{"id":"bd3f4f88-7543-44d6-8ba5-599d23ce164e","shortId":"Uthza8","kind":"skill","title":"azure-enterprise-infra-planner","tagline":"Architect and provision enterprise Azure infrastructure from workload descriptions. For cloud architects and platform engineers planning networking, identity, security, compliance, and multi-resource topologies with WAF alignment. Generates Bicep or Terraform directly (no azd). W","description":"# Azure Enterprise Infra Planner\n\n## When to Use This Skill\n\nActivate this skill when user wants to:\n- Plan enterprise Azure infrastructure from a workload or architecture description\n- Architect a landing zone, hub-spoke network, or multi-region topology\n- Design networking infrastructure: VNets, subnets, firewalls, private endpoints, VPN gateways\n- Plan identity, RBAC, and compliance-driven infrastructure\n- Generate Bicep or Terraform for subscription-scope or multi-resource-group deployments\n- Plan disaster recovery, failover, or cross-region high-availability topologies\n\n## Quick Reference\n\n| Property | Details |\n|---|---|\n| MCP tools | `get_azure_bestpractices_get`, `wellarchitectedframework_serviceguide_get`, `microsoft_docs_fetch`, `microsoft_docs_search`, `bicepschema_get` |\n| CLI commands | `az deployment group create`, `az bicep build`, `az resource list`, `terraform init`, `terraform plan`, `terraform validate`, `terraform apply` |\n| Output schema | [plan-schema.md](references/plan-schema.md) |\n| Key references | [research.md](references/research.md), [resources/](references/resources/README.md), [waf-checklist.md](references/waf-checklist.md), [constraints/](references/constraints/README.md) |\n\n## Workflow\n\nRead [workflow.md](references/workflow.md) for detailed step-by-step instructions, including MCP tool usage, CLI commands, and decision points. Follow the phases in order, ensuring all key gates are passed before proceeding to the next phase.\n\n| Phase | Action | Key Gate |\n|-------|--------|----------|\n| 1 | Research — WAF Tools | All MCP tool calls complete |\n| 2 | Research — Refine & Lookup | Resource list approved by user |\n| 3 | Plan Generation | Plan JSON written to disk |\n| 4 | Verification | All checks pass, user approves |\n| 5 | IaC Generation | `meta.status` = `approved` |\n| 6 | Deployment | User confirms destructive actions |\n\n## MCP Tools\n\n| Tool | Purpose |\n|------|---------|\n| `get_azure_bestpractices_get` | Azure best practices for code generation, operations, and deployment |\n| `wellarchitectedframework_serviceguide_get` | WAF service guide for a specific Azure service |\n| `microsoft_docs_search` | Search Microsoft Learn for relevant documentation chunks |\n| `microsoft_docs_fetch` | Fetch full content of a Microsoft Learn page by URL |\n| `bicepschema_get` | Bicep schema definition for any Azure resource type (latest API version) |\n\n## Error Handling\n\n| Error | Cause | Fix |\n|---|---|---|\n| MCP tool error or not available | Tool call timeout, connection error, or tool doesn't exist | Retry once; fall back to reference files and notify user if unresolved |\n| Plan approval missing | `meta.status` is not `approved` | Stop and prompt user for approval before IaC generation or deployment |\n| IaC validation failure | `az bicep build` or `terraform validate` returns errors | Fix the generated code and re-validate; notify user if unresolved |\n| Pairing constraint violation | Incompatible SKU or resource combination | Fix in plan before proceeding to IaC generation |\n| Infra plan or IaC files not found | Files written to wrong location or not created | Verify files exist at `<project-root>/.azure/` and `<project-root>/infra/`; if missing, re-create the files by following [workflow.md](references/workflow.md) exactly |","tags":["azure","enterprise","infra","planner","skills","microsoft","agent-skills"],"capabilities":["skill","source-microsoft","skill-azure-enterprise-infra-planner","topic-agent-skills"],"categories":["azure-skills"],"synonyms":[],"warnings":[],"endpointUrl":"https://skills.sh/microsoft/azure-skills/azure-enterprise-infra-planner","protocol":"skill","transport":"skills-sh","auth":{"type":"none","details":{"cli":"npx skills add microsoft/azure-skills","source_repo":"https://github.com/microsoft/azure-skills","install_from":"skills.sh"}},"qualityScore":"0.950","qualityRationale":"deterministic score 0.95 from registry signals: · indexed on github topic:agent-skills · official publisher · 1014 github stars · SKILL.md body (3,297 chars)","verified":false,"liveness":"unknown","lastLivenessCheck":null,"agentReviews":{"count":0,"score_avg":null,"cost_usd_avg":null,"success_rate":null,"latency_p50_ms":null,"narrative_summary":null,"summary_updated_at":null},"enrichmentModel":"deterministic:skill-github:v1","enrichmentVersion":1,"enrichedAt":"2026-05-18T18:53:16.779Z","embedding":null,"createdAt":"2026-04-18T20:23:29.352Z","updatedAt":"2026-05-18T18:53:16.779Z","lastSeenAt":"2026-05-18T18:53:16.779Z","tsv":"'/.azure':438 '/infra':440 '1':221 '2':230 '3':239 '4':247 '5':254 '6':259 'action':218,264 'activ':51 'align':33 'api':327 'appli':165 'approv':236,253,258,363,368,374 'architect':6,17,68 'architectur':66 'avail':123,339 'az':148,152,155,383 'azd':40 'azur':2,10,42,60,132,270,273,291,323 'azure-enterprise-infra-plann':1 'back':353 'best':274 'bestpractic':133,271 'bicep':35,100,153,318,384 'bicepschema':144,316 'build':154,385 'call':228,341 'caus':332 'check':250 'chunk':302 'cli':146,195 'cloud':16 'code':277,394 'combin':410 'command':147,196 'complet':229 'complianc':25,96 'compliance-driven':95 'confirm':262 'connect':343 'constraint':178,404 'content':308 'creat':151,433,445 'cross':119 'cross-region':118 'decis':198 'definit':320 'deploy':112,149,260,281,379 'descript':14,67 'design':81 'destruct':263 'detail':128,185 'direct':38 'disast':114 'disk':246 'doc':139,142,294,304 'document':301 'doesn':347 'driven':97 'endpoint':88 'engin':20 'ensur':205 'enterpris':3,9,43,59 'error':329,331,336,344,390 'exact':452 'exist':349,436 'failov':116 'failur':382 'fall':352 'fetch':140,305,306 'file':356,423,426,435,447 'firewal':86 'fix':333,391,411 'follow':200,449 'found':425 'full':307 'gate':208,220 'gateway':90 'generat':34,99,241,256,278,377,393,418 'get':131,134,137,145,269,272,284,317 'group':111,150 'guid':287 'handl':330 'high':122 'high-avail':121 'hub':73 'hub-spok':72 'iac':255,376,380,417,422 'ident':23,92 'includ':191 'incompat':406 'infra':4,44,419 'infrastructur':11,61,83,98 'init':159 'instruct':190 'json':243 'key':170,207,219 'land':70 'latest':326 'learn':298,312 'list':157,235 'locat':430 'lookup':233 'mcp':129,192,226,265,334 'meta.status':257,365 'microsoft':138,141,293,297,303,311 'miss':364,442 'multi':28,78,109 'multi-region':77 'multi-resourc':27 'multi-resource-group':108 'network':22,75,82 'next':215 'notifi':358,399 'oper':279 'order':204 'output':166 'page':313 'pair':403 'pass':210,251 'phase':202,216,217 'plan':21,58,91,113,161,240,242,362,413,420 'plan-schema.md':168 'planner':5,45 'platform':19 'point':199 'practic':275 'privat':87 'proceed':212,415 'prompt':371 'properti':127 'provis':8 'purpos':268 'quick':125 'rbac':93 're':397,444 're-creat':443 're-valid':396 'read':181 'recoveri':115 'refer':126,171,355 'references/constraints/readme.md':179 'references/plan-schema.md':169 'references/research.md':173 'references/resources/readme.md':175 'references/waf-checklist.md':177 'references/workflow.md':183,451 'refin':232 'region':79,120 'relev':300 'research':222,231 'research.md':172 'resourc':29,110,156,174,234,324,409 'retri':350 'return':389 'schema':167,319 'scope':106 'search':143,295,296 'secur':24 'servic':286,292 'serviceguid':136,283 'skill':50,53 'skill-azure-enterprise-infra-planner' 'sku':407 'source-microsoft' 'specif':290 'spoke':74 'step':187,189 'step-by-step':186 'stop':369 'subnet':85 'subscript':105 'subscription-scop':104 'terraform':37,102,158,160,162,164,387 'timeout':342 'tool':130,193,224,227,266,267,335,340,346 'topic-agent-skills' 'topolog':30,80,124 'type':325 'unresolv':361,402 'url':315 'usag':194 'use':48 'user':55,238,252,261,359,372,400 'valid':163,381,388,398 'verif':248 'verifi':434 'version':328 'violat':405 'vnet':84 'vpn':89 'w':41 'waf':32,223,285 'waf-checklist.md':176 'want':56 'wellarchitectedframework':135,282 'workflow':180 'workflow.md':182,450 'workload':13,64 'written':244,427 'wrong':429 'zone':71","prices":[{"id":"7acf0ad8-fce8-45ae-8a3b-fa20a56bca0e","listingId":"bd3f4f88-7543-44d6-8ba5-599d23ce164e","amountUsd":"0","unit":"free","nativeCurrency":null,"nativeAmount":null,"chain":null,"payTo":null,"paymentMethod":"skill-free","isPrimary":true,"details":{"org":"microsoft","category":"azure-skills","install_from":"skills.sh"},"createdAt":"2026-04-18T20:23:29.352Z"}],"sources":[{"listingId":"bd3f4f88-7543-44d6-8ba5-599d23ce164e","source":"github","sourceId":"microsoft/azure-skills/azure-enterprise-infra-planner","sourceUrl":"https://github.com/microsoft/azure-skills/tree/main/skills/azure-enterprise-infra-planner","isPrimary":false,"firstSeenAt":"2026-04-18T21:57:10.900Z","lastSeenAt":"2026-05-18T18:53:16.779Z"},{"listingId":"bd3f4f88-7543-44d6-8ba5-599d23ce164e","source":"skills_sh","sourceId":"microsoft/azure-skills/azure-enterprise-infra-planner","sourceUrl":"https://skills.sh/microsoft/azure-skills/azure-enterprise-infra-planner","isPrimary":true,"firstSeenAt":"2026-04-18T20:23:29.352Z","lastSeenAt":"2026-05-07T22:40:12.041Z"}],"details":{"listingId":"bd3f4f88-7543-44d6-8ba5-599d23ce164e","quickStartSnippet":null,"exampleRequest":null,"exampleResponse":null,"schema":null,"openapiUrl":null,"agentsTxtUrl":null,"citations":[],"useCases":[],"bestFor":[],"notFor":[],"kindDetails":{"org":"microsoft","slug":"azure-enterprise-infra-planner","github":{"repo":"microsoft/azure-skills","stars":1014,"topics":["agent-skills"],"license":"mit","html_url":"https://github.com/microsoft/azure-skills","pushed_at":"2026-05-18T14:38:04Z","description":"Official agent plugin providing skills and MCP server configurations for Azure scenarios.","skill_md_sha":"bee517ce5dcd6f710bb8a81a0beaf9b24dad2558","skill_md_path":"skills/azure-enterprise-infra-planner/SKILL.md","default_branch":"main","skill_tree_url":"https://github.com/microsoft/azure-skills/tree/main/skills/azure-enterprise-infra-planner"},"layout":"multi","source":"github","category":"azure-skills","frontmatter":{"name":"azure-enterprise-infra-planner","license":"MIT","description":"Architect and provision enterprise Azure infrastructure from workload descriptions. For cloud architects and platform engineers planning networking, identity, security, compliance, and multi-resource topologies with WAF alignment. Generates Bicep or Terraform directly (no azd). WHEN: 'plan Azure infrastructure', 'architect Azure landing zone', 'design hub-spoke network', 'plan multi-region DR topology', 'set up VNets firewalls and private endpoints', 'subscription-scope Bicep deployment', 'Azure Backup for VM workloads'. PREFER azure-prepare FOR app-centric workflows."},"skills_sh_url":"https://skills.sh/microsoft/azure-skills/azure-enterprise-infra-planner"},"updatedAt":"2026-05-18T18:53:16.779Z"}}