Back to blog
7 minKim Ytredal

Azure Security Configuration: The 10 Most Common Mistakes

AzureCloud SecurityConfiguration

After reviewing hundreds of Azure environments, we see the same mistakes repeating. Many are simple to fix, but the consequences of ignoring them can be severe.

1. Overly Broad Role Assignments

Users with Global Administrator or Contributor at the subscription level are more common than they should be. Follow least privilege — grant access at resource group level with specific roles.

2. Conditional Access Is Not Configured

Azure AD / Entra ID without Conditional Access is like a door without a lock. At minimum: require MFA for all users, block legacy authentication, and require compliant devices for sensitive apps.

3. Security Defaults Disabled Without Replacement

Many disable Security Defaults to configure Conditional Access but forget to implement equivalent policies. The result is weaker security than the starting point.

4. Storage Accounts Are Publicly Accessible

Blob containers with Public access level set to "Blob" or "Container" expose data to the entire internet. Check all storage accounts and set access to "Private" unless it's a deliberate decision.

5. Network Security Groups Missing or Too Open

NSGs allowing all inbound traffic (0.0.0.0/0) on RDP (3389) or SSH (22) are an open invitation. Restrict access to known IP addresses and use Azure Bastion for administration.

6. Diagnostic Logging Not Enabled

Without logging, you can't detect or investigate incidents. Enable diagnostic settings on all critical resources and send logs to a Log Analytics workspace (and Sentinel).

7. Legacy Authentication Still Active

Older protocols like POP3, IMAP, and SMTP Basic Auth don't support MFA. Block legacy auth via Conditional Access — it's one of the most effective security measures you can take.

8. Privileged Identity Management (PIM) Not Used

Permanent admin roles are an unnecessary risk. PIM provides just-in-time access — administrators activate their role when needed, with time limits and approval workflows.

9. MFA Coverage Gaps

MFA is enabled for some users but not all. Service accounts, emergency access accounts, and guest users are often forgotten. Map all accounts and ensure 100% MFA coverage.

10. Guest Users Not Monitored

External users invited via B2B collaboration may have access to sensitive resources without anyone watching. Review guest access regularly with Access Reviews in Entra ID.

How to Get Started

  • Run Microsoft Secure Score — it provides a baseline and concrete recommendations
  • Prioritize the three highest-risk findings
  • Implement changes with proper change management and testing
  • Repeat quarterly

ForSec conducts Azure security reviews and helps close gaps between current configuration and best practices. Book a review of your Azure environment.

Need help with cybersecurity?

We help Norwegian organizations protect against digital threats. Contact us for a no-obligation conversation.

Contact us