Security and Compliance
-
Enable Security Event Logs Collection
currently the Diagnostics Module does nott support collecting Security Event Logs.
This could be helpful in monitoring and real-time alerting of security events such as multiple log-in retries through RDP endpoint by a malware that's trying to hack into the VM, trying to invoke secure methods on the server and could help identify security breaches in our roles.
There should be some API that will enable the Diagnostics Agent collect Security Event Logs
441 votesHello. The engineering team is working on some updated guidance about security logs, but in the mean time there is an article on MSDN that may help: http://blogs.msdn.com/b/ericgolpe/archive/2012/04/30/the-easy-way-of-collecting-security-logs-from-your-windows-azure-roles.aspx.
We don’t currently have a firm date for the new documentation, but will update this forum as soon as it is published. Thanks!
-
Provide a dynamic security dashboard indicating how my Azure instances and services are protected.
Look at each role/endpoint and determine whether they are secure and if so, what type of security is used.
290 votesThank you for this suggestion! It has been escalated to the Windows Azure engineering team for further evaluation. We will post here to gather additional information as-appropriate.
-
211 votes
Thank you for this suggestion! It has been escalated to the Windows Azure engineering team for further evaluation. We will post here to gather additional information as-appropriate.
-
Really, really need to clarify the PCI Compliance documentation.
Make it simple on yourselves and your customers.
The PCI compliance center says: Scope: The Information Security Management System (ISMS) for Windows Azure, including infrastructure, development, operations and support for Compute, Data Services, App Services and Network Services are in scope for the PCI DSS Attestation of Compliance.
Which would seem to indicate that Azure is PCI compliant. The problem is that Azure encompasses at least 20 different services and not all of them are PCI compliant. For example Azure Web Sites ARE NOT PCI compliant because you can't turn off FTP. "Information Security Management System (ISMS) for Windows Azure"…
49 votesHi Joseph! Thanks for bringing this issue to our attention. We have recently published updates to the Microsoft Azure Trust Center [http://azure.microsoft.com/en-us/support/trust-center/compliance/], and we are planning on releasing updated guidance specifically covering PCI compliance. Keep an eye on the Trust Center Resources page for the latest information, as well as the Azure Security and Compliance blog at http://azure.microsoft.com/blog. Thank you for your patience! Best regards,
—Joel
-
PKI as a Azure Service
Certificate Services (ADCS/PKI/CA) should be offered as a service in Azure at least for infrastructure purpose such as machine certificates for MFM, Wi-Fi access and
for user web authentication e.g. to Azure itself. CA Private keys can be store in Azure Key Vault to be secured.
A hybrid client should be provided to support autoenrollment to Windows 7 and better clients to simulate a onprem Enterprise CA. The web interface should be in Azure and support other platforms than Windows.
I am willing to spend time and effort to be part of a user group, think tank, beta test group…41 votes -
Provide an updated Azure Customer PCI guide for version 3.0
The current documentation is for version 2, but Azure is now 3.0 compliant.
37 votes -
ECC support for Azure Key Vault
Give Azure Key Vault the option to perform Encrypt/Decrypt/Sign/Verify functions using ECC keypairs instead of using RSA keypairs.
This allows Azure Key Vault to create digital signatures which are far smaller to transmit and faster to verify than their RSA counterparts. This is an extremely useful function for many scenarios, such as deferring to Azure Key Vault for signing (and potentially verifying) JWT tokens for use as API access tokens.
31 votes -
Cover DocumentDB with HIPAA compliance
Hello,
we were looking forward to utilize the new DocumentDb service, if it had HIPAA compliance, to store some medical data.If it is possible we would like to know if the feature is already planned or in development.
Moreover, i know the service is "new" in azure, if you can specify it on the trust center page with a new line, I imagine it should not be considered under SQL or Storage
http://azure.microsoft.com/en-us/support/trust-center/services/
Thanks
25 votes -
Provide Better Developer Integration Experience for Azure Key Vault / Reduce Surface Area for Attacks
Currently Azure developers have to wrestle with how to protect the data that they would like to protect and retrieve with Azure Key Vault. Developers work in source control, and the data that they have to provide in app.config can be considered secret and/or sensitive. App.config can be checked into source control and can even be available as an open source project in GitHub for the whole world to see.
Even if a developer chooses to use a client ID and a certificate, the developer still has to provide a REST-based URL within the code base as well, and this…
19 votes -
FIPS compliant Azure PowerShell & AzCopy
You cannot authenticate via Azure PowerShell (Add-AzureAccount) on a machine with FIPS compliance as a Local Security policy (encryption used is not strong enough). Furthermore, AzCopy does not function between its encryption is not sufficient. It'd be great if these tools worked in our FedRAMP approved environment.
19 votes -
Azure should enable Remote Access Services (RAS) with Smart Cards for customers who want it.
Smart cards allow for a very high level of security. This is why Microsoft uses it for employees who need remote access to the Microsoft network. It’s difficult for an external computer to log onto the Microsoft network without a smart card. A user name and password is not enough.
A smart card would give some corporate customers confidence if they could give their employees a more secure way for logging onto their applications than standard credentials.
External consumers might want it too, to safeguard their identity. Such customers would have a choice of either the standard login or enhanced…
12 votesThank you bringing up this idea. As it happens, Smart Card access was covered in a TechNet blog post in October 2013: http://blogs.technet.com/b/kevinremde/archive/2013/10/01/windows-azure-and-smartcards-so-many-questions-so-little-time-part-47.aspx.
In addition, the new Windows Azure Multi-Factor Authentication capability provides further options for securing remote access. You can learn more about MFA and other Windows Azure Active Directory services here: http://www.windowsazure.com/en-us/solutions/identity/.
-
Add Timestamp Service to keyvault
Most HSMs provide the ablity to timesamp according to RFC standards. Please expose this ability via the Azure API.
9 votes -
Allow more finegrained control of baseline rules in security center.
At the moment you have to either disable or enable all the Baseline Rules.
This is bad. There are certain rules that a base installation with some services trigger. A good example is CCE-10274-9, this is trigger with a basic installation of ASP.NET - because all the ASP.NET accounts get added, which the baseline rule assumes to be a problem.
8 votes -
Allow regular scheduling of external scans for compliance activity
We use an external service (QualysGuard Express) to verify our applications meet requirements for PCIDSS or Information Security in general. We scan our applications every fortnight. I have to set these manually on both sides once approval is granted.
It would be extremely useful if I could nominate a recurring schedule for scanning.
6 votes -
Provide GUI for creating/administering Network Security Groups (NSG)
As above.
Maintaining this using a cache of powershell scripts becomes unmanageable very quickly.
6 votes -
Limit Endpoints where you can manage Azure from
I would love to have a possibility to control what endpoints you are allowed to manage your Azure Services from. Like an ACL, management can be done from these endpoints (ip addresses) and from no place else. Today we have to use ADFS and special domains in the UPN to be able to resolve this. But it doesn't apply for all accounts.
So having that possibility would be great. Jump Servers has been used for many years in the on-prem world. And even if you use MFA there is no way to guarantee that the endpoint that you are managing…
3 votes -
Dashbord security administrator where we can find all resources avaliably via RBAC for some AD User
RBAC is cool, but managing rights in huge enterprise environment is too hard.
We need a dashboard, where security administrator will can input user name from AzureAD and on a dashboard will be all subscriptions, resource groups and resources with effective user permissions3 votes -
Allow me to run ISO 27001 service using all Microsoft PaaS, make it easy to tell which ones I cannot use
Currently, the trust center says many PaaS are ISO 27001. Microsoft also has a document that recommends encryption for all services on Azure: https://azure.microsoft.com/en-us/blog/13-effective-security-controls-for-iso-27001-compliance/
Yet, HDInsight, and other services, do not offer encryption, which violates the 13 effective security controls.
It would be helpful if Microsoft could provide guidance on how to deal with this.
3 votes -
CipherDB provides highest security and compliance to .NET developers for securing their Application on Azure Cloud
Solution: CipherDB on Azure Marketplace enables applications to be PCI, HIPAA, CIJS, FIP-140-2 compliant in any environment by providing military grade encryption and robust automated key management.
http://azure.microsoft.com/en-us/marketplace/partners/crypteron/cipherdb/
www.cipherdb.com3 votes -
Send Security mails to AAD Security Contact and make it available in the Azure/O365 Portal
I would like that the Azure AD Security Contact be made available from both the Azure Portal (Ibiza) and the Office 365 Portal. It should be part the basic configuration for Office 365 like the Technical Contact Azure.
"Set-MsolCompanySecurityComplianceContactInformation cmdlet"
https://msdn.microsoft.com/da-dk/library/azure/dn912658.aspx
If some part of the customers Azure virtual machine or other parts of their deployments like website is hit my an attack, exploit, being hijacked or other please make sure that the person(s) part of the AA Security Contact list gets this information so they can act on the knowledge.
2 votes
- Don't see your idea?
