microsoft / microsoft/AzureTRE

Defender for Cloud Security Recommendations

Open
#4,303 7 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
235
Forks
192
Avg merge
1d 23h
Merged PRs (30d)
13

Description

There are a number of security findings from Azure Defender for Cloud. Let me know if an issue needs to be created for each of these but here is the list from a TRE deployment with an airlock in place with a workspace using Databricks, VMs, AzureML and SQL services enabled:

  • TLS should be updated to the latest version for function apps - func-airlock-processor-[treid]
  • TLS should be updated to the latest version for web apps - api-[treid], guacamole-[treid]-ws-f9a2-svc-095e, guacamole-[treid]-ws-a4a3-svc-8ae7
  • Storage accounts should prevent shared key access - All storage accounts
  • Storage accounts should restrict network access using virtual network rules - TRE Core Storage Accounts
  • Storage account should use a private link connection - TRE Core Storage Accounts
  • Azure DDoS Protection Standard should be enabled - vnet-[treid]
  • Firewall should be enabled on Key Vault - kv-[treid]
  • Azure Event Grid topics should use private link - evgt-airlock-scan-result-v2-[treid]
  • Azure Cosmos DB should disable public network access - cosmos-[treid], cosmos-mongo-[treid]
  • Azure Cosmos DB accounts should use Azure Active Directory as the only authentication method - cosmos-[treid]
  • Virtual machines and virtual machine scale sets should have encryption at host enabled - vmss-rp-porter-[treid], nexus-[treid], All workspace VMs
  • Machines should have a vulnerability assessment solution - nexus-[treid], All workspace VMs
  • Machines should be configured to periodically check for missing system updates - nexus-[treid]
  • Linux virtual machines should enable Azure Disk Encryption or EncryptionAtHost. - nexus-[treid]
  • Guest Configuration extension should be installed on machines - nexus-[treid], All workspace VMs
  • Azure Backup should be enabled for virtual machines - nexus-[treid], All workspace VMs
  • Resource logs in Azure Machine Learning Workspaces should be enabled
  • Resource logs in Azure Databricks Workspaces should be enabled
  • Windows virtual machines should enable Azure Disk Encryption or EncryptionAtHost. - All workspace VMs
  • Container registries should use private link - Management Container Registry
  • Container registries should not allow unrestricted network access - Management Container Registry

I understand that potentially some of these findings may have already been highlighted and some may not be possible without breaking functionality. But it would be useful to know the justifications for this to audit the security findings on a customer's system and if our client/s have any questions on the vulnerabilities found.

We can potentially resolve most of these ourselves but it would be good for the repo to be updated, especially things like TLS version updates and making sure VMs created have the recommended extensions with Update Management and Backup in place.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files or tests are named. Start by auditing the unchecked Azure Defender for Cloud recommendations against the TRE deployment resources listed in the issue and checking which findings already have mitigations. Done means each finding is either addressed in the repository or has a documented justification and customer-facing audit guidance.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure
Domain
cloud, infrastructure, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.