Microsoft Entra Agent ID
Give each AI agent its own OAuth 2.0 identity: Blueprints, per-instance Agent Identities, token exchange, OBO, polyglot sidecar
- What
- Give each AI agent its own OAuth 2.0 identity: Blueprints, per-instance Agent Identities, token exchange, OBO, polyglot sidecar
- Cost
- Free
- Needs
- a Microsoft Entra tenant with an Agent Identity Developer, Agent Identity Administrator, or Application Administrator role; PowerShell 7+ with the Microsoft.Graph.Applications module (or Python with azure-identity + requests) — NOT Azure CLI tokens; a dedicated app registration for Graph calls.
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — an identity-provisioning skill for AI agents on Microsoft Entra: create an Agent Identity Blueprint and its mandatory BlueprintPrincipal, then mint per-instance Agent Identities via Microsoft Graph so every agent gets a distinct identity, audit trail, and independently-scoped permission grants. It covers the two-step `fmi_path` runtime token exchange (autonomous and OBO), cross-tenant flows, the Microsoft Entra SDK for AgentID sidecar for polyglot agents (Python, Node, Go, Java), and a troubleshooting matrix for errors like AADSTS82001 and AADSTS700211. By @microsoft, listed here with credit to its creator. Honest caveats: this is admin-grade work — you need one of the Agent Identity Developer, Agent Identity Administrator or Application Administrator Entra roles plus admin consent; Azure CLI tokens are hard-rejected, so credential setup (Federated Identity Credentials in production, client secrets for local dev only) is on you; credentials live on the Blueprint, never on the Agent Identity; and the Graph API shapes evolve, so it leans on Microsoft Learn docs for verification. Skill Harbor never reviews the code, review it yourself before use.
Version:
Install
Prerequisites: a Microsoft Entra tenant with an Agent Identity Developer, Agent Identity Administrator, or Application Administrator role; PowerShell 7+ with the Microsoft.Graph.Applications module (or Python with azure-identity + requests) — NOT Azure CLI tokens; a dedicated app registration for Graph calls. Install "Microsoft Entra Agent ID" for me. It provisions OAuth 2.0-capable identities for AI agents: Blueprints, per-instance Agent Identities, fmi_path token exchange, OBO, and the polyglot SDK sidecar. Repository: https://github.com/microsoft/azure-skills/blob/main/.github/plugins/azure-skills/skills/entra-agent-id/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "microsoft-azure-entra-agent-id". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. set up my dedicated app registration and credential in the vault). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.