Official agent skill

Azure Lighthouse

by MicrosoftDocs in MicrosoftDocs/Agent-Skills

Expert knowledge for Azure Lighthouse development including decision making, security, configuration, integrations & coding patterns, and deployment.

OfficialCC-BY-4.0Auto-check passedBackend & APIs

Install Azure Lighthouse

skills CLI
$ npx skills add MicrosoftDocs/Agent-Skills --skill azure-lighthouse -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install MicrosoftDocs/Agent-Skills azure-lighthouse --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/MicrosoftDocs/Agent-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/azure-lighthouse .claude/skills/azure-lighthouse && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-lighthouse
GitHub stars
775
Token cost
~1.6k tokens
SKILL.md length
453 words
Files
1
Skills in repo
149
Repo updated
First seen
Licence
CC-BY-4.0

At a glance

Expert knowledge for Azure Lighthouse development including decision making, security, configuration, integrations & coding patterns, and deployment.

  • Configuring Lighthouse delegations
  • SKILL.md covers How to Use This Skill and Category Index
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • AOBO/PIM access

What it does

Azure Lighthouse is an agent skill from MicrosoftDocs/Agent-Skills, published by the product's own GitHub organization. Expert knowledge for Azure Lighthouse development including decision making, security, configuration, integrations & coding patterns, and deployment. Use when configuring Lighthouse delegations, AOBO/PIM access, Arc/Sentinel integrations, policies/remediation, or Marketplace offers, and other Azure Lighthouse related development tasks. Not for Azure Arc (use azure-arc), Azure Managed Applications (use azure-managed-applications), Azure Resource Manager (use azure-resource-manager), Azure Role-based access control…

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires network access. Uses mcpmicrosoftdocs:microsoftdocsfetch or fetchwebpage to retrieve documentation.

It sits in Backend & APIs, covering Web performance and Authorization and RBAC. It works with Microsoft Azure. The repository describes itself as: Curated Agent Skills for Microsoft & Azure – giving AI coding assistants structured, real-time expertise from Microsoft Learn docs. The licence is CC-BY-4.0.

When your agent uses it

  • Configuring Lighthouse delegations
  • AOBO/PIM access
  • Arc/Sentinel integrations
  • Policies/remediation

Example prompts

  • “/azure-lighthouse”

Requirements

  • Compatibility (from SKILL.md): Requires network access. Uses mcp_microsoftdocs:microsoft_docs_fetch or fetch_webpage to retrieve documentation.

What it can do on your machine

Read from SKILL.md and the folder at commit ba74e8f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires network access. Uses mcp_microsoftdocs:microsoft_docs_fetch or fetch_webpage to retrieve documentation.

    From compatibility in the SKILL.md frontmatter.

Context cost

Azure Lighthouse loads about 1.6k tokens when it runs. Until then it costs about 138 tokens; SKILL.md has 453 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~138
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from MicrosoftDocs/Agent-Skills at commit ba74e8f, republished under its CC-BY-4.0 licence (© MicrosoftDocs). 453 words, ~1,587 tokens.

Download SKILL.mdSave it as .claude/skills/azure-lighthouse/SKILL.md (or your agent's skills folder).
name
azure-lighthouse
description
Expert knowledge for Azure Lighthouse development including decision making, security, configuration, integrations & coding patterns, and deployment. Use when configuring Lighthouse delegations, AOBO/PIM access, Arc/Sentinel integrations, policies/remediation, or Marketplace offers, and other Azure Lighthouse related development tasks. Not for Azure Arc (use azure-arc), Azure Managed Applications (use azure-managed-applications), Azure Resource Manager (use azure-resource-manager), Azure Role-based access control (use azure-rbac).
compatibility
Requires network access. Uses mcp_microsoftdocs:microsoft_docs_fetch or fetch_webpage to retrieve documentation.
metadata.generated_at
2026-04-12
metadata.generator
docs2skills/1.0.0

Azure Lighthouse Skill

This skill provides expert guidance for Azure Lighthouse. Covers decision making, security, configuration, integrations & coding patterns, and deployment. It combines local quick-reference content with remote documentation fetching capabilities.

How to Use This Skill

IMPORTANT for Agent: Use the Category Index below to locate relevant sections. For categories with line ranges (e.g., L35-L120), use read_file with the specified lines. For categories with file links (e.g., [security.md](security.md)), use read_file on the linked reference file

IMPORTANT for Agent: If metadata.generated_at is more than 3 months old, suggest the user pull the latest version from the repository. If mcp_microsoftdocs tools are not available, suggest the user install it: Installation Guide

This skill requires network access to fetch documentation content:

  • Preferred: Use mcp_microsoftdocs:microsoft_docs_fetch with query string from=learn-agent-skill. Returns Markdown.
  • Fallback: Use fetch_webpage with query string from=learn-agent-skill&accept=text/markdown. Returns Markdown.

Category Index

CategoryLinesDescription
Decision MakingL33-L39Guidance on when and how to use Azure Lighthouse: multi-tenant enterprise setups, ISV SaaS patterns, comparing Lighthouse vs managed apps, and designing Managed Service offers.
SecurityL40-L47Managing secure access in Azure Lighthouse: roles, tenants, AOBO, PIM eligible authorizations, and recommended security controls/practices for cross-tenant management.
ConfigurationL48-L60Configuring and managing Azure Lighthouse delegations: onboarding via ARM/policy, updating/removing access, deploying/using policies (incl. built-ins), remediation with managed identities, and monitoring changes.
Integrations & Coding PatternsL61-L68Cross-tenant integration patterns for managing Arc servers, Sentinel workspaces, Migrate projects, and Monitor Logs at scale using Azure Lighthouse.
DeploymentL69-L72Guidance for packaging, publishing, and managing Azure Lighthouse managed service offers in Azure Marketplace, including requirements, steps, and configuration details.
Show full SKILL.md (194 more words)Show less
Decision Making
TopicURL
Apply Azure Lighthouse in ISV SaaS scenarioshttps://learn.microsoft.com/en-us/azure/lighthouse/concepts/isv-scenarios
Choose between Azure Lighthouse and managed applicationshttps://learn.microsoft.com/en-us/azure/lighthouse/concepts/managed-applications
Design Managed Service offers for Azure Lighthousehttps://learn.microsoft.com/en-us/azure/lighthouse/concepts/managed-services-offers
Security
TopicURL
Apply CSP AOBO and Lighthouse security controlshttps://learn.microsoft.com/en-us/azure/lighthouse/concepts/cloud-solution-provider
Implement recommended security practices for Azure Lighthousehttps://learn.microsoft.com/en-us/azure/lighthouse/concepts/recommended-security-practices
Use tenants, users, and roles with Azure Lighthousehttps://learn.microsoft.com/en-us/azure/lighthouse/concepts/tenants-users-roles
Configure eligible authorizations with Azure Lighthouse and PIMhttps://learn.microsoft.com/en-us/azure/lighthouse/how-to/create-eligible-authorizations
Configuration
TopicURL
Configure policy remediation with managed identities via Lighthousehttps://learn.microsoft.com/en-us/azure/lighthouse/how-to/deploy-policy-remediation
Monitor Azure Lighthouse delegation changes via activity logshttps://learn.microsoft.com/en-us/azure/lighthouse/how-to/monitor-delegation-changes
Onboard customers to Azure Lighthouse with ARMhttps://learn.microsoft.com/en-us/azure/lighthouse/how-to/onboard-customer
Delegate all subscriptions in a management group with policyhttps://learn.microsoft.com/en-us/azure/lighthouse/how-to/onboard-management-group
Deploy Azure Policy across tenants with Lighthousehttps://learn.microsoft.com/en-us/azure/lighthouse/how-to/policy-at-scale
Remove Azure Lighthouse delegations and accesshttps://learn.microsoft.com/en-us/azure/lighthouse/how-to/remove-delegation
Update Azure Lighthouse delegations and role assignmentshttps://learn.microsoft.com/en-us/azure/lighthouse/how-to/update-delegation
Use Azure Lighthouse ARM templates and sampleshttps://learn.microsoft.com/en-us/azure/lighthouse/samples/
Use built-in Azure Policy definitions for Lighthousehttps://learn.microsoft.com/en-us/azure/lighthouse/samples/policy-reference
Integrations & Coding Patterns
TopicURL
Integrate Azure Lighthouse with Azure Arc at scalehttps://learn.microsoft.com/en-us/azure/lighthouse/how-to/manage-hybrid-infrastructure-arc
Manage Microsoft Sentinel workspaces at scale with Lighthousehttps://learn.microsoft.com/en-us/azure/lighthouse/how-to/manage-sentinel-workspaces
Manage Azure Migrate projects across tenants with Lighthousehttps://learn.microsoft.com/en-us/azure/lighthouse/how-to/migration-at-scale
Use Azure Monitor Logs across tenants via Lighthousehttps://learn.microsoft.com/en-us/azure/lighthouse/how-to/monitor-at-scale
Deployment

© MicrosoftDocs, CC-BY-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/azure-lighthouse of MicrosoftDocs/Agent-Skills.

Open the folder on GitHubat commit ba74e8f

Compare with similar skills

Azure Lighthouse next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Lighthouse compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Lighthouse this skillMicrosoftDocs/Agent-Skills775—~1.6kAutomated safety check: PassCC-BY-4.0
Azure Resource Manager Cosmosdb Dotnetmicrosoft/skills3.1k5 repos~2.1kAutomated safety check: PassMIT
Apex Azure Rbacjonathan-vella/apex217—~1.8kAutomated safety check: PassMIT
Writing Bicep Templatesmicrosoft-foundry/foundry-agent-webapp127—~1.2kAutomated safety check: PassMIT
Apex Entra App Registrationjonathan-vella/apex217—~1.3kAutomated safety check: PassMIT
Azure Key VaultKilo-Org/kilo-marketplace1891 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Official

    Azure Resource Manager SDK for Cosmos DB in .NET. An agent skill from microsoft/skills.

    3.1k GitHub starsUsed in 5 repos~2.1k tokens
    Backend & APIsAuto-check passed
  • Apex Azure Rbac

    jonathan-vella/apex

    ANALYSIS SKILL — Find the right Azure RBAC role for an identity with least-privilege access; generate CLI, Bicep, and Terraform code to assign it.

    217 GitHub stars~1.8k tokensUpdated today
    Backend & APIsAuto-check passed
  • Writing Bicep Templates

    microsoft-foundry/foundry-agent-webapp

    Provides Bicep coding standards for Azure infrastructure in this repository.

    127 GitHub stars~1.2k tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed
  • Apex Entra App Registration

    jonathan-vella/apex

    WORKFLOW SKILL — Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

    217 GitHub stars~1.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • Azure Key Vault

    Kilo-Org/kilo-marketplace

    Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation.

    189 GitHub starsUsed in 1 repo~1.9k tokens
    Backend & APIsAuto-check passed
  • Microsoft Foundry

    microsoft/GitHub-Copilot-for-Azure

    Official

    Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end.

    255 GitHub starsUsed in 1 repo~6.7k tokens
    AI & LLM EngineeringAuto-check passed

More from MicrosoftDocs/Agent-Skills

All 149 skills in this repo
  • Azure Personalizer

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure AI Personalizer development including troubleshooting, decision making, security, configuration, and integrations & coding patterns.

    775 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Azure Architecture Advisor

    MicrosoftDocs/Agent-Skills

    Official

    Guides Azure solution design by category, from reference architectures and design patterns to technology choices and migrations, fetching current Microsoft Learn pages over the network.

    775 GitHub stars~15k tokensUpdated yesterday
    Auto-check passed
  • Azure Advisor Guidance

    MicrosoftDocs/Agent-Skills

    Official

    Reference guidance for Azure Advisor work: recommendations, alerts and digests, workbooks, RBAC access and sovereign-cloud limits, fetched from Microsoft Learn.

    775 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Azure AI Vision Reference

    MicrosoftDocs/Agent-Skills

    Official

    Looks up Microsoft Learn guidance for Azure AI Vision: Image Analysis, Read OCR containers, smart-crop thumbnails, background removal and video frame analysis, plus limits and deployment.

    775 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Azure Analysis Services

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Analysis Services development including troubleshooting.

    775 GitHub stars~608 tokensUpdated yesterday
    Auto-check passed
  • Azure Anomaly Detector

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure AI Anomaly Detector development including troubleshooting, best practices, limits & quotas, configuration, and deployment.

    775 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Azure Lighthouse

What does Azure Lighthouse do?

Expert knowledge for Azure Lighthouse development including decision making, security, configuration, integrations & coding patterns, and deployment. Azure Lighthouse is an agent skill from MicrosoftDocs/Agent-Skills, published by the product's own GitHub organization. Expert knowledge for Azure Lighthouse development including decision making, security, configuration, integrations & coding patterns, and deployment.

When should I use Azure Lighthouse?

Azure Lighthouse fits situations like: configuring Lighthouse delegations; AOBO/PIM access; arc/Sentinel integrations; policies/remediation.

How do I install Azure Lighthouse in Claude Code?

Run `npx skills add MicrosoftDocs/Agent-Skills --skill azure-lighthouse -a claude-code`. Or copy the skill folder (skills/azure-lighthouse in MicrosoftDocs/Agent-Skills) into .claude/skills/azure-lighthouse in your project. Claude Code loads it when a task matches its description.

How do I install Azure Lighthouse in Codex?

Run `npx skills add MicrosoftDocs/Agent-Skills --skill azure-lighthouse -a codex`. Or copy the skill folder (skills/azure-lighthouse in MicrosoftDocs/Agent-Skills) into .agents/skills/azure-lighthouse in your project. Codex loads it when a task matches its description.

Can I use Azure Lighthouse in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MicrosoftDocs/Agent-Skills --skill azure-lighthouse -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-lighthouse, .gemini/skills/azure-lighthouse, .github/skills/azure-lighthouse and .opencode/skills/azure-lighthouse in your project.

What does Azure Lighthouse need to run?

SKILL.md names no scripts, command-line tools or credentials: Azure Lighthouse is instructions for the agent only. Compatibility (from SKILL.md): Requires network access. Uses mcp_microsoftdocs:microsoft_docs_fetch or fetch_webpage to retrieve documentation..

Does Azure Lighthouse access the network?

SKILL.md names 2 domains. As links in the text: learn.microsoft.com and github.com. This is read from the text; nothing was executed.

Is Azure Lighthouse safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Lighthouse use?

Azure Lighthouse is published under the CC-BY-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Lighthouse use?

About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Azure Lighthouse?

Skills that share tags, products or a category with Azure Lighthouse: Azure Resource Manager Cosmosdb Dotnet (microsoft/skills, 3.1k stars), Apex Azure Rbac (jonathan-vella/apex, 217 stars), Writing Bicep Templates (microsoft-foundry/foundry-agent-webapp, 127 stars) and Apex Entra App Registration (jonathan-vella/apex, 217 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Lighthouse?

MicrosoftDocs (a GitHub organization, an official publisher) maintains it in MicrosoftDocs/Agent-Skills, which has 775 GitHub stars. The repository holds 149 skills in this directory. The repository was last updated on October 5, 2026.

Source: MicrosoftDocs/Agent-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.