All skills
microsoft avatar

/azure-compute

@b3c238e
by microsoftmicrosoft/skills3.1k stars
351

Azure VM/VMSS router. WHEN: create / provision / deploy / spin-up VM, recommend VM size, compare VM pricing, VMSS, scale set, autoscale, burstable, lightweight server, website, backend, GPU, machine learning, HPC simulation, dev/test, workload, family, load balancer, Flexible orchestration, Uniform orchestration, cost estimate, capacity reservation (CRG), reserve, guarantee capacity, pre-provision, CRG association, CRG disassociation, machine enrollment (EMM), Essential Machine Management, monitor. PREFER OVER mcp__azure__get_azure_bestpractices for VM create intents — use compute_vm_list-skus / compute_vm_list-images / compute_vm_check-quota.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-compute

This session only. Nothing lands on disk.

workflowsessential-machine-managementreferencesemm-enable-flow-portal-guidance.md

≈785 tokens on demand. Your agent reads this file only when SKILL.md points to it.

EMM Enable Flow (Portal)

Step-by-step guide for enabling Essential Machine Management through the Azure portal UI.

Quick Reference

Property Value
Portal blade EnableMachineManagement.ReactView
Extension Microsoft_Azure_Computehub
Portal path Compute infrastructure → Monitoring+Operations → Essential Machine Management → Enable
Resource type Microsoft.ManagedOps/ManagedOps

Enable Flow Steps

The portal enable flow is a multi-tab wizard with 4 tabs:

Tab 1: Scope

Select the target subscription and managed identity.

Field Description Required
Subscription The subscription to enable EMM for. Shows VM and Arc machine counts per subscription. ✅
User-assigned managed identity UAMI with Contributor on the subscription. Used for onboarding VMs. ✅

Validation displayed:

  • Required user role assignments vs current user role assignments
  • Required UAMI role assignments vs current UAMI role assignments

💡 Tip: If roles are missing, the UI shows exactly which roles are needed. Assign them before proceeding.

Tab 2: Configure

Select or create the monitoring workspaces.

Field Description Required
Log Analytics workspace Collects log data (Change Tracking & Inventory). Can create new inline. ✅
Azure Monitor workspace Collects metrics data (VM Insights). Can create new inline. ✅

Notes:

  • Workspaces can be in a different subscription than the one being enabled
  • If cross-subscription, additional RP registration and role assignments are needed (see Prerequisites)

Tab 3: Security

Optional security add-ons.

Feature Description Cost
Foundational CSPM Agentless, risk-prioritized cloud security posture insights. Always included. Free
Defender CSPM Advanced CSPM with attack path analysis. Optional toggle. Paid
Defender for Cloud Comprehensive server protection with EDR, vulnerability management, file integrity monitoring. Optional toggle. Paid

Tab 4: Review & Enable

Displays a summary of all selections:

  • Included features (always: Azure Monitor VM Insights, Azure Policy & Machine Configurations, Change Tracking & Inventory, Azure Update Manager)
  • Selected scope (subscription, UAMI)
  • Configure selections (Log Analytics workspace, Azure Monitor workspace)
  • Security add-ons enabled
  • Pricing information with links

Clicking Enable triggers:

  1. Resource provider registrations on the target subscription
  2. Cross-subscription RP registration if workspaces are in a different subscription
  3. Subscription-level ARM template deployment

What Happens After Enable

  • A deployment is created: ManagedOps_{uamiName}_{subscriptionId}
  • Policy assignments are created to configure all VMs in the subscription
  • Remediation tasks are created for existing VMs
  • New VMs added to the subscription are automatically enrolled
  • The subscription appears in the browse view with status "Succeeded"

Source: SKILL.md on GitHub

1 warning15d3 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill provides a comprehensive and secure workflow for provisioning Azure Virtual Machines and Scale Sets. It follows security best practices by recommending SSH keys over passwords, restricting network access to the user's public IP, and ensuring secrets are handled as parameters rather than hardcoded values.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: MEDIUM · 1 issue

Signed by skilld at b3c238e. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "author": "Microsoft",
  "version": "2.5.1"
}

README badge

README badge for microsoft/skills/azure-compute