← all publishers

vinayaklatthe

@vinayaklatthe source repo

88 published skills

  1. Azure Key Vault · vinayaklatthe
    Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation. Covers when to use standard Key Vault vs Managed HSM (FIPS 140-3 Level 3), one-vault-per-app blast radius principle, and Key Vault references in App Service / Functions. WHEN: Azure Key Vault, store secrets, manage certificates, encryption keys, secret rotation, Key Vault RBAC, purge protection, soft delete, private endpoint Key Vault, managed identity access secrets, Managed HSM, Key Vault references, BYOK CMK. DO NOT USE for certificate authority design (use pki-design), entra app credentials only (use entra-id), or PaaS networking topology (use azure-network-security-design).
    0
    installs
  2. Purview Data Map · vinayaklatthe
    Guidance for the Microsoft Purview Data Map - the foundation that scans and maps data sources across multicloud and on-premises estates to power cataloging and governance. Covers source registration, integration runtimes (managed vs self-hosted), scan rule sets, classifications, collections, and cost control. WHEN: Purview Data Map, scan data sources, register data source, data discovery, integration runtime, map enterprise data, multicloud data scanning, classification scan, collections, glossary.
    0
    installs
  3. Purview Data Catalog · vinayaklatthe
    Guidance for the Microsoft Purview Unified Catalog (data catalog) — business-friendly discovery, governance domains, data products, glossary terms, and data quality on top of the Data Map. Covers governance domains, data products, and curation. WHEN: Purview data catalog, unified catalog, data products, governance domain, business glossary, data quality, data discovery for analysts, curate data assets, data stewardship.
    0
    installs
  4. Entra Id · vinayaklatthe
    Guidance for Microsoft Entra ID (formerly Azure AD) — cloud identity and access management and the control plane for Zero Trust. Covers tenant and identity model, authentication methods (passkeys, FIDO2, certificate-based), hybrid identity with Entra Connect or Cloud Sync, app registrations and consent governance, groups and administrative units, break-glass accounts, and Zero Trust identity foundations. WHEN: Microsoft Entra ID, Azure AD, identity provider setup, SSO, hybrid identity, Entra Connect, Cloud Sync, authentication methods, passwordless, passkey, FIDO2, certificate-based auth, app registration, enterprise application, illicit consent grant, break-glass account, emergency access, administrative units, SSPR, password writeback. DO NOT USE for risk-based detection (use entra-id-protection), Conditional Access design (use conditional-access-mfa), PIM (use azure-pim), or identity governance lifecycle (use entra-id-governance).
    0
    installs
  5. Sentinel · vinayaklatthe
    Guidance for designing and operating Microsoft Sentinel, the cloud-native SIEM and SOAR delivered through the Defender portal. Covers workspace design, data connectors, ingestion tiers (Analytics/Basic/Auxiliary/ADX), analytics rules, hunting, watchlists, automation playbooks, and cost/commitment-tier optimisation. WHEN: deploy Microsoft Sentinel, design SIEM, onboard data connectors, write analytics rule, KQL detection, Sentinel playbook, SOAR automation, Sentinel cost optimization, log ingestion tiers, commitment tier, Sentinel workspace design, how do I set up a SIEM, collect logs from third-party tools, ingest firewall or Linux syslog into Azure, write a detection rule, automate incident response, how much does Sentinel cost, Auxiliary logs, Basic logs, ADX archive, codeless connector. DO NOT USE when the goal is correlating Microsoft 365 XDR alerts into incidents (use defender-xdr) or onboarding Sentinel into the unified Defender portal (use unified-secops-platform).
    0
    installs
  6. Azure Arc · vinayaklatthe
    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management. Covers Arc-enabled servers onboarding, extending Defender for Cloud and Azure Policy to non-Azure machines, and Arc-enabled Kubernetes. WHEN: Azure Arc, manage on-prem servers from Azure, hybrid management, Arc-enabled servers, Arc Kubernetes, extend Defender for Cloud to on-prem, govern multicloud machines, Connected Machine agent, Arc agent, hybrid security posture, machine configuration, guest configuration. DO NOT USE for Azure-native VMs only (use Azure Resource Manager directly), Intune-managed endpoints (use intune-device-mgmt), or Azure Stack HCI specifically (separate product).
    0
    installs
  7. Azure Pim · vinayaklatthe
    Guidance for Microsoft Entra Privileged Identity Management (PIM) — just-in-time, time-bound, approval-based, audited elevation for Entra roles, Azure resource roles, and privileged groups. Covers eligible vs active assignments, activation controls (MFA + approval + justification + ticket), access reviews, PIM for Groups, and removing standing access. WHEN: Privileged Identity Management, PIM, just-in-time access, time-bound role, eligible assignment, require approval to activate, privileged role activation, PIM for groups, access review privileged roles, reduce standing access, how do I remove permanent admin rights, temporary admin access, admins should not have standing Global Admin, JIT access for Azure roles, PIM activation alert, role activation audit. DO NOT USE for entitlement management of resource access packages (use entra-id-governance) or risk detection (use entra-id-protection).
    0
    installs
  8. Azure Waf · vinayaklatthe
    Guidance for Azure Web Application Firewall — deployed on Azure Front Door (global, edge-tier) or Azure Application Gateway (regional, integrated with backend pools). Covers WAF policy design with managed rule sets (Microsoft Default Rule Set, Bot Manager, OWASP CRS), custom rules (rate limit, geo-block, IP allow/deny), exclusion design (the long-tail tuning task that decides whether WAF stays in Prevention), JSON challenge / CAPTCHA, log analytics integration, false-positive triage workflow, integration with Defender for Cloud and Sentinel, regional vs global trade-off, and migration from third-party WAF. WHEN: Azure WAF, Front Door WAF, Application Gateway WAF, OWASP CRS Azure, bot manager Azure, WAF custom rules, WAF rate limiting, WAF false positives, WAF exclusions, WAF prevention vs detection, JSON challenge WAF, geo-block WAF. DO NOT USE for L3/L4 DDoS (use azure-ddos-protection), Azure Firewall design (use azure-firewall), or non-HTTP workloads.
    0
    installs
  9. Paw Design · vinayaklatthe
    Guidance for designing Privileged Access Workstations (PAW) and the Microsoft privileged access strategy (enterprise access model, clean source principle, tiered admin isolation). Covers when to use Enterprise vs Specialized vs Privileged device profiles, hardening (Entra-join, Intune, app allowlisting, Credential Guard), Conditional Access enforcement, and rollout. WHEN: privileged access workstation, PAW, secure admin workstation, enterprise access model, privileged access strategy, admin isolation, secured workstation, clean source principle, tier 0 protection, control plane, dedicated admin device, hardened workstation, Credential Guard, FIDO2 admin. DO NOT USE for general endpoint hardening (use defender-for-endpoint) or device compliance policy (use intune-device-mgmt).
    0
    installs
  10. Pki Design · vinayaklatthe
    Guidance for designing public key infrastructure (PKI) and certificate management on Azure and hybrid environments. Covers CA strategy (offline root + issuing CAs, AD CS vs managed/third-party vs public CA), Azure Key Vault certificates, HSM key protection, Entra certificate-based authentication (CBA), certificate lifecycle (issuance, renewal, rotation, revocation), and Intune SCEP/PKCS distribution. WHEN: PKI design, certificate authority, root CA offline, issuing CA, certificate management, Key Vault certificates, certificate-based authentication, CBA, certificate lifecycle, issue and rotate certificates, mTLS certificates, code signing, CRL OCSP, certificate expiry, certificate rotation, AD CS, HSM, Managed HSM. DO NOT USE for Entra ID identity model (use entra-id) or Key Vault secrets/keys only (use azure-key-vault).
    0
    installs
  11. Azure Policy · vinayaklatthe
    Guidance for Azure Policy — enforcing and auditing governance and security guardrails at scale across Azure with definitions, initiatives, assignments, and remediation tasks. Covers effects (Audit, Deny, Append, Modify, DeployIfNotExists, AuditIfNotExists), management group inheritance, audit-first rollout, parameterised reusable policies, and exclusion discipline. Powers Defender for Cloud regulatory compliance. WHEN: Azure Policy, governance guardrails, enforce compliance, policy initiative, deny resource, audit configuration, remediation task, deployIfNotExists, management group policy, security baseline enforcement, MCSB initiative, regulatory compliance Azure. DO NOT USE for resource RBAC role choice (use azure-role-selector), Defender posture only (use defender-for-cloud-hardening), or Bicep / IaC templating.
    0
    installs
  12. Defender Tvm · vinayaklatthe
    Guidance for Microsoft Defender Threat Intelligence (Defender TI) and Microsoft Defender Vulnerability Management (MDVM) — the threat-and-vulnerability layer of Defender XDR. Covers MDVM exposure score, CVE prioritization with threat insights and active campaigns, security baselines (CIS/STIG), browser-extension and certificate inventory, network share assessment, hardware/firmware inventory, security recommendations and remediation tasks (Intune integration), and Defender TI for adversary-tracked indicators, intel profiles, infrastructure pivoting, and MDTI APIs. WHEN: Defender Vulnerability Management, MDVM, MDVM add-on, exposure score, threat-aware vulnerability prioritization, CIS benchmark CVEs, security baselines assessment, browser extension inventory, firmware vuln, Microsoft Defender Threat Intelligence, MDTI, intel profiles, threat actor tracking, IOC pivoting, MDTI API, threat hunting with intel. DO NOT USE for endpoint EDR config (use defender-for-endpoint), Sentinel detections (use sentinel-detec
    0
    installs
  13. Defender Xdr · vinayaklatthe
    Guidance for Microsoft Defender XDR — the unified extended detection and response suite that correlates signals across endpoints, identities, email, and cloud apps into prioritised incidents with attack-graph context. Covers onboarding the four core workloads, incident investigation, advanced hunting in KQL, custom detection rules, automatic attack disruption, AIR, and unified RBAC. WHEN: Microsoft Defender XDR, XDR incident investigation, correlate alerts across workloads, advanced hunting KQL, automatic attack disruption, AIR, Defender portal incidents, cross-domain detection, how do I investigate an attack across multiple Microsoft 365 products, alert correlation across endpoint and identity, unified incident view, attack graph, custom detection rule, unified RBAC. DO NOT USE when the need is SIEM log ingestion or custom KQL detections from third-party sources (use sentinel), merging Sentinel into the Defender portal (use unified-secops-platform), or endpoint-only EDR (use defender-for-endpoint).
    0
    installs
  14. Iac Security · vinayaklatthe
    Guidance for securing Infrastructure-as-Code (Bicep, ARM, Terraform, and ACI/Container) pipelines on Azure — shift-left scanning, policy-as-code, secret hygiene, identity for pipelines, drift detection, and supply chain. Covers Microsoft Defender for Cloud DevOps Security (GitHub / Azure DevOps connectors), Microsoft Security DevOps (MSDO) extension, Bicep linter and template specs, Terraform best practices on Azure (state management, backend hardening, provider versions), Azure Policy as deploy-time and CI-time gate, GitOps with Flux/ArgoCD on AKS, secret scanning and dependency review, signed commits / artifact signing, OIDC federation for pipeline identity (no client secrets), and integration with Defender for Cloud posture. WHEN: IaC security, Bicep security, Terraform Azure security, Defender for Cloud DevOps Security, MSDO, Microsoft Security DevOps, shift-left Azure, policy as code, OIDC GitHub Actions Azure, secrets in IaC, drift detection, signed Bicep, supply chain Azure. DO NOT USE for Kubernetes a
    0
    installs
  15. Azure Pricing · vinayaklatthe
    Guidance for estimating and reasoning about the cost of Azure security services — using the Azure Pricing Calculator, understanding key cost drivers (Sentinel ingestion, Defender plans, Key Vault operations), and cost-optimization levers. WHEN: Azure security pricing, estimate cost, Sentinel cost, Defender for Cloud pricing, pricing calculator, cost drivers, optimize security spend, ingestion cost, licensing vs consumption, budget for security.
    0
    installs
  16. Defender Easm · vinayaklatthe
    Guidance for Microsoft Defender External Attack Surface Management (Defender EASM) — discovers and inventories an organization's internet-facing assets (domains, hosts, IPs, SSL certs, ASNs, web pages, contacts) from the outside-in. Covers seed-based discovery, attack surface insights (CVEs, expiring certs, deprecated tech, unsanctioned cloud), labels and groups, integration with Defender for Cloud (CSPM), Defender XDR, and Sentinel, and pricing model (per asset). WHEN: Defender EASM, external attack surface management, internet-facing inventory, shadow IT discovery, expired SSL discovery, exposed RDP discovery, unknown subdomain, attack surface insights, seed-based discovery, outside-in scanning, third-party asset risk, M&A asset discovery. DO NOT USE for internal asset discovery (use defender-for-cloud-hardening / Defender XDR), endpoint vuln scan (use defender-for-endpoint MDVM), or Sentinel hunting alone.
    0
    installs
  17. Purview Audit · vinayaklatthe
    Guidance for Microsoft Purview Audit (Standard and Premium) - logging and searching user/admin activity across Microsoft 365 for investigations and compliance. Covers tier differences, default and extended retention, high-value events, audit search UX, Office 365 Management Activity API / Microsoft Graph audit API, and Sentinel/SIEM integration. WHEN: Purview Audit, audit log search, Microsoft 365 audit, Audit Premium, investigate user activity, audit log retention, Microsoft Graph audit API, forensic logging, crucial audit events, MailItemsAccessed.
    0
    installs
  18. Windows Hello · vinayaklatthe
    Guidance for Windows Hello for Business (WHfB) — passwordless, phishing-resistant authentication using a PIN or biometric backed by an asymmetric key or certificate. Covers trust model selection (cloud Kerberos trust default for hybrid; key trust legacy; certificate trust niche), prerequisites (Entra join, MFA registration, Entra Kerberos for cloud Kerberos trust), Intune-based provisioning, multi-factor unlock, and Conditional Access authentication strengths. WHEN: Windows Hello for Business, WHfB, passwordless Windows, biometric sign-in, PIN sign-in, cloud Kerberos trust, key trust, certificate trust, hybrid sign-in, Entra Kerberos, multi-factor unlock, FIDO2 vs Hello, Hello provisioning. DO NOT USE for FIDO2 security keys (use entra-id), CA policy authoring (use conditional-access-mfa), or Intune compliance baseline (use intune-device-mgmt).
    0
    installs
  19. Azure Firewall · vinayaklatthe
    Guidance for Azure Firewall — managed cloud-native L3-L7 stateful network firewall for centralised egress, east-west, and ingress control. Covers SKU choice (Basic vs Standard vs Premium), Firewall Policy hierarchy, application/network/DNAT rules, threat intelligence and IDPS, TLS inspection, hub-spoke deployment with UDRs, and forced tunneling. WHEN: Azure Firewall, network firewall, egress filtering, FQDN filtering, Firewall Policy, IDPS, TLS inspection, forced tunneling, central network control, firewall SKU Premium Standard Basic, hub spoke firewall, UDR through firewall, DNAT inbound. DO NOT USE for L7 web application protection (use Front Door / Application Gateway WAF), subnet microsegmentation (use NSGs in azure-network-security-design), or third-party NVA design.
    0
    installs
  20. Passkeys Fido2 · vinayaklatthe
    Guidance for rolling out passkeys (device-bound and synced) and FIDO2 security keys in Microsoft Entra ID as the primary phishing-resistant authentication method. Covers passkey types (device-bound in Microsoft Authenticator, synced passkeys via platform providers, hardware security keys), Conditional Access authentication strength, registration campaigns, Temporary Access Pass (TAP) bootstrapping, lifecycle (lost device, attestation), Conditional Access requiring phishing-resistant MFA, decommissioning legacy methods (SMS, voice, weaker app push), and integration with Windows Hello for Business. WHEN: passkey rollout, FIDO2 keys, phishing-resistant MFA, Microsoft Authenticator passkey, device-bound passkey, synced passkey, Temporary Access Pass, TAP, Conditional Access authentication strength, kill SMS MFA, retire voice MFA, passwordless rollout, FIDO2 attestation, security key registration. DO NOT USE for general CA policy authoring (use conditional-access-mfa), Windows desktop sign-in design end-to-end (us
    0
    installs
  21. Purview AI Hub · vinayaklatthe
    Guidance for Microsoft Purview AI Hub (now part of Data Security Posture Management for AI) — discover, govern, and protect sensitive data flowing into AI applications (Microsoft 365 Copilot, Copilot Studio agents, ChatGPT, Gemini, third-party generative AI). Covers AI app discovery via Defender for Cloud Apps + endpoint signals, sensitive data risk surface, ready-to-use policies for Copilot oversharing and risky AI usage, DLP for generative AI endpoints (browser blocking), prompt/response auditing, integration with IRM (risky AI usage), Sentinel reporting, and difference vs Defender for Cloud AI workload protection. WHEN: Purview AI Hub, DSPM for AI, AI app discovery, ChatGPT data leakage, Gemini DLP, generative AI risk, prompt audit, Copilot Studio agent governance, sensitive data to AI, shadow AI, agent data risk. DO NOT USE for Defender for Cloud's AI workload protection (use defender-for-cloud-ai), Azure AI Content Safety (use azure-ai-content-safety), or Microsoft 365 Copilot rollout (use copilot-for-m3
    0
    installs
  22. Microsoft Priva · vinayaklatthe
    Guidance for Microsoft Priva — privacy risk management and subject rights requests. Covers Priva Privacy Risk Management and Priva Subject Rights Requests to find privacy risks and fulfill data subject requests (GDPR/CCPA). WHEN: Microsoft Priva, privacy risk management, subject rights request, DSAR, data subject request, GDPR fulfillment, privacy risk policies, data minimization, overexposed personal data.
    0
    installs
  23. Purview Dspm AI · vinayaklatthe
    Guidance for Microsoft Purview Data Security Posture Management for AI (DSPM for AI) - discovering, monitoring, and protecting sensitive data interactions with generative AI apps like Microsoft 365 Copilot, Security Copilot, Copilot Studio agents, and third-party AI (ChatGPT, Gemini). Covers AI usage visibility, one-click recommendations, oversharing risk surfaced to AI, and DLP for AI. WHEN: DSPM for AI, AI data security posture, Copilot data risk, monitor AI prompts, sensitive data in AI, generative AI data protection, third-party AI usage visibility, secure Copilot data, what sensitive data is being sent to AI, monitor what users are putting into Copilot prompts, detect sensitive data in AI responses, ChatGPT data leakage risk. DO NOT USE when the goal is remediating overshared SharePoint content before Copilot rollout (use purview-copilot-oversharing) or building IRM policies for departing users (use insider-risk-baseline).
    0
    installs
  24. Purview General · vinayaklatthe
    Orientation skill for the Microsoft Purview data security, governance, and compliance suite. Helps choose the right Purview solution for a goal and understand the unified portal, roles, and licensing model. WHEN: Microsoft Purview overview, which Purview solution, Purview portal, data governance vs data security vs compliance, Purview roles and permissions, where to start with Purview, Purview licensing, I do not know which Purview feature to use, what does Purview cover, getting started with Purview, Purview product overview, which compliance tool do I need. Use this skill first for Purview orientation, then follow up with the specific skill for your use case.
    0
    installs
  25. Bitlocker Design · vinayaklatthe
    Guidance for designing BitLocker drive encryption for Windows endpoints managed via Microsoft Intune — encryption policy, silent enablement, recovery key escrow to Entra ID, TPM, pre-boot authentication trade-offs, and BitLocker To Go for removable media. Covers compliance integration with Conditional Access and recovery workflows. WHEN: BitLocker, disk encryption, Windows encryption policy, BitLocker recovery key, silent BitLocker enablement, Intune disk encryption, TPM 2.0, escrow recovery key, encrypt endpoints, XTS-AES, BitLocker To Go, pre-boot authentication, removable drive encryption. DO NOT USE for general Intune device management (use intune-device-mgmt), Linux/macOS encryption (use intune-device-mgmt FileVault), or Azure disk encryption (use azure-key-vault).
    0
    installs
  26. Defender For Iot · vinayaklatthe
    Guidance for Microsoft Defender for IoT — agentless OT/ICS network detection and response for industrial environments, plus enterprise IoT (EIoT) protection integrated with Defender XDR. Covers OT sensor deployment (physical/virtual, SPAN/TAP), Purdue model alignment, on-premises management console, cloud-managed sensors, EIoT (printers, cameras, VoIP) discovered through MDE, asset inventory, vulnerability data, threat intelligence, and integration with Sentinel and Defender XDR. WHEN: Defender for IoT, OT security, ICS security, SCADA monitoring, Purdue model network security, OT sensor deployment, SPAN port monitoring, enterprise IoT discovery, unmanaged device protection, factory floor security, NDR for OT, ICS threat detection, IoT asset inventory. DO NOT USE for IoT Hub data-plane security (Azure platform), Azure Sphere device hardening, or generic endpoint EDR (use defender-for-endpoint).
    0
    installs
  27. M365 Oversharing · vinayaklatthe
    Guidance for remediating oversharing across Microsoft 365 (SharePoint, OneDrive, Teams, Exchange) using the Secure & Governed Data Foundation blueprint - a three-pillar program (remediate oversharing, set up guardrails, meet regulations) built on SharePoint Advanced Management data access governance, sensitivity and container labels, secure-by-default labelling, Restricted Access Control, and Microsoft Purview. WHEN: Microsoft 365 oversharing, M365 oversharing, secure and governed data foundation, oversharing blueprint, too many people have access to SharePoint, EEEU everyone except external users, tighten permissions, data access governance report, restricted content discovery, secure by default labels, prepare data foundation, reduce sharing link sprawl, governed data estate. DO NOT USE for Copilot-specific readiness framing only (use purview-copilot-oversharing) or building a broad DLP program (use purview-dlp-policy).
    0
    installs
  28. Purview For M365 · vinayaklatthe
    Guidance for applying Microsoft Purview data security and compliance across Microsoft 365 workloads (Exchange, SharePoint, OneDrive, Teams) - coordinating labels, DLP, retention, and Copilot data protection per workload with each workload's distinct behaviour. WHEN: Purview for Microsoft 365, protect SharePoint and Teams data, M365 compliance, labels and DLP across Office, retention for Exchange, Teams data security, OneDrive governance, Microsoft 365 data protection, per-workload Purview.
    0
    installs
  29. Security Copilot · vinayaklatthe
    Guidance for Microsoft Security Copilot - the generative-AI security platform that helps analysts investigate, hunt, summarise, and respond using natural language, plugins, promptbooks, and embedded experiences. Covers SCU provisioning, plugins, promptbooks, governance, and the standalone vs embedded experience choice. WHEN: Microsoft Security Copilot, AI for SOC, security copilot units SCU, promptbooks, Copilot plugins, natural language investigation, summarise incident with AI, Copilot for Security setup, how do I use AI in my SOC, explain a KQL query with AI, summarise an alert for a stakeholder. DO NOT USE when the goal is configuring autonomous triage or remediation agents (use security-copilot-agents).
    0
    installs
  30. Threat Modelling · vinayaklatthe
    Guidance for threat modelling using STRIDE and the Microsoft Security Development Lifecycle (SDL). Covers data-flow diagrams, trust boundaries, the STRIDE categories, mitigation mapping, and tooling (Microsoft Threat Modeling Tool). WHEN: threat modeling, STRIDE, data flow diagram, trust boundary, identify threats, SDL threat modeling, security design review, threat model a system, mitigation mapping, Microsoft Threat Modeling Tool, secure design review, design-time security. DO NOT USE for org-wide security architecture (use security-architecture) or for runtime detection (use sentinel / defender-xdr).
    0
    installs
  31. Azure Bastion Jit · vinayaklatthe
    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access. Covers Bastion SKU selection (Developer / Basic / Standard / Premium), IP-based and shareable-link connections, native client (RDP/SSH from local machine via az CLI), session recording (Premium), private-only deployment, JIT request workflow and policy, RBAC for connect operations, integration with Conditional Access (via Bastion + Entra login on the VM), Azure Policy enforcement to require Bastion + JIT and prohibit public IP on VMs, and migration off VPN/jump-box patterns. WHEN: Azure Bastion design, Bastion SKU comparison, JIT VM access, just-in-time access Azure, Bastion shareable link, native client Bastion, session recording Bastion, eliminate public IP on VMs, replace jump host with Bastion, secure RDP SSH Azure, Bastion Premium recording. DO NOT USE for hybrid/SD-WAN VPN design, GSA Private Access (use entra-global-secure-access), or cluster-only K8s access.
    0
    installs
  32. Defender For Apis · vinayaklatthe
    Guidance for Microsoft Defender for APIs — a Defender for Cloud plan that discovers, prioritizes by risk, and protects APIs published in Azure API Management against threats and abuse. Covers onboarding, security findings, and threat detection. WHEN: Defender for APIs, API threat protection, secure APIs in API Management, API security posture, detect API abuse, onboard APIs to Defender, API attack detection, sensitive data exposure in APIs.
    0
    installs
  33. Entra External Id · vinayaklatthe
    Guidance for Microsoft Entra External ID — the unified customer identity and access management (CIAM) and external collaboration platform that replaces Azure AD B2C (for new tenants) and consolidates B2B guest scenarios. Covers external tenant creation, user flows (sign-up/sign-in, password reset), custom branding, identity providers (Google, Facebook, Apple, SAML/OIDC), email OTP and passkey support, custom attributes, custom authentication extensions (replaces B2C custom policies), API connectors, Conditional Access for external users, self-service sign-up in workforce tenants, B2B collaboration vs B2B direct connect, cross-tenant access settings, and migration considerations from Azure AD B2C. WHEN: Entra External ID, CIAM Microsoft, customer identity, replace Azure AD B2C, B2B guest user, B2B direct connect, cross-tenant access settings, external tenant, self-service sign-up, custom authentication extension, social identity provider, partner collaboration Entra, external user lifecycle, guest user expirat
    0
    installs
  34. Entra Verified Id · vinayaklatthe
    Guidance for Microsoft Entra Verified ID — verifiable credentials issuance and verification platform based on open standards (W3C Verifiable Credentials, DIDs, OpenID4VC). Covers issuer setup (tenant configuration, DID registration, signing key in Key Vault), credential schema design, rules and display files, issuance flows (QR / deep link), verification flows, Face Check biometric matching, integration with Entra ID for workforce onboarding and access, integration with verification partners, and use cases (employee verification, remote onboarding, low-friction account recovery, vendor/contractor identity proofing). WHEN: Entra Verified ID, verifiable credentials, decentralized identity, DID issuance, issue credential Entra, verify credential, Face Check, remote onboarding identity proofing, account recovery with VC, contractor identity verification, vendor verification, workforce onboarding VC. DO NOT USE for B2C/CIAM (use entra-external-id), workforce identity admin (use entra-id), or PKI/certificate design
    0
    installs
  35. Compliance Manager · vinayaklatthe
    Guidance for Microsoft Purview Compliance Manager — continuous compliance posture across Microsoft and non-Microsoft assets, mapped to 360+ regulatory templates (ISO 27001/27018/27701, SOC 2, NIST 800-53/171/CSF, PCI DSS, HIPAA, GDPR, FedRAMP, IRAP, Essential Eight, DORA, EU AI Act, etc.). Covers compliance score, improvement actions (Microsoft-managed vs customer-managed), evidence collection, assessment authoring (custom templates from CSV), multi-assessment grouping, automated testing of technical controls via Microsoft 365 / Defender for Cloud / Entra, evidence repository, audit-ready reports, and continuous assessment vs point-in-time. WHEN: Compliance Manager, compliance score, regulatory assessment Purview, NIST 800-53 assessment, ISO 27001 evidence, FedRAMP assessment, custom compliance template, improvement action, technical control automation, audit evidence M365, DORA assessment, EU AI Act assessment. DO NOT USE for Defender for Cloud regulatory dashboard (use defender-for-cloud-hardening), Records
    0
    installs
  36. Intune Device Mgmt · vinayaklatthe
    Guidance for Microsoft Intune device management — enrollment, configuration, compliance, and security baselines across Windows, macOS, iOS/iPadOS, and Android. Covers Autopilot vs corporate-vs-BYOD enrollment, compliance policies that feed Conditional Access, Intune security baselines, update rings / Autopatch, and using filters and ring-based rollouts to avoid lockouts. WHEN: Microsoft Intune, MDM, device enrollment, Autopilot, Apple ABM, Android Enterprise, compliance policy, security baseline, configuration profile, settings catalog, manage devices, device compliance for Conditional Access, endpoint management, Windows Autopatch, update rings. DO NOT USE for app-only protection on BYOD (use intune-app-protection), endpoint detection / EDR (use defender-for-endpoint), or disk encryption only (use bitlocker-design).
    0
    installs
  37. M365 Govern Manage · vinayaklatthe
    Guidance for governing and managing Microsoft 365 collaboration sprawl — Teams/group lifecycle, sharing and guest access governance, and SharePoint Advanced Management — to keep the data estate secure and Copilot-ready. WHEN: Microsoft 365 governance, Teams sprawl, group lifecycle, guest access governance, external sharing controls, SharePoint Advanced Management, site lifecycle, manage collaboration sprawl, container governance.
    0
    installs
  38. Purview Dlp Policy · vinayaklatthe
    Guidance for designing baseline Microsoft Purview Data Loss Prevention (DLP) policies across Exchange, SharePoint, OneDrive, Teams, and Endpoint. Covers locations, conditions (SITs/labels/classifiers), severity-tiered actions, simulation mode, exception handling, Endpoint DLP onboarding, and tuning. WHEN: Purview DLP, data loss prevention policy, prevent data exfiltration, Endpoint DLP, DLP rule conditions, DLP simulation mode, block sensitive sharing, policy tips, DLP across Microsoft 365, tune DLP false positives.
    0
    installs
  39. Purview Ediscovery · vinayaklatthe
    Guidance for Microsoft Purview eDiscovery (unified experience consolidating prior Standard and Premium) - identifying, preserving, collecting, reviewing, analysing, and exporting content across Microsoft 365 for legal cases, regulatory requests, and investigations. Covers cases, custodians, legal holds, searches, review sets, analytics, and export. WHEN: eDiscovery, legal hold, preserve content, collect for litigation, review set, export evidence, eDiscovery case, custodian, search and hold Microsoft 365, legal investigation, EDRM workflow, defensible collection.
    0
    installs
  40. API Security Design · vinayaklatthe
    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API Security Top 10 and Azure API Management. WHEN: API security design, secure API, OWASP API Top 10, API authentication, API gateway security, rate limiting, validate JWT, protect backend API, API Management security policies, secure API architecture, BOLA, BFLA. DO NOT USE for general application security or web app design (use security-architecture / threat-modelling) or for API runtime detection only (use defender-for-apis).
    0
    installs
  41. Azure Role Selector · vinayaklatthe
    Guidance for selecting the right Azure RBAC role with least privilege - mapping required actions to built-in roles, deciding when a custom role is needed, scoping assignments correctly, and choosing between control-plane and data-plane roles. Covers scope levels (management group → resource), groups vs direct assignment, and PIM for privileged roles. WHEN: which Azure role, least privilege role, Azure RBAC role selection, built-in vs custom role, scope role assignment, role for managed identity, data plane role, assign minimal permissions, RBAC design, control plane vs data plane, Storage Blob Data Reader vs Reader. DO NOT USE for Entra ID directory roles (use entra-id) or for Microsoft 365 admin roles (use m365-govern-manage).
    0
    installs
  42. Azure Site Recovery · vinayaklatthe
    Guidance for Azure Site Recovery (ASR) — disaster-recovery-as-a-service that replicates Azure VMs and on-premises machines to a secondary region for orchestrated failover. Covers RPO / RTO design, replication setup, recovery plans with start-up ordering and scripts, test failover discipline, and the separation between DR (ASR) and backup (Azure Backup) for ransomware resilience. WHEN: Azure Site Recovery, ASR, disaster recovery, DR replication, failover, recovery plan, business continuity, RPO RTO, test failover, region failover, ransomware resilience DR, paired region, failover and failback. DO NOT USE for point-in-time backup / restore (use Azure Backup), database HA / geo-replication only (use SQL geo-replication), or general BCDR design without an Azure tilt.
    0
    installs
  43. Compromise Recovery · vinayaklatthe
    Guidance for responding to and recovering from a significant identity/tenant compromise - regaining administrative control, evicting the adversary in a single coordinated action, and hardening to prevent reentry. Covers trusted foundation (PAW), containment, eviction, identity recovery (krbtgt, federation), and post-eviction hardening. WHEN: compromise recovery, incident response, regain control after breach, evict attacker, tenant compromise, rebuild trust, ransomware recovery, post-breach hardening, kick out adversary, emergency response, attacker is in our tenant right now, ransomware hit our organisation, regain admin access after a breach, adversary has domain admin or Global Admin. DO NOT USE for routine SOC investigation (use defender-xdr / sentinel) or for preventive hardening with no active compromise (use security-architecture / entra-id).
    0
    installs
  44. Entra Id Governance · vinayaklatthe
    Guidance for Microsoft Entra ID Governance — automating identity lifecycle and access with entitlement management (access packages), access reviews, lifecycle workflows for joiner-mover-leaver, separation of duties, and guest access governance. Covers when to use access packages vs direct group assignment, reviewer choice and fallback actions, and integration with PIM for privileged access. WHEN: Entra ID Governance, entitlement management, access packages, access reviews, lifecycle workflows, joiner mover leaver, JML, certify access, separation of duties, govern guest access, B2B guest expiration, identity lifecycle automation, sponsor approval, recertify access. DO NOT USE for risk-based detection (use entra-id-protection), CA policy authoring (use conditional-access-mfa), or PIM activation (use azure-pim).
    0
    installs
  45. Entra Id Protection · vinayaklatthe
    Guidance for Microsoft Entra ID Protection — risk-based identity security that detects user and sign-in risk and automates remediation. Covers risk detections, risk-based Conditional Access, self-remediation via MFA / secure password change, risky-user investigation, and streaming risk to Sentinel. WHEN: Entra ID Protection, identity risk policy, risky users, risky sign-ins, user risk policy, sign-in risk policy, risk-based Conditional Access, leaked credentials, anonymous IP detection, atypical travel, automate identity remediation, alert about leaked credentials, user flagged as risky, force password reset for compromised accounts, block sign-in when identity risk is high, EID P2 risk policy. DO NOT USE for on-prem AD attack detection (use defender-for-identity), CA policy authoring without risk signals (use conditional-access-mfa), or PIM activation (use azure-pim).
    0
    installs
  46. Microsoft Agent 365 · vinayaklatthe
    Guidance for managing AI agents at enterprise scale with Microsoft Agent 365 - the control plane that lets admins observe, govern, and secure every agent (Microsoft, Copilot Studio, and third-party) from a single registry, using Microsoft Entra Agent ID for identity, Microsoft Purview for data security, and Microsoft Defender for runtime threat protection. WHEN: Microsoft Agent 365, Agent 365, manage agents at scale, agent control plane, agent registry, agent map, observe govern secure agents, Entra Agent ID, agent identity lifecycle, third-party agent governance, secure AI agents tenant-wide, agent sprawl, agent inventory. DO NOT USE for Purview-only data controls on a single agent (use purview-agent-365-security) or end-user Copilot oversharing (use purview-copilot-oversharing).
    0
    installs
  47. Defender For Servers · vinayaklatthe
    Guidance for Microsoft Defender for Servers (Plan 1 and Plan 2) — server-specific protection in Microsoft Defender for Cloud. Covers plan selection, agentless vs agent-based scanning, MDE for Servers integration, file integrity monitoring (FIM via MDE), just-in-time VM access, vulnerability assessment, adaptive application controls, network hardening, and free data ingestion to Sentinel/Log Analytics. Applies to Azure VMs, Azure Arc-enabled servers (on-prem, AWS EC2, GCP Compute), and Azure VMSS. WHEN: Defender for Servers, MDE for Servers, server EDR, FIM, file integrity monitoring, JIT VM access, just-in-time access, agentless scanning servers, vulnerability assessment for VMs, hybrid server protection, Arc-enabled servers security, AWS EC2 in Defender for Cloud, GCP Compute in Defender for Cloud, server hardening Azure, Plan 1 vs Plan 2 servers. DO NOT USE for endpoint client devices (use defender-for-endpoint), generic Azure resource posture (use defender-for-cloud-hardening), or container hosts (use defe
    0
    installs
  48. Defender For Storage · vinayaklatthe
    Guidance for Microsoft Defender for Storage — threat protection for Azure Storage accounts (Blob, Files, Data Lake Gen2). Covers the v2 (per-storage-account) plan, on-upload malware scanning powered by Defender Antivirus, sensitive data threat detection (integrated with Purview classification), activity-based threat detection, override per storage account, exclusion of high-volume accounts, Event Grid integration for scan results, and cost controls (per-GB scan cap). WHEN: Defender for Storage, Azure Storage malware scan, Blob malware scanning, sensitive data threat detection, on-upload scan, Defender for Storage v2, Storage account threat protection, scan results Event Grid, Purview classification storage, malicious blob upload, exfiltration alert storage, untrusted upload scan. DO NOT USE for SQL/Cosmos DB protection (use defender-for-cloud-hardening), VM disk malware (use defender-for-servers agentless scan), or M365 SharePoint/OneDrive (use defender-for-office-365).
    0
    installs
  49. Purview Advanced Dlp · vinayaklatthe
    Guidance for advanced Microsoft Purview DLP capabilities - Adaptive Protection (risk-based DLP driven by Insider Risk), Exact Data Match, contextual conditions, and advanced Endpoint DLP egress controls. Covers dynamic, risk-adaptive enforcement and high-precision matching for mature programs. WHEN: advanced DLP, Adaptive Protection, risk-based DLP, Exact Data Match DLP, dynamic DLP enforcement, Insider Risk driven DLP, advanced Endpoint DLP, contextual DLP conditions, dynamic block actions.
    0
    installs
  50. Purview Customer Key · vinayaklatthe
    Guidance for Microsoft Purview Customer Key and Double Key Encryption (DKE) — customer-controlled encryption for service-side data (Customer Key for Exchange/SharePoint/OneDrive/Teams/Purview) and client-side double encryption for highly sensitive documents (DKE via sensitivity labels and a customer-hosted key service). Covers Azure Key Vault setup (HSM-backed, recoverable, soft-delete, purge protection, redundant regions), data encryption policies (DEPs) for M365 services, key rotation and revocation, DKE service deployment (containerized key release service), DKE label authoring, end-user experience trade-offs (no eDiscovery into DKE content), and decision criteria vs Microsoft-managed encryption. WHEN: Customer Key M365, BYOK Exchange, DKE Microsoft, double key encryption, customer-managed keys SharePoint OneDrive Teams, key rotation Customer Key, HYOK alternative, sovereignty encryption, regulator-controlled encryption, sensitivity label DKE. DO NOT USE for Azure resource CMK (use azure-key-vault), genera
    0
    installs
  51. Azure Ddos Protection · vinayaklatthe
    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform. Covers tier selection vs free Basic infrastructure protection, scope (VNet vs single IP), traffic profiling and mitigation policy auto-tuning, attack analytics and metrics, attack alerts to Sentinel, DDoS Rapid Response engagement, integration with Azure WAF and Front Door, cost-protection guarantee, mitigation reports for compliance, and per-region capacity planning. WHEN: Azure DDoS Protection, DDoS Network Protection, DDoS IP Protection, layer 3/4 DDoS, attack analytics Azure, DDoS rapid response, cost protection DDoS, DDoS metrics, mitigation report, simulate DDoS Azure. DO NOT USE for layer 7 / app-layer attack mitigation alone (use azure-waf), Azure Firewall design (use azure-firewall), or hybrid network DDoS via on-prem appliances.
    0
    installs
  52. Defender For Business · vinayaklatthe
    Guidance for Microsoft Defender for Business (MDB) — the SMB-segment endpoint security product (≤300 employees), bundled with Microsoft 365 Business Premium and available as a standalone SKU. Covers what's included vs MDE Plan 1/2 (next-gen AV, EDR with simplified configuration, ASR, automated investigation and response, vulnerability management, web content filtering, attack surface reduction, mobile threat defense add-on), wizard-driven onboarding, server add-on for SMB servers, the simplified portal experience vs full Defender XDR, transition path to MDE P2 / E5 as the org grows, and integration with Microsoft 365 Lighthouse for MSP delivery. WHEN: Defender for Business, MDB, SMB endpoint security, M365 Business Premium security, MDB server add-on, simplified EDR small business, MSP Defender for Business, M365 Lighthouse Defender, SMB upgrade to MDE Plan 2. DO NOT USE for enterprise EDR (use defender-for-endpoint), Defender XDR cross-product investigation (use defender-xdr), or Defender for Servers / Cloud
    0
    installs
  53. Defender For Cloud AI · vinayaklatthe
    Guidance for Microsoft Defender for Cloud — AI workload protection (AI-SPM and runtime threat detection for generative AI). Covers AI Security Posture Management (discovery of Azure OpenAI / Azure AI Foundry / Amazon Bedrock / Google Vertex AI resources, identification of grounding data exposure, model deployment posture), runtime threat detection on Azure OpenAI (prompt injection / jailbreak attempts, sensitive data leakage in prompts/responses, wallet abuse, credential leakage), integration with Azure AI Content Safety Prompt Shields, attack path analysis for AI workloads, alert investigation in Defender XDR, and pairing with Purview DSPM for AI (user side) and Azure AI Content Safety (model side). WHEN: Defender for Cloud AI, AI-SPM, AI workload protection, Azure OpenAI threat detection, prompt injection alert, jailbreak alert Azure OpenAI, AI wallet abuse, AI workload posture, Amazon Bedrock posture, Vertex AI posture, generative AI security Azure. DO NOT USE for end-user AI usage governance (use purview-
    0
    installs
  54. Defender For Endpoint · vinayaklatthe
    Guidance for Microsoft Defender for Endpoint (MDE) — enterprise endpoint security with next-gen AV, EDR, attack surface reduction (ASR), Defender Vulnerability Management, automated investigation and remediation (AIR), and live response. Covers Plan 1 vs Plan 2 selection, onboarding paths (Intune, Configuration Manager, GPO, scripts), ASR rule rollout in audit→block, EDR in block mode, tamper protection, device groups and RBAC, and response actions (isolate, restrict, live response). WHEN: Defender for Endpoint, MDE, MDE onboarding, endpoint EDR, attack surface reduction rules, ASR rules audit mode, next-gen antivirus policy, device isolation, endpoint vulnerability management, EDR block mode, tamper protection, onboard devices to Defender, live response, MDE Plan 1 vs Plan 2, security settings management, MDE for Linux, MDE for macOS, controlled folder access. DO NOT USE for non-endpoint Defender workloads (use defender-xdr for cross-workload, defender-for-cloud-hardening for Azure resources).
    0
    installs
  55. Defender For Identity · vinayaklatthe
    Guidance for Microsoft Defender for Identity (MDI) — identity threat detection (ITDR) across on-premises Active Directory, AD CS, AD FS, and Entra Connect using sensors. Covers sensor placement, prerequisites, posture assessments, and lateral-movement detection. WHEN: Defender for Identity, MDI, MDI sensors, detect lateral movement, on-prem AD threat detection, identity security posture, AD CS monitoring, ADCS abuse, domain controller sensor, detect Kerberoasting, DCSync, Golden Ticket, identity ITDR, honeytoken, gMSA Directory Service Account, suspicious LDAP, ESC1 ESC8. DO NOT USE when the goal is cloud identity protection in Entra ID (use entra-id-protection) or correlating cross-workload incidents (use defender-xdr).
    0
    installs
  56. Insider Risk Baseline · vinayaklatthe
    Guidance for establishing a Microsoft Purview Insider Risk Management (IRM) baseline - detecting and managing risky insider activity (data theft, leaks, policy violations) with privacy-by-design. Covers prerequisites, HR connector, policy templates, indicators, pseudonymisation, triage workflow, and Adaptive Protection integration. WHEN: Insider Risk Management, IRM, detect data theft by departing employee, insider threat, risky user activity, IRM policy templates, pseudonymization, Adaptive Protection, insider risk indicators, HR connector, departing user, separation of duties.
    0
    installs
  57. Intune App Protection · vinayaklatthe
    Guidance for Microsoft Intune app protection policies (MAM) — protecting corporate data inside mobile apps with or without device enrollment. Covers MAM-WE for BYOD vs APP on managed devices, data-relocation controls (cut/copy/paste, Save As, encryption), app PIN/biometric and offline grace, selective wipe of corporate data, and pairing with Conditional Access grant control 'Require app protection policy'. WHEN: Intune app protection policy, app protection policy, APP, MAM, MAM-WE, MAM without enrollment, protect data in mobile apps, BYOD data protection, selective wipe, restrict copy paste, app-based Conditional Access, manage apps without enrollment, Intune SDK apps. DO NOT USE for full device management (use intune-device-mgmt) or disk encryption (use bitlocker-design).
    0
    installs
  58. Macos Intune Baseline · vinayaklatthe
    Guidance for hardening macOS endpoints managed by Microsoft Intune — automated device enrollment via Apple Business Manager (ABM), platform single sign-on (PSSO) with Entra ID, FileVault disk encryption escrow, security configuration profiles (Gatekeeper, XProtect, system extensions allowlist, firewall, login window, Privacy Preferences Policy Control / PPPC), Microsoft Defender for Endpoint on macOS, app management (VPP / managed apps / shell scripts via Intune), patching strategy (managed software updates / DDM), Conditional Access compliance signal, and cross-platform identity model. WHEN: Mac Intune baseline, macOS hardening Intune, FileVault escrow, ABM Apple Business Manager, Platform SSO macOS, PSSO Entra, MDE on Mac, Gatekeeper Intune, system extensions Intune, PPPC Intune, macOS compliance Conditional Access. DO NOT USE for general Intune device management end-to-end (use intune-device-mgmt), MDE config alone (use defender-for-endpoint), or iOS device management.
    0
    installs
  59. Security Architecture · vinayaklatthe
    Guidance for designing security architecture using Zero Trust, the Microsoft Cybersecurity Reference Architectures (MCRA), Cloud Adoption Framework Secure methodology, and Well-Architected Security pillar. Covers the six Zero Trust pillars, defense-in-depth, and reference architecture alignment. WHEN: security architecture, Zero Trust design, MCRA, defense in depth, security reference architecture, CAF secure methodology, Well-Architected security pillar, end-to-end security design, security strategy, target state. DO NOT USE for tactical product configuration (use the product-specific skill) or for SOC tooling design (use sentinel / unified-secops-platform).
    0
    installs
  60. Azure Monitor Security · vinayaklatthe
    Guidance for the security-side use of Azure Monitor and Log Analytics — designing the workspace strategy that feeds Microsoft Sentinel and Defender for Cloud, choosing analytics vs basic vs auxiliary log tiers, retention and archive, table-level transformations to drop noise pre-ingestion, Data Collection Rules (DCRs) and Azure Monitor Agent (AMA), workspace topology (single vs regional vs sovereign), commitment tiers and cost control, customer-managed keys for the workspace, RBAC including table-level RBAC, integration with Sentinel (workspace requirements), and decommissioning legacy MMA. WHEN: Log Analytics workspace design, Azure Monitor security data, Sentinel workspace, log tier basic auxiliary, AMA Azure Monitor Agent, DCR data collection rule, drop columns ingestion transform, log retention archive, workspace CMK, table-level RBAC, log ingestion cost control. DO NOT USE for Sentinel detection authoring (use sentinel-detection-engineering), App Insights instrumentation (use appinsights-instrumentation)
    0
    installs
  61. Conditional Access Mfa · vinayaklatthe
    Guidance for Microsoft Entra Conditional Access (CA) and multifactor authentication — the Zero Trust policy engine that enforces grant/block decisions based on user, device, location, app, and risk signals. Covers a baseline 6-policy set, authentication strengths for phishing-resistant MFA, report-only rollout, break-glass exclusions, session controls, and policy lifecycle. WHEN: Conditional Access, MFA enforcement, require compliant device, block legacy authentication, Zero Trust access policy, phishing-resistant MFA, FIDO2, passkey, session controls, sign-in frequency, CA policy design, require MFA for admins, baseline CA policies, report-only mode, What If tool, exclude break-glass, named locations, app protection policy grant, terms of use. DO NOT USE for risk-based detection signal sources (use entra-id-protection) or PIM activation (use azure-pim).
    0
    installs
  62. Purview Data Lifecycle · vinayaklatthe
    Guidance for Microsoft Purview Data Lifecycle Management and Records Management - retention labels and policies to retain and delete content across Microsoft 365, plus declaring records. Covers retention strategy, adaptive vs static scopes, principle of precedence, disposition review, and regulatory records. WHEN: data lifecycle management, retention policy, retention label, records management, declare record, disposition review, adaptive scopes, retain and delete content, file plan, regulatory retention, immutable records.
    0
    installs
  63. Azure AI Content Safety · vinayaklatthe
    Guidance for Azure AI Content Safety — programmatic content moderation for text, images, multimodal, and generative AI guardrails. Covers Content Safety categories (hate, violence, sexual, self-harm) with severity levels, Prompt Shields for jailbreak and indirect prompt injection detection, groundedness detection (hallucination check vs grounding sources), protected material detection (text and code), custom categories, blocklists, Content Safety Studio for tuning, integration with Azure OpenAI as input/output filters (built-in plus custom), latency/cost trade-offs, agent guardrails, and deployment patterns (sidecar in app, integrated with Azure OpenAI). WHEN: Azure AI Content Safety, prompt shields, jailbreak detection, indirect prompt injection, groundedness check, protected material detection, content moderation, generative AI guardrails, harmful content categories, custom blocklist AI, agent guardrail. DO NOT USE for AI workload threat detection / SOC alerts (use defender-for-cloud-ai), end-user AI usage
    0
    installs
  64. Defender For Cloud Apps · vinayaklatthe
    Guidance for Microsoft Defender for Cloud Apps (MDA) — the CASB for SaaS discovery, app governance, session controls, and threat detection. Covers Cloud Discovery via Defender for Endpoint integration, OAuth app governance, Conditional Access App Control (reverse-proxy session policies), and SaaS security posture (SSPM). WHEN: Defender for Cloud Apps, MDA, CASB, shadow IT discovery, cloud app governance, OAuth app risk, session control, Conditional Access App Control, SaaS security posture management, SSPM, sanction or unsanction app, Cloud App Catalog, app connectors. DO NOT USE for IaaS / PaaS posture (use defender-for-cloud-hardening), endpoint EDR (use defender-for-endpoint), or DLP (use purview-dlp-policy).
    0
    installs
  65. Defender For Containers · vinayaklatthe
    Guidance for Microsoft Defender for Containers — Kubernetes and container security across AKS, Azure Arc-enabled Kubernetes, EKS, GKE, and OpenShift. Covers agentless discovery, agentless vulnerability assessment for images and running containers (powered by Microsoft Defender Vulnerability Management), runtime threat detection via the Defender sensor (eBPF on Linux), Kubernetes data plane hardening with Azure Policy / Gatekeeper, registry scanning for ACR / ECR / GAR, admission control, attack path analysis, and Sentinel integration. WHEN: Defender for Containers, AKS security, container runtime threat detection, Kubernetes admission control, image vulnerability scanning, ACR scan, EKS GKE security in Defender for Cloud, K8s posture, container attack path, Defender container sensor, Gatekeeper Azure Policy AKS, agentless container scan. DO NOT USE for VM/host hardening (use defender-for-servers), AKS networking design (use azure-network-security-design), or general AKS day-2 ops unrelated to security.
    0
    installs
  66. Defender For Office 365 · vinayaklatthe
    Guidance for Microsoft Defender for Office 365 (MDO) — protection for email and collaboration (Teams, SharePoint, OneDrive) against phishing, malware, spoofing, and business email compromise. Covers Plan 1 vs Plan 2 selection, preset security policies (Standard/Strict), Safe Links, Safe Attachments, anti-phishing impersonation protection, configuration analyzer drift detection, Submissions portal triage, Threat Explorer hunting, AIR, and attack simulation training. WHEN: Defender for Office 365, MDO, email security policy, Safe Links, Safe Attachments, anti-phishing, anti-spoofing, impersonation protection, preset security policies, Standard preset, Strict preset, configuration analyzer, phishing protection, attack simulation training, Threat Explorer, Submissions portal, tenant allow block list, BEC, business email compromise, DMARC, MDO Plan 1 vs Plan 2. DO NOT USE for endpoint protection (use defender-for-endpoint) or M365 oversharing (use purview-copilot-oversharing).
    0
    installs
  67. Entra Workload Identity · vinayaklatthe
    Guidance for Microsoft Entra workload identities — managed identities, service principals, and workload identity federation. Covers system-assigned vs user-assigned managed identity, federated credentials (GitHub Actions, Azure DevOps, Kubernetes, other OIDC issuers) to eliminate secrets, Workload Identities Premium (Conditional Access for workloads, risk detection, lifecycle reviews), credential hygiene (no client secrets where federation works), least-privilege RBAC, and integration with Defender for Cloud / Microsoft Entra Permissions Management. WHEN: managed identity, system-assigned identity, user-assigned identity, service principal hardening, workload identity federation, GitHub OIDC to Azure, Azure DevOps OIDC, AKS workload identity, kill client secrets, federated credential, Workload Identities Premium, Conditional Access for workloads, non-human identity governance, NHI, app registration hardening. DO NOT USE for user/human identity (use entra-id), permissions discovery across clouds (use entra-per
    0
    installs
  68. Security Copilot Agents · vinayaklatthe
    Guidance for Microsoft Security Copilot agents — autonomous, purpose-built AI agents (e.g., phishing triage, alert triage, conditional access optimization, vulnerability remediation) that work within Security Copilot. Covers available agents, identity/permissions, and supervision. WHEN: Security Copilot agents, autonomous SOC agent, phishing triage agent, alert triage agent, agent identity, supervise AI agent, agentic security, Copilot agent permissions, automate phishing triage, AI agent for SOC, autonomous alert triage, hands-off triage of high-volume alerts. DO NOT USE for basic Security Copilot setup, SCU provisioning, or promptbooks (use security-copilot).
    0
    installs
  69. Unified Secops Platform · vinayaklatthe
    Guidance for the Microsoft unified security operations platform that brings Microsoft Sentinel, Microsoft Defender XDR, Security Copilot, Threat Intelligence, and Microsoft Security Exposure Management together in the Microsoft Defender portal. Covers prerequisites, onboarding Sentinel, unified incident queue, advanced hunting across SIEM+XDR, and RBAC. WHEN: unified SecOps, onboard Sentinel to Defender portal, single SOC pane of glass, unified incident queue, connect Sentinel workspace to Defender XDR, exposure management, unified portal, merge Sentinel and Defender XDR, reduce context-switching for analysts, single pane of glass, move off the Azure Sentinel portal. DO NOT USE for Sentinel-only workspace design (use sentinel) or Defender XDR-only incident investigation (use defender-xdr).
    0
    installs
  70. Azure Security Benchmark · vinayaklatthe
    Guidance for the Microsoft Cloud Security Benchmark (MCSB) — Microsoft's canonical set of cloud security best-practice controls mapped to industry frameworks and monitored in Microsoft Defender for Cloud. Covers control domains, applying the benchmark, and compliance tracking. WHEN: Microsoft Cloud Security Benchmark, MCSB, Azure Security Benchmark, security baseline controls, CIS NIST mapping, Defender for Cloud regulatory compliance, cloud security best practices, security controls framework.
    0
    installs
  71. Agent Identity Governance · vinayaklatthe
    Guidance for governing the identities of AI agents and non-human identities (NHIs) — Microsoft 365 Copilot Studio agents, Microsoft Foundry agents, custom AI agents, and traditional service principals/managed identities — through their full lifecycle. Covers ownership and tagging, scoped permissions and consent (delegated vs application; Sites.Selected; mailbox-scoped Graph), credential hygiene (federated credentials, certificates, no secrets), Conditional Access for workloads, agent-level access reviews via Entra ID Governance, lifecycle workflows for agent decommissioning, audit (agent prompts, agent actions, agent identity sign-ins), incident response when an agent is compromised, and integration with Purview AI Hub for usage signals. WHEN: AI agent identity governance, non-human identity governance, NHI lifecycle, Copilot Studio agent identity, Foundry agent governance, agent service principal, scoped Graph permissions agent, agent access review, decommission AI agent, agent credential rotation, compromis
    0
    installs
  72. Azure App Service Security · vinayaklatthe
    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening, Key Vault references for secrets, and front-end WAF (Front Door / App Gateway). WHEN: App Service security, secure web app on Azure, Easy Auth, App Service managed identity, private endpoint web app, VNet integration, App Service TLS, Key Vault references, harden App Service, FTP disable, WAF in front of App Service, access restrictions. DO NOT USE for Azure Functions specifics only (similar but separate), AKS workloads (different platform), or VM-hosted web apps.
    0
    installs
  73. Cloud App Security Posture · vinayaklatthe
    Guidance for cloud and SaaS security posture management - combining Defender for Cloud CSPM (IaaS/PaaS) and Defender for Cloud Apps SSPM (SaaS) to assess and harden posture across cloud and SaaS apps. Covers Secure Score, MCSB, attack-path analysis, SSPM recommendations, and governance. WHEN: cloud security posture, SaaS security posture management, SSPM, CSPM, secure cloud apps, posture recommendations, harden SaaS configuration, app security posture, multicloud and SaaS hardening, harden Microsoft 365 SaaS settings, find misconfigured Salesforce or ServiceNow settings, SaaS app misconfiguration. DO NOT USE for IaaS/PaaS workload threat protection plans (use defender-for-cloud-hardening) or for SaaS threat detection only (use defender-for-cloud-apps).
    0
    installs
  74. Copilot For M365 Readiness · vinayaklatthe
    Guidance for safely deploying Microsoft 365 Copilot — end-to-end readiness covering oversharing remediation, SharePoint Advanced Management (SAM) restricted sites and content discovery, sensitivity label coverage, Purview DLP for Copilot, Restricted SharePoint Search (RSS) interim safeguard, site lifecycle and ownership, Copilot interaction auditing, Copilot in Defender XDR alerts, prompt-shield risks, licensing prerequisites, and a phased rollout that doesn't surface confidential data on day one. WHEN: M365 Copilot rollout, Copilot oversharing remediation, SAM, SharePoint Advanced Management, Restricted SharePoint Search, RSS Copilot, sensitivity labels Copilot, DLP for Copilot, Copilot audit, safe Copilot deployment, Copilot pilot, prevent Copilot data leakage. DO NOT USE for tenant-wide oversharing program design (use m365-oversharing), Purview DSPM for AI alone (use purview-dspm-ai), or Microsoft Foundry agent security (use microsoft-agent-365).
    0
    installs
  75. Entra Global Secure Access · vinayaklatthe
    Guidance for Microsoft Entra Global Secure Access (GSA) — Microsoft's Security Service Edge (SSE) combining Entra Internet Access (SWG/Secure Web Gateway) and Entra Private Access (ZTNA replacement for VPN). Covers client deployment (Windows, macOS, iOS, Android), traffic forwarding profiles (Microsoft, Internet, Private), Conditional Access for network traffic, source IP restoration, app discovery, Quick Access and per-app access for Private Access, connector deployment, branch site connectivity (IPSec), TLS inspection, and Universal CA integration. WHEN: Entra Global Secure Access, GSA, Microsoft SSE, Entra Internet Access, Entra Private Access, ZTNA Microsoft, replace VPN with ZTNA, secure web gateway Entra, Conditional Access on network, source IP restoration, Quick Access app, Private Access connector, branch IPSec to Microsoft, GSA client rollout. DO NOT USE for general Conditional Access policy design (use conditional-access-mfa), Azure VPN/ExpressRoute design, or third-party SSE (Zscaler/Netskope) con
    0
    installs
  76. Purview Agent 365 Security · vinayaklatthe
    Guidance for securing and governing AI agents (Microsoft 365 Copilot agents, Copilot Studio agents, and Security Copilot agents) with Microsoft Purview - applying DSPM for AI, DLP, sensitivity labels, Communication Compliance, and audit to agent data interactions and identities. WHEN: secure AI agents, govern Copilot agents, Purview for agents, agent data security, DLP for agents, audit agent interactions, Copilot Studio agent security, agent oversharing, agent compliance, agent identity governance.
    0
    installs
  77. Purview Records Management · vinayaklatthe
    Guidance for Microsoft Purview Records Management — declaring, managing, and disposing records across SharePoint, OneDrive, Exchange, and Teams. Covers retention labels with record / regulatory record options, file plan import, event-based retention (employee leaves, contract expires), disposition review (single- and multi-stage), proof of deletion / records of disposition, retention label policies vs auto-apply policies (KQL/sensitive info types/trainable classifiers), label-aware DLP, integration with Information Governance vs Records Management licensing, and role separation between records managers and admins. WHEN: records management Purview, file plan, retention label record, regulatory record, event-based retention, disposition review, record declaration SharePoint, immutable records, audit-proof deletion, file plan import. DO NOT USE for non-records data lifecycle (use purview-data-lifecycle), DLP policies (use purview-dlp-policy), or eDiscovery (use purview-ediscovery).
    0
    installs
  78. Purview Copilot Oversharing · vinayaklatthe
    Guidance for assessing and remediating oversharing before and during Microsoft 365 Copilot adoption, using SharePoint Advanced Management (SAM), sensitivity labels, restricted content discovery, and DLP for Copilot so Copilot only surfaces content users should access. Covers data access governance reports, EEEU cleanup, and ongoing governance. WHEN: Copilot oversharing, prepare data for Copilot, restrict Copilot access, SharePoint Advanced Management, data access governance, oversharing remediation, Copilot readiness data security, limit Copilot content, Copilot is surfacing files users should not see, too many people have access to SharePoint sites, tighten up permissions before Copilot rollout, how do I make SharePoint Copilot-ready. DO NOT USE when the goal is monitoring what sensitive data users are actively sending in AI prompts (use purview-dspm-ai).
    0
    installs
  79. Purview Data Classification · vinayaklatthe
    Guidance for Microsoft Purview data classification and sensitivity labels - sensitive information types (SITs), trainable classifiers, exact data match, and sensitivity label taxonomy with auto-labelling. Covers building a label taxonomy, picking detection methods, and rolling out auto-labelling in simulation. WHEN: data classification, sensitivity labels, sensitive information types, SIT, trainable classifier, exact data match EDM, auto-labelling, label taxonomy, classify data, information protection labels, MIP labels.
    0
    installs
  80. Azure Confidential Computing · vinayaklatthe
    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs). Covers Confidential VMs (AMD SEV-SNP, Intel TDX), Confidential containers on AKS (Kata + AMD SEV-SNP), confidential GPU VMs (NVIDIA H100 with TDX), Azure Key Vault Managed HSM and Premium with secure-key-release for confidential workloads, attestation (Microsoft Azure Attestation service), confidential ledger, scenarios (multi-party data sharing, regulated workload isolation, AI training on sensitive data), key-release policies tying secrets to attested TEE state, and decision criteria vs CMK/Customer Key. WHEN: Azure Confidential Computing, AMD SEV-SNP, Intel TDX, confidential VM, confidential AKS container, confidential GPU H100, Azure Attestation, secure key release, multi-party computation, confidential AI, encrypted memory Azure, hardware enclave Azure. DO NOT USE for general data-at-rest CMK (use azure-key-vault), application encryption SDK only, or non-Azure TEE design.
    0
    installs
  81. Defender For Cloud Hardening · vinayaklatthe
    Guidance for Microsoft Defender for Cloud — cloud security posture management (CSPM) and cloud workload protection (CWPP) across Azure, AWS, and GCP. Covers Foundational vs Defender CSPM, Secure Score, Defender plans (Servers, Storage, Containers, Databases, App Service, Key Vault, APIs, AI), agentless scanning, attack path analysis, and remediation prioritisation. WHEN: Defender for Cloud, CSPM, cloud workload protection, Secure Score, harden cloud posture, Defender plans, attack path analysis, multicloud security, remediate recommendations, cloud security hardening, improve Azure Secure Score, harden Azure subscription, protect VMs and containers, multicloud CSPM across AWS and GCP, cloud security graph. DO NOT USE for SaaS posture (use cloud-app-security-posture), Sentinel SIEM (use sentinel), or extending Azure to on-prem servers (use azure-arc).
    0
    installs
  82. Entra Permissions Management · vinayaklatthe
    Guidance for Microsoft Entra Permissions Management (CIEM) — discovers, right-sizes, and monitors permissions across Microsoft Azure, AWS, and Google Cloud. Covers cloud onboarding, the Permission Creep Index (PCI), generating least-privilege policies from observed activity, on-demand permission grants, and workload identity coverage. WHEN: Entra Permissions Management, CIEM, multicloud permissions, Permission Creep Index, PCI, right-size permissions, unused permissions, least privilege across AWS GCP Azure, cloud entitlement management, over-privileged workload identity, IAM right-sizing, multicloud IAM posture. DO NOT USE for Azure-only RBAC role choice (use azure-role-selector) or Defender for Cloud security posture (use defender-for-cloud-hardening).
    0
    installs
  83. Windows 11 Security Baseline · vinayaklatthe
    Guidance for the Windows 11 enterprise security baseline — Microsoft's recommended security settings deployed via Intune (Settings catalog / security baselines) or GPO. Covers core hardware-rooted controls (TPM 2.0, Secure Boot, virtualization-based security / VBS, Hypervisor-Protected Code Integrity / HVCI, Memory Integrity, Credential Guard, Local Security Authority protection), Windows LAPS (Microsoft's modern local admin password solution, replacement for legacy LAPS), Smart App Control, Personal Data Encryption (PDE), Windows Hello for Business deployment, controlled folder access, exploit protection, BitLocker baseline, app control with WDAC, removable storage controls, and integration with Intune compliance and Defender for Endpoint. WHEN: Windows 11 baseline, Windows security baseline, VBS HVCI Memory Integrity, Credential Guard, LSA protection, Windows LAPS, replace legacy LAPS, Smart App Control, WDAC, exploit protection, PDE Windows 11, Intune security baseline. DO NOT USE for endpoint EDR config (
    0
    installs
  84. Azure Network Security Design · vinayaklatthe
    Guidance for designing secure Azure network architecture — hub-spoke topology (or Virtual WAN), segmentation with NSGs/ASGs, private endpoints / Private Link for PaaS, egress through Azure Firewall, DDoS protection, WAF on Front Door/App Gateway, and centralised private DNS. Aligned to the Zero Trust network pillar. WHEN: Azure network security, hub spoke, Virtual WAN, network segmentation, NSG ASG design, private endpoint, Private Link, DDoS protection, secure virtual network, egress control, Zero Trust network, private connectivity design, Bastion, JIT VM access. DO NOT USE for the firewall itself (use azure-firewall), VM-level hardening (use defender-for-cloud-hardening), or Key Vault networking only (use azure-key-vault).
    0
    installs
  85. Purview Information Governance · vinayaklatthe
    Guidance for an end-to-end Microsoft Purview information governance / information protection strategy - sequencing classification, labelling, protection, lifecycle, and risk into a coherent program aligned to the Zero Trust data pillar. Covers maturity-based rollout sequencing, ownership, and metrics. WHEN: information governance, information protection strategy, data protection program, sequence Purview rollout, MIP strategy, protect and govern data end to end, Zero Trust data pillar program, Purview roadmap, data security maturity.
    0
    installs
  86. Sentinel Detection Engineering · vinayaklatthe
    Guidance for detection engineering in Microsoft Sentinel — building, testing, deploying, and maintaining analytics rules, hunting queries, and SOAR automation. Covers the Content Hub solution model, MITRE ATT&CK mapping, scheduled vs near-real-time (NRT) vs Fusion vs anomalies analytics, KQL detection patterns (joins, summarize, bin, materialize), entity mapping and incident enrichment, custom detections from Defender XDR vs Sentinel-only, automation rules, playbooks (Logic Apps), watchlists, threat intel matching, content as code with Azure DevOps / GitHub repositories integration, and detection lifecycle (validate → tune → version). WHEN: Sentinel analytics rule, KQL detection, MITRE mapping, Sentinel content hub, scheduled analytics, NRT rule, hunting query, Sentinel automation rule, Logic App playbook, custom detection, repositories Sentinel CI/CD, detection-as-code, watchlist, threat intel matching analytics, fusion alerts, anomalies, incident enrichment, entity mapping. DO NOT USE for Sentinel architect
    0
    installs
  87. Purview Insider Risk Management · vinayaklatthe
    Guidance for Microsoft Purview Insider Risk Management (IRM) — detect, investigate, and act on risky user activity (data theft by departing employees, intellectual property leaks, security policy violations) using signals from M365, Entra, Defender, Windows endpoints, HR systems, and Adaptive Protection. Covers policy templates (data theft by departing users, data leaks, security policy violations), HRIS connector setup, indicator selection, sequence detection, anomaly detection, alerts triage, case investigation with content explorer, integration with eDiscovery and Communication Compliance, Adaptive Protection's automatic DLP policy adjustment, privacy controls (pseudonymization), role separation, and tenant-allow-list. WHEN: insider risk management, IRM policy, data theft departing user, IP leak detection, HRIS connector Purview, Adaptive Protection, insider risk indicators, sequence detection Purview, IRM case investigation, IRM privacy controls, IRM pseudonymization, insider risk Sentinel. DO NOT USE for
    0
    installs
  88. Purview Communication Compliance · vinayaklatthe
    Guidance for Microsoft Purview Communication Compliance — detecting and remediating policy violations and risky/inappropriate messages across Exchange, Teams, Viva Engage, and connected platforms, including AI prompt risks. Covers policy design, privacy controls, and remediation workflow. WHEN: communication compliance, monitor messages, detect harassment or sensitive info in chat, code of conduct policy, regulatory communication monitoring, Teams message compliance, pseudonymization reviewers.
    0
    installs