Official agent skill

Azure Identity Py

by microsoft in microsoft/skills

Azure Identity SDK for Python authentication with Microsoft Entra ID.

OfficialMITAuto-check passedBackend & APIs

Install Azure Identity Py

skills CLI
$ npx skills add microsoft/skills --skill azure-identity-py -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/skills azure-identity-py --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/plugins/azure-sdk-python/skills/azure-identity-py .claude/skills/azure-identity-py && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-identity-py
GitHub stars
3.1k
Token cost
~4.4k tokens
SKILL.md length
818 words
Files
3 (incl. references)
Skills in repo
150
Repo updated
First seen
Licence
MIT

At a glance

Azure Identity SDK for Python authentication with Microsoft Entra ID.

  • Works in 12 steps: Pick sync OR async and stay consistent.… → Use credentials as context managers… → Use DefaultAzureCredential for code that… → …
  • DefaultAzureCredential
  • SKILL.md covers Installation, Python Version, Environment Variables and Authentication & Lifecycle, plus 6 more sections
  • Calls pip and az; reaches management.azure.com and cognitiveservices.azure.com; needs AZURE_TOKEN_CREDENTIALS and AZURE_CLIENT_SECRET

What it does

Azure Identity Py is an agent skill from microsoft/skills, published by the product's own GitHub organization. Azure Identity SDK for Python authentication with Microsoft Entra ID. Use for DefaultAzureCredential, managed identity, service principals, and token caching. Triggers: "azure-identity", "DefaultAzureCredential", "authentication", "managed identity", "service principal", "credential".

Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/capabilities.md` and `references/non-hero-scenarios.md`).

It sits in Backend & APIs, covering Authentication and Caching. It works with Microsoft Azure, Python, Microsoft Entra ID and Visual Studio Code. The repository describes itself as: Skills, MCP servers, Custom Agents, Agents.md for SDKs to ground Coding Agents. The licence is MIT.

When your agent uses it

  • DefaultAzureCredential
  • Managed identity
  • Service principals

Example prompts

  • “azure-identity”
  • “DefaultAzureCredential”
  • “authentication”
  • “/azure-identity-py”

Requirements

  • Python 3
  • A credential in AZURE_CLIENT_SECRET

Workflow steps

12 steps, taken from the first numbered list in SKILL.md.

  1. Pick sync OR async and stay consistent. Do not mix azure.xxx sync clients with azure.xxx.aio async clients in the same call path. Choose…
  2. Use credentials as context managers (with DefaultAzureCredential() as credential:) when they own token caches / HTTP transports you want…
  3. Use DefaultAzureCredential for code that runs locally. Use a specific token credential for code that runs in Azure.
  4. Never hardcode credentials — use environment variables or managed identity
  5. Prefer managed identity in production Azure deployments
  6. Use get_bearer_token_provider for non-Azure-SDK clients (OpenAI, REST APIs)
  7. Use ChainedTokenCredential when you need a custom credential order
  8. Set AZURE_CLIENT_ID for user-assigned managed identities (object ID and resource ID are also valid identifiers)
  9. Exclude unused credentials to speed up DefaultAzureCredential authentication
  10. Use CertificateCredential (not ClientCertificateCredential — that name doesn't exist)
  11. Enable cache_persistence_options for long-running services to reduce token requests
  12. Reuse credential instances — same credential can be shared across multiple clients

What it can do on your machine

Read from SKILL.md and the folder at commit 3898ec8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pip
    • az

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • management.azure.com
    • cognitiveservices.azure.com
    • ossrdbms-aad.database.windows.net

    Also links to:

    • aka.ms
    • pypi.org
    • learn.microsoft.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AZURE_TOKEN_CREDENTIALS
    • AZURE_CLIENT_SECRET
    • AZURE_CLIENT_CERTIFICATE_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Identity Py loads about 4.4k tokens when it runs, and up to ~6.1k if it reads all its reference files. Until then it costs about 76 tokens; SKILL.md has 818 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~4.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/skills at commit 3898ec8, republished under its MIT licence (© microsoft). 818 words, ~4,422 tokens.

Download SKILL.mdSave it as .claude/skills/azure-identity-py/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
azure-identity-py
description
Azure Identity SDK for Python authentication with Microsoft Entra ID. Use for DefaultAzureCredential, managed identity, service principals, and token caching. Triggers: "azure-identity", "DefaultAzureCredential", "authentication", "managed identity", "service principal", "credential".
license
MIT
metadata.author
Microsoft
metadata.version
1.0.0
metadata.package
azure-identity

Azure Identity library for Python

Authentication library for Azure SDK clients using Microsoft Entra ID.

Use this skill when:

  • An app needs to authenticate to Azure services from Python
  • You need DefaultAzureCredential for local dev + Azure deployment
  • You need ManagedIdentityCredential for Azure-hosted workloads
  • You need service principal auth with secret or certificate
  • You need direct token acquisition with get_token()
  • You need to troubleshoot credential chain failures

Installation

bash
pip install azure-identity

For VS Code or broker-based desktop auth:

bash
pip install azure-identity-broker

Python Version

azure-identity supports Python 3.9+.

Environment Variables

bash
# Service principal with client secret
AZURE_TENANT_ID=<your-tenant-id>
AZURE_CLIENT_ID=<your-client-id>
AZURE_CLIENT_SECRET=<your-client-secret>

# Service principal with certificate
AZURE_TENANT_ID=<your-tenant-id>
AZURE_CLIENT_ID=<your-client-id>
AZURE_CLIENT_CERTIFICATE_PATH=/path/to/cert.pem
AZURE_CLIENT_CERTIFICATE_PASSWORD=<optional-password>

# Authority (sovereign clouds)
AZURE_AUTHORITY_HOST=login.microsoftonline.com  # Default; or login.chinacloudapi.cn, login.microsoftonline.us

# User-assigned managed identity
AZURE_CLIENT_ID=<managed-identity-client-id>

# Credential selection (new)
AZURE_TOKEN_CREDENTIALS=dev|prod|<credential-name>  # Optional, restricts DAC chain

Authentication & Lifecycle

🔑 Two rules apply to every code sample below:

  1. Prefer DefaultAzureCredential. It works locally (Azure CLI / VS Code / Developer CLI) and in Azure (managed identity, workload identity) with no code change. Avoid connection strings, account/API keys — they bypass Entra audit and rotation.
    • Local dev: DefaultAzureCredential works as-is.
    • Production: set AZURE_TOKEN_CREDENTIALS=prod (or AZURE_TOKEN_CREDENTIALS=<specific_credential>) to constrain the credential chain to production-safe credentials.
  2. Wrap credentials and clients in context managers when they own token caches / transports:
    • Sync: with DefaultAzureCredential() as credential:
    • Async: async with DefaultAzureCredential() as credential: (from azure.identity.aio)

Snippets may abbreviate this setup, but production code should always follow both rules.

DefaultAzureCredential

The recommended credential for most scenarios. Tries multiple authentication methods in order:

python
from azure.identity import DefaultAzureCredential
from azure.storage.blob import BlobServiceClient

# Works in local dev AND production without code changes
credential = DefaultAzureCredential()

with BlobServiceClient(
    account_url="https://<account>.blob.core.windows.net",
    credential=credential
) as client:
    containers = list(client.list_containers())
Credential Chain Order

See DefaultAzureCredential overview for the current credential chain order and defaults.

Customizing DefaultAzureCredential
python
# Exclude credentials you don't need
credential = DefaultAzureCredential(
    exclude_environment_credential=True,
    exclude_shared_token_cache_credential=True,
    managed_identity_client_id="<user-assigned-mi-client-id>"  # For user-assigned MI (also accepts object ID or resource ID)
)

# Enable interactive browser (disabled by default)
credential = DefaultAzureCredential(
    exclude_interactive_browser_credential=False
)

# Set subprocess timeout for CLI-based credentials (default: 10s)
credential = DefaultAzureCredential(process_timeout=30)

# Require AZURE_TOKEN_CREDENTIALS env var to be set
credential = DefaultAzureCredential(require_envvar=True)
Exclude Parameters
ParameterDefaultEffect
exclude_environment_credentialFalseSkip env-var-based auth
exclude_workload_identity_credentialFalseSkip Kubernetes workload identity
exclude_managed_identity_credentialFalseSkip managed identity
exclude_shared_token_cache_credentialFalseSkip shared token cache
exclude_visual_studio_code_credentialFalseSkip VS Code credential
exclude_cli_credentialFalseSkip Azure CLI
exclude_powershell_credentialFalseSkip Azure PowerShell
exclude_developer_cli_credentialFalseSkip Azure Developer CLI
exclude_interactive_browser_credentialTrueSkip interactive browser
exclude_broker_credentialFalseSkip WAM broker

get_bearer_token_provider

Helper that wraps a credential into a callable returning a bearer token string. Essential for OpenAI SDK and other non-Azure-SDK clients:

python
from azure.identity import DefaultAzureCredential, get_bearer_token_provider

credential = DefaultAzureCredential()
token_provider = get_bearer_token_provider(
    credential, "https://cognitiveservices.azure.com/.default"
)

# Use with OpenAI SDK
from openai import AzureOpenAI

with AzureOpenAI(
    azure_endpoint="https://<resource>.openai.azure.com/",
    azure_ad_token_provider=token_provider,
    api_version="2024-10-21",
) as client:
    # response = client.chat.completions.create(...)
    ...

Credential Types

Credential Chains
CredentialUse Case
DefaultAzureCredentialMost scenarios — auto-detects environment
ChainedTokenCredentialCustom credential chain with explicit ordering
Azure-Hosted Applications
CredentialUse Case
EnvironmentCredentialAuth via AZURE_CLIENT_SECRET / AZURE_CLIENT_CERTIFICATE_PATH env vars
ManagedIdentityCredentialAzure VMs, App Service, Functions, AKS, Arc, Service Fabric
WorkloadIdentityCredentialKubernetes with Microsoft Entra Workload ID
Service Principals
CredentialUse Case
ClientSecretCredentialService principal with client secret
CertificateCredentialService principal with PEM/PKCS12 certificate
ClientAssertionCredentialService principal with signed JWT assertion
AzurePipelinesCredentialAzure Pipelines with workload identity federation
OnBehalfOfCredentialMiddle-tier on-behalf-of flow (delegated user identity)
User Authentication
CredentialUse Case
InteractiveBrowserCredentialInteractive browser OAuth sign-in
DeviceCodeCredentialHeadless/SSH device code flow
AuthorizationCodeCredentialPreviously obtained authorization code
Developer Tools
CredentialUse Case
AzureCliCredentialaz login
AzureDeveloperCliCredentialazd auth login
AzurePowerShellCredentialConnect-AzAccount
VisualStudioCodeCredentialVS Code Azure Resources extension

Specific Credential Examples

ManagedIdentityCredential

For Azure-hosted resources (VMs, App Service, Functions, AKS):

python
from azure.identity import ManagedIdentityCredential

# System-assigned managed identity
credential = ManagedIdentityCredential()

# User-assigned managed identity (client_id, object_id, or resource_id)
credential = ManagedIdentityCredential(
    client_id="<user-assigned-mi-client-id>"
)
# Also valid:
# credential = ManagedIdentityCredential(object_id="<object-id>")
# credential = ManagedIdentityCredential(resource_id="<resource-id>")
ClientSecretCredential
python
import os
from azure.identity import ClientSecretCredential

credential = ClientSecretCredential(
    tenant_id=os.environ["AZURE_TENANT_ID"],
    client_id=os.environ["AZURE_CLIENT_ID"],
    client_secret=os.environ["AZURE_CLIENT_SECRET"],
)
CertificateCredential

Note: The class is CertificateCredential, NOT ClientCertificateCredential.

python
from azure.identity import CertificateCredential

# From file path
credential = CertificateCredential(
    tenant_id="<tenant-id>",
    client_id="<client-id>",
    certificate_path="/path/to/cert.pem",
)

# From bytes with password
credential = CertificateCredential(
    tenant_id="<tenant-id>",
    client_id="<client-id>",
    certificate_data=cert_bytes,
    password="<cert-password>",
    send_certificate_chain=True,  # Required for SNI auth
)
AzureCliCredential
python
from azure.identity import AzureCliCredential

credential = AzureCliCredential()
# With tenant restriction
credential = AzureCliCredential(tenant_id="<tenant-id>")
ChainedTokenCredential

Custom credential chain:

python
from azure.identity import (
    ChainedTokenCredential,
    ManagedIdentityCredential,
    AzureCliCredential,
)

# Try managed identity first, fall back to CLI
credential = ChainedTokenCredential(
    ManagedIdentityCredential(client_id="<user-assigned-mi-client-id>"),
    AzureCliCredential(),
)
WorkloadIdentityCredential

For Azure Kubernetes Service with workload identity:

python
from azure.identity import WorkloadIdentityCredential

# Reads from AZURE_TENANT_ID, AZURE_CLIENT_ID, AZURE_FEDERATED_TOKEN_FILE
credential = WorkloadIdentityCredential()

# Or explicit configuration
credential = WorkloadIdentityCredential(
    tenant_id="<tenant-id>",
    client_id="<client-id>",
    token_file_path="/var/run/secrets/azure/tokens/azure-identity-token",
)
DeviceCodeCredential

For headless devices (IoT, SSH, CLI tools):

python
from azure.identity import DeviceCodeCredential

credential = DeviceCodeCredential()
# Prints device code prompt to stdout by default

# With custom prompt callback
def prompt_callback(verification_uri, user_code, expires_on):
    print(f"Go to {verification_uri} and enter code {user_code}")

credential = DeviceCodeCredential(
    client_id="<client-id>",
    prompt_callback=prompt_callback,
)
InteractiveBrowserCredential

For interactive OAuth browser sign-in:

python
from azure.identity import InteractiveBrowserCredential

credential = InteractiveBrowserCredential()

# With specific tenant and client
credential = InteractiveBrowserCredential(
    tenant_id="<tenant-id>",
    client_id="<client-id>",
)
OnBehalfOfCredential

For middle-tier services propagating user identity:

python
from azure.identity import OnBehalfOfCredential

credential = OnBehalfOfCredential(
    tenant_id="<tenant-id>",
    client_id="<client-id>",
    client_secret="<client-secret>",
    user_assertion="<access-token-from-client>",
)
AzurePipelinesCredential

For Azure DevOps pipelines with workload identity federation:

python
import os
from azure.identity import AzurePipelinesCredential

credential = AzurePipelinesCredential(
    tenant_id="<tenant-id>",
    client_id="<client-id>",
    service_connection_id="<service-connection-id>",
    system_access_token=os.environ["SYSTEM_ACCESSTOKEN"],
)

Getting Tokens Directly

python
from azure.identity import DefaultAzureCredential

with DefaultAzureCredential() as credential:
    # Get token for a specific scope
    token = credential.get_token("https://management.azure.com/.default")
    print(f"Token expires: {token.expires_on}")

    # For Azure Database for PostgreSQL
    token = credential.get_token("https://ossrdbms-aad.database.windows.net/.default")
Show full SKILL.md (331 more words)Show less

Async Credentials

Async credentials are in azure.identity.aio. Always close them or use async with:

python
from azure.identity.aio import DefaultAzureCredential
from azure.storage.blob.aio import BlobServiceClient

async def main():
    # Preferred: use async context manager for both credential and client
    async with DefaultAzureCredential() as credential:
        async with BlobServiceClient(
            account_url="https://<account>.blob.core.windows.net",
            credential=credential,
        ) as client:
            # ... async operations
            pass

The async get_bearer_token_provider is at azure.identity.aio.get_bearer_token_provider.

Sovereign Clouds

Use AzureAuthorityHosts or the AZURE_AUTHORITY_HOST env var:

python
from azure.identity import DefaultAzureCredential, AzureAuthorityHosts

# Azure Government
credential = DefaultAzureCredential(authority=AzureAuthorityHosts.AZURE_GOVERNMENT)

# Azure China
credential = DefaultAzureCredential(authority=AzureAuthorityHosts.AZURE_CHINA)
ConstantAuthority
AzureAuthorityHosts.AZURE_PUBLIC_CLOUDlogin.microsoftonline.com (default)
AzureAuthorityHosts.AZURE_GOVERNMENTlogin.microsoftonline.us
AzureAuthorityHosts.AZURE_CHINAlogin.chinacloudapi.cn

Persistent Token Caching

Opt-in disk-based caching with TokenCachePersistenceOptions:

python
from azure.identity import DefaultAzureCredential, TokenCachePersistenceOptions

credential = DefaultAzureCredential(
    cache_persistence_options=TokenCachePersistenceOptions()
)

# Allow unencrypted fallback (NOT recommended for production)
credential = DefaultAzureCredential(
    cache_persistence_options=TokenCachePersistenceOptions(allow_unencrypted_storage=True)
)

Storage: Windows (DPAPI), macOS (Keychain), Linux (Keyring).

Multi-Tenant Support

Allow token acquisition for additional tenants beyond the configured one:

python
from azure.identity import ClientSecretCredential

credential = ClientSecretCredential(
    tenant_id="<home-tenant>",
    client_id="<client-id>",
    client_secret="<secret>",
    additionally_allowed_tenants=["<other-tenant>", "*"],  # "*" allows any tenant
)

Error Handling

python
from azure.identity import DefaultAzureCredential, CredentialUnavailableError
from azure.core.exceptions import ClientAuthenticationError

with DefaultAzureCredential() as credential:
    try:
        token = credential.get_token("https://management.azure.com/.default")
    except CredentialUnavailableError:
        # No credential in the chain could attempt authentication
        pass
    except ClientAuthenticationError as e:
        # Authentication was attempted but failed
        # e.message contains details from each credential in the chain
        pass

Logging

Enable authentication logging for debugging:

python
import logging

# Enable verbose Azure Identity logging
logging.basicConfig(level=logging.DEBUG)
logger = logging.getLogger("azure.identity")
logger.setLevel(logging.DEBUG)
bash
# Or via environment variable
AZURE_LOG_LEVEL=debug

Credential Selection Matrix

EnvironmentRecommended Credential
Local DevelopmentDefaultAzureCredential (uses Azure CLI)
Azure App ServiceDefaultAzureCredential (uses Managed Identity)
Azure FunctionsDefaultAzureCredential (uses Managed Identity)
Azure Kubernetes ServiceWorkloadIdentityCredential
Azure VMsDefaultAzureCredential (uses Managed Identity)
CI/CD PipelineEnvironmentCredential or AzurePipelinesCredential
Desktop AppInteractiveBrowserCredential
CLI / Headless ToolDeviceCodeCredential
Middle-tier ServiceOnBehalfOfCredential

Best Practices

  1. Pick sync OR async and stay consistent. Do not mix azure.xxx sync clients with azure.xxx.aio async clients in the same call path. Choose one mode per module.
  2. Use credentials as context managers (with DefaultAzureCredential() as credential:) when they own token caches / HTTP transports you want cleaned up; for async, use async with on credentials from azure.identity.aio.
  3. Use DefaultAzureCredential for code that runs locally. Use a specific token credential for code that runs in Azure.
  4. Never hardcode credentials — use environment variables or managed identity
  5. Prefer managed identity in production Azure deployments
  6. Use get_bearer_token_provider for non-Azure-SDK clients (OpenAI, REST APIs)
  7. Use ChainedTokenCredential when you need a custom credential order
  8. Set AZURE_CLIENT_ID for user-assigned managed identities (object ID and resource ID are also valid identifiers)
  9. Exclude unused credentials to speed up DefaultAzureCredential authentication
  10. Use CertificateCredential (not ClientCertificateCredential — that name doesn't exist)
  11. Enable cache_persistence_options for long-running services to reduce token requests
  12. Reuse credential instances — same credential can be shared across multiple clients

Reference Files

FileContents
references/capabilities.mdAdditional non-hero capabilities, operation-group coverage, and production checklists.
references/non-hero-scenarios.mdDedicated non-hero examples for secondary/advanced scenarios.

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .github/plugins/azure-sdk-python/skills/azure-identity-py of microsoft/skills.

  • SKILL.md
  • references/capabilities.md
  • references/non-hero-scenarios.md

Open the folder on GitHubat commit 3898ec8

Compare with similar skills

Azure Identity Py next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Identity Py compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Identity Py this skillmicrosoft/skills3.1k—~4.4kAutomated safety check: PassMIT
Azure Identity Pyaiskillstore/marketplace4304 repos~1.4kAutomated safety check: PassNone
Apex Entra App Registrationjonathan-vella/apex217—~1.3kAutomated safety check: PassMIT
Entra Agent Idmicrosoft/GitHub-Copilot-for-Azure2552 repos~4kAutomated safety check: PassMIT
Entra App Registrationmicrosoft/GitHub-Copilot-for-Azure2552 repos~2.1kAutomated safety check: PassMIT
Troubleshooting Authenticationmicrosoft-foundry/foundry-agent-webapp127—~682Automated safety check: NotesMIT

Similar skills

  • Azure Identity Py

    aiskillstore/marketplace

    Azure Identity SDK for Python authentication. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 4 repos~1.4k tokens
    Backend & APIsAuto-check passed
  • Apex Entra App Registration

    jonathan-vella/apex

    WORKFLOW SKILL — Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

    217 GitHub stars~1.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • Entra Agent Id

    microsoft/GitHub-Copilot-for-Azure

    Official

    Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…

    255 GitHub starsUsed in 2 repos~4k tokens
    Backend & APIsAuto-check passed
  • Entra App Registration

    microsoft/GitHub-Copilot-for-Azure

    Official

    Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

    255 GitHub starsUsed in 2 repos~2.1k tokens
    Backend & APIsAuto-check passed
  • Troubleshooting Authentication

    microsoft-foundry/foundry-agent-webapp

    Provides authentication troubleshooting for MSAL, JWT, and Entra ID.

    127 GitHub stars~682 tokensUpdated 5 mo ago
    Backend & APIsAuto-check: notes
  • Iam Audit

    briiirussell/cybersecurity-skills

    Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…

    413 GitHub stars~3.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes

More from microsoft/skills

All 150 skills in this repo
  • Official

    Covers producer, consumer, and checkpoint-store setup for Azure Event Hubs streaming in Python, with Entra ID auth and partition targeting.

    3.1k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Official

    Builds podcast-style audio narration from text with Azure OpenAI's GPT Realtime Mini over WebSocket, from a Python FastAPI backend to a React player.

    3.1k GitHub starsUsed in 1 repo~947 tokens
    Auto-check passed
  • Frontend UI Dark TS

    microsoft/skills

    Official

    Build dark-themed React applications using Tailwind CSS with custom theming, glassmorphism effects, and Framer Motion animations.

    3.1k GitHub starsUsed in 5 repos~3.6k tokens
    Auto-check passed
  • Pydantic Models Py

    microsoft/skills

    Official

    Create Pydantic models following the multi-model pattern with Base, Create, Update, Response, and InDB variants.

    3.1k GitHub starsUsed in 5 repos~496 tokens
    Auto-check passed
  • Official

    Reference for building on Microsoft Foundry with the azure-ai-projects Python SDK: project clients, versioned agents, evaluations, connections, datasets and indexes.

    3.1k GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Skill Creator

    microsoft/skills

    Official

    Guide for creating effective skills for AI coding agents working with Azure SDKs and Microsoft Foundry services.

    3.1k GitHub starsUsed in 5 repos~17k tokens
    Auto-check passed

Questions about Azure Identity Py

What does Azure Identity Py do?

Azure Identity SDK for Python authentication with Microsoft Entra ID. Azure Identity Py is an agent skill from microsoft/skills, published by the product's own GitHub organization. Azure Identity SDK for Python authentication with Microsoft Entra ID.

When should I use Azure Identity Py?

Azure Identity Py fits situations like: defaultAzureCredential; managed identity; service principals.

How do I install Azure Identity Py in Claude Code?

Run `npx skills add microsoft/skills --skill azure-identity-py -a claude-code`. Or copy the skill folder (.github/plugins/azure-sdk-python/skills/azure-identity-py in microsoft/skills) into .claude/skills/azure-identity-py in your project. Claude Code loads it when a task matches its description.

How do I install Azure Identity Py in Codex?

Run `npx skills add microsoft/skills --skill azure-identity-py -a codex`. Or copy the skill folder (.github/plugins/azure-sdk-python/skills/azure-identity-py in microsoft/skills) into .agents/skills/azure-identity-py in your project. Codex loads it when a task matches its description.

Can I use Azure Identity Py in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/skills --skill azure-identity-py -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-identity-py, .gemini/skills/azure-identity-py, .github/skills/azure-identity-py and .opencode/skills/azure-identity-py in your project.

What does Azure Identity Py need to run?

Going by SKILL.md and its folder, Azure Identity Py needs the command-line tools its instructions call (pip and az) and credentials named AZURE_TOKEN_CREDENTIALS, AZURE_CLIENT_SECRET and AZURE_CLIENT_CERTIFICATE_PASSWORD. Our summary lists: Python 3; A credential in AZURE_CLIENT_SECRET.

Does Azure Identity Py access the network?

SKILL.md names 7 domains. In commands or code: management.azure.com, cognitiveservices.azure.com and ossrdbms-aad.database.windows.net; the agent is likely to contact these when it follows the instructions. As links in the text: aka.ms, pypi.org, learn.microsoft.com and github.com. This is read from the text; nothing was executed.

Is Azure Identity Py safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Identity Py use?

Azure Identity Py is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Identity Py use?

About 4.4k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.

What are the alternatives to Azure Identity Py?

Skills that share tags, products or a category with Azure Identity Py: Azure Identity Py (aiskillstore/marketplace, 430 stars), Apex Entra App Registration (jonathan-vella/apex, 217 stars), Entra Agent Id (microsoft/GitHub-Copilot-for-Azure, 255 stars) and Entra App Registration (microsoft/GitHub-Copilot-for-Azure, 255 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Identity Py?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/skills, which has 3,094 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on October 9, 2026.

Source: microsoft/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.