Links

Microsoft Network VirtualNetworks

Best practices and references below are based on published guidance from the cloud service provider and may reference native capabilities the cloud service provider offers. If you are not using the native security capabilities, the same security requirement can be met using other security capabilities your organization utilizes

Asset Inventory

Design Guidance:

Microsoft.Network/virtualNetworks

Microsoft.Network/virtualNetworks/virtualNetworkPeerings

Microsoft.Network/virtualNetworks/subnets


Subnet Isolation

Design Guidance:

Microsoft.Network/virtualNetworks

Address Space-Address Prefixes
Terraform
Dhcp Options-Dns Servers
Terraform

Microsoft.Network/virtualNetworks/virtualNetworkPeerings

Remote Virtual Network-Id
Terraform
Remote Address Space-Address Prefixes
Terraform

Microsoft.Network/virtualNetworks/subnets

Address Prefix
Terraform
Address Prefixes
Terraform
Delegations-Service Name
Terraform
Delegations-Name
Terraform

DoS Monitoring

Design Guidance:

Microsoft.Network/virtualNetworks

Enable Ddos Protection
Terraform
Ddos Protection Plan-Id
Terraform

Design for High Availability

Design Guidance:

Microsoft.Network/virtualNetworks

Enable Vm Protection
Terraform

Microsoft.Network/virtualNetworks/virtualNetworkPeerings

Peering State
Terraform

Information Flow Routing

Microsoft.Network/virtualNetworks

Bgp Communities-Virtual Network Community
Terraform

Microsoft.Network/virtualNetworks/subnets

Route Table-Id
Terraform

Deny-all Communications and Only Allow-by-Exception

Microsoft.Network/virtualNetworks/virtualNetworkPeerings

Allow Virtual Network Access
Terraform

Traffic Minimization

Microsoft.Network/virtualNetworks/virtualNetworkPeerings

Allow Forwarded Traffic
Terraform

Design for Secure Failure

Design Guidance:

Microsoft.Network/virtualNetworks/virtualNetworkPeerings

Allow Gateway Transit
Terraform
Use Remote Gateways
Terraform

Microsoft.Network/virtualNetworks/subnets

Nat Gateway-Id
Terraform

Firewalls

Design Guidance:

Microsoft.Network/virtualNetworks/subnets

Network Security Group-Id
Terraform
Private Endpoint Network Policies
Terraform
Private Link Service Network Policies
Terraform