Control: Azure > Cognitive Services > Account > Firewall
Determine the firewall settings required for Azure > Cognitive Services > Account.
The Firewall control governs the account's networkAcls.defaultAction: Allow all networks (defaultAction = Allow) or Allow only approved virtual networks and IP ranges (defaultAction = Deny). When set to an Enforce value, a non-compliant account is remediated in place by updating networkAcls.defaultAction; existing IP and virtual-network allow-rules are preserved.
Resource Types
This control targets the following resource types:
Policies
The following policies can be used to configure this control:
Permissions
Cloud permissions used by this control and its actions:
microsoft.cognitiveservices/accounts/write
Category
In Your Workspace
Developers
- tmod:@turbot/azure-cognitiveservices#/control/types/accountFirewall
- tmod:@turbot/turbot#/control/categories/security
- turbot graphql controls --filter "controlTypeId:tmod:@turbot/azure-cognitiveservices#/control/types/accountFirewall"
Get Controls
Control Type URI
Category URI
GraphQL
CLI