CIS Microsoft Azure Foundations v6.0.0 L1

Audit Details

Name: CIS Microsoft Azure Foundations v6.0.0 L1

Updated: 6/3/2026

Authority: CIS

Plugin: microsoft_azure

Revision: 1.0

Estimated Item Count: 74

File Details

Filename: CIS_Microsoft_Azure_Foundations_v6.0.0_L1.audit

Size: 276 kB

MD5: 9f75d2a85fe8129feefc31498d63353e
SHA256: f20a3baf1afcb837820d85afc22a4c7882eaf0f10dfb7e86211f650d11a5ab6a

Audit Items

DescriptionCategories
2.1.1 Ensure that Azure Databricks is deployed in a customer-managed virtual network (VNet)

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION

2.1.2 Ensure that Network Security Groups are Configured for Databricks Subnets

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.1.4 Ensure that Users and Groups are Synced from Microsoft Entra ID to Azure Databricks

ACCESS CONTROL

2.1.5 Ensure that Unity Catalog is Configured for Azure Databricks

ACCESS CONTROL

2.1.6 Ensure that Usage is Restricted and Expiry is Enforced for Databricks Personal Access Tokens

ACCESS CONTROL

2.1.7 Ensure that Diagnostic Log Delivery is Configured for Azure Databricks

AUDIT AND ACCOUNTABILITY

2.1.9 Ensure 'No Public IP' is Set to 'Enabled'

ACCESS CONTROL, MEDIA PROTECTION

2.1.10 Ensure 'Allow Public Network Access' is set to 'Disabled'

ACCESS CONTROL, MEDIA PROTECTION

2.1.12 Ensure Azure Databricks groups are reviewed periodically

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.1 Ensure that 'security defaults' is Enabled in Microsoft Entra ID

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

5.1.2 Ensure that 'Require Multifactor Authentication to register or join devices with Microsoft Entra' is set to 'Yes'

IDENTIFICATION AND AUTHENTICATION

5.1.3 Ensure that 'multifactor authentication' is 'enabled' For All Users

IDENTIFICATION AND AUTHENTICATION

5.1.4 Ensure that 'Allow users to remember multifactor authentication on devices they trust' is Disabled

IDENTIFICATION AND AUTHENTICATION

5.3.1 Ensure that Azure Admin Accounts Are Not Used for Daily Operations

ACCESS CONTROL

5.3.2 Ensure that Guest Users are Reviewed on a Regular Basis

ACCESS CONTROL

5.3.3 Ensure That Use of the 'User Access Administrator' Role is Restricted

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.3.4 Ensure that All 'Privileged' Role Assignments are Periodically Reviewed

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.3.5 Ensure Disabled User Accounts do not Have Read, Write, or Owner Permissions

ACCESS CONTROL

5.3.6 Ensure 'Tenant Creator' Role Assignments are Periodically Reviewed

ACCESS CONTROL

5.3.7 Ensure All Non-privileged Role Assignments are Periodically Reviewed

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.4 Ensure that No Custom Subscription Administrator Roles Exist

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.7 Ensure there are between 2 and 3 Subscription Owners

ACCESS CONTROL

6.1.1.1 Ensure that a 'Diagnostic Setting' Exists for Subscription Activity Logs

AUDIT AND ACCOUNTABILITY

6.1.1.2 Ensure Diagnostic Setting Captures Appropriate Categories

AUDIT AND ACCOUNTABILITY

6.1.1.4 Ensure that Logging for Azure Key Vault is 'Enabled'

AUDIT AND ACCOUNTABILITY

6.1.2.1 Ensure that Activity Log Alert Exists for Create Policy Assignment

AUDIT AND ACCOUNTABILITY

6.1.2.2 Ensure that Activity Log Alert exists for Delete Policy Assignment

AUDIT AND ACCOUNTABILITY

6.1.2.3 Ensure that Activity Log Alert Exists for Create or Update Network Security Group

AUDIT AND ACCOUNTABILITY

6.1.2.4 Ensure that Activity Log Alert Exists for Delete Network Security Group

AUDIT AND ACCOUNTABILITY

6.1.2.5 Ensure that Activity Log Alert Exists for Create or Update Security Solution

AUDIT AND ACCOUNTABILITY

6.1.2.6 Ensure that Activity Log Alert Exists for Delete Security Solution

AUDIT AND ACCOUNTABILITY

6.1.2.7 Ensure that Activity Log Alert Exists for Create or Update SQL Server Firewall Rule

AUDIT AND ACCOUNTABILITY

6.1.2.8 Ensure that Activity Log Alert Exists for Delete SQL Server Firewall Rule

AUDIT AND ACCOUNTABILITY

6.1.2.9 Ensure that Activity Log Alert Exists for Create or Update Public IP Address rule

AUDIT AND ACCOUNTABILITY

6.1.2.10 Ensure that Activity Log Alert Exists for Delete Public IP Address rule

AUDIT AND ACCOUNTABILITY

6.1.2.11 Ensure that an Activity Log Alert Exists for Service Health

AUDIT AND ACCOUNTABILITY

6.1.4 Ensure that Azure Monitor Resource Logging is Enabled for All Services that Support it

AUDIT AND ACCOUNTABILITY

7.1 Ensure that RDP Access from the Internet is Evaluated and Restricted

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.2 Ensure that SSH Access from the Internet is Evaluated and Restricted

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.3 Ensure that UDP Port Access from the Internet is Evaluated and Restricted

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.4 Ensure that HTTP(S) Access from the Internet is Evaluated and Restricted

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.7 Ensure that Public IP Addresses are Evaluated on a Periodic Basis

CONFIGURATION MANAGEMENT

7.11 Ensure Subnets Are Associated with Network Security Groups

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.12 Ensure the SSL Policy's 'Min protocol version' is Set to 'TLSv1_2' or Higher on Azure Application Gateway

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.13 Ensure 'HTTP2' is Set to 'Enabled' on Azure Application Gateway

SYSTEM AND SERVICES ACQUISITION

8.1.10 Ensure that Microsoft Defender for Cloud is Configured to Check VM Operating Systems for Updates

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

8.1.11 Ensure that non-deprecated Microsoft Cloud Security Benchmark policies are not set to 'Disabled'

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

8.1.12 Ensure That 'All users with the following roles' is Set to 'Owner'

INCIDENT RESPONSE

8.1.13 Ensure 'Additional email addresses' is Configured with a Security Contact Email

INCIDENT RESPONSE

8.1.14 Ensure that 'Notify about alerts with the following severity (or higher)' is Enabled

SYSTEM AND INFORMATION INTEGRITY