Reports for Every Cloud
Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.
58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results

Database Best Practices
87 controls
12 services covered
Reviews Azure database services, including SQL, MySQL, PostgreSQL, MariaDB, Cosmos DB, Redis, Data Explorer, and Synapse, for private access, public exposure, logging, TLS, encryption, backup, vulnerability assessment, and availability controls.
What we check
SQL Servers15
- Azure Active Directory Authentication is Configured for SQL Databases
- Databases Servers Public Network Access Disabled
- SQL Database Allow Internet Access Disabled
- SQL Servers use Private Link
- SQL Servers use a Virtual Network Service Endpoint
- Auditing is Enabled for SQL Servers
- SQL Server Auditing Retention Period 90 Days
- Servers TDE CMK Encryption Enabled
- SQL Server Threat Detection Enabled for All Servers
- Microsoft Defender for Cloud is Enabled SQL Servers
- Vulnerability Assessment should be Enabled on your SQL Servers
- SQL Database Vulnerability Assessment Findings are Resolved
- SQL Server Vulnerability Assessment Periodic Scans Enabled
- SQL Server Vulnerability Assessment Reports Notify Admins
- SQL Server Vulnerability Assessment Scan Reports Configured
PostgreSQL Servers13
- PostgreSQL TLS Enabled
- PostgreSQL Servers 'Minimum TLS version' should be set to '1.2'
- PostgreSQL Server All IP Access Disabled
- PostgreSQL Servers Public Network Access Disabled
- PostgreSQL Servers should use Private Link
- Infrastructure Encryption is Enabled for PostgreSQL Servers
- Geo-Redundant Backup Should Be Enabled For PostgreSQL Servers
- PostgreSQL DB Server Connection Throttling On
- Postgres DB Server Log Checkpoints On
- Connection Logging is Enabled for PostgreSQL Servers
- Postgres DB Server Log Disconnections On
- PostgreSQL Server Log Duration Enabled
- Postgres DB Server Log Retention Days 3
PostgreSQL Flexible Servers11
- PostgreSQL Flexible Server All IP Access Disabled
- PostgreSQL Flexible Servers Public Network Access Disabled
- PostgreSQL Flexible Servers should use Private Link
- PostgreSQL Flexible Servers Should be Encrypted with CMK
- PostgreSQL Flexible Servers TLS Enabled
- Geo-Redundant Backup Should Be Enabled For PostgreSQL Flexible Servers
- Connection Throttling is Enabled for PostgreSQL Flexible Servers
- Postgres Flexible Servers Log Checkpoints Parameter Enabled
- Postgres Flexible Servers Log Connections Parameter Enabled
- Postgres Flexible Servers Log Disconnections Parameter Enabled
- Postgres Flexible Servers Log Retention Days Parameter
Cosmos DB Accounts10
- CosmosDB Account Should Use CMK To Encrypt Data At Rest
- CosmosDB Account Should Disable Key Based Metadata Write Access
- Cosmos DB account 'Access Control' should be configured to use Azure Active Directory (AAD) and Role-Based Access Control (RBAC)
- CosmosDB Account Use Private Link
- CosmosDB Account Has Virtual Network Filter Enabled
- CosmosDB Account Should Have Firewall Rules
- Configure CosmosDB to Use a Virtual Network Service Endpoint
- Idle Cosmos DB Containers should be Checked
- Cosmos DB should use Manual Throughput
- Cosmos DB Autoscale should be Enabled
Redis Caches8
- Only Secure Connections to Azure Cache for Redis Should be Enabled
- Redis Cache Enforces TLS 1.2 or higher
- Azure Cache for Redis Should Use Standard SKUs as a Minimum
- Azure Cache for Redis Should Use Private Link
- Azure Cache for Redis Should Reside Within a Virtual Network
- Redis Enterprise Cache Enforces TLS 1.2 or higher
- Azure Cache for Redis Enterprise Should Use Private Link
- Azure Cache for Redis Enterprise Should Reside Within a Virtual Network
Data Explorer Clusters6
- Disk Encryption Should Be Enabled On Azure Data Explorer
- Double Encryption Should Be Enabled On Azure Data Explorer
- Azure Data Explorer Encryption At Rest Should Use A CMK
- Azure Data Explorer Clusters Should Use SKU With An SLA
- Data Explorer Table Cache Policy should be Configured
- Data Ingestion Anomalies should be Detected
MySQL Servers6
- MySQL TLS Enabled
- MySQL Servers 'TLS Version' should be set to 'TLSV1.2'
- Audit Logs are Enabled for MySQL Servers
- Connection Events Audit Logging are Enabled for MySQL Servers
- Servers CMK Encryption at Rest
- Servers Infrastructure Encryption Enabled
MySQL Flexible Servers6
- MySQL Flexible Servers 'tls_version' should be set to 'TLSv1.2' or higher
- Audit Logs are Enabled for MySQL Flexible Servers
- Connection Events Audit Logging are Enabled for MySQL Flexible Servers
- Flexible Servers CMK Encryption at Rest
- MySQL Flexible Servers TLS Enabled
- Geo-Redundant Backup Should Be Enabled For MySQL MySQL Flexible Servers
MariaDB Servers4
- MariaDB Server Geo-Redundant Backup Enabled
- MariaDB Servers use Private Link
- MariaDB Server Public Network Access Disabled
- MariaDB Server TLS Enabled
Synapse Workspaces4
- Synapse Workspaces Should Have Data Exfiltration Protection Enabled
- Synapse Workspaces Should Use Customer-Managed Keys to Encrypt Data at Rest
- Synapse Workspaces Use Private Link
- Synapse Workspace Managed SQL Server Vulnerability Assessment is Enabled
SQL Databases2
- SQL Database Long Term Geo-Redundant Backup Enabled
- SQL Server Database Transparent Data Encryption Enabled
SQL Managed Instances2
- Managed Instance Encryption At Rest Uses CMK
- Managed Instance Vulnerability Assessment Enabled
Run these reports on your own cloud
Connect an account and get your first set of reports in minutes — free to start, no credit card required.
