Entra User & Group Lifecycle Automation
$2.99OfficialUse when onboarding, transferring, disabling or offboarding Microsoft Entra ID users, their group memberships and their licenses through Microsoft Graph.
cloudentraidentitymicrosoft-graphprovisioningoffboardingrbacautomationยท by SkillingMain
What you get
- โ10-step procedure
- โRunnable Python / JSON included
- โ9-point quality checklist
- โ10 pitfalls to avoid
- โInstalls into 6 tools
- Version
- v1 โ
- Last updated
- today
- Length
- 11 min read
- Requires
- Best with a strong model (claude-opus-4-6)
Works in: Claude Code, Codex, Cline, opencode, OpenClaw, Hermes ยท Built for large codebases
What you'll need to set up
Some setup ยท 20-35 minRegister a single-tenant Entra application, give it a client secret or certificate, grant it the Microsoft Graph application permissions below with tenant-wide admin consent, and assign its service principal the User Administrator directory role so it may act on other users.
AZURE_TENANT_IDAZURE_CLIENT_IDAZURE_CLIENT_SECRETAZURE_CLIENT_CERTIFICATE_PATHGRAPH_BASE_URLENTRA_MANAGED_GROUP_PREFIXPreview
When to use
Invoke this skill for identity lifecycle work in Microsoft Entra ID (formerly Azure AD) driven through Microsoft Graph:
- Joiner โ "onboard Priya as a Solutions Engineer", "create these 40 users from the HR export", "give the new hire the standard EMEA engineering access".
- Mover โ "Marcus moved from Support to Platform, fix his groups", "reassign this team to a new manager", "reconcile memberships against the HRIS role mapping".
- Leaver โ "offboard Dana today", "disable and revoke sessions for a terminated contractor", "reclaim licenses for everyone who left last quarter", "restore the account we deleted on Tuesday".
- Reconcile โ diff the directory agains
โฆ
๐ Buy once ($2.99) to unlock the full playbook, download it, and install it in every tool you use.