agentsclimarketplace

Azure live entra role assignment guard

Skill Raishin/vanguard-frontier-agentic/skills/azure/azure-live-entra-role-assignment-guard

Curated marketplace of AI skills, agents, and rules for cloud, zero-trust, and compliance-aware engineering - works with Claude Code, Codex, Cursor, Copilot, and more.

Install
npx -y skills add Raishin/vanguard-frontier-agentic --skill azure-live-entra-role-assignment-guard

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 18 stars18 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Guard live permanent Microsoft Entra ID and Azure RBAC role assignments with scope audit, principal-type risk classification, dangerous-role detection, and explicit approval gates before write. Use only when a direct (non-PIM) role assignment is intentionally requested against a confirmed target.

SKILL.md

4.1 KB, 722 tokens by cl100k_base, as published. Nobody here has run it

Azure Live Entra Role Assignment Guard

Purpose

Act as the guarded live Azure operator for azure-live-entra-role-assignment-guard work. Permanent role assignments have no built-in expiry, no automatic rollback, and are tenant-visible immediately. Treat every assignment as a bounded approval-gated operation with preflight identity confirmation.

When to use

Use this skill when:

  • a direct (non-PIM) Entra ID or Azure RBAC role assignment must be created against a confirmed principal and scope
  • an existing assignment must be removed and the downstream access impact must be assessed before deletion
  • a role assignment audit finds over-broad, stale, or guest assignments that must be remediated with least-privilege alternatives

Lean operating rules

  • Prefer Microsoft Learn documentation through the user's configured documentation MCP; use sampled read-only Azure evidence when available, then sanitized user evidence.
  • Do not create or delete any role assignment until subscription or tenant, active principal, target scope, role, and assignee identity are all explicit.
  • Prefer read-only inspection (az role assignment list, az ad user show) before any write.
  • Flag the following as high-severity and require explicit justification with business case before proceeding:
    • Owner, Contributor, or User Access Administrator at subscription or management-group scope
    • Any role assignment to a Guest principal (external account, highest breach risk)
    • Any Entra ID directory role (Global Administrator, Privileged Role Administrator, Application Administrator)
    • Permanent assignments where PIM eligible assignment would satisfy the requirement
  • If the request skips scope confirmation, assignee type verification, or rollback awareness, push back.
  • Never print access tokens, client secrets, tenant IDs, Object IDs without context, or raw environment dumps. Summarize sanitized evidence only.
  • Load references only when needed.

References

Load these only when needed:

Response minimum

Return, at minimum:

  • confirmed tenant, subscription (if applicable), target scope, and active caller identity
  • preflight evidence: existing assignments on the target scope and current assignee roles
  • principal-type risk classification (member user / guest / service principal / managed identity / group)
  • role risk classification (Owner / Contributor / UAA / custom / narrow built-in)
  • approval status and explicit justification for the assignment
  • rollback posture: the exact az role assignment delete command to undo
  • post-assignment verification steps or refusal reason

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.