What AzureProof checks
The services we read, and exactly what the control count means.
AzureProof reads your Azure subscription and Microsoft Entra directory and runs 247 checks against them. Every one of those checks calls a real Azure or Microsoft Graph API and returns a pass or a fail with the raw response behind it. There is nothing in your control list that we cannot answer for you.
What we read
- Microsoft Entra ID — sign-in policy, privileged roles, guest access, account lifecycle
- Storage — encryption, network exposure, keys and shared access signatures, retention
- Databases — SQL, PostgreSQL, MySQL, Cosmos DB and Redis: encryption, auth and network access
- Compute — App Service, Function Apps, App Service Environments, Virtual Machines, Containers, Batch
- Key Vault — access model, network isolation, key and secret lifecycle
- Networking — network security groups, public exposure, Application Gateway and WAF
- Microsoft Defender for Cloud — plan coverage, alerts and security contacts
- Governance and logging — diagnostic settings, activity log alerts, policy and resource locks
What the frameworks column means
Every control carries the SOC 2 Trust Services criterion it satisfies. 40 of them additionally carry a specific CIS Azure Foundations Benchmark v3.0.0 requirement code and an ISO/IEC 27001:2022 Annex A clause, so one evidence run answers all three for that set. The rest of the library is written from the CIS Azure Foundations v6.0.0 benchmark and the Storage, Compute and Database Services v2.0.0 benchmarks; adding their per-requirement codes is in progress.
We do not claim to cover a benchmark end to end. The number we publish is the number of checks that run.