Skip to content

The Azure container services nobody's AKS dashboard is looking at.

Container Apps, Container App Environments, Container Instances and Dynamic Session Pools are not clusters, so generic Kubernetes tooling largely ignores them. QubeAuditor assesses them directly, with 17 container-scope controls plus Azure subscription posture through Prowler.

Book a baseline assessment
  • Container Apps
  • App Environments
  • Container Instances
  • Dynamic Session Pools
  • Container registries
  • Subscription posture

Controls

What is actually checked.

Seventeen curated container-scope controls, mapped to CIS Azure and to NIS2 Article 21 measures. Each one names the condition it looks for, so you can tell in advance whether it applies to you.

Identity · CAZ-13 controls
CAZ-1.1
Ensure managed identities are used instead of credentials
CAZ-1.2
Restrict registry access to managed identity
CAZ-1.3
Avoid anonymous registry pulls
Network · CAZ-34 controls
CAZ-3.1
Restrict public network access
CAZ-3.2
Integrate workloads into a virtual network
CAZ-3.3
Do not expose container groups via public IP
CAZ-3.4
Restrict external ingress with IP rules
Transport · CAZ-42 controls
CAZ-4.1
Enforce HTTPS and disable insecure transport
CAZ-4.2
Enable peer-to-peer mTLS
Logging · CAZ-51 control
CAZ-5.1
Send diagnostic logs to Log Analytics
Secrets · CAZ-62 controls
CAZ-6.1
Store secrets in Key Vault
CAZ-6.2
Do not store secrets in plaintext
Supply chain · CAZ-72 controls
CAZ-7.1
Use approved container registries
CAZ-7.2
Pin immutable image tags
Workload · CAZ-83 controls
CAZ-8.1
Run untrusted code in isolated dynamic sessions
CAZ-8.2
Disable session pool egress for untrusted code
CAZ-8.3
Do not run privileged containers

Session pools

Dynamic Session Pools are where untrusted code runs.

Session pools exist to execute code you do not trust — agent tool calls, customer-submitted snippets, generated scripts. That makes isolation and egress the two settings that matter most, and they are the two most likely to have been left at whatever the first prototype used.

Isolation is a choice, not a default state

A pool that runs untrusted code outside an isolated session type gives that code the surrounding execution context. The check looks for exactly this condition rather than inferring it from a naming convention.

Egress is the exfiltration path

A session pool with unrestricted egress lets executed code reach the internet and anything else it can route to. For untrusted workloads, egress should be off unless there is a specific reason it is on.

The image still matters

Custom session pool images are subject to the same registry provenance and tag immutability checks as any other workload. An untrusted execution environment built from a mutable tag pulled from an unapproved registry is two problems, not one.

Beyond containers

The subscription underneath.

Container posture is only half the picture. Several NIS2 measures are evidenced at subscription scope, not workload scope, so Prowler assesses the Azure subscription as part of the same engagement.

identity
Entra security defaults and MFA posture at tenant scope — the technical evidence for NIS2 21(2)(j)
logging
Activity-log diagnostic settings — the audit trail that evidences incident handling under 21(2)(b)
encryption
Storage secure-transfer enforcement — part of the cryptography evidence under 21(2)(h)
registry
Container registry provenance and, optionally, image vulnerability scanning

Defender

This is not a replacement for Defender for Cloud.

If you need broad Azure posture management across every resource type, Defender for Cloud does that better and is already integrated with the platform. QubeAuditor is worth adding for three specific reasons, and if none of them applies to you, you probably do not need it.

  • The party operating your Azure environment is also the party producing your security reporting, and you need an assessment they do not control
  • You run Container Apps, Container Instances or Session Pools and want service-specific evidence rather than generic posture
  • You need findings assigned to a supplier with a deadline, re-tested on the next scan, and packaged as evidence for an auditor

Questions

Azure questions

Or start with something you already have

Bring one recent security report from the vendor operating your estate. We will map how many of its findings have an accountable owner, a verification state, and evidence you could hand to an auditor.

Book a baseline assessment

Contact

Book a baseline assessment

Tell us what you run and who operates it. We will come back with a scope, a timeline and a fixed price for one estate.