Azure Storage Services Benchmark

Ensure Backup Data in Recovery Services Vaults Is Encrypted Using Customer-Managed Keys (CMK)
Profile Applicability:  Level 2 Description:  Encrypting backup data in Azure Recovery Services Vaults with Customer-Managed Keys (CMK) allows organization...
Fri, 16 May, 2025 at 2:29 AM
Ensure Use Infrastructure Encryption for This Vault Is Enabled on Recovery Services Vaults
Profile Applicability:  Level 2 Description:  Infrastructure encryption provides an additional, second layer of encryption for backup data stored in Azure ...
Fri, 16 May, 2025 at 2:32 AM
Ensure Public Network Access on Recovery Services Vaults is Disabled
Profile Applicability:  Level 1 Description:  Disabling public network access on Azure Recovery Services Vaults restricts access to the vault exclusively t...
Fri, 16 May, 2025 at 2:36 AM
Ensure Cross Region Restore Is Set to Enabled on Recovery Services Vaults
Profile Applicability:  Level 2 Description:  Cross Region Restore (CRR) allows Azure Recovery Services Vaults to restore backup data to a different Azure ...
Fri, 16 May, 2025 at 2:41 AM
Ensure 'Cross Subscription Restore' Is Set to 'Disabled' or 'Permanently Disabled' on Recovery Services Vaults
Profile Applicability:  Level 1 Description:  Cross Subscription Restore (CSR) allows restoring backup data from a Recovery Services Vault in one Azure sub...
Fri, 16 May, 2025 at 2:45 AM
Ensure Soft Delete for Azure File Shares is Enabled
Profile Applicability:  Level 1 Description:  Soft Delete for Azure File Shares protects against accidental or malicious deletion by retaining deleted file...
Fri, 16 May, 2025 at 2:49 AM
Ensure Root Squash for NFS File Shares Is Configured
Profile Applicability:  Level 1 Description:  Root Squash is an NFS export option that maps requests from the root user (UID 0) on client machines to an an...
Fri, 16 May, 2025 at 2:53 AM
Ensure 'SMB Protocol Version' Is Set to 'SMB 3.1.1' or Higher for SMB File Shares
Profile Applicability:  Level 1 Description:  The SMB protocol version controls the security and features of Server Message Block (SMB) used for accessing ...
Fri, 16 May, 2025 at 2:57 AM
Ensure That 'Allow Blob Anonymous Access' Is Set to 'Disabled
Profile Applicability: Level 1 Description:  The 'Allow Blob Anonymous Access' setting controls whether blobs in an Azure Storage Account can be...
Fri, 16 May, 2025 at 3:00 AM
Ensure 'Allowed Protocols' for SAS Tokens Are Restricted to HTTPS Only for Azure Blob Storage
Profile Applicability:  Level 1 Description:  Shared access signatures (SAS) can be used to grant limited access to Azure Storage resources. When generatin...
Fri, 16 May, 2025 at 3:01 AM