🚀Launch Week 08, April 14th - 18th, 2025🚀
Policy Packs
Azure CIS v2.0.0 - Section 4 - Database Services

Permissions

The Azure CIS v2.0.0 - Section 4 - Database Services policy pack requires 20 permissions:

  • Application.Read.All
  • Group.Read.All
  • User.Read.All
  • microsoft.dbformysql/flexibleservers/configurations/write
  • microsoft.dbforpostgresql/flexibleservers/configurations/write
  • microsoft.dbforpostgresql/servers/configurations/write
  • microsoft.dbforpostgresql/servers/delete
  • microsoft.dbforpostgresql/servers/write
  • microsoft.documentdb/databaseaccounts/write
  • microsoft.sql/servers/administrators/delete
  • microsoft.sql/servers/administrators/write
  • microsoft.sql/servers/auditingsettings/write
  • microsoft.sql/servers/azureadonlyauthentications/delete
  • microsoft.sql/servers/azureadonlyauthentications/write
  • microsoft.sql/servers/databases/transparentdataencryption/write
  • microsoft.sql/servers/firewallrules/delete
  • microsoft.sql/servers/securityalertpolicies/write
  • microsoft.sql/servers/vulnerabilityassessments/write
  • microsoft.storage/storageaccounts/listkeys/action
  • microsoft.storage/storageaccounts/read