skills/azure-sovereign-us/SKILL.md
Expert knowledge for Azure US Government development including decision making, architecture & design patterns, security, configuration, integrations & coding patterns, and deployment. Use when designing IL5/FedRAMP Gov envs, SACA-based architectures, ASE/DISA CAP deploys, Gov Marketplace, or Entra auth, and other Azure US Government related development tasks. Not for Azure Security (use azure-security), Azure Defender For Cloud (use azure-defender-for-cloud), Azure Policy (use azure-policy), Azure Monitor (use azure-monitor).
npx skillsauth add microsoftdocs/agent-skills azure-sovereign-usInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
This skill provides expert guidance for Azure US Government. Covers decision making, architecture & design patterns, security, configuration, integrations & coding patterns, and deployment. It combines local quick-reference content with remote documentation fetching capabilities.
IMPORTANT for Agent: Use the Category Index below to locate relevant sections. For categories with line ranges (e.g.,
L35-L120), useread_filewith the specified lines. For categories with file links (e.g.,[security.md](security.md)), useread_fileon the linked reference file
IMPORTANT for Agent: If
metadata.generated_atis more than 3 months old, suggest the user pull the latest version from the repository. Ifmcp_microsoftdocstools are not available, suggest the user install it: Installation Guide
This skill requires network access to fetch documentation content:
mcp_microsoftdocs:microsoft_docs_fetch with query string from=learn-agent-skill. Returns Markdown.fetch_webpage with query string from=learn-agent-skill&accept=text/markdown. Returns Markdown.| Category | Lines | Description | |----------|-------|-------------| | Decision Making | L34-L46 | Guidance on choosing Azure Government vs global, FedRAMP/DoD scope and ATO, CSP reseller options, marketplace and DoD regions, and sector-specific compliance (NERC CIP, public safety, worldwide public sector). | | Architecture & Design Patterns | L47-L51 | Guidance on applying Secure Azure Computing Architecture (SACA) patterns to design compliant, secure, and resilient solutions in Azure Sovereign Cloud environments. | | Security | L52-L64 | Designing secure, compliant Azure Government environments: isolation/IL5, FedRAMP Rev5 & DoD scope, TIC, identity/Entra auth, resource naming, and workload security controls. | | Configuration | L65-L73 | Guidance for configuring and operating Azure Government: app deployment, VM extensions, EA billing, marketplace images, and Azure Monitor logs in sovereign US regions. | | Integrations & Coding Patterns | L74-L80 | Coding patterns and connection guidance for Azure Government: building Foundry Tools apps, connecting SSMS to Gov SQL, and using Azure Storage APIs in sovereign clouds. | | Deployment | L81-L87 | Guides for deploying apps and solutions to Azure Government: CI/CD with Azure Pipelines, ASE baseline with DISA CAP, App Service deployment, and publishing to Gov Marketplace. |
| Topic | URL | |-------|-----| | Choose between Azure Government and global Azure | https://learn.microsoft.com/en-us/azure/azure-government/compare-azure-government-global-azure | | Accelerate FedRAMP ATO on Azure with tooling | https://learn.microsoft.com/en-us/azure/azure-government/compliance/documentation-accelerate-compliance | | Become an Azure Government CSP reseller | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-csp-application | | Find authorized Azure Government CSP resellers | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-csp-list | | Use Azure Government Marketplace solutions | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-manage-marketplace | | Use Azure Government DoD regions for workloads | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-overview-dod | | Run public safety and justice workloads on Azure | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-overview-jps | | Apply NERC CIP standards to Azure cloud use | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-overview-nerc | | Adopt Azure for worldwide public sector securely | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-overview-wwps |
| Topic | URL | |-------|-----| | Apply Secure Azure Computing Architecture (SACA) | https://learn.microsoft.com/en-us/azure/azure-government/compliance/secure-azure-computing-architecture |
| Topic | URL | |-------|-----| | Design secure isolation for Azure Government and multitenant | https://learn.microsoft.com/en-us/azure/azure-government/azure-secure-isolation-guidance | | Understand FedRAMP and DoD compliance scope for Azure clouds | https://learn.microsoft.com/en-us/azure/azure-government/compliance/azure-services-in-fedramp-auditscope | | Meet Trusted Internet Connections using Azure | https://learn.microsoft.com/en-us/azure/azure-government/compliance/compliance-tic | | Configure Azure securely for FedRAMP Rev5 | https://learn.microsoft.com/en-us/azure/azure-government/compliance/recommended-secure-configuration | | Integrate Microsoft Entra auth on Azure Government | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-aad-auth-qs | | Name Azure resources without exposing sensitive data | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-concept-naming-resources | | Configure Azure Government for DoD IL5 isolation | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-impact-level-5 | | Plan identity architecture for Azure Government | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-plan-identity | | Implement security controls for Azure Government workloads | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-plan-security |
| Topic | URL | |-------|-----| | Develop and deploy applications on Azure Government | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-developer-guide | | List and use VM extensions in Azure Government | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-extension | | Access and manage EA billing in Azure Government | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-how-to-access-enterprise-agreement-billing-account | | Use Azure Government Marketplace image gallery | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-image-gallery | | Use Azure Monitor logs in Azure Government | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-manage-oms |
| Topic | URL | |-------|-----| | Develop Foundry Tools apps on Azure Government | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-cognitiveservices | | Connect SSMS to Azure Government SQL resources | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-connect-ssms | | Use Azure Storage APIs in Azure Government | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-get-started-connect-to-storage |
| Topic | URL | |-------|-----| | Set up Azure Pipelines CI/CD to Azure Government | https://learn.microsoft.com/en-us/azure/azure-government/connect-with-azure-pipelines | | Baseline ASE deployment with DISA CAP in Azure Gov | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-ase-disa-cap | | Deploy Azure App Service apps to Azure Government | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-howto-deploy-webandmobile | | Publish solutions to Azure Government Marketplace | https://learn.microsoft.com/en-us/azure/azure-government/documentation-government-manage-marketplace-partners |
tools
Expert knowledge for Microsoft Foundry (aka Azure AI Foundry) development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when building Foundry agents with IQ retrieval, Entra RBAC, Azure OpenAI, M365/Teams publishing, or MCP tools, and other Microsoft Foundry related development tasks. Not for Microsoft Foundry Classic (use microsoft-foundry-classic), Microsoft Foundry Local (use microsoft-foundry-local), Microsoft Foundry Tools (use microsoft-foundry-tools).
tools
Expert knowledge for Microsoft Foundry Local (aka Azure AI Foundry Local) development including best practices, configuration, and integrations & coding patterns. Use when compiling HF models with Olive, managing local models via CLI, or building chat, embeddings, or transcription apps, and other Microsoft Foundry Local related development tasks. Not for Microsoft Foundry (use microsoft-foundry), Microsoft Foundry Classic (use microsoft-foundry-classic), Microsoft Foundry Tools (use microsoft-foundry-tools), Azure Local (use azure-local).
tools
Expert knowledge for Microsoft Foundry Classic (aka Azure AI Foundry classic) development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when configuring Foundry agents, routing Azure OpenAI models, integrating tools/RAG, securing endpoints, or deploying hubs, and other Microsoft Foundry Classic related development tasks. Not for Microsoft Foundry (use microsoft-foundry), Microsoft Foundry Local (use microsoft-foundry-local), Microsoft Foundry Tools (use microsoft-foundry-tools).
development
Expert knowledge for Azure Web PubSub development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when using WebSockets/MQTT, Socket.IO, Functions bindings, geo-replication, or Premium autoscale in Web PubSub, and other Azure Web PubSub related development tasks. Not for Azure SignalR Service (use azure-signalr-service), Azure Event Hubs (use azure-event-hubs), Azure Service Bus (use azure-service-bus), Azure Relay (use azure-relay).