| name | cis-azure-foundations-8.3.6 |
| description | Ensure that Private Endpoints are Used for Azure Key Vault |
| category | cis-azure-foundations |
| version | 5.0.0 |
| author | cyberstrike-official |
| tags | ["cis","azure","security","key-vault","private-endpoints","networking"] |
| cis_id | 8.3.6 |
| cis_benchmark | CIS Microsoft Azure Foundations Benchmark v5.0.0 |
| tech_stack | ["azure"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
8.3.6 Ensure that Private Endpoints are Used for Azure Key Vault (Automated)
Description
Ensure that Azure Key Vaults are configured with private endpoints, enabling secure access to Key Vault over a private link from within the virtual network and eliminating exposure to the public internet.
Rationale
By default, Azure Key Vault is accessible over the public internet. While access is still protected by authentication and authorization, exposing Key Vault to the public internet increases the attack surface and risk of data exfiltration. Private endpoints provide a private IP address within the virtual network for Key Vault, ensuring all traffic between the virtual network and Key Vault traverses the Microsoft backbone network. This eliminates exposure to the public internet and provides network-level isolation.
Impact
Configuring private endpoints requires additional networking setup including virtual network configuration, private DNS zones, and potentially changes to existing network architecture. Applications accessing Key Vault must be within the virtual network or connected via VPN/ExpressRoute. External access from outside the network will be blocked unless also allowed via firewall rules. This may require changes to CI/CD pipelines and developer workflows.
Audit Procedure
From Azure Portal:
- Go to
Key vaults.
- Click the name of a Key Vault.
- Under
Settings, click Networking.
- Click the
Private endpoint connections tab.
- Verify that at least one private endpoint connection exists with a status of
Approved.
From Azure CLI:
az keyvault list --query "[].name" -o tsv
For each Key Vault:
az keyvault private-endpoint-connection list --vault-name {vaultName} --query "[].{Name:name, Status:properties.privateLinkServiceConnectionState.status}" -o table
Ensure at least one connection exists with status Approved.
From PowerShell:
Get-AzKeyVault | ForEach-Object {
$connections = Get-AzPrivateEndpointConnection -PrivateLinkResourceId $_.ResourceId
[PSCustomObject]@{
VaultName = $_.VaultName
PrivateEndpoints = $connections.Count
Status = ($connections | Select-Object -ExpandProperty PrivateLinkServiceConnectionState).Status
}
}
Ensure each vault has at least one private endpoint with Approved status.
Expected Result
All Key Vaults should have at least one private endpoint connection with an status.