Official agent skill

Entra App Registration

by microsoft in microsoft/GitHub-Copilot-for-Azure

Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

OfficialMITAuto-check passedBackend & APIs

Install Entra App Registration

skills CLI
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill entra-app-registration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/GitHub-Copilot-for-Azure entra-app-registration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/azure-skills/skills/entra-app-registration .claude/skills/entra-app-registration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
entra-app-registration
GitHub stars
255
Used in
2 other repos
Token cost
~2.1k tokens
SKILL.md length
747 words
Files
18 (incl. references)
Skills in repo
61
Repo updated
First seen
Licence
MIT

At a glance

Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

  • Works in 5 steps: Register the Application → Configure Authentication → Configure API Permissions → …
  • : create app registration
  • SKILL.md covers Overview, Core Workflow, Common Patterns and MCP Tools and CLI, plus 4 more sections
  • Calls az

What it does

Entra App Registration is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization. Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration. USE FOR: create app registration, register Azure AD app, configure OAuth, set up authentication, add API permissions, generate service principal, MSAL example, console app auth, Entra ID setup, Azure AD authentication. DO NOT USE FOR: Key Vault secrets (use azure-keyvault-expiration-audit), general Azure resource security guidance.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 19 other files, including reference files (for example `references/api-permissions.md`, `references/auth-best-practices.md` and `references/cli-commands.md`).

It sits in Backend & APIs, covering Authentication, OAuth and OpenID Connect and Secrets management. It works with Microsoft Entra ID, Microsoft Azure, Azure Key Vault and Bicep. The repository describes itself as: GitHub Copilot for Azure. The licence is MIT.

When your agent uses it

  • : create app registration
  • Register Azure AD app
  • Configure OAuth
  • Set up authentication

Example prompts

  • “Use the entra-app-registration skill to guide Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration”
  • “/entra-app-registration”

Requirements

  • Python 3
  • Node.js

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Register the Application
  2. Configure Authentication
  3. Configure API Permissions
  4. Create Client Credentials (if needed)
  5. Implement OAuth Flow

What it can do on your machine

Read from SKILL.md and the folder at commit ce94fce. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • az

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Entra App Registration loads about 2.1k tokens when it runs, and up to ~21k if it reads all its reference files. Until then it costs about 112 tokens; SKILL.md has 747 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~112
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~21k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/GitHub-Copilot-for-Azure at commit ce94fce, republished under its MIT licence (© microsoft). 747 words, ~2,058 tokens.

Download SKILL.mdSave it as .claude/skills/entra-app-registration/SKILL.md (or your agent's skills folder). This skill also uses 17 other files; get the full folder from GitHub.
name
entra-app-registration
description
Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration. USE FOR: create app registration, register Azure AD app, configure OAuth, set up authentication, add API permissions, generate service principal, MSAL example, console app auth, Entra ID setup, Azure AD authentication. DO NOT USE FOR: Key Vault secrets (use azure-keyvault-expiration-audit), general Azure resource security guidance.
license
MIT
metadata.author
Microsoft
metadata.version
0.0.0-placeholder

Overview

Microsoft Entra ID (formerly Azure Active Directory) is Microsoft's cloud-based identity and access management service. App registrations allow applications to authenticate users and access Azure resources securely.

Key Concepts
ConceptDescription
App RegistrationConfiguration that allows an app to use Microsoft identity platform
Application (Client) IDUnique identifier for your application
Tenant IDUnique identifier for your Azure AD tenant/directory
Client SecretPassword for the application (confidential clients only)
Redirect URIURL where authentication responses are sent
API PermissionsAccess scopes your app requests
Service PrincipalIdentity created in your tenant when you register an app
Application Types
TypeUse Case
Web ApplicationServer-side apps, APIs
Single Page App (SPA)JavaScript/React/Angular apps
Mobile/Native AppDesktop, mobile apps
Daemon/ServiceBackground services, APIs

Core Workflow

Step 1: Register the Application

Create an app registration in the Azure portal or using Azure CLI.

Portal Method:

  1. Navigate to Azure Portal → Microsoft Entra ID → App registrations
  2. Click "New registration"
  3. Provide name, supported account types, and redirect URI
  4. Click "Register"

CLI Method: See references/cli-commands.md IaC Method: See references/BICEP-EXAMPLE.bicep

It's highly recommended to use the IaC to manage Entra app registration if you already use IaC in your project, need a scalable solution for managing lots of app registrations or need fine-grained audit history of the configuration changes.

Step 2: Configure Authentication

Set up authentication settings based on your application type.

  • Web Apps: Add redirect URIs, enable ID tokens if needed
  • SPAs: Add redirect URIs, enable implicit grant flow if necessary
  • Mobile/Desktop: Use http://localhost or custom URI scheme
  • Services: No redirect URI needed for client credentials flow
Step 3: Configure API Permissions

Grant your application permission to access Microsoft APIs or your own APIs.

Common Microsoft Graph Permissions:

  • User.Read - Read user profile
  • User.ReadWrite.All - Read and write all users
  • Directory.Read.All - Read directory data
  • Mail.Send - Send mail as a user

Details: See references/api-permissions.md

Step 4: Create Client Credentials (if needed)

For confidential client applications (web apps, services), create a client secret, certificate or federated identity credential.

Client Secret:

  • Navigate to "Certificates & secrets"
  • Create new client secret
  • Copy the value immediately (only shown once)
  • Store securely (Key Vault recommended)

Certificate: For production environments, use certificates instead of secrets for enhanced security. Upload certificate via "Certificates & secrets" section.

Federated Identity Credential: For dynamically authenticating the confidential client to Entra platform.

Step 5: Implement OAuth Flow

Integrate the OAuth flow into your application code.

See:

Common Patterns

Pattern 1: First-Time App Registration

Walk user through their first app registration step-by-step.

Required Information:

  • Application name
  • Application type (web, SPA, mobile, service)
  • Redirect URIs (if applicable)
  • Required permissions

Script: See references/first-app-registration.md

Show full SKILL.md (306 more words)Show less
Pattern 2: Console Application with User Authentication

Create a .NET/Python/Node.js console app that authenticates users.

Required Information:

  • Programming language (C#, Python, JavaScript, etc.)
  • Authentication library (MSAL recommended)
  • Required permissions

Example: See references/console-app-example.md

Pattern 3: Service-to-Service Authentication

Set up daemon/service authentication without user interaction.

Required Information:

  • Service/app name
  • Target API/resource
  • Whether to use secret or certificate

Implementation: Use Client Credentials flow (see references/oauth-flows.md#client-credentials-flow)

MCP Tools and CLI

Azure CLI Commands
CommandPurpose
az ad app createCreate new app registration
az ad app listList app registrations
az ad app showShow app details
az ad app permission addAdd API permission
az ad app credential resetGenerate new client secret
az ad sp createCreate service principal

Complete reference: See references/cli-commands.md

Microsoft Authentication Library (MSAL)

MSAL is the recommended library for integrating Microsoft identity platform.

Supported Languages:

  • .NET/C# - Microsoft.Identity.Client
  • JavaScript/TypeScript - @azure/msal-browser, @azure/msal-node
  • Python - msal

Examples: See references/console-app-example.md

Security Best Practices

PracticeRecommendation
Never hardcode secretsUse environment variables, Azure Key Vault, or managed identity
Rotate secrets regularlySet expiration, automate rotation
Use certificates over secretsMore secure for production
Least privilege permissionsRequest only required API permissions
Enable MFARequire multi-factor authentication for users
Use managed identityFor Azure-hosted apps, avoid secrets entirely
Validate tokensAlways validate issuer, audience, expiration
Use HTTPS onlyAll redirect URIs must use HTTPS (except localhost)
Monitor sign-insUse Entra ID sign-in logs for anomaly detection

SDK Quick References

References

External Resources

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 17 other files (references) in plugins/azure-skills/skills/entra-app-registration of microsoft/GitHub-Copilot-for-Azure.

  • SKILL.md
  • references/BICEP-EXAMPLE.bicep
  • references/api-permissions.md
  • references/auth-best-practices.md
  • references/cli-commands.md
  • references/console-app-example.md
  • references/first-app-registration.md
  • references/oauth-flows.md
  • references/sdk/azure-identity-dotnet.md
  • references/sdk/azure-identity-java.md
  • references/sdk/azure-identity-py.md
  • references/sdk/azure-identity-rust.md
  • references/sdk/azure-identity-ts.md
  • references/sdk/azure-keyvault-py.md
  • references/sdk/azure-keyvault-secrets-ts.md
  • references/sdk/microsoft-azure-webjobs-extensions-authentication-events-dotnet.md
  • references/troubleshooting.md
  • version.json

Open the folder on GitHubat commit ce94fce

Used in 4 other repositories

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in microsoft/GitHub-Copilot-for-Azure, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Entra App Registration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Entra App Registration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Entra App Registration this skillmicrosoft/GitHub-Copilot-for-Azure2552 repos~2.1kAutomated safety check: PassMIT
Apex Entra App Registrationjonathan-vella/apex217—~1.3kAutomated safety check: PassMIT
Iam Auditbriiirussell/cybersecurity-skills413—~3.1kAutomated safety check: NotesMIT
Azure Key VaultKilo-Org/kilo-marketplace1901 repos~1.9kAutomated safety check: PassMIT
Azure AuthLeoYeAI/openclaw-master-skills2.2k—~4.9kAutomated safety check: NotesMIT
Entra Idvinayaklatthe/microsoft-security-skills175—~2.3kAutomated safety check: PassMIT

Similar skills

  • Apex Entra App Registration

    jonathan-vella/apex

    WORKFLOW SKILL — Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

    217 GitHub stars~1.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • Iam Audit

    briiirussell/cybersecurity-skills

    Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…

    413 GitHub stars~3.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Azure Key Vault

    Kilo-Org/kilo-marketplace

    Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation.

    190 GitHub starsUsed in 1 repo~1.9k tokens
    Backend & APIsAuto-check passed
  • Azure Auth

    LeoYeAI/openclaw-master-skills

    Microsoft Entra ID (Azure AD) authentication for React SPAs with MSAL.js and Cloudflare Workers JWT validation using jose library.

    2.2k GitHub stars~4.9k tokensUpdated 2 mo ago
    Backend & APIsAuto-check: notes
  • Entra Id

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Entra ID (formerly Azure AD) — cloud identity and access management and the control plane for Zero Trust.

    175 GitHub stars~2.3k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Azure Bicep Skill

    timothywarner-org/claude-code

    A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.

    224 GitHub stars~2.9k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed

More from microsoft/GitHub-Copilot-for-Azure

All 61 skills in this repo
  • Capacity

    microsoft/GitHub-Copilot-for-Azure

    Official

    Discovers available Azure OpenAI model capacity across regions and projects.

    255 GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed
  • Deploy Model

    microsoft/GitHub-Copilot-for-Azure

    Official

    Unified Azure OpenAI model deployment skill with intelligent intent-based routing.

    255 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Azure Storage

    microsoft/GitHub-Copilot-for-Azure

    Official

    Azure Storage Services including Blob Storage, File Shares, Queue Storage, Table Storage, and Data Lake.

    255 GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check passed
  • Microsoft Foundry

    microsoft/GitHub-Copilot-for-Azure

    Official

    Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end.

    255 GitHub starsUsed in 1 repo~6.7k tokens
    Auto-check passed
  • Entra Agent Id

    microsoft/GitHub-Copilot-for-Azure

    Official

    Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…

    255 GitHub starsUsed in 2 repos~4k tokens
    Auto-check passed
  • Azure Kubernetes Automatic Readiness

    microsoft/GitHub-Copilot-for-Azure

    Official

    Assess Kubernetes workloads and cluster configuration for AKS Automatic compatibility.

    255 GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed

Categories

Questions about Entra App Registration

What does Entra App Registration do?

Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration. Entra App Registration is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization.0 authentication, and MSAL integration.

When should I use Entra App Registration?

Entra App Registration fits situations like: : create app registration; register Azure AD app; configure OAuth; set up authentication.

How do I install Entra App Registration in Claude Code?

Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill entra-app-registration -a claude-code`. Or copy the skill folder (plugins/azure-skills/skills/entra-app-registration in microsoft/GitHub-Copilot-for-Azure) into .claude/skills/entra-app-registration in your project. Claude Code loads it when a task matches its description.

How do I install Entra App Registration in Codex?

Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill entra-app-registration -a codex`. Or copy the skill folder (plugins/azure-skills/skills/entra-app-registration in microsoft/GitHub-Copilot-for-Azure) into .agents/skills/entra-app-registration in your project. Codex loads it when a task matches its description.

Can I use Entra App Registration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill entra-app-registration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/entra-app-registration, .gemini/skills/entra-app-registration, .github/skills/entra-app-registration and .opencode/skills/entra-app-registration in your project.

What does Entra App Registration need to run?

Going by SKILL.md and its folder, Entra App Registration needs the command-line tools its instructions call (az). Our summary lists: Python 3; Node.js.

Does Entra App Registration access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Entra App Registration safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Entra App Registration use?

Entra App Registration is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Entra App Registration use?

About 2.1k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 19k tokens, read only when the agent opens those files.

What are the alternatives to Entra App Registration?

Skills that share tags, products or a category with Entra App Registration: Apex Entra App Registration (jonathan-vella/apex, 217 stars), Iam Audit (briiirussell/cybersecurity-skills, 413 stars), Azure Key Vault (Kilo-Org/kilo-marketplace, 190 stars) and Azure Auth (LeoYeAI/openclaw-master-skills, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Entra App Registration?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/GitHub-Copilot-for-Azure, which has 255 GitHub stars. The repository holds 61 skills in this directory. The repository was last updated on October 9, 2026.

Source: microsoft/GitHub-Copilot-for-Azure on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.