Skip to content

Network - 25533 - DDoS Protection is enabled for all Public IP Addresses in VNETs #DUP#921

Closed
Manoj-Kesana wants to merge 35 commits intomainfrom
Feature-25533
Closed

Network - 25533 - DDoS Protection is enabled for all Public IP Addresses in VNETs #DUP#921
Manoj-Kesana wants to merge 35 commits intomainfrom
Feature-25533

Conversation

@Manoj-Kesana
Copy link
Collaborator

DDoS Protection is enabled for all Public IP Addresses in VNETs

@Manoj-Kesana Manoj-Kesana self-assigned this Feb 19, 2026
@Manoj-Kesana Manoj-Kesana added the ready for review PR is ready for review and merging label Feb 19, 2026
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a new Azure Network Security assessment (TestId 25533) to validate that public IP addresses are protected by Azure DDoS Protection (either IP Protection directly on the public IP or Network Protection inherited from the associated VNET), along with the accompanying remediation guidance content.

Changes:

  • Introduces Test-Assessment-25533 PowerShell test that queries Azure Resource Graph for public IPs, NIC/VNET associations, and VNET DDoS settings, then generates a markdown report.
  • Adds markdown description/remediation content for test 25533 (note: currently added with an uppercase .MD extension).

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 3 comments.

File Description
src/powershell/tests/Test-Assessment.25533.ps1 New assessment logic + reporting for DDoS protection coverage of public IPs.
src/powershell/tests/Test-Assessment.25533.MD New test description and remediation links (currently named with .MD, which breaks repo’s .md loader on case-sensitive systems).

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@Manoj-Kesana Manoj-Kesana removed the ready for review PR is ready for review and merging label Feb 20, 2026
SagarSathe and others added 7 commits February 20, 2026 14:11
Network - 26887 - Diagnostic logging is enabled in Azure Firewall
Network - 26888 - Diagnostic logging is enabled in Application Gateway WAF
Network 25375: GSA Licenses are available in the Tenant and assigned to users
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
@Manoj-Kesana
Copy link
Collaborator Author

Will raise a fresh PR. to avoid merge conflicts

@Manoj-Kesana Manoj-Kesana changed the title Network - 25533 - DDoS Protection is enabled for all Public IP Addresses in VNETs Network - 25533 - DDoS Protection is enabled for all Public IP Addresses in VNETs #DUP Feb 20, 2026
@Manoj-Kesana Manoj-Kesana deleted the Feature-25533 branch February 20, 2026 16:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants