Agent Plugins Marketplace
← All plugins

m365-governance

v0.3.0

Microsoft 365 governance skills for Claude Code: Graph permission preflight for apps and connectors, Entra ID posture review, Conditional Access gap analysis, privileged access review, guest and external sharing review, licence and service plan audit, Intune baseline check, Teams and group sprawl report, a quarterly access review pack, and a Copilot oversharing readiness score with fixes by site owner. Scripts are standard-library Python and evaluate exported Microsoft Graph JSON offline.

Claude Code10 Skills

By Muhammad Basit AliLicense: MIT1 GitHub starsUpdated 3 days ago

Directory evidence

Runtimes
Claude Code
Parsed components
10 skill or MCP entries
Source updated
Oct 4, 2026
Manifest status
Canonical path parsed

The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →

Install m365-governance for Claude Code

Installs for the current user
claude plugin marketplace add IchenDEV/agent-plugin-mkt
claude plugin marketplace update agent-plugin-marketplace
claude plugin install m365-governance@agent-plugin-marketplace

Paste and run these commands in a terminal with Claude Code. They add and refresh the PluginsMP catalog, then install this plugin.

The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.

Get the source manually
git clone https://github.com/basitalisandhu/m365-governance-skills

Clone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is plugins/m365-governance/.

Plugin files

plugins/m365-governance/
├── .claude-plugin/plugin.json
├── skills/access-review-pack/SKILL.md
├── skills/conditional-access-gap-analysis/SKILL.md
├── skills/copilot-oversharing-readiness/SKILL.md
├── skills/entra-posture-review/SKILL.md
├── skills/graph-permission-preflight/SKILL.md
├── skills/guest-and-external-sharing-review/SKILL.md
├── skills/intune-baseline-check/SKILL.md
├── skills/license-and-service-plan-audit/SKILL.md
├── skills/privileged-access-review/SKILL.md
└── skills/teams-and-groups-sprawl/SKILL.md

Included Skills10

access-review-packskills/access-review-pack/SKILL.md

Build a quarterly Microsoft 365 access review package from read-only Graph exports, listing directory role holders (active and PIM-eligible) with last sign-in, app owners and ownerless apps, owners of sensitive groups, guests per group and expiring app secrets and certificates, with a reviewer checklist and a sign-off CSV. Use when asked to "prepare the quarterly access review", or for ISO 27001 or SOC 2 access review evidence. Not for finding misconfigurations (entra-posture-review), running Entra ID Governance reviews, or removing access.

conditional-access-gap-analysisskills/conditional-access-gap-analysis/SKILL.md

Find gaps, overlaps and exclusion problems in Microsoft Entra Conditional Access from read-only Graph exports, resolving who each policy really covers and checking MFA for all users and admins, legacy authentication, device and risk policies, break-glass and unexplained exclusions, report-only and self-cancelling policies, with a coverage matrix by persona. Use when asked "who is not covered by MFA?", before turning off security defaults or redesigning Conditional Access. Not for the wider tenant posture (entra-posture-review), simulating sign-ins, or changing policies.

copilot-oversharing-readinessskills/copilot-oversharing-readiness/SKILL.md

Score a Microsoft 365 tenant's readiness for a Copilot rollout against Microsoft's oversharing checks and produce a fix list per site owner, from read-only exports of SharePoint sites, sensitivity labels, Everyone grants, sharing links and DLP policies. Use when asked "are we ready to turn on Copilot?", before a Copilot pilot or before it widens. Not for tenant guest settings alone (guest-and-external-sharing-review), reading file contents, or changing any permission.

entra-posture-reviewskills/entra-posture-review/SKILL.md

Review a Microsoft Entra ID tenant's identity posture from read-only Graph exports, checking Conditional Access basics, security defaults, standing Global Administrators, guests with roles, stale guests, long-lived app secrets, high-risk Graph application permissions, consent and invitation settings and legacy sign-ins. Use when asked "who are our Global Admins?", to baseline a tenant, before an ISO 27001 or Essential Eight audit, or after taking one over. Not for Intune devices (intune-baseline-check), one app's permissions (graph-permission-preflight), or incident response.

graph-permission-preflightskills/graph-permission-preflight/SKILL.md

Check the Microsoft Graph permissions an app, connector or MCP server requests or holds against a needs manifest, flag high-risk, .All, write-where-read-suffices and unused grants, and propose a least-privilege set. Use when asked "is it safe to grant admin consent to this app?", before granting consent, or before connecting an automation to Microsoft 365. Not for tenant-wide app review (entra-posture-review); it never changes consent.

guest-and-external-sharing-reviewskills/guest-and-external-sharing-review/SKILL.md

Review guest accounts and external sharing in Microsoft 365 from read-only exports, reporting guests from blocked domains or in sensitive groups, stale and unaccepted invitations, anyone links and links that never expire, guest resharing and open Teams external access, with a per-guest access map and a draft removal list. Use when asked "who are our guests and what can they reach?", before tightening sharing or after a partner leaves. Not for tenant posture (entra-posture-review), per-file links or site permissions, or removing anyone.

intune-baseline-checkskills/intune-baseline-check/SKILL.md

Check a Microsoft Intune estate against a device baseline from read-only Graph exports, reporting non-compliant, stale, unencrypted, jailbroken and outdated devices, personal devices, unassigned compliance policies, platforms missing baseline controls and the no-policy-means-compliant setting, per platform. Use when asked "which devices are not compliant?", or for Essential Eight or ISO 27001 device evidence. Not for identity settings (entra-posture-review), Defender for Endpoint alerts, or remote wipe and retire.

license-and-service-plan-auditskills/license-and-service-plan-audit/SKILL.md

Find wasted Microsoft 365 licences from read-only Graph exports, reporting licences on disabled, never-signed-in or inactive accounts, overlapping SKUs, unwanted service plans, group-based licensing errors and unassigned units, with a draft reclaim list per SKU; costs appear only when you supply unit prices. Use when asked "where are we wasting licences?", before a renewal or true-up, or after a leavers clean-up. Not for buying or changing subscriptions, app usage analytics, or removing licences.

privileged-access-reviewskills/privileged-access-review/SKILL.md

Review privileged Microsoft Entra ID role holders from read-only Graph exports and score each admin account, reporting permanent privileged assignments, never-activated PIM eligibility, admins without phishing-resistant MFA, admin accounts used daily, stale or synchronised admins, and service principals and groups in roles, with the evidence per deduction. Use when asked "which admins still use SMS?", to review admins or PIM, or before a privileged access audit. Not for the quarterly sign-off (access-review-pack), Azure resource roles, or changing assignments.

teams-and-groups-sprawlskills/teams-and-groups-sprawl/SKILL.md

Report Microsoft Teams and Microsoft 365 group sprawl from read-only Graph exports, finding ownerless and single-owner groups, groups with guests, public and inactive teams, empty groups, naming convention breaks and groups outside the expiration policy, and proposing owners for orphaned groups as a draft. Use when asked to "find ownerless teams", or to clean up before a naming policy or migration. Not for SharePoint site permissions or sharing links, mailbox content, or deleting or archiving anything.

Plugin manifests1

plugins/m365-governance/.claude-plugin/plugin.json
{
  "name": "m365-governance",
  "displayName": "Microsoft 365 Governance",
  "version": "0.3.0",
  "description": "Microsoft 365 governance skills for Claude Code: Graph permission preflight for apps and connectors, Entra ID posture review, Conditional Access gap analysis, privileged access review, guest and external sharing review, licence and service plan audit, Intune baseline check, Teams and group sprawl report, a quarterly access review pack, and a Copilot oversharing readiness score with fixes by site owner. Scripts are standard-library Python and evaluate exported Microsoft Graph JSON offline.",
  "author": {
    "name": "Muhammad Basit Ali",
    "url": "https://github.com/basitalisandhu"
  },
  "homepage": "https://github.com/basitalisandhu/m365-governance-skills",
  "repository": "https://github.com/basitalisandhu/m365-governance-skills",
  "license": "MIT",
  "keywords": [
    "microsoft-365",
    "entra-id",
    "azure-ad",
    "intune",
    "microsoft-graph",
    "conditional-access",
    "least-privilege",
    "access-review",
    "microsoft-teams",
    "governance",
    "pim",
    "external-sharing",
    "licensing",
    "copilot",
    "oversharing",
    "sharepoint"
  ]
}

If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.

[m365-governance on Agent Plugins Marketplace](https://pluginsmp.com/plugins/m365-governance)