Repository navigation
v1.20.0-B0085
Pre-release
Pre-release
·
1345 commits
to main
since this release
What's changed since pre-release v1.20.0-B0028:
- New rules:
- Azure Cache for Redis:
- Check the number of firewall rules for caches by Johnny Ruiz (@jonathanruiz).
#544 - Check the number of IP addresses in firewall rules for caches by Johnny Ruiz (@jonathanruiz).
#544
- Check the number of firewall rules for caches by Johnny Ruiz (@jonathanruiz).
- App Configuration:
- Check identity-based authentication is used for configuration stores by David Pazdera (@pazdedav).
#1691
- Check identity-based authentication is used for configuration stores by David Pazdera (@pazdedav).
- Container Registry:
- Check soft delete policy is enabled by @bengeset96.
#1674
- Check soft delete policy is enabled by @bengeset96.
- Defender for Cloud:
- Check Microsoft Defender for Cloud is enabled for Containers by jdewisscher.
#1632 - Check Microsoft Defender for Cloud is enabled for Virtual Machines by jdewisscher.
#1632 - Check Microsoft Defender for Cloud is enabled for SQL Servers by jdewisscher.
#1632 - Check Microsoft Defender for Cloud is enabled for App Services by jdewisscher.
#1632 - Check Microsoft Defender for Cloud is enabled for Storage Accounts by jdewisscher.
#1632 - Check Microsoft Defender for Cloud is enabled for SQL Servers on machines by jdewisscher.
#1632
- Check Microsoft Defender for Cloud is enabled for Containers by jdewisscher.
- Network Security Group:
- Check AKS managed NSGs don't contain custom rules by Sam Bell (@ms-sambell).
#8
- Check AKS managed NSGs don't contain custom rules by Sam Bell (@ms-sambell).
- Storage Account:
- Check blob container soft delete is enabled by David Pazdera (@pazdedav).
#1671 - Check file share soft delete is enabled by Johnny Ruiz (@jonathanruiz).
#966
- Check blob container soft delete is enabled by David Pazdera (@pazdedav).
- Azure Cache for Redis:
- Updated rules:
- Important change: Updated rules, tests and docs with Microsoft Defender for Cloud by Johnny Ruiz (@jonathanruiz).
#545- The following rules have been renamed with aliases:
- Renamed
Azure.SQL.ThreatDetectiontoAzure.SQL.DefenderCloud. - Renamed
Azure.SecurityCenter.ContacttoAzure.DefenderCloud.Contact. - Renamed
Azure.SecurityCenter.ProvisioningtoAzure.DefenderCloud.Provisioning.
- Renamed
- If you are referencing the old names please consider updating to the new names.
- The following rules have been renamed with aliases:
- Updated documentation examples for Front Door and Key Vault rules by Lyle (Microsoft) Luppes (@lluppesms).
#1667 - Improved the way we check that VM or VMSS has Linux by Vera Bogdanich Espina (@VeraBE)
#1704
- Important change: Updated rules, tests and docs with Microsoft Defender for Cloud by Johnny Ruiz (@jonathanruiz).
- General improvements:
- Updated NSG documentation with code snippets and links by Simone (@simone-bennett).
#1607 - Updated Application Gateway documentation with code snippets by Sam Bell (@ms-sambell).
#1608 - Updated SQL firewall rules documentation by Sam Bell (@ms-sambell).
#1569 - Updated Container Apps documentation and rule to new resource type by Marie Schmidt (@marie-schmidt).
#1672 - Updated KeyVault and FrontDoor documentation with code snippets by Lyle (Microsoft) Luppes (@lluppesms).
#1667 - Added tag and annotation metadata from policy for rules generation by @BernieWhite.
#1652
- Updated NSG documentation with code snippets and links by Simone (@simone-bennett).
- Bug fixes:
See change log