m365-governance
v0.3.0Microsoft 365 governance skills for Claude Code: Graph permission preflight for apps and connectors, Entra ID posture review, Conditional Access gap analysis, privileged access review, guest and external sharing review, licence and service plan audit, Intune baseline check, Teams and group sprawl report, a quarterly access review pack, and a Copilot oversharing readiness score with fixes by site owner. Scripts are standard-library Python and evaluate exported Microsoft Graph JSON offline.
By Muhammad Basit AliLicense: MIT1 GitHub starsUpdated 3 days ago
Directory evidence
- Runtimes
- Claude Code
- Parsed components
- 10 skill or MCP entries
- Source updated
- Oct 4, 2026
- Manifest status
- Canonical path parsed
The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →
Install m365-governance for Claude Code
claude plugin marketplace add IchenDEV/agent-plugin-mkt
claude plugin marketplace update agent-plugin-marketplace
claude plugin install m365-governance@agent-plugin-marketplacePaste and run these commands in a terminal with Claude Code. They add and refresh the PluginsMP catalog, then install this plugin.
The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.
Get the source manually
git clone https://github.com/basitalisandhu/m365-governance-skillsClone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is plugins/m365-governance/.
Plugin files
├── .claude-plugin/plugin.json├── skills/access-review-pack/SKILL.md├── skills/conditional-access-gap-analysis/SKILL.md├── skills/copilot-oversharing-readiness/SKILL.md├── skills/entra-posture-review/SKILL.md├── skills/graph-permission-preflight/SKILL.md├── skills/guest-and-external-sharing-review/SKILL.md├── skills/intune-baseline-check/SKILL.md├── skills/license-and-service-plan-audit/SKILL.md├── skills/privileged-access-review/SKILL.md└── skills/teams-and-groups-sprawl/SKILL.md
Included Skills10
Build a quarterly Microsoft 365 access review package from read-only Graph exports, listing directory role holders (active and PIM-eligible) with last sign-in, app owners and ownerless apps, owners of sensitive groups, guests per group and expiring app secrets and certificates, with a reviewer checklist and a sign-off CSV. Use when asked to "prepare the quarterly access review", or for ISO 27001 or SOC 2 access review evidence. Not for finding misconfigurations (entra-posture-review), running Entra ID Governance reviews, or removing access.
Find gaps, overlaps and exclusion problems in Microsoft Entra Conditional Access from read-only Graph exports, resolving who each policy really covers and checking MFA for all users and admins, legacy authentication, device and risk policies, break-glass and unexplained exclusions, report-only and self-cancelling policies, with a coverage matrix by persona. Use when asked "who is not covered by MFA?", before turning off security defaults or redesigning Conditional Access. Not for the wider tenant posture (entra-posture-review), simulating sign-ins, or changing policies.
Score a Microsoft 365 tenant's readiness for a Copilot rollout against Microsoft's oversharing checks and produce a fix list per site owner, from read-only exports of SharePoint sites, sensitivity labels, Everyone grants, sharing links and DLP policies. Use when asked "are we ready to turn on Copilot?", before a Copilot pilot or before it widens. Not for tenant guest settings alone (guest-and-external-sharing-review), reading file contents, or changing any permission.
Review a Microsoft Entra ID tenant's identity posture from read-only Graph exports, checking Conditional Access basics, security defaults, standing Global Administrators, guests with roles, stale guests, long-lived app secrets, high-risk Graph application permissions, consent and invitation settings and legacy sign-ins. Use when asked "who are our Global Admins?", to baseline a tenant, before an ISO 27001 or Essential Eight audit, or after taking one over. Not for Intune devices (intune-baseline-check), one app's permissions (graph-permission-preflight), or incident response.
Check the Microsoft Graph permissions an app, connector or MCP server requests or holds against a needs manifest, flag high-risk, .All, write-where-read-suffices and unused grants, and propose a least-privilege set. Use when asked "is it safe to grant admin consent to this app?", before granting consent, or before connecting an automation to Microsoft 365. Not for tenant-wide app review (entra-posture-review); it never changes consent.
Review guest accounts and external sharing in Microsoft 365 from read-only exports, reporting guests from blocked domains or in sensitive groups, stale and unaccepted invitations, anyone links and links that never expire, guest resharing and open Teams external access, with a per-guest access map and a draft removal list. Use when asked "who are our guests and what can they reach?", before tightening sharing or after a partner leaves. Not for tenant posture (entra-posture-review), per-file links or site permissions, or removing anyone.
Check a Microsoft Intune estate against a device baseline from read-only Graph exports, reporting non-compliant, stale, unencrypted, jailbroken and outdated devices, personal devices, unassigned compliance policies, platforms missing baseline controls and the no-policy-means-compliant setting, per platform. Use when asked "which devices are not compliant?", or for Essential Eight or ISO 27001 device evidence. Not for identity settings (entra-posture-review), Defender for Endpoint alerts, or remote wipe and retire.
Find wasted Microsoft 365 licences from read-only Graph exports, reporting licences on disabled, never-signed-in or inactive accounts, overlapping SKUs, unwanted service plans, group-based licensing errors and unassigned units, with a draft reclaim list per SKU; costs appear only when you supply unit prices. Use when asked "where are we wasting licences?", before a renewal or true-up, or after a leavers clean-up. Not for buying or changing subscriptions, app usage analytics, or removing licences.
Review privileged Microsoft Entra ID role holders from read-only Graph exports and score each admin account, reporting permanent privileged assignments, never-activated PIM eligibility, admins without phishing-resistant MFA, admin accounts used daily, stale or synchronised admins, and service principals and groups in roles, with the evidence per deduction. Use when asked "which admins still use SMS?", to review admins or PIM, or before a privileged access audit. Not for the quarterly sign-off (access-review-pack), Azure resource roles, or changing assignments.
Report Microsoft Teams and Microsoft 365 group sprawl from read-only Graph exports, finding ownerless and single-owner groups, groups with guests, public and inactive teams, empty groups, naming convention breaks and groups outside the expiration policy, and proposing owners for orphaned groups as a draft. Use when asked to "find ownerless teams", or to clean up before a naming policy or migration. Not for SharePoint site permissions or sharing links, mailbox content, or deleting or archiving anything.
Plugin manifests1
{
"name": "m365-governance",
"displayName": "Microsoft 365 Governance",
"version": "0.3.0",
"description": "Microsoft 365 governance skills for Claude Code: Graph permission preflight for apps and connectors, Entra ID posture review, Conditional Access gap analysis, privileged access review, guest and external sharing review, licence and service plan audit, Intune baseline check, Teams and group sprawl report, a quarterly access review pack, and a Copilot oversharing readiness score with fixes by site owner. Scripts are standard-library Python and evaluate exported Microsoft Graph JSON offline.",
"author": {
"name": "Muhammad Basit Ali",
"url": "https://github.com/basitalisandhu"
},
"homepage": "https://github.com/basitalisandhu/m365-governance-skills",
"repository": "https://github.com/basitalisandhu/m365-governance-skills",
"license": "MIT",
"keywords": [
"microsoft-365",
"entra-id",
"azure-ad",
"intune",
"microsoft-graph",
"conditional-access",
"least-privilege",
"access-review",
"microsoft-teams",
"governance",
"pim",
"external-sharing",
"licensing",
"copilot",
"oversharing",
"sharepoint"
]
}For maintainers
If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.
[m365-governance on Agent Plugins Marketplace](https://pluginsmp.com/plugins/m365-governance)