Ensure that Azure Network Watcher service is enabled for all regions in your Microsoft Azure subscription in order to help you monitor and diagnose various conditions at the network level. Microsoft Azure Network Watcher provides tools to monitor, diagnose, and enable or disable logs for the cloud resources within a Virtual Network (VNet).
This rule resolution is part of the Conformity Security & Compliance tool for Azure.
The network diagnostic and visualization tools provided by the Network Watcher service help users and organizations understand, diagnose, and troubleshoot their Azure cloud network infrastructure.
Audit
To determine if Azure Network Watcher is enabled for your Microsoft Azure subscriptions, perform the following operations:
Remediation / Resolution
To enable Network Watcher service for all your Microsoft Azure subscriptions, perform the following:
References
- Azure Official Documentation
- What is Azure Network Watcher?
- Enable or disable Azure Network Watcher
- Security Control V2: Logging and Threat Detection
- Azure Command Line Interface (CLI) Documentation
- az network watcher list
- az network watcher configure
- az account list-locations