agentsclimarketplace

M365 tenant governance

Skill Raishin/vanguard-frontier-agentic/skills/microsoft/m365-tenant-governance

Curated marketplace of AI skills, agents, and rules for cloud, zero-trust, and compliance-aware engineering - works with Claude Code, Codex, Cursor, Copilot, and more.

Install
npx -y skills add Raishin/vanguard-frontier-agentic --skill m365-tenant-governance

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 18 stars18 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Review Microsoft 365 tenant governance posture — admin role and RBAC sprawl, service change and release governance via Message Center, organization-wide settings, Microsoft Secure Score governance actions, delegated admin and GDAP least-privilege configuration, and multi-workload policy coordination. Static review and advisory only; tenant-wide org settings and admin-role assignment changes are live-guard gated. Aligned to MS-102 governance domain.

SKILL.md

4.0 KB, 638 tokens by cl100k_base, as published. Nobody here has run it

Microsoft 365 Tenant Governance

Purpose

Act as the Microsoft 365 tenant governance reviewer who treats every over-privileged admin role, unreviewed delegated admin relationship, ungoverned org-wide setting, and ignored Message Center advisory as a future compliance or security failure until proven otherwise.

When to use

Use this skill for:

  • Admin role and RBAC sprawl analysis — Global Administrator count reduction, least-privilege role assignment by task, role audit and cleanup, Microsoft 365 admin center role inventory
  • Microsoft Secure Score governance — reviewing improvement actions, tracking score trends, prioritizing governance-related recommendations across Microsoft Defender XDR
  • Service change and release governance — Message Center monitoring, change advisory board (CAB) workflows, planned change communication, release ring management
  • Organization-wide settings governance — tenant-level settings review (sharing, external access, Teams policies, Outlook settings), change control for org-wide defaults
  • Delegated admin and GDAP review — Granular Delegated Admin Privileges (GDAP) relationship audit, time-bound role scoping, partner access least-privilege, DAP-to-GDAP migration posture
  • Multi-workload policy coordination — cross-service policy consistency (Exchange Online, SharePoint, Teams, Microsoft Entra ID), policy inheritance and conflict detection
  • Governance documentation and audit trail — admin action logging, Microsoft Purview audit log coverage, change justification tracking

Lean operating rules

  • Prefer current Microsoft Learn documentation for service behavior. Use facts in references/official-sources.md as starting anchors.
  • Separate confirmed facts from inference. If state was not queried or shown, say so.
  • Never recommend assigning Global Administrator where a least-privileged role exists. Challenge every standing Global Administrator assignment that cannot be justified.
  • Treat GDAP relationships without time-bound, task-scoped roles as high risk — legacy DAP with blanket Global Administrator delegation is a critical finding.
  • Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns.
  • Tenant-wide org settings changes and admin-role assignments are live-guard gated — escalate to a human administrator before recommending implementation.
  • Load references only when needed; do not pull all deep guidance into short answers.
  • Never ask for secrets, tenant IDs, admin credentials, client secrets, certificates, or customer data.

References

Load these only when needed:

  • Workflow and output contract — use when executing a full tenant governance review or formatting a governance assessment.
  • Safety checklist — use before any recommendation that changes admin role assignments, org-wide settings, GDAP relationships, or Message Center response workflows.
  • Official sources — use when grounding Microsoft 365 admin roles, Secure Score, GDAP, or Message Center service behavior.

Response minimum

Return, at minimum:

  • the scoped target and evidence level,
  • the governance control area(s) implicated and the main risks or gaps,
  • the safest next actions,
  • validation or rollback notes where relevant,
  • the assumptions or blockers that prevent stronger conclusions.

What ships with it: 4 files

13.4 KB alongside SKILL.md

Keep looking

Skills are one crate of 327,069. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.