We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. Azure security audit
Azure security audit for US businesses

Almost everything an Azure security audit runs on is already sitting unused in your subscription at no cost.

The secure score, the cloud security benchmark and the ability to pull in other cloud providers all live in the free Foundational tier of Defender for Cloud. Hardly anybody has ever turned them on. We look at what your estate genuinely contains and then tell you which parts actually warrant paying for.

Book an Azure security auditSee what we examine
Azure subscription and resource security audit for US organizations
  • Foundational CSPMFree, and usually not enabled
  • Subscription-wideIdentity, network, data, workloads
  • Free firstWe use what you already have
  • AWS and GCP tooMulticloud connection is free
What we examine

Eight areas, starting with the tooling you already own.

These estates grow the way a garage fills up. One subscription created for a single project, a resource group somebody stood up to test something, a storage account that outlasted whatever it was for. The audit is far less about hunting exotic misconfigurations than about establishing what is actually there and who can get to it.

Turn on what is free before buying anything

Defender for Cloud ships with a free foundational tier, and that tier explicitly covers the secure score, centralized policy management with the cloud security benchmark built in, the posture dashboard, and connecting AWS and Google Cloud environments alongside. In most estates we assess, not one of those is switched on. That is a real finding, and fixing it costs nothing at all.

Who can do what, across subscriptions

Who holds what at management group, subscription and resource group level, how many people carry Owner or Contributor, whether those assignments are permanent or activated only when needed, and which service principals and managed identities hold anything significant. Service principals are the ones companies lose sight of, because each was created during a deployment and nobody was ever handed responsibility for it afterward.

What is reachable from the internet

Public addresses, management ports facing the internet, storage accounts and databases reachable from the public network, application endpoints, and anything still listening from a project that wrapped up two years ago. This section produces something urgent more often than any other, and the cause is nearly always a temporary arrangement nobody ever undid rather than anybody deciding it was fine.

Where the data is and how it is protected

Storage accounts and databases, and how access to them actually works. Network restrictions, how shared access signatures get issued, encryption and where the keys live, and whether anything holding personal or regulated data is reachable more widely than anybody meant. Shared access tokens come up again and again, because they are trivially easy to issue, long lived unless somebody says otherwise, and awkward to revoke one at a time.

Key Vault, secrets, and whatever is sitting in plain text somewhere

Whether secrets actually live in Key Vault or are scattered through application settings, pipeline variables and configuration files, who is able to read them, whether anybody would know if they had been read, and whether something is due to expire that nobody is watching. The pattern we see constantly is a Key Vault that exists, is used correctly by the newest workload, and is quietly bypassed by everything built before it.

Policy, and whether anything is actually enforced

Which policies are assigned, how many of them merely observe rather than prevent, and whether exemptions handed out as a temporary measure were ever revisited. Centralized policy management is in the free tier, so an estate carrying no policy assignments does not have a licensing problem, it has an unconfigured one. Policy that actually enforces is the only thing that stops the estate sliding back after you have tidied it.

Logging, retention, and whether an investigation is possible

Which resources are sending diagnostic logs anywhere, where those end up, how long they survive, and whether an alert would reach a person who would act on it. Retention here is a decision somebody made rather than a default that happens to suit you, and companies typically discover exactly how far back their logs go in the middle of an investigation rather than before one.

Which paid plans are actually worth it for you

The paid posture plan adds attack path analysis, the security explorer, regulatory compliance reporting and governance. The workload plans are separate again, covering servers, containers, storage, databases, Key Vault, App Service, APIs and Resource Manager individually. Which of them earns a place depends entirely on what you actually run, and for a small estate the honest answer is usually rather fewer than a vendor would put in a proposal.

Before anybody quotes you for anything

Turn the free tier on and go and read the score.

Of everything on this page, this is the most useful, and you can do it yourself before the end of the day. What is included at no cost is published openly, and it covers considerably more than most people assume.

  • Defender for Cloud comes with a free foundational tier. Explicitly named within it: the secure score, centralized policy management with the cloud security benchmark built in as a standard, the posture dashboard, and multicloud coverage so AWS and Google Cloud environments can be brought into the same view.
  • What you get from that is a ranked list of misconfigurations across the whole estate without spending a cent. What you do not get is attack path analysis, the security explorer, compliance reporting or governance rules, all of which sit in the paid posture plan, nor any of the workload protection. It will however tell you whether there is a problem here worth looking into properly.
  • What the score is emphatically not is a rating to be optimized. It is computed against a baseline that knows nothing whatsoever about your business, so it hands out points for controls you have no use for while saying nothing at all about the one thing that would genuinely hurt you. Treat it as a starting index and a trend line. Never as an answer.
  • This matters commercially because a great many proposals open with purchasing Defender plans. Occasionally that is the right call. But an estate where the free tier has never been switched on has no idea what its actual problems are, and buying advanced tooling before establishing that is simply the wrong order to do things in.
Ask us to read what the free tier is already telling you
How we audit

Four things that stop this turning into a licensing proposal.

Cloud security assessments have an obvious commercial pull to them, because every single finding has a product that could be sold against it. We work in the opposite direction on purpose.

The free tier gets used before any paid one is recommended

The foundational tier hands you the secure score, policy management, the cloud security benchmark and multicloud connection for nothing. We switch that on and read it before anything else, because it establishes what your real problems are. Recommending the paid posture plan or workload protection before knowing that is selling ahead of diagnosing, and it produces spending that bears no relationship to the actual risk.

We separate what is urgent from what is untidy

Any Azure estate will produce a long list of recommendations, and most of them are housekeeping. A management port facing the internet, a service principal with far more rights than it needs, and a storage account holding personal data reachable from anywhere are a different category altogether. The report opens with that second group, because a list of a hundred items gets filed and a list of five gets fixed.

We connect findings to the obligations you actually carry

Where HIPAA applies, or GLBA and the FTC Safeguards Rule, or a state privacy law, or SOC 2 commitments, or simply the security terms in a contract with a large customer, the findings worth caring about are the ones touching those obligations. We map them rather than reporting generically, which also makes the fixes easier to get funded, because the justification is a specific obligation rather than a security preference.

We look at the estate you actually have, including whatever sits outside Azure

Connecting AWS and Google Cloud is part of the free tier, so where you run workloads across more than one provider they can all come into a single view rather than assessing Azure on its own. A great many American companies have a primary platform and a second one that arrived through an acquisition or a single project, and the second one is always, without exception, the less governed of the two.

When this is worth doing

Six situations that bring US organizations to an Azure audit.

Whatever prompted the audit shapes what it covers. One driven by a finance review of cloud spend looks quite different from one driven by a customer security questionnaire, and the scope follows the reason.

A customer or insurer has asked specific questions

Questions about who can reach what, how it is encrypted, what gets logged and what is exposed to the network, all of which somebody has to answer accurately and in writing, whether on a security questionnaire, an insurance application or a SOC 2 evidence request. The audit produces those answers and, more valuably, tells you which ones you ought to fix before you answer them. This is the most common reason people call and the one with the clearest finish line.

Azure grew from one project into an estate

It began with one workload, it worked, and five years on there are several subscriptions, resources nobody will claim ownership of, and access granted for reasons long since forgotten. Nothing is exactly wrong, and nobody has ever examined the whole thing at once. These audits dependably turn up things worth fixing and rarely turn up a crisis, which is precisely the right moment to be looking.

A financial firm under GLBA, FTC Safeguards, or NYDFS Part 500

Governance of the cloud, control over access, and the ability to prove both come up in every examination and assessment, and for a firm running anything material in Azure that proof lives inside the subscription itself. Where NYDFS Part 500 applies, lining up its requirements against your actual configuration is work worth doing on your own schedule rather than during an examination.

An organization holding personal or regulated data in Azure

HIPAA if you are a covered entity or a business associate, and CCPA and CPRA alongside the other state privacy laws where consumer data is involved. The practical questions are where that data physically sits in the estate, who can reach it, whether anything outside can reach it, and whether you could prove who has opened it. Every one of those is an audit question long before it becomes a legal one.

A company that inherited an estate from an engineer who left

One person built the whole thing, understood the whole thing, and has since moved on. What is left is infrastructure nobody can fully account for, carrying service principals, automation and access whose purpose was never written down anywhere. The first value of an audit here is simply an accurate picture, well before anybody starts talking about improving it.

After a cost review raised uncomfortable questions

When finance goes looking at Azure spend, what usually surfaces is resources nobody can account for, and that is a security question every bit as much as a cost one. Anything running without an owner is also anything running without anybody patching it, watching it or securing it. The two exercises overlap far more than people expect and are worth running together.

Three positions

What we find when we audit an Azure estate.

The middle column is where most companies are. Azure came in for one particular project, it worked well, more things got added on top, and nobody ever stood back to look at the whole thing at once.
Complete inventory of subscriptions and owners
Governed
Grown by accretionPartial
Unexamined
Defender for Cloud switched on, at minimum on the free tier
Governed
Grown by accretionSometimes
Unexamined
Secure score tracked as a trend
Governed
Grown by accretion
Unexamined
Privileged role assignments reviewed
Governed
Grown by accretionRarely
Unexamined
Service principals owned and understood
Governed
Grown by accretion
Unexamined
Internet exposure known and intentional
Governed
Grown by accretionPartly
Unexamined
Secrets held in Key Vault
Governed
Grown by accretionNewer workloads only
UnexaminedIn config files
Policy enforces rather than only audits
Governed
Grown by accretionAudit only
UnexaminedNone
Diagnostic logging with deliberate retention
Governed
Grown by accretionDefault or absent
Unexamined
Resources from finished projects removed
Governed
Grown by accretion
Unexamined
Feature
Governed
Grown by accretion
Unexamined
Complete inventory of subscriptions and owners
Partial
Defender for Cloud switched on, at minimum on the free tier
Sometimes
Secure score tracked as a trend
Privileged role assignments reviewed
Rarely
Service principals owned and understood
Internet exposure known and intentional
Partly
Secrets held in Key Vault
Newer workloads onlyIn config files
Policy enforces rather than only audits
Audit onlyNone
Diagnostic logging with deliberate retention
Default or absent
Resources from finished projects removed
What costs money and what does not

Defender for Cloud capabilities by plan.

Drawn from the published capability tables. It matters for two reasons: the free tier reaches further than most companies realize, and the paid plans can be bought individually rather than as one bundle, so you can take only what your particular workloads justify.

Capability

Secure score

Plan
Foundational CSPM, free

Capability

Centralized policy management

Plan
Foundational CSPM, free

Capability

Microsoft cloud security benchmark as a built-in standard

Plan
Foundational CSPM, free

Capability

CSPM dashboard

Plan
Foundational CSPM, free

Capability

Connect AWS and GCP environments

Plan
Foundational CSPM, free

Capability

Code pipeline insights

Plan
Foundational CSPM and Defender CSPM

Capability

Attack path analysis

Plan
Defender CSPM

Capability

Cloud security explorer

Plan
Defender CSPM

Capability

Regulatory compliance reporting

Plan
Defender CSPM

Capability

Security governance rules

Plan
Defender CSPM

Capability

Data security posture management

Plan
Defender CSPM or Defender for Storage

Capability

Server, container, storage, database and other workload protection

Plan
Separate CWPP plans, per workload type
CapabilityPlan
Secure scoreFoundational CSPM, free
Centralized policy managementFoundational CSPM, free
Microsoft cloud security benchmark as a built-in standardFoundational CSPM, free
CSPM dashboardFoundational CSPM, free
Connect AWS and GCP environmentsFoundational CSPM, free
Code pipeline insightsFoundational CSPM and Defender CSPM
Attack path analysisDefender CSPM
Cloud security explorerDefender CSPM
Regulatory compliance reportingDefender CSPM
Security governance rulesDefender CSPM
Data security posture managementDefender CSPM or Defender for Storage
Server, container, storage, database and other workload protectionSeparate CWPP plans, per workload type
How the audit runs

Five stages, typically one to two weeks.

Collection is read-only, delivered remotely, and does not affect running workloads. The time goes into interpretation, because whether a configuration is a risk depends entirely on what the resource does and who is meant to reach it.
  1. 1

    Inventory the estate and enable what is free

    Every subscription, who owns it, what runs in it, and Defender for Cloud enabled at least on Foundational CSPM so the secure score and benchmark recommendations are available. For many organizations this stage alone produces the first useful output, because the complete subscription list does not currently exist anywhere.

  2. 2

    Identity and access review

    Role assignments across management groups, subscriptions, and resource groups, privileged role holders, whether access is standing or activated when needed, and the service principals and managed identities that hold meaningful rights. This is where the highest-severity findings usually sit, and it is the part most often missing from automated reports.

  3. 3

    Exposure and data review

    What the internet can currently reach, which network restrictions exist on storage and databases, how shared access tokens get issued and whether anybody could revoke one, encryption and where keys are held, and where regulated data physically sits. We work from the configuration as it stands rather than from whatever the policy says it ought to be.

  4. 4

    Logging, policy, and detection review

    Diagnostic settings resource type by resource type, where the logs land and how long they survive there, whether an alert reaches a person, which policies are assigned and whether they prevent anything or merely observe, and which exemptions were handed out temporarily and never looked at again.

  5. 5

    Report, prioritize, and decide what to buy

    Findings ordered by how exploitable they actually are rather than by whatever severity a tool assigned, and split between what costs configuration effort and what would cost money. Where a paid plan genuinely earns its place given what you run, we name it and explain why. Where it does not, you hear that too, and the recommendation is the free tier plus some configuration work.

Straight answers

What organizations ask about Azure security audits.

No, and this is the single most useful thing to know before anybody sends you a quote. There is a free foundational tier, and it explicitly covers the secure score, centralized policy management with the cloud security benchmark built in, the posture dashboard, and connecting AWS and Google Cloud. That is more than enough to establish whether you have a problem worth investigating. The paid posture plan layers attack path analysis, the security explorer, compliance reporting and governance rules on top of it.

No. It is calculated against a baseline that knows nothing about your business, so it awards points for controls you may have no need of while remaining entirely blind to the one misconfiguration that would genuinely hurt you. We have audited estates carrying a perfectly respectable score alongside a management port open to the internet on a machine holding client data. Use it as a starting index and as a trend over time, and use an audit to answer whether you are actually exposed.

They fall into two groups. The advanced posture plan brings attack path analysis, the security explorer, compliance reporting and governance rules. Separately from that sit the workload protection plans, one each for servers, containers, storage, databases, Key Vault, App Service, APIs, Resource Manager and AI services, every one tied to a particular resource type. Because they are sold individually you can take only what your workloads justify, and on a small estate that is usually a good deal fewer than any vendor would put in front of you.

No. Everything collected is read only, it asks configuration questions rather than changing anything, and nothing running is affected. What can be disruptive is fixing things afterward, particularly anything touching network access or identity, which is exactly why the two are kept separate and changes are planned with you rather than applied mid-audit. If something genuinely urgent turns up, a management port facing the internet or a publicly readable store of personal data, you hear about it that hour rather than in the report.

Something the internet can reach that was never intended to be reachable, almost always left behind by a project that finished. After that, in order: Owner or Contributor at subscription level held by more people than anybody had realized, service principals carrying broad permissions with no owner because they were created during a deployment and forgotten, secrets sitting in application settings or pipeline variables instead of Key Vault, and diagnostic logging that was never switched on for precisely the resources you would need it for.

Different estate, different questions, very often the same company. A Microsoft 365 audit examines the tenant, meaning identity, mail, sharing, devices and what evidence you retain. An Azure audit examines the subscription and everything inside it: what is actually running, who can reach it, what the internet can see, where data lives, and whether you could investigate an incident afterward. The two share an identity layer through Entra, which is why they are frequently run together, but neither one stands in for the other.

Yes, and connecting them costs nothing. Multicloud coverage for AWS and Google Cloud sits inside the free foundational tier, so a mixed estate comes into one view without buying anything further. Worth knowing for any American company with a primary platform and a second one that arrived through an acquisition or a single project. In our experience that second platform is invariably the less governed of the pair.

Diagnostic logging is a decision taken per resource type rather than something comprehensively on from the start, and how long it is kept is likewise a choice somebody makes rather than a default that happens to suit you. The consequence is the same as on any cloud platform: companies find out what they kept in the middle of an investigation instead of beforehand. We check what is enabled, where it goes and how long it survives, then tell you what you could genuinely reconstruct.

Managing it, yes. Assessing it independently is a separate matter, because a partner auditing an estate they built and run every day is marking their own homework. That is a structural point rather than an accusation, and it applies to us equally: where we manage a client Azure estate, our audit of it is not independent and we say exactly that. For an insurer, a SOC 2 auditor or a demanding enterprise customer, independence is very often the thing that makes the assessment worth anything at all.

Directly, because if you hold personal or regulated data in Azure, the obligations follow the data. HIPAA asks who can access protected health information and whether you could evidence it. GLBA and the FTC Safeguards Rule expect access controls, encryption, and monitoring on customer financial data. CCPA/CPRA and the other state privacy laws assume you know where personal information sits and who reaches it. The audit answers the questions those obligations depend on, and we map findings against the ones that apply to you rather than reporting them generically.

These estates change continuously, so once a year is sensible, plus an extra look after anything significant: a migration, an acquisition, a change of provider, or a major new workload arriving. In between, the free secure score gives you a trend line that shows drift without anybody having to run a project to find it. What matters most is that the second audit is comparable to the first, so it can measure whether anything actually got better. Each engagement is scoped individually around the subscriptions, the size of the estate, and whether the fixing is included.

Switch Defender for Cloud on at the free foundational tier and read the secure score. Then separately, count how many resources across your subscriptions carry a public address. The first tells you what Microsoft thinks is wrong. The second tells you what the internet can actually see, which is the thing most likely to hurt you and a number hardly any company has ever counted. Neither costs anything and both fit inside an afternoon.
Azure estate check

Fifteen questions about your own subscriptions.

The first block asks what exists at all, which turns out to be a harder question than it sounds. The second asks what is exposed. The third asks whether you could reconstruct events after something has already happened.

What actually exists

  • How many Azure subscriptions do you have, and who owns each?
    Shadow subscriptions on a departmental card are common.
  • Has Defender for Cloud been enabled at all, even on the free tier?
    Free, and usually not switched on.
  • What does the secure score say, and has anybody actually opened it?
    A starting index, not a target to optimize.
  • Are there resources from projects that finished?
    They keep running, keep costing, and keep being exposed.
  • Can you name which resources are holding personal or regulated data?
    Needed for HIPAA, GLBA, and state privacy laws alike.

Exposure

  • How many resources have a public IP address?
    Count them. The number is usually a surprise.
  • Are any management ports reachable from the internet?
    The most common route into a cloud estate.
  • Do storage accounts or databases allow public network access?
    Check per resource, not per policy intention.
  • At subscription level, how many people are carrying Owner or Contributor?
    And is that access permanent or activated when needed.
  • Which service principals hold significant permissions?
    Created during deployments, rarely owned afterwards.

Could you investigate

  • Are diagnostic logs enabled on resources that matter?
    Off by default on many resource types.
  • Where do the logs actually end up, and how far back do they reach?
    Retention is a configuration decision, not a sensible default.
  • Would an alert ever reach somebody who would do something about it?
    Collection without response is not detection.
  • Do the secrets live in Key Vault, or in application settings and build pipelines?
    The older the workload, the more likely the latter.
  • Does any policy assignment actually prevent anything, or do they all just observe?
    A policy that only observes records the drift. It does not prevent any of it.
Related reading

The pages around this one.

Microsoft 365 security audit

The tenant side of the same Microsoft estate. Identity, mail, sharing, devices, and how far back your evidence genuinely goes.

Learn more

Microsoft Defender for Cloud

The posture and workload protection platform this audit works with, and what each plan actually adds.

Learn more

Cybersecurity audit and compliance

The broader audit practice, and how to work out which sort of engagement your situation genuinely needs.

Learn more
Next step

Turn on the free tier, then go and count your public addresses.

Both are free, both fit in an afternoon, and between them they will tell you whether there is a problem here. If you want help making sense of what comes back, or a proper look at the estate behind it, that is a short conversation and we will tell you what we would open first.

Book an Azure security auditSee the audit practice

Related Services

Explore more solutions that work great with this service

Microsoft 365 Security Audit

Independent Microsoft 365 tenant security audit for US organizations

Learn more

Cloud Security Posture Audit

Cloud security posture audits for US organizations: true inventory

Learn more

Active Directory Security Audit

On-premises Active Directory security audit for US organizations:

Learn more

Microsoft Defender

Advanced endpoint and email threat protection

Learn more

Vulnerability Assessment

Vulnerability assessment for US businesses across external attack

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA