We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. Azure security audit
Azure security audit, UAE

Most of what an Azure security audit needs is already free in your subscription.

Secure score, the Microsoft cloud security benchmark and multicloud connection all sit in the free Foundational CSPM tier of Defender for Cloud. Very few UAE organisations have switched them on. We audit what your estate actually looks like, and tell you what genuinely needs paying for.

Book an Azure security auditSee what we examine
Azure subscription and resource security audit for UAE organisations
  • Foundational CSPMFree, and usually not enabled
  • Subscription-wideIdentity, network, data, workloads
  • Free firstWe use what you already have
  • AWS and GCP tooMulticloud connection is free
What we examine

Eight areas, starting with the tooling you already own.

Azure estates grow by accretion. A subscription created for one project, a resource group somebody spun up for a test, a storage account that outlived its purpose. The audit is less about finding exotic misconfigurations than about establishing what actually exists and who can reach it.

Turn on what is free before buying anything

Microsoft states that Defender for Cloud includes free Foundational CSPM capabilities, and the free tier explicitly covers secure score, centralised policy management with the Microsoft cloud security benchmark as a built-in standard, the CSPM dashboard, and connecting AWS and GCP environments. In most UAE estates we assess, none of this is enabled. That is a genuine finding and it costs nothing to fix.

Who can do what, across subscriptions

Role assignments at management group, subscription and resource group level, how many people hold Owner or Contributor, whether those assignments are permanent or activated when needed, and which service principals and managed identities hold significant rights. Service principals are the ones organisations lose track of, because they were created during a deployment and nobody owns them afterwards.

What is reachable from the internet

Public IP addresses, exposed management ports, storage accounts and databases with public network access, application endpoints, and anything left listening from a project that finished. This is the section that most often produces something urgent, and the cause is almost always a temporary arrangement that was never reversed rather than a deliberate decision.

Where the data is and how it is protected

Storage accounts, databases and their access model: network restrictions, shared access signatures and how they are issued, encryption and key management, and whether anything holding personal or regulated data is reachable more broadly than anybody intended. Shared access tokens are a recurring finding because they are easy to issue, long-lived by default and hard to revoke individually.

Key Vault, secrets and what is sitting in plain text

Whether secrets are in Key Vault or in application settings, pipeline variables and configuration files, who can read them, whether access is logged, and whether anything has an expiry nobody is tracking. The common pattern is a Key Vault that exists, is used properly by the newest workload, and is bypassed by everything older.

Policy, and whether anything is actually enforced

Azure Policy assignments, what they audit rather than enforce, and whether exemptions were granted temporarily and never reviewed. Centralised policy management sits in the free tier, so an estate with no policy assignments is not a licensing problem, it is an unconfigured one. Effective policy is what stops the estate drifting back after you fix it.

Logging, retention and whether an investigation is possible

Which resources send diagnostic logs, where those logs go, how long they are kept, and whether anybody would notice an alert. As with any cloud platform, the retention you have is a configuration decision rather than a default that suits you, and organisations discover the limit during an investigation rather than before one.

Which paid plans are actually worth it for you

Defender CSPM adds attack path analysis, cloud security explorer, regulatory compliance and governance. The workload plans cover servers, containers, storage, databases, Key Vault, App Service, APIs and Resource Manager separately. Which of these earns its place depends entirely on what you run, and the honest answer for a small estate is often fewer of them than a vendor would propose.

Before anybody quotes you for anything

Switch on the free tier and look at the score.

This is the single most useful thing on this page and you can do it yourself this afternoon. Microsoft publishes what is included at no cost, and it is more than most people assume.

  • Microsoft states that Defender for Cloud includes free Foundational CSPM capabilities. Explicitly listed in that free tier: secure score, centralised policy management including the Microsoft cloud security benchmark as a built-in standard, the CSPM dashboard, and multicloud coverage so you can connect AWS and GCP environments as well.
  • That gives you a prioritised list of misconfigurations across your Azure estate without spending anything. It will not give you attack path analysis, the cloud security explorer, regulatory compliance reporting or governance rules, which sit in the paid Defender CSPM plan, and it will not give you the workload protection plans. But it will tell you whether you have a problem worth investigating.
  • What the score is not is a security rating you should optimise. It is calculated against a Microsoft baseline that does not know your business, so it will award points for controls you do not need and stay silent on the specific thing that would actually hurt you. Use it as a starting index and a trend line, not as an answer.
  • The reason this matters commercially is that plenty of proposals in this market start with buying Defender plans. Sometimes that is right. But an estate that has never enabled the free tier has no idea what its actual problems are, and buying advanced tooling before knowing that is a poor sequence.
Ask us to review what your free tier is already telling you
How we audit

Four things that keep this from becoming a licensing proposal.

Cloud security assessments have an obvious commercial gravity: every finding can be answered with a product. We work in the opposite order deliberately.

We use the free tier before recommending a paid one

Foundational CSPM gives you secure score, policy management, the Microsoft cloud security benchmark and multicloud connection at no cost. We enable and read that first, because it establishes what your actual problems are. Recommending Defender CSPM or workload plans before knowing that is selling before diagnosing, and it produces spend that does not match the risk.

We separate what is urgent from what is untidy

An Azure estate will generate a long list of recommendations, most of which are housekeeping. A management port open to the internet, an over-permissioned service principal and a storage account holding personal data with public access are a different category entirely. The report leads with the second group, because a hundred-item list gets filed and a five-item list gets fixed.

We connect findings to the obligations you actually carry

Where you are subject to UAE data protection obligations, sector requirements or client commitments, the findings that matter are the ones touching those. We map them rather than reporting generically, which also makes the remediation easier to fund because the justification is concrete rather than a security preference.

We cover the estate you have, including the parts outside Azure

Multicloud connection for AWS and GCP is in the free tier, so if you run workloads across more than one provider we can bring them into the same view rather than assessing Azure in isolation. Plenty of UAE organisations have a primary platform and a second one that arrived through an acquisition or a single project, and the second one is invariably the less governed.

When this is worth doing

Six situations that bring UAE organisations to an Azure audit.

The trigger shapes the scope. An audit prompted by a cost review looks different from one prompted by a client security questionnaire, and we scope accordingly.

A client or insurer has asked specific questions

Questions about cloud access control, encryption, logging and network exposure, which somebody has to answer accurately and in writing. An audit produces the answers and, more usefully, identifies which ones you should fix before answering. This is the most common trigger and the one with the clearest finish line.

Azure grew from one project into an estate

It started with a single workload, it worked, and five years later there are several subscriptions, resources nobody claims and access granted for reasons nobody remembers. Nothing is wrong exactly, and nobody has ever looked at it as a whole. These audits reliably find things worth fixing and rarely find a crisis, which is the right time to look.

A regulated firm in DIFC, ADGM or under CBUAE supervision

Cloud governance, access control and the ability to evidence both come up in supervisory conversations, and for a firm running material workloads in Azure that evidence lives in the subscription. Where the Central Bank requirements applying to you set the UAE Information Assurance Standards as a floor, the mapping between those and your Azure configuration is work worth doing deliberately.

An organisation holding personal or regulated data in Azure

The federal data protection law and, for free zone entities, their own regimes apply to data wherever it sits. The practical questions are where that data actually is in your estate, who can reach it, whether it is reachable from outside, and whether you could evidence access. Those are audit questions before they are legal ones.

A business that inherited an estate from a departed engineer

One person built it, understood it and has left. What remains is infrastructure nobody can fully explain, with service principals, automation and access whose purpose is undocumented. The first value of an audit here is simply an accurate picture, before any question of improving it arises.

After a cost review raised uncomfortable questions

A finance-driven look at Azure spend often surfaces resources nobody can account for, which is a security question as much as a cost one. Anything running that nobody owns is also anything running that nobody is patching, monitoring or securing. The two exercises overlap more than people expect and are worth doing together.

Three positions

What we find when we audit an Azure estate in the UAE.

The middle column is the most common. Azure was adopted for a specific project, it worked, more things were added, and nobody ever stepped back to look at the estate as a whole.
Complete inventory of subscriptions and owners
Governed
Grown by accretionPartial
Unexamined
Defender for Cloud enabled at least on the free tier
Governed
Grown by accretionSometimes
Unexamined
Secure score tracked as a trend
Governed
Grown by accretion
Unexamined
Privileged role assignments reviewed
Governed
Grown by accretionRarely
Unexamined
Service principals owned and understood
Governed
Grown by accretion
Unexamined
Internet exposure known and intentional
Governed
Grown by accretionPartly
Unexamined
Secrets held in Key Vault
Governed
Grown by accretionNewer workloads only
UnexaminedIn config files
Policy enforces rather than only audits
Governed
Grown by accretionAudit only
UnexaminedNone
Diagnostic logging with deliberate retention
Governed
Grown by accretionDefault or absent
Unexamined
Resources from finished projects removed
Governed
Grown by accretion
Unexamined
Feature
Governed
Grown by accretion
Unexamined
Complete inventory of subscriptions and owners
Partial
Defender for Cloud enabled at least on the free tier
Sometimes
Secure score tracked as a trend
Privileged role assignments reviewed
Rarely
Service principals owned and understood
Internet exposure known and intentional
Partly
Secrets held in Key Vault
Newer workloads onlyIn config files
Policy enforces rather than only audits
Audit onlyNone
Diagnostic logging with deliberate retention
Default or absent
Resources from finished projects removed
What costs money and what does not

Defender for Cloud capabilities by plan.

Taken from Microsoft published capability tables. This matters because the free tier covers more than most organisations realise, and because the paid plans are separable rather than a single purchase, so you can buy only what your workloads justify.
CapabilityPlan
Secure scoreFoundational CSPM, free
Centralised policy managementFoundational CSPM, free
Microsoft cloud security benchmark as a built-in standardFoundational CSPM, free
CSPM dashboardFoundational CSPM, free
Connect AWS and GCP environmentsFoundational CSPM, free
Code pipeline insightsFoundational CSPM and Defender CSPM
Attack path analysisDefender CSPM
Cloud security explorerDefender CSPM
Regulatory compliance reportingDefender CSPM
Security governance rulesDefender CSPM
Data security posture managementDefender CSPM or Defender for Storage
Server, container, storage, database and other workload protectionSeparate CWPP plans, per workload type
How the audit runs

Five stages, typically one to two weeks.

Collection is read-only and does not affect running workloads. The time goes into interpretation, because whether a configuration is a risk depends entirely on what the resource does and who is meant to reach it.
  1. 1

    Inventory the estate and enable what is free

    Every subscription, who owns it, what runs in it, and Defender for Cloud enabled at least on Foundational CSPM so the secure score and benchmark recommendations are available. For many organisations this stage alone produces the first useful output, because the complete subscription list does not currently exist anywhere.

  2. 2

    Identity and access review

    Role assignments across management groups, subscriptions and resource groups, privileged role holders, whether access is standing or activated when needed, and the service principals and managed identities that hold meaningful rights. This is where the highest-severity findings usually sit, and it is the part most often missing from automated reports.

  3. 3

    Exposure and data review

    What is reachable from the internet, what network restrictions exist on storage and databases, how shared access tokens are issued and whether they can be revoked, encryption and key management, and where regulated data actually lives. We work from what is configured now rather than from what the policy intends.

  4. 4

    Logging, policy and detection review

    Diagnostic settings across resource types, where logs go and for how long, whether alerts reach anybody, Azure Policy assignments and whether they enforce or merely audit, and which exemptions were granted temporarily and never revisited.

  5. 5

    Report, prioritise, and decide what to buy

    Findings ranked by exploitability rather than by tool severity, separated into what costs configuration effort and what would cost licensing. Where a paid Defender plan genuinely earns its place for your workloads we say which and why. Where it does not, we say that too, and the free tier plus configuration is the recommendation.

Straight answers

What organisations ask about Azure security audits.

No, and this is the most useful thing to know before anybody quotes you. Microsoft states that Defender for Cloud includes free Foundational CSPM capabilities, and the free tier explicitly covers secure score, centralised policy management with the Microsoft cloud security benchmark built in, the CSPM dashboard, and connecting AWS and GCP environments. That is enough to establish whether you have a problem worth investigating. The paid Defender CSPM plan adds attack path analysis, the cloud security explorer, regulatory compliance and governance rules on top.

No. Secure score is calculated against a Microsoft baseline that has no knowledge of your business, so it awards points for controls you may not need and cannot see the specific misconfiguration that would actually harm you. We have audited estates with respectable scores and a management port open to the internet on a machine holding client data. Use the score as a starting index and as a trend line over time, and use an audit to answer whether you are actually exposed.

They divide into two groups. Defender CSPM is the advanced posture plan, adding attack path analysis, the cloud security explorer, regulatory compliance reporting and governance rules. Then there are separate workload protection plans for servers, containers, storage, databases, Key Vault, App Service, APIs, Resource Manager and AI services, each covering a specific resource type. Because they are separable, you can buy only what your workloads justify, and for a small estate that is often considerably fewer than a vendor would propose.

No. Collection is read-only, it queries configuration rather than changing it, and running services are unaffected. What can be disruptive is remediation, particularly anything touching network access or identity, so we separate the two and plan changes with you rather than applying them during the audit. If we find something genuinely urgent, an exposed management port or a publicly readable store of personal data, we tell you immediately rather than waiting for the report.

Something reachable from the internet that was never meant to be, usually left from a project that ended. After that: subscription-level Owner or Contributor held by more people than anybody realised, service principals with broad permissions that nobody owns because they were created during a deployment, secrets sitting in application settings or pipeline variables rather than Key Vault, and diagnostic logging that was never enabled on the resources you would need it for.

Different estate, different questions, frequently the same organisation. A Microsoft 365 audit looks at the tenant: identity, mail, sharing, devices and audit evidence. An Azure audit looks at the subscription and the resources in it: what is running, who can reach it, what is exposed to the internet, where data sits and whether you could investigate an incident. They share an identity layer through Entra, which is why we often run them together, but neither substitutes for the other.

Yes, and the connection is free. Microsoft lists multicloud coverage, connecting AWS and GCP environments, in the Foundational CSPM free tier, so a mixed estate can be brought into one view without an additional purchase. This is worth knowing for UAE organisations that have a primary platform and a second one that arrived through an acquisition or a single project. In our experience the second platform is almost always the less governed of the two.

Diagnostic logging is a configuration decision per resource type rather than something that is comprehensively on by default, and retention is likewise something you choose rather than something that arrives suitable. The practical consequence is the same as in any cloud platform: organisations find out what they retained during an investigation rather than before one. We check what is enabled, where it goes and how long it is kept, and tell you what you could actually reconstruct.

Managing it is. Independently assessing it is a different question, because a partner auditing an estate they built and operate is assessing their own work. That is a structural issue rather than an accusation, and we apply it to ourselves: where we manage a client Azure estate, our audit of it is not independent and we say so. For an insurer, a regulator or a demanding client, independence is frequently part of what makes the assessment worth anything.

Directly, because if you hold personal data in Azure the federal data protection law applies to it, and free zone entities in DIFC or ADGM have their own regimes as well. The audit answers the questions those obligations depend on: where that data actually is, who can reach it, whether it is reachable from outside your network, whether it is encrypted, and whether you could evidence access if asked. We map findings against the obligations that apply to you rather than reporting them generically.

We scope per organisation, driven by the number of subscriptions, the size and variety of the resource estate, and whether you want the assessment alone or remediation with it. What we will tell you free in the first conversation is how to enable Foundational CSPM and read your own secure score, because that is included in your subscription already and you should not have to pay anybody to find out what it says.

An Azure estate changes continuously, so annually is a reasonable cadence with an additional review after a significant change: a migration, an acquisition, a change of partner, or a major new workload. Between audits, the free secure score gives you a trend line that will show drift without anybody running a project. What matters most is that the second audit is comparable to the first, so it measures whether anything actually improved.

For a genuinely small estate, a few resources in one subscription, the answer may be that enabling the free tier and reading the recommendations yourself gets you most of the way, and we would say so. Where it becomes worth a formal audit is when there are multiple subscriptions, when nobody can produce a complete inventory, when a client or regulator is asking, or when the person who built it has left. Size matters less than whether anybody currently understands what is there.

This is common enough that we plan for it. The sequence is to establish what the resource does before touching it, identify who created it from the activity log, and check whether anything depends on it, because deleting something that turns out to matter is a worse outcome than leaving it another week. Genuinely orphaned resources get decommissioned, which improves both security and cost. Resources that turn out to be important get an owner, which is the actual fix.

Enable Defender for Cloud on the free Foundational CSPM tier, look at the secure score, and separately count how many resources in your subscriptions have a public IP address. The first tells you what Microsoft thinks is wrong. The second tells you your actual exposure to the internet, which is the thing most likely to hurt you and the number most organisations have never checked. Both are free and both take an afternoon.
Azure estate check

Fifteen questions about your own subscriptions.

The first group is what exists at all, which is harder to answer than it sounds. The second is exposure. The third is whether you could investigate something after the fact.

What actually exists

  • How many Azure subscriptions do you have, and who owns each?
    Shadow subscriptions on a departmental card are common.
  • Is Defender for Cloud enabled, even on the free tier?
    Free, and usually not switched on.
  • What is your secure score, and has anyone looked at it?
    A starting index, not a target to optimise.
  • Are there resources from projects that finished?
    They keep running, keep costing and keep being exposed.
  • Do you know which resources hold personal or regulated data?
    Needed for both security and data protection obligations.

Exposure

  • How many resources have a public IP address?
    Count them. The number is usually a surprise.
  • Are any management ports reachable from the internet?
    The most common route into a cloud estate.
  • Do storage accounts or databases allow public network access?
    Check per resource, not per policy intention.
  • How many people hold Owner or Contributor at subscription level?
    And is that access permanent or activated when needed.
  • Which service principals hold significant permissions?
    Created during deployments, rarely owned afterwards.

Could you investigate

  • Are diagnostic logs enabled on resources that matter?
    Off by default on many resource types.
  • Where do those logs go, and how long are they kept?
    Retention is a configuration decision, not a sensible default.
  • Would an alert reach a human who would act on it?
    Collection without response is not detection.
  • Are secrets in Key Vault, or in app settings and pipelines?
    The older the workload, the more likely the latter.
  • Do any Azure Policy assignments actually enforce, or only audit?
    Audit-only policy documents drift, it does not stop it.
Related reading

The pages around this one.

Microsoft 365 security audit

The tenant half of the same Microsoft estate: identity, mail, sharing, devices, and how far back your audit evidence actually reaches.

Learn more

IT audit services in Dubai

The wider audit practice, and how to tell which kind of engagement your situation actually calls for before anybody quotes for one.

Learn more

NIST CSF 2.0 assessment

If you want a picture across the whole security function rather than one platform, this is the broader framework a cloud audit feeds into.

Learn more
Next step

Enable the free tier and count your public IP addresses.

Those two things cost nothing, take an afternoon, and between them tell you whether you have a problem. If you would like help interpreting what you find, or a proper look at the estate behind it, that is a short conversation and we will tell you what we would examine first.

Book an Azure security auditCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Microsoft 365 Security Audit

Tenant review, and how far back your evidence really goes

Learn more

IT Audit Services Dubai

Assessment, technical test or certification, scoped properly

Learn more

NIST CSF 2.0 Assessment

Know where you stand, without committing to certification

Learn more

Microsoft Entra

Identity and access management solutions

Learn more

Microsoft Security Dubai

Entra, Defender, Purview, Sentinel, and what you already own

Learn more

Azure Cloud Solutions

Azure landing zone, migration, FinOps, managed

Learn more

UAE PDPL Compliance

Federal Decree-Law 45 of 2021 readiness and operations

Learn more

Managed Security Services

MSS on Microsoft Defender XDR and Sentinel

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy