airunway-aks-setup
Set up AI Runway on AKS — from bare cluster to running model. Covers cluster verification, controller install, GPU assessment, provider setup, and first…
Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration. USE FOR: create app registration, register Azure AD app, configure OAuth, set up authentication, add API permissions, generate service principal, MSAL example, console app auth, Entra ID
$ npx -y skills add microsoft/azure-skills --skill entra-app-registration --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/entra-app-registrationContext preview
The summary Claude sees to decide when to auto-load this skill.
Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration. USE FOR: create app registration, register Azure AD app, configure OAuth, set up authentication, add API permissions, generate service principal, MSAL example, console app auth, Entra ID
name: entra-app-registration description: "Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration. USE FOR: create app registration, register Azure AD app, configure OAuth, set up authentication, add API permissions, generate service principal, MSAL example, console app auth, Entra ID setup, Azure AD authentication. DO NOT USE FOR: Key Vault secrets (use azure-keyvault-expiration-audit), general Azure resource security guidance." license: MIT metadata: author: Microsoft version: "1.2.1"
Microsoft Entra ID (formerly Azure Active Directory) is Microsoft's cloud-based identity and access management service. App registrations allow applications to authenticate users and access Azure resources securely.
| Concept | Description | |---------|-------------| | **App Registration** | Configuration that allows an app to use Microsoft identity platform | | **Application (Client) ID** | Unique identifier for your application | | **Tenant ID** | Unique identifier for your Azure AD tenant/directory | | **Client Secret** | Password for the application (confidential clients only) | | **Redirect URI** | URL where authentication responses are sent | | **API Permissions** | Access scopes your app requests | | **Service Principal** | Identity created in your tenant when you register an app |
| Type | Use Case | |------|----------| | **Web Application** | Server-side apps, APIs | | **Single Page App (SPA)** | JavaScript/React/Angular apps | | **Mobile/Native App** | Desktop, mobile apps | | **Daemon/Service** | Background services, APIs |
Create an app registration in the Azure portal or using Azure CLI.
**Portal Method:** 1. Navigate to Azure Portal → Microsoft Entra ID → App registrations 2. Click "New registration" 3. Provide name, supported account types, and redirect URI 4. Click "Register"
**CLI Method:** See [references/cli-commands.md](references/cli-commands.md) **IaC Method:** See [references/BICEP-EXAMPLE.bicep](references/BICEP-EXAMPLE.bicep)
It's highly recommended to use the IaC to manage Entra app registration if you already use IaC in your project, need a scalable solution for managing lots of app registrations or need fine-grained audit history of the configuration changes.
Set up authentication settings based on your application type.
Grant your application permission to access Microsoft APIs or your own APIs.
**Common Microsoft Graph Permissions:**
**Details:** See [references/api-permissions.md](references/api-permissions.md)
For confidential client applications (web apps, services), create a client secret, certificate or federated identity credential.
**Client Secret:**
**Certificate:** For production environments, use certificates instead of secrets for enhanced security. Upload certificate via "Certificates & secrets" section.
**Federated Identity Credential:** For dynamically authenticating the confidential client to Entra platform.
Integrate the OAuth flow into your application code.
**See:**
Walk user through their first app registration step-by-step.
**Required Information:**
**Script:** See [references/first-app-registration.md](references/first-app-registration.md)
Create a .NET/Python/Node.js console app that authenticates users.
**Required Information:**
**Example:** See [references/console-app-example.md](references/console-app-example.md)
Set up daemon/service authentication without user interaction.
**Required Information:**
**Implementation:** Use Client Credentials flow (see [references/oauth-flows.md#client-credentials-flow](references/oauth-flows.md#client-credentials-flow))
| Command | Purpose | |---------|---------| | `az ad app create` | Create new app registration | | `az ad app list` | List app registrations | | `az ad app show` | Show app details | | `az ad app permission add` | Add API permission | | `az ad app credential reset` | Generate new client secret | | `az ad sp create` | Create service principal |
**Complete reference:** See [references/cli-commands.md](references/cli-commands.md)
MSAL is the recommended library for integrating Microsoft identity platform.
**Supported Languages:**
**Examples:** See [references/console-app-example.md](references/console-ap
Azure work is not just a code problem. It is a decision problem: which service fits this app, what needs to be validated before deployment, which tools should run, and what guardrails matter.
Repo: microsoft/azure-skills
Set up AI Runway on AKS — from bare cluster to running model. Covers cluster verification, controller install, GPU assessment, provider setup, and first…
Guidance for instrumenting webapps with Azure Application Insights. Provides telemetry patterns, SDK setup, and configuration references. WHEN: how to…
Use for Azure AI: Search, Speech, OpenAI, Document Intelligence. Helps with search, vector/hybrid search, speech-to-text, text-to-speech, transcription, OCR.…
Configure Azure API Management as an AI Gateway for AI models, MCP tools, and agents. WHEN: semantic caching, token limit, content safety, load balancing, AI…
Assess whether source code is ready to deploy to Azure — the check BEFORE infrastructure work. Evaluates build health, app completeness, dependencies and local…
End-to-end orchestrator: from a business idea, app idea, or existing app to running Azure deployment with cost estimates and pre-deploy approval. Analyzes your…