Azure Advertizer Data Diff Report Resource Type: microsoft.app/containerapps -------------------------------------------------- New Advisor Recommendations: - [Authentication should be enabled on Azure Container Apps](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/8c7d9a3e-5f4b-4e1a-9d2c-7b8e3f6a1d4c) - [Azure Container Apps should not be exposed to the public internet unless required](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/4f6e5d7e-1c0d-4e2f-b8a9-0b1c2d3e4f5a) - [Managed identities assigned to Azure Container Apps should follow least privilege](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/2d4f3e5e-9a8b-4c0d-b6e7-8f9a0b1c2d3e) Resource Type: microsoft.containerinstance/containergroups -------------------------------------------------- New Advisor Recommendations: - [Azure Container Instances should not be publicly exposed](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/3b8c6f2a-7d4e-4a9b-8e5f-1c9d3a7b6e4f) - [Managed identities assigned to Azure Container Instances should follow least privilege](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/6e9a2d5c-4b8f-4d3a-9e7b-5f2c8a1d4e7b) Resource Type: microsoft.network/azurefirewalls -------------------------------------------------- New APRL Recommendations: - [Monitor "AZFW Latency Probe" metric](https://azure.github.io/Azure-Proactive-Resiliency-Library-v2/azure-resources/Network/azureFirewalls/#monitor-azfw-latency-probe-metric) Resource Type: microsoft.security/awsresource -------------------------------------------------- New Advisor Recommendations: - [Avoid the use of the "root" account](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/a47a6c3b-0629-406c-ad09-d91f7d9f78a3) - [IAM policies that allow full "*:*" administrative privileges should not be created](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/1d08b362-7e24-46b0-bed1-4a6c1d1526a5) - [ECS Fargate tasks should not be publicly exposed](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/b7f4c8e2-3d91-4a6f-9f2a-8c5d7e1a4b39) - [IAM task roles assigned to ECS Fargate tasks should follow least privilege](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/8f3d2c7a-4b91-4e6b-9a2e-7c1f8b2d3e45) - [ECS Fargate tasks should not run containers with elevated privileges](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/3a7e9f4b-6c28-4d1a-8b5f-2e9c7d8a1f34) Resource Type: microsoft.workloads/virtualinstances/components -------------------------------------------------- New Advisor Recommendations: - [Ensure PREFER_SITE_TAKEOVER is set to true for high availability (HA) SAP workloads on RHEL](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/600720f1-fe59-48eb-9d29-0c261bb44ac3) - [Ensure STONITH is enabled in the high availability (HA) configuration for SAP workloads on RHEL](https://portal.azure.com/#view/Microsoft_Azure_Expert/RecommendationList.ReactView/recommendationTypeId/98dd295e-59d5-40f7-a0aa-5cbedfe627b0)
Azure Advertizer Data Diff Report
Resource Type: microsoft.app/containerapps
New Advisor Recommendations:
- Authentication should be enabled on Azure Container Apps
- Azure Container Apps should not be exposed to the public internet unless required
- Managed identities assigned to Azure Container Apps should follow least privilege
Resource Type: microsoft.containerinstance/containergroups
New Advisor Recommendations:
- Azure Container Instances should not be publicly exposed
- Managed identities assigned to Azure Container Instances should follow least privilege
Resource Type: microsoft.network/azurefirewalls
New APRL Recommendations:
- Monitor "AZFW Latency Probe" metric
Resource Type: microsoft.security/awsresource
New Advisor Recommendations:
- Avoid the use of the "root" account
- IAM policies that allow full ":" administrative privileges should not be created
- ECS Fargate tasks should not be publicly exposed
- IAM task roles assigned to ECS Fargate tasks should follow least privilege
- ECS Fargate tasks should not run containers with elevated privileges
Resource Type: microsoft.workloads/virtualinstances/components
New Advisor Recommendations:
- Ensure PREFER_SITE_TAKEOVER is set to true for high availability (HA) SAP workloads on RHEL
- Ensure STONITH is enabled in the high availability (HA) configuration for SAP workloads on RHEL