A

azure-compliance

by @microsoftv
4.9(2,000)

帮助用户理解和满足Azure云平台上的各种行业和法规合规性要求,确保云部署符合安全标准和治理策略。

azure-policyregulatory-compliancesecurity-auditsdata-governancecloud-securityGitHub
安装方式
npx skills add microsoft/github-copilot-for-azure --skill azure-compliance
compare_arrows

Before / After 效果对比

1
使用前

确保Azure资源符合行业和企业合规标准复杂。手动检查和配置耗时,容易出现合规漏洞,面临审计风险。

使用后

智能辅助Azure合规性检查和配置,提供建议。显著降低合规风险,简化审计流程,确保云环境安全合规。

SKILL.md

azure-compliance

Azure Compliance & Security Auditing

Quick Reference

Property Details

Best for Compliance scans, security audits, Key Vault expiration checks

Primary capabilities Comprehensive Resources Assessment, Key Vault Expiration Monitoring

MCP tools azqr, subscription and resource group listing, Key Vault item inspection

When to Use This Skill

  • Run azqr or Azure Quick Review for compliance assessment

  • Validate Azure resource configuration against best practices

  • Identify orphaned or misconfigured resources

  • Audit Key Vault keys, secrets, and certificates for expiration

Skill Activation Triggers

Activate this skill when user wants to:

  • Check Azure compliance or best practices

  • Assess Azure resources for configuration issues

  • Run azqr or Azure Quick Review

  • Identify orphaned or misconfigured resources

  • Review Azure security posture

  • "Show me expired certificates/keys/secrets in my Key Vault"

  • "Check what's expiring in the next 30 days"

  • "Audit my Key Vault for compliance"

  • "Find secrets without expiration dates"

  • "Check certificate expiration dates"

Prerequisites

  • Authentication: user is logged in to Azure via az login

  • Permissions to read resource configuration and Key Vault metadata

Assessments

Assessment Reference

Comprehensive Compliance (azqr) references/azure-quick-review.md

Key Vault Expiration references/azure-keyvault-expiration-audit.md

Resource Graph Queries references/azure-resource-graph.md

MCP Tools

Tool Purpose

mcp_azure_mcp_extension_azqr Run azqr compliance scans

mcp_azure_mcp_subscription_list List available subscriptions

mcp_azure_mcp_group_list List resource groups

keyvault_key_list List all keys in vault

keyvault_key_get Get key details including expiration

keyvault_secret_list List all secrets in vault

keyvault_secret_get Get secret details including expiration

keyvault_certificate_list List all certificates in vault

keyvault_certificate_get Get certificate details including expiration

Assessment Workflow

  • Select scope (subscription or resource group) for Comprehensive Resources Assessment.

  • Run azqr and capture output artifacts.

  • Analyze Scan Results and summarize findings and recommendations.

  • Review Key Vault Expiration Monitoring output for keys, secrets, and certificates.

  • Classify issues and propose remediation or fix steps for each finding.

Priority Classification

Priority Guidance

Critical Immediate remediation required for high-impact exposure

High Resolve within days to reduce risk

Medium Plan a resolution in the next sprint

Low Track and fix during regular maintenance

Error Handling

Error Message Remediation

Authentication required "Please login" Run az login and retry

Access denied "Forbidden" Confirm permissions and fix role assignments

Missing resource "Not found" Verify subscription and resource group selection

Best Practices

  • Run compliance scans on a regular schedule (weekly or monthly)

  • Track findings over time and verify remediation effectiveness

  • Separate compliance reporting from remediation execution

  • Keep Key Vault expiration policies documented and enforced

SDK Quick References

For programmatic Key Vault access, see the condensed SDK guides:

Weekly Installs103.0KRepositorymicrosoft/githu…or-azureGitHub Stars157First SeenFeb 8, 2026Security AuditsGen Agent Trust HubPassSocketPassSnykPassInstalled ongithub-copilot102.9Kcodex374gemini-cli363opencode337cursor327kimi-cli326

用户评价 (0)

发表评价

效果
易用性
文档
兼容性

暂无评价

统计数据

安装量293.2K
评分4.9 / 5.0
版本
更新日期2026年5月23日
对比案例1 组

用户评分

4.9(2,000)
5
41%
4
47%
3
12%
2
1%
1
0%

为此 Skill 评分

0.0

兼容平台

🔧Claude Code
🔧OpenClaw
🔧OpenCode
🔧Codex
🔧Gemini CLI
🔧GitHub Copilot
🔧Amp
🔧Kimi CLI

时间线

创建2026年3月17日
最后更新2026年5月23日