> **azure-enterprise-infra-planner** — chapter 16 of 37 in [microsoft/azure-skills](https://skillsdocs.com/microsoft/azure-skills).
>
> Book (all chapters, one file): https://skillsdocs.com/microsoft/azure-skills.md
> Machine manifest: https://skillsdocs.com/microsoft/azure-skills/.well-known/agent-skills/index.json
> Install the book: `npx skills add microsoft/azure-skills`
> Upstream: https://github.com/microsoft/azure-skills/blob/main/skills/azure-enterprise-infra-planner/SKILL.md @ `main`
> Raw bytes, no header: https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/SKILL.md
> Base for relative paths: https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/
> Licence: MIT — https://spdx.org/licenses/MIT.html
>
> Bundled files (39), referenced from this skill's directory:
>   - `references/bicep-generation.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/bicep-generation.md
>   - `references/constraints/ai-ml.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/constraints/ai-ml.md
>   - `references/constraints/compute-apps.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/constraints/compute-apps.md
>   - `references/constraints/compute-infra.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/constraints/compute-infra.md
>   - `references/constraints/data-analytics.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/constraints/data-analytics.md
>   - `references/constraints/data-relational.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/constraints/data-relational.md
>   - `references/constraints/messaging.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/constraints/messaging.md
>   - `references/constraints/monitoring.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/constraints/monitoring.md
>   - `references/constraints/networking-connectivity.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/constraints/networking-connectivity.md
>   - `references/constraints/networking-core.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/constraints/networking-core.md
>   - `references/constraints/networking-traffic.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/constraints/networking-traffic.md
>   - `references/constraints/README.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/constraints/README.md
>   - `references/constraints/security.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/constraints/security.md
>   - `references/deployment.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/deployment.md
>   - `references/pairing-checks.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/pairing-checks.md
>   - `references/phases/1-extract-insights.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/phases/1-extract-insights.md
>   - `references/phases/2-research-best-practices.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/phases/2-research-best-practices.md
>   - `references/phases/3-research-resources.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/phases/3-research-resources.md
>   - `references/phases/4-generate-plan.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/phases/4-generate-plan.md
>   - `references/phases/5-verify.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/phases/5-verify.md
>   - `references/phases/6-generate-iac.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/phases/6-generate-iac.md
>   - `references/phases/7-deploy.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/phases/7-deploy.md
>   - `references/resources/ai-ml.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/resources/ai-ml.md
>   - `references/resources/compute-apps.md` — https://raw.githubusercontent.com/microsoft/azure-skills/main/skills/azure-enterprise-infra-planner/references/resources/compute-apps.md
>   - …and 15 more, listed in https://skillsdocs.com/api/v1/books/microsoft/azure-skills/skills/azure-enterprise-infra-planner
>
> Content © its authors, served unmodified. Takedown: https://github.com/kyleledbetter/skillsdocs/issues/new?labels=takedown&title=Takedown+request

<!-- Verbatim upstream SKILL.md follows, YAML frontmatter included. -->

---
name: azure-enterprise-infra-planner
description: "Architect and provision enterprise Azure infrastructure from workload descriptions. For cloud architects and platform engineers planning networking, identity, security, compliance, and multi-resource topologies with WAF alignment. Generates Bicep or Terraform directly (no azd). WHEN: 'plan Azure infrastructure', 'architect Azure landing zone', 'design hub-spoke network', 'plan multi-region DR topology', 'set up VNets firewalls and private endpoints', 'subscription-scope Bicep deployment', 'Azure Backup for VM workloads'. PREFER azure-prepare FOR app-centric workflows."
license: MIT
metadata:
  author: Microsoft
  version: "1.3.1"
---

# Azure Enterprise Infra Planner

## When to Use This Skill

Activate this skill when user wants to:
- Plan enterprise Azure infrastructure from a workload or architecture description
- Architect a landing zone, hub-spoke network, or multi-region topology
- Design networking infrastructure: VNets, subnets, firewalls, private endpoints, VPN gateways
- Plan identity, RBAC, and compliance-driven infrastructure
- Generate Bicep or Terraform for subscription-scope or multi-resource-group deployments
- Plan disaster recovery, failover, or cross-region high-availability topologies

## Quick Reference

| Property | Details |
|---|---|
| MCP tools | `insights_get`, `get_azure_bestpractices_get`, `wellarchitectedframework_serviceguide_get`, `microsoft_docs_fetch`, `microsoft_docs_search`, `bicepschema_get` |
| CLI commands | `az deployment group create`, `az bicep build`, `az resource list`, `terraform init`, `terraform plan`, `terraform validate`, `terraform apply` |
| Output schema | [schema.md](references/schema.md) |
| Key references | [workflow.md](references/workflow.md), [waf-checklist.md](references/waf-checklist.md), [resources/](references/resources/README.md), [constraints/](references/constraints/README.md) |

## Workflow (Start Here)

Follow the step-by-step instructions in [workflow.md](references/workflow.md) to execute the 7 phases of infrastructure planning and provisioning.

## MCP Tools

| Tool | Purpose |
|------|---------|
| `insights_get` | Retrieve insights about the user's existing Azure environment to guide planning decisions |
| `get_azure_bestpractices_get` | Azure best practices for code generation, operations, and deployment |
| `wellarchitectedframework_serviceguide_get` | WAF service guide for a specific Azure service |
| `microsoft_docs_search` | Search Microsoft Learn for relevant documentation chunks |
| `microsoft_docs_fetch` | Fetch full content of a Microsoft Learn page by URL |
| `bicepschema_get` | Bicep schema definition for any Azure resource type (latest API version) |

## Error Handling

| Error | Cause | Fix |
|---|---|---|
| MCP tool error or not available | Tool call timeout, connection error, or tool doesn't exist | Retry once; fall back to reference files and notify user if unresolved |
| Plan approval missing | `meta.status` is not `approved` | Stop and prompt user for approval before IaC generation or deployment |
| IaC validation failure | `az bicep build` or `terraform validate` returns errors | Fix the generated code and re-validate; notify user if unresolved |
| Pairing constraint violation | Incompatible SKU or resource combination | Fix in plan before proceeding to IaC generation |
| Infra plan or IaC files not found | Files written to wrong location or not created | Verify files exist at `<project-root>/.azure/` and `<project-root>/infra/`; if missing, re-create the files by following [workflow.md](references/workflow.md) exactly |
