Azure Misconfigurations
Key Vault Audit
Checks performed
- AuditEvent logging should be enabled
- Key Vault Recoverability should be enabled
- Enable Trusted Microsoft Services access for Key Vault
- Default Network Access should be restricted
- User, Group or Applications have full administrator privileges
- Keys should have an expiration time
- Keys are about to expire and need rotation
- Secrets should have an expiration time
- Secrets are about to expire and need rotation
- Auto Renewal should be enabled for SSL Certificates
- Certificates have insufficient auto renewal period
- Certificates key size is less than recommended key size
- Certificate Transparency should be enabled
- Check for Allowed Certificate Key Types
- Enable Azure Resource Locks