This security baseline applies guidance from the Microsoft cloud security benchmark version 1.0 to Resource Mover. The Microsoft cloud security benchmark provides recommendations on how you can secure your cloud solutions on Azure. The content is grouped by the security controls defined by the Microsoft cloud security benchmark and the related guidance applicable to Resource Mover.
You can monitor this security baseline and its recommendations using Microsoft Defender for Cloud. Azure Policy definitions will be listed in the Regulatory Compliance section of the Microsoft Defender for Cloud portal page.
When a feature has relevant Azure Policy Definitions, they are listed in this baseline to help you measure compliance with the Microsoft cloud security benchmark controls and recommendations. Some recommendations may require a paid Microsoft Defender plan to enable certain security scenarios.
Piezīme
Features not applicable to Resource Mover have been excluded. To see how Resource Mover completely maps to the Microsoft cloud security benchmark, see the full Resource Mover security baseline mapping file.
Security profile
The security profile summarizes high-impact behaviors of Resource Mover, which may result in increased security considerations.
Service Behavior Attribute
Value
Product Category
MGMT/Governance, Migration
Customer can access HOST / OS
No Access
Service can be deployed into customer's virtual network
IM-3: Manage application identities securely and automatically
Features
Managed Identities
Description: Data plane actions support authentication using managed identities. Learn more.
Supported
Enabled By Default
Configuration Responsibility
True
False
Shared
Feature notes: The feature is within an underlying resource section and service doesn't configure any default settings.
Configuration Guidance: Use Azure managed identities instead of service principals when possible, which can authenticate to Azure services and resources that support Azure Active Directory (Azure AD) authentication. Managed identity credentials are fully managed, rotated, and protected by the platform, avoiding hard-coded credentials in source code or configuration files.
Description: Data plane supports authentication using service principals. Learn more.
Supported
Enabled By Default
Configuration Responsibility
True
False
Customer
Configuration Guidance: There is no current Microsoft guidance for this feature configuration. Please review and determine if your organization wants to configure this security feature.
PA-7: Follow just enough administration (least privilege) principle
Features
Azure RBAC for Data Plane
Description: Azure Role-Based Access Control (Azure RBAC) can be used to managed access to service's data plane actions. Learn more.
Supported
Enabled By Default
Configuration Responsibility
True
False
Shared
Feature notes: This feature is within an underlying resource type and the user has to manually check in order to view and make any necessary changes to RBAC. No default role is assigned by the service.
Brief steps at Azure portal,
Enterprise applications
Filter application type to "Managed Identity"
Search for corresponding Move-collection name
Configuration Guidance: Use Azure role-based access control (Azure RBAC) to manage Azure resource access through built-in role assignments. Azure RBAC roles can be assigned to users, groups, service principals, and managed identities.
Description: Service supports data in-transit encryption for data plane. Learn more.
Supported
Enabled By Default
Configuration Responsibility
True
True
Microsoft
Feature notes: Azure Resource Movers supports TLS 1.2 which is enabled on the service by default and not configurable by the end user.
Configuration Guidance: No additional configurations are required as this is enabled on a default deployment.
DP-4: Enable data at rest encryption by default
Features
Data at Rest Encryption Using Platform Keys
Description: Data at-rest encryption using platform keys is supported, any customer content at rest is encrypted with these Microsoft managed keys. Learn more.
Supported
Enabled By Default
Configuration Responsibility
True
True
Microsoft
Feature notes: Azure Resource Mover supports data at rest encryption by default and cannot be disabled by users.
Configuration Guidance: No additional configurations are required as this is enabled on a default deployment.