Skip to content

Assessment Catalogue

Azure Scout ships 46 assessments backed by 44 rule files holding 395 rules, of which 173 are evaluated automatically and 222 require manual confirmation.

Run one, several, or all of them:

powershell
Invoke-AzureScout -TenantID '<guid>' -Assessment 'LandingZone'
Invoke-AzureScout -TenantID '<guid>' -Assessment 'WAF: Security','Assess: Networking'
Invoke-AzureScout -TenantID '<guid>' -Assessment 'All'

This page is generated

Regenerate it with scripts/Build-AssessmentCatalog.ps1. Rows and counts come from manifests/assessments.psd1 and src/assess/rules/; tests/DocsAssessmentCatalog.Tests.ps1 fails the build if the committed page and a fresh regeneration disagree. Do not hand-edit it.

26 of the 46 assessments ingest governance data and therefore need ARM Reader at the tenant-root management group to resolve fully; below that scope they degrade to an explicit Unknown rather than a false zero. They are marked Gov in the tables below. See Auth & permissions per scan type.

Manual rules are not failures

A manual rule is one no collected data can decide — a process control, or a source Azure does not expose. Manual rules are excluded from every score rather than counted as failures, and they are reported separately. An assessment whose rules are largely manual produces a worklist, not a grade.

Cloud Adoption Framework (9)

AssessmentWhat it coversRulesAutomatedManualGovRule files
CAF: Azure billing and Microsoft Entra tenantCAF landing zone design area — Azure billing and Microsoft Entra ID tenant setup606Govcaf.billing
CAF: Azure Landing ZoneCAF/WAF landing zone audit (all areas)935835Govcaf.billing
caf.identity
caf.network
caf.resourceorg
caf.security
caf.management
caf.governance
caf.platformauto
waf.cost
waf.operational
waf.performance
waf.reliability
waf.security
xr.crossresource
CAF: GovernanceCAF landing zone design area — Governance (policy & compliance)743Govcaf.governance
CAF: Identity and access managementCAF landing zone design area — Identity and access management743Govcaf.identity
CAF: ManagementCAF landing zone design area — Management (monitoring, operations baseline)651Govcaf.management
CAF: Network topology and connectivityCAF landing zone design area — Network topology and connectivity761Govcaf.network
CAF: Platform automation and DevOpsCAF landing zone design area — Platform automation and DevOps624Govcaf.platformauto
CAF: Resource organizationCAF landing zone design area — Resource organization (management groups, subscriptions, tags)642Govcaf.resourceorg
CAF: SecurityCAF landing zone design area — Security761Govcaf.security

Well-Architected Framework (7)

AssessmentWhat it coversRulesAutomatedManualGovRule files
WAF: Azure LocalWell-Architected Framework — Azure Local (platform 2311+ and Azure Local VMs) workload review33726Govwaf.azurelocal.cost
waf.azurelocal.operational
waf.azurelocal.performance
waf.azurelocal.reliability
waf.azurelocal.security
WAF: Cost OptimizationWell-Architected Framework — Cost Optimization pillar only963Govwaf.cost
WAF: Maturity ModelWell-Architected Framework — maturity levels per pillar (same rules as the five WAF pillar assessments, different output framing)352114Govwaf.reliability
waf.security
waf.cost
waf.operational
waf.performance
WAF: Operational ExcellenceWell-Architected Framework — Operational Excellence pillar only633Govwaf.operational
WAF: Performance EfficiencyWell-Architected Framework — Performance Efficiency pillar only642Govwaf.performance
WAF: ReliabilityWell-Architected Framework — Reliability pillar only734Govwaf.reliability
WAF: SecurityWell-Architected Framework — Security pillar only752Govwaf.security

Service category slices (19)

AssessmentWhat it coversRulesAutomatedManualGovRule files
Assess: AIAI/Cognitive private access and responsible-AI posture541caf.ai
Assess: AI WorkloadAI workload review (Well-Architected Framework AI workload guidance) -- 34 items across 7 of 10 AI design areas; mostly manual, see docs/frameworks/waf-ai-workload-checklist.md34232waf.ai
Assess: AnalyticsAnalytics data governance and network isolation532caf.analytics
Assess: AVD WorkloadAVD-on-Azure-Local workload review (Well-Architected Framework) -- 20 items across all 5 pillars; scoped to AVD deployed on Azure Local, not general Azure Virtual Desktop20614waf.avd
Assess: Cloud GovernanceCAF Govern methodology -- 1-10 maturity score per risk category (regulatory compliance, security, cost, operations, data, resource management, AI), radar + heatmap report18810Govcaf.govern.ai
caf.govern.cm
caf.govern.dg
caf.govern.op
caf.govern.rc
caf.govern.rm
caf.govern.sc
Assess: ComplianceRegulatory compliance — scores every Azure Policy regulatory-compliance initiative assigned in the scanned scope (MCSB, CIS, ISO 27001, NIST, PCI-DSS, ...) from compliance state Azure already evaluatedcompliance.initiative
Assess: ComputeVM resilience, zones, backup, right-size, orphans22139waf.reliability
waf.cost
waf.performance
Assess: ContainersAKS private clusters, RBAC, registry hardening871caf.containers
Assess: DatabasesSQL/DB private access, TDE, zone redundancy734caf.databases
Assess: HybridArc onboarding, agent currency, Azure Local642caf.hybrid
Assess: IdentityIdentity & access — PIM, Conditional Access, RBAC743Govcaf.identity
Assess: IntegrationMessaging redundancy and APIM network isolation660caf.integration
Assess: IoTIoT Hub/DPS network isolation and device auth1385caf.iot
Assess: ManagementGovernance, policy, cost, backup, automation, update manager19910Govcaf.governance
caf.management
caf.billing
Assess: MonitorMonitoring, alerting, diagnostics coverage1284caf.management
waf.operational
Assess: NetworkingNetwork topology, firewall, DDoS, exposure, private link761caf.network
Assess: SecurityDefender, Key Vault, secure score, exposure14113caf.security
waf.security
Assess: StorageStorage public access, TLS, encryption, redundancy642caf.storage
Assess: WebApp Service HTTPS-only, TLS, managed identity642caf.web

Specialised and workload assessments (11)

AssessmentWhat it coversRulesAutomatedManualGovRule files
Microsoft: CASACloud Adoption Security Assessment — cloud security maturity aligned to the CAF Secure methodology (question text is Scout's own inference from the published CAF Secure checklist, not Microsoft's numbered CASA questions; see docs/frameworks/casa-question-set.md)32824Govcasa.security
Microsoft: DevOps CapabilityDevOps Capability Assessment -- scores against the Microsoft DevOps Resource Center's five practice phases (docs/frameworks/devops-capability-question-set.md). The assessment itself and its question numbering are INFERRED, not Microsoft-published. A DIFFERENT, narrower assessment than "CAF: Platform automation and DevOps" (the landing-zone design area) -- the two overlap in subject but are not the same enumeration. Azure DevOps access is opt-in (-IncludeDevOps) and sits behind its own auth boundary; when it was not granted, the affected findings report NotAssessed, never a scored zero.1899Govdevops.capability
Microsoft: FinOps ReviewFinOps Review -- scores against the FinOps Framework's 22 published capabilities (docs/frameworks/finops-review-question-set.md). The assessment itself and its question numbering are INFERRED, not Microsoft-published -- Microsoft names the assessment and publishes the framework, but not the assessment's own question text. Cost data sits behind the EA/MCA billing permission system, a different boundary than ARM Reader; when that gate blocks the pull, the affected findings report NotAssessed, never a scored zero.22715Govfinops.review
Microsoft: SMART MigrationStrategic Migration Assessment — migration readiness (see docs/frameworks/smart-question-set.md)1174Govsmart.migration
Scout: Cost OptimizationCost / TCO data pull963waf.cost
Scout: Cross-ResourceFindings that require two collected datasets correlated660xr.crossresource
Scout: Governance BaselineManagement sub-bundle — policy assignments, locks, budgets743Govcaf.governance
Scout: Monitoring BaselineMonitor sub-bundle (subset of "Assess: Monitor") — diagnostic settings coverage only633waf.operational
Scout: Update ManagerManagement sub-bundle (subset of "Assess: Management") — patch/update compliance only651caf.management
Workload: AVSAzure VMware Solution workload — Reliability, Security, and Governance coverage (no published WAF pillar service guide exists for AVS; see docs/frameworks/waf-avs-workload-checklist.md)27918Govavs.workload
Workload: AVS Landing ZoneAzure VMware Solution Landing Zone Assessment Review — platform readiness (see docs/frameworks/avs-landing-zone-question-set.md)25916Govcaf.avslandingzone

Rule files

Each file declares one framework area. An assessment selects files by glob.

Rule fileRulesAutomatedManual
avs.workload27918
caf.ai541
caf.analytics532
caf.avslandingzone25916
caf.billing606
caf.containers871
caf.databases734
caf.govern.ai202
caf.govern.cm422
caf.govern.dg211
caf.govern.op422
caf.govern.rc211
caf.govern.rm110
caf.govern.sc312
caf.governance743
caf.hybrid642
caf.identity743
caf.integration660
caf.iot1385
caf.management651
caf.network761
caf.platformauto624
caf.resourceorg642
caf.security761
caf.storage642
caf.web642
casa.security32824
compliance.initiative000
devops.capability1899
finops.review22715
smart.migration1174
waf.ai34232
waf.avd20614
waf.azurelocal.cost624
waf.azurelocal.operational642
waf.azurelocal.performance606
waf.azurelocal.reliability615
waf.azurelocal.security909
waf.cost963
waf.operational633
waf.performance642
waf.reliability734
waf.security752
xr.crossresource660

Total — 44 files, 395 rules, 173 automated, 222 manual.

Released under the MIT License.