Maui Authentication
davidortinau/maui-skills
Add authentication to .NET MAUI apps. An agent skill from davidortinau/maui-skills.
Guidance for hardening macOS endpoints managed by Microsoft Intune — automated device enrollment via Apple Business Manager (ABM), platform single sign-on (PSSO) with Entra ID, FileVault disk…
$ npx skills add vinayaklatthe/microsoft-security-skills --skill macos-intune-baseline -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills macos-intune-baseline --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/macos-intune-baseline .claude/skills/macos-intune-baseline && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "macos-intune-baseline" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/macos-intune-baseline into .claude/skills/macos-intune-baseline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "macos-intune-baseline", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/macos-intune-baselineType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill macos-intune-baseline -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills macos-intune-baseline --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/macos-intune-baseline .agents/skills/macos-intune-baseline && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "macos-intune-baseline" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/macos-intune-baseline into .agents/skills/macos-intune-baseline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "macos-intune-baseline", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill macos-intune-baseline -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills macos-intune-baseline --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/macos-intune-baseline .cursor/skills/macos-intune-baseline && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "macos-intune-baseline" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/macos-intune-baseline into .cursor/skills/macos-intune-baseline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "macos-intune-baseline", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/vinayaklatthe/microsoft-security-skills.git --path skills/macos-intune-baseline--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill macos-intune-baseline -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills macos-intune-baseline --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/macos-intune-baseline .gemini/skills/macos-intune-baseline && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "macos-intune-baseline" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/macos-intune-baseline into .gemini/skills/macos-intune-baseline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "macos-intune-baseline", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install vinayaklatthe/microsoft-security-skills macos-intune-baselineInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add vinayaklatthe/microsoft-security-skills --skill macos-intune-baseline -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/macos-intune-baseline .github/skills/macos-intune-baseline && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "macos-intune-baseline" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/macos-intune-baseline into .github/skills/macos-intune-baseline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "macos-intune-baseline", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill macos-intune-baseline -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills macos-intune-baseline --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/macos-intune-baseline .opencode/skills/macos-intune-baseline && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "macos-intune-baseline" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/macos-intune-baseline into .opencode/skills/macos-intune-baseline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "macos-intune-baseline", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
macos-intune-baselineGuidance for hardening macOS endpoints managed by Microsoft Intune — automated device enrollment via Apple Business Manager (ABM), platform single sign-on (PSSO) with Entra ID, FileVault disk…
macOS Intune Baseline is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for hardening macOS endpoints managed by Microsoft Intune — automated device enrollment via Apple Business Manager (ABM), platform single sign-on (PSSO) with Entra ID, FileVault disk encryption escrow, security configuration profiles (Gatekeeper, XProtect, system extensions allowlist, firewall, login window, Privacy Preferences Policy Control / PPPC), Microsoft Defender for Endpoint on macOS, app management (VPP / managed apps / shell scripts via Intune), patching strategy (managed software updates /…
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Authentication and Shell scripting. It works with macOS, Microsoft Defender, Microsoft Entra ID and iOS. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.
9 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
learn.microsoft.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
macOS Intune Baseline loads about 2.4k tokens when it runs. Until then it costs about 252 tokens; SKILL.md has 969 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 969 words, ~2,399 tokens.
.claude/skills/macos-intune-baseline/SKILL.md (or your agent's skills folder).Mac fleets in Microsoft-shop enterprises are usually under-governed compared to Windows. Intune-managed macOS with the right configuration profiles, FileVault escrow, Defender for Endpoint, and Platform SSO with Entra ID closes most of the gap and gives you a Conditional Access compliance signal that actually means something.
Designing or hardening macOS endpoint management in an Intune + Entra ID environment (workforce devices, BYOD via user-enrollment is a separate model).
Do not use this skill for end-to-end Intune (intune-device-mgmt), MDE policy
authoring (defender-for-endpoint), or iOS / iPadOS management.
| Layer | Tool / Profile |
|---|---|
| Provisioning | Apple Business Manager + Intune Automated Device Enrollment |
| Identity / SSO | Platform SSO (Entra ID), Enterprise SSO plug-in |
| Disk encryption | FileVault enabled + escrow recovery key to Intune |
| App control | Gatekeeper, XProtect (Apple-managed), notarized apps allowlist via system extensions |
| Endpoint protection | Microsoft Defender for Endpoint on macOS |
| Configuration | Settings catalog profiles (preferred), legacy templates where required |
| Privacy / kernel | Privacy Preferences Policy Control (PPPC), System Extensions, Notification Center policy |
| Updates | Managed Software Updates / Declarative Device Management (DDM) |
| Compliance | Intune compliance policy → Conditional Access |
Enroll via ABM + Automated Device Enrollment. Manual enrollment is fine for pilots; production needs ABM so devices arrive supervised, can't be unenrolled by the user, and pick up policy at first boot.
Platform SSO (PSSO) with Entra ID is the modern macOS SSO. User signs into the Mac with their Entra credentials (password, smart card, or passkey-style secure enclave). Replaces the older Enterprise SSO plug-in for sign-in scenarios. Requires deployment of the Microsoft Enterprise SSO plug-in package + a PSSO configuration profile.
FileVault profile with escrow to Intune. Keys are recoverable by IT (with audit). Don't deploy FileVault without escrow — locked-out users brick devices.
Defender for Endpoint on macOS via Intune app deployment + onboarding profile. Includes:
mdatp health post-onboarding.Configuration profiles — start with the Microsoft macOS security baseline (or CIS macOS benchmark) and adapt. Critical settings:
App management. Apps via VPP (Apple Volume Purchase Program) for App Store apps; PKG/DMG for non-store apps via Intune; shell scripts for the long tail. Maintain an "approved apps" catalogue.
Patching: Managed Software Updates / DDM. Apple's modern patch model uses Declarative Device Management — deferral windows, target OS versions, force-install deadlines. Replaces the older "deferral days" model. Roll out:
Compliance policy → Conditional Access.
Operate.
Stand up macOS management for a 5,000-device creative workforce: ABM + Intune ADE + PSSO + FileVault escrow + MDE + baseline.Build the system extensions and PPPC allowlist for Defender, our VPN, and our DLP agent.Migrate from the older Enterprise SSO plug-in to Platform SSO with Entra ID password / Smart Card use case.Compliance policy mapping macOS to Conditional Access for M365 and Azure portal.Patching policy with Managed Software Updates / DDM for Sonoma → Sequoia cutover.Compare Microsoft macOS baseline with CIS macOS benchmark and reconcile conflicts.BYOD user-enrollment design vs corporate-owned ADE — capability and trade-off table.MDE on Mac: confirm EDR coverage via PPPC, validate vulnerability assessment pipeline.© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/macos-intune-baseline of vinayaklatthe/microsoft-security-skills.
Open the folder on GitHubat commit 15f16df
macOS Intune Baseline next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| macOS Intune Baseline this skillvinayaklatthe/microsoft-security-skills | 175 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Maui Authenticationdavidortinau/maui-skills | 175 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Web3authWeb3Auth/web3auth-examples | 144 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Stellar iOS Mac SDKSoneso/stellar-ios-mac-sdk | 132 | — | ~4.3k | Automated safety check: Pass | Apache-2.0 | |
| Msal Client CredentialsAzureAD/microsoft-authentication-library-for-dotnet | 1.5k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Azure APIM Policy Authoringthomast1906/github-copilot-agent-skills | 202 | — | ~1.5k | Automated safety check: Pass | MIT |
davidortinau/maui-skills
Add authentication to .NET MAUI apps. An agent skill from davidortinau/maui-skills.
Web3Auth/web3auth-examples
Integrates MetaMask Embedded Wallets (Web3Auth) for non-custodial wallets via social login or custom JWT (Firebase, Auth0, Cognito).
Soneso/stellar-ios-mac-sdk
Guides Stellar blockchain development in Swift using stellar-ios-mac-sdk.
AzureAD/microsoft-authentication-library-for-dotnet
Client Credentials Flow for service-to-service (daemon) authentication in MSAL.NET without user involvement
thomast1906/github-copilot-agent-skills
Generates Azure API Management policy XML for authentication, rate limiting, CORS, error handling and transformations, consulting Azure best-practice and documentation tools first.
microsoft/skills
Microsoft Entra Authentication Events SDK for .NET. An agent skill from microsoft/skills.
vinayaklatthe/microsoft-security-skills
Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…
vinayaklatthe/microsoft-security-skills
Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…
vinayaklatthe/microsoft-security-skills
Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.
vinayaklatthe/microsoft-security-skills
Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.
vinayaklatthe/microsoft-security-skills
Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).
vinayaklatthe/microsoft-security-skills
Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.
Categories
Guidance for hardening macOS endpoints managed by Microsoft Intune — automated device enrollment via Apple Business Manager (ABM), platform single sign-on (PSSO) with Entra ID, FileVault disk…. macOS Intune Baseline is an agent skill from vinayaklatthe/microsoft-security-skills.
macOS Intune Baseline fits situations like: general Intune device management end-to-end (use intune-device-mgmt); MDE config alone (use defender-for-endpoint); IOS device management.
Run `npx skills add vinayaklatthe/microsoft-security-skills --skill macos-intune-baseline -a claude-code`. Or copy the skill folder (skills/macos-intune-baseline in vinayaklatthe/microsoft-security-skills) into .claude/skills/macos-intune-baseline in your project. Claude Code loads it when a task matches its description.
Run `npx skills add vinayaklatthe/microsoft-security-skills --skill macos-intune-baseline -a codex`. Or copy the skill folder (skills/macos-intune-baseline in vinayaklatthe/microsoft-security-skills) into .agents/skills/macos-intune-baseline in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill macos-intune-baseline -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/macos-intune-baseline, .gemini/skills/macos-intune-baseline, .github/skills/macos-intune-baseline and .opencode/skills/macos-intune-baseline in your project.
SKILL.md names no scripts, command-line tools or credentials: macOS Intune Baseline is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
macOS Intune Baseline is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with macOS Intune Baseline: Maui Authentication (davidortinau/maui-skills, 175 stars), Web3auth (Web3Auth/web3auth-examples, 144 stars), Stellar iOS Mac SDK (Soneso/stellar-ios-mac-sdk, 132 stars) and Msal Client Credentials (AzureAD/microsoft-authentication-library-for-dotnet, 1.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.
Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.