Skip to content

Commit 0bc5b9b

Browse files
authored
Merge pull request #114626 from parulbansal2009/master
Updating Policies
2 parents 235b6f9 + 327c169 commit 0bc5b9b

File tree

6 files changed

+32
-38
lines changed

6 files changed

+32
-38
lines changed

articles/governance/blueprints/samples/canada-federal-pbmm/control-mapping.md

Lines changed: 18 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: Canada Federal PBMM blueprint sample controls
33
description: Control mapping of the Canada Federal PBMM blueprint samples. Each control is mapped to one or more Azure Policies that assist with assessment.
4-
ms.date: 09/04/2019
4+
ms.date: 05/08/2020
55
ms.topic: sample
66
---
77
# Control mapping of the Canada Federal PBMM blueprint sample
@@ -91,8 +91,8 @@ separation of duties.
9191

9292
- A maximum of 3 owners should be designated for your subscription
9393
- There should be more than one owner assigned to your subscription
94-
- Audit Windows VMs in which the Administrators group contains any of the specified members
95-
- Audit Windows VMs in which the Administrators group does not contain all of the specified members
94+
- Show audit results from Windows VMs in which the Administrators group contains any of the specified members
95+
- Show audit results from Windows VMs in which the Administrators group does not contain all of the specified members
9696
- Deploy requirements to audit Windows VMs in which the Administrators group contains any of the specified members
9797
- Deploy requirements to audit Windows VMs in which the Administrators group does not contain all of the specified members
9898

@@ -106,8 +106,8 @@ indicators can help you ensure least privilege controls are implemented.
106106

107107
- A maximum of 3 owners should be designated for your subscription
108108
- There should be more than one owner assigned to your subscription
109-
- Audit Windows VMs in which the Administrators group contains any of the specified members
110-
- Audit Windows VMs in which the Administrators group does not contain all of the specified members
109+
- Show audit results from Windows VMs in which the Administrators group contains any of the specified members
110+
- Show audit results from Windows VMs in which the Administrators group does not contain all of the specified members
111111
- Deploy requirements to audit Windows VMs in which the Administrators group contains any of the specified members
112112
- Deploy requirements to audit Windows VMs in which the Administrators group does not contain all of the specified members
113113

@@ -134,7 +134,7 @@ connections from accounts without passwords. Additionally, the blueprint assigns
134134
definition that helps you monitor unrestricted access to storage accounts. Monitoring these
135135
indicators can help you ensure remote access methods comply with your security policy.
136136

137-
- \[Preview\]: Audit Linux VMs that allow remote connections from accounts without passwords
137+
- \[Preview\]: Show audit results from Linux VMs that allow remote connections from accounts without passwords
138138
- \[Preview\]: Deploy requirements to audit Linux VMs that allow remote connections from accounts without passwords
139139
- Audit unrestricted network access to storage accounts
140140
- Remote debugging should be turned off for API App
@@ -160,7 +160,7 @@ audit and event logging configurations. Monitoring these configurations can prov
160160
an audit system failure or misconfiguration and help you take corrective action.
161161

162162
- Audit diagnostic setting
163-
- Audit SQL server level Auditing settings
163+
- Auditing on SQL server should be enabled
164164
- Advanced data security should be enabled on your managed instances
165165
- Advanced data security should be enabled on your SQL servers
166166

@@ -191,7 +191,7 @@ and Advanced Data Security are configured on SQL servers.
191191
- \[Preview\]: Deploy Log Analytics Agent for Linux VMs
192192
- \[Preview\]: Deploy Log Analytics Agent for Windows VMs
193193
- Audit diagnostic setting
194-
- Audit SQL server level Auditing settings
194+
- Auditing on SQL server should be enabled
195195
- Advanced data security should be enabled on your managed instances
196196
- Advanced data security should be enabled on your SQL servers
197197
- Deploy Advanced Data Security on SQL servers
@@ -250,8 +250,8 @@ configuration of the password encryption type for Windows virtual machines. Moni
250250
indicators helps you ensure that system authenticators comply with your organization's
251251
identification and authentication policy.
252252

253-
- \[Preview\]: Audit Linux VMs that do not have the passwd file permissions set to 0644
254-
- \[Preview\]: Audit Linux VMs that have accounts without passwords
253+
- \[Preview\]: Show audit results from Linux VMs that do not have the passwd file permissions set to 0644
254+
- \[Preview\]: Show audit results from Linux VMs that have accounts without passwords
255255
- \[Preview\]: Deploy requirements to audit Linux VMs that do not have the passwd file permissions set to 0644
256256
- \[Preview\]: Deploy requirements to audit Linux VMs that have accounts without passwords
257257

@@ -263,11 +263,11 @@ password requirements. Awareness of virtual machines in violation of the passwor
263263
helps you take corrective actions to ensure passwords for all virtual machine user accounts comply
264264
with your organization's password policy.
265265

266-
- \[Preview\]: Audit Windows VMs that allow re-use of the previous 24 passwords
267-
- \[Preview\]: Audit Windows VMs that do not have a maximum password age of 70 days
268-
- \[Preview\]: Audit Windows VMs that do not have a minimum password age of 1 day
269-
- \[Preview\]: Audit Windows VMs that do not have the password complexity setting enabled
270-
- \[Preview\]: Audit Windows VMs that do not restrict the minimum password length to 14 characters
266+
- \[Preview\]: Show audit results from Windows VMs that allow re-use of the previous 24 passwords
267+
- \[Preview\]: Show audit results from Windows VMs that do not have a maximum password age of 70 days
268+
- \[Preview\]: Show audit results from Windows VMs that do not have a minimum password age of 1 day
269+
- \[Preview\]: Show audit results from Windows VMs that do not have the password complexity setting enabled
270+
- \[Preview\]: Show audit results from Windows VMs that do not restrict the minimum password length to 14 characters
271271
- \[Preview\]: Deploy requirements to audit Windows VMs that allow re-use of the previous 24 passwords
272272
- \[Preview\]: Deploy requirements to audit Windows VMs that do not have a maximum password age of 70 days
273273
- \[Preview\]: Deploy requirements to audit Windows VMs that do not have a minimum password age of 1 day
@@ -325,10 +325,9 @@ endpoints, applications, and storage accounts. Endpoints and applications that a
325325
firewall, and storage accounts with unrestricted access can allow unintended access to information
326326
contained within the information system.
327327

328-
- Network Security Group Rules for Internet facing virtual machines should be hardened
328+
- Adaptive Network Hardening recommendations should be applied on internet facing virtual machines
329329
- Access through Internet facing endpoint should be restricted
330330
- Audit unrestricted network access to storage accounts
331-
- The NSGs rules for web applications on IaaS should be hardened
332331

333332
## SC-7 (3) Boundary Protection | Access Points
334333

@@ -360,7 +359,7 @@ properly encrypted can help you meet your organization's requirements or protect
360359
from unauthorized disclosure and modification.
361360

362361
- API App should only be accessible over HTTPS
363-
- Audit Windows web servers that are not using secure communication protocols
362+
- Show audit results from Windows web servers that are not using secure communication protocols
364363
- Deploy requirements to audit Windows web servers that are not using secure communication protocols
365364
- Function App should only be accessible over HTTPS
366365
- Only secure connections to your Redis Cache should be enabled
@@ -465,4 +464,4 @@ Additional articles about blueprints and how to use them:
465464
- Understand how to use [static and dynamic parameters](../../concepts/parameters.md).
466465
- Learn to customize the [blueprint sequencing order](../../concepts/sequencing-order.md).
467466
- Find out how to make use of [blueprint resource locking](../../concepts/resource-locking.md).
468-
- Learn how to [update existing assignments](../../how-to/update-existing-assignments.md).
467+
- Learn how to [update existing assignments](../../how-to/update-existing-assignments.md).

articles/governance/blueprints/samples/canada-federal-pbmm/deploy.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: Deploy Canada Federal PBMM blueprint sample
33
description: Deploy steps for the Canada Federal PBMM blueprint sample including blueprint artifact parameter details.
4-
ms.date: 09/05/2019
4+
ms.date: 05/08/2020
55
ms.topic: sample
66
---
77
# Deploy the Canada Federal PBMM blueprint samples
@@ -149,4 +149,4 @@ Additional articles about blueprints and how to use them:
149149
- Understand how to use [static and dynamic parameters](../../concepts/parameters.md).
150150
- Learn to customize the [blueprint sequencing order](../../concepts/sequencing-order.md).
151151
- Find out how to make use of [blueprint resource locking](../../concepts/resource-locking.md).
152-
- Learn how to [update existing assignments](../../how-to/update-existing-assignments.md).
152+
- Learn how to [update existing assignments](../../how-to/update-existing-assignments.md).

articles/governance/blueprints/samples/canada-federal-pbmm/index.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: Canada Federal PBMM blueprint sample overview
33
description: Overview of the Canada Federal PBMM blueprint sample. This blueprint sample helps customers assess specific Canada Federal PBMM controls.
4-
ms.date: 09/04/2019
4+
ms.date: 05/08/2020
55
ms.topic: sample
66
---
77
# Overview of the Canada Federal PBMM blueprint sample
@@ -35,4 +35,4 @@ Additional articles about blueprints and how to use them:
3535
- Understand how to use [static and dynamic parameters](../../concepts/parameters.md).
3636
- Learn to customize the [blueprint sequencing order](../../concepts/sequencing-order.md).
3737
- Find out how to make use of [blueprint resource locking](../../concepts/resource-locking.md).
38-
- Learn how to [update existing assignments](../../how-to/update-existing-assignments.md).
38+
- Learn how to [update existing assignments](../../how-to/update-existing-assignments.md).

articles/governance/blueprints/samples/ukofficial/control-mapping.md

Lines changed: 6 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: UK OFFICIAL & UK NHS blueprint sample controls
33
description: Control mapping of the UK OFFICIAL and UK NHS blueprint samples. Each control is mapped to one or more Azure Policies that assist with assessment.
4-
ms.date: 12/04/2019
4+
ms.date: 05/08/2020
55
ms.topic: sample
66
---
77
# Control mapping of the UK OFFICIAL and UK NHS blueprint samples
@@ -37,9 +37,6 @@ definitions that audit insecure connections to storage accounts and Redis Cache.
3737
- Secure transfer to storage accounts should be enabled
3838
- Show audit results from Windows web servers that are not using secure communication protocols
3939
- Deploy prerequisites to audit Windows web servers that are not using secure communication protocols
40-
- Latest TLS version should be used in your API App
41-
- Latest TLS version should be used in your Web App
42-
- Latest TLS version should be used in your Function App
4340

4441
## 2.3 Data at rest protection
4542

@@ -172,8 +169,8 @@ help you take corrective actions to ensure access Azure resources is restricted
172169

173170
- \[Preview\]: Deploy requirements to audit Linux VMs that have accounts without passwords
174171
- \[Preview\]: Deploy requirements to audit Linux VMs that allow remote connections from accounts without passwords
175-
- \[Preview\]: Audit Linux VMs that have accounts without passwords
176-
- \[Preview\]: Audit Linux VMs that allow remote connections from accounts without passwords
172+
- \[Preview\]: Show audit results from Linux VMs that have accounts without passwords
173+
- \[Preview\]: Show audit results from Linux VMs that allow remote connections from accounts without passwords
177174
- Storage accounts should be migrated to new Azure Resource Manager resources
178175
- Virtual machines should be migrated to new Azure Resource Manager resources
179176
- Audit VMs that do not use managed disks
@@ -188,12 +185,10 @@ also assigns a policy that enables adaptive application controls on virtual mach
188185

189186
- Audit unrestricted network access to storage accounts
190187
- Adaptive Application Controls should be enabled on virtual machines
191-
- The NSGs rules for web applications on IaaS should be hardened
192188
- Access through Internet facing endpoint should be restricted
193-
- Network Security Group Rules for Internet facing virtual machines should be hardened
189+
- Adaptive Network Hardening recommendations should be applied on internet facing virtual machines
194190
- Endpoint protection solution should be installed on virtual machine scale sets
195191
- Just-In-Time network access control should be applied on virtual machines
196-
- Audit unrestricted network access to storage accounts
197192
- Remote debugging should be turned off for Function App
198193
- Remote debugging should be turned off for Web Application
199194
- Remote debugging should be turned off for API App
@@ -246,15 +241,15 @@ This blueprint also assigns an Azure Policy definition that audits Linux VM pass
246241
permissions to alert if they're set incorrectly. This design enables you to take corrective action
247242
to ensure authenticators aren't compromised.
248243

249-
- \[Preview\]: Audit Linux VM /etc/passwd file permissions are set to 0644
244+
- \[Preview\]: Show audit results from Linux VMs that do not have the passwd file permissions set to 0644
250245

251246
## 13 Audit Information for Users
252247

253248
This blueprint helps you ensure system events are logged by assigning [Azure Policy](../../../policy/overview.md)
254249
definitions that audit log settings on Azure resources. An assigned policy also audits if virtual
255250
machines aren't sending logs to a specified log analytics workspace.
256251

257-
- Auditing should be enabled on advanced data security settings on SQL Server
252+
- Advanced data security should be enabled on your SQL servers
258253
- Audit diagnostic setting
259254
- \[Preview\]: Deploy Log Analytics Agent for Linux VMs
260255
- \[Preview\]: Deploy Log Analytics Agent for Windows VMs

articles/governance/blueprints/samples/ukofficial/deploy.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: Deploy UK OFFICIAL & UK NHS blueprint samples
33
description: Deploy steps for the UK OFFICIAL and UK NHS blueprint samples including blueprint artifact parameter details.
4-
ms.date: 06/26/2019
4+
ms.date: 05/08/2020
55
ms.topic: sample
66
---
77
# Deploy the UK OFFICIAL and UK NHS blueprint samples
@@ -136,4 +136,4 @@ Additional articles about blueprints and how to use them:
136136
- Understand how to use [static and dynamic parameters](../../concepts/parameters.md).
137137
- Learn to customize the [blueprint sequencing order](../../concepts/sequencing-order.md).
138138
- Find out how to make use of [blueprint resource locking](../../concepts/resource-locking.md).
139-
- Learn how to [update existing assignments](../../how-to/update-existing-assignments.md).
139+
- Learn how to [update existing assignments](../../how-to/update-existing-assignments.md).

articles/governance/blueprints/samples/ukofficial/index.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: UK OFFICIAL & UK NHS blueprint sample overview
33
description: Overview and architecture of the UK OFFICIAL and UK NHS blueprint samples. This blueprint sample helps customers assess specific controls.
4-
ms.date: 06/26/2019
4+
ms.date: 05/08/2020
55
ms.topic: sample
66
---
77
# Overview of the UK OFFICIAL and UK NHS blueprint samples
@@ -33,4 +33,4 @@ Additional articles about blueprints and how to use them:
3333
- Understand how to use [static and dynamic parameters](../../concepts/parameters.md).
3434
- Learn to customize the [blueprint sequencing order](../../concepts/sequencing-order.md).
3535
- Find out how to make use of [blueprint resource locking](../../concepts/resource-locking.md).
36-
- Learn how to [update existing assignments](../../how-to/update-existing-assignments.md).
36+
- Learn how to [update existing assignments](../../how-to/update-existing-assignments.md).

0 commit comments

Comments
 (0)