Azure_compliance/control/check

Ensure server parameter 'audit_log_enabled' is set to 'ON' for MySQL Database Server
Description: Enable audit_log_enabled on MySQL Servers. Rationale: Enabling audit_log_enabled helps MySQL Database to log items such as connection att...
Tue, 22 Aug, 2023 at 5:49 AM
Ensure Virtual Machines are utilizing Managed Disks
Description: This check ensures that Azure Virtual Machines (VMs) are using Managed Disks for storage. Managed Disks provide high availability, durability,...
Tue, 13 Jan, 2026 at 1:43 PM
Ensure server parameter 'audit_log_events' has 'CONNECTION' set for MySQL Database Server
Description: Set audit_log_enabled to include CONNECTION on MySQL Servers. Rationale: Enabling CONNECTION helps MySQL Database to log items such as su...
Tue, 22 Aug, 2023 at 5:53 AM
Ensure That 'Firewalls & Networks' Is Limited to Use Selected Networks Instead of All Networks for CosmosDB
Description: Limiting your Cosmos DB to only communicate on whitelisted networks lowers its attack footprint.                 Rationale: Selecting certain...
Thu, 7 Sep, 2023 at 10:48 AM
Ensure an Azure Bastion Host Exists
Description: Azure Bastion provides secure RDP and SSH access to Virtual Machines directly through the Azure Portal using TLS over port 443. This prevents ...
Tue, 13 Jan, 2026 at 1:46 PM
Use Azure Active Directory (AAD) Client Authentication and Azure RBAC where possible.
Description: Azure Active Directory (now Microsoft Entra ID) provides identity-based authentication and Role-Based Access Control (RBAC) for managing acces...
Wed, 31 Dec, 2025 at 3:27 AM
Ensure that Network Watcher is 'Enabled' for Azure subscriptions
Description: Azure Network Watcher is a regional network monitoring and diagnostic service that provides visibility into network resources. It enables esse...
Tue, 13 Jan, 2026 at 1:50 PM
Ensure that Network Security Group Flow Log retention period is 'greater than 90 days'
Description: Network Security Group (NSG) Flow Logs capture information about inbound and outbound IP traffic for NSGs. These logs support threat detection...
Fri, 2 Jan, 2026 at 4:07 AM
Ensure that logging for Azure Key Vault is 'Enabled' .
Description: Azure Key Vault stores sensitive secrets, keys, and certificates used by applications and services. Logging must be enabled to capture all acc...
Wed, 31 Dec, 2025 at 3:38 AM
Ensure that HTTP(S) access from the Internet is evaluated and restricted .
Description: HTTP and HTTPS traffic coming from the Internet should be reviewed and restricted so that only required access is allowed. Only the ports and ...
Fri, 2 Jan, 2026 at 4:04 AM