Msal Client Credentials
AzureAD/microsoft-authentication-library-for-dotnet
Client Credentials Flow for service-to-service (daemon) authentication in MSAL.NET without user involvement
Guidance for Windows Hello for Business (WHfB) — passwordless, phishing-resistant authentication using a PIN or biometric backed by an asymmetric key or certificate.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill windows-hello -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills windows-hello --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/windows-hello .claude/skills/windows-hello && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "windows-hello" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/windows-hello into .claude/skills/windows-hello/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "windows-hello", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/windows-helloType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill windows-hello -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills windows-hello --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/windows-hello .agents/skills/windows-hello && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "windows-hello" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/windows-hello into .agents/skills/windows-hello/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "windows-hello", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill windows-hello -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills windows-hello --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/windows-hello .cursor/skills/windows-hello && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "windows-hello" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/windows-hello into .cursor/skills/windows-hello/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "windows-hello", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/vinayaklatthe/microsoft-security-skills.git --path skills/windows-hello--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill windows-hello -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills windows-hello --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/windows-hello .gemini/skills/windows-hello && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "windows-hello" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/windows-hello into .gemini/skills/windows-hello/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "windows-hello", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install vinayaklatthe/microsoft-security-skills windows-helloInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add vinayaklatthe/microsoft-security-skills --skill windows-hello -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/windows-hello .github/skills/windows-hello && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "windows-hello" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/windows-hello into .github/skills/windows-hello/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "windows-hello", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill windows-hello -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills windows-hello --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/windows-hello .opencode/skills/windows-hello && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "windows-hello" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/windows-hello into .opencode/skills/windows-hello/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "windows-hello", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
windows-helloGuidance for Windows Hello for Business (WHfB) — passwordless, phishing-resistant authentication using a PIN or biometric backed by an asymmetric key or certificate.
Windows Hello is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Windows Hello for Business (WHfB) — passwordless, phishing-resistant authentication using a PIN or biometric backed by an asymmetric key or certificate. Covers trust model selection (cloud Kerberos trust default for hybrid; key trust legacy; certificate trust niche), prerequisites (Entra join, MFA registration, Entra Kerberos for cloud Kerberos trust), Intune-based provisioning, multi-factor unlock, and Conditional Access authentication strengths. WHEN: Windows Hello for Business, WHfB, passwordless…
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Authentication. It works with Microsoft Entra ID. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
learn.microsoft.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Windows Hello loads about 2k tokens when it runs. Until then it costs about 218 tokens; SKILL.md has 859 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 859 words, ~2,028 tokens.
.claude/skills/windows-hello/SKILL.md (or your agent's skills folder).Windows Hello for Business (WHfB) replaces passwords on Windows with a phishing-resistant 2-factor credential: a PIN or biometric (something you know/are) that unlocks a per-device asymmetric key (something you have, bound to TPM). The credential never leaves the device and is not replayable.
Eliminating password sign-in on Windows endpoints and meeting phishing-resistant MFA requirements for users on Windows. Use this skill to choose the trust model, satisfy prerequisites, and roll out provisioning.
Do not use this skill for FIDO2 keys on shared devices (entra-id), CA policy
(conditional-access-mfa), or device compliance (intune-device-mgmt).
WHfB has three trust models. The choice depends on whether on-prem AD SSO is needed and the state of the AD environment.
| Scenario | Trust model | Why |
|---|---|---|
| Cloud-only (Entra-joined, no on-prem AD) | Cloud-only (default) | No on-prem trust needed |
| Hybrid (Entra-joined / hybrid-joined, AD SSO needed) | Cloud Kerberos trust (recommended) | Simplest hybrid model; requires Entra Kerberos server objects |
| Hybrid, can't deploy Entra Kerberos | Key trust | Legacy; needs Windows Server 2016+ DCs + cert on each DC |
| Hybrid with strict cert-based environment | Certificate trust | Requires AD CS + NDES + Intune cert connector; most complex |
Rule of thumb: cloud Kerberos trust is the default for hybrid in 2026 unless there is a specific blocker (no Entra Connect Sync, regulated environment forbidding new auth models). Don't deploy key trust or certificate trust on new tenants - both are legacy.
Verify prerequisites — Devices: Windows 10 1903+ / Windows 11; TPM 2.0 (TPM 1.2 in
limited cases). Users: Entra-joined or hybrid-joined; MFA registered; supported license.
For cloud Kerberos trust: deploy Entra Kerberos server objects in AD (Set-AzureADKerberosServer).
Verify: dsregcmd /status shows AzureAdJoined = YES; Get-AzureADKerberosServer returns
one object per AD forest.
Provision via Intune — Use Intune Account Protection policy (preferred) or the legacy WHfB Identity Protection profile. Set tenant-wide WHfB off, then target-on via Intune profile for the pilot ring; don't enable tenant-wide WHfB on day one. Verify: pilot device shows the WHfB provisioning experience at first sign-in; PIN complexity matches policy.
PIN complexity and biometric policy — Minimum 6 digits (6-8 typical); allow biometric (Windows Hello face / fingerprint) on supported hardware. Don't require special characters in PIN - it's not a password, it's a local unlock.
Disable convenience PIN — Some legacy estates have "convenience PIN" enabled (a PIN for password fill, not WHfB). Disable it explicitly; otherwise users may end up with the wrong credential type and think they're using WHfB.
Conditional Access - authentication strength — Create a CA policy that requires phishing-resistant MFA authentication strength for sensitive apps. WHfB satisfies it; password+SMS does not. Combine with PIM and PAW for Tier 0. Verify: CA What If on a sensitive app with a password-only sign-in = blocked.
Multi-factor unlock for shared / kiosk — On devices accessed by multiple users (lab, shared kiosk), configure multi-factor unlock (PIN + biometric, or PIN + trusted signal).
Plan credential recovery (PIN reset) and shared-device scenarios — Configure Microsoft PIN reset service so users self-recover without help desk; alternative is destructive reset (re-provision WHfB credential from scratch). Plan and communicate before rollout. Verify: PIN reset tested end-to-end by pilot user.
Choose between cloud Kerberos trust and key trust for our hybrid deployment.Roll out Windows Hello for Business via Intune to a 50-device pilot ring.Configure phishing-resistant MFA authentication strength in Conditional Access for SharePoint admin.Set up the PIN reset service so users can self-recover.Why do my hybrid users still get prompted for password after WHfB enrollment?Plan multi-factor unlock on shared lab devices.© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/windows-hello of vinayaklatthe/microsoft-security-skills.
Open the folder on GitHubat commit 15f16df
Windows Hello next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Windows Hello this skillvinayaklatthe/microsoft-security-skills | 175 | — | ~2k | Automated safety check: Pass | MIT | |
| Msal Client CredentialsAzureAD/microsoft-authentication-library-for-dotnet | 1.5k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Azure APIM Policy Authoringthomast1906/github-copilot-agent-skills | 202 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Maui Authenticationdavidortinau/maui-skills | 175 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Microsoft Azure Webjobs Extensions Authentication Events Dotnetmicrosoft/skills | 3.1k | 5 repos | ~3.8k | Automated safety check: Pass | MIT | |
| Authentication TracingSCStelz/security-investigator | 249 | — | ~8.6k | Automated safety check: Pass | MIT |
AzureAD/microsoft-authentication-library-for-dotnet
Client Credentials Flow for service-to-service (daemon) authentication in MSAL.NET without user involvement
thomast1906/github-copilot-agent-skills
Generates Azure API Management policy XML for authentication, rate limiting, CORS, error handling and transformations, consulting Azure best-practice and documentation tools first.
davidortinau/maui-skills
Add authentication to .NET MAUI apps. An agent skill from davidortinau/maui-skills.
microsoft/skills
Microsoft Entra Authentication Events SDK for .NET. An agent skill from microsoft/skills.
SCStelz/security-investigator
A skill your agent uses when asked to trace authentication flows, analyze SessionId chains, investigate token reuse vs interactive MFA, or assess geographic anomalies in sign-ins.
mukul975/Anthropic-Cybersecurity-Skills
Configures SAML 2.0 single sign-on for Google Workspace against a third-party identity provider (Okta, Azure AD/Entra ID, ADFS), with Workspace as the Service Provider, to centralize authentication…
vinayaklatthe/microsoft-security-skills
Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…
vinayaklatthe/microsoft-security-skills
Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…
vinayaklatthe/microsoft-security-skills
Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.
vinayaklatthe/microsoft-security-skills
Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.
vinayaklatthe/microsoft-security-skills
Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).
vinayaklatthe/microsoft-security-skills
Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.
Works with
Categories
Guidance for Windows Hello for Business (WHfB) — passwordless, phishing-resistant authentication using a PIN or biometric backed by an asymmetric key or certificate. Windows Hello is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Windows Hello for Business (WHfB) — passwordless, phishing-resistant authentication using a PIN or biometric backed by an asymmetric key or certificate.
Windows Hello fits situations like: FIDO2 security keys (use entra-id); CA policy authoring (use conditional-access-mfa); intune compliance baseline (use intune-device-mgmt).
Run `npx skills add vinayaklatthe/microsoft-security-skills --skill windows-hello -a claude-code`. Or copy the skill folder (skills/windows-hello in vinayaklatthe/microsoft-security-skills) into .claude/skills/windows-hello in your project. Claude Code loads it when a task matches its description.
Run `npx skills add vinayaklatthe/microsoft-security-skills --skill windows-hello -a codex`. Or copy the skill folder (skills/windows-hello in vinayaklatthe/microsoft-security-skills) into .agents/skills/windows-hello in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill windows-hello -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/windows-hello, .gemini/skills/windows-hello, .github/skills/windows-hello and .opencode/skills/windows-hello in your project.
SKILL.md names no scripts, command-line tools or credentials: Windows Hello is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Windows Hello is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Windows Hello: Msal Client Credentials (AzureAD/microsoft-authentication-library-for-dotnet, 1.5k stars), Azure APIM Policy Authoring (thomast1906/github-copilot-agent-skills, 202 stars), Maui Authentication (davidortinau/maui-skills, 175 stars) and Microsoft Azure Webjobs Extensions Authentication Events Dotnet (microsoft/skills, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.
Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.