Azure Storage Services Benchmark

Ensure that shared access signature (SAS) tokens expire within an hour for Storage Explorer
Profile Applicability:  Level 1 Description: Shared access signature (SAS) tokens provide restricted access to Azure Storage resources (such as blobs, file...
Fri, 16 May, 2025 at 3:30 AM
Ensure stored access policies (SAP) are used when generating shared access signature (SAS) tokens for Storage Explorer
Profile Applicability:  Level 1 Description:  Use stored access policies (SAP) when generating shared access signature (SAS) tokens in Azure to centrally m...
Fri, 16 May, 2025 at 3:34 AM
Ensure Storage Logging Is Enabled for Queue Service for 'Read', 'Write', and 'Delete' Requests
Profile Applicability: Level 2 Description:  Storage Logging tracks and records requests made to the Azure Queue service, including read, write, and del...
Fri, 16 May, 2025 at 3:38 AM
Ensure Soft Delete Is Enabled for Azure Containers and Blob Storage
Profile Applicability: Level 1 Description:  Soft Delete protects blobs and containers in Azure Storage by retaining deleted data for a configurable ret...
Fri, 16 May, 2025 at 3:57 AM
Ensure 'Allow Azure Services on the Trusted Services List to Access This Storage Account' Is Enabled for Storage Account Access
Profile Applicability: Level 2 Description:  This setting allows trusted Azure services (such as Azure Backup, Azure Site Recovery, and Azure DevOps) to...
Fri, 16 May, 2025 at 4:07 AM
Ensure That ‘Enable Infrastructure Encryption’ for Each Storage Account in Azure Storage Is Set to ‘Enabled’
Profile Applicability: Level 2 Description:  Infrastructure encryption provides an additional layer of encryption for data at rest in Azure Storage Acco...
Fri, 16 May, 2025 at 4:30 AM
Ensure ‘Secure Transfer Required’ is Enabled for Azure Storage Accounts
Profile Applicability: Level 1 Description:  The 'Secure transfer required' setting enforces that all requests to an Azure Storage Account use s...
Fri, 16 May, 2025 at 4:42 AM
Ensure That Storage Account Access Keys Are Periodically Regenerated
Profile Applicability: Level 1 Description:  Storage Account Access Keys provide full access to Azure Storage resources. Periodic regeneration of these ...
Fri, 16 May, 2025 at 4:47 AM
Ensure that shared access signature (SAS) tokens expire within an hour for Storage Accounts
Profile Applicability: Level 1 Description:  Shared access signature (SAS) tokens provide restricted access to Azure Storage resources (such as blobs, f...
Fri, 16 May, 2025 at 4:53 AM
Ensure 'Allow Storage Account Key Access' for Azure Storage Accounts Is 'Disabled'
Profile Applicability:  Level 1 Description:  The setting 'Allow Storage Account Key Access' controls whether applications and users can access ...
Fri, 16 May, 2025 at 4:58 AM