ASC means Azure Security Center, now called Microsoft Defender for Cloud.
ASC Default is an Azure Policy initiative assignment: it applies a bundle of security checks to a scope, such as your subscription.
See its results in Azure portal → Policy → Compliance → ASC Default. You do not need to open Defender for Cloud to view assignment compliance. Defender has related security recommendations; the two views can differ. Microsoft: viewing compliance
For one shared assignment across subscriptions, see MCSB managed centrally, simply.
Saved policy reference
224 saved policies. Open a group for details and JSON.
Defender and cross-service checks (53)
| Policy / sources | Flagged when… | Saved default effect |
|---|---|---|
| Guest Configuration extension should be installed on your machines · JSON · Docs | a supported virtual machine lacks a successfully installed Guest Configuration extension for inspecting settings inside it. | AuditIfNotExists |
| Virtual machines' Guest Configuration extension should be deployed with system-assigned managed identity · JSON · Docs | a machine using Guest Configuration lacks its own system-assigned identity for authenticating to Azure. | AuditIfNotExists |
| System updates should be installed on your machines (powered by Update Center) · JSON · Docs | Defender reports missing system updates, or no passing assessment exists for the Azure or Arc-connected machine. | AuditIfNotExists |
| Management ports of virtual machines should be protected with just-in-time network access control · JSON · Docs | Defender reports missing time-limited administration access, or no passing assessment exists for the machine. | AuditIfNotExists |
| Subnets should be associated with a Network Security Group · JSON · Docs | Defender reports missing subnet network security-group protection, or no passing assessment exists for that protection. | Disabled |
| Internet-facing virtual machines should be protected with network security groups · JSON · Docs | Defender reports missing network security-group protection for an Internet-facing machine, or no passing assessment exists. | AuditIfNotExists |
| Non-internet-facing virtual machines should be protected with network security groups · JSON · Docs | Defender reports missing network security-group protection for an internal machine, or no passing assessment exists. | AuditIfNotExists |
| A vulnerability assessment solution should be enabled on your virtual machines · JSON · Docs | Defender reports no supported vulnerability scanner on the machine, or no passing assessment exists. | AuditIfNotExists |
| All network ports should be restricted on network security groups associated to your virtual machine · JSON · Docs | Defender reports overly broad incoming network rules, such as Internet-wide access, or no passing assessment exists. | AuditIfNotExists |
| SQL databases should have vulnerability findings resolved · JSON · Docs | Defender reports unresolved database vulnerability findings, or no passing assessment exists for the server or managed instance. | AuditIfNotExists |
| SQL servers on machines should have vulnerability findings resolved · JSON · Docs | Defender reports unresolved SQL Server vulnerability findings on an Azure or Arc-connected machine, or no passing assessment exists. | AuditIfNotExists |
| A maximum of 3 owners should be designated for your subscription · JSON · Docs | Defender reports more than three subscription owners, or no passing assessment of owner count exists. | AuditIfNotExists |
| There should be more than one owner assigned to your subscription · JSON · Docs | Defender reports fewer than two subscription owners, or no passing assessment of administrator redundancy exists. | AuditIfNotExists |
| Blocked accounts with owner permissions on Azure resources should be removed · JSON · Docs | Defender reports blocked sign-in accounts retaining owner permissions, or no passing assessment exists for those accounts. | AuditIfNotExists |
| Blocked accounts with read and write permissions on Azure resources should be removed · JSON · Docs | Defender reports blocked sign-in accounts retaining read or write access, or no passing assessment exists. | AuditIfNotExists |
| Guest accounts with owner permissions on Azure resources should be removed · JSON · Docs | Defender reports guest accounts from outside the tenant holding owner permissions, or no passing assessment exists. | AuditIfNotExists |
| Guest accounts with write permissions on Azure resources should be removed · JSON · Docs | Defender reports guest accounts from outside the tenant holding write permissions, or no passing assessment exists. | AuditIfNotExists |
| Guest accounts with read permissions on Azure resources should be removed · JSON · Docs | Defender reports guest accounts from outside the tenant holding read permissions, or no passing assessment exists. | AuditIfNotExists |
| Azure DDoS Protection should be enabled · JSON · Docs | Defender reports missing DDoS protection for applicable networks serving a public Application Gateway, or no passing assessment exists. | AuditIfNotExists |
| Microsoft Defender for SQL should be enabled for unprotected Synapse workspaces · JSON · Docs | the workspace lacks an enabled SQL security alert policy for detecting suspicious database activity. | AuditIfNotExists |
| Azure Defender for SQL should be enabled for unprotected PostgreSQL flexible servers · JSON · Docs | the flexible server lacks an enabled advanced threat protection setting for detecting suspicious database activity. | AuditIfNotExists |
| Azure Defender for SQL should be enabled for unprotected MySQL flexible servers · JSON · Docs | the flexible server lacks an enabled advanced threat protection setting for detecting suspicious database activity. | AuditIfNotExists |
| SQL server-targeted autoprovisioning should be enabled for SQL servers on machines plan · JSON · Docs | the Standard SQL-on-machines plan lacks an expected monitoring-setup policy assignment; successful agent installation is not checked. | AuditIfNotExists |
| Microsoft Defender for APIs should be enabled · JSON · Docs | the subscription lacks the Standard Defender for APIs plan. | AuditIfNotExists |
| Role-Based Access Control (RBAC) should be used on Kubernetes Services · JSON · Docs | the cluster explicitly turns off role-based permissions, which limit the actions each user can perform. | Audit |
| Authorized IP ranges should be defined on Kubernetes Services · JSON · Docs | the authorized-IP-ranges setting is missing from a non-private cluster's management interface; private clusters are excluded. | Audit |
| Management ports should be closed on your virtual machines · JSON · Docs | Defender reports administration ports exposed to the Internet, or no passing assessment exists for the machine. | AuditIfNotExists |
| IP Forwarding on your virtual machine should be disabled · JSON · Docs | Defender reports IP forwarding enabled, allowing traffic for other destinations, or no passing assessment exists. | AuditIfNotExists |
| Azure Defender for Key Vault should be enabled · JSON · Docs | the subscription lacks the Standard Defender for Key Vault plan. | AuditIfNotExists |
| Azure Defender for Azure SQL Database servers should be enabled · JSON · Docs | the subscription lacks the Standard Defender for SQL Databases plan; server alert settings are checked separately. | AuditIfNotExists |
| Azure Defender for SQL servers on machines should be enabled · JSON · Docs | the subscription lacks the Standard Defender plan for SQL Server on machines. | AuditIfNotExists |
| Azure Defender for App Service should be enabled · JSON · Docs | the subscription lacks the Standard Defender for App Service plan. | AuditIfNotExists |
| Microsoft Defender for Containers should be enabled · JSON · Docs | the subscription lacks the Standard Defender for Containers plan. | AuditIfNotExists |
| Azure Defender for servers should be enabled · JSON · Docs | the subscription lacks the Standard Defender for Servers plan. | AuditIfNotExists |
| Azure registry container images should have vulnerabilities resolved (powered by Microsoft Defender Vulnerability Management) · JSON · Docs | Defender reports unresolved vulnerabilities in registry images, or no passing assessment exists for those images. | AuditIfNotExists |
| Azure running container images should have vulnerabilities resolved (powered by Microsoft Defender Vulnerability Management) · JSON · Docs | Defender reports unresolved vulnerabilities in images running on the cluster, or no passing assessment exists. | AuditIfNotExists |
| Subscriptions should have a contact email address for security issues · JSON · Docs | the subscription lacks a security-contact record with an email address. The rule does not test email delivery. | AuditIfNotExists |
| Email notification for high severity alerts should be enabled · JSON · Docs | no security-contact record enables alert emails in a supported format. The rule does not verify the severity threshold. | AuditIfNotExists |
| Email notification to subscription owner for high severity alerts should be enabled · JSON · Docs | no contact passes the legacy check, which rejects administrator emails off combined with a High-only alert threshold. | AuditIfNotExists |
| Azure Defender for Resource Manager should be enabled · JSON · Docs | the subscription lacks the Standard Defender plan for detecting suspicious operations that create, change or delete Azure resources. | AuditIfNotExists |
| [Preview]: vTPM should be enabled on supported virtual machines · JSON · Docs | a supported Trusted Launch machine lacks an enabled virtual TPM, the security device used to record and verify startup. | Audit |
| [Preview]: Secure Boot should be enabled on supported Windows virtual machines · JSON · Docs | Secure Boot is off on a supported Windows Trusted Launch or Confidential machine, allowing startup without this signature check. | Audit |
| [Preview]: Guest Attestation extension should be installed on supported Linux virtual machines · JSON · Docs | a supported secure Linux machine lacks a successfully installed Guest Attestation extension, which reports evidence about startup integrity. | AuditIfNotExists |
| [Preview]: Guest Attestation extension should be installed on supported Linux virtual machines scale sets · JSON · Docs | a supported secure Linux scale set lacks its Guest Attestation extension. Installation presence, not startup results, is checked. | AuditIfNotExists |
| [Preview]: Guest Attestation extension should be installed on supported Windows virtual machines · JSON · Docs | a supported secure Windows machine lacks a successfully installed Guest Attestation extension, which reports evidence about startup integrity. | AuditIfNotExists |
| [Preview]: Guest Attestation extension should be installed on supported Windows virtual machines scale sets · JSON · Docs | a supported secure Windows scale set lacks its Guest Attestation extension. Installation presence, not startup results, is checked. | AuditIfNotExists |
| [Preview]: Linux virtual machines should use only signed and trusted boot components · JSON · Docs | Defender's assessment of trusted startup files is missing or reports a problem. A NotApplicable assessment also passes. | AuditIfNotExists |
| Azure Defender for open-source relational databases should be enabled · JSON · Docs | the subscription lacks the Standard Defender plan covering threat detection for supported MySQL, PostgreSQL and MariaDB databases. | AuditIfNotExists |
| Microsoft Defender CSPM should be enabled · JSON · Docs | the subscription lacks the Standard Defender CSPM plan, which adds deeper security analysis beyond the free foundational checks. | AuditIfNotExists |
| Machines should have secret findings resolved · JSON · Docs | Defender's assessment of exposed passwords, keys or tokens is missing or reports a problem. NotApplicable results pass. | AuditIfNotExists |
| API endpoints that are unused should be disabled and removed from the Azure API Management service · JSON · Docs | Defender's assessment of endpoints unused for 30 days is missing or reports a problem. It does not delete endpoints. | AuditIfNotExists |
| API endpoints in Azure API Management should be authenticated · JSON · Docs | Defender's endpoint-authentication assessment is missing or reports a problem. It relies on Defender's findings rather than inspecting every authentication setting. | AuditIfNotExists |
| Microsoft Defender for Storage should be enabled · JSON · Docs | the newer Defender for Storage plan is missing, or upload malware scanning or sensitive-data discovery is not enabled. | AuditIfNotExists |
Key Vault and access to secrets (9)
| Policy / sources | Flagged when… | Saved default effect |
|---|---|---|
| Certificates should have the specified maximum validity period · JSON · Docs | a certificate stays valid beyond the configured maximum, which defaults to 12 months. | Disabled |
| Key Vault secrets should have an expiration date · JSON · Docs | a secret has no recorded expiry date; this does not check whether its stored password was changed. | Disabled |
| Key Vault keys should have an expiration date · JSON · Docs | an encryption key has no recorded expiry date; automatic key replacement is not checked. | Disabled |
| Resource logs in Key Vault should be enabled · JSON · Docs | logging is missing or off, or applicable retention is below one day; unlimited retention also passes. | AuditIfNotExists |
| Key vaults should have deletion protection enabled · JSON · Docs | required soft-delete or purge-protection settings are missing or disabled. Vault recovery requests are excluded. | Audit |
| Key vaults should have soft delete enabled · JSON · Docs | soft delete is missing or disabled, so deleted vaults lack recovery protection. Purge protection is checked separately. | Audit |
| Azure Key Vault should have firewall enabled or public network access disabled · JSON · Docs | public access remains enabled and the firewall does not block connections by default. Either restriction satisfies this rule. | Audit |
| Azure Key Vaults should use private link · JSON · Docs | no approved private endpoint exists for the vault. Public internet access is a separate setting. | Audit |
| Azure Key Vault should use RBAC permission model · JSON · Docs | the vault does not use Azure role-based permissions instead of older access policies. Vault recovery requests are excluded. | Audit |
Servers and hybrid infrastructure (18)
| Policy / sources | Flagged when… | Saved default effect |
|---|---|---|
| Windows Defender Exploit Guard should be enabled on your machines · JSON · Docs | the machine's configuration assessment is missing or fails the Windows Defender Exploit Guard protection requirements. | AuditIfNotExists |
| Windows machines should meet requirements of the Azure compute security baseline · Explained · JSON · Docs | the machine's configuration assessment is missing or fails Azure's recommended Windows security settings. | AuditIfNotExists |
| Linux machines should meet requirements for the Azure compute security baseline · JSON · Docs | the machine's configuration assessment is missing or fails Azure's recommended Linux security settings. | AuditIfNotExists |
| Service Fabric clusters should have the ClusterProtectionLevel property set to EncryptAndSign · JSON · Docs | cluster messages are not configured to be both encrypted and signed to detect tampering. | Audit |
| Service Fabric clusters should only use Azure Active Directory for client authentication · JSON · Docs | no Microsoft Entra tenant is configured for client sign-in; alternative sign-in methods are not checked. | Audit |
| Virtual machines should be migrated to new Azure Resource Manager resources · JSON · Docs | a virtual machine still uses Azure's older classic resource type instead of Azure Resource Manager. | Audit |
| Machines should be configured to periodically check for missing system updates · JSON · Docs | automatic daily checks for missing updates are not configured; this setting does not install updates. | Audit |
| Azure Backup should be enabled for Virtual Machines · JSON · Docs | no Azure Backup protection record exists for an applicable machine; successful recent backups are not checked. | AuditIfNotExists |
| VM Image Builder templates should use private link · JSON · Docs | the image-building template lacks virtual-network settings. Despite its official title, this rule does not check private endpoints directly. | Audit |
| Authentication to Linux machines should require SSH keys · JSON · Docs | the machine's assessment does not confirm password-free SSH sign-in. Supported servers connected through Azure Arc are included. | AuditIfNotExists |
| Windows machines should be configured to use secure communication protocols · JSON · Docs | the machine lacks a passing assessment for TLS 1.2 or newer connection encryption. Supported Azure Arc servers are included. | AuditIfNotExists |
| Linux virtual machines should enable Azure Disk Encryption or EncryptionAtHost. · JSON · Docs | a supported machine lacks a passing encryption assessment accepting either Azure Disk Encryption or encryption at host. | AuditIfNotExists |
| Windows virtual machines should enable Azure Disk Encryption or EncryptionAtHost. · JSON · Docs | a supported machine lacks a passing encryption assessment accepting either Azure Disk Encryption or encryption at host. | AuditIfNotExists |
| Virtual machines and virtual machine scale sets should have encryption at host enabled · JSON · Docs | encryption at host is not enabled. This setting protects temporary disks and operating-system and data-disk caches. | Audit |
| [Preview]: Azure Stack HCI servers should meet Secured-core requirements · JSON · Docs | the supported cluster lacks a Secured-core status of Compliant or Pending. A pending assessment is accepted. | AuditIfNotExists |
| [Preview]: Azure Stack HCI servers should have consistently enforced application control policies · JSON · Docs | the cluster's application-control status is neither Compliant nor Pending, or missing. Pending does not prove enforcement has been verified. | AuditIfNotExists |
| [Preview]: Azure Stack HCI systems should have encrypted volumes · JSON · Docs | the cluster's disk-encryption status is neither Compliant nor Pending, or missing. Pending does not prove encryption has been verified. | AuditIfNotExists |
| [Preview]: Host and VM networking should be protected on Azure Stack HCI systems · JSON · Docs | the cluster's network-protection status is neither Compliant nor Pending, or missing. Pending does not prove protection has been verified. | AuditIfNotExists |
Containers and Kubernetes (24)
| Policy / sources | Flagged when… | Saved default effect |
|---|---|---|
| Azure Policy Add-on for Kubernetes service (AKS) should be installed and enabled on your clusters · JSON · Docs | the Azure Policy add-on is missing or disabled, preventing its workload checks inside the cluster. | Audit |
| Azure Arc enabled Kubernetes clusters should have the Azure Policy extension installed · JSON · Docs | an applicable Arc-connected cluster lacks a successfully installed Azure Policy extension for workload checks. | AuditIfNotExists |
| Kubernetes cluster containers should only use allowed images · JSON · Docs | an image name fails the allowed-name pattern; the default pattern matches no normal image names. | Audit |
| Kubernetes cluster should not allow privileged containers · JSON · Docs | a container requests privileged mode, granting broad access to the machine hosting it. | Audit |
| Kubernetes cluster services should listen only on allowed ports · JSON · Docs | a service exposes a port outside the allowed list; the default -1 permits no valid service ports. | Audit |
| Kubernetes cluster containers CPU and memory resource limits should not exceed the specified limits · JSON · Docs | resource limits are missing or exceed the defaults: 32 CPU units or 64 GiB of memory per container. | Audit |
| Kubernetes cluster pods and containers should only run with approved user and group IDs · JSON · Docs | a container lacks a non-root user or primary group above 0, or declares other group IDs below 1. | Audit |
| [Preview]: Azure Arc enabled Kubernetes clusters should have Microsoft Defender for Cloud extension installed · JSON · Docs | an applicable cluster lacks a successfully installed Defender extension; AKS, EKS, GKE, and other listed distributions are excluded. | AuditIfNotExists |
| Azure Kubernetes Service clusters should have Defender profile enabled · JSON · Docs | the cluster's Defender security monitoring profile is not enabled to collect security event data. | Audit |
| Kubernetes clusters should not allow container privilege escalation · JSON · Docs | a container can let running programs gain extra permissions, such as becoming the root administrator. | Audit |
| Kubernetes cluster containers should not share host process ID or host IPC namespace · JSON · Docs | a container shares the host machine's process list or communication area instead of keeping those areas separate. | Audit |
| Kubernetes cluster containers should run with a read only root file system · JSON · Docs | the container's main filesystem is writable; separately configured writable storage volumes are still allowed. | Audit |
| Kubernetes cluster containers should only use allowed capabilities · JSON · Docs | a container adds unapproved Linux administrative privileges; the default allowed-capability list is empty. | Audit |
| Kubernetes cluster containers should only use allowed AppArmor profiles · JSON · Docs | a container uses an unapproved AppArmor security profile; the default approved profile is runtime/default. | Audit |
| Kubernetes cluster pods should only use approved host network and port range · JSON · Docs | a workload uses the host network or ordinary host ports; the defaults permit neither. | Audit |
| Kubernetes cluster pod hostPath volumes should only use allowed host paths · JSON · Docs | a container mounts an unapproved host folder; the default approved-folder list is empty. | Audit |
| Container registries should be encrypted with a customer-managed key · JSON · Docs | the registry does not enable encryption using a key you control. Microsoft's default encryption keys do not qualify. | Disabled |
| Container registries should not allow unrestricted network access · JSON · Docs | public access is enabled without network rules that block connections by default. Either restriction satisfies this rule. | Audit |
| Container registries should use private link · JSON · Docs | no approved private endpoint exists for the registry. Public internet access is a separate setting. | Audit |
| Kubernetes clusters should be accessible only over HTTPS · JSON · Docs | application entry-point settings allow unencrypted web traffic. This checks Kubernetes Ingress settings, not every cluster connection. | Audit |
| Kubernetes clusters should not use the default namespace · JSON · Docs | Pods, Services or ServiceAccounts use the default namespace, the shared area used when no separate namespace is specified. | Audit |
| Kubernetes clusters should disable automounting API credentials · JSON · Docs | application Pods automatically receive service-account tokens, credentials that can allow calls to the cluster's management interface. | Audit |
| Kubernetes clusters should not grant CAP_SYS_ADMIN security capabilities · JSON · Docs | containers request SYS_ADMIN, a broad Linux administrative privilege. | Audit |
| Resource logs in Azure Kubernetes Service should be enabled · JSON · Docs | no enabled log entry meets the rule. Applicable Storage retention must be unlimited or at least one day. | AuditIfNotExists |
Web apps and API Management (26)
| Policy / sources | Flagged when… | Saved default effect |
|---|---|---|
| Resource logs in Logic Apps should be enabled · JSON · Docs | logging is missing or off, or its applicable retention setting falls below the one-day default requirement. | AuditIfNotExists |
| Function apps should have remote debugging turned off · JSON · Docs | the app's configuration does not show remote debugging turned off, leaving development-tool access potentially available. | AuditIfNotExists |
| App Service apps should have remote debugging turned off · JSON · Docs | the app's configuration does not show remote debugging turned off, leaving development-tool access potentially available. | AuditIfNotExists |
| Function apps should only be accessible over HTTPS · JSON · Docs | the HTTPS-only setting is missing or off, allowing web traffic without an encrypted connection. | Audit |
| App Service apps should only be accessible over HTTPS · JSON · Docs | the HTTPS-only setting is missing or off, allowing web traffic without an encrypted connection. | Audit |
| Function apps should not have CORS configured to allow every resource to access your apps · JSON · Docs | cross-origin settings allow any website to read the app's responses in a browser, or no qualifying configuration exists. | AuditIfNotExists |
| App Service apps should not have CORS configured to allow every resource to access your apps · JSON · Docs | cross-origin settings allow any website to read the app's responses in a browser, or no qualifying configuration exists. | AuditIfNotExists |
| Function apps should use managed identity · JSON · Docs | the app's configuration lacks an Azure-managed identity for signing into supported services without stored passwords. | AuditIfNotExists |
| App Service apps should use managed identity · JSON · Docs | the app's configuration lacks an Azure-managed identity for signing into supported services without stored passwords. | AuditIfNotExists |
| App Service apps should have resource logs enabled · JSON · Docs | logging is missing or off, or applicable retention is below 365 days; unlimited retention also passes. | AuditIfNotExists |
| App Service apps should use the latest TLS version · JSON · Docs | minimum TLS is missing or below 1.2; the rule does not require the newest available version. | AuditIfNotExists |
| Function apps should use the latest TLS version · JSON · Docs | minimum TLS is missing or below 1.2; the rule does not require the newest available version. | AuditIfNotExists |
| Function apps should require FTPS only · JSON · Docs | file-transfer settings allow unencrypted FTP or are missing; encrypted FTPS only or disabled FTP both pass. | AuditIfNotExists |
| App Service apps should require FTPS only · JSON · Docs | file-transfer settings are missing or allow unencrypted FTP; encrypted FTPS only or disabled FTP both pass. | AuditIfNotExists |
| App Configuration should use private link · JSON · Docs | no approved private endpoint exists for the configuration store. Public internet access is a separate setting. | AuditIfNotExists |
| Azure SignalR Service should use private link · JSON · Docs | no approved private endpoint exists for the messaging service. Public internet access is a separate setting. | Audit |
| Azure Spring Cloud should use network injection · JSON · Docs | a Standard or Enterprise Spring instance lacks a service-runtime subnet connecting it to your virtual network. | Audit |
| API Management services should use a virtual network · JSON · Docs | a Developer or Premium API Management service lacks virtual-network settings. Both internal and internet-facing network modes qualify. | Audit |
| API Management subscriptions should not be scoped to all APIs · JSON · Docs | an active API-consumer subscription key grants access to all APIs, rather than one API or a selected product. | Audit |
| API Management calls to API backends should not bypass certificate thumbprint or name validation · JSON · Docs | backend settings disable either certificate trust or server-name verification, weakening checks that the gateway reached the intended server. | Audit |
| API Management APIs should use only encrypted protocols · JSON · Docs | an API allows unencrypted HTTP or WebSocket connections. HTTPS and secure WebSocket connections satisfy the encryption requirement. | Audit |
| API Management secret named values should be stored in Azure Key Vault · JSON · Docs | a reusable configuration value marked secret lacks a Key Vault reference. Secrets stored directly in API Management do not qualify. | Audit |
| API Management direct management endpoint should not be enabled · JSON · Docs | direct management access is enabled, providing an administrative route outside Azure Resource Manager's normal permission controls. | Audit |
| API Management should disable public network access to the service configuration endpoints · JSON · Docs | the selected configuration endpoint, currently Management, is not disabled. Consumption-tier services are excluded from this check. | AuditIfNotExists |
| API Management calls to API backends should be authenticated · JSON · Docs | an HTTP-type backend has neither a certificate nor authorization credentials. Authentication in API policies may not be recognized. | Audit |
| Azure API Management platform version should be stv2 · JSON · Docs | API Management still reports the retired stv1 hosting platform. The policy identifies services needing platform migration. | Audit |
Databases and caches (44)
| Policy / sources | Flagged when… | Saved default effect |
|---|---|---|
| An Azure Active Directory administrator should be provisioned for SQL servers · JSON · Docs | the server lacks a Microsoft Entra administrator; this does not require other sign-in methods to be disabled. | AuditIfNotExists |
| Only secure connections to your Azure Cache for Redis should be enabled · JSON · Docs | the port allowing unencrypted connections is enabled, rather than accepting only encrypted Redis connections. | Audit |
| Transparent Data Encryption on SQL databases should be enabled · JSON · Docs | database encryption is missing or disabled; the system database named master is excluded. | AuditIfNotExists |
| Auditing on SQL server should be enabled · JSON · Docs | the server's audit setting is missing or fails the required value, which defaults to enabled. | AuditIfNotExists |
| Azure Defender for SQL should be enabled for unprotected Azure SQL servers · JSON · Docs | the server's security alert policy is missing or disabled; subscription-level Defender plan settings are checked separately. | AuditIfNotExists |
| Azure Defender for SQL should be enabled for unprotected SQL Managed Instances · JSON · Docs | the managed instance lacks an enabled security alert policy for detecting suspicious database activity. | AuditIfNotExists |
| Vulnerability assessment should be enabled on your SQL servers · JSON · Docs | no expected assessment record exists under the server's databases; scan success and resolved findings are not checked. | AuditIfNotExists |
| Vulnerability assessment should be enabled on SQL Managed Instance · JSON · Docs | no expected assessment record exists under the instance's databases; scan success and resolved findings are not checked. | AuditIfNotExists |
| SQL servers should use customer-managed keys to encrypt data at rest · JSON · Docs | encryption does not reference a key you manage in Key Vault; Synapse-managed resource groups are excluded. | Disabled |
| SQL managed instances should use customer-managed keys to encrypt data at rest · JSON · Docs | encryption does not reference a key you manage in Key Vault instead of Microsoft's default key. | Disabled |
| Geo-redundant backup should be enabled for Azure Database for MariaDB · JSON · Docs | the server's setting for copying backups to another region is missing or disabled. | Audit |
| Geo-redundant backup should be enabled for Azure Database for PostgreSQL · JSON · Docs | backup replication to another region is not enabled on the older server resource type; flexible servers are excluded. | Audit |
| Geo-redundant backup should be enabled for Azure Database for MySQL · JSON · Docs | backup replication to another region is not enabled on the older server resource type; flexible servers are excluded. | Audit |
| Enforce SSL connection should be enabled for PostgreSQL database servers · JSON · Docs | the older server's existing SSL enforcement setting is not enabled; flexible servers are excluded. | Audit |
| Enforce SSL connection should be enabled for MySQL database servers · JSON · Docs | the older server's existing SSL enforcement setting is not enabled; flexible servers are excluded. | Audit |
| Private endpoint should be enabled for PostgreSQL servers · JSON · Docs | the older server lacks an approved private endpoint; public access being disabled is not checked, and flexible servers are excluded. | AuditIfNotExists |
| Private endpoint should be enabled for MariaDB servers · JSON · Docs | the server lacks an approved private endpoint; public access being disabled is not checked. | AuditIfNotExists |
| Private endpoint should be enabled for MySQL servers · JSON · Docs | the older server lacks an approved private endpoint; public access being disabled is not checked, and flexible servers are excluded. | AuditIfNotExists |
| SQL servers with auditing to storage account destination should be configured with 90 days retention or higher · JSON · Docs | storage audit settings are missing or retain logs for under 90 days; unlimited retention and Azure Monitor-only destinations also pass. | AuditIfNotExists |
| Azure Cosmos DB accounts should use customer-managed keys to encrypt data at rest · JSON · Docs | the account lacks a reference to your Key Vault encryption key. Microsoft's default encryption keys do not qualify. | Disabled |
| Cosmos DB database accounts should have local authentication methods disabled · JSON · Docs | account-key sign-in remains enabled instead of requiring Microsoft Entra identities. MongoDB, Cassandra and Gremlin accounts are excluded. | Audit |
| Azure Cache for Redis should use private link · JSON · Docs | no approved private endpoint exists for the cache. This rule does not require public access to be disabled. | AuditIfNotExists |
| Public network access should be disabled for MariaDB servers · JSON · Docs | public network access is not disabled; private connectivity is not verified. | Audit |
| Public network access should be disabled for MySQL servers · JSON · Docs | public network access is not disabled on an older MySQL server. Flexible servers are outside this check. | Audit |
| MySQL servers should use customer-managed keys to encrypt data at rest · JSON · Docs | an older server lacks a nonempty reference to a Key Vault encryption key. Flexible servers are excluded. | Disabled |
| Public network access should be disabled for PostgreSQL servers · JSON · Docs | public network access is not disabled on an older PostgreSQL server. Flexible servers are outside this check. | Audit |
| PostgreSQL servers should use customer-managed keys to encrypt data at rest · JSON · Docs | an older server lacks a nonempty reference to a Key Vault encryption key. Flexible servers are excluded. | Disabled |
| Private endpoint connections on Azure SQL Database should be enabled · JSON · Docs | no approved private endpoint exists for the SQL server. Public internet access is a separate setting. | Audit |
| Public network access on Azure SQL Database should be disabled · JSON · Docs | public network access is not disabled on the SQL server. This does not test private connectivity. | Audit |
| Azure Cosmos DB accounts should have firewall rules · JSON · Docs | public access is enabled without any recognized restriction: virtual-network filtering, IP rules, or an approved private endpoint. | Audit |
| Azure SQL logical servers should have Microsoft Entra-only authentication enabled during creation · JSON · Docs | server creation settings do not require Microsoft Entra-only sign-in. Later changes to the authentication setting are checked separately. | Audit |
| Azure SQL Database should have Microsoft Entra-only authentication enabled · JSON · Docs | the separate authentication setting does not require Microsoft Entra-only sign-in. The initial server creation request is checked separately. | Audit |
| A Microsoft Entra administrator should be provisioned for MySQL servers · JSON · Docs | an older MySQL server lacks a Microsoft Entra administrator. This does not require local password sign-in to be disabled. | AuditIfNotExists |
| A Microsoft Entra administrator should be provisioned for PostgreSQL servers · JSON · Docs | an older PostgreSQL server lacks a Microsoft Entra administrator. This does not require local password sign-in to be disabled. | AuditIfNotExists |
| Azure SQL Managed Instances should have Microsoft Entra-only authentication enabled during creation · JSON · Docs | instance creation settings do not require Microsoft Entra-only sign-in. Later changes to the authentication setting are checked separately. | Audit |
| Azure SQL Managed Instance should have Microsoft Entra-only authentication enabled · JSON · Docs | the separate authentication setting does not require Microsoft Entra-only sign-in. The initial instance creation request is checked separately. | Audit |
| Synapse Workspaces should use only Microsoft Entra identities for authentication during workspace creation · JSON · Docs | workspace creation settings do not consistently require Microsoft Entra-only sign-in. Later changes to the authentication setting are checked separately. | Audit |
| Synapse Workspaces should have Microsoft Entra-only authentication enabled · JSON · Docs | the separate authentication setting does not require Microsoft Entra-only sign-in. The initial workspace creation request is checked separately. | Audit |
| Azure MySQL flexible server should have Microsoft Entra Only Authentication enabled · JSON · Docs | Microsoft Entra-only sign-in is not enabled, which is the server setting that excludes local password authentication. | AuditIfNotExists |
| Azure Cosmos DB should disable public network access · JSON · Docs | public network access is not disabled; private connectivity is not verified. | Audit |
| CosmosDB accounts should use private link · JSON · Docs | no approved private endpoint exists for the database account. Public internet access is a separate setting. | Audit |
| Azure SQL Database should be running TLS version 1.2 or newer · JSON · Docs | the minimum allowed connection-encryption version is missing or below TLS 1.2. Older versions do not satisfy this rule. | Audit |
| Azure SQL Managed Instances should disable public network access · JSON · Docs | the instance's public database endpoint is enabled. Private-network access is not tested. | Audit |
| [Preview]: Azure PostgreSQL flexible server should have Microsoft Entra Only Authentication enabled · JSON · Docs | Microsoft Entra authentication is not enabled or password authentication is not disabled. Both settings must meet the requirement. | Audit |
Storage and data lakes (18)
| Policy / sources | Flagged when… | Saved default effect |
|---|---|---|
| Storage accounts should restrict network access · JSON · Docs | network rules allow connections by default instead of requiring an allowed rule or configured exception. | Disabled |
| Storage accounts should restrict network access (excluding storage accounts managed by Azure Red Hat OpenShift) · JSON · Docs | network rules allow connections by default; storage in resource groups managed by Azure Red Hat OpenShift is excluded. | Disabled |
| Secure transfer to storage accounts should be enabled · JSON · Docs | secure transfer is disabled or missing where required, allowing supported storage connections without encryption. | Audit |
| Resource logs in Azure Data Lake Store should be enabled · JSON · Docs | logging is missing or off, or applicable retention is below one day; unlimited retention also passes. | AuditIfNotExists |
| Resource logs in Data Lake Analytics should be enabled · JSON · Docs | logging is missing or off, or applicable retention is below one day; unlimited retention also passes. | AuditIfNotExists |
| Storage accounts should be migrated to new Azure Resource Manager resources · JSON · Docs | an account still uses Azure's older classic resource type instead of Azure Resource Manager. | Audit |
| Storage account public access should be disallowed · JSON · Docs | the account does not explicitly disable anonymous blob access; public network access is separate, and selected OpenShift accounts are excluded. | Audit |
| Storage accounts should use customer-managed key for encryption · JSON · Docs | storage encryption does not use a key you control in Key Vault. Microsoft's default encryption keys do not qualify. | Disabled |
| Storage accounts should use customer-managed key for encryption (excluding storage accounts managed by Azure Red Hat OpenShift) · JSON · Docs | storage encryption does not use your Key Vault key, excluding storage in resource groups managed by Azure Red Hat OpenShift. | Disabled |
| Storage accounts should restrict network access using virtual network rules · JSON · Docs | the firewall allows access by default or allows public IP exceptions. No actual virtual-network rule is required. | Audit |
| Storage accounts should restrict network access using virtual network rules (excluding storage accounts managed by ARO) · JSON · Docs | the firewall allows access by default or public IP exceptions, excluding storage managed by Azure Red Hat OpenShift. | Audit |
| Storage accounts should restrict network access using virtual network rules (excluding storage accounts created by Databricks) · JSON · Docs | the firewall allows access by default or public IP exceptions, excluding storage in resource groups managed by Databricks. | Audit |
| Storage accounts should use private link · JSON · Docs | no approved storage private endpoint exists. Public access and coverage of every storage service are not checked. | AuditIfNotExists |
| Storage accounts should use private link (excluding storage accounts managed by Azure Red Hat OpenShift) · JSON · Docs | no approved private endpoint exists, excluding storage managed by Azure Red Hat OpenShift. Public access is checked separately. | AuditIfNotExists |
| Storage accounts should use private link (excluding storage accounts created by Databricks) · JSON · Docs | no approved private endpoint exists, excluding storage in Databricks-managed resource groups. Public access is checked separately. | AuditIfNotExists |
| Storage accounts should prevent shared key access · JSON · Docs | storage-account key access is not disabled. Supported identity-based authorization avoids depending on a shared account key. | Audit |
| Storage accounts should prevent shared key access (excluding storage accounts managed by Azure Red Hat OpenShift) · JSON · Docs | shared account-key access is not disabled, excluding storage in resource groups managed by Azure Red Hat OpenShift. | Audit |
| Storage accounts should prevent shared key access (excluding storage accounts created by Databricks) · JSON · Docs | shared account-key access is not disabled, excluding storage in resource groups managed by Azure Databricks. | Audit |
AI and analytics (19)
| Policy / sources | Flagged when… | Saved default effect |
|---|---|---|
| Resource logs in Azure Stream Analytics should be enabled · JSON · Docs | logging is missing or off, or applicable retention is below one day; unlimited retention also passes. | AuditIfNotExists |
| Resource logs in Search services should be enabled · JSON · Docs | logging is missing or off, or applicable retention is below one day; unlimited retention also passes. | AuditIfNotExists |
| Azure AI Services resources should encrypt data at rest with a customer-managed key (CMK) · JSON · Docs | supported AI accounts do not use encryption keys you control in Key Vault. Several account types are excluded. | Disabled |
| Azure Machine Learning workspaces should be encrypted with a customer-managed key · JSON · Docs | workspace encryption does not use a key you control. Resources marked as projects are excluded. | Disabled |
| Azure Machine Learning workspaces should use private link · JSON · Docs | no approved private endpoint exists for the workspace. Public internet access is a separate setting. | Audit |
| Azure AI Services resources should restrict network access · JSON · Docs | public access remains unrestricted: AI accounts need a default-block firewall; AI Search needs IP restrictions. Disabling public access also passes. | Audit |
| Diagnostic logs in Azure AI services resources should be enabled · JSON · Docs | no diagnostic setting contains log entries. The rule does not require those entries to be enabled or successfully collected. | AuditIfNotExists |
| Azure AI Services resources should use Azure Private Link · JSON · Docs | no approved private endpoint exists for the AI account or AI Search service. Public access is checked separately. | Audit |
| Resource logs in Azure Machine Learning Workspaces should be enabled · JSON · Docs | no enabled log entry meets the rule. Applicable Storage retention must be unlimited or at least 365 days. | AuditIfNotExists |
| Azure Machine Learning Workspaces should disable public network access · JSON · Docs | public network access is not explicitly disabled; private connectivity is not verified. | Audit |
| Azure Machine Learning Computes should be in a virtual network · JSON · Docs | a compute cluster or instance lacks a virtual-network subnet reference. The rule does not inspect public IP settings. | Audit |
| Azure Machine Learning Computes should have local authentication methods disabled · JSON · Docs | local authentication remains enabled on compute clusters or instances instead of requiring supported Microsoft Entra sign-in. | Audit |
| Azure Machine Learning compute instances should be recreated to get the latest software updates · JSON · Docs | a compute instance reports an outdated operating-system image. Recreating it with a current image is the recommended fix. | Audit |
| Resource logs in Azure Databricks Workspaces should be enabled · JSON · Docs | no enabled log entry meets the rule. Applicable Storage retention must be unlimited or at least 365 days. | AuditIfNotExists |
| Azure Databricks Workspaces should disable public network access · JSON · Docs | public network access is not disabled on the workspace. Private endpoints and cluster public IPs are separate checks. | Audit |
| Azure Databricks Clusters should disable public IP · JSON · Docs | the workspace's no-public-IP setting for cluster machines is not enabled. Public access to the workspace interface is separate. | Audit |
| Azure Databricks Workspaces should be in a virtual network · JSON · Docs | the workspace lacks its own virtual-network reference or either required subnet reference. Detailed firewall rules are not inspected. | Audit |
| Azure Databricks Workspaces should use private link · JSON · Docs | no approved private endpoint exists for the workspace. Public internet access is a separate setting. | Audit |
| Azure AI Services resources should have key access disabled (disable local authentication) · JSON · Docs | AI accounts or AI Search still allow local API keys instead of requiring supported Microsoft Entra authentication. | Audit |
Network protection (5)
| Policy / sources | Flagged when… | Saved default effect |
|---|---|---|
| [Preview]: All Internet traffic should be routed via your deployed Azure Firewall · JSON · Docs | a qualifying subnet has at least two IP configurations and no route table, but its network lacks the expected Azure Firewall; actual traffic routing is not verified. | AuditIfNotExists |
| Azure Web Application Firewall should be enabled for Azure Front Door entry-points · JSON · Docs | Front Door classic lacks linked web firewall protection. The rule checks policy links, not whether attack blocking is enabled. | Audit |
| Web Application Firewall (WAF) should be enabled for Application Gateway · JSON · Docs | neither a web firewall configuration nor a linked policy exists. It does not verify the firewall is enabled. | Audit |
| Network Watcher should be enabled · JSON · Docs | a virtual network's region lacks a Network Watcher in NetworkWatcherRG. Individual monitoring features are not checked. | AuditIfNotExists |
| VPN gateways should use only Azure Active Directory (Azure AD) authentication for point-to-site users · JSON · Docs | a configured remote-user VPN allows an authentication method other than Microsoft Entra. This does not prove Entra is correctly configured. | Audit |
Messaging and connected devices (5)
| Policy / sources | Flagged when… | Saved default effect |
|---|---|---|
| Resource logs in IoT Hub should be enabled · JSON · Docs | logging is missing or off, or applicable retention is below one day; unlimited retention also passes. | AuditIfNotExists |
| Resource logs in Service Bus should be enabled · JSON · Docs | logging is missing or off, or applicable retention is below one day; unlimited retention also passes. | AuditIfNotExists |
| Resource logs in Event Hub should be enabled · JSON · Docs | logging is missing or off, or applicable retention is below one day; unlimited retention also passes. | AuditIfNotExists |
| Azure Event Grid domains should use private link · JSON · Docs | no approved private endpoint exists for the event domain. Public internet access is a separate setting. | Audit |
| Azure Event Grid topics should use private link · JSON · Docs | no approved private endpoint exists for the event topic. Topics connected through Azure Arc are excluded. | Audit |
Automation and other resources (3)
| Policy / sources | Flagged when… | Saved default effect |
|---|---|---|
| Audit usage of custom RBAC roles · JSON · Docs | a custom permission-role definition exists, even if nobody uses it; built-in roles are excluded. | Audit |
| Resource logs in Batch accounts should be enabled · JSON · Docs | logging is missing or off, or applicable retention is below one day; unlimited retention also passes. | AuditIfNotExists |
| Automation account variables should be encrypted · JSON · Docs | a reusable variable stored in Azure Automation does not have its encryption setting enabled. | Audit |
Source and version details
Recorded as 57.59.0 on 5 September 2026; exact membership is unverified. The available initiative JSON is 57.58.0 / 226 entries, so it does not match this saved list.
Initiative JSON lists policy references and parameters. Each row's JSON links to its rule. Effects are saved defaults, not live results.
References
- Original saved 224-row reference
- Microsoft's current policy reference
- Assignment settings and versioning
Upcoming change: from 27 October 2026, new subscriptions must opt in to Foundational CSPM. Already-enabled subscriptions stay enabled. Microsoft notice