
Microsoft Azure
Mycroft tests your Azure subscriptions daily for RBAC assignments, encryption, network exposure, Key Vault configuration and log retention.
Azure estates spread across subscriptions faster than they are documented, and the control that fails is rarely the one being watched. Mycroft reads configuration at subscription or management group scope and ingests Defender for Cloud findings into the vulnerability queue.
How Mycroft connects to Microsoft Azure
- How it connects
- You register an application in Entra ID, grant it read access to the subscriptions you want covered, and give Mycroft the application (client) ID, directory (tenant) ID and a credential you issue.
- What Mycroft can access
- Read-only. Mycroft reads subscription configuration and role assignments through that application, and does not write back.
Which controls Microsoft Azure evidence maps to
Each row is a control an auditor tests and the specific artifact Mycroft collects from Microsoft Azure to satisfy it. Collection runs on a schedule and every result is timestamped.
| Framework | Control | What it requires | Evidence collected from Microsoft Azure |
|---|---|---|---|
| SOC 2 | CC6.1 | Logical access controls restrict access to information assets. | Azure RBAC role assignments by scope, with Owner and Contributor holders enumerated and reconciled to current employees. |
| SOC 2 | CC6.6 | Access measures protect against threats from outside the system boundary. | Network security group rules flagged for unrestricted inbound access; storage accounts allowing public blob access; public network access settings on SQL and Cosmos DB. |
| SOC 2 | CC7.1 | Monitoring detects configuration changes and vulnerabilities. | Activity log diagnostic settings and retention; Microsoft Defender for Cloud enablement and its secure score findings with severity and age. |
| SOC 2 | CC7.2 | System components are monitored for anomalies indicative of security events. | Defender for Cloud alert history with triage state, plus diagnostic settings proving log flow to a retained workspace. |
| ISO 27001 | A.5.23 | Information security for the use of cloud services is managed. | Per-subscription configuration baseline covering encryption, logging, network exposure and privileged role assignment, re-tested daily. |
| ISO 27001 | A.8.24 | Cryptography is used effectively to protect information. | Storage account and managed disk encryption state, TLS minimum version enforcement, and Key Vault soft-delete, purge protection and key expiry configuration. |
| ISO 27001 | A.8.8 | Technical vulnerabilities are identified and remediated. | Defender for Cloud recommendations and vulnerability assessment findings, deduplicated with owner and time-to-remediate. |
| HIPAA | §164.312(a)(1) | Technical policies limit ePHI access to authorized persons. | RBAC assignment inventory at every scope holding regulated workloads, with privileged role holders identified. |
| HIPAA | §164.312(b) | Audit controls record activity in systems containing ePHI. | Activity log and resource diagnostic settings shown as enabled with retention meeting your documented period. |
What Mycroft collects automatically
Gathered from Microsoft Azure on a schedule, dated and stored against the controls above.
- Azure RBAC role assignments across subscriptions, resource groups and resources
- Storage account encryption, secure-transfer enforcement, TLS minimum version and public blob access settings
- Managed disk and SQL database encryption state, including transparent data encryption
- Network security group rules with unrestricted inbound exposure highlighted
- Key Vault configuration: soft delete, purge protection, key rotation and expiry
- Activity log diagnostic settings and retention period
- Microsoft Defender for Cloud enablement, secure score and open findings with age
Manual work this removes
The tasks that disappear from someone's quarter once Microsoft Azure is connected.
- Screenshotting RBAC assignments subscription by subscription before each review
- Maintaining a spreadsheet of which storage accounts allow public blob access
- Exporting Defender for Cloud recommendations to show they were triaged
- Reconciling role assignments against the leaver list each quarter
- Identifying subscriptions that were never added to the review scope
Microsoft Azure and Mycroft: frequently asked questions
We turn the compliance nightmare into a dream


