Azure Security Configuration: The 10 Most Common Mistakes
After reviewing hundreds of Azure environments, we see the same mistakes repeating. Many are simple to fix, but the consequences of ignoring them can be severe.
1. Overly Broad Role Assignments
Users with Global Administrator or Contributor at the subscription level are more common than they should be. Follow least privilege — grant access at resource group level with specific roles.
2. Conditional Access Is Not Configured
Azure AD / Entra ID without Conditional Access is like a door without a lock. At minimum: require MFA for all users, block legacy authentication, and require compliant devices for sensitive apps.
3. Security Defaults Disabled Without Replacement
Many disable Security Defaults to configure Conditional Access but forget to implement equivalent policies. The result is weaker security than the starting point.
4. Storage Accounts Are Publicly Accessible
Blob containers with Public access level set to "Blob" or "Container" expose data to the entire internet. Check all storage accounts and set access to "Private" unless it's a deliberate decision.
5. Network Security Groups Missing or Too Open
NSGs allowing all inbound traffic (0.0.0.0/0) on RDP (3389) or SSH (22) are an open invitation. Restrict access to known IP addresses and use Azure Bastion for administration.
6. Diagnostic Logging Not Enabled
Without logging, you can't detect or investigate incidents. Enable diagnostic settings on all critical resources and send logs to a Log Analytics workspace (and Sentinel).
7. Legacy Authentication Still Active
Older protocols like POP3, IMAP, and SMTP Basic Auth don't support MFA. Block legacy auth via Conditional Access — it's one of the most effective security measures you can take.
8. Privileged Identity Management (PIM) Not Used
Permanent admin roles are an unnecessary risk. PIM provides just-in-time access — administrators activate their role when needed, with time limits and approval workflows.
9. MFA Coverage Gaps
MFA is enabled for some users but not all. Service accounts, emergency access accounts, and guest users are often forgotten. Map all accounts and ensure 100% MFA coverage.
10. Guest Users Not Monitored
External users invited via B2B collaboration may have access to sensitive resources without anyone watching. Review guest access regularly with Access Reviews in Entra ID.
How to Get Started
- Run Microsoft Secure Score — it provides a baseline and concrete recommendations
- Prioritize the three highest-risk findings
- Implement changes with proper change management and testing
- Repeat quarterly
ForSec conducts Azure security reviews and helps close gaps between current configuration and best practices. Book a review of your Azure environment.
Need help with cybersecurity?
We help Norwegian organizations protect against digital threats. Contact us for a no-obligation conversation.
Contact us