Agent skill

Azure Network Security Design

by vinayaklatthe in vinayaklatthe/microsoft-security-skills

Guidance for designing secure Azure network architecture — hub-spoke topology (or Virtual WAN), segmentation with NSGs/ASGs, private endpoints / Private Link for PaaS, egress through Azure Firewall…

MITAuto-check passedSecurity

Install Azure Network Security Design

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-network-security-design -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills azure-network-security-design --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/azure-network-security-design .claude/skills/azure-network-security-design && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-network-security-design
GitHub stars
175
Token cost
~1.8k tokens
SKILL.md length
797 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for designing secure Azure network architecture — hub-spoke topology (or Virtual WAN), segmentation with NSGs/ASGs, private endpoints / Private Link for PaaS, egress through Azure Firewall…

  • Works in 7 steps: Topology and address plan — Pick… → Segmentation with NSGs and ASGs — NSG at… → Private endpoints for PaaS — Use Private… → …
  • The firewall itself (use azure-firewall)
  • SKILL.md covers When to use, Pick the topology, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Azure Network Security Design is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for designing secure Azure network architecture — hub-spoke topology (or Virtual WAN), segmentation with NSGs/ASGs, private endpoints / Private Link for PaaS, egress through Azure Firewall, DDoS protection, WAF on Front Door/App Gateway, and centralised private DNS. Aligned to the Zero Trust network pillar. WHEN: Azure network security, hub spoke, Virtual WAN, network segmentation, NSG ASG design, private endpoint, Private Link, DDoS protection, secure virtual network, egress control, Zero Trust network…

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Network security. It works with Microsoft Azure, Azure Key Vault and Microsoft Defender. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • The firewall itself (use azure-firewall)
  • VM-level hardening (use defender-for-cloud-hardening)
  • Key Vault networking only (use azure-key-vault)

Example prompts

  • “/azure-network-security-design”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Topology and address plan — Pick hub-spoke or Virtual WAN. Allocate non-overlapping RFC
  2. Segmentation with NSGs and ASGs — NSG at subnet level (preferred over per-NIC).
  3. Private endpoints for PaaS — Use Private Endpoints / Private Link for sensitive
  4. Centralise egress through Azure Firewall — UDR on spokes: 0.0.0.0/0 next hop =
  5. DDoS + WAF for public-facing — Enable Azure DDoS Network Protection on VNets
  6. Centralised DNS — Private DNS zones linked from the hub; spokes auto-resolve PaaS
  7. Block management plane on the internet — No direct RDP / SSH from internet to VMs.

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Network Security Design loads about 1.8k tokens when it runs. Until then it costs about 191 tokens; SKILL.md has 797 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~191
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 797 words, ~1,817 tokens.

Download SKILL.mdSave it as .claude/skills/azure-network-security-design/SKILL.md (or your agent's skills folder).
name
azure-network-security-design
description
Guidance for designing secure Azure network architecture — hub-spoke topology (or Virtual WAN), segmentation with NSGs/ASGs, private endpoints / Private Link for PaaS, egress through Azure Firewall, DDoS protection, WAF on Front Door/App Gateway, and centralised private DNS. Aligned to the Zero Trust network pillar. WHEN: Azure network security, hub spoke, Virtual WAN, network segmentation, NSG ASG design, private endpoint, Private Link, DDoS protection, secure virtual network, egress control, Zero Trust network, private connectivity design, Bastion, JIT VM access. DO NOT USE for the firewall itself (use azure-firewall), VM-level hardening (use defender-for-cloud-hardening), or Key Vault networking only (use azure-key-vault).
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Azure Network Security Design

Secure Azure networking applies Zero Trust to the network pillar: segment, control traffic explicitly, prefer private connectivity, and inspect / filter egress, assuming the network is hostile. The output is a hub-spoke (or Virtual WAN) topology with NSG microsegmentation, private endpoints, and a single controlled egress path.

When to use

Designing the network topology and controls for an Azure landing zone or workload. Use this skill to pick topology, design segmentation, and place controls.

Do not use this skill for the firewall product itself (azure-firewall), VM hardening (defender-for-cloud-hardening), or single-service networking (azure-key-vault).

Pick the topology

Estate shapeTopologyNotes
Single region, few subscriptionsHub-spoke (single region)Default for most
Multi-region with many spokes / branch sitesVirtual WANMicrosoft-managed transit
Greenfield enterprise-scaleAzure Landing Zones (CAF) - VWAN or hub-spokeUse CAF blueprints
Heavy on-prem + AzureHub-spoke + ExpressRoute / VPN gatewayHub holds gateway + firewall
Small / single-workloadSingle VNet, no hubDon't over-engineer

Rule of thumb: hub-spoke for most enterprises, Virtual WAN at multi-region branch scale. The hub holds shared services (firewall, gateway, DNS, Bastion); workloads sit in spokes. Don't put workloads in the hub.

Approach

  1. Topology and address plan — Pick hub-spoke or Virtual WAN. Allocate non-overlapping RFC 1918 ranges per region / spoke; reserve gateway subnet, firewall subnet, Bastion subnet in the hub. Verify: address plan documented; no overlap with on-prem ranges; no overlap between regions.

  2. Segmentation with NSGs and ASGs — NSG at subnet level (preferred over per-NIC). Group workloads with Application Security Groups (ASGs) instead of static IP lists - ASGs survive scale events. Microsegment by tier: web / app / data. Verify: NSG flow logs enabled to a Log Analytics workspace; default-deny rule present; ASGs used instead of IP-based source/dest for VM groups.

  3. Private endpoints for PaaS — Use Private Endpoints / Private Link for sensitive PaaS (Storage, SQL, Key Vault, Cosmos DB). Traffic stays on Microsoft backbone. Disable public network access on the PaaS resource itself. Verify: publicNetworkAccess = Disabled on the resource; private endpoint resolves to a private IP via private DNS zone.

  4. Centralise egress through Azure Firewall — UDR on spokes: 0.0.0.0/0 next hop = firewall private IP. All outbound goes through the firewall for FQDN filtering and logging. Verify: effective routes on a spoke NIC show next-hop = firewall; no spoke has its own public IP egress.

  5. DDoS + WAF for public-facing — Enable Azure DDoS Network Protection on VNets with public IPs. Place public web apps behind Front Door or Application Gateway with WAF in Prevention mode. Verify: DDoS plan associated; WAF rules in Prevention (not Detection) for prod.

  6. Centralised DNS — Private DNS zones linked from the hub; spokes auto-resolve PaaS private endpoints via the zones. Don't let each spoke run its own DNS.

  7. Block management plane on the internet — No direct RDP / SSH from internet to VMs. Use Azure Bastion (in the hub) or Defender for Cloud just-in-time VM access. Verify: NSGs block 3389 / 22 from internet on all VM subnets; Bastion deployed in hub.

Show full SKILL.md (308 more words)Show less

Guardrails

  • Prefer private endpoints over service endpoints for sensitive PaaS data planes. Service endpoints leave the PaaS resource public; private endpoints make it truly private.
  • Default-deny NSGs; document every allow rule's purpose. Allow lists drift to "allow everything" without discipline. Use ASGs + comments.
  • Don't expose management ports (RDP/SSH) to the internet - use Bastion / just-in-time access. Internet-exposed 3389 / 22 = compromise within hours.
  • DNS is part of network security. Untrusted DNS resolution undermines private endpoint isolation.
  • DDoS Network Protection is per-VNet, billed monthly. Cheap insurance for public-facing VNets; don't blanket-enable on every VNet.
  • NSG flow logs to a workspace. Without them, an incident has no network forensics.

Common anti-patterns

  • "Workloads in the hub - it's just one VNet" - Hub holds shared services only. Workloads in spokes for blast radius.
  • "Service endpoints because they're cheaper than private endpoints" - Service endpoint doesn't make the PaaS private; only the routing. Private endpoint for sensitive data.
  • "NSG per NIC for every VM" - Unmanageable. Subnet NSGs + ASGs.
  • "WAF in Detection forever" - Logs attacks; doesn't block them. Move to Prevention after tuning.
  • "Each spoke has its own egress public IP" - No central inspection, no egress logging. Force through hub firewall.
  • "Bastion later - we'll RDP through the VPN for now" - VPN credential theft = lateral movement. Bastion + JIT from day one.

Example prompts

  • Design a hub-and-spoke network with segmentation and private endpoints for an Azure landing zone.
  • How do I apply Zero Trust principles to an Azure virtual network?
  • Plan NSG and ASG rules plus DDoS protection for a secure VNet.
  • Control egress traffic and private connectivity across spokes.
  • Replace internet-exposed RDP with Bastion and just-in-time VM access.
  • Should I use hub-spoke or Virtual WAN for our multi-region estate?

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/azure-network-security-design of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Azure Network Security Design next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Network Security Design compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Network Security Design this skillvinayaklatthe/microsoft-security-skills175—~1.8kAutomated safety check: PassMIT
Azure Key VaultKilo-Org/kilo-marketplace1901 repos~1.9kAutomated safety check: PassMIT
Azure Information ProtectionMicrosoftDocs/Agent-Skills776—~1.3kAutomated safety check: PassCC-BY-4.0
Implementing Cloud Security Posture Managementmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Azure Compliancemicrosoft/GitHub-Copilot-for-Azure2552 repos~997Automated safety check: PassMIT
Detecting Compromised Cloud Credentialsmukul975/Anthropic-Cybersecurity-Skills34k—~3.9kAutomated safety check: PassApache-2.0

Similar skills

  • Azure Key Vault

    Kilo-Org/kilo-marketplace

    Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation.

    190 GitHub starsUsed in 1 repo~1.9k tokens
    Backend & APIsAuto-check passed
  • Azure Information Protection

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Information Protection development including best practices, decision making, configuration, and deployment.

    776 GitHub stars~1.3k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Implementing Cloud Security Posture Management

    mukul975/Anthropic-Cybersecurity-Skills

    Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Azure Compliance

    microsoft/GitHub-Copilot-for-Azure

    Official

    Run Azure compliance and security audits with azqr plus Key Vault expiration checks.

    255 GitHub starsUsed in 2 repos~997 tokens
    SecurityAuto-check passed
  • Detecting Compromised Cloud Credentials

    mukul975/Anthropic-Cybersecurity-Skills

    Detect compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible-travel patterns, and credential-stuffing indicators using GuardDuty, Microsoft…

    34k GitHub stars~3.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Implementing Azure Defender For Cloud

    mukul975/Anthropic-Cybersecurity-Skills

    Enable Microsoft Defender for Cloud (CSPM + CWPP) across VMs, containers, SQL, storage, and Key Vault, using Azure Policy for evaluation, Log Analytics for telemetry, Azure Arc for hybrid coverage…

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Questions about Azure Network Security Design

What does Azure Network Security Design do?

Guidance for designing secure Azure network architecture — hub-spoke topology (or Virtual WAN), segmentation with NSGs/ASGs, private endpoints / Private Link for PaaS, egress through Azure Firewall…. Azure Network Security Design is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for designing secure Azure network architecture — hub-spoke topology (or Virtual WAN), segmentation with NSGs/ASGs, private endpoints / Private Link for PaaS, egress through Azure Firewall, DDoS protection, WAF on Front Door/App Gateway, and centralised private DNS.

When should I use Azure Network Security Design?

Azure Network Security Design fits situations like: the firewall itself (use azure-firewall); VM-level hardening (use defender-for-cloud-hardening); key Vault networking only (use azure-key-vault).

How do I install Azure Network Security Design in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-network-security-design -a claude-code`. Or copy the skill folder (skills/azure-network-security-design in vinayaklatthe/microsoft-security-skills) into .claude/skills/azure-network-security-design in your project. Claude Code loads it when a task matches its description.

How do I install Azure Network Security Design in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-network-security-design -a codex`. Or copy the skill folder (skills/azure-network-security-design in vinayaklatthe/microsoft-security-skills) into .agents/skills/azure-network-security-design in your project. Codex loads it when a task matches its description.

Can I use Azure Network Security Design in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-network-security-design -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-network-security-design, .gemini/skills/azure-network-security-design, .github/skills/azure-network-security-design and .opencode/skills/azure-network-security-design in your project.

What does Azure Network Security Design need to run?

SKILL.md names no scripts, command-line tools or credentials: Azure Network Security Design is instructions for the agent only.

Does Azure Network Security Design access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Azure Network Security Design safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Network Security Design use?

Azure Network Security Design is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Network Security Design use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Azure Network Security Design?

Skills that share tags, products or a category with Azure Network Security Design: Azure Key Vault (Kilo-Org/kilo-marketplace, 190 stars), Azure Information Protection (MicrosoftDocs/Agent-Skills, 776 stars), Implementing Cloud Security Posture Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Azure Compliance (microsoft/GitHub-Copilot-for-Azure, 255 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Network Security Design?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.