACE_ID: $(MONITORWORKSPACEID)\n PSRULE_CONFIGURATION_MONITOR_WORKSPACE_KEY: $(MONITORWORKSPACEKEY)\n
Important
Variables can be configured in YAML, on the pipeline, or referenced from a defined variable group. To keep MONITORWORKSPACEKEY
secure, use a variable group linked to an Azure Key Vault.
Continue reading for some sample resources you can try once this integration is setup Azure Monitor integration.
"},{"location":"setup/setup-azure-monitor-logs/#log-analytics-queries","title":"Log Analytics Queries","text":""},{"location":"setup/setup-azure-monitor-logs/#results-with-annotations","title":"Results with annotations","text":"Kusto// Show extended info\nPSRule_CL\n| where TimeGenerated > ago(30d)\n| extend Pillar = tostring(parse_json(Annotations_s).pillar)\n| extend Link = tostring(parse_json(Annotations_s).[\"online version\"])\n
"},{"location":"setup/setup-azure-monitor-logs/#summarize-results-by-run","title":"Summarize results by run","text":"Kusto// Group by run\nPSRule_CL\n| where TimeGenerated > ago(30d)\n| summarize Pass=countif(Outcome_s == \"Pass\"), Fail=countif(Outcome_s == \"Fail\") by RunId_s\n
"},{"location":"setup/setup-azure-monitor-logs/#querying-the-data","title":"Querying The Data","text":"Once the results have been published to the Log Analytics workspace, they can be queried by executing results against the PSRule_CL
table (under Custom Logs). For more information on how to write Log Analytics querys, review the Log Analytics tutortial.
Workbook
A sample Azure Monitor Workbook is available in the PSRule for Azure GitHub repository. This workbook can be imported directly into Azure Monitor and used as a foundation to build from. Review the Workbook creation tutorial for instructions on how to work with the sample Workbook.
"},{"location":"setup/setup-bicep/","title":"Setup Bicep","text":"To expand Azure resources for analysis from Bicep source files the Bicep CLI is required. The Bicep CLI is already installed on hosted runners and agents used by GitHub Actions and Azure Pipelines.
Abstract
This topic covers setting up support for analyzing Azure resources within Bicep source files.
"},{"location":"setup/setup-bicep/#installing-bicep-cli","title":"Installing Bicep CLI","text":"PSRule for Azure requires a minimum of Bicep CLI version 0.4.451. However the features you use within Bicep may require a newer version of the Bicep CLI.
You may need to install or upgrade the Bicep CLI in the following scenarios:
The Bicep CLI can be installed on MacOS, Linux, and Windows. For installation instructions see Setup your Bicep development environment.
Tip
When installing Bicep using the Azure CLI, Bicep is not added to the PATH
environment variable. To use PSRule for Azure with the Azure CLI set the PSRULE_AZURE_BICEP_USE_AZURE_CLI
to true
. Setting this environment variable is explained in the next section.
When expanding Bicep files, the path to the Bicep CLI binary is required. By default, the PATH
environment variable will be used to discover the binary path. When using this option, add the sub-directory containing the Bicep binary to the environment variable.
Alternatively, the path can be overridden by setting the PSRULE_AZURE_BICEP_PATH
environment variable. When setting PSRULE_AZURE_BICEP_PATH
specify the full path to the Bicep binary including the file name. File names used for Bicep binaries include bicep
, or bicep.exe
.
Example
Bashexport PSRULE_AZURE_BICEP_PATH='/usr/local/bin/bicep'\n
PowerShell$Env:PSRULE_AZURE_BICEP_PATH = '/usr/local/bin/bicep';\n
GitHub Actionsenv:\n PSRULE_AZURE_BICEP_PATH: '/usr/local/bin/bicep'\n
Azure Pipelinesvariables:\n- name: PSRULE_AZURE_BICEP_PATH\n value: '/usr/local/bin/bicep'\n
"},{"location":"setup/setup-bicep/#using-azure-cli","title":"Using Azure CLI","text":"By default, PSRule for Azure uses the Bicep CLI directly. An additional option is to use the Azure CLI to invoke the Bicep CLI. When using this option the required version of the CLI must be installed prior to using PSRule for Azure. This is explained in Setup your Bicep development environment.
To enable this option, set the PSRULE_AZURE_BICEP_USE_AZURE_CLI
environment variable to true
.
Example
Bashexport PSRULE_AZURE_BICEP_USE_AZURE_CLI=true\n
PowerShell$Env:PSRULE_AZURE_BICEP_USE_AZURE_CLI = 'true'\n
GitHub Actionsenv:\n PSRULE_AZURE_BICEP_USE_AZURE_CLI: true\n
Azure Pipelinesvariables:\n- name: PSRULE_AZURE_BICEP_USE_AZURE_CLI\n value: true\n
"},{"location":"setup/setup-bicep/#additional-arguments","title":"Additional arguments","text":"For configuration, additional arguments can be passed to the Bicep CLI. This is intended to improve forward compatibility with Bicep CLI.
To configure additional arguments, set the PSRULE_AZURE_BICEP_ARGS
environment variable.
Docs
PSRule for Azure can automatically expand Bicep source files. When enabled, PSRule for Azure automatically expands and analyzes Azure resource from .bicep
files.
To enabled this feature, set the Configuration.AZURE_BICEP_FILE_EXPANSION
to true
. This option can be set within the ps-rule.yaml
file.
configuration:\n # Enable automatic expansion of bicep source files.\n AZURE_BICEP_FILE_EXPANSION: true\n
Tip
If you deploy Bicep code using JSON parameter files this option does not need to be set. Set Configuration.AZURE_PARAMETER_FILE_EXPANSION
to true
instead. See Using parameter files and By metadata for more information.
Docs
In certain environments it may be necessary to increase the default timeout for building Bicep files. This can occur if your Bicep deployments are:
If you are experiencing timeout errors you can increase the default timeout of 5 seconds. To configure the timeout, set Configuration.AZURE_BICEP_FILE_EXPANSION_TIMEOUT
to the timeout in seconds.
configuration:\n # Enable automatic expansion of bicep source files.\n AZURE_BICEP_FILE_EXPANSION: true\n\n # Configure the timeout for bicep build to 15 seconds.\n AZURE_BICEP_FILE_EXPANSION_TIMEOUT: 15\n
"},{"location":"setup/setup-bicep/#checking-bicep-version","title":"Checking Bicep version","text":"v1.25.0
To use Bicep files with PSRule for Azure:
It may not always be clear which version of Bicep CLI is being used if you have multiple versions installed. Additionally, the version installed in your CI/ CD pipeline may not be the same as your local development environment.
You can enable checking the Bicep CLI version during initialization. To enable this feature, set the Configuration.AZURE_BICEP_CHECK_TOOL
option to true
. Additionally, you can set the minimum version required using the Configuration.AZURE_BICEP_MINIMUM_VERSION
option.
configuration:\n # Enable Bicep CLI checks.\n AZURE_BICEP_CHECK_TOOL: true\n\n # Optionally, configure the minimum version of the Bicep CLI.\n AZURE_BICEP_MINIMUM_VERSION: '0.16.2'\n
"},{"location":"setup/setup-bicep/#configuring-minimum-version","title":"Configuring minimum version","text":"v1.25.0
The Azure Bicep CLI is updated regularly, with new features and bug fixes. You must use a version of the Bicep CLI that supports the features you are using. If you attempt to use a feature that is not supported by the Bicep CLI, expansion will fail with a BCP error.
Tip
It may not always be clear which version of Bicep CLI is being used if you have multiple versions installed. Using the Bicep CLI via az bicep
is not the default, and you may need to set additional options to use it.
To ensure you are using the correct version of the Bicep CLI, you can configure the minimum version required. If an earlier version is detected, PSRule for Azure will generate an error. To configure the minimum version, set the Configuration.AZURE_BICEP_MINIMUM_VERSION
option. By default, the minimum version is set to 0.4.451
.
configuration:\n # Enable Bicep CLI checks.\n AZURE_BICEP_CHECK_TOOL: true\n\n # Configure the minimum version of the Bicep CLI.\n AZURE_BICEP_MINIMUM_VERSION: '0.16.2'\n
Important
The Configuration.AZURE_BICEP_CHECK_TOOL
must be set to true
for this option to take effect.
Tip
For troubleshooting Bicep compilation errors see Bicep compile errors.
"},{"location":"setup/setup-bicep/#recommended-content","title":"Recommended content","text":"To support analysis of in-flight resources, the configuration data must be exported from Azure. This spec documents this mode of operation.
"},{"location":"specs/inflight-export-spec/#requirements","title":"Requirements","text":"The requirements for this feature/ mode of operation include:
Additonally some non-function requirements include:
@VLZ7r@d( zfA)VQ?{J0x03tlsMZr{V&qhsLq5mV*-uKz}trZ(pka9zmAj5x039kmmi9q~iYjoma zjOka(k<}qYM4HnPnF{rQ#Q=I%#kKN|qO;AB%D3hf-|F9e8)&r_o2q{al)=-?$gvQj z{suI+TAH%f^B%Kxpxt5#A0kxV6tOUKsIpEM;zu*%j%Q z9$did!6m#NT*B+YCA=P7!t23%U_F=(va1Bwu}p=O%p?PC-EHZ_!Pm#exh<)Q05dsy z;v^+0kn@FKGo@tK+7!%_jMi(xg=gA>GcEj+Y$c>{=p-5O${>GZ7 mw2CfyblVJ3f6_E4cpKW7D@%KoKdhAD^A_~8|T1%)*fC #<0`=<=m1+unrhBuzXG)* zCQ&HC#Jlz4kvSTvywpNDi;7XLyj2bCWq!_*ew7P1)f<0c0Jqgf{P0SVB135J=1Y`b z48K6QYx<19B0T#4v^{ iDRP-#pI{-nIOIfG zvDrG fGJpvb|uri>gi!+q1P5fvdLZoDJpw4n$P7TPg~JQ|LvoSA%j zg-UQ2ic<*nG$jC7=-3AGa+FSH;meRLH=^|VY;k`vVu)D=kiqRD1Ge{S1Ts#n1rJAC zPo*%xB%<6BuvT=DvVqi94olJIY}_+h5$;&rESKpO;}3p7pc%T;YFLOEVoWuMQ2sl* z{V}Vg6ARiz!Z7xm-j3l;D%faQ5WcaSu9yWzFgmZe>zAd`k4&O-#Nb-AC|R{?Sddq$ zmSulQrhpz0r@5B61X+D4RXZ4%7}>}hAmQFMy1&E(7~^hsW!bdz22Wc&U__CXe4qg@ zG&^wMt4CUyO;~0fafeNkeZB()81Lc;&ekN|mUn@SpeEsZSD?mUuR@@fk=F79FRfns z+pqmB#T7qv(*Q0ctr@ax3VcdbBivaE@#KFDn&4~y8drWV{741EJBMaiz_ytQ1Rfwk zABCFXiOb5u+`|4VjN|4o(>Xz-gx8FXu1eGq=_+lI&7}jwS8X0_$zZMSjLf6p{^4TL zU$2EiJvu!hkvq1xw+b917*QAC3^AO^pU?=EN~Z8BmeULzVm?|TXGk1D(wj6A5U+n3 zT>uKVK F)YkyewJRY}3{O5+D>90l ze@&NFi;5D4g^ahkL}*Idti$1u36iIBx~NN#z|X>u9EWsgBSKUN9VZ6U{zwB~33^2F ztMZN354a^7SNF-JC@L4U1X6x4O&EU&)ace=I8VB20Az+>^rFg+>!b(iy~lBFv~okO zA+4!HPbhEfCfLOo&rsTYJmfg ;| RC=rsUCDy7~Rq}=iDX9XIh zI$@dPBivSwOw)B3pQNl@gHrc11m|hOA}KR|k~z$bxED0Q 6z>Y?j-It&yOdkm%*uPI;U^j^)1HMwg)~Wr3FeA6sc?2M+#db%G z%rOT(rS2>Z7~g`15ub5@wud@0fOjW)4gzZoKBIu&_F|b+_+77_q2PDEdWM7D{i^da z!X{$+){2dy998otdWnA>nCdcnk|x%P+j;W{QaRmS-WdT-7cPN@@DETm{J?-3<~abs zj{thl`vVB-t*{4x=9nLTLS=gGh9n6ytT4Tb;`#xPfjW`A=&*54FMD@IIA{%%-;f0l zg`;&oNN9DjG-9*C%+;AqlYuVE%F!g3lx-`Q>z%?TxmTE3ZJvK1hO`Nffu6?V5kiz8 zg7e8)=y^8uJGPX1S3d B|y(na{6V?YTnh3%#L8VtI! z)K>uJl{Xxf3zxoEB{B_e;I<=Z%F)ngmEYyFY>G^9KOZfj^;;|9bW`3aINcDFpl0tr z`!Y@X{UNmQw@QERfdOK$a%&QN+pxxn!7_XXf^8SpD3MrFH4CsERm%@ %;c{iKdJ%*+3%G2UJ+=goq0A+`kyn{`#x*=)qbK@eoxLb zT^Y>V0Ba6wH5bf*s<9^+lG=L{yd4cxim4w0!{pMi&~JZ-NmLHhMYTzuOPUnT&_$q2 z*1XzBfion_jVPVQZ06MR#6dB7qM{5Ln{nWLWx}snxcASb+PaM);6U1Q0@P^QDMbV! zwG$lpxY`Lz1i`geXrLo(Cp>Y4*-n6PV{Io8*a5c_5Zr)OYQ&>=vATQCaQ&1z$!(HG zkqv!-8P0#RDO-_*hL~97i0A=hCN{=vN|!GU%>u9G;92XT_9q$Wx(} iN@` zWE?6-+rfUhFENLLa$%$JCK{3m;#1E-phHs)%8Y+K&8X03zaSezAvrLLP^h+eCqHOB zt&xAORc2+X4X`>i-rbzsPMZhZ1C9m;_>#^VV5A(G(g;iFx^Y4hws6onW$SdR<^+)P z1#M89vK>&ov$SLzXolKd#q~CH psaJnZND?*k
XGh=ec48_8O8&qyVu0?199!4Yzr9r;Lregp$d0PTl^Q4tOBkq4(8m8 nhCAGnfn;c+5^rvZZvJUqTMZtpVY8^mk #nm51vUF78?gnu!Z9w z>84sFG(yeT(>;?_B*T;OEfuk_IHT1DesMnV;7_wIak$$!qkzHQV!8+LJ52YWUcp#A zDA=Ro{o{cyfRf{&3AT hg{y)xP#W61(pr29$Yaic=k|%ir?O=ZGbglDC`4rPskQw-~oSdRX7lU z&!J5GAoN{%#=K2UiYZP5t=0l{I<@UlaSc3RT}ab0vh+q58h1Z#QglDl9#sD9%e1N5 z4J#@tLmihKJ^6*yqDChJ##UD{pKEtTnbTznYaKQ1nI&k$L=SLR=6*9nokw?;ZuTo9 za{u6p6s?8BC2328!s-M%9$9~e8~5_E<2#%l0^L0I2+*HDxRvAyqOdXMqh*MHg_F;$ zS}Ag{6kRn5I7VFyKAdN;0I;i45I&`lB*z>sK_=8j67mFU6c~CMc`J3EjX`&WaVXAJ z#KWF|I|}1uwD`GMKWO8V24+ed#`nMo$aCpFo%g*$JW}%&86zH@@HBtWO7WFKI|skr z#nA2K2m{(L BRpW1 E<`FPy=Jnm|cJM9xqX(ZT530VcVs3ut@6LcJC}osn1J*V-q!)4qdN9c(-S1 zD(g@g#-!VxH>d=Y!aJZh#3V{Hm6r(N#zB;%v6s^0c%Cn1|57o-loJY;U_oIGf~miM z2>{f!*aAi_EMnwB5;Lm#+Iti^>7KWB1c<%X2(LqtreGL#nSOu&CuOO}y+vchs)D&j z>{Y?Hj6X29MM-RVm0@S 2abejqEq|*IqOC3$29HrYBKuXE{Zv7g-FcOXBuSsI?TEtqc09jq8PH|Nr9G R-~0#m=|A>hBBpnl0RZ_i;SK-*