Azure App Service Security - **name_fr:** Sécurité Azure App Service - **tl_en:** Harden App Service web apps and APIs — managed identity, Easy Auth, private endpoints, TLS, Key Vault, WAF - **tl_fr:** Durcir les apps et API App Service — identité managée, Easy Auth, points de terminaison privés, TLS, Key Vault, WAF - **creator:** @vinayaklatthe - **type:** Agent skill - **url:** https://github.com/vinayaklatthe/microsoft-security-skills - **cat:** Security - **kws:** azure, app service, hardening, managed identity, entra, key vault, waf, tls, easy auth - **license:** MIT **Description EN:** Curated by Skill Harbor — guidance for securing Azure App Service web apps and APIs: managed identity with least-privilege roles, Easy Auth with Microsoft Entra ID, network isolation (private endpoints + VNet integration), HTTPS/TLS hardening, Key Vault references for secrets, and a front-end WAF (Front Door / App Gateway) — with an exposure-pattern matrix (internal-only, public sensitive, public basic, partner API, background worker) and a rule of thumb for each. By @vinayaklatthe, listed here with credit to its creator. Honest caveats: planning guidance, not automated remediation — you apply the settings yourself; requires an Azure subscription (private endpoints, WAF and some hardening options are paid-tier features); not for Azure Functions, AKS or VM-hosted apps (the skill says so itself). Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh. **Description FR:** Sélectionné par Skill Harbor — conseils pour sécuriser les apps web et API Azure App Service : identité managée avec rôles moindre-privilège, Easy Auth avec Microsoft Entra ID, isolation réseau (points de terminaison privés + intégration VNet), durcissement HTTPS/TLS, références Key Vault pour les secrets, et un WAF en frontal (Front Door / App Gateway) — avec une matrice de patterns d'exposition (interne seul, public sensible, public basique, API partenaire, worker sans inbound) et une règle du pouce pour chacun. Crédit : @vinayaklatthe. Bémols honnêtes : des conseils de planification, pas une remédiation automatisée — vous appliquez les réglages vous-même ; nécessite un abonnement Azure (points de terminaison privés, WAF et certaines options de durcissement sont des fonctionnalités payantes) ; pas pour Azure Functions, AKS ou apps hébergées sur VM (le skill le précise lui-même). Skill Harbor ne vérifie jamais le code, examinez-le vous-même avant usage. Découvert via skills.sh. **Install prompt EN:** ``` Prerequisites: an Azure subscription and an App Service app/API to harden (private endpoints, WAF and some hardening options are paid-tier features); an agent with access to the Azure portal or CLI for applying settings Install "Azure App Service Security" for me. Give my agent the App Service hardening guidance — identity, Easy Auth, network isolation, TLS, secrets via Key Vault, WAF fronting — with the exposure-pattern matrix and per-pattern rules of thumb Repository: https://github.com/vinayaklatthe/microsoft-security-skills/blob/main/skills/azure-app-service-security/SKILL.md 1. Fetch the SKILL.md file for the vinayaklatthe-microsoft-security-skills-azure-app-service-security skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md into the agent's skills directory, in a folder named "vinayaklatthe-microsoft-security-skills-azure-app-service-security". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. apply the settings in Azure myself — this skill plans, it does not remediate). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me. ``` **Install prompt FR:** ``` Prérequis : un abonnement Azure et une app/API App Service à durcir (points de terminaison privés, WAF et certaines options de durcissement sont des fonctionnalités payantes) ; un agent avec accès au portail Azure ou à la CLI pour appliquer les réglages Installe-moi « Sécurité Azure App Service ». Donne à mon agent les conseils de durcissement App Service — identité, Easy Auth, isolation réseau, TLS, secrets via Key Vault, frontal WAF — avec la matrice de patterns d'exposition et les règles du pouce par pattern Dépôt : https://github.com/vinayaklatthe/microsoft-security-skills/blob/main/skills/azure-app-service-security/SKILL.md 1. Récupère le fichier SKILL.md du skill vinayaklatthe-microsoft-security-skills-azure-app-service-security depuis le dépôt dans un dossier temporaire et résume en une ou deux phrases ce qu'il fait. 2. Contrôle de sécurité : examine le SKILL.md pour tout contenu suspect (appels réseau inattendus, commandes shell, récolte d'identifiants). Ce dépôt ne doit contenir aucun secret dans le code ; les identifiants passent uniquement par le coffre sécurisé, les hôtes autorisés sont déclarés dans le SKILL.md. Vérifie que c'est bien le cas ; STOP sur le moindre signal d'alerte et préviens-moi. 3. Installe-le comme skill : copie SKILL.md dans le répertoire des skills de l'agent, dans un dossier nommé « vinayaklatthe-microsoft-security-skills-azure-app-service-security ». 4. Vérifie sans aucun appel réseau : frontmatter valide, fichiers en place. 5. Indique ce qui a été installé, où, et ce qu'il me reste à faire moi-même (p. ex. appliquer les réglages dans Azure moi-même — ce skill planifie, il ne remédie pas). GitHub est optionnel : si j'ai un compte GitHub ou la CLI gh, tu peux l'utiliser ; sinon l'accès public suffit. Ne jamais l'exiger sauf si c'est dans les prérequis ci-dessus. Règles : ne touche à rien en dehors du dossier temporaire et de la cible d'installation. Si quelque chose semble anormal, arrête-toi et demande-moi. ``` ---
Harden App Service web apps and APIs — managed identity, Easy Auth, private endpoints, TLS, Key Vault, WAF - **tl_fr:** Durcir les apps et API App Service — identité managée, Easy Auth, points de terminaison privés, TLS, Key Vault, WAF - **creator:** @vinayaklatthe - **type:** Agent skill - **url:** https://github.com/vinayaklatthe/microsoft-security-skills - **cat:** Security - **kws:** azure, app service, hardening, managed identity, entra, key vault, waf, tls, easy auth - **license:** MIT **Description EN:** Curated by Skill Harbor — guidance for securing Azure App Service web apps and APIs: managed identity with least-privilege roles, Easy Auth with Microsoft Entra ID, network isolation (private endpoints + VNet integration), HTTPS/TLS hardening, Key Vault references for secrets, and a front-end WAF (Front Door / App Gateway) — with an exposure-pattern matrix (internal-only, public sensitive, public basic, partner API, background worker) and a rule of thumb for each. By @vinayaklatthe, listed here with credit to its creator. Honest caveats: planning guidance, not automated remediation — you apply the settings yourself; requires an Azure subscription (private endpoints, WAF and some hardening options are paid-tier features); not for Azure Functions, AKS or VM-hosted apps (the skill says so itself). Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh. **Description FR:** Sélectionné par Skill Harbor — conseils pour sécuriser les apps web et API Azure App Service : identité managée avec rôles moindre-privilège, Easy Auth avec Microsoft Entra ID, isolation réseau (points de terminaison privés + intégration VNet), durcissement HTTPS/TLS, références Key Vault pour les secrets, et un WAF en frontal (Front Door / App Gateway) — avec une matrice de patterns d'exposition (interne seul, public sensible, public basique, API partenaire, worker sans inbound) et une règle du pouce pour chacun. Crédit : @vinayaklatthe. Bémols honnêtes : des conseils de planification, pas une remédiation automatisée — vous appliquez les réglages vous-même ; nécessite un abonnement Azure (points de terminaison privés, WAF et certaines options de durcissement sont des fonctionnalités payantes) ; pas pour Azure Functions, AKS ou apps hébergées sur VM (le skill le précise lui-même). Skill Harbor ne vérifie jamais le code, examinez-le vous-même avant usage. Découvert via skills.sh. **Install prompt EN:** ``` Prerequisites: an Azure subscription and an App Service app/API to harden (private endpoints, WAF and some hardening options are paid-tier features); an agent with access to the Azure portal or CLI for applying settings Install "Azure App Service Security" for me. Give my agent the App Service hardening guidance — identity, Easy Auth, network isolation, TLS, secrets via Key Vault, WAF fronting — with the exposure-pattern matrix and per-pattern rules of thumb Repository: https://github.com/vinayaklatthe/microsoft-security-skills/blob/main/skills/azure-app-service-security/SKILL.md 1. Fetch the SKILL.md file for the vinayaklatthe-microsoft-security-skills-azure-app-service-security skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md into the agent's skills directory, in a folder named "vinayaklatthe-microsoft-security-skills-azure-app-service-security". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. apply the settings in Azure myself — this skill plans, it does not remediate). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me. ``` **Install prompt FR:** ``` Prérequis : un abonnement Azure et une app/API App Service à durcir (points de terminaison privés, WAF et certaines options de durcissement sont des fonctionnalités payantes) ; un agent avec accès au portail Azure ou à la CLI pour appliquer les réglages Installe-moi « Sécurité Azure App Service ». Donne à mon agent les conseils de durcissement App Service — identité, Easy Auth, isolation réseau, TLS, secrets via Key Vault, frontal WAF — avec la matrice de patterns d'exposition et les règles du pouce par pattern Dépôt : https://github.com/vinayaklatthe/microsoft-security-skills/blob/main/skills/azure-app-service-security/SKILL.md 1. Récupère le fichier SKILL.md du skill vinayaklatthe-microsoft-security-skills-azure-app-service-security depuis le dépôt dans un dossier temporaire et résume en une ou deux phrases ce qu'il fait. 2. Contrôle de sécurité : examine le SKILL.md pour tout contenu suspect (appels réseau inattendus, commandes shell, récolte d'identifiants). Ce dépôt ne doit contenir aucun secret dans le code ; les identifiants passent uniquement par le coffre sécurisé, les hôtes autorisés sont déclarés dans le SKILL.md. Vérifie que c'est bien le cas ; STOP sur le moindre signal d'alerte et préviens-moi. 3. Installe-le comme skill : copie SKILL.md dans le répertoire des skills de l'agent, dans un dossier nommé « vinayaklatthe-microsoft-security-skills-azure-app-service-security ». 4. Vérifie sans aucun appel réseau : frontmatter valide, fichiers en place. 5. Indique ce qui a été installé, où, et ce qu'il me reste à faire moi-même (p. ex. appliquer les réglages dans Azure moi-même — ce skill planifie, il ne remédie pas). GitHub est optionnel : si j'ai un compte GitHub ou la CLI gh, tu peux l'utiliser ; sinon l'accès public suffit. Ne jamais l'exiger sauf si c'est dans les prérequis ci-dessus. Règles : ne touche à rien en dehors du dossier temporaire et de la cible d'installation. Si quelque chose semble anormal, arrête-toi et demande-moi. ``` ---
- What
- Harden App Service web apps and APIs — managed identity, Easy Auth, private endpoints, TLS, Key Vault, WAF - **tl_fr:** Durcir les apps et API App Service — identité managée, Easy Auth, points de terminaison privés, TLS, Key Vault, WAF - **creator:** @vinayaklatthe - **type:** Agent skill - **url:** https://github.com/vinayaklatthe/microsoft-security-skills - **cat:** Security - **kws:** azure, app service, hardening, managed identity, entra, key vault, waf, tls, easy auth - **license:** MIT **Description EN:** Curated by Skill Harbor — guidance for securing Azure App Service web apps and APIs: managed identity with least-privilege roles, Easy Auth with Microsoft Entra ID, network isolation (private endpoints + VNet integration), HTTPS/TLS hardening, Key Vault references for secrets, and a front-end WAF (Front Door / App Gateway) — with an exposure-pattern matrix (internal-only, public sensitive, public basic, partner API, background worker) and a rule of thumb for each. By @vinayaklatthe, listed here with credit to its creator. Honest caveats: planning guidance, not automated remediation — you apply the settings yourself; requires an Azure subscription (private endpoints, WAF and some hardening options are paid-tier features); not for Azure Functions, AKS or VM-hosted apps (the skill says so itself). Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh. **Description FR:** Sélectionné par Skill Harbor — conseils pour sécuriser les apps web et API Azure App Service : identité managée avec rôles moindre-privilège, Easy Auth avec Microsoft Entra ID, isolation réseau (points de terminaison privés + intégration VNet), durcissement HTTPS/TLS, références Key Vault pour les secrets, et un WAF en frontal (Front Door / App Gateway) — avec une matrice de patterns d'exposition (interne seul, public sensible, public basique, API partenaire, worker sans inbound) et une règle du pouce pour chacun. Crédit : @vinayaklatthe. Bémols honnêtes : des conseils de planification, pas une remédiation automatisée — vous appliquez les réglages vous-même ; nécessite un abonnement Azure (points de terminaison privés, WAF et certaines options de durcissement sont des fonctionnalités payantes) ; pas pour Azure Functions, AKS ou apps hébergées sur VM (le skill le précise lui-même). Skill Harbor ne vérifie jamais le code, examinez-le vous-même avant usage. Découvert via skills.sh. **Install prompt EN:** ``` Prerequisites: an Azure subscription and an App Service app/API to harden (private endpoints, WAF and some hardening options are paid-tier features); an agent with access to the Azure portal or CLI for applying settings Install "Azure App Service Security" for me. Give my agent the App Service hardening guidance — identity, Easy Auth, network isolation, TLS, secrets via Key Vault, WAF fronting — with the exposure-pattern matrix and per-pattern rules of thumb Repository: https://github.com/vinayaklatthe/microsoft-security-skills/blob/main/skills/azure-app-service-security/SKILL.md 1. Fetch the SKILL.md file for the vinayaklatthe-microsoft-security-skills-azure-app-service-security skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md into the agent's skills directory, in a folder named "vinayaklatthe-microsoft-security-skills-azure-app-service-security". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. apply the settings in Azure myself — this skill plans, it does not remediate). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me. ``` **Install prompt FR:** ``` Prérequis : un abonnement Azure et une app/API App Service à durcir (points de terminaison privés, WAF et certaines options de durcissement sont des fonctionnalités payantes) ; un agent avec accès au portail Azure ou à la CLI pour appliquer les réglages Installe-moi « Sécurité Azure App Service ». Donne à mon agent les conseils de durcissement App Service — identité, Easy Auth, isolation réseau, TLS, secrets via Key Vault, frontal WAF — avec la matrice de patterns d'exposition et les règles du pouce par pattern Dépôt : https://github.com/vinayaklatthe/microsoft-security-skills/blob/main/skills/azure-app-service-security/SKILL.md 1. Récupère le fichier SKILL.md du skill vinayaklatthe-microsoft-security-skills-azure-app-service-security depuis le dépôt dans un dossier temporaire et résume en une ou deux phrases ce qu'il fait. 2. Contrôle de sécurité : examine le SKILL.md pour tout contenu suspect (appels réseau inattendus, commandes shell, récolte d'identifiants). Ce dépôt ne doit contenir aucun secret dans le code ; les identifiants passent uniquement par le coffre sécurisé, les hôtes autorisés sont déclarés dans le SKILL.md. Vérifie que c'est bien le cas ; STOP sur le moindre signal d'alerte et préviens-moi. 3. Installe-le comme skill : copie SKILL.md dans le répertoire des skills de l'agent, dans un dossier nommé « vinayaklatthe-microsoft-security-skills-azure-app-service-security ». 4. Vérifie sans aucun appel réseau : frontmatter valide, fichiers en place. 5. Indique ce qui a été installé, où, et ce qu'il me reste à faire moi-même (p. ex. appliquer les réglages dans Azure moi-même — ce skill planifie, il ne remédie pas). GitHub est optionnel : si j'ai un compte GitHub ou la CLI gh, tu peux l'utiliser ; sinon l'accès public suffit. Ne jamais l'exiger sauf si c'est dans les prérequis ci-dessus. Règles : ne touche à rien en dehors du dossier temporaire et de la cible d'installation. Si quelque chose semble anormal, arrête-toi et demande-moi. ``` ---
- Cost
- Free
- Needs
- an Azure subscription and an App Service app/API to harden (private endpoints, WAF and some hardening options are paid-tier features); an agent with access to the Azure portal or CLI for applying settings
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — guidance for securing Azure App Service web apps and APIs: managed identity with least-privilege roles, Easy Auth with Microsoft Entra ID, network isolation (private endpoints + VNet integration), HTTPS/TLS hardening, Key Vault references for secrets, and a front-end WAF (Front Door / App Gateway) — with an exposure-pattern matrix (internal-only, public sensitive, public basic, partner API, background worker) and a rule of thumb for each. By @vinayaklatthe, listed here with credit to its creator. Honest caveats: planning guidance, not automated remediation — you apply the settings yourself; requires an Azure subscription (private endpoints, WAF and some hardening options are paid-tier features); not for Azure Functions, AKS or VM-hosted apps (the skill says so itself). Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: an Azure subscription and an App Service app/API to harden (private endpoints, WAF and some hardening options are paid-tier features); an agent with access to the Azure portal or CLI for applying settings Install "Azure App Service Security" for me. Give my agent the App Service hardening guidance — identity, Easy Auth, network isolation, TLS, secrets via Key Vault, WAF fronting — with the exposure-pattern matrix and per-pattern rules of thumb Repository: https://github.com/vinayaklatthe/microsoft-security-skills/blob/main/skills/azure-app-service-security/SKILL.md 1. Fetch the SKILL.md file for the vinayaklatthe-microsoft-security-skills-azure-app-service-security skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md into the agent's skills directory, in a folder named "vinayaklatthe-microsoft-security-skills-azure-app-service-security". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. apply the settings in Azure myself — this skill plans, it does not remediate). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.