[ Applies to ] StorageGuard / Azure storage and backup / Cloud Storage & STaaS
This article lists the recommended baseline checks for Azure storage and backup. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
Azure storage and backup services include Azure Blob Storage for object storage, Azure Files, Azure Disk Storage for block storage, the Archive access tier for long-term retention and Azure Backup for data protection.
Why hardening Azure storage and backup matters
Public access, weak shared access signatures and missing immutability are common causes of cloud data exposure. Validating encryption, access policies, network restrictions and backup settings protects stored data and backup copies from unauthorized access and loss.
Recommended baseline checks
The baseline below contains 11 checks, listed alphabetically.
| ID | Configuration check |
|---|---|
| SG-C0519T233V01 | Approved blob data soft deleted retention period |
| SG-F9118T233V01 | Blob container stored access policy maximum duration |
| SG-C0518T233V01 | Blob lifecycle management configuration |
| SG-C0517T233V01 | Blob lifecycle management status |
| SG-C0516T233V01 | Delete policy status |
| SG-C0068T233V01 | Hardware-based encryption status - Azure Storage Account |
| SG-C0381T233V01 | HTTP service status - Azure Storage Account |
| SG-F7446T233V01 | Permissive blob container stored access policy |
| SG-C0515T233V01 | Public access blocked at storage account level |
| SG-C0514T233V01 | Public access to activity monitoring blob web container |
| SG-C0390T233V01 | TLS level - Azure Storage Account |
Related components
A complete baseline also covers the components that manage, connect to or protect Azure storage and backup. Review the configuration of:
- Microsoft Entra ID
- Azure Key Vault
- Recovery Services and Backup vaults
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.