azure-compliance

por Azure

Capacidades abrangentes de auditoria de conformidade e segurança do Azure, incluindo avaliação de melhores práticas, monitoramento de expiração do Key Vault e validação de configuração de recursos.

npx skills add https://github.com/microsoft/GitHub-Copilot-for-Azure --skill azure-compliance

Azure Compliance & Security Auditing

Quick Reference

PropertyDetails
Best forCompliance scans, security audits, Key Vault expiration checks
Primary capabilitiesComprehensive Resources Assessment, Key Vault Expiration Monitoring
MCP toolsazqr, subscription and resource group listing, Key Vault item inspection

When to Use This Skill

  • Run azqr or Azure Quick Review for compliance assessment
  • Validate Azure resource configuration against best practices
  • Identify orphaned or misconfigured resources
  • Audit Key Vault keys, secrets, and certificates for expiration

Skill Activation Triggers

Activate this skill when user wants to:

  • Check Azure compliance or best practices
  • Assess Azure resources for configuration issues
  • Run azqr or Azure Quick Review
  • Identify orphaned or misconfigured resources
  • Review Azure security posture
  • "Show me expired certificates/keys/secrets in my Key Vault"
  • "Check what's expiring in the next 30 days"
  • "Audit my Key Vault for compliance"
  • "Find secrets without expiration dates"
  • "Check certificate expiration dates"

Prerequisites

  • Authentication: user is logged in to Azure via az login
  • Permissions to read resource configuration and Key Vault metadata

Assessments

AssessmentReference
Comprehensive Compliance (azqr)references/azure-quick-review.md
Key Vault Expirationreferences/azure-keyvault-expiration-audit.md
Resource Graph Queriesreferences/azure-resource-graph.md

MCP Tools

ToolPurpose
mcp_azure_mcp_extension_azqrRun azqr compliance scans
mcp_azure_mcp_subscription_listList available subscriptions
mcp_azure_mcp_group_listList resource groups
keyvault_key_listList all keys in vault
keyvault_key_getGet key details including expiration
keyvault_secret_listList all secrets in vault
keyvault_secret_getGet secret details including expiration
keyvault_certificate_listList all certificates in vault
keyvault_certificate_getGet certificate details including expiration

Assessment Workflow

  1. Select scope (subscription or resource group) for Comprehensive Resources Assessment.
  2. Run azqr and capture output artifacts.
  3. Analyze Scan Results and summarize findings and recommendations.
  4. Review Key Vault Expiration Monitoring output for keys, secrets, and certificates.
  5. Classify issues and propose remediation or fix steps for each finding.

Priority Classification

PriorityGuidance
CriticalImmediate remediation required for high-impact exposure
HighResolve within days to reduce risk
MediumPlan a resolution in the next sprint
LowTrack and fix during regular maintenance

Error Handling

ErrorMessageRemediation
Authentication required"Please login"Run az login and retry
Access denied"Forbidden"Confirm permissions and fix role assignments
Missing resource"Not found"Verify subscription and resource group selection

Best Practices

  • Run compliance scans on a regular schedule (weekly or monthly)
  • Track findings over time and verify remediation effectiveness
  • Separate compliance reporting from remediation execution
  • Keep Key Vault expiration policies documented and enforced

SDK Quick References

For programmatic Key Vault access, see the condensed SDK guides:

Mais skills de Azure

azure-ai
Azure
Use para Azure AI: Search, Speech, OpenAI, Document Intelligence. Ajuda com pesquisa, busca vetorial/híbrida, fala-para-texto, texto-para-fala, transcrição, OCR.
appinsights-instrumentation
Azure
Orientação para instrumentar aplicações web com Azure Application Insights. Fornece padrões de telemetria, configuração do SDK e referências de configuração.
azure-aigateway
Azure
Configure o Azure API Management (APIM) como AI Gateway para proteger, observar, controlar modelos de IA, servidores MCP e agentes. Ajuda com limitação de taxa, cache semântico, segurança de conteúdo e balanceamento de carga.
azure-compute
Azure
Recomendar tamanhos de VM do Azure, Conjuntos de Escala de VM (VMSS) e configurações com base nos requisitos de carga de trabalho, necessidades de desempenho e restrições orçamentárias.
azure-cost-optimization
Azure
Identifique e quantifique economias de custos em assinaturas do Azure analisando custos reais, métricas de utilização e gerando recomendações acionáveis de otimização.
azure-deploy
Azure
Executar implantação no Azure. Etapa final após preparação e validação. Executa comandos azd up, azd deploy ou provisionamento de infraestrutura.
azure-diagnostics
Azure
Depure e solucione problemas de produção no Azure. Abrange diagnósticos de Container Apps e Function Apps, análise de logs com KQL, verificações de integridade e resolução de problemas comuns.
azure-hosted-copilot-sdk
Azure
Crie e implante aplicativos do SDK do GitHub Copilot no Azure.