Information
The Microsoft Cloud Security Benchmark (MCSB) is an Azure Policy initiative automatically assigned to all subscriptions that evaluates resource configurations against Microsoft security best practice recommendations. Policies set to a Disabled effect are not evaluated, removing visibility into the associated recommendation. Microsoft deprecates policies when controls are superseded or no longer applicable; deprecated policies are set to Disabled by default and require no corrective action. Non-deprecated policies should not be set to Disabled without a documented organizational exception.
Note: A policy is considered deprecated when its definition name is prefixed with [Deprecated]: in the Azure Policy portal and its policyDeprecated metadata property is true.
Disabling a non-deprecated MCSB policy prevents Microsoft Defender for Cloud from evaluating the associated control and surfacing relevant recommendations, creating an undetected gap in security posture visibility. Exceptions allowing non-deprecated MCSB policies to be disabled can be reasonably made but each exception should be documented and reconsidered periodically.
Examples of reasonable exceptions:
- A compensating control exists which cannot be evaluated by the policy
- A scope exemption exists for certain resources within the evaluated scope
- The policy effect conflicts with architecturally deliberate choices
- The resource type is not used in the evaluated scope
Deprecated policies set to Disabled reflect an intentional Microsoft lifecycle decision and are not a finding.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
No remediation is required for deprecated MCSB policies set to Disabled.
For non-deprecated policies found to be set to Disabled, restore the effect to its default value or document an approved organizational exception.
Remediate from Azure Portal
- From Azure Home, select the Portal Menu.
- Select Microsoft Defender for Cloud.
- Under Management, select Environment settings.
- Click on the appropriate Management Group or Subscription.
- Click Security policies in the left column.
- Click Microsoft cloud security benchmark.
- Click Add filter, select Effect, check Disabled, and click Apply.
- Confirm the displayed policy is not deprecated before proceeding.
- Click the blue ellipsis ... to the right of the policy name and select Manage effect and parameters.
- Under Policy effect, select Audit.
- Click Save, then click Refresh.
- Repeat steps 8-11 for each non-deprecated disabled policy.
- Repeat steps 1-12 for each Management Group or Subscription requiring remediation.
Impact:
MCSB policies default to an Audit or AuditIfNotExists effect, which evaluates but does not enforce recommendations. Re-enabling a non-deprecated disabled policy restores evaluation only; no enforcement action occurs unless the effect is subsequently changed to Deny or DeployIfNotExists by the administrator.
Item Details
Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION
References: 800-53|AC-18, 800-53|AC-18(1), 800-53|AC-18(3), 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|5.1, CSCv7|5.5
Control ID: 64d74796170e2efaf8c55e3d56880fe945148115947eb11555f79afd97c62cb8