| Virtual networks and subnets | Address space, region, owner, workload, peering, delegations, service endpoints, NSGs | Are trust zones explicit and non-overlapping? | Resource Graph export, topology, effective rules |
| Public IP addresses | Address, SKU, association, DNS, owner, purpose, protection, last use | Is every public endpoint required and protected? | Public IP inventory, listeners, flow and application logs |
| Load balancing and edge | Front Door, Application Gateway, Load Balancer, Traffic Manager, listeners, backends, TLS, WAF | Where is traffic terminated, filtered, and forwarded? | Configuration export, WAF policy, health and access logs |
| Network security groups | Rules, priority, source, destination, port, protocol, service tag, application security group | Do rules permit only expected traffic at the right scope? | NSG export, effective security rules, flow data |
| Routes and firewalls | User-defined routes, BGP, next hops, firewall policies, rule collections, threat intelligence, DNS proxy | Can traffic bypass required inspection or leave by an uncontrolled path? | Effective routes, policy export, firewall logs, reachability test |
| Private endpoints | Target service, subnet, approval, private DNS, public network state, consumers | Does the intended name resolve privately from every authorized network? | Private endpoint and DNS records, connection test |
| Hybrid links | VPN, ExpressRoute, gateways, circuits, peers, routes, encryption, failover | What on-premises or partner networks become trusted? | Gateway configuration, route tables, monitoring, provider records |
| Administrative access | Bastion, JIT, VPN, privileged workstations, SSH/RDP paths, serial console | Can management ports be reached from the internet or normal user networks? | NSG rules, JIT policy, Bastion configuration, sign-in and activity logs |
| DNS | Private zones, resolvers, forwarders, custom DNS, links, records, logging | Can name resolution send traffic to the wrong or public endpoint? | Zone and link export, resolver rules, query tests |
| Egress | NAT Gateway, firewall, public IP, service tags, FQDN rules, proxy, direct internet paths | Can compromised workloads exfiltrate or download tools without control? | Effective routes, firewall policy, DNS and flow logs |