Policy DisplayName |
Policy Id |
Category |
Version |
Versioning |
Effect |
Roles# |
Roles |
State |
policy in AzUSGov |
[Deprecated]: Advanced Threat Protection types should be set to 'All' in SQL Managed Instance advanced data security settings |
bda18df3-5e41-4709-add9-2554ce68c966 |
SQL |
1.0.1 (1.0.1-deprecated) |
1x 1.0.1 |
Default Disabled Allowed AuditIfNotExists, Disabled |
0 |
|
Deprecated |
unknown |
[Deprecated]: Advanced Threat Protection types should be set to 'All' in SQL server Advanced Data Security settings |
e756b945-1b1b-480b-8de8-9a0859d5f7ad |
SQL |
1.0.0 (1.0.0-deprecated) |
1x 1.0.0 |
Default Disabled Allowed AuditIfNotExists, Disabled |
0 |
|
Deprecated |
unknown |
[Deprecated]: App Service apps should have 'Client Certificates (Incoming client certificates)' enabled |
5bb220d9-2698-4ee4-8404-b9c30c9df609 |
App Service |
3.1.0 (3.1.0-deprecated) |
1x 3.1.0 |
Default Disabled Allowed Audit, Disabled |
0 |
|
Deprecated |
unknown |
[Deprecated]: Cognitive Services accounts should enable data encryption |
2bdd0062-9d75-436e-89df-487dd8e4b3c7 |
Cognitive Services |
2.0.0 (2.0.0-deprecated) |
1x 2.0.0 |
Default Disabled Allowed Audit, Deny, Disabled |
0 |
|
Deprecated |
unknown |
[Deprecated]: Cognitive Services accounts should use customer owned storage or enable data encryption. |
11566b39-f7f7-4b82-ab06-68d8700eb0a4 |
Cognitive Services |
2.0.0 (2.0.0-deprecated) |
1x 2.0.0 |
Default Disabled Allowed Audit, Deny, Disabled |
0 |
|
Deprecated |
unknown |
[Deprecated]: FTPS only should be required in your API App |
9a1b8c48-453a-4044-86c3-d8bfd823e4f5 |
App Service |
2.0.0 (2.0.0-deprecated) |
1x 2.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
Deprecated |
unknown |
[Deprecated]: Log Analytics Extension should be enabled for listed virtual machine images |
32133ab0-ee4b-4b44-98d6-042180979d50 |
Monitoring |
2.1.0 (2.1.0-deprecated) |
2x 2.1.0, 2.0.1-preview |
Default Disabled Allowed AuditIfNotExists, Disabled |
0 |
|
Deprecated |
unknown |
[Deprecated]: Log Analytics extension should be enabled in virtual machine scale sets for listed virtual machine images |
5c3bc7b8-a64c-4e08-a9cd-7ff0f31e1138 |
Monitoring |
2.1.0 (2.1.0-deprecated) |
2x 2.1.0, 2.0.1 |
Default Disabled Allowed AuditIfNotExists, Disabled |
0 |
|
Deprecated |
unknown |
[Deprecated]: SQL managed instances should use customer-managed keys to encrypt data at rest |
048248b0-55cd-46da-b1ff-39efd52db260 |
SQL |
1.0.2 (1.0.2-deprecated) |
1x 1.0.2 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
Deprecated |
unknown |
[Deprecated]: SQL servers should use customer-managed keys to encrypt data at rest |
0d134df8-db83-46fb-ad72-fe0c9428c8dd |
SQL |
2.0.1 (2.0.1-deprecated) |
1x 2.0.1 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
Deprecated |
unknown |
[Deprecated]: Virtual machines should have the Log Analytics extension installed |
a70ca396-0a34-413a-88e1-b956c1e683be |
Monitoring |
1.1.0 (1.1.0-deprecated) |
2x 1.1.0, 1.0.1 |
Default Disabled Allowed AuditIfNotExists, Disabled |
0 |
|
Deprecated |
unknown |
[Preview]: Azure Recovery Services vaults should use customer-managed keys for encrypting backup data |
2e94d99a-8a36-4563-bc77-810d8893b671 |
Backup |
1.0.0-preview |
1x 1.0.0-preview |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
Preview |
true |
[Preview]: IoT Hub device provisioning service data should be encrypted using customer-managed keys (CMK) |
47031206-ce96-41f8-861b-6a915f3de284 |
Internet of Things |
1.0.0-preview |
1x 1.0.0-preview |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
Preview |
true |
[Preview]: Log Analytics extension should be installed on your Linux Azure Arc machines |
842c54e8-c2f9-4d79-ae8d-38d8b8019373 |
Monitoring |
1.0.1-preview |
1x 1.0.1-preview |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
Preview |
unknown |
[Preview]: Log Analytics extension should be installed on your Windows Azure Arc machines |
d69b1763-b96d-40b8-a2d9-ca31e9fd0d3e |
Monitoring |
1.0.1-preview |
1x 1.0.1-preview |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
Preview |
unknown |
[Preview]: Machines should have ports closed that might expose attack vectors |
af99038c-02fd-4a2f-ac24-386b62bf32de |
Security Center |
1.0.0-preview |
1x 1.0.0-preview |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
Preview |
unknown |
[Preview]: Network traffic data collection agent should be installed on Linux virtual machines |
04c4380f-3fae-46e8-96c9-30193528f602 |
Monitoring |
1.0.2-preview |
1x 1.0.2-preview |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
Preview |
true |
[Preview]: Network traffic data collection agent should be installed on Windows virtual machines |
2f2ee1de-44aa-4762-b6bd-0893fc3f306d |
Monitoring |
1.0.2-preview |
1x 1.0.2-preview |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
Preview |
true |
[Preview]: Recovery Services vaults should use private link |
11e3da8c-1d68-4392-badd-0ff3c43ab5b0 |
Site Recovery |
1.0.0-preview |
1x 1.0.0-preview |
Default Audit Allowed Audit, Disabled |
0 |
|
Preview |
unknown |
Activity log should be retained for at least one year |
b02aacc0-b073-424e-8298-42b22829ee0a |
Monitoring |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
API Management APIs should use only encrypted protocols |
ee7495e7-3ba7-40b6-bfee-c29e22cc75d4 |
API Management |
2.0.2 |
1x 2.0.2 |
Default Audit Allowed Audit, Disabled, Deny |
0 |
|
GA |
unknown |
App Configuration should use a customer-managed key |
967a4b4b-2da9-43c1-b7d0-f98d0d74d0b1 |
App Configuration |
1.1.0 |
1x 1.1.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
unknown |
App Configuration should use private link |
ca610c1d-041c-4332-9d88-7ed3094967c7 |
App Configuration |
1.0.2 |
1x 1.0.2 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
App Service apps should require FTPS only |
4d24b6d4-5e53-4a4f-a7f4-618fa573ee4b |
App Service |
3.0.0 |
1x 3.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
App Service apps should use a virtual network service endpoint |
2d21331d-a4c2-4def-a9ad-ee4e1e023beb |
Network |
2.0.1 |
1x 2.0.1 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Audit flow logs configuration for every virtual network |
4c3c6c5f-0d47-4402-99b8-aa543dd8bcee |
Network |
1.0.1 |
2x 1.0.1, 1.0.0 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
unknown |
Audit virtual machines without disaster recovery configured |
0015ea4d-51ff-4ce3-8d8c-f3f8f0179a56 |
Compute |
1.0.0 |
1x 1.0.0 |
Fixed auditIfNotExists |
0 |
|
GA |
true |
Azure AI Search service should use a SKU that supports private link |
a049bf77-880b-470f-ba6d-9f21c530cf83 |
Search |
1.0.1 |
2x 1.0.1, 1.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Azure AI Services resources should encrypt data at rest with a customer-managed key (CMK) |
67121cc7-ff39-4ab8-b7e3-95b84dab487d |
Cognitive Services |
2.2.0 |
2x 2.2.0, 2.1.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Azure AI Services resources should use Azure Private Link |
d6759c02-b87f-42b7-892e-71b3f471d782 |
Azure Ai Services |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
Azure API for FHIR should use a customer-managed key to encrypt data at rest |
051cba44-2429-45b9-9649-46cec11c7119 |
API for FHIR |
1.1.0 |
1x 1.1.0 |
Default Audit Allowed audit, Audit, disabled, Disabled |
0 |
|
GA |
unknown |
Azure API for FHIR should use private link |
1ee56206-5dd1-42ab-b02d-8aae8b1634ce |
API for FHIR |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
unknown |
Azure Automation accounts should use customer-managed keys to encrypt data at rest |
56a5ee18-2ae6-4810-86f7-18e39ce5629b |
Automation |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Azure Backup should be enabled for Virtual Machines |
013e242c-8828-4970-87b3-ab247555486d |
Backup |
3.0.0 |
1x 3.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Azure Batch account should use customer-managed keys to encrypt data |
99e9ccd8-3db9-4592-b0d1-14b1715a4d8a |
Batch |
1.0.1 |
1x 1.0.1 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Azure Cache for Redis should use private link |
7803067c-7d34-46e3-8c79-0ca68fc4036d |
Cache |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Azure Container Instance container group should use customer-managed key for encryption |
0aa61e00-0a01-4a3c-9945-e93cffedf0e6 |
Container Instance |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Disabled, Deny |
0 |
|
GA |
true |
Azure Cosmos DB accounts should have firewall rules |
862e97cf-49fc-4a5c-9de4-40d4e2e7c8eb |
Cosmos DB |
2.1.0 |
2x 2.1.0, 2.0.0 |
Default Deny Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Azure Cosmos DB accounts should use customer-managed keys to encrypt data at rest |
1f905d99-2ab7-462c-a6b0-f709acca6c8f |
Cosmos DB |
1.1.0 |
1x 1.1.0 |
Default Audit Allowed audit, Audit, deny, Deny, disabled, Disabled |
0 |
|
GA |
true |
Azure Data Box jobs should enable double encryption for data at rest on the device |
c349d81b-9985-44ae-a8da-ff98d108ede8 |
Data Box |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Azure Data Box jobs should use a customer-managed key to encrypt the device unlock password |
86efb160-8de7-451d-bc08-5d475b0aadae |
Data Box |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Azure Data Explorer encryption at rest should use a customer-managed key |
81e74cea-30fd-40d5-802f-d72103c2aaaa |
Azure Data Explorer |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Azure data factories should be encrypted with a customer-managed key |
4ec52d6d-beb7-40c4-9a9e-fe753254690e |
Data Factory |
1.0.1 |
1x 1.0.1 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Azure Data Factory should use private link |
8b0323be-cc25-4b61-935d-002c3798c6ea |
Data Factory |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Azure Databricks Clusters should disable public IP |
51c1490f-3319-459c-bbbc-7f391bbed753 |
Azure Databricks |
1.0.1 |
1x 1.0.1 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Azure Databricks Workspaces should use private link |
258823f2-4595-4b52-b333-cc96192710d8 |
Azure Databricks |
1.0.2 |
1x 1.0.2 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
Azure Defender for App Service should be enabled |
2913021d-f2fd-4f3d-b958-22354e2bdbcb |
Security Center |
1.0.3 |
1x 1.0.3 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
unknown |
Azure Defender for Azure SQL Database servers should be enabled |
7fe3b40f-802b-4cdd-8bd4-fd799c948cc2 |
Security Center |
1.0.2 |
1x 1.0.2 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Azure Defender for Key Vault should be enabled |
0e6763cc-5078-4e64-889d-ff4d9a839047 |
Security Center |
1.0.3 |
1x 1.0.3 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
unknown |
Azure Defender for open-source relational databases should be enabled |
0a9fbe0d-c5c4-4da8-87d8-f4fd77338835 |
Security Center |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
unknown |
Azure Defender for Resource Manager should be enabled |
c3d20c29-b36d-48fe-808b-99a87530ad99 |
Security Center |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Azure Defender for servers should be enabled |
4da35fc9-c9e7-4960-aec9-797fe7d9051d |
Security Center |
1.0.3 |
1x 1.0.3 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Azure Defender for SQL servers on machines should be enabled |
6581d072-105e-4418-827f-bd446d56421b |
Security Center |
1.0.2 |
1x 1.0.2 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
unknown |
Azure Defender for SQL should be enabled for unprotected Azure SQL servers |
abfb4388-5bf4-4ad7-ba82-2cd2f41ceae9 |
SQL |
2.0.1 |
1x 2.0.1 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Azure Defender for SQL should be enabled for unprotected MySQL flexible servers |
3bc8a0d5-38e0-4a3d-a657-2cb64468fc34 |
Security Center |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Azure Defender for SQL should be enabled for unprotected PostgreSQL flexible servers |
d38668f5-d155-42c7-ab3d-9b57b50f8fbf |
Security Center |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Azure Defender for SQL should be enabled for unprotected SQL Managed Instances |
abfb7388-5bf4-4ad7-ba99-2cd2f41cebb9 |
SQL |
1.0.2 |
1x 1.0.2 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Azure Event Grid domains should use private link |
9830b652-8523-49cc-b1b3-e17dce1127ca |
Event Grid |
1.0.2 |
1x 1.0.2 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
Azure Event Grid topics should use private link |
4b90e17e-8448-49db-875e-bd83fb6f804f |
Event Grid |
1.0.2 |
1x 1.0.2 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
Azure File Sync should use private link |
1d320205-c6a1-4ac6-873d-46224024e8e2 |
Storage |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Azure HDInsight clusters should use customer-managed keys to encrypt data at rest |
64d314f6-6062-4780-a861-c23e8951bee5 |
HDInsight |
1.0.1 |
1x 1.0.1 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Azure HDInsight clusters should use encryption at host to encrypt data at rest |
1fd32ebd-e4c3-4e13-a54a-d7422d4d95f6 |
HDInsight |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Azure HDInsight clusters should use encryption in transit to encrypt communication between Azure HDInsight cluster nodes |
d9da03a1-f3c3-412a-9709-947156872263 |
HDInsight |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Azure Key Vault should have firewall enabled or public network access disabled |
55615ac9-af46-4a59-874e-391cc3dfb490 |
Key Vault |
3.3.0 |
2x 3.3.0, 3.2.1 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Azure Key Vault should use RBAC permission model |
12d4fa5e-1f9f-4c21-97a9-b99b3c6611b5 |
Key Vault |
1.0.1 |
2x 1.0.1, 1.0.0-preview |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
unknown |
Azure Key Vaults should use private link |
a6abeaec-4d90-4a02-805f-6b26c4d3fbe9 |
Key Vault |
1.2.1 |
1x 1.2.1 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Azure Machine Learning compute instances should be recreated to get the latest software updates |
f110a506-2dcb-422e-bcea-d533fc8c35e2 |
Machine Learning |
1.0.3 |
1x 1.0.3 |
Fixed [parameters('effects')] |
0 |
|
GA |
true |
Azure Machine Learning workspaces should be encrypted with a customer-managed key |
ba769a63-b8cc-4b2d-abf6-ac33c7204be8 |
Machine Learning |
1.1.0 |
2x 1.1.0, 1.0.3 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Azure Machine Learning workspaces should use private link |
45e05259-1eb5-4f70-9574-baf73e9d219b |
Machine Learning |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
Azure Monitor Logs clusters should be encrypted with customer-managed key |
1f68a601-6e6d-4e42-babf-3f643a047ea2 |
Monitoring |
1.1.0 |
1x 1.1.0 |
Default Audit Allowed audit, Audit, deny, Deny, disabled, Disabled |
0 |
|
GA |
true |
Azure Monitor Logs for Application Insights should be linked to a Log Analytics workspace |
d550e854-df1a-4de9-bf44-cd894b39a95e |
Monitoring |
1.1.0 |
1x 1.1.0 |
Default Audit Allowed audit, Audit, deny, Deny, disabled, Disabled |
0 |
|
GA |
unknown |
Azure Monitor should collect activity logs from all regions |
41388f1c-2db0-4c25-95b2-35d7f5ccbfa9 |
Monitoring |
2.0.0 |
1x 2.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Azure Monitor solution 'Security and Audit' must be deployed |
3e596b57-105f-48a6-be97-03e9243bad6e |
Monitoring |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
unknown |
Azure MySQL flexible server should have Microsoft Entra Only Authentication enabled |
40e85574-ef33-47e8-a854-7a65c7500560 |
SQL |
1.0.1 |
2x 1.0.1, 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
unknown |
Azure Service Bus namespaces should use private link |
1c06e275-d63d-4540-b761-71f364c2111d |
Service Bus |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Azure SignalR Service should use private link |
2393d2cf-a342-44cd-a2e2-fe0188fd1234 |
SignalR |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
Azure SQL Database should be running TLS version 1.2 or newer |
32e6bbec-16b6-44c2-be37-c5b672d103cf |
SQL |
2.0.0 |
1x 2.0.0 |
Default Audit Allowed Audit, Disabled, Deny |
0 |
|
GA |
true |
Azure SQL Database should have Microsoft Entra-only authentication enabled during creation |
abda6d70-9778-44e7-84a8-06713e6db027 |
SQL |
1.2.0 |
2x 1.2.0, 1.1.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Azure Stream Analytics jobs should use customer-managed keys to encrypt data |
87ba29ef-1ab3-4d82-b763-87fcd4f531f7 |
Stream Analytics |
1.1.0 |
1x 1.1.0 |
Default Audit Allowed audit, Audit, deny, Deny, disabled, Disabled |
0 |
|
GA |
true |
Azure subscriptions should have a log profile for Activity Log |
7796937f-307b-4598-941c-67d3a05ebfe7 |
Monitoring |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Azure Synapse workspaces should use customer-managed keys to encrypt data at rest |
f7d52b2d-e161-4dfa-a82b-55e564167385 |
Synapse |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Azure Synapse workspaces should use private link |
72d11df1-dd8a-41f7-8925-b05b960ebafc |
Synapse |
1.0.1 |
1x 1.0.1 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
Azure Web PubSub Service should use private link |
eb907f70-7514-460d-92b3-a5ae93b4f917 |
Web PubSub |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
unknown |
Bot Service should be encrypted with a customer-managed key |
51522a96-0869-4791-82f3-981000c2c67f |
Bot Service |
1.1.0 |
1x 1.1.0 |
Default Audit Allowed audit, Audit, deny, Deny, disabled, Disabled |
0 |
|
GA |
true |
Both operating systems and data disks in Azure Kubernetes Service clusters should be encrypted by customer-managed keys |
7d7be79c-23ba-4033-84dd-45e2a5ccdd67 |
Kubernetes |
1.0.1 |
1x 1.0.1 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Configure Azure SQL Server to enable private endpoint connections |
8e8ca470-d980-4831-99e6-dc70d9f6af87 |
SQL |
1.0.0 |
1x 1.0.0 |
Default DeployIfNotExists Allowed DeployIfNotExists, Disabled |
2 |
Network Contributor, SQL Server Contributor |
GA |
unknown |
Configure backup on virtual machines without a given tag to an existing recovery services vault in the same location |
09ce66bc-1220-4153-8104-e3f51c936913 |
Backup |
9.4.0 |
4x 9.4.0, 9.3.0, 9.2.0, 9.1.0 |
Default DeployIfNotExists Allowed auditIfNotExists, AuditIfNotExists, deployIfNotExists, DeployIfNotExists, disabled, Disabled |
2 |
Backup Contributor, Virtual Machine Contributor |
GA |
unknown |
Container registries should be encrypted with a customer-managed key |
5b9159ae-1701-4a6f-9a7a-aa9c8ddd0580 |
Container Registry |
1.1.2 |
1x 1.1.2 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Container registries should use private link |
e8eef0a8-67cf-4eb4-9386-14b0e78733d4 |
Container Registry |
1.0.1 |
1x 1.0.1 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
CosmosDB accounts should use private link |
58440f8a-10c5-4151-bdce-dfbaad4a20b7 |
Cosmos DB |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
Deploy - Configure diagnostic settings for SQL Databases to Log Analytics workspace |
b79fa14e-238a-4c2d-b376-442ce508fc84 |
SQL |
4.0.0 |
1x 4.0.0 |
Default DeployIfNotExists Allowed DeployIfNotExists, Disabled |
2 |
Log Analytics Contributor, Monitoring Contributor |
GA |
true |
Deploy - Configure Log Analytics extension to be enabled on Windows virtual machine scale sets |
3c1b3629-c8f8-4bf6-862c-037cb9094038 |
Monitoring |
3.1.0 |
1x 3.1.0 |
Default DeployIfNotExists Allowed DeployIfNotExists, Disabled |
2 |
Log Analytics Contributor, Virtual Machine Contributor |
GA |
unknown |
Deploy - Configure Log Analytics extension to be enabled on Windows virtual machines |
0868462e-646c-4fe3-9ced-a733534b6a2c |
Monitoring |
3.1.0 |
1x 3.1.0 |
Default DeployIfNotExists Allowed DeployIfNotExists, Disabled |
1 |
Log Analytics Contributor |
GA |
true |
Deploy a Flow Log resource with target virtual network |
cd6f7aff-2845-4dab-99f2-6d1754a754b0 |
Network |
1.1.1 |
3x 1.1.1, 1.1.0, 1.0.0 |
Default DeployIfNotExists Allowed DeployIfNotExists, Disabled |
1 |
Contributor |
GA |
unknown |
Deploy Advanced Threat Protection for Cosmos DB Accounts |
b5f04e03-92a3-4b09-9410-2cc5e5047656 |
Cosmos DB |
1.0.0 |
1x 1.0.0 |
Default DeployIfNotExists Allowed DeployIfNotExists, Disabled |
1 |
Security Admin |
GA |
true |
Deploy Diagnostic Settings for Batch Account to Log Analytics workspace |
c84e5349-db6d-4769-805e-e14037dab9b5 |
Monitoring |
1.1.0 |
2x 1.1.0, 1.0.0 |
Default DeployIfNotExists Allowed DeployIfNotExists, Disabled |
2 |
Log Analytics Contributor, Monitoring Contributor |
GA |
unknown |
Deploy Diagnostic Settings for Data Lake Analytics to Log Analytics workspace |
d56a5a7c-72d7-42bc-8ceb-3baf4c0eae03 |
Monitoring |
1.0.0 |
1x 1.0.0 |
Default DeployIfNotExists Allowed DeployIfNotExists, Disabled |
2 |
Log Analytics Contributor, Monitoring Contributor |
GA |
unknown |
Deploy Diagnostic Settings for Data Lake Storage Gen1 to Log Analytics workspace |
25763a0a-5783-4f14-969e-79d4933eb74b |
Monitoring |
1.0.0 |
1x 1.0.0 |
Default DeployIfNotExists Allowed DeployIfNotExists, Disabled |
2 |
Log Analytics Contributor, Monitoring Contributor |
GA |
unknown |
Deploy Diagnostic Settings for Event Hub to Log Analytics workspace |
1f6e93e8-6b31-41b1-83f6-36e449a42579 |
Monitoring |
2.1.0 |
2x 2.1.0, 2.0.0 |
Default DeployIfNotExists Allowed DeployIfNotExists, Disabled |
2 |
Log Analytics Contributor, Monitoring Contributor |
GA |
unknown |
Deploy Diagnostic Settings for Key Vault to Log Analytics workspace |
bef3f64c-5290-43b7-85b0-9b254eef4c47 |
Monitoring |
3.0.0 |
1x 3.0.0 |
Default DeployIfNotExists Allowed DeployIfNotExists, Disabled |
2 |
Log Analytics Contributor, Monitoring Contributor |
GA |
true |
Deploy Diagnostic Settings for Logic Apps to Log Analytics workspace |
b889a06c-ec72-4b03-910a-cb169ee18721 |
Monitoring |
1.0.0 |
1x 1.0.0 |
Default DeployIfNotExists Allowed DeployIfNotExists, Disabled |
2 |
Log Analytics Contributor, Monitoring Contributor |
GA |
true |
Deploy Diagnostic Settings for Search Services to Log Analytics workspace |
08ba64b8-738f-4918-9686-730d2ed79c7d |
Monitoring |
1.0.0 |
1x 1.0.0 |
Default DeployIfNotExists Allowed DeployIfNotExists, Disabled |
2 |
Log Analytics Contributor, Monitoring Contributor |
GA |
unknown |
Deploy Diagnostic Settings for Service Bus to Log Analytics workspace |
04d53d87-841c-4f23-8a5b-21564380b55e |
Monitoring |
2.2.0 |
2x 2.2.0, 2.1.0 |
Default DeployIfNotExists Allowed DeployIfNotExists, Disabled |
2 |
Log Analytics Contributor, Monitoring Contributor |
GA |
unknown |
Deploy Diagnostic Settings for Stream Analytics to Log Analytics workspace |
237e0f7e-b0e8-4ec4-ad46-8c12cb66d673 |
Monitoring |
1.0.0 |
1x 1.0.0 |
Default DeployIfNotExists Allowed DeployIfNotExists, Disabled |
2 |
Log Analytics Contributor, Monitoring Contributor |
GA |
unknown |
Deploy network watcher when virtual networks are created |
a9b99dd8-06c5-4317-8629-9d86a3c6e7d9 |
Network |
1.0.0 |
1x 1.0.0 |
Fixed DeployIfNotExists |
1 |
Network Contributor |
GA |
unknown |
Disk access resources should use private link |
f39f5f49-4abf-44de-8c70-0756997bfb51 |
Compute |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Enable Security Center's auto provisioning of the Log Analytics agent on your subscriptions with custom workspace. |
8e7da0a5-0a0e-4bbc-bfc0-7773c018b616 |
Security Center |
1.0.0 |
1x 1.0.0 |
Default DeployIfNotExists Allowed DeployIfNotExists, Disabled |
1 |
Contributor |
GA |
true |
Enable Security Center's auto provisioning of the Log Analytics agent on your subscriptions with default workspace. |
6df2fee6-a9ed-4fef-bced-e13be1b25f1c |
Security Center |
1.0.0 |
1x 1.0.0 |
Default DeployIfNotExists Allowed DeployIfNotExists, Disabled |
1 |
Contributor |
GA |
true |
Enforce SSL connection should be enabled for MySQL database servers |
e802a67a-daf5-4436-9ea6-f6d821dd0c5d |
SQL |
1.0.1 |
1x 1.0.1 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
Enforce SSL connection should be enabled for PostgreSQL database servers |
d158790f-bfb0-486c-8631-2dc6b4e8e6af |
SQL |
1.0.1 |
1x 1.0.1 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
Event Hub namespaces should use a customer-managed key for encryption |
a1ad735a-e96f-45d2-a7b2-9a4932cab7ec |
Event Hub |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
Event Hub namespaces should use private link |
b8564268-eb4a-4337-89be-a19db070c59d |
Event Hub |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Flow logs should be configured for every network security group |
c251913d-7d24-4958-af87-478ed3b9ba41 |
Network |
1.1.0 |
1x 1.1.0 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
Function apps should require FTPS only |
399b2637-a50f-4f95-96f8-3a145476eb15 |
App Service |
3.0.0 |
1x 3.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Geo-redundant backup should be enabled for Azure Database for MariaDB |
0ec47710-77ff-4a3d-9181-6aa50af424d0 |
SQL |
1.0.1 |
1x 1.0.1 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
Geo-redundant backup should be enabled for Azure Database for MySQL |
82339799-d096-41ae-8538-b108becf0970 |
SQL |
1.0.1 |
1x 1.0.1 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
Geo-redundant backup should be enabled for Azure Database for PostgreSQL |
48af4db5-9b8b-401c-8e74-076be876a430 |
SQL |
1.0.1 |
1x 1.0.1 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
Geo-redundant storage should be enabled for Storage Accounts |
bf045164-79ba-4215-8f95-f8048dc1780b |
Storage |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
HPC Cache accounts should use customer-managed key for encryption |
970f84d8-71b6-4091-9979-ace7e3fb6dbb |
Storage |
2.0.0 |
1x 2.0.0 |
Default Audit Allowed Audit, Disabled, Deny |
0 |
|
GA |
unknown |
Infrastructure encryption should be enabled for Azure Database for MySQL servers |
3a58212a-c829-4f13-9872-6371df2fd0b4 |
SQL |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
unknown |
IoT Hub device provisioning service instances should use private link |
df39c015-56a4-45de-b4a3-efe77bed320d |
Internet of Things |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
Key Vault keys should have an expiration date |
152b15f7-8e1f-4c1f-ab71-8c010ba5dbc0 |
Key Vault |
1.0.2 |
1x 1.0.2 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Key vaults should have soft delete enabled |
1e66c121-a66a-4b1f-9b83-0fd99bf0fc2d |
Key Vault |
3.0.0 |
1x 3.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Keys should have a rotation policy ensuring that their rotation is scheduled within the specified number of days after creation. |
d8cf8476-a2ec-4916-896e-992351803c44 |
Key Vault |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
unknown |
Kubernetes cluster containers should run with a read only root file system |
df49d893-a74c-421d-bc95-c663042e5b80 |
Kubernetes |
6.3.0 |
3x 6.3.0, 6.2.0, 6.1.0 |
Default Audit Allowed audit, Audit, deny, Deny, disabled, Disabled |
0 |
|
GA |
true |
Log checkpoints should be enabled for PostgreSQL database servers |
eb6f77b9-bd53-4e35-a23d-7f65d5f0e43d |
SQL |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Log connections should be enabled for PostgreSQL database servers |
eb6f77b9-bd53-4e35-a23d-7f65d5f0e442 |
SQL |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Logic Apps Integration Service Environment should be encrypted with customer-managed keys |
1fafeaf6-7927-4059-a50a-8eb2a7a6f2b5 |
Logic Apps |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Long-term geo-redundant backup should be enabled for Azure SQL Databases |
d38fc420-0735-4ef3-ac11-c806f651a570 |
SQL |
2.0.0 |
1x 2.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Machines should be configured to periodically check for missing system updates |
bd876905-5b84-4f73-ab2d-2e7a7c4568d9 |
Azure Update Manager |
3.8.0 |
5x 3.8.0, 3.7.0, 3.6.0, 3.5.0, 3.4.1 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Managed disks should be double encrypted with both platform-managed and customer-managed keys |
ca91455f-eace-4f96-be59-e6e2c35b4816 |
Compute |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Managed disks should use a specific set of disk encryption sets for the customer-managed key encryption |
d461a302-a187-421a-89ac-84acdb4edc04 |
Compute |
2.0.0 |
1x 2.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
unknown |
Microsoft Antimalware for Azure should be configured to automatically update protection signatures |
c43e4a30-77cb-48ab-a4dd-93f175c63b57 |
Compute |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Microsoft Defender CSPM should be enabled |
1f90fc71-a595-4066-8974-d4d0802e8ef0 |
Security Center |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
unknown |
Microsoft Defender for APIs should be enabled |
7926a6d1-b268-4586-8197-e8ae90c877d7 |
Security Center |
1.0.3 |
1x 1.0.3 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
unknown |
Microsoft Defender for Azure Cosmos DB should be enabled |
adbe85b5-83e6-4350-ab58-bf3a4f736e5e |
Security Center |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
unknown |
Microsoft Defender for Containers should be enabled |
1c988dd6-ade4-430f-a608-2a3e5b0a6d38 |
Security Center |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Microsoft Defender for SQL should be enabled for unprotected Synapse workspaces |
d31e5c31-63b2-4f12-887b-e49456834fa1 |
Security Center |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Microsoft Defender for SQL status should be protected for Arc-enabled SQL Servers |
938c4981-c2c9-4168-9cd6-972b8675f906 |
Security Center |
1.1.0 |
2x 1.1.0, 1.0.1 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
unknown |
Microsoft Defender for Storage should be enabled |
640d2586-54d2-465f-877f-9ffc1d2109f4 |
Security Center |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
unknown |
MySQL servers should use customer-managed keys to encrypt data at rest |
83cef61d-dbd1-4b20-a4fc-5fbc7da10833 |
SQL |
1.0.4 |
1x 1.0.4 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
unknown |
Network Watcher flow logs should have traffic analytics enabled |
2f080164-9f4d-497e-9db6-416dc9f7b48a |
Network |
1.0.1 |
1x 1.0.1 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
unknown |
Only secure connections to your Azure Cache for Redis should be enabled |
22bee202-a82f-4305-9a2a-6d7f44d4dedb |
Cache |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
OS and data disks should be encrypted with a customer-managed key |
702dd420-7fcc-42c5-afe8-4026edd20fe0 |
Compute |
3.0.0 |
1x 3.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
PostgreSQL servers should use customer-managed keys to encrypt data at rest |
18adea5e-f416-4d0f-8aa8-d24321e3e274 |
SQL |
1.0.4 |
1x 1.0.4 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Private endpoint connections on Azure SQL Database should be enabled |
7698e800-9299-47a6-b3b6-5a0fee576eed |
SQL |
1.1.0 |
1x 1.1.0 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
Private endpoint connections on Batch accounts should be enabled |
009a0c92-f5b4-4776-9b66-4ed2b4775563 |
Batch |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
unknown |
Private endpoint should be enabled for MariaDB servers |
0a1302fb-a631-4106-9753-f3d494733990 |
SQL |
1.0.2 |
1x 1.0.2 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Private endpoint should be enabled for MySQL servers |
7595c971-233d-4bcf-bd18-596129188c49 |
SQL |
1.0.2 |
1x 1.0.2 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Private endpoint should be enabled for PostgreSQL servers |
0564d078-92f5-4f97-8398-b9f58a51f70b |
SQL |
1.0.2 |
1x 1.0.2 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Role-Based Access Control (RBAC) should be used on Kubernetes Services |
ac4a19c2-fa67-49b4-8ae5-0b2e78c49457 |
Security Center |
1.1.0 |
3x 1.1.0, 1.0.4, 1.0.3 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
Saved-queries in Azure Monitor should be saved in customer storage account for logs encryption |
fa298e57-9444-42ba-bf04-86e8470e32c7 |
Monitoring |
1.1.0 |
1x 1.1.0 |
Default Audit Allowed audit, Audit, deny, Deny, disabled, Disabled |
0 |
|
GA |
true |
Secure transfer to storage accounts should be enabled |
404c3081-a854-4457-ae30-26a93ef643f9 |
Storage |
2.0.0 |
1x 2.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Service Bus Premium namespaces should use a customer-managed key for encryption |
295fc8b1-dc9f-4f53-9c61-3f313ceab40a |
Service Bus |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
SQL Auditing settings should have Action-Groups configured to capture critical activities |
7ff426e2-515f-405a-91c8-4f2333442eb5 |
SQL |
1.0.0 |
1x 1.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
SQL managed instances should use customer-managed keys to encrypt data at rest |
ac01ad65-10e5-46df-bdd9-6b0cad13e1d2 |
SQL |
2.0.0 |
1x 2.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
SQL servers should use customer-managed keys to encrypt data at rest |
0a370ff3-6cab-4e85-8995-295fd854c5b8 |
SQL |
2.0.1 |
1x 2.0.1 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Storage account encryption scopes should use customer-managed keys to encrypt data at rest |
b5ec538c-daa0-4006-8596-35468b9148e8 |
Storage |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Storage account encryption scopes should use double encryption for data at rest |
bfecdea6-31c4-4045-ad42-71b9dc87247d |
Storage |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
unknown |
Storage accounts should allow access from trusted Microsoft services |
c9d007d0-c057-4772-b18c-01e546713bcd |
Storage |
1.0.0 |
1x 1.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Storage accounts should prevent shared key access |
8c6a50c6-9ffd-4ae7-986f-5fa6111f9a54 |
Storage |
2.0.0 |
1x 2.0.0 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
Storage accounts should use customer-managed key for encryption |
6fac406b-40ca-413b-bf8e-0bf964659c25 |
Storage |
1.0.3 |
1x 1.0.3 |
Default Audit Allowed Audit, Disabled |
0 |
|
GA |
true |
Storage accounts should use private link |
6edd7eda-6dd8-40f7-810d-67160c639cd9 |
Storage |
2.0.0 |
1x 2.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
System updates should be installed on your machines (powered by Update Center) |
f85bf3e0-d513-442e-89c3-1784ad63382b |
Security Center |
1.0.1 |
2x 1.0.1, 1.0.0-preview |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Temp disks and cache for agent node pools in Azure Kubernetes Service clusters should be encrypted at host |
41425d9f-d1a5-499a-9932-f8ed8453932c |
Kubernetes |
1.0.1 |
1x 1.0.1 |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
true |
The Log Analytics extension should be installed on Virtual Machine Scale Sets |
efbde977-ba53-4479-b8e9-10b957924fbf |
Monitoring |
1.0.1 |
1x 1.0.1 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
There should be more than one owner assigned to your subscription |
09024ccc-0c5f-475e-9457-b7c0d9ed487b |
Security Center |
3.0.0 |
1x 3.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
VM Image Builder templates should use private link |
2154edb9-244f-4741-9970-660785bccdaa |
VM Image Builder |
1.1.0 |
1x 1.1.0 |
Default Audit Allowed Audit, Disabled, Deny |
0 |
|
GA |
unknown |
Windows Defender Exploit Guard should be enabled on your machines |
bed48b13-6647-468e-aa2f-1af1d3f4dd40 |
Guest Configuration |
2.0.0 |
1x 2.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Windows machines should be configured to use secure communication protocols |
5752e6d6-1206-46d8-8ab1-ecc2f71a8112 |
Guest Configuration |
4.1.1 |
1x 4.1.1 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |
Windows machines should meet requirements for 'Security Options - Recovery console' |
f71be03e-e25b-4d0f-b8bc-9b3e309b66c0 |
Guest Configuration |
3.0.0 |
1x 3.0.0 |
Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
0 |
|
GA |
true |