Azure.MCSB.v1

March 30, 2026 ยท View on GitHub

Rules for GA Azure features that align to the Microsoft Cloud Security Benchmark v1. This baseline is updated each release.

Controls

The following rules are included within the Azure.MCSB.v1 baseline.

This baseline includes a total of 146 rules.

NameSynopsisSeverity
Azure.ACR.AdminUserThe local admin account allows depersonalized access to a container registry using a shared secret.Critical
Azure.ACR.AnonymousAccessAnonymous pull access allows unidentified downloading of images and metadata from a container registry.Important
Azure.ACR.AuditLogsEnsure container registry audit diagnostic logs are enabled.Important
Azure.ACR.ContainerScanContainer images or their base images may have vulnerabilities discovered after they are built.Critical
Azure.ACR.ExportPolicyExport policy on Azure container registry may allow artifact exfiltration.Important
Azure.ACR.FirewallContainer Registry without restrictions can be accessed from any network location including the Internet.Important
Azure.ACR.ImageHealthRemove container images with known vulnerabilities.Critical
Azure.ADX.DiskEncryptionUse disk encryption for Azure Data Explorer (ADX) clusters.Important
Azure.ADX.ManagedIdentityConfigure Data Explorer clusters to use managed identities to access Azure resources securely.Important
Azure.ADX.PublicAccessAzure Data Explorer (ADX) clusters should have public network access disabled.Critical
Azure.AI.DisableLocalAuthAccess keys allow depersonalized access to Azure AI using a shared secret.Important
Azure.AI.ManagedIdentityConfigure managed identities to access Azure resources.Important
Azure.AI.PrivateEndpointsUse Private Endpoints to access Azure AI services accounts.Important
Azure.AI.PublicAccessRestrict access of Azure AI services to authorized virtual networks.Important
Azure.AKS.AuditLogsAKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads.Important
Azure.AKS.AuthorizedIPsRestrict access to API server endpoints to authorized IP addresses.Important
Azure.AKS.AutoUpgradeNew versions of Kubernetes are released regularly. Upgrading each release manually can add operational overhead without realizing equivalent value.Important
Azure.AKS.AzurePolicyAddOnConfigure Azure Kubernetes Service (AKS) clusters to use Azure Policy Add-on for Kubernetes.Important
Azure.AKS.AzureRBACUse Azure RBAC for Kubernetes Authorization with AKS clusters.Important
Azure.AKS.ContainerInsightsEnable Container insights to monitor AKS cluster workloads.Important
Azure.AKS.HttpAppRoutingDisable HTTP application routing add-on in AKS clusters.Important
Azure.AKS.LocalAccountsEnforce named user accounts with RBAC assigned permissions.Important
Azure.AKS.ManagedAADUse AKS-managed Azure AD to simplify authorization and improve security.Important
Azure.AKS.ManagedIdentityConfigure AKS clusters to use managed identities for managing cluster infrastructure.Important
Azure.AKS.NetworkPolicyAKS clusters without inter-pod network restrictions may be permit unauthorized lateral movement.Important
Azure.AKS.PlatformLogsAKS clusters should collect platform diagnostic logs to monitor the state of workloads.Important
Azure.AKS.SecretStoreDeploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault.Important
Azure.AKS.SecretStoreRotationEnable autorotation of Secrets Store CSI Driver secrets for AKS clusters.Important
Azure.AKS.UseRBACDeploy AKS cluster with role-based access control (RBAC) enabled.Important
Azure.AKS.VersionOlder versions of Kubernetes may have known bugs or security vulnerabilities, and may have limited support.Important
Azure.APIM.CiphersAPI Management should not accept weak or deprecated ciphers for client or backend communication.Critical
Azure.APIM.DefenderCloudAPIs published in Azure API Management should be onboarded to Microsoft Defender for APIs.Critical
Azure.APIM.EncryptValuesEncrypt all API Management named values with Key Vault secrets.Important
Azure.APIM.HTTPBackendUnencrypted communication could allow disclosure of information to an untrusted party.Critical
Azure.APIM.HTTPEndpointUnencrypted communication could allow disclosure of information to an untrusted party.Important
Azure.APIM.ManagedIdentityConfigure managed identities to access Azure resources.Important
Azure.APIM.ProtocolsAPI Management should only accept a minimum of TLS 1.2 for client and backend communication.Critical
Azure.AppConfig.AuditLogsEnsure app configuration store audit diagnostic logs are enabled.Important
Azure.AppConfig.DisableLocalAuthAccess keys allow depersonalized access to App Configuration using a shared secret.Important
Azure.AppConfig.SecretLeakSecrets stored as key values in an App Configuration Store may be leaked to unauthorized users.Critical
Azure.AppGw.SSLPolicyApplication Gateway should only accept a minimum of TLS 1.2.Critical
Azure.AppGw.UseHTTPSApplication Gateways should only expose frontend HTTP endpoints over HTTPS.Critical
Azure.AppGw.UseWAFInternet accessible Application Gateways should use protect endpoints with WAF.Critical
Azure.AppGw.WAFEnabledApplication Gateway Web Application Firewall (WAF) must be enabled to protect backend resources.Critical
Azure.AppService.ManagedIdentityConfigure managed identities to access Azure resources.Important
Azure.AppService.MinTLSApp Service should not accept weak or deprecated transport protocols for client-server communication.Critical
Azure.AppService.RemoteDebugDisable remote debugging on App Service apps when not in use.Important
Azure.AppService.UseHTTPSUnencrypted communication could allow disclosure of information to an untrusted party.Important
Azure.AppService.WebSecureFtpWeb apps should disable insecure FTP and configure SFTP when required.Important
Azure.Automation.AuditLogsEnsure automation account audit diagnostic logs are enabled.Important
Azure.Automation.EncryptVariablesAzure Automation variables should be encrypted.Important
Azure.Automation.ManagedIdentityEnsure Managed Identity is used for authentication.Important
Azure.BV.ImmutableEnsure immutability is configured to protect backup data.Important
Azure.CDN.HTTPUnencrypted communication could allow disclosure of information to an untrusted party.Important
Azure.CDN.MinTLSAzure CDN endpoints should reject TLS versions older than 1.2.Important
Azure.ContainerApp.InsecureEnsure insecure inbound traffic is not permitted to the container app.Important
Azure.ContainerApp.ManagedIdentityEnsure managed identity is used for authentication.Important
Azure.ContainerApp.PublicAccessEnsure public network access for Container Apps environment is disabled.Important
Azure.ContainerApp.RestrictIngressIP ingress restrictions mode should be set to allow action for all rules defined.Important
Azure.Cosmos.DefenderCloudEnable Microsoft Defender for Azure Cosmos DB.Critical
Azure.Cosmos.DisableMetadataWriteUse Entra ID identities for management place operations in Azure Cosmos DB.Important
Azure.Cosmos.MongoEntraIDMongoDB vCore clusters should have Microsoft Entra ID authentication enabled.Critical
Azure.Cosmos.NoSQLLocalAuthAccess keys allow depersonalized access to Cosmos DB NoSQL API accounts using a shared secret.Critical
Azure.Cosmos.PublicAccessAzure Cosmos DB should have public network access disabled.Critical
Azure.Defender.ApiEnable Microsoft Defender for APIs.Critical
Azure.Defender.AppServicesEnable Microsoft Defender for App Service.Critical
Azure.Defender.ArmEnable Microsoft Defender for Azure Resource Manager (ARM).Critical
Azure.Defender.ContainersEnable Microsoft Defender for Containers.Critical
Azure.Defender.CosmosDbEnable Microsoft Defender for Azure Cosmos DB.Critical
Azure.Defender.CspmEnable Microsoft Defender Cloud Security Posture Management Standard plan.Critical
Azure.Defender.DnsEnable Microsoft Defender for DNS.Critical
Azure.Defender.KeyVaultEnable Microsoft Defender for Key Vault.Critical
Azure.Defender.OssRdbEnable Microsoft Defender for open-source relational databases.Critical
Azure.Defender.ServersEnable Microsoft Defender for Servers.Critical
Azure.Defender.SQLEnable Microsoft Defender for SQL servers.Critical
Azure.Defender.SQLOnVMEnable Microsoft Defender for SQL servers on machines.Critical
Azure.Defender.StorageEnable Microsoft Defender for Storage.Critical
Azure.Defender.Storage.MalwareScanEnable Malware Scanning in Microsoft Defender for Storage.Critical
Azure.DefenderCloud.ProvisioningEnable auto-provisioning on to improve Microsoft Defender for Cloud insights.Important
Azure.EntraDS.TLSDisable TLS v1 for Microsoft Entra Domain Services.Critical
Azure.EventGrid.DisableLocalAuthAuthenticate publishing clients with Azure AD identities.Important
Azure.EventGrid.ManagedIdentityUse managed identities to deliver Event Grid Topic events.Important
Azure.EventGrid.TopicPublicAccessUse Private Endpoints to access Event Grid topics and domains.Important
Azure.EventHub.DisableLocalAuthAuthenticate Event Hub publishers and consumers with Entra ID identities.Important
Azure.EventHub.FirewallAccess to the namespace endpoints should be restricted to only allowed sources.Critical
Azure.EventHub.MinTLSWeak or deprecated transport protocols for client-server communication introduce security vulnerabilities.Critical
Azure.Firewall.PolicyModeDeny high confidence malicious IP addresses, domains and URLs.Critical
Azure.FrontDoor.LogsAudit and monitor access through Azure Front Door profiles.Important
Azure.FrontDoor.ManagedIdentityEnsure Front Door uses a managed identity to authorize access to Azure resources.Important
Azure.FrontDoor.MinTLSFront Door Classic instances should reject TLS versions older than 1.2.Critical
Azure.FrontDoor.UseWAFEnable Web Application Firewall (WAF) policies on each Front Door endpoint.Critical
Azure.FrontDoor.WAF.EnabledFront Door Web Application Firewall (WAF) policy must be enabled to protect back end resources.Critical
Azure.IoTHub.MinTLSIoT Hubs should reject TLS versions older than 1.2.Critical
Azure.KeyVault.AutoRotationPolicyKeys that become compromised may be used to spoof, decrypt, or gain access to sensitive data.Important
Azure.KeyVault.FirewallKey Vault should only accept explicitly allowed traffic.Important
Azure.KeyVault.LogsEnsure audit diagnostics logs are enabled to audit Key Vault access.Important
Azure.KeyVault.RBACKey Vaults should use Azure RBAC as the authorization system for the data plane.Awareness
Azure.ML.ComputeVnetAzure Machine Learning Computes should be hosted in a virtual network (VNet).Critical
Azure.ML.PublicAccessDisable public network access from a Azure Machine Learning workspace.Critical
Azure.ML.UserManagedIdentityML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity.Important
Azure.MySQL.AADUse Entra ID authentication with Azure Database for MySQL databases.Critical
Azure.MySQL.AADOnlyEnsure Entra ID only authentication is enabled with Azure Database for MySQL databases.Important
Azure.MySQL.MinTLSMySQL DB servers should reject TLS versions older than 1.2.Critical
Azure.MySQL.UseSSLEnforce encrypted MySQL connections.Critical
Azure.PostgreSQL.AADUse Entra ID authentication with Azure Database for PostgreSQL databases.Critical
Azure.PostgreSQL.AADOnlyEnsure Entra ID only authentication is enabled with Azure Database for PostgreSQL databases.Important
Azure.PostgreSQL.MinTLSPostgreSQL DB servers should reject TLS versions older than 1.2.Critical
Azure.PostgreSQL.UseSSLEnforce encrypted PostgreSQL connections.Critical
Azure.PublicIP.IsAttachedPublic IP addresses should be attached or cleaned up if not in use.Important
Azure.RBAC.CoAdministratorDelegate access to manage Azure resources using role-based access control (RBAC).Important
Azure.RBAC.LimitMGDelegationLimit Role-Base Access Control (RBAC) inheritance from Management Groups.Important
Azure.RBAC.LimitOwnerLimit the number of subscription Owners.Important
Azure.RBAC.PIMUse just-in-time (JiT) activation of roles instead of persistent role assignment.Important
Azure.RBAC.UseGroupsUse groups for assigning permissions instead of individual user accounts.Important
Azure.RBAC.UseRGDelegationUse RBAC assignments on resource groups instead of individual resources.Important
Azure.Redis.EntraIDUse Entra ID authentication with cache instances.Critical
Azure.Redis.LocalAuthAccess keys allow depersonalized access to Azure Cache for Redis using a shared secret.Important
Azure.Redis.MinTLSRedis Cache should reject TLS versions older than 1.2.Critical
Azure.Redis.NonSslPortAzure Cache for Redis should only accept secure connections.Critical
Azure.Redis.PublicNetworkAccessRedis cache should disable public network access.Critical
Azure.RedisEnterprise.MinTLSRedis Cache should reject TLS versions older than 1.2.Critical
Azure.RSV.ImmutableEnsure immutability is configured to protect backup data.Important
Azure.Search.ManagedIdentityConfigure managed identities to access Azure resources.Important
Azure.ServiceBus.DisableLocalAuthAuthenticate Service Bus publishers and consumers with Entra ID identities.Important
Azure.ServiceBus.MinTLSService Bus namespaces should reject TLS versions older than 1.2.Important
Azure.ServiceFabric.AADUse Entra ID client authentication for Service Fabric clusters.Critical
Azure.SignalR.ManagedIdentityConfigure SignalR Services to use managed identities to access Azure resources securely.Important
Azure.SQL.AADUse Entra ID authentication with Azure SQL databases.Critical
Azure.SQL.AuditingEnable auditing for Azure SQL logical server.Important
Azure.SQL.DefenderCloudEnable Microsoft Defender for Azure SQL logical server.Important
Azure.SQL.MinTLSAzure SQL Database servers should reject TLS versions older than 1.2.Critical
Azure.SQL.TDEUse Transparent Data Encryption (TDE) with Azure SQL Database.Critical
Azure.SQLMI.AADUse Azure Active Directory (AAD) authentication with Azure SQL Managed Instance.Critical
Azure.SQLMI.ManagedIdentityEnsure managed identity is used to allow support for Azure AD authentication.Important
Azure.Storage.BlobPublicAccessStorage Accounts should only accept authorized requests.Important
Azure.Storage.Defender.MalwareScanEnable Malware Scanning in Microsoft Defender for Storage.Critical
Azure.Storage.DefenderCloudEnable Microsoft Defender for Storage for storage accounts.Critical
Azure.Storage.LocalAuthAccess keys allow depersonalized access to Storage Accounts using a shared secret.Important
Azure.Storage.MinTLSStorage Accounts should not accept weak or deprecated transport protocols for client-server communication.Critical
Azure.Storage.SecureTransferStorage accounts should only accept encrypted connections.Important
Azure.VM.ADEUse Azure Disk Encryption (ADE).Important
Azure.VM.UpdatesEnsure automatic updates are enabled at deployment.Important
Azure.VM.UseManagedDisksVirtual machines (VMs) should use managed disks.Important
Azure.VMSS.PublicKeyUse SSH keys instead of common credentials to secure virtual machine scale sets against malicious activities.Important
Azure.VNET.UseNSGsVirtual network (VNET) subnets should have Network Security Groups (NSGs) assigned.Critical
Azure.WebPubSub.ManagedIdentityConfigure Web PubSub Services to use managed identities to access Azure resources securely.Important