Policy: Azure > CIS v3.0 > 08 - Virtual Machines > 08.07 - Ensure that Only Approved Extensions Are Installed
Configures auditing against a CIS Benchmark item.
Level: 1
For added security, only install organization-approved extensions on VMs.
Azure virtual machine extensions are small applications that provide post-deployment configuration and automation tasks on Azure virtual machines. These extensions run with administrative privileges and could potentially access anything on a virtual machine. The Azure Portal and community provide several such extensions. Each organization should carefully evaluate these extensions and ensure that only those that are approved for use are actually implemented.
Targets
This policy targets the following resource types:
Primary Policy
This policy is used with the following primary policy:
Related Policies
Policy Specification
Schema Type |
|
---|---|
Default |
|
Valid Values [YAML] |
|
Category
In Your Workspace
Developers
- tmod:@turbot/cis#/control/categories/v070201
- tmod:@turbot/azure-cisv3-0#/policy/types/r0807
- turbot graphql policy-type --id "tmod:@turbot/azure-cisv3-0#/policy/types/r0807"
- turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/azure-cisv3-0#/policy/types/r0807"
Get Policy TypeGet Policy Settings
Category URI
Policy Type URI
GraphQL
CLI