π‘οΈ Azure Key Vault Private Endpoints are not usedπ’
- Contextual name: π‘οΈ Private Endpoints are not usedπ’
- ID:
/ce/ca/azure/key-vault/private-endpoints-use - Tags:
- π’ Policy with categories
- π’ Policy with type
- π’ Production policy
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
SECURITY
Logicβ
- π§ prod.logic.yamlπ’
Similar Policiesβ
- Internal:
dec-x-807a37c9
Similar Internal Rulesβ
| Rule | Policies | Flags |
|---|---|---|
| βοΈ dec-x-807a37c9 | 1 |
Descriptionβ
Descriptionβ
Use private endpoints to allow clients and services to securely access data located over a network via an encrypted Private Link. To do this, the private endpoint uses an IP address from the VNet for each service. Network traffic between disparate services securely traverses encrypted over the VNet. This VNet can also link addressing space, extending your network and accessing resources on it. Similarly, it can be a tunnel through public networks to connect remote infrastructures together. This creates further security through segmenting network traffic and preventing outside sources from accessing it.
Private endpoints will secure network traffic from Azure Key Vault to the resources requesting secrets and keys.
Rationaleβ
Securing traffic between services through encryption protects the data from easy interception and reading.
Private endpoints will keep network requests to Azure Key Vault limited to the endpoints attached to the resources that are whitelisted to communicate with each other. Assigning the Key Vault to a network without an endpoint will allow other resources on that network to view all traffic from the Key Vault to its destination. In spite of the complexity in configuration, this is recommended for high security secrets.
... see more
Remediationβ
Remediationβ
Please see the additional information about the requirements needed before starting this remediation procedure.
From Azure Portalβ
- From Azure Home open the Portal Menu in the top left.
- Select
Key Vaults.- Select a Key Vault to audit.
- Select
Networkingin the left column.- Select
Private endpoint connectionsfrom the top row.- Select
+ Create.- Select the subscription the Key Vault is within, and other desired configuration.
- Select
Next.- For resource type select
Microsoft.KeyVault/vaults.- Select the Key Vault to associate the Private Endpoint with.
- Select
Next.- In the
Virtual Networkingfield, select the network to assign the Endpoint.- Select other configuration options as desired, including an existing or new application security group.
- Select
Next.- Select the private DNS the Private Endpoints will use.
- Select
Next.- Optionally add
Tags.- Select
Next : Review + Create.- Review the information and select
Create. Follow the Audit Procedure to determine if it has successfully applied.... see more