Security and Compliance

How can we improve Windows Azure security and compliance?

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  1. Enable Security Event Logs Collection

    currently the Diagnostics Module does nott support collecting Security Event Logs.

    This could be helpful in monitoring and real-time alerting of security events such as multiple log-in retries through RDP endpoint by a malware that's trying to hack into the VM, trying to invoke secure methods on the server and could help identify security breaches in our roles.

    There should be some API that will enable the Diagnostics Agent collect Security Event Logs

    441 votes
    Vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      3 comments  ·  Flag idea as inappropriate…  ·  Admin →
    • Provide a dynamic security dashboard indicating how my Azure instances and services are protected.

      Look at each role/endpoint and determine whether they are secure and if so, what type of security is used.

      290 votes
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        I agree to the terms of service
        Signed in as (Sign out)
        You have left! (?) (thinking…)
        0 comments  ·  Flag idea as inappropriate…  ·  Admin →
        under review  ·  Joel SlossJoel Sloss responded

        Thank you for this suggestion! It has been escalated to the Windows Azure engineering team for further evaluation. We will post here to gather additional information as-appropriate.

      • 211 votes
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          I agree to the terms of service
          Signed in as (Sign out)
          You have left! (?) (thinking…)
          5 comments  ·  Flag idea as inappropriate…  ·  Admin →
          under review  ·  Joel SlossJoel Sloss responded

          Thank you for this suggestion! It has been escalated to the Windows Azure engineering team for further evaluation. We will post here to gather additional information as-appropriate.

        • Really, really need to clarify the PCI Compliance documentation.

          Make it simple on yourselves and your customers.

          The PCI compliance center says: Scope: The Information Security Management System (ISMS) for Windows Azure, including infrastructure, development, operations and support for Compute, Data Services, App Services and Network Services are in scope for the PCI DSS Attestation of Compliance.

          Which would seem to indicate that Azure is PCI compliant. The problem is that Azure encompasses at least 20 different services and not all of them are PCI compliant. For example Azure Web Sites ARE NOT PCI compliant because you can't turn off FTP. "Information Security Management System (ISMS) for Windows Azure"…

          49 votes
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            I agree to the terms of service
            Signed in as (Sign out)
            You have left! (?) (thinking…)
            7 comments  ·  Flag idea as inappropriate…  ·  Admin →

            Hi Joseph! Thanks for bringing this issue to our attention. We have recently published updates to the Microsoft Azure Trust Center [http://azure.microsoft.com/en-us/support/trust-center/compliance/], and we are planning on releasing updated guidance specifically covering PCI compliance. Keep an eye on the Trust Center Resources page for the latest information, as well as the Azure Security and Compliance blog at http://azure.microsoft.com/blog. Thank you for your patience! Best regards,

            —Joel

          • PKI as a Azure Service

            Certificate Services (ADCS/PKI/CA) should be offered as a service in Azure at least for infrastructure purpose such as machine certificates for MFM, Wi-Fi access and
            for user web authentication e.g. to Azure itself. CA Private keys can be store in Azure Key Vault to be secured.
            A hybrid client should be provided to support autoenrollment to Windows 7 and better clients to simulate a onprem Enterprise CA. The web interface should be in Azure and support other platforms than Windows.
            I am willing to spend time and effort to be part of a user group, think tank, beta test group…

            41 votes
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              I agree to the terms of service
              Signed in as (Sign out)
              You have left! (?) (thinking…)
              0 comments  ·  Flag idea as inappropriate…  ·  Admin →
            • Provide an updated Azure Customer PCI guide for version 3.0

              The current documentation is for version 2, but Azure is now 3.0 compliant.

              37 votes
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                I agree to the terms of service
                Signed in as (Sign out)
                You have left! (?) (thinking…)
                1 comment  ·  Flag idea as inappropriate…  ·  Admin →
              • ECC support for Azure Key Vault

                Give Azure Key Vault the option to perform Encrypt/Decrypt/Sign/Verify functions using ECC keypairs instead of using RSA keypairs.

                This allows Azure Key Vault to create digital signatures which are far smaller to transmit and faster to verify than their RSA counterparts. This is an extremely useful function for many scenarios, such as deferring to Azure Key Vault for signing (and potentially verifying) JWT tokens for use as API access tokens.

                31 votes
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  I agree to the terms of service
                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                  5 comments  ·  Flag idea as inappropriate…  ·  Admin →
                • Cover DocumentDB with HIPAA compliance

                  Hello,
                  we were looking forward to utilize the new DocumentDb service, if it had HIPAA compliance, to store some medical data.

                  If it is possible we would like to know if the feature is already planned or in development.

                  Moreover, i know the service is "new" in azure, if you can specify it on the trust center page with a new line, I imagine it should not be considered under SQL or Storage

                  http://azure.microsoft.com/en-us/support/trust-center/services/

                  Thanks

                  25 votes
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    I agree to the terms of service
                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                    1 comment  ·  Flag idea as inappropriate…  ·  Admin →
                  • Provide Better Developer Integration Experience for Azure Key Vault / Reduce Surface Area for Attacks

                    Currently Azure developers have to wrestle with how to protect the data that they would like to protect and retrieve with Azure Key Vault. Developers work in source control, and the data that they have to provide in app.config can be considered secret and/or sensitive. App.config can be checked into source control and can even be available as an open source project in GitHub for the whole world to see.

                    Even if a developer chooses to use a client ID and a certificate, the developer still has to provide a REST-based URL within the code base as well, and this…

                    19 votes
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      I agree to the terms of service
                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                      1 comment  ·  Flag idea as inappropriate…  ·  Admin →
                    • FIPS compliant Azure PowerShell & AzCopy

                      You cannot authenticate via Azure PowerShell (Add-AzureAccount) on a machine with FIPS compliance as a Local Security policy (encryption used is not strong enough). Furthermore, AzCopy does not function between its encryption is not sufficient. It'd be great if these tools worked in our FedRAMP approved environment.

                      19 votes
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        I agree to the terms of service
                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                        2 comments  ·  Flag idea as inappropriate…  ·  Admin →
                      • Azure should enable Remote Access Services (RAS) with Smart Cards for customers who want it.

                        Smart cards allow for a very high level of security. This is why Microsoft uses it for employees who need remote access to the Microsoft network. It’s difficult for an external computer to log onto the Microsoft network without a smart card. A user name and password is not enough.

                        A smart card would give some corporate customers confidence if they could give their employees a more secure way for logging onto their applications than standard credentials.

                        External consumers might want it too, to safeguard their identity. Such customers would have a choice of either the standard login or enhanced…

                        12 votes
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          I agree to the terms of service
                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                          1 comment  ·  Flag idea as inappropriate…  ·  Admin →
                          under review  ·  Joel SlossJoel Sloss responded

                          Thank you bringing up this idea. As it happens, Smart Card access was covered in a TechNet blog post in October 2013: http://blogs.technet.com/b/kevinremde/archive/2013/10/01/windows-azure-and-smartcards-so-many-questions-so-little-time-part-47.aspx.

                          In addition, the new Windows Azure Multi-Factor Authentication capability provides further options for securing remote access. You can learn more about MFA and other Windows Azure Active Directory services here: http://www.windowsazure.com/en-us/solutions/identity/.

                        • Add Timestamp Service to keyvault

                          Most HSMs provide the ablity to timesamp according to RFC standards. Please expose this ability via the Azure API.

                          9 votes
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            I agree to the terms of service
                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                            0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                          • Allow more finegrained control of baseline rules in security center.

                            At the moment you have to either disable or enable all the Baseline Rules.

                            This is bad. There are certain rules that a base installation with some services trigger. A good example is CCE-10274-9, this is trigger with a basic installation of ASP.NET - because all the ASP.NET accounts get added, which the baseline rule assumes to be a problem.

                            8 votes
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              I agree to the terms of service
                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                              0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                            • Allow regular scheduling of external scans for compliance activity

                              We use an external service (QualysGuard Express) to verify our applications meet requirements for PCIDSS or Information Security in general. We scan our applications every fortnight. I have to set these manually on both sides once approval is granted.

                              It would be extremely useful if I could nominate a recurring schedule for scanning.

                              6 votes
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                I agree to the terms of service
                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                                0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                              • Provide GUI for creating/administering Network Security Groups (NSG)

                                As above.

                                Maintaining this using a cache of powershell scripts becomes unmanageable very quickly.

                                6 votes
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  I agree to the terms of service
                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                  1 comment  ·  Flag idea as inappropriate…  ·  Admin →
                                • Limit Endpoints where you can manage Azure from

                                  I would love to have a possibility to control what endpoints you are allowed to manage your Azure Services from. Like an ACL, management can be done from these endpoints (ip addresses) and from no place else. Today we have to use ADFS and special domains in the UPN to be able to resolve this. But it doesn't apply for all accounts.

                                  So having that possibility would be great. Jump Servers has been used for many years in the on-prem world. And even if you use MFA there is no way to guarantee that the endpoint that you are managing…

                                  3 votes
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    I agree to the terms of service
                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                    0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                                  • Dashbord security administrator where we can find all resources avaliably via RBAC for some AD User

                                    RBAC is cool, but managing rights in huge enterprise environment is too hard.
                                    We need a dashboard, where security administrator will can input user name from AzureAD and on a dashboard will be all subscriptions, resource groups and resources with effective user permissions

                                    3 votes
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      I agree to the terms of service
                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                      0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                                    • Allow me to run ISO 27001 service using all Microsoft PaaS, make it easy to tell which ones I cannot use

                                      Currently, the trust center says many PaaS are ISO 27001. Microsoft also has a document that recommends encryption for all services on Azure: https://azure.microsoft.com/en-us/blog/13-effective-security-controls-for-iso-27001-compliance/

                                      Yet, HDInsight, and other services, do not offer encryption, which violates the 13 effective security controls.

                                      It would be helpful if Microsoft could provide guidance on how to deal with this.

                                      3 votes
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        I agree to the terms of service
                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)
                                        0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                                      • CipherDB provides highest security and compliance to .NET developers for securing their Application on Azure Cloud

                                        Solution: CipherDB on Azure Marketplace enables applications to be PCI, HIPAA, CIJS, FIP-140-2 compliant in any environment by providing military grade encryption and robust automated key management.
                                        http://azure.microsoft.com/en-us/marketplace/partners/crypteron/cipherdb/
                                        www.cipherdb.com

                                        3 votes
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          I agree to the terms of service
                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)
                                          0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                                        • Send Security mails to AAD Security Contact and make it available in the Azure/O365 Portal

                                          I would like that the Azure AD Security Contact be made available from both the Azure Portal (Ibiza) and the Office 365 Portal. It should be part the basic configuration for Office 365 like the Technical Contact Azure.

                                          "Set-MsolCompanySecurityComplianceContactInformation cmdlet"

                                          https://msdn.microsoft.com/da-dk/library/azure/dn912658.aspx

                                          If some part of the customers Azure virtual machine or other parts of their deployments like website is hit my an attack, exploit, being hijacked or other please make sure that the person(s) part of the AA Security Contact list gets this information so they can act on the knowledge.

                                          2 votes
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            I agree to the terms of service
                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                            0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                                          ← Previous 1
                                          • Don't see your idea?

                                          Security and Compliance

                                          Feedback and Knowledge Base