Guidance for Hardening Nerdio Manager Storage Accounts?

Hello,

There is guidance around hardening the Nerdio App Service and there is also guidance around hardening the Nerdio SQL Server. 

We would really like to see guidance around hardening Nerdio-related/created storage accounts.

If Public Network Access is restricted on the Nerdio Storage accounts, we fail to run custom scripts with the following error, “Error: This request is not authorized to perform this operation.” 

Is there a workaround that we are unaware of?

5

Comments (3 comments)

0
Avatar
Dave Stephenson

Great idea, Peter Gibbons.

We don't have anything like that, yet. We do have some guidance for our Nerdio for Enterprise product, but the MSP edition is considerably more complicated with the multi-tenant configurations we need to take into account.

Can you expand a little more on your use-case for this?
Is it just one of those "if we can, we should" scenarios or are you trying to meet some kind of compliance requirement?

1
Avatar
Martijn Van Braeckel
(Edited )

We're also looking into the possibility to harden storage accounts.
At this time MS Defender for cloud marks the recommendations below on the Nerdio Storage accounts.

Recommendation 1: Storage account public access should be disallowed
Recommendation 2: Storage accounts should only be accessible private via private endpoint
Recommendation 3: Storage accounts should prevent shared key access

0
Avatar
Luke Reilly

Hi guys, we are also very interested in this. We are measuring our customer deployments against the following regulatory compliance recommendations:

  • Microsoft cloud security benchmark
  • CIS Azure Foundations

We have implemented a NAT gateway with VNet integration for the NMM app service and attempted to restrict public access to the storage accounts using the egress IP of the NAT gateway (as per the guide below) but this configuration broke some of the Nerdio functionality (as described above).

App Service NAT Gateway Integration – Nerdio Help Center

When we enabled logging on the storage account, the IPs we observed attempting to connect to the storage account did not match the NAT IP we had assigned. We were able to observe some activity in the Entra logs showing the NAT IP but for some reason this was not the case for the storage account.

 

Please sign in to leave a comment.