defender-for-apis

Installation
SKILL.md

Microsoft Defender for APIs

Defender for APIs is a Microsoft Defender for Cloud plan that provides visibility into the security posture of APIs published in Azure API Management, prioritises them by risk, and detects active threats and abuse. It is detection and posture, not a WAF or API gateway.

When to use

Use this skill when securing APIs that are already published through Azure API Management and you need risk-based prioritisation plus runtime threat detection.

Do not use this skill for:

  • Designing API security from scratch (use api-security-design for OWASP API Top 10)
  • APIs fronted by Application Gateway / Front Door without APIM (out of scope today)
  • WAF tuning or rate-limiting design (APIM policies, not Defender)

Triage which APIs to protect first

Defender for APIs onboards everything in APIM by default. The work is prioritisation. Use this table to rank your inventory:

Installs
79
GitHub Stars
173
First Seen
Jun 10, 2026
defender-for-apis — vinayaklatthe/microsoft-security-skills