openapi: 3.2.0 info: title: Applications.application.Actions API version: v1.0 servers: - url: https://graph.microsoft.com/v1.0/ description: Core security: - azureaadv2: [] tags: - name: applications.application.Actions paths: /applications/{application-id}/microsoft.graph.addKey: post: tags: - applications.application.Actions summary: Invoke action addKey description: Add a key credential to an application. This method, along with removeKey can be used by an application to automate rolling its expiring keys. As part of the request validation for this method, a proof of possession of an existing key is verified before the action can be performed. Applications that don't have any existing valid certificates (no certificates have been added yet, or all certificates have expired), won't be able to use this service action. You can use the Update application operation to perform an update instead. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/application-addkey?view=graph-rest-1.0 operationId: application_addKey parameters: - name: application-id in: path description: The unique identifier of application required: true style: simple schema: type: string x-ms-docs-key-type: application requestBody: description: Action parameters content: application/json: schema: type: object properties: keyCredential: $ref: '#/components/schemas/microsoft.graph.keyCredential' passwordCredential: $ref: '#/components/schemas/microsoft.graph.passwordCredential' proof: type: string additionalProperties: type: object required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.keyCredential' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action /applications/{application-id}/microsoft.graph.addPassword: post: tags: - applications.application.Actions summary: Invoke action addPassword description: Adds a strong password or secret to an application. You can also add passwords while creating the application. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/application-addpassword?view=graph-rest-1.0 operationId: application_addPassword parameters: - name: application-id in: path description: The unique identifier of application required: true style: simple schema: type: string x-ms-docs-key-type: application requestBody: description: Action parameters content: application/json: schema: type: object properties: passwordCredential: $ref: '#/components/schemas/microsoft.graph.passwordCredential' additionalProperties: type: object required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.passwordCredential' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action /applications/{application-id}/microsoft.graph.checkMemberGroups: post: tags: - applications.application.Actions summary: Invoke action checkMemberGroups description: 'Check for membership in a specified list of group IDs, and return from that list the IDs of groups where a specified object is a member. The specified object can be of one of the following types: - user - group - service principal - organizational contact - device - directory object This function is transitive. You can check up to a maximum of 20 groups per request. This function supports all groups provisioned in Microsoft Entra ID. Because Microsoft 365 groups cannot contain other groups, membership in a Microsoft 365 group is always direct.' externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/directoryobject-checkmembergroups?view=graph-rest-1.0 operationId: application_checkMemberGroup parameters: - name: application-id in: path description: The unique identifier of application required: true style: simple schema: type: string x-ms-docs-key-type: application requestBody: description: Action parameters content: application/json: schema: type: object properties: groupIds: type: array items: type: string additionalProperties: type: object required: true responses: 2XX: description: Success content: application/json: schema: type: object properties: value: type: array items: type: string '@odata.nextLink': type: - string - 'null' additionalProperties: type: object default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore /applications/{application-id}/microsoft.graph.checkMemberObjects: post: tags: - applications.application.Actions summary: Invoke action checkMemberObjects operationId: application_checkMemberObject parameters: - name: application-id in: path description: The unique identifier of application required: true style: simple schema: type: string x-ms-docs-key-type: application requestBody: description: Action parameters content: application/json: schema: type: object properties: ids: type: array items: type: string additionalProperties: type: object required: true responses: 2XX: description: Success content: application/json: schema: type: object properties: value: type: array items: type: string '@odata.nextLink': type: - string - 'null' additionalProperties: type: object default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore /applications/{application-id}/microsoft.graph.getMemberGroups: post: tags: - applications.application.Actions summary: Invoke action getMemberGroups description: Return all the group IDs for the groups that the specified user, group, service principal, organizational contact, device, or directory object is a member of. This function is transitive. This API returns up to 11,000 group IDs. If more than 11,000 results are available, it returns a 400 Bad Request error with the DirectoryResultSizeLimitExceeded error code. If you get the DirectoryResultSizeLimitExceeded error code, use the List group transitive memberOf API instead. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/directoryobject-getmembergroups?view=graph-rest-1.0 operationId: application_getMemberGroup parameters: - name: application-id in: path description: The unique identifier of application required: true style: simple schema: type: string x-ms-docs-key-type: application requestBody: description: Action parameters content: application/json: schema: type: object properties: securityEnabledOnly: type: - boolean - 'null' default: false additionalProperties: type: object required: true responses: 2XX: description: Success content: application/json: schema: type: object properties: value: type: array items: type: string '@odata.nextLink': type: - string - 'null' additionalProperties: type: object default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore /applications/{application-id}/microsoft.graph.getMemberObjects: post: tags: - applications.application.Actions summary: Invoke action getMemberObjects description: 'Return all IDs for the groups, administrative units, and directory roles that an object of one of the following types is a member of: - user - group - service principal - organizational contact - device - directory object This function is transitive. Only users and role-enabled groups can be members of directory roles.' externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/directoryobject-getmemberobjects?view=graph-rest-1.0 operationId: application_getMemberObject parameters: - name: application-id in: path description: The unique identifier of application required: true style: simple schema: type: string x-ms-docs-key-type: application requestBody: description: Action parameters content: application/json: schema: type: object properties: securityEnabledOnly: type: - boolean - 'null' default: false additionalProperties: type: object required: true responses: 2XX: description: Success content: application/json: schema: type: object properties: value: type: array items: type: string '@odata.nextLink': type: - string - 'null' additionalProperties: type: object default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore /applications/{application-id}/microsoft.graph.removeKey: post: tags: - applications.application.Actions summary: Invoke action removeKey description: Remove a key credential from an agentIdentityBlueprint. This method along with addKey can be used to automate rolling its expiring keys. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/agentidentityblueprint-removekey?view=graph-rest-1.0 operationId: application_removeKey parameters: - name: application-id in: path description: The unique identifier of application required: true style: simple schema: type: string x-ms-docs-key-type: application requestBody: description: Action parameters content: application/json: schema: type: object properties: keyId: pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$ type: string format: uuid proof: type: string additionalProperties: type: object required: true responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action /applications/{application-id}/microsoft.graph.removePassword: post: tags: - applications.application.Actions summary: Invoke action removePassword description: Remove a password from an application. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/application-removepassword?view=graph-rest-1.0 operationId: application_removePassword parameters: - name: application-id in: path description: The unique identifier of application required: true style: simple schema: type: string x-ms-docs-key-type: application requestBody: description: Action parameters content: application/json: schema: type: object properties: keyId: pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$ type: string format: uuid additionalProperties: type: object required: true responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action /applications/{application-id}/microsoft.graph.restore: post: tags: - applications.application.Actions summary: Invoke action restore description: 'Restore a recently deleted directory object from deleted items. The following types are supported: - administrativeUnit - application - agentIdentityBlueprint - agentIdentity - agentIdentityBlueprintPrincipal - agentUser - certificateBasedAuthPki - certificateAuthorityDetail - group - servicePrincipal - user If an item is accidentally deleted, you can fully restore the item. Additionally, restoring an application doesn''t automatically restore the associated service principal automatically. You must call this API to explicitly restore the deleted service principal. A recently deleted item remains available for up to 30 days. After 30 days, the item is permanently deleted.' externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/directory-deleteditems-restore?view=graph-rest-1.0 operationId: application_restore parameters: - name: application-id in: path description: The unique identifier of application required: true style: simple schema: type: string x-ms-docs-key-type: application responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.directoryObject' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action /applications/{application-id}/microsoft.graph.setVerifiedPublisher: post: tags: - applications.application.Actions summary: Invoke action setVerifiedPublisher description: Set the the verifiedPublisher on an agentIdentityBlueprint. For more information, including prerequisites to setting a verified publisher, see Publisher verification. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/agentidentityblueprint-setverifiedpublisher?view=graph-rest-1.0 operationId: application_setVerifiedPublisher parameters: - name: application-id in: path description: The unique identifier of application required: true style: simple schema: type: string x-ms-docs-key-type: application requestBody: description: Action parameters content: application/json: schema: type: object properties: verifiedPublisherId: type: string additionalProperties: type: object required: true responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action /applications/{application-id}/microsoft.graph.unsetVerifiedPublisher: post: tags: - applications.application.Actions summary: Invoke action unsetVerifiedPublisher description: Unset the verifiedPublisher previously set on an agentIdentityBlueprint, removing all verified publisher properties. For more information, see Publisher verification. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/agentidentityblueprint-unsetverifiedpublisher?view=graph-rest-1.0 operationId: application_unsetVerifiedPublisher parameters: - name: application-id in: path description: The unique identifier of application required: true style: simple schema: type: string x-ms-docs-key-type: application responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action /applications/microsoft.graph.getAvailableExtensionProperties: post: tags: - applications.application.Actions summary: Invoke action getAvailableExtensionProperties description: 'Return all directory extension definitions that are registered in a directory, including through multitenant apps. The following entities support extension properties:' externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/directoryobject-getavailableextensionproperties?view=graph-rest-1.0 operationId: application_getAvailableExtensionProperty requestBody: description: Action parameters content: application/json: schema: type: object properties: isSyncedFromOnPremises: type: - boolean - 'null' default: false additionalProperties: type: object required: true responses: 2XX: description: Success content: application/json: schema: title: Collection of extensionProperty type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.extensionProperty' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore /applications/microsoft.graph.getByIds: post: tags: - applications.application.Actions summary: Invoke action getByIds description: 'Return the directory objects specified in a list of IDs. Only a subset of user properties are returned by default in v1.0. Some common uses for this function are to:' externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/directoryobject-getbyids?view=graph-rest-1.0 operationId: application_getGraphBPreId requestBody: description: Action parameters content: application/json: schema: type: object properties: ids: type: array items: type: string types: type: array items: type: - string - 'null' additionalProperties: type: object required: true responses: 2XX: description: Success content: application/json: schema: title: Collection of directoryObject type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.directoryObject' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore /applications/microsoft.graph.validateProperties: post: tags: - applications.application.Actions summary: Invoke action validateProperties description: 'Validate that a Microsoft 365 group''s display name or mail nickname complies with naming policies. Clients can use this API to determine whether a display name or mail nickname is valid before trying to create a Microsoft 365 group. To validate the properties of an existing group, use the group: validateProperties function. The following policy validations are performed for the display name and mail nickname properties: 1. Validate the prefix and suffix naming policy 2. Validate the custom banned words policy 3. Validate that the mail nickname is unique This API only returns the first validation failure that is encountered. If the properties fail multiple validations, only the first validation failure is returned. However, you can validate both the mail nickname and the display name and receive a collection of validation errors if you''re only validating the prefix and suffix naming policy. To learn more about configuring naming policies, see Configure naming policy.' externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/directoryobject-validateproperties?view=graph-rest-1.0 operationId: application_validateProperty requestBody: description: Action parameters content: application/json: schema: type: object properties: entityType: type: - string - 'null' displayName: type: - string - 'null' mailNickname: type: - string - 'null' onBehalfOfUserId: pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$ type: - string - 'null' format: uuid additionalProperties: type: object required: true responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action components: schemas: microsoft.graph.ODataErrors.InnerError: type: object additionalProperties: type: object description: The structure of this object is service-specific microsoft.graph.keyCredential: title: keyCredential type: object properties: customKeyIdentifier: type: - string - 'null' description: A 40-character binary type that can be used to identify the credential. Optional. When not provided in the payload, defaults to the thumbprint of the certificate. format: base64url displayName: type: - string - 'null' description: The friendly name for the key, with a maximum length of 90 characters. Longer values are accepted but shortened. Optional. endDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The date and time at which the credential expires. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. format: date-time key: type: - string - 'null' description: The certificate's raw data in byte array converted to Base64 string. Requires $select to retrieve; only available for single object requests (GET /applications/{applicationId}?$select=keyCredentials or GET /servicePrincipals/{servicePrincipalId}?$select=keyCredentials); otherwise, it's always null. From a .cer certificate, you can read the key using the Convert.ToBase64String() method. For more information, see Get the certificate key. format: base64url keyId: pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$ type: - string - 'null' description: The unique identifier (GUID) for the key. format: uuid startDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The date and time at which the credential becomes valid.The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. format: date-time type: type: - string - 'null' description: The type of key credential; for example, Symmetric, AsymmetricX509Cert. usage: type: - string - 'null' description: A string that describes the purpose for which the key can be used; for example, Verify. additionalProperties: type: object microsoft.graph.directoryObject: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: directoryObject type: object properties: deletedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: Date and time when this object was deleted. Always null when the object hasn't been deleted. format: date-time additionalProperties: type: object microsoft.graph.ODataErrors.ErrorDetails: required: - code - message type: object properties: code: type: string message: type: string target: type: - string - 'null' additionalProperties: type: object microsoft.graph.ODataErrors.MainError: required: - code - message type: object properties: code: type: string message: type: string x-ms-primary-error-message: true target: type: - string - 'null' details: type: array items: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails' innerError: $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError' additionalProperties: type: object microsoft.graph.ODataErrors.ODataError: required: - error type: object properties: error: $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError' additionalProperties: type: object microsoft.graph.entity: title: entity type: object properties: id: type: string description: The unique identifier for an entity. Read-only. additionalProperties: type: object microsoft.graph.extensionProperty: allOf: - $ref: '#/components/schemas/microsoft.graph.directoryObject' - title: extensionProperty type: object properties: appDisplayName: type: - string - 'null' description: Display name of the application object on which this extension property is defined. Read-only. dataType: type: string description: Specifies the data type of the value the extension property can hold. Following values are supported. Binary - 256 bytes maximumBooleanDateTime - Must be specified in ISO 8601 format. Will be stored in UTC.Integer - 32-bit value.LargeInteger - 64-bit value.String - 256 characters maximumNot nullable. For multivalued directory extensions, these limits apply per value in the collection. isMultiValued: type: boolean description: 'Defines the directory extension as a multi-valued property. When true, the directory extension property can store a collection of objects of the dataType; for example, a collection of string types such as ''extensionb7b1c57b532f40b8b5ed4b7a7ba67401jobGroupTracker'': [''String 1'', ''String 2'']. The default value is false. Supports $filter (eq).' isSyncedFromOnPremises: type: - boolean - 'null' description: Indicates if this extension property was synced from on-premises active directory using Microsoft Entra Connect. Read-only. name: type: string description: Name of the extension property. Not nullable. Supports $filter (eq). targetObjects: type: array items: type: string description: Following values are supported. Not nullable. UserGroupAdministrativeUnitApplicationDeviceOrganization additionalProperties: type: object microsoft.graph.passwordCredential: title: passwordCredential type: object properties: customKeyIdentifier: type: - string - 'null' description: Do not use. format: base64url displayName: type: - string - 'null' description: Friendly name for the password. Optional. endDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The date and time at which the password expires represented using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. Optional. format: date-time hint: type: - string - 'null' description: Contains the first three characters of the password. Read-only. keyId: pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$ type: - string - 'null' description: The unique identifier for the password. format: uuid secretText: type: - string - 'null' description: Read-only; Contains the strong passwords generated by Microsoft Entra ID that are 16-64 characters in length. The generated password value is only returned during the initial POST request to addPassword. There is no way to retrieve this password in the future. startDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The date and time at which the password becomes valid. The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. Optional. format: date-time additionalProperties: type: object responses: error: description: error content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError' securitySchemes: azureaadv2: type: oauth2 flows: authorizationCode: authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token scopes: {}