Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

MITAuto-check passedDevOps & Cloud

Install Azure Arc

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-arc -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills azure-arc --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/azure-arc .claude/skills/azure-arc && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-arc
GitHub stars
175
Token cost
~1.9k tokens
SKILL.md length
856 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

  • Works in 7 steps: Plan the onboarding scope and identity —… → Plan network and proxy requirements —… → Onboard servers at scale — Pilot 5-10… → …
  • Azure-native VMs only (use Azure Resource Manager directly)
  • SKILL.md covers When to use, Pick the Arc capability by…, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Azure Arc is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management. Covers Arc-enabled servers onboarding, extending Defender for Cloud and Azure Policy to non-Azure machines, and Arc-enabled Kubernetes. WHEN: Azure Arc, manage on-prem servers from Azure, hybrid management, Arc-enabled servers, Arc Kubernetes, extend Defender for Cloud to on-prem, govern multicloud machines, Connected…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Container orchestration. It works with Microsoft Azure, Kubernetes, Microsoft Defender and Amazon Web Services. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • Azure-native VMs only (use Azure Resource Manager directly)
  • Intune-managed endpoints (use intune-device-mgmt)
  • Azure Stack HCI specifically (separate product)

Example prompts

  • “/azure-arc”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Plan the onboarding scope and identity — Decide which subscriptions / resource groups
  2. Plan network and proxy requirements — Connected Machine agent needs outbound HTTPS
  3. Onboard servers at scale — Pilot 5-10 servers manually (one Windows, one Linux).
  4. Govern with Azure Policy + machine configuration — Assign Azure Policy initiatives
  5. Extend Defender for Cloud — Enable Defender for Servers Plan 2 on the subscription
  6. Unify monitoring + updates — Send Arc machines' logs to Log Analytics via Azure
  7. Grant access via Azure RBAC — Arc machines are ARM resources. Use Azure RBAC + PIM

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Arc loads about 1.9k tokens when it runs. Until then it costs about 200 tokens; SKILL.md has 856 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~200
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 856 words, ~1,946 tokens.

Download SKILL.mdSave it as .claude/skills/azure-arc/SKILL.md (or your agent's skills folder).
name
azure-arc
description
Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management. Covers Arc-enabled servers onboarding, extending Defender for Cloud and Azure Policy to non-Azure machines, and Arc-enabled Kubernetes. WHEN: Azure Arc, manage on-prem servers from Azure, hybrid management, Arc-enabled servers, Arc Kubernetes, extend Defender for Cloud to on-prem, govern multicloud machines, Connected Machine agent, Arc agent, hybrid security posture, machine configuration, guest configuration. DO NOT USE for Azure-native VMs only (use Azure Resource Manager directly), Intune-managed endpoints (use intune-device-mgmt), or Azure Stack HCI specifically (separate product).
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Azure Arc

Azure Arc projects on-premises, multicloud, and edge resources into Azure Resource Manager so they can be governed, secured, and managed with the same control plane as Azure-native resources, extending Azure Policy, Microsoft Defender for Cloud, and Azure Monitor to hybrid estates.

When to use

Bringing non-Azure servers, Kubernetes clusters, and data services under consistent Azure governance and security. Use this skill when you need one pane of glass and policy plane across hybrid / multicloud machines.

Do not use this skill for Azure-native VMs (use ARM directly), Intune-managed endpoints (intune-device-mgmt), or Azure Stack HCI deployment.

Pick the Arc capability by resource type

Resource typeArc serviceWhat you get
On-prem / AWS / GCP serverArc-enabled serversDefender for Cloud, Policy, Update Manager, Monitor, RBAC
Non-AKS Kubernetes (on-prem, EKS, GKE)Arc-enabled KubernetesGitOps via Flux, Policy, Monitor, Defender for Containers
SQL Server on-prem / other cloudArc-enabled SQL ServerInventory, best-practice assessment, Defender
PostgreSQL / SQL MI at edgeArc-enabled data servicesManaged PaaS-like experience at edge
Hybrid app platform (containerised)Arc-enabled App Services / FunctionsPaaS runtime on Arc-enabled K8s

Rule of thumb: start with Arc-enabled servers for hybrid posture - it's the highest-value, lowest-friction step. The Connected Machine agent gives you Defender for Cloud and Azure Policy across the hybrid estate for the price of an outbound HTTPS connection.

Approach

  1. Plan the onboarding scope and identity — Decide which subscriptions / resource groups own the Arc resources. Define the target resource group per region / per business unit. Pre-create service principals if onboarding at scale via script. Verify: target RG exists with the Azure Connected Machine Onboarding role assigned to the onboarding identity.

  2. Plan network and proxy requirements — Connected Machine agent needs outbound HTTPS (443) to a defined list of Microsoft endpoints. If servers are behind a corporate proxy, configure the agent for proxy + auth. Some endpoints require firewall allowlisting. Verify: a pilot server can reach *.his.arc.azure.com, *.guestconfiguration.azure.com, *.dp.kubernetesconfiguration.azure.com (for K8s); agent install completes.

  3. Onboard servers at scale — Pilot 5-10 servers manually (one Windows, one Linux). Then script the rollout: GPO / Ansible / Configuration Manager for Windows; cloud-init / Ansible for Linux. The agent script accepts service principal + tags. Verify: Arc resource appears in the target RG; Connected status; tags applied.

  4. Govern with Azure Policy + machine configuration — Assign Azure Policy initiatives (e.g. Azure Security Benchmark) at the RG / subscription scope. Machine configuration (formerly guest configuration) audits in-OS settings on Arc machines just like Azure VMs. Verify: ASB initiative shows compliance state for Arc machines; in-OS audit returns results (e.g. password complexity).

  5. Extend Defender for Cloud — Enable Defender for Servers Plan 2 on the subscription that contains the Arc resources. Defender deploys MDE, file integrity monitoring, and adaptive controls to the Arc machines. Verify: Defender for Servers shows Arc machines as protected; MDE shows them onboarded.

  6. Unify monitoring + updates — Send Arc machines' logs to Log Analytics via Azure Monitor Agent (extension). Use Azure Update Manager to assess and deploy updates from Azure across the hybrid fleet.

  7. Grant access via Azure RBAC — Arc machines are ARM resources. Use Azure RBAC + PIM for who can manage them. The Arc agent also enables a managed identity on the machine for outbound calls to Azure services.

Show full SKILL.md (326 more words)Show less

Guardrails

  • Secure the Connected Machine agent and its outbound connectivity; scope its managed identity to least privilege. A compromised agent identity = lateral path into Azure.
  • Plan network/proxy and firewall requirements before broad onboarding. Failed agents silently never report - looks like the estate is healthy when it's blind.
  • Use Arc to unify security posture - don't leave hybrid servers outside Defender for Cloud. A "we'll get to hybrid later" gap is where ransomware lives.
  • Arc Policy = on-prem Policy. Same policies you apply to Azure VMs should hit Arc machines. Assign at the management group / subscription level for inheritance.
  • Tag Arc resources consistently with Azure-native ones. Otherwise cost reports, ownership, and Defender prioritisation break.
  • Defender for Servers Plan 2 is per-machine-billed. Cost-aware onboarding; pilot first.

Common anti-patterns

  • "Onboard servers without firewall planning" - Agents fail silently; estate looks unmanaged. Allowlist first.
  • "Manual onboarding for 5,000 servers" - Not maintainable. Script with SP + tags.
  • "Defender for Servers Plan 1 only" - Plan 1 lacks MDE / vuln management /file integrity. Plan 2 for production.
  • "Use Arc agent as a remote-execution back door" - Tempting but breaks the security model. Use Run Command via ARM, governed by RBAC.
  • "Tag Arc machines differently from Azure VMs" - Reports diverge. Same tagging scheme.
  • "Don't onboard servers in legacy DCs because they're going away" - They're not going away as fast as you think; unmanaged DCs are the breach origin.

Example prompts

  • Onboard on-premises servers to Azure with Arc and extend Defender for Cloud to them.
  • How do I govern multicloud machines from Azure using Azure Arc?
  • Deploy the Azure Arc agent at scale via service principal and apply security policy.
  • Bring Arc-enabled Kubernetes clusters under central governance with Flux GitOps.
  • Apply the Azure Security Benchmark initiative to Arc-enabled servers.
  • Plan network and proxy requirements before broad Arc onboarding.

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/azure-arc of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Azure Arc next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Arc compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Arc this skillvinayaklatthe/microsoft-security-skills175—~1.9kAutomated safety check: PassMIT
Provider Bug Reviewmondoohq/mql412—~2.9kAutomated safety check: PassCustom licence
Kcli Cluster Deploymentkarmab/kcli653—~1.5kAutomated safety check: PassApache-2.0
Extend Discovery Typerunwhen-contrib/runwhen-local163—~1.7kAutomated safety check: PassApache-2.0
Kclikarmab/kcli653—~2.6kAutomated safety check: WarnApache-2.0
Provider API Call Dedupmondoohq/mql412—~7.7kAutomated safety check: PassCustom licence

Similar skills

  • Deep static code review of an mql provider for logic errors, nil-handling bugs, pagination truncation, caching/id collisions, and other defects that silently give users wrong data.

    412 GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Guides deployment and management of Kubernetes clusters with kcli.

    653 GitHub stars~1.5k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Extend Discovery Type

    runwhen-contrib/runwhen-local

    Add or enrich a resource type in an existing RunWhen Local discovery indexer (Azure azureapi, GCP gcpapi, AWS, or Kubernetes).

    163 GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Kcli

    karmab/kcli

    Comprehensive guide for kcli usage. An agent skill from karmab/kcli.

    653 GitHub stars~2.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: warnings
  • A skill your agent uses when a provider scan is slow, times out, or trips rate limits (429, throttling, Retry-After), when the same request URL appears many times in a debug log, when an asset's…

    412 GitHub stars~7.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Cloud Devops

    davila7/claude-code-templates

    Cloud infrastructure and DevOps workflow covering AWS, Azure, GCP, Kubernetes, Terraform, CI/CD, monitoring, and cloud-native development.

    33k GitHub starsUsed in 4 repos~1.4k tokens
    DevOps & CloudAuto-check passed

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Firewall

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Firewall — managed cloud-native L3-L7 stateful network firewall for centralised egress, east-west, and ingress control.

    175 GitHub stars~1.7k tokensUpdated 3 mo ago
    Auto-check passed

Categories

Questions about Azure Arc

What does Azure Arc do?

Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management. Azure Arc is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

When should I use Azure Arc?

Azure Arc fits situations like: azure-native VMs only (use Azure Resource Manager directly); intune-managed endpoints (use intune-device-mgmt); azure Stack HCI specifically (separate product).

How do I install Azure Arc in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-arc -a claude-code`. Or copy the skill folder (skills/azure-arc in vinayaklatthe/microsoft-security-skills) into .claude/skills/azure-arc in your project. Claude Code loads it when a task matches its description.

How do I install Azure Arc in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-arc -a codex`. Or copy the skill folder (skills/azure-arc in vinayaklatthe/microsoft-security-skills) into .agents/skills/azure-arc in your project. Codex loads it when a task matches its description.

Can I use Azure Arc in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-arc -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-arc, .gemini/skills/azure-arc, .github/skills/azure-arc and .opencode/skills/azure-arc in your project.

What does Azure Arc need to run?

SKILL.md names no scripts, command-line tools or credentials: Azure Arc is instructions for the agent only.

Does Azure Arc access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Azure Arc safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Arc use?

Azure Arc is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Arc use?

About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Azure Arc?

Skills that share tags, products or a category with Azure Arc: Provider Bug Review (mondoohq/mql, 412 stars), Kcli Cluster Deployment (karmab/kcli, 653 stars), Extend Discovery Type (runwhen-contrib/runwhen-local, 163 stars) and Kcli (karmab/kcli, 653 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Arc?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.