azure-compliance
Azure 合規掃描器
此技能協助安全團隊審計 Azure 資源的合規違規、監控 Key Vault 過期日期,並使用官方 Microsoft 工具實施修復最佳實踐。
تنزيل ZIP المهارة
رفع في Claude
اذهب إلى Settings → Capabilities → Skills → Upload skill
فعّل وابدأ الاستخدام
اختبرها
استخدام "azure-compliance". Run azqr compliance scan on my subscription
النتيجة المتوقعة:
Compliance Scan Results:
Critical (3):
- Storage accounts with public access enabled
- Key Vaults without purge protection
- SQL servers without firewall rules
High (7):
- Web apps without HTTPS
- Function apps using legacy runtime
- Load balancers without availability zones
Medium (12):
- Storage accounts with weak encryption
- VMs without managed identities
- Containers without private registries
استخدام "azure-compliance". Show expiring Key Vault items
النتيجة المتوقعة:
Key Vault Expiration Report:
Expiring in 7 days:
- Certificate: ssl-cert-prod (expires: Feb 28, 2026)
- Secret: db-password-main (expires: Mar 1, 2026)
Expiring in 30 days:
- Key: encryption-key-backup (expires: Mar 15, 2026)
- Certificate: client-auth-cert (expires: Mar 20, 2026)
التدقيق الأمني
آمنThis is an official Microsoft Azure compliance documentation skill. Static findings flagged Azure CLI commands in markdown documentation, reference URLs to Azure documentation, and mentions of deprecated protocols - all are legitimate compliance content. The skill provides remediation patterns, SDK references, and best practices for Azure compliance. No malicious intent detected.
عوامل الخطر
⚙️ الأوامر الخارجية
🌐 الوصول إلى الشبكة
درجة الجودة
ماذا يمكنك بناءه
安全團隊執行定期審計
安全團隊使用此技能在 Azure 訂用帳戶上執行排定的合規審計,識別配置錯誤和過期憑證。
DevOps 驗證資源配置
DevOps 工程師驗證新部署的資源在生產部署前符合組織的合規原則。
雲端系統管理員監控 Key Vault
雲端系統管理員監控 Key Vault,以防止過期憑證、密碼和金鑰造成的服務中斷。
جرّب هذه الموجهات
Run azqr compliance scan on my Azure subscription and summarize the findings by severity
Show me all expired and expiring (within 30 days) keys, secrets, and certificates in my Key Vault
Find all storage accounts without private endpoints and show me the remediation steps
Generate a comprehensive compliance report for my subscription including all critical and high findings with remediation recommendations
أفضل الممارسات
- 定期排程執行合規掃描(每週或每月)以追蹤一段時間內的趨勢
- 將合規報告與修復執行分開,以維護審計追蹤記錄
- 使用優先順序分類將修復工作重点放在關鍵和高風險發現上
تجنب
- 不要使用此技能來部署資源 - 它是唯讀的合規評估
- 避免在營業時間內對生產訂用帳戶執行掃描而不排程
- 不要忽略中度和低風險發現 - 它們往往會隨著時間演變成關鍵問題
الأسئلة المتكررة
什麼是 azqr?
此技能會修改我的 Azure 資源嗎?
執行掃描需要什麼權限?
我應該多久執行一次合規掃描?
我可以將此整合到 CI/CD 管線中嗎?
這與 Azure Advisor 有什麼不同?
تفاصيل المطور
المؤلف
microsoftالترخيص
MIT
المستودع
https://github.com/microsoft/github-copilot-for-azure/tree/main/plugin/skills/azure-compliance/مرجع
main
بنية الملفات
📁 sdk/
📄 azure-keyvault-certificates-rust.md
📄 azure-keyvault-secrets-rust.md
📄 azure-keyvault-secrets-ts.md
📄 azure-security-keyvault-keys-dotnet.md
📄 azure-security-keyvault-keys-java.md
📄 azure-security-keyvault-secrets-java.md
📄 azqr-remediation-patterns.md
📄 azure-keyvault-expiration-audit.md
📄 SKILL.md