last sync: 2025-Jun-26 17:23:22 UTC

K ISMS P 2018

Azure BuiltIn Policy Initiative (PolicySet)

Source Azure Portal
Display nameK ISMS P 2018
Ide0782c37-30da-4a78-9f92-50bfe7aa2553
Version1.0.0
Details on versioning
Versioning Versions supported for Versioning: 1
1.0.0
Built-in Versioning [Preview]
CategoryRegulatory Compliance
Microsoft Learn
DescriptionK-ISMS-P establishes requirements for protecting personal data and securing information systems in South Korea. The framework establishes administrative, physical, and technical controls for data privacy and system security.
Cloud environmentsAzureCloud = true
AzureChinaCloud = unknown
AzureUSGovernment = unknown
Available in AzUSGovUnknown, no evidence if PolicySet definition is/not available in AzureUSGovernment
TypeBuiltIn
DeprecatedFalse
PreviewFalse
Policy-used summary
Policy types Policy states Policy categories
Total Policies: 456
Builtin Policies: 456
Static Policies: 0
Deprecated: 24
GA: 408
Preview: 24
48 categories:
API for FHIR: 3
API Management: 10
App Configuration: 4
App Platform: 1
App Service: 38
Automation: 2
Azure Ai Services: 4
Azure Data Explorer: 3
Azure Databricks: 5
Azure Stack Edge: 1
Azure Update Manager: 1
Backup: 4
Batch: 3
Bot Service: 1
Cache: 3
Cognitive Services: 3
Compute: 14
Container Instance: 2
Container Registry: 5
Cosmos DB: 5
Data Box: 2
Data Factory: 2
Data Lake: 3
Event Grid: 2
Event Hub: 4
General: 2
Guest Configuration: 42
HDInsight: 3
Internet of Things: 3
Key Vault: 19
Kubernetes: 24
Logic Apps: 2
Machine Learning: 8
Monitoring: 47
Network: 25
Search: 2
Security Center: 57
Service Bus: 4
Service Fabric: 2
SignalR: 1
Site Recovery: 1
SQL: 58
Stack HCI: 4
Storage: 18
Stream Analytics: 2
Synapse: 5
VM Image Builder: 1
Web PubSub: 1
Policy-used
Policy DisplayName Policy Id Category Version Versioning Effect Roles# Roles State policy in AzUSGov
[Deprecated]: Advanced Threat Protection types should be set to 'All' in SQL Managed Instance advanced data security settings bda18df3-5e41-4709-add9-2554ce68c966 SQL 1.0.1 (1.0.1-deprecated) 1x
1.0.1
Default
Disabled
Allowed
AuditIfNotExists, Disabled
0 Deprecated unknown
[Deprecated]: Advanced Threat Protection types should be set to 'All' in SQL server Advanced Data Security settings e756b945-1b1b-480b-8de8-9a0859d5f7ad SQL 1.0.0 (1.0.0-deprecated) 1x
1.0.0
Default
Disabled
Allowed
AuditIfNotExists, Disabled
0 Deprecated unknown
[Deprecated]: API App should only be accessible over HTTPS b7ddfbdc-1260-477d-91fd-98bd9be789a6 App Service 1.0.0 (1.0.0-deprecated) 1x
1.0.0
Default
Audit
Allowed
Audit, Disabled
0 Deprecated unknown
[Deprecated]: API apps should have 'Client Certificates (Incoming client certificates)' enabled 0c192fe8-9cbb-4516-85b3-0ade8bd03886 App Service 1.0.0 (1.0.0-deprecated) 1x
1.0.0
Default
Audit
Allowed
Audit, Disabled
0 Deprecated unknown
[Deprecated]: API apps that use Python should use the latest 'Python version' 74c3584d-afae-46f7-a20a-6f8adba71a16 App Service 3.0.0 (3.0.0-deprecated) 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 Deprecated unknown
[Deprecated]: App Service apps should have 'Client Certificates (Incoming client certificates)' enabled 5bb220d9-2698-4ee4-8404-b9c30c9df609 App Service 3.1.0 (3.1.0-deprecated) 1x
3.1.0
Default
Disabled
Allowed
Audit, Disabled
0 Deprecated unknown
[Deprecated]: Azure Cache for Redis should reside within a virtual network 7d092e0a-7acd-40d2-a975-dca21cae48c4 Cache 1.0.3 (1.0.3-deprecated) 1x
1.0.3
Default
Audit
Allowed
Audit, Deny, Disabled
0 Deprecated true
[Deprecated]: Azure Machine Learning workspaces should use private link 40cec1dd-a100-4920-b15b-3024fe8901ab Machine Learning 1.1.0 (1.1.0-deprecated) 1x
1.1.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 Deprecated unknown
[Deprecated]: Cognitive Services accounts should enable data encryption 2bdd0062-9d75-436e-89df-487dd8e4b3c7 Cognitive Services 2.0.0 (2.0.0-deprecated) 1x
2.0.0
Default
Disabled
Allowed
Audit, Deny, Disabled
0 Deprecated unknown
[Deprecated]: Cognitive Services accounts should use customer owned storage or enable data encryption. 11566b39-f7f7-4b82-ab06-68d8700eb0a4 Cognitive Services 2.0.0 (2.0.0-deprecated) 1x
2.0.0
Default
Disabled
Allowed
Audit, Deny, Disabled
0 Deprecated unknown
[Deprecated]: CORS should not allow every resource to access your API App 358c20a6-3f9e-4f0e-97ff-c6ce485e2aac App Service 1.0.0 (1.0.0-deprecated) 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 Deprecated unknown
[Deprecated]: Ensure that 'Java version' is the latest, if used as a part of the API app 88999f4c-376a-45c8-bcb3-4058f713cf39 App Service 2.0.0 (2.0.0-deprecated) 1x
2.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 Deprecated unknown
[Deprecated]: Ensure that 'PHP version' is the latest, if used as a part of the API app 1bc1795e-d44a-4d48-9b3b-6fff0fd5f9ba App Service 2.1.0 (2.1.0-deprecated) 1x
2.1.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 Deprecated unknown
[Deprecated]: FTPS only should be required in your API App 9a1b8c48-453a-4044-86c3-d8bfd823e4f5 App Service 2.0.0 (2.0.0-deprecated) 1x
2.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 Deprecated unknown
[Deprecated]: Function apps should have 'Client Certificates (Incoming client certificates)' enabled eaebaea7-8013-4ceb-9d14-7eb32271373c App Service 3.1.0 (3.1.0-deprecated) 1x
3.1.0
Default
Disabled
Allowed
Audit, Disabled
0 Deprecated true
[Deprecated]: Latest TLS version should be used in your API App 8cb6aa8b-9e41-4f4e-aa25-089a7ac2581e App Service 1.0.0 (1.0.0-deprecated) 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 Deprecated unknown
[Deprecated]: Log Analytics Extension should be enabled for listed virtual machine images 32133ab0-ee4b-4b44-98d6-042180979d50 Monitoring 2.1.0 (2.1.0-deprecated) 2x
2.1.0, 2.0.1-preview
Default
Disabled
Allowed
AuditIfNotExists, Disabled
0 Deprecated unknown
[Deprecated]: Log Analytics extension should be enabled in virtual machine scale sets for listed virtual machine images 5c3bc7b8-a64c-4e08-a9cd-7ff0f31e1138 Monitoring 2.1.0 (2.1.0-deprecated) 2x
2.1.0, 2.0.1
Default
Disabled
Allowed
AuditIfNotExists, Disabled
0 Deprecated unknown
[Deprecated]: Managed identity should be used in your API App c4d441f8-f9d9-4a9e-9cef-e82117cb3eef App Service 2.0.0 (2.0.0-deprecated) 1x
2.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 Deprecated unknown
[Deprecated]: Remote debugging should be turned off for API Apps e9c8d085-d9cc-4b17-9cdc-059f1f01f19e App Service 1.0.0 (1.0.0-deprecated) 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 Deprecated unknown
[Deprecated]: SQL managed instances should use customer-managed keys to encrypt data at rest 048248b0-55cd-46da-b1ff-39efd52db260 SQL 1.0.2 (1.0.2-deprecated) 1x
1.0.2
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 Deprecated unknown
[Deprecated]: SQL servers should use customer-managed keys to encrypt data at rest 0d134df8-db83-46fb-ad72-fe0c9428c8dd SQL 2.0.1 (2.0.1-deprecated) 1x
2.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 Deprecated unknown
[Deprecated]: Virtual machines should be connected to a specified workspace f47b5582-33ec-4c5c-87c0-b010a6b2e917 Monitoring 1.2.0 (1.2.0-deprecated) 2x
1.2.0, 1.1.0
Default
Disabled
Allowed
AuditIfNotExists, Disabled
0 Deprecated unknown
[Deprecated]: Virtual machines should have the Log Analytics extension installed a70ca396-0a34-413a-88e1-b956c1e683be Monitoring 1.1.0 (1.1.0-deprecated) 2x
1.1.0, 1.0.1
Default
Disabled
Allowed
AuditIfNotExists, Disabled
0 Deprecated unknown
[Preview]: All Internet traffic should be routed via your deployed Azure Firewall fc5e4038-4584-4632-8c85-c0448d374b2c Network 3.0.0-preview 1x
3.0.0-preview
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 Preview unknown
[Preview]: Azure Arc enabled Kubernetes clusters should have Microsoft Defender for Cloud extension installed 8dfab9c4-fe7b-49ad-85e4-1e9be085358f Kubernetes 6.0.0-preview 1x
6.0.0-preview
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 Preview true
[Preview]: Azure PostgreSQL flexible server should have Microsoft Entra Only Authentication enabled fa498b91-8a7e-4710-9578-da944c68d1fe SQL 1.0.0-preview 1x
1.0.0-preview
Default
Audit
Allowed
Audit, Disabled
0 Preview true
[Preview]: Azure Recovery Services vaults should use customer-managed keys for encrypting backup data 2e94d99a-8a36-4563-bc77-810d8893b671 Backup 1.0.0-preview 1x
1.0.0-preview
Default
Audit
Allowed
Audit, Deny, Disabled
0 Preview true
[Preview]: Azure Recovery Services vaults should use private link for backup deeddb44-9f94-4903-9fa0-081d524406e3 Backup 2.0.0-preview 1x
2.0.0-preview
Default
Audit
Allowed
Audit, Disabled
0 Preview unknown
[Preview]: Azure Stack HCI servers should have consistently enforced application control policies dad3a6b9-4451-492f-a95c-69efc6f3fada Stack HCI 1.0.0-preview 1x
1.0.0-preview
Default
AuditIfNotExists
Allowed
Audit, Disabled, AuditIfNotExists
0 Preview unknown
[Preview]: Azure Stack HCI servers should meet Secured-core requirements 5e6bf724-0154-49bc-985f-27b2e07e636b Stack HCI 1.0.0-preview 1x
1.0.0-preview
Default
AuditIfNotExists
Allowed
Audit, Disabled, AuditIfNotExists
0 Preview unknown
[Preview]: Azure Stack HCI systems should have encrypted volumes ee8ca833-1583-4d24-837e-96c2af9488a4 Stack HCI 1.0.0-preview 1x
1.0.0-preview
Default
AuditIfNotExists
Allowed
Audit, Disabled, AuditIfNotExists
0 Preview unknown
[Preview]: Container Registry should use a virtual network service endpoint c4857be7-912a-4c75-87e6-e30292bcdf78 Network 1.0.0-preview 1x
1.0.0-preview
Default
Audit
Allowed
Audit, Disabled
0 Preview true
[Preview]: Guest Attestation extension should be installed on supported Linux virtual machines 672fe5a1-2fcd-42d7-b85d-902b6e28c6ff Security Center 6.0.0-preview 1x
6.0.0-preview
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 Preview true
[Preview]: Guest Attestation extension should be installed on supported Linux virtual machines scale sets a21f8c92-9e22-4f09-b759-50500d1d2dda Security Center 5.1.0-preview 1x
5.1.0-preview
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 Preview true
[Preview]: Guest Attestation extension should be installed on supported Windows virtual machines 1cb4d9c2-f88f-4069-bee0-dba239a57b09 Security Center 4.0.0-preview 1x
4.0.0-preview
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 Preview true
[Preview]: Guest Attestation extension should be installed on supported Windows virtual machines scale sets f655e522-adff-494d-95c2-52d4f6d56a42 Security Center 3.1.0-preview 1x
3.1.0-preview
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 Preview true
[Preview]: Host and VM networking should be protected on Azure Stack HCI systems 36f0d6bc-a253-4df8-b25b-c3a5023ff443 Stack HCI 1.0.0-preview 1x
1.0.0-preview
Default
AuditIfNotExists
Allowed
Audit, Disabled, AuditIfNotExists
0 Preview unknown
[Preview]: IoT Hub device provisioning service data should be encrypted using customer-managed keys (CMK) 47031206-ce96-41f8-861b-6a915f3de284 Internet of Things 1.0.0-preview 1x
1.0.0-preview
Default
Audit
Allowed
Audit, Deny, Disabled
0 Preview true
[Preview]: Linux virtual machines should use only signed and trusted boot components 13a6c84f-49a5-410a-b5df-5b880c3fe009 Security Center 1.0.0-preview 1x
1.0.0-preview
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 Preview unknown
[Preview]: Log Analytics extension should be installed on your Linux Azure Arc machines 842c54e8-c2f9-4d79-ae8d-38d8b8019373 Monitoring 1.0.1-preview 1x
1.0.1-preview
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 Preview unknown
[Preview]: Log Analytics extension should be installed on your Windows Azure Arc machines d69b1763-b96d-40b8-a2d9-ca31e9fd0d3e Monitoring 1.0.1-preview 1x
1.0.1-preview
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 Preview unknown
[Preview]: Machines should have ports closed that might expose attack vectors af99038c-02fd-4a2f-ac24-386b62bf32de Security Center 1.0.0-preview 1x
1.0.0-preview
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 Preview unknown
[Preview]: Network traffic data collection agent should be installed on Linux virtual machines 04c4380f-3fae-46e8-96c9-30193528f602 Monitoring 1.0.2-preview 1x
1.0.2-preview
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 Preview true
[Preview]: Network traffic data collection agent should be installed on Windows virtual machines 2f2ee1de-44aa-4762-b6bd-0893fc3f306d Monitoring 1.0.2-preview 1x
1.0.2-preview
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 Preview true
[Preview]: Recovery Services vaults should use private link 11e3da8c-1d68-4392-badd-0ff3c43ab5b0 Site Recovery 1.0.0-preview 1x
1.0.0-preview
Default
Audit
Allowed
Audit, Disabled
0 Preview unknown
[Preview]: Secure Boot should be enabled on supported Windows virtual machines 97566dd7-78ae-4997-8b36-1c7bfe0d8121 Security Center 4.0.0-preview 1x
4.0.0-preview
Default
Audit
Allowed
Audit, Disabled
0 Preview true
[Preview]: vTPM should be enabled on supported virtual machines 1c30f9cd-b84c-49cc-aa2c-9288447cc3b3 Security Center 2.0.0-preview 1x
2.0.0-preview
Default
Audit
Allowed
Audit, Disabled
0 Preview true
A custom IPsec/IKE policy must be applied to all Azure virtual network gateway connections 50b83b09-03da-41c1-b656-c293c914862b Network 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Disabled
0 GA unknown
A maximum of 3 owners should be designated for your subscription 4f11b553-d42e-4e3a-89be-32ca364cad4c Security Center 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
A Microsoft Entra administrator should be provisioned for MySQL servers 146412e9-005c-472b-9e48-c87b72ac229e SQL 1.1.1 2x
1.1.1, 1.1.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
A Microsoft Entra administrator should be provisioned for PostgreSQL servers b4dec045-250a-48c2-b5cc-e0c4eec8b5b4 SQL 1.0.1 2x
1.0.1, 1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
A vulnerability assessment solution should be enabled on your virtual machines 501541f7-f7e7-4cd6-868c-4190fdad3ac9 Security Center 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Activity log should be retained for at least one year b02aacc0-b073-424e-8298-42b22829ee0a Monitoring 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Add system-assigned managed identity to enable Guest Configuration assignments on virtual machines with no identities 3cf2ab00-13f1-4d0c-8971-2ac904541a7e Guest Configuration 4.1.0 2x
4.1.0, 4.0.0
Fixed
modify
1 Contributor GA true
Add system-assigned managed identity to enable Guest Configuration assignments on VMs with a user-assigned identity 497dff13-db2a-4c0f-8603-28fa3b331ab6 Guest Configuration 4.1.0 2x
4.1.0, 4.0.0
Fixed
modify
1 Contributor GA true
All authorization rules except RootManageSharedAccessKey should be removed from Service Bus namespace a1817ec0-a368-432a-8057-8371e17ac6ee Service Bus 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA unknown
All flow log resources should be in enabled state 27960feb-a23c-4577-8d36-ef8b5f35e0be Network 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Disabled
0 GA unknown
All network ports should be restricted on network security groups associated to your virtual machine 9daedab3-fb2d-461e-b861-71790eead4f6 Security Center 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
An activity log alert should exist for specific Administrative operations b954148f-4c11-4c38-8221-be76711e194a Monitoring 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
An activity log alert should exist for specific Policy operations c5447c04-a4d7-4ba8-a263-c9ee321a6858 Monitoring 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
An Azure Active Directory administrator should be provisioned for SQL servers 1f314764-cb73-4fc9-b863-8eca98ac36e9 SQL 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
API endpoints in Azure API Management should be authenticated 8ac833bd-f505-48d5-887e-c993a1d3eea0 Security Center 1.0.1 1x
1.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
API endpoints that are unused should be disabled and removed from the Azure API Management service c8acafaf-3d23-44d1-9624-978ef0f8652c Security Center 1.0.1 1x
1.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
API Management APIs should use only encrypted protocols ee7495e7-3ba7-40b6-bfee-c29e22cc75d4 API Management 2.0.2 1x
2.0.2
Default
Audit
Allowed
Audit, Disabled, Deny
0 GA unknown
API Management calls to API backends should be authenticated c15dcc82-b93c-4dcb-9332-fbf121685b54 API Management 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Disabled, Deny
0 GA unknown
API Management calls to API backends should not bypass certificate thumbprint or name validation 92bb331d-ac71-416a-8c91-02f2cb734ce4 API Management 1.0.2 1x
1.0.2
Default
Audit
Allowed
Audit, Disabled, Deny
0 GA unknown
API Management direct management endpoint should not be enabled b741306c-968e-4b67-b916-5675e5c709f4 API Management 1.0.2 1x
1.0.2
Default
Audit
Allowed
Audit, Disabled, Deny
0 GA unknown
API Management minimum API version should be set to 2019-12-01 or higher 549814b6-3212-4203-bdc8-1548d342fb67 API Management 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA unknown
API Management secret named values should be stored in Azure Key Vault f1cc7827-022c-473e-836e-5a51cae0b249 API Management 1.0.2 1x
1.0.2
Default
Audit
Allowed
Audit, Disabled, Deny
0 GA unknown
API Management services should use a virtual network ef619a2c-cc4d-4d03-b2ba-8c94a834d85b API Management 1.0.2 1x
1.0.2
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
API Management should disable public network access to the service configuration endpoints df73bd95-24da-4a4f-96b9-4e8b94b402bd API Management 1.0.1 1x
1.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
API Management subscriptions should not be scoped to all APIs 3aa03346-d8c5-4994-a5bc-7652c2a2aef1 API Management 1.1.0 1x
1.1.0
Default
Audit
Allowed
Audit, Disabled, Deny
0 GA unknown
App Configuration should disable public network access 3d9f5e4c-9947-4579-9539-2a7695fbc187 App Configuration 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA unknown
App Configuration should use a customer-managed key 967a4b4b-2da9-43c1-b7d0-f98d0d74d0b1 App Configuration 1.1.0 1x
1.1.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA unknown
App Configuration should use private link ca610c1d-041c-4332-9d88-7ed3094967c7 App Configuration 1.0.2 1x
1.0.2
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
App Service app slots that use PHP should use a specified 'PHP version' f466b2a6-823d-470d-8ea5-b031e72d79ae App Service 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
App Service app slots that use Python should use a specified 'Python version' 9c014953-ef68-4a98-82af-fd0f6b2306c8 App Service 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
App Service apps should have authentication enabled 95bccee9-a7f8-4bec-9ee9-62c3473701fc App Service 2.0.1 1x
2.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
App Service apps should have remote debugging turned off cb510bfd-1cba-4d9f-a230-cb0976f4bb71 App Service 2.0.0 1x
2.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
App Service apps should have resource logs enabled 91a78b24-f231-4a8a-8da9-02c35b2b6510 App Service 2.0.1 1x
2.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
App Service apps should not have CORS configured to allow every resource to access your apps 5744710e-cc2f-4ee8-8809-3b11e89f4bc9 App Service 2.0.0 1x
2.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
App Service apps should only be accessible over HTTPS a4af4a39-4135-47fb-b175-47fbdf85311d App Service 4.0.0 1x
4.0.0
Default
Audit
Allowed
Audit, Disabled, Deny
0 GA true
App Service apps should require FTPS only 4d24b6d4-5e53-4a4f-a7f4-618fa573ee4b App Service 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
App Service apps should use a virtual network service endpoint 2d21331d-a4c2-4def-a9ad-ee4e1e023beb Network 2.0.1 1x
2.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
App Service apps should use latest 'HTTP Version' 8c122334-9d20-4eb8-89ea-ac9a705b74ae App Service 4.0.0 1x
4.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
App Service apps should use managed identity 2b9ad585-36bc-4615-b300-fd4435808332 App Service 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
App Service apps should use the latest TLS version f0e6e85b-9b9f-4a4b-b67b-f730d42f1b0b App Service 2.1.0 2x
2.1.0, 2.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
App Service apps that use Java should use a specified 'Java version' 496223c3-ad65-4ecd-878a-bae78737e9ed App Service 3.1.0 1x
3.1.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
App Service apps that use PHP should use a specified 'PHP version' 7261b898-8a84-4db8-9e04-18527132abb3 App Service 3.2.0 1x
3.2.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
App Service apps that use Python should use a specified 'Python version' 7008174a-fd10-4ef0-817e-fc820a951d73 App Service 4.1.0 1x
4.1.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
App Service Environment should have internal encryption enabled fb74e86f-d351-4b8d-b034-93da7391c01f App Service 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Disabled
0 GA true
Application Insights components should block log ingestion and querying from public networks 1bc02227-0cb6-4e11-8f53-eb0b22eab7e8 Monitoring 1.1.0 1x
1.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA unknown
Audit diagnostic setting for selected resource types 7f89b1eb-583c-429a-8828-af049802c1d9 Monitoring 2.0.1 1x
2.0.1
Fixed
AuditIfNotExists
0 GA true
Audit flow logs configuration for every virtual network 4c3c6c5f-0d47-4402-99b8-aa543dd8bcee Network 1.0.1 2x
1.0.1, 1.0.0
Default
Audit
Allowed
Audit, Disabled
0 GA unknown
Audit Linux machines that allow remote connections from accounts without passwords ea53dbee-c6c9-4f0e-9f9e-de0039b78023 Guest Configuration 3.1.0 2x
3.1.0, 3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Audit Linux machines that do not have the passwd file permissions set to 0644 e6955644-301c-44b5-a4c4-528577de6861 Guest Configuration 3.1.0 2x
3.1.0, 3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Audit Linux machines that have accounts without passwords f6ec09a3-78bf-4f8f-99dc-6c77182d0f99 Guest Configuration 3.1.0 2x
3.1.0, 3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Audit resource location matches resource group location 0a914e76-4921-4c19-b460-a2d36003525a General 2.0.0 1x
2.0.0
Fixed
audit
0 GA unknown
Audit usage of custom RBAC roles a451c1ef-c6ca-483d-87ed-f49761e3ffb5 General 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Disabled
0 GA true
Audit virtual machines without disaster recovery configured 0015ea4d-51ff-4ce3-8d8c-f3f8f0179a56 Compute 1.0.0 1x
1.0.0
Fixed
auditIfNotExists
0 GA true
Audit VMs that do not use managed disks 06a78e20-9358-41c9-923c-fb736d382a4d Compute 1.0.0 1x
1.0.0
Fixed
audit
0 GA true
Audit Windows machines missing any of specified members in the Administrators group 30f71ea1-ac77-4f26-9fc5-2d926bbd4ba7 Guest Configuration 2.0.0 1x
2.0.0
Fixed
auditIfNotExists
0 GA true
Audit Windows machines on which the Log Analytics agent is not connected as expected 6265018c-d7e2-432f-a75d-094d5f6f4465 Guest Configuration 2.0.0 1x
2.0.0
Fixed
auditIfNotExists
0 GA true
Audit Windows machines that allow re-use of the passwords after the specified number of unique passwords 5b054a0d-39e2-4d53-bea3-9734cad2c69b Guest Configuration 2.1.0 1x
2.1.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Audit Windows machines that contain certificates expiring within the specified number of days 1417908b-4bff-46ee-a2a6-4acc899320ab Guest Configuration 2.0.0 1x
2.0.0
Fixed
auditIfNotExists
0 GA true
Audit Windows machines that do not contain the specified certificates in Trusted Root 934345e1-4dfb-4c70-90d7-41990dc9608b Guest Configuration 3.0.0 1x
3.0.0
Fixed
auditIfNotExists
0 GA true
Audit Windows machines that do not have the maximum password age set to specified number of days 4ceb8dc2-559c-478b-a15b-733fbf1e3738 Guest Configuration 2.1.0 1x
2.1.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Audit Windows machines that do not have the minimum password age set to specified number of days 237b38db-ca4d-4259-9e47-7882441ca2c0 Guest Configuration 2.1.0 1x
2.1.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Audit Windows machines that do not have the password complexity setting enabled bf16e0bb-31e1-4646-8202-60a235cc7e74 Guest Configuration 2.0.0 1x
2.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Audit Windows machines that do not restrict the minimum password length to specified number of characters a2d0e922-65d0-40c4-8f87-ea6da2d307a2 Guest Configuration 2.1.0 1x
2.1.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Audit Windows machines that do not store passwords using reversible encryption da0f98fe-a24b-4ad5-af69-bd0400233661 Guest Configuration 2.0.0 1x
2.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Audit Windows machines that don't have the specified applications installed ebb67efd-3c46-49b0-adfe-5599eb944998 Guest Configuration 2.0.0 1x
2.0.0
Fixed
auditIfNotExists
0 GA true
Audit Windows machines that have extra accounts in the Administrators group 3d2a3320-2a72-4c67-ac5f-caa40fbee2b2 Guest Configuration 2.0.0 1x
2.0.0
Fixed
auditIfNotExists
0 GA true
Audit Windows machines that have the specified members in the Administrators group 69bf4abd-ca1e-4cf6-8b5a-762d42e61d4f Guest Configuration 2.0.0 1x
2.0.0
Fixed
auditIfNotExists
0 GA true
Audit Windows VMs with a pending reboot 4221adbc-5c0f-474f-88b7-037a99e6114c Guest Configuration 2.0.0 1x
2.0.0
Fixed
auditIfNotExists
0 GA true
Auditing on SQL server should be enabled a6fb4358-5bf4-4ad7-ba82-2cd2f41ce5e9 SQL 2.0.0 1x
2.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Authentication to Linux machines should require SSH keys 630c64f9-8b6b-4c64-b511-6544ceff6fd6 Guest Configuration 3.2.0 2x
3.2.0, 3.1.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Authorization rules on the Event Hub instance should be defined f4826e5f-6a27-407c-ae3e-9582eb39891d Event Hub 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Authorized IP ranges should be defined on Kubernetes Services 0e246bcf-5f6f-4f87-bc6f-775d4712c7ea Security Center 2.0.1 1x
2.0.1
Default
Audit
Allowed
Audit, Disabled
0 GA true
Automation account variables should be encrypted 3657f5a0-770e-44a3-b44e-9431ba1e9735 Automation 1.1.0 1x
1.1.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure AI Search service should use a SKU that supports private link a049bf77-880b-470f-ba6d-9f21c530cf83 Search 1.0.1 2x
1.0.1, 1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure AI Search services should disable public network access ee980b6d-0eca-4501-8d54-f6290fd512c3 Search 1.0.1 2x
1.0.1, 1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure AI Services resources should encrypt data at rest with a customer-managed key (CMK) 67121cc7-ff39-4ab8-b7e3-95b84dab487d Cognitive Services 2.2.0 2x
2.2.0, 2.1.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure AI Services resources should have key access disabled (disable local authentication) 71ef260a-8f18-47b7-abcb-62d0673d94dc Azure Ai Services 1.1.0 2x
1.1.0, 1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure AI Services resources should restrict network access 037eea7a-bd0a-46c5-9a66-03aea78705d3 Azure Ai Services 3.2.0 3x
3.2.0, 3.1.0, 3.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure AI Services resources should use Azure Private Link d6759c02-b87f-42b7-892e-71b3f471d782 Azure Ai Services 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Disabled
0 GA true
Azure API for FHIR should use a customer-managed key to encrypt data at rest 051cba44-2429-45b9-9649-46cec11c7119 API for FHIR 1.1.0 1x
1.1.0
Default
Audit
Allowed
audit, Audit, disabled, Disabled
0 GA unknown
Azure API for FHIR should use private link 1ee56206-5dd1-42ab-b02d-8aae8b1634ce API for FHIR 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Disabled
0 GA unknown
Azure API Management platform version should be stv2 1dc2fc00-2245-4143-99f4-874c937f13ef API Management 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA unknown
Azure Arc enabled Kubernetes clusters should have the Azure Policy extension installed 6b2122c1-8120-4ff5-801b-17625a355590 Kubernetes 1.1.0 1x
1.1.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure Automation accounts should use customer-managed keys to encrypt data at rest 56a5ee18-2ae6-4810-86f7-18e39ce5629b Automation 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure Backup should be enabled for Virtual Machines 013e242c-8828-4970-87b3-ab247555486d Backup 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure Batch account should use customer-managed keys to encrypt data 99e9ccd8-3db9-4592-b0d1-14b1715a4d8a Batch 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure Cache for Redis should use private link 7803067c-7d34-46e3-8c79-0ca68fc4036d Cache 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure Container Instance container group should deploy into a virtual network 8af8f826-edcb-4178-b35f-851ea6fea615 Container Instance 2.0.0 1x
2.0.0
Default
Audit
Allowed
Audit, Disabled, Deny
0 GA unknown
Azure Container Instance container group should use customer-managed key for encryption 0aa61e00-0a01-4a3c-9945-e93cffedf0e6 Container Instance 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Disabled, Deny
0 GA true
Azure Cosmos DB accounts should use customer-managed keys to encrypt data at rest 1f905d99-2ab7-462c-a6b0-f709acca6c8f Cosmos DB 1.1.0 1x
1.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Azure Cosmos DB should disable public network access 797b37f7-06b8-444c-b1ad-fc62867f335a Cosmos DB 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure Data Box jobs should enable double encryption for data at rest on the device c349d81b-9985-44ae-a8da-ff98d108ede8 Data Box 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure Data Box jobs should use a customer-managed key to encrypt the device unlock password 86efb160-8de7-451d-bc08-5d475b0aadae Data Box 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure Data Explorer encryption at rest should use a customer-managed key 81e74cea-30fd-40d5-802f-d72103c2aaaa Azure Data Explorer 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure data factories should be encrypted with a customer-managed key 4ec52d6d-beb7-40c4-9a9e-fe753254690e Data Factory 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure Data Factory should use private link 8b0323be-cc25-4b61-935d-002c3798c6ea Data Factory 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure Databricks Clusters should disable public IP 51c1490f-3319-459c-bbbc-7f391bbed753 Azure Databricks 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure Databricks Workspaces should be in a virtual network 9c25c9e4-ee12-4882-afd2-11fb9d87893f Azure Databricks 1.0.2 1x
1.0.2
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure Databricks Workspaces should disable public network access 0e7849de-b939-4c50-ab48-fc6b0f5eeba2 Azure Databricks 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure Databricks Workspaces should use private link 258823f2-4595-4b52-b333-cc96192710d8 Azure Databricks 1.0.2 1x
1.0.2
Default
Audit
Allowed
Audit, Disabled
0 GA true
Azure DDoS Protection should be enabled a7aca53f-2ed4-4466-a25e-0b45ade68efd Security Center 3.0.1 2x
3.0.1, 3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure Defender for App Service should be enabled 2913021d-f2fd-4f3d-b958-22354e2bdbcb Security Center 1.0.3 1x
1.0.3
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Azure Defender for Azure SQL Database servers should be enabled 7fe3b40f-802b-4cdd-8bd4-fd799c948cc2 Security Center 1.0.2 1x
1.0.2
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure Defender for Key Vault should be enabled 0e6763cc-5078-4e64-889d-ff4d9a839047 Security Center 1.0.3 1x
1.0.3
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Azure Defender for open-source relational databases should be enabled 0a9fbe0d-c5c4-4da8-87d8-f4fd77338835 Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Azure Defender for Resource Manager should be enabled c3d20c29-b36d-48fe-808b-99a87530ad99 Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure Defender for servers should be enabled 4da35fc9-c9e7-4960-aec9-797fe7d9051d Security Center 1.0.3 1x
1.0.3
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure Defender for SQL servers on machines should be enabled 6581d072-105e-4418-827f-bd446d56421b Security Center 1.0.2 1x
1.0.2
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Azure Defender for SQL should be enabled for unprotected Azure SQL servers abfb4388-5bf4-4ad7-ba82-2cd2f41ceae9 SQL 2.0.1 1x
2.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure Defender for SQL should be enabled for unprotected MySQL flexible servers 3bc8a0d5-38e0-4a3d-a657-2cb64468fc34 Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure Defender for SQL should be enabled for unprotected PostgreSQL flexible servers d38668f5-d155-42c7-ab3d-9b57b50f8fbf Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure Defender for SQL should be enabled for unprotected SQL Managed Instances abfb7388-5bf4-4ad7-ba99-2cd2f41cebb9 SQL 1.0.2 1x
1.0.2
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure Event Grid domains should use private link 9830b652-8523-49cc-b1b3-e17dce1127ca Event Grid 1.0.2 1x
1.0.2
Default
Audit
Allowed
Audit, Disabled
0 GA true
Azure Event Grid topics should use private link 4b90e17e-8448-49db-875e-bd83fb6f804f Event Grid 1.0.2 1x
1.0.2
Default
Audit
Allowed
Audit, Disabled
0 GA true
Azure File Sync should use private link 1d320205-c6a1-4ac6-873d-46224024e8e2 Storage 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure HDInsight clusters should use customer-managed keys to encrypt data at rest 64d314f6-6062-4780-a861-c23e8951bee5 HDInsight 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure HDInsight clusters should use encryption at host to encrypt data at rest 1fd32ebd-e4c3-4e13-a54a-d7422d4d95f6 HDInsight 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure HDInsight clusters should use encryption in transit to encrypt communication between Azure HDInsight cluster nodes d9da03a1-f3c3-412a-9709-947156872263 HDInsight 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure Key Vault Managed HSM should have purge protection enabled c39ba22d-4428-4149-b981-70acb31fc383 Key Vault 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA unknown
Azure Key Vault should have firewall enabled or public network access disabled 55615ac9-af46-4a59-874e-391cc3dfb490 Key Vault 3.3.0 2x
3.3.0, 3.2.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure Key Vault should use RBAC permission model 12d4fa5e-1f9f-4c21-97a9-b99b3c6611b5 Key Vault 1.0.1 2x
1.0.1, 1.0.0-preview
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA unknown
Azure Key Vaults should use private link a6abeaec-4d90-4a02-805f-6b26c4d3fbe9 Key Vault 1.2.1 1x
1.2.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure Kubernetes Service clusters should have Defender profile enabled a1840de2-8088-4ea8-b153-b4c723e9cb01 Kubernetes 2.0.1 1x
2.0.1
Default
Audit
Allowed
Audit, Disabled
0 GA true
Azure Machine Learning compute instances should be recreated to get the latest software updates f110a506-2dcb-422e-bcea-d533fc8c35e2 Machine Learning 1.0.3 1x
1.0.3
Fixed
[parameters('effects')]
0 GA true
Azure Machine Learning Computes should be in a virtual network 7804b5c7-01dc-4723-969b-ae300cc07ff1 Machine Learning 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Disabled
0 GA true
Azure Machine Learning Computes should have local authentication methods disabled e96a9a5f-07ca-471b-9bc5-6a0f33cbd68f Machine Learning 2.1.0 2x
2.1.0, 2.0.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure Machine Learning workspaces should be encrypted with a customer-managed key ba769a63-b8cc-4b2d-abf6-ac33c7204be8 Machine Learning 1.1.0 2x
1.1.0, 1.0.3
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure Machine Learning Workspaces should disable public network access 438c38d2-3772-465a-a9cc-7a6666a275ce Machine Learning 2.0.1 1x
2.0.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure Machine Learning workspaces should use private link 45e05259-1eb5-4f70-9574-baf73e9d219b Machine Learning 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Disabled
0 GA true
Azure Monitor log profile should collect logs for categories 'write,' 'delete,' and 'action' 1a4e592a-6a6e-44a5-9814-e36264ca96e7 Monitoring 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure Monitor Logs clusters should be created with infrastructure-encryption enabled (double encryption) ea0dfaed-95fb-448c-934e-d6e713ce393d Monitoring 1.1.0 1x
1.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Azure Monitor Logs clusters should be encrypted with customer-managed key 1f68a601-6e6d-4e42-babf-3f643a047ea2 Monitoring 1.1.0 1x
1.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Azure Monitor Logs for Application Insights should be linked to a Log Analytics workspace d550e854-df1a-4de9-bf44-cd894b39a95e Monitoring 1.1.0 1x
1.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA unknown
Azure Monitor should collect activity logs from all regions 41388f1c-2db0-4c25-95b2-35d7f5ccbfa9 Monitoring 2.0.0 1x
2.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure Monitor solution 'Security and Audit' must be deployed 3e596b57-105f-48a6-be97-03e9243bad6e Monitoring 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Azure MySQL flexible server should have Microsoft Entra Only Authentication enabled 40e85574-ef33-47e8-a854-7a65c7500560 SQL 1.0.1 2x
1.0.1, 1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Azure Policy Add-on for Kubernetes service (AKS) should be installed and enabled on your clusters 0a15ec92-a229-4763-bb14-0ea34a568f8d Kubernetes 1.0.2 1x
1.0.2
Default
Audit
Allowed
Audit, Disabled
0 GA true
Azure registry container images should have vulnerabilities resolved (powered by Microsoft Defender Vulnerability Management) 090c7b07-b4ed-4561-ad20-e9075f3ccaff Security Center 1.0.1 2x
1.0.1, 1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure running container images should have vulnerabilities resolved (powered by Microsoft Defender Vulnerability Management) 17f4b1cc-c55c-4d94-b1f9-2978f6ac2957 Security Center 1.0.1 2x
1.0.1, 1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure Service Bus namespaces should use private link 1c06e275-d63d-4540-b761-71f364c2111d Service Bus 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure SignalR Service should use private link 2393d2cf-a342-44cd-a2e2-fe0188fd1234 SignalR 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Disabled
0 GA true
Azure Spring Cloud should use network injection af35e2a4-ef96-44e7-a9ae-853dd97032c4 App Platform 1.2.0 1x
1.2.0
Default
Audit
Allowed
Audit, Disabled, Deny
0 GA unknown
Azure SQL Database should be running TLS version 1.2 or newer 32e6bbec-16b6-44c2-be37-c5b672d103cf SQL 2.0.0 1x
2.0.0
Default
Audit
Allowed
Audit, Disabled, Deny
0 GA true
Azure SQL Database should have Microsoft Entra-only authentication enabled during creation abda6d70-9778-44e7-84a8-06713e6db027 SQL 1.2.0 2x
1.2.0, 1.1.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure SQL Managed Instances should disable public network access 9dfea752-dd46-4766-aed1-c355fa93fb91 SQL 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure SQL Managed Instances should have Microsoft Entra-only authentication enabled during creation 78215662-041e-49ed-a9dd-5385911b3a1f SQL 1.2.0 2x
1.2.0, 1.1.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure Stack Edge devices should use double-encryption b4ac1030-89c5-4697-8e00-28b5ba6a8811 Azure Stack Edge 1.1.0 1x
1.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Azure Stream Analytics jobs should use customer-managed keys to encrypt data 87ba29ef-1ab3-4d82-b763-87fcd4f531f7 Stream Analytics 1.1.0 1x
1.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Azure subscriptions should have a log profile for Activity Log 7796937f-307b-4598-941c-67d3a05ebfe7 Monitoring 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Azure Synapse workspaces should use customer-managed keys to encrypt data at rest f7d52b2d-e161-4dfa-a82b-55e564167385 Synapse 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure Synapse workspaces should use private link 72d11df1-dd8a-41f7-8925-b05b960ebafc Synapse 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Disabled
0 GA true
Azure VPN gateways should not use 'basic' SKU e345b6c3-24bd-4c93-9bbb-7e5e49a17b78 Network 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Disabled
0 GA unknown
Azure Web Application Firewall should be enabled for Azure Front Door entry-points 055aa869-bc98-4af8-bafc-23f1ab6ffe2c Network 1.0.2 1x
1.0.2
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Azure Web PubSub Service should use private link eb907f70-7514-460d-92b3-a5ae93b4f917 Web PubSub 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Disabled
0 GA unknown
Blocked accounts with owner permissions on Azure resources should be removed 0cfea604-3201-4e14-88fc-fae4c427a6c5 Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Blocked accounts with read and write permissions on Azure resources should be removed 8d7e1fde-fe26-4b5f-8108-f8e432cbc2be Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Bot Service should be encrypted with a customer-managed key 51522a96-0869-4791-82f3-981000c2c67f Bot Service 1.1.0 1x
1.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Both operating systems and data disks in Azure Kubernetes Service clusters should be encrypted by customer-managed keys 7d7be79c-23ba-4033-84dd-45e2a5ccdd67 Kubernetes 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Certificates should be issued by the specified integrated certificate authority 8e826246-c976-48f6-b03e-619bb92b3d82 Key Vault 2.1.0 1x
2.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Certificates should have the specified maximum validity period 0a075868-4c26-42ef-914c-5bc007359560 Key Vault 2.2.1 2x
2.2.1, 2.2.0-preview
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Certificates should use allowed key types 1151cede-290b-4ba0-8b38-0ad145ac888f Key Vault 2.1.0 1x
2.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Certificates using elliptic curve cryptography should have allowed curve names bd78111f-4953-4367-9fd5-7e08808b54bf Key Vault 2.1.0 1x
2.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Certificates using RSA cryptography should have the specified minimum key size cee51871-e572-4576-855c-047c820360f0 Key Vault 2.1.0 1x
2.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Configure App Configuration to disable public network access 73290fa2-dfa7-4bbb-945d-a5e23b75df2c App Configuration 1.0.0 1x
1.0.0
Default
Modify
Allowed
Modify, Disabled
1 Contributor GA unknown
Configure Azure Defender to be enabled on SQL servers 36d49e87-48c4-4f2e-beed-ba4ed02b71f5 SQL 2.1.0 1x
2.1.0
Fixed
DeployIfNotExists
1 SQL Security Manager GA true
Configure Azure SQL Server to disable public network access 28b0b1e5-17ba-4963-a7a4-5a1ab4400a0b SQL 1.0.0 1x
1.0.0
Default
Modify
Allowed
Modify, Disabled
1 SQL Server Contributor GA true
Configure Azure SQL Server to enable private endpoint connections 8e8ca470-d980-4831-99e6-dc70d9f6af87 SQL 1.0.0 1x
1.0.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
2 Network Contributor, SQL Server Contributor GA unknown
Configure backup on virtual machines without a given tag to an existing recovery services vault in the same location 09ce66bc-1220-4153-8104-e3f51c936913 Backup 9.4.0 4x
9.4.0, 9.3.0, 9.2.0, 9.1.0
Default
DeployIfNotExists
Allowed
auditIfNotExists, AuditIfNotExists, deployIfNotExists, DeployIfNotExists, disabled, Disabled
2 Backup Contributor, Virtual Machine Contributor GA unknown
Configure Container registries to disable public network access a3701552-92ea-433e-9d17-33b7f1208fc9 Container Registry 1.0.0 1x
1.0.0
Default
Modify
Allowed
Modify, Disabled
1 Contributor GA true
Configure managed disks to disable public network access 8426280e-b5be-43d9-979e-653d12a08638 Compute 2.0.0 1x
2.0.0
Default
Modify
Allowed
Modify, Disabled
1 Contributor GA unknown
Connection throttling should be enabled for PostgreSQL database servers 5345bb39-67dc-4960-a1bf-427e16b9a0bd SQL 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Container registries should be encrypted with a customer-managed key 5b9159ae-1701-4a6f-9a7a-aa9c8ddd0580 Container Registry 1.1.2 1x
1.1.2
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Container registries should not allow unrestricted network access d0793b48-0edc-4296-a390-4c75d1bdfd71 Container Registry 2.0.0 1x
2.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Container registries should use private link e8eef0a8-67cf-4eb4-9386-14b0e78733d4 Container Registry 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Disabled
0 GA true
CORS should not allow every domain to access your API for FHIR 0fea8f8a-4169-495d-8307-30ec335f387d API for FHIR 1.1.0 1x
1.1.0
Default
Audit
Allowed
audit, Audit, disabled, Disabled
0 GA unknown
Cosmos DB database accounts should have local authentication methods disabled 5450f5bd-9c72-4390-a9c4-a7aba4edfdd2 Cosmos DB 1.1.0 1x
1.1.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Cosmos DB should use a virtual network service endpoint e0a2b1a3-f7f9-4569-807f-2a9edebdf4d9 Network 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Disabled
0 GA true
CosmosDB accounts should use private link 58440f8a-10c5-4151-bdce-dfbaad4a20b7 Cosmos DB 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Disabled
0 GA true
Dependency agent should be enabled for listed virtual machine images 11ac78e3-31bc-4f0c-8434-37ab963cea07 Monitoring 2.0.0 1x
2.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Dependency agent should be enabled in virtual machine scale sets for listed virtual machine images e2dd799a-a932-4e9d-ac17-d473bc3c6c10 Monitoring 2.0.0 1x
2.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Deploy - Configure diagnostic settings for SQL Databases to Log Analytics workspace b79fa14e-238a-4c2d-b376-442ce508fc84 SQL 4.0.0 1x
4.0.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
2 Log Analytics Contributor, Monitoring Contributor GA true
Deploy - Configure Log Analytics extension to be enabled on Windows virtual machine scale sets 3c1b3629-c8f8-4bf6-862c-037cb9094038 Monitoring 3.1.0 1x
3.1.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
2 Log Analytics Contributor, Virtual Machine Contributor GA unknown
Deploy - Configure Log Analytics extension to be enabled on Windows virtual machines 0868462e-646c-4fe3-9ced-a733534b6a2c Monitoring 3.1.0 1x
3.1.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
1 Log Analytics Contributor GA true
Deploy a Flow Log resource with target virtual network cd6f7aff-2845-4dab-99f2-6d1754a754b0 Network 1.1.1 3x
1.1.1, 1.1.0, 1.0.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
1 Contributor GA unknown
Deploy Advanced Threat Protection for Cosmos DB Accounts b5f04e03-92a3-4b09-9410-2cc5e5047656 Cosmos DB 1.0.0 1x
1.0.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
1 Security Admin GA true
Deploy default Microsoft IaaSAntimalware extension for Windows Server 2835b622-407b-4114-9198-6f7064cbe0dc Compute 1.1.0 1x
1.1.0
Fixed
deployIfNotExists
1 Virtual Machine Contributor GA unknown
Deploy Diagnostic Settings for Batch Account to Event Hub db51110f-0865-4a6e-b274-e2e07a5b2cd7 Monitoring 2.0.0 1x
2.0.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
1 Contributor GA unknown
Deploy Diagnostic Settings for Batch Account to Log Analytics workspace c84e5349-db6d-4769-805e-e14037dab9b5 Monitoring 1.1.0 2x
1.1.0, 1.0.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
2 Log Analytics Contributor, Monitoring Contributor GA unknown
Deploy Diagnostic Settings for Data Lake Analytics to Event Hub 4daddf25-4823-43d4-88eb-2419eb6dcc08 Monitoring 2.0.0 1x
2.0.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
1 Contributor GA unknown
Deploy Diagnostic Settings for Data Lake Analytics to Log Analytics workspace d56a5a7c-72d7-42bc-8ceb-3baf4c0eae03 Monitoring 1.0.0 1x
1.0.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
2 Log Analytics Contributor, Monitoring Contributor GA unknown
Deploy Diagnostic Settings for Data Lake Storage Gen1 to Event Hub e8d096bc-85de-4c5f-8cfb-857bd1b9d62d Monitoring 2.0.0 1x
2.0.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
1 Contributor GA unknown
Deploy Diagnostic Settings for Data Lake Storage Gen1 to Log Analytics workspace 25763a0a-5783-4f14-969e-79d4933eb74b Monitoring 1.0.0 1x
1.0.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
2 Log Analytics Contributor, Monitoring Contributor GA unknown
Deploy Diagnostic Settings for Event Hub to Event Hub ef7b61ef-b8e4-4c91-8e78-6946c6b0023f Monitoring 2.1.0 1x
2.1.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
1 Contributor GA unknown
Deploy Diagnostic Settings for Event Hub to Log Analytics workspace 1f6e93e8-6b31-41b1-83f6-36e449a42579 Monitoring 2.1.0 2x
2.1.0, 2.0.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
2 Log Analytics Contributor, Monitoring Contributor GA unknown
Deploy Diagnostic Settings for Key Vault to Log Analytics workspace bef3f64c-5290-43b7-85b0-9b254eef4c47 Monitoring 3.0.0 1x
3.0.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
2 Log Analytics Contributor, Monitoring Contributor GA true
Deploy Diagnostic Settings for Logic Apps to Event Hub a1dae6c7-13f3-48ea-a149-ff8442661f60 Monitoring 2.0.0 1x
2.0.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
1 Contributor GA unknown
Deploy Diagnostic Settings for Logic Apps to Log Analytics workspace b889a06c-ec72-4b03-910a-cb169ee18721 Monitoring 1.0.0 1x
1.0.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
2 Log Analytics Contributor, Monitoring Contributor GA true
Deploy Diagnostic Settings for Network Security Groups c9c29499-c1d1-4195-99bd-2ec9e3a9dc89 Monitoring 2.0.1 1x
2.0.1
Fixed
deployIfNotExists
2 Monitoring Contributor, Storage Account Contributor GA unknown
Deploy Diagnostic Settings for Search Services to Event Hub 3d5da587-71bd-41f5-ac95-dd3330c2d58d Monitoring 2.0.0 1x
2.0.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
1 Contributor GA unknown
Deploy Diagnostic Settings for Search Services to Log Analytics workspace 08ba64b8-738f-4918-9686-730d2ed79c7d Monitoring 1.0.0 1x
1.0.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
2 Log Analytics Contributor, Monitoring Contributor GA unknown
Deploy Diagnostic Settings for Service Bus to Event Hub 6b51af03-9277-49a9-a3f8-1c69c9ff7403 Monitoring 2.0.0 1x
2.0.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
1 Contributor GA unknown
Deploy Diagnostic Settings for Service Bus to Log Analytics workspace 04d53d87-841c-4f23-8a5b-21564380b55e Monitoring 2.2.0 2x
2.2.0, 2.1.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
2 Log Analytics Contributor, Monitoring Contributor GA unknown
Deploy Diagnostic Settings for Stream Analytics to Event Hub edf3780c-3d70-40fe-b17e-ab72013dafca Monitoring 2.0.0 1x
2.0.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
1 Contributor GA unknown
Deploy Diagnostic Settings for Stream Analytics to Log Analytics workspace 237e0f7e-b0e8-4ec4-ad46-8c12cb66d673 Monitoring 1.0.0 1x
1.0.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
2 Log Analytics Contributor, Monitoring Contributor GA unknown
Deploy network watcher when virtual networks are created a9b99dd8-06c5-4317-8629-9d86a3c6e7d9 Network 1.0.0 1x
1.0.0
Fixed
DeployIfNotExists
1 Network Contributor GA unknown
Deploy SQL DB transparent data encryption 86a912f6-9a06-4e26-b447-11b16ba8659f SQL 2.2.0 1x
2.2.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
1 SQL DB Contributor GA true
Deploy the Linux Guest Configuration extension to enable Guest Configuration assignments on Linux VMs 331e8ea8-378a-410f-a2e5-ae22f38bb0da Guest Configuration 3.2.0 3x
3.2.0, 3.1.0, 3.0.0
Fixed
deployIfNotExists
1 Contributor GA true
Deploy the Windows Guest Configuration extension to enable Guest Configuration assignments on Windows VMs 385f5831-96d4-41db-9a3c-cd3af78aaae6 Guest Configuration 1.3.0 2x
1.3.0, 1.2.0
Fixed
deployIfNotExists
1 Contributor GA true
Diagnostic logs in Azure AI services resources should be enabled 1b4d1c4e-934c-4703-944c-27c82c06bebb Azure Ai Services 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Disconnections should be logged for PostgreSQL database servers. eb6f77b9-bd53-4e35-a23d-7f65d5f0e446 SQL 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Disk access resources should use private link f39f5f49-4abf-44de-8c70-0756997bfb51 Compute 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Disk encryption should be enabled on Azure Data Explorer f4b53539-8df9-40e4-86c6-6b607703bd4e Azure Data Explorer 2.0.0 1x
2.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Double encryption should be enabled on Azure Data Explorer ec068d99-e9c7-401f-8cef-5bdde4e6ccf1 Azure Data Explorer 2.0.0 1x
2.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Email notification for high severity alerts should be enabled 6e2593d9-add6-4083-9c9b-4b7d2188c899 Security Center 1.2.0 3x
1.2.0, 1.1.0, 1.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Email notification to subscription owner for high severity alerts should be enabled 0b15565f-aa9e-48ba-8619-45960f2c314d Security Center 2.1.0 2x
2.1.0, 2.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Enable Security Center's auto provisioning of the Log Analytics agent on your subscriptions with custom workspace. 8e7da0a5-0a0e-4bbc-bfc0-7773c018b616 Security Center 1.0.0 1x
1.0.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
1 Contributor GA true
Enable Security Center's auto provisioning of the Log Analytics agent on your subscriptions with default workspace. 6df2fee6-a9ed-4fef-bced-e13be1b25f1c Security Center 1.0.0 1x
1.0.0
Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
1 Contributor GA true
Enforce SSL connection should be enabled for MySQL database servers e802a67a-daf5-4436-9ea6-f6d821dd0c5d SQL 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Disabled
0 GA true
Enforce SSL connection should be enabled for PostgreSQL database servers d158790f-bfb0-486c-8631-2dc6b4e8e6af SQL 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Disabled
0 GA true
Event Hub namespaces should use a customer-managed key for encryption a1ad735a-e96f-45d2-a7b2-9a4932cab7ec Event Hub 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Disabled
0 GA true
Event Hub namespaces should use private link b8564268-eb4a-4337-89be-a19db070c59d Event Hub 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Event Hub should use a virtual network service endpoint d63edb4a-c612-454d-b47d-191a724fcbf0 Network 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Flow logs should be configured for every network security group c251913d-7d24-4958-af87-478ed3b9ba41 Network 1.1.0 1x
1.1.0
Default
Audit
Allowed
Audit, Disabled
0 GA true
Function app slots that use Java should use a specified 'Java version' e1d1b522-02b0-4d18-a04f-5ab62d20445f App Service 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Function apps should have authentication enabled c75248c1-ea1d-4a9c-8fc9-29a6aabd5da8 App Service 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Function apps should have remote debugging turned off 0e60b895-3786-45da-8377-9c6b4b6ac5f9 App Service 2.0.0 1x
2.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Function apps should not have CORS configured to allow every resource to access your apps 0820b7b9-23aa-4725-a1ce-ae4558f718e5 App Service 2.0.0 1x
2.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Function apps should only be accessible over HTTPS 6d555dd1-86f2-4f1c-8ed7-5abae7c6cbab App Service 5.0.0 1x
5.0.0
Default
Audit
Allowed
Audit, Disabled, Deny
0 GA true
Function apps should require FTPS only 399b2637-a50f-4f95-96f8-3a145476eb15 App Service 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Function apps should use latest 'HTTP Version' e2c1c086-2d84-4019-bff3-c44ccd95113c App Service 4.0.0 1x
4.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Function apps should use managed identity 0da106f2-4ca3-48e8-bc85-c638fe6aea8f App Service 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Function apps should use the latest TLS version f9d614c5-c173-4d56-95a7-b4437057d193 App Service 2.1.0 2x
2.1.0, 2.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Function apps that use Java should use a specified 'Java version' 9d0b6ea4-93e2-4578-bf2f-6bb17d22b4bc App Service 3.1.0 1x
3.1.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Function apps that use Python should use a specified 'Python version' 7238174a-fd10-4ef0-817e-fc820a951d73 App Service 4.1.0 1x
4.1.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Gateway subnets should not be configured with a network security group 35f9c03a-cc27-418e-9c0c-539ff999d010 Network 1.0.0 1x
1.0.0
Fixed
deny
0 GA unknown
Geo-redundant backup should be enabled for Azure Database for MariaDB 0ec47710-77ff-4a3d-9181-6aa50af424d0 SQL 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Disabled
0 GA true
Geo-redundant backup should be enabled for Azure Database for MySQL 82339799-d096-41ae-8538-b108becf0970 SQL 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Disabled
0 GA true
Geo-redundant backup should be enabled for Azure Database for PostgreSQL 48af4db5-9b8b-401c-8e74-076be876a430 SQL 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Disabled
0 GA true
Geo-redundant storage should be enabled for Storage Accounts bf045164-79ba-4215-8f95-f8048dc1780b Storage 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Disabled
0 GA true
Guest accounts with owner permissions on Azure resources should be removed 339353f6-2387-4a45-abe4-7f529d121046 Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Guest accounts with read permissions on Azure resources should be removed e9ac8f8e-ce22-4355-8f04-99b911d6be52 Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Guest accounts with write permissions on Azure resources should be removed 94e1c2ac-cbbe-4cac-a2b5-389c812dee87 Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Guest Configuration extension should be installed on your machines ae89ebca-1c92-4898-ac2c-9f63decb045c Security Center 1.0.3 1x
1.0.3
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
HPC Cache accounts should use customer-managed key for encryption 970f84d8-71b6-4091-9979-ace7e3fb6dbb Storage 2.0.0 1x
2.0.0
Default
Audit
Allowed
Audit, Disabled, Deny
0 GA unknown
Infrastructure encryption should be enabled for Azure Database for MySQL servers 3a58212a-c829-4f13-9872-6371df2fd0b4 SQL 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA unknown
Infrastructure encryption should be enabled for Azure Database for PostgreSQL servers 24fba194-95d6-48c0-aea7-f65bf859c598 SQL 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Internet-facing virtual machines should be protected with network security groups f6de0be7-9a8a-4b8a-b349-43cf02d22f7c Security Center 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
IoT Hub device provisioning service instances should use private link df39c015-56a4-45de-b4a3-efe77bed320d Internet of Things 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Disabled
0 GA true
IP firewall rules on Azure Synapse workspaces should be removed 56fd377d-098c-4f02-8406-81eb055902b8 Synapse 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Disabled
0 GA unknown
IP Forwarding on your virtual machine should be disabled bd352bd5-2853-4985-bf0d-73806b4a5744 Security Center 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Key Vault keys should have an expiration date 152b15f7-8e1f-4c1f-ab71-8c010ba5dbc0 Key Vault 1.0.2 1x
1.0.2
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Key Vault secrets should have an expiration date 98728c90-32c7-4049-8429-847dc0f4fe37 Key Vault 1.0.2 1x
1.0.2
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Key Vault should use a virtual network service endpoint ea4d6841-2173-4317-9747-ff522a45120f Network 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Disabled
0 GA true
Key vaults should have deletion protection enabled 0b60c0b2-2dc2-4e1c-b5c9-abbed971de53 Key Vault 2.1.0 1x
2.1.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Key vaults should have soft delete enabled 1e66c121-a66a-4b1f-9b83-0fd99bf0fc2d Key Vault 3.0.0 1x
3.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Keys should be the specified cryptographic type RSA or EC 75c4f823-d65c-4f29-a733-01d0077fdbcb Key Vault 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Keys should have a rotation policy ensuring that their rotation is scheduled within the specified number of days after creation. d8cf8476-a2ec-4916-896e-992351803c44 Key Vault 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Disabled
0 GA unknown
Keys using elliptic curve cryptography should have the specified curve names ff25f3c8-b739-4538-9d07-3d6d25cfb255 Key Vault 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Keys using RSA cryptography should have a specified minimum key size 82067dbb-e53b-4e06-b631-546d197452d9 Key Vault 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Kubernetes cluster containers CPU and memory resource limits should not exceed the specified limits e345eecc-fa47-480f-9e88-67dcc122b164 Kubernetes 9.3.0 3x
9.3.0, 9.2.0, 9.1.0
Default
Deny
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Kubernetes cluster containers should not share host process ID or host IPC namespace 47a1ee2f-2a2a-4576-bf2a-e0e36709c2b8 Kubernetes 5.2.0 2x
5.2.0, 5.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Kubernetes cluster containers should only use allowed AppArmor profiles 511f5417-5d12-434d-ab2e-816901e72a5e Kubernetes 6.2.0 2x
6.2.0, 6.1.1
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Kubernetes cluster containers should only use allowed capabilities c26596ff-4d70-4e6a-9a30-c2506bd2f80c Kubernetes 6.2.0 2x
6.2.0, 6.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Kubernetes cluster containers should only use allowed images febd0533-8e55-448f-b837-bd0e06f16469 Kubernetes 9.3.0 4x
9.3.0, 9.2.0, 9.1.1, 9.1.0
Default
Deny
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Kubernetes cluster containers should run with a read only root file system df49d893-a74c-421d-bc95-c663042e5b80 Kubernetes 6.3.0 3x
6.3.0, 6.2.0, 6.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Kubernetes cluster pod hostPath volumes should only use allowed host paths 098fc59e-46c7-4d99-9b16-64990e543d75 Kubernetes 6.2.0 2x
6.2.0, 6.1.1
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Kubernetes cluster pods and containers should only run with approved user and group IDs f06ddb64-5fa3-4b77-b166-acb36f7f6042 Kubernetes 6.2.0 2x
6.2.0, 6.1.1
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Kubernetes cluster pods should only use approved host network and port range 82985f06-dc18-4a48-bc1c-b9f4f0098cfe Kubernetes 6.2.0 2x
6.2.0, 6.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Kubernetes cluster services should listen only on allowed ports 233a2a17-77ca-4fb1-9b6b-69223d272a44 Kubernetes 8.2.0 2x
8.2.0, 8.1.0
Default
Deny
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Kubernetes cluster services should only use allowed external IPs d46c275d-1680-448d-b2ec-e495a3b6cc89 Kubernetes 5.2.0 2x
5.2.0, 5.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Kubernetes cluster should not allow privileged containers 95edb821-ddaf-4404-9732-666045e056b4 Kubernetes 9.2.0 2x
9.2.0, 9.1.0
Default
Deny
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Kubernetes clusters should be accessible only over HTTPS 1a5b4dca-0b6f-4cf5-907c-56316bc1bf3d Kubernetes 8.2.0 2x
8.2.0, 8.1.0
Default
Deny
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Kubernetes clusters should disable automounting API credentials 423dd1ba-798e-40e4-9c4d-b6902674b423 Kubernetes 4.2.0 2x
4.2.0, 4.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Kubernetes clusters should not allow container privilege escalation 1c6e92c9-99f0-4e55-9cf2-0c234dc48f99 Kubernetes 7.2.0 2x
7.2.0, 7.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Kubernetes clusters should not grant CAP_SYS_ADMIN security capabilities d2e7ea85-6b44-4317-a0be-1b951587f626 Kubernetes 5.1.0 1x
5.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Kubernetes clusters should not use the default namespace 9f061a12-e40d-4183-a00e-171812443373 Kubernetes 4.2.0 2x
4.2.0, 4.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Kubernetes Services should be upgraded to a non-vulnerable Kubernetes version fb893a29-21bb-418c-a157-e99480ec364c Security Center 1.0.2 1x
1.0.2
Default
Audit
Allowed
Audit, Disabled
0 GA true
Linux machines should meet requirements for the Azure compute security baseline fc9b3da7-8347-4380-8e70-0a0361d8dedd Guest Configuration 2.2.0 2x
2.2.0, 2.1.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Linux virtual machines should enable Azure Disk Encryption or EncryptionAtHost. ca88aadc-6e2b-416c-9de2-5a0f01d1693f Guest Configuration 1.2.1 3x
1.2.1, 1.2.0-preview, 1.1.0-preview
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Log Analytics workspaces should block log ingestion and querying from public networks 6c53d030-cc64-46f0-906d-2bc061cd1334 Monitoring 1.1.0 1x
1.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA unknown
Log Analytics Workspaces should block non-Azure Active Directory based ingestion. e15effd4-2278-4c65-a0da-4d6f6d1890e2 Monitoring 1.0.0 1x
1.0.0
Default
Audit
Allowed
Deny, Audit, Disabled
0 GA unknown
Log checkpoints should be enabled for PostgreSQL database servers eb6f77b9-bd53-4e35-a23d-7f65d5f0e43d SQL 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Log connections should be enabled for PostgreSQL database servers eb6f77b9-bd53-4e35-a23d-7f65d5f0e442 SQL 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Log duration should be enabled for PostgreSQL database servers eb6f77b9-bd53-4e35-a23d-7f65d5f0e8f3 SQL 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Logic Apps Integration Service Environment should be encrypted with customer-managed keys 1fafeaf6-7927-4059-a50a-8eb2a7a6f2b5 Logic Apps 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Long-term geo-redundant backup should be enabled for Azure SQL Databases d38fc420-0735-4ef3-ac11-c806f651a570 SQL 2.0.0 1x
2.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Machines should be configured to periodically check for missing system updates bd876905-5b84-4f73-ab2d-2e7a7c4568d9 Azure Update Manager 3.8.0 5x
3.8.0, 3.7.0, 3.6.0, 3.5.0, 3.4.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Machines should have secret findings resolved 3ac7c827-eea2-4bde-acc7-9568cd320efa Security Center 1.0.2 1x
1.0.2
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Managed disks should be double encrypted with both platform-managed and customer-managed keys ca91455f-eace-4f96-be59-e6e2c35b4816 Compute 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Managed disks should disable public network access 8405fdab-1faf-48aa-b702-999c9c172094 Compute 2.1.0 2x
2.1.0, 2.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA unknown
Managed disks should use a specific set of disk encryption sets for the customer-managed key encryption d461a302-a187-421a-89ac-84acdb4edc04 Compute 2.0.0 1x
2.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA unknown
Management ports of virtual machines should be protected with just-in-time network access control b0f33259-77d7-4c9e-aac6-3aabcfae693c Security Center 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Management ports should be closed on your virtual machines 22730e10-96f6-4aac-ad84-9383d35b5917 Security Center 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
MariaDB server should use a virtual network service endpoint dfbd9a64-6114-48de-a47d-90574dc2e489 SQL 1.0.2 1x
1.0.2
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Microsoft Antimalware for Azure should be configured to automatically update protection signatures c43e4a30-77cb-48ab-a4dd-93f175c63b57 Compute 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Microsoft Defender CSPM should be enabled 1f90fc71-a595-4066-8974-d4d0802e8ef0 Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Microsoft Defender for APIs should be enabled 7926a6d1-b268-4586-8197-e8ae90c877d7 Security Center 1.0.3 1x
1.0.3
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Microsoft Defender for Azure Cosmos DB should be enabled adbe85b5-83e6-4350-ab58-bf3a4f736e5e Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Microsoft Defender for Containers should be enabled 1c988dd6-ade4-430f-a608-2a3e5b0a6d38 Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Microsoft Defender for SQL should be enabled for unprotected Synapse workspaces d31e5c31-63b2-4f12-887b-e49456834fa1 Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Microsoft Defender for SQL status should be protected for Arc-enabled SQL Servers 938c4981-c2c9-4168-9cd6-972b8675f906 Security Center 1.1.0 2x
1.1.0, 1.0.1
Default
Audit
Allowed
Audit, Disabled
0 GA unknown
Microsoft Defender for Storage should be enabled 640d2586-54d2-465f-877f-9ffc1d2109f4 Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Microsoft IaaSAntimalware extension should be deployed on Windows servers 9b597639-28e4-48eb-b506-56b05d366257 Compute 1.1.0 1x
1.1.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Modify - Configure Azure File Sync to disable public network access 0e07b2e9-6cd9-4c40-9ccb-52817b95133b Storage 1.0.0 1x
1.0.0
Default
Modify
Allowed
Modify, Disabled
1 Contributor GA true
MySQL server should use a virtual network service endpoint 3375856c-3824-4e0e-ae6a-79e011dd4c47 SQL 1.0.2 1x
1.0.2
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
MySQL servers should use customer-managed keys to encrypt data at rest 83cef61d-dbd1-4b20-a4fc-5fbc7da10833 SQL 1.0.4 1x
1.0.4
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Network Watcher flow logs should have traffic analytics enabled 2f080164-9f4d-497e-9db6-416dc9f7b48a Network 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Disabled
0 GA unknown
Network Watcher should be enabled b6e2945c-0b7b-40f5-9233-7a5323b5cdc6 Network 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Non-internet-facing virtual machines should be protected with network security groups bb91dfba-c30d-4263-9add-9c2384e659a6 Security Center 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Only approved VM extensions should be installed c0e996f8-39cf-4af9-9f45-83fbde810432 Compute 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Only secure connections to your Azure Cache for Redis should be enabled 22bee202-a82f-4305-9a2a-6d7f44d4dedb Cache 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
OS and data disks should be encrypted with a customer-managed key 702dd420-7fcc-42c5-afe8-4026edd20fe0 Compute 3.0.0 1x
3.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
PostgreSQL server should use a virtual network service endpoint 3c14b034-bcb6-4905-94e7-5b8e98a47b65 SQL 1.0.2 1x
1.0.2
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
PostgreSQL servers should use customer-managed keys to encrypt data at rest 18adea5e-f416-4d0f-8aa8-d24321e3e274 SQL 1.0.4 1x
1.0.4
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Private endpoint connections on Azure SQL Database should be enabled 7698e800-9299-47a6-b3b6-5a0fee576eed SQL 1.1.0 1x
1.1.0
Default
Audit
Allowed
Audit, Disabled
0 GA true
Private endpoint connections on Batch accounts should be enabled 009a0c92-f5b4-4776-9b66-4ed2b4775563 Batch 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Private endpoint should be enabled for MariaDB servers 0a1302fb-a631-4106-9753-f3d494733990 SQL 1.0.2 1x
1.0.2
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Private endpoint should be enabled for MySQL servers 7595c971-233d-4bcf-bd18-596129188c49 SQL 1.0.2 1x
1.0.2
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Private endpoint should be enabled for PostgreSQL servers 0564d078-92f5-4f97-8398-b9f58a51f70b SQL 1.0.2 1x
1.0.2
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Public network access on Azure SQL Database should be disabled 1b8ca024-1d5c-4dec-8995-b1a932b41780 SQL 1.1.0 1x
1.1.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Public network access should be disabled for Container registries 0fdf0491-d080-4575-b627-ad0e843cba0f Container Registry 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Public network access should be disabled for MariaDB servers fdccbe47-f3e3-4213-ad5d-ea459b2fa077 SQL 2.0.0 1x
2.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA unknown
Public network access should be disabled for MySQL flexible servers c9299215-ae47-4f50-9c54-8a392f68a052 SQL 2.3.0 3x
2.3.0, 2.2.0, 2.1.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA unknown
Public network access should be disabled for MySQL servers d9844e8a-1437-4aeb-a32c-0c992f056095 SQL 2.0.0 1x
2.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA unknown
Public network access should be disabled for PostgreSQL flexible servers 5e1de0e3-42cb-4ebc-a86d-61d0c619ca48 SQL 3.1.0 2x
3.1.0, 3.0.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA unknown
Public network access should be disabled for PostgreSQL servers b52376f7-9612-48a1-81cd-1ffe4b61032c SQL 2.0.1 1x
2.0.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Require encryption on Data Lake Store accounts a7ff3161-0087-490a-9ad9-ad6217f4f43a Data Lake 1.0.0 1x
1.0.0
Fixed
deny
0 GA unknown
Resource logs in Azure Data Lake Store should be enabled 057ef27e-665e-4328-8ea3-04b3122bd9fb Data Lake 5.0.0 1x
5.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Resource logs in Azure Databricks Workspaces should be enabled 138ff14d-b687-4faa-a81c-898c91a87fa2 Azure Databricks 1.0.1 1x
1.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Resource logs in Azure Key Vault Managed HSM should be enabled a2a5b911-5617-447e-a49e-59dbe0e0434b Key Vault 1.1.0 1x
1.1.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Resource logs in Azure Kubernetes Service should be enabled 245fc9df-fa96-4414-9a0b-3738c2f7341c Kubernetes 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Resource logs in Azure Machine Learning Workspaces should be enabled afe0c3be-ba3b-4544-ba52-0c99672a8ad6 Machine Learning 1.0.1 1x
1.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Resource logs in Azure Stream Analytics should be enabled f9be5368-9bf5-4b84-9e0a-7850da98bb46 Stream Analytics 5.0.0 1x
5.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Resource logs in Batch accounts should be enabled 428256e6-1fac-4f48-a757-df34c2b3336d Batch 5.0.0 1x
5.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Resource logs in Data Lake Analytics should be enabled c95c74d9-38fe-4f0d-af86-0c7d626a315c Data Lake 5.0.0 1x
5.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Resource logs in Event Hub should be enabled 83a214f7-d01a-484b-91a9-ed54470c9a6a Event Hub 5.0.0 1x
5.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Resource logs in IoT Hub should be enabled 383856f8-de7f-44a2-81fc-e5135b5c2aa4 Internet of Things 3.1.0 1x
3.1.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Resource logs in Key Vault should be enabled cf820ca0-f99e-4f3e-84fb-66e913812d21 Key Vault 5.0.0 1x
5.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Resource logs in Logic Apps should be enabled 34f95f76-5386-4de7-b824-0d8478470c9d Logic Apps 5.1.0 1x
5.1.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Resource logs in Service Bus should be enabled f8d36e2f-389b-4ee4-898d-21aeb69a0f45 Service Bus 5.0.0 1x
5.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Role-Based Access Control (RBAC) should be used on Kubernetes Services ac4a19c2-fa67-49b4-8ae5-0b2e78c49457 Security Center 1.1.0 3x
1.1.0, 1.0.4, 1.0.3
Default
Audit
Allowed
Audit, Disabled
0 GA true
Saved-queries in Azure Monitor should be saved in customer storage account for logs encryption fa298e57-9444-42ba-bf04-86e8470e32c7 Monitoring 1.1.0 1x
1.1.0
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA true
Secure transfer to storage accounts should be enabled 404c3081-a854-4457-ae30-26a93ef643f9 Storage 2.0.0 1x
2.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Service Bus Premium namespaces should use a customer-managed key for encryption 295fc8b1-dc9f-4f53-9c61-3f313ceab40a Service Bus 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Disabled
0 GA true
Service Fabric clusters should have the ClusterProtectionLevel property set to EncryptAndSign 617c02be-7f02-4efd-8836-3180d47b6c68 Service Fabric 1.1.0 1x
1.1.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Service Fabric clusters should only use Azure Active Directory for client authentication b54ed75b-3e1a-44ac-a333-05ba39b99ff0 Service Fabric 1.1.0 1x
1.1.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
SQL Auditing settings should have Action-Groups configured to capture critical activities 7ff426e2-515f-405a-91c8-4f2333442eb5 SQL 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
SQL Managed Instance should have the minimal TLS version of 1.2 a8793640-60f7-487c-b5c3-1d37215905c4 SQL 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Disabled
0 GA true
SQL managed instances should use customer-managed keys to encrypt data at rest ac01ad65-10e5-46df-bdd9-6b0cad13e1d2 SQL 2.0.0 1x
2.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
SQL Server should use a virtual network service endpoint ae5d2f14-d830-42b6-9899-df6cfe9c71a3 Network 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
SQL servers on machines should have vulnerability findings resolved 6ba6d016-e7c3-4842-b8f2-4992ebc0d72d Security Center 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
SQL servers should use customer-managed keys to encrypt data at rest 0a370ff3-6cab-4e85-8995-295fd854c5b8 SQL 2.0.1 1x
2.0.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
SQL servers with auditing to storage account destination should be configured with 90 days retention or higher 89099bee-89e0-4b26-a5f4-165451757743 SQL 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Storage account containing the container with activity logs must be encrypted with BYOK fbb99e8e-e444-4da0-9ff1-75c92f5a85b2 Monitoring 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Storage account encryption scopes should use customer-managed keys to encrypt data at rest b5ec538c-daa0-4006-8596-35468b9148e8 Storage 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Storage account encryption scopes should use double encryption for data at rest bfecdea6-31c4-4045-ad42-71b9dc87247d Storage 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA unknown
Storage account keys should not be expired 044985bb-afe1-42cd-8a36-9d5d42424537 Storage 3.0.0 1x
3.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA unknown
Storage account public access should be disallowed 4fa4b6c0-31ca-4c0d-b10d-24b96f62a751 Storage 3.1.1 2x
3.1.1, 3.1.0-preview
Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
0 GA unknown
Storage accounts should allow access from trusted Microsoft services c9d007d0-c057-4772-b18c-01e546713bcd Storage 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Storage accounts should be migrated to new Azure Resource Manager resources 37e0d2fe-28a5-43d6-a273-67d37d1f5606 Storage 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Storage accounts should have infrastructure encryption 4733ea7b-a883-42fe-8cac-97454c2a9e4a Storage 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Storage accounts should have the specified minimum TLS version fe83a0eb-a853-422d-aac2-1bffd182c5d0 Storage 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Storage accounts should prevent shared key access 8c6a50c6-9ffd-4ae7-986f-5fa6111f9a54 Storage 2.0.0 1x
2.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Storage accounts should restrict network access 34c877ad-507e-4c82-993e-3452a6e0ad3c Storage 1.1.1 1x
1.1.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Storage accounts should restrict network access using virtual network rules 2a1a9cdf-e04d-429a-8416-3bfb72a1b26f Storage 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Storage Accounts should use a virtual network service endpoint 60d21c4f-21a3-4d94-85f4-b924e6aeeda4 Network 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Disabled
0 GA true
Storage accounts should use customer-managed key for encryption 6fac406b-40ca-413b-bf8e-0bf964659c25 Storage 1.0.3 1x
1.0.3
Default
Audit
Allowed
Audit, Disabled
0 GA true
Storage accounts should use private link 6edd7eda-6dd8-40f7-810d-67160c639cd9 Storage 2.0.0 1x
2.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Subnets should be associated with a Network Security Group e71308d3-144b-4262-b144-efdc3cc90517 Security Center 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Subscriptions should have a contact email address for security issues 4f4f78b8-e367-4b10-a341-d9a4ad5cf1c7 Security Center 1.0.1 1x
1.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Synapse Workspaces should use only Microsoft Entra identities for authentication during workspace creation 2158ddbe-fefa-408e-b43f-d4faef8ff3b8 Synapse 1.2.0 2x
1.2.0, 1.1.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
System updates should be installed on your machines (powered by Update Center) f85bf3e0-d513-442e-89c3-1784ad63382b Security Center 1.0.1 2x
1.0.1, 1.0.0-preview
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Temp disks and cache for agent node pools in Azure Kubernetes Service clusters should be encrypted at host 41425d9f-d1a5-499a-9932-f8ed8453932c Kubernetes 1.0.1 1x
1.0.1
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
The Log Analytics extension should be installed on Virtual Machine Scale Sets efbde977-ba53-4479-b8e9-10b957924fbf Monitoring 1.0.1 1x
1.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
There should be more than one owner assigned to your subscription 09024ccc-0c5f-475e-9457-b7c0d9ed487b Security Center 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Transparent Data Encryption on SQL databases should be enabled 17k78e20-9358-41c9-923c-fb736d382a12 SQL 2.0.0 1x
2.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Virtual machines and virtual machine scale sets should have encryption at host enabled fc4d8e41-e223-45ea-9bf5-eada37891d87 Compute 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Virtual machines' Guest Configuration extension should be deployed with system-assigned managed identity d26f7642-7545-4e18-9b75-8c9bbdee3a9a Security Center 1.0.1 1x
1.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Virtual machines should be connected to an approved virtual network d416745a-506c-48b6-8ab1-83cb814bcaa3 Network 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Virtual machines should be migrated to new Azure Resource Manager resources 1d84d5fb-01f6-4d12-ba4f-4a26081d403d Compute 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Virtual network firewall rule on Azure SQL Database should be enabled to allow traffic from the specified subnet 77e8b146-0078-4fb2-b002-e112381199f0 SQL 1.0.0 1x
1.0.0
Fixed
AuditIfNotExists
0 GA unknown
Virtual networks should use specified virtual network gateway f1776c76-f58c-4245-a8d0-2b207198dc8b Network 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
VM Image Builder templates should use private link 2154edb9-244f-4741-9970-660785bccdaa VM Image Builder 1.1.0 1x
1.1.0
Default
Audit
Allowed
Audit, Disabled, Deny
0 GA unknown
VPN gateways should use only Azure Active Directory (Azure AD) authentication for point-to-site users 21a6bc25-125e-4d13-b82d-2e19b7208ab7 Network 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Vulnerability assessment should be enabled on SQL Managed Instance 1b7aa243-30e4-4c9e-bca8-d0d3022b634a SQL 1.0.1 1x
1.0.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Vulnerability assessment should be enabled on your SQL servers ef2a8f2a-b3d9-49cd-a8a8-9a3aaaf647d9 SQL 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Vulnerability assessment should be enabled on your Synapse workspaces 0049a6b3-a662-4f3e-8635-39cf44ace45a Synapse 1.0.0 1x
1.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Web Application Firewall (WAF) should be enabled for Application Gateway 564feb30-bf6a-4854-b4bb-0d2d2d1e6c66 Network 2.0.0 1x
2.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Web Application Firewall (WAF) should use the specified mode for Application Gateway 12430be1-6cc8-4527-a9a8-e3d38f250096 Network 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Web Application Firewall (WAF) should use the specified mode for Azure Front Door Service 425bea59-a659-4cbb-8d31-34499bd030b8 Network 1.0.0 1x
1.0.0
Default
Audit
Allowed
Audit, Deny, Disabled
0 GA true
Windows Defender Exploit Guard should be enabled on your machines bed48b13-6647-468e-aa2f-1af1d3f4dd40 Guest Configuration 2.0.0 1x
2.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Windows machines should be configured to use secure communication protocols 5752e6d6-1206-46d8-8ab1-ecc2f71a8112 Guest Configuration 4.1.1 1x
4.1.1
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Windows machines should meet requirements for 'Administrative Templates - Network' 67e010c1-640d-438e-a3a5-feaccb533a98 Guest Configuration 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Windows machines should meet requirements for 'Security Options - Accounts' ee984370-154a-4ee8-9726-19d900e56fc0 Guest Configuration 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Windows machines should meet requirements for 'Security Options - Audit' 33936777-f2ac-45aa-82ec-07958ec9ade4 Guest Configuration 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Windows machines should meet requirements for 'Security Options - Interactive Logon' d472d2c9-d6a3-4500-9f5f-b15f123005aa Guest Configuration 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Windows machines should meet requirements for 'Security Options - Microsoft Network Server' caf2d518-f029-4f6b-833b-d7081702f253 Guest Configuration 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Windows machines should meet requirements for 'Security Options - Network Access' 3ff60f98-7fa4-410a-9f7f-0b00f5afdbdd Guest Configuration 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Windows machines should meet requirements for 'Security Options - Network Security' 1221c620-d201-468c-81e7-2817e6107e84 Guest Configuration 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Windows machines should meet requirements for 'Security Options - Recovery console' f71be03e-e25b-4d0f-b8bc-9b3e309b66c0 Guest Configuration 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Windows machines should meet requirements for 'Security Options - User Account Control' 492a29ed-d143-4f03-b6a4-705ce081b463 Guest Configuration 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Windows machines should meet requirements for 'Security Settings - Account Policies' f2143251-70de-4e81-87a8-36cee5a2f29d Guest Configuration 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Windows machines should meet requirements for 'System Audit Policies - Account Management' 94d9aca8-3757-46df-aa51-f218c5f11954 Guest Configuration 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Windows machines should meet requirements for 'System Audit Policies - Detailed Tracking' 58383b73-94a9-4414-b382-4146eb02611b Guest Configuration 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Windows machines should meet requirements for 'System Audit Policies - Policy Change' 2a7a701e-dff3-4da9-9ec5-42cb98594c0b Guest Configuration 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Windows machines should meet requirements for 'System Audit Policies - Privilege Use' 87845465-c458-45f3-af66-dcd62176f397 Guest Configuration 3.0.0 1x
3.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Windows machines should meet requirements of the Azure compute security baseline 72650e9f-97bc-4b2a-ab5f-9781a9fcecbc Guest Configuration 2.0.0 1x
2.0.0
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA true
Windows virtual machines should enable Azure Disk Encryption or EncryptionAtHost. 3dc5edcd-002d-444c-b216-e123bbfa37c0 Guest Configuration 1.1.1 2x
1.1.1, 1.1.0-preview
Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
0 GA unknown
Roles used Total Roles usage: 54
Total Roles unique usage: 11
Role Role Id #Policies Policies
SQL DB Contributor 9b7fa17d-e63e-47b0-bb0a-15c516ac86ec 1 Deploy SQL DB transparent data encryption
Virtual Machine Contributor 9980e02c-c2be-4d73-94e8-173b1dc7cf3c 3 Configure backup on virtual machines without a given tag to an existing recovery services vault in the same location, Deploy - Configure Log Analytics extension to be enabled on Windows virtual machine scale sets, Deploy default Microsoft IaaSAntimalware extension for Windows Server
SQL Server Contributor 6d8ee4ec-f05a-4a1d-8b00-a9b17e38b437 2 Configure Azure SQL Server to disable public network access, Configure Azure SQL Server to enable private endpoint connections
Security Admin fb1c8493-542b-48eb-b624-b4c8fea62acd 1 Deploy Advanced Threat Protection for Cosmos DB Accounts
SQL Security Manager 056cd41c-7e88-42e1-933e-88ba6a50c9c3 1 Configure Azure Defender to be enabled on SQL servers
Contributor b24988ac-6180-42a0-ab88-20f7382dd24c 19 Add system-assigned managed identity to enable Guest Configuration assignments on virtual machines with no identities, Add system-assigned managed identity to enable Guest Configuration assignments on VMs with a user-assigned identity, Configure App Configuration to disable public network access, Configure Container registries to disable public network access, Configure managed disks to disable public network access, Deploy a Flow Log resource with target virtual network, Deploy Diagnostic Settings for Batch Account to Event Hub, Deploy Diagnostic Settings for Data Lake Analytics to Event Hub, Deploy Diagnostic Settings for Data Lake Storage Gen1 to Event Hub, Deploy Diagnostic Settings for Event Hub to Event Hub, Deploy Diagnostic Settings for Logic Apps to Event Hub, Deploy Diagnostic Settings for Search Services to Event Hub, Deploy Diagnostic Settings for Service Bus to Event Hub, Deploy Diagnostic Settings for Stream Analytics to Event Hub, Deploy the Linux Guest Configuration extension to enable Guest Configuration assignments on Linux VMs, Deploy the Windows Guest Configuration extension to enable Guest Configuration assignments on Windows VMs, Enable Security Center's auto provisioning of the Log Analytics agent on your subscriptions with custom workspace., Enable Security Center's auto provisioning of the Log Analytics agent on your subscriptions with default workspace., Modify - Configure Azure File Sync to disable public network access
Backup Contributor 5e467623-bb1f-42f4-a55d-6e525e11384b 1 Configure backup on virtual machines without a given tag to an existing recovery services vault in the same location
Network Contributor 4d97b98b-1d4f-4787-a291-c67834d212e7 2 Configure Azure SQL Server to enable private endpoint connections, Deploy network watcher when virtual networks are created
Monitoring Contributor 749f88d5-cbae-40b8-bcfc-e573ddc772fa 11 Deploy - Configure diagnostic settings for SQL Databases to Log Analytics workspace, Deploy Diagnostic Settings for Batch Account to Log Analytics workspace, Deploy Diagnostic Settings for Data Lake Analytics to Log Analytics workspace, Deploy Diagnostic Settings for Data Lake Storage Gen1 to Log Analytics workspace, Deploy Diagnostic Settings for Event Hub to Log Analytics workspace, Deploy Diagnostic Settings for Key Vault to Log Analytics workspace, Deploy Diagnostic Settings for Logic Apps to Log Analytics workspace, Deploy Diagnostic Settings for Network Security Groups, Deploy Diagnostic Settings for Search Services to Log Analytics workspace, Deploy Diagnostic Settings for Service Bus to Log Analytics workspace, Deploy Diagnostic Settings for Stream Analytics to Log Analytics workspace
Storage Account Contributor 17d1049b-9a84-46fb-8f53-869881c3d3ab 1 Deploy Diagnostic Settings for Network Security Groups
Log Analytics Contributor 92aaf0da-9dab-42b6-94a3-d43ce8d16293 12 Deploy - Configure diagnostic settings for SQL Databases to Log Analytics workspace, Deploy - Configure Log Analytics extension to be enabled on Windows virtual machine scale sets, Deploy - Configure Log Analytics extension to be enabled on Windows virtual machines, Deploy Diagnostic Settings for Batch Account to Log Analytics workspace, Deploy Diagnostic Settings for Data Lake Analytics to Log Analytics workspace, Deploy Diagnostic Settings for Data Lake Storage Gen1 to Log Analytics workspace, Deploy Diagnostic Settings for Event Hub to Log Analytics workspace, Deploy Diagnostic Settings for Key Vault to Log Analytics workspace, Deploy Diagnostic Settings for Logic Apps to Log Analytics workspace, Deploy Diagnostic Settings for Search Services to Log Analytics workspace, Deploy Diagnostic Settings for Service Bus to Log Analytics workspace, Deploy Diagnostic Settings for Stream Analytics to Log Analytics workspace
History
Date/Time (UTC ymd) (i) Changes
2025-06-25 17:22:28 add Initiative e0782c37-30da-4a78-9f92-50bfe7aa2553
JSON compare n/a
JSON
api-version=2023-04-01
EPAC