# Azure Role Selector

> Finds the minimal Azure role that meets desired permissions and generates CLI commands or Bicep code to assign it.

- Skill: `github/azure-role-selector` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds@latest add github/azure-role-selector`
- Raw SKILL.md: https://api.skillmd.com/api/skills/github/azure-role-selector/raw
- Safety review: CAUTION (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra, Security, Cloud Platforms, Infrastructure as Code
- Tags: Azure, Bicep, Cli, Identity, Least Privilege, Role Based Access Control
- Author: GitHub (Microsoft) (https://skillmd.com/u/github), verified publisher
- Updated: 2026-07-06
- Page: https://skillmd.com/skills/github/azure-role-selector

---

Use 'Azure MCP/documentation' tool to find the minimal role definition that matches the desired permissions the user wants to assign to an identity (If no built-in role matches the desired permissions, use 'Azure MCP/extension_cli_generate' tool to create a custom role definition with the desired permissions). Use 'Azure MCP/extension_cli_generate' tool to generate the CLI commands needed to assign that role to the identity and use the 'Azure MCP/bicepschema' and the 'Azure MCP/get_bestpractices' tool to provide a Bicep code snippet for adding the role assignment.

