turbot/steampipe-mod-azure-compliance

Control: Ensure 'Allow Public Network Access' is set to 'Disabled'

Description

Disable public network access to prevent exposure to the internet and reduce the risk of unauthorized access. Use private endpoints to securely manage access within trusted networks.

Usage

Run the control in your terminal:

powerpipe control run azure_compliance.control.databricks_workspace_public_network_access_disabled

Snapshot and share results via Turbot Pipes:

powerpipe login
powerpipe control run azure_compliance.control.databricks_workspace_public_network_access_disabled --share

SQL

This control uses a named query:

select
w.id as resource,
case
when public_network_access = 'Disabled' then 'ok'
else 'alarm'
end as status,
case
when public_network_access = 'Disabled' then name || ' public network access disabled.'
else name || ' public network access enabled.'
end as reason
, w.resource_group as resource_group
, sub.display_name as subscription
from
azure_databricks_workspace as w
left join azure_subscription sub on sub.subscription_id = w.subscription_id;

Tags