Official agent skill

Entra Agent Id

by microsoft in microsoft/GitHub-Copilot-for-Azure

Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…

OfficialMITAuto-check passedBackend & APIs

Install Entra Agent Id

skills CLI
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill entra-agent-id -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/GitHub-Copilot-for-Azure entra-agent-id --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/azure-skills/skills/entra-agent-id .claude/skills/entra-agent-id && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
entra-agent-id
GitHub stars
255
Used in
3 other repos
Token cost
~4k tokens
SKILL.md length
1,142 words
Files
8 (incl. references)
Skills in repo
56
Repo updated
First seen
Licence
MIT

At a glance

Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…

  • Works in 3 steps: Create Agent Identity Blueprint → Create BlueprintPrincipal → Create Agent Identities
  • : Agent Identity Blueprint
  • SKILL.md covers Quick Reference, When to Use This Skill, MCP Tools and Before You Start, plus 12 more sections
  • Calls pip and az; reaches graph.microsoft.com; needs AZURE_CLIENT_SECRET

What it does

Entra Agent Id is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization. Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant) including the Microsoft Entra SDK for AgentID sidecar. USE FOR: Agent Identity Blueprint, BlueprintPrincipal, agent OAuth, fmipath token exchange, agent OBO, Workload Identity Federation for agents, polyglot agent auth, Microsoft.Identity.Web.AgentIdentities. DO NOT USE FOR: standard Entra app registration (use…

Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `references/known-limitations.md`, `references/oauth2-token-flow.md` and `references/obo-blueprint-setup.md`).

It sits in Backend & APIs, covering OAuth and OpenID Connect. It works with Microsoft Entra ID, Microsoft 365, Microsoft Azure and Python. The repository describes itself as: GitHub Copilot for Azure. The licence is MIT.

When your agent uses it

  • : Agent Identity Blueprint
  • BlueprintPrincipal
  • Fmipath token exchange
  • Workload Identity Federation for agents

Example prompts

  • “/entra-agent-id”

Requirements

  • Python 3
  • A credential in AZURE_CLIENT_SECRET

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Create Agent Identity Blueprint
  2. Create BlueprintPrincipal
  3. Create Agent Identities

What it can do on your machine

Read from SKILL.md and the folder at commit fcf2f3b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pip
    • az

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • graph.microsoft.com

    Also links to:

    • learn.microsoft.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AZURE_CLIENT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Entra Agent Id loads about 4k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 153 tokens; SKILL.md has 1,142 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~153
When it runs · the whole SKILL.md, loaded when a task matches
~4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~12k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/GitHub-Copilot-for-Azure at commit fcf2f3b, republished under its MIT licence (© microsoft). 1,142 words, ~3,994 tokens.

Download SKILL.mdSave it as .claude/skills/entra-agent-id/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
entra-agent-id
description
Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmi_path, OBO, cross-tenant) including the Microsoft Entra SDK for AgentID sidecar. USE FOR: Agent Identity Blueprint, BlueprintPrincipal, agent OAuth, fmi_path token exchange, agent OBO, Workload Identity Federation for agents, polyglot agent auth, Microsoft.Identity.Web.AgentIdentities. DO NOT USE FOR: standard Entra app registration (use entra-app-registration), Microsoft Foundry agent authoring (use microsoft-foundry).
license
MIT
metadata.author
Microsoft
metadata.version
0.0.0-placeholder

Microsoft Entra Agent ID

Create and manage OAuth 2.0-capable identities for AI agents using Microsoft Graph. Every agent instance gets a distinct identity, audit trail, and independently-scoped permission grants.

Quick Reference

PropertyValue
ServiceMicrosoft Entra Agent ID
APIMicrosoft Graph (https://graph.microsoft.com/v1.0)
Required roleAgent Identity Developer, Agent Identity Administrator, or Application Administrator
Object modelBlueprint (application) → BlueprintPrincipal (SP) → Agent Identity (SP)
Runtime exchangeTwo-step fmi_path exchange (autonomous and OBO)
.NET helperMicrosoft.Identity.Web.AgentIdentities
Polyglot helperMicrosoft Entra SDK for AgentID (sidecar container)

When to Use This Skill

  • Provisioning a new Agent Identity Blueprint and BlueprintPrincipal
  • Creating per-instance Agent Identities under a Blueprint
  • Configuring credentials (FIC, Managed Identity, or client secret) on the Blueprint
  • Implementing the two-step fmi_path runtime token exchange (autonomous or OBO)
  • Cross-tenant agent token flows
  • Deploying the Microsoft Entra SDK for AgentID sidecar for polyglot agents (Python, Node, Go, Java)
  • Granting per-Agent-Identity application (appRoleAssignments) or delegated (oauth2PermissionGrants) permissions
  • Diagnosing Agent ID errors such as AADSTS82001, AADSTS700211, or PropertyNotCompatibleWithAgentIdentity

MCP Tools

ToolUse
mcp_azure_mcp_documentationSearch Microsoft Learn for current Agent ID setup, Graph API shapes, and SDK configuration

There is no dedicated Agent Identity MCP server today. This skill guides direct Microsoft Graph API calls (PowerShell or Python requests). Use mcp_azure_mcp_documentation to verify request bodies and endpoints against current docs before running.

Before You Start

Use the mcp_azure_mcp_documentation tool to search Microsoft Learn for current Agent ID documentation:

  • "Microsoft Entra Agent ID setup instructions"
  • "Microsoft Entra SDK for AgentID"

Verify request bodies and endpoints against the installed SDK version — Graph API shapes evolve.

Conceptual Model

Agent Identity Blueprint (application)         ← one per agent type/project
  └── BlueprintPrincipal (service principal)    ← MUST be created explicitly
        ├── Agent Identity (SP): agent-1        ← one per agent instance
        ├── Agent Identity (SP): agent-2
        └── Agent Identity (SP): agent-3
ConceptDescription
BlueprintApplication object that defines a type/class of agent. Holds credentials (secret, certificate, federated identity).
BlueprintPrincipalService principal for the Blueprint in the tenant. Not auto-created.
Agent IdentityService-principal-only identity for a single agent instance. Cannot hold its own credentials.
SponsorA User (or Group, for Agent Identity) who is responsible for the identity. Required on creation.

Prerequisites

Required Entra Roles

One of: Agent Identity Developer, Agent Identity Administrator, or Application Administrator.

PowerShell (interactive setup)
powershell
# PowerShell 7+
Install-Module Microsoft.Graph.Applications -Scope CurrentUser -Force
Python (programmatic provisioning)
bash
pip install azure-identity requests

Authentication

DefaultAzureCredential is not supported. Azure CLI tokens carry Directory.AccessAsUser.All, which Agent Identity APIs hard-reject (403). Use a dedicated app registration with client_credentials, or Connect-MgGraph with explicit delegated scopes.

PowerShell (delegated)
powershell
Connect-MgGraph -Scopes @(
    "AgentIdentityBlueprint.Create",
    "AgentIdentityBlueprint.ReadWrite.All",
    "AgentIdentityBlueprintPrincipal.Create",
    "AgentIdentity.Create.All",
    "User.Read"
)
Python (application)
python
import os, requests
from azure.identity import ClientSecretCredential

credential = ClientSecretCredential(
    tenant_id=os.environ["AZURE_TENANT_ID"],
    client_id=os.environ["AZURE_CLIENT_ID"],
    client_secret=os.environ["AZURE_CLIENT_SECRET"],
)
token = credential.get_token("https://graph.microsoft.com/.default")

GRAPH = "https://graph.microsoft.com/v1.0"
headers = {
    "Authorization": f"Bearer {token.token}",
    "Content-Type": "application/json",
    "OData-Version": "4.0",
}

Core Workflow

Step 1: Create Agent Identity Blueprint

Use the typed endpoint. Sponsors must be Users at Blueprint creation. This snippet assumes the requests client and headers dict from the Python authentication block above.

python
import subprocess
import requests

user_id = subprocess.run(
    ["az", "ad", "signed-in-user", "show", "--query", "id", "-o", "tsv"],
    capture_output=True, text=True, check=True,
).stdout.strip()

blueprint_body = {
    "displayName": "My Agent Blueprint",
    "sponsors@odata.bind": [
        f"https://graph.microsoft.com/v1.0/users/{user_id}"
    ],
}
resp = requests.post(
    f"{GRAPH}/applications/microsoft.graph.agentIdentityBlueprint",
    headers=headers, json=blueprint_body,
)
resp.raise_for_status()

blueprint = resp.json()
app_id = blueprint["appId"]
blueprint_obj_id = blueprint["id"]
Step 2: Create BlueprintPrincipal

Mandatory. Creating a Blueprint does NOT auto-create its service principal. Skipping this step produces: 400: The Agent Blueprint Principal for the Agent Blueprint does not exist.

python
sp_body = {"appId": app_id}
resp = requests.post(
    f"{GRAPH}/servicePrincipals/microsoft.graph.agentIdentityBlueprintPrincipal",
    headers=headers, json=sp_body,
)
resp.raise_for_status()

Make your provisioning scripts idempotent — always check for the BlueprintPrincipal even when the Blueprint already exists.

Step 3: Create Agent Identities

Sponsors for an Agent Identity may be Users or Groups.

python
agent_body = {
    "displayName": "my-agent-instance-1",
    "agentIdentityBlueprintId": app_id,
    "sponsors@odata.bind": [
        f"https://graph.microsoft.com/v1.0/users/{user_id}"
    ],
}
resp = requests.post(
    f"{GRAPH}/servicePrincipals/microsoft.graph.agentIdentity",
    headers=headers, json=agent_body,
)
resp.raise_for_status()
agent = resp.json()
agent_sp_id = agent["id"]

Runtime Authentication

Agents authenticate at runtime using credentials configured on the Blueprint (not on the Agent Identity — Agent Identities can't hold credentials).

OptionUse caseCredential on Blueprint
Managed Identity + WIFProduction (Azure-hosted)Federated Identity Credential
Client secretLocal dev / testingPassword credential
Microsoft Entra SDK for AgentIDPolyglot / 3P agentsSidecar container acquires tokens over HTTP

For the two-step fmi_path exchange (parent token → per-Agent-Identity Graph token) that gives each agent instance a distinct sub claim and audit trail, see references/runtime-token-exchange.md.

For OBO (agent acting on behalf of a user), see references/obo-blueprint-setup.md.

For the containerized polyglot auth sidecar (Python, Node, Go, Java — no SDK embedding), see references/sdk-sidecar.md.

For MI+WIF and client-secret setup details, see references/oauth2-token-flow.md.

.NET quick path

For .NET services, use Microsoft.Identity.Web.AgentIdentities — it handles Federated Identity Credential management and the two-step exchange for you. See the package README at github.com/AzureAD/microsoft-identity-web under src/Microsoft.Identity.Web.AgentIdentities/.

Granting Permissions (Per Agent Identity)

Agent Identities support both application permissions (autonomous) and delegated permissions (OBO). Grants are scoped per Agent Identity, not to the BlueprintPrincipal.

Application permissions (autonomous)
python
graph_sp = requests.get(
    f"{GRAPH}/servicePrincipals?$filter=appId eq '00000003-0000-0000-c000-000000000000'",
    headers=headers,
).json()["value"][0]

user_read_all = next(r for r in graph_sp["appRoles"] if r["value"] == "User.Read.All")

requests.post(
    f"{GRAPH}/servicePrincipals/{agent_sp_id}/appRoleAssignments",
    headers=headers,
    json={
        "principalId": agent_sp_id,
        "resourceId": graph_sp["id"],
        "appRoleId": user_read_all["id"],
    },
).raise_for_status()
Delegated permissions (OBO)
python
from datetime import datetime, timedelta, timezone

expiry = (datetime.now(timezone.utc) + timedelta(days=3650)).strftime("%Y-%m-%dT%H:%M:%SZ")

requests.post(
    f"{GRAPH}/oauth2PermissionGrants",
    headers=headers,
    json={
        "clientId": agent_sp_id,
        "consentType": "AllPrincipals",
        "resourceId": graph_sp["id"],
        "scope": "User.Read Tasks.ReadWrite Mail.Send",
        "expiryTime": expiry,
    },
).raise_for_status()

Browser-based admin consent URLs do not work for Agent Identities — use oauth2PermissionGrants for programmatic delegated consent.

Cross-Tenant Agent Identities

Blueprints can be multi-tenant (signInAudience: AzureADMultipleOrgs). When exchanging tokens cross-tenant:

Step 1 of the parent token exchange MUST target the Agent Identity's home tenant, not the Blueprint's. Wrong tenant → AADSTS700211: No matching federated identity record found.

See references/runtime-token-exchange.md for full cross-tenant examples.

Show full SKILL.md (442 more words)Show less

API Reference

OperationMethodEndpoint
Create BlueprintPOST/applications/microsoft.graph.agentIdentityBlueprint
Create BlueprintPrincipalPOST/servicePrincipals/microsoft.graph.agentIdentityBlueprintPrincipal
Create Agent IdentityPOST/servicePrincipals/microsoft.graph.agentIdentity
Add FIC to BlueprintPOST/applications/{id}/microsoft.graph.agentIdentityBlueprint/federatedIdentityCredentials
List Agent IdentitiesGET/servicePrincipals/microsoft.graph.agentIdentity
Grant app permissionPOST/servicePrincipals/{id}/appRoleAssignments
Grant delegated permissionPOST/oauth2PermissionGrants
Delete Agent IdentityDELETE/servicePrincipals/{id}
Delete BlueprintDELETE/applications/{id}

Base URL: https://graph.microsoft.com/v1.0.

Required Graph Permissions

PermissionPurpose
AgentIdentityBlueprint.CreateCreate Blueprints
AgentIdentityBlueprint.ReadWrite.AllRead/update Blueprints
AgentIdentityBlueprintPrincipal.CreateCreate BlueprintPrincipals
AgentIdentity.Create.AllCreate Agent Identities
AgentIdentity.ReadWrite.AllRead/update Agent Identities
Application.ReadWrite.AllBlueprint CRUD on application objects
AppRoleAssignment.ReadWrite.AllGrant application permissions
DelegatedPermissionGrant.ReadWrite.AllGrant delegated permissions

Grant admin consent (required for application permissions):

bash
az ad app permission admin-consent --id <client-id>

After admin consent, tokens may not include new claims for 30–120 seconds — retry with exponential backoff.

Best Practices

  1. Always create BlueprintPrincipal after Blueprint — not auto-created.
  2. Use typed endpoints (/applications/microsoft.graph.agentIdentityBlueprint) instead of raw /applications with @odata.type.
  3. Credentials live on the Blueprint — Agent Identities can't hold secrets/certs (PropertyNotCompatibleWithAgentIdentity).
  4. Include OData-Version: 4.0 on every Graph request.
  5. Use Workload Identity Federation for production — client secrets only for local dev.
  6. Set identifierUris: ["api://{appId}"] on the Blueprint before OAuth2 scope resolution.
  7. Never use Azure CLI tokens for Agent Identity APIs — Directory.AccessAsUser.All causes hard 403.
  8. Use fmi_path with client_credentials — NOT RFC 8693 urn:ietf:params:oauth:grant-type:token-exchange (returns AADSTS82001).
  9. Always use /.default scope in both steps of the exchange — individual scopes fail.
  10. Step 1 targets the Agent Identity's home tenant in cross-tenant flows.
  11. Grant permissions per Agent Identity, not to the BlueprintPrincipal.
  12. Handle permission-propagation delays — retry 403s with 30–120s backoff after admin consent.
  13. Keep the Entra SDK for AgentID on localhost — never expose via LoadBalancer or Ingress.

Troubleshooting

ErrorCauseFix
AADSTS82001Used RFC 8693 token-exchange grantUse client_credentials with fmi_path
AADSTS700211Step 1 parent token targeted wrong tenantTarget Agent Identity's home tenant
AADSTS50013OBO user token targets Graph, not BlueprintUse api://{blueprint_app_id}/access_as_user
AADSTS65001Missing grant or used individual scopesUse /.default and verify oauth2PermissionGrants
403 Authorization_RequestDeniedNo grant on this Agent IdentityAdd via appRoleAssignments or oauth2PermissionGrants
PropertyNotCompatibleWithAgentIdentityTried to add credential to Agent Identity SPPut credentials on the Blueprint
Agent Blueprint Principal does not existBlueprintPrincipal not createdStep 2 of the Core Workflow
AADSTS650051 on admin consentSP already exists from partial consentGrant directly via appRoleAssignments

References

FileContents
references/runtime-token-exchange.mdTwo-step fmi_path exchange: autonomous + OBO, cross-tenant
references/oauth2-token-flow.mdMI + WIF (production) and client secret (local dev)
references/obo-blueprint-setup.mdConfiguring the Blueprint as an OAuth2 API for OBO
references/sdk-sidecar.mdMicrosoft Entra SDK for AgentID — architecture, configuration, endpoints
references/sdk-sidecar-deployment.mdSDK code patterns (Python/TypeScript), Docker/Kubernetes manifests, security, troubleshooting
references/known-limitations.mdDocumented gaps organized by category

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (references) in plugins/azure-skills/skills/entra-agent-id of microsoft/GitHub-Copilot-for-Azure.

  • SKILL.md
  • references/known-limitations.md
  • references/oauth2-token-flow.md
  • references/obo-blueprint-setup.md
  • references/runtime-token-exchange.md
  • references/sdk-sidecar-deployment.md
  • references/sdk-sidecar.md
  • version.json

Open the folder on GitHubat commit fcf2f3b

Used in 5 other repositories

We found 10 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in microsoft/GitHub-Copilot-for-Azure, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Entra Agent Id next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Entra Agent Id compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Entra Agent Id this skillmicrosoft/GitHub-Copilot-for-Azure2553 repos~4kAutomated safety check: PassMIT
Detecting OAuth Token Theftmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Auditing Azure Active Directory Configurationmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Detecting Email Account Compromisemukul975/Anthropic-Cybersecurity-Skills34k—~823Automated safety check: PassApache-2.0
Entra Agent Idmicrosoft/skills3.1k1 repos~2.3kAutomated safety check: PassMIT
CLI Microsoft365 Scriptpnp/cli-microsoft365-mcp-server131—~3.3kAutomated safety check: PassMIT

Similar skills

  • Detecting OAuth Token Theft

    mukul975/Anthropic-Cybersecurity-Skills

    Detect and respond to OAuth token theft and replay in Microsoft Entra ID (Azure AD), covering access token theft, refresh token replay, Primary Refresh Token (PRT) abuse, pass-the-cookie attacks…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Auditing Azure Active Directory Configuration

    mukul975/Anthropic-Cybersecurity-Skills

    Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Detecting Email Account Compromise

    mukul975/Anthropic-Cybersecurity-Skills

    Detect compromised O365 and Google Workspace email accounts by analyzing Unified Audit Logs and Azure AD sign-in logs for impossible travel, inbox rule creation/deletion (Set-InboxRule…

    34k GitHub stars~823 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Entra Agent Id

    microsoft/skills

    Official

    Microsoft Entra Agent ID (preview) for creating OAuth2-capable AI agent identities via Microsoft Graph beta API.

    3.1k GitHub starsUsed in 1 repo~2.3k tokens
    DevOps & CloudAuto-check passed
  • CLI Microsoft365 Script

    pnp/cli-microsoft365-mcp-server

    Write PowerShell scripts using CLI for Microsoft 365 commands to automate Microsoft 365 management tasks.

    131 GitHub stars~3.3k tokensUpdated 3 days ago
    Documents & OfficeAuto-check passed
  • Entra Agent User

    github/awesome-copilot

    Official

    Create Agent Users in Microsoft Entra ID from Agent Identities, enabling AI agents to act as digital workers with user identity capabilities in Microsoft 365 and Azure environments.

    40k GitHub starsUsed in 1 repo~2.3k tokens
    Documents & OfficeAuto-check passed

More from microsoft/GitHub-Copilot-for-Azure

All 56 skills in this repo
  • Capacity

    microsoft/GitHub-Copilot-for-Azure

    Official

    Discovers available Azure OpenAI model capacity across regions and projects.

    255 GitHub starsUsed in 2 repos~1.7k tokens
    Auto-check passed
  • Deploy Model

    microsoft/GitHub-Copilot-for-Azure

    Official

    Unified Azure OpenAI model deployment skill with intelligent intent-based routing.

    255 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Microsoft Foundry

    microsoft/GitHub-Copilot-for-Azure

    Official

    Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end.

    255 GitHub starsUsed in 1 repo~6.7k tokens
    Auto-check passed
  • Azure Storage

    microsoft/GitHub-Copilot-for-Azure

    Official

    Azure Storage Services including Blob Storage, File Shares, Queue Storage, Table Storage, and Data Lake.

    255 GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check passed
  • Preset

    microsoft/GitHub-Copilot-for-Azure

    Official

    Intelligently deploys Azure OpenAI models to optimal regions by analyzing capacity across all available regions.

    255 GitHub starsUsed in 2 repos~1.2k tokens
    Auto-check passed
  • Azure Quotas

    microsoft/GitHub-Copilot-for-Azure

    Official

    Check/manage Azure quotas and usage across providers. An agent skill from microsoft/GitHub-Copilot-for-Azure.

    255 GitHub starsUsed in 1 repo~3k tokens
    Auto-check passed

Categories

Questions about Entra Agent Id

What does Entra Agent Id do?

Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…. Entra Agent Id is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization.0 token exchange (fmipath, OBO, cross-tenant) including the Microsoft Entra SDK for AgentID sidecar.

When should I use Entra Agent Id?

Entra Agent Id fits situations like: : Agent Identity Blueprint; blueprintPrincipal; fmipath token exchange; workload Identity Federation for agents.

How do I install Entra Agent Id in Claude Code?

Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill entra-agent-id -a claude-code`. Or copy the skill folder (plugins/azure-skills/skills/entra-agent-id in microsoft/GitHub-Copilot-for-Azure) into .claude/skills/entra-agent-id in your project. Claude Code loads it when a task matches its description.

How do I install Entra Agent Id in Codex?

Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill entra-agent-id -a codex`. Or copy the skill folder (plugins/azure-skills/skills/entra-agent-id in microsoft/GitHub-Copilot-for-Azure) into .agents/skills/entra-agent-id in your project. Codex loads it when a task matches its description.

Can I use Entra Agent Id in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill entra-agent-id -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/entra-agent-id, .gemini/skills/entra-agent-id, .github/skills/entra-agent-id and .opencode/skills/entra-agent-id in your project.

What does Entra Agent Id need to run?

Going by SKILL.md and its folder, Entra Agent Id needs the command-line tools its instructions call (pip and az) and credentials named AZURE_CLIENT_SECRET. Our summary lists: Python 3; A credential in AZURE_CLIENT_SECRET.

Does Entra Agent Id access the network?

SKILL.md names 3 domains. In commands or code: graph.microsoft.com; the agent is likely to contact it when it follows the instructions. As links in the text: learn.microsoft.com and github.com. This is read from the text; nothing was executed.

Is Entra Agent Id safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Entra Agent Id use?

Entra Agent Id is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Entra Agent Id use?

About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.2k tokens, read only when the agent opens those files.

What are the alternatives to Entra Agent Id?

Skills that share tags, products or a category with Entra Agent Id: Detecting OAuth Token Theft (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Auditing Azure Active Directory Configuration (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting Email Account Compromise (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Entra Agent Id (microsoft/skills, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Entra Agent Id?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/GitHub-Copilot-for-Azure, which has 255 GitHub stars. The repository holds 56 skills in this directory. The repository was last updated on October 8, 2026.

Source: microsoft/GitHub-Copilot-for-Azure on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.