More Info:

Ensure that your Microsoft Azure Key Vaults are configured to deny access to traffic from all networks (including the public Internet). This adds an important layer of security.

Risk Level

Critical

Address

Security

Compliance Standards

CISAZURE, CBP

Triage and Remediation

Remediation

To remediate the misconfiguration of Default Network Access being unrestricted in Azure, follow these steps:

  1. Log in to the Azure portal (https://portal.azure.com/).
  2. Navigate to the resource group that contains the resources you want to secure.
  3. Select the Virtual Network that you want to secure.
  4. Click on the “Firewalls and virtual networks” tab.
  5. Under the “Firewalls and virtual networks” tab, select “Selected networks” to restrict access to the virtual network.
  6. Under the “Selected networks” option, select “Add existing virtual network”.
  7. Select the virtual network that you want to allow access to and click “Add”.
  8. Under the “Firewalls and virtual networks” tab, select “Selected IP addresses” to restrict access to specific IP addresses.
  9. Under the “Selected IP addresses” option, select “Add IP address range”.
  10. Enter the IP address range that you want to allow access to and click “Add”.
  11. Click “Save” to apply the changes.

By following these steps, you have successfully remediated the misconfiguration of Default Network Access being unrestricted in Azure.

Additional Reading: