Cloud platform
Microsoft Entra ID agent skills, page 2
Microsoft Entra ID skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | Configures Microsoft Entra ID (Azure AD) Conditional Access policies for zero trust access control, covering signal-based policy design, device compliance requirements, risk-based authentication… | mukul975/ | 34k | — | ~689 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 50 | A skill your agent uses when asked to investigate a computer, device, endpoint, or machine for security issues, suspicious activity, malware, or compliance review. | SCStelz/ | 249 | — | ~15k | Automated safety check: Warn | MIT | 2 days ago |
| 51 | 51.Azure Pim Guidance for Microsoft Entra Privileged Identity Management (PIM) — just-in-time, time-bound, approval-based, audited elevation for Entra roles, Azure resource roles, and privileged groups. | vinayaklatthe/ | 175 | — | ~1.9k | Automated safety check: Pass | MIT | 3 mo ago |
| 52 | Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation… | mukul975/ | 34k | — | ~808 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 53 | Detect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit logs, and permission analysis to identify illicit consent grant attacks. | mukul975/ | 34k | — | ~605 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 54 | Diagnose and fix incomplete local development setup. An agent skill from microsoft-foundry/foundry-agent-webapp. | microsoft-foundry/ | 127 | — | ~1.2k | Automated safety check: Notes | MIT | 5 mo ago |
| 55 | WORKFLOW SKILL — Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration. | jonathan-vella/ | 217 | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |
| 56 | Load token usage data from Azure Table Storage for faster iteration and analysis in chat conversations | rajbos/ | 116 | — | ~3k | Automated safety check: Pass | MIT | today |
| 57 | 57.Hunt M365 Microsoft 365 / Entra ID attack - tenant discovery, user enumeration via OneDrive differential (2026 verified), AADSTS code reference, Smart Lockout math (hard cap 1-2 attempts/user), ROPC… | Encod3d-Sec/ | 329 | — | ~2k | Automated safety check: Pass | MIT | 1 mo ago |
| 58 | Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation. | Kilo-Org/ | 190 | 1 repo | ~1.9k | Automated safety check: Pass | MIT | 9 days ago |
| 59 | Guidance for selecting the right Azure RBAC role with least privilege - mapping required actions to built-in roles, deciding when a custom role is needed, scoping assignments correctly, and choosing… | vinayaklatthe/ | 175 | — | ~2.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 60 | 60.Azure Auth Microsoft Entra ID (Azure AD) authentication for React SPAs with MSAL.js and Cloudflare Workers JWT validation using jose library. | LeoYeAI/ | 2.2k | — | ~4.9k | Automated safety check: Notes | MIT | 2 mo ago |
| 61 | Attack and enumerate Azure AD / Entra ID tenants — initial recon with AADInternals and ROADtools, password spraying, token theft (PRT, CAE, refresh tokens), application and service principal abuse… | trilwu/ | 156 | — | ~4.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 62 | Investigate security incidents in Microsoft 365 and Entra ID (Azure AD) -- search the Unified Audit Log, correlate sign-in and audit events, trace illicit OAuth consent grants, analyze mailbox rule… | trilwu/ | 156 | — | ~4.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 63 | Configure SAML 2.0 and OIDC SSO for Cursor with Okta, Microsoft Entra ID, and Google Workspace. | jeremylongshore/ | 2.8k | — | ~2k | Automated safety check: Pass | MIT | today |
| 64 | Microsoft 365 tenant administration for Global Administrators. | borghei/ | 881 | — | ~1.8k | Automated safety check: Pass | MIT | yesterday |
| 65 | Create new Azure Database for PostgreSQL Flexible Server instances and configure passwordless authentication with Microsoft Entra ID. | aiskillstore/ | 430 | — | ~1.5k | Automated safety check: Pass | No licence | yesterday |
| 66 | A skill your agent uses when operating Microsoft Power Automate cloud flows from code — create, enable, update, list or delete via the Dataverse Web API (workflow table, category 5) with Entra ID… | ericrisco/ | 167 | — | ~3.1k | Automated safety check: Notes | MIT | today |
| 67 | End-to-end autopilot orchestrator for setting up Microsoft Teams integration in Salesforce Service Cloud ITSM — runs the whole flow (enable the Teams for Employee Service Go feature, register the… | forcedotcom/ | 1.1k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 68 | Guidance for designing BitLocker drive encryption for Windows endpoints managed via Microsoft Intune — encryption policy, silent enablement, recovery key escrow to Entra ID, TPM, pre-boot… | vinayaklatthe/ | 175 | — | ~1.9k | Automated safety check: Pass | MIT | 3 mo ago |
| 69 | Guidance for responding to and recovering from a significant identity/tenant compromise - regaining administrative control, evicting the adversary in a single coordinated action, and hardening to… | vinayaklatthe/ | 175 | — | ~2.4k | Automated safety check: Pass | MIT | 3 mo ago |
| 70 | Guidance for Microsoft Entra Conditional Access (CA) and multifactor authentication — the Zero Trust policy engine that enforces grant/block decisions based on user, device, location, app, and risk… | vinayaklatthe/ | 175 | — | ~1.8k | Automated safety check: Pass | MIT | 3 mo ago |
| 71 | Guidance for Microsoft Defender for Identity (MDI) — identity threat detection (ITDR) across on-premises Active Directory, AD CS, AD FS, and Entra Connect using sensors. | vinayaklatthe/ | 175 | — | ~2k | Automated safety check: Pass | MIT | 3 mo ago |
| 72 | 72.Defender Xdr Guidance for Microsoft Defender XDR — the unified extended detection and response suite that correlates signals across endpoints, identities, email, and cloud apps into prioritised incidents with… | vinayaklatthe/ | 175 | — | ~2.1k | Automated safety check: Pass | MIT | 3 mo ago |
| 73 | 73.Entra Id Guidance for Microsoft Entra ID (formerly Azure AD) — cloud identity and access management and the control plane for Zero Trust. | vinayaklatthe/ | 175 | — | ~2.3k | Automated safety check: Pass | MIT | 3 mo ago |
| 74 | Guidance for Microsoft Entra ID Governance — automating identity lifecycle and access with entitlement management (access packages), access reviews, lifecycle workflows for joiner-mover-leaver… | vinayaklatthe/ | 175 | — | ~2k | Automated safety check: Pass | MIT | 3 mo ago |
| 75 | Guidance for Microsoft Entra ID Protection — risk-based identity security that detects user and sign-in risk and automates remediation. | vinayaklatthe/ | 175 | — | ~1.6k | Automated safety check: Pass | MIT | 3 mo ago |
| 76 | Guidance for Microsoft Entra Permissions Management (CIEM) — discovers, right-sizes, and monitors permissions across Microsoft Azure, AWS, and Google Cloud. | vinayaklatthe/ | 175 | — | ~1.7k | Automated safety check: Pass | MIT | 3 mo ago |
| 77 | Guidance for hardening macOS endpoints managed by Microsoft Intune — automated device enrollment via Apple Business Manager (ABM), platform single sign-on (PSSO) with Entra ID, FileVault disk… | vinayaklatthe/ | 175 | — | ~2.4k | Automated safety check: Pass | MIT | 3 mo ago |
| 78 | Guidance for managing AI agents at enterprise scale with Microsoft Agent 365 - the control plane that lets admins observe, govern, and secure every agent (Microsoft, Copilot Studio, and third-party)… | vinayaklatthe/ | 175 | — | ~2k | Automated safety check: Pass | MIT | 3 mo ago |
| 79 | 79.Pki Design Guidance for designing public key infrastructure (PKI) and certificate management on Azure and hybrid environments. | vinayaklatthe/ | 175 | — | ~2.1k | Automated safety check: Pass | MIT | 3 mo ago |
| 80 | Guidance for Windows Hello for Business (WHfB) — passwordless, phishing-resistant authentication using a PIN or biometric backed by an asymmetric key or certificate. | vinayaklatthe/ | 175 | — | ~2k | Automated safety check: Pass | MIT | 3 mo ago |