๐ก๏ธ Azure Databricks Workspace does not use private endpoint connections๐ข
- Contextual name: ๐ก๏ธ Databricks Workspace does not use private endpoint connections๐ข
- ID:
/ce/ca/azure/databricks/private-endpoint-connection - Tags:
- ๐ข Policy with categories
- ๐ข Policy with type
- ๐ข Production policy
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
SECURITY
Logicโ
- ๐ง prod.logic.yaml๐ข
Descriptionโ
Descriptionโ
This policy identifies Azure Databricks Workspaces that do not utilize private endpoints.
Private endpoints provide secure, private connectivity to Azure Databricks workspaces over an encrypted Azure Private Link. Each service receives an IP address from the associated Virtual Network (VNet), ensuring that network traffic between clients, services, and resources remains private and encrypted. Private endpoints also enable network segmentation, hybrid connectivity through VNet peering or VPN/ExpressRoute, and secure tunneling across public networks, reducing exposure to external threats.
Rationaleโ
Using private endpoints for Azure Databricks workspaces ensures that all communication occurs over a private IP space within a customer-managed VNet, eliminating exposure to the public internet. This approach:
- Minimizes the attack surface and supports Zero Trust principles.
- Enables network segmentation and fine-grained access control.
- Supports hybrid connectivity for accessing on-premises or remote resources securely.
... see more
Remediationโ
Remediationโ
From Azure Portalโ
- Go to
Azure Databricks.- Click the name of a workspace.
- Under
Settings, clickNetworking.- Click
Private endpoint connections.- Click
+ Private endpoint.- Under
Project details, select aSubscriptionand aResource group.- Under
Instance details, provide aName,Network Interface Name, and select aRegion.- Click
Next : Resource }}.- Select a
Target sub-resource.- Click
Next : Virtual Network }}.- Under
Networking, select aVirtual networkand aSubnet.- Optionally, configure
Private IP configurationandApplication security group.- Click
Next : DNS }}.- Optionally, configure
Private DNS integration.- Click
Next : Tags }}.- Optionally, configure tags.
- Click
Next : Review + create }}.- Click
Create.- Repeat steps 1-18 for each workspace requiring remediation.
From Azure CLIโ
For each workspace requiring remediation, run the following command to create a private endpoint connection:
az network private-endpoint create /
... [see more](remediation.md)
policy.yamlโ
Linked Framework Sectionsโ
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| ๐ผ CIS Azure v5.0.0 โ ๐ผ 2.1.11 Ensure private endpoints are used to access Azure Databricks workspaces (Automated) | 1 | no data | |||
| ๐ผ Cloudaware Framework โ ๐ผ Secure Access | 67 | no data |