https://azure.github.io/PSRule.Rules.Azure/en/selectors/Azure.ServiceBus.IsPremium/
Azure.ServiceBus.IsPremium - PSRule for Azure
Ready to go rules for testing Azure Infrastructure as Code (IaC).
azureservicebus
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.AKS.AutoUpgrade/
Azure.AKS.AutoUpgrade - PSRule for Azure
New versions of Kubernetes are released regularly. Upgrading each release manually can add operational overhead without realizing equivalent value.
azure aksautoupgrade
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.VNET.BastionSubnet/
Azure.VNET.BastionSubnet - PSRule for Azure
VNETs with a GatewaySubnet should have an AzureBastionSubnet to allow for out of band remote access to VMs.
azurevnet
https://azure.github.io/PSRule.Rules.Azure/es/rules/Azure.ACR.Usage/
Azure.ACR.Usage - PSRule for Azure
Consider freeing up registry space.
azureacrusage
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.ADX.DiskEncryption/
Azure.ADX.DiskEncryption - PSRule for Azure
Use disk encryption for Azure Data Explorer (ADX) clusters.
azureadx
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.AKS.MinUserPoolNodes/
Azure.AKS.MinUserPoolNodes - PSRule for Azure
User node pools in an AKS cluster should have a minimum number of nodes for failover and updates.
azure aks
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.RBAC.LimitMGDelegation/
Azure.RBAC.LimitMGDelegation - PSRule for Azure
Limit Role-Base Access Control (RBAC) inheritance from Management Groups.
azurerbac
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.AKS.SecretStoreRotation/
Azure.AKS.SecretStoreRotation - PSRule for Azure
Enable autorotation of Secrets Store CSI Driver secrets for AKS clusters.
azure aks
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.ContainerApp.DisableAffinity/
Azure.ContainerApp.DisableAffinity - PSRule for Azure
Disable session affinity to prevent unbalanced distribution.
azure
https://microsoft.github.io/PSRule/v2/analysis-output/
Analysis output - PSRule
Validate infrastructure as code (IaC) and objects using PowerShell rules.
analysisoutput
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.ACR.MinSku/
Azure.ACR.MinSku - PSRule for Azure
The Basic SKU provides limited performance and features for production container registry workloads.
azureacr
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.ACR.Name/
Azure.ACR.Name - PSRule for Azure
Container registry names should meet naming requirements.
azureacrname
https://azure.github.io/PSRule.Rules.Azure/en/baselines/Azure.GA_2021_09/
Azure.GA_2021_09 - PSRule for Azure
Ready to go rules for testing Azure Infrastructure as Code (IaC).
azurega
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.PublicIP.MigrateStandard/
Azure.PublicIP.MigrateStandard - PSRule for Azure
Use the Standard SKU for Public IP addresses as the Basic SKU will be retired.
azure
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.APIM.CertificateExpiry/
Azure.APIM.CertificateExpiry - PSRule for Azure
Renew certificates used for custom domain bindings.
azureapim
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.Cosmos.DefenderCloud/
Azure.Cosmos.DefenderCloud - PSRule for Azure
Enable Microsoft Defender for Azure Cosmos DB.
azurecosmos
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.AppInsights.Workspace/
Azure.AppInsights.Workspace - PSRule for Azure
Configure Application Insights resources to store data in a workspace.
azureworkspace
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.PublicIP.IsAttached/
Azure.PublicIP.IsAttached - PSRule for Azure
Public IP addresses should be attached or cleaned up if not in use.
azure
https://microsoft.github.io/PSRule/v2/faq/
Frequently Asked Questions - PSRule
Validate infrastructure as code (IaC) and objects using PowerShell rules.
frequently asked questions
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.TrafficManager.Protocol/
Azure.TrafficManager.Protocol - PSRule for Azure
Monitor Traffic Manager web-based endpoints with HTTPS.
azuretrafficmanagerprotocol
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.LB.Probe/
Azure.LB.Probe - PSRule for Azure
Use a specific probe for web protocols.
azurelbprobe
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.RedisEnterprise.Zones/
Azure.RedisEnterprise.Zones - PSRule for Azure
Enterprise Redis cache should be zone-redundant for high availability.
azurezones
https://azure.github.io/PSRule.Rules.Azure/en/baselines/Azure.GA_2026_03/
Azure.GA_2026_03 - PSRule for Azure
Ready to go rules for testing Azure Infrastructure as Code (IaC).
azurega
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.Storage.Name/
Azure.Storage.Name - PSRule for Azure
Azure Resource Manager (ARM) has requirements for Storage Account names.
azure storagename
https://azure.github.io/PSRule.Rules.Azure/contribute/rules/prerequisites/
Complete prerequisites for contributing rules - PSRule for Azure
Learn about the learning resources and required tooling for contributing rules to PSRule for Azure.
completeprerequisitescontributingrulesazure
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.ACR.AnonymousAccess/
Azure.ACR.AnonymousAccess - PSRule for Azure
Anonymous pull access allows unidentified downloading of images and metadata from a container registry.
azureacr
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.ContainerApp.JobNaming/
Azure.ContainerApp.JobNaming - PSRule for Azure
Container App Job resources without a standard naming convention may be difficult to identify and manage.
azure
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.Identity.UserAssignedName/
Azure.Identity.UserAssignedName - PSRule for Azure
Managed Identity names should meet naming requirements.
azureidentity
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.EventGrid.NamespaceTLS/
Azure.EventGrid.NamespaceTLS - PSRule for Azure
Weak or deprecated transport protocols for client-server communication introduce security vulnerabilities.
azureeventgrid
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.Defender.SQLOnVM/
Azure.Defender.SQLOnVM - PSRule for Azure
Enable Microsoft Defender for SQL servers on machines.
azuredefender
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.Defender.KeyVault/
Azure.Defender.KeyVault - PSRule for Azure
Enable Microsoft Defender for Key Vault.
azuredefenderkeyvault
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.VM.DiskSizeAlignment/
Azure.VM.DiskSizeAlignment - PSRule for Azure
Align to the Managed Disk billing increments to improve cost efficiency.
azure vm
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.Firewall.Name/
Azure.Firewall.Name - PSRule for Azure
Firewall names should meet naming requirements.
azure firewallname
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.ACR.AuditLogs/
Azure.ACR.AuditLogs - PSRule for Azure
Ensure container registry audit diagnostic logs are enabled.
azureacr
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.NIC.Attached/
Azure.NIC.Attached - PSRule for Azure
Network interfaces (NICs) that are not used should be removed.
azurenicattached
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.FrontDoorWAF.Exclusions/
Azure.FrontDoorWAF.Exclusions - PSRule for Azure
Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions.
azureexclusions
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.AKS.NodeAutoUpgrade/
Azure.AKS.NodeAutoUpgrade - PSRule for Azure
Operating system (OS) security updates should be applied to AKS nodes and rebooted as required to address security vulnerabilities.
azure aks
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.MariaDB.ServerName/
Azure.MariaDB.ServerName - PSRule for Azure
Azure Database for MariaDB servers should meet naming requirements.
azuremariadb
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.Template.ParameterMinMaxValue/
Azure.Template.ParameterMinMaxValue - PSRule for Azure
Template parameters minValue and maxValue constraints must be valid.
azuretemplate
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.SQL.AAD/
Azure.SQL.AAD - PSRule for Azure
Use Entra ID authentication with Azure SQL databases.
azure sqlaad
https://azure.github.io/PSRule.Rules.Azure/en/selectors/Azure.Resource.SupportsTags/
Azure.Resource.SupportsTags - PSRule for Azure
Ready to go rules for testing Azure Infrastructure as Code (IaC).
azureresource
https://azure.github.io/PSRule.Rules.Azure/en/baselines/Azure.GA_2024_03/
Azure.GA_2024_03 - PSRule for Azure
Ready to go rules for testing Azure Infrastructure as Code (IaC).
azurega
https://azure.github.io/PSRule.Rules.Azure/contribute/overview/
Contribution process overview - PSRule for Azure
Learn how to contribute to PSRule for Azure.
contribution processoverviewazure
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.VNG.VPNAvailabilityZoneSKU/
Azure.VNG.VPNAvailabilityZoneSKU - PSRule for Azure
Use availability zone SKU for virtual network gateways deployed with VPN gateway type.
azurevng
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.ContainerApp.Name/
Azure.ContainerApp.Name - PSRule for Azure
Container Apps should meet naming requirements.
azurename
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.ACR.ContentTrust/
Container Registry Docker content trust is not enabled - PSRule for Azure
Docker content trust allows images to be signed and verified when pulled from a container registry.
container registrydockercontenttrust
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.Storage.Naming/
Azure.Storage.Naming - PSRule for Azure
Storage Accounts without a standard naming convention may be difficult to identify and manage.
azure storagenaming
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.MySQL.ServerNaming/
Azure.MySQL.ServerNaming - PSRule for Azure
MySQL database server resources without a standard naming convention may be difficult to identify and manage.
azure mysql
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.MariaDB.FirewallIPRange/
Azure.MariaDB.FirewallIPRange - PSRule for Azure
Determine if there is an excessive number of permitted IP addresses.
azuremariadb
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.Cosmos.AccountName/
Azure.Cosmos.AccountName - PSRule for Azure
Cosmos DB account names should meet naming requirements.
azurecosmos
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.Storage.Firewall/
Azure.Storage.Firewall - PSRule for Azure
Storage Accounts should only accept explicitly allowed traffic.
azure storagefirewall
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.Storage.Defender.MalwareScan/
Azure.Storage.Defender.MalwareScan - PSRule for Azure
Enable Malware Scanning in Microsoft Defender for Storage.
azure storagedefender
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.Cosmos.NoSQLNaming/
Azure.Cosmos.NoSQLNaming - PSRule for Azure
Cosmos DB for NoSQL account resources without a standard naming convention may be difficult to identify and manage.
azurecosmos
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.Redis.AvailabilityZone/
Azure.Redis.AvailabilityZone - PSRule for Azure
Premium Redis cache should be deployed with availability zones for high availability.
azureredis
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.ACR.ReplicaLocation/
Azure.ACR.ReplicaLocation - PSRule for Azure
The replication location determines the country or region where container images and metadata are stored and processed.
azureacr
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.VM.Name/
Azure.VM.Name - PSRule for Azure
Virtual Machine (VM) names should meet naming requirements.
azure vmname
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.FrontDoor.ProbeMethod/
Azure.FrontDoor.ProbeMethod - PSRule for Azure
Configure health probes to use HEAD requests to reduce performance overhead.
azurefrontdoor
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.LB.Name/
Azure.LB.Name - PSRule for Azure
Load Balancer names should meet naming requirements.
azurelbname
https://azure.github.io/PSRule.Rules.Azure/license-contributing/hackathons/
Past hackathons - PSRule for Azure
Ready to go rules for testing Azure Infrastructure as Code (IaC).
pasthackathonsazure
https://microsoft.github.io/PSRule/v3/concepts/cli/module/
ps-rule module command - PSRule
Validate infrastructure as code (IaC) and objects using PowerShell rules.
psrulemodulecommand
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.Cosmos.DatabaseNaming/
Azure.Cosmos.DatabaseNaming - PSRule for Azure
Cosmos DB database resources without a standard naming convention may be difficult to identify and manage.
azurecosmos
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.VM.ASAlignment/
Azure.VM.ASAlignment - PSRule for Azure
Use availability sets aligned with managed disks fault domains.
azure vm
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.ACR.Naming/
Azure.ACR.Naming - PSRule for Azure
Container Registry resources without a standard naming convention may be difficult to identify and manage.
azureacrnaming
https://azure.github.io/PSRule.Rules.Azure/updates/v1.46/
September 2025 (version 1.46) - PSRule for Azure
Learn what is new in PSRule for Azure release 1.46.
septemberversionazure
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.AKS.CNISubnetSize/
Azure.AKS.CNISubnetSize - PSRule for Azure
AKS clusters using Azure CNI should use large subnets to reduce IP exhaustion issues.
azure aks
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.Group.Name/
Azure.Group.Name - PSRule for Azure
Azure Resource Manager (ARM) has requirements for Resource Groups names.
azuregroupname
https://azure.github.io/PSRule.Rules.Azure/en/baselines/Azure.Preview_2025_06/
Azure.Preview_2025_06 - PSRule for Azure
Ready to go rules for testing Azure Infrastructure as Code (IaC).
azurepreview
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.VM.SQLServerDisk/
Azure.VM.SQLServerDisk - PSRule for Azure
Use Premium SSD disks or greater for data and log files for production SQL Server workloads.
azure vm
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.Cosmos.CassandraNaming/
Azure.Cosmos.CassandraNaming - PSRule for Azure
Cosmos DB for Apache Cassandra account resources without a standard naming convention may be difficult to identify and manage.
azurecosmos
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.Storage.BlobAccessType/
Azure.Storage.BlobAccessType - PSRule for Azure
Use containers configured with a private access type that requires authorization.
azure storage
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.AppGw.MigrateWAFPolicy/
Azure.AppGw.MigrateWAFPolicy - PSRule for Azure
Migrate to Application Gateway WAF policy.
azure
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.VM.SecureBoot/
Azure.VM.SecureBoot - PSRule for Azure
Operating systems or drivers may be maliciously modified or injected if an actor gains access to VM/ OS storage or build media.
azure vmsecureboot
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.NIC.UniqueDns/
Azure.NIC.UniqueDns - PSRule for Azure
Network interfaces (NICs) should inherit DNS from virtual networks.
azurenic
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.Redis.FirewallIPRange/
Azure.Redis.FirewallIPRange - PSRule for Azure
Determine if there is an excessive number of permitted IP addresses for the Redis cache.
azureredis
https://microsoft.github.io/PSRule/stable/install/
Install - PSRule
Validate infrastructure as code (IaC) and objects using PowerShell rules.
install
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.Template.ParameterScheme/
Azure.Template.ParameterScheme - PSRule for Azure
Use an Azure template parameter file schema with the https scheme.
azuretemplate
https://azure.github.io/PSRule.Rules.Azure/license-contributing/expansion-internals/
Expansion internals - PSRule for Azure
Expansion is the process of converting an Azure Resource Manager (ARM) deployment into a set of resources that represent the desired state of the deployment....
expansioninternalsazure
https://microsoft.github.io/PSRule/v3/commands/PSRule/en-US/Invoke-PSRule/
Invoke-PSRule - PSRule
Validate infrastructure as code (IaC) and objects using PowerShell rules.
invoke
https://azure.github.io/PSRule.Rules.Azure/es/rules/Azure.ACR.Retention/
Azure.ACR.Retention - PSRule for Azure
Use a retention policy to cleanup untagged manifests.
azureacrretention
https://microsoft.github.io/PSRule/v3/commands/PSRule/en-US/New-PSRuleOption/
New-PSRuleOption - PSRule
Validate infrastructure as code (IaC) and objects using PowerShell rules.
new
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.ContainerApp.EnvNaming/
Azure.ContainerApp.EnvNaming - PSRule for Azure
Container App Environment resources without a standard naming convention may be difficult to identify and manage.
azure
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.Storage.Defender.DataScan/
Azure.Storage.Defender.DataScan - PSRule for Azure
Enable sensitive data threat detection in Microsoft Defender for Storage.
azure storagedefenderdatascan
https://microsoft.github.io/PSRule/v3/concepts/capabilities/
Capabilities - PSRule
Capabilities are a way to declare or require a minimum set of features or functionality.
capabilities
https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.VM.MigrateAMA/
Azure.VM.MigrateAMA - PSRule for Azure
Use Azure Monitor Agent as replacement for Log Analytics Agent.
azure vm