Official agent skill

Entra Agent User

by github in github/awesome-copilot

Create Agent Users in Microsoft Entra ID from Agent Identities, enabling AI agents to act as digital workers with user identity capabilities in Microsoft 365 and Azure environments.

OfficialMITAuto-check passedDocuments & Office

Install Entra Agent User

skills CLI
$ npx skills add github/awesome-copilot --skill entra-agent-user -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install github/awesome-copilot entra-agent-user --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/github/awesome-copilot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/entra-agent-user .claude/skills/entra-agent-user && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
entra-agent-user
GitHub stars
40k
Used in
1 other repo
Token cost
~2.3k tokens
SKILL.md length
626 words
Files
1
Skills in repo
417
Repo updated
First seen
Licence
MIT

At a glance

Create Agent Users in Microsoft Entra ID from Agent Identities, enabling AI agents to act as digital workers with user identity capabilities in Microsoft 365 and Azure environments.

  • Works in 4 steps: Verify the Agent Identity Exists → Create the Agent User → Assign a Manager (Optional) → …
  • Tasks that involve Building AI agents
  • SKILL.md covers Overview, Prerequisites, Architecture and Step 1: Verify the Agent…, plus 8 more sections
  • Reaches graph.microsoft.com

What it does

Entra Agent User is an agent skill from github/awesome-copilot, published by the product's own GitHub organization. Create Agent Users in Microsoft Entra ID from Agent Identities, enabling AI agents to act as digital workers with user identity capabilities in Microsoft 365 and Azure environments.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Documents & Office, covering Building AI agents and Cloud office suites. It works with Microsoft Entra ID, Microsoft 365, Microsoft Azure and PowerShell. The repository describes itself as: Community-contributed instructions, agents, skills, and configurations to help you make the most of GitHub Copilot. The licence is MIT.

When your agent uses it

  • Tasks that involve Building AI agents
  • Tasks that involve Cloud office suites

Example prompts

  • “/entra-agent-user”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Verify the Agent Identity Exists
  2. Create the Agent User
  3. Assign a Manager (Optional)
  4. Set Usage Location and Assign Licenses (Optional)

What it can do on your machine

Read from SKILL.md and the folder at commit 727ff2e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are http, powershell and json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • graph.microsoft.com

    Also links to:

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Entra Agent User loads about 2.3k tokens when it runs. Until then it costs about 50 tokens; SKILL.md has 626 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~50
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from github/awesome-copilot at commit 727ff2e, republished under its MIT licence (© github). 626 words, ~2,308 tokens.

Download SKILL.mdSave it as .claude/skills/entra-agent-user/SKILL.md (or your agent's skills folder).
name
entra-agent-user
description
Create Agent Users in Microsoft Entra ID from Agent Identities, enabling AI agents to act as digital workers with user identity capabilities in Microsoft 365 and Azure environments.

SKILL: Creating Agent Users in Microsoft Entra Agent ID

Overview

An agent user is a specialized user identity in Microsoft Entra ID that enables AI agents to act as digital workers. It allows agents to access APIs and services that strictly require user identities (e.g., Exchange mailboxes, Teams, org charts), while maintaining appropriate security boundaries.

Agent users receive tokens with idtyp=user, unlike regular agent identities which receive idtyp=app.


Prerequisites

  • A Microsoft Entra tenant with Agent ID capabilities
  • An agent identity (service principal of type ServiceIdentity) created from an agent identity blueprint
  • One of the following permissions:
    • AgentIdUser.ReadWrite.IdentityParentedBy (least privileged)
    • AgentIdUser.ReadWrite.All
    • User.ReadWrite.All
  • The caller must have at minimum the Agent ID Administrator role (in delegated scenarios)

Important: The identityParentId must reference a true agent identity (created via an agent identity blueprint), NOT a regular application service principal. You can verify by checking that the service principal has @odata.type: #microsoft.graph.agentIdentity and servicePrincipalType: ServiceIdentity.


Architecture

Agent Identity Blueprint (application template)
    │
    ├── Agent Identity (service principal - ServiceIdentity)
    │       │
    │       └── Agent User (user - agentUser) ← 1:1 relationship
    │
    └── Agent Identity Blueprint Principal (service principal in tenant)
ComponentTypeToken ClaimPurpose
Agent IdentityService Principalidtyp=appBackend/API operations
Agent UserUser (agentUser)idtyp=userAct as a digital worker in M365

Step 1: Verify the Agent Identity Exists

Before creating an agent user, confirm the agent identity is a proper agentIdentity type:

http
GET https://graph.microsoft.com/beta/servicePrincipals/{agent-identity-id}
Authorization: Bearer <token>

Verify the response contains:

json
{
  "@odata.type": "#microsoft.graph.agentIdentity",
  "servicePrincipalType": "ServiceIdentity",
  "agentIdentityBlueprintId": "<blueprint-id>"
}
PowerShell
powershell
Connect-MgGraph -Scopes "Application.Read.All" -TenantId "<tenant>" -UseDeviceCode -NoWelcome
Invoke-MgGraphRequest -Method GET `
  -Uri "https://graph.microsoft.com/beta/servicePrincipals/<agent-identity-id>" | ConvertTo-Json -Depth 3

Common mistake: Using an app registration's appId or a regular application service principal's id will fail. Only agent identities created from blueprints work.


Step 2: Create the Agent User

HTTP Request
http
POST https://graph.microsoft.com/beta/users/microsoft.graph.agentUser
Content-Type: application/json
Authorization: Bearer <token>

{
  "accountEnabled": true,
  "displayName": "My Agent User",
  "mailNickname": "my-agent-user",
  "userPrincipalName": "my-agent-user@yourtenant.onmicrosoft.com",
  "identityParentId": "<agent-identity-object-id>"
}
Required Properties
PropertyTypeDescription
accountEnabledBooleantrue to enable the account
displayNameStringHuman-friendly name
mailNicknameStringMail alias (no spaces/special chars)
userPrincipalNameStringUPN — must be unique in the tenant (alias@verified-domain)
identityParentIdStringObject ID of the parent agent identity
PowerShell
powershell
Connect-MgGraph -Scopes "User.ReadWrite.All" -TenantId "<tenant>" -UseDeviceCode -NoWelcome

$body = @{
  accountEnabled    = $true
  displayName       = "My Agent User"
  mailNickname      = "my-agent-user"
  userPrincipalName = "my-agent-user@yourtenant.onmicrosoft.com"
  identityParentId  = "<agent-identity-object-id>"
} | ConvertTo-Json

Invoke-MgGraphRequest -Method POST `
  -Uri "https://graph.microsoft.com/beta/users/microsoft.graph.agentUser" `
  -Body $body -ContentType "application/json" | ConvertTo-Json -Depth 3
Key Notes
  • No password — agent users cannot have passwords. They authenticate via their parent agent identity's credentials.
  • 1:1 relationship — each agent identity can have at most one agent user. Attempting to create a second returns 400 Bad Request.
  • The userPrincipalName must be unique. Don't reuse an existing user's UPN.

Step 3: Assign a Manager (Optional)

Assigning a manager allows the agent user to appear in org charts (e.g., Teams).

http
PUT https://graph.microsoft.com/beta/users/{agent-user-id}/manager/$ref
Content-Type: application/json
Authorization: Bearer <token>

{
  "@odata.id": "https://graph.microsoft.com/beta/users/{manager-user-id}"
}
PowerShell
powershell
$managerBody = '{"@odata.id":"https://graph.microsoft.com/beta/users/<manager-user-id>"}'
Invoke-MgGraphRequest -Method PUT `
  -Uri "https://graph.microsoft.com/beta/users/<agent-user-id>/manager/`$ref" `
  -Body $managerBody -ContentType "application/json"

Step 4: Set Usage Location and Assign Licenses (Optional)

A license is needed for the agent user to have a mailbox, Teams presence, etc. Usage location must be set first.

Show full SKILL.md (250 more words)Show less
Set Usage Location
http
PATCH https://graph.microsoft.com/beta/users/{agent-user-id}
Content-Type: application/json
Authorization: Bearer <token>

{
  "usageLocation": "US"
}
List Available Licenses
http
GET https://graph.microsoft.com/beta/subscribedSkus?$select=skuPartNumber,skuId,consumedUnits,prepaidUnits
Authorization: Bearer <token>

Requires Organization.Read.All permission.

Assign a License
http
POST https://graph.microsoft.com/beta/users/{agent-user-id}/assignLicense
Content-Type: application/json
Authorization: Bearer <token>

{
  "addLicenses": [
    { "skuId": "<sku-id>" }
  ],
  "removeLicenses": []
}
PowerShell (all in one)
powershell
Connect-MgGraph -Scopes "User.ReadWrite.All","Organization.Read.All" -TenantId "<tenant>" -NoWelcome

# Set usage location
Invoke-MgGraphRequest -Method PATCH `
  -Uri "https://graph.microsoft.com/beta/users/<agent-user-id>" `
  -Body '{"usageLocation":"US"}' -ContentType "application/json"

# Assign license
$licenseBody = '{"addLicenses":[{"skuId":"<sku-id>"}],"removeLicenses":[]}'
Invoke-MgGraphRequest -Method POST `
  -Uri "https://graph.microsoft.com/beta/users/<agent-user-id>/assignLicense" `
  -Body $licenseBody -ContentType "application/json"

Tip: You can also assign licenses via the Entra admin center under Identity → Users → All users → select the agent user → Licenses and apps.


Provisioning Times

ServiceEstimated Time
Exchange mailbox5–30 minutes
Teams availability15 min – 24 hours
Org chart / People searchUp to 24–48 hours
SharePoint / OneDrive5–30 minutes
Global Address ListUp to 24 hours

Agent User Capabilities

  • ✅ Added to Microsoft Entra groups (including dynamic groups)
  • ✅ Access user-only APIs (idtyp=user tokens)
  • ✅ Own a mailbox, calendar, and contacts
  • ✅ Participate in Teams chats and channels
  • ✅ Appear in org charts and People search
  • ✅ Added to administrative units
  • ✅ Assigned licenses

Agent User Security Constraints

  • ❌ Cannot have passwords, passkeys, or interactive sign-in
  • ❌ Cannot be assigned privileged admin roles
  • ❌ Cannot be added to role-assignable groups
  • ❌ Permissions similar to guest users by default
  • ❌ Custom role assignment not available

Troubleshooting

ErrorCauseFix
Agent user IdentityParent does not existidentityParentId points to a non-existent or non-agent-identity objectVerify the ID is an agentIdentity service principal, not a regular app
400 Bad Request (identityParentId already linked)The agent identity already has an agent userEach agent identity supports only one agent user
409 Conflict on UPNThe userPrincipalName is already takenUse a unique UPN
License assignment failsUsage location not setSet usageLocation before assigning licenses

References

© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/entra-agent-user of github/awesome-copilot.

Open the folder on GitHubat commit 727ff2e

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in github/awesome-copilot, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Entra Agent User next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Entra Agent User compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Entra Agent User this skillgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: PassMIT
CLI Microsoft365 Scriptpnp/cli-microsoft365-mcp-server131—~3.3kAutomated safety check: PassMIT
Ms365 Tenant Managerborghei/Claude-Skills874—~1.8kAutomated safety check: PassMIT
Azure Role Selectorvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT
Entra Agent Idmicrosoft/GitHub-Copilot-for-Azure2553 repos~4kAutomated safety check: PassMIT
Auditing Azure Active Directory Configurationmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0

Similar skills

  • CLI Microsoft365 Script

    pnp/cli-microsoft365-mcp-server

    Write PowerShell scripts using CLI for Microsoft 365 commands to automate Microsoft 365 management tasks.

    131 GitHub stars~3.3k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Ms365 Tenant Manager

    borghei/Claude-Skills

    Microsoft 365 tenant administration for Global Administrators.

    874 GitHub stars~1.8k tokensUpdated today
    Documents & OfficeAuto-check passed
  • Azure Role Selector

    vinayaklatthe/microsoft-security-skills

    Guidance for selecting the right Azure RBAC role with least privilege - mapping required actions to built-in roles, deciding when a custom role is needed, scoping assignments correctly, and choosing…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Entra Agent Id

    microsoft/GitHub-Copilot-for-Azure

    Official

    Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…

    255 GitHub starsUsed in 3 repos~4k tokens
    Backend & APIsAuto-check passed
  • Auditing Azure Active Directory Configuration

    mukul975/Anthropic-Cybersecurity-Skills

    Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • CLI Microsoft365

    pnp/cli-microsoft365-mcp-server

    Use CLI for Microsoft 365 to manage Microsoft 365 tenants from the terminal.

    131 GitHub stars~3.5k tokensUpdated yesterday
    Documents & OfficeAuto-check passed

More from github/awesome-copilot

All 417 skills in this repo
  • Acquire Codebase Knowledge

    github/awesome-copilot

    Official

    Maps an unfamiliar codebase into seven evidence-backed documents in docs/codebase/, using a scan script and templates, for onboarding or architecture write-ups.

    40k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Azure Architecture Autopilot

    github/awesome-copilot

    Official

    Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.

    40k GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Draw.io Diagram Generator

    github/awesome-copilot

    Official

    Generates, edits and validates draw.io files with correct mxGraph XML, covering flowcharts, architecture, sequence, ER and UML class diagrams.

    40k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed
  • Credit Risk Data Cleaning

    github/awesome-copilot

    Official

    Cleans raw credit data and screens variables before loan modeling, dropping unstable, noisy or redundant features and writing an Excel report of every step.

    40k GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Daily Focus Board

    github/awesome-copilot

    Official

    Builds a warm, browser-based daily focus board the user updates by talking to their agent, with Eisenhower priorities, a brain-dump box and kind not-today carryover.

    40k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Python Pypi Package Builder

    github/awesome-copilot

    Official

    End-to-end skill for building, testing, linting, versioning, and publishing a production-grade Python library to PyPI.

    40k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Questions about Entra Agent User

What does Entra Agent User do?

Create Agent Users in Microsoft Entra ID from Agent Identities, enabling AI agents to act as digital workers with user identity capabilities in Microsoft 365 and Azure environments. Entra Agent User is an agent skill from github/awesome-copilot, published by the product's own GitHub organization. Create Agent Users in Microsoft Entra ID from Agent Identities, enabling AI agents to act as digital workers with user identity capabilities in Microsoft 365 and Azure environments.

When should I use Entra Agent User?

Entra Agent User fits situations like: tasks that involve Building AI agents; tasks that involve Cloud office suites.

How do I install Entra Agent User in Claude Code?

Run `npx skills add github/awesome-copilot --skill entra-agent-user -a claude-code`. Or copy the skill folder (skills/entra-agent-user in github/awesome-copilot) into .claude/skills/entra-agent-user in your project. Claude Code loads it when a task matches its description.

How do I install Entra Agent User in Codex?

Run `npx skills add github/awesome-copilot --skill entra-agent-user -a codex`. Or copy the skill folder (skills/entra-agent-user in github/awesome-copilot) into .agents/skills/entra-agent-user in your project. Codex loads it when a task matches its description.

Can I use Entra Agent User in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/awesome-copilot --skill entra-agent-user -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/entra-agent-user, .gemini/skills/entra-agent-user, .github/skills/entra-agent-user and .opencode/skills/entra-agent-user in your project.

What does Entra Agent User need to run?

SKILL.md names no scripts, command-line tools or credentials: Entra Agent User is instructions for the agent only.

Does Entra Agent User access the network?

SKILL.md names 2 domains. In commands or code: graph.microsoft.com; the agent is likely to contact it when it follows the instructions. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Entra Agent User safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Entra Agent User use?

Entra Agent User is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Entra Agent User use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Entra Agent User?

Skills that share tags, products or a category with Entra Agent User: CLI Microsoft365 Script (pnp/cli-microsoft365-mcp-server, 131 stars), Ms365 Tenant Manager (borghei/Claude-Skills, 874 stars), Azure Role Selector (vinayaklatthe/microsoft-security-skills, 175 stars) and Entra Agent Id (microsoft/GitHub-Copilot-for-Azure, 255 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Entra Agent User?

github (a GitHub organization, an official publisher) maintains it in github/awesome-copilot, which has 39,748 GitHub stars. The repository holds 417 skills in this directory. The repository was last updated on October 7, 2026.

Source: github/awesome-copilot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.