defender-for-apis
Installation
SKILL.md
Microsoft Defender for APIs
Defender for APIs is a Microsoft Defender for Cloud plan that provides visibility into the security posture of APIs published in Azure API Management, prioritises them by risk, and detects active threats and abuse. It is detection and posture, not a WAF or API gateway.
When to use
Use this skill when securing APIs that are already published through Azure API Management and you need risk-based prioritisation plus runtime threat detection.
Do not use this skill for:
- Designing API security from scratch (use
api-security-designfor OWASP API Top 10) - APIs fronted by Application Gateway / Front Door without APIM (out of scope today)
- WAF tuning or rate-limiting design (APIM policies, not Defender)
Triage which APIs to protect first
Defender for APIs onboards everything in APIM by default. The work is prioritisation. Use this table to rank your inventory: