azure_analyze_keyvault_security
Assess Azure Key Vault security for risks like disabled soft delete, public network access, missing purge protection, and expiration issues. Provides risk-scored findings and remediation guidance.
Instructions
Key Vault security assessment. Checks: soft delete disabled (data loss risk), purge protection disabled, public network access enabled, RBAC vs Access Policies, secret/certificate expiration, diagnostic logging. Returns risk-scored findings (CRITICAL/HIGH/MEDIUM/LOW) with remediation guidance.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| subscriptionId | Yes | Azure subscription ID | |
| resourceGroup | No | Optional: Filter by specific resource group | |
| format | No | Output format: 'markdown' (default, human-readable) or 'json' (machine-readable) |