Skills azure-compliance
๐Ÿ“ฆ

azure-compliance

v0.0.0-placeholder Content revision r2 Safe โš™๏ธ External commands๐Ÿ”‘ Env variables๐ŸŒ Network access๐Ÿ“ Filesystem access

Audit Azure Compliance and Key Vault Expiration

Azure teams need a consistent way to identify compliance gaps and expiring Key Vault assets. This skill runs scoped assessments and produces prioritized remediation guidance.

Supports: Claude Codex Code(CC)
๐Ÿฅ‰ 79 Bronze

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "azure-compliance" from https://skillstore.io/skills/microsoft-azure-compliance.md and its manifest at https://skillstore.io/api/skills/microsoft-azure-compliance/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "azure-compliance". Check Key Vault payments-prod for items expiring within 30 days.

Expected outcome:

  • Summary: 24 items reviewed; one secret is expired, three certificates expire within 30 days, and two keys lack expiration dates.
  • Priority: Rotate the expired secret, schedule certificate renewal, and assign expiration policies to undated keys.

Using "azure-compliance". Assess the production resource group and prioritize its compliance findings.

Expected outcome:

  • Critical: One storage account permits public network access and requires an approved private-endpoint migration.
  • High: Two virtual machines lack backup coverage, and one Key Vault lacks purge protection.
  • Next steps: Validate dependencies, assign owners, test each change, and rerun azqr after remediation.

Security Audit

Safe
v5 โ€ข 7/23/2026 Open versioned report

The skill is documentation-driven and contains no executable scripts. All 76 alerts are benign Markdown, SDK, authentication, Azure endpoint, or scoped remediation examples. No prompt injection, credential exfiltration, covert execution, or malicious intent was found.

17
Files scanned
1,445
Lines analyzed
0
Review items
0
False positives ignored

Risk Factors

โš™๏ธ External commands (25)
๐Ÿ”‘ Env variables (13)
๐ŸŒ Network access (9)
๐Ÿ“ Filesystem access (6)
No confirmed security findings were detected by the latest completed static and semantic audit. This does not prove the skill has no side effects.
Audited by: codex View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/microsoft-azure-compliance/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/microsoft-azure-compliance/security.svg)](https://skillstore.io/skills/microsoft-azure-compliance?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/microsoft-azure-compliance?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/microsoft-azure-compliance/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/microsoft-azure-compliance.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

microsoft. (2026). azure-compliance security audit report (audit version 5) [Author version 0.0.0-placeholder]. Skillstore. https://skillstore.io/skills/microsoft-azure-compliance/audits/5

BibTeX citation

@techreport{microsoft-microsoft-azure-compliance-2026, author = {microsoft}, title = {azure-compliance security audit report (audit version 5)}, institution = {Skillstore}, year = {2026}, number = {5}, url = {https://skillstore.io/skills/microsoft-azure-compliance/audits/5}, note = {Author version 0.0.0-placeholder} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "azure-compliance security audit report (audit version 5)" version: "0.0.0-placeholder" type: report authors: - name: "microsoft" date-released: "2026-07-23" url: "https://skillstore.io/skills/microsoft-azure-compliance/audits/5" identifiers: - type: other value: "skillstore:microsoft-azure-compliance:audit:5" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: High
50
Architecture
90
Maintainability
87
Content
69
Community
100
Spec Compliance

What You Can Build

Subscription compliance review

Scan a selected subscription and prioritize security, reliability, policy, cost, and operational findings.

Key Vault expiration planning

Find expired, expiring, disabled, or undated keys, secrets, and certificates before they disrupt services.

Remediation preparation

Translate azqr findings into reviewed Azure CLI or Bicep actions for an approved change window.

Try These Prompts

Quick compliance scan
Audit subscription <subscription-id> with azqr. Summarize critical and high findings, affected resources, and recommended next steps.
Key Vault expiration review
Audit Key Vault <vault-name> for expired items, items expiring within <days> days, disabled items, and missing expiration dates.
Resource group security assessment
Assess resource group <resource-group> in subscription <subscription-id>. Correlate azqr and Resource Graph findings, then rank remediation by risk and effort.
Enterprise remediation backlog
Assess management group <management-group-id>. Correlate policy, Defender, reliability, and orphaned-resource findings into a prioritized backlog without executing changes.

Best Practices

  • Confirm scope and read permissions before starting any assessment.
  • Use Reader access and least-privilege data-plane permissions for Key Vault metadata.
  • Review every remediation command and test changes in a nonproduction scope before execution.

Avoid

  • Do not scan every subscription when the user requested one resource group.
  • Do not expose secret values, tokens, or complete sensitive inventories in reports.
  • Do not execute remediation commands automatically or treat every recommendation as equally urgent.

Frequently Asked Questions

What Azure access does this skill require?
Use Reader access for configuration scans and the narrowest Key Vault data-plane permissions needed to read item metadata.
Does this skill change Azure resources?
The assessment workflow is read-oriented. Remediation references include changes, so review and approve every command separately.
Can it read Key Vault secret values?
The documented audit needs expiration and status metadata. Reports should not retrieve or display secret values.
Which Azure scopes are supported?
The references cover resource groups, subscriptions, management groups, selected services, and individual Key Vaults.
How are findings prioritized?
Findings are grouped by security, reliability, performance, cost, and operations, then ranked by impact and urgency.
Does this replace a formal compliance certification?
No. It reviews Azure configuration and best practices, but formal certification also requires control evidence, governance review, and auditor judgment.

Developer Details

Author

microsoft

License

MIT

Author version

v0.0.0-placeholder

Skillstore revision

r2

Ref

ebdfe608f5de2b66ff37ab4af12af8ac4f5e8006

Maintenance freshness

7/25/2026

Usage

10 downloads ยท 145 views

More from microsoft

View all
View all