Azure_compliance/control/check

Ensure ‘User consent for applications’ Is Set To ‘Allow for Verified Publishers’
Description: The User consent for applications setting in Azure Active Directory (Azure AD) controls whether users can grant permissions to applications re...
Tue, 23 Dec, 2025 at 11:45 AM
Ensure That 'Guest users access restrictions' is set to 'Guest user access is restricted to properties and memberships of their own directory objects'
Description: This setting controls what guest users can see in Microsoft Entra ID. When it is set to “Guest user access is restricted to properties and mem...
Tue, 23 Dec, 2025 at 11:58 AM
Ensure that 'Guest invite restrictions' is set to "Only users assigned to specific admin roles can invite guest users" .
Description: This setting controls who can invite guest users. When set to “Only users assigned to specific admin roles can invite guest users,” only ap...
Tue, 23 Dec, 2025 at 12:12 PM
Ensure that 'Restrict user ability to access groups features in the Access Pane' is Set to 'Yes'
Description: This policy restricts users from accessing group management features in the Azure Active Directory (Azure AD) Access Pane. This helps to protec...
Mon, 7 Aug, 2023 at 6:37 AM
Ensure a Custom Role is Assigned Permissions for Administering Resource Locks
Description: Resource locking is a powerful protection mechanism that can prevent inadvertentmodification/deletion of resources within Azure subscriptions/...
Mon, 21 Aug, 2023 at 6:30 AM
Ensure that ‘Enable Infrastructure Encryption’ for Each Storage Account in Azure Storage is Set to ‘enabled’ (Automated)
Description: Infrastructure Encryption adds a second layer of encryption to Azure Storage accounts. It cannot be enabled on an existing storage account. To...
Fri, 26 Dec, 2025 at 5:53 AM
Ensure that 'Enable key rotation reminders' is enabled for each Storage Account
Description: Storage Account access keys are used by applications to authenticate and access data. Because these keys act like passwords, they should be ro...
Fri, 26 Dec, 2025 at 5:58 AM
Ensure Private Endpoints are used to access Storage Accounts
Description: This control ensures that Azure Storage Accounts are accessed through Private Endpoints, which provide private IP addresses within a virtual n...
Tue, 13 Jan, 2026 at 2:07 PM
Ensure a Custom Role is Assigned Permissions for Administering Resource Locks
Description: This control ensures that permissions for managing Azure resource locks are granted only through a custom role. Using a custom role limits ...
Tue, 23 Dec, 2025 at 1:07 PM
Ensure That Microsoft Defender for Databases Is Set To 'On'
Description: Microsoft Defender for Databases is a security feature in Microsoft Defender for Cloud that provides advanced threat protection for database s...
Fri, 26 Dec, 2025 at 3:13 AM