Ensure resource lock enabled for Azure Resource Group

LOW

Description

Resource lock is disabled for Azure Resource Group, this may lead to unauthorized access.

Remediation

In Azure Console -

  1. In the settings for a Resource Group, select Locks.
  2. Select Add to create a lock.
  3. Give the lock a name and a level.

In terraform -

  1. Create a new azurerm_management_lock resource.
  2. Configure name, scope, lock_level, and notes.

References:
https://learn.microsoft.com/en-us/rest/api/resources/management-locks/create-or-update-at-resource-level?tabs=HTTP
https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/management_lock

Policy Details

Rule Reference ID: AC_AZURE_0389
CSP: Azure
Remediation Available: Yes
Resource Type: Policy

Frameworks