Policy DisplayName |
Policy Id |
Category |
Version |
Versioning |
Effect |
Roles# |
Roles |
State |
policy in AzUSGov |
A maximum of 3 owners should be designated for your subscription |
4f11b553-d42e-4e3a-89be-32ca364cad4c |
Security Center |
3.0.0 |
1x 3.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
A vulnerability assessment solution should be enabled on your virtual machines |
501541f7-f7e7-4cd6-868c-4190fdad3ac9 |
Security Center |
3.0.0 |
1x 3.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Add system-assigned managed identity to enable Guest Configuration assignments on virtual machines with no identities |
3cf2ab00-13f1-4d0c-8971-2ac904541a7e |
Guest Configuration |
4.1.0 |
2x 4.1.0, 4.0.0 |
Fixed modify |
1 |
Contributor |
GA |
true |
Add system-assigned managed identity to enable Guest Configuration assignments on VMs with a user-assigned identity |
497dff13-db2a-4c0f-8603-28fa3b331ab6 |
Guest Configuration |
4.1.0 |
2x 4.1.0, 4.0.0 |
Fixed modify |
1 |
Contributor |
GA |
true |
An Azure Active Directory administrator should be provisioned for SQL servers |
1f314764-cb73-4fc9-b863-8eca98ac36e9 |
SQL |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
App Service apps should have remote debugging turned off |
cb510bfd-1cba-4d9f-a230-cb0976f4bb71 |
App Service |
2.0.0 |
1x 2.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
App Service apps should not have CORS configured to allow every resource to access your apps |
5744710e-cc2f-4ee8-8809-3b11e89f4bc9 |
App Service |
2.0.0 |
1x 2.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
App Service apps should only be accessible over HTTPS |
a4af4a39-4135-47fb-b175-47fbdf85311d |
App Service |
4.0.0 |
1x 4.0.0 |
Default Audit Allowed Audit, Disabled, Deny |
0 |
|
GA |
true |
App Service apps should use the latest TLS version |
f0e6e85b-9b9f-4a4b-b67b-f730d42f1b0b |
App Service |
2.2.0 |
3x 2.2.0, 2.1.0, 2.0.1 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Audit diagnostic setting for selected resource types |
7f89b1eb-583c-429a-8828-af049802c1d9 |
Monitoring |
2.0.1 |
1x 2.0.1 |
Fixed AuditIfNotExists |
0 |
|
GA |
true |
Audit Linux machines that allow remote connections from accounts without passwords |
ea53dbee-c6c9-4f0e-9f9e-de0039b78023 |
Guest Configuration |
3.1.0 |
2x 3.1.0, 3.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Audit Linux machines that have accounts without passwords |
f6ec09a3-78bf-4f8f-99dc-6c77182d0f99 |
Guest Configuration |
3.1.0 |
2x 3.1.0, 3.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Audit virtual machines without disaster recovery configured |
0015ea4d-51ff-4ce3-8d8c-f3f8f0179a56 |
Compute |
1.0.0 |
1x 1.0.0 |
Fixed auditIfNotExists |
0 |
|
GA |
true |
Audit Windows machines that have the specified members in the Administrators group |
69bf4abd-ca1e-4cf6-8b5a-762d42e61d4f |
Guest Configuration |
2.0.0 |
1x 2.0.0 |
Fixed auditIfNotExists |
0 |
|
GA |
true |
Azure DDoS Protection should be enabled |
a7aca53f-2ed4-4466-a25e-0b45ade68efd |
Security Center |
3.0.1 |
2x 3.0.1, 3.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Azure Defender for SQL should be enabled for unprotected Azure SQL servers |
abfb4388-5bf4-4ad7-ba82-2cd2f41ceae9 |
SQL |
2.0.1 |
1x 2.0.1 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Azure Defender for SQL should be enabled for unprotected SQL Managed Instances |
abfb7388-5bf4-4ad7-ba99-2cd2f41cebb9 |
SQL |
1.0.2 |
1x 1.0.2 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Blocked accounts with owner permissions on Azure resources should be removed |
0cfea604-3201-4e14-88fc-fae4c427a6c5 |
Security Center |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Blocked accounts with read and write permissions on Azure resources should be removed |
8d7e1fde-fe26-4b5f-8108-f8e432cbc2be |
Security Center |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Deploy the Linux Guest Configuration extension to enable Guest Configuration assignments on Linux VMs |
331e8ea8-378a-410f-a2e5-ae22f38bb0da |
Guest Configuration |
3.2.0 |
3x 3.2.0, 3.1.0, 3.0.0 |
Fixed deployIfNotExists |
1 |
Contributor |
GA |
true |
Deploy the Windows Guest Configuration extension to enable Guest Configuration assignments on Windows VMs |
385f5831-96d4-41db-9a3c-cd3af78aaae6 |
Guest Configuration |
1.3.0 |
2x 1.3.0, 1.2.0 |
Fixed deployIfNotExists |
1 |
Contributor |
GA |
true |
Function apps should have remote debugging turned off |
0e60b895-3786-45da-8377-9c6b4b6ac5f9 |
App Service |
2.1.0 |
2x 2.1.0, 2.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Function apps should only be accessible over HTTPS |
6d555dd1-86f2-4f1c-8ed7-5abae7c6cbab |
App Service |
5.1.0 |
2x 5.1.0, 5.0.0 |
Default Audit Allowed Audit, Disabled, Deny |
0 |
|
GA |
true |
Function apps should use the latest TLS version |
f9d614c5-c173-4d56-95a7-b4437057d193 |
App Service |
2.3.0 |
4x 2.3.0, 2.2.0, 2.1.0, 2.0.1 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Guest accounts with owner permissions on Azure resources should be removed |
339353f6-2387-4a45-abe4-7f529d121046 |
Security Center |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Guest accounts with write permissions on Azure resources should be removed |
94e1c2ac-cbbe-4cac-a2b5-389c812dee87 |
Security Center |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Internet-facing virtual machines should be protected with network security groups |
f6de0be7-9a8a-4b8a-b349-43cf02d22f7c |
Security Center |
3.0.0 |
1x 3.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Management ports of virtual machines should be protected with just-in-time network access control |
b0f33259-77d7-4c9e-aac6-3aabcfae693c |
Security Center |
3.0.0 |
1x 3.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Microsoft IaaSAntimalware extension should be deployed on Windows servers |
9b597639-28e4-48eb-b506-56b05d366257 |
Compute |
1.1.0 |
1x 1.1.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Only secure connections to your Azure Cache for Redis should be enabled |
22bee202-a82f-4305-9a2a-6d7f44d4dedb |
Cache |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Secure transfer to storage accounts should be enabled |
404c3081-a854-4457-ae30-26a93ef643f9 |
Storage |
2.0.0 |
1x 2.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Service Fabric clusters should only use Azure Active Directory for client authentication |
b54ed75b-3e1a-44ac-a333-05ba39b99ff0 |
Service Fabric |
1.1.0 |
1x 1.1.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
SQL databases should have vulnerability findings resolved |
feedbf84-6b99-488c-acc2-71c829aa5ffc |
Security Center |
4.1.0 |
1x 4.1.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Storage accounts should restrict network access |
34c877ad-507e-4c82-993e-3452a6e0ad3c |
Storage |
1.1.1 |
1x 1.1.1 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
There should be more than one owner assigned to your subscription |
09024ccc-0c5f-475e-9457-b7c0d9ed487b |
Security Center |
3.0.0 |
1x 3.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Transparent Data Encryption on SQL databases should be enabled |
17k78e20-9358-41c9-923c-fb736d382a12 |
SQL |
2.0.0 |
1x 2.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Vulnerability assessment should be enabled on SQL Managed Instance |
1b7aa243-30e4-4c9e-bca8-d0d3022b634a |
SQL |
1.0.1 |
1x 1.0.1 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Vulnerability assessment should be enabled on your SQL servers |
ef2a8f2a-b3d9-49cd-a8a8-9a3aaaf647d9 |
SQL |
3.0.0 |
1x 3.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Windows machines should be configured to use secure communication protocols |
5752e6d6-1206-46d8-8ab1-ecc2f71a8112 |
Guest Configuration |
4.1.1 |
1x 4.1.1 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Windows machines should meet requirements for 'Security Settings - Account Policies' |
f2143251-70de-4e81-87a8-36cee5a2f29d |
Guest Configuration |
3.0.0 |
1x 3.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |