No description
  • HCL 66.4%
  • Makefile 33.6%
Find a file
Shrishyam Bhat 15d2f9c56b
Merge pull request #10 from hashicorp/compliance/update-headers
[IND-4227] [COMPLIANCE] Update Copyright Headers
2026-01-12 17:27:21 +05:30
.github Merge pull request #9 from hashicorp/compliance-template 2025-08-13 13:54:05 +10:00
docs/policies Update policy descriptions 2023-06-06 14:15:22 +12:00
example [COMPLIANCE] Update Copyright and License Headers 2025-12-09 11:18:27 +00:00
policies [COMPLIANCE] Update Copyright and License Headers 2025-12-09 11:18:27 +00:00
.gitignore Update policy descriptions 2023-06-06 14:15:22 +12:00
CONTRIBUTING.md Add descriptions to policies 2022-08-04 14:08:17 +12:00
LICENSE [COMPLIANCE] Update Copyright and License Headers 2025-12-09 11:18:27 +00:00
Makefile Update policy descriptions 2023-06-06 14:15:22 +12:00
readme.md Update readme.md 2022-08-11 11:53:59 -07:00
sentinel.hcl [COMPLIANCE] Update Copyright and License Headers 2025-12-09 11:18:27 +00:00

Azure Compute Sentinel Policies for Terraform

This library, provides prescriptive Terraform policies that can be used to establish secure Terraform configuration for Microsoft Azure. The policies that are contained in this library are based on the CIS Microsoft Azure Foundations Security Benchmark. Terraform Cloud/Enterprise users can use the policies in this library to establish a foundational level of security for the services that they are adopting in Microsoft Azure.

NOTE:

This Policy Library is not an exhaustive list of all of possible security configurations and architecture that is available in Microsoft Azure. If you have questions, comments, or have identified ways for us to improve this library, please create a new GitHub issue.

Alternatively, We welcome any contributions that improve the quality of this library! To learn more about contributing and suggesting changes to this library, refer to the contributing guide.


Policies

This library covers the following security recommendations for configuring Virtual Machine resources in a Microsoft Azure subscription.

  • Ensure that all managed disks (OS and Data) are encrypted (docs | code)
  • Ensure that only approved extensions are installed (docs | code)