All skills
microsoft avatar

/azure-compliance

@b283057
by microsoftmicrosoft/skills3.1k stars
351

Run Azure compliance and security audits with azqr plus Key Vault expiration checks. Covers best-practice assessment, resource review, policy/compliance validation, and security posture checks. WHEN: compliance scan, security audit, BEFORE running azqr (compliance cli tool), Azure best practices, Key Vault expiration check, expired certificates, expiring secrets, orphaned resources, compliance assessment.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-compliance

This session only. Nothing lands on disk.

referencessdkazure-security-keyvault-secrets-java.md

≈380 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Key Vault Secrets — Java SDK Quick Reference

Condensed from azure-security-keyvault-secrets-java. Full patterns (async client, secret rotation, backup/restore, config loader) in the azure-security-keyvault-secrets-java plugin skill if installed.

Install

<dependency>
    <groupId>com.azure</groupId>
    <artifactId>azure-security-keyvault-secrets</artifactId>
    <version>4.9.0</version>
</dependency>
<dependency>
    <groupId>com.azure</groupId>
    <artifactId>azure-identity</artifactId>
</dependency>

Quick Start

Auth: DefaultAzureCredential is for local development. See auth-best-practices.md for production patterns.

import com.azure.security.keyvault.secrets.SecretClientBuilder;
import com.azure.identity.DefaultAzureCredentialBuilder;
var secretClient = new SecretClientBuilder()
    .vaultUrl("https://<vault>.vault.azure.net")
    .credential(new DefaultAzureCredentialBuilder().build())
    .buildClient();

Best Practices

  • Enable soft delete — protects against accidental deletion
  • Use tags — tag secrets with environment, service, owner
  • Set expiration — use setExpiresOn() for credentials that should rotate
  • Content type — set contentType to indicate format (e.g., application/json)
  • Version management — don't delete old versions immediately during rotation
  • Access logging — enable diagnostic logging on Key Vault
  • Least privilege — use separate vaults for different environments

Source: SKILL.md on GitHub

1 warning15d4 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill provides a comprehensive framework for Azure compliance and security auditing, utilizing specialized tools and remediation templates. It adheres to industry-standard best practices by promoting managed identities and least-privilege access across Azure environments.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    15/15 files flagged

Signed by skilld at b283057. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 weeks ago
metadata
{
  "author": "Microsoft",
  "version": "1.2.2"
}

README badge

README badge for microsoft/skills/azure-compliance