From azure-agent-skills
Expert guidance for Azure Defender for Cloud development: troubleshooting, best practices, architecture, security, configuration, and deployment. Use for securing Azure VMs, containers/Kubernetes, SQL, storage, and API/CLI integrations.
How this skill is triggered — by the user, by Claude, or both
Slash command
/azure-agent-skills:azure-defender-for-cloudThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
This skill provides expert guidance for Azure Defender For Cloud. Covers troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. It combines local quick-reference content with remote documentation fetching capabilities.
This skill provides expert guidance for Azure Defender For Cloud. Covers troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. It combines local quick-reference content with remote documentation fetching capabilities.
IMPORTANT for Agent: Use the Category Index below to locate relevant sections. For categories with line ranges (e.g.,
L35-L120), useread_filewith the specified lines. For categories with file links (e.g.,[security.md](security.md)), useread_fileon the linked reference file
IMPORTANT for Agent: If
metadata.generated_atis more than 3 months old, suggest the user pull the latest version from the repository. Ifmcp_microsoftdocstools are not available, suggest the user install it: Installation Guide
This skill requires network access to fetch documentation content:
mcp_microsoftdocs:microsoft_docs_fetch with query string from=learn-agent-skill. Returns Markdown.fetch_webpage with query string from=learn-agent-skill&accept=text/markdown. Returns Markdown.| Category | Lines | Description |
|---|---|---|
| Troubleshooting | L37-L70 | Diagnosing and fixing Defender for Cloud issues: alert validation, incident triage, connector/onboarding problems (AWS/GCP/K8s/SQL/APIs), and remediation steps for specific Defender plans. |
| Best Practices | L71-L96 | Hands-on guides for investigating, prioritizing, and remediating Defender for Cloud security findings (VMs, containers, Kubernetes, APIs, SQL, secrets, networking, OS hardening, attack paths). |
| Decision Making | L97-L115 | Guidance for choosing and planning Defender for Cloud plans, costs, portals, migrations, partner integrations, and feature transitions across Azure, GCP, servers, containers, and storage. |
| Architecture & Design Patterns | L116-L124 | Architectural guidance for Defender for Servers/Containers: agentless VM malware scanning, data collection design, workspace/data residency planning, and deployment/topology patterns. |
| Limits & Quotas | L125-L134 | Limits, quotas, and constraints for Defender for Cloud: data ingestion and extensions, portal and DevOps feature limits, alert export caps, and free trial scope/prerequisites. |
| Security | L135-L214 | Security alerts, threat protection, roles/RBAC, CIEM, JIT, malware scanning, AI/API/Kubernetes/storage/SQL protections, and how to configure, interpret, and act on Defender for Cloud security features |
| Configuration | L215-L285 | Configuring Defender for Cloud features: onboarding, plans, policies, alerts, exports, vulnerability/malware scanning, DevOps and data security, containers/SQL/storage, and cross-tenant settings. |
| Integrations & Coding Patterns | L286-L321 | Integrating Defender for Cloud with tools and platforms (Power BI, SIEM, ServiceNow, CI/CD, GitHub, APIs), exporting data, and automating security scans, alerts, and SQL VA via CLI/PowerShell/REST. |
| Deployment | L322-L341 | Guides for deploying, enabling, migrating, and safely removing Defender for Cloud components (Servers, SQL, Storage, Containers), including CI/CD, policy/CLI/REST/PowerShell, and support matrices. |
| Topic | URL |
|---|---|
| Use agentless malware scanning for virtual machines | https://learn.microsoft.com/en-us/azure/defender-for-cloud/agentless-malware-scanning |
| Understand Defender for Containers security architecture | https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-architecture |
| Design a Defender for Servers deployment architecture | https://learn.microsoft.com/en-us/azure/defender-for-cloud/plan-defender-for-servers |
| Understand Defender for Servers data collection design | https://learn.microsoft.com/en-us/azure/defender-for-cloud/plan-defender-for-servers-agents |
| Plan Defender for Servers data residency and workspaces | https://learn.microsoft.com/en-us/azure/defender-for-cloud/plan-defender-for-servers-data-workspace |
| Topic | URL |
|---|---|
| Understand Defender for Servers data ingestion benefit | https://learn.microsoft.com/en-us/azure/defender-for-cloud/data-ingestion-benefit |
| Understand current limitations of Defender portal experience | https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-portal/known-limitations |
| Review support scope and prerequisites for DevOps security | https://learn.microsoft.com/en-us/azure/defender-for-cloud/devops-support |
| Export Defender for Cloud alerts to CSV with limits | https://learn.microsoft.com/en-us/azure/defender-for-cloud/export-alerts-to-csv |
| Check and understand Defender for Cloud free trial limits | https://learn.microsoft.com/en-us/azure/defender-for-cloud/free-trial |
| Understand Defender data collection extensions and retirement | https://learn.microsoft.com/en-us/azure/defender-for-cloud/monitoring-components |
npx claudepluginhub microsoftdocs/agent-skills --plugin azure-agent-skillsEnables Microsoft Defender for Cloud plans, configures auto-provisioning, and sets up security posture management across Azure workloads including VMs, containers, SQL, storage, and Key Vault.
Enables Microsoft Defender for Cloud plans, configures auto-provisioning, and sets up security posture management across Azure workloads including VMs, containers, SQL, storage, and Key Vault.
Implements Microsoft Defender for Cloud for cloud security posture management, workload protection across Azure VMs, containers, databases, storage, security recommendations, and adaptive controls with automated remediation.