All skills
microsoft avatar

/azure-compliance

@2120de9 official

Run Azure compliance and security audits with azqr plus Key Vault expiration checks. Covers best-practice assessment, resource review, policy/compliance validation, and security posture checks. WHEN: compliance scan, security audit, BEFORE running azqr (compliance cli tool), Azure best practices, Key Vault expiration check, expired certificates, expiring secrets, orphaned resources, compliance assessment.

Use this Skill: https://skilld.dev/gh/microsoft/github-copilot-for-azure/azure-compliance

This session only. Nothing lands on disk.

referencesazure-resource-graph.md

≈699 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Azure Resource Graph Queries for Compliance Auditing

Azure Resource Graph (ARG) enables fast, cross-subscription resource querying using KQL via az graph query. Use it for compliance scanning, tag audits, and configuration validation.

How to Query

Use the extension_cli_generate MCP tool to generate az graph query commands:

mcp_azure_mcp_extension_cli_generate
  intent: "query Azure Resource Graph to <describe what you want to audit>"
  cli-type: "az"

Or construct directly:

az graph query -q "<KQL>" --query "data[].{name:name, type:type}" -o table

⚠️ Prerequisite: az extension add --name resource-graph

Key Tables

Table Contains
Resources All ARM resources (name, type, location, properties, tags)
ResourceContainers Subscriptions, resource groups, management groups
AuthorizationResources Role assignments and role definitions
AdvisorResources Azure Advisor recommendations

Compliance Query Patterns

Find resources missing a required tag:

Resources
| where isnull(tags['Environment']) or isnull(tags['CostCenter'])
| project name, type, resourceGroup, tags

Tag coverage analysis:

Resources
| extend hasEnvTag = isnotnull(tags['Environment'])
| summarize total=count(), tagged=countif(hasEnvTag) by type
| extend coverage=round(100.0 * tagged / total, 1)
| order by coverage asc

Find storage accounts without HTTPS enforcement:

Resources
| where type =~ 'microsoft.storage/storageaccounts'
| where properties.supportsHttpsTrafficOnly == false
| project name, resourceGroup, location

Find resources with public network access enabled:

Resources
| where properties.publicNetworkAccess =~ 'Enabled'
| project name, type, resourceGroup, location

Query role assignments across subscriptions:

AuthorizationResources
| where type == 'microsoft.authorization/roleassignments'
| extend principalType = tostring(properties.principalType)
| summarize count() by principalType

Find resource groups without locks:

ResourceContainers
| where type == 'microsoft.resources/subscriptions/resourcegroups'
| project rgName=name, rgId=id
| join kind=leftanti (
    Resources
    | where type == 'microsoft.authorization/locks'
    | project rgId=tostring(properties.resourceId)
) on rgId

Tips

  • Use =~ for case-insensitive type matching (resource types are lowercase)
  • Navigate properties with properties.fieldName
  • Use --first N to limit result count
  • Use --subscriptions to scope to specific subscriptions
  • Combine with AdvisorResources for security recommendations

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill includes some potential considerations regarding indirect prompt injection surfaces due to processing Azure environment metadata. While these warrant review, they are used within the skill's intended auditing functionality and present a minimal risk under normal circumstances.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    11/16 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 2120de9. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 17 hours ago.

Activeupdated 3 weeks ago
metadata
{
  "author": "Microsoft",
  "version": "0.0.0-placeholder"
}
  • Security
  • azure
  • compliance
  • audit
  • azqr
  • keyvault
  • certificates
  • secrets
  • expiration

README badge

README badge for microsoft/github-copilot-for-azure/azure-compliance

Runs Azure compliance and security audits using azqr, plus monitors Key Vault for expired or expiring keys, secrets, and certificates. Identifies orphaned resources, configuration drift, and compliance violations against Azure best practices.

Generated from the current SKILL.md.

Does this skill work with subscriptions I don't have direct access to?
No. The skill requires you to be authenticated via `az login` and have permissions to read resource configuration and Key Vault metadata in the target subscription or resource group.
What does azqr audit check for?
azqr (Azure Quick Review) runs a comprehensive compliance and best-practices assessment across Azure resources, identifying misconfigurations, orphaned resources, and security posture issues. See the Azure Quick Review reference for the full list of checks.
Can this skill check Key Vault expiration dates?
Yes. The skill includes dedicated tools to list and inspect keys, secrets, and certificates in Key Vault, returning expiration dates and identifying items without expiration policies set.
Does this skill fix compliance issues or just report them?
The skill reports findings and classifies them by priority (Critical, High, Medium, Low), then proposes remediation steps. It does not automatically apply fixes.
What authentication method does this skill require?
You must be logged in to Azure via the `az login` command. The skill uses your existing Azure CLI session to access subscriptions and resources.

Generated from the current SKILL.md. These answers refresh after source changes.