JSON
api-version=2023-04-01
Copy definition Copy definition 4 EPAC EPAC
{ 9 items displayName: "CIS Microsoft Azure Foundations Benchmark v1.1.0" , policyType: "BuiltIn" , description: "The Center for Internet Security (CIS) is a nonprofit entity whose mission is to 'identify, develop, validate, promote, and sustain best practice solutions for cyberdefense.' CIS benchmarks are configuration baselines and best practices for securely configuring a system. These policies address a subset of CIS Microsoft Azure Foundations Benchmark v1.1.0 controls. For more information, visit https://aka.ms/cisazure110-initiative" , metadata: { 2 items version: "16.10.0" , category: "Regulatory Compliance" } , version: "16.10.0" , parameters: { 3 items listOfRegionsWhereNetworkWatcherShouldBeEnabled: { 3 items type: "Array" , metadata: { 4 items displayName: "[Deprecated]: List of regions where Network Watcher should be enabled" , description: "To see a complete list of regions use Get-AzLocation" , strongType: "location" , deprecated: true } , defaultValue: [ 1 item ] } , NetworkWatcherResourceGroupName: { 3 items type: "String" , metadata: { 2 items displayName: "NetworkWatcher resource group name" , description: "Name of the resource group of NetworkWatcher, such as NetworkWatcherRG" } , defaultValue: "NetworkWatcherRG" } , listOfApprovedVMExtensions: { 3 items type: "Array" , metadata: { 2 items displayName: "List of virtual machine extensions that are approved for use" , description: "A semicolon-separated list of virtual machine extensions; to see a complete list of extensions, use Get-AzVMExtensionImage" } , defaultValue: [ 13 items "AzureDiskEncryption" , "AzureDiskEncryptionForLinux" , "DependencyAgentWindows" , "DependencyAgentLinux" , "IaaSAntimalware" , "IaaSDiagnostics" , "LinuxDiagnostic" , "MicrosoftMonitoringAgent" , "NetworkWatcherAgentLinux" , "NetworkWatcherAgentWindows" , "OmsAgentForLinux" , "VMSnapshot" , "VMSnapshotLinux" ] } } , policyDefinitions: [ 153 items { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items policyDefinitionReferenceId: "CISv110x2x14CISv110x4x1" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/a6fb4358-5bf4-4ad7-ba82-2cd2f41ce5e9 Auditing on SQL server should be enabled , definitionVersion: 2.*.*2.0.0 , parameters: {} , groupNames: [ 2 items "CIS_Azure_1.1.0_2.14" , "CIS_Azure_1.1.0_4.1" ] } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items } , { 5 items policyDefinitionReferenceId: "7d7a8356-5c34-9a95-3118-1424cfaf192a" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/7d7a8356-5c34-9a95-3118-1424cfaf192a Adopt biometric authentication mechanisms , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 4 items "CIS_Azure_1.1.0_1.1" , "CIS_Azure_1.1.0_1.2" , "CIS_Azure_1.1.0_1.4" , "CIS_Azure_1.1.0_1.22" ] } , { 5 items policyDefinitionReferenceId: "2cc9c165-46bd-9762-5739-d2aae5ba90a1" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/2cc9c165-46bd-9762-5739-d2aae5ba90a1 Automate account management , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 6 items "CIS_Azure_1.1.0_1.6" , "CIS_Azure_1.1.0_1.7" , "CIS_Azure_1.1.0_1.8" , "CIS_Azure_1.1.0_4.8" , "CIS_Azure_1.1.0_4.19" , "CIS_Azure_1.1.0_9.5" ] } , { 5 items policyDefinitionReferenceId: "34d38ea7-6754-1838-7031-d7fd07099821" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/34d38ea7-6754-1838-7031-d7fd07099821 Manage system and admin accounts , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 6 items "CIS_Azure_1.1.0_1.6" , "CIS_Azure_1.1.0_1.7" , "CIS_Azure_1.1.0_1.8" , "CIS_Azure_1.1.0_4.8" , "CIS_Azure_1.1.0_4.19" , "CIS_Azure_1.1.0_9.5" ] } , { 5 items policyDefinitionReferenceId: "48c816c5-2190-61fc-8806-25d6f3df162f" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/48c816c5-2190-61fc-8806-25d6f3df162f Monitor access across the organization , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 6 items "CIS_Azure_1.1.0_1.6" , "CIS_Azure_1.1.0_1.7" , "CIS_Azure_1.1.0_1.8" , "CIS_Azure_1.1.0_4.8" , "CIS_Azure_1.1.0_4.19" , "CIS_Azure_1.1.0_9.5" ] } , { 5 items policyDefinitionReferenceId: "8489ff90-8d29-61df-2d84-f9ab0f4c5e84" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/8489ff90-8d29-61df-2d84-f9ab0f4c5e84 Notify when account is not needed , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 6 items "CIS_Azure_1.1.0_1.6" , "CIS_Azure_1.1.0_1.7" , "CIS_Azure_1.1.0_1.8" , "CIS_Azure_1.1.0_4.8" , "CIS_Azure_1.1.0_4.19" , "CIS_Azure_1.1.0_9.5" ] } , { 5 items } , { 5 items policyDefinitionReferenceId: "aeed863a-0f56-429f-945d-8bb66bd06841" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/aeed863a-0f56-429f-945d-8bb66bd06841 Authorize access to security functions and information , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 15 items "CIS_Azure_1.1.0_1.9" , "CIS_Azure_1.1.0_1.10" , "CIS_Azure_1.1.0_1.11" , "CIS_Azure_1.1.0_1.12" , "CIS_Azure_1.1.0_1.13" , "CIS_Azure_1.1.0_1.14" , "CIS_Azure_1.1.0_1.15" , "CIS_Azure_1.1.0_1.16" , "CIS_Azure_1.1.0_1.17" , "CIS_Azure_1.1.0_1.18" , "CIS_Azure_1.1.0_1.19" , "CIS_Azure_1.1.0_1.20" , "CIS_Azure_1.1.0_1.23" , "CIS_Azure_1.1.0_3.6" , "CIS_Azure_1.1.0_8.5" ] } , { 5 items policyDefinitionReferenceId: "50e9324a-7410-0539-0662-2c1e775538b7" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/50e9324a-7410-0539-0662-2c1e775538b7 Authorize and manage access , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 15 items "CIS_Azure_1.1.0_1.9" , "CIS_Azure_1.1.0_1.10" , "CIS_Azure_1.1.0_1.11" , "CIS_Azure_1.1.0_1.12" , "CIS_Azure_1.1.0_1.13" , "CIS_Azure_1.1.0_1.14" , "CIS_Azure_1.1.0_1.15" , "CIS_Azure_1.1.0_1.16" , "CIS_Azure_1.1.0_1.17" , "CIS_Azure_1.1.0_1.18" , "CIS_Azure_1.1.0_1.19" , "CIS_Azure_1.1.0_1.20" , "CIS_Azure_1.1.0_1.23" , "CIS_Azure_1.1.0_3.6" , "CIS_Azure_1.1.0_8.5" ] } , { 5 items policyDefinitionReferenceId: "10c4210b-3ec9-9603-050d-77e4d26c7ebb" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/10c4210b-3ec9-9603-050d-77e4d26c7ebb Enforce logical access , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 6 items "CIS_Azure_1.1.0_1.12" , "CIS_Azure_1.1.0_1.13" , "CIS_Azure_1.1.0_1.14" , "CIS_Azure_1.1.0_1.15" , "CIS_Azure_1.1.0_3.6" , "CIS_Azure_1.1.0_8.5" ] } , { 5 items policyDefinitionReferenceId: "b1666a13-8f67-9c47-155e-69e027ff6823" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/b1666a13-8f67-9c47-155e-69e027ff6823 Enforce mandatory and discretionary access control policies , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 15 items "CIS_Azure_1.1.0_1.9" , "CIS_Azure_1.1.0_1.10" , "CIS_Azure_1.1.0_1.11" , "CIS_Azure_1.1.0_1.12" , "CIS_Azure_1.1.0_1.13" , "CIS_Azure_1.1.0_1.14" , "CIS_Azure_1.1.0_1.15" , "CIS_Azure_1.1.0_1.16" , "CIS_Azure_1.1.0_1.17" , "CIS_Azure_1.1.0_1.18" , "CIS_Azure_1.1.0_1.19" , "CIS_Azure_1.1.0_1.20" , "CIS_Azure_1.1.0_1.23" , "CIS_Azure_1.1.0_3.6" , "CIS_Azure_1.1.0_8.5" ] } , { 5 items policyDefinitionReferenceId: "de770ba6-50dd-a316-2932-e0d972eaa734" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/de770ba6-50dd-a316-2932-e0d972eaa734 Require approval for account creation , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 6 items "CIS_Azure_1.1.0_1.12" , "CIS_Azure_1.1.0_1.13" , "CIS_Azure_1.1.0_1.14" , "CIS_Azure_1.1.0_1.15" , "CIS_Azure_1.1.0_3.6" , "CIS_Azure_1.1.0_8.5" ] } , { 5 items policyDefinitionReferenceId: "eb1c944e-0e94-647b-9b7e-fdb8d2af0838" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/eb1c944e-0e94-647b-9b7e-fdb8d2af0838 Review user groups and applications with access to sensitive data , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 6 items "CIS_Azure_1.1.0_1.12" , "CIS_Azure_1.1.0_1.13" , "CIS_Azure_1.1.0_1.14" , "CIS_Azure_1.1.0_1.15" , "CIS_Azure_1.1.0_3.6" , "CIS_Azure_1.1.0_8.5" ] } , { 5 items policyDefinitionReferenceId: "bd4dc286-2f30-5b95-777c-681f3a7913d3" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/bd4dc286-2f30-5b95-777c-681f3a7913d3 Establish and document change control processes , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 8 items "CIS_Azure_1.1.0_1.15" , "CIS_Azure_1.1.0_1.16" , "CIS_Azure_1.1.0_1.17" , "CIS_Azure_1.1.0_1.18" , "CIS_Azure_1.1.0_1.19" , "CIS_Azure_1.1.0_1.20" , "CIS_Azure_1.1.0_1.23" , "CIS_Azure_1.1.0_8.3" ] } , { 5 items policyDefinitionReferenceId: "dad8a2e9-6f27-4fc2-8933-7e99fe700c9c" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/dad8a2e9-6f27-4fc2-8933-7e99fe700c9c Authorize remote access , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 1 item ] } , { 5 items policyDefinitionReferenceId: "83dfb2b8-678b-20a0-4c44-5c75ada023e6" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/83dfb2b8-678b-20a0-4c44-5c75ada023e6 Document mobility training , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 1 item ] } , { 5 items policyDefinitionReferenceId: "3d492600-27ba-62cc-a1c3-66eb919f6a0d" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/3d492600-27ba-62cc-a1c3-66eb919f6a0d Document remote access guidelines , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 1 item ] } , { 5 items } , { 5 items policyDefinitionReferenceId: "518eafdd-08e5-37a9-795b-15a8d798056d" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/518eafdd-08e5-37a9-795b-15a8d798056d Provide privacy training , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 1 item ] } , { 5 items policyDefinitionReferenceId: "ae5345d5-8dab-086a-7290-db43a3272198" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/ae5345d5-8dab-086a-7290-db43a3272198 Identify and authenticate network devices , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 2 items "CIS_Azure_1.1.0_1.4" , "CIS_Azure_1.1.0_1.22" ] } , { 5 items policyDefinitionReferenceId: "056a723b-4946-9d2a-5243-3aa27c4d31a1" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/056a723b-4946-9d2a-5243-3aa27c4d31a1 Satisfy token quality requirements , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 2 items "CIS_Azure_1.1.0_1.4" , "CIS_Azure_1.1.0_1.22" ] } , { 5 items policyDefinitionReferenceId: "49c23d9b-02b0-0e42-4f94-e8cef1b8381b" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/49c23d9b-02b0-0e42-4f94-e8cef1b8381b Audit user account status , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 11 items "CIS_Azure_1.1.0_1.3" , "CIS_Azure_1.1.0_2.14" , "CIS_Azure_1.1.0_3.3" , "CIS_Azure_1.1.0_4.1" , "CIS_Azure_1.1.0_4.2" , "CIS_Azure_1.1.0_4.12" , "CIS_Azure_1.1.0_4.14" , "CIS_Azure_1.1.0_4.15" , "CIS_Azure_1.1.0_4.16" , "CIS_Azure_1.1.0_4.17" , "CIS_Azure_1.1.0_5.1.7" ] } , { 5 items policyDefinitionReferenceId: "a830fe9e-08c9-a4fb-420c-6f6bf1702395" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/a830fe9e-08c9-a4fb-420c-6f6bf1702395 Review account provisioning logs , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 1 item ] } , { 5 items policyDefinitionReferenceId: "79f081c7-1634-01a1-708e-376197999289" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/79f081c7-1634-01a1-708e-376197999289 Review user accounts , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 1 item ] } , { 5 items policyDefinitionReferenceId: "f96d2186-79df-262d-3f76-f371e3b71798" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/f96d2186-79df-262d-3f76-f371e3b71798 Review user privileges , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 1 item ] } , { 5 items } , { 5 items policyDefinitionReferenceId: "f26af0b1-65b6-689a-a03f-352ad2d00f98" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/f26af0b1-65b6-689a-a03f-352ad2d00f98 Audit privileged functions , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 11 items "CIS_Azure_1.1.0_1.8" , "CIS_Azure_1.1.0_2.14" , "CIS_Azure_1.1.0_3.3" , "CIS_Azure_1.1.0_4.1" , "CIS_Azure_1.1.0_4.2" , "CIS_Azure_1.1.0_4.12" , "CIS_Azure_1.1.0_4.14" , "CIS_Azure_1.1.0_4.15" , "CIS_Azure_1.1.0_4.16" , "CIS_Azure_1.1.0_4.17" , "CIS_Azure_1.1.0_5.1.7" ] } , { 5 items policyDefinitionReferenceId: "ed87d27a-9abf-7c71-714c-61d881889da4" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/ed87d27a-9abf-7c71-714c-61d881889da4 Monitor privileged role assignment , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 1 item ] } , { 5 items } , { 5 items policyDefinitionReferenceId: "32f22cfa-770b-057c-965b-450898425519" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/32f22cfa-770b-057c-965b-450898425519 Revoke privileged roles as appropriate , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 2 items "CIS_Azure_1.1.0_1.8" , "CIS_Azure_1.1.0_3.4" ] } , { 5 items policyDefinitionReferenceId: "e714b481-8fac-64a2-14a9-6f079b2501a4" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/e714b481-8fac-64a2-14a9-6f079b2501a4 Use privileged identity management , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 1 item ] } , { 5 items policyDefinitionReferenceId: "03b6427e-6072-4226-4bd9-a410ab65317e" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/03b6427e-6072-4226-4bd9-a410ab65317e Design an access control model , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 4 items "CIS_Azure_1.1.0_1.12" , "CIS_Azure_1.1.0_1.13" , "CIS_Azure_1.1.0_1.14" , "CIS_Azure_1.1.0_1.23" ] } , { 5 items policyDefinitionReferenceId: "1bc7fd64-291f-028e-4ed6-6e07886e163f" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/1bc7fd64-291f-028e-4ed6-6e07886e163f Employ least privilege access , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 4 items "CIS_Azure_1.1.0_1.12" , "CIS_Azure_1.1.0_1.13" , "CIS_Azure_1.1.0_1.14" , "CIS_Azure_1.1.0_1.23" ] } , { 5 items } , { 5 items policyDefinitionReferenceId: "63f63e71-6c3f-9add-4c43-64de23e554a7" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/63f63e71-6c3f-9add-4c43-64de23e554a7 Manage gateways , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 3 items "CIS_Azure_1.1.0_2.1" , "CIS_Azure_1.1.0_2.5" , "CIS_Azure_1.1.0_7.6" ] } , { 5 items policyDefinitionReferenceId: "50e81644-923d-33fc-6ebb-9733bc8d1a06" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/50e81644-923d-33fc-6ebb-9733bc8d1a06 Perform a trend analysis on threats , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 5 items "CIS_Azure_1.1.0_2.1" , "CIS_Azure_1.1.0_2.5" , "CIS_Azure_1.1.0_4.4" , "CIS_Azure_1.1.0_4.5" , "CIS_Azure_1.1.0_7.6" ] } , { 5 items policyDefinitionReferenceId: "3c5e0e1a-216f-8f49-0a15-76ed0d8b8e1f" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/3c5e0e1a-216f-8f49-0a15-76ed0d8b8e1f Perform vulnerability scans , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 4 items "CIS_Azure_1.1.0_2.1" , "CIS_Azure_1.1.0_2.4" , "CIS_Azure_1.1.0_2.5" , "CIS_Azure_1.1.0_7.6" ] } , { 5 items policyDefinitionReferenceId: "4a6f5cbd-6c6b-006f-2bb1-091af1441bce" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/4a6f5cbd-6c6b-006f-2bb1-091af1441bce Review malware detections report weekly , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 3 items "CIS_Azure_1.1.0_2.1" , "CIS_Azure_1.1.0_2.5" , "CIS_Azure_1.1.0_7.6" ] } , { 5 items policyDefinitionReferenceId: "fad161f5-5261-401a-22dd-e037bae011bd" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/fad161f5-5261-401a-22dd-e037bae011bd Review threat protection status weekly , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 3 items "CIS_Azure_1.1.0_2.1" , "CIS_Azure_1.1.0_2.5" , "CIS_Azure_1.1.0_7.6" ] } , { 5 items policyDefinitionReferenceId: "ea9d7c95-2f10-8a4d-61d8-7469bd2e8d65" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/ea9d7c95-2f10-8a4d-61d8-7469bd2e8d65 Update antivirus definitions , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 3 items "CIS_Azure_1.1.0_2.1" , "CIS_Azure_1.1.0_2.5" , "CIS_Azure_1.1.0_7.6" ] } , { 5 items } , { 5 items policyDefinitionReferenceId: "2c6bee3a-2180-2430-440d-db3c7a849870" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/2c6bee3a-2180-2430-440d-db3c7a849870 Document security operations , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 2 items "CIS_Azure_1.1.0_2.2" , "CIS_Azure_1.1.0_7.6" ] } , { 5 items policyDefinitionReferenceId: "5fc24b95-53f7-0ed1-2330-701b539b97fe" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/5fc24b95-53f7-0ed1-2330-701b539b97fe Turn on sensors for endpoint security solution , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 2 items "CIS_Azure_1.1.0_2.2" , "CIS_Azure_1.1.0_7.6" ] } , { 5 items policyDefinitionReferenceId: "be38a620-000b-21cf-3cb3-ea151b704c3b" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/be38a620-000b-21cf-3cb3-ea151b704c3b Remediate information system flaws , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 8 items "CIS_Azure_1.1.0_2.3" , "CIS_Azure_1.1.0_2.4" , "CIS_Azure_1.1.0_7.5" , "CIS_Azure_1.1.0_9.6" , "CIS_Azure_1.1.0_9.7" , "CIS_Azure_1.1.0_9.8" , "CIS_Azure_1.1.0_9.9" , "CIS_Azure_1.1.0_9.10" ] } , { 5 items policyDefinitionReferenceId: "3c9aa856-6b86-35dc-83f4-bc72cec74dea" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/3c9aa856-6b86-35dc-83f4-bc72cec74dea Establish a data leakage management procedure , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 8 items "CIS_Azure_1.1.0_2.6" , "CIS_Azure_1.1.0_2.11" , "CIS_Azure_1.1.0_2.15" , "CIS_Azure_1.1.0_4.9" , "CIS_Azure_1.1.0_4.10" , "CIS_Azure_1.1.0_7.1" , "CIS_Azure_1.1.0_7.2" , "CIS_Azure_1.1.0_7.3" ] } , { 5 items policyDefinitionReferenceId: "a315c657-4a00-8eba-15ac-44692ad24423" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/a315c657-4a00-8eba-15ac-44692ad24423 Protect special information , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 8 items "CIS_Azure_1.1.0_2.6" , "CIS_Azure_1.1.0_2.11" , "CIS_Azure_1.1.0_2.15" , "CIS_Azure_1.1.0_4.9" , "CIS_Azure_1.1.0_4.10" , "CIS_Azure_1.1.0_7.1" , "CIS_Azure_1.1.0_7.2" , "CIS_Azure_1.1.0_7.3" ] } , { 5 items policyDefinitionReferenceId: "e435f7e3-0dd9-58c9-451f-9b44b96c0232" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/e435f7e3-0dd9-58c9-451f-9b44b96c0232 Implement controls to secure all media , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 8 items "CIS_Azure_1.1.0_2.6" , "CIS_Azure_1.1.0_2.11" , "CIS_Azure_1.1.0_2.15" , "CIS_Azure_1.1.0_4.9" , "CIS_Azure_1.1.0_4.10" , "CIS_Azure_1.1.0_7.1" , "CIS_Azure_1.1.0_7.2" , "CIS_Azure_1.1.0_7.3" ] } , { 5 items policyDefinitionReferenceId: "b11697e8-9515-16f1-7a35-477d5c8a1344" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/b11697e8-9515-16f1-7a35-477d5c8a1344 Protect data in transit using encryption , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 14 items "CIS_Azure_1.1.0_2.6" , "CIS_Azure_1.1.0_2.11" , "CIS_Azure_1.1.0_2.15" , "CIS_Azure_1.1.0_3.1" , "CIS_Azure_1.1.0_3.5" , "CIS_Azure_1.1.0_4.9" , "CIS_Azure_1.1.0_4.10" , "CIS_Azure_1.1.0_4.11" , "CIS_Azure_1.1.0_4.13" , "CIS_Azure_1.1.0_7.1" , "CIS_Azure_1.1.0_7.2" , "CIS_Azure_1.1.0_7.3" , "CIS_Azure_1.1.0_9.2" , "CIS_Azure_1.1.0_9.3" ] } , { 5 items policyDefinitionReferenceId: "59bedbdc-0ba9-39b9-66bb-1d1c192384e6" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/59bedbdc-0ba9-39b9-66bb-1d1c192384e6 Control information flow , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 5 items "CIS_Azure_1.1.0_2.7" , "CIS_Azure_1.1.0_2.8" , "CIS_Azure_1.1.0_2.9" , "CIS_Azure_1.1.0_3.8" , "CIS_Azure_1.1.0_6.3" ] } , { 5 items policyDefinitionReferenceId: "79365f13-8ba4-1f6c-2ac4-aa39929f56d0" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/79365f13-8ba4-1f6c-2ac4-aa39929f56d0 Employ flow control mechanisms of encrypted information , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 5 items "CIS_Azure_1.1.0_2.7" , "CIS_Azure_1.1.0_2.8" , "CIS_Azure_1.1.0_2.9" , "CIS_Azure_1.1.0_3.8" , "CIS_Azure_1.1.0_6.3" ] } , { 5 items policyDefinitionReferenceId: "2f67e567-03db-9d1f-67dc-b6ffb91312f4" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/2f67e567-03db-9d1f-67dc-b6ffb91312f4 Determine auditable events , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 10 items "CIS_Azure_1.1.0_2.14" , "CIS_Azure_1.1.0_3.3" , "CIS_Azure_1.1.0_4.1" , "CIS_Azure_1.1.0_4.2" , "CIS_Azure_1.1.0_4.12" , "CIS_Azure_1.1.0_4.14" , "CIS_Azure_1.1.0_4.15" , "CIS_Azure_1.1.0_4.16" , "CIS_Azure_1.1.0_4.17" , "CIS_Azure_1.1.0_5.1.7" ] } , { 5 items policyDefinitionReferenceId: "6625638f-3ba1-7404-5983-0ea33d719d34" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/6625638f-3ba1-7404-5983-0ea33d719d34 Review audit data , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 10 items "CIS_Azure_1.1.0_2.14" , "CIS_Azure_1.1.0_3.3" , "CIS_Azure_1.1.0_4.1" , "CIS_Azure_1.1.0_4.2" , "CIS_Azure_1.1.0_4.12" , "CIS_Azure_1.1.0_4.14" , "CIS_Azure_1.1.0_4.15" , "CIS_Azure_1.1.0_4.16" , "CIS_Azure_1.1.0_4.17" , "CIS_Azure_1.1.0_5.1.7" ] } , { 5 items policyDefinitionReferenceId: "b2d3e5a2-97ab-5497-565a-71172a729d93" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/b2d3e5a2-97ab-5497-565a-71172a729d93 Protect passwords with encryption , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 6 items "CIS_Azure_1.1.0_3.1" , "CIS_Azure_1.1.0_3.5" , "CIS_Azure_1.1.0_4.11" , "CIS_Azure_1.1.0_4.13" , "CIS_Azure_1.1.0_9.2" , "CIS_Azure_1.1.0_9.3" ] } , { 5 items policyDefinitionReferenceId: "26daf649-22d1-97e9-2a8a-01b182194d59" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/26daf649-22d1-97e9-2a8a-01b182194d59 Configure workstations to check for digital certificates , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 6 items "CIS_Azure_1.1.0_3.1" , "CIS_Azure_1.1.0_3.5" , "CIS_Azure_1.1.0_4.11" , "CIS_Azure_1.1.0_4.13" , "CIS_Azure_1.1.0_9.2" , "CIS_Azure_1.1.0_9.3" ] } , { 5 items policyDefinitionReferenceId: "51e4b233-8ee3-8bdc-8f5f-f33bd0d229b7" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/51e4b233-8ee3-8bdc-8f5f-f33bd0d229b7 Define a physical key management process , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 3 items "CIS_Azure_1.1.0_3.2" , "CIS_Azure_1.1.0_8.1" , "CIS_Azure_1.1.0_8.2" ] } , { 5 items policyDefinitionReferenceId: "c4ccd607-702b-8ae6-8eeb-fc3339cd4b42" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/c4ccd607-702b-8ae6-8eeb-fc3339cd4b42 Define cryptographic use , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 3 items "CIS_Azure_1.1.0_3.2" , "CIS_Azure_1.1.0_8.1" , "CIS_Azure_1.1.0_8.2" ] } , { 5 items } , { 5 items policyDefinitionReferenceId: "7a0ecd94-3699-5273-76a5-edb8499f655a" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/7a0ecd94-3699-5273-76a5-edb8499f655a Determine assertion requirements , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 3 items "CIS_Azure_1.1.0_3.2" , "CIS_Azure_1.1.0_8.1" , "CIS_Azure_1.1.0_8.2" ] } , { 5 items policyDefinitionReferenceId: "97d91b33-7050-237b-3e23-a77d57d84e13" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/97d91b33-7050-237b-3e23-a77d57d84e13 Issue public key certificates , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 3 items "CIS_Azure_1.1.0_3.2" , "CIS_Azure_1.1.0_8.1" , "CIS_Azure_1.1.0_8.2" ] } , { 5 items policyDefinitionReferenceId: "9c276cf3-596f-581a-7fbd-f5e46edaa0f4" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/9c276cf3-596f-581a-7fbd-f5e46edaa0f4 Manage symmetric cryptographic keys , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 3 items "CIS_Azure_1.1.0_3.2" , "CIS_Azure_1.1.0_8.1" , "CIS_Azure_1.1.0_8.2" ] } , { 5 items policyDefinitionReferenceId: "8d140e8b-76c7-77de-1d46-ed1b2e112444" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/8d140e8b-76c7-77de-1d46-ed1b2e112444 Restrict access to private keys , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 3 items "CIS_Azure_1.1.0_3.2" , "CIS_Azure_1.1.0_8.1" , "CIS_Azure_1.1.0_8.2" ] } , { 5 items } , { 5 items policyDefinitionReferenceId: "4502e506-5f35-0df4-684f-b326e3cc7093" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/4502e506-5f35-0df4-684f-b326e3cc7093 Terminate user session automatically , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 1 item ] } , { 5 items policyDefinitionReferenceId: "a3e98638-51d4-4e28-910a-60e98c1a756f" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/a3e98638-51d4-4e28-910a-60e98c1a756f Configure Azure Audit capabilities , definitionVersion: 1.*.*1.1.1 , parameters: {} , groupNames: [ 1 item ] } , { 5 items } , { 5 items } , { 5 items } , { 5 items policyDefinitionReferenceId: "333b4ada-4a02-0648-3d4d-d812974f1bb2" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/333b4ada-4a02-0648-3d4d-d812974f1bb2 Govern and monitor audit processing activities , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 5 items "CIS_Azure_1.1.0_4.3" , "CIS_Azure_1.1.0_4.18" , "CIS_Azure_1.1.0_5.1.1" , "CIS_Azure_1.1.0_5.1.3" , "CIS_Azure_1.1.0_5.1.4" ] } , { 5 items policyDefinitionReferenceId: "1ecb79d7-1a06-9a3b-3be8-f434d04d1ec1" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/1ecb79d7-1a06-9a3b-3be8-f434d04d1ec1 Adhere to retention periods defined , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 7 items "CIS_Azure_1.1.0_4.3" , "CIS_Azure_1.1.0_4.18" , "CIS_Azure_1.1.0_5.1.1" , "CIS_Azure_1.1.0_5.1.2" , "CIS_Azure_1.1.0_5.1.3" , "CIS_Azure_1.1.0_5.1.4" , "CIS_Azure_1.1.0_6.4" ] } , { 5 items policyDefinitionReferenceId: "efef28d0-3226-966a-a1e8-70e89c1b30bc" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/efef28d0-3226-966a-a1e8-70e89c1b30bc Retain security policies and procedures , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 7 items "CIS_Azure_1.1.0_4.3" , "CIS_Azure_1.1.0_4.18" , "CIS_Azure_1.1.0_5.1.1" , "CIS_Azure_1.1.0_5.1.2" , "CIS_Azure_1.1.0_5.1.3" , "CIS_Azure_1.1.0_5.1.4" , "CIS_Azure_1.1.0_6.4" ] } , { 5 items policyDefinitionReferenceId: "7c7032fe-9ce6-9092-5890-87a1a3755db1" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/7c7032fe-9ce6-9092-5890-87a1a3755db1 Retain terminated user data , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 7 items "CIS_Azure_1.1.0_4.3" , "CIS_Azure_1.1.0_4.18" , "CIS_Azure_1.1.0_5.1.1" , "CIS_Azure_1.1.0_5.1.2" , "CIS_Azure_1.1.0_5.1.3" , "CIS_Azure_1.1.0_5.1.4" , "CIS_Azure_1.1.0_6.4" ] } , { 5 items policyDefinitionReferenceId: "9622aaa9-5c49-40e2-5bf8-660b7cd23deb" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/9622aaa9-5c49-40e2-5bf8-660b7cd23deb Alert personnel of information spillage , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 11 items "CIS_Azure_1.1.0_4.6" , "CIS_Azure_1.1.0_4.7" , "CIS_Azure_1.1.0_5.2.1" , "CIS_Azure_1.1.0_5.2.2" , "CIS_Azure_1.1.0_5.2.3" , "CIS_Azure_1.1.0_5.2.4" , "CIS_Azure_1.1.0_5.2.5" , "CIS_Azure_1.1.0_5.2.6" , "CIS_Azure_1.1.0_5.2.7" , "CIS_Azure_1.1.0_5.2.8" , "CIS_Azure_1.1.0_5.2.9" ] } , { 5 items policyDefinitionReferenceId: "2b4e134f-1e4c-2bff-573e-082d85479b6e" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/2b4e134f-1e4c-2bff-573e-082d85479b6e Develop an incident response plan , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 11 items "CIS_Azure_1.1.0_4.6" , "CIS_Azure_1.1.0_4.7" , "CIS_Azure_1.1.0_5.2.1" , "CIS_Azure_1.1.0_5.2.2" , "CIS_Azure_1.1.0_5.2.3" , "CIS_Azure_1.1.0_5.2.4" , "CIS_Azure_1.1.0_5.2.5" , "CIS_Azure_1.1.0_5.2.6" , "CIS_Azure_1.1.0_5.2.7" , "CIS_Azure_1.1.0_5.2.8" , "CIS_Azure_1.1.0_5.2.9" ] } , { 5 items policyDefinitionReferenceId: "af38215f-70c4-0cd6-40c2-c52d86690a45" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/af38215f-70c4-0cd6-40c2-c52d86690a45 Set automated notifications for new and trending cloud applications in your organization , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 11 items "CIS_Azure_1.1.0_4.6" , "CIS_Azure_1.1.0_4.7" , "CIS_Azure_1.1.0_5.2.1" , "CIS_Azure_1.1.0_5.2.2" , "CIS_Azure_1.1.0_5.2.3" , "CIS_Azure_1.1.0_5.2.4" , "CIS_Azure_1.1.0_5.2.5" , "CIS_Azure_1.1.0_5.2.6" , "CIS_Azure_1.1.0_5.2.7" , "CIS_Azure_1.1.0_5.2.8" , "CIS_Azure_1.1.0_5.2.9" ] } , { 5 items policyDefinitionReferenceId: "2c843d78-8f64-92b5-6a9b-e8186c0e7eb6" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/2c843d78-8f64-92b5-6a9b-e8186c0e7eb6 Enable dual or joint authorization , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 2 items "CIS_Azure_1.1.0_5.1.5" , "CIS_Azure_1.1.0_5.1.6" ] } , { 5 items policyDefinitionReferenceId: "0e696f5a-451f-5c15-5532-044136538491" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/0e696f5a-451f-5c15-5532-044136538491 Protect audit information , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 2 items "CIS_Azure_1.1.0_5.1.5" , "CIS_Azure_1.1.0_5.1.6" ] } , { 5 items policyDefinitionReferenceId: "c0559109-6a27-a217-6821-5a6d44f92897" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/c0559109-6a27-a217-6821-5a6d44f92897 Maintain integrity of audit system , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 1 item ] } , { 5 items policyDefinitionReferenceId: "ece8bb17-4080-5127-915f-dc7267ee8549" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/ece8bb17-4080-5127-915f-dc7267ee8549 Verify security functions , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 1 item ] } , { 5 items } , { 5 items policyDefinitionReferenceId: "3ad7f0bc-3d03-0585-4d24-529779bb02c2" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/3ad7f0bc-3d03-0585-4d24-529779bb02c2 Maintain availability of information , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 1 item ] } , { 5 items policyDefinitionReferenceId: "e336d5f4-4d8f-0059-759c-ae10f63d1747" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/e336d5f4-4d8f-0059-759c-ae10f63d1747 Enforce user uniqueness , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 1 item ] } , { 5 items } , { 5 items policyDefinitionReferenceId: "6f1de470-79f3-1572-866e-db0771352fc8" , policyDefinitionId: /providers/Microsoft.Authorization/policyDefinitions/6f1de470-79f3-1572-866e-db0771352fc8 Authenticate to cryptographic module , definitionVersion: 1.*.*1.1.0 , parameters: {} , groupNames: [ 2 items "CIS_Azure_1.1.0_9.1" , "CIS_Azure_1.1.0_9.4" ] } ] , policyDefinitionGroups: [ 111 items { 2 items name: "CIS_Azure_1.1.0_1.1" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.1" } , { 2 items name: "CIS_Azure_1.1.0_1.5" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.5" } , { 2 items name: "CIS_Azure_1.1.0_1.6" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.6" } , { 2 items name: "CIS_Azure_1.1.0_1.7" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.7" } , { 2 items name: "CIS_Azure_1.1.0_1.15" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.15" } , { 2 items name: "CIS_Azure_1.1.0_1.21" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.21" } , { 2 items name: "CIS_Azure_1.1.0_1.22" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.22" } , { 2 items name: "CIS_Azure_1.1.0_1.2" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.2" } , { 2 items name: "CIS_Azure_1.1.0_1.3" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.3" } , { 2 items name: "CIS_Azure_1.1.0_1.4" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.4" } , { 2 items name: "CIS_Azure_1.1.0_1.8" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.8" } , { 2 items name: "CIS_Azure_1.1.0_1.9" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.9" } , { 2 items name: "CIS_Azure_1.1.0_1.10" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.10" } , { 2 items name: "CIS_Azure_1.1.0_1.11" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.11" } , { 2 items name: "CIS_Azure_1.1.0_1.12" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.12" } , { 2 items name: "CIS_Azure_1.1.0_1.13" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.13" } , { 2 items name: "CIS_Azure_1.1.0_1.14" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.14" } , { 2 items name: "CIS_Azure_1.1.0_1.16" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.16" } , { 2 items name: "CIS_Azure_1.1.0_1.17" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.17" } , { 2 items name: "CIS_Azure_1.1.0_1.18" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.18" } , { 2 items name: "CIS_Azure_1.1.0_1.19" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.19" } , { 2 items name: "CIS_Azure_1.1.0_1.20" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.20" } , { 2 items name: "CIS_Azure_1.1.0_1.23" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_1.23" } , { 2 items name: "CIS_Azure_1.1.0_2.1" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_2.1" } , { 2 items name: "CIS_Azure_1.1.0_2.2" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_2.2" } , { 2 items name: "CIS_Azure_1.1.0_2.3" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_2.3" } , { 2 items name: "CIS_Azure_1.1.0_2.4" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_2.4" } , { 2 items name: "CIS_Azure_1.1.0_2.5" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_2.5" } , { 2 items name: "CIS_Azure_1.1.0_2.6" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_2.6" } , { 2 items name: "CIS_Azure_1.1.0_2.7" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_2.7" } , { 2 items name: "CIS_Azure_1.1.0_2.8" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_2.8" } , { 2 items name: "CIS_Azure_1.1.0_2.9" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_2.9" } , { 2 items name: "CIS_Azure_1.1.0_2.10" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_2.10" } , { 2 items name: "CIS_Azure_1.1.0_2.11" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_2.11" } , { 2 items name: "CIS_Azure_1.1.0_2.12" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_2.12" } , { 2 items name: "CIS_Azure_1.1.0_2.13" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_2.13" } , { 2 items name: "CIS_Azure_1.1.0_2.14" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_2.14" } , { 2 items name: "CIS_Azure_1.1.0_2.15" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_2.15" } , { 2 items name: "CIS_Azure_1.1.0_2.16" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_2.16" } , { 2 items name: "CIS_Azure_1.1.0_2.17" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_2.17" } , { 2 items name: "CIS_Azure_1.1.0_2.18" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_2.18" } , { 2 items name: "CIS_Azure_1.1.0_2.19" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_2.19" } , { 2 items name: "CIS_Azure_1.1.0_3.1" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_3.1" } , { 2 items name: "CIS_Azure_1.1.0_3.2" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_3.2" } , { 2 items name: "CIS_Azure_1.1.0_3.4" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_3.4" } , { 2 items name: "CIS_Azure_1.1.0_3.5" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_3.5" } , { 2 items name: "CIS_Azure_1.1.0_3.6" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_3.6" } , { 2 items name: "CIS_Azure_1.1.0_3.3" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_3.3" } , { 2 items name: "CIS_Azure_1.1.0_3.7" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_3.7" } , { 2 items name: "CIS_Azure_1.1.0_3.8" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_3.8" } , { 2 items name: "CIS_Azure_1.1.0_4.1" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_4.1" } , { 2 items name: "CIS_Azure_1.1.0_4.2" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_4.2" } , { 2 items name: "CIS_Azure_1.1.0_4.3" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_4.3" } , { 2 items name: "CIS_Azure_1.1.0_4.4" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_4.4" } , { 2 items name: "CIS_Azure_1.1.0_4.5" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_4.5" } , { 2 items name: "CIS_Azure_1.1.0_4.6" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_4.6" } , { 2 items name: "CIS_Azure_1.1.0_4.7" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_4.7" } , { 2 items name: "CIS_Azure_1.1.0_4.8" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_4.8" } , { 2 items name: "CIS_Azure_1.1.0_4.9" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_4.9" } , { 2 items name: "CIS_Azure_1.1.0_4.10" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_4.10" } , { 2 items name: "CIS_Azure_1.1.0_4.11" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_4.11" } , { 2 items name: "CIS_Azure_1.1.0_4.12" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_4.12" } , { 2 items name: "CIS_Azure_1.1.0_4.13" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_4.13" } , { 2 items name: "CIS_Azure_1.1.0_4.14" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_4.14" } , { 2 items name: "CIS_Azure_1.1.0_4.15" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_4.15" } , { 2 items name: "CIS_Azure_1.1.0_4.16" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_4.16" } , { 2 items name: "CIS_Azure_1.1.0_4.17" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_4.17" } , { 2 items name: "CIS_Azure_1.1.0_4.18" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_4.18" } , { 2 items name: "CIS_Azure_1.1.0_4.19" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_4.19" } , { 2 items name: "CIS_Azure_1.1.0_5.1.1" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_5.1.1" } , { 2 items name: "CIS_Azure_1.1.0_5.1.2" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_5.1.2" } , { 2 items name: "CIS_Azure_1.1.0_5.1.3" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_5.1.3" } , { 2 items name: "CIS_Azure_1.1.0_5.1.4" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_5.1.4" } , { 2 items name: "CIS_Azure_1.1.0_5.1.5" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_5.1.5" } , { 2 items name: "CIS_Azure_1.1.0_5.1.6" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_5.1.6" } , { 2 items name: "CIS_Azure_1.1.0_5.1.7" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_5.1.7" } , { 2 items name: "CIS_Azure_1.1.0_5.2.1" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_5.2.1" } , { 2 items name: "CIS_Azure_1.1.0_5.2.2" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_5.2.2" } , { 2 items name: "CIS_Azure_1.1.0_5.2.3" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_5.2.3" } , { 2 items name: "CIS_Azure_1.1.0_5.2.4" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_5.2.4" } , { 2 items name: "CIS_Azure_1.1.0_5.2.5" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_5.2.5" } , { 2 items name: "CIS_Azure_1.1.0_5.2.6" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_5.2.6" } , { 2 items name: "CIS_Azure_1.1.0_5.2.7" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_5.2.7" } , { 2 items name: "CIS_Azure_1.1.0_5.2.8" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_5.2.8" } , { 2 items name: "CIS_Azure_1.1.0_5.2.9" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_5.2.9" } , { 2 items name: "CIS_Azure_1.1.0_6.1" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_6.1" } , { 2 items name: "CIS_Azure_1.1.0_6.2" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_6.2" } , { 2 items name: "CIS_Azure_1.1.0_6.3" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_6.3" } , { 2 items name: "CIS_Azure_1.1.0_6.5" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_6.5" } , { 2 items name: "CIS_Azure_1.1.0_6.4" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_6.4" } , { 2 items name: "CIS_Azure_1.1.0_7.1" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_7.1" } , { 2 items name: "CIS_Azure_1.1.0_7.2" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_7.2" } , { 2 items name: "CIS_Azure_1.1.0_7.3" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_7.3" } , { 2 items name: "CIS_Azure_1.1.0_7.4" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_7.4" } , { 2 items name: "CIS_Azure_1.1.0_7.5" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_7.5" } , { 2 items name: "CIS_Azure_1.1.0_7.6" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_7.6" } , { 2 items name: "CIS_Azure_1.1.0_8.1" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_8.1" } , { 2 items name: "CIS_Azure_1.1.0_8.2" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_8.2" } , { 2 items name: "CIS_Azure_1.1.0_8.4" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_8.4" } , { 2 items name: "CIS_Azure_1.1.0_8.5" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_8.5" } , { 2 items name: "CIS_Azure_1.1.0_8.3" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_8.3" } , { 2 items name: "CIS_Azure_1.1.0_9.1" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_9.1" } , { 2 items name: "CIS_Azure_1.1.0_9.2" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_9.2" } , { 2 items name: "CIS_Azure_1.1.0_9.3" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_9.3" } , { 2 items name: "CIS_Azure_1.1.0_9.4" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_9.4" } , { 2 items name: "CIS_Azure_1.1.0_9.5" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_9.5" } , { 2 items name: "CIS_Azure_1.1.0_9.6" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_9.6" } , { 2 items name: "CIS_Azure_1.1.0_9.7" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_9.7" } , { 2 items name: "CIS_Azure_1.1.0_9.8" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_9.8" } , { 2 items name: "CIS_Azure_1.1.0_9.9" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_9.9" } , { 2 items name: "CIS_Azure_1.1.0_9.10" , additionalMetadataId: "/providers/Microsoft.PolicyInsights/policyMetadata/CIS_Azure_1.1.0_9.10" } ] , versions: [ 9 items "16.10.0" , "16.9.0" , "16.8.0" , "16.7.0" , "16.6.0" , "16.5.0" , "16.4.0" , "16.3.0" , "16.2.0" ] }