last sync: 2023-Nov-30 18:20:17 UTC

Azure Landing Zones (ALZ) Policy definition

Azure Cache for Redis only secure connections should be enabled

Source Repository Azure Landing Zones (ALZ) GitHub
JSON Deny-Redis-http
Display name Azure Cache for Redis only secure connections should be enabled
Id Deny-Redis-http
Version 1.0.0
Details on versioning
Category Cache
Description Audit enabling of only connections via SSL to Azure Cache for Redis. Validate both minimum TLS version and enableNonSslPort is disabled. Use of secure connections ensures authentication between the server and the service and protects data in transit from network layer attacks such as man-in-the-middle, eavesdropping, and session-hijacking
Mode Indexed
Type Custom Azure Landing Zones (ALZ)
Preview False
Deprecated False
Effect Default
Deny
Allowed
Audit, Deny, Disabled
RBAC role(s) none
Rule aliases IF (2)
Alias Namespace ResourceType DefaultPath Modifiable
Microsoft.Cache/Redis/enableNonSslPort Microsoft.Cache Redis properties.enableNonSslPort true
Microsoft.Cache/Redis/minimumTlsVersion Microsoft.Cache Redis properties.minimumTlsVersion true
Rule resource types IF (1)
Microsoft.Cache/redis
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State
Deny or Deploy and append TLS requirements and SSL enforcement on resources without Encryption in transit Enforce-EncryptTransit Encryption GA
History none
JSON compare n/a
JSON
EPAC