Control: Azure > CIS v4.0 > 09 - Security Services > 09.03 - Key Vault > 09.03.08 - Ensure that Private Endpoints are Used for Azure Key Vault
Configures auditing against a CIS Benchmark item.
Level: 2
Private endpoints will secure network traffic from Azure Key Vault to the resources requesting secrets and keys.
Private endpoints will keep network requests to Azure Key Vault limited to the endpoints attached to the resources that are whitelisted to communicate with each other. Assigning the Key Vault to a network without an endpoint will allow other resources on that network to view all traffic from the Key Vault to its destination. In spite of the complexity in configuration, this is recommended for high security secrets.
By default, Private Endpoints are not enabled for any services within Azure.
Resource Types
This control targets the following resource types:
Policies
This control type relies on these other policies when running actions:
- Azure > CIS v4.0 > 09 - Security Services > 09.03 - Key Vault > 09.03.08 - Ensure that Private Endpoints are Used for Azure Key Vault
- Azure > CIS v4.0
- Azure > CIS v4.0 > 09 - Security Services
Category
In Your Workspace
Developers
- tmod:@turbot/azure-cisv4-0#/control/types/r090308
- tmod:@turbot/cis#/control/categories/v071401
- turbot graphql controls --filter "controlTypeId:tmod:@turbot/azure-cisv4-0#/control/types/r090308"
Get Controls