microsoft / microsoft/AzureTRE
Defender for Cloud Security Recommendations
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 235
- Forks
- 192
- Avg merge
- 1d 23h
- Merged PRs (30d)
- 13
Description
There are a number of security findings from Azure Defender for Cloud. Let me know if an issue needs to be created for each of these but here is the list from a TRE deployment with an airlock in place with a workspace using Databricks, VMs, AzureML and SQL services enabled:
- TLS should be updated to the latest version for function apps - func-airlock-processor-[treid]
- TLS should be updated to the latest version for web apps - api-[treid], guacamole-[treid]-ws-f9a2-svc-095e, guacamole-[treid]-ws-a4a3-svc-8ae7
- Storage accounts should prevent shared key access - All storage accounts
- Storage accounts should restrict network access using virtual network rules - TRE Core Storage Accounts
- Storage account should use a private link connection - TRE Core Storage Accounts
- Azure DDoS Protection Standard should be enabled - vnet-[treid]
- Firewall should be enabled on Key Vault - kv-[treid]
- Azure Event Grid topics should use private link - evgt-airlock-scan-result-v2-[treid]
- Azure Cosmos DB should disable public network access - cosmos-[treid], cosmos-mongo-[treid]
- Azure Cosmos DB accounts should use Azure Active Directory as the only authentication method - cosmos-[treid]
- Virtual machines and virtual machine scale sets should have encryption at host enabled - vmss-rp-porter-[treid], nexus-[treid], All workspace VMs
- Machines should have a vulnerability assessment solution - nexus-[treid], All workspace VMs
- Machines should be configured to periodically check for missing system updates - nexus-[treid]
- Linux virtual machines should enable Azure Disk Encryption or EncryptionAtHost. - nexus-[treid]
- Guest Configuration extension should be installed on machines - nexus-[treid], All workspace VMs
- Azure Backup should be enabled for virtual machines - nexus-[treid], All workspace VMs
- Resource logs in Azure Machine Learning Workspaces should be enabled
- Resource logs in Azure Databricks Workspaces should be enabled
- Windows virtual machines should enable Azure Disk Encryption or EncryptionAtHost. - All workspace VMs
- Container registries should use private link - Management Container Registry
- Container registries should not allow unrestricted network access - Management Container Registry
I understand that potentially some of these findings may have already been highlighted and some may not be possible without breaking functionality. But it would be useful to know the justifications for this to audit the security findings on a customer's system and if our client/s have any questions on the vulnerabilities found.
We can potentially resolve most of these ourselves but it would be good for the repo to be updated, especially things like TLS version updates and making sure VMs created have the recommended extensions with Update Management and Backup in place.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files or tests are named. Start by auditing the unchecked Azure Defender for Cloud recommendations against the TRE deployment resources listed in the issue and checking which findings already have mitigations. Done means each finding is either addressed in the repository or has a documented justification and customer-facing audit guidance.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure
- Domain
- cloud, infrastructure, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100