← All articles

ASC Default, simply

A security checklist assigned in Azure Policy, with a saved policy-by-policy reference.

  1. Your subscriptionResources in this subscription
  2. ASC DefaultMicrosoft cloud security benchmark
  3. Policy complianceAssignment compliance view
  4. Defender for CloudRelated, not the same list
Illustrative checks, not live Azure activity. Reports gaps; does not fix settings. Paid Defender plans are separate.

ASC means Azure Security Center, now called Microsoft Defender for Cloud.

ASC Default is an Azure Policy initiative assignment: it applies a bundle of security checks to a scope, such as your subscription.

See its results in Azure portal → Policy → Compliance → ASC Default. You do not need to open Defender for Cloud to view assignment compliance. Defender has related security recommendations; the two views can differ. Microsoft: viewing compliance

For one shared assignment across subscriptions, see MCSB managed centrally, simply.

Saved policy reference

224 saved policies. Open a group for details and JSON.

Defender and cross-service checks (53)

Policy / sources Flagged when… Saved default effect
Guest Configuration extension should be installed on your machines · JSON · Docs a supported virtual machine lacks a successfully installed Guest Configuration extension for inspecting settings inside it. AuditIfNotExists
Virtual machines' Guest Configuration extension should be deployed with system-assigned managed identity · JSON · Docs a machine using Guest Configuration lacks its own system-assigned identity for authenticating to Azure. AuditIfNotExists
System updates should be installed on your machines (powered by Update Center) · JSON · Docs Defender reports missing system updates, or no passing assessment exists for the Azure or Arc-connected machine. AuditIfNotExists
Management ports of virtual machines should be protected with just-in-time network access control · JSON · Docs Defender reports missing time-limited administration access, or no passing assessment exists for the machine. AuditIfNotExists
Subnets should be associated with a Network Security Group · JSON · Docs Defender reports missing subnet network security-group protection, or no passing assessment exists for that protection. Disabled
Internet-facing virtual machines should be protected with network security groups · JSON · Docs Defender reports missing network security-group protection for an Internet-facing machine, or no passing assessment exists. AuditIfNotExists
Non-internet-facing virtual machines should be protected with network security groups · JSON · Docs Defender reports missing network security-group protection for an internal machine, or no passing assessment exists. AuditIfNotExists
A vulnerability assessment solution should be enabled on your virtual machines · JSON · Docs Defender reports no supported vulnerability scanner on the machine, or no passing assessment exists. AuditIfNotExists
All network ports should be restricted on network security groups associated to your virtual machine · JSON · Docs Defender reports overly broad incoming network rules, such as Internet-wide access, or no passing assessment exists. AuditIfNotExists
SQL databases should have vulnerability findings resolved · JSON · Docs Defender reports unresolved database vulnerability findings, or no passing assessment exists for the server or managed instance. AuditIfNotExists
SQL servers on machines should have vulnerability findings resolved · JSON · Docs Defender reports unresolved SQL Server vulnerability findings on an Azure or Arc-connected machine, or no passing assessment exists. AuditIfNotExists
A maximum of 3 owners should be designated for your subscription · JSON · Docs Defender reports more than three subscription owners, or no passing assessment of owner count exists. AuditIfNotExists
There should be more than one owner assigned to your subscription · JSON · Docs Defender reports fewer than two subscription owners, or no passing assessment of administrator redundancy exists. AuditIfNotExists
Blocked accounts with owner permissions on Azure resources should be removed · JSON · Docs Defender reports blocked sign-in accounts retaining owner permissions, or no passing assessment exists for those accounts. AuditIfNotExists
Blocked accounts with read and write permissions on Azure resources should be removed · JSON · Docs Defender reports blocked sign-in accounts retaining read or write access, or no passing assessment exists. AuditIfNotExists
Guest accounts with owner permissions on Azure resources should be removed · JSON · Docs Defender reports guest accounts from outside the tenant holding owner permissions, or no passing assessment exists. AuditIfNotExists
Guest accounts with write permissions on Azure resources should be removed · JSON · Docs Defender reports guest accounts from outside the tenant holding write permissions, or no passing assessment exists. AuditIfNotExists
Guest accounts with read permissions on Azure resources should be removed · JSON · Docs Defender reports guest accounts from outside the tenant holding read permissions, or no passing assessment exists. AuditIfNotExists
Azure DDoS Protection should be enabled · JSON · Docs Defender reports missing DDoS protection for applicable networks serving a public Application Gateway, or no passing assessment exists. AuditIfNotExists
Microsoft Defender for SQL should be enabled for unprotected Synapse workspaces · JSON · Docs the workspace lacks an enabled SQL security alert policy for detecting suspicious database activity. AuditIfNotExists
Azure Defender for SQL should be enabled for unprotected PostgreSQL flexible servers · JSON · Docs the flexible server lacks an enabled advanced threat protection setting for detecting suspicious database activity. AuditIfNotExists
Azure Defender for SQL should be enabled for unprotected MySQL flexible servers · JSON · Docs the flexible server lacks an enabled advanced threat protection setting for detecting suspicious database activity. AuditIfNotExists
SQL server-targeted autoprovisioning should be enabled for SQL servers on machines plan · JSON · Docs the Standard SQL-on-machines plan lacks an expected monitoring-setup policy assignment; successful agent installation is not checked. AuditIfNotExists
Microsoft Defender for APIs should be enabled · JSON · Docs the subscription lacks the Standard Defender for APIs plan. AuditIfNotExists
Role-Based Access Control (RBAC) should be used on Kubernetes Services · JSON · Docs the cluster explicitly turns off role-based permissions, which limit the actions each user can perform. Audit
Authorized IP ranges should be defined on Kubernetes Services · JSON · Docs the authorized-IP-ranges setting is missing from a non-private cluster's management interface; private clusters are excluded. Audit
Management ports should be closed on your virtual machines · JSON · Docs Defender reports administration ports exposed to the Internet, or no passing assessment exists for the machine. AuditIfNotExists
IP Forwarding on your virtual machine should be disabled · JSON · Docs Defender reports IP forwarding enabled, allowing traffic for other destinations, or no passing assessment exists. AuditIfNotExists
Azure Defender for Key Vault should be enabled · JSON · Docs the subscription lacks the Standard Defender for Key Vault plan. AuditIfNotExists
Azure Defender for Azure SQL Database servers should be enabled · JSON · Docs the subscription lacks the Standard Defender for SQL Databases plan; server alert settings are checked separately. AuditIfNotExists
Azure Defender for SQL servers on machines should be enabled · JSON · Docs the subscription lacks the Standard Defender plan for SQL Server on machines. AuditIfNotExists
Azure Defender for App Service should be enabled · JSON · Docs the subscription lacks the Standard Defender for App Service plan. AuditIfNotExists
Microsoft Defender for Containers should be enabled · JSON · Docs the subscription lacks the Standard Defender for Containers plan. AuditIfNotExists
Azure Defender for servers should be enabled · JSON · Docs the subscription lacks the Standard Defender for Servers plan. AuditIfNotExists
Azure registry container images should have vulnerabilities resolved (powered by Microsoft Defender Vulnerability Management) · JSON · Docs Defender reports unresolved vulnerabilities in registry images, or no passing assessment exists for those images. AuditIfNotExists
Azure running container images should have vulnerabilities resolved (powered by Microsoft Defender Vulnerability Management) · JSON · Docs Defender reports unresolved vulnerabilities in images running on the cluster, or no passing assessment exists. AuditIfNotExists
Subscriptions should have a contact email address for security issues · JSON · Docs the subscription lacks a security-contact record with an email address. The rule does not test email delivery. AuditIfNotExists
Email notification for high severity alerts should be enabled · JSON · Docs no security-contact record enables alert emails in a supported format. The rule does not verify the severity threshold. AuditIfNotExists
Email notification to subscription owner for high severity alerts should be enabled · JSON · Docs no contact passes the legacy check, which rejects administrator emails off combined with a High-only alert threshold. AuditIfNotExists
Azure Defender for Resource Manager should be enabled · JSON · Docs the subscription lacks the Standard Defender plan for detecting suspicious operations that create, change or delete Azure resources. AuditIfNotExists
[Preview]: vTPM should be enabled on supported virtual machines · JSON · Docs a supported Trusted Launch machine lacks an enabled virtual TPM, the security device used to record and verify startup. Audit
[Preview]: Secure Boot should be enabled on supported Windows virtual machines · JSON · Docs Secure Boot is off on a supported Windows Trusted Launch or Confidential machine, allowing startup without this signature check. Audit
[Preview]: Guest Attestation extension should be installed on supported Linux virtual machines · JSON · Docs a supported secure Linux machine lacks a successfully installed Guest Attestation extension, which reports evidence about startup integrity. AuditIfNotExists
[Preview]: Guest Attestation extension should be installed on supported Linux virtual machines scale sets · JSON · Docs a supported secure Linux scale set lacks its Guest Attestation extension. Installation presence, not startup results, is checked. AuditIfNotExists
[Preview]: Guest Attestation extension should be installed on supported Windows virtual machines · JSON · Docs a supported secure Windows machine lacks a successfully installed Guest Attestation extension, which reports evidence about startup integrity. AuditIfNotExists
[Preview]: Guest Attestation extension should be installed on supported Windows virtual machines scale sets · JSON · Docs a supported secure Windows scale set lacks its Guest Attestation extension. Installation presence, not startup results, is checked. AuditIfNotExists
[Preview]: Linux virtual machines should use only signed and trusted boot components · JSON · Docs Defender's assessment of trusted startup files is missing or reports a problem. A NotApplicable assessment also passes. AuditIfNotExists
Azure Defender for open-source relational databases should be enabled · JSON · Docs the subscription lacks the Standard Defender plan covering threat detection for supported MySQL, PostgreSQL and MariaDB databases. AuditIfNotExists
Microsoft Defender CSPM should be enabled · JSON · Docs the subscription lacks the Standard Defender CSPM plan, which adds deeper security analysis beyond the free foundational checks. AuditIfNotExists
Machines should have secret findings resolved · JSON · Docs Defender's assessment of exposed passwords, keys or tokens is missing or reports a problem. NotApplicable results pass. AuditIfNotExists
API endpoints that are unused should be disabled and removed from the Azure API Management service · JSON · Docs Defender's assessment of endpoints unused for 30 days is missing or reports a problem. It does not delete endpoints. AuditIfNotExists
API endpoints in Azure API Management should be authenticated · JSON · Docs Defender's endpoint-authentication assessment is missing or reports a problem. It relies on Defender's findings rather than inspecting every authentication setting. AuditIfNotExists
Microsoft Defender for Storage should be enabled · JSON · Docs the newer Defender for Storage plan is missing, or upload malware scanning or sensitive-data discovery is not enabled. AuditIfNotExists

Key Vault and access to secrets (9)

Policy / sources Flagged when… Saved default effect
Certificates should have the specified maximum validity period · JSON · Docs a certificate stays valid beyond the configured maximum, which defaults to 12 months. Disabled
Key Vault secrets should have an expiration date · JSON · Docs a secret has no recorded expiry date; this does not check whether its stored password was changed. Disabled
Key Vault keys should have an expiration date · JSON · Docs an encryption key has no recorded expiry date; automatic key replacement is not checked. Disabled
Resource logs in Key Vault should be enabled · JSON · Docs logging is missing or off, or applicable retention is below one day; unlimited retention also passes. AuditIfNotExists
Key vaults should have deletion protection enabled · JSON · Docs required soft-delete or purge-protection settings are missing or disabled. Vault recovery requests are excluded. Audit
Key vaults should have soft delete enabled · JSON · Docs soft delete is missing or disabled, so deleted vaults lack recovery protection. Purge protection is checked separately. Audit
Azure Key Vault should have firewall enabled or public network access disabled · JSON · Docs public access remains enabled and the firewall does not block connections by default. Either restriction satisfies this rule. Audit
Azure Key Vaults should use private link · JSON · Docs no approved private endpoint exists for the vault. Public internet access is a separate setting. Audit
Azure Key Vault should use RBAC permission model · JSON · Docs the vault does not use Azure role-based permissions instead of older access policies. Vault recovery requests are excluded. Audit

Servers and hybrid infrastructure (18)

Policy / sources Flagged when… Saved default effect
Windows Defender Exploit Guard should be enabled on your machines · JSON · Docs the machine's configuration assessment is missing or fails the Windows Defender Exploit Guard protection requirements. AuditIfNotExists
Windows machines should meet requirements of the Azure compute security baseline · Explained · JSON · Docs the machine's configuration assessment is missing or fails Azure's recommended Windows security settings. AuditIfNotExists
Linux machines should meet requirements for the Azure compute security baseline · JSON · Docs the machine's configuration assessment is missing or fails Azure's recommended Linux security settings. AuditIfNotExists
Service Fabric clusters should have the ClusterProtectionLevel property set to EncryptAndSign · JSON · Docs cluster messages are not configured to be both encrypted and signed to detect tampering. Audit
Service Fabric clusters should only use Azure Active Directory for client authentication · JSON · Docs no Microsoft Entra tenant is configured for client sign-in; alternative sign-in methods are not checked. Audit
Virtual machines should be migrated to new Azure Resource Manager resources · JSON · Docs a virtual machine still uses Azure's older classic resource type instead of Azure Resource Manager. Audit
Machines should be configured to periodically check for missing system updates · JSON · Docs automatic daily checks for missing updates are not configured; this setting does not install updates. Audit
Azure Backup should be enabled for Virtual Machines · JSON · Docs no Azure Backup protection record exists for an applicable machine; successful recent backups are not checked. AuditIfNotExists
VM Image Builder templates should use private link · JSON · Docs the image-building template lacks virtual-network settings. Despite its official title, this rule does not check private endpoints directly. Audit
Authentication to Linux machines should require SSH keys · JSON · Docs the machine's assessment does not confirm password-free SSH sign-in. Supported servers connected through Azure Arc are included. AuditIfNotExists
Windows machines should be configured to use secure communication protocols · JSON · Docs the machine lacks a passing assessment for TLS 1.2 or newer connection encryption. Supported Azure Arc servers are included. AuditIfNotExists
Linux virtual machines should enable Azure Disk Encryption or EncryptionAtHost. · JSON · Docs a supported machine lacks a passing encryption assessment accepting either Azure Disk Encryption or encryption at host. AuditIfNotExists
Windows virtual machines should enable Azure Disk Encryption or EncryptionAtHost. · JSON · Docs a supported machine lacks a passing encryption assessment accepting either Azure Disk Encryption or encryption at host. AuditIfNotExists
Virtual machines and virtual machine scale sets should have encryption at host enabled · JSON · Docs encryption at host is not enabled. This setting protects temporary disks and operating-system and data-disk caches. Audit
[Preview]: Azure Stack HCI servers should meet Secured-core requirements · JSON · Docs the supported cluster lacks a Secured-core status of Compliant or Pending. A pending assessment is accepted. AuditIfNotExists
[Preview]: Azure Stack HCI servers should have consistently enforced application control policies · JSON · Docs the cluster's application-control status is neither Compliant nor Pending, or missing. Pending does not prove enforcement has been verified. AuditIfNotExists
[Preview]: Azure Stack HCI systems should have encrypted volumes · JSON · Docs the cluster's disk-encryption status is neither Compliant nor Pending, or missing. Pending does not prove encryption has been verified. AuditIfNotExists
[Preview]: Host and VM networking should be protected on Azure Stack HCI systems · JSON · Docs the cluster's network-protection status is neither Compliant nor Pending, or missing. Pending does not prove protection has been verified. AuditIfNotExists

Containers and Kubernetes (24)

Policy / sources Flagged when… Saved default effect
Azure Policy Add-on for Kubernetes service (AKS) should be installed and enabled on your clusters · JSON · Docs the Azure Policy add-on is missing or disabled, preventing its workload checks inside the cluster. Audit
Azure Arc enabled Kubernetes clusters should have the Azure Policy extension installed · JSON · Docs an applicable Arc-connected cluster lacks a successfully installed Azure Policy extension for workload checks. AuditIfNotExists
Kubernetes cluster containers should only use allowed images · JSON · Docs an image name fails the allowed-name pattern; the default pattern matches no normal image names. Audit
Kubernetes cluster should not allow privileged containers · JSON · Docs a container requests privileged mode, granting broad access to the machine hosting it. Audit
Kubernetes cluster services should listen only on allowed ports · JSON · Docs a service exposes a port outside the allowed list; the default -1 permits no valid service ports. Audit
Kubernetes cluster containers CPU and memory resource limits should not exceed the specified limits · JSON · Docs resource limits are missing or exceed the defaults: 32 CPU units or 64 GiB of memory per container. Audit
Kubernetes cluster pods and containers should only run with approved user and group IDs · JSON · Docs a container lacks a non-root user or primary group above 0, or declares other group IDs below 1. Audit
[Preview]: Azure Arc enabled Kubernetes clusters should have Microsoft Defender for Cloud extension installed · JSON · Docs an applicable cluster lacks a successfully installed Defender extension; AKS, EKS, GKE, and other listed distributions are excluded. AuditIfNotExists
Azure Kubernetes Service clusters should have Defender profile enabled · JSON · Docs the cluster's Defender security monitoring profile is not enabled to collect security event data. Audit
Kubernetes clusters should not allow container privilege escalation · JSON · Docs a container can let running programs gain extra permissions, such as becoming the root administrator. Audit
Kubernetes cluster containers should not share host process ID or host IPC namespace · JSON · Docs a container shares the host machine's process list or communication area instead of keeping those areas separate. Audit
Kubernetes cluster containers should run with a read only root file system · JSON · Docs the container's main filesystem is writable; separately configured writable storage volumes are still allowed. Audit
Kubernetes cluster containers should only use allowed capabilities · JSON · Docs a container adds unapproved Linux administrative privileges; the default allowed-capability list is empty. Audit
Kubernetes cluster containers should only use allowed AppArmor profiles · JSON · Docs a container uses an unapproved AppArmor security profile; the default approved profile is runtime/default. Audit
Kubernetes cluster pods should only use approved host network and port range · JSON · Docs a workload uses the host network or ordinary host ports; the defaults permit neither. Audit
Kubernetes cluster pod hostPath volumes should only use allowed host paths · JSON · Docs a container mounts an unapproved host folder; the default approved-folder list is empty. Audit
Container registries should be encrypted with a customer-managed key · JSON · Docs the registry does not enable encryption using a key you control. Microsoft's default encryption keys do not qualify. Disabled
Container registries should not allow unrestricted network access · JSON · Docs public access is enabled without network rules that block connections by default. Either restriction satisfies this rule. Audit
Container registries should use private link · JSON · Docs no approved private endpoint exists for the registry. Public internet access is a separate setting. Audit
Kubernetes clusters should be accessible only over HTTPS · JSON · Docs application entry-point settings allow unencrypted web traffic. This checks Kubernetes Ingress settings, not every cluster connection. Audit
Kubernetes clusters should not use the default namespace · JSON · Docs Pods, Services or ServiceAccounts use the default namespace, the shared area used when no separate namespace is specified. Audit
Kubernetes clusters should disable automounting API credentials · JSON · Docs application Pods automatically receive service-account tokens, credentials that can allow calls to the cluster's management interface. Audit
Kubernetes clusters should not grant CAP_SYS_ADMIN security capabilities · JSON · Docs containers request SYS_ADMIN, a broad Linux administrative privilege. Audit
Resource logs in Azure Kubernetes Service should be enabled · JSON · Docs no enabled log entry meets the rule. Applicable Storage retention must be unlimited or at least one day. AuditIfNotExists

Web apps and API Management (26)

Policy / sources Flagged when… Saved default effect
Resource logs in Logic Apps should be enabled · JSON · Docs logging is missing or off, or its applicable retention setting falls below the one-day default requirement. AuditIfNotExists
Function apps should have remote debugging turned off · JSON · Docs the app's configuration does not show remote debugging turned off, leaving development-tool access potentially available. AuditIfNotExists
App Service apps should have remote debugging turned off · JSON · Docs the app's configuration does not show remote debugging turned off, leaving development-tool access potentially available. AuditIfNotExists
Function apps should only be accessible over HTTPS · JSON · Docs the HTTPS-only setting is missing or off, allowing web traffic without an encrypted connection. Audit
App Service apps should only be accessible over HTTPS · JSON · Docs the HTTPS-only setting is missing or off, allowing web traffic without an encrypted connection. Audit
Function apps should not have CORS configured to allow every resource to access your apps · JSON · Docs cross-origin settings allow any website to read the app's responses in a browser, or no qualifying configuration exists. AuditIfNotExists
App Service apps should not have CORS configured to allow every resource to access your apps · JSON · Docs cross-origin settings allow any website to read the app's responses in a browser, or no qualifying configuration exists. AuditIfNotExists
Function apps should use managed identity · JSON · Docs the app's configuration lacks an Azure-managed identity for signing into supported services without stored passwords. AuditIfNotExists
App Service apps should use managed identity · JSON · Docs the app's configuration lacks an Azure-managed identity for signing into supported services without stored passwords. AuditIfNotExists
App Service apps should have resource logs enabled · JSON · Docs logging is missing or off, or applicable retention is below 365 days; unlimited retention also passes. AuditIfNotExists
App Service apps should use the latest TLS version · JSON · Docs minimum TLS is missing or below 1.2; the rule does not require the newest available version. AuditIfNotExists
Function apps should use the latest TLS version · JSON · Docs minimum TLS is missing or below 1.2; the rule does not require the newest available version. AuditIfNotExists
Function apps should require FTPS only · JSON · Docs file-transfer settings allow unencrypted FTP or are missing; encrypted FTPS only or disabled FTP both pass. AuditIfNotExists
App Service apps should require FTPS only · JSON · Docs file-transfer settings are missing or allow unencrypted FTP; encrypted FTPS only or disabled FTP both pass. AuditIfNotExists
App Configuration should use private link · JSON · Docs no approved private endpoint exists for the configuration store. Public internet access is a separate setting. AuditIfNotExists
Azure SignalR Service should use private link · JSON · Docs no approved private endpoint exists for the messaging service. Public internet access is a separate setting. Audit
Azure Spring Cloud should use network injection · JSON · Docs a Standard or Enterprise Spring instance lacks a service-runtime subnet connecting it to your virtual network. Audit
API Management services should use a virtual network · JSON · Docs a Developer or Premium API Management service lacks virtual-network settings. Both internal and internet-facing network modes qualify. Audit
API Management subscriptions should not be scoped to all APIs · JSON · Docs an active API-consumer subscription key grants access to all APIs, rather than one API or a selected product. Audit
API Management calls to API backends should not bypass certificate thumbprint or name validation · JSON · Docs backend settings disable either certificate trust or server-name verification, weakening checks that the gateway reached the intended server. Audit
API Management APIs should use only encrypted protocols · JSON · Docs an API allows unencrypted HTTP or WebSocket connections. HTTPS and secure WebSocket connections satisfy the encryption requirement. Audit
API Management secret named values should be stored in Azure Key Vault · JSON · Docs a reusable configuration value marked secret lacks a Key Vault reference. Secrets stored directly in API Management do not qualify. Audit
API Management direct management endpoint should not be enabled · JSON · Docs direct management access is enabled, providing an administrative route outside Azure Resource Manager's normal permission controls. Audit
API Management should disable public network access to the service configuration endpoints · JSON · Docs the selected configuration endpoint, currently Management, is not disabled. Consumption-tier services are excluded from this check. AuditIfNotExists
API Management calls to API backends should be authenticated · JSON · Docs an HTTP-type backend has neither a certificate nor authorization credentials. Authentication in API policies may not be recognized. Audit
Azure API Management platform version should be stv2 · JSON · Docs API Management still reports the retired stv1 hosting platform. The policy identifies services needing platform migration. Audit

Databases and caches (44)

Policy / sources Flagged when… Saved default effect
An Azure Active Directory administrator should be provisioned for SQL servers · JSON · Docs the server lacks a Microsoft Entra administrator; this does not require other sign-in methods to be disabled. AuditIfNotExists
Only secure connections to your Azure Cache for Redis should be enabled · JSON · Docs the port allowing unencrypted connections is enabled, rather than accepting only encrypted Redis connections. Audit
Transparent Data Encryption on SQL databases should be enabled · JSON · Docs database encryption is missing or disabled; the system database named master is excluded. AuditIfNotExists
Auditing on SQL server should be enabled · JSON · Docs the server's audit setting is missing or fails the required value, which defaults to enabled. AuditIfNotExists
Azure Defender for SQL should be enabled for unprotected Azure SQL servers · JSON · Docs the server's security alert policy is missing or disabled; subscription-level Defender plan settings are checked separately. AuditIfNotExists
Azure Defender for SQL should be enabled for unprotected SQL Managed Instances · JSON · Docs the managed instance lacks an enabled security alert policy for detecting suspicious database activity. AuditIfNotExists
Vulnerability assessment should be enabled on your SQL servers · JSON · Docs no expected assessment record exists under the server's databases; scan success and resolved findings are not checked. AuditIfNotExists
Vulnerability assessment should be enabled on SQL Managed Instance · JSON · Docs no expected assessment record exists under the instance's databases; scan success and resolved findings are not checked. AuditIfNotExists
SQL servers should use customer-managed keys to encrypt data at rest · JSON · Docs encryption does not reference a key you manage in Key Vault; Synapse-managed resource groups are excluded. Disabled
SQL managed instances should use customer-managed keys to encrypt data at rest · JSON · Docs encryption does not reference a key you manage in Key Vault instead of Microsoft's default key. Disabled
Geo-redundant backup should be enabled for Azure Database for MariaDB · JSON · Docs the server's setting for copying backups to another region is missing or disabled. Audit
Geo-redundant backup should be enabled for Azure Database for PostgreSQL · JSON · Docs backup replication to another region is not enabled on the older server resource type; flexible servers are excluded. Audit
Geo-redundant backup should be enabled for Azure Database for MySQL · JSON · Docs backup replication to another region is not enabled on the older server resource type; flexible servers are excluded. Audit
Enforce SSL connection should be enabled for PostgreSQL database servers · JSON · Docs the older server's existing SSL enforcement setting is not enabled; flexible servers are excluded. Audit
Enforce SSL connection should be enabled for MySQL database servers · JSON · Docs the older server's existing SSL enforcement setting is not enabled; flexible servers are excluded. Audit
Private endpoint should be enabled for PostgreSQL servers · JSON · Docs the older server lacks an approved private endpoint; public access being disabled is not checked, and flexible servers are excluded. AuditIfNotExists
Private endpoint should be enabled for MariaDB servers · JSON · Docs the server lacks an approved private endpoint; public access being disabled is not checked. AuditIfNotExists
Private endpoint should be enabled for MySQL servers · JSON · Docs the older server lacks an approved private endpoint; public access being disabled is not checked, and flexible servers are excluded. AuditIfNotExists
SQL servers with auditing to storage account destination should be configured with 90 days retention or higher · JSON · Docs storage audit settings are missing or retain logs for under 90 days; unlimited retention and Azure Monitor-only destinations also pass. AuditIfNotExists
Azure Cosmos DB accounts should use customer-managed keys to encrypt data at rest · JSON · Docs the account lacks a reference to your Key Vault encryption key. Microsoft's default encryption keys do not qualify. Disabled
Cosmos DB database accounts should have local authentication methods disabled · JSON · Docs account-key sign-in remains enabled instead of requiring Microsoft Entra identities. MongoDB, Cassandra and Gremlin accounts are excluded. Audit
Azure Cache for Redis should use private link · JSON · Docs no approved private endpoint exists for the cache. This rule does not require public access to be disabled. AuditIfNotExists
Public network access should be disabled for MariaDB servers · JSON · Docs public network access is not disabled; private connectivity is not verified. Audit
Public network access should be disabled for MySQL servers · JSON · Docs public network access is not disabled on an older MySQL server. Flexible servers are outside this check. Audit
MySQL servers should use customer-managed keys to encrypt data at rest · JSON · Docs an older server lacks a nonempty reference to a Key Vault encryption key. Flexible servers are excluded. Disabled
Public network access should be disabled for PostgreSQL servers · JSON · Docs public network access is not disabled on an older PostgreSQL server. Flexible servers are outside this check. Audit
PostgreSQL servers should use customer-managed keys to encrypt data at rest · JSON · Docs an older server lacks a nonempty reference to a Key Vault encryption key. Flexible servers are excluded. Disabled
Private endpoint connections on Azure SQL Database should be enabled · JSON · Docs no approved private endpoint exists for the SQL server. Public internet access is a separate setting. Audit
Public network access on Azure SQL Database should be disabled · JSON · Docs public network access is not disabled on the SQL server. This does not test private connectivity. Audit
Azure Cosmos DB accounts should have firewall rules · JSON · Docs public access is enabled without any recognized restriction: virtual-network filtering, IP rules, or an approved private endpoint. Audit
Azure SQL logical servers should have Microsoft Entra-only authentication enabled during creation · JSON · Docs server creation settings do not require Microsoft Entra-only sign-in. Later changes to the authentication setting are checked separately. Audit
Azure SQL Database should have Microsoft Entra-only authentication enabled · JSON · Docs the separate authentication setting does not require Microsoft Entra-only sign-in. The initial server creation request is checked separately. Audit
A Microsoft Entra administrator should be provisioned for MySQL servers · JSON · Docs an older MySQL server lacks a Microsoft Entra administrator. This does not require local password sign-in to be disabled. AuditIfNotExists
A Microsoft Entra administrator should be provisioned for PostgreSQL servers · JSON · Docs an older PostgreSQL server lacks a Microsoft Entra administrator. This does not require local password sign-in to be disabled. AuditIfNotExists
Azure SQL Managed Instances should have Microsoft Entra-only authentication enabled during creation · JSON · Docs instance creation settings do not require Microsoft Entra-only sign-in. Later changes to the authentication setting are checked separately. Audit
Azure SQL Managed Instance should have Microsoft Entra-only authentication enabled · JSON · Docs the separate authentication setting does not require Microsoft Entra-only sign-in. The initial instance creation request is checked separately. Audit
Synapse Workspaces should use only Microsoft Entra identities for authentication during workspace creation · JSON · Docs workspace creation settings do not consistently require Microsoft Entra-only sign-in. Later changes to the authentication setting are checked separately. Audit
Synapse Workspaces should have Microsoft Entra-only authentication enabled · JSON · Docs the separate authentication setting does not require Microsoft Entra-only sign-in. The initial workspace creation request is checked separately. Audit
Azure MySQL flexible server should have Microsoft Entra Only Authentication enabled · JSON · Docs Microsoft Entra-only sign-in is not enabled, which is the server setting that excludes local password authentication. AuditIfNotExists
Azure Cosmos DB should disable public network access · JSON · Docs public network access is not disabled; private connectivity is not verified. Audit
CosmosDB accounts should use private link · JSON · Docs no approved private endpoint exists for the database account. Public internet access is a separate setting. Audit
Azure SQL Database should be running TLS version 1.2 or newer · JSON · Docs the minimum allowed connection-encryption version is missing or below TLS 1.2. Older versions do not satisfy this rule. Audit
Azure SQL Managed Instances should disable public network access · JSON · Docs the instance's public database endpoint is enabled. Private-network access is not tested. Audit
[Preview]: Azure PostgreSQL flexible server should have Microsoft Entra Only Authentication enabled · JSON · Docs Microsoft Entra authentication is not enabled or password authentication is not disabled. Both settings must meet the requirement. Audit

Storage and data lakes (18)

Policy / sources Flagged when… Saved default effect
Storage accounts should restrict network access · JSON · Docs network rules allow connections by default instead of requiring an allowed rule or configured exception. Disabled
Storage accounts should restrict network access (excluding storage accounts managed by Azure Red Hat OpenShift) · JSON · Docs network rules allow connections by default; storage in resource groups managed by Azure Red Hat OpenShift is excluded. Disabled
Secure transfer to storage accounts should be enabled · JSON · Docs secure transfer is disabled or missing where required, allowing supported storage connections without encryption. Audit
Resource logs in Azure Data Lake Store should be enabled · JSON · Docs logging is missing or off, or applicable retention is below one day; unlimited retention also passes. AuditIfNotExists
Resource logs in Data Lake Analytics should be enabled · JSON · Docs logging is missing or off, or applicable retention is below one day; unlimited retention also passes. AuditIfNotExists
Storage accounts should be migrated to new Azure Resource Manager resources · JSON · Docs an account still uses Azure's older classic resource type instead of Azure Resource Manager. Audit
Storage account public access should be disallowed · JSON · Docs the account does not explicitly disable anonymous blob access; public network access is separate, and selected OpenShift accounts are excluded. Audit
Storage accounts should use customer-managed key for encryption · JSON · Docs storage encryption does not use a key you control in Key Vault. Microsoft's default encryption keys do not qualify. Disabled
Storage accounts should use customer-managed key for encryption (excluding storage accounts managed by Azure Red Hat OpenShift) · JSON · Docs storage encryption does not use your Key Vault key, excluding storage in resource groups managed by Azure Red Hat OpenShift. Disabled
Storage accounts should restrict network access using virtual network rules · JSON · Docs the firewall allows access by default or allows public IP exceptions. No actual virtual-network rule is required. Audit
Storage accounts should restrict network access using virtual network rules (excluding storage accounts managed by ARO) · JSON · Docs the firewall allows access by default or public IP exceptions, excluding storage managed by Azure Red Hat OpenShift. Audit
Storage accounts should restrict network access using virtual network rules (excluding storage accounts created by Databricks) · JSON · Docs the firewall allows access by default or public IP exceptions, excluding storage in resource groups managed by Databricks. Audit
Storage accounts should use private link · JSON · Docs no approved storage private endpoint exists. Public access and coverage of every storage service are not checked. AuditIfNotExists
Storage accounts should use private link (excluding storage accounts managed by Azure Red Hat OpenShift) · JSON · Docs no approved private endpoint exists, excluding storage managed by Azure Red Hat OpenShift. Public access is checked separately. AuditIfNotExists
Storage accounts should use private link (excluding storage accounts created by Databricks) · JSON · Docs no approved private endpoint exists, excluding storage in Databricks-managed resource groups. Public access is checked separately. AuditIfNotExists
Storage accounts should prevent shared key access · JSON · Docs storage-account key access is not disabled. Supported identity-based authorization avoids depending on a shared account key. Audit
Storage accounts should prevent shared key access (excluding storage accounts managed by Azure Red Hat OpenShift) · JSON · Docs shared account-key access is not disabled, excluding storage in resource groups managed by Azure Red Hat OpenShift. Audit
Storage accounts should prevent shared key access (excluding storage accounts created by Databricks) · JSON · Docs shared account-key access is not disabled, excluding storage in resource groups managed by Azure Databricks. Audit

AI and analytics (19)

Policy / sources Flagged when… Saved default effect
Resource logs in Azure Stream Analytics should be enabled · JSON · Docs logging is missing or off, or applicable retention is below one day; unlimited retention also passes. AuditIfNotExists
Resource logs in Search services should be enabled · JSON · Docs logging is missing or off, or applicable retention is below one day; unlimited retention also passes. AuditIfNotExists
Azure AI Services resources should encrypt data at rest with a customer-managed key (CMK) · JSON · Docs supported AI accounts do not use encryption keys you control in Key Vault. Several account types are excluded. Disabled
Azure Machine Learning workspaces should be encrypted with a customer-managed key · JSON · Docs workspace encryption does not use a key you control. Resources marked as projects are excluded. Disabled
Azure Machine Learning workspaces should use private link · JSON · Docs no approved private endpoint exists for the workspace. Public internet access is a separate setting. Audit
Azure AI Services resources should restrict network access · JSON · Docs public access remains unrestricted: AI accounts need a default-block firewall; AI Search needs IP restrictions. Disabling public access also passes. Audit
Diagnostic logs in Azure AI services resources should be enabled · JSON · Docs no diagnostic setting contains log entries. The rule does not require those entries to be enabled or successfully collected. AuditIfNotExists
Azure AI Services resources should use Azure Private Link · JSON · Docs no approved private endpoint exists for the AI account or AI Search service. Public access is checked separately. Audit
Resource logs in Azure Machine Learning Workspaces should be enabled · JSON · Docs no enabled log entry meets the rule. Applicable Storage retention must be unlimited or at least 365 days. AuditIfNotExists
Azure Machine Learning Workspaces should disable public network access · JSON · Docs public network access is not explicitly disabled; private connectivity is not verified. Audit
Azure Machine Learning Computes should be in a virtual network · JSON · Docs a compute cluster or instance lacks a virtual-network subnet reference. The rule does not inspect public IP settings. Audit
Azure Machine Learning Computes should have local authentication methods disabled · JSON · Docs local authentication remains enabled on compute clusters or instances instead of requiring supported Microsoft Entra sign-in. Audit
Azure Machine Learning compute instances should be recreated to get the latest software updates · JSON · Docs a compute instance reports an outdated operating-system image. Recreating it with a current image is the recommended fix. Audit
Resource logs in Azure Databricks Workspaces should be enabled · JSON · Docs no enabled log entry meets the rule. Applicable Storage retention must be unlimited or at least 365 days. AuditIfNotExists
Azure Databricks Workspaces should disable public network access · JSON · Docs public network access is not disabled on the workspace. Private endpoints and cluster public IPs are separate checks. Audit
Azure Databricks Clusters should disable public IP · JSON · Docs the workspace's no-public-IP setting for cluster machines is not enabled. Public access to the workspace interface is separate. Audit
Azure Databricks Workspaces should be in a virtual network · JSON · Docs the workspace lacks its own virtual-network reference or either required subnet reference. Detailed firewall rules are not inspected. Audit
Azure Databricks Workspaces should use private link · JSON · Docs no approved private endpoint exists for the workspace. Public internet access is a separate setting. Audit
Azure AI Services resources should have key access disabled (disable local authentication) · JSON · Docs AI accounts or AI Search still allow local API keys instead of requiring supported Microsoft Entra authentication. Audit

Network protection (5)

Policy / sources Flagged when… Saved default effect
[Preview]: All Internet traffic should be routed via your deployed Azure Firewall · JSON · Docs a qualifying subnet has at least two IP configurations and no route table, but its network lacks the expected Azure Firewall; actual traffic routing is not verified. AuditIfNotExists
Azure Web Application Firewall should be enabled for Azure Front Door entry-points · JSON · Docs Front Door classic lacks linked web firewall protection. The rule checks policy links, not whether attack blocking is enabled. Audit
Web Application Firewall (WAF) should be enabled for Application Gateway · JSON · Docs neither a web firewall configuration nor a linked policy exists. It does not verify the firewall is enabled. Audit
Network Watcher should be enabled · JSON · Docs a virtual network's region lacks a Network Watcher in NetworkWatcherRG. Individual monitoring features are not checked. AuditIfNotExists
VPN gateways should use only Azure Active Directory (Azure AD) authentication for point-to-site users · JSON · Docs a configured remote-user VPN allows an authentication method other than Microsoft Entra. This does not prove Entra is correctly configured. Audit

Messaging and connected devices (5)

Policy / sources Flagged when… Saved default effect
Resource logs in IoT Hub should be enabled · JSON · Docs logging is missing or off, or applicable retention is below one day; unlimited retention also passes. AuditIfNotExists
Resource logs in Service Bus should be enabled · JSON · Docs logging is missing or off, or applicable retention is below one day; unlimited retention also passes. AuditIfNotExists
Resource logs in Event Hub should be enabled · JSON · Docs logging is missing or off, or applicable retention is below one day; unlimited retention also passes. AuditIfNotExists
Azure Event Grid domains should use private link · JSON · Docs no approved private endpoint exists for the event domain. Public internet access is a separate setting. Audit
Azure Event Grid topics should use private link · JSON · Docs no approved private endpoint exists for the event topic. Topics connected through Azure Arc are excluded. Audit

Automation and other resources (3)

Policy / sources Flagged when… Saved default effect
Audit usage of custom RBAC roles · JSON · Docs a custom permission-role definition exists, even if nobody uses it; built-in roles are excluded. Audit
Resource logs in Batch accounts should be enabled · JSON · Docs logging is missing or off, or applicable retention is below one day; unlimited retention also passes. AuditIfNotExists
Automation account variables should be encrypted · JSON · Docs a reusable variable stored in Azure Automation does not have its encryption setting enabled. Audit

Source and version details

Recorded as 57.59.0 on 5 September 2026; exact membership is unverified. The available initiative JSON is 57.58.0 / 226 entries, so it does not match this saved list.

Initiative JSON lists policy references and parameters. Each row's JSON links to its rule. Effects are saved defaults, not live results.

References

Upcoming change: from 27 October 2026, new subscriptions must opt in to Foundational CSPM. Already-enabled subscriptions stay enabled. Microsoft notice