Azure Security Ecosystem Archives - Azure Security Architect https://azuresecurityarchitect.com/category/azure-security-ecosystem/ For all your cloud security needs Sun, 29 Dec 2024 16:32:53 +0000 en-US hourly 1 https://wordpress.org/?v=6.7.2 214478653 Azure Policy Recommended Policies https://azuresecurityarchitect.com/azure-security-ecosystem/azure-policy-recommended-policies/ https://azuresecurityarchitect.com/azure-security-ecosystem/azure-policy-recommended-policies/#respond Sun, 29 Dec 2024 16:32:53 +0000 https://azuresecurityarchitect.com/?p=318 These are the top recommended policies for most customers. Enforce resource tagging Limit allowed locations Prohibit specific resources deployment (e.g. Public IP addresses) Require Secure Transfer for Storage Accounts Block […]

The post Azure Policy Recommended Policies appeared first on Azure Security Architect.

]]>
These are the top recommended policies for most customers.

  1. Enforce resource tagging
  2. Limit allowed locations
  3. Prohibit specific resources deployment (e.g. Public IP addresses)
  4. Require Secure Transfer for Storage Accounts
  5. Block Public Access to Storage Accounts
  6. Block Anonymous access to storage accounts
  7. Configure Cosmos DB accounts to disable public network access
  8. Configure Azure SQL accounts to disable public network access

The post Azure Policy Recommended Policies appeared first on Azure Security Architect.

]]>
https://azuresecurityarchitect.com/azure-security-ecosystem/azure-policy-recommended-policies/feed/ 0 318
Azure Firewall – Stateful, Packet Inspection https://azuresecurityarchitect.com/azure-security-ecosystem/azure-firewall-stateful-packet-inspection/ https://azuresecurityarchitect.com/azure-security-ecosystem/azure-firewall-stateful-packet-inspection/#respond Mon, 15 Apr 2024 14:38:25 +0000 https://azuresecurityarchitect.com/?p=177 What is needed to deploy an Azure Firewall? Azure Firewall requires it’s own empty subnet and an unused IP address space. You will need to create an address space, if […]

The post Azure Firewall – Stateful, Packet Inspection appeared first on Azure Security Architect.

]]>
What is needed to deploy an Azure Firewall?

Azure Firewall requires it’s own empty subnet and an unused IP address space. You will need to create an address space, if one isn’t available.

Do I also need NSGs?

No. Once an Azure Firewall is in place, no NSGs are needed.

Do I also need ASGs?

No. An Application Security Group is a grouped set of azure resources that can be referenced via a common set of NSGs rules.

Do I also Azure Policy?

No. These are different from Firewalls – these are more around Governance.

The post Azure Firewall – Stateful, Packet Inspection appeared first on Azure Security Architect.

]]>
https://azuresecurityarchitect.com/azure-security-ecosystem/azure-firewall-stateful-packet-inspection/feed/ 0 177