What problem does it solve?
Azure security oversight is often fragmented across IAM, networking, and monitoring. This Skill provides a cohesive blueprint to audit, harden, and maintain Azure infrastructure by migrating Key Vault access policies to RBAC, enforcing Entra ID Conditional Access, configuring private endpoints, enabling Defender for Cloud, and auditing NSG rules and diagnostic settings.
Core Features & Use Cases
- Identity & Access Security (CRITICAL): migrate from access policies to RBAC, enforce Conditional Access for admin roles, disable legacy authentication, and implement least-privilege access controls.
- Network Security (HIGH): deploy private endpoints for data services, enforce deny-by-default NSG rules, enable NSG flow logs, and ensure secure DNS resolution.
- Threat Protection (HIGH): enable Defender for Cloud coverage across storage, VMs, containers, and keys, plus security contacts and alerts.
- Policy & Compliance (HIGH): apply built-in and custom Azure Policy definitions to enforce or audit security controls across resources.
- Secret Management (HIGH): implement secret rotation and managed access through Key Vault with automated expiration handling.
- Monitoring & Incident Response (MEDIUM): configure diagnostic settings, alerts, and a structured incident response runbook with investigation queries.
Quick Start
Review your Azure configuration and implement the recommended hardening steps to establish a secure baseline