8.1.11 Ensure that non-deprecated Microsoft Cloud Security Benchmark policies are not set to 'Disabled'

Information

The Microsoft Cloud Security Benchmark (MCSB) is an Azure Policy initiative automatically assigned to all subscriptions that evaluates resource configurations against Microsoft security best practice recommendations. Policies set to a Disabled effect are not evaluated, removing visibility into the associated recommendation. Microsoft deprecates policies when controls are superseded or no longer applicable; deprecated policies are set to Disabled by default and require no corrective action. Non-deprecated policies should not be set to Disabled without a documented organizational exception.

Note: A policy is considered deprecated when its definition name is prefixed with [Deprecated]: in the Azure Policy portal and its policyDeprecated metadata property is true.

Disabling a non-deprecated MCSB policy prevents Microsoft Defender for Cloud from evaluating the associated control and surfacing relevant recommendations, creating an undetected gap in security posture visibility. Exceptions allowing non-deprecated MCSB policies to be disabled can be reasonably made but each exception should be documented and reconsidered periodically.

Examples of reasonable exceptions:

- A compensating control exists which cannot be evaluated by the policy
- A scope exemption exists for certain resources within the evaluated scope
- The policy effect conflicts with architecturally deliberate choices
- The resource type is not used in the evaluated scope

Deprecated policies set to Disabled reflect an intentional Microsoft lifecycle decision and are not a finding.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

No remediation is required for deprecated MCSB policies set to Disabled.

For non-deprecated policies found to be set to Disabled, restore the effect to its default value or document an approved organizational exception.

Remediate from Azure Portal

- From Azure Home, select the Portal Menu.
- Select Microsoft Defender for Cloud.
- Under Management, select Environment settings.
- Click on the appropriate Management Group or Subscription.
- Click Security policies in the left column.
- Click Microsoft cloud security benchmark.
- Click Add filter, select Effect, check Disabled, and click Apply.
- Confirm the displayed policy is not deprecated before proceeding.
- Click the blue ellipsis ... to the right of the policy name and select Manage effect and parameters.
- Under Policy effect, select Audit.
- Click Save, then click Refresh.
- Repeat steps 8-11 for each non-deprecated disabled policy.
- Repeat steps 1-12 for each Management Group or Subscription requiring remediation.

Impact:

MCSB policies default to an Audit or AuditIfNotExists effect, which evaluates but does not enforce recommendations. Re-enabling a non-deprecated disabled policy restores evaluation only; no enforcement action occurs unless the effect is subsequently changed to Deny or DeployIfNotExists by the administrator.

See Also

https://workbench.cisecurity.org/benchmarks/24282

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

References: 800-53|AC-18, 800-53|AC-18(1), 800-53|AC-18(3), 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|5.1, CSCv7|5.5

Plugin: microsoft_azure

Control ID: 64d74796170e2efaf8c55e3d56880fe945148115947eb11555f79afd97c62cb8