last sync: 2022-Sep-23 16:35:49 UTC

Azure Policy definition

Public network access should be disabled for PostgreSQL flexible servers

Name Public network access should be disabled for PostgreSQL flexible servers
Azure Portal
Id 5e1de0e3-42cb-4ebc-a86d-61d0c619ca48
Version 3.0.0
details on versioning
Category SQL
Microsoft docs
Description Disabling the public network access property improves security by ensuring your Azure Database for PostgreSQL flexible servers can only be accessed from a private endpoint. This configuration strictly disables access from any public address space outside of Azure IP range and denies all logins that match IP or virtual network-based firewall rules.
Mode Indexed
Type BuiltIn
Preview FALSE
Deprecated FALSE
Effect Default: Audit
Allowed: (Audit, Deny, Disabled)
Used RBAC Role none
Rule Aliases IF (3)
Alias Namespace ResourceType DefaultPath Modifiable
Microsoft.DBforPostgreSQL/flexibleServers/createMode Microsoft.DBforPostgreSQL flexibleServers properties.createMode false
Microsoft.DBforPostgreSQL/flexibleServers/network.delegatedSubnetResourceId Microsoft.DBforPostgreSQL flexibleServers false
Microsoft.DBforPostgreSQL/flexibleServers/network.privateDnsZoneArmResourceId Microsoft.DBforPostgreSQL flexibleServers false
Rule ResourceTypes IF (1)
Date/Time (UTC ymd) (i) Change type Change detail
2022-04-22 19:50:54 change Major (2.0.0 > 3.0.0)
2022-02-18 17:44:00 change Major (1.0.0 > 2.0.0)
2020-10-20 13:29:33 add 5e1de0e3-42cb-4ebc-a86d-61d0c619ca48
Used in Initiatives
Initiative DisplayName Initiative Id Initiative Category State Type
[Preview]: CMMC 2.0 Level 2 4e50fd13-098b-3206-61d6-d1d78205cb45 Regulatory Compliance Preview BuiltIn
[Preview]: RMIT Malaysia 97a6d4f1-3bed-4cf4-ac5b-0e444c0408d6 Regulatory Compliance Preview BuiltIn
Audit Public Network Access f1535064-3294-48fa-94e2-6e83095a5c08 SDN GA BuiltIn
CMMC Level 3 b5629c75-5c77-4422-87b9-2509e680f8de Regulatory Compliance GA BuiltIn
Public network access should be disabled for PaaS services Deny-PublicPaaSEndpoints Network GA ALZ
JSON Changes