All Subnets should have a Network Security Group associated
Impact:LowCategory:Security
APRL GUID:f0bf9ae6-25a5-974d-87d5-025abec73539
Description:
Network security groups and application security groups allow filtering of inbound and outbound traffic by IP, port, and protocol, adding a security layer at the Subnet level.
When available, use Private Endpoints instead of Service Endpoints for PaaS Services
Impact:MediumCategory:Security
APRL GUID:24ae3773-cc2c-3649-88de-c9788e25b463
Description:
Use VNet service endpoints only if Private Link isn't available and no data movement concerns. This feature restricts Azure service access to specified VNet and subnet, enhancing network security and isolating service traffic.