# vinayaklatthe

> Open-source publisher. Listings imported from github.com/vinayaklatthe — credited to the original author with their license.

- **Listings:** 49
- **Total installs:** 0
- **Profile:** https://agentstack.voostack.com/s/vinayaklatthe
- **Website:** https://github.com/vinayaklatthe

## Published listings

- [Defender Easm](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-defender-easm) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-defender-easm`
  Guidance for Microsoft Defender External Attack Surface Management (Defender EASM) — discovers and inventories an organization's internet-facing assets (domains, hosts, IPs, SSL certs, ASNs, web pages, contacts) from the outside-in. Covers seed-based discovery, attack surface insights (CVEs, expiring certs, deprecated tech, unsanctioned cloud), labels and groups, integration with Defender for Clo…
- [Iac Security](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-iac-security) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-iac-security`
  Guidance for securing Infrastructure-as-Code (Bicep, ARM, Terraform, and ACI/Container) pipelines on Azure — shift-left scanning, policy-as-code, secret hygiene, identity for pipelines, drift detection, and supply chain. Covers Microsoft Defender for Cloud DevOps Security (GitHub / Azure DevOps connectors), Microsoft Security DevOps (MSDO) extension, Bicep linter and template specs, Terraform bes…
- [Entra Verified Id](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-entra-verified-id) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-entra-verified-id`
  Guidance for Microsoft Entra Verified ID — verifiable credentials issuance and verification platform based on open standards (W3C Verifiable Credentials, DIDs, OpenID4VC). Covers issuer setup (tenant configuration, DID registration, signing key in Key Vault), credential schema design, rules and display files, issuance flows (QR / deep link), verification flows, Face Check biometric matching, inte…
- [Api Security Design](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-api-security-design) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-api-security-design`
  Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API Security Top 10 and Azure API Management. WHEN: API security design, secure API, OWASP API Top 10, API authentication, API gateway security, rate limiting, validate JWT, protect backend API, API Manag…
- [Defender For Cloud Hardening](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-defender-for-cloud-hardening) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-defender-for-cloud-hardening`
  Guidance for Microsoft Defender for Cloud — cloud security posture management (CSPM) and cloud workload protection (CWPP) across Azure, AWS, and GCP. Covers Foundational vs Defender CSPM, Secure Score, Defender plans (Servers, Storage, Containers, Databases, App Service, Key Vault, APIs, AI), agentless scanning, attack path analysis, and remediation prioritisation. WHEN: Defender for Cloud, CSPM,…
- [Azure Bastion Jit](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-azure-bastion-jit) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-azure-bastion-jit`
  Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access. Covers Bastion SKU selection (Developer / Basic / Standard / Premium), IP-based and shareable-link connections, native client (RDP/SSH from local machine via az CLI), session recording (Premium), private-only deployment, JIT request workflow and policy, RBAC for con…
- [Defender For Apis](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-defender-for-apis) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-defender-for-apis`
  Guidance for Microsoft Defender for APIs — a Defender for Cloud plan that discovers, prioritizes by risk, and protects APIs published in Azure API Management against threats and abuse. Covers onboarding, security findings, and threat detection. WHEN: Defender for APIs, API threat protection, secure APIs in API Management, API security posture, detect API abuse, onboard APIs to Defender, API attac…
- [Entra Permissions Management](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-entra-permissions-management) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-entra-permissions-management`
  Guidance for Microsoft Entra Permissions Management (CIEM) — discovers, right-sizes, and monitors permissions across Microsoft Azure, AWS, and Google Cloud. Covers cloud onboarding, the Permission Creep Index (PCI), generating least-privilege policies from observed activity, on-demand permission grants, and workload identity coverage. WHEN: Entra Permissions Management, CIEM, multicloud permissio…
- [Insider Risk Baseline](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-insider-risk-baseline) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-insider-risk-baseline`
  Guidance for establishing a Microsoft Purview Insider Risk Management (IRM) baseline - detecting and managing risky insider activity (data theft, leaks, policy violations) with privacy-by-design. Covers prerequisites, HR connector, policy templates, indicators, pseudonymisation, triage workflow, and Adaptive Protection integration. WHEN: Insider Risk Management, IRM, detect data theft by departin…
- [Azure Role Selector](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-azure-role-selector) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-azure-role-selector`
  Guidance for selecting the right Azure RBAC role with least privilege - mapping required actions to built-in roles, deciding when a custom role is needed, scoping assignments correctly, and choosing between control-plane and data-plane roles. Covers scope levels (management group → resource), groups vs direct assignment, and PIM for privileged roles. WHEN: which Azure role, least privilege role,…
- [Compliance Manager](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-compliance-manager) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-compliance-manager`
  Guidance for Microsoft Purview Compliance Manager — continuous compliance posture across Microsoft and non-Microsoft assets, mapped to 360+ regulatory templates (ISO 27001/27018/27701, SOC 2, NIST 800-53/171/CSF, PCI DSS, HIPAA, GDPR, FedRAMP, IRAP, Essential Eight, DORA, EU AI Act, etc.). Covers compliance score, improvement actions (Microsoft-managed vs customer-managed), evidence collection, a…
- [Conditional Access Mfa](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-conditional-access-mfa) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-conditional-access-mfa`
  Guidance for Microsoft Entra Conditional Access (CA) and multifactor authentication — the Zero Trust policy engine that enforces grant/block decisions based on user, device, location, app, and risk signals. Covers a baseline 6-policy set, authentication strengths for phishing-resistant MFA, report-only rollout, break-glass exclusions, session controls, and policy lifecycle. WHEN: Conditional Acce…
- [Azure Arc](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-azure-arc) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-azure-arc`
  Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management. Covers Arc-enabled servers onboarding, extending Defender for Cloud and Azure Policy to non-Azure machines, and Arc-enabled Kubernetes. WHEN: Azure Arc, manage on-prem servers from Azure, hybrid managem…
- [Entra External Id](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-entra-external-id) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-entra-external-id`
  Guidance for Microsoft Entra External ID — the unified customer identity and access management (CIAM) and external collaboration platform that replaces Azure AD B2C (for new tenants) and consolidates B2B guest scenarios. Covers external tenant creation, user flows (sign-up/sign-in, password reset), custom branding, identity providers (Google, Facebook, Apple, SAML/OIDC), email OTP and passkey sup…
- [Copilot For M365 Readiness](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-copilot-for-m365-readiness) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-copilot-for-m365-readiness`
  Guidance for safely deploying Microsoft 365 Copilot — end-to-end readiness covering oversharing remediation, SharePoint Advanced Management (SAM) restricted sites and content discovery, sensitivity label coverage, Purview DLP for Copilot, Restricted SharePoint Search (RSS) interim safeguard, site lifecycle and ownership, Copilot interaction auditing, Copilot in Defender XDR alerts, prompt-shield…
- [Azure App Service Security](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-azure-app-service-security) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-azure-app-service-security`
  Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening, Key Vault references for secrets, and front-end WAF (Front Door / App Gateway). WHEN: App Service security, secure web app on Azure, Easy Auth, App Service managed identity, private endpoint web app, VNe…
- [Compromise Recovery](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-compromise-recovery) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-compromise-recovery`
  Guidance for responding to and recovering from a significant identity/tenant compromise - regaining administrative control, evicting the adversary in a single coordinated action, and hardening to prevent reentry. Covers trusted foundation (PAW), containment, eviction, identity recovery (krbtgt, federation), and post-eviction hardening. WHEN: compromise recovery, incident response, regain control…
- [Azure Pricing](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-azure-pricing) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-azure-pricing`
  Guidance for estimating and reasoning about the cost of Azure security services — using the Azure Pricing Calculator, understanding key cost drivers (Sentinel ingestion, Defender plans, Key Vault operations), and cost-optimization levers. WHEN: Azure security pricing, estimate cost, Sentinel cost, Defender for Cloud pricing, pricing calculator, cost drivers, optimize security spend, ingestion cos…
- [Azure Waf](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-azure-waf) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-azure-waf`
  Guidance for Azure Web Application Firewall — deployed on Azure Front Door (global, edge-tier) or Azure Application Gateway (regional, integrated with backend pools). Covers WAF policy design with managed rule sets (Microsoft Default Rule Set, Bot Manager, OWASP CRS), custom rules (rate limit, geo-block, IP allow/deny), exclusion design (the long-tail tuning task that decides whether WAF stays in…
- [Defender For Identity](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-defender-for-identity) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-defender-for-identity`
  Guidance for Microsoft Defender for Identity (MDI) — identity threat detection (ITDR) across on-premises Active Directory, AD CS, AD FS, and Entra Connect using sensors. Covers sensor placement, prerequisites, posture assessments, and lateral-movement detection. WHEN: Defender for Identity, MDI, MDI sensors, detect lateral movement, on-prem AD threat detection, identity security posture, AD CS mo…
- [Entra Id Protection](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-entra-id-protection) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-entra-id-protection`
  Guidance for Microsoft Entra ID Protection — risk-based identity security that detects user and sign-in risk and automates remediation. Covers risk detections, risk-based Conditional Access, self-remediation via MFA / secure password change, risky-user investigation, and streaming risk to Sentinel. WHEN: Entra ID Protection, identity risk policy, risky users, risky sign-ins, user risk policy, sig…
- [Azure Security Benchmark](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-azure-security-benchmark) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-azure-security-benchmark`
  Guidance for the Microsoft Cloud Security Benchmark (MCSB) — Microsoft's canonical set of cloud security best-practice controls mapped to industry frameworks and monitored in Microsoft Defender for Cloud. Covers control domains, applying the benchmark, and compliance tracking. WHEN: Microsoft Cloud Security Benchmark, MCSB, Azure Security Benchmark, security baseline controls, CIS NIST mapping, D…
- [Azure Monitor Security](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-azure-monitor-security) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-azure-monitor-security`
  Guidance for the security-side use of Azure Monitor and Log Analytics — designing the workspace strategy that feeds Microsoft Sentinel and Defender for Cloud, choosing analytics vs basic vs auxiliary log tiers, retention and archive, table-level transformations to drop noise pre-ingestion, Data Collection Rules (DCRs) and Azure Monitor Agent (AMA), workspace topology (single vs regional vs sovere…
- [Defender For Containers](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-defender-for-containers) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-defender-for-containers`
  Guidance for Microsoft Defender for Containers — Kubernetes and container security across AKS, Azure Arc-enabled Kubernetes, EKS, GKE, and OpenShift. Covers agentless discovery, agentless vulnerability assessment for images and running containers (powered by Microsoft Defender Vulnerability Management), runtime threat detection via the Defender sensor (eBPF on Linux), Kubernetes data plane harden…
- [Defender For Iot](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-defender-for-iot) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-defender-for-iot`
  Guidance for Microsoft Defender for IoT — agentless OT/ICS network detection and response for industrial environments, plus enterprise IoT (EIoT) protection integrated with Defender XDR. Covers OT sensor deployment (physical/virtual, SPAN/TAP), Purdue model alignment, on-premises management console, cloud-managed sensors, EIoT (printers, cameras, VoIP) discovered through MDE, asset inventory, vul…
- [Agent Identity Governance](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-agent-identity-governance) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-agent-identity-governance`
  Guidance for governing the identities of AI agents and non-human identities (NHIs) — Microsoft 365 Copilot Studio agents, Microsoft Foundry agents, custom AI agents, and traditional service principals/managed identities — through their full lifecycle. Covers ownership and tagging, scoped permissions and consent (delegated vs application; Sites.Selected; mailbox-scoped Graph), credential hygiene (…
- [Azure Ai Content Safety](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-azure-ai-content-safety) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-azure-ai-content-safety`
  Guidance for Azure AI Content Safety — programmatic content moderation for text, images, multimodal, and generative AI guardrails. Covers Content Safety categories (hate, violence, sexual, self-harm) with severity levels, Prompt Shields for jailbreak and indirect prompt injection detection, groundedness detection (hallucination check vs grounding sources), protected material detection (text and c…
- [Defender For Cloud Ai](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-defender-for-cloud-ai) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-defender-for-cloud-ai`
  Guidance for Microsoft Defender for Cloud — AI workload protection (AI-SPM and runtime threat detection for generative AI). Covers AI Security Posture Management (discovery of Azure OpenAI / Azure AI Foundry / Amazon Bedrock / Google Vertex AI resources, identification of grounding data exposure, model deployment posture), runtime threat detection on Azure OpenAI (prompt injection / jailbreak att…
- [Bitlocker Design](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-bitlocker-design) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-bitlocker-design`
  Guidance for designing BitLocker drive encryption for Windows endpoints managed via Microsoft Intune — encryption policy, silent enablement, recovery key escrow to Entra ID, TPM, pre-boot authentication trade-offs, and BitLocker To Go for removable media. Covers compliance integration with Conditional Access and recovery workflows. WHEN: BitLocker, disk encryption, Windows encryption policy, BitL…
- [Defender Xdr](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-defender-xdr) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-defender-xdr`
  Guidance for Microsoft Defender XDR — the unified extended detection and response suite that correlates signals across endpoints, identities, email, and cloud apps into prioritised incidents with attack-graph context. Covers onboarding the four core workloads, incident investigation, advanced hunting in KQL, custom detection rules, automatic attack disruption, AIR, and unified RBAC. WHEN: Microso…
- [Defender For Cloud Apps](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-defender-for-cloud-apps) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-defender-for-cloud-apps`
  Guidance for Microsoft Defender for Cloud Apps (MDA) — the CASB for SaaS discovery, app governance, session controls, and threat detection. Covers Cloud Discovery via Defender for Endpoint integration, OAuth app governance, Conditional Access App Control (reverse-proxy session policies), and SaaS security posture (SSPM). WHEN: Defender for Cloud Apps, MDA, CASB, shadow IT discovery, cloud app gov…
- [Azure Policy](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-azure-policy) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-azure-policy`
  Guidance for Azure Policy — enforcing and auditing governance and security guardrails at scale across Azure with definitions, initiatives, assignments, and remediation tasks. Covers effects (Audit, Deny, Append, Modify, DeployIfNotExists, AuditIfNotExists), management group inheritance, audit-first rollout, parameterised reusable policies, and exclusion discipline. Powers Defender for Cloud regul…
- [Entra Global Secure Access](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-entra-global-secure-access) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-entra-global-secure-access`
  Guidance for Microsoft Entra Global Secure Access (GSA) — Microsoft's Security Service Edge (SSE) combining Entra Internet Access (SWG/Secure Web Gateway) and Entra Private Access (ZTNA replacement for VPN). Covers client deployment (Windows, macOS, iOS, Android), traffic forwarding profiles (Microsoft, Internet, Private), Conditional Access for network traffic, source IP restoration, app discove…
- [Azure Firewall](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-azure-firewall) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-azure-firewall`
  Guidance for Azure Firewall — managed cloud-native L3-L7 stateful network firewall for centralised egress, east-west, and ingress control. Covers SKU choice (Basic vs Standard vs Premium), Firewall Policy hierarchy, application/network/DNAT rules, threat intelligence and IDPS, TLS inspection, hub-spoke deployment with UDRs, and forced tunneling. WHEN: Azure Firewall, network firewall, egress filt…
- [Defender For Endpoint](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-defender-for-endpoint) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-defender-for-endpoint`
  Guidance for Microsoft Defender for Endpoint (MDE) — enterprise endpoint security with next-gen AV, EDR, attack surface reduction (ASR), Defender Vulnerability Management, automated investigation and remediation (AIR), and live response. Covers Plan 1 vs Plan 2 selection, onboarding paths (Intune, Configuration Manager, GPO, scripts), ASR rule rollout in audit→block, EDR in block mode, tamper pro…
- [Azure Pim](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-azure-pim) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-azure-pim`
  Guidance for Microsoft Entra Privileged Identity Management (PIM) — just-in-time, time-bound, approval-based, audited elevation for Entra roles, Azure resource roles, and privileged groups. Covers eligible vs active assignments, activation controls (MFA + approval + justification + ticket), access reviews, PIM for Groups, and removing standing access. WHEN: Privileged Identity Management, PIM, ju…
- [Defender For Servers](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-defender-for-servers) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-defender-for-servers`
  Guidance for Microsoft Defender for Servers (Plan 1 and Plan 2) — server-specific protection in Microsoft Defender for Cloud. Covers plan selection, agentless vs agent-based scanning, MDE for Servers integration, file integrity monitoring (FIM via MDE), just-in-time VM access, vulnerability assessment, adaptive application controls, network hardening, and free data ingestion to Sentinel/Log Analy…
- [Entra Id](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-entra-id) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-entra-id`
  Guidance for Microsoft Entra ID (formerly Azure AD) — cloud identity and access management and the control plane for Zero Trust. Covers tenant and identity model, authentication methods (passkeys, FIDO2, certificate-based), hybrid identity with Entra Connect or Cloud Sync, app registrations and consent governance, groups and administrative units, break-glass accounts, and Zero Trust identity foun…
- [Azure Ddos Protection](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-azure-ddos-protection) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-azure-ddos-protection`
  Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform. Covers tier selection vs free Basic infrastructure protection, scope (VNet vs single IP), traffic profiling and mitigation policy auto-tuning, attack analytics and metrics, attack alerts to Sentinel, DDoS Rapid Response engagement, integration…
- [Azure Network Security Design](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-azure-network-security-design) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-azure-network-security-design`
  Guidance for designing secure Azure network architecture — hub-spoke topology (or Virtual WAN), segmentation with NSGs/ASGs, private endpoints / Private Link for PaaS, egress through Azure Firewall, DDoS protection, WAF on Front Door/App Gateway, and centralised private DNS. Aligned to the Zero Trust network pillar. WHEN: Azure network security, hub spoke, Virtual WAN, network segmentation, NSG A…
- [Defender For Storage](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-defender-for-storage) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-defender-for-storage`
  Guidance for Microsoft Defender for Storage — threat protection for Azure Storage accounts (Blob, Files, Data Lake Gen2). Covers the v2 (per-storage-account) plan, on-upload malware scanning powered by Defender Antivirus, sensitive data threat detection (integrated with Purview classification), activity-based threat detection, override per storage account, exclusion of high-volume accounts, Event…
- [Defender Tvm](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-defender-tvm) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-defender-tvm`
  Guidance for Microsoft Defender Threat Intelligence (Defender TI) and Microsoft Defender Vulnerability Management (MDVM) — the threat-and-vulnerability layer of Defender XDR. Covers MDVM exposure score, CVE prioritization with threat insights and active campaigns, security baselines (CIS/STIG), browser-extension and certificate inventory, network share assessment, hardware/firmware inventory, sec…
- [Azure Confidential Computing](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-azure-confidential-computing) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-azure-confidential-computing`
  Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs). Covers Confidential VMs (AMD SEV-SNP, Intel TDX), Confidential containers on AKS (Kata + AMD SEV-SNP), confidential GPU VMs (NVIDIA H100 with TDX), Azure Key Vault Managed HSM and Premium with secure-key-release for confidential workloads, attestation (Microsoft Azure A…
- [Defender For Business](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-defender-for-business) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-defender-for-business`
  Guidance for Microsoft Defender for Business (MDB) — the SMB-segment endpoint security product (≤300 employees), bundled with Microsoft 365 Business Premium and available as a standalone SKU. Covers what's included vs MDE Plan 1/2 (next-gen AV, EDR with simplified configuration, ASR, automated investigation and response, vulnerability management, web content filtering, attack surface reduction, m…
- [Azure Site Recovery](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-azure-site-recovery) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-azure-site-recovery`
  Guidance for Azure Site Recovery (ASR) — disaster-recovery-as-a-service that replicates Azure VMs and on-premises machines to a secondary region for orchestrated failover. Covers RPO / RTO design, replication setup, recovery plans with start-up ordering and scripts, test failover discipline, and the separation between DR (ASR) and backup (Azure Backup) for ransomware resilience. WHEN: Azure Site…
- [Entra Id Governance](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-entra-id-governance) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-entra-id-governance`
  Guidance for Microsoft Entra ID Governance — automating identity lifecycle and access with entitlement management (access packages), access reviews, lifecycle workflows for joiner-mover-leaver, separation of duties, and guest access governance. Covers when to use access packages vs direct group assignment, reviewer choice and fallback actions, and integration with PIM for privileged access. WHEN:…
- [Entra Workload Identity](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-entra-workload-identity) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-entra-workload-identity`
  Guidance for Microsoft Entra workload identities — managed identities, service principals, and workload identity federation. Covers system-assigned vs user-assigned managed identity, federated credentials (GitHub Actions, Azure DevOps, Kubernetes, other OIDC issuers) to eliminate secrets, Workload Identities Premium (Conditional Access for workloads, risk detection, lifecycle reviews), credential…
- [Cloud App Security Posture](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-cloud-app-security-posture) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-cloud-app-security-posture`
  Guidance for cloud and SaaS security posture management - combining Defender for Cloud CSPM (IaaS/PaaS) and Defender for Cloud Apps SSPM (SaaS) to assess and harden posture across cloud and SaaS apps. Covers Secure Score, MCSB, attack-path analysis, SSPM recommendations, and governance. WHEN: cloud security posture, SaaS security posture management, SSPM, CSPM, secure cloud apps, posture recommen…
- [Defender For Office 365](https://agentstack.voostack.com/l/skill-vinayaklatthe-microsoft-security-skills-defender-for-office-365) — Skill · Free · security-reviewed — `agentstack add skill-vinayaklatthe-microsoft-security-skills-defender-for-office-365`
  Guidance for Microsoft Defender for Office 365 (MDO) — protection for email and collaboration (Teams, SharePoint, OneDrive) against phishing, malware, spoofing, and business email compromise. Covers Plan 1 vs Plan 2 selection, preset security policies (Standard/Strict), Safe Links, Safe Attachments, anti-phishing impersonation protection, configuration analyzer drift detection, Submissions portal…

---
Seller on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Install any with `agentstack add <slug>`.
