You may see that the ASC Default Azure Policy makes the Nerdio Manager look like a security issue. This article explains how to mitigate this issue.
To mitigate the Defender for Cloud alerts:
-
TLS should be updated to latest version for web apps.
Note
This can be changed on existing installs with no adverse effects.
-
SQL Servers should have an Entra ID administrator provisioned.
Note
-
This can be changed on existing installs with no adverse effects.
-
Ensure the option to Support only Entra ID authentication for this server is not enabled.
-
See this Microsoft article for additional information.
-
-
SQL Servers should have vulnerability assessment configured.
Warning
This option adds a significant cost because of Defender for SQL,
Note
-
This can be changed on existing installs with no adverse effects.
-
See this Microsoft article for additional information.
-
-
FTPS should be required in web apps.
Note
-
This can be changed on existing installs with no adverse effects.
-
See this Microsoft article for additional information.
-
-
Key Vaults should have soft delete enabled.
Note
-
This can be changed on existing installs with no adverse effects.
-
See this Microsoft article for additional details.
-
-
Microsoft Defender for SQL should be enabled for unprotected Azure SQL servers.
Warning
This option adds a significant cost because of Defender for SQL,
Note
This can be changed on existing installs with no adverse effects.
-
Public network access on Azure SQL Database should be disabled.
Note
-
Public access can be disabled, but the option to Allow Azure services and resources to connect to this server must be enabled.
-
See this Microsoft article for additional details.
-
-
A firewall should be enabled on Key Vault.
Comments (0 comments)