Official agent skill

Azure Validate

by microsoft in microsoft/GitHub-Copilot-for-Azure

Pre-deployment validation for Azure readiness. An agent skill from microsoft/GitHub-Copilot-for-Azure.

OfficialMITAuto-check passedDevOps & Cloud

Install Azure Validate

skills CLI
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-validate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-validate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/azure-skills/skills/azure-validate .claude/skills/azure-validate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-validate
GitHub stars
255
Used in
1 other repo
Token cost
~880 tokens
SKILL.md length
312 words
Files
32 (incl. references)
Skills in repo
56
Repo updated
First seen
Licence
MIT

At a glance

Pre-deployment validation for Azure readiness. An agent skill from microsoft/GitHub-Copilot-for-Azure.

  • Works in 3 steps: Run after azure-prepare, before… → All checks must pass—do not deploy with… → ⛔ Destructive actions require ask_user —…
  • Tasks that involve Infrastructure as code
  • SKILL.md covers Triggers, Rules and Steps
  • Runs PowerShell and Shell scripts from its folder; calls pwsh

What it does

Azure Validate is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization. Pre-deployment validation for Azure readiness. Run deep checks on configuration, infrastructure (Bicep or Terraform), RBAC role assignments, managed identity permissions, and prerequisites before deploying. WHEN: validate my app, check deployment readiness, run preflight checks, verify configuration, check if ready to deploy, validate azure.yaml, validate Bicep, test before deploying, troubleshoot deployment errors, validate Azure Functions, validate function app, validate serverless deployment, verify RBAC…

Its SKILL.md is about 880 tokens, which your agent loads only when the skill is triggered. The skill folder holds 37 other files, including reference files (for example `references/aspire-functions-secrets.md`, `references/global-rules.md` and `references/policy-validation.md`).

It sits in DevOps & Cloud, covering Infrastructure as code, Authorization and RBAC and Deployment. It works with Microsoft Azure, Bicep, Azure Functions and Terraform. The repository describes itself as: GitHub Copilot for Azure. The licence is MIT.

When your agent uses it

  • Tasks that involve Infrastructure as code
  • Tasks that involve Authorization and RBAC
  • Tasks that involve Deployment

Example prompts

  • “/azure-validate”

Requirements

  • A Bash shell
  • PowerShell

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Run after azure-prepare, before azure-deploy
  2. All checks must pass—do not deploy with failures
  3. ⛔ Destructive actions require ask_user — global-rules

What it can do on your machine

Read from SKILL.md and the folder at commit d8f4f4e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (PowerShell and Shell, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • pwsh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Validate loads about 880 tokens when it runs, and up to ~23k if it reads all its reference files. Until then it costs about 162 tokens; SKILL.md has 312 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~162
When it runs · the whole SKILL.md, loaded when a task matches
~880
With references · SKILL.md plus every file in references/, read only if the agent opens them
~23k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/GitHub-Copilot-for-Azure at commit d8f4f4e, republished under its MIT licence (© microsoft). 312 words, ~880 tokens.

Download SKILL.mdSave it as .claude/skills/azure-validate/SKILL.md (or your agent's skills folder). This skill also uses 31 other files; get the full folder from GitHub.
name
azure-validate
description
Pre-deployment validation for Azure readiness. Run deep checks on configuration, infrastructure (Bicep or Terraform), RBAC role assignments, managed identity permissions, and prerequisites before deploying. WHEN: validate my app, check deployment readiness, run preflight checks, verify configuration, check if ready to deploy, validate azure.yaml, validate Bicep, test before deploying, troubleshoot deployment errors, validate Azure Functions, validate function app, validate serverless deployment, verify RBAC roles, check role assignments, review managed identity permissions, what-if analysis, validate Container Apps deployment.
license
MIT
metadata.author
Microsoft
metadata.version
0.0.0-placeholder

Azure Validate

AUTHORITATIVE GUIDANCE — Follow these instructions exactly unless they contradict security policies given to you.

⛔ STOP — PREREQUISITE CHECK REQUIRED

Before proceeding, verify this prerequisite is met:

azure-prepare was invoked and completed → .azure/deployment-plan.md exists with status Approved or later

If the plan is missing, STOP IMMEDIATELY and invoke azure-prepare first.

The complete workflow ensures success:

azure-prepare → azure-validate → azure-deploy

Triggers

  • Check if app is ready to deploy
  • Validate azure.yaml or Bicep
  • Run preflight checks
  • Troubleshoot deployment errors

Rules

  1. Run after azure-prepare, before azure-deploy
  2. All checks must pass—do not deploy with failures
  3. ⛔ Destructive actions require ask_user — global-rules

Steps

Run the workflow script and follow its instructions. It walks you through each validation step one at a time, recording progress in .azure/validate-status.json. Use references/scripts/workflow.ps1 on Windows or references/scripts/workflow.sh on macOS/Linux.

Start by calling the script without the completed-step argument:

bash
pwsh references/scripts/workflow.ps1 -WorkspacePath <workspace-path>
# macOS/Linux: bash references/scripts/workflow.sh --workspace-path <workspace-path>

Each run prints the next action and the value to pass next. Perform the action, then re-run with that value (-CompletedStep <value> for pwsh, --completed-step <value> for bash). Repeat until it reports the azure-validate workflow is complete.

The steps reference recipe details in references/recipes/README.md and role checks in references/role-verification.md.

⛔ VALIDATION AUTHORITY

This skill is the officially verified way to set plan status to Validated. You MUST follow the script's instructions to completion before setting status to Validated. Do NOT set status to Validated without doing so.


⚠️ NEXT STEP — DEPENDS ON USER INTENT

After ALL validations pass, check whether the user asked to deploy:

  • If the user explicitly requested deployment, you MUST invoke azure-deploy to execute it. Do NOT run azd up, azd deploy, or any deployment commands directly — let azure-deploy handle execution.
  • If the user only asked to validate or prepare (not deploy), STOP after recording proof and setting status to Validated. Report the validation results and do NOT invoke azure-deploy.

If any validation failed, fix the issues and re-run azure-validate before proceeding.

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 31 other files (references) in plugins/azure-skills/skills/azure-validate of microsoft/GitHub-Copilot-for-Azure.

  • SKILL.md
  • references/aspire-functions-secrets.md
  • references/global-rules.md
  • references/policy-validation.md
  • references/recipes/README.md
  • references/recipes/azcli/README.md
  • references/recipes/azcli/errors.md
  • references/recipes/azd/README.md
  • references/recipes/azd/aspire.md
  • references/recipes/azd/environment.md
  • references/recipes/azd/errors.md
  • references/recipes/azd/scripts/set-aspire-aca-env.ps1
  • references/recipes/azd/scripts/set-aspire-aca-env.sh
  • references/recipes/bicep/README.md
  • references/recipes/bicep/errors.md
  • … and 17 more

Open the folder on GitHubat commit d8f4f4e

Used in 3 other repositories

We found 4 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in microsoft/GitHub-Copilot-for-Azure, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Azure Validate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Validate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Validate this skillmicrosoft/GitHub-Copilot-for-Azure2551 repos~880Automated safety check: PassMIT
Apex Azure Validatejonathan-vella/apex217—~1.8kAutomated safety check: PassMIT
Apex Azure Deployjonathan-vella/apex217—~2.3kAutomated safety check: PassMIT
Azure EnclaveMicrosoftDocs/Agent-Skills775—~2.7kAutomated safety check: PassCC-BY-4.0
Azure Developer CLIgithub/awesome-copilot40k—~1.9kAutomated safety check: NotesMIT
Apex Azure Rbacjonathan-vella/apex217—~1.8kAutomated safety check: PassMIT

Similar skills

  • Apex Azure Validate

    jonathan-vella/apex

    WORKFLOW SKILL — Pre-deployment validation for Azure: config, infrastructure (Bicep/Terraform), permissions, prerequisites.

    217 GitHub stars~1.8k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Apex Azure Deploy

    jonathan-vella/apex

    WORKFLOW SKILL — Execute Azure deployments (azd up, azd deploy, terraform apply) for already-prepared apps with built-in error recovery.

    217 GitHub stars~2.3k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Azure Enclave

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Enclave development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, and deployment.

    775 GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Azure Developer CLI

    github/awesome-copilot

    Official

    Design, create, review, migrate, or troubleshoot Azure Developer CLI (azd) projects using current Microsoft guidance.

    40k GitHub stars~1.9k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Apex Azure Rbac

    jonathan-vella/apex

    ANALYSIS SKILL — Find the right Azure RBAC role for an identity with least-privilege access; generate CLI, Bicep, and Terraform code to assign it.

    217 GitHub stars~1.8k tokensUpdated today
    Backend & APIsAuto-check passed
  • Azure Firmware Analysis

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Firmware Analysis development including best practices, security, integrations & coding patterns, and deployment.

    775 GitHub stars~1.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from microsoft/GitHub-Copilot-for-Azure

All 56 skills in this repo
  • Capacity

    microsoft/GitHub-Copilot-for-Azure

    Official

    Discovers available Azure OpenAI model capacity across regions and projects.

    255 GitHub starsUsed in 2 repos~1.7k tokens
    Auto-check passed
  • Deploy Model

    microsoft/GitHub-Copilot-for-Azure

    Official

    Unified Azure OpenAI model deployment skill with intelligent intent-based routing.

    255 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Entra Agent Id

    microsoft/GitHub-Copilot-for-Azure

    Official

    Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…

    255 GitHub starsUsed in 3 repos~4k tokens
    Auto-check passed
  • Microsoft Foundry

    microsoft/GitHub-Copilot-for-Azure

    Official

    Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end.

    255 GitHub starsUsed in 1 repo~6.7k tokens
    Auto-check passed
  • Azure Storage

    microsoft/GitHub-Copilot-for-Azure

    Official

    Azure Storage Services including Blob Storage, File Shares, Queue Storage, Table Storage, and Data Lake.

    255 GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check passed
  • Azure Diagnostics

    microsoft/GitHub-Copilot-for-Azure

    Official

    Debug Azure production issues on Azure using AppLens, Azure Monitor, resource health, and safe triage.

    255 GitHub starsUsed in 1 repo~1.6k tokens
    Auto-check passed

Questions about Azure Validate

What does Azure Validate do?

Pre-deployment validation for Azure readiness. An agent skill from microsoft/GitHub-Copilot-for-Azure. Azure Validate is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization. Pre-deployment validation for Azure readiness.

When should I use Azure Validate?

Azure Validate fits situations like: tasks that involve Infrastructure as code; tasks that involve Authorization and RBAC; tasks that involve Deployment.

How do I install Azure Validate in Claude Code?

Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-validate -a claude-code`. Or copy the skill folder (plugins/azure-skills/skills/azure-validate in microsoft/GitHub-Copilot-for-Azure) into .claude/skills/azure-validate in your project. Claude Code loads it when a task matches its description.

How do I install Azure Validate in Codex?

Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-validate -a codex`. Or copy the skill folder (plugins/azure-skills/skills/azure-validate in microsoft/GitHub-Copilot-for-Azure) into .agents/skills/azure-validate in your project. Codex loads it when a task matches its description.

Can I use Azure Validate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-validate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-validate, .gemini/skills/azure-validate, .github/skills/azure-validate and .opencode/skills/azure-validate in your project.

What does Azure Validate need to run?

Going by SKILL.md and its folder, Azure Validate needs PowerShell and a shell for the scripts in its folder and the command-line tools its instructions call (pwsh). Our summary lists: A Bash shell; PowerShell.

Does Azure Validate access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Azure Validate safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Validate use?

Azure Validate is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Validate use?

About 880 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 22k tokens, read only when the agent opens those files.

What are the alternatives to Azure Validate?

Skills that share tags, products or a category with Azure Validate: Apex Azure Validate (jonathan-vella/apex, 217 stars), Apex Azure Deploy (jonathan-vella/apex, 217 stars), Azure Enclave (MicrosoftDocs/Agent-Skills, 775 stars) and Azure Developer CLI (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Validate?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/GitHub-Copilot-for-Azure, which has 255 GitHub stars. The repository holds 56 skills in this directory. The repository was last updated on October 7, 2026.

Source: microsoft/GitHub-Copilot-for-Azure on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.