Integrations / Cloud & infrastructure
Screenata + AzureHow do you continuously monitor Azure for SOC 2, ISO 27001, and HIPAA?
Quick answer
Yes, you can run a SOC 2, ISO 27001, or HIPAA compliant workload on Azure, but Azure itself is not the thing that gets audited. Microsoft certifies the Azure infrastructure layer and publishes its own attestation reports for it. Your subscription configuration, role assignments, encryption settings, and logging are yours to get right and yours to evidence. Screenata runs 115 native checks against that configuration on a schedule and turns each result into signed evidence mapped to the control it satisfies.
Screenata connects to Azure through a read-only service principal and runs 115 native checks against your subscription configuration: RBAC assignments, storage encryption, activity logs, and network security groups. Each finding becomes a signed, timestamped evidence artifact mapped to SOC 2, HIPAA, and ISO 27001 controls through a shared control catalog, so one scan feeds every framework you run.
115 native checks · read-only · signed evidence
What it proves
Azure evidence, mapped to controls.
Role assignments across the subscription, privileged role sprawl, and whether access follows least privilege.
Proof that production access is granted through defined roles and that privileged assignments are limited, the first thing an auditor samples.
Encryption at rest on storage accounts and whether transfers are forced over encrypted connections.
Per-account findings showing data is encrypted at rest, mapped to the encryption requirements in each framework.
Activity log coverage on the subscription, retention settings, and delivery to durable storage.
Proof that administrative activity is recorded and retained, which monitoring controls depend on.
Open inbound rules on sensitive ports, wide address ranges, and unrestricted access to management endpoints.
Findings that production networks restrict inbound access to what the system description claims.
Control references are the requirements each evidence area supports, via the shared control catalog. Your auditor decides sufficiency; the artifacts are theirs to verify.
Compliance checks
What Screenata checks on Azure, and why each matters.
Defender for Servers Enabled
Without server threat protection, attacks on virtual machines such as brute-force logons and privilege abuse go undetected. An auditor verifies the Defender for Servers plan is on the Standard tier.
All Defender Plans Enabled
Without full Defender coverage, malicious or misconfigured deployments across services go unnoticed. An auditor checks that Defender for Cloud plans are set to the Standard tier for the subscription.
Diagnostic Settings Exist
Without exporting the activity log, control-plane events lack central retention, so RBAC changes and deletions are hard to detect. An auditor verifies diagnostic settings export the activity log to a durable destination.
Storage Minimum TLS 1.2
Allowing TLS 1.0 or 1.1 permits downgrade attacks that expose data in transit. An auditor checks that storage accounts require a minimum TLS version of 1.2.
Storage Public Blob Access Disabled
Public blob access lets unauthenticated users read or enumerate container contents. An auditor verifies blob public access is disabled on storage accounts.
Storage Secure Transfer Required
Allowing HTTP to storage endpoints opens the door to interception and tampering of credentials and data. An auditor confirms secure transfer requires HTTPS only.
Storage Accounts Use Customer-Managed Keys
With provider-managed keys you cannot revoke access on demand, rotate on your own schedule, or audit key use. An auditor verifies storage accounts encrypt at rest with customer-managed keys.
Storage Infrastructure Encryption Enabled
Infrastructure encryption adds a second layer so a single key or algorithm compromise does not expose stored data. An auditor checks that infrastructure encryption is enabled on storage accounts.
Storage Accounts Have Private Endpoints
Relying on the public endpoint widens exposure to key compromise and internet scanning. An auditor verifies storage accounts use private endpoint connections.
Key Vault Soft Delete and Purge Protection
Without these protections, deleted keys and secrets can be permanently purged, which can render data unreadable and break applications. An auditor confirms soft delete and purge protection are enabled.
Key Vault Secret Rotation
Secrets without expiry and rotation outlive policy and stay usable if leaked. An auditor verifies Key Vault secrets have expiry set and are rotated on schedule.
Key Vault Access Policy Least Privilege
Wildcard or purge permissions on a vault let a single principal read or destroy keys and secrets. An auditor checks that access policies follow least privilege and reviews the key-access roster.
Network Flow Logs Captured And Sent
Without flow logging there is no visibility into lateral movement or exfiltration patterns. An auditor verifies flow logs are enabled and sent to storage or a Log Analytics workspace.
SQL Server TDE Encryption
Without transparent data encryption, database files, backups, and snapshots may be readable by anyone with disk access. An auditor confirms TDE is enabled on each database.
SQL Server Auditing Enabled
Without auditing, logins, privilege changes, and query activity are invisible, so data theft can go undetected. An auditor verifies auditing is enabled at the server level.
SQL Server Minimum TLS 1.2
Without a modern minimum, clients can negotiate weak TLS and be downgraded, exposing credentials and data. An auditor checks that SQL servers require TLS 1.2 or higher.
AKS Private Access Only
Public node addresses expose worker VMs to internet scanning and exploitation of OS and kubelet services. An auditor verifies AKS node pools disable public IP assignment.
Users With VM Access Have MFA
Accounts with VM access but no second factor are open to phishing and password spraying that lead to remote login and lateral movement. An auditor checks that users with VM roles have MFA configured.
Defender For Databases Enabled
Without database threat protection, brute force, injection, and exfiltration attempts go undetected. An auditor verifies Defender plans covering SQL and other databases are enabled.
No Public IP Addresses Exposed
Internet-visible IPs are easy to discover and probe for open ports and known vulnerabilities. An auditor checks that the subscription does not expose publicly reachable IP resources.
SQL Server Unrestricted Inbound Access Disabled
A firewall rule spanning the entire IPv4 range lets any host reach the database for scanning and brute force. An auditor verifies no rule allows the full address range.
Attached VM Disks Encrypted With CMK
With platform-managed keys you cannot enforce independent rotation or revoke access to crypto-lock stolen copies. An auditor confirms attached managed disks use customer-managed keys.
Key Vault Key Rotation Enabled
Keys without a rotation policy outlive policy and raise exposure if the material leaks. An auditor verifies Key Vault keys have a rotation policy configured.
Azure Backup Protection Configured
Unprotected VMs have no recoverable copy outside the primary disks, so ransomware or deletion becomes permanent loss. An auditor checks that in-scope VMs are protected in a Recovery Services vault with schedule and retention.
Drawn from Screenata’s Azure check library. Control refs are the requirements each check produces evidence for; your auditor decides sufficiency.
How it connects
Read-only, revocable, yours.
Read-only by construction
OAuth scopes and IAM roles are scoped to read. Vera never gets write access to your systems.
Signed findings
SHA-256 per artifact, RSA/ECDSA signatures, RFC 3161 timestamps. Verifiable without a Screenata account.
Mapped to controls
Each finding lands on the shared control catalog, so one scan satisfies SOC 2, HIPAA, and ISO 27001 at once.
BAA & attestation status
Microsoft offers a Business Associate Agreement covering the Azure services it designates as in scope for HIPAA, and it publishes its SOC and ISO certifications through the Service Trust Portal. That covers Microsoft's side of the arrangement. Your subscription is still yours: RBAC assignments, storage and disk encryption, TLS settings, and activity log retention are configuration you own and evidence you have to produce.
What access does Screenata need to my Azure subscription?
A service principal with read-only access that you create and control. Screenata uses it for scheduled scans and never receives write access. You can inspect exactly what it permits before connecting, and revoke it at any time from your own Azure portal.
Is the Azure integration enough for SOC 2?
It covers the infrastructure slice: access control, encryption, logging, and network boundary evidence from your subscription. A full SOC 2 program also needs policies, HR and vendor evidence, and organizational controls, which come from your other connections and documents. About 70% of evidence across a typical program is collected automatically.
How often do the Azure checks run?
On a schedule, with weekly cloud scans as the default cadence. Each run produces fresh findings, and evidence freshness is tracked so anything approaching staleness gets flagged before an auditor sees it.
Can my auditor verify the Azure evidence independently?
Yes. Every finding is hashed with SHA-256, signed with RSA or ECDSA, and timestamped under RFC 3161. The evidence pack verifies with a free CLI outside Screenata, so the auditor does not have to trust a dashboard screenshot.
What are the steps to implement SOC 2 with Azure?
First, connect the subscription with a read-only service principal so the scan can see your configuration without any write path. Second, let the first scan run and establish a baseline of where the subscription stands against the SOC 2 control set, instead of guessing which controls are already met. Third, fix what fails, which in most subscriptions means requiring secure transfer and a minimum TLS version of 1.2 on storage accounts, disabling public blob access, exporting the activity log through diagnostic settings, enabling TDE and auditing on SQL servers, and requiring MFA for users who can reach virtual machines. Fourth, let the scheduled scans collect the passing results as signed, timestamped evidence, so you build a history over the observation window rather than a single snapshot. Fifth, hand the evidence package to an independent auditor. The audit itself is a separate engagement you contract with a CPA firm; Screenata produces the evidence, it does not issue the report.
Is Azure HIPAA compliant?
No cloud provider is HIPAA compliant on its own, and Microsoft does not claim Azure is. Microsoft will sign a BAA covering the Azure services it designates as in scope, which makes those services usable for PHI. Compliance is a property of how you configure and operate your workload on top of them. What makes the difference is encryption at rest and in transit, access control with MFA and least privilege on RBAC assignments, audit logging that captures administrative activity, and evidence that those controls actually operated over time rather than on the one day you looked.
Do auditors accept evidence Screenata collects from Azure?
Yes. Every finding is exported as a signed, timestamped artifact, a SHA-256 hash with an RSA or ECDSA signature and an RFC 3161 timestamp, that an auditor verifies outside Screenata with a free CLI. A person reviews and approves the evidence before it reaches the auditor. Screenata collects and signs it; it does not decide the audit result.
Connect and see
Fifteen minutes after connecting Azure, you know your real posture.
Related: AWS · Google Cloud · Microsoft 365 · Azure DevOps