Automation & Ops ✓ Microsoft · Official azurecompliance-auditsecurity-auditkey-vaultazqrresource-graph

Azure Compliance Auditor

Audit Azure resources with azqr and detect expiration risks across Key Vault keys, secrets, and certificates.

FollowSkills review · FSRS-2.0
Not recommended
50/ 100 5-point scale 2.5 / 5
Trust14 / 25 · 2.8/5

The documentation requires existing Azure authentication and read permissions, and promotes managed identities, RBAC, and avoiding hardcoded credentials, providing partial least-privilege and sensitive-data guidance. Points are deducted because execution confirmation, data-flow disclosure, output redaction, and rollback are not specified; secret_get may expose secret values, and remediation commands modify resources.

Reliability8 / 20 · 2.0/5

The main workflow, tool inventory, and authentication/permission error guidance are broadly consistent and provide actionable failure feedback. Points are deducted because no key-path reproduction is included, MCP availability is unverified, some scope and tool behavior depend on external conditions, and abnormal-input and report-failure handling are limited.

Adaptability10 / 15 · 3.3/5

Activation triggers and the Azure compliance and Key Vault expiration scenarios are clear, with subscription, resource-group, and multi-vault scopes described. Points are deducted for weak non-fit boundaries and input constraints, no explicit Chinese-language support, and no evidence regarding reachability from mainland-China networks.

Convention8 / 15 · 2.7/5

The skill is readable and layered, with prerequisites, workflow, error handling, priorities, references, MIT licensing, and a version number. Points are deducted for lacking a changelog, explicit maintenance owner, or update path; several referenced SDK files are absent from the supplied material, and the example report is Markdown rather than a strictly machine-readable format.

Effectiveness6 / 15 · 2.0/5

The documentation covers azqr scans, Key Vault expiration analysis, result classification, and multiple CLI/Bicep remediation templates, so the core audit value is plausible. Points are deducted because this is a static review with no execution evidence; tool results, Excel parsing, and report completeness are unverified, and remediation examples require human review and environment-specific adaptation.

Verifiability4 / 10 · 2.0/5

The materials include linked source references for Azure authentication, azqr, Resource Graph, and CLI usage, and the repository shows general CI/test materials. Points are deducted because there are no skill-specific tests, pinned input/output fixtures, or third-party execution results, so key paths cannot be independently reproduced from the supplied evidence.

Evidence confidence:Low Reviewed Jul 20, 2026 Reviewed revision 9ccaf7c3704a
Before you use it
  • Confirm each target subscription, resource, and change impact before running remediation commands, and establish a recoverable backup or rollback plan.
  • Avoid Key Vault operations that return secret values; redact audit reports and restrict their access.
  • Verify MCP tool names, parameters, azqr output format, and CLI/Bicep examples against the current Azure environment.
  • The supplied materials do not establish Chinese-language support or mainland-China network reachability.
See the full review method →

What it does & when to use it

azure-compliance is Microsoft’s Agent Skill for Azure compliance and security auditing. It runs Azure Quick Review (azqr), reviews resource configuration and security posture, and checks expiration metadata for Key Vault items. It is suited to teams that need recurring compliance reviews, configuration checks, or expiration monitoring. Azure CLI authentication and read access to resource configuration and Key Vault metadata are required.

Selects a subscription or resource group as the audit scope; runs azqr and captures its output artifacts; lists subscriptions and resource groups; lists Key Vault keys, secrets, and certificates; retrieves item details and expiration dates; identifies expired, soon-to-expire, or undated items; summarizes findings, assigns Critical-to-Low priorities, and proposes remediation steps.

  1. An Azure administrator wants a best-practice review before deploying or changing a resource group.
  2. A security team runs recurring scans to identify orphaned or misconfigured Azure resources.
  3. A Key Vault owner needs to find expired items or items expiring within the next 30 days.
  4. A platform team wants to review Azure security posture and track remediation over time.
  5. A compliance team needs audit findings grouped by Critical, High, Medium, and Low priority.

Pros & cons

Pros
  • Combines Azure resource compliance assessment with Key Vault expiration monitoring.
  • Defines a concrete workflow around azqr, subscription, resource-group, and Key Vault MCP tools.
  • Includes priority classification, error handling, and recurring-scan guidance.
  • Provides condensed Key Vault SDK references for Python, TypeScript, Rust, Java, and .NET.
Limitations
  • Requires Azure authentication, read permissions, azqr, and Azure MCP tools.
  • The source does not specify the azqr version, output format, or standalone test coverage for this skill.
  • It describes assessment and recommendations, not automatic remediation.
  • The documented Key Vault scope is metadata and expiration inspection; secret-value retrieval is not described.

How to install

Use the repository’s documented installation flow: run npx skills add microsoft/skills and select the required skill in the wizard. The repository also documents Copilot CLI plugin installation with /plugin marketplace add microsoft/skills, followed by /plugin install azure-skills@skills. The source does not document a standalone azure-compliance installation command.

How to use

Run az login first and confirm that the identity can read Azure resource configuration and Key Vault metadata. Then use a focused request such as Run an Azure compliance scan for this resource group, Show me expired certificates, keys, and secrets in my Key Vault, or Check what's expiring in the next 30 days. The skill selects the scope, runs azqr, and performs Key Vault checks when requested.

FAQ

What Azure access is required?
You must authenticate with `az login` and have permission to read resource configuration and Key Vault metadata.
Does the skill automatically fix findings?
The source describes scanning, analysis, prioritization, and remediation proposals, but does not document automatic fixes.
Which Key Vault objects can it inspect?
It can list and inspect keys, secrets, and certificates, including their expiration information.

More skills from this repository

All from microsoft/agent-skills

Dev & Engineering ✓ Microsoft · Official

Azure Identity for Python

A practical skill for securing Python Azure applications with Microsoft Entra ID credentials.

Dev & Engineering ✓ Microsoft · Official

Azure Event Hubs Java Skill

Build production-oriented Java event streaming applications on Azure Event Hubs.

Dev & Engineering ✓ Microsoft · Official

Azure Tables for Python

A practical guide to building authenticated Azure Tables applications with Python entity CRUD, queries, and partition-scoped batch operations.

Dev & Engineering ✓ Microsoft · Official

Azure Identity for TypeScript

Configure secure, flexible Microsoft Entra ID authentication for TypeScript Azure applications.

Automation & Ops ✓ Microsoft · Official

Azure Reliability Advisor

Assess and improve reliability for Azure Functions and App Service.

Dev & Engineering ✓ Microsoft · Official

Azure Cloud Architect

Guides coding agents through production-grade Azure architecture design and review using Azure Architecture Center practices.

Dev & Engineering ✓ Microsoft · Official

Azure AI Text Analytics for Python

Guides Python developers through Azure-powered text analysis and NLP workflows.

Automation & Ops ✓ Microsoft · Official

Azure Resource Architecture Visualizer

Analyze Azure resource groups and turn their dependencies into detailed Mermaid architecture diagrams.

Dev & Engineering ✓ Microsoft · Official

Azure Maps for .NET

Build .NET location features for search, routing, maps, geolocation, and weather.

Dev & Engineering ✓ Microsoft · Official

Azure AI Vision Image Analysis

Guides Python coding agents in implementing Azure AI Vision image understanding.

Dev & Engineering ✓ Microsoft · Official

Azure Blob Storage for Python

Guides secure, production-minded Blob Storage operations in Python.

Dev & Engineering ✓ Microsoft · Official

Azure Queue Storage for Python

Gives coding agents reliable Python patterns for secure Azure Queue Storage messaging and asynchronous task processing.

Automation & Ops ✓ Microsoft · Official

Azure AI Gateway Governance

Use Azure API Management to govern traffic across AI models, MCP tools, and agents.

Automation & Ops ✓ Microsoft · Official

AKS Automatic Readiness

Assess Kubernetes workloads for AKS Automatic compatibility and identify migration blockers before you switch.

Dev & Engineering ✓ Microsoft · Official

Azure Cosmos DB ARM for .NET

Provision and manage Azure Cosmos DB resources from .NET through ARM.

Dev & Engineering ✓ Microsoft · Official

Azure Playwright Workspace Manager

Provision and manage Microsoft Playwright Testing workspaces with .NET and Azure Resource Manager.

Dev & Engineering ✓ Microsoft · Official

Azure Cosmos DB for Python

A practical guide for building reliable Python applications on Azure Cosmos DB’s NoSQL API.

Dev & Engineering ✓ Microsoft · Official

Azure Key Vault SDK for Python

Gives Python coding agents practical guidance for securely managing Azure Key Vault secrets, keys, and certificates.

Dev & Engineering ✓ Microsoft · Official

Azure API Management for Python

Gives coding agents practical Python SDK patterns for managing Azure API Management services, APIs, products, subscriptions, and policies.

Dev & Engineering ✓ Microsoft · Official

Azure Monitor Query for Python

Generate Python code for querying Azure Monitor logs and metrics.

Related skills