Azure / Azure/Azure-Verified-Modules

AzAdvertizer data changes detected

Open
#2,566 1 comment 0 reactions 0 assignees View on GitHub
Needs: Triage :mag:
Dominant language
PowerShell
Stars
580
Forks
161
Avg merge
11h 3m
Merged PRs (30d)
15

Description

Azure Advertizer Data Diff Report

Resource Type: microsoft.network/azurefirewalls
--------------------------------------------------
New APRL Recommendations:
- [Monitor "AZFW Latency Probe" metric](https://azure.github.io/Azure-Proactive-Resiliency-Library-v2/azure-resources/Network/azureFirewalls/#monitor-azfw-latency-probe-metric)

Resource Type: microsoft.recoveryservices/vaults
--------------------------------------------------
New Advisor Recommendations:
- [Enable Zone Redundant Storage (ZRS) for vault storage to protect backups from zone failures](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/21ac578c-0fb9-42eb-9c58-69716f87e7fb)

Resource Type: microsoft.security/awsresource
--------------------------------------------------
New Advisor Recommendations:
- [Avoid the use of the "root" account](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/a47a6c3b-0629-406c-ad09-d91f7d9f78a3)
- [IAM policies that allow full "*:*" administrative privileges should not be created](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/1d08b362-7e24-46b0-bed1-4a6c1d1526a5)
- [Public Access Block configuration should be enabled on AWS S3 Access Point](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/8806e836-76d1-4821-a4b0-3e56f3bbd19d)
- [AWS Batch job definitions should not run containers in privileged mode](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/5740b24c-872f-4540-b12b-7d384ba0e6ed)
- [Knowledge Base field mapping should be securely configured on Amazon Bedrock](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/9d2f01d7-0111-4d8e-b989-706fe091a3e9)
- [Use Server-Side-Encryption (SSE) on your SQS queue](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/edbffa73-1007-4233-bbb0-bff9dae7ed15)
- [Unauthenticated IAM role assignment should be disabled on Amazon Cognito Identity Pools](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/313321ed-623f-4d36-baf6-5efbd4661b8a)
- [TLS encryption should be enabled on Pinecone Enterprise Cloud Connections for Amazon Bedrock](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/7aa370c8-e57f-45c9-8785-5e0045ed70e6)
- [Prompt execution state should be enabled for critical agent stages on Amazon Bedrock](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/d8101051-9342-42dc-83ab-b2fd3318ad6b)
- [Parser override should be disabled for Amazon Bedrock Agents](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/b5ce1507-f55f-4325-8d99-66c64dc3b29e)
- [Secrets should be configured for containers to prevent the use of sensitive plaintext environment variables](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/208db1ba-ab93-400b-ab6d-5461a6f80791)
- [Health Checks should be enabled for Route 53](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/5f583875-2919-4a1f-ae28-45be37588253)
- [Ensure VPC Flow Logs have a valid destination](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/401f6740-b979-43be-8956-d723a2572207)
- [Sensitive parameters should have NoEcho attribute enabled on AWS CloudFormation stacks](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/a963259f-fb4f-41c8-8ae4-8b1f22e65b68)
- [Sensitive data exposure mitigation should be enabled on AWS CloudFormation stack outputs](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/e5d0018a-279b-49d3-a773-e6f29225a430)
- [Public read access on LightSail buckets should be disabled](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/2dcd240e-e1d7-4976-b3c6-53326612ec12)

Resource Type: microsoft.security/gcpresource
--------------------------------------------------
New Advisor Recommendations:
- [Public email domains should be barred from receiving privileged roles on BigQuery](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/51244366-47bf-4ff6-ac7e-deee2bd4e03e)
- [Broad Owner or Editor roles should be eliminated from service accounts on BigQuery datasets](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/81ea1766-24bc-4e2a-a4d6-84e147d9b939)
- [OIDC token authentication should be enabled on Pub/Sub push subscriptions](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/accb96ae-d7e2-4baa-9689-4ab5e841f61f)

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.