Guidance needed to comply with Defender network security group flow log policy.

Ashutosh Jadhav 0 Reputation points
2025-10-20T13:32:57.0333333+00:00

I am working on implementing the Azure Defender compliance policy: “Flow logs should be configured for every network security group.”

This policy requires enabling flow logs for all Network Security Groups (NSGs). However, I am facing an issue where the option to select Flow log type: Network security group is disabled by default, as indicated by the notification provided in the Azure portal.

How can I achieve compliance with this policy? We need to meet this requirement as part of our Azure SOC 2 2023 compliance efforts.

User's image

Thanks,

Ashutosh

Azure Network Watcher
Azure Network Watcher
An Azure service that is used to monitor, diagnose, and gain insights into network performance and health.
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.