116 checks across every corner of the subscription
An agentless scan reads each connected Azure subscription through a read-only service principal and runs 116 checks — a 100-check baseline plus a 12-check App Service / Function Apps gap pack — flagging public exposure, weak identity, and misconfiguration.
Entra & identity
Global Administrator sprawl and privileged accounts without MFA, legacy authentication left enabled, dormant and guest accounts, and whether Conditional Access or security defaults actually cover the tenant’s sign-ins.
Storage
Public blob and container access, account-level public access left allowed, secure-transfer and minimum-TLS enforcement, blob soft-delete, infrastructure encryption, and shared-key access open to the internet.
Network & NSG
Network security groups exposing RDP, SSH and database ports to 0.0.0.0/0, over-permissive inbound rules, unprotected public IPs, and missing NSG flow logs across the virtual network.
Key Vault
Soft-delete and purge protection, public network access, the RBAC-versus-access-policy model, key and secret expiration, and firewall or private-endpoint restriction on every vault.
Virtual Machines
Unencrypted OS and data disks, missing encryption-at-host, directly attached public IPs, absent endpoint protection, and managed-identity and boot-diagnostics posture across every VM.
SQL & databases
Server firewalls that allow all Azure services or the whole internet, Transparent Data Encryption, auditing, a Microsoft Entra admin, Defender for SQL, and minimum-TLS enforcement on managed databases.
Defender for Cloud
Which Defender plans are switched on across resource types, Secure Score, agent auto-provisioning and a security-contact email — plus the AKS and Microsoft Sentinel coverage that rounds out the baseline.
App Service & Functions
The 12-check gap pack: HTTPS-only and minimum TLS 1.2, FTPS state, managed identity, client certificates, diagnostics, public access, built-in authentication, end-of-life runtimes, IP restrictions, and plaintext secrets in app settings.
Network & data-flow diagram
Every VNet, subnet, gateway, firewall and storage account, auto-drawn into the network and data-flow diagram PCI DSS 1.2.3 / 1.2.4 (and CMMC, ISO 27001, SOC 2, HIPAA) require — generated from the live scan and exportable as SVG for auditors.