More Info:

Ensure that, Allow trusted Microsoft services to bypass this firewall, exception is enabled within your Azure Key Vault network settings in order to grant vault access to trusted Azure cloud services.

Risk Level

High

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the misconfiguration of enabling Trusted Microsoft Services access for Key Vault in AZURE, you can follow the below steps:

  1. Login to the AZURE portal (https://portal.azure.com/) using your credentials.

  2. Navigate to the Key Vault service from the left-hand side menu.

  3. Select the Key Vault for which you want to enable Trusted Microsoft Services access.

  4. Click on the “Access policies” option from the left-hand side menu.

  5. Click on the ”+ Add Access Policy” button to add a new access policy.

  6. In the “Add access policy” blade, select “Azure Key Vault” for “Configure from template”.

  7. In the “Secret permissions” section, select the permissions that you want to grant to the Trusted Microsoft Services.

  8. In the “Select principal” section, select “Microsoft.AzureServices.AppAuthentication” as the principal.

  9. Click on the “Add” button to add the access policy.

  10. Click on the “Save” button to save the changes.

Once the above steps are completed, Trusted Microsoft Services access will be enabled for the selected Key Vault in AZURE.

Additional Reading: