Agent skill

Ms365 Tenant Manager

by alirezarezvani in alirezarezvani/claude-code-skill-factory

Comprehensive Microsoft 365 tenant administration skill for setup, configuration, user management, security policies, and organizational structure optimization for Global Administrators

MITAuto-check passedDocuments & Office

Install Ms365 Tenant Manager

skills CLI
$ npx skills add alirezarezvani/claude-code-skill-factory --skill ms365-tenant-manager -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alirezarezvani/claude-code-skill-factory ms365-tenant-manager --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alirezarezvani/claude-code-skill-factory.git skills-src && mkdir -p .claude/skills && cp -r skills-src/generated-skills/ms365-tenant-manager .claude/skills/ms365-tenant-manager && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ms365-tenant-manager
GitHub stars
882
Used in
1 other repo
Token cost
~2.4k tokens
SKILL.md length
1,061 words
Files
10
Skills in repo
12
Repo updated
First seen
Licence
MIT

At a glance

Comprehensive Microsoft 365 tenant administration skill for setup, configuration, user management, security policies, and organizational structure optimization for Global Administrators

  • Works in 5 steps: Enable MFA first - Before adding users,… → Configure named locations - Define… → Set up privileged access - Use separate… → …
  • Tasks that involve Cloud office suites
  • SKILL.md covers Capabilities, Input Requirements, Output Formats and How to Use, plus 8 more sections
  • Runs Python scripts from its folder

What it does

Ms365 Tenant Manager is an agent skill from alirezarezvani/claude-code-skill-factory. Comprehensive Microsoft 365 tenant administration skill for setup, configuration, user management, security policies, and organizational structure optimization for Global Administrators

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files (for example `HOW_TO_USE.md`, `expected_output.json` and `powershell_generator.py`).

It sits in Documents & Office, covering Cloud office suites. It works with Microsoft 365. The repository describes itself as: Claude Code Skill Factory — A powerful open-source toolkit for building and deploying production-ready Claude Skills, Code Agents, custom Slash Commands, and LLM Prompts at… The licence is MIT.

When your agent uses it

  • Tasks that involve Cloud office suites

Example prompts

  • “/ms365-tenant-manager”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Enable MFA first - Before adding users, enforce multi-factor authentication
  2. Configure named locations - Define trusted IP ranges for Conditional Access
  3. Set up privileged access - Use separate admin accounts, enable PIM (Privileged Identity Management)
  4. Domain verification - Add and verify custom domains before bulk user creation
  5. Baseline security - Apply Microsoft Secure Score recommendations immediately

What it can do on your machine

Read from SKILL.md and the folder at commit ba18b31. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • admin.microsoft.com
    • developer.microsoft.com
    • powershellgallery.com
    • compliance.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ms365 Tenant Manager loads about 2.4k tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 1,061 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alirezarezvani/claude-code-skill-factory at commit ba18b31, republished under its MIT licence (© alirezarezvani). 1,061 words, ~2,385 tokens.

Download SKILL.mdSave it as .claude/skills/ms365-tenant-manager/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
ms365-tenant-manager
description
Comprehensive Microsoft 365 tenant administration skill for setup, configuration, user management, security policies, and organizational structure optimization for Global Administrators

Microsoft 365 Tenant Manager

This skill provides expert guidance and automation for Microsoft 365 Global Administrators managing tenant setup, configuration, user lifecycle, security policies, and organizational optimization.

Capabilities

  • Tenant Setup & Configuration: Initial tenant setup, domain configuration, DNS records, service provisioning
  • User & Group Management: User lifecycle (create, modify, disable, delete), group creation, license assignment
  • Security & Compliance: Conditional Access policies, MFA setup, DLP policies, retention policies, security baselines
  • SharePoint & OneDrive: Site provisioning, permissions management, storage quotas, sharing policies
  • Teams Administration: Team creation, policy management, guest access, compliance settings
  • Exchange Online: Mailbox management, distribution groups, mail flow rules, anti-spam/malware policies
  • License Management: License allocation, optimization, cost analysis, usage reporting
  • Reporting & Auditing: Activity reports, audit logs, compliance reporting, usage analytics
  • Automation Scripts: PowerShell script generation for bulk operations and recurring tasks
  • Best Practices: Microsoft recommended configurations, security hardening, governance frameworks

Input Requirements

Tenant management tasks require:

  • Action type: setup, configure, create, modify, delete, report, audit
  • Resource details: User info, group names, policy settings, service configurations
  • Organizational context: Company size, industry, compliance requirements (GDPR, HIPAA, etc.)
  • Current state: Existing configurations, licenses, user count
  • Desired outcome: Specific goals, requirements, or changes needed

Formats accepted:

  • Text descriptions of administrative tasks
  • JSON with structured configuration data
  • CSV for bulk user/group operations
  • Existing PowerShell scripts to review or modify

Output Formats

Results include:

  • Step-by-step instructions: Detailed guidance for manual configuration via Admin Center
  • PowerShell scripts: Ready-to-use scripts for automation (with safety checks)
  • Configuration recommendations: Security and governance best practices
  • Validation checklists: Pre/post-implementation verification steps
  • Documentation: Markdown documentation of changes and configurations
  • Rollback procedures: Instructions to undo changes if needed
  • Compliance reports: Security posture and compliance status

How to Use

"Set up a new Microsoft 365 tenant for a 50-person company with security best practices" "Create a PowerShell script to provision 100 users from a CSV file with appropriate licenses" "Configure Conditional Access policy requiring MFA for all admin accounts" "Generate a report of all inactive users in the past 90 days" "Set up Teams policies for external collaboration with security controls"

Scripts

  • tenant_setup.py: Initial tenant configuration and service provisioning automation
  • user_management.py: User lifecycle operations and bulk provisioning
  • security_policies.py: Security policy configuration and compliance checks
  • reporting.py: Analytics, audit logs, and compliance reporting
  • powershell_generator.py: Generates PowerShell scripts for Microsoft Graph API and admin modules

Best Practices

Tenant Setup
  1. Enable MFA first - Before adding users, enforce multi-factor authentication
  2. Configure named locations - Define trusted IP ranges for Conditional Access
  3. Set up privileged access - Use separate admin accounts, enable PIM (Privileged Identity Management)
  4. Domain verification - Add and verify custom domains before bulk user creation
  5. Baseline security - Apply Microsoft Secure Score recommendations immediately
User Management
  1. License assignment - Use group-based licensing for scalability
  2. Naming conventions - Establish consistent user principal names (UPNs) and display names
  3. Lifecycle management - Implement automated onboarding/offboarding workflows
  4. Guest access - Enable only when necessary, set expiration policies
  5. Shared mailboxes - Use for department emails instead of assigning licenses
Security & Compliance
  1. Zero Trust approach - Verify explicitly, use least privilege access, assume breach
  2. Conditional Access - Start with report-only mode, then enforce gradually
  3. Data Loss Prevention - Define sensitive information types, test policies before enforcement
  4. Retention policies - Balance compliance requirements with storage costs
  5. Regular audits - Review permissions, licenses, and security settings quarterly
SharePoint & Teams
  1. Site provisioning - Use templates and governance policies
  2. External sharing - Restrict to specific domains, require authentication
  3. Storage management - Set quotas, enable auto-cleanup of old content
  4. Teams templates - Create standardized team structures for consistency
  5. Guest lifecycle - Set expiration and regular recertification
PowerShell Automation
  1. Use Microsoft Graph - Prefer Graph API over legacy MSOnline modules
  2. Error handling - Include try/catch blocks and validation checks
  3. Dry-run mode - Test scripts with -WhatIf before executing
  4. Logging - Capture all operations for audit trails
  5. Credential management - Use Azure Key Vault or managed identities, never hardcode

Common Tasks

Show full SKILL.md (424 more words)Show less
Initial Tenant Setup
  • Configure company branding
  • Add and verify custom domains
  • Set up DNS records (MX, SPF, DKIM, DMARC)
  • Enable required services (Teams, SharePoint, Exchange)
  • Create organizational structure (departments, locations)
  • Set default user settings and policies
User Onboarding
  • Create user accounts (single or bulk)
  • Assign appropriate licenses
  • Add to security and distribution groups
  • Configure mailbox and OneDrive
  • Set up multi-factor authentication
  • Provision Teams access
Security Hardening
  • Enable Security Defaults or Conditional Access
  • Configure MFA enforcement
  • Set up admin role assignments
  • Enable audit logging
  • Configure anti-phishing policies
  • Set up DLP and retention policies
Reporting & Monitoring
  • Active users and license utilization
  • Security incidents and alerts
  • Mailbox usage and storage
  • SharePoint site activity
  • Teams usage and adoption
  • Compliance and audit logs

Limitations

  • Permissions required: Global Administrator or specific role-based permissions
  • API rate limits: Microsoft Graph API has throttling limits for bulk operations
  • License dependencies: Some features require specific license tiers (E3, E5)
  • Delegation constraints: Some tasks cannot be delegated to service principals
  • Regional variations: Compliance features may vary by geographic region
  • Hybrid scenarios: On-premises Active Directory integration requires additional configuration
  • Third-party integrations: External apps may require separate authentication and permissions
  • PowerShell prerequisites: Requires appropriate modules installed (Microsoft.Graph, ExchangeOnlineManagement, etc.)

Security Considerations

Authentication
  • Never store credentials in scripts or configuration files
  • Use Azure Key Vault for credential management
  • Implement certificate-based authentication for automation
  • Enable Conditional Access for admin accounts
  • Use Privileged Identity Management (PIM) for JIT access
Authorization
  • Follow principle of least privilege
  • Use custom admin roles instead of Global Admin when possible
  • Regularly review and audit admin role assignments
  • Enable PIM for temporary elevated access
  • Separate user accounts from admin accounts
Compliance
  • Enable audit logging for all activities
  • Retain logs according to compliance requirements
  • Configure data residency for regulated industries
  • Implement information barriers where needed
  • Regular compliance assessments and reporting

PowerShell Modules Required

To execute generated scripts, ensure these modules are installed:

  • Microsoft.Graph (recommended, modern Graph API)
  • ExchangeOnlineManagement (Exchange Online management)
  • MicrosoftTeams (Teams administration)
  • SharePointPnPPowerShellOnline (SharePoint management)
  • AzureAD or AzureADPreview (Azure AD management - being deprecated)
  • MSOnline (Legacy, being deprecated - avoid when possible)

Updates & Maintenance

  • Microsoft 365 features and APIs evolve rapidly
  • Review Microsoft 365 Roadmap regularly for upcoming changes
  • Test scripts in non-production tenant before production deployment
  • Subscribe to Microsoft 365 Admin Center message center for updates
  • Keep PowerShell modules updated to latest versions
  • Regular security baseline reviews (quarterly recommended)

Helpful Resources

© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files in generated-skills/ms365-tenant-manager of alirezarezvani/claude-code-skill-factory.

  • SKILL.md
  • HOW_TO_USE.md
  • __pycache__/powershell_generator.cpython-313.pyc
  • __pycache__/tenant_setup.cpython-313.pyc
  • __pycache__/user_management.cpython-313.pyc
  • expected_output.json
  • powershell_generator.py
  • sample_input.json
  • tenant_setup.py
  • user_management.py

Open the folder on GitHubat commit ba18b31

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in alirezarezvani/claude-code-skill-factory, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Ms365 Tenant Manager next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ms365 Tenant Manager compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ms365 Tenant Manager this skillalirezarezvani/claude-code-skill-factory8821 repos~2.4kAutomated safety check: PassMIT
M365 Agent Evaluatormicrosoft/work-iq1k—~2kAutomated safety check: NotesCustom licence
Microsoft 365 Agents ToolkitOfficeDev/microsoft-365-agents-toolkit780—~2.8kAutomated safety check: NotesCustom licence
Msgraphcodemie-ai/codemie-code294—~4.1kAutomated safety check: PassApache-2.0
aai-cli Microsoft 365aai-labs/agent-barn109—~1.2kAutomated safety check: PassApache-2.0
Workiqmicrosoft/work-iq1k—~15kAutomated safety check: PassCustom licence

Similar skills

  • M365 Agent Evaluator

    microsoft/work-iq

    Official

    A skill your agent uses when a user wants to create, run, or analyze evaluation suites for Microsoft 365 Copilot declarative agents with the public @microsoft/m365-copilot-eval CLI.

    1k GitHub stars~2k tokensUpdated yesterday
    Documents & OfficeAuto-check: notes
  • Microsoft 365 Agents Toolkit

    OfficeDev/microsoft-365-agents-toolkit

    Builds, tests, and deploys Microsoft 365 apps and agents for Teams and Copilot.

    780 GitHub stars~2.8k tokensUpdated today
    Documents & OfficeAuto-check: notes
  • Msgraph

    codemie-ai/codemie-code

    Work with Microsoft 365 services via the Graph API — emails, calendar events, SharePoint sites (read and write), Teams chats and channel messages, OneDrive files, OneNote notebooks, Planner task…

    294 GitHub stars~4.1k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • aai-cli Microsoft 365

    aai-labs/agent-barn

    Guides work with Outlook, OneDrive, SharePoint, Teams, Excel, To Do and Planner through aai-cli's Microsoft Graph commands, starting from which service owns the data.

    109 GitHub stars~1.2k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Workiq

    microsoft/work-iq

    Official

    WorkIQ tools for Microsoft 365 workplace data and actions. An agent skill from microsoft/work-iq.

    1k GitHub stars~15k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Workiq Preview

    microsoft/work-iq

    Official

    WorkIQ tools for Microsoft 365 workplace data and actions. An agent skill from microsoft/work-iq.

    1k GitHub stars~3.3k tokensUpdated yesterday
    Documents & OfficeAuto-check passed

More from alirezarezvani/claude-code-skill-factory

All 12 skills in this repo
  • App Store Optimization

    alirezarezvani/claude-code-skill-factory

    Complete App Store Optimization (ASO) toolkit for researching, optimizing, and tracking mobile app performance on Apple App Store and Google Play Store

    882 GitHub starsUsed in 8 repos~4.1k tokens
    Auto-check passed
  • Claude Md Enhancer

    alirezarezvani/claude-code-skill-factory

    Analyzes, generates, and enhances CLAUDE.md files for any project type using best practices, modular architecture support, and tech stack customization.

    882 GitHub stars~4.1k tokensUpdated 11 mo ago
    Auto-check passed
  • Content Trend Researcher

    alirezarezvani/claude-code-skill-factory

    Advanced content and topic research skill that analyzes trends across Google Analytics, Google Trends, Substack, Medium, Reddit, LinkedIn, X, blogs, podcasts, and YouTube to generate data-driven…

    882 GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • TDD Guide

    alirezarezvani/claude-code-skill-factory

    Comprehensive Test Driven Development guide for engineering subagents with multi-framework support, coverage analysis, and intelligent test generation

    882 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed
  • Agent Factory

    alirezarezvani/claude-code-skill-factory

    Claude Code agent generation system that creates custom agents and sub-agents with enhanced YAML frontmatter, tool access patterns, and MCP integration support following proven production patterns

    882 GitHub stars~2k tokensUpdated 11 mo ago
    Auto-check passed
  • Codex CLI Bridge

    alirezarezvani/claude-code-skill-factory

    Bridge between Claude Code and OpenAI Codex CLI - generates AGENTS.md from CLAUDE.md, provides Codex CLI execution helpers, and enables seamless interoperability between both tools

    882 GitHub stars~2.2k tokensUpdated 11 mo ago
    Auto-check passed

Works with

Questions about Ms365 Tenant Manager

What does Ms365 Tenant Manager do?

Comprehensive Microsoft 365 tenant administration skill for setup, configuration, user management, security policies, and organizational structure optimization for Global Administrators. Ms365 Tenant Manager is an agent skill from alirezarezvani/claude-code-skill-factory.

When should I use Ms365 Tenant Manager?

Ms365 Tenant Manager fits situations like: tasks that involve Cloud office suites.

How do I install Ms365 Tenant Manager in Claude Code?

Run `npx skills add alirezarezvani/claude-code-skill-factory --skill ms365-tenant-manager -a claude-code`. Or copy the skill folder (generated-skills/ms365-tenant-manager in alirezarezvani/claude-code-skill-factory) into .claude/skills/ms365-tenant-manager in your project. Claude Code loads it when a task matches its description.

How do I install Ms365 Tenant Manager in Codex?

Run `npx skills add alirezarezvani/claude-code-skill-factory --skill ms365-tenant-manager -a codex`. Or copy the skill folder (generated-skills/ms365-tenant-manager in alirezarezvani/claude-code-skill-factory) into .agents/skills/ms365-tenant-manager in your project. Codex loads it when a task matches its description.

Can I use Ms365 Tenant Manager in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-code-skill-factory --skill ms365-tenant-manager -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ms365-tenant-manager, .gemini/skills/ms365-tenant-manager, .github/skills/ms365-tenant-manager and .opencode/skills/ms365-tenant-manager in your project.

What does Ms365 Tenant Manager need to run?

Going by SKILL.md and its folder, Ms365 Tenant Manager needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Ms365 Tenant Manager access the network?

SKILL.md names 4 domains. As links in the text: admin.microsoft.com, developer.microsoft.com, powershellgallery.com and compliance.microsoft.com. This is read from the text; nothing was executed.

Is Ms365 Tenant Manager safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ms365 Tenant Manager use?

Ms365 Tenant Manager is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ms365 Tenant Manager use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ms365 Tenant Manager?

Skills that share tags, products or a category with Ms365 Tenant Manager: M365 Agent Evaluator (microsoft/work-iq, 1k stars), Microsoft 365 Agents Toolkit (OfficeDev/microsoft-365-agents-toolkit, 780 stars), Msgraph (codemie-ai/codemie-code, 294 stars) and aai-cli Microsoft 365 (aai-labs/agent-barn, 109 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ms365 Tenant Manager?

alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-code-skill-factory, which has 882 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on November 12, 2025.

Source: alirezarezvani/claude-code-skill-factory on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.