Azure.Pillar.Security.L1

March 30, 2026 ยท View on GitHub

Microsoft Azure Well-Architected Framework - Security pillar Level 1 maturity baseline.

Rules

The following rules are included within the Azure.Pillar.Security.L1 baseline.

This baseline includes a total of 86 rules.

NameSynopsisSeverityMaturity
Azure.ACR.AdminUserThe local admin account allows depersonalized access to a container registry using a shared secret.CriticalL1
Azure.ACR.AuditLogsEnsure container registry audit diagnostic logs are enabled.ImportantL1
Azure.ADX.DiskEncryptionUse disk encryption for Azure Data Explorer (ADX) clusters.ImportantL1
Azure.ADX.ManagedIdentityConfigure Data Explorer clusters to use managed identities to access Azure resources securely.ImportantL1
Azure.AI.DisableLocalAuthAccess keys allow depersonalized access to Azure AI using a shared secret.ImportantL1
Azure.AI.ManagedIdentityConfigure managed identities to access Azure resources.ImportantL1
Azure.AKS.AuditLogsAKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads.ImportantL1
Azure.AKS.LocalAccountsEnforce named user accounts with RBAC assigned permissions.ImportantL1
Azure.AKS.ManagedAADUse AKS-managed Azure AD to simplify authorization and improve security.ImportantL1
Azure.AKS.ManagedIdentityConfigure AKS clusters to use managed identities for managing cluster infrastructure.ImportantL1
Azure.APIM.CiphersAPI Management should not accept weak or deprecated ciphers for client or backend communication.CriticalL1
Azure.APIM.HTTPBackendUnencrypted communication could allow disclosure of information to an untrusted party.CriticalL1
Azure.APIM.HTTPEndpointUnencrypted communication could allow disclosure of information to an untrusted party.ImportantL1
Azure.APIM.ManagedIdentityConfigure managed identities to access Azure resources.ImportantL1
Azure.APIM.ProtocolsAPI Management should only accept a minimum of TLS 1.2 for client and backend communication.CriticalL1
Azure.AppConfig.AuditLogsEnsure app configuration store audit diagnostic logs are enabled.ImportantL1
Azure.AppConfig.DisableLocalAuthAccess keys allow depersonalized access to App Configuration using a shared secret.ImportantL1
Azure.AppConfig.ReplicaLocationThe replication location determines the country or region where configuration data is stored and processed.ImportantL1
Azure.AppGw.SSLPolicyApplication Gateway should only accept a minimum of TLS 1.2.CriticalL1
Azure.AppGw.UseHTTPSApplication Gateways should only expose frontend HTTP endpoints over HTTPS.CriticalL1
Azure.AppInsights.LocalAuthLocal authentication allows depersonalized access to store telemetry in Application Insights using a shared identifier.CriticalL1
Azure.AppService.ManagedIdentityConfigure managed identities to access Azure resources.ImportantL1
Azure.AppService.MinTLSApp Service should not accept weak or deprecated transport protocols for client-server communication.CriticalL1
Azure.AppService.UseHTTPSUnencrypted communication could allow disclosure of information to an untrusted party.ImportantL1
Azure.AppService.WebSecureFtpWeb apps should disable insecure FTP and configure SFTP when required.ImportantL1
Azure.Automation.AuditLogsEnsure automation account audit diagnostic logs are enabled.ImportantL1
Azure.Automation.ManagedIdentityEnsure Managed Identity is used for authentication.ImportantL1
Azure.CDN.MinTLSAzure CDN endpoints should reject TLS versions older than 1.2.ImportantL1
Azure.ContainerApp.InsecureEnsure insecure inbound traffic is not permitted to the container app.ImportantL1
Azure.ContainerApp.ManagedIdentityEnsure managed identity is used for authentication.ImportantL1
Azure.Cosmos.MinTLSCosmos DB accounts should reject TLS versions older than 1.2.CriticalL1
Azure.Cosmos.MongoEntraIDMongoDB vCore clusters should have Microsoft Entra ID authentication enabled.CriticalL1
Azure.Cosmos.NoSQLLocalAuthAccess keys allow depersonalized access to Cosmos DB NoSQL API accounts using a shared secret.CriticalL1
Azure.EntraDS.NTLMDisable NTLM v1 for Microsoft Entra Domain Services.CriticalL1
Azure.EntraDS.RC4Disable RC4 encryption for Microsoft Entra Domain Services.CriticalL1
Azure.EntraDS.TLSDisable TLS v1 for Microsoft Entra Domain Services.CriticalL1
Azure.EventGrid.DisableLocalAuthAuthenticate publishing clients with Azure AD identities.ImportantL1
Azure.EventGrid.DomainTLSWeak or deprecated transport protocols for client-server communication introduce security vulnerabilities.CriticalL1
Azure.EventGrid.ManagedIdentityUse managed identities to deliver Event Grid Topic events.ImportantL1
Azure.EventGrid.NamespaceTLSWeak or deprecated transport protocols for client-server communication introduce security vulnerabilities.CriticalL1
Azure.EventGrid.TopicTLSWeak or deprecated transport protocols for client-server communication introduce security vulnerabilities.CriticalL1
Azure.EventHub.DisableLocalAuthAuthenticate Event Hub publishers and consumers with Entra ID identities.ImportantL1
Azure.EventHub.MinTLSWeak or deprecated transport protocols for client-server communication introduce security vulnerabilities.CriticalL1
Azure.FrontDoor.ManagedIdentityEnsure Front Door uses a managed identity to authorize access to Azure resources.ImportantL1
Azure.FrontDoor.MinTLSFront Door Classic instances should reject TLS versions older than 1.2.CriticalL1
Azure.IoTHub.MinTLSIoT Hubs should reject TLS versions older than 1.2.CriticalL1
Azure.KeyVault.AccessPolicyUse the principal of least privilege when assigning access to Key Vault.ImportantL1
Azure.KeyVault.LogsEnsure audit diagnostics logs are enabled to audit Key Vault access.ImportantL1
Azure.KeyVault.RBACKey Vaults should use Azure RBAC as the authorization system for the data plane.AwarenessL1
Azure.MariaDB.MinTLSAzure Database for MariaDB servers should reject TLS versions older than 1.2.CriticalL1
Azure.MariaDB.UseSSLAzure Database for MariaDB servers should only accept encrypted connections.CriticalL1
Azure.ML.DisableLocalAuthAzure Machine Learning compute resources should have local authentication methods disabled.CriticalL1
Azure.ML.UserManagedIdentityML workspaces should use user-assigned managed identity, rather than the default system-assigned managed identity.ImportantL1
Azure.MySQL.AADUse Entra ID authentication with Azure Database for MySQL databases.CriticalL1
Azure.MySQL.AADOnlyEnsure Entra ID only authentication is enabled with Azure Database for MySQL databases.ImportantL1
Azure.MySQL.MinTLSMySQL DB servers should reject TLS versions older than 1.2.CriticalL1
Azure.MySQL.UseSSLEnforce encrypted MySQL connections.CriticalL1
Azure.PostgreSQL.AADUse Entra ID authentication with Azure Database for PostgreSQL databases.CriticalL1
Azure.PostgreSQL.AADOnlyEnsure Entra ID only authentication is enabled with Azure Database for PostgreSQL databases.ImportantL1
Azure.PostgreSQL.MinTLSPostgreSQL DB servers should reject TLS versions older than 1.2.CriticalL1
Azure.PostgreSQL.UseSSLEnforce encrypted PostgreSQL connections.CriticalL1
Azure.Redis.EntraIDUse Entra ID authentication with cache instances.CriticalL1
Azure.Redis.LocalAuthAccess keys allow depersonalized access to Azure Cache for Redis using a shared secret.ImportantL1
Azure.Redis.MinTLSRedis Cache should reject TLS versions older than 1.2.CriticalL1
Azure.Redis.NonSslPortAzure Cache for Redis should only accept secure connections.CriticalL1
Azure.RedisEnterprise.MinTLSRedis Cache should reject TLS versions older than 1.2.CriticalL1
Azure.Search.ManagedIdentityConfigure managed identities to access Azure resources.ImportantL1
Azure.ServiceBus.AuditLogsEnsure namespaces audit diagnostic logs are enabled.ImportantL1
Azure.ServiceBus.DisableLocalAuthAuthenticate Service Bus publishers and consumers with Entra ID identities.ImportantL1
Azure.ServiceBus.MinTLSService Bus namespaces should reject TLS versions older than 1.2.ImportantL1
Azure.ServiceFabric.AADUse Entra ID client authentication for Service Fabric clusters.CriticalL1
Azure.ServiceFabric.ProtectionLevelNode to node communication that is not signed and encrypted may be susceptible to man-in-the-middle attacks.ImportantL1
Azure.SignalR.ManagedIdentityConfigure SignalR Services to use managed identities to access Azure resources securely.ImportantL1
Azure.SQL.AADUse Entra ID authentication with Azure SQL databases.CriticalL1
Azure.SQL.AADOnlyEnsure Entra ID only authentication is enabled with Azure SQL Database.ImportantL1
Azure.SQL.MinTLSAzure SQL Database servers should reject TLS versions older than 1.2.CriticalL1
Azure.SQL.TDEUse Transparent Data Encryption (TDE) with Azure SQL Database.CriticalL1
Azure.SQLMI.AADUse Azure Active Directory (AAD) authentication with Azure SQL Managed Instance.CriticalL1
Azure.SQLMI.AADOnlyEnsure Azure AD-only authentication is enabled with Azure SQL Managed Instance.ImportantL1
Azure.SQLMI.ManagedIdentityEnsure managed identity is used to allow support for Azure AD authentication.ImportantL1
Azure.Storage.LocalAuthAccess keys allow depersonalized access to Storage Accounts using a shared secret.ImportantL1
Azure.Storage.MinTLSStorage Accounts should not accept weak or deprecated transport protocols for client-server communication.CriticalL1
Azure.Storage.SecureTransferStorage accounts should only accept encrypted connections.ImportantL1
Azure.TrafficManager.ProtocolMonitor Traffic Manager web-based endpoints with HTTPS.ImportantL1
Azure.VM.ADEUse Azure Disk Encryption (ADE).ImportantL1
Azure.WebPubSub.ManagedIdentityConfigure Web PubSub Services to use managed identities to access Azure resources securely.ImportantL1