Agent skill

Implementing Azure Ad Privileged Identity Management

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Configure Microsoft Entra Privileged Identity Management (PIM) to convert standing privileged assignments into eligible, time-bound roles requiring justification, MFA, and approval, covering Entra…

Apache-2.0Auto-check passedSecurity

Install Implementing Azure Ad Privileged Identity Management

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-azure-ad-privileged-identity-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-azure-ad-privileged-identity-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-azure-ad-privileged-identity-management .claude/skills/implementing-azure-ad-privileged-identity-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-azure-ad-privileged-identity-management
GitHub stars
34k
Token cost
~2.6k tokens
SKILL.md length
712 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configure Microsoft Entra Privileged Identity Management (PIM) to convert standing privileged assignments into eligible, time-bound roles requiring justification, MFA, and approval, covering Entra…

  • Works in 5 steps: Plan Role Assignments → Configure Role Settings → Configure via Microsoft Graph API → …
  • Role-assignment audits
  • SKILL.md covers Overview, When to Use, Prerequisites and Core Concepts, plus 3 more sections
  • Runs Python scripts from its folder; reaches graph.microsoft.com and login.microsoftonline.com

What it does

Implementing Azure Ad Privileged Identity Management is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Configure Microsoft Entra Privileged Identity Management (PIM) to convert standing privileged assignments into eligible, time-bound roles requiring justification, MFA, and approval, covering Entra roles, Azure resource roles, and PIM for Groups, plus access reviews. Use for role-assignment audits, just-in-time admin activation, or Zero Trust identity governance in Entra/Azure AD.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security, covering Access reviews and audit trails. It works with Microsoft Entra ID and Microsoft Azure. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Role-assignment audits
  • Just-in-time admin activation
  • Zero Trust identity governance in Entra/Azure AD

Example prompts

  • “/implementing-azure-ad-privileged-identity-management”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Plan Role Assignments
  2. Configure Role Settings
  3. Configure via Microsoft Graph API
  4. Configure Access Reviews
  5. Configure Alerts

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • graph.microsoft.com
    • login.microsoftonline.com

    Also links to:

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Azure Ad Privileged Identity Management loads about 2.6k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 109 tokens; SKILL.md has 712 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~109
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 712 words, ~2,627 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-azure-ad-privileged-identity-management/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
implementing-azure-ad-privileged-identity-management
description
Configure Microsoft Entra Privileged Identity Management (PIM) to convert standing privileged assignments into eligible, time-bound roles requiring justification, MFA, and approval, covering Entra roles, Azure resource roles, and PIM for Groups, plus access reviews. Use for role-assignment audits, just-in-time admin activation, or Zero Trust identity governance in Entra/Azure AD.
domain
cybersecurity
subdomain
identity-access-management
tags
azure-ad, pim, entra-id, just-in-time, privileged-roles, identity-governance, zero-trust
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.AA-01, PR.AA-02, PR.AA-05, PR.AA-06
mitre_attack
T1078, T1110, T1556, T1098
mitre_f3.version
1.1
mitre_f3.tactics
initial-access, positioning, defense-impairment

Implementing Azure AD Privileged Identity Management

Overview

Microsoft Entra Privileged Identity Management (PIM) provides time-based and approval-based role activation to mitigate risks from excessive, unnecessary, or misused access to critical resources. PIM replaces permanent (standing) privilege assignments with eligible assignments that require users to explicitly activate their role before use, with configurable duration, MFA enforcement, approval workflows, and justification requirements. This is a core component of Zero Trust identity governance in Microsoft environments.

When to Use

  • When deploying or configuring implementing azure ad privileged identity management capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Microsoft Entra ID P2 or Microsoft Entra ID Governance license
  • Global Administrator or Privileged Role Administrator role
  • Azure subscription for Azure resource role management
  • MFA configured for all privileged users
  • Microsoft Authenticator or FIDO2 key for admin accounts

Core Concepts

Assignment Types
TypeBehaviorUse Case
EligibleUser must activate the role before use; expires after configured durationDay-to-day admin work
ActiveRole is always active; no activation neededService accounts, break-glass accounts
Time-BoundEither type with explicit start/end datesTemporary project access, contractor access
PIM Activation Flow
User with Eligible Assignment
        │
        ├── Opens PIM portal → My Roles
        │
        ├── Clicks "Activate" on the desired role
        │
        ├── Provides justification and optional ticket number
        │
        ├── Completes MFA challenge (if required)
        │
        ├── [If approval required] → Notification sent to approvers
        │       │
        │       ├── Approver reviews and approves/denies
        │       └── User notified of decision
        │
        ├── Role activated for configured duration (e.g., 8 hours)
        │
        └── Role automatically deactivated when duration expires
Supported Resource Types
  1. Microsoft Entra Roles: Global Admin, Exchange Admin, Security Admin, etc.
  2. Azure Resource Roles: Owner, Contributor, User Access Administrator on subscriptions/resource groups
  3. PIM for Groups: Manage membership in privileged security groups

Workflow

Step 1: Plan Role Assignments

Audit current permanent role assignments and determine which should be converted to eligible:

Current RolePermanent HoldersAction
Global Administrator2-3 adminsConvert to eligible, keep 1 break-glass active
Exchange AdministratorIT teamConvert all to eligible
Security AdministratorSOC teamConvert to eligible
User AdministratorHelp deskConvert to eligible
Application AdministratorDevOpsConvert to eligible

Best practice: Maintain no more than 2 permanent Global Administrators (break-glass accounts).

Step 2: Configure Role Settings

For each Entra directory role, configure PIM settings:

Via Microsoft Entra Admin Center:

  1. Navigate to Identity Governance > Privileged Identity Management > Microsoft Entra roles
  2. Select "Settings" and choose the role to configure
  3. Configure the following:

Activation Settings:

  • Maximum activation duration: 8 hours (recommended; max 72 hours)
  • Require MFA on activation: Enabled
  • Require justification: Enabled
  • Require ticket information: Enabled (for change management integration)
  • Require approval: Enabled for Global Admin, Security Admin

Assignment Settings:

  • Allow permanent eligible assignment: No (set expiry)
  • Expire eligible assignments after: 6 months (requires re-certification)
  • Allow permanent active assignment: Only for break-glass accounts
  • Require MFA on active assignment: Enabled
  • Require justification on active assignment: Enabled

Notification Settings:

  • Send email when members are assigned eligible: Role assigners, admins
  • Send email when members activate: Admins, security team
  • Send email when eligible members activate roles: Role assignees
Show full SKILL.md (254 more words)Show less
Step 3: Configure via Microsoft Graph API
python
import requests

# Acquire token for Microsoft Graph
def get_graph_token(tenant_id, client_id, client_secret):
    url = f"https://login.microsoftonline.com/{tenant_id}/oauth2/v2.0/token"
    data = {
        "grant_type": "client_credentials",
        "client_id": client_id,
        "client_secret": client_secret,
        "scope": "https://graph.microsoft.com/.default"
    }
    response = requests.post(url, data=data)
    return response.json()["access_token"]

# Create eligible role assignment
def create_eligible_assignment(token, role_definition_id, principal_id,
                                directory_scope="/", duration_hours=8):
    url = "https://graph.microsoft.com/v1.0/roleManagement/directory/roleEligibilityScheduleRequests"
    headers = {
        "Authorization": f"Bearer {token}",
        "Content-Type": "application/json"
    }
    body = {
        "action": "adminAssign",
        "justification": "PIM eligible assignment",
        "roleDefinitionId": role_definition_id,
        "directoryScopeId": directory_scope,
        "principalId": principal_id,
        "scheduleInfo": {
            "startDateTime": "2025-01-01T00:00:00Z",
            "expiration": {
                "type": "afterDuration",
                "duration": "P180D"  # 180-day eligible window
            }
        }
    }
    response = requests.post(url, headers=headers, json=body)
    return response.json()

# Activate a role (user self-service)
def activate_role(token, role_definition_id, principal_id, justification,
                   duration_hours=8):
    url = "https://graph.microsoft.com/v1.0/roleManagement/directory/roleAssignmentScheduleRequests"
    headers = {
        "Authorization": f"Bearer {token}",
        "Content-Type": "application/json"
    }
    body = {
        "action": "selfActivate",
        "principalId": principal_id,
        "roleDefinitionId": role_definition_id,
        "directoryScopeId": "/",
        "justification": justification,
        "scheduleInfo": {
            "startDateTime": None,  # Now
            "expiration": {
                "type": "afterDuration",
                "duration": f"PT{duration_hours}H"
            }
        }
    }
    response = requests.post(url, headers=headers, json=body)
    return response.json()
Step 4: Configure Access Reviews

Set up recurring access reviews to verify eligible assignments remain appropriate:

  1. Navigate to Identity Governance > Access Reviews > New Access Review
  2. Configure:
    • Review scope: Privileged Identity Management role assignments
    • Roles: Select all critical roles (Global Admin, Security Admin, etc.)
    • Reviewers: Managers or self-review with justification
    • Frequency: Quarterly for critical roles, semi-annually for others
    • Auto-apply results: Remove access for non-responsive reviews
    • Duration: 14 days for reviewers to respond
Step 5: Configure Alerts

Enable PIM security alerts:

AlertTriggerAction
Too many global admins> 5 Global AdminsReview and reduce
Roles being assigned outside PIMDirect role assignmentInvestigate and convert to PIM
Roles not requiring MFAActivation without MFAEnable MFA requirement
Stale eligible assignmentsNot activated in 90 daysReview and potentially remove
Potential stale service accountsActive assignments not usedInvestigate and decommission

Validation Checklist

  • All permanent privileged role assignments converted to eligible (except break-glass)
  • Break-glass accounts configured as active with monitoring alerts
  • MFA required for all role activations
  • Approval workflow configured for Global Administrator and Security Administrator
  • Maximum activation duration set to 8 hours or less for critical roles
  • Eligible assignments expire after 6 months (requires re-certification)
  • Justification and ticket information required for activations
  • Email notifications configured for role assignments and activations
  • Access reviews scheduled quarterly for all privileged roles
  • PIM alerts enabled and reviewed weekly
  • Audit logs forwarded to SIEM for monitoring

References

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/implementing-azure-ad-privileged-identity-management of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Azure Ad Privileged Identity Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Azure Ad Privileged Identity Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Azure Ad Privileged Identity Management this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.6kAutomated safety check: PassApache-2.0
Azure Pimvinayaklatthe/microsoft-security-skills175—~1.9kAutomated safety check: PassMIT
Entra Id Governancevinayaklatthe/microsoft-security-skills175—~2kAutomated safety check: PassMIT
Entra Idvinayaklatthe/microsoft-security-skills175—~2.3kAutomated safety check: PassMIT
Attacking Entra Idtrilwu/secskills157—~4.3kAutomated safety check: PassMIT
Pki Designvinayaklatthe/microsoft-security-skills175—~2.1kAutomated safety check: PassMIT

Similar skills

  • Azure Pim

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Entra Privileged Identity Management (PIM) — just-in-time, time-bound, approval-based, audited elevation for Entra roles, Azure resource roles, and privileged groups.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Entra Id Governance

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Entra ID Governance — automating identity lifecycle and access with entitlement management (access packages), access reviews, lifecycle workflows for joiner-mover-leaver…

    175 GitHub stars~2k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Entra Id

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Entra ID (formerly Azure AD) — cloud identity and access management and the control plane for Zero Trust.

    175 GitHub stars~2.3k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Attacking Entra Id

    trilwu/secskills

    Attack and enumerate Azure AD / Entra ID tenants — initial recon with AADInternals and ROADtools, password spraying, token theft (PRT, CAE, refresh tokens), application and service principal abuse…

    157 GitHub stars~4.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Pki Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing public key infrastructure (PKI) and certificate management on Azure and hybrid environments.

    175 GitHub stars~2.1k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Azure Key Vault

    Kilo-Org/kilo-marketplace

    Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation.

    190 GitHub starsUsed in 1 repo~1.9k tokens
    Backend & APIsAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Implementing Azure Ad Privileged Identity Management

What does Implementing Azure Ad Privileged Identity Management do?

Configure Microsoft Entra Privileged Identity Management (PIM) to convert standing privileged assignments into eligible, time-bound roles requiring justification, MFA, and approval, covering Entra…. Implementing Azure Ad Privileged Identity Management is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Configure Microsoft Entra Privileged Identity Management (PIM) to convert standing privileged assignments into eligible, time-bound roles requiring justification, MFA, and approval, covering Entra roles, Azure resource roles, and PIM for Groups, plus access reviews.

When should I use Implementing Azure Ad Privileged Identity Management?

Implementing Azure Ad Privileged Identity Management fits situations like: role-assignment audits; just-in-time admin activation; zero Trust identity governance in Entra/Azure AD.

How do I install Implementing Azure Ad Privileged Identity Management in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-azure-ad-privileged-identity-management -a claude-code`. Or copy the skill folder (skills/implementing-azure-ad-privileged-identity-management in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-azure-ad-privileged-identity-management in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Azure Ad Privileged Identity Management in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-azure-ad-privileged-identity-management -a codex`. Or copy the skill folder (skills/implementing-azure-ad-privileged-identity-management in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-azure-ad-privileged-identity-management in your project. Codex loads it when a task matches its description.

Can I use Implementing Azure Ad Privileged Identity Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-azure-ad-privileged-identity-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-azure-ad-privileged-identity-management, .gemini/skills/implementing-azure-ad-privileged-identity-management, .github/skills/implementing-azure-ad-privileged-identity-management and .opencode/skills/implementing-azure-ad-privileged-identity-management in your project.

What does Implementing Azure Ad Privileged Identity Management need to run?

Going by SKILL.md and its folder, Implementing Azure Ad Privileged Identity Management needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Implementing Azure Ad Privileged Identity Management access the network?

SKILL.md names 3 domains. In commands or code: graph.microsoft.com and login.microsoftonline.com; the agent is likely to contact these when it follows the instructions. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Implementing Azure Ad Privileged Identity Management safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Azure Ad Privileged Identity Management use?

Implementing Azure Ad Privileged Identity Management is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Azure Ad Privileged Identity Management use?

About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Implementing Azure Ad Privileged Identity Management?

Skills that share tags, products or a category with Implementing Azure Ad Privileged Identity Management: Azure Pim (vinayaklatthe/microsoft-security-skills, 175 stars), Entra Id Governance (vinayaklatthe/microsoft-security-skills, 175 stars), Entra Id (vinayaklatthe/microsoft-security-skills, 175 stars) and Attacking Entra Id (trilwu/secskills, 157 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Azure Ad Privileged Identity Management?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.