Reports for Every Cloud
Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.
58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results

Governance Best Practices
47 controls
6 services covered
Checks Azure governance controls across Advisor, subscription IAM, tenant settings, activity monitoring, policy-change alerts, Defender contacts and integrations, and Defender plan coverage for key service families.
What we check
Defender Plan Coverage13
- Microsoft Defender for Cloud is Enabled for Virtual Machines
- Defender for Cloud is Enabled for SQL Servers
- Defender for Cloud is Enabled for App Services
- Defender for Cloud is Enabled for Storage Accounts
- Defender for Cloud is Enabled for Sql Server Virtual Machines
- Defender for Cloud is Enabled for Key Vaults
- Defender for Cloud is Enabled for Arm
- Defender for Cloud is Enabled for Open Source Relational Databases
- Defender for Cloud is Enabled for Cosmos DBs
- Defender for Cloud is Enabled for Containers
- Defender for Cloud is Enabled for Cloud Posture
- Defender for Cloud is Enabled for API
- Microsoft Defender for DNS is Enabled
Subscription IAM Governance9
- Subscription Should Have More Than 1 Owner Assigned
- Subscription Should Have Maximum of 3 Owners Assigned
- Audit Usage of Custom RBAC Roles
- Subscriptions with custom roles should not be overly permissive
- Blocked accounts with owner permissions on Azure resources should be removed
- Remove Guest Accounts with Owner Permissions on Azure Resources
- Ensure that no custom subscription owner roles are created
- Use of the 'User Access Administrator' role should be restricted
- IAM users should not have built in contributor role
Tenant Governance8
- Security Defaults are Enabled on Azure Active Directory
- Admin Consent Workflow is Enabled
- Ensure User Consent for Applications is Disabled
- Ensure User Consent is Limited to Verified Publishers and Selected Permissions
- Ensure Microsoft 365 Group Creation is Disabled
- Ensure third party integrated applications are not allowed
- Ensure Users Cannot Create Security Groups
- Ensure Users Cannot Create Tenants
Policy and Activity Monitoring7
- Log Profile Enabled for All Subscriptions
- Diagnostic Settings Exists for Subscription
- Diagnostic Settings Capture Required Categories
- Log Profile Retention 365 Days
- Log Alert for Administrative Operations
- Create Policy Assignment Log Alert Exists
- Delete Policy Assignment Log Alert Exists
Defender Governance6
- 'Additional email addresses' is Configured with a Security Contact Email
- 'All users with the following roles' is set to 'Owner'
- Alert Notifications are Enabled
- 'Log Analytics agent/Azure Monitor agent' is Enabled
- Microsoft Defender for Cloud Apps Integration is Enabled in Defender for Cloud
- Microsoft Defender for Endpoint Integration is Enabled in Defender for Cloud
Advisor and Quota Governance4
- Azure Advisor Should Be Enabled
- Resource Quota Limit Reached
- Azure Advisor Recommendations should be Followed
- General Cost Optimization should be Applied
Run these reports on your own cloud
Connect an account and get your first set of reports in minutes — free to start, no credit card required.
