Official agent skill

Azure Security

by MicrosoftDocs in MicrosoftDocs/Agent-Skills

Expert knowledge for Azure Security development including best practices, decision making, security, configuration, integrations & coding patterns, and deployment.

OfficialCC-BY-4.0Auto-check passedSecurity

Install Azure Security

skills CLI
$ npx skills add MicrosoftDocs/Agent-Skills --skill azure-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install MicrosoftDocs/Agent-Skills azure-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/MicrosoftDocs/Agent-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/azure-security .claude/skills/azure-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-security
GitHub stars
775
Token cost
~3.4k tokens
SKILL.md length
840 words
Files
1
Skills in repo
149
Repo updated
First seen
Licence
CC-BY-4.0

At a glance

Expert knowledge for Azure Security development including best practices, decision making, security, configuration, integrations & coding patterns, and deployment.

  • Configuring Azure antimalware
  • SKILL.md covers How to Use This Skill and Category Index
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Container SBOM/signing

What it does

Azure Security is an agent skill from MicrosoftDocs/Agent-Skills, published by the product's own GitHub organization. Expert knowledge for Azure Security development including best practices, decision making, security, configuration, integrations & coding patterns, and deployment. Use when configuring Azure antimalware, container SBOM/signing, CMK encryption, AKS/VM hardening, or Key Vault keys, and other Azure Security related development tasks. Not for Azure Defender For Cloud (use azure-defender-for-cloud), Azure Information Protection (use azure-information-protection), Azure DDoS Protection (use azure-ddos-protection)…

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires network access. Uses mcpmicrosoftdocs:microsoftdocsfetch or fetchwebpage to retrieve documentation.

It sits in Security, covering Cloud security and Secrets management. It works with Microsoft Azure and Microsoft Defender. The repository describes itself as: Curated Agent Skills for Microsoft & Azure – giving AI coding assistants structured, real-time expertise from Microsoft Learn docs. The licence is CC-BY-4.0.

When your agent uses it

  • Configuring Azure antimalware
  • Container SBOM/signing
  • AKS/VM hardening
  • Other Azure Security related development tasks

Example prompts

  • “/azure-security”

Requirements

  • Compatibility (from SKILL.md): Requires network access. Uses mcp_microsoftdocs:microsoft_docs_fetch or fetch_webpage to retrieve documentation.

What it can do on your machine

Read from SKILL.md and the folder at commit ba74e8f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires network access. Uses mcp_microsoftdocs:microsoft_docs_fetch or fetch_webpage to retrieve documentation.

    From compatibility in the SKILL.md frontmatter.

Context cost

Azure Security loads about 3.4k tokens when it runs. Until then it costs about 149 tokens; SKILL.md has 840 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~149
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from MicrosoftDocs/Agent-Skills at commit ba74e8f, republished under its CC-BY-4.0 licence (© MicrosoftDocs). 840 words, ~3,356 tokens.

Download SKILL.mdSave it as .claude/skills/azure-security/SKILL.md (or your agent's skills folder).
name
azure-security
description
Expert knowledge for Azure Security development including best practices, decision making, security, configuration, integrations & coding patterns, and deployment. Use when configuring Azure antimalware, container SBOM/signing, CMK encryption, AKS/VM hardening, or Key Vault keys, and other Azure Security related development tasks. Not for Azure Defender For Cloud (use azure-defender-for-cloud), Azure Information Protection (use azure-information-protection), Azure DDoS Protection (use azure-ddos-protection), Azure Web Application Firewall (use azure-web-application-firewall).
compatibility
Requires network access. Uses mcp_microsoftdocs:microsoft_docs_fetch or fetch_webpage to retrieve documentation.
metadata.generated_at
2026-09-27
metadata.generator
docs2skills/1.0.0

Azure Security Skill

This skill provides expert guidance for Azure Security. Covers best practices, decision making, security, configuration, integrations & coding patterns, and deployment. It combines local quick-reference content with remote documentation fetching capabilities.

How to Use This Skill

IMPORTANT for Agent: Use the Category Index below to locate relevant sections. For categories with line ranges (e.g., L35-L120), use read_file with the specified lines. For categories with file links (e.g., [security.md](security.md)), use read_file on the linked reference file

IMPORTANT for Agent: If metadata.generated_at is more than 3 months old, suggest the user pull the latest version from the repository. If mcp_microsoftdocs tools are not available, suggest the user install it: Installation Guide

This skill requires network access to fetch documentation content:

  • Preferred: Use mcp_microsoftdocs:microsoft_docs_fetch with query string from=learn-agent-skill. Returns Markdown.
  • Fallback: Use fetch_webpage with query string from=learn-agent-skill&accept=text/markdown. Returns Markdown.

Category Index

CategoryLinesDescription
Best PracticesL34-L58End-to-end Azure security guidance: hardening IaaS/PaaS, identity and access, network and operational security, backups and ransomware resilience, secrets management, and service-specific checklists.
Decision MakingL59-L64Guidance on choosing Azure security options: comparing feature availability in US Gov clouds and selecting the appropriate key management service (e.g., Key Vault, managed keys).
SecurityL65-L97Security best practices for Azure: threat modeling mitigations, platform and network hardening, access control, encryption/keys, infrastructure integrity, and secure AKS/VM/SQL operations.
ConfigurationL98-L108Configuring Azure security features: antimalware, container scanning (Dependabot/Copacetic), firewall rules, CMK encryption, logging/auditing, TLS changes, ransomware protections, and Customer Lockbox alerts.
Integrations & Coding PatternsL109-L114Guides for generating signed SBOMs for container images and scripting Microsoft Antimalware configuration in Azure using PowerShell.
DeploymentL115-L120Guides for signing and verifying container images with Notation in Azure Pipelines/GitHub Actions, plus comparing security feature availability in Azure vs Azure Government.
Best Practices
TopicURL
Harden Azure Marketplace images before publishinghttps://learn.microsoft.com/en-us/azure/security/fundamentals/azure-marketplace-images
Design Azure backup and restore plans against ransomwarehttps://learn.microsoft.com/en-us/azure/security/fundamentals/backup-plan-to-protect-against-ransomware
Implement Azure security best practices and patternshttps://learn.microsoft.com/en-us/azure/security/fundamentals/best-practices-and-patterns
Apply Azure data security and encryption best practiceshttps://learn.microsoft.com/en-us/azure/security/fundamentals/data-encryption-best-practices
Use Azure SQL database security checklisthttps://learn.microsoft.com/en-us/azure/security/fundamentals/database-security-checklist
Secure Azure IaaS workloads and virtual machineshttps://learn.microsoft.com/en-us/azure/security/fundamentals/iaas
Apply Azure identity and access control best practiceshttps://learn.microsoft.com/en-us/azure/security/fundamentals/identity-management-best-practices
Implement incident response processes for Azurehttps://learn.microsoft.com/en-us/azure/security/fundamentals/incident-response-overview
Apply Azure network security best practiceshttps://learn.microsoft.com/en-us/azure/security/fundamentals/network-best-practices
Apply Azure operational security best practiceshttps://learn.microsoft.com/en-us/azure/security/fundamentals/operational-best-practices
Secure Azure App Service PaaS applicationshttps://learn.microsoft.com/en-us/azure/security/fundamentals/paas-applications-using-app-services
Secure PaaS databases with Azure SQL and Synapsehttps://learn.microsoft.com/en-us/azure/security/fundamentals/paas-applications-using-sql
Secure PaaS applications using Azure Storagehttps://learn.microsoft.com/en-us/azure/security/fundamentals/paas-applications-using-storage
Design and operate secure Azure PaaS deploymentshttps://learn.microsoft.com/en-us/azure/security/fundamentals/paas-deployments
Detect and respond to ransomware in Azurehttps://learn.microsoft.com/en-us/azure/security/fundamentals/ransomware-detect-respond
Prepare Azure environments for ransomware resiliencehttps://learn.microsoft.com/en-us/azure/security/fundamentals/ransomware-prepare
Harden Azure Firewall Premium for ransomware defensehttps://learn.microsoft.com/en-us/azure/security/fundamentals/ransomware-protection-with-azure-firewall
Protect and manage secrets in Azure workloadshttps://learn.microsoft.com/en-us/azure/security/fundamentals/secrets-best-practices
Harden Azure Service Fabric clusters and securityhttps://learn.microsoft.com/en-us/azure/security/fundamentals/service-fabric-best-practices
Implement Microsoft Entra identity security checklisthttps://learn.microsoft.com/en-us/azure/security/fundamentals/steps-secure-identity
Prevent Azure subdomain takeover via DNS hygienehttps://learn.microsoft.com/en-us/azure/security/fundamentals/subdomain-takeover
Decision Making
TopicURL
Compare security feature availability in US Government cloudshttps://learn.microsoft.com/en-us/azure/security/fundamentals/feature-availability
Select the right Azure key management servicehttps://learn.microsoft.com/en-us/azure/security/fundamentals/key-management-choose
Show full SKILL.md (364 more words)Show less
Security
TopicURL
Enforce AKS image signature validation with Ratify and Azure Policyhttps://learn.microsoft.com/en-us/azure/security/container-secure-supply-chain/articles/validating-image-signatures-using-ratify-aks
Implement auditing and logging mitigations with Threat Modeling Toolhttps://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool-auditing-and-logging
Implement authentication mitigations with Threat Modeling Toolhttps://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool-authentication
Mitigate authorization threats in Threat Modeling Toolhttps://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool-authorization
Secure communications based on Threat Modeling Tool findingshttps://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool-communication-security
Harden configuration management using Threat Modeling Tool mitigationshttps://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool-configuration-management
Implement cryptography mitigations from Threat Modeling Toolhttps://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool-cryptography
Secure exception management using Threat Modeling Tool guidancehttps://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool-exception-management
Apply secure input validation mitigations from Threat Modeling Toolhttps://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool-input-validation
Protect sensitive data using Threat Modeling Tool mitigationshttps://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool-sensitive-data
Implement secure session management from Threat Modeling Toolhttps://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool-session-management
Apply Azure-specific security controls to AI workloadshttps://learn.microsoft.com/en-us/azure/security/fundamentals/ai-security-best-practices
Review Azure service certificate authorities and requirementshttps://learn.microsoft.com/en-us/azure/security/fundamentals/azure-certificate-authority-details
Enforce platform code integrity in Azure productionhttps://learn.microsoft.com/en-us/azure/security/fundamentals/code-integrity
Understand and configure Azure Customer Lockbox accesshttps://learn.microsoft.com/en-us/azure/security/fundamentals/customer-lockbox-faq
Control Microsoft engineer data access with Customer Lockboxhttps://learn.microsoft.com/en-us/azure/security/fundamentals/customer-lockbox-overview
Identify Azure services supporting customer-managed keyshttps://learn.microsoft.com/en-us/azure/security/fundamentals/encryption-customer-managed-keys-support
Secure Azure hardware, firmware, and supply chainhttps://learn.microsoft.com/en-us/azure/security/fundamentals/firmware
Maintain Azure infrastructure integrity and security controlshttps://learn.microsoft.com/en-us/azure/security/fundamentals/infrastructure-integrity
Monitor Azure infrastructure for security and vulnerabilitieshttps://learn.microsoft.com/en-us/azure/security/fundamentals/infrastructure-monitoring
Manage and operate the Azure production network securelyhttps://learn.microsoft.com/en-us/azure/security/fundamentals/infrastructure-operations
Understand Azure SQL Database security capabilitieshttps://learn.microsoft.com/en-us/azure/security/fundamentals/infrastructure-sql
Apply firmware measured boot and host attestation in Azurehttps://learn.microsoft.com/en-us/azure/security/fundamentals/measured-boot-host-attestation
Apply Azure operational security checklist controlshttps://learn.microsoft.com/en-us/azure/security/fundamentals/operational-checklist
Follow Azure penetration testing rules and scopehttps://learn.microsoft.com/en-us/azure/security/fundamentals/pen-testing
Verify Azure platform integrity and secure host lifecyclehttps://learn.microsoft.com/en-us/azure/security/fundamentals/platform
Secure access to the Azure production networkhttps://learn.microsoft.com/en-us/azure/security/fundamentals/production-network
Control and audit access to customer data in Azurehttps://learn.microsoft.com/en-us/azure/security/fundamentals/protection-customer-data
Use Secure Boot to protect Azure virtual machineshttps://learn.microsoft.com/en-us/azure/security/fundamentals/secure-boot
Configuration
Integrations & Coding Patterns
Deployment

© MicrosoftDocs, CC-BY-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/azure-security of MicrosoftDocs/Agent-Skills.

Open the folder on GitHubat commit ba74e8f

Compare with similar skills

Azure Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Security this skillMicrosoftDocs/Agent-Skills775—~3.4kAutomated safety check: PassCC-BY-4.0
Defender For Cloud Hardeningvinayaklatthe/microsoft-security-skills175—~1.9kAutomated safety check: PassMIT
Implementing Azure Defender For Cloudmukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.0
Implementing Cloud Vulnerability Posture Managementmukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.0
Implementing Cloud Security Posture Managementmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Detecting Compromised Cloud Credentialsmukul975/Anthropic-Cybersecurity-Skills34k—~3.9kAutomated safety check: PassApache-2.0

Similar skills

  • Defender For Cloud Hardening

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Defender for Cloud — cloud security posture management (CSPM) and cloud workload protection (CWPP) across Azure, AWS, and GCP.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Implementing Azure Defender For Cloud

    mukul975/Anthropic-Cybersecurity-Skills

    Enable Microsoft Defender for Cloud (CSPM + CWPP) across VMs, containers, SQL, storage, and Key Vault, using Azure Policy for evaluation, Log Analytics for telemetry, Azure Arc for hybrid coverage…

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Implementing Cloud Vulnerability Posture Management

    mukul975/Anthropic-Cybersecurity-Skills

    Implement multi-cloud CSPM to detect cloud-native misconfigurations and vulnerabilities (IAM over-permissions, exposed storage, unencrypted data, missing network controls) using AWS Security Hub…

    34k GitHub stars~1.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Implementing Cloud Security Posture Management

    mukul975/Anthropic-Cybersecurity-Skills

    Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting Compromised Cloud Credentials

    mukul975/Anthropic-Cybersecurity-Skills

    Detect compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible-travel patterns, and credential-stuffing indicators using GuardDuty, Microsoft…

    34k GitHub stars~3.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Securing Azure With Microsoft Defender

    mukul975/Anthropic-Cybersecurity-Skills

    Deploys and configures Microsoft Defender for Cloud as a CNAPP for Azure, multi-cloud, and hybrid environments: enabling Defender plans for servers, containers, storage, and databases, configuring…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from MicrosoftDocs/Agent-Skills

All 149 skills in this repo
  • Azure Personalizer

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure AI Personalizer development including troubleshooting, decision making, security, configuration, and integrations & coding patterns.

    775 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Azure Architecture Advisor

    MicrosoftDocs/Agent-Skills

    Official

    Guides Azure solution design by category, from reference architectures and design patterns to technology choices and migrations, fetching current Microsoft Learn pages over the network.

    775 GitHub stars~15k tokensUpdated yesterday
    Auto-check passed
  • Azure Advisor Guidance

    MicrosoftDocs/Agent-Skills

    Official

    Reference guidance for Azure Advisor work: recommendations, alerts and digests, workbooks, RBAC access and sovereign-cloud limits, fetched from Microsoft Learn.

    775 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Azure AI Vision Reference

    MicrosoftDocs/Agent-Skills

    Official

    Looks up Microsoft Learn guidance for Azure AI Vision: Image Analysis, Read OCR containers, smart-crop thumbnails, background removal and video frame analysis, plus limits and deployment.

    775 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Azure Analysis Services

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Analysis Services development including troubleshooting.

    775 GitHub stars~608 tokensUpdated yesterday
    Auto-check passed
  • Azure Anomaly Detector

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure AI Anomaly Detector development including troubleshooting, best practices, limits & quotas, configuration, and deployment.

    775 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Azure Security

What does Azure Security do?

Expert knowledge for Azure Security development including best practices, decision making, security, configuration, integrations & coding patterns, and deployment. Azure Security is an agent skill from MicrosoftDocs/Agent-Skills, published by the product's own GitHub organization. Expert knowledge for Azure Security development including best practices, decision making, security, configuration, integrations & coding patterns, and deployment.

When should I use Azure Security?

Azure Security fits situations like: configuring Azure antimalware; container SBOM/signing; AKS/VM hardening; other Azure Security related development tasks.

How do I install Azure Security in Claude Code?

Run `npx skills add MicrosoftDocs/Agent-Skills --skill azure-security -a claude-code`. Or copy the skill folder (skills/azure-security in MicrosoftDocs/Agent-Skills) into .claude/skills/azure-security in your project. Claude Code loads it when a task matches its description.

How do I install Azure Security in Codex?

Run `npx skills add MicrosoftDocs/Agent-Skills --skill azure-security -a codex`. Or copy the skill folder (skills/azure-security in MicrosoftDocs/Agent-Skills) into .agents/skills/azure-security in your project. Codex loads it when a task matches its description.

Can I use Azure Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MicrosoftDocs/Agent-Skills --skill azure-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-security, .gemini/skills/azure-security, .github/skills/azure-security and .opencode/skills/azure-security in your project.

What does Azure Security need to run?

SKILL.md names no scripts, command-line tools or credentials: Azure Security is instructions for the agent only. Compatibility (from SKILL.md): Requires network access. Uses mcp_microsoftdocs:microsoft_docs_fetch or fetch_webpage to retrieve documentation..

Does Azure Security access the network?

SKILL.md names 2 domains. As links in the text: learn.microsoft.com and github.com. This is read from the text; nothing was executed.

Is Azure Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Security use?

Azure Security is published under the CC-BY-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Security use?

About 3.4k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Azure Security?

Skills that share tags, products or a category with Azure Security: Defender For Cloud Hardening (vinayaklatthe/microsoft-security-skills, 175 stars), Implementing Azure Defender For Cloud (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Cloud Vulnerability Posture Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Implementing Cloud Security Posture Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Security?

MicrosoftDocs (a GitHub organization, an official publisher) maintains it in MicrosoftDocs/Agent-Skills, which has 775 GitHub stars. The repository holds 149 skills in this directory. The repository was last updated on October 5, 2026.

Source: MicrosoftDocs/Agent-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.