Skip to content
View simon-vedder's full-sized avatar

Block or report simon-vedder

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
simon-vedder/README.md

Simon Vedder, cloud and cloud-security engineer in Zurich. Azure automation, identity audits, infrastructure as code: unattended OS upgrades, credential rotation, scheduled VM power, privileged-role audits, app-registration audits, least-privilege RBAC.

Blog Tools LinkedIn

Cloud & cloud-security engineer near Zurich. I work across Azure platform engineering and cloud security, with a focus on Microsoft Entra ID, RBAC and infrastructure-as-code. Some of the tools below run tedious Azure work unattended, the others audit what a tenant actually allows. All of them are tested against live tenants before they're written up at simonvedder.com, and each one with a page there comes with deploy steps and a command reference.

Tools

Tool Kind What it does Ships as
Least Privilege Studio Web app Pick the actions you need for Azure RBAC or Entra ID and get the narrowest roles that cover them — or just paste in your Terraform. Browser
RiskyRolesAnalyzer Audit One script, one HTML report: every privileged Azure RBAC and Entra role assignment, including the ones behind groups, custom roles and dormant apps PowerShell · page
AppLifecycleAnalyzer Audit One script, one HTML report: every Entra ID app registration with its credentials, their expiry dates and when the app was last used PowerShell · page
AzureInPlaceUpgrade Automation Name a VM and a target, and it goes from Windows Server 2016, 2019 or 2022 to 2025 in place — nobody logs on Module + Bicep (preview) · page · Gallery
AzureVMCredentialRotation Automation Rotates local admin passwords and SSH keys on the Azure VMs that Windows LAPS and Entra login cannot reach PowerShell · page · Gallery
VM Power Management Automation Start and stop VMs on a schedule without keeping a list of machines — the tag names the schedule Runbook (preview) · page · Gallery
Deallocate on Activity Log Automation A guest shutdown stops the OS and keeps billing the VM — an activity-log alert and a Logic App deallocate it within minutes Logic App · page
NSG Gap Finder Audit Azure VMs whose NIC or subnet has no network security group attached PowerShell
VM OS Audit Audit The operating systems actually running, including the forgotten ones PowerShell
Golden Image Builder Blueprint Gallery, image definitions, build templates and the monthly schedule Bicep
Self-Service VM Ordering Blueprint A web form, a Logic App and a queue instead of portal access — VMs and AVD session hosts ARM

Claude Code skills in skills: azure-cost · azure-rbac-advisor · azure-updates

Collections: powershell · terraform-azure · bicep · arm · kql

Recently shipped

Upstream

Latest posts

More at simonvedder.com · LinkedIn

The tools table, releases, upstream list and posts are regenerated every Monday by a workflow from the tools catalogue, GitHub and the blog.

Pinned Loading

  1. least-privilege-studio least-privilege-studio Public

    Least-privilege Azure RBAC — find the minimal role that covers a set of Azure actions.

    JavaScript 1

  2. app-lifecycle-analyzer app-lifecycle-analyzer Public

    Read-only lifecycle audit for Entra ID app registrations — secrets, certs, federated creds, sign-in activity, in one HTML report

    PowerShell

  3. azure-vm-power-management azure-vm-power-management Public

    Tag-driven start/stop for Azure VMs via an AutoShutdown tag — runbook + Terraform + optional GUI

    PowerShell

  4. azure-vm-inplace-upgrade azure-vm-inplace-upgrade Public

    Tag-driven, unattended in-place upgrades of Windows Server on Azure VMs: preflight, snapshot, detached Setup, Azure Automation state machine, Log Analytics workbook.

    PowerShell