last sync: 2025-Apr-29 17:15:47 UTC

CIS Microsoft Azure Foundations Benchmark v2.0.0

Azure BuiltIn Policy Initiative (PolicySet)

Source Azure Portal
Display nameCIS Microsoft Azure Foundations Benchmark v2.0.0
Id06f19060-9e68-4070-92ca-f15cc126059e
Version1.5.0
Details on versioning
Versioning Versions supported for Versioning: 6
1.5.0
1.4.0
1.3.0
1.2.0
1.1.0
1.0.0
Built-in Versioning [Preview]
CategoryRegulatory Compliance
Microsoft Learn
DescriptionThe Center for Internet Security (CIS) is a nonprofit entity whose mission is to 'identify, develop, validate, promote, and sustain best practice solutions for cyberdefense.' CIS benchmarks are configuration baselines and best practices for securely configuring a system. These policies address a subset of CIS Microsoft Azure Foundations Benchmark v2.0.0 controls. For more information, visit https://aka.ms/cisazure200-initiative
Cloud environmentsAzureCloud = true
AzureChinaCloud = unknown
AzureUSGovernment = unknown
Available in AzUSGovUnknown, no evidence if PolicySet definition is/not available in AzureUSGovernment
TypeBuiltIn
DeprecatedFalse
PreviewFalse
Policy-used summary
Policy types Policy states Policy categories
Total Policies: 193
Builtin Policies: 193
Static Policies: 0
Deprecated: 3
GA: 202
20 categories:
App Service: 20
Azure Update Manager: 1
Batch: 1
Compute: 3
Cosmos DB: 3
Data Lake: 2
Event Hub: 1
General: 1
Internet of Things: 1
Key Vault: 8
Logic Apps: 1
Monitoring: 16
Network: 4
Regulatory Compliance: 93
Search: 1
Security Center: 18
Service Bus: 1
SQL: 20
Storage: 9
Stream Analytics: 1
Policy-used
Policy DisplayName Policy Id Category Version Versioning Effect Roles# Roles State policy in AzUSGov
[Deprecated]: App Service apps should have 'Client Certificates (Incoming client certificates)' enabled 5bb220d9-2698-4ee4-8404-b9c30c9df609 App Service 3.1.0 (3.1.0-deprecated) 1x
3.1.0
Default
Disabled
Allowed
Audit, Disabled
0 Deprecated unknown
[Deprecated]: Azure Defender for DNS should be enabled bdc59948-5574-49b3-bb91-76b7c986428d Security Center 1.1.0 (1.1.0-deprecated) 2x
1.1.0, 1.0.0
Default
Disabled
Allowed
AuditIfNotExists, Disabled
0 Deprecated unknown
[Deprecated]: Function apps should have 'Client Certificates (Incoming client certificates)' enabled eaebaea7-8013-4ceb-9d14-7eb32271373c App Service 3.1.0 (3.1.0-deprecated) 1x
3.1.0
Default
Disabled
Allowed
Audit, Disabled
0 Deprecated true
Adhere to retention periods defined 1ecb79d7-1a06-9a3b-3be8-f434d04d1ec1 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Adopt biometric authentication mechanisms 7d7a8356-5c34-9a95-3118-1424cfaf192a Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Alert personnel of information spillage 9622aaa9-5c49-40e2-5bf8-660b7cd23deb Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
All flow log resources should be in enabled state 27960feb-a23c-4577-8d36-ef8b5f35e0be Network 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Disabled
0 GA unknown
An activity log alert should exist for specific Administrative operations b954148f-4c11-4c38-8221-be76711e194a Monitoring 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
An activity log alert should exist for specific Policy operations c5447c04-a4d7-4ba8-a263-c9ee321a6858 Monitoring 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
An activity log alert should exist for specific Security operations 3b980d31-7904-4bb7-8575-5665739a8052 Monitoring 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
An Azure Active Directory administrator should be provisioned for SQL servers 1f314764-cb73-4fc9-b863-8eca98ac36e9 SQL 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
App Service app slots that use PHP should use a specified 'PHP version' f466b2a6-823d-470d-8ea5-b031e72d79ae App Service 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
App Service app slots that use Python should use a specified 'Python version' 9c014953-ef68-4a98-82af-fd0f6b2306c8 App Service 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
App Service apps should have authentication enabled 95bccee9-a7f8-4bec-9ee9-62c3473701fc App Service 2.0.1 1x
2.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
App Service apps should have resource logs enabled 91a78b24-f231-4a8a-8da9-02c35b2b6510 App Service 2.0.1 1x
2.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
App Service apps should only be accessible over HTTPS a4af4a39-4135-47fb-b175-47fbdf85311d App Service 4.0.0 1x
4.0.0
Default
Audit
Allowed
Audit, Disabled, Deny
0 GA true
App Service apps should require FTPS only 4d24b6d4-5e53-4a4f-a7f4-618fa573ee4b App Service 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
App Service apps should use latest 'HTTP Version' 8c122334-9d20-4eb8-89ea-ac9a705b74ae App Service 4.0.0 1x
4.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
App Service apps should use managed identity 2b9ad585-36bc-4615-b300-fd4435808332 App Service 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
App Service apps should use the latest TLS version f0e6e85b-9b9f-4a4b-b67b-f730d42f1b0b App Service 2.1.0 2x
2.1.0, 2.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
App Service apps that use PHP should use a specified 'PHP version' 7261b898-8a84-4db8-9e04-18527132abb3 App Service 3.2.0 1x
3.2.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
App Service apps that use Python should use a specified 'Python version' 7008174a-fd10-4ef0-817e-fc820a951d73 App Service 4.1.0 1x
4.1.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Audit flow logs configuration for every virtual network 4c3c6c5f-0d47-4402-99b8-aa543dd8bcee Network 1.0.1 2x
1.0.1, 1.0.0
Default
Audit
Allowed
Audit, Disabled
0 GA unknown
Audit privileged functions f26af0b1-65b6-689a-a03f-352ad2d00f98 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Audit usage of custom RBAC roles a451c1ef-c6ca-483d-87ed-f49761e3ffb5 General 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Disabled
0 GA true
Audit user account status 49c23d9b-02b0-0e42-4f94-e8cef1b8381b Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Audit VMs that do not use managed disks 06a78e20-9358-41c9-923c-fb736d382a4d Compute 1.0.0 1x
1.0.0
Fixed
audit
0 GA true
Auditing on SQL server should be enabled a6fb4358-5bf4-4ad7-ba82-2cd2f41ce5e9 SQL 2.0.0 1x
2.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Authenticate to cryptographic module 6f1de470-79f3-1572-866e-db0771352fc8 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Authorize access to security functions and information aeed863a-0f56-429f-945d-8bb66bd06841 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Authorize and manage access 50e9324a-7410-0539-0662-2c1e775538b7 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Authorize remote access dad8a2e9-6f27-4fc2-8933-7e99fe700c9c Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Automate account management 2cc9c165-46bd-9762-5739-d2aae5ba90a1 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Azure Cosmos DB accounts should have firewall rules 862e97cf-49fc-4a5c-9de4-40d4e2e7c8eb Cosmos DB 2.1.0 2x
2.1.0, 2.0.0
Default
Deny
Allowed
Audit, Deny, Disabled
0 GA true
Azure Defender for App Service should be enabled 2913021d-f2fd-4f3d-b958-22354e2bdbcb Security Center 1.0.3 1x
1.0.3
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Azure Defender for Azure SQL Database servers should be enabled 7fe3b40f-802b-4cdd-8bd4-fd799c948cc2 Security Center 1.0.2 1x
1.0.2
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure Defender for Key Vault should be enabled 0e6763cc-5078-4e64-889d-ff4d9a839047 Security Center 1.0.3 1x
1.0.3
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Azure Defender for open-source relational databases should be enabled 0a9fbe0d-c5c4-4da8-87d8-f4fd77338835 Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Azure Defender for Resource Manager should be enabled c3d20c29-b36d-48fe-808b-99a87530ad99 Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure Defender for servers should be enabled 4da35fc9-c9e7-4960-aec9-797fe7d9051d Security Center 1.0.3 1x
1.0.3
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure Defender for SQL servers on machines should be enabled 6581d072-105e-4418-827f-bd446d56421b Security Center 1.0.2 1x
1.0.2
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Azure Defender for SQL should be enabled for unprotected Azure SQL servers abfb4388-5bf4-4ad7-ba82-2cd2f41ceae9 SQL 2.0.1 1x
2.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure Defender for SQL should be enabled for unprotected SQL Managed Instances abfb7388-5bf4-4ad7-ba99-2cd2f41cebb9 SQL 1.0.2 1x
1.0.2
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure Key Vault should use RBAC permission model 12d4fa5e-1f9f-4c21-97a9-b99b3c6611b5 Key Vault 1.0.1 2x
1.0.1, 1.0.0-preview
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA unknown
Azure Key Vaults should use private link a6abeaec-4d90-4a02-805f-6b26c4d3fbe9 Key Vault 1.2.1 1x
1.2.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Block untrusted and unsigned processes that run from USB 3d399cf3-8fc6-0efc-6ab0-1412f1198517 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Configure actions for noncompliant devices b53aa659-513e-032c-52e6-1ce0ba46582f Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Configure Azure Audit capabilities a3e98638-51d4-4e28-910a-60e98c1a756f Regulatory Compliance 1.1.1 1x
1.1.1
Default
Manual
Allowed
Manual, Disabled
0 GA true
Configure workstations to check for digital certificates 26daf649-22d1-97e9-2a8a-01b182194d59 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Connection throttling should be enabled for PostgreSQL database servers 5345bb39-67dc-4960-a1bf-427e16b9a0bd SQL 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Control information flow 59bedbdc-0ba9-39b9-66bb-1d1c192384e6 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Control physical access 55a7f9a0-6397-7589-05ef-5ed59a8149e7 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Correlate Vulnerability scan information e3905a3c-97e7-0b4f-15fb-465c0927536f Regulatory Compliance 1.1.1 1x
1.1.1
Default
Manual
Allowed
Manual, Disabled
0 GA unknown
Cosmos DB database accounts should have local authentication methods disabled 5450f5bd-9c72-4390-a9c4-a7aba4edfdd2 Cosmos DB 1.1.0 1x
1.1.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
CosmosDB accounts should use private link 58440f8a-10c5-4151-bdce-dfbaad4a20b7 Cosmos DB 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Disabled
0 GA true
Define a physical key management process 51e4b233-8ee3-8bdc-8f5f-f33bd0d229b7 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Define cryptographic use c4ccd607-702b-8ae6-8eeb-fc3339cd4b42 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Define organizational requirements for cryptographic key management d661e9eb-4e15-5ba1-6f02-cdc467db0d6c Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Design an access control model 03b6427e-6072-4226-4bd9-a410ab65317e Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Detect network services that have not been authorized or approved 86ecd378-a3a0-5d5b-207c-05e6aaca43fc Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Determine assertion requirements 7a0ecd94-3699-5273-76a5-edb8499f655a Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Determine auditable events 2f67e567-03db-9d1f-67dc-b6ffb91312f4 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Develop an incident response plan 2b4e134f-1e4c-2bff-573e-082d85479b6e Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Develop and maintain baseline configurations 2f20840e-7925-221c-725d-757442753e7c Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Disable authenticators upon termination d9d48ffb-0d8c-0bd5-5f31-5a5826d19f10 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Disconnections should be logged for PostgreSQL database servers. eb6f77b9-bd53-4e35-a23d-7f65d5f0e446 SQL 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Document mobility training 83dfb2b8-678b-20a0-4c44-5c75ada023e6 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Document remote access guidelines 3d492600-27ba-62cc-a1c3-66eb919f6a0d Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Document security operations 2c6bee3a-2180-2430-440d-db3c7a849870 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Email notification for high severity alerts should be enabled 6e2593d9-add6-4083-9c9b-4b7d2188c899 Security Center 1.2.0 3x
1.2.0, 1.1.0, 1.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Employ flow control mechanisms of encrypted information 79365f13-8ba4-1f6c-2ac4-aa39929f56d0 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Employ least privilege access 1bc7fd64-291f-028e-4ed6-6e07886e163f Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Enable dual or joint authorization 2c843d78-8f64-92b5-6a9b-e8186c0e7eb6 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Enforce logical access 10c4210b-3ec9-9603-050d-77e4d26c7ebb Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Enforce mandatory and discretionary access control policies b1666a13-8f67-9c47-155e-69e027ff6823 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Enforce security configuration settings 058e9719-1ff9-3653-4230-23f76b6492e0 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Enforce SSL connection should be enabled for MySQL database servers e802a67a-daf5-4436-9ea6-f6d821dd0c5d SQL 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Disabled
0 GA true
Enforce SSL connection should be enabled for PostgreSQL database servers d158790f-bfb0-486c-8631-2dc6b4e8e6af SQL 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Disabled
0 GA true
Enforce user uniqueness e336d5f4-4d8f-0059-759c-ae10f63d1747 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Ensure cryptographic mechanisms are under configuration management b8dad106-6444-5f55-307e-1e1cc9723e39 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA unknown
Establish a configuration control board 7380631c-5bf5-0e3a-4509-0873becd8a63 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Establish a data leakage management procedure 3c9aa856-6b86-35dc-83f4-bc72cec74dea Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Establish and document a configuration management plan 526ed90e-890f-69e7-0386-ba5c0f1f784f Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Establish and document change control processes bd4dc286-2f30-5b95-777c-681f3a7913d3 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Establish firewall and router configuration standards 398fdbd8-56fd-274d-35c6-fa2d3b2755a1 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Establish network segmentation for card holder data environment f476f3b0-4152-526e-a209-44e5f8c968d7 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Flow logs should be configured for every network security group c251913d-7d24-4958-af87-478ed3b9ba41 Network 1.1.0 1x
1.1.0
Default
Audit
Allowed
Audit, Disabled
0 GA true
Function app slots that use Java should use a specified 'Java version' e1d1b522-02b0-4d18-a04f-5ab62d20445f App Service 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Function apps should have authentication enabled c75248c1-ea1d-4a9c-8fc9-29a6aabd5da8 App Service 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Function apps should require FTPS only 399b2637-a50f-4f95-96f8-3a145476eb15 App Service 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Function apps should use latest 'HTTP Version' e2c1c086-2d84-4019-bff3-c44ccd95113c App Service 4.0.0 1x
4.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Function apps should use managed identity 0da106f2-4ca3-48e8-bc85-c638fe6aea8f App Service 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Function apps should use the latest TLS version f9d614c5-c173-4d56-95a7-b4437057d193 App Service 2.1.0 2x
2.1.0, 2.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Function apps that use Java should use a specified 'Java version' 9d0b6ea4-93e2-4578-bf2f-6bb17d22b4bc App Service 3.1.0 1x
3.1.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Govern and monitor audit processing activities 333b4ada-4a02-0648-3d4d-d812974f1bb2 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Guest accounts with owner permissions on Azure resources should be removed 339353f6-2387-4a45-abe4-7f529d121046 Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Guest accounts with read permissions on Azure resources should be removed e9ac8f8e-ce22-4355-8f04-99b911d6be52 Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Guest accounts with write permissions on Azure resources should be removed 94e1c2ac-cbbe-4cac-a2b5-389c812dee87 Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Identify and authenticate network devices ae5345d5-8dab-086a-7290-db43a3272198 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Identify and manage downstream information exchanges c7fddb0e-3f44-8635-2b35-dc6b8e740b7c Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Implement an automated configuration management tool 33832848-42ab-63f3-1a55-c0ad309d44cd Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Implement controls to secure all media e435f7e3-0dd9-58c9-451f-9b44b96c0232 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Implement controls to secure alternate work sites cd36eeec-67e7-205a-4b64-dbfe3b4e3e4e Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Implement training for protecting authenticators e4b00788-7e1c-33ec-0418-d048508e095b Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Infrastructure encryption should be enabled for Azure Database for PostgreSQL servers 24fba194-95d6-48c0-aea7-f65bf859c598 SQL 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Issue public key certificates 97d91b33-7050-237b-3e23-a77d57d84e13 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Key Vault keys should have an expiration date 152b15f7-8e1f-4c1f-ab71-8c010ba5dbc0 Key Vault 1.0.2 1x
1.0.2
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Key Vault secrets should have an expiration date 98728c90-32c7-4049-8429-847dc0f4fe37 Key Vault 1.0.2 1x
1.0.2
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Key vaults should have deletion protection enabled 0b60c0b2-2dc2-4e1c-b5c9-abbed971de53 Key Vault 2.1.0 1x
2.1.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Key vaults should have soft delete enabled 1e66c121-a66a-4b1f-9b83-0fd99bf0fc2d Key Vault 3.0.0 1x
3.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Keys should have a rotation policy ensuring that their rotation is scheduled within the specified number of days after creation. d8cf8476-a2ec-4916-896e-992351803c44 Key Vault 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Disabled
0 GA unknown
Log checkpoints should be enabled for PostgreSQL database servers eb6f77b9-bd53-4e35-a23d-7f65d5f0e43d SQL 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Log connections should be enabled for PostgreSQL database servers eb6f77b9-bd53-4e35-a23d-7f65d5f0e442 SQL 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Machines should be configured to periodically check for missing system updates bd876905-5b84-4f73-ab2d-2e7a7c4568d9 Azure Update Manager 3.7.0 4x
3.7.0, 3.6.0, 3.5.0, 3.4.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Maintain availability of information 3ad7f0bc-3d03-0585-4d24-529779bb02c2 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Maintain integrity of audit system c0559109-6a27-a217-6821-5a6d44f92897 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA unknown
Manage gateways 63f63e71-6c3f-9add-4c43-64de23e554a7 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Manage symmetric cryptographic keys 9c276cf3-596f-581a-7fbd-f5e46edaa0f4 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Manage system and admin accounts 34d38ea7-6754-1838-7031-d7fd07099821 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Manage the input, output, processing, and storage of data e603da3a-8af7-4f8a-94cb-1bcc0e0333d2 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Managed disks should be double encrypted with both platform-managed and customer-managed keys ca91455f-eace-4f96-be59-e6e2c35b4816 Compute 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Management ports should be closed on your virtual machines 22730e10-96f6-4aac-ad84-9383d35b5917 Security Center 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Microsoft Defender for Azure Cosmos DB should be enabled adbe85b5-83e6-4350-ab58-bf3a4f736e5e Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Microsoft Defender for Containers should be enabled 1c988dd6-ade4-430f-a608-2a3e5b0a6d38 Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Microsoft Defender for Storage should be enabled 640d2586-54d2-465f-877f-9ffc1d2109f4 Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Monitor access across the organization 48c816c5-2190-61fc-8806-25d6f3df162f Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Monitor privileged role assignment ed87d27a-9abf-7c71-714c-61d881889da4 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Network Watcher should be enabled b6e2945c-0b7b-40f5-9233-7a5323b5cdc6 Network 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Notify when account is not needed 8489ff90-8d29-61df-2d84-f9ab0f4c5e84 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Only approved VM extensions should be installed c0e996f8-39cf-4af9-9f45-83fbde810432 Compute 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Perform a trend analysis on threats 50e81644-923d-33fc-6ebb-9733bc8d1a06 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Perform vulnerability scans 3c5e0e1a-216f-8f49-0a15-76ed0d8b8e1f Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Protect audit information 0e696f5a-451f-5c15-5532-044136538491 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Protect data in transit using encryption b11697e8-9515-16f1-7a35-477d5c8a1344 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Protect passwords with encryption b2d3e5a2-97ab-5497-565a-71172a729d93 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Protect special information a315c657-4a00-8eba-15ac-44692ad24423 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Provide privacy training 518eafdd-08e5-37a9-795b-15a8d798056d Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Public network access on Azure SQL Database should be disabled 1b8ca024-1d5c-4dec-8995-b1a932b41780 SQL 1.1.0 1x
1.1.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Public network access should be disabled for PostgreSQL flexible servers 5e1de0e3-42cb-4ebc-a86d-61d0c619ca48 SQL 3.1.0 2x
3.1.0, 3.0.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA unknown
Public network access should be disabled for PostgreSQL servers b52376f7-9612-48a1-81cd-1ffe4b61032c SQL 2.0.1 1x
2.0.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Reassign or remove user privileges as needed 7805a343-275c-41be-9d62-7215b96212d8 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Remediate information system flaws be38a620-000b-21cf-3cb3-ea151b704c3b Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Require approval for account creation de770ba6-50dd-a316-2932-e0d972eaa734 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Resource logs in Azure Data Lake Store should be enabled 057ef27e-665e-4328-8ea3-04b3122bd9fb Data Lake 5.0.0 1x
5.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Resource logs in Azure Stream Analytics should be enabled f9be5368-9bf5-4b84-9e0a-7850da98bb46 Stream Analytics 5.0.0 1x
5.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Resource logs in Batch accounts should be enabled 428256e6-1fac-4f48-a757-df34c2b3336d Batch 5.0.0 1x
5.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Resource logs in Data Lake Analytics should be enabled c95c74d9-38fe-4f0d-af86-0c7d626a315c Data Lake 5.0.0 1x
5.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Resource logs in Event Hub should be enabled 83a214f7-d01a-484b-91a9-ed54470c9a6a Event Hub 5.0.0 1x
5.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Resource logs in IoT Hub should be enabled 383856f8-de7f-44a2-81fc-e5135b5c2aa4 Internet of Things 3.1.0 1x
3.1.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Resource logs in Key Vault should be enabled cf820ca0-f99e-4f3e-84fb-66e913812d21 Key Vault 5.0.0 1x
5.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Resource logs in Logic Apps should be enabled 34f95f76-5386-4de7-b824-0d8478470c9d Logic Apps 5.1.0 1x
5.1.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Resource logs in Search services should be enabled b4330a05-a843-4bc8-bf9a-cacce50c67f4 Search 5.0.0 1x
5.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Resource logs in Service Bus should be enabled f8d36e2f-389b-4ee4-898d-21aeb69a0f45 Service Bus 5.0.0 1x
5.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Restrict access to private keys 8d140e8b-76c7-77de-1d46-ed1b2e112444 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Restrict access to privileged accounts 873895e8-0e3a-6492-42e9-22cd030e9fcd Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Retain security policies and procedures efef28d0-3226-966a-a1e8-70e89c1b30bc Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Retain terminated user data 7c7032fe-9ce6-9092-5890-87a1a3755db1 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Review account provisioning logs a830fe9e-08c9-a4fb-420c-6f6bf1702395 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Review audit data 6625638f-3ba1-7404-5983-0ea33d719d34 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Review label activity and analytics e23444b9-9662-40f3-289e-6d25c02b48fa Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Review malware detections report weekly 4a6f5cbd-6c6b-006f-2bb1-091af1441bce Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Review threat protection status weekly fad161f5-5261-401a-22dd-e037bae011bd Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Review user accounts 79f081c7-1634-01a1-708e-376197999289 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Review user groups and applications with access to sensitive data eb1c944e-0e94-647b-9b7e-fdb8d2af0838 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Review user privileges f96d2186-79df-262d-3f76-f371e3b71798 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Revoke privileged roles as appropriate 32f22cfa-770b-057c-965b-450898425519 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Satisfy token quality requirements 056a723b-4946-9d2a-5243-3aa27c4d31a1 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Secure transfer to storage accounts should be enabled 404c3081-a854-4457-ae30-26a93ef643f9 Storage 2.0.0 1x
2.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Set automated notifications for new and trending cloud applications in your organization af38215f-70c4-0cd6-40c2-c52d86690a45 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
SQL databases should have vulnerability findings resolved feedbf84-6b99-488c-acc2-71c829aa5ffc Security Center 4.1.0 1x
4.1.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
SQL managed instances should use customer-managed keys to encrypt data at rest ac01ad65-10e5-46df-bdd9-6b0cad13e1d2 SQL 2.0.0 1x
2.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
SQL servers should use customer-managed keys to encrypt data at rest 0a370ff3-6cab-4e85-8995-295fd854c5b8 SQL 2.0.1 1x
2.0.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
SQL servers with auditing to storage account destination should be configured with 90 days retention or higher 89099bee-89e0-4b26-a5f4-165451757743 SQL 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Storage account containing the container with activity logs must be encrypted with BYOK fbb99e8e-e444-4da0-9ff1-75c92f5a85b2 Monitoring 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Storage account public access should be disallowed 4fa4b6c0-31ca-4c0d-b10d-24b96f62a751 Storage 3.1.1 2x
3.1.1, 3.1.0-preview
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA unknown
Storage accounts should allow access from trusted Microsoft services c9d007d0-c057-4772-b18c-01e546713bcd Storage 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Storage accounts should have infrastructure encryption 4733ea7b-a883-42fe-8cac-97454c2a9e4a Storage 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Storage accounts should have the specified minimum TLS version fe83a0eb-a853-422d-aac2-1bffd182c5d0 Storage 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Storage accounts should restrict network access 34c877ad-507e-4c82-993e-3452a6e0ad3c Storage 1.1.1 1x
1.1.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Storage accounts should restrict network access using virtual network rules 2a1a9cdf-e04d-429a-8416-3bfb72a1b26f Storage 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Storage accounts should use customer-managed key for encryption 6fac406b-40ca-413b-bf8e-0bf964659c25 Storage 1.0.3 1x
1.0.3
Default
Audit
Allowed
Audit, Disabled
0 GA true
Storage accounts should use private link 6edd7eda-6dd8-40f7-810d-67160c639cd9 Storage 2.0.0 1x
2.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Subscriptions should have a contact email address for security issues 4f4f78b8-e367-4b10-a341-d9a4ad5cf1c7 Security Center 1.0.1 1x
1.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Support personal verification credentials issued by legal authorities 1d39b5d9-0392-8954-8359-575ce1957d1a Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Terminate user session automatically 4502e506-5f35-0df4-684f-b326e3cc7093 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Transparent Data Encryption on SQL databases should be enabled 17k78e20-9358-41c9-923c-fb736d382a12 SQL 2.0.0 1x
2.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Turn on sensors for endpoint security solution 5fc24b95-53f7-0ed1-2330-701b539b97fe Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Update antivirus definitions ea9d7c95-2f10-8a4d-61d8-7469bd2e8d65 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Use privileged identity management e714b481-8fac-64a2-14a9-6f079b2501a4 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Verify security functions ece8bb17-4080-5127-915f-dc7267ee8549 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Verify software, firmware and information integrity db28735f-518f-870e-15b4-49623cbe3aa0 Regulatory Compliance 1.1.0 1x
1.1.0
Default
Manual
Allowed
Manual, Disabled
0 GA true
Vulnerability assessment should be enabled on SQL Managed Instance 1b7aa243-30e4-4c9e-bca8-d0d3022b634a SQL 1.0.1 1x
1.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Vulnerability assessment should be enabled on your SQL servers ef2a8f2a-b3d9-49cd-a8a8-9a3aaaf647d9 SQL 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Roles used No Roles used
History
JSON compare
compare mode: version left: version right:
JSON
api-version=2023-04-01
EPAC