Skip to main content
compliance · azure

Network security groups that allow inbound traffic from any internet address

resource types
1
rule IDs covered
1
severity
critical

What does ZopNight detect here?

ZopNight flags a network security group with an inbound allow rule from any source address (`0.0.0.0/0`). Exposure of a management port such as SSH 22 or RDP 3389 is rated critical; any other open port is rated high. The finding has no saving attached, only a fix: narrow the source, or reach VMs through Azure Bastion or just-in-time access.

Signal and threshold

How ZopNight evaluates Network security groups that allow inbound traffic from any internet address.
Field Value
Rule IDsRC-1360
Categorycompliance
Severitycritical
Metricnone — pure configuration read
Thresholdinbound allow from 0.0.0.0/0
SourceZopNight
Permissions usedMicrosoft.Network/networkSecurityGroups/read · Microsoft.Network/networkSecurityGroups/securityRules/read

What an any-source rule really opens

A network security group filters traffic to subnets and network interfaces by rules processed in priority order, from 100 to 4096, with Azure’s default rules at 65000 and above. In the NSG rule reference, 0.0.0.0/0 in the source column represents all IP addresses. An inbound allow rule with that source hands the port to every scanner on the internet.

On a management port the consequence is immediate: SSH and RDP are the first services automated brute-force tools try. On a data port such as SQL Server 1433, MongoDB 27017 or Redis 6379, the database is one weak password or unpatched flaw from exposure.

Listing internet-facing inbound rules

Terminal window
az network nsg rule list --resource-group my-rg --nsg-name my-nsg \
--query "[?direction=='Inbound' && access=='Allow' && (sourceAddressPrefix=='*' || sourceAddressPrefix=='0.0.0.0/0' || sourceAddressPrefix=='Internet')].{name:name, port:destinationPortRange, priority:priority}" \
-o table

Rules that use sourceAddressPrefixes (plural) or ranges of ports need a second look, since the query above checks only the single-value fields.

Two severities from one check

ZopNight derives two exposure signals from the NSG’s inbound rules when it inventories the NSG. If a management port (SSH 22, RDP 3389 or another administrative port) is reachable from any source, the finding is raised at critical severity. If only other ports are open to any source, it is raised at high. A management-port exposure is reported once, at critical, not twice.

When no finding appears

A signal counts only when it is explicitly true. If the exposure analysis is missing for an NSG, ZopNight raises nothing rather than assume the worst, and a customer tag claiming the NSG is open is not enough on its own to trigger a finding. An NSG whose inbound allow rules all name specific source ranges does not trigger it.

An attack surface, not an invoice

There is no saving on this finding. The exposure is direct: remote code execution and lateral movement on management ports, data theft on database ports.

Narrowing the rules without locking yourself out

  1. Set up another way in first: Azure Bastion gives RDP and SSH over TLS on port 443 without exposing the VM’s own ports, and just-in-time VM access opens a port only on request and only for a set time.
  2. Restrict each rule’s source to known ranges: az network nsg rule update --resource-group my-rg --nsg-name my-nsg --name allow-ssh --source-address-prefixes 203.0.113.0/24.
  3. Delete management-port rules that Bastion or JIT now replaces with az network nsg rule delete.
  4. For data services, prefer Private Link or service endpoints over any public rule.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·