| Policy DisplayName | 
                            Policy Id | 
                            Category | 
                            Version | 
                            Versioning | 
                            Effect | 
                            Roles# | 
                            Roles | 
                            State | 
                            policy in AzUSGov | 
                        
                                            
                            | [Preview]: All Internet traffic should be routed via your deployed Azure Firewall | 
                            fc5e4038-4584-4632-8c85-c0448d374b2c | 
                            Network | 
                            3.0.0-preview | 
                            1x 3.0.0-preview | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            Preview | 
                            unknown | 
                        
                        
                            | [Preview]: Azure Recovery Services vaults should use customer-managed keys for encrypting backup data | 
                            2e94d99a-8a36-4563-bc77-810d8893b671 | 
                            Backup | 
                            1.0.0-preview | 
                            1x 1.0.0-preview | 
                            Default Audit Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            Preview | 
                            true | 
                        
                        
                            | [Preview]: Azure Recovery Services vaults should use private link for backup | 
                            deeddb44-9f94-4903-9fa0-081d524406e3 | 
                            Backup | 
                            2.0.0-preview | 
                            1x 2.0.0-preview | 
                            Default Audit Allowed Audit, Disabled | 
                            0 | 
                             | 
                            Preview | 
                            unknown | 
                        
                        
                            | [Preview]: Network traffic data collection agent should be installed on Linux virtual machines | 
                            04c4380f-3fae-46e8-96c9-30193528f602 | 
                            Monitoring | 
                            1.0.2-preview | 
                            1x 1.0.2-preview | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            Preview | 
                            true | 
                        
                        
                            | [Preview]: Network traffic data collection agent should be installed on Windows virtual machines | 
                            2f2ee1de-44aa-4762-b6bd-0893fc3f306d | 
                            Monitoring | 
                            1.0.2-preview | 
                            1x 1.0.2-preview | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            Preview | 
                            true | 
                        
                        
                            | [Preview]: Recovery Services vaults should use private link | 
                            11e3da8c-1d68-4392-badd-0ff3c43ab5b0 | 
                            Site Recovery | 
                            1.0.0-preview | 
                            1x 1.0.0-preview | 
                            Default Audit Allowed Audit, Disabled | 
                            0 | 
                             | 
                            Preview | 
                            unknown | 
                        
                        
                            | [Preview]: Secure Boot should be enabled on supported Windows virtual machines | 
                            97566dd7-78ae-4997-8b36-1c7bfe0d8121 | 
                            Security Center | 
                            4.0.0-preview | 
                            1x 4.0.0-preview | 
                            Default Audit Allowed Audit, Disabled | 
                            0 | 
                             | 
                            Preview | 
                            true | 
                        
                        
                            | [Preview]: vTPM should be enabled on supported virtual machines | 
                            1c30f9cd-b84c-49cc-aa2c-9288447cc3b3 | 
                            Security Center | 
                            2.0.0-preview | 
                            1x 2.0.0-preview | 
                            Default Audit Allowed Audit, Disabled | 
                            0 | 
                             | 
                            Preview | 
                            true | 
                        
                        
                            | A maximum of 3 owners should be designated for your subscription | 
                            4f11b553-d42e-4e3a-89be-32ca364cad4c | 
                            Security Center | 
                            3.0.0 | 
                            1x 3.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | A vulnerability assessment solution should be enabled on your virtual machines | 
                            501541f7-f7e7-4cd6-868c-4190fdad3ac9 | 
                            Security Center | 
                            3.0.0 | 
                            1x 3.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Activity log should be retained for at least one year | 
                            b02aacc0-b073-424e-8298-42b22829ee0a | 
                            Monitoring | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | All flow log resources should be in enabled state | 
                            27960feb-a23c-4577-8d36-ef8b5f35e0be | 
                            Network | 
                            1.0.1 | 
                            1x 1.0.1 | 
                            Default Audit Allowed Audit, Disabled | 
                            0 | 
                             | 
                            GA | 
                            unknown | 
                        
                        
                            | All network ports should be restricted on network security groups associated to your virtual machine | 
                            9daedab3-fb2d-461e-b861-71790eead4f6 | 
                            Security Center | 
                            3.0.0 | 
                            1x 3.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | App Configuration should use a customer-managed key | 
                            967a4b4b-2da9-43c1-b7d0-f98d0d74d0b1 | 
                            App Configuration | 
                            1.1.0 | 
                            1x 1.1.0 | 
                            Default Audit Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            GA | 
                            unknown | 
                        
                        
                            | App Service apps should have Client Certificates (Incoming client certificates) enabled | 
                            19dd1db6-f442-49cf-a838-b0786b4401ef | 
                            App Service | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | App Service apps should have remote debugging turned off | 
                            cb510bfd-1cba-4d9f-a230-cb0976f4bb71 | 
                            App Service | 
                            2.0.0 | 
                            1x 2.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | App Service apps should only be accessible over HTTPS | 
                            a4af4a39-4135-47fb-b175-47fbdf85311d | 
                            App Service | 
                            4.0.0 | 
                            1x 4.0.0 | 
                            Default Audit Allowed Audit, Disabled, Deny | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | App Service apps should use the latest TLS version | 
                            f0e6e85b-9b9f-4a4b-b67b-f730d42f1b0b | 
                            App Service | 
                            2.2.0 | 
                            3x 2.2.0, 2.1.0, 2.0.1 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | App Service Environment should have internal encryption enabled | 
                            fb74e86f-d351-4b8d-b034-93da7391c01f | 
                            App Service | 
                            1.0.1 | 
                            1x 1.0.1 | 
                            Default Audit Allowed Audit, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Application Insights components should block log ingestion and querying from public networks | 
                            1bc02227-0cb6-4e11-8f53-eb0b22eab7e8 | 
                            Monitoring | 
                            1.1.0 | 
                            1x 1.1.0 | 
                            Default Audit Allowed audit, Audit, deny, Deny, disabled, Disabled | 
                            0 | 
                             | 
                            GA | 
                            unknown | 
                        
                        
                            | Audit usage of custom RBAC roles | 
                            a451c1ef-c6ca-483d-87ed-f49761e3ffb5 | 
                            General | 
                            1.0.1 | 
                            1x 1.0.1 | 
                            Default Audit Allowed Audit, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Audit virtual machines without disaster recovery configured | 
                            0015ea4d-51ff-4ce3-8d8c-f3f8f0179a56 | 
                            Compute | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Fixed auditIfNotExists | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Automation account variables should be encrypted | 
                            3657f5a0-770e-44a3-b44e-9431ba1e9735 | 
                            Automation | 
                            1.1.0 | 
                            1x 1.1.0 | 
                            Default Audit Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Azure Backup should be enabled for Virtual Machines | 
                            013e242c-8828-4970-87b3-ab247555486d | 
                            Backup | 
                            3.0.0 | 
                            1x 3.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Azure Cosmos DB accounts should have firewall rules | 
                            862e97cf-49fc-4a5c-9de4-40d4e2e7c8eb | 
                            Cosmos DB | 
                            2.1.0 | 
                            2x 2.1.0, 2.0.0 | 
                            Default Deny Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Azure Cosmos DB accounts should use customer-managed keys to encrypt data at rest | 
                            1f905d99-2ab7-462c-a6b0-f709acca6c8f | 
                            Cosmos DB | 
                            1.1.0 | 
                            1x 1.1.0 | 
                            Default Audit Allowed audit, Audit, deny, Deny, disabled, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Azure Defender for App Service should be enabled | 
                            2913021d-f2fd-4f3d-b958-22354e2bdbcb | 
                            Security Center | 
                            1.0.3 | 
                            1x 1.0.3 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            unknown | 
                        
                        
                            | Azure Defender for Azure SQL Database servers should be enabled | 
                            7fe3b40f-802b-4cdd-8bd4-fd799c948cc2 | 
                            Security Center | 
                            1.0.2 | 
                            1x 1.0.2 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Azure Defender for Key Vault should be enabled | 
                            0e6763cc-5078-4e64-889d-ff4d9a839047 | 
                            Security Center | 
                            1.0.3 | 
                            1x 1.0.3 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            unknown | 
                        
                        
                            | Azure Defender for open-source relational databases should be enabled | 
                            0a9fbe0d-c5c4-4da8-87d8-f4fd77338835 | 
                            Security Center | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            unknown | 
                        
                        
                            | Azure Defender for Resource Manager should be enabled | 
                            c3d20c29-b36d-48fe-808b-99a87530ad99 | 
                            Security Center | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Azure Defender for servers should be enabled | 
                            4da35fc9-c9e7-4960-aec9-797fe7d9051d | 
                            Security Center | 
                            1.0.3 | 
                            1x 1.0.3 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Azure Defender for SQL servers on machines should be enabled | 
                            6581d072-105e-4418-827f-bd446d56421b | 
                            Security Center | 
                            1.0.2 | 
                            1x 1.0.2 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            unknown | 
                        
                        
                            | Azure Defender for SQL should be enabled for unprotected Azure SQL servers | 
                            abfb4388-5bf4-4ad7-ba82-2cd2f41ceae9 | 
                            SQL | 
                            2.0.1 | 
                            1x 2.0.1 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Azure Defender for SQL should be enabled for unprotected SQL Managed Instances | 
                            abfb7388-5bf4-4ad7-ba99-2cd2f41cebb9 | 
                            SQL | 
                            1.0.2 | 
                            1x 1.0.2 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Azure Key Vault should have firewall enabled or public network access disabled | 
                            55615ac9-af46-4a59-874e-391cc3dfb490 | 
                            Key Vault | 
                            3.3.0 | 
                            2x 3.3.0, 3.2.1 | 
                            Default Audit Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Azure Key Vaults should use private link | 
                            a6abeaec-4d90-4a02-805f-6b26c4d3fbe9 | 
                            Key Vault | 
                            1.2.1 | 
                            1x 1.2.1 | 
                            Default Audit Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Azure Kubernetes Service clusters should have Defender profile enabled | 
                            a1840de2-8088-4ea8-b153-b4c723e9cb01 | 
                            Kubernetes | 
                            2.0.1 | 
                            1x 2.0.1 | 
                            Default Audit Allowed Audit, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Azure Monitor log profile should collect logs for categories 'write,' 'delete,' and 'action' | 
                            1a4e592a-6a6e-44a5-9814-e36264ca96e7 | 
                            Monitoring | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Azure Monitor Logs clusters should be created with infrastructure-encryption enabled (double encryption) | 
                            ea0dfaed-95fb-448c-934e-d6e713ce393d | 
                            Monitoring | 
                            1.1.0 | 
                            1x 1.1.0 | 
                            Default Audit Allowed audit, Audit, deny, Deny, disabled, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Azure Monitor Logs clusters should be encrypted with customer-managed key | 
                            1f68a601-6e6d-4e42-babf-3f643a047ea2 | 
                            Monitoring | 
                            1.1.0 | 
                            1x 1.1.0 | 
                            Default Audit Allowed audit, Audit, deny, Deny, disabled, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Azure Monitor Logs for Application Insights should be linked to a Log Analytics workspace | 
                            d550e854-df1a-4de9-bf44-cd894b39a95e | 
                            Monitoring | 
                            1.1.0 | 
                            1x 1.1.0 | 
                            Default Audit Allowed audit, Audit, deny, Deny, disabled, Disabled | 
                            0 | 
                             | 
                            GA | 
                            unknown | 
                        
                        
                            | Azure Monitor should collect activity logs from all regions | 
                            41388f1c-2db0-4c25-95b2-35d7f5ccbfa9 | 
                            Monitoring | 
                            2.0.0 | 
                            1x 2.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Azure subscriptions should have a log profile for Activity Log | 
                            7796937f-307b-4598-941c-67d3a05ebfe7 | 
                            Monitoring | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Azure Web Application Firewall should be enabled for Azure Front Door entry-points | 
                            055aa869-bc98-4af8-bafc-23f1ab6ffe2c | 
                            Network | 
                            1.0.2 | 
                            1x 1.0.2 | 
                            Default Audit Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Blocked accounts with owner permissions on Azure resources should be removed | 
                            0cfea604-3201-4e14-88fc-fae4c427a6c5 | 
                            Security Center | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Blocked accounts with read and write permissions on Azure resources should be removed | 
                            8d7e1fde-fe26-4b5f-8108-f8e432cbc2be | 
                            Security Center | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Certificates should be issued by the specified integrated certificate authority | 
                            8e826246-c976-48f6-b03e-619bb92b3d82 | 
                            Key Vault | 
                            2.1.0 | 
                            1x 2.1.0 | 
                            Default Audit Allowed audit, Audit, deny, Deny, disabled, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Certificates should have the specified maximum validity period | 
                            0a075868-4c26-42ef-914c-5bc007359560 | 
                            Key Vault | 
                            2.2.1 | 
                            2x 2.2.1, 2.2.0-preview | 
                            Default Audit Allowed audit, Audit, deny, Deny, disabled, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Certificates should use allowed key types | 
                            1151cede-290b-4ba0-8b38-0ad145ac888f | 
                            Key Vault | 
                            2.1.0 | 
                            1x 2.1.0 | 
                            Default Audit Allowed audit, Audit, deny, Deny, disabled, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Certificates using elliptic curve cryptography should have allowed curve names | 
                            bd78111f-4953-4367-9fd5-7e08808b54bf | 
                            Key Vault | 
                            2.1.0 | 
                            1x 2.1.0 | 
                            Default Audit Allowed audit, Audit, deny, Deny, disabled, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Certificates using RSA cryptography should have the specified minimum key size | 
                            cee51871-e572-4576-855c-047c820360f0 | 
                            Key Vault | 
                            2.1.0 | 
                            1x 2.1.0 | 
                            Default Audit Allowed audit, Audit, deny, Deny, disabled, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Disconnections should be logged for PostgreSQL database servers. | 
                            eb6f77b9-bd53-4e35-a23d-7f65d5f0e446 | 
                            SQL | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Disk encryption should be enabled on Azure Data Explorer | 
                            f4b53539-8df9-40e4-86c6-6b607703bd4e | 
                            Azure Data Explorer | 
                            2.0.0 | 
                            1x 2.0.0 | 
                            Default Audit Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Email notification for high severity alerts should be enabled | 
                            6e2593d9-add6-4083-9c9b-4b7d2188c899 | 
                            Security Center | 
                            1.2.0 | 
                            3x 1.2.0, 1.1.0, 1.0.1 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Email notification to subscription owner for high severity alerts should be enabled | 
                            0b15565f-aa9e-48ba-8619-45960f2c314d | 
                            Security Center | 
                            2.1.0 | 
                            2x 2.1.0, 2.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Enforce SSL connection should be enabled for MySQL database servers | 
                            e802a67a-daf5-4436-9ea6-f6d821dd0c5d | 
                            SQL | 
                            1.0.1 | 
                            1x 1.0.1 | 
                            Default Audit Allowed Audit, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Enforce SSL connection should be enabled for PostgreSQL database servers | 
                            d158790f-bfb0-486c-8631-2dc6b4e8e6af | 
                            SQL | 
                            1.0.1 | 
                            1x 1.0.1 | 
                            Default Audit Allowed Audit, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Flow logs should be configured for every network security group | 
                            c251913d-7d24-4958-af87-478ed3b9ba41 | 
                            Network | 
                            1.1.0 | 
                            1x 1.1.0 | 
                            Default Audit Allowed Audit, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Function apps should have remote debugging turned off | 
                            0e60b895-3786-45da-8377-9c6b4b6ac5f9 | 
                            App Service | 
                            2.1.0 | 
                            2x 2.1.0, 2.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Function apps should only be accessible over HTTPS | 
                            6d555dd1-86f2-4f1c-8ed7-5abae7c6cbab | 
                            App Service | 
                            5.1.0 | 
                            2x 5.1.0, 5.0.0 | 
                            Default Audit Allowed Audit, Disabled, Deny | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Function apps should use the latest TLS version | 
                            f9d614c5-c173-4d56-95a7-b4437057d193 | 
                            App Service | 
                            2.3.0 | 
                            4x 2.3.0, 2.2.0, 2.1.0, 2.0.1 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Geo-redundant backup should be enabled for Azure Database for MariaDB | 
                            0ec47710-77ff-4a3d-9181-6aa50af424d0 | 
                            SQL | 
                            1.0.1 | 
                            1x 1.0.1 | 
                            Default Audit Allowed Audit, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Geo-redundant backup should be enabled for Azure Database for MySQL | 
                            82339799-d096-41ae-8538-b108becf0970 | 
                            SQL | 
                            1.0.1 | 
                            1x 1.0.1 | 
                            Default Audit Allowed Audit, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Geo-redundant backup should be enabled for Azure Database for PostgreSQL | 
                            48af4db5-9b8b-401c-8e74-076be876a430 | 
                            SQL | 
                            1.0.1 | 
                            1x 1.0.1 | 
                            Default Audit Allowed Audit, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Guest accounts with owner permissions on Azure resources should be removed | 
                            339353f6-2387-4a45-abe4-7f529d121046 | 
                            Security Center | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Guest accounts with read permissions on Azure resources should be removed | 
                            e9ac8f8e-ce22-4355-8f04-99b911d6be52 | 
                            Security Center | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Guest accounts with write permissions on Azure resources should be removed | 
                            94e1c2ac-cbbe-4cac-a2b5-389c812dee87 | 
                            Security Center | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Infrastructure encryption should be enabled for Azure Database for MySQL servers | 
                            3a58212a-c829-4f13-9872-6371df2fd0b4 | 
                            SQL | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default Audit Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            GA | 
                            unknown | 
                        
                        
                            | Infrastructure encryption should be enabled for Azure Database for PostgreSQL servers | 
                            24fba194-95d6-48c0-aea7-f65bf859c598 | 
                            SQL | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default Audit Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Internet-facing virtual machines should be protected with network security groups | 
                            f6de0be7-9a8a-4b8a-b349-43cf02d22f7c | 
                            Security Center | 
                            3.0.0 | 
                            1x 3.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | IP firewall rules on Azure Synapse workspaces should be removed | 
                            56fd377d-098c-4f02-8406-81eb055902b8 | 
                            Synapse | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default Audit Allowed Audit, Disabled | 
                            0 | 
                             | 
                            GA | 
                            unknown | 
                        
                        
                            | IP Forwarding on your virtual machine should be disabled | 
                            bd352bd5-2853-4985-bf0d-73806b4a5744 | 
                            Security Center | 
                            3.0.0 | 
                            1x 3.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Key Vault keys should have an expiration date | 
                            152b15f7-8e1f-4c1f-ab71-8c010ba5dbc0 | 
                            Key Vault | 
                            1.0.2 | 
                            1x 1.0.2 | 
                            Default Audit Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Key Vault secrets should have an expiration date | 
                            98728c90-32c7-4049-8429-847dc0f4fe37 | 
                            Key Vault | 
                            1.0.2 | 
                            1x 1.0.2 | 
                            Default Audit Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Key vaults should have deletion protection enabled | 
                            0b60c0b2-2dc2-4e1c-b5c9-abbed971de53 | 
                            Key Vault | 
                            2.1.0 | 
                            1x 2.1.0 | 
                            Default Audit Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Key vaults should have soft delete enabled | 
                            1e66c121-a66a-4b1f-9b83-0fd99bf0fc2d | 
                            Key Vault | 
                            3.1.0 | 
                            2x 3.1.0, 3.0.0 | 
                            Default Audit Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Kubernetes Services should be upgraded to a non-vulnerable Kubernetes version | 
                            fb893a29-21bb-418c-a157-e99480ec364c | 
                            Security Center | 
                            1.0.2 | 
                            1x 1.0.2 | 
                            Default Audit Allowed Audit, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Log Analytics workspaces should block log ingestion and querying from public networks | 
                            6c53d030-cc64-46f0-906d-2bc061cd1334 | 
                            Monitoring | 
                            1.1.0 | 
                            1x 1.1.0 | 
                            Default Audit Allowed audit, Audit, deny, Deny, disabled, Disabled | 
                            0 | 
                             | 
                            GA | 
                            unknown | 
                        
                        
                            | Log Analytics Workspaces should block non-Azure Active Directory based ingestion. | 
                            e15effd4-2278-4c65-a0da-4d6f6d1890e2 | 
                            Monitoring | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default Audit Allowed Deny, Audit, Disabled | 
                            0 | 
                             | 
                            GA | 
                            unknown | 
                        
                        
                            | Log checkpoints should be enabled for PostgreSQL database servers | 
                            eb6f77b9-bd53-4e35-a23d-7f65d5f0e43d | 
                            SQL | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Log connections should be enabled for PostgreSQL database servers | 
                            eb6f77b9-bd53-4e35-a23d-7f65d5f0e442 | 
                            SQL | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Log duration should be enabled for PostgreSQL database servers | 
                            eb6f77b9-bd53-4e35-a23d-7f65d5f0e8f3 | 
                            SQL | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Logic Apps Integration Service Environment should be encrypted with customer-managed keys | 
                            1fafeaf6-7927-4059-a50a-8eb2a7a6f2b5 | 
                            Logic Apps | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default Audit Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Long-term geo-redundant backup should be enabled for Azure SQL Databases | 
                            d38fc420-0735-4ef3-ac11-c806f651a570 | 
                            SQL | 
                            2.0.0 | 
                            1x 2.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Managed disks should use a specific set of disk encryption sets for the customer-managed key encryption | 
                            d461a302-a187-421a-89ac-84acdb4edc04 | 
                            Compute | 
                            2.0.0 | 
                            1x 2.0.0 | 
                            Default Audit Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            GA | 
                            unknown | 
                        
                        
                            | Management ports of virtual machines should be protected with just-in-time network access control | 
                            b0f33259-77d7-4c9e-aac6-3aabcfae693c | 
                            Security Center | 
                            3.0.0 | 
                            1x 3.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Management ports should be closed on your virtual machines | 
                            22730e10-96f6-4aac-ad84-9383d35b5917 | 
                            Security Center | 
                            3.0.0 | 
                            1x 3.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Microsoft Defender for Storage should be enabled | 
                            640d2586-54d2-465f-877f-9ffc1d2109f4 | 
                            Security Center | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            unknown | 
                        
                        
                            | MySQL servers should use customer-managed keys to encrypt data at rest | 
                            83cef61d-dbd1-4b20-a4fc-5fbc7da10833 | 
                            SQL | 
                            1.0.4 | 
                            1x 1.0.4 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            unknown | 
                        
                        
                            | Network Watcher flow logs should have traffic analytics enabled | 
                            2f080164-9f4d-497e-9db6-416dc9f7b48a | 
                            Network | 
                            1.0.1 | 
                            1x 1.0.1 | 
                            Default Audit Allowed Audit, Disabled | 
                            0 | 
                             | 
                            GA | 
                            unknown | 
                        
                        
                            | Non-internet-facing virtual machines should be protected with network security groups | 
                            bb91dfba-c30d-4263-9add-9c2384e659a6 | 
                            Security Center | 
                            3.0.0 | 
                            1x 3.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | PostgreSQL servers should use customer-managed keys to encrypt data at rest | 
                            18adea5e-f416-4d0f-8aa8-d24321e3e274 | 
                            SQL | 
                            1.0.4 | 
                            1x 1.0.4 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Role-Based Access Control (RBAC) should be used on Kubernetes Services | 
                            ac4a19c2-fa67-49b4-8ae5-0b2e78c49457 | 
                            Security Center | 
                            1.1.0 | 
                            3x 1.1.0, 1.0.4, 1.0.3 | 
                            Default Audit Allowed Audit, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Saved-queries in Azure Monitor should be saved in customer storage account for logs encryption | 
                            fa298e57-9444-42ba-bf04-86e8470e32c7 | 
                            Monitoring | 
                            1.1.0 | 
                            1x 1.1.0 | 
                            Default Audit Allowed audit, Audit, deny, Deny, disabled, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Secure transfer to storage accounts should be enabled | 
                            404c3081-a854-4457-ae30-26a93ef643f9 | 
                            Storage | 
                            2.0.0 | 
                            1x 2.0.0 | 
                            Default Audit Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | SQL databases should have vulnerability findings resolved | 
                            feedbf84-6b99-488c-acc2-71c829aa5ffc | 
                            Security Center | 
                            4.1.0 | 
                            1x 4.1.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | SQL servers on machines should have vulnerability findings resolved | 
                            6ba6d016-e7c3-4842-b8f2-4992ebc0d72d | 
                            Security Center | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | SQL servers with auditing to storage account destination should be configured with 90 days retention or higher | 
                            89099bee-89e0-4b26-a5f4-165451757743 | 
                            SQL | 
                            3.0.0 | 
                            1x 3.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Storage account containing the container with activity logs must be encrypted with BYOK | 
                            fbb99e8e-e444-4da0-9ff1-75c92f5a85b2 | 
                            Monitoring | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Storage account encryption scopes should use customer-managed keys to encrypt data at rest | 
                            b5ec538c-daa0-4006-8596-35468b9148e8 | 
                            Storage | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default Audit Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Storage account encryption scopes should use double encryption for data at rest | 
                            bfecdea6-31c4-4045-ad42-71b9dc87247d | 
                            Storage | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default Audit Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            GA | 
                            unknown | 
                        
                        
                            | Storage accounts should have infrastructure encryption | 
                            4733ea7b-a883-42fe-8cac-97454c2a9e4a | 
                            Storage | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default Audit Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Storage accounts should use customer-managed key for encryption | 
                            6fac406b-40ca-413b-bf8e-0bf964659c25 | 
                            Storage | 
                            1.0.3 | 
                            1x 1.0.3 | 
                            Default Audit Allowed Audit, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Subnets should be associated with a Network Security Group | 
                            e71308d3-144b-4262-b144-efdc3cc90517 | 
                            Security Center | 
                            3.0.0 | 
                            1x 3.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Subscriptions should have a contact email address for security issues | 
                            4f4f78b8-e367-4b10-a341-d9a4ad5cf1c7 | 
                            Security Center | 
                            1.0.1 | 
                            1x 1.0.1 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | The Log Analytics extension should be installed on Virtual Machine Scale Sets | 
                            efbde977-ba53-4479-b8e9-10b957924fbf | 
                            Monitoring | 
                            1.0.1 | 
                            1x 1.0.1 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | There should be more than one owner assigned to your subscription | 
                            09024ccc-0c5f-475e-9457-b7c0d9ed487b | 
                            Security Center | 
                            3.0.0 | 
                            1x 3.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Transparent Data Encryption on SQL databases should be enabled | 
                            17k78e20-9358-41c9-923c-fb736d382a12 | 
                            SQL | 
                            2.0.0 | 
                            1x 2.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Virtual machines' Guest Configuration extension should be deployed with system-assigned managed identity | 
                            d26f7642-7545-4e18-9b75-8c9bbdee3a9a | 
                            Security Center | 
                            1.0.1 | 
                            1x 1.0.1 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Vulnerability assessment should be enabled on SQL Managed Instance | 
                            1b7aa243-30e4-4c9e-bca8-d0d3022b634a | 
                            SQL | 
                            1.0.1 | 
                            1x 1.0.1 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Vulnerability assessment should be enabled on your SQL servers | 
                            ef2a8f2a-b3d9-49cd-a8a8-9a3aaaf647d9 | 
                            SQL | 
                            3.0.0 | 
                            1x 3.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Vulnerability assessment should be enabled on your Synapse workspaces | 
                            0049a6b3-a662-4f3e-8635-39cf44ace45a | 
                            Synapse | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default AuditIfNotExists Allowed AuditIfNotExists, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Web Application Firewall (WAF) should be enabled for Application Gateway | 
                            564feb30-bf6a-4854-b4bb-0d2d2d1e6c66 | 
                            Network | 
                            2.0.0 | 
                            1x 2.0.0 | 
                            Default Audit Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Web Application Firewall (WAF) should use the specified mode for Application Gateway | 
                            12430be1-6cc8-4527-a9a8-e3d38f250096 | 
                            Network | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default Audit Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true | 
                        
                        
                            | Web Application Firewall (WAF) should use the specified mode for Azure Front Door Service | 
                            425bea59-a659-4cbb-8d31-34499bd030b8 | 
                            Network | 
                            1.0.0 | 
                            1x 1.0.0 | 
                            Default Audit Allowed Audit, Deny, Disabled | 
                            0 | 
                             | 
                            GA | 
                            true |