Azure Defender For Cloud Skill
SkillDatabases & dataExpert knowledge for Azure Defender For Cloud development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when securing VMs, containers/AKS, SQL/storage, multicloud connectors, or exporting data via APIs/CLI/ARG, and other Azure Defender For Cloud related development tasks. Not for Azure Security (use azure-security), Azure Sentinel (use azure-sentinel), Azure External Attack Surface Management (use azure-external-attack-surface-management), Azure DDoS Protection (use azure-ddos-protection).
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Azure Defender For Cloud Skill skill
What this skill tells your AI
The instructions your AI receives, as published by microsoftdocs/agent-skills in skills/azure-defender-for-cloud/SKILL.md and read by ahel’s review.
This skill provides expert guidance for Azure Defender For Cloud. Covers troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. It combines local quick-reference content with remote documentation fetching capabilities.
How to Use This Skill
IMPORTANT for Agent: Use the Category Index below to locate relevant sections. For categories with line ranges (e.g.,
L35-L120), useread_filewith the specified lines. For categories with file links (e.g.,[security.md](security.md)), useread_fileon the linked reference file
IMPORTANT for Agent: If
metadata.generated_atis more than 3 months old, suggest the user pull the latest version from the repository. Ifmcp_microsoftdocstools are not available, suggest the user install it: Installation Guide
This skill requires network access to fetch documentation content:
- Preferred: Use
mcp_microsoftdocs:microsoft_docs_fetchwith query stringfrom=learn-agent-skill. Returns Markdown. - Fallback: Use
fetch_webpagewith query stringfrom=learn-agent-skill&accept=text/markdown. Returns Markdown.
Category Index
| Category | Lines | Description |
|---|---|---|
| Troubleshooting | L37-L86 | Diagnosing, interpreting, and responding to Defender for Cloud alerts and deployment issues across VMs, containers, SQL, storage, APIs, DNS, and multi-cloud connectors. |
| Best Practices | L87-L105 | Best-practice guides for configuring, investigating, and remediating Defender for Cloud alerts, vulnerabilities, misconfigurations, and EDR gaps across VMs, SQL, Kubernetes, containers, and storage. |
| Decision Making | L106-L131 | Planning and cost/feature decisions for Defender for Cloud: choosing plans and portals, multicloud support, migrations (Storage, Servers, agents), secure score, CSPM, and spend optimization. |
| Architecture & Design Patterns | L132-L141 | Multicloud security architecture for Defender for Cloud: connector auth for AWS/GCP, secure/private connectivity, container protection design, ownership models, and applying Zero Trust. |
| Limits & Quotas | L142-L151 | Limits, quotas, and constraints for Defender for Cloud: data ingestion benefits, free trial caps, portal limitations, CSV export limits, data collection extension lifecycles, and storage malware scan capacity. |
| Security | L152-L210 | Configuring and managing Defender for Cloud security: roles/RBAC, compliance, recommendations, alerts, incident response, storage/VM/container/AKS protections, and secure integrations across clouds. |
| Configuration | L211-L279 | Configuring Defender for Cloud features: agentless and container scanning, storage/SQL protection, alerts/export, DevOps/IaC integration, cross-cloud coverage, and automation settings. |
| Integrations & Coding Patterns | L280-L315 | Integrating Defender for Cloud with SIEMs, XDR, ServiceNow, CI/CD, multi‑cloud logs, partner tools, and using APIs/CLI/ARG to export, query, and automate alerts and SQL VA data. |
| Deployment | L316-L339 | Guides for planning and deploying Defender for Cloud components (Servers, Containers, SQL, APIs, DevOps, GHAS) at scale, including prerequisites, platform support, and automation options. |
Troubleshooting
Best Practices
Decision Making
Architecture & Design Patterns
| Topic | URL |
|---|---|
| Understand GCP connector authentication architecture in Defender for Cloud | https://learn.microsoft.com/en-us/azure/defender-for-cloud/authentication-architecture-google-cloud |
| Understand AWS connector authentication architecture in Defender for Cloud | https://learn.microsoft.com/en-us/azure/defender-for-cloud/concept-authentication-architecture-aws |
| Design secure connectivity with Microsoft Security Private Link for Defender for Cloud | https://learn.microsoft.com/en-us/azure/defender-for-cloud/concept-private-links |
| Review Defender for Containers security architecture and connectivity | https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-architecture |
| Understand Defender for Containers deployment architecture options | https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-deployment-overview |
| Apply Zero Trust principles with Defender for Cloud | https://learn.microsoft.com/en-us/azure/defender-for-cloud/zero-trust |
Limits & Quotas
| Topic | URL |
|---|---|
| Understand Defender for Servers data ingestion benefit | https://learn.microsoft.com/en-us/azure/defender-for-cloud/data-ingestion-benefit |
| Review current limitations in Defender portal | https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-portal/known-limitations |
| Export Defender for Cloud alerts to CSV with limits | https://learn.microsoft.com/en-us/azure/defender-for-cloud/export-alerts-to-csv |
| Understand Defender for Cloud free trial limits | https://learn.microsoft.com/en-us/azure/defender-for-cloud/free-trial |
| Review Defender for Cloud data collection extensions and retirement timelines | https://learn.microsoft.com/en-us/azure/defender-for-cloud/monitoring-components |
| Interpret Defender for Storage malware scan results and capacity limits | https://learn.microsoft.com/en-us/azure/defender-for-cloud/understand-malware-scan-results |
Shortened here. Read the whole file on GitHub.
Signals
- GitHub stars
- 742
- Forks
- 120
- Last commit
- Sep 2026
ahel review
S4info
community integration — published by microsoftdocs, not azure
Automated review, not a security audit. Ruleset v1+k2.
Advanced
- Catalog kind
- skill
- Gateway key
azure-defender-for-cloud- Source
- github.com/microsoftdocs/agent-skills