Azure OpenAI: dave-openai-test
Azure & Power Platform Microsoft · Cloud AI platform · resource type microsoft.cognitiveservices/accounts (OpenAI)
Policy · none set
Policy changes re-score this app on the next sync, which starts right away.
Finding · Open
Risk score
55
High
People
0
Owner tag on the resource
Network
Public
API key auth enabled
Deployments
1
gpt-4.1
azurefirst-partypublic-endpointkey-authno-owner-tagmodel-deployments
Next steps
Recommended actions
- 01'Azure OpenAI: dave-openai-test' accepts traffic from any network. Put it behind a private endpoint or restrict network ACLs to your VNet and office ranges.
- 02API key authentication is enabled. Disable local auth and use managed identities with Cognitive Services roles so a leaked key cannot be replayed.
- 03No owner tag. Tag the resource with an owner and cost center so someone answers for its prompts, spend, and content-filter settings.
- 041 model deployment (gpt-4.1). Confirm content filtering and abuse monitoring are on, and that logging captures prompts if your policy requires it.
Billing · Azure
What it costs
Last 30 days
$2,665
Previous 30
$1,733
Change
+54%
06-1609-13
Contoso Production $1,909 · Contoso Sandbox $756
Azure
Resource posture
- Resource
- /subscriptions/5c2e1f4a-2222-4a5b-9c8d-000000000002/resourceGroups/rg-sandbox-dave/providers/Microsoft.CognitiveServices/accounts/dave-openai-test
- Type
- microsoft.cognitiveservices/accounts (OpenAI)
- Subscription
- 5c2e1f4a-2222-4a5b-9c8d-000000000002
- Resource group
- rg-sandbox-dave
- Region
- swedencentral
- Public network
- enabled
- Local auth (keys)
- enabled
- Managed identity
- no
- Owner
- no owner tag
Model deployments
| Deployment | Model | Version |
|---|---|---|
| gpt-4.1 | gpt-4.1 | 2025-04-14 |
Same app, other lanes
Related findings
- Medium30Azure OpenAI: aoai-prod-eastusAzure & Power Platform1 person
- Medium30Azure OpenAI via Power PlatformAzure & Power Platform3 people
- Medium26Azure OpenAICode · GitHub (demo)0 people
Who
People
Identifiers come from device telemetry and proxy logs, so they may be account names rather than full directory entries.
No people are linked to this app.
Why
Evidence
- azure_resourceAzure OpenAI resource 'dave-openai-test' in rg-sandbox-dave (swedencentral), subscription 5c2e1f4a: 1 deployment, public network access, API key auth enabled
Detail
{ "kind": "OpenAI", "tags": {}, "resourceId": "/subscriptions/5c2e1f4a-2222-4a5b-9c8d-000000000002/resourceGroups/rg-sandbox-dave/providers/Microsoft.CognitiveServices/accounts/dave-openai-test", "deployments": [ { "name": "gpt-4.1", "model": "gpt-4.1", "version": "2025-04-14" } ], "localAuthDisabled": false, "publicNetworkAccess": true }