Azure Enterprise Governance Framework
Overview
Master enterprise-level Azure governance, security, and compliance. This skill combines Microsoft Cloud Adoption Framework (CAF) naming standards with comprehensive security architecture (Zero Trust principles), compliance frameworks (NIST, SOC 2, PCI-DSS, HIPAA), and operational best practices. Design secure, compliant, and scalable Azure infrastructure aligned with industry standards.
Core Capabilities
1. Naming Convention Design & Validation
Design and validate Azure resource naming strategies that are:
- Compliant: Follow Microsoft Cloud Adoption Framework (CAF) standards
- Scalable: Support hundreds of resources across multiple environments
- Auditable: Enable automated compliance checking
- Human-friendly: Clear, consistent, and easy to parse
🎯 Interactive Decision Guide:
Use references/naming-decision-guide.md for step-by-step guidance:
- Decision flowchart - Visual guide for choosing naming patterns
- Questionnaire - Answer questions to determine your needs
- Template library - Ready-to-use naming templates for common scenarios:
- Lab/Experimental environments (for learning and POC)
- Single application deployment (simple architectures)
- Microservices architecture (distributed systems)
- Multi-tenant SaaS (platform services)
- Interactive naming generator - Auto-generate naming schemes
📚 Detailed Reference:
See references/naming-conventions.md for:
- Microsoft-recommended naming format
- Resource type abbreviations from official CAF documentation
- Naming constraints and restrictions per resource type
- Multi-environment naming strategies
- Hierarchical resource organization patterns
Usage Pattern:
- Start with decision guide: Run
python scripts/generate_naming.py for interactive help
- Review your organization structure (org, department, project)
- Select naming template based on scenario (lab, app, microservices, multi-tenant)
- Define abbreviations for resource types and environments
- Validate naming scheme:
python scripts/validate_naming.py --resource-group <name>
- Apply naming scheme consistently across all resources
2. Security & Compliance Framework
Implement security controls across Azure infrastructure using:
- Zero Trust Architecture: Assume breach, verify everything
- NIST Cybersecurity Framework: Security standards and controls
- Azure Well-Architected Framework: Security pillar best practices
- Managed Identity: Eliminate shared credentials and key management
Reference references/security-best-practices.md for:
- Identity and access management (IAM) patterns
- Network security and isolation strategies
- Data protection and encryption requirements
- Compliance frameworks (NIST, SOC 2, PCI-DSS, HIPAA)
- Security assessment checklist
- Common security misconfigurations and fixes
Key Security Principles:
- Never use secrets in code (use Key Vault + Managed Identity)
- Implement defense in depth (network, application, data layers)
- Enable monitoring and alerting on all resources
- Enforce role-based access control (RBAC)
- Require multi-factor authentication (MFA)
- Use private endpoints for sensitive services
- Encrypt data in transit and at rest
- Regular security assessments and penetration testing
3. Automated Validation & Compliance Checking
Validate resource naming and security configurations using Python scripts in scripts/:
validate_naming.py
- Check resource names against CAF standards
- Verify naming constraints (length, characters, uniqueness)
- Detect naming pattern violations
- Generate compliance reports
- Usage:
python scripts/validate_naming.py --resource-group mygroup --check-all
security_audit.py
- Audit Azure resources for security misconfigurations
- Check for managed identity usage
- Verify encryption settings (data, transport)
- Validate network isolation (NSGs, private endpoints)
- Identify overly permissive RBAC assignments
- Generate security assessment report
- Usage:
python scripts/security_audit.py --resource-group mygroup --severity high
compliance_checker.py
- Verify compliance with organizational policies
- Check naming convention compliance
- Validate security controls alignment
- Generate audit trail for compliance documentation
- Support multiple compliance frameworks (NIST, SOC2, etc.)
- Usage:
python scripts/compliance_checker.py --framework nist --resource-group mygroup
4. Organization Hierarchy & Governance
Structure Azure resources using hierarchies that support:
- Multi-tenant organizations: Separate by customer/tenant
- Environment management: dev, test, stg, prod isolation
- Cost allocation: Easy chargeback and cost center mapping
- Access control: Align resource hierarchy with RBAC
- Disaster recovery: Regional isolation and failover strategy
Hierarchy Template:
Subscription (billing boundary)
├── Resource Group: rg-{org}-{workload}-{env}
│ ├── Compute: asp-{org}-{workload}-{env}
│ ├── Storage: st{org}{env}001
│ ├── Database: sqldb-{org}-{workload}-{env}
│ └── Security: kv-{org}-{env}
├── Resource Group: rg-{org}-{workload}-{env}
└── Resource Group: rg-{org}-platform-{env}
Best Practices Checklist
Before Deployment
Post-Deployment
Common Use Cases
Scenario 1: Migrate 100+ Resources to Compliant Naming
# Validate current resources
python scripts/validate_naming.py --resource-group oldgroup --check-all
# Identify violations
python scripts/validate_naming.py --resource-group oldgroup --report violations.json
# Create migration plan with new compliant names
# Use references/naming-conventions.md to determine new names
Scenario 2: Implement Zero Trust Security
- Review
references/security-best-practices.md section on Zero Trust
- Audit current state:
python scripts/security_audit.py --resource-group mygroup
- Identify gaps compared to Zero Trust checklist
- Implement controls: Managed Identity, Private Endpoints, NSGs
- Re-audit and validate:
python scripts/security_audit.py --resource-group mygroup
Scenario 3: Prepare for SOC 2 / HIPAA Compliance
- Select compliance framework:
python scripts/compliance_checker.py --framework soc2
- Review required controls in
references/security-best-practices.md
- Generate gap analysis report
- Implement required security controls
- Document compliance evidence and controls
- Schedule regular audits:
python scripts/compliance_checker.py --framework soc2 --schedule monthly
Scenario 4: Design Multi-Tenant Naming Strategy
- Review
references/naming-conventions.md section on multi-tenant patterns
- Define tenant/customer identifier (e.g., tenant ID, subdomain)
- Create resource group naming pattern:
rg-{tenant}-{workload}-{env}
- Map resources to resource groups by tenant
- Enforce access isolation using RBAC and subscriptions per tenant
Related Skills
- azure-expert: Comprehensive Azure service architecture and deployment
- skill-creator: Create and manage AI skills in VS Code
Additional Resources
1---2name: azure-enterprise-governance3description: Enterprise-grade Azure governance, security, and compliance framework. Combines Microsoft Cloud Adoption Framework (CAF) naming standards with comprehensive security architecture (Zero Trust), compliance frameworks (NIST, SOC2, PCI-DSS, HIPAA), and best practices. Provides naming validation, security audits, RBAC design, and compliance checklists for production-ready Azure deployments.4---56# Azure Enterprise Governance Framework78## Overview910Master enterprise-level Azure governance, security, and compliance. This skill combines Microsoft Cloud Adoption Framework (CAF) naming standards with comprehensive security architecture (Zero Trust principles), compliance frameworks (NIST, SOC 2, PCI-DSS, HIPAA), and operational best practices. Design secure, compliant, and scalable Azure infrastructure aligned with industry standards.1112## Core Capabilities1314### 1. Naming Convention Design & Validation15Design and validate Azure resource naming strategies that are:16- **Compliant**: Follow Microsoft Cloud Adoption Framework (CAF) standards17- **Scalable**: Support hundreds of resources across multiple environments18- **Auditable**: Enable automated compliance checking19- **Human-friendly**: Clear, consistent, and easy to parse2021**🎯 Interactive Decision Guide:**2223Use `references/naming-decision-guide.md` for step-by-step guidance:24- **Decision flowchart** - Visual guide for choosing naming patterns25- **Questionnaire** - Answer questions to determine your needs26- **Template library** - Ready-to-use naming templates for common scenarios:27 - Lab/Experimental environments (for learning and POC)28 - Single application deployment (simple architectures)29 - Microservices architecture (distributed systems)30 - Multi-tenant SaaS (platform services)31- **Interactive naming generator** - Auto-generate naming schemes3233**📚 Detailed Reference:**3435See `references/naming-conventions.md` for:36- Microsoft-recommended naming format37- Resource type abbreviations from official CAF documentation38- Naming constraints and restrictions per resource type39- Multi-environment naming strategies40- Hierarchical resource organization patterns4142**Usage Pattern:**431. **Start with decision guide**: Run `python scripts/generate_naming.py` for interactive help442. Review your organization structure (org, department, project)453. Select naming template based on scenario (lab, app, microservices, multi-tenant)464. Define abbreviations for resource types and environments475. Validate naming scheme: `python scripts/validate_naming.py --resource-group <name>`486. Apply naming scheme consistently across all resources4950### 2. Security & Compliance Framework51Implement security controls across Azure infrastructure using:52- **Zero Trust Architecture**: Assume breach, verify everything53- **NIST Cybersecurity Framework**: Security standards and controls54- **Azure Well-Architected Framework**: Security pillar best practices55- **Managed Identity**: Eliminate shared credentials and key management5657Reference `references/security-best-practices.md` for:58- Identity and access management (IAM) patterns59- Network security and isolation strategies60- Data protection and encryption requirements61- Compliance frameworks (NIST, SOC 2, PCI-DSS, HIPAA)62- Security assessment checklist63- Common security misconfigurations and fixes6465**Key Security Principles:**66- Never use secrets in code (use Key Vault + Managed Identity)67- Implement defense in depth (network, application, data layers)68- Enable monitoring and alerting on all resources69- Enforce role-based access control (RBAC)70- Require multi-factor authentication (MFA)71- Use private endpoints for sensitive services72- Encrypt data in transit and at rest73- Regular security assessments and penetration testing7475### 3. Automated Validation & Compliance Checking76Validate resource naming and security configurations using Python scripts in `scripts/`:7778**validate_naming.py**79- Check resource names against CAF standards80- Verify naming constraints (length, characters, uniqueness)81- Detect naming pattern violations82- Generate compliance reports83- Usage: `python scripts/validate_naming.py --resource-group mygroup --check-all`8485**security_audit.py**86- Audit Azure resources for security misconfigurations87- Check for managed identity usage88- Verify encryption settings (data, transport)89- Validate network isolation (NSGs, private endpoints)90- Identify overly permissive RBAC assignments91- Generate security assessment report92- Usage: `python scripts/security_audit.py --resource-group mygroup --severity high`9394**compliance_checker.py**95- Verify compliance with organizational policies96- Check naming convention compliance97- Validate security controls alignment98- Generate audit trail for compliance documentation99- Support multiple compliance frameworks (NIST, SOC2, etc.)100- Usage: `python scripts/compliance_checker.py --framework nist --resource-group mygroup`101102### 4. Organization Hierarchy & Governance103104Structure Azure resources using hierarchies that support:105- **Multi-tenant organizations**: Separate by customer/tenant106- **Environment management**: dev, test, stg, prod isolation107- **Cost allocation**: Easy chargeback and cost center mapping108- **Access control**: Align resource hierarchy with RBAC109- **Disaster recovery**: Regional isolation and failover strategy110111**Hierarchy Template:**112```113Subscription (billing boundary)114├── Resource Group: rg-{org}-{workload}-{env}115│ ├── Compute: asp-{org}-{workload}-{env}116│ ├── Storage: st{org}{env}001117│ ├── Database: sqldb-{org}-{workload}-{env}118│ └── Security: kv-{org}-{env}119├── Resource Group: rg-{org}-{workload}-{env}120└── Resource Group: rg-{org}-platform-{env}121```122123## Best Practices Checklist124125### Before Deployment126127- [ ] **Naming Validated**: Run `validate_naming.py` against all resource names128- [ ] **Security Review**: Complete `security-best-practices.md` checklist129- [ ] **RBAC Configured**: Use managed identities, no shared credentials130- [ ] **Encryption Enabled**: Data at rest and in transit encrypted131- [ ] **Monitoring Setup**: Application Insights, Log Analytics configured132- [ ] **Network Isolation**: Private endpoints for sensitive services133- [ ] **Compliance Check**: Run `compliance_checker.py` for your framework134- [ ] **Documentation**: Resource hierarchy and naming documented135- [ ] **Access Control**: Principle of least privilege applied136- [ ] **Backup Strategy**: Automated backups configured and tested137138### Post-Deployment139140- [ ] **Audit Baseline**: Run `security_audit.py` to establish baseline141- [ ] **Monitoring Active**: Alerts configured for security events142- [ ] **Regular Reviews**: Monthly compliance and security reviews143- [ ] **Access Reviews**: Quarterly RBAC access reviews144- [ ] **Threat Analysis**: Regular threat modeling and updates145- [ ] **Incident Response**: Runbooks documented and tested146- [ ] **Disaster Recovery**: DR procedures documented and practiced147148## Common Use Cases149150### Scenario 1: Migrate 100+ Resources to Compliant Naming151```bash152# Validate current resources153python scripts/validate_naming.py --resource-group oldgroup --check-all154155# Identify violations156python scripts/validate_naming.py --resource-group oldgroup --report violations.json157158# Create migration plan with new compliant names159# Use references/naming-conventions.md to determine new names160```161162### Scenario 2: Implement Zero Trust Security1631. Review `references/security-best-practices.md` section on Zero Trust1642. Audit current state: `python scripts/security_audit.py --resource-group mygroup`1653. Identify gaps compared to Zero Trust checklist1664. Implement controls: Managed Identity, Private Endpoints, NSGs1675. Re-audit and validate: `python scripts/security_audit.py --resource-group mygroup`168169### Scenario 3: Prepare for SOC 2 / HIPAA Compliance1701. Select compliance framework: `python scripts/compliance_checker.py --framework soc2`1712. Review required controls in `references/security-best-practices.md`1723. Generate gap analysis report1734. Implement required security controls1745. Document compliance evidence and controls1756. Schedule regular audits: `python scripts/compliance_checker.py --framework soc2 --schedule monthly`176177### Scenario 4: Design Multi-Tenant Naming Strategy1781. Review `references/naming-conventions.md` section on multi-tenant patterns1792. Define tenant/customer identifier (e.g., tenant ID, subdomain)1803. Create resource group naming pattern: `rg-{tenant}-{workload}-{env}`1814. Map resources to resource groups by tenant1825. Enforce access isolation using RBAC and subscriptions per tenant183184## Related Skills185186- **azure-expert**: Comprehensive Azure service architecture and deployment187- **skill-creator**: Create and manage AI skills in VS Code188189## Additional Resources190191- [Microsoft Cloud Adoption Framework - Naming](https://learn.microsoft.com/azure/cloud-adoption-framework/ready/azure-best-practices/resource-naming)192- [Microsoft Cloud Adoption Framework - Naming Abbreviations](https://learn.microsoft.com/azure/cloud-adoption-framework/ready/azure-best-practices/resource-abbreviations)193- [Azure Well-Architected Framework - Security Pillar](https://learn.microsoft.com/azure/well-architected/security/)194- [Azure Security Best Practices](https://learn.microsoft.com/security/benchmark/azure/)195- [NIST Cybersecurity Framework](https://www.nist.gov/cyberframework/)196- [Zero Trust Principles - Microsoft](https://learn.microsoft.com/security/zero-trust/)