Azure Storage Services Benchmark

Ensure 'Allowed Protocols' for Shared Access Signature (SAS) Tokens Are Restricted to HTTPS Only for Secrets and Keys
Profile Applicability:  Level 1 Description: Shared access signatures (SAS) provide limited access to Azure Storage resources. When generating a SAS token,...
Fri, 16 May, 2025 at 2:10 AM
Ensure that shared access signature (SAS) tokens expire within an hour for Secrets and Keys
Profile Applicability:  Level 1 Description:  Shared Access Signatures (SAS) provide delegated access to Azure Storage resources with fine-grained permissi...
Fri, 16 May, 2025 at 2:14 AM
Ensure stored access policies (SAP) are used when generating shared access signature (SAS) tokens
Profile Applicability:  Level 1 Description:  Stored Access Policies (SAP) are named policies that define constraints such as permissions and expiration ti...
Thu, 15 May, 2025 at 2:51 AM
Ensure Critical Data is Encrypted with Microsoft Managed Keys (MMK)
Profile Applicability:  Level 1 Description:  Microsoft Managed Keys (MMK) provide default encryption at rest for critical data stored in Azure services, m...
Thu, 15 May, 2025 at 2:55 AM
Ensure 'Versioning' is set to 'Enabled' on Azure Blob Storage storage accounts
Profile Applicability: Level 2 Description: Enabling blob versioning allows Azure to retain previous versions of blobs automatically. When versioning...
Thu, 15 May, 2025 at 2:57 AM
Ensure Critical Data is Encrypted with Customer Managed Keys (CMK)
Profile Applicability:  Level 2 Description:  Customer Managed Keys (CMK) enable organizations to have full control over the encryption keys used to protec...
Thu, 15 May, 2025 at 3:00 AM
Ensure locked immutability policies are used for containers storing business-critical blob data
Profile Applicability: Level 2 Description: This control enforces the use of locked immutability policies on Azure Blob Storage containers that store...
Thu, 15 May, 2025 at 3:01 AM
Ensure double encryption is used for Azure Data Box in high-security environments
Profile Applicability: Level 2 Description: Azure Data Box enables secure, large-scale offline data transfer to Azure. By default, it uses BitLocker ...
Thu, 15 May, 2025 at 3:05 AM
Ensure Public Network Access is Disabled
Profile Applicability:  Level 1 Description:  Disabling public network access on Azure resources, such as Storage Accounts, SQL servers, and other data ser...
Thu, 15 May, 2025 at 3:05 AM
Ensure Network Access Rules are Set to Deny-by-Default
Profile Applicability:  Level 1 Description:  Network Access Rules govern which IP addresses or networks can connect to Azure resources such as Storage Acc...
Thu, 15 May, 2025 at 3:09 AM