Cosmos DB - oWretch/policy GitHub Wiki

Policy Effects by Policy

Category Policy Platform Landing Zones Production Decommissioned Management Corp Connectivity Sandbox Identity
Cosmos DB Azure Cosmos DB accounts should have firewall rules
Firewall rules should be defined on your Azure Cosmos DB accounts to prevent traffic from unauthorized sources. Accounts that have at least one IP rule defined with the virtual network filter enabled are deemed compliant. Accounts disabling public access are also deemed compliant.
Deny
Disabled
Audit
Deny
Disabled
Audit
Audit
Deny
Disabled
Cosmos DB Azure Cosmos DB accounts should use customer-managed keys to encrypt data at rest
Use customer-managed keys to manage the encryption at rest of your Azure Cosmos DB. By default, the data is encrypted at rest with service-managed keys, but customer-managed keys are commonly required to meet regulatory compliance standards. Customer-managed keys enable the data to be encrypted with an Azure Key Vault key created and owned by you. You have full control and responsibility for the key lifecycle, including rotation and management. Learn more at https://aka.ms/cosmosdb-cmk.
deny
disabled
audit
deny
disabled
audit
disabled
deny
audit
Cosmos DB Azure Cosmos DB key based metadata write access should be disabled
This policy enables you to ensure all Azure Cosmos DB accounts disable key based metadata write access.
append append
Cosmos DB Azure Cosmos DB should disable public network access
Disabling public network access improves security by ensuring that your CosmosDB account isn't exposed on the public internet. Creating private endpoints can limit exposure of your CosmosDB account. Learn more at: https://docs.microsoft.com/azure/cosmos-db/how-to-configure-private-endpoints#blocking-public-network-access-during-account-creation.
Audit
Deny
Disabled
Deny
Disabled
Audit
Cosmos DB Configure Cosmos DB database accounts to disable local authentication
Disable local authentication methods so that your Cosmos DB database accounts exclusively require Azure Active Directory identities for authentication. Learn more at: https://docs.microsoft.com/azure/cosmos-db/how-to-setup-rbac#disable-local-auth.
Modify
Disabled
Modify
Disabled
Cosmos DB Configure CosmosDB accounts to disable public network access
Disable public network access for your CosmosDB resource so that it's not accessible over the public internet. This can reduce data leakage risks. Learn more at: https://docs.microsoft.com/azure/cosmos-db/how-to-configure-private-endpoints#blocking-public-network-access-during-account-creation.
Modify
Disabled
Modify
Disabled
Cosmos DB Configure CosmosDB accounts to use private DNS zones
Use private DNS zones to override the DNS resolution for a private endpoint. A private DNS zone links to your virtual network to resolve to CosmosDB account. Learn more at: https://aka.ms/privatednszone.
DeployIfNotExists
Disabled
Cosmos DB Configure CosmosDB accounts to use private DNS zones
Use private DNS zones to override the DNS resolution for a private endpoint. A private DNS zone links to your virtual network to resolve to CosmosDB account. Learn more at: https://aka.ms/privatednszone.
DeployIfNotExists
Disabled
Cosmos DB Configure CosmosDB accounts to use private DNS zones
Use private DNS zones to override the DNS resolution for a private endpoint. A private DNS zone links to your virtual network to resolve to CosmosDB account. Learn more at: https://aka.ms/privatednszone.
DeployIfNotExists
Disabled
Cosmos DB Configure CosmosDB accounts to use private DNS zones
Use private DNS zones to override the DNS resolution for a private endpoint. A private DNS zone links to your virtual network to resolve to CosmosDB account. Learn more at: https://aka.ms/privatednszone.
DeployIfNotExists
Disabled
Cosmos DB Configure CosmosDB accounts to use private DNS zones
Use private DNS zones to override the DNS resolution for a private endpoint. A private DNS zone links to your virtual network to resolve to CosmosDB account. Learn more at: https://aka.ms/privatednszone.
DeployIfNotExists
Disabled
Cosmos DB Cosmos DB database accounts should have local authentication methods disabled
Disabling local authentication methods improves security by ensuring that Cosmos DB database accounts exclusively require Azure Active Directory identities for authentication. Learn more at: https://docs.microsoft.com/azure/cosmos-db/how-to-setup-rbac#disable-local-auth.
Deny
Disabled
Audit
Deny
Disabled
Audit
Audit
Deny
Disabled
Cosmos DB CosmosDB accounts should use private link
Azure Private Link lets you connect your virtual network to Azure services without a public IP address at the source or destination. The Private Link platform handles the connectivity between the consumer and services over the Azure backbone network. By mapping private endpoints to your CosmosDB account, data leakage risks are reduced. Learn more about private links at: https://docs.microsoft.com/azure/cosmos-db/how-to-configure-private-endpoints.
Audit
Disabled
Cosmos DB Deploy Advanced Threat Protection for Cosmos DB Accounts
This policy enables Advanced Threat Protection across Cosmos DB accounts.
DeployIfNotExists
Disabled
DeployIfNotExists
Disabled

Policy Parameters by Policy

Category Policy Platform Landing Zones Production Decommissioned Management Corp Connectivity Sandbox Identity
Cosmos DB Configure CosmosDB accounts to use private DNS zones
Use private DNS zones to override the DNS resolution for a private endpoint. A private DNS zone links to your virtual network to resolve to CosmosDB account. Learn more at: https://aka.ms/privatednszone.
azureCosmosTablePrivateDnsZoneId = --DNSZonePrefix--privatelink.table.cosm...
Cosmos DB Configure CosmosDB accounts to use private DNS zones
Use private DNS zones to override the DNS resolution for a private endpoint. A private DNS zone links to your virtual network to resolve to CosmosDB account. Learn more at: https://aka.ms/privatednszone.
azureCosmosCassandraPrivateDnsZoneId = --DNSZonePrefix--privatelink.cassandra....
Cosmos DB Configure CosmosDB accounts to use private DNS zones
Use private DNS zones to override the DNS resolution for a private endpoint. A private DNS zone links to your virtual network to resolve to CosmosDB account. Learn more at: https://aka.ms/privatednszone.
azureCosmosSQLPrivateDnsZoneId = --DNSZonePrefix--privatelink.documents....
Cosmos DB Configure CosmosDB accounts to use private DNS zones
Use private DNS zones to override the DNS resolution for a private endpoint. A private DNS zone links to your virtual network to resolve to CosmosDB account. Learn more at: https://aka.ms/privatednszone.
azureCosmosGremlinPrivateDnsZoneId = --DNSZonePrefix--privatelink.gremlin.co...
Cosmos DB Configure CosmosDB accounts to use private DNS zones
Use private DNS zones to override the DNS resolution for a private endpoint. A private DNS zone links to your virtual network to resolve to CosmosDB account. Learn more at: https://aka.ms/privatednszone.
azureCosmosMongoPrivateDnsZoneId = --DNSZonePrefix--privatelink.mongo.cosm...
⚠️ **GitHub.com Fallback** ⚠️