Giter Club home page Giter Club logo

azure-blueprint's People

Contributors

bhavyasinghal avatar davoodharun avatar dciceman avatar jomolesk avatar justinbacaais avatar manishkumar-agarwal avatar reetikatech avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

azure-blueprint's Issues

Account Management Principals

For all accounts , as applicable (e.g OS-level, RDP, Azure Portal):

  • Automatic disable of temporary accounts, inactive accounts
  • Inactivity logout / session termination
  • Unsuccessful logon attempts
  • System use notification
  • Concurrent session control
  • Session lock, termination

Boundary protection

  • Deny by default
  • Restrict incoming traffic
  • Application firewall
  • NSGs
  • Host-based firewall

password validation not working for keyvault creation

while running powershell script for keyvault.
given password in simple string ie. reetikatech and its accepted and created successfully. without validation check mentioned in #7.
also displayed error on powershell screen but still created key vault.

Deployment failed due to wafEnabled setting

Able to run and deploy in new resource group with provided steps it was successfully deployed yesterday for today displaying below error in template
for web application firewall enabled
ie. "wafEnabled": true
Deployment template validation failed: 'The value for the template parameter 'wafEnabled' at line '50' and column '20' is not provided. Please see https://aka.ms/arm-deploy/#parameter-file for usage details.'.

(Code: InvalidTemplate)

Uniform baseline applied to operating systems

  • Baseline deviation reporting in OMS via Automation
  • OS baseline configuration requirements
    • Limit software installation
    • Signed components only
    • Whitelisting
    • Alerting if unauthorized software installed
    • Least functionality (ports, protocols, services, etc.)

SQL AO extension timeout while deploying template

The template errored out while installing extension on SQLAO VM with message- "Provisioning of VM extension 'sqlAOPrepare' has timed out. Extension installation may be taking too long, or extension status could not be obtained.

This was while deploying the template for Azure commercial subscription. I forked the azure-blueprint directory to my own github repo and changed the values to deploy in an azure non-gov subscription.

Rest of the deployment succeeded.

3

Not dispalying connected servers under AZ-MGT-VM

Resource group: bPrint700
Steps:
Remote desktop login to AZ-MGT-VM publicip: 57.227.167.226

observation:
yesterday:
when previously logged in its displaying all Servers under MGT server,using resource group Blueprint40.
today :resource group bprint700 displaying no servers under MGT server.

image

Partitioning

  • user / admin function separation
  • security function isolation
  • bastion host / management subnet
  • NSGs
    • Security component isolation
    • SQL tier / DB tier separation

Backup

  • User-level
  • System-level
  • Encrypted (SSE)
  • Dashboard reporting

Password Restrictions

  • Strong initial password
  • Minimum lifetime (1 day)
  • Maximum lifetime (60 days)
  • Complexity (14 char. length, at least one of each: upper case, lower case, number, special char.)
  • Change entropy (at least 50%)
  • Reuse restrictions (24 generations)
  • Change at first logon requirement [do not enable in ref. arch.]
  • Password strength enforcement
  • Storage/transmission encryption

Patching

  • Windows update configured
  • Dashboard reporting in OMS

Anti-malware [SI-3(1), SI-3(2), SI-3(7)]

  • Installed/configured on operating systems
    • automatic signature updates
    • periodic scanning
    • real-time detection
    • detection action(s)
    • nonsignature-based detection
    • logging/alerting
    • OMS reporting
  • Application firewall
    • Inbound/outbound traffic monitoring

All VM Disks are not encrypted

in reference to the issue #35 information at rest
issue All Diskes should be encrypted
steps:
Checked disk encryption of all VMs
Expected : encrypted
Actual: not encrypted
image

Azure Commercial support

Hi Harun,

I am facing errors in the template- it errors out while provisioning the virtual machines:
1

When I looked at the template from where it is provisioning the diagnostic storage account- it is giving the URI as “blob.core.usgovcloudapi.net”
2

Please let me know what to do.

Thanks
Bhavya

Role Based Access Control (RBAC)

  • OS roles, Azure roles
  • Separation of duties
  • Least privilege – e.g.:
    • Security admin
    • Web admin
    • DB admin
    • Audit manager

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.