basitalisandhu

M365 Governance Skills — Development skill for Claude Code

Development community

Claude Code skills for Microsoft 365 governance: a plugin with five skills for Graph permission preflight, Entra ID posture review, Intune baseline check, Teams and group sprawl and a quarterly access.

How to install M365 Governance Skills

This entry records only its repository, not the path inside it, so there is no exact command to give. Open basitalisandhu/m365-governance-skills and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What M365 Governance Skills does

Claude Code skills for Microsoft 365 governance: a plugin with five skills for Graph permission preflight, Entra ID posture review, Intune baseline check, Teams and group sprawl and a quarterly access review pack. Read-only Graph exports; tested standard-library scripts evaluate the JSON offline.

Alternatives in Development

  • Flavor — PUA 切换味道 — 从 15 种味道中选择,包括阿里/字节/华为/腾讯/Netflix/Musk/Jobs/Microsoft/钉内钉外 19.5k ★
  • Ext Skills — Experimental exploration of skills discovery and distribution through MCP primitives 214 ★
  • Agents To Im — Feishu/Lark group for Claude Code and Codex sessions, vibe coding anytime, anywhere 118 ★

README

Claude Code skills for Microsoft 365 governance

**Microsoft 365 governance skills for Claude Code: Entra ID posture review, Intune baseline check, Graph permission preflight, Teams and group sprawl report, access review pack. Scripts read exported Graph JSON offline.**

m365-governance-skills is a Claude Code plugin marketplace with one plugin, `m365-governance`, holding five skills. Each skill is a fixed procedure plus a tested Python script (standard library only). The skill tells Claude which read-only Microsoft Graph exports to run and which permission each one needs; the script then evaluates the saved JSON on your machine. Results are repeatable, can be checked by someone without tenant access, and are produced without the script ever calling Microsoft Graph.

It is written for administrators who look after Microsoft 365, Entra ID and Intune for a company or for clients, often alongside other duties. It exists because the governance questions repeat in every tenant (who are the Global Admins, is MFA really enforced, which teams have no owner, what is this connector asking for, what goes into this quarter's access review), and agents now connect to Microsoft 365 with broad Graph permissions. Message triage and daily digests are already covered by first-party plugins; this pack is the governance layer underneath: what can touch the tenant, and is the tenant in the state you think it is.

No network access from the scripts, no telemetry. Nothing in this repository changes a tenant: every skill proposes a portal path or a Graph call and runs a change only after you confirm that exact command.

/plugin marketplace add basitalisandhu/m365-governance-skills
/plugin install m365-governance@m365-governance-skills

Quickstart

In a Claude Code session, after installing:

  • "This connector wants Mail.ReadWrite and Sites.FullControl.All to sync one calendar. Preflight it." Claude follows graph-permission-preflight: it writes a needs manifest with you,