Skills azure-postgres
๐Ÿ“ฆ

azure-postgres

Content revision r1 High Risk ๐Ÿ“ Filesystem accessโš™๏ธ External commands๐Ÿ”‘ Env variables๐ŸŒ Network access

Configure Azure PostgreSQL Passwordless Access

Teams need secure PostgreSQL access without shared passwords. This skill guides Entra ID setup, managed identities, group permissions, and migrations for Azure PostgreSQL.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "azure-postgres" from https://skillstore.io/skills/microsoft-azure-postgres.md and its manifest at https://skillstore.io/api/skills/microsoft-azure-postgres/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "azure-postgres". Help me add a developer with read-only access.

Expected outcome:

  • Confirms the server, database, and Entra admin prerequisites.
  • Identifies the developer principal and creates the mapped PostgreSQL role.
  • Applies connect, schema usage, and table read permissions.
  • Gives a validation checklist for token-based connection testing.

Using "azure-postgres". Set up managed identity access for my web app.

Expected outcome:

  • Looks up the managed identity object and client identifiers.
  • Creates or reuses a PostgreSQL role for the service identity.
  • Grants only the requested database permission level.
  • Summarizes the connection settings the application needs.

Using "azure-postgres". Troubleshoot password authentication failed errors.

Expected outcome:

  • Checks token freshness, username format, and mapped role existence.
  • Separates database permission problems from network or firewall failures.
  • Recommends follow-up checks for Entra admin and group sync state.

Security Audit

High Risk
v4 โ€ข 7/5/2026 Open versioned report

Most static findings are false positives caused by Markdown links, portal URL examples, code fences, and legitimate Azure CLI guidance. The skill includes shell scripts that run administrative Azure and PostgreSQL actions; the main confirmed issue is unsafe SQL construction from caller-provided names. No prompt-injection text or hidden exfiltration intent was found.

15
Files scanned
1,983
Lines analyzed
0
Review items
0
False positives ignored

Confirmed security concerns (1)

High
Unsafe SQL Construction in Administration Scripts
The helper scripts insert command-line values such as users, groups, identities, and database names directly into SQL statements. A malicious or malformed value could change SQL executed by an Entra administrator.
The cited lines concatenate or interpolate script parameters and Azure-derived names into SQL strings. These scripts run as an administrative database user, so SQL injection or identifier confusion has high impact.

Risk Factors

๐Ÿ“ Filesystem access (12)
โš™๏ธ External commands (69)
references/group-sync.md:27 references/group-sync.md:30 references/group-sync.md:50 references/group-sync.md:95 references/group-sync.md:98 references/group-sync.md:121 references/group-sync.md:54 references/group-sync.md:55 references/group-sync.md:125 references/group-sync.md:126 references/troubleshooting.md:28 references/troubleshooting.md:52 references/troubleshooting.md:54 scripts/az-commands.sh:16 scripts/az-commands.sh:48 scripts/az-commands.sh:1 scripts/migrate-to-entra.sh:21-24 scripts/migrate-to-entra.sh:35-38 scripts/migrate-to-entra.sh:46 scripts/migrate-to-entra.sh:49 scripts/migrate-to-entra.sh:98 scripts/migrate-to-entra.sh:114 scripts/migrate-to-entra.sh:1 scripts/setup-group.sh:28-31 scripts/setup-group.sh:42 scripts/setup-group.sh:49 scripts/setup-group.sh:50 scripts/setup-group.sh:63-66 scripts/setup-group.sh:77 scripts/setup-group.sh:83 scripts/setup-group.sh:112-113 scripts/setup-group.sh:137 scripts/setup-group.sh:182 scripts/setup-group.sh:189 scripts/setup-group.sh:1 scripts/setup-managed-identity.sh:26-29 scripts/setup-managed-identity.sh:40-43 scripts/setup-managed-identity.sh:45 scripts/setup-managed-identity.sh:46 scripts/setup-managed-identity.sh:59-62 scripts/setup-managed-identity.sh:73 scripts/setup-managed-identity.sh:79 scripts/setup-managed-identity.sh:92-93 scripts/setup-managed-identity.sh:97-98 scripts/setup-managed-identity.sh:1 scripts/setup-user.sh:25-28 scripts/setup-user.sh:39-42 scripts/setup-user.sh:59 scripts/setup-user.sh:65 scripts/setup-user.sh:78-79 scripts/setup-user.sh:132 scripts/setup-user.sh:1 SKILL.md:22 SKILL.md:23 SKILL.md:24 SKILL.md:25 SKILL.md:26 SKILL.md:30-35 SKILL.md:35-43 SKILL.md:43-44 SKILL.md:44-55 SKILL.md:55-57 SKILL.md:57-60 SKILL.md:60-63 SKILL.md:63-107 SKILL.md:107 SKILL.md:108 SKILL.md:109 SKILL.md:110-111
๐Ÿ”‘ Env variables (3)
๐ŸŒ Network access (2)
Audited by: codex View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/microsoft-azure-postgres/audits/4?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/microsoft-azure-postgres/security.svg)](https://skillstore.io/skills/microsoft-azure-postgres?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/microsoft-azure-postgres?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/microsoft-azure-postgres/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/microsoft-azure-postgres.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

microsoft. (2026). azure-postgres security audit report (audit version 4) [Author version unspecified]. Skillstore. https://skillstore.io/skills/microsoft-azure-postgres/audits/4

BibTeX citation

@techreport{microsoft-microsoft-azure-postgres-2026, author = {microsoft}, title = {azure-postgres security audit report (audit version 4)}, institution = {Skillstore}, year = {2026}, number = {4}, url = {https://skillstore.io/skills/microsoft-azure-postgres/audits/4}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "azure-postgres security audit report (audit version 4)" version: "unspecified" type: report authors: - name: "microsoft" date-released: "2026-07-05" url: "https://skillstore.io/skills/microsoft-azure-postgres/audits/4" identifiers: - type: other value: "skillstore:microsoft-azure-postgres:audit:4" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
73
Architecture
85
Maintainability
87
Content
70
Community
83
Spec Compliance

What You Can Build

Add Developer Database Access

Grant a developer read-only, read-write, or admin access through an Entra ID user account.

Connect Applications Without Secrets

Map a managed identity to a PostgreSQL role so an Azure app can connect without stored passwords.

Move Teams to Group-Based Access

Use Entra groups to manage PostgreSQL permissions and choose the right group sync mode.

Try These Prompts

Check Server Readiness
Help me check whether my Azure PostgreSQL Flexible Server is ready for Microsoft Entra ID authentication.
Grant User Access
Guide me through granting {user_upn} {permission_level} access to database {database_name} on server {server_name}.
Configure Managed Identity
Plan managed identity access for app identity {identity_name} to Azure PostgreSQL database {database_name} with least privilege.
Plan Password Migration
Create a staged migration plan from password authentication to Entra-only authentication for Azure PostgreSQL server {server_name}.

Best Practices

  • Test changes in a non-production database before changing production authentication mode.
  • Grant the smallest permission level needed for each user, group, or managed identity.
  • Review generated SQL and Azure commands before running scripts with administrator privileges.

Avoid

  • Do not pass untrusted names or database identifiers directly into the included scripts.
  • Do not grant azure_pg_admin to application identities without a documented requirement.
  • Do not disable password authentication until every migrated role has been tested with Entra ID.

Frequently Asked Questions

What does this skill configure?
It configures Microsoft Entra ID authentication and database permissions for Azure PostgreSQL Flexible Server.
Does it create PostgreSQL servers?
It includes a basic create command reference, but its main focus is authentication and access configuration.
Can it support managed identities?
Yes. It includes a managed identity workflow that maps the identity to a PostgreSQL role.
Can it manage team access?
Yes. It documents Entra group roles, group sync modes, and group permission grants.
What tools must be installed for scripts?
The scripts expect Azure CLI, jq, psql, Bash, and an authenticated Azure session.
Is it safe to run scripts automatically?
No. Review all parameters and SQL before running scripts because they can change database permissions.

Developer Details

Author

microsoft

License

MIT

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

6425ec35f4ac137735cff58cd7877843bba23e3b

Maintenance freshness

7/18/2026

Usage

11 downloads ยท 175 views

File structure