All skills
microsoft avatar

/entra-app-registration

@2a31526 official

Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration. USE FOR: create app registration, register Azure AD app, configure OAuth, set up authentication, add API permissions, generate service principal, MSAL example, console app auth, Entra ID setup, Azure AD authentication. DO NOT USE FOR: Key Vault secrets (use azure-keyvault-expiration-audit), general Azure resource security guidance.

Use this Skill: https://skilld.dev/gh/microsoft/github-copilot-for-azure/entra-app-registration

This session only. Nothing lands on disk.

referencessdkazure-keyvault-py.md

≈284 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Key Vault — Python SDK Quick Reference

Condensed from azure-keyvault-py. Full patterns (async clients, cryptographic operations, certificate management, error handling) in the azure-keyvault-py plugin skill if installed.

Install

pip install azure-keyvault-secrets azure-keyvault-keys azure-keyvault-certificates azure-identity

Quick Start

from azure.identity import DefaultAzureCredential
from azure.keyvault.secrets import SecretClient
client = SecretClient(vault_url="https://<vault>.vault.azure.net/", credential=DefaultAzureCredential())

Best Practices

  • Use DefaultAzureCredential for local development only. In production, use ManagedIdentityCredential — see auth-best-practices.md
  • Use managed identity in Azure-hosted applications
  • Enable soft-delete for recovery (enabled by default)
  • Use RBAC over access policies for fine-grained control
  • Rotate secrets regularly using versioning
  • Use Key Vault references in App Service/Functions config
  • Cache secrets appropriately to reduce API calls
  • Use async clients for high-throughput scenarios

Source: SKILL.md on GitHub

1 alert16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill acts as a comprehensive reference guide for Microsoft Entra ID application registration, token flows, and MSAL SDK implementations. It does not execute dynamic code, perform remote downloads, or contain unsafe credential management patterns.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    14/17 files flagged

Signed by skilld at 2a31526. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 months ago
metadata
{
  "author": "Microsoft",
  "version": "0.0.0-placeholder"
}
  • entra-id
  • azure-ad
  • oauth2
  • msal
  • app-registration
  • authentication
  • service-principal
  • azure-cli
  • microsoft-identity

README badge

README badge for microsoft/github-copilot-for-azure/entra-app-registration

Guides Microsoft Entra ID app registration, OAuth 2.0 configuration, and MSAL integration for authenticating applications against Azure AD. Covers web apps, SPAs, mobile clients, and service-to-service flows, including client secret management, API permission grants, and token validation.

Generated from the current SKILL.md.

Does this skill cover Azure RBAC or role assignments?
No. This skill focuses on app registration and OAuth authentication. For Azure RBAC and role assignments, use the azure-rbac skill.
What authentication libraries does this skill support?
The skill covers MSAL (Microsoft Authentication Library) for .NET/C#, JavaScript/TypeScript, and Python, plus Azure Identity SDKs for multiple languages.
Can I use certificates instead of client secrets?
Yes. The skill recommends certificates over secrets for production environments and covers federated identity credentials as an alternative to both.
Does this skill include code examples?
Yes. The skill provides console app examples, OAuth flow implementations, and references for multiple programming languages including C#, Python, JavaScript, and Java.
Can I manage app registrations with Infrastructure as Code?
Yes. The skill includes a Bicep example for managing Entra app registrations through IaC, recommended for scalable or audit-heavy scenarios.

Generated from the current SKILL.md. These answers refresh after source changes.