Agent skill

Security Architecture

by vinayaklatthe in vinayaklatthe/microsoft-security-skills

Guidance for designing security architecture using Zero Trust, the Microsoft Cybersecurity Reference Architectures (MCRA), Cloud Adoption Framework Secure methodology, and Well-Architected Security…

MITAuto-check passedSecurity

Install Security Architecture

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill security-architecture -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills security-architecture --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-architecture .claude/skills/security-architecture && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-architecture
GitHub stars
175
Token cost
~2k tokens
SKILL.md length
909 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for designing security architecture using Zero Trust, the Microsoft Cybersecurity Reference Architectures (MCRA), Cloud Adoption Framework Secure methodology, and Well-Architected Security…

  • Works in 7 steps: Anchor on Zero Trust principles first -… → Map the six Zero Trust pillars -… → Validate identity is the primary control… → …
  • Tactical product configuration (use the product-specific skill)
  • SKILL.md covers When to use, Pick the right framework for…, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Security Architecture is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for designing security architecture using Zero Trust, the Microsoft Cybersecurity Reference Architectures (MCRA), Cloud Adoption Framework Secure methodology, and Well-Architected Security pillar. Covers the six Zero Trust pillars, defense-in-depth, and reference architecture alignment. WHEN: security architecture, Zero Trust design, MCRA, defense in depth, security reference architecture, CAF secure methodology, Well-Architected security pillar, end-to-end security design, security strategy, target…

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Cloud architecture and Secure coding. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • Tactical product configuration (use the product-specific skill)
  • For SOC tooling design (use sentinel / unified-secops-platform)

Example prompts

  • “/security-architecture”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Anchor on Zero Trust principles first - Verify explicitly, *use least-privilege
  2. Map the six Zero Trust pillars - **identity, endpoints, data, apps, infrastructure,
  3. Validate identity is the primary control plane - if identity is weak, no other pillar
  4. Anchor capabilities to MCRA - Use the Microsoft Cybersecurity Reference Architectures to
  5. Build defense in depth - layer preventive, detective, and responsive controls so no
  6. Sequence the roadmap by risk and dependency - Current state → target state per pillar,
  7. Build monitoring and response in, not on - the SIEM/XDR architecture is part of the

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Architecture loads about 2k tokens when it runs. Until then it costs about 172 tokens; SKILL.md has 909 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~172
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 909 words, ~1,953 tokens.

Download SKILL.mdSave it as .claude/skills/security-architecture/SKILL.md (or your agent's skills folder).
name
security-architecture
description
Guidance for designing security architecture using Zero Trust, the Microsoft Cybersecurity Reference Architectures (MCRA), Cloud Adoption Framework Secure methodology, and Well-Architected Security pillar. Covers the six Zero Trust pillars, defense-in-depth, and reference architecture alignment. WHEN: security architecture, Zero Trust design, MCRA, defense in depth, security reference architecture, CAF secure methodology, Well-Architected security pillar, end-to-end security design, security strategy, target state. DO NOT USE for tactical product configuration (use the product-specific skill) or for SOC tooling design (use sentinel / unified-secops-platform).
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Security Architecture (Zero Trust & MCRA)

Security architecture defines how identity, endpoints, data, apps, infrastructure, and network controls combine to protect an organisation - anchored to Zero Trust and the Microsoft Cybersecurity Reference Architectures (MCRA), with delivery scaffolding from the Cloud Adoption Framework Secure methodology and workload-level rigour from the Well-Architected Framework Security pillar.

When to use

Designing an end-to-end security target state, aligning a multi-year roadmap to a recognised framework, or reviewing an architecture for gaps before a major programme of work.

Do not use this skill for:

  • Tactical product configuration (use the product-specific skill, e.g. defender-xdr, sentinel)
  • SOC tooling architecture only (use unified-secops-platform)
  • Single-workload code review (use threat-modelling)

Pick the right framework for the conversation

Question being askedUse this frameworkOutput
What is our 3-year security target state?MCRA + CAF SecureCapability map + roadmap
What capabilities cover identity / endpoints / data / apps / infra / network?Zero Trust six pillarsPillar maturity heatmap
How do we deliver the programme (strategy → operate)?CAF Secure methodologyWorkstream plan
Is this single workload designed securely?Well-Architected Security pillarWorkload review
What threats apply to a specific design?STRIDE / SDL (use threat-modelling)Threat model
Are we meeting a regulatory baseline?Microsoft Cloud Security BenchmarkCompliance evidence

Rule of thumb: Zero Trust is the principles layer. MCRA is the capability layer. CAF Secure is the delivery layer. Well-Architected is the workload layer. A real architecture uses all four - do not try to substitute one for another.

Approach

  1. Anchor on Zero Trust principles first - Verify explicitly, use least-privilege access, assume breach. Every later decision must trace back to one of these. Verify: every control in your design can be tagged to one of the three principles. If it cannot, ask why it exists.
  2. Map the six Zero Trust pillars - identity, endpoints, data, apps, infrastructure, network, with visibility/analytics and automation across all. Score current maturity per pillar (Traditional / Advanced / Optimal) so investment lands where the gap is widest. Verify: pillar heatmap shows clear deltas; you can name the top two pillars to invest in.
  3. Validate identity is the primary control plane - if identity is weak, no other pillar compensates. Confirm MFA coverage, privileged access design (PIM, PAW), and Conditional Access posture before investing heavily in network, data, or endpoint pillars. Verify: % of human accounts behind phishing-resistant MFA and % of privileged accounts in PIM are baselined and on a roadmap.
  4. Anchor capabilities to MCRA - Use the Microsoft Cybersecurity Reference Architectures to map Microsoft products (Defender, Sentinel, Entra, Purview, Intune, Defender for Cloud) to the functions they cover and to validate no capability is missing or duplicated. Verify: MCRA poster overlaid with your current/planned products shows zero unaddressed functions in your scope.
  5. Build defense in depth - layer preventive, detective, and responsive controls so no single control failure equals a breach. For each asset class, name at least one preventive and one detective control. Verify: removing any one control still leaves a detection or compensating control in place.
  6. Sequence the roadmap by risk and dependency - Current state → target state per pillar, ordered so prerequisites land first (e.g. identity hygiene before data classification, log ingestion before XDR, posture management before automation). Verify: roadmap shows ordered milestones with named owners and risks; not a flat backlog.
  7. Build monitoring and response in, not on - the SIEM/XDR architecture is part of the design, not a follow-up project. Confirm log sources, retention, and response handoffs. Verify: every pillar produces signals into a documented detection pipeline.
Show full SKILL.md (334 more words)Show less

Guardrails

  • Architecture must be driven by business risk and data sensitivity - not product inventory, vendor pressure, or "what we already own". Start from the threat and the asset, then pick the control.
  • Identity is non-negotiable. No Zero Trust architecture works if MFA, privileged access, and Conditional Access are weak. Fix this pillar first.
  • Visibility and automation are cross-cutting - they are not a seventh pillar but a prerequisite for all six. Design log ingestion and orchestration up front.
  • Defense in depth, not defence in expense - layered controls only count if each layer detects/blocks a different class of failure. Two SIEMs are not defence in depth.
  • A roadmap without owners is a wish list. Every milestone needs a named owner and a measurable exit criterion.
  • Re-baseline annually. MCRA, CAF Secure, and the Zero Trust pillars all evolve - last year's reference architecture is not this year's.

Common anti-patterns

  • "We bought Defender / Sentinel so we are Zero Trust." Products do not equal architecture. Without the principles, pillars, and operating model, you have shelfware.
  • Investing in network or data pillars while identity remains weak. Adversaries pivot through the weakest pillar; identity is almost always it.
  • Treating the SIEM as an afterthought. Detection retrofitted to an existing design has blind spots that are expensive to close later.
  • A 60-page architecture document with no roadmap. Architecture without sequencing is not actionable. Pair every target state with the next 90 days of work.
  • Using Well-Architected as the org-wide framework. WAF is workload-level; use CAF Secure for the programme view.

Example prompts

  • Design a Zero Trust security architecture aligned to MCRA.
  • Apply the Cloud Adoption Framework secure methodology to our 3-year roadmap.
  • How do I build defence in depth across identity, network, and data?
  • Review my workload design against the Well-Architected security pillar.
  • Score our current state across the six Zero Trust pillars.

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/security-architecture of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Security Architecture next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Architecture compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Architecture this skillvinayaklatthe/microsoft-security-skills175—~2kAutomated safety check: PassMIT
Hadolint Dockerfile Security LintingAgentSecOps/SecOpsAgentKit2201 repos~4.4kAutomated safety check: PassCustom licence
Implementing Cloud Security Posture Managementmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Google Cloud Waf Securitygoogle/skills21k1 repos~4.2kAutomated safety check: PassApache-2.0
Configuring Firewallsancoleman/ai-design-components525—~3.5kAutomated safety check: NotesMIT
Oraclecloud Prod Checklistjeremylongshore/tons-of-skills-marketplace2.8k—~2.6kAutomated safety check: PassMIT

Similar skills

  • Hadolint Dockerfile Security Linting

    AgentSecOps/SecOpsAgentKit

    Lints Dockerfiles with Hadolint for security misconfigurations and best-practice violations, locally and in CI, with strict, balanced and permissive rule templates.

    220 GitHub starsUsed in 1 repo~4.4k tokens
    SecurityAuto-check passed
  • Implementing Cloud Security Posture Management

    mukul975/Anthropic-Cybersecurity-Skills

    Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Official

    Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected Framework (WAF).

    21k GitHub starsUsed in 1 repo~4.2k tokens
    SecurityAuto-check passed
  • Configuring Firewalls

    ancoleman/ai-design-components

    Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts.

    525 GitHub stars~3.5k tokensUpdated 10 mo ago
    SecurityAuto-check: notes
  • Oraclecloud Prod Checklist

    jeremylongshore/tons-of-skills-marketplace

    Pre-production readiness checklist for OCI — backup policies, security audit, key rotation, encryption, and Cloud Guard.

    2.8k GitHub stars~2.6k tokensUpdated today
    SecurityAuto-check passed
  • Vercel Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Apply Vercel security best practices for secrets, headers, and access control.

    2.8k GitHub stars~1.9k tokensUpdated today
    SecurityAuto-check: notes

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Questions about Security Architecture

What does Security Architecture do?

Guidance for designing security architecture using Zero Trust, the Microsoft Cybersecurity Reference Architectures (MCRA), Cloud Adoption Framework Secure methodology, and Well-Architected Security…. Security Architecture is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for designing security architecture using Zero Trust, the Microsoft Cybersecurity Reference Architectures (MCRA), Cloud Adoption Framework Secure methodology, and Well-Architected Security pillar.

When should I use Security Architecture?

Security Architecture fits situations like: tactical product configuration (use the product-specific skill); for SOC tooling design (use sentinel / unified-secops-platform).

How do I install Security Architecture in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill security-architecture -a claude-code`. Or copy the skill folder (skills/security-architecture in vinayaklatthe/microsoft-security-skills) into .claude/skills/security-architecture in your project. Claude Code loads it when a task matches its description.

How do I install Security Architecture in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill security-architecture -a codex`. Or copy the skill folder (skills/security-architecture in vinayaklatthe/microsoft-security-skills) into .agents/skills/security-architecture in your project. Codex loads it when a task matches its description.

Can I use Security Architecture in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill security-architecture -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-architecture, .gemini/skills/security-architecture, .github/skills/security-architecture and .opencode/skills/security-architecture in your project.

What does Security Architecture need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Architecture is instructions for the agent only.

Does Security Architecture access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Security Architecture safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Architecture use?

Security Architecture is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Architecture use?

About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Architecture?

Skills that share tags, products or a category with Security Architecture: Hadolint Dockerfile Security Linting (AgentSecOps/SecOpsAgentKit, 220 stars), Implementing Cloud Security Posture Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Google Cloud Waf Security (google/skills, 21k stars) and Configuring Firewalls (ancoleman/ai-design-components, 525 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Architecture?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.