Entra App Registration
microsoft/GitHub-Copilot-for-Azure
Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.
Guidance for designing BitLocker drive encryption for Windows endpoints managed via Microsoft Intune — encryption policy, silent enablement, recovery key escrow to Entra ID, TPM, pre-boot…
$ npx skills add vinayaklatthe/microsoft-security-skills --skill bitlocker-design -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills bitlocker-design --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/bitlocker-design .claude/skills/bitlocker-design && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "bitlocker-design" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/bitlocker-design into .claude/skills/bitlocker-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bitlocker-design", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/bitlocker-designType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill bitlocker-design -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills bitlocker-design --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/bitlocker-design .agents/skills/bitlocker-design && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "bitlocker-design" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/bitlocker-design into .agents/skills/bitlocker-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bitlocker-design", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill bitlocker-design -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills bitlocker-design --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/bitlocker-design .cursor/skills/bitlocker-design && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "bitlocker-design" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/bitlocker-design into .cursor/skills/bitlocker-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bitlocker-design", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/vinayaklatthe/microsoft-security-skills.git --path skills/bitlocker-design--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill bitlocker-design -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills bitlocker-design --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/bitlocker-design .gemini/skills/bitlocker-design && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "bitlocker-design" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/bitlocker-design into .gemini/skills/bitlocker-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bitlocker-design", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install vinayaklatthe/microsoft-security-skills bitlocker-designInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add vinayaklatthe/microsoft-security-skills --skill bitlocker-design -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/bitlocker-design .github/skills/bitlocker-design && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "bitlocker-design" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/bitlocker-design into .github/skills/bitlocker-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bitlocker-design", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill bitlocker-design -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills bitlocker-design --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/bitlocker-design .opencode/skills/bitlocker-design && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "bitlocker-design" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/bitlocker-design into .opencode/skills/bitlocker-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bitlocker-design", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
bitlocker-designGuidance for designing BitLocker drive encryption for Windows endpoints managed via Microsoft Intune — encryption policy, silent enablement, recovery key escrow to Entra ID, TPM, pre-boot…
Bitlocker Design is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for designing BitLocker drive encryption for Windows endpoints managed via Microsoft Intune — encryption policy, silent enablement, recovery key escrow to Entra ID, TPM, pre-boot authentication trade-offs, and BitLocker To Go for removable media. Covers compliance integration with Conditional Access and recovery workflows. WHEN: BitLocker, disk encryption, Windows encryption policy, BitLocker recovery key, silent BitLocker enablement, Intune disk encryption, TPM 2.0, escrow recovery key, encrypt…
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs. It works with Azure Key Vault, Microsoft Azure, Microsoft Entra ID and macOS. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
learn.microsoft.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Bitlocker Design loads about 1.9k tokens when it runs. Until then it costs about 199 tokens; SKILL.md has 815 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 815 words, ~1,901 tokens.
.claude/skills/bitlocker-design/SKILL.md (or your agent's skills folder).BitLocker provides full-volume encryption for Windows devices, protecting data at rest against device loss or theft. In cloud-managed estates it is deployed and monitored through Intune disk encryption endpoint security policies with recovery key escrow to Microsoft Entra ID.
Encrypting Windows endpoints and centrally managing recovery keys and compliance. Use this skill to choose pre-boot mode, configure silent enablement, and plan recovery before rollout.
Do not use this skill for general Intune device baseline (intune-device-mgmt),
macOS FileVault (use Intune disk encryption policy directly), or Azure VM disk
encryption (azure-key-vault).
| Device profile | Pre-boot auth | Encryption | Notes |
|---|---|---|---|
| Modern corporate laptop (TPM 2.0, Secure Boot) | TPM-only (no PIN) | XTS-AES 256 | Default; silent enable |
| High-sensitivity admin / Tier 0 (PAW) | TPM + PIN | XTS-AES 256 | Stronger; pairs with PAW |
| Kiosk / unattended | TPM-only with Network Unlock | XTS-AES 256 | No user to type PIN |
| Legacy device (no TPM 2.0 / no Secure Boot) | Replace device | n/a | Don't try to enable on bare-metal legacy |
| Removable media (USB) | BitLocker To Go (password or smart card) | XTS-AES 256 | Separate policy |
| Fixed data drives | Auto-unlock with OS drive | XTS-AES 256 | Encrypt with OS drive |
Rule of thumb: TPM-only + silent enablement is the right default for 95% of modern corporate laptops. TPM+PIN doubles the security against physical attack but triples support calls. Reserve TPM+PIN for Tier 0 / PAW.
Confirm prerequisites — TPM 2.0 (TPM 1.2 in narrow cases), Secure Boot UEFI, supported
Windows edition (Pro/Enterprise), Entra-joined or hybrid-joined (required for key escrow).
Verify: Get-Tpm shows TpmReady=True; manage-bde -status shows the drive as
encryptable.
Configure Intune disk encryption policy — Endpoint security → Disk encryption → create a BitLocker profile. Set encryption method (XTS-AES 256), encrypt OS drive + fixed drives, pre-boot mode (TPM-only by default).
Silent enablement — Enable silently enable BitLocker on devices and escrow recovery keys to Microsoft Entra ID automatically. User sees no prompt; encryption completes in background. This is the modern default. Verify: pilot device shows BitLocker = On, key escrowed to Entra (visible on device object), no user interaction recorded.
Verify recovery key escrow before broad rollout — Pull a pilot device's recovery key from the Entra device blade. If you can't retrieve it, your policy is wrong - fix before scaling. Un-escrowed keys mean unrecoverable devices. Verify: 100% of pilot ring devices have key visible in Entra; help desk can retrieve.
BitLocker To Go for removable drives — Separate policy: require password (8+ chars) or smart card for removable-drive encryption. Block writes to unencrypted removable drives via Defender for Endpoint device control if data sensitivity warrants.
Feed compliance and Conditional Access — Add BitLocker / encryption to the Intune compliance policy. CA grant control "Require compliant device" then gates corporate apps on encryption status. Verify: an unencrypted device is reported non-compliant within the compliance grace period; blocked by CA.
Monitor + recovery operations — Encryption report daily; alert on devices stuck at encrypting > 7 days. Document the help-desk recovery flow: user reads recovery key ID from boot screen → help desk looks up in Entra → reads back the key.
Design a BitLocker policy with silent enablement via Intune and Entra escrow.Set up TPM+PIN pre-boot authentication for our PAW devices.Verify recovery key escrow on a pilot ring before broad rollout.Configure BitLocker To Go for removable USB drives with password protection.Add disk encryption to Intune compliance policy and gate Conditional Access.Plan and document the help-desk recovery key workflow.© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/bitlocker-design of vinayaklatthe/microsoft-security-skills.
Open the folder on GitHubat commit 15f16df
Bitlocker Design next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Bitlocker Design this skillvinayaklatthe/microsoft-security-skills | 175 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Entra App Registrationmicrosoft/GitHub-Copilot-for-Azure | 255 | 2 repos | ~2.1k | Automated safety check: Pass | MIT | |
| Azure Key VaultKilo-Org/kilo-marketplace | 190 | 1 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Releasing Blancbnfy/blanc | 114 | — | ~2.9k | Automated safety check: Notes | MIT | |
| Azure Key VaultMicrosoftDocs/Agent-Skills | 777 | — | ~4.9k | Automated safety check: Pass | CC-BY-4.0 | |
| Agent Notifications777genius/agent-notifications | 816 | — | ~1.8k | Automated safety check: Pass | Custom licence |
microsoft/GitHub-Copilot-for-Azure
Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.
Kilo-Org/kilo-marketplace
Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation.
bnfy/blanc
Full runbook for cutting a Blanc desktop release — scripts/release.sh mechanics and its required BLANCRELEASE env vars, macOS notarization via 1Password, the Touch ID provisioning profile and…
MicrosoftDocs/Agent-Skills
Expert knowledge for Azure Key Vault development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations &…
777genius/agent-notifications
Send an Agent Notifications desktop notification when the user requests one, attention is needed, or a meaningful milestone warrants an alert during ongoing work.
dallison/subspace
Build and test Subspace across supported platforms and build systems.
vinayaklatthe/microsoft-security-skills
Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…
vinayaklatthe/microsoft-security-skills
Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…
vinayaklatthe/microsoft-security-skills
Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.
vinayaklatthe/microsoft-security-skills
Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.
vinayaklatthe/microsoft-security-skills
Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).
vinayaklatthe/microsoft-security-skills
Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.
Categories
Guidance for designing BitLocker drive encryption for Windows endpoints managed via Microsoft Intune — encryption policy, silent enablement, recovery key escrow to Entra ID, TPM, pre-boot…. Bitlocker Design is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for designing BitLocker drive encryption for Windows endpoints managed via Microsoft Intune — encryption policy, silent enablement, recovery key escrow to Entra ID, TPM, pre-boot authentication trade-offs, and BitLocker To Go for removable media.
Bitlocker Design fits situations like: general Intune device management (use intune-device-mgmt); linux/macOS encryption (use intune-device-mgmt FileVault); azure disk encryption (use azure-key-vault).
Run `npx skills add vinayaklatthe/microsoft-security-skills --skill bitlocker-design -a claude-code`. Or copy the skill folder (skills/bitlocker-design in vinayaklatthe/microsoft-security-skills) into .claude/skills/bitlocker-design in your project. Claude Code loads it when a task matches its description.
Run `npx skills add vinayaklatthe/microsoft-security-skills --skill bitlocker-design -a codex`. Or copy the skill folder (skills/bitlocker-design in vinayaklatthe/microsoft-security-skills) into .agents/skills/bitlocker-design in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill bitlocker-design -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bitlocker-design, .gemini/skills/bitlocker-design, .github/skills/bitlocker-design and .opencode/skills/bitlocker-design in your project.
SKILL.md names no scripts, command-line tools or credentials: Bitlocker Design is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Bitlocker Design is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Bitlocker Design: Entra App Registration (microsoft/GitHub-Copilot-for-Azure, 255 stars), Azure Key Vault (Kilo-Org/kilo-marketplace, 190 stars), Releasing Blanc (bnfy/blanc, 114 stars) and Azure Key Vault (MicrosoftDocs/Agent-Skills, 777 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.
Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.