INTERACTIVE SECURITY ASSESSMENT

Azure Security Checklist

Review Microsoft Entra ID, Azure subscriptions, networking, storage, compute, Key Vault, logging, and Defender for Cloud controls.

ASSESSMENT FOCUS

What this checklist covers

  • Entra ID roles, MFA, and Conditional Access
  • Subscription and management-group governance
  • Network segmentation and private endpoints
  • Storage, Key Vault, and managed identities
  • Defender for Cloud, activity logs, and alerting

REFERENCE BASELINE

Standards and guidance

  • Microsoft Cloud Security Benchmark
  • CIS Microsoft Azure Foundations
  • Azure Well-Architected Framework

Tailor every control to the system's architecture, data classification, threat model, and written scope.

Open the interactive checklist

Search controls, filter by severity, expand technical guidance, and keep progress in your browser.

Start assessment β†’

How to use it professionally

Before testing

Confirm authorization, scope, exclusions, test windows, data handling, emergency contacts, and stop conditions.

During testing

Record the asset, request, expected control, observed result, evidence, and any cleanup action. Avoid destructive proof when a safer validation demonstrates the same issue.

After testing

Deduplicate related symptoms, identify the root cause, assign risk in business context, provide actionable remediation, and retest the final implementation.