Azure Governance Baseline
$2.99OfficialUse when applying or auditing an Azure landing-zone baseline: management groups, Azure Policy, RBAC, Defender for Cloud, budgets and Log Analytics.
What you get
- โ8-step procedure
- โRunnable Shell / Terraform / Kusto included
- โ7-point quality checklist
- โ9 pitfalls to avoid
- โInstalls into 6 tools
- Version
- v1 โ
- Last updated
- today
- Length
- 12 min read
- Requires
- Best with a strong model (Claude Opus 5)
Works in: Claude Code, Codex, Cline, opencode, OpenClaw, Hermes ยท Built for large codebases
What you'll need to set up
Fiddly setup โ follow closely ยท 45-90 minProvision an Azure AD (Entra ID) service principal that holds Owner or an equivalent role-bundle at the Tenant Root Management Group, register the Microsoft.Management / Microsoft.PolicyInsights / Microsoft.Security / Microsoft.CostManagement resource providers, install Azure CLI with the resource-graph and costmanagement extensions, and export the tenant, subscription and Entra group object IDs the skill's commands interpolate.
AZURE_TENANT_IDAZURE_CLIENT_IDAZURE_CLIENT_SECRETAZURE_SUBSCRIPTION_IDTENANT_IDSUB_IDPreview
When to use
Invoke when the request touches the Azure governance plane rather than a single workload:
- "Stand up a landing zone", "build our management group hierarchy", "apply the ALZ baseline".
- "Enforce Azure Policy" โ allowed regions, mandatory tags, deny public blob/SQL, deny unmanaged disks.
- "Enable Defender for Cloud everywhere", "raise our Secure Score", "we failed a CIS/NIST audit", or "we have no cost visibility" โ budgets, forecast alerts, cost exports, Log Analytics ingestion overrun.
- "Prove compliance" โ evidence from Azure Policy compliance state vs MCSB / CIS 2.0 / NIST 800-53 R5 / ISO 27001.
- Anything mentioning
az account management-group,az policy, `az se
โฆ
๐ Buy once ($2.99) to unlock the full playbook, download it, and install it in every tool you use.