- CAZ-1.1
- Ensure managed identities are used instead of credentials
- CAZ-1.2
- Restrict registry access to managed identity
- CAZ-1.3
- Avoid anonymous registry pulls
Services
- Container Apps
- App Environments
- Container Instances
- Dynamic Session Pools
- Container registries
- Subscription posture
The Azure container services nobody's AKS dashboard is looking at.
Container Apps, Container App Environments, Container Instances and Dynamic Session Pools are not clusters, so generic Kubernetes tooling largely ignores them. QubeAuditor assesses them directly, with 17 container-scope controls plus Azure subscription posture through Prowler.
Book a baseline assessment- Container Apps
- App Environments
- Container Instances
- Dynamic Session Pools
- Container registries
- Subscription posture
Controls
What is actually checked.
Seventeen curated container-scope controls, mapped to CIS Azure and to NIS2 Article 21 measures. Each one names the condition it looks for, so you can tell in advance whether it applies to you.
- CAZ-3.1
- Restrict public network access
- CAZ-3.2
- Integrate workloads into a virtual network
- CAZ-3.3
- Do not expose container groups via public IP
- CAZ-3.4
- Restrict external ingress with IP rules
- CAZ-4.1
- Enforce HTTPS and disable insecure transport
- CAZ-4.2
- Enable peer-to-peer mTLS
- CAZ-5.1
- Send diagnostic logs to Log Analytics
- CAZ-6.1
- Store secrets in Key Vault
- CAZ-6.2
- Do not store secrets in plaintext
- CAZ-7.1
- Use approved container registries
- CAZ-7.2
- Pin immutable image tags
- CAZ-8.1
- Run untrusted code in isolated dynamic sessions
- CAZ-8.2
- Disable session pool egress for untrusted code
- CAZ-8.3
- Do not run privileged containers
Session pools
Dynamic Session Pools are where untrusted code runs.
Session pools exist to execute code you do not trust — agent tool calls, customer-submitted snippets, generated scripts. That makes isolation and egress the two settings that matter most, and they are the two most likely to have been left at whatever the first prototype used.
Isolation is a choice, not a default state
A pool that runs untrusted code outside an isolated session type gives that code the surrounding execution context. The check looks for exactly this condition rather than inferring it from a naming convention.
Egress is the exfiltration path
A session pool with unrestricted egress lets executed code reach the internet and anything else it can route to. For untrusted workloads, egress should be off unless there is a specific reason it is on.
The image still matters
Custom session pool images are subject to the same registry provenance and tag immutability checks as any other workload. An untrusted execution environment built from a mutable tag pulled from an unapproved registry is two problems, not one.
Beyond containers
The subscription underneath.
Container posture is only half the picture. Several NIS2 measures are evidenced at subscription scope, not workload scope, so Prowler assesses the Azure subscription as part of the same engagement.
- identity
- Entra security defaults and MFA posture at tenant scope — the technical evidence for NIS2 21(2)(j)
- logging
- Activity-log diagnostic settings — the audit trail that evidences incident handling under 21(2)(b)
- encryption
- Storage secure-transfer enforcement — part of the cryptography evidence under 21(2)(h)
- registry
- Container registry provenance and, optionally, image vulnerability scanning
Defender
This is not a replacement for Defender for Cloud.
If you need broad Azure posture management across every resource type, Defender for Cloud does that better and is already integrated with the platform. QubeAuditor is worth adding for three specific reasons, and if none of them applies to you, you probably do not need it.
- The party operating your Azure environment is also the party producing your security reporting, and you need an assessment they do not control
- You run Container Apps, Container Instances or Session Pools and want service-specific evidence rather than generic posture
- You need findings assigned to a supplier with a deadline, re-tested on the next scan, and packaged as evidence for an auditor
Questions
Azure questions
Or start with something you already have
Bring one recent security report from the vendor operating your estate. We will map how many of its findings have an accountable owner, a verification state, and evidence you could hand to an auditor.
Book a baseline assessmentContact
Book a baseline assessment
Tell us what you run and who operates it. We will come back with a scope, a timeline and a fixed price for one estate.