AWS & Azure security controls
Every AWS Security Hub and Microsoft Defender for Cloud recommendation we map to a fix: 360 AWS controls across 55 services, plus 226 Azure recommendations across 49. Each links to the risk in plain English and a step-by-step remediation lesson.
Account · 1
- Account.1
No security contact is set for AWS to reach you
Fix it Set AWS account security contact information
ACM · 2
- ACM.1
Certificates are close to expiry
Fix it Manage and renew TLS certificates - ACM.2
An ACM RSA certificate uses a key shorter than 2048 bits
Fix it Manage and renew TLS certificates
APIGateway · 8
- APIGateway.1
REST/WebSocket API execution logging
Fix it Enable application and API logging - APIGateway.2
REST stages should use SSL certs for backend auth
Fix it Enforce TLS on APIs and search domains - APIGateway.4
API Gateway should be associated with a WAF web ACL
Fix it Protect APIs and edge with WAF - APIGateway.5
REST API cache data should be encrypted at rest
Fix it Encrypt other services at rest (queues, streams, logs, ML) - APIGateway.8
Routes should specify an authorization type
Fix it Require authentication on data and API services - APIGateway.9
V2 stages should have access logging
Fix it Enable application and API logging - APIGateway.10
V2 integrations should use HTTPS for private connections
Fix it Enforce TLS on APIs and search domains - APIGateway.11
Domain names should use recommended security policies
Fix it Enforce TLS on APIs and search domains
AppSync · 2
- AppSync.2
AppSync should have field-level logging
Fix it Enable application and API logging - AppSync.5
An AppSync GraphQL API is authenticated with API keys
Fix it Require authentication on data and API services
Athena · 1
- Athena.4
Athena query access is not logged
Fix it Enable application and API logging
AutoScaling · 6
- AutoScaling.1
ASGs with an LB should use ELB health checks
Fix it Harden load balancers (ALB/NLB/CLB) - AutoScaling.2
A single-AZ Auto Scaling group is one outage from zero capacity
Fix it Deploy across multiple Availability Zones - AutoScaling.3
Launched instances still allow IMDSv1
Fix it Enforce IMDSv2 on EC2 - AutoScaling.5
A launch config gives ASG instances public IPs
Fix it Block public access to AWS resources - AutoScaling.6
ASGs should use multiple instance types/AZs
Fix it Deploy across multiple Availability Zones - AutoScaling.9
Deprecated launch configurations are still in use
Fix it Migrate ASGs from Launch Configurations to Launch Templates
Backup · 1
- Backup.1
Backup vault recovery points are not KMS-encrypted
Fix it Encrypt other services at rest (queues, streams, logs, ML)
CloudFormation · 2
- CloudFormation.3
Stacks can be deleted without termination protection
Fix it Enable deletion and termination protection - CloudFormation.4
Stacks deploy with user creds instead of a scoped role
Fix it Harden resource and service-role policies
CloudFront · 11
- CloudFront.1
No default root object, exposing the distribution listing
Fix it Protect CloudFront distributions and origins - CloudFront.3
Distributions should require encryption in transit
Fix it Protect CloudFront distributions and origins - CloudFront.5
Distributions should have logging enabled
Fix it Protect CloudFront distributions and origins - CloudFront.6
Distributions should have WAF enabled
Fix it Protect CloudFront distributions and origins - CloudFront.9
Distributions should encrypt traffic to custom origins
Fix it Protect CloudFront distributions and origins - CloudFront.10
No deprecated SSL protocols to custom origins
Fix it Protect CloudFront distributions and origins - CloudFront.12
A distribution points at a non-existent S3 origin (takeover risk)
Fix it Protect CloudFront distributions and origins - CloudFront.13
Distributions should use origin access control
Fix it Protect CloudFront distributions and origins - CloudFront.15
Distributions should use recommended TLS policy
Fix it Protect CloudFront distributions and origins - CloudFront.16
OAC for Lambda function URL origins
Fix it Protect CloudFront distributions and origins - CloudFront.17
Use trusted key groups for signed URLs/cookies
Fix it Protect CloudFront distributions and origins
CloudTrail · 8
- CloudTrail.1
No multi-Region trail captures read/write management events
Fix it Enable CloudTrail and API activity logging - CloudTrail.2
CloudTrail logs are not KMS-encrypted
Fix it Manage KMS encryption keys - CloudTrail.3
No CloudTrail trail is enabled at all
Fix it Enable CloudTrail and API activity logging - CloudTrail.4
CloudTrail log file validation should be enabled
Fix it Enable CloudTrail and API activity logging - CloudTrail.5
CloudTrail is not wired to CloudWatch for alerting
Fix it Enable CloudTrail and API activity logging - CloudTrail.6
The CloudTrail log bucket is publicly accessible
Fix it Block public access to AWS resources - CloudTrail.7
Enable access logging on the CloudTrail S3 bucket
Fix it Enable CloudTrail and API activity logging - CloudTrail.10
CloudTrail Lake stores should use customer-managed KMS
Fix it Manage KMS encryption keys
CodeBuild · 5
- CodeBuild.1
A CodeBuild Bitbucket URL contains embedded credentials
Fix it Rotate and remove stale IAM credentials - CodeBuild.2
CodeBuild env vars contain clear-text credentials
Fix it Rotate and remove stale IAM credentials - CodeBuild.3
CodeBuild S3 logs should be encrypted
Fix it Encrypt S3 object storage at rest - CodeBuild.4
Projects should have a logging configuration
Fix it Enable application and API logging - CodeBuild.7
Report group exports should be encrypted at rest
Fix it Encrypt other services at rest (queues, streams, logs, ML)
Cognito · 5
- Cognito.1
Cognito threat protection is not enforced
Fix it Enable Cognito threat protection (Advanced Security) - Cognito.3
Cognito password policy is too weak
Fix it Rotate and remove stale IAM credentials - Cognito.4
Cognito threat protection is not enforced
Fix it Enable Cognito threat protection (Advanced Security) - Cognito.5
Cognito users can sign in without MFA
Fix it Enable MFA for root and IAM users - Cognito.6
A Cognito user pool can be deleted by accident
Fix it Enable deletion and termination protection
Config · 1
- Config.1
AWS Config is off, so most other controls cannot evaluate
Fix it Enable AWS security tooling (Config, Access Analyzer, SSM)
DataSync · 1
- DataSync.1
DataSync tasks should have logging enabled
Fix it Enable application and API logging
DMS · 9
- DMS.1
A DMS replication instance is publicly accessible
Fix it Block public access to AWS resources - DMS.6
DMS instances auto minor version upgrade
Fix it Keep software and engines patched - DMS.7
DMS target DB tasks should have logging
Fix it Enable application and API logging - DMS.8
DMS source DB tasks should have logging
Fix it Enable application and API logging - DMS.9
DMS endpoints should use SSL
Fix it Enforce TLS on database and cache connections - DMS.10
DMS Neptune endpoints should have IAM auth
Fix it Harden database auth, ports and access - DMS.11
DMS MongoDB endpoints should have auth
Fix it Require authentication on data and API services - DMS.12
DMS Redis endpoints should have TLS
Fix it Enforce TLS on database and cache connections - DMS.13
DMS replication instances should be Multi-AZ
Fix it Deploy across multiple Availability Zones
DocumentDB · 6
- DocumentDB.1
DocumentDB clusters should encrypt at rest
Fix it Encrypt AWS databases at rest - DocumentDB.2
DocumentDB adequate backup retention
Fix it Configure backups and retention - DocumentDB.3
A DocumentDB manual snapshot is public
Fix it Configure backups and retention - DocumentDB.4
DocumentDB clusters should export audit logs to CW
Fix it Harden database auth, ports and access - DocumentDB.5
DocumentDB clusters should have deletion protection
Fix it Enable deletion and termination protection - DocumentDB.6
DocumentDB clusters should encrypt in transit
Fix it Enforce TLS on database and cache connections
DynamoDB · 6
- DynamoDB.1
DynamoDB tables should auto-scale capacity
Fix it Make DynamoDB tables scale capacity with demand - DynamoDB.2
DynamoDB tables should have PITR
Fix it Configure backups and retention - DynamoDB.3
DAX clusters should be encrypted at rest
Fix it Encrypt AWS databases at rest - DynamoDB.4
DynamoDB tables should be in a backup plan
Fix it Configure backups and retention - DynamoDB.6
DynamoDB tables should have deletion protection
Fix it Enable deletion and termination protection - DynamoDB.7
DAX clusters should be encrypted in transit
Fix it Enforce TLS on database and cache connections
EC2 · 31
- EC2.1
An EBS snapshot is publicly restorable by any account
Fix it Configure backups and retention - EC2.2
Default security groups still allow traffic
Fix it Harden security groups and restrict ingress - EC2.3
Attached EBS volumes are not encrypted at rest
Fix it Encrypt EBS and EFS storage at rest - EC2.4
Long-stopped instances are abandoned attack surface
Fix it Remove long-stopped EC2 instances - EC2.6
No VPC flow logs, so there is no network audit trail
Fix it Enable VPC flow logs in every VPC - EC2.7
New EBS volumes are not encrypted by default
Fix it Encrypt EBS and EFS storage at rest - EC2.8
IMDSv1 lets an SSRF steal instance credentials
Fix it Enforce IMDSv2 on EC2 - EC2.9
Instances are directly reachable on public IPv4
Fix it Block public access to AWS resources - EC2.10
EC2 API traffic leaves the VPC over the internet
Fix it Move resources into private networks (VPC isolation) - EC2.13
SSH (port 22) is open to the entire internet
Fix it Harden security groups and restrict ingress - EC2.14
RDP (port 3389) is open to the entire internet
Fix it Harden security groups and restrict ingress - EC2.15
Subnets auto-assign public IPs to new instances
Fix it Block public access to AWS resources - EC2.17
Instances with multiple ENIs can bridge network boundaries
Fix it Move resources into private networks (VPC isolation) - EC2.18
Security groups open ports beyond what is authorised
Fix it Harden security groups and restrict ingress - EC2.19
Security groups expose SSH, RDP, or database ports to the world
Fix it Harden security groups and restrict ingress - EC2.20
Both Site-to-Site VPN tunnels should be up
Fix it Secure Site-to-Site VPN connections - EC2.21
NACLs should not allow ingress to ports 22/3389
Fix it Harden security groups and restrict ingress - EC2.23
A Transit Gateway auto-accepts any VPC attachment request
Fix it Disable insecure access modes and protocols - EC2.24
Paravirtual instance types should not be used
Fix it Keep software and engines patched - EC2.25
A launch template assigns public IPs to new instances
Fix it Block public access to AWS resources - EC2.51
Client VPN endpoints should log connections
Fix it Secure Site-to-Site VPN connections - EC2.55
VPC is missing an ECR API endpoint
Fix it Move resources into private networks (VPC isolation) - EC2.56
VPC is missing a Docker Registry endpoint
Fix it Move resources into private networks (VPC isolation) - EC2.57
VPC is missing a Systems Manager endpoint
Fix it Move resources into private networks (VPC isolation) - EC2.58
VPC is missing an Incident Manager Contacts endpoint
Fix it Move resources into private networks (VPC isolation) - EC2.60
VPC is missing an Incident Manager endpoint
Fix it Move resources into private networks (VPC isolation) - EC2.171
Site-to-site VPN tunnels are not logging
Fix it Secure Site-to-Site VPN connections - EC2.172
VPC Block Public Access is not enabled
Fix it Block public access to AWS resources - EC2.180
ENIs with source/dest check off can route around controls
Fix it Move resources into private networks (VPC isolation) - EC2.182
A public EBS snapshot exposes an entire disk
Fix it Configure backups and retention - EC2.183
VPN is using deprecated IKEv1
Fix it Secure Site-to-Site VPN connections
ECR · 3
- ECR.1
Container images are not scanned on push
Fix it Enable threat detection and vulnerability scanning - ECR.2
Mutable image tags can be swapped under you
Fix it Enable ECR tag immutability - ECR.3
ECR repos grow without lifecycle cleanup
Fix it Configure lifecycle and versioning policies
ECS · 13
- ECS.2
An ECS service auto-assigns public IPs to tasks
Fix it Block public access to AWS resources - ECS.3
A task definition shares the host PID namespace
Fix it Harden ECS container workloads - ECS.4
A container runs in privileged mode
Fix it Harden ECS container workloads - ECS.5
A container has a writable root filesystem
Fix it Harden ECS container workloads - ECS.8
Secrets are passed as plaintext container env vars
Fix it Harden ECS container workloads - ECS.9
A task definition has no logging configuration
Fix it Harden ECS container workloads - ECS.10
Fargate services should run latest platform version
Fix it Keep software and engines patched - ECS.12
ECS clusters should use Container Insights
Fix it Harden ECS container workloads - ECS.16
An ECS task set auto-assigns public IPs
Fix it Harden ECS container workloads - ECS.18
ECS task defs should encrypt EFS volumes in transit
Fix it Require TLS for storage and remaining services - ECS.19
Capacity providers managed termination protection
Fix it Enable deletion and termination protection - ECS.20
Linux containers should run as non-root users
Fix it Harden ECS container workloads - ECS.21
Windows containers should run as non-admin users
Fix it Harden ECS container workloads
EFS · 7
- EFS.1
EFS data is not encrypted at rest
Fix it Encrypt EBS and EFS storage at rest - EFS.2
EFS has no automatic backups
Fix it Configure backups and retention - EFS.3
EFS access points should enforce a root directory
Fix it Enforce a root directory on EFS access points - EFS.4
EFS access points should enforce a user identity
Fix it Enforce a user identity on EFS access points - EFS.6
Mount targets not in public-IP subnets
Fix it Block public access to AWS resources - EFS.7
EFS file systems should have automatic backups
Fix it Configure backups and retention - EFS.8
EFS file systems should be encrypted at rest
Fix it Encrypt EBS and EFS storage at rest
EKS · 5
- EKS.1
An EKS cluster API endpoint is public
Fix it Disable insecure access modes and protocols - EKS.2
An EKS cluster runs an unsupported Kubernetes version
Fix it Keep software and engines patched - EKS.3
EKS clusters should use encrypted K8s secrets
Fix it Manage secrets (rotation and hygiene) - EKS.8
EKS clusters should have audit logging
Fix it Enable cluster and search audit logging - EKS.9
An EKS node group runs an unsupported Kubernetes version
Fix it Keep software and engines patched
ElastiCache · 7
- ElastiCache.1
A Redis cluster has no automatic backups
Fix it Configure backups and retention - ElastiCache.2
ElastiCache is not auto-applying minor patches
Fix it Keep software and engines patched - ElastiCache.3
Replication groups should have auto-failover
Fix it Deploy across multiple Availability Zones - ElastiCache.4
Replication groups encrypted at rest
Fix it Encrypt AWS databases at rest - ElastiCache.5
Replication groups encrypted in transit
Fix it Enforce TLS on database and cache connections - ElastiCache.6
Redis replication groups should have AUTH
Fix it Require authentication on data and API services - ElastiCache.7
A cluster uses the default subnet group
Fix it Configure ElastiCache clusters with a custom subnet group
ElasticBeanstalk · 3
- ElasticBeanstalk.1
Environments should have enhanced health reporting
Fix it Enable enhanced health reporting on Elastic Beanstalk environments - ElasticBeanstalk.2
Managed platform updates are disabled
Fix it Keep software and engines patched - ElasticBeanstalk.3
Beanstalk logs are not streamed to CloudWatch
Fix it Stream Elastic Beanstalk logs to CloudWatch
ELB · 18
- ELB.1
ALB serves HTTP without redirecting to HTTPS
Fix it Enforce TLS on load balancer listeners - ELB.2
CLB SSL/HTTPS listeners should use ACM certs
Fix it Use ACM certificates on Classic Load Balancers - ELB.3
CLB listeners should use HTTPS/TLS termination
Fix it Enforce TLS on load balancer listeners - ELB.4
ALB accepts malformed HTTP headers
Fix it Harden load balancers (ALB/NLB/CLB) - ELB.5
Load balancers are not writing access logs
Fix it Enable network and edge logging (LB, WAF, firewall, DNS) - ELB.6
Load balancers can be deleted by accident
Fix it Enable deletion and termination protection - ELB.7
CLBs should have connection draining
Fix it Harden load balancers (ALB/NLB/CLB) - ELB.8
CLB SSL listeners should use strong policy
Fix it Enforce TLS on load balancer listeners - ELB.9
CLBs should have cross-zone balancing
Fix it Harden load balancers (ALB/NLB/CLB) - ELB.10
CLBs should span multiple AZs
Fix it Deploy across multiple Availability Zones - ELB.12
ALB desync mitigation mode
Fix it Harden load balancers (ALB/NLB/CLB) - ELB.13
A single-AZ load balancer is a data-plane single point of failure
Fix it Deploy across multiple Availability Zones - ELB.14
CLB desync mitigation mode
Fix it Harden load balancers (ALB/NLB/CLB) - ELB.16
ALBs should be associated with a WAF web ACL
Fix it Protect APIs and edge with WAF - ELB.17
TLS policy allows weak ciphers or TLS 1.0 to 1.1
Fix it Require TLS for storage and remaining services - ELB.18
A public listener exposes traffic over plain HTTP
Fix it Enforce TLS on load balancer listeners - ELB.21
Health-check probes ride unencrypted HTTP
Fix it Encrypt other services at rest (queues, streams, logs, ML) - ELB.22
Load-balancer-to-target traffic is not encrypted
Fix it Encrypt other services at rest (queues, streams, logs, ML)
ELBv2 · 1
- ELBv2.1
ALB serves HTTP without redirecting to HTTPS
Fix it Enforce TLS on load balancer listeners
EMR · 4
- EMR.1
An EMR primary node has a public IP
Fix it Block public access to AWS resources - EMR.2
EMR account-level block public access is off
Fix it Block public access to AWS resources - EMR.3
EMR security configs should encrypt at rest
Fix it Encrypt other services at rest (queues, streams, logs, ML) - EMR.4
EMR security configs should encrypt in transit
Fix it Enforce TLS on database and cache connections
ES · 8
- ES.1
ES domains should encrypt at rest
Fix it Encrypt other services at rest (queues, streams, logs, ML) - ES.2
A legacy Elasticsearch domain is publicly accessible
Fix it Move resources into private networks (VPC isolation) - ES.3
ES should encrypt node-to-node traffic
Fix it Encrypt other services at rest (queues, streams, logs, ML) - ES.4
ES error logging to CW should be enabled
Fix it Enable cluster and search audit logging - ES.5
ES domains should have audit logging
Fix it Enable cluster and search audit logging - ES.6
ES domains should have >= 3 data nodes
Fix it Deploy across multiple Availability Zones - ES.7
ES domains should have >= 3 dedicated master nodes
Fix it Deploy across multiple Availability Zones - ES.8
ES should use latest TLS policy
Fix it Enforce TLS on APIs and search domains
EventBridge · 2
- EventBridge.3
Custom event buses should have a resource policy
Fix it Harden resource and service-role policies - EventBridge.4
Global endpoints should have event replication
Fix it Enable event replication on EventBridge global endpoints
FSx · 3
- FSx.3
FSx for OpenZFS should be Multi-AZ
Fix it Deploy across multiple Availability Zones - FSx.4
FSx for NetApp ONTAP should be Multi-AZ
Fix it Deploy across multiple Availability Zones - FSx.5
FSx for Windows File Server should be Multi-AZ
Fix it Deploy across multiple Availability Zones
Glue · 2
- Glue.3
Glue ML transforms should be encrypted at rest
Fix it Encrypt other services at rest (queues, streams, logs, ML) - Glue.4
Glue Spark jobs on supported versions
Fix it Keep software and engines patched
GuardDuty · 5
- GuardDuty.1
GuardDuty threat detection is not enabled
Fix it Enable threat detection and vulnerability scanning - GuardDuty.5
GuardDuty EKS audit log monitoring is off
Fix it Enable cluster and search audit logging - GuardDuty.10
GuardDuty S3 Protection is off
Fix it Enable threat detection and vulnerability scanning - GuardDuty.11
GuardDuty Runtime Monitoring is off
Fix it Enable threat detection and vulnerability scanning - GuardDuty.13
GuardDuty runtime monitoring is off for EC2
Fix it Enable threat detection and vulnerability scanning
IAM · 16
- IAM.1
A policy grants full "*" administrative privileges
Fix it Harden resource and service-role policies - IAM.2
Policies attached directly to users do not scale or audit cleanly
Fix it Enforce IAM least privilege - IAM.3
Long-lived access keys have not been rotated
Fix it Manage KMS encryption keys - IAM.4
The root user still has long-lived access keys
Fix it Disable insecure access modes and protocols - IAM.5
Console users without MFA are one phish from compromise
Fix it Enable MFA for root and IAM users - IAM.6
The root user is not protected by hardware MFA
Fix it Enable MFA for root and IAM users - IAM.7
The IAM password policy is too weak
Fix it Rotate and remove stale IAM credentials - IAM.8
Unused IAM keys and passwords are waiting to be leaked
Fix it Rotate and remove stale IAM credentials - IAM.9
The root user can sign in without MFA
Fix it Enable MFA for root and IAM users - IAM.10
IAM user password policies should be strong (PCI DSS)
Fix it Rotate and remove stale IAM credentials - IAM.19
MFA should be enabled for all IAM users
Fix it Enable MFA for root and IAM users - IAM.21
Wildcard permissions grant far more access than intended
Fix it Enforce IAM least privilege - IAM.22
IAM credentials unused for 45 days should be removed
Fix it Rotate and remove stale IAM credentials - IAM.26
Expired IAM-managed SSL/TLS certs should be removed
Fix it Manage and renew TLS certificates - IAM.27
Identities should not have AWSCloudShellFullAccess attached
Fix it Enforce IAM least privilege - IAM.28
No Access Analyzer is watching for unintended external access
Fix it Enable AWS security tooling (Config, Access Analyzer, SSM)
Inspector · 4
- Inspector.1
EC2 is not being scanned for vulnerabilities
Fix it Enable threat detection and vulnerability scanning - Inspector.2
Container images are not scanned by Inspector
Fix it Enable threat detection and vulnerability scanning - Inspector.3
Lambda code is not scanned by Inspector
Fix it Enable threat detection and vulnerability scanning - Inspector.4
Lambda is not fully covered by Inspector
Fix it Enable threat detection and vulnerability scanning
Kinesis · 2
- Kinesis.1
Kinesis streams should be encrypted at rest
Fix it Encrypt other services at rest (queues, streams, logs, ML) - Kinesis.3
Kinesis streams should have adequate retention
Fix it Configure backups and retention
KMS · 5
- KMS.1
IAM policies should not allow decrypt on all KMS keys
Fix it Manage KMS encryption keys - KMS.2
Decrypt is granted on all KMS keys
Fix it Manage KMS encryption keys - KMS.3
A KMS key is scheduled for deletion and will take data with it
Fix it Manage KMS encryption keys - KMS.4
KMS key rotation should be enabled
Fix it Manage KMS encryption keys - KMS.5
A KMS key policy allows public access
Fix it Manage KMS encryption keys
Lambda · 4
- Lambda.1
A Lambda resource policy allows public invocation
Fix it Disable insecure access modes and protocols - Lambda.2
Lambdas run on deprecated, unpatched runtimes
Fix it Keep software and engines patched - Lambda.3
Lambda functions should be in a VPC
Fix it Move resources into private networks (VPC isolation) - Lambda.5
VPC Lambda functions should span multiple AZs
Fix it Deploy across multiple Availability Zones
Macie · 2
- Macie.1
Sensitive data in S3 is not being discovered
Fix it Enable threat detection and vulnerability scanning - Macie.2
Macie automated sensitive data discovery is off
Fix it Enable threat detection and vulnerability scanning
MSK · 5
- MSK.1
MSK should encrypt in transit among broker nodes
Fix it Enforce TLS on database and cache connections - MSK.3
MSK Connect connectors encrypted in transit
Fix it Enforce TLS on database and cache connections - MSK.4
An MSK cluster allows public access
Fix it Block public access to AWS resources - MSK.5
MSK connectors should have logging
Fix it Enable application and API logging - MSK.6
MSK clusters should disable unauthenticated access
Fix it Require authentication on data and API services
Neptune · 7
- Neptune.1
Neptune clusters should encrypt at rest
Fix it Encrypt AWS databases at rest - Neptune.2
Neptune clusters should export audit logs to CW
Fix it Harden database auth, ports and access - Neptune.3
A Neptune snapshot is shared publicly
Fix it Configure backups and retention - Neptune.5
Neptune clusters should have automated backups
Fix it Configure backups and retention - Neptune.6
Neptune snapshots should be encrypted at rest
Fix it Encrypt AWS databases at rest - Neptune.7
Neptune clusters should have IAM DB auth
Fix it Harden database auth, ports and access - Neptune.9
Neptune clusters should span multiple AZs
Fix it Deploy across multiple Availability Zones
NetworkFirewall · 8
- NetworkFirewall.1
Firewalls should span multiple AZs
Fix it Deploy across multiple Availability Zones - NetworkFirewall.2
Network Firewall logging should be enabled
Fix it Enable network and edge logging (LB, WAF, firewall, DNS) - NetworkFirewall.3
Policies should have >= 1 rule group
Fix it Protect APIs and edge with WAF - NetworkFirewall.4
Default stateless action (full packets)
Fix it Protect APIs and edge with WAF - NetworkFirewall.5
Default stateless action (fragmented)
Fix it Protect APIs and edge with WAF - NetworkFirewall.6
Stateless rule groups should not be empty
Fix it Protect APIs and edge with WAF - NetworkFirewall.9
Firewalls should have deletion protection
Fix it Protect APIs and edge with WAF - NetworkFirewall.10
Firewalls should have subnet change protection
Fix it Protect APIs and edge with WAF
Opensearch · 9
- Opensearch.1
OpenSearch domains should encrypt at rest
Fix it Encrypt AWS databases at rest - Opensearch.2
An OpenSearch domain is reachable from the public internet
Fix it Move resources into private networks (VPC isolation) - Opensearch.3
OpenSearch should encrypt node-to-node traffic
Fix it Encrypt AWS databases at rest - Opensearch.4
OpenSearch error logging to CW should be enabled
Fix it Enable database audit and log exports - Opensearch.5
OpenSearch domains should have audit logging
Fix it Enable database audit and log exports - Opensearch.6
OpenSearch domains should have >= 3 data nodes
Fix it Deploy across multiple Availability Zones - Opensearch.7
OpenSearch has no fine-grained access control
Fix it Harden database auth, ports and access - Opensearch.8
OpenSearch should use latest TLS policy
Fix it Enforce TLS on APIs and search domains - Opensearch.10
OpenSearch should have latest software update
Fix it Keep software and engines patched
RDS · 39
- RDS.1
An RDS snapshot is shared publicly
Fix it Configure backups and retention - RDS.2
An RDS instance is publicly accessible from the internet
Fix it Block public access to AWS resources - RDS.3
RDS DB instances should be encrypted at rest
Fix it Encrypt AWS databases at rest - RDS.4
RDS snapshots should be encrypted at rest
Fix it Encrypt AWS databases at rest - RDS.5
RDS DB instances should use multiple AZs
Fix it Deploy across multiple Availability Zones - RDS.6
RDS lacks enhanced monitoring
Fix it Enable RDS Enhanced Monitoring - RDS.7
RDS clusters should have deletion protection
Fix it Enable deletion and termination protection - RDS.8
RDS DB instances should have deletion protection
Fix it Enable deletion and termination protection - RDS.9
RDS engine logs are not shipped to CloudWatch
Fix it Enable database audit and log exports - RDS.10
RDS relies on long-lived database passwords
Fix it Harden database auth, ports and access - RDS.11
RDS instances should have automatic backups
Fix it Configure backups and retention - RDS.12
IAM auth should be configured for RDS clusters
Fix it Harden database auth, ports and access - RDS.13
RDS is not receiving automatic minor security patches
Fix it Keep software and engines patched - RDS.14
Aurora has no backtracking safety net
Fix it Enable Aurora MySQL backtracking - RDS.15
The RDS or Aurora cluster is single-AZ
Fix it Deploy across multiple Availability Zones - RDS.19
RDS cluster event notification subscriptions
Fix it Configure event notifications and subscriptions - RDS.20
RDS instance event notification subscriptions
Fix it Configure event notifications and subscriptions - RDS.21
RDS parameter-group event notifications
Fix it Configure event notifications and subscriptions - RDS.22
RDS security-group event notifications
Fix it Configure event notifications and subscriptions - RDS.23
RDS runs on a well-known default port
Fix it Harden security groups and restrict ingress - RDS.24
RDS uses a default admin username
Fix it Harden database auth, ports and access - RDS.25
RDS instances should use a custom admin username
Fix it Harden database auth, ports and access - RDS.26
RDS instances should be in a backup plan
Fix it Configure backups and retention - RDS.27
No alerts on RDS failovers or changes
Fix it Configure event notifications and subscriptions - RDS.34
Aurora MySQL clusters should export audit logs to CW
Fix it Harden database auth, ports and access - RDS.35
RDS clusters auto minor version upgrade
Fix it Keep software and engines patched - RDS.36
RDS MySQL accepts unencrypted connections
Fix it Enforce TLS on database and cache connections - RDS.37
Aurora PostgreSQL clusters should export logs to CW
Fix it Harden database auth, ports and access - RDS.38
RDS PostgreSQL should be encrypted in transit
Fix it Enforce TLS on database and cache connections - RDS.39
RDS MySQL should be encrypted in transit
Fix it Enforce TLS on database and cache connections - RDS.40
RDS SQL Server should export logs to CW
Fix it Enable application and API logging - RDS.41
RDS SQL Server should be encrypted in transit
Fix it Enforce TLS on database and cache connections - RDS.42
RDS MariaDB should export logs to CW
Fix it Enable application and API logging - RDS.43
RDS DB proxies should require TLS
Fix it Enforce TLS on database and cache connections - RDS.44
RDS MariaDB should be encrypted in transit
Fix it Enforce TLS on database and cache connections - RDS.45
Aurora MySQL audit logging is off
Fix it Enable database audit and log exports - RDS.46
An RDS instance sits in a public subnet with an internet route
Fix it Harden database auth, ports and access - RDS.50
RDS clusters should have adequate backup retention
Fix it Configure backups and retention - RDS.51
An Aurora MySQL global cluster runs an unsupported version
Fix it Keep software and engines patched
Redshift · 11
- Redshift.1
A Redshift cluster is publicly accessible
Fix it Block public access to AWS resources - Redshift.2
Connections to Redshift should be encrypted in transit
Fix it Enforce TLS on database and cache connections - Redshift.3
Redshift clusters should have automatic snapshots
Fix it Configure backups and retention - Redshift.4
Redshift clusters should have audit logging
Fix it Enable database audit and log exports - Redshift.6
Redshift should auto-upgrade major versions
Fix it Keep software and engines patched - Redshift.7
Redshift clusters should use enhanced VPC routing
Fix it Move resources into private networks (VPC isolation) - Redshift.8
Redshift should not use the default admin username
Fix it Harden database auth, ports and access - Redshift.10
Redshift clusters should be encrypted at rest
Fix it Encrypt AWS databases at rest - Redshift.15
Redshift accepts cluster-port traffic from anywhere
Fix it Harden security groups and restrict ingress - Redshift.16
Redshift subnet groups should span multiple AZs
Fix it Deploy across multiple Availability Zones - Redshift.18
Redshift clusters should have Multi-AZ enabled
Fix it Deploy across multiple Availability Zones
Route53 · 1
- Route53.2
DNS query logging is off
Fix it Enable network and edge logging (LB, WAF, firewall, DNS)
S3 · 17
- S3.1
Account-level S3 public access is not fully blocked
Fix it Block public access to AWS resources - S3.2
Public S3 buckets expose data to anyone on the internet
Fix it Block public access to AWS resources - S3.3
Buckets can be written to by anyone on the internet
Fix it Block public access to AWS resources - S3.5
S3 is accepting unencrypted HTTP requests
Fix it Require TLS for storage and remaining services - S3.6
Bucket policy grants broad access to other AWS accounts
Fix it Lock down S3 bucket policies that hand sensitive actions to other AWS accounts - S3.8
Buckets can still be made public; Block Public Access is off
Fix it Block public access to AWS resources - S3.9
No S3 access logs, so reads and writes go unaudited
Fix it Enable S3 access and object-level logging - S3.10
Versioned buckets should have lifecycle configurations
Fix it Configure lifecycle and versioning policies - S3.11
Buckets should have event notifications enabled
Fix it Configure event notifications and subscriptions - S3.12
ACLs should not be used to manage bucket access
Fix it Disable insecure access modes and protocols - S3.13
Buckets have no lifecycle rules and grow forever
Fix it Configure lifecycle and versioning policies - S3.15
Buckets should have Object Lock enabled
Fix it Enable Object Lock on S3 general purpose buckets - S3.17
Buckets should be encrypted at rest with KMS keys
Fix it Encrypt S3 object storage at rest - S3.19
An S3 access point can expose the bucket publicly
Fix it Block public access to AWS resources - S3.22
Buckets should log object-level write events
Fix it Enable S3 access and object-level logging - S3.23
Buckets should log object-level read events
Fix it Enable S3 access and object-level logging - S3.24
A Multi-Region Access Point can expose data publicly
Fix it Block public access to AWS resources
SageMaker · 16
- SageMaker.1
A SageMaker notebook has direct internet access
Fix it Harden SageMaker and ML workloads - SageMaker.2
A SageMaker notebook is not launched in a VPC
Fix it Harden SageMaker and ML workloads - SageMaker.3
Users have root access on a SageMaker notebook
Fix it Harden SageMaker and ML workloads - SageMaker.4
Endpoint variants should have > 1 instance
Fix it Harden SageMaker and ML workloads - SageMaker.5
Models should have network isolation enabled
Fix it Harden SageMaker and ML workloads - SageMaker.8
Notebook instances should run supported platforms
Fix it Harden SageMaker and ML workloads - SageMaker.9
Data quality jobs inter-container encryption
Fix it Harden SageMaker and ML workloads - SageMaker.10
Explainability jobs inter-container encryption
Fix it Harden SageMaker and ML workloads - SageMaker.11
Data quality jobs network isolation
Fix it Harden SageMaker and ML workloads - SageMaker.12
Model bias jobs network isolation
Fix it Harden SageMaker and ML workloads - SageMaker.13
Model quality jobs inter-container encryption
Fix it Harden SageMaker and ML workloads - SageMaker.14
Monitoring schedules network isolation
Fix it Harden SageMaker and ML workloads - SageMaker.15
Model bias jobs inter-container encryption
Fix it Harden SageMaker and ML workloads - SageMaker.16
Private registry for primary containers
Fix it Harden SageMaker and ML workloads - SageMaker.17
Feature group offline stores KMS encryption
Fix it Harden SageMaker and ML workloads - SageMaker.19
Private registry for multi-container pipelines
Fix it Harden SageMaker and ML workloads
SecretsManager · 4
- SecretsManager.1
Secrets are not rotated automatically
Fix it Manage secrets (rotation and hygiene) - SecretsManager.2
Rotation-configured secrets should rotate successfully
Fix it Manage secrets (rotation and hygiene) - SecretsManager.3
Stale unused secrets linger as a leak risk
Fix it Manage secrets (rotation and hygiene) - SecretsManager.4
Secrets lack a rotation schedule
Fix it Manage secrets (rotation and hygiene)
SNS · 1
- SNS.4
An SNS topic policy allows public access
Fix it Block public access to AWS resources
SQS · 2
- SQS.1
SQS messages are not encrypted at rest
Fix it Encrypt other services at rest (queues, streams, logs, ML) - SQS.3
An SQS queue policy allows public access
Fix it Block public access to AWS resources
SSM · 6
- SSM.1
Instances are not managed by Systems Manager, so no patching or audit
Fix it Enable AWS security tooling (Config, Access Analyzer, SSM) - SSM.2
Instances are missing security patches
Fix it Keep software and engines patched - SSM.3
SSM associations are non-compliant
Fix it Enable AWS security tooling (Config, Access Analyzer, SSM) - SSM.4
SSM documents can be shared publicly
Fix it Block public access to AWS resources - SSM.6
SSM Automation runs are not logged
Fix it Enable application and API logging - SSM.7
SSM documents can be shared publicly
Fix it Block public access to AWS resources
StepFunctions · 1
- StepFunctions.1
State machines should have logging on
Fix it Enable application and API logging
Transfer · 2
- Transfer.2
Transfer servers should not use FTP
Fix it Disable insecure access modes and protocols - Transfer.3
Transfer connectors should have logging
Fix it Enable application and API logging
WAF · 9
- WAF.1
WAF Classic global web ACL logging
Fix it Enable network and edge logging (LB, WAF, firewall, DNS) - WAF.2
WAF Classic regional rules should have a condition
Fix it Protect APIs and edge with WAF - WAF.3
WAF Classic regional rule groups should have a rule
Fix it Protect APIs and edge with WAF - WAF.4
WAF Classic regional web ACLs should have a rule
Fix it Protect APIs and edge with WAF - WAF.6
WAF Classic global rules should have a condition
Fix it Protect APIs and edge with WAF - WAF.7
WAF Classic global rule groups should have a rule
Fix it Protect APIs and edge with WAF - WAF.8
WAF Classic global web ACLs should have a rule
Fix it Protect APIs and edge with WAF - WAF.10
WAFv2 web ACLs should have a rule or rule group
Fix it Protect APIs and edge with WAF - WAF.11
WAFv2 web ACL logging should be enabled
Fix it Enable network and edge logging (LB, WAF, firewall, DNS)
WorkSpaces · 2
- WorkSpaces.1
WorkSpaces user volumes should be encrypted at rest
Fix it Encrypt EBS and EFS storage at rest - WorkSpaces.2
WorkSpaces root volumes should be encrypted at rest
Fix it Encrypt EBS and EFS storage at rest
Microsoft Defender for Cloud — Azure
Azure security recommendations we cover, 226 across 49 services, each cross-referenced to its Microsoft Cloud Security Benchmark (MCSB) control and a remediation lesson.
App Service · 4
-
App Service has no diagnostic logs, leaving no activity trail for investigation
Fix it Turn on diagnostic logging for Azure resources -
A Function app still answers plain HTTP
Fix it Enforce encryption in transit across Azure services -
A function app authenticates with stored credentials instead of a managed identity
Fix it Use managed identities instead of stored secrets -
An App Service web app still answers plain HTTP
Fix it Enforce encryption in transit across Azure services
Automation · 1
-
Unencrypted Automation account variables expose secrets and sensitive runbook data to anyone who can read them.
Fix it Encrypt Azure automation and configuration data
Azure API Management · 8
-
Unauthenticated API endpoints let attackers reach data through missing or broken access controls.
Fix it Harden Azure API Management - API endpoints that are unused should be disabled and removed from the Azure API Management service MCSB AM-3
Stale unused API endpoints stay exposed without current security coverage and widen the attack surface.
Fix it Harden Azure API Management -
Serving APIs over plain HTTP or WS exposes data in transit to interception and tampering.
Fix it Enforce encryption in transit across Azure services - API Management calls to API backends shouldn't bypass certificate thumbprint or name validation MCSB IM-4
Skipping backend certificate validation lets attackers impersonate backends in man-in-the-middle attacks.
Fix it Harden Azure API Management -
The direct management REST API bypasses Azure RBAC, authorisation and throttling, weakening the service.
Fix it Harden Azure API Management -
Secrets held inline in API Management miss Key Vault access control and rotation, raising leak risk.
Fix it Harden Azure API Management -
All-API subscription scope grants more access than needed and risks excessive data exposure.
Fix it Harden Azure API Management -
APIs not onboarded to Defender for APIs go unmonitored for runtime attacks and data exposure.
Fix it Harden Azure API Management
Azure App Configuration · 1
-
App Configuration on public endpoints risks leaking application settings and feature flags
Fix it Require private endpoints for Azure PaaS services
Azure App Service · 17
-
API apps reachable over plain HTTP let attackers eavesdrop on traffic in transit.
Fix it Enforce encryption in transit across Azure services -
A wildcard CORS policy lets any external site call your API app on a user's behalf.
Fix it Harden Azure App Service apps -
An unrestricted CORS configuration lets any domain interact with your web application.
Fix it Harden Azure App Service apps -
Without incoming client certificates, an API app cannot verify the callers reaching it.
Fix it Harden Azure App Service apps - FTPS should be required in API apps MCSB DP-3
Unencrypted FTP to API apps lets credentials and content be sniffed off the wire.
Fix it Enforce encryption in transit across Azure services - FTPS should be required in web apps MCSB DP-3
Permitting unencrypted FTP to web apps lets attackers intercept publishing credentials.
Fix it Enforce encryption in transit across Azure services -
Running an outdated Java runtime on API apps leaves known security flaws unpatched.
Fix it Harden Azure App Service apps -
Without a managed identity, API apps rely on stored credentials that can leak or be stolen.
Fix it Use managed identities instead of stored secrets -
Web apps without a managed identity must hold secrets that are easy to expose or misuse.
Fix it Use managed identities instead of stored secrets -
Without Defender for App Service, common web app attacks go undetected across your plans.
Fix it Enable Microsoft Defender for Cloud plans -
An outdated PHP runtime on API apps carries unpatched vulnerabilities attackers can target.
Fix it Harden Azure App Service apps -
Stale Python versions on API apps miss security fixes shipped in newer releases.
Fix it Harden Azure App Service apps -
Remote debugging opens inbound ports on API apps that broaden the attack surface.
Fix it Harden Azure App Service apps -
Active remote debugging on a web app exposes inbound ports that should stay closed.
Fix it Harden Azure App Service apps -
Old TLS versions on API apps carry known cryptographic weaknesses attackers can exploit.
Fix it Enforce encryption in transit across Azure services -
Serving web apps over legacy TLS exposes traffic to known cipher and downgrade attacks.
Fix it Enforce encryption in transit across Azure services -
Not requesting client certificates lets any unauthenticated client reach the web app.
Fix it Harden Azure App Service apps
Azure Arc-enabled Kubernetes · 2
-
Without the Azure Policy extension you cannot audit or enforce security guardrails across Arc-connected clusters.
Fix it Harden the AKS control plane -
Without the Defender extension, Arc-connected clusters get no run-time threat detection on their control plane.
Fix it Enable Microsoft Defender for Cloud plans
Azure Container Registry · 3
-
Without a customer-managed key you cannot meet compliance requirements that mandate control over registry encryption keys.
Fix it Harden Azure Container Registry -
A registry open to the whole internet is exposed to untrusted hosts that could pull or tamper with images.
Fix it Harden Azure Container Registry -
Without private link, registry traffic traverses public endpoints and is exposed to data leakage risks.
Fix it Harden Azure Container Registry
Azure Cosmos DB · 4
-
Without customer-managed keys you cannot independently control or revoke Cosmos DB data encryption
Fix it Encrypt Azure data at rest, including customer-managed keys -
Key-based access to Cosmos DB bypasses centralised identity controls and cannot be revoked cleanly when compromised.
Fix it Require Microsoft Entra authentication -
A Cosmos DB account exposed to the public internet is open to untrusted network probing
Fix it Harden Azure Cosmos DB -
Cosmos DB reachable over public endpoints widens the data exfiltration surface
Fix it Harden Azure Cosmos DB
Azure Data Lake Analytics · 1
-
Missing Data Lake Analytics logs leave job activity invisible to security investigations
Fix it Turn on diagnostic logging for Azure resources
Azure Data Lake Store · 1
-
Without diagnostic logs you cannot reconstruct activity on Data Lake Store after an incident
Fix it Turn on diagnostic logging for Azure resources
Azure Database for MySQL · 6
- (Enable if required) MySQL servers should use customer-managed keys to encrypt data at rest MCSB DP-5
Without customer-managed keys you cannot control or revoke the keys protecting MySQL data
Fix it Harden Azure MySQL and PostgreSQL -
Missing an Entra administrator forces reliance on weaker local database credentials
Fix it Harden Azure MySQL and PostgreSQL -
Connections to MySQL can travel unencrypted, exposing data to interception
Fix it Harden Azure MySQL and PostgreSQL -
Without geo-redundant backups a regional outage can cause permanent MySQL data loss
Fix it Harden Azure MySQL and PostgreSQL -
Without a private endpoint MySQL traffic crosses the public network
Fix it Harden Azure MySQL and PostgreSQL -
Public network access leaves MySQL servers reachable for attack from the internet
Fix it Harden Azure MySQL and PostgreSQL
Azure Database for PostgreSQL · 6
- (Enable if required) PostgreSQL servers should use customer-managed keys to encrypt data at rest MCSB DP-5
Without customer-managed keys you cannot control or revoke the keys protecting PostgreSQL data
Fix it Harden Azure MySQL and PostgreSQL -
Missing an Entra administrator forces reliance on weaker local database credentials
Fix it Harden Azure MySQL and PostgreSQL -
Connections to PostgreSQL can travel unencrypted, exposing data to interception
Fix it Harden Azure MySQL and PostgreSQL -
Without geo-redundant backups a regional outage can cause permanent PostgreSQL data loss
Fix it Harden Azure MySQL and PostgreSQL -
Without a private endpoint PostgreSQL traffic crosses the public network
Fix it Harden Azure MySQL and PostgreSQL -
Public network access leaves PostgreSQL servers reachable for attack from the internet
Fix it Harden Azure MySQL and PostgreSQL
Azure Database for PostgreSQL flexible server · 11
-
Allowing all Azure services bypasses isolation and opens access from other tenants
Fix it Harden Azure MySQL and PostgreSQL -
Allowing local passwords alongside Entra weakens centralised identity control
Fix it Harden Azure MySQL and PostgreSQL -
Without connection throttling the server is open to brute-force and denial-of-service floods
Fix it Harden Azure MySQL and PostgreSQL -
Short log retention lets attackers wait out the window in which evidence survives
Fix it Harden Azure MySQL and PostgreSQL -
Excluding privilege and schema changes from audit logs hides malicious activity
Fix it Harden Azure MySQL and PostgreSQL -
A weaker audit log level can suppress security-relevant events from the record
Fix it Harden Azure MySQL and PostgreSQL -
Without statement logging executed SQL goes unrecorded for investigation
Fix it Harden Azure MySQL and PostgreSQL - pgaudit.log_statement_once should be set to "on" for Azure Database for PostgreSQL Servers MCSB LT-3
Inconsistent statement logging leaves gaps in the audit trail
Fix it Harden Azure MySQL and PostgreSQL -
Without a configured private endpoint database traffic traverses the public internet
Fix it Harden Azure MySQL and PostgreSQL -
A public IP lets attackers scan and brute-force the PostgreSQL server directly
Fix it Harden Azure MySQL and PostgreSQL -
Clients can connect without TLS, leaving credentials and queries open to interception
Fix it Harden Azure MySQL and PostgreSQL
Azure Event Grid · 2
-
Event Grid domains on public endpoints expose event traffic to data leakage
Fix it Require private endpoints for Azure PaaS services -
Publicly reachable Event Grid topics broaden the surface for intercepting event data
Fix it Require private endpoints for Azure PaaS services
Azure Functions · 7
-
Function App API endpoints without authentication can leak sensitive data to anonymous callers.
Fix it Harden Azure Function apps -
Allowing all origins to call a function app widens its exposure to cross-site abuse.
Fix it Harden Azure Function apps - FTPS should be required in function apps MCSB DP-3
Allowing plain FTP to function apps exposes deployment credentials and code to interception.
Fix it Enforce encryption in transit across Azure services -
Disabling client certificates lets unverified clients reach the function app directly.
Fix it Harden Azure Function apps -
Leaving remote debugging on a function app keeps inbound debug ports needlessly open.
Fix it Harden Azure Function apps -
Function apps on outdated TLS remain open to downgrade and protocol weakness attacks.
Fix it Enforce encryption in transit across Azure services -
Dormant HTTP-triggered Function endpoints linger unpatched and broaden the exposed attack surface.
Fix it Harden Azure Function apps
Azure Key Vault · 1
-
Without Key Vault diagnostic logs, access to your secrets and keys cannot be reconstructed after a breach.
Fix it Turn on diagnostic logging for Azure resources
Azure Kubernetes Service · 18
-
Clusters without the Defender profile collect no security event data and miss run-time threat alerts.
Fix it Enable Microsoft Defender for Cloud plans - Azure Kubernetes Service clusters should have the Azure Policy add-on for Kubernetes installed MCSB PV-2
Without the Azure Policy add-on, Defender cannot audit or enforce in-cluster hardening and compliance.
Fix it Harden the AKS control plane -
Known CVEs in images already running in your clusters expand the live attack surface of containerised workloads.
Fix it Run vulnerability assessment across Azure -
Containers without resource limits can exhaust node CPU and memory, enabling denial-of-service against the cluster.
Fix it Enforce AKS pod security -
Pulling images from unknown registries can introduce malicious or vulnerable code into the cluster.
Fix it Enforce AKS pod security -
Allowing privilege escalation lets a container process gain more rights than its parent and approach root on the node.
Fix it Enforce AKS pod security -
Pods that share the host process ID or IPC namespace can escalate privileges outside the container boundary.
Fix it Enforce AKS pod security -
Without diagnostic logs you cannot reconstruct cluster activity trails to investigate a security incident.
Fix it Turn on diagnostic logging for Azure resources -
A writable root filesystem lets an attacker drop malicious binaries into a running container at run-time.
Fix it Enforce AKS pod security -
An unrestricted Kubernetes API server is reachable from any network, widening the attack surface for cluster takeover.
Fix it Harden the AKS control plane -
Allowing plain HTTP ingress exposes cluster traffic to network-layer eavesdropping and tampering.
Fix it Enforce encryption in transit across Azure services -
Auto-mounted API credentials let a compromised pod issue commands against the Kubernetes API server.
Fix it Enforce AKS pod security -
Using the default namespace weakens isolation and risks unauthorised access to shared cluster resources.
Fix it Enforce AKS pod security -
Granting broad Linux capabilities widens the container attack surface beyond what the workload needs.
Fix it Enforce AKS pod security - Privileged containers should be avoided MCSB PV-2
Privileged containers hold all host root capabilities and serve as a ready entry point for host compromise.
Fix it Enforce AKS pod security -
Without Kubernetes RBAC, permissions cannot be scoped and users gain broad access to cluster resources.
Fix it Apply least-privilege RBAC on Azure subscriptions -
A container running as root runs as root on the host, making any misconfiguration far easier to exploit.
Fix it Enforce AKS pod security -
Out-of-date AKS-managed system pods carry known CVEs that an attacker can exploit until the cluster is upgraded.
Fix it Keep Azure machines patched
Azure Local · 4
-
Unencrypted OS and data volumes expose all stored data if a disk is removed or the host is physically accessed.
Fix it Encrypt Azure data at rest, including customer-managed keys -
Inconsistent WDAC enforcement across a cluster lets unsigned or malicious code run on whichever node is weakest.
Fix it Apply guest configuration baselines -
Azure Local hosts that miss Secured-core hardening lack the firmware and boot protections that block low-level attacks.
Fix it Enable secure boot and attestation -
Unprotected Azure Local host and VM networking exposes east-west traffic to interception and lateral movement.
Fix it Protect Azure networks with DDoS and firewalls
Azure Logic Apps · 2
-
Logic App API endpoints without authentication expose workflows and data to unauthorised access.
Fix it Harden Azure API Management -
Idle Logic App API endpoints remain live without recent security updates and invite abuse.
Fix it Harden Azure API Management
Azure Machine Learning · 2
-
Service-managed keys leave you unable to control or revoke encryption of machine learning data
Fix it Encrypt Azure data at rest, including customer-managed keys -
Public workspace endpoints let training data and models leak across the internet
Fix it Require private endpoints for Azure PaaS services
Azure Network Watcher · 1
- Network Watcher should be enabled MCSB LT-4
Without Network Watcher, you lack the flow logs and diagnostics needed to investigate network-level incidents.
Fix it Turn on diagnostic logging for Azure resources
Azure SignalR Service · 1
-
SignalR without private link keeps real-time messaging exposed on public networks
Fix it Require private endpoints for Azure PaaS services
Azure SQL Database · 8
- All advanced threat protection types should be enabled in SQL server advanced data security settings MCSB LT-1
Disabling threat protection types leaves SQL injection and anomalous activity undetected on your servers
Fix it Harden Azure SQL Database -
Short audit retention means forensic logs may be purged before an incident is detected and investigated
Fix it Retain Azure audit and activity logs - Auditing on SQL server should be enabled MCSB LT-3
Without server auditing there is no record of database activity to investigate breaches or misuse
Fix it Turn on diagnostic logging for Azure resources -
Allowing legacy TLS lets clients connect over protocols with known weaknesses, exposing data in transit
Fix it Enforce encryption in transit across Azure services -
Without private endpoints, database traffic traverses public network paths instead of staying on the backbone
Fix it Require private endpoints for Azure PaaS services -
No Entra administrator forces reliance on local logins and blocks centralised, auditable identity management
Fix it Require Microsoft Entra authentication -
Without vulnerability assessment configured, database misconfigurations and excessive permissions go undiscovered
Fix it Run vulnerability assessment across Azure -
Relying on platform-managed keys removes the control and separation of duties some compliance regimes demand
Fix it Harden Azure SQL encryption
Azure SQL Managed Instance · 4
-
Disabling threat protection types leaves SQL injection and anomalous activity undetected on managed instances
Fix it Harden Azure SQL Database -
A public endpoint on a managed instance widens the attack surface beyond the virtual network and private links
Fix it Restrict public network access to Azure databases -
Without vulnerability assessment on managed instances, weak baselines and unprotected data stay invisible
Fix it Run vulnerability assessment across Azure -
Without a customer-managed TDE key you lose control over the protector and HSM-backed key separation
Fix it Harden Azure SQL encryption
Azure Storage · 5
- Access to storage accounts with firewall and virtual network configurations should be restricted MCSB NS-2
Storage accounts open to all networks let attackers reach your data from any public IP
Fix it Harden Azure Storage accounts -
Storage accounts reachable over public endpoints can be enumerated and exfiltrated without private network isolation.
Fix it Require private endpoints for Azure PaaS services -
Classic deployment model storage accounts lack RBAC, managed identity and modern auditing protections.
Fix it Harden Azure Storage accounts -
Shared key authorisation hands out long-lived account secrets that bypass Microsoft Entra identity controls.
Fix it Harden Azure Storage accounts -
Storage accounts open to any public IP let attackers reach data instead of only trusted virtual networks.
Fix it Harden Azure Storage accounts
Azure Synapse Analytics · 1
-
Permitting local SQL authentication alongside Entra weakens centralised identity control on Synapse workspaces
Fix it Require Microsoft Entra authentication
Azure Virtual Machines · 4
- All network ports should be restricted on network security groups associated to your virtual machine MCSB NS-1
Overly permissive NSG inbound rules let any internet host probe and attack your VMs
Fix it Restrict virtual machine network exposure -
IP forwarding lets a compromised VM intercept and reroute traffic meant for other hosts
Fix it Restrict virtual machine network exposure -
Exposed risky ports give attackers a direct route into your machines
Fix it Restrict virtual machine network exposure -
Internal VMs without an NSG allow unchecked lateral movement once an attacker is inside the network
Fix it Restrict virtual machine network exposure
Azure Virtual Network · 3
-
Subnets without an NSG leave every resource in them open to unfiltered network traffic
Fix it Restrict virtual machine network exposure -
Public-facing virtual networks without DDoS protection can be knocked offline by volumetric attacks
Fix it Protect Azure networks with DDoS and firewalls -
Virtual networks without a firewall lack edge filtering against inbound and outbound threats
Fix it Protect Azure networks with DDoS and firewalls
Batch · 1
-
Batch accounts without logging leave investigators blind to how compute jobs were created or tampered with.
Fix it Turn on diagnostic logging for Azure resources
Compute · 9
-
Endpoint protection is installed but unhealthy or out of date
Fix it Ensure endpoint protection on Azure machines -
Machines have no anti-malware endpoint protection installed
Fix it Ensure endpoint protection on Azure machines -
Machines lack the Guest Configuration agent that audits in-guest security settings
Fix it Keep Azure machines patched -
An internet-facing VM has no network security group restricting traffic
Fix it Restrict virtual machine network exposure -
Machines have no vulnerability scanner, so known CVEs go undetected
Fix it Run vulnerability assessment across Azure - Management ports of virtual machines should be protected with just-in-time network access control MCSB NS-3
VM management ports are always open instead of just-in-time
Fix it Restrict virtual machine network exposure -
RDP or SSH management ports are open to the internet on a VM
Fix it Restrict virtual machine network exposure -
Machines are missing operating-system security updates that attackers commonly exploit
Fix it Keep Azure machines patched -
VM temp disks and caches are left unencrypted
Fix it Encrypt Azure data at rest, including customer-managed keys
Containers · 2
-
Container images in the registry carry unresolved known vulnerabilities
Fix it Run vulnerability assessment across Azure -
Misconfigured Docker hosts give attackers an easy path to break out of containers and compromise the underlying node.
Fix it Harden the AKS control plane
Databases · 2
-
Cosmos DB has no IP firewall, so it is reachable from any address
Fix it Restrict public network access to Azure databases -
Azure Database for PostgreSQL accepts connections from the public internet
Fix it Restrict public network access to Azure databases
Defender · 5
-
High-severity alert emails are off, so critical alerts are missed
Fix it Set a security contact and high-severity alerts -
Defender for SQL is off, so database attacks and anomalies are not detected
Fix it Enable Microsoft Defender for Cloud plans -
Defender for Servers is off, so VMs get no real-time threat detection or alerts
Fix it Enable Microsoft Defender for Cloud plans -
Defender for Storage is off, so malicious access to blobs goes undetected
Fix it Enable Microsoft Defender for Cloud plans -
No security contact email, so Defender breach notices reach nobody
Fix it Set a security contact and high-severity alerts
Event Hubs · 1
-
Disabled Event Hubs logging removes the audit trail needed to trace data exfiltration through the messaging layer.
Fix it Turn on diagnostic logging for Azure resources
Identity · 3
-
Too many subscription owners widen the blast radius of a compromise
Fix it Apply least-privilege RBAC on Azure subscriptions -
Blocked or deleted directory accounts still hold subscription access
Fix it Apply least-privilege RBAC on Azure subscriptions -
Guest or external accounts hold owner rights on a subscription
Fix it Apply least-privilege RBAC on Azure subscriptions
Key Vault · 8
-
Key Vault firewall is off, so any network can reach the vault endpoint
Fix it Put Azure Key Vault behind a private network - Azure Key Vaults should use private link MCSB NS-2
Key Vault is reachable over its public endpoint rather than private link
Fix it Put Azure Key Vault behind a private network -
A Key Vault key never expires, so it lives indefinitely
Fix it Harden Key Vault data protection -
Secrets that never expire give an attacker who steals them unlimited time to use the credentials undetected
Fix it Harden Key Vault data protection -
A deleted vault or key can be permanently purged before its retention ends
Fix it Harden Key Vault data protection -
Deleted vault objects cannot be recovered because soft delete is off
Fix it Harden Key Vault data protection -
Key vaults using legacy access policies grant coarse permissions, so attackers and over-privileged users can read every secret and key
Fix it Apply least-privilege RBAC on Azure subscriptions -
Long-lived certificates extend the period an attacker can abuse a compromised key before rotation.
Fix it Harden Key Vault data protection
Key Vault / Defender for Cloud · 1
-
Without Defender for Key Vault, unusual or malicious attempts to access your secrets go undetected.
Fix it Enable Microsoft Defender for Cloud plans
Logic Apps · 1
-
Logic Apps without diagnostic logs hide who triggered workflows, hampering incident investigation.
Fix it Turn on diagnostic logging for Azure resources
Microsoft Defender for APIs · 1
-
Without the APIs plan you miss discovery, threat detection and attack alerts for your published APIs.
Fix it Enable Microsoft Defender for Cloud plans
Microsoft Defender for Cloud · 8
-
Without owner notifications, subscription owners may not learn of a high-severity breach in time to act.
Fix it Set a security contact and high-severity alerts -
Without Defender for Azure Cosmos DB, injection and exfiltration attempts against your databases go undetected.
Fix it Enable Microsoft Defender for Cloud plans -
Without Defender for Containers, your Kubernetes clusters lack run-time threat detection and hardening.
Fix it Enable Microsoft Defender for Cloud plans -
Without Defender for DNS, malicious DNS queries from compromised resources are not detected.
Fix it Enable Microsoft Defender for Cloud plans -
Without Defender for open-source databases, anomalous access to your MySQL and PostgreSQL servers is not alerted.
Fix it Enable Microsoft Defender for Cloud plans -
Without Defender for Resource Manager, suspicious control-plane operations across your subscription go unnoticed.
Fix it Enable Microsoft Defender for Cloud plans -
With Defender for Servers off at the workspace, reporting machines miss protections you are already paying for.
Fix it Enable Microsoft Defender for Cloud plans -
Without Defender for SQL on machines, SQL servers hosted on your VMs lack threat detection and vulnerability assessment.
Fix it Enable Microsoft Defender for Cloud plans
Redis · 1
-
Azure Cache for Redis accepts unencrypted non-TLS connections
Fix it Enforce encryption in transit across Azure services
Service Bus · 1
-
Service Bus without logging gives no record of message access, so abuse of the queue goes undetected.
Fix it Turn on diagnostic logging for Azure resources
Service Fabric · 2
- Service Fabric clusters should have the ClusterProtectionLevel property set to EncryptAndSign MCSB DP-3
Node-to-node traffic that is not encrypted and signed can be intercepted or forged within the cluster.
Fix it Enforce encryption in transit across Azure services -
Client authentication outside Microsoft Entra ID bypasses central identity governance and conditional access.
Fix it Require Microsoft Entra authentication
SQL · 3
-
Azure SQL Database is reachable from any network rather than a private endpoint
Fix it Restrict public network access to Azure databases -
Open SQL vulnerability findings remain unresolved on your databases
Fix it Run vulnerability assessment across Azure -
Transparent Data Encryption is off on an Azure SQL database
Fix it Encrypt Azure data at rest, including customer-managed keys
Storage · 3
- (Enable if required) Storage accounts should use customer-managed key (CMK) for encryption MCSB DP-5
A regulated storage account relies on the platform key, not a customer-managed key
Fix it Encrypt Azure data at rest, including customer-managed keys -
Storage accepting plain HTTP lets requests and SAS tokens be intercepted
Fix it Harden Azure Storage accounts -
Anonymous public blob access can expose storage data to the internet
Fix it Harden Azure Storage accounts
Stream Analytics · 1
-
Without diagnostic logs there is no activity trail to reconstruct events when a Stream Analytics job is abused.
Fix it Turn on diagnostic logging for Azure resources
Subscription / RBAC · 13
-
Identities holding far more rights than they use enlarge the blast radius of any single compromise.
Fix it Apply least-privilege RBAC on Azure subscriptions -
Sign-in blocked owner accounts remain assigned and offer attackers a quiet route to full resource control.
Fix it Remove stale and external Azure identities -
Sign-in blocked accounts that keep read and write access give attackers an unmonitored path to your data.
Fix it Remove stale and external Azure identities -
Deprecated owner accounts that can no longer sign in are prime targets for takeover of the whole subscription.
Fix it Remove stale and external Azure identities -
External read accounts sit outside your tenant governance and can quietly exfiltrate subscription data.
Fix it Remove stale and external Azure identities -
External write accounts can modify resources without tenant oversight, widening your attack surface.
Fix it Remove stale and external Azure identities -
Guest owners are governed to lower standards than tenant identities yet hold full control of your resources.
Fix it Remove stale and external Azure identities -
Guest read access lives outside tenant governance and offers attackers an unmonitored view of your data.
Fix it Remove stale and external Azure identities -
Guest write access lets externally provisioned identities change resources without tenant oversight.
Fix it Remove stale and external Azure identities -
Identities idle for 45 days keep live permissions that an attacker can hijack without anyone noticing.
Fix it Keep Azure privileged access clean - Privileged roles should not have permanent access at the subscription and resource group level MCSB PA-2
Standing privileged assignments give attackers always-on admin access instead of brief just-in-time windows.
Fix it Keep Azure privileged access clean -
Service principals with Owner or Contributor rights become high-value, non-human targets for privilege abuse.
Fix it Apply least-privilege RBAC on Azure subscriptions -
A single subscription owner is a single point of failure for administrative access and recovery.
Fix it Apply least-privilege RBAC on Azure subscriptions
Virtual Machine Scale Sets · 4
-
Scale sets without diagnostic logs leave no forensic trail when instances are compromised and recycled.
Fix it Turn on diagnostic logging for Azure resources - Guest Attestation extension should be installed on supported Linux virtual machine scale sets MCSB PV-4
Without the Guest Attestation extension, boot-chain compromise of Linux scale-set instances cannot be detected.
Fix it Enable secure boot and attestation - Guest Attestation extension should be installed on supported Windows virtual machine scale sets MCSB PV-4
Windows scale sets without Guest Attestation cannot prove boot integrity, hiding firmware-level compromise.
Fix it Enable secure boot and attestation -
Scale-set instances built from an insecure baseline replicate the same exploitable misconfiguration at scale.
Fix it Apply guest configuration baselines
Virtual Machines · 28
- Adaptive application controls for defining safe applications should be enabled on your machines MCSB ES-2
Without application allowlisting, any unexpected or malicious binary can execute freely on your servers.
Fix it Ensure endpoint protection on Azure machines -
Stale allowlist rules either block legitimate apps or let newly observed unsafe binaries slip through unmonitored.
Fix it Ensure endpoint protection on Azure machines -
Password-based SSH leaves Linux VMs exposed to brute-force credential attacks that key pairs would defeat.
Fix it Require Microsoft Entra authentication -
VMs without Azure Backup have no recovery point, so ransomware or accidental deletion means permanent data loss.
Fix it Protect Azure resources with backup -
Misconfigured endpoint detection silently degrades protection, so advanced threats on the VM go unseen.
Fix it Ensure endpoint protection on Azure machines -
VMs without an EDR solution have no means to detect, investigate or respond to advanced endpoint threats.
Fix it Ensure endpoint protection on Azure machines -
Without file integrity monitoring, tampering of critical files and registry keys by an intruder passes unnoticed.
Fix it Enable file integrity monitoring -
Missing Guest Attestation on Linux VMs means rootkit or bootkit tampering of the boot chain stays invisible.
Fix it Enable secure boot and attestation -
Without Guest Attestation, a Windows VM cannot attest its boot integrity, masking bootkit infection.
Fix it Enable secure boot and attestation -
Unencrypted Linux VM disks, caches and temp data expose everything if underlying storage is accessed out of band.
Fix it Encrypt Azure data at rest, including customer-managed keys -
Without kernel module signature validation, malicious or unauthorised modules can load and run in kernel mode.
Fix it Enable secure boot and attestation -
Untrusted boot components on Linux VMs are a classic vector for persistent rootkit and bootkit infection.
Fix it Enable secure boot and attestation -
Without Secure Boot, unsigned operating systems and drivers can load, enabling boot-level malware on Linux VMs.
Fix it Enable secure boot and attestation - Machines should be configured securely MCSB PV-4
Machines left off the CIS-aligned security baseline carry weak settings that attackers routinely exploit.
Fix it Apply guest configuration baselines -
Machines that never assess for missing updates drift out of patch compliance and quietly accumulate exploitable holes.
Fix it Keep Azure machines patched -
Pending security configuration updates are not active until reboot, leaving the machine exposed in the interim.
Fix it Apply guest configuration baselines -
Unresolved scanner findings are known, fixable weaknesses an attacker can chain into a full compromise.
Fix it Run vulnerability assessment across Azure -
Without Exploit Guard, Windows machines lack the attack-surface-reduction defences that block common malware behaviours.
Fix it Ensure endpoint protection on Azure machines -
Without Secure Boot, unauthorised changes to the Windows boot chain can install persistent boot-level malware.
Fix it Enable secure boot and attestation -
Missing system, security and critical updates leave machines open to the malware that routinely weaponises known patches.
Fix it Keep Azure machines patched -
Without encryption at host, temp disks and disk caches stay in cleartext on the underlying hypervisor storage.
Fix it Encrypt Azure data at rest, including customer-managed keys -
An unhealthy attestation status signals the boot chain may be compromised by a bootkit or rootkit.
Fix it Enable secure boot and attestation -
Guest Configuration without a managed identity falls back to weaker auth and cannot securely report compliance.
Fix it Use managed identities instead of stored secrets -
Without a virtual TPM, Measured Boot and other integrity features that detect boot tampering cannot operate.
Fix it Enable secure boot and attestation -
Linux machines off the Azure security baseline carry hardening gaps that attackers exploit for footholds.
Fix it Apply guest configuration baselines -
Windows machines off the Azure security baseline keep weak settings that broaden the attack surface.
Fix it Apply guest configuration baselines -
Unencrypted Windows VM disks, caches and temp data are readable if the underlying storage is accessed out of band.
Fix it Encrypt Azure data at rest, including customer-managed keys -
Web servers without current TLS expose traffic to interception and downgrade attacks over the network.
Fix it Enforce encryption in transit across Azure services
Click a control ID for its in-depth page (360 controls covered), or “Fix it” for the full remediation lesson.