The 63 Azure security checks Black Cat runs
Black Cat SSPM evaluates 63 security policies against your Azure configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect Azure — what access Black Cat needs, and why.
Access control & privilege
8 checks · highest severity: high
Encryption, keys & secrets
3 checks · highest severity: high
Logging & audit
13 checks · highest severity: high
Configuration hardening
38 checks · highest severity: critical
Access control & privilege (8)
- Owner Count Exceeded severity: medium
- Custom Admin Roles severity: medium
- Classic Administrators severity: medium
- Guest Privileged Role severity: high
- Key Vault RBAC Not Enabled severity: high
- SQL AD Admin Not Configured severity: high
- App Service Managed Identity Disabled severity: high
- App Service Auth Disabled severity: high
Encryption, keys & secrets (3)
- Storage Key Not Rotated severity: high
- Key Vault Key No Expiry severity: high
- Key Vault Secret No Expiry severity: high
Logging & audit (13)
- NSG Flow Logs Disabled severity: high
- Key Vault Diagnostic Logging Disabled severity: medium
- SQL Auditing Disabled severity: high
- SQL Audit Retention Short severity: medium
- App Service Logging Disabled severity: high
- Diagnostic Retention Short severity: medium
- Alert Policy Assignment Missing severity: medium
- Alert NSG Create Missing severity: medium
- Alert NSG Delete Missing severity: medium
- Alert Security Solution Create Missing severity: medium
- Alert Security Solution Delete Missing severity: medium
- Alert SQL Firewall Missing severity: medium
- Alert Disabled severity: medium
Configuration hardening (38)
- NSG Unrestricted SSH severity: critical
- NSG Unrestricted RDP severity: critical
- NSG All Ports Open severity: critical
- NSG UDP Open severity: high
- NSG Permissive Outbound severity: high
- Network Watcher Disabled severity: medium
- Storage HTTPS Not Required severity: high
- Storage Network Default Allow severity: high
- Storage Minimum TLS severity: high
- Storage Infrastructure Encryption Disabled severity: high
- Storage Blob Soft Delete Disabled severity: high
- Storage Container Soft Delete Disabled severity: high
- Key Vault Soft Delete Disabled severity: high
- Key Vault Purge Protection Disabled severity: high
- Key Vault Network ACLs Allow severity: high
- Key Vault No Private Endpoint severity: medium
- Defender Servers Disabled severity: high
- Defender App Service Disabled severity: high
- Defender SQL Disabled severity: high
- Defender Storage Disabled severity: high
- Defender Containers Disabled severity: high
- Defender Key Vault Disabled severity: high
- Defender Resource Manager Disabled severity: high
- Security Contact Email Missing severity: high
- Security Contact Phone Missing severity: low
- Security Alert Notifications Disabled severity: high
- SQL TDE Disabled severity: high
- SQL Firewall Allow Azure Services severity: medium
- SQL Firewall Unrestricted severity: critical
- SQL Minimum TLS severity: high
- SQL Vulnerability Assessment Disabled severity: high
- SQL Threat Detection Disabled severity: high
- App Service HTTPS Disabled severity: high
- App Service Minimum TLS severity: high
- App Service FTP Enabled severity: high
- App Service Remote Debugging Enabled severity: high
- App Service HTTP/2 Disabled severity: low
Other checks (1)
severity: high Storage Public Blob Access fix difficulty: easy #
Disable public blob access on the storage account to prevent anonymous data exposure
- Navigate to the Azure Portal and open Storage accounts
- Select the flagged storage account and click Configuration
- Locate the Allow Blob public access setting
- Set the toggle to Disabled
- Click Save to apply the change
- Review any existing public containers and remove public access at the container level if needed
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11