Info icon
End of Life Notice: For Trend Cloud One™ - Conformity Customers, Conformity will reach its End of Sale on “July 31st, 2025” and End of Life “July 31st, 2026”. The same capabilities and much more is available in TrendAI Vision One™ Cloud Risk Management. For details, please refer to Upgrade to TrendAI Vision One™

Ensure Non-Deprecated Microsoft Cloud Security Benchmark Policies Are Not Disabled

TrendAI Vision One™ provides continuous assurance that gives peace of mind for your cloud infrastructure, delivering over 1400 automated best practice checks.

Risk Level: High (not acceptable risk)

Ensure that your Microsoft Azure MCSB policy initiative does not have non-deprecated policies set to a Disabled effect. The Microsoft Cloud Security Benchmark (MCSB) is an Azure Policy initiative automatically assigned to all subscriptions that evaluates resource configurations against Microsoft security best practice recommendations. When policies are set to a Disabled effect, they are not evaluated. Microsoft deprecates policies when controls are superseded or no longer applicable; a deprecated policy's definition name is prefixed with [Deprecated]: in the Azure Policy portal and its policyDeprecated metadata property is set to true.

Security
Operational
excellence

Disabling a non-deprecated MCSB policy prevents Microsoft Defender for Cloud from evaluating the associated control and surfacing relevant security recommendations, creating an undetected gap in your security posture visibility. This gap may allow misconfigurations and security issues to go unnoticed until they are exploited. By keeping non-deprecated policies enabled (at minimum with an Audit effect), you ensure that Microsoft Defender for Cloud continues to evaluate these controls and surface recommendations for remediation. Exceptions allowing non-deprecated MCSB policies to be disabled can be reasonably made when a compensating control exists, a scope exemption exists for certain resources, the policy effect conflicts with architecturally deliberate choices, or the resource type is not used in the evaluated scope; however, each exception should be documented and reconsidered periodically.


Audit

To determine if non-deprecated MCSB policies are set to a Disabled effect, perform the following operations:

Using Azure Console

  1. Sign in to the Microsoft Azure Portal.

  2. Navigate to Microsoft Defender for Cloud available at https://portal.azure.com/#view/Microsoft_Azure_Security/SecurityMenuBlade/~/Overview.

  3. In the left navigation panel, under Management, select Environment settings.

  4. Select the Azure subscription or management group that you want to examine from the Environment settings list.

  5. In the left navigation panel, select Security policies.

  6. Select the Microsoft cloud security benchmark initiative to view the policies.

  7. To filter for disabled policies, click Add filter, select Effect, check the Disabled checkbox, and click Apply.

  8. For each policy returned, confirm whether the definition is deprecated:

    - Deprecated definitions display a [Deprecated]: name prefix.

    - Deprecated policies set to Disabled are expected and compliant.

  9. Verify that no non-deprecated policies (those without a [Deprecated]: prefix) are displayed with a Disabled effect.

  10. Repeat steps 4 – 9 for each subscription or management group available within your Microsoft Azure account.

Remediation / Resolution

To restore non-deprecated MCSB policies that are set to a Disabled effect, perform the following operations:

No remediation is required for deprecated MCSB policies set to Disabled. Only non-deprecated policies with a Disabled effect require remediation. Before remediating, cross-reference each policy against the current documented organizational exceptions and the Azure Policy definitions list to confirm deprecation status. If a documented exception exists, no remediation is required.

Using Azure Console

  1. Sign in to the Microsoft Azure Portal.

  2. Navigate to Microsoft Defender for Cloud available at https://portal.azure.com/#view/Microsoft_Azure_Security/SecurityMenuBlade/~/Overview.

  3. In the left navigation panel, under Management, select Environment settings.

  4. Select the Azure subscription or management group that contains the non-compliant policy (see Audit section to identify the right resource).

  5. In the left navigation panel, select Security policies.

  6. Select the Microsoft cloud security benchmark initiative.

  7. Click Add filter, select Effect, check the Disabled checkbox, and click Apply to display only disabled policies.

  8. Verify that the displayed policy is not deprecated before proceeding.

  9. Click the blue ellipsis (...) button to the right of the policy name and select Manage effect and parameters.

  10. Under Policy effect, select Audit to restore the policy to its default effect.

  11. Click Save, then click Refresh to apply the changes.

  12. Repeat steps 8 – 11 for each non-deprecated policy with a Disabled effect.

  13. Repeat steps 4 – 12 for each subscription or management group requiring remediation.

References

Publication date Sep 9, 2026