Agent skill

Ms365 Tenant Manager

by borghei in borghei/Claude-Skills

Microsoft 365 tenant administration for Global Administrators.

MITAuto-check passedDocuments & Office

Install Ms365 Tenant Manager

skills CLI
$ npx skills add borghei/Claude-Skills --skill ms365-tenant-manager -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills ms365-tenant-manager --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/engineering/ms365-tenant-manager .claude/skills/ms365-tenant-manager && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ms365-tenant-manager
GitHub stars
886
Token cost
~1.8k tokens
SKILL.md length
743 words
Files
11 (incl. scripts, references)
Skills in repo
354
Repo updated
First seen
Licence
MIT

At a glance

Microsoft 365 tenant administration for Global Administrators.

  • Azure AD user management
  • SKILL.md covers Core Capabilities, When to Use, Clarify First and Tools, plus 3 more sections
  • Runs Python scripts from its folder
  • Exchange Online and Teams config

What it does

Ms365 Tenant Manager is an agent skill from borghei/Claude-Skills. Microsoft 365 tenant administration for Global Administrators. Use for tenant setup, Azure AD user management, Exchange Online and Teams config, Conditional Access policies, license management, and PowerShell bulk-operation scripts.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files, including scripts and reference files (for example `expected_output.json`, `references/operations-and-best-practices.md` and `references/powershell-templates.md`).

It sits in Documents & Office, covering Cloud office suites and Security review. It works with Microsoft 365, PowerShell and Microsoft Entra ID. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • Azure AD user management
  • Exchange Online and Teams config
  • Conditional Access policies
  • License management

Example prompts

  • “/ms365-tenant-manager”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ms365 Tenant Manager loads about 1.8k tokens when it runs, and up to ~17k if it reads all its reference files. Until then it costs about 63 tokens; SKILL.md has 743 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~17k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 743 words, ~1,849 tokens.

Download SKILL.mdSave it as .claude/skills/ms365-tenant-manager/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
ms365-tenant-manager
description
Microsoft 365 tenant administration for Global Administrators. Use for tenant setup, Azure AD user management, Exchange Online and Teams config, Conditional Access policies, license management, and PowerShell bulk-operation scripts.
license
MIT + Commons Clause
metadata.version
1.1.0
metadata.author
borghei
metadata.category
engineering
metadata.domain
cloud-administration
metadata.updated
2026-06-17
metadata.tags
microsoft-365, azure-ad, office-365, administration

Microsoft 365 Tenant Manager

The agent generates production-ready PowerShell scripts for M365 tenant setup, bulk user provisioning, Conditional Access policies, security audits, and license management. It automates user lifecycle operations (onboarding, offboarding), recommends license SKUs by role, and produces 7-category security audit reports via Microsoft Graph.

Core Capabilities

  • Tenant lifecycle — setup checklists, domain verification, DNS record generation, security baseline, and PowerShell setup scripts for Exchange, SharePoint, Teams.
  • User lifecycle automation — bulk provisioning from CSV, secure 11-step offboarding, license recommendations by role/department, group membership suggestions, data validation.
  • Security & compliance — Conditional Access policy generation (report-only first), MFA enforcement, and 7-category security audits (MFA, admin roles, inactive users, guests, licenses, mailbox delegations, CA policies).
  • License management — SKU recommendations and distribution/cost estimates adjusted for GDPR/HIPAA compliance requirements.
  • PowerShell generation — Microsoft Graph-based scripts with error handling, logging, and -WhatIf support.

When to Use

  • New tenant setup — generate phased checklist, DNS records, and baseline scripts.
  • Security hardening — run audits and stand up Conditional Access / MFA policies.
  • Bulk user provisioning or secure offboarding.
  • License planning and quarterly utilization review.

Clarify First

Before generating scripts, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Task — tenant setup, security audit/hardening, bulk provisioning, or offboarding (selects tenant_setup.py vs powershell_generator.py vs user_management.py)
  • Tenant inputs — the domain, the user CSV, or the role/department data (the input the modules consume)
  • Compliance regime — GDPR/HIPAA or none (adjusts license SKU recommendations and the security baseline)

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the artifact.

Tools

The scripts are importable Python modules (instantiate a class, not a CLI). Full API, parameters, and worked examples are in references/tools-and-workflows.md.

ToolPurposeEntry point
powershell_generator.pySecurity audit, Conditional Access, and bulk license scriptsfrom powershell_generator import PowerShellScriptGenerator
user_management.pyProvisioning, offboarding, license/group recommendations, validationfrom user_management import UserLifecycleManager
tenant_setup.pySetup checklist, DNS records, setup script, license distributionfrom tenant_setup import TenantSetupManager

References

Load the reference that matches the task — keep this file lean and pull detail on demand:

  • references/tools-and-workflows.md — Quick Start commands, per-tool usage/parameters, the 3 end-to-end workflows (setup, hardening, offboarding), and the full Python module API for all three scripts. Read when running the tools or wiring up the API.
  • references/operations-and-best-practices.md — best practices, limitations, required modules/permissions, anti-patterns, the troubleshooting table, and success criteria. Read before hardening a tenant or shipping scripts.
  • references/powershell-templates.md — ready-to-use script templates: Conditional Access policy examples, bulk user provisioning, and security audit scripts.
  • references/security-policies.md — Conditional Access configuration, MFA enforcement strategies, DLP/retention policies, and security baseline settings.
  • references/troubleshooting.md — common error resolutions, PowerShell module issues, permission troubleshooting, and DNS propagation problems.
Show full SKILL.md (306 more words)Show less

Scope & Limitations

What This Skill Covers

  • Tenant lifecycle management -- initial setup, domain verification, DNS configuration, security baseline, and service provisioning for Exchange Online, SharePoint, Teams, and OneDrive
  • User lifecycle automation -- bulk provisioning from CSV, license assignment by role/department, group membership recommendations, secure offboarding with mailbox preservation
  • Security and compliance -- Conditional Access policy generation, MFA enforcement, comprehensive 7-category security audits, and audit log enablement
  • PowerShell script generation -- production-ready scripts with error handling, logging, -WhatIf support, and Microsoft Graph best practices

What This Skill Does NOT Cover

  • Hybrid identity (AD Connect) -- on-premises Active Directory synchronization and pass-through authentication require the senior-devops skill and Microsoft AD Connect tooling
  • Intune device management -- endpoint compliance policies, app deployment, and mobile device management are outside scope; see senior-secops for device security posture
  • Power Platform administration -- Power Apps, Power Automate, and Power BI tenant-level governance fall under separate platform administration
  • Third-party SSO and SCIM provisioning -- integration with non-Microsoft identity providers (Okta, Ping, Auth0) requires dedicated identity engineering

Integration Points

SkillIntegrationData Flow
senior-secopsSecurity audit findings feed into SecOps incident response and threat remediation workflowsAudit CSV reports (MFA status, admin roles, inactive users) → SecOps triage and hardening actions
senior-devopsTenant setup scripts integrate with infrastructure-as-code pipelines for repeatable deploymentsGenerated PowerShell scripts → CI/CD pipeline execution → tenant configuration state
senior-architectLicense distribution recommendations and tenant topology inform enterprise architecture decisionsLicense cost analysis and user count projections → architecture capacity planning
code-reviewerGenerated PowerShell scripts can be reviewed for security anti-patterns and credential handlingPowerShell script output → code review for hardcoded secrets, missing error handling
aws-solution-architectMulti-cloud identity federation between Azure AD and AWS IAM for organizations using both platformsAzure AD tenant configuration → cross-cloud SSO and role mapping
senior-securityConditional Access policies and MFA enforcement align with broader organizational security postureCA policy configurations and security audit results → security policy compliance validation

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files (scripts, references) in engineering/ms365-tenant-manager of borghei/Claude-Skills.

  • SKILL.md
  • expected_output.json
  • references/operations-and-best-practices.md
  • references/powershell-templates.md
  • references/security-policies.md
  • references/tools-and-workflows.md
  • references/troubleshooting.md
  • sample_input.json
  • scripts/powershell_generator.py
  • scripts/tenant_setup.py
  • scripts/user_management.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Ms365 Tenant Manager next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ms365 Tenant Manager compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ms365 Tenant Manager this skillborghei/Claude-Skills886—~1.8kAutomated safety check: PassMIT
CLI Microsoft365 Scriptpnp/cli-microsoft365-mcp-server132—~3.3kAutomated safety check: PassMIT
Entra Agent Usergithub/awesome-copilot40k1 repos~2.3kAutomated safety check: PassMIT
CLI Microsoft365pnp/cli-microsoft365-mcp-server132—~3.5kAutomated safety check: PassMIT
Ms365 Tenant Manageralirezarezvani/claude-skills28k1 repos~2.8kAutomated safety check: PassMIT
Code Reviewpnp/powershell906—~385Automated safety check: PassMIT

Similar skills

  • CLI Microsoft365 Script

    pnp/cli-microsoft365-mcp-server

    Write PowerShell scripts using CLI for Microsoft 365 commands to automate Microsoft 365 management tasks.

    132 GitHub stars~3.3k tokensUpdated 4 days ago
    Documents & OfficeAuto-check passed
  • Entra Agent User

    github/awesome-copilot

    Official

    Create Agent Users in Microsoft Entra ID from Agent Identities, enabling AI agents to act as digital workers with user identity capabilities in Microsoft 365 and Azure environments.

    40k GitHub starsUsed in 1 repo~2.3k tokens
    Documents & OfficeAuto-check passed
  • CLI Microsoft365

    pnp/cli-microsoft365-mcp-server

    Use CLI for Microsoft 365 to manage Microsoft 365 tenants from the terminal.

    132 GitHub stars~3.5k tokensUpdated 4 days ago
    Documents & OfficeAuto-check passed
  • Ms365 Tenant Manager

    alirezarezvani/claude-skills

    Microsoft 365 tenant administration for Global Administrators.

    28k GitHub starsUsed in 1 repo~2.8k tokens
    Documents & OfficeAuto-check passed
  • Code Review

    pnp/powershell

    Reviews changes to PnP PowerShell, a .NET 8 module of 800+ cmdlets for Microsoft 365.

    906 GitHub stars~385 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Detecting Email Account Compromise

    mukul975/Anthropic-Cybersecurity-Skills

    Detect compromised O365 and Google Workspace email accounts by analyzing Unified Audit Logs and Azure AD sign-in logs for impossible travel, inbox rule creation/deletion (Set-InboxRule…

    34k GitHub stars~823 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from borghei/Claude-Skills

All 354 skills in this repo
  • Agent Harness

    borghei/Claude-Skills

    Test and evaluation harness for AI agents — scenario suites, deterministic replay, regression diffing, cost and latency budgets.

    886 GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    886 GitHub stars~4.2k tokensUpdated 2 days ago
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    886 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    886 GitHub stars~3.6k tokensUpdated 2 days ago
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    886 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    886 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed

Questions about Ms365 Tenant Manager

What does Ms365 Tenant Manager do?

Microsoft 365 tenant administration for Global Administrators. Ms365 Tenant Manager is an agent skill from borghei/Claude-Skills. Microsoft 365 tenant administration for Global Administrators.

When should I use Ms365 Tenant Manager?

Ms365 Tenant Manager fits situations like: azure AD user management; exchange Online and Teams config; conditional Access policies; license management.

How do I install Ms365 Tenant Manager in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill ms365-tenant-manager -a claude-code`. Or copy the skill folder (engineering/ms365-tenant-manager in borghei/Claude-Skills) into .claude/skills/ms365-tenant-manager in your project. Claude Code loads it when a task matches its description.

How do I install Ms365 Tenant Manager in Codex?

Run `npx skills add borghei/Claude-Skills --skill ms365-tenant-manager -a codex`. Or copy the skill folder (engineering/ms365-tenant-manager in borghei/Claude-Skills) into .agents/skills/ms365-tenant-manager in your project. Codex loads it when a task matches its description.

Can I use Ms365 Tenant Manager in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill ms365-tenant-manager -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ms365-tenant-manager, .gemini/skills/ms365-tenant-manager, .github/skills/ms365-tenant-manager and .opencode/skills/ms365-tenant-manager in your project.

What does Ms365 Tenant Manager need to run?

Going by SKILL.md and its folder, Ms365 Tenant Manager needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Ms365 Tenant Manager access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ms365 Tenant Manager safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Ms365 Tenant Manager use?

Ms365 Tenant Manager is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ms365 Tenant Manager use?

About 1.8k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 15k tokens, read only when the agent opens those files.

What are the alternatives to Ms365 Tenant Manager?

Skills that share tags, products or a category with Ms365 Tenant Manager: CLI Microsoft365 Script (pnp/cli-microsoft365-mcp-server, 132 stars), Entra Agent User (github/awesome-copilot, 40k stars), CLI Microsoft365 (pnp/cli-microsoft365-mcp-server, 132 stars) and Ms365 Tenant Manager (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ms365 Tenant Manager?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 886 GitHub stars. The repository holds 354 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.