All skills
microsoft avatar

/azure-compliance

@b283057
by microsoftmicrosoft/skills3.1k stars
351

Run Azure compliance and security audits with azqr plus Key Vault expiration checks. Covers best-practice assessment, resource review, policy/compliance validation, and security posture checks. WHEN: compliance scan, security audit, BEFORE running azqr (compliance cli tool), Azure best practices, Key Vault expiration check, expired certificates, expiring secrets, orphaned resources, compliance assessment.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-compliance

This session only. Nothing lands on disk.

referencesazure-resource-graph.md

≈699 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Azure Resource Graph Queries for Compliance Auditing

Azure Resource Graph (ARG) enables fast, cross-subscription resource querying using KQL via az graph query. Use it for compliance scanning, tag audits, and configuration validation.

How to Query

Use the extension_cli_generate MCP tool to generate az graph query commands:

mcp_azure_mcp_extension_cli_generate
  intent: "query Azure Resource Graph to <describe what you want to audit>"
  cli-type: "az"

Or construct directly:

az graph query -q "<KQL>" --query "data[].{name:name, type:type}" -o table

⚠️ Prerequisite: az extension add --name resource-graph

Key Tables

Table Contains
Resources All ARM resources (name, type, location, properties, tags)
ResourceContainers Subscriptions, resource groups, management groups
AuthorizationResources Role assignments and role definitions
AdvisorResources Azure Advisor recommendations

Compliance Query Patterns

Find resources missing a required tag:

Resources
| where isnull(tags['Environment']) or isnull(tags['CostCenter'])
| project name, type, resourceGroup, tags

Tag coverage analysis:

Resources
| extend hasEnvTag = isnotnull(tags['Environment'])
| summarize total=count(), tagged=countif(hasEnvTag) by type
| extend coverage=round(100.0 * tagged / total, 1)
| order by coverage asc

Find storage accounts without HTTPS enforcement:

Resources
| where type =~ 'microsoft.storage/storageaccounts'
| where properties.supportsHttpsTrafficOnly == false
| project name, resourceGroup, location

Find resources with public network access enabled:

Resources
| where properties.publicNetworkAccess =~ 'Enabled'
| project name, type, resourceGroup, location

Query role assignments across subscriptions:

AuthorizationResources
| where type == 'microsoft.authorization/roleassignments'
| extend principalType = tostring(properties.principalType)
| summarize count() by principalType

Find resource groups without locks:

ResourceContainers
| where type == 'microsoft.resources/subscriptions/resourcegroups'
| project rgName=name, rgId=id
| join kind=leftanti (
    Resources
    | where type == 'microsoft.authorization/locks'
    | project rgId=tostring(properties.resourceId)
) on rgId

Tips

  • Use =~ for case-insensitive type matching (resource types are lowercase)
  • Navigate properties with properties.fieldName
  • Use --first N to limit result count
  • Use --subscriptions to scope to specific subscriptions
  • Combine with AdvisorResources for security recommendations

Source: SKILL.md on GitHub

1 warning15d4 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill provides a comprehensive framework for Azure compliance and security auditing, utilizing specialized tools and remediation templates. It adheres to industry-standard best practices by promoting managed identities and least-privilege access across Azure environments.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    15/15 files flagged

Signed by skilld at b283057. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 weeks ago
metadata
{
  "author": "Microsoft",
  "version": "1.2.2"
}

README badge

README badge for microsoft/skills/azure-compliance