High
Publicly Accessible Management Endpoint
A resource exposes a management endpoint to the public internet without sufficient network restriction.
Impact: This increases the attack surface and may allow unauthorised access attempts against sensitive infrastructure.
- Subscription: Production
- Resource group: rg-prod-network
- Resource: vm-management-01
- Public IP: Enabled
Recommendation: Restrict access using private endpoints, network security group rules, or approved administrative access paths.
Medium
Missing Required Resource Tags
Several production resources do not include required ownership, environment, or cost centre tags.
Impact: This reduces cost visibility, operational ownership, and governance reporting accuracy.
- Missing tag: Owner
- Missing tag: CostCentre
- Affected resources: 27
Recommendation: Apply mandatory tagging policies and remediate existing untagged resources.
Medium
Azure Policy Coverage Is Incomplete
Policy assignments are not consistently applied across all production subscriptions.
Impact: Governance controls may be bypassed or inconsistently enforced across environments.
- Production subscription without required baseline policy
- Management group inheritance incomplete
Recommendation: Review management group structure and assign baseline policies at the correct scope.