Skip to content
Back to skills

Apex Entra App Registration

ASecurity

**WORKFLOW SKILL** — Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration. WHEN: "create app registration", "register Azure AD app", "configure OAuth", "add API permissions", "generate service principal", "MSAL example", "Entra ID setup". DO NOT USE FOR: Azure RBAC (apex-azure-rbac), Key Vault audits (apex-azure-compliance), resource security scanning (apex-azure-compliance).

  • 216 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
ai-agentsjavascripttypescriptpythonrustjavac#nodeazureapisecurity

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 13 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add jonathan-vella/apex --skill apex-entra-app-registration --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Apex Entra App Registration?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Apex Entra App Registration
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/jonathan-vella-apex-entra-app-registration/badge)](https://www.skillsdirectory.com/skills/jonathan-vella-apex-entra-app-registration)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: apex-entra-app-registration
user-invocable: true
disable-model-invocation: false
argument-hint: "application type and authentication requirements"
description: '**WORKFLOW SKILL** — Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration. WHEN: "create app registration", "register Azure AD app", "configure OAuth", "add API permissions", "generate service principal", "MSAL example", "Entra ID setup". DO NOT USE FOR: Azure RBAC (apex-azure-rbac), Key Vault audits (apex-azure-compliance), resource security scanning (apex-azure-compliance).'
license: MIT
metadata:
  author: Microsoft
  version: "1.0.0"
---

# Entra App Registration

Microsoft Entra ID (formerly Azure AD) is Microsoft's cloud identity and
access-management service. This skill guides app registration, OAuth 2.0
flows, and MSAL integration.

For key concepts, application types, and the 3 common patterns (first-time
registration, console app with user auth, service-to-service), read
[`references/common-patterns.md`](references/common-patterns.md).

## Rules

- **Prefer IaC** for managing app registrations when the project uses IaC, scales to many apps, or needs audit history (see [`references/BICEP-EXAMPLE.bicep`](references/BICEP-EXAMPLE.bicep))
- **Prefer certificates or federated identity credentials over client secrets** in production
- **Protect credential handoff** — follow the
  [additive credential procedure](references/cli-commands.md#client-credentials-secrets--certificates);
  never expose values to chat, tool output or logs
- **Bind identity and approval** — use the
  [identity and permission boundary](references/auth-best-practices.md#identity-and-permission-boundary)
  before authentication, creation, rotation or consent; instructions are not write authorization
- **Grant least-privilege API permissions** — only the scopes the app actually uses
- **CLI for ad-hoc**, **IaC for production** — see [`references/cli-commands.md`](references/cli-commands.md)
- **Out of scope**: Azure RBAC (apex-azure-rbac), Key Vault audits (apex-azure-compliance), resource security scanning (apex-azure-compliance)

## Core Workflow

Five-step procedure (full per-step detail in
[`references/core-workflow.md`](references/core-workflow.md)):

1. **Register the Application** — portal, CLI ([`cli-commands.md`](references/cli-commands.md)), or IaC ([`BICEP-EXAMPLE.bicep`](references/BICEP-EXAMPLE.bicep))
2. **Configure Authentication** — redirect URIs / token settings per app type
3. **Configure API Permissions** — Graph and custom-API scopes ([`api-permissions.md`](references/api-permissions.md))
4. **Create Client Credentials** — secret / certificate / federated identity (Key Vault)
5. **Implement OAuth Flow** — code integration ([`oauth-flows.md`](references/oauth-flows.md), [`console-app-example.md`](references/console-app-example.md))

## Microsoft Authentication Library (MSAL)

Recommended library for integrating with the Microsoft identity platform:

- .NET / C# — `Microsoft.Identity.Client`
- JavaScript / TypeScript — `@azure/msal-browser`, `@azure/msal-node`
- Python — `msal`

Examples: [`references/console-app-example.md`](references/console-app-example.md).
SDK quick references in `references/sdk/`: Azure Identity for Rust and the Functions authentication-events
extension for .NET. Azure Identity for other languages lives in `apex-azure-deploy/references/sdk/`.

## Security Best Practices

Never hardcode secrets · rotate regularly · prefer certificates over secrets in
production · least-privilege API permissions · enable MFA · use managed
identity for Azure-hosted apps · validate tokens (issuer / audience /
expiration) · HTTPS-only redirect URIs (per the canonical
[security baseline](../../instructions/references/iac-security-baseline.md)) ·
monitor sign-ins via Entra ID logs.

Full details in
[`references/auth-best-practices.md`](references/auth-best-practices.md).

## Reference Index

| Reference                              | When to Load                                          |
| -------------------------------------- | ----------------------------------------------------- |
| `references/common-patterns.md`        | Key concepts, app types, 3 common registration patterns |
| `references/core-workflow.md`          | Full per-step procedure for app registration          |
| `references/api-permissions.md`        | Graph and custom-API permission configuration         |
| `references/auth-best-practices.md`    | Detailed security best practices                      |
| `references/cli-commands.md`           | Azure CLI reference for app registrations             |
| `references/console-app-example.md`    | Complete working code examples (multiple languages)   |
| `references/first-app-registration.md` | Step-by-step guide for beginners                      |
| `references/oauth-flows.md`            | Detailed OAuth 2.0 flow explanations                  |
| `references/troubleshooting.md`        | Common issues and solutions                           |
| `references/BICEP-EXAMPLE.bicep`       | Bicep template for IaC-managed app registration       |
| `references/sdk/*.md`                  | Language-specific SDK quick references                |

Files in this skill

  • SKILL.md5.2 KB
  • references/BICEP-EXAMPLE.bicep5.2 KB
  • references/api-permissions.md11 KB
  • references/auth-best-practices.md8.2 KB
  • references/cli-commands.md10.6 KB
  • references/common-patterns.md2.3 KB
  • references/console-app-example.md11.7 KB
  • references/core-workflow.md2.5 KB
  • references/first-app-registration.md8 KB
  • references/oauth-flows.md9.7 KB
  • references/sdk/azure-identity-rust.md808 B
  • references/sdk/microsoft-azure-webjobs-extensions-authentication-events-dotnet.md1.5 KB
  • references/troubleshooting.md8.2 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…