Official agent skill

Azure Identity Dotnet

by microsoft in microsoft/skills

Azure Identity library for .NET. An agent skill from microsoft/skills.

OfficialMITAuto-check passedDevOps & Cloud

Install Azure Identity Dotnet

skills CLI
$ npx skills add microsoft/skills --skill azure-identity-dotnet -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/skills azure-identity-dotnet --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/plugins/azure-sdk-dotnet/skills/azure-identity-dotnet .claude/skills/azure-identity-dotnet && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-identity-dotnet
GitHub stars
3.1k
Used in
5 other repos
Token cost
~2.5k tokens
SKILL.md length
286 words
Files
1
Skills in repo
150
Repo updated
First seen
Licence
MIT

At a glance

Azure Identity library for .NET. An agent skill from microsoft/skills.

  • Works in 4 steps: Use Deterministic Credentials in… → Reuse Credential Instances → Configure Retry Policies → …
  • DefaultAzureCredential
  • SKILL.md covers Installation, Environment Variables, DefaultAzureCredential and Credential Types, plus 10 more sections
  • Calls dotnet; needs AZURE_CLIENT_SECRET and AZURE_CLIENT_CERTIFICATE_PASSWORD

What it does

Azure Identity Dotnet is an agent skill from microsoft/skills, published by the product's own GitHub organization. Azure Identity library for .NET. Authentication library for Azure SDK clients using Microsoft Entra ID. Use for DefaultAzureCredential, managed identity, service principals, and developer credentials. Triggers: "Azure Identity", "DefaultAzureCredential", "ManagedIdentityCredential", "ClientSecretCredential", "authentication .NET", "Azure auth", "credential chain".

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Authentication. It works with Microsoft Azure, .NET and Microsoft Entra ID. The repository describes itself as: Skills, MCP servers, Custom Agents, Agents.md for SDKs to ground Coding Agents. The licence is MIT.

When your agent uses it

  • DefaultAzureCredential
  • Managed identity
  • Service principals
  • Developer credentials

Example prompts

  • “Azure Identity”
  • “DefaultAzureCredential”
  • “ManagedIdentityCredential”
  • “/azure-identity-dotnet”

Requirements

  • A credential in AZURE_CLIENT_SECRET

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Use Deterministic Credentials in Production
  2. Reuse Credential Instances
  3. Configure Retry Policies
  4. Enable Logging for Debugging

What it can do on your machine

Read from SKILL.md and the folder at commit 3898ec8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • dotnet

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • aka.ms
    • learn.microsoft.com
    • nuget.org
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AZURE_CLIENT_SECRET
    • AZURE_CLIENT_CERTIFICATE_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Identity Dotnet loads about 2.5k tokens when it runs. Until then it costs about 97 tokens; SKILL.md has 286 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~97
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/skills at commit 3898ec8, republished under its MIT licence (© microsoft). 286 words, ~2,464 tokens.

Download SKILL.mdSave it as .claude/skills/azure-identity-dotnet/SKILL.md (or your agent's skills folder).
name
azure-identity-dotnet
description
Azure Identity library for .NET. Authentication library for Azure SDK clients using Microsoft Entra ID. Use for DefaultAzureCredential, managed identity, service principals, and developer credentials. Triggers: "Azure Identity", "DefaultAzureCredential", "ManagedIdentityCredential", "ClientSecretCredential", "authentication .NET", "Azure auth", "credential chain".
license
MIT
metadata.author
Microsoft
metadata.version
1.0.0
metadata.package
Azure.Identity

Azure Identity library for .NET

Authentication library for Azure SDK clients using Microsoft Entra ID.

Installation

bash
dotnet add package Azure.Identity

# For ASP.NET Core integration
dotnet add package Microsoft.Extensions.Azure

# For brokered authentication and Visual Studio Code credential support
dotnet add package Azure.Identity.Broker

Environment Variables

Service Principal with Secret
bash
AZURE_CLIENT_ID=<application-client-id>
AZURE_TENANT_ID=<directory-tenant-id>
AZURE_CLIENT_SECRET=<client-secret-value>
Service Principal with Certificate
bash
AZURE_CLIENT_ID=<application-client-id>
AZURE_TENANT_ID=<directory-tenant-id>
AZURE_CLIENT_CERTIFICATE_PATH=<path-to-pfx-or-pem>
AZURE_CLIENT_CERTIFICATE_PASSWORD=<certificate-password>  # Optional
Managed Identity
bash
AZURE_CLIENT_ID=<user-assigned-managed-identity-client-id>  # Only for user-assigned

DefaultAzureCredential

The recommended credential for most scenarios. Tries multiple authentication methods in order. See DefaultAzureCredential overview for the current credential chain order and defaults.

Basic Usage
csharp
using Azure.Identity;
using Azure.Storage.Blobs;

var credential = new DefaultAzureCredential();
var blobClient = new BlobServiceClient(
    new Uri("https://myaccount.blob.core.windows.net"),
    credential);
ASP.NET Core with Dependency Injection
csharp
using Azure.Identity;
using Microsoft.Extensions.Azure;

builder.Services.AddAzureClients(clientBuilder =>
{
    clientBuilder.AddBlobServiceClient(
        new Uri("https://myaccount.blob.core.windows.net"));
    clientBuilder.AddSecretClient(
        new Uri("https://myvault.vault.azure.net"));
    
    // Uses DefaultAzureCredential by default
    clientBuilder.UseCredential(new DefaultAzureCredential());
});
Customizing DefaultAzureCredential
csharp
var credential = new DefaultAzureCredential(
    new DefaultAzureCredentialOptions
    {
        ExcludeEnvironmentCredential = true,
        ExcludeManagedIdentityCredential = false,
        ExcludeVisualStudioCredential = false,
        ExcludeAzureCliCredential = false,
        ExcludeInteractiveBrowserCredential = false, // Enable interactive
        TenantId = "<tenant-id>",
        ManagedIdentityClientId = "<user-assigned-mi-client-id>"
    });

Credential Types

ManagedIdentityCredential (Production)
csharp
// System-assigned managed identity
var credential = new ManagedIdentityCredential(ManagedIdentityId.SystemAssigned);

// User-assigned by client ID
var credential = new ManagedIdentityCredential(
    ManagedIdentityId.FromUserAssignedClientId("<client-id>"));

// User-assigned by resource ID
var credential = new ManagedIdentityCredential(
    ManagedIdentityId.FromUserAssignedResourceId("<resource-id>"));

// User-assigned by object ID
var credential = new ManagedIdentityCredential(
    ManagedIdentityId.FromUserAssignedObjectId("<object-id>"));
ClientSecretCredential
csharp
var credential = new ClientSecretCredential(
    tenantId: "<tenant-id>",
    clientId: "<client-id>",
    clientSecret: "<client-secret>");

var client = new SecretClient(
    new Uri("https://myvault.vault.azure.net"),
    credential);
ClientCertificateCredential
csharp
var certificate = X509CertificateLoader.LoadCertificateFromFile("MyCertificate.pfx");
var credential = new ClientCertificateCredential(
    tenantId: "<tenant-id>",
    clientId: "<client-id>",
    certificate);
ChainedTokenCredential (Custom Chain)
csharp
var credential = new ChainedTokenCredential(
    new ManagedIdentityCredential(),
    new AzureCliCredential());

var client = new SecretClient(
    new Uri("https://myvault.vault.azure.net"),
    credential);
Developer Credentials
csharp
// Azure CLI
var credential = new AzureCliCredential();

// Azure PowerShell
var credential = new AzurePowerShellCredential();

// Azure Developer CLI (azd)
var credential = new AzureDeveloperCliCredential();

// Visual Studio
var credential = new VisualStudioCredential();

// Interactive Browser
var credential = new InteractiveBrowserCredential();

Environment-Based Configuration

csharp
// Production vs Development
TokenCredential credential = builder.Environment.IsProduction()
    ? new ManagedIdentityCredential("<client-id>")
    : new DefaultAzureCredential();

Sovereign Clouds

csharp
var credential = new DefaultAzureCredential(
    new DefaultAzureCredentialOptions
    {
        AuthorityHost = AzureAuthorityHosts.AzureGovernment
    });

// Available authority hosts:
// AzureAuthorityHosts.AzurePublicCloud (default)
// AzureAuthorityHosts.AzureGovernment
// AzureAuthorityHosts.AzureChina

Credential Types Reference

CategoryCredentialPurpose
ChainsDefaultAzureCredentialPreconfigured chain for dev-to-prod
ChainedTokenCredentialCustom credential chain
Azure-HostedManagedIdentityCredentialAzure managed identity
WorkloadIdentityCredentialKubernetes workload identity
EnvironmentCredentialEnvironment variables
Service PrincipalClientSecretCredentialClient ID + secret
ClientCertificateCredentialClient ID + certificate
ClientAssertionCredentialSigned client assertion
UserInteractiveBrowserCredentialBrowser-based auth
DeviceCodeCredentialDevice code flow
OnBehalfOfCredentialDelegated identity
DeveloperAzureCliCredentialAzure CLI
AzurePowerShellCredentialAzure PowerShell
AzureDeveloperCliCredentialAzure Developer CLI
VisualStudioCredentialVisual Studio

Best Practices

1. Use Deterministic Credentials in Production
csharp
// Development
var devCredential = new DefaultAzureCredential();

// Production - use specific credential
var prodCredential = new ManagedIdentityCredential(
    ManagedIdentityId.FromUserAssignedClientId("<client-id>"));
2. Reuse Credential Instances
csharp
// Good: Single credential instance shared across clients
var credential = new DefaultAzureCredential();
var blobClient = new BlobServiceClient(blobUri, credential);
var secretClient = new SecretClient(vaultUri, credential);
3. Configure Retry Policies
csharp
var options = new ManagedIdentityCredentialOptions(
    ManagedIdentityId.FromUserAssignedClientId(clientId))
{
    Retry =
    {
        MaxRetries = 3,
        Delay = TimeSpan.FromSeconds(0.5),
    }
};
var credential = new ManagedIdentityCredential(options);
4. Enable Logging for Debugging
csharp
using Azure.Core.Diagnostics;

using AzureEventSourceListener listener = new((args, message) =>
{
    if (args is { EventSource.Name: "Azure-Identity" })
    {
        Console.WriteLine(message);
    }
}, EventLevel.LogAlways);

Error Handling

csharp
using Azure.Identity;
using Azure.Security.KeyVault.Secrets;

var client = new SecretClient(
    new Uri("https://myvault.vault.azure.net"),
    new DefaultAzureCredential());

try
{
    KeyVaultSecret secret = await client.GetSecretAsync("secret1");
}
catch (AuthenticationFailedException e)
{
    Console.WriteLine($"Authentication Failed: {e.Message}");
}
catch (CredentialUnavailableException e)
{
    Console.WriteLine($"Credential Unavailable: {e.Message}");
}

Key Exceptions

ExceptionDescription
AuthenticationFailedExceptionBase exception for authentication errors
CredentialUnavailableExceptionCredential cannot authenticate in current environment
AuthenticationRequiredExceptionInteractive authentication is required

Managed Identity Support

Supported Azure services:

  • Azure App Service and Azure Functions
  • Azure Arc
  • Azure Cloud Shell
  • Azure Kubernetes Service (AKS)
  • Azure Service Fabric
  • Azure Virtual Machines
  • Azure Virtual Machine Scale Sets

Thread Safety

All credential implementations are thread-safe. A single credential instance can be safely shared across multiple clients and threads.

PackagePurposeInstall
Azure.IdentityAuthentication (this library)dotnet add package Azure.Identity
Microsoft.Extensions.AzureDI integrationdotnet add package Microsoft.Extensions.Azure
Azure.Identity.BrokerBrokered authdotnet add package Azure.Identity.Broker

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/plugins/azure-sdk-dotnet/skills/azure-identity-dotnet of microsoft/skills.

Open the folder on GitHubat commit 3898ec8

Used in 5 other repositories

We found 14 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 5 other GitHub owners. This page covers the copy in microsoft/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Azure Identity Dotnet next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Identity Dotnet compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Identity Dotnet this skillmicrosoft/skills3.1k5 repos~2.5kAutomated safety check: PassMIT
Apex Entra App Registrationjonathan-vella/apex217—~1.3kAutomated safety check: PassMIT
Msal Client CredentialsAzureAD/microsoft-authentication-library-for-dotnet1.5k—~1.1kAutomated safety check: PassMIT
Akka.NET Management and DiscoveryAaronontheweb/dotnet-skills1.2k1 repos~2.5kAutomated safety check: PassMIT
Nuget Trusted Publishingdotnet/skills5.6k2 repos~2.3kAutomated safety check: PassMIT
AzureRightNow-AI/openfang18k—~932Automated safety check: PassApache-2.0

Similar skills

  • Apex Entra App Registration

    jonathan-vella/apex

    WORKFLOW SKILL — Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

    217 GitHub stars~1.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • Msal Client Credentials

    AzureAD/microsoft-authentication-library-for-dotnet

    Client Credentials Flow for service-to-service (daemon) authentication in MSAL.NET without user involvement

    1.5k GitHub stars~1.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Akka.NET Management and Discovery

    Aaronontheweb/dotnet-skills

    Sets up Akka.Management and Cluster.Bootstrap so Akka.NET clusters form through service discovery on Kubernetes, Azure or config instead of static seed nodes.

    1.2k GitHub starsUsed in 1 repo~2.5k tokens
    DevOps & CloudAuto-check passed
  • Official

    Set up NuGet trusted publishing (OIDC) on a GitHub Actions repo — replaces long-lived API keys with short-lived tokens.

    5.6k GitHub starsUsed in 2 repos~2.3k tokens
    DevOps & CloudAuto-check passed
  • Azure

    RightNow-AI/openfang

    Microsoft Azure expert for az CLI, AKS, App Service, and cloud infrastructure

    18k GitHub stars~932 tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Entra App Registration

    microsoft/GitHub-Copilot-for-Azure

    Official

    Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

    255 GitHub starsUsed in 2 repos~2.1k tokens
    Backend & APIsAuto-check passed

More from microsoft/skills

All 150 skills in this repo
  • Official

    Covers producer, consumer, and checkpoint-store setup for Azure Event Hubs streaming in Python, with Entra ID auth and partition targeting.

    3.1k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Official

    Builds podcast-style audio narration from text with Azure OpenAI's GPT Realtime Mini over WebSocket, from a Python FastAPI backend to a React player.

    3.1k GitHub starsUsed in 1 repo~947 tokens
    Auto-check passed
  • Frontend UI Dark TS

    microsoft/skills

    Official

    Build dark-themed React applications using Tailwind CSS with custom theming, glassmorphism effects, and Framer Motion animations.

    3.1k GitHub starsUsed in 5 repos~3.6k tokens
    Auto-check passed
  • Pydantic Models Py

    microsoft/skills

    Official

    Create Pydantic models following the multi-model pattern with Base, Create, Update, Response, and InDB variants.

    3.1k GitHub starsUsed in 5 repos~496 tokens
    Auto-check passed
  • Official

    Reference for building on Microsoft Foundry with the azure-ai-projects Python SDK: project clients, versioned agents, evaluations, connections, datasets and indexes.

    3.1k GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Skill Creator

    microsoft/skills

    Official

    Guide for creating effective skills for AI coding agents working with Azure SDKs and Microsoft Foundry services.

    3.1k GitHub starsUsed in 5 repos~17k tokens
    Auto-check passed

Questions about Azure Identity Dotnet

What does Azure Identity Dotnet do?

Azure Identity library for .NET. An agent skill from microsoft/skills. Azure Identity Dotnet is an agent skill from microsoft/skills, published by the product's own GitHub organization.NET.

When should I use Azure Identity Dotnet?

Azure Identity Dotnet fits situations like: defaultAzureCredential; managed identity; service principals; developer credentials.

How do I install Azure Identity Dotnet in Claude Code?

Run `npx skills add microsoft/skills --skill azure-identity-dotnet -a claude-code`. Or copy the skill folder (.github/plugins/azure-sdk-dotnet/skills/azure-identity-dotnet in microsoft/skills) into .claude/skills/azure-identity-dotnet in your project. Claude Code loads it when a task matches its description.

How do I install Azure Identity Dotnet in Codex?

Run `npx skills add microsoft/skills --skill azure-identity-dotnet -a codex`. Or copy the skill folder (.github/plugins/azure-sdk-dotnet/skills/azure-identity-dotnet in microsoft/skills) into .agents/skills/azure-identity-dotnet in your project. Codex loads it when a task matches its description.

Can I use Azure Identity Dotnet in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/skills --skill azure-identity-dotnet -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-identity-dotnet, .gemini/skills/azure-identity-dotnet, .github/skills/azure-identity-dotnet and .opencode/skills/azure-identity-dotnet in your project.

What does Azure Identity Dotnet need to run?

Going by SKILL.md and its folder, Azure Identity Dotnet needs the command-line tools its instructions call (dotnet) and credentials named AZURE_CLIENT_SECRET and AZURE_CLIENT_CERTIFICATE_PASSWORD. Our summary lists: A credential in AZURE_CLIENT_SECRET.

Does Azure Identity Dotnet access the network?

SKILL.md names 4 domains. As links in the text: aka.ms, learn.microsoft.com, nuget.org and github.com. This is read from the text; nothing was executed.

Is Azure Identity Dotnet safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Identity Dotnet use?

Azure Identity Dotnet is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Identity Dotnet use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Azure Identity Dotnet?

Skills that share tags, products or a category with Azure Identity Dotnet: Apex Entra App Registration (jonathan-vella/apex, 217 stars), Msal Client Credentials (AzureAD/microsoft-authentication-library-for-dotnet, 1.5k stars), Akka.NET Management and Discovery (Aaronontheweb/dotnet-skills, 1.2k stars) and Nuget Trusted Publishing (dotnet/skills, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Identity Dotnet?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/skills, which has 3,094 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on October 9, 2026.

Source: microsoft/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.