| Best for | Compliance scans, security audits, Key Vault expiration checks | | Primary capabilities | Comprehensive Resources Assessment, Key Vault Expiration Monitoring | | MCP tools | azqr, subscription and resource group listing, Key Vault item inspection |
| Comprehensive Compliance (azqr) | references/azure-quick-review.md | | Key Vault Expiration | references/azure-keyvault-expiration-audit.md | | Resource Graph Queries | references/azure-resource-graph.md |
| mcpazuremcpextensionazqr | Run azqr compliance scans | | mcpazuremcpsubscriptionlist | List available subscriptions | | mcpazuremcpgrouplist | List resource groups | | keyvaultkeylist | List all keys in vault | | keyvaultkeyget | Get key details including expiration | | keyvaultsecretlist | List all secrets in vault |
Comprehensive Azure compliance and security auditing capabilities including best practices assessment, Key Vault expiration monitoring, and resource configuration validation. USE FOR: compliance scan, security audit, azqr, Azure best practices, Key Vault expiration check, compliance assessment, resource review, configuration validation, expired certificates, expiring secrets, orphaned resources, policy compliance, security posture evaluation. DO NOT USE FOR: deploying resources (use azure-deploy), cost analysis alone (use azure-cost-optimization), active security hardening (use azure-security-hardening), general Azure Advisor queries (use azure-observability). Source: microsoft/github-copilot-for-azure.