Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…
Install the "entra-agent-id" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-skills/skills/entra-agent-id into .claude/skills/entra-agent-id/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "entra-agent-id", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill entra-agent-id -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "entra-agent-id" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-skills/skills/entra-agent-id into .agents/skills/entra-agent-id/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "entra-agent-id", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill entra-agent-id -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "entra-agent-id" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-skills/skills/entra-agent-id into .cursor/skills/entra-agent-id/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "entra-agent-id", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill entra-agent-id -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "entra-agent-id" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-skills/skills/entra-agent-id into .gemini/skills/entra-agent-id/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "entra-agent-id", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill entra-agent-id -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "entra-agent-id" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-skills/skills/entra-agent-id into .github/skills/entra-agent-id/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "entra-agent-id", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill entra-agent-id -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "entra-agent-id" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-skills/skills/entra-agent-id into .opencode/skills/entra-agent-id/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "entra-agent-id", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
entra-agent-id
GitHub stars
255
Used in
3 other repos
Token cost
~4k tokens
SKILL.md length
1,142 words
Files
8 (incl. references)
Skills in repo
56
Repo updated
First seen
Licence
MIT
At a glance
Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…
Works in 3 steps: Create Agent Identity Blueprint → Create BlueprintPrincipal → Create Agent Identities
: Agent Identity Blueprint
SKILL.md covers Quick Reference, When to Use This Skill, MCP Tools and Before You Start, plus 12 more sections
Calls pip and az; reaches graph.microsoft.com; needs AZURE_CLIENT_SECRET
What it does
Entra Agent Id is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization. Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant) including the Microsoft Entra SDK for AgentID sidecar. USE FOR: Agent Identity Blueprint, BlueprintPrincipal, agent OAuth, fmipath token exchange, agent OBO, Workload Identity Federation for agents, polyglot agent auth, Microsoft.Identity.Web.AgentIdentities. DO NOT USE FOR: standard Entra app registration (use…
Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `references/known-limitations.md`, `references/oauth2-token-flow.md` and `references/obo-blueprint-setup.md`).
It sits in Backend & APIs, covering OAuth and OpenID Connect. It works with Microsoft Entra ID, Microsoft 365, Microsoft Azure and Python. The repository describes itself as: GitHub Copilot for Azure. The licence is MIT.
When your agent uses it
: Agent Identity Blueprint
BlueprintPrincipal
Fmipath token exchange
Workload Identity Federation for agents
Example prompts
“/entra-agent-id”
Requirements
Python 3
A credential in AZURE_CLIENT_SECRET
Workflow steps
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit fcf2f3b. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
pip
az
From the folder's file list and the shell code blocks in SKILL.md.
Network
Hosts in commands or code, which the agent is likely to contact:
graph.microsoft.com
Also links to:
learn.microsoft.com
github.com
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names these keys or tokens, usually read from environment variables:
AZURE_CLIENT_SECRET
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Entra Agent Id loads about 4k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 153 tokens; SKILL.md has 1,142 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~153
When it runs· the whole SKILL.md, loaded when a task matches
~4k
With references· SKILL.md plus every file in references/, read only if the agent opens them
~12k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/entra-agent-id/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
entra-agent-id
description
Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmi_path, OBO, cross-tenant) including the Microsoft Entra SDK for AgentID sidecar. USE FOR: Agent Identity Blueprint, BlueprintPrincipal, agent OAuth, fmi_path token exchange, agent OBO, Workload Identity Federation for agents, polyglot agent auth, Microsoft.Identity.Web.AgentIdentities. DO NOT USE FOR: standard Entra app registration (use entra-app-registration), Microsoft Foundry agent authoring (use microsoft-foundry).
license
MIT
metadata.author
Microsoft
metadata.version
0.0.0-placeholder
Microsoft Entra Agent ID
Create and manage OAuth 2.0-capable identities for AI agents using Microsoft Graph. Every agent instance gets a distinct identity, audit trail, and independently-scoped permission grants.
Quick Reference
Property
Value
Service
Microsoft Entra Agent ID
API
Microsoft Graph (https://graph.microsoft.com/v1.0)
Required role
Agent Identity Developer, Agent Identity Administrator, or Application Administrator
Microsoft Entra SDK for AgentID (sidecar container)
When to Use This Skill
Provisioning a new Agent Identity Blueprint and BlueprintPrincipal
Creating per-instance Agent Identities under a Blueprint
Configuring credentials (FIC, Managed Identity, or client secret) on the Blueprint
Implementing the two-step fmi_path runtime token exchange (autonomous or OBO)
Cross-tenant agent token flows
Deploying the Microsoft Entra SDK for AgentID sidecar for polyglot agents (Python, Node, Go, Java)
Granting per-Agent-Identity application (appRoleAssignments) or delegated (oauth2PermissionGrants) permissions
Diagnosing Agent ID errors such as AADSTS82001, AADSTS700211, or PropertyNotCompatibleWithAgentIdentity
MCP Tools
Tool
Use
mcp_azure_mcp_documentation
Search Microsoft Learn for current Agent ID setup, Graph API shapes, and SDK configuration
There is no dedicated Agent Identity MCP server today. This skill guides direct Microsoft Graph API calls (PowerShell or Python requests). Use mcp_azure_mcp_documentation to verify request bodies and endpoints against current docs before running.
Before You Start
Use the mcp_azure_mcp_documentation tool to search Microsoft Learn for current Agent ID documentation:
"Microsoft Entra Agent ID setup instructions"
"Microsoft Entra SDK for AgentID"
Verify request bodies and endpoints against the installed SDK version — Graph API shapes evolve.
Conceptual Model
Agent Identity Blueprint (application) ← one per agent type/project
└── BlueprintPrincipal (service principal) ← MUST be created explicitly
├── Agent Identity (SP): agent-1 ← one per agent instance
├── Agent Identity (SP): agent-2
└── Agent Identity (SP): agent-3
Concept
Description
Blueprint
Application object that defines a type/class of agent. Holds credentials (secret, certificate, federated identity).
BlueprintPrincipal
Service principal for the Blueprint in the tenant. Not auto-created.
Agent Identity
Service-principal-only identity for a single agent instance. Cannot hold its own credentials.
Sponsor
A User (or Group, for Agent Identity) who is responsible for the identity. Required on creation.
Prerequisites
Required Entra Roles
One of: Agent Identity Developer, Agent Identity Administrator, or Application Administrator.
DefaultAzureCredential is not supported. Azure CLI tokens carry Directory.AccessAsUser.All, which Agent Identity APIs hard-reject (403). Use a dedicated app registration with client_credentials, or Connect-MgGraph with explicit delegated scopes.
Use the typed endpoint. Sponsors must be Users at Blueprint creation. This snippet assumes the requests client and headers dict from the Python authentication block above.
Mandatory. Creating a Blueprint does NOT auto-create its service principal. Skipping this step produces:
400: The Agent Blueprint Principal for the Agent Blueprint does not exist.
Agents authenticate at runtime using credentials configured on the Blueprint (not on the Agent Identity — Agent Identities can't hold credentials).
Option
Use case
Credential on Blueprint
Managed Identity + WIF
Production (Azure-hosted)
Federated Identity Credential
Client secret
Local dev / testing
Password credential
Microsoft Entra SDK for AgentID
Polyglot / 3P agents
Sidecar container acquires tokens over HTTP
For the two-step fmi_path exchange (parent token → per-Agent-Identity Graph token) that gives each agent instance a distinct sub claim and audit trail, see references/runtime-token-exchange.md.
For .NET services, use Microsoft.Identity.Web.AgentIdentities — it handles Federated Identity Credential management and the two-step exchange for you. See the package README at github.com/AzureAD/microsoft-identity-web under src/Microsoft.Identity.Web.AgentIdentities/.
Granting Permissions (Per Agent Identity)
Agent Identities support both application permissions (autonomous) and delegated permissions (OBO). Grants are scoped per Agent Identity, not to the BlueprintPrincipal.
Application permissions (autonomous)
python
graph_sp = requests.get(
f"{GRAPH}/servicePrincipals?$filter=appId eq '00000003-0000-0000-c000-000000000000'",
headers=headers,
).json()["value"][0]
user_read_all = next(r for r in graph_sp["appRoles"] if r["value"] == "User.Read.All")
requests.post(
f"{GRAPH}/servicePrincipals/{agent_sp_id}/appRoleAssignments",
headers=headers,
json={
"principalId": agent_sp_id,
"resourceId": graph_sp["id"],
"appRoleId": user_read_all["id"],
},
).raise_for_status()
Browser-based admin consent URLs do not work for Agent Identities — use oauth2PermissionGrants for programmatic delegated consent.
Cross-Tenant Agent Identities
Blueprints can be multi-tenant (signInAudience: AzureADMultipleOrgs). When exchanging tokens cross-tenant:
Step 1 of the parent token exchange MUST target the Agent Identity's home tenant, not the Blueprint's. Wrong tenant → AADSTS700211: No matching federated identity record found.
We found 10 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in microsoft/GitHub-Copilot-for-Azure, which our catalogue first saw on October 7, 2026.
Entra Agent Id next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Entra Agent Id compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Entra Agent Id this skillmicrosoft/GitHub-Copilot-for-Azure
Detect and respond to OAuth token theft and replay in Microsoft Entra ID (Azure AD), covering access token theft, refresh token replay, Primary Refresh Token (PRT) abuse, pass-the-cookie attacks…
Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest…
Detect compromised O365 and Google Workspace email accounts by analyzing Unified Audit Logs and Azure AD sign-in logs for impossible travel, inbox rule creation/deletion (Set-InboxRule…
Create Agent Users in Microsoft Entra ID from Agent Identities, enabling AI agents to act as digital workers with user identity capabilities in Microsoft 365 and Azure environments.
Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…. Entra Agent Id is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization.0 token exchange (fmipath, OBO, cross-tenant) including the Microsoft Entra SDK for AgentID sidecar.
When should I use Entra Agent Id?
Entra Agent Id fits situations like: : Agent Identity Blueprint; blueprintPrincipal; fmipath token exchange; workload Identity Federation for agents.
How do I install Entra Agent Id in Claude Code?
Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill entra-agent-id -a claude-code`. Or copy the skill folder (plugins/azure-skills/skills/entra-agent-id in microsoft/GitHub-Copilot-for-Azure) into .claude/skills/entra-agent-id in your project. Claude Code loads it when a task matches its description.
How do I install Entra Agent Id in Codex?
Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill entra-agent-id -a codex`. Or copy the skill folder (plugins/azure-skills/skills/entra-agent-id in microsoft/GitHub-Copilot-for-Azure) into .agents/skills/entra-agent-id in your project. Codex loads it when a task matches its description.
Can I use Entra Agent Id in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill entra-agent-id -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/entra-agent-id, .gemini/skills/entra-agent-id, .github/skills/entra-agent-id and .opencode/skills/entra-agent-id in your project.
What does Entra Agent Id need to run?
Going by SKILL.md and its folder, Entra Agent Id needs the command-line tools its instructions call (pip and az) and credentials named AZURE_CLIENT_SECRET. Our summary lists: Python 3; A credential in AZURE_CLIENT_SECRET.
Does Entra Agent Id access the network?
SKILL.md names 3 domains. In commands or code: graph.microsoft.com; the agent is likely to contact it when it follows the instructions. As links in the text: learn.microsoft.com and github.com. This is read from the text; nothing was executed.
Is Entra Agent Id safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Entra Agent Id use?
Entra Agent Id is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Entra Agent Id use?
About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.2k tokens, read only when the agent opens those files.
What are the alternatives to Entra Agent Id?
Skills that share tags, products or a category with Entra Agent Id: Detecting OAuth Token Theft (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Auditing Azure Active Directory Configuration (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting Email Account Compromise (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Entra Agent Id (microsoft/skills, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Entra Agent Id?
microsoft (a GitHub organization, an official publisher) maintains it in microsoft/GitHub-Copilot-for-Azure, which has 255 GitHub stars. The repository holds 56 skills in this directory. The repository was last updated on October 8, 2026.