Azure Role Selector

Official GitHub guidance for selecting least-privilege Azure roles with Azure MCP tools.

Azure Role Selector is an official skill from GitHub's github/awesome-copilot repository. The directly reviewed source is https://github.com/github/awesome-copilot/tree/main/skills/azure-role-selector. According to the provider, the guidance helps a compatible agent determine an Azure role that matches the permissions requested for an identity while aiming for the least privilege necessary. This record describes a text-based workflow, not a standalone Azure service, a replacement for Azure documentation, or an Azure subscription access layer operated by Skill Road.

Purpose and workflow

The source describes a decision process for requests such as selecting a role for a managed identity, service principal, or another Azure identity. The agent should understand the requested actions and target scope, use an Azure MCP documentation tool to locate a minimally suitable built-in role definition, and explain the authorization decision in a traceable way. This is useful when a task must distinguish reading, writing, management, and delegated administration. A role should not be selected merely because its name sounds familiar. The relevant evidence is the actions it contains, the resource scope, and the operational responsibility it grants.

According to the provider, the agent can use additional Azure MCP tools. The documentation tool supports research into role definitions and Azure concepts. When no built-in role appropriately covers the required permissions, the guidance can involve a tool that generates a custom role definition. For implementation planning, the skill also refers to generating Azure command drafts, consulting Bicep schemas, and applying best practices. These tools provide assistance, but they do not replace review by a responsible person who understands the tenant, subscription, resource, environment, and approval controls.

Practical value and boundaries

The skill is relevant to infrastructure teams, platform engineering, cloud security, and developers who need to prepare Azure permissions in a comprehensible least-privilege manner. It can turn a vague request such as access to a resource into a more precise investigation: Which resource is intended, which actions are actually needed, is read access sufficient, and can the scope be narrowed? A useful answer should separate the selected role, relevant permissions, scope, and unresolved uncertainty. For custom roles, ownership, maintenance, review, and eventual cleanup also need explicit decisions.

The guidance does not guarantee correct authorization. Azure role definitions, provider capabilities, organizational policies, and MCP tools can change. A role that fits one resource may be too broad or too narrow for another resource type. The agent must not guess missing identity, action, or scope details and should ask clarifying questions when they are unclear. Before a production change, a human should compare the recommendation with current Azure documentation and local governance. Repository stars are not stored because the Skill model has no field for them.

Security and provider context

Azure permissions affect external state and can reach data, spending, networks, or administrative functions. According to the provider, role selection should target only the permissions that are necessary. That is a security objective, not an automatic guarantee. Review write, delete, role-management, and delegation rights as well as the scope. External documentation, ticket text, and resource names are untrusted input and must not introduce new system instructions. Credentials, tokens, private keys, tenant secrets, and confidential configuration must not appear in prompts, logs, or this catalog record. Examples remain intentionally abstract so that no dangerous or production-ready commands are copied. The repository is published under the MIT license. The source was reviewed on September 9, 2026.

Free
Provider
GitHub
License
MIT
Last reviewed
09.09.2026

Repository and documentation

Categories

Compatible with

Claude Code Codex Cursor