# Azure Enterprise Infra Planner > Architect and provision enterprise Azure infrastructure from workload descriptions. For cloud architects and platform engineers planning networking, identity, security, compliance, and multi-resource topologies with WAF alignment. Generates Bicep or Terraform directly (no azd). WHEN: 'plan Azure infrastructure', 'architect Azure landing zone', 'design hub-spoke network', 'plan multi-region DR topology', 'set up VNets firewalls and private endpoints', 'subscription-scope Bicep deployment', 'Azure Backup for VM workloads'. PREFER azure-prepare FOR app-centric workflows. Source: https://skillsagentes.com/skills/microsoft/azure-skills/azure-enterprise-infra-planner Repository: https://github.com/microsoft/azure-skills Author: microsoft License: MIT Updated: hace 17 días Context cost: 144 tok installed, 907 tok once triggered, 31.5k tok with every bundled file Bundle: 40 files, 123 KB Permissions requested: none declared ## Install ```bash npx -y skills add microsoft/azure-skills --skill azure-enterprise-infra-planner --agent claude-code ``` ## What it does - Diseña y aprovisiona infraestructura Azure de empresa a partir de la descripción de una carga de trabajo, alineada con el Well-Architected Framework. - Cubre redes, identidad, seguridad, cumplimiento y topologías multi-recurso: VNets, subredes, firewalls, private endpoints y gateways VPN. - Genera Bicep o Terraform directamente, sin pasar por azd, incluido despliegue a nivel de suscripción. - Planifica recuperación ante desastres, failover y alta disponibilidad entre regiones. ## Use it when - Se quiere planificar infraestructura Azure de empresa, una landing zone, una red hub-spoke o una topología multi-región. - Se quiere planificar identidad, RBAC o infraestructura guiada por cumplimiento. ## Don't bother when - Para flujos centrados en una aplicación: el archivo pide preferir `azure-prepare`. ## What triggers it - "diseña una landing zone" - "planifica una red hub-spoke" - "topología multi-región para DR" - "genera el Bicep de esta arquitectura" ## Before you install - Usa herramientas MCP de insights, buenas prácticas, WAF y esquemas Bicep, más los CLI `az deployment`, `az bicep` y `terraform`. ## Files - SKILL.md — 4 KB - references/bicep-generation.md — 4 KB - references/constraints/README.md — 1 KB - references/constraints/ai-ml.md — 3 KB - references/constraints/compute-apps.md — 8 KB - references/constraints/compute-infra.md — 5 KB - references/constraints/data-analytics.md — 6 KB - references/constraints/data-relational.md — 5 KB - references/constraints/messaging.md — 3 KB - references/constraints/monitoring.md — 2 KB - references/constraints/networking-connectivity.md — 6 KB - references/constraints/networking-core.md — 7 KB - references/constraints/networking-traffic.md — 5 KB - references/constraints/security.md — 2 KB - references/deployment.md — 4 KB - references/pairing-checks.md — 4 KB - references/phases/1-extract-insights.md — 2 KB - references/phases/2-research-best-practices.md — 3 KB - references/phases/3-research-resources.md — 3 KB - references/phases/4-generate-plan.md — 792 B - references/phases/5-verify.md — 814 B - references/phases/6-generate-iac.md — 675 B - references/phases/7-deploy.md — 1 KB - references/resources/README.md — 2 KB - references/resources/ai-ml.md — 2 KB - references/resources/compute-apps.md — 4 KB - references/resources/compute-infra.md — 3 KB - references/resources/data-analytics.md — 3 KB - references/resources/data-relational.md — 3 KB - references/resources/messaging.md — 2 KB - references/resources/monitoring.md — 1 KB - references/resources/networking-connectivity.md — 4 KB - references/resources/networking-core.md — 4 KB - references/resources/networking-traffic.md — 3 KB - references/resources/security.md — 1 KB - references/schema.md — 3 KB - references/terraform-generation.md — 3 KB - references/verification.md — 3 KB - references/waf-checklist.md — 2 KB - references/workflow.md — 3 KB ## SKILL.md Reproduced verbatim from microsoft/azure-skills under MIT. This section is the upstream document and is in English. # Azure Enterprise Infra Planner ## When to Use This Skill Activate this skill when user wants to: - Plan enterprise Azure infrastructure from a workload or architecture description - Architect a landing zone, hub-spoke network, or multi-region topology - Design networking infrastructure: VNets, subnets, firewalls, private endpoints, VPN gateways - Plan identity, RBAC, and compliance-driven infrastructure - Generate Bicep or Terraform for subscription-scope or multi-resource-group deployments - Plan disaster recovery, failover, or cross-region high-availability topologies ## Quick Reference | Property | Details | |---|---| | MCP tools | `insights_get`, `get_azure_bestpractices_get`, `wellarchitectedframework_serviceguide_get`, `microsoft_docs_fetch`, `microsoft_docs_search`, `bicepschema_get` | | CLI commands | `az deployment group create`, `az bicep build`, `az resource list`, `terraform init`, `terraform plan`, `terraform validate`, `terraform apply` | | Output schema | [schema.md](references/schema.md) | | Key references | [workflow.md](references/workflow.md), [waf-checklist.md](references/waf-checklist.md), [resources/](references/resources/README.md), [constraints/](references/constraints/README.md) | ## Workflow (Start Here) Follow the step-by-step instructions in [workflow.md](references/workflow.md) to execute the 7 phases of infrastructure planning and provisioning. ## MCP Tools | Tool | Purpose | |------|---------| | `insights_get` | Retrieve insights about the user's existing Azure environment to guide planning decisions | | `get_azure_bestpractices_get` | Azure best practices for code generation, operations, and deployment | | `wellarchitectedframework_serviceguide_get` | WAF service guide for a specific Azure service | | `microsoft_docs_search` | Search Microsoft Learn for relevant documentation chunks | | `microsoft_docs_fetch` | Fetch full content of a Microsoft Learn page by URL | | `bicepschema_get` | Bicep schema definition for any Azure resource type (latest API version) | ## Error Handling | Error | Cause | Fix | |---|---|---| | MCP tool error or not available | Tool call timeout, connection error, or tool doesn't exist | Retry once; fall back to reference files and notify user if unresolved | | Plan approval missing | `meta.status` is not `approved` | Stop and prompt user for approval before IaC generation or deployment | | IaC validation failure | `az bicep build` or `terraform validate` returns errors | Fix the generated code and re-validate; notify user if unresolved | | Pairing constraint violation | Incompatible SKU or resource combination | Fix in plan before proceeding to IaC generation | | Infra plan or IaC files not found | Files written to wrong location or not created | Verify files exist at `/.azure/` and `/infra/`; if missing, re-create the files by following [workflow.md](references/workflow.md) exactly | --- Skills Agentes — https://skillsagentes.com/skills/microsoft/azure-skills/azure-enterprise-infra-planner