| name | cis-azure-compute-2.1.18 |
| description | Ensure app is integrated with a virtual network |
| category | cis-azure-compute |
| version | 2.0.0 |
| author | cyberstrike-official |
| tags | ["cis","azure","app-service","vnet-integration","virtual-network","network-security"] |
| cis_id | 2.1.18 |
| cis_benchmark | CIS Microsoft Azure Compute Services Benchmark v2.0.0 |
| tech_stack | ["azure"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
Ensure app is integrated with a virtual network
Description
Integrate App Service apps with a virtual network to enable access to resources in or through a non-internet-routable virtual network.
Rationale
Integrate App Service apps with a virtual network for increased security and control.
Impact
Additional configuration may be required to ensure that traffic is routed properly.
Audit Procedure
Using Azure Portal
- Go to
App Services.
- Click the name of an app.
- Under
Settings, click Networking.
- Under
Outbound traffic configuration, next to Virtual network integration, ensure that a virtual network and subnet name are displayed.
- Repeat steps 1-4 for each app.
Using Azure CLI
Run the following command to list apps:
az webapp list
For each app, run the following command to get the virtual network subnet ID:
az webapp show --resource-group <resource-group-name> --name <app-name> --query "virtualNetworkSubnetId"
Ensure that a virtual network subnet ID is returned.
Using Azure PowerShell
Run the following command to list apps:
Get-AzWebApp
Run the following command to get the app in a resource group with a given name:
$app = Get-AzWebapp -ResourceGroupName <resource-group-name> -Name <app-name>
Run the following command to get the virtual network subnet ID:
$app.virtualNetworkSubnetId
Ensure that a virtual network subnet ID is returned. Repeat for each app.
Expected Result
A virtual network subnet ID should be returned, indicating the app is integrated with a virtual network.
Remediation
Using Azure Portal
- Go to
App Services.
- Click the name of an app.
- Under
Settings, click Networking.
- Under
Outbound traffic configuration, next to Virtual network integration, click Not configured.
- Click
Add virtual network integration.
- Select an existing App Service Plan connection, or select and select a subscription, virtual network, and subnet.