Skip to main content

Data Factory should not be publicly exposed

SeverityExploitabilityProvidersCategories
CRITICALMEDIUMAzureDATA

Description

Data Factory services are publicly accessible. The default configuration for Data Factory access is public.

Impact

Potential data exposureVisible in logsUser interaction requiredPrivileges required
TrueFalseFalseFalse

Public access to Data factory may lead to data breach, data tampering or DDoS (Distributed Denial-of-Service).

Remediation guidelines

Set public_network_enabled to false, to disable public access for Data Factory.

References

How can I help you ?