microsoft / microsoft/mcp

Feature request: Incorporate Security Best Practices into Azure MCP Server’s Best Practices Tool

Open
#1,094 4 comments 1 reaction 1 assignee View on GitHub

Nobody has claimed this yet.

enhancement onboarding
Dominant language
C#
Stars
3.7k
Forks
624
Avg merge
2d 20h
Merged PRs (30d)
220

Description

I'm the Azure Security Lead in the Learn organization, and am leading an effort to create “Secure your Service” articles. Some examples of published articles are:

We’d like to start a discussion about incorporating security best practices into the Azure MCP Server’s Best Practices tool so that customers can get security guidance alongside deployment guidance. This would help customers follow recommended security patterns when provisioning services. The security best practices could be interwoven with general best practices or kept distinct (perhaps via a separate call or parameter)

I already maintain https://github.com/msmbaldwin/security-horizontal-copilot, which uses the Learn MCP server to generate these articles based on best practices in Microsoft Docs. Incorporating this functionality into Azure MCP Server might be a better way to scale this.

Relatedly, the Microsoft Cloud Security Benchmark (MCSB) teams plans to release a v2 next week. This could serve as another source of security best practices.

Lastly, we have an SFI Pattern and Practices library at https://learn.microsoft.com/en-us/security/zero-trust/sfi/phishing-resistant-mfa, which is also publishing security best practices.

Thanks!

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.