entra-app-registration

entra-app-registration is a skill for Claude Code from thangchung/agent-engineering-experiment. It costs 93 tokens per session (1,800 once invoked), scanned A, a copy of entra-app-registration, MIT.

A guide for registering applications with Microsoft Entra ID, Microsoft's service for managing sign-in and access to cloud resources, and connecting them with OAuth 2.0 and MSAL.

In plain words
What is it for?
Use it to create app registrations, configure web, single-page, mobile, or background applications, add API permissions, create service principals, and write MSAL authentication examples.
Why use it?
It explains the settings needed for an app to sign users in and request access to APIs or Azure resources. This helps avoid confusion around client IDs, tenants, redirect URLs, secrets, and permissions.

Skill for Claude Code

Written for Claude Code: installed under .claude/.

Good fit Use it to create app registrations, configure web, single-page, mobile, or background applications, add API permissions, create service principals, and write MSAL authentication examples.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/thangchung/agent-engineering-experiment/entra-app-registration
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add thangchung/agent-engineering-experiment --skill entra-app-registration
Clone the repo
git clone --depth 1 https://github.com/thangchung/agent-engineering-experiment

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for entra-app-registration

README.md
[![agentmods](https://agentmods.dev/badge/skills/thangchung/agent-engineering-experiment/entra-app-registration/github.svg)](https://agentmods.dev/skills/thangchung/agent-engineering-experiment/entra-app-registration)
Your own site
<a href="https://agentmods.dev/skills/thangchung/agent-engineering-experiment/entra-app-registration"><img src="https://agentmods.dev/badge/skills/thangchung/agent-engineering-experiment/entra-app-registration/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for entra-app-registration

Your own site · 80×15
<a href="https://agentmods.dev/skills/thangchung/agent-engineering-experiment/entra-app-registration"><img src="https://agentmods.dev/badge/skills/thangchung/agent-engineering-experiment/entra-app-registration.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 93 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,800 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin 97% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00093 $0.01800
Opus 5 $0.00046 $0.00900
Sonnet 5 $0.00019 $0.00360
Haiku 4.5 $0.00009 $0.00180

Measured 9d ago against content hash d61088b7f410, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-09, from the pricing page.

Security

Grade A, and why

entra-app-registration scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

97% identical to entra-app-registration — 2 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

agentgateway-entraid-obo/.claude/skills/entra-app-registration/SKILL.md · 192 lines

How it starts

The opening of the file, as written. The whole thing — 192 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Overview

Microsoft Entra ID (formerly Azure Active Directory) is Microsoft's cloud-based identity and access management service. App registrations allow applications to authenticate users and access Azure resources securely.

Key Concepts

Concept Description
App Registration Configuration that allows an app to use Microsoft identity platform
Application (Client) ID Unique identifier for your application
Tenant ID Unique identifier for your Azure AD tenant/directory
Client Secret Password for the application (confidential clients only)
Redirect URI URL where authentication responses are sent
API Permissions Access scopes your app requests
Service Principal Identity created in your tenant when you register an app

Application Types

Type Use Case
Web Application Server-side apps, APIs
Single Page App (SPA) JavaScript/React/Angular apps
Mobile/Native App Desktop, mobile apps
Daemon/Service Background services, APIs

Core Workflow

Step 1: Register the Application

Create an app registration in the Azure portal or using Azure CLI.

Portal Method:

  1. Navigate to Azure Portal → Microsoft Entra ID → App registrations
  2. Click "New registration"
  3. Provide name, supported account types, and redirect URI
  4. Click "Register"

CLI Method: See references/cli-commands.md IaC Method: See references/BICEP-EXAMPLE.bicep

It's highly recommended to use the IaC to manage Entra app registration if you already use IaC in your project, need a scalable solution for managing lots of app registrations or need fine-grained audit history of the configuration changes.

Step 2: Configure Authentication

Set up authentication settings based on your application type.

  • Web Apps: Add redirect URIs, enable ID tokens if needed
  • SPAs: Add redirect URIs, enable implicit grant flow if necessary
  • Mobile/Desktop: Use http://localhost or custom URI scheme
  • Services: No redirect URI needed for client credentials flow

Read the full file on GitHub · 192 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 192 lines · 93 tokens per session scan A d61088b7f410

Subscribe to this mod's changes

entra-app-registration is a skill published in the GitHub repository thangchung/agent-engineering-experiment (24 stars, last pushed 1mo ago), licensed MIT. It adds 93 tokens to every session and 1,800 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. It is 97% identical to entra-app-registration, differing in 2 lines, and is treated as a copy.

Related

Other skills, from other repositories

phoenix-cli-development

Design and implementation guide for the Phoenix CLI (px). Covers the noun-verb command structure, dual-audience design (humans and coding agents), Commander.js patterns, configuration resolution, output formats, exit codes, and conventions for adding or modifying commands. Triggers when working on phoenix-cli commands…

Arize-ai/phoenix · 105 tokens

phoenix-graphql

Write efficient GraphQL queries against the Phoenix API. Load this skill in two cases: (1) before composing any non-trivial GraphQL query yourself for data analysis (via the phoenix-gql bash command) — it contains schema entrypoints and patterns that eliminate the need for introspection; (2) when the user asks for…

Arize-ai/phoenix · 102 tokens

phoenix-otel-development

Guide for the phoenix-otel TypeScript package — OTel registration, stack-based global provider management, and provider lifecycle.

Arize-ai/phoenix · 30 tokens

voicelive-realtime

Azure AI VoiceLive SDK (1.2.0, async-only): a guided interview that confirms managed-model vs Foundry-hosted BYOM before writing config, the managed model catalogue, local microphone/speaker prototypes, connect(), RequestSession, turn detection, barge-in, audio formats, voices, interim responses, and tools. Load for…

JinLee794/agent-framework-skills · 101 tokens

maf-voice-agent

Repo layout, fixed MAF-bridge topology, two-resource default with optional alternate VoiceLive overrides, and conformance checklist. Load when scaffolding, placing code/config, or reviewing this Foundry + Azure AI Search voice seed before it ships.

JinLee794/agent-framework-skills · 54 tokens

mem0-oss-to-platform

Plan and then execute a migration of a project from the mem0 open-source / self-hosted SDK (the local Memory class) to the mem0 Platform / hosted / managed SDK (the MemoryClient class). Use this whenever a developer wants to move, switch, or migrate their mem0 usage off OSS/self-hosted to the hosted API — e.g.…

mem0ai/mem0 · 273 tokens