All features Cloud · Azure

CSPM for every Azure subscription

116 checks across Entra identity, Storage, Network, Key Vault, VMs, SQL, Defender for Cloud, App Service and resource hygiene (unattached public IPs, unattached disks, orphaned NICs, empty resource groups) — misconfiguration and public exposure surfaced per subscription.

Get started Run a free scan
116Azure checks
8services
Persubscription
azure-security-posture 50
STORStoragePASS
NETWNetworkCHECK
KEYKey VaultFAIL
DEFEDefenderPASS
What we check across Azure

116 checks across every corner of the subscription

An agentless scan reads each connected Azure subscription through a read-only service principal and runs 116 checks — a 100-check baseline plus a 12-check App Service / Function Apps gap pack — flagging public exposure, weak identity, and misconfiguration.

Entra & identity

Global Administrator sprawl and privileged accounts without MFA, legacy authentication left enabled, dormant and guest accounts, and whether Conditional Access or security defaults actually cover the tenant’s sign-ins.

Storage

Public blob and container access, account-level public access left allowed, secure-transfer and minimum-TLS enforcement, blob soft-delete, infrastructure encryption, and shared-key access open to the internet.

Network & NSG

Network security groups exposing RDP, SSH and database ports to 0.0.0.0/0, over-permissive inbound rules, unprotected public IPs, and missing NSG flow logs across the virtual network.

Key Vault

Soft-delete and purge protection, public network access, the RBAC-versus-access-policy model, key and secret expiration, and firewall or private-endpoint restriction on every vault.

Virtual Machines

Unencrypted OS and data disks, missing encryption-at-host, directly attached public IPs, absent endpoint protection, and managed-identity and boot-diagnostics posture across every VM.

SQL & databases

Server firewalls that allow all Azure services or the whole internet, Transparent Data Encryption, auditing, a Microsoft Entra admin, Defender for SQL, and minimum-TLS enforcement on managed databases.

Defender for Cloud

Which Defender plans are switched on across resource types, Secure Score, agent auto-provisioning and a security-contact email — plus the AKS and Microsoft Sentinel coverage that rounds out the baseline.

App Service & Functions

The 12-check gap pack: HTTPS-only and minimum TLS 1.2, FTPS state, managed identity, client certificates, diagnostics, public access, built-in authentication, end-of-life runtimes, IP restrictions, and plaintext secrets in app settings.

Network & data-flow diagram

Every VNet, subnet, gateway, firewall and storage account, auto-drawn into the network and data-flow diagram PCI DSS 1.2.3 / 1.2.4 (and CMMC, ISO 27001, SOC 2, HIPAA) require — generated from the live scan and exportable as SVG for auditors.

How it connects

A read-only service principal, then it runs itself

Connecting a subscription is a one-time app registration granted read-only access — no agent to install, and no write permissions anywhere in your environment.

Read-only service principal

A single app registration is granted the built-in Reader role at the subscription scope, plus read-only Microsoft Graph. Provide the tenant, application and subscription IDs once and the subscription is connected. No agent, and no write access anywhere in the environment.

Continuous re-scan

Once connected, the subscription is re-scanned on a schedule with the same zero footprint. Each scan tracks what is new and what has been resolved since last time, so both drift and fixes surface on their own.

Unified findings

Azure findings land in the same queue as every other source — ranked by real-world risk, paired with AI remediation guidance, mapped to your compliance frameworks, and folded into cross-surface attack paths.

Part of one platform

Cloud exposure, in the context of everything else

Azure posture never sits in its own console. Every finding is correlated with your Windows, Linux and macOS endpoint agents and your M365 / Entra identity data on one platform — so a public storage account or an over-privileged role becomes a named step in a real attack path, not an isolated ticket.

  • Correlated with endpoint & M365 / Entra
  • Findings become steps in named attack paths
  • KEV / EPSS-ranked, real-world severity
  • Paired with AI remediation, mapped to 10 frameworks
See the full platform
82
+27 pts
projected after top fixes

Run your first scan free

See a client’s real posture in minutes — then unlock all 1,692 checks.