Azure Storage Services Benchmark

Ensure that shared access signature (SAS) tokens expire within an hour for Azure Blob Storage
Profile Applicability:  Level 1 Description: Shared access signature (SAS) tokens provide restricted access to Azure Storage resources (such as blobs, file...
Fri, 16 May, 2025 at 3:05 AM
Ensure Cross Tenant Replication is Disabled for Azure Storage Accounts
Profile Applicability:  Level 1 Description:  Cross Tenant Replication allows Azure Storage Accounts to replicate data across different Azure Active Dir...
Fri, 16 May, 2025 at 3:07 AM
Ensure stored access policies (SAP) are used when generating shared access signature (SAS) tokens for Azure Blob Storage
Profile Applicability:  Level 1 Description:  Use stored access policies (SAP) when generating shared access signature (SAS) tokens in Azure to centrally m...
Fri, 16 May, 2025 at 3:08 AM
Ensure 'Allowed Protocols' for SAS Tokens Are Restricted to HTTPS Only for Azure Queue Storage
Profile Applicability:  Level 1 Description:  Shared access signatures (SAS) provide limited access to Azure Storage resources. When generating a SAS, it i...
Fri, 16 May, 2025 at 3:11 AM
Ensure the 'Minimum TLS Version' for Storage Accounts Is Set to 'Version 1.2
Profile Applicability:  Level 1 Description:  The minimum TLS version setting enforces the lowest version of Transport Layer Security (TLS) protocol all...
Fri, 16 May, 2025 at 3:13 AM
Ensure Storage Logging Is Enabled for Table Service for 'Read', 'Write', and 'Delete' Requests
Profile Applicability:  Level 2 Description:  Storage Logging records requests to the Azure Table service, capturing read, write, and delete operations....
Fri, 16 May, 2025 at 3:19 AM
Ensure that shared access signature (SAS) tokens expire within an hour for Queue Storage
Profile Applicability:  Level 1 Description:  Shared access signature (SAS) tokens provide restricted, time-limited access to Azure Queue Storage resources...
Fri, 16 May, 2025 at 3:19 AM
Ensure stored access policies (SAP) are used when generating shared access signature (SAS) tokens for Queue Storage
Profile Applicability:  Level 1 Description:  Use stored access policies (SAP) when generating shared access signature (SAS) tokens in Azure to centrally m...
Fri, 16 May, 2025 at 3:23 AM
Ensure 'Allowed Protocols' for Shared Access Signature (SAS) Tokens Are Restricted to HTTPS Only for Azure Storage Services
Profile Applicability:  Level 1 Description:  Shared access signatures (SAS) can be used to grant limited access to Azure Storage resources. When generatin...
Fri, 16 May, 2025 at 3:26 AM
Ensure Storage Logging Is Enabled for Blob Service for 'Read', 'Write', and 'Delete' Requests
Profile Applicability: Level 2 Description:  Storage Logging captures and records all requests made to the Azure Blob service, including read, write, an...
Fri, 16 May, 2025 at 3:28 AM