Azure Storage Services Benchmark

Ensure 'Cross Subscription Restore' is Set to 'Disabled' or 'Permanently Disabled' on Backup Vaults
Profile Applicability:  Level 1 Description:  Cross Subscription Restore (CSR) enables restoring backup data from a Recovery Services Vault in one Azure su...
Thu, 15 May, 2025 at 3:42 AM
Ensure 'SMB Channel Encryption' Is Set to 'AES-256-GCM' or Higher for SMB File Shares
Profile Applicability: Level 1 Description:  SMB channel encryption secures data transmitted between clients and Azure SMB file shares by encrypting the...
Thu, 15 May, 2025 at 3:57 AM
Ensure Customer-Managed Keys (CMK) Are Used to Encrypt Data at Rest on Azure Elastic SAN Volume Groups
Profile Applicability:  Level 2 Description:  Azure Elastic SAN volume groups support encryption at rest using either Microsoft-managed keys or Customer...
Thu, 15 May, 2025 at 4:03 AM
Ensure That 'Enable Key Rotation Reminders' Is Enabled for Each Storage Account
Profile Applicability:  Level 1 Description:  Key rotation reminders notify administrators when storage account access keys are nearing expiration or re...
Thu, 15 May, 2025 at 5:30 AM
Ensure Storage Explorer Is Using the Latest Version
Profile Applicability  Level 1 Description:  Azure Storage Explorer is a tool for managing Azure Storage resources. Ensuring that Storage Explorer is up...
Thu, 15 May, 2025 at 5:40 AM
Ensure Redundancy Is Set to 'Geo-Redundant Storage (GRS)' on Critical Azure Storage Accounts
Profile Applicability:  Level 2 Description:  Geo-Redundant Storage (GRS) replicates data synchronously within the primary region and asynchronously to ...
Thu, 15 May, 2025 at 5:48 AM
Ensure Azure Resource Manager ReadOnly Locks Are Considered for Azure Storage Accounts
Profile Applicability: Level 2 Description:  ReadOnly locks restrict modifications and deletions on Azure Storage Accounts by allowing only read operati...
Thu, 15 May, 2025 at 5:56 AM
Ensure Azure Resource Manager Delete Locks Are Applied to Azure Storage Accounts
Profile Applicability: Level 1 Description:  Delete locks prevent accidental or unauthorized deletion of Azure Storage Accounts by restricting delete op...
Thu, 15 May, 2025 at 6:10 AM
Ensure Soft Delete on Recovery Services Vaults is Enabled
Profile Applicability:  Level 1 Description: Soft Delete on Azure Recovery Services Vaults ensures that when backup data or recovery points are deleted, th...
Fri, 16 May, 2025 at 2:18 AM
Ensure Immutability for Recovery Services Vaults is Enabled
Profile Applicability:  Level 1 Description:  Immutability on Azure Recovery Services Vaults ensures that backup data and recovery points cannot be altered...
Fri, 16 May, 2025 at 2:25 AM