openapi: 3.2.0 info: title: Identity.DirectoryManagement Directory.directory API version: v1.0 servers: - url: https://graph.microsoft.com/v1.0/ description: Core security: - azureaadv2: [] tags: - name: Directory directory paths: /directory: get: tags: - Directory directory summary: Get directory operationId: directory_GetDirectory parameters: - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved entity content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.directory' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - Directory directory summary: Update directory operationId: directory_UpdateDirectory requestBody: description: New property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.directory' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.directory' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation components: schemas: microsoft.graph.certificateBasedAuthPki: allOf: - $ref: '#/components/schemas/microsoft.graph.directoryObject' - title: certificateBasedAuthPki type: object properties: displayName: type: - string - 'null' description: The name of the object. Maximum length is 256 characters. lastModifiedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: string description: The date and time when the object was created or last modified. format: date-time status: type: - string - 'null' description: The status of any asynchronous jobs runs on the object which can be upload or delete. statusDetails: type: - string - 'null' description: The status details of the upload/deleted operation of PKI (Public Key Infrastructure). certificateAuthorities: type: array items: $ref: '#/components/schemas/microsoft.graph.certificateAuthorityDetail' description: The collection of certificate authorities contained in this public key infrastructure resource. x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.entraRecoveryServices.recoveryPreviewJob: allOf: - $ref: '#/components/schemas/microsoft.graph.entraRecoveryServices.recoveryJobBase' - title: recoveryPreviewJob type: object additionalProperties: type: object microsoft.graph.publicKeyInfrastructureRoot: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: publicKeyInfrastructureRoot type: object properties: certificateBasedAuthConfigurations: type: array items: $ref: '#/components/schemas/microsoft.graph.certificateBasedAuthPki' description: The collection of public key infrastructure instances for the certificate-based authentication feature for users. x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.remoteTenantGroup: allOf: - $ref: '#/components/schemas/microsoft.graph.directoryObject' - title: remoteTenantGroup type: object properties: remoteGroupDisplayName: type: - string - 'null' description: Display name of the group in the remote tenant. remoteGroupId: pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$ type: - string - 'null' description: Unique identifier of the group in the remote tenant. format: uuid remoteTenantDisplayName: type: - string - 'null' description: Display name of the remote tenant. remoteTenantId: pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$ type: - string - 'null' description: Unique identifier of the remote tenant. format: uuid remoteTenantPrimaryDomain: type: - string - 'null' description: Primary domain name of the remote tenant. additionalProperties: type: object microsoft.graph.ODataErrors.ODataError: required: - error type: object properties: error: $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError' additionalProperties: type: object microsoft.graph.entraRecoveryServices.recoveryJobFilteringCriteriaBase: title: recoveryJobFilteringCriteriaBase type: object additionalProperties: type: object microsoft.graph.entraRecoveryServices.recoveryJobBase: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: recoveryJobBase type: object properties: filteringCriteria: $ref: '#/components/schemas/microsoft.graph.entraRecoveryServices.recoveryJobFilteringCriteriaBase' jobCompletionDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' format: date-time jobStartDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: string format: date-time status: $ref: '#/components/schemas/microsoft.graph.entraRecoveryServices.recoveryStatus' targetStateDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: string format: date-time totalChangedLinksCalculated: maximum: 2147483647 minimum: -2147483648 type: - number - 'null' format: int32 totalChangedObjectsCalculated: maximum: 2147483647 minimum: -2147483648 type: - number - 'null' format: int32 additionalProperties: type: object microsoft.graph.directory: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: directory type: object properties: administrativeUnits: type: array items: $ref: '#/components/schemas/microsoft.graph.administrativeUnit' description: Conceptual container for user and group directory objects. x-ms-navigationProperty: true attributeSets: type: array items: $ref: '#/components/schemas/microsoft.graph.attributeSet' description: Group of related custom security attribute definitions. x-ms-navigationProperty: true customSecurityAttributeDefinitions: type: array items: $ref: '#/components/schemas/microsoft.graph.customSecurityAttributeDefinition' description: Schema of a custom security attributes (key-value pairs). x-ms-navigationProperty: true deletedItems: type: array items: $ref: '#/components/schemas/microsoft.graph.directoryObject' description: Recently deleted items. Read-only. Nullable. x-ms-navigationProperty: true deviceLocalCredentials: type: array items: $ref: '#/components/schemas/microsoft.graph.deviceLocalCredentialInfo' description: The credentials of the device's local administrator account backed up to Microsoft Entra ID. x-ms-navigationProperty: true federationConfigurations: type: array items: $ref: '#/components/schemas/microsoft.graph.identityProviderBase' description: Configure domain federation with organizations whose identity provider (IdP) supports either the SAML or WS-Fed protocol. x-ms-navigationProperty: true onPremisesSynchronization: type: array items: $ref: '#/components/schemas/microsoft.graph.onPremisesDirectorySynchronization' description: A container for on-premises directory synchronization functionalities that are available for the organization. x-ms-navigationProperty: true publicKeyInfrastructure: $ref: '#/components/schemas/microsoft.graph.publicKeyInfrastructureRoot' recovery: $ref: '#/components/schemas/microsoft.graph.entraRecoveryServices.recovery' remoteTenantGroups: type: array items: $ref: '#/components/schemas/microsoft.graph.remoteTenantGroup' description: Collection of groups in remote Microsoft Entra tenants that are available in the directory. x-ms-navigationProperty: true subscriptions: type: array items: $ref: '#/components/schemas/microsoft.graph.companySubscription' description: List of commercial subscriptions that an organization acquired. x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.certificateAuthorityDetail: allOf: - $ref: '#/components/schemas/microsoft.graph.directoryObject' - title: certificateAuthorityDetail type: object properties: certificate: type: string description: The public key of the certificate authority. format: base64url certificateAuthorityType: $ref: '#/components/schemas/microsoft.graph.certificateAuthorityType' certificateRevocationListUrl: type: - string - 'null' description: The URL to check if the certificate is revoked. createdDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The date and time when the certificate authority was created. format: date-time deltaCertificateRevocationListUrl: type: - string - 'null' displayName: type: - string - 'null' description: The display name of the certificate authority. expirationDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: string description: The date and time when the certificate authority expires. Supports $filter (eq) and $orderby. format: date-time isIssuerHintEnabled: type: - boolean - 'null' description: Indicates whether the certificate picker presents the certificate authority to the user to use for authentication. Default value is false. Optional. issuer: type: - string - 'null' description: The issuer of the certificate authority. issuerSubjectKeyIdentifier: type: - string - 'null' description: The subject key identifier of certificate authority. thumbprint: type: string description: The thumbprint of certificate authority certificate. Supports $filter (eq, startswith). additionalProperties: type: object microsoft.graph.scopedRoleMembership: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: scopedRoleMembership type: object properties: administrativeUnitId: type: string description: Unique identifier for the administrative unit that the directory role is scoped to roleId: type: string description: Unique identifier for the directory role that the member is in. roleMemberInfo: $ref: '#/components/schemas/microsoft.graph.identity' additionalProperties: type: object microsoft.graph.ODataErrors.InnerError: type: object additionalProperties: type: object description: The structure of this object is service-specific microsoft.graph.attributeSet: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: attributeSet type: object properties: description: type: - string - 'null' description: Description of the attribute set. Can be up to 128 characters long and include Unicode characters. Can be changed later. maxAttributesPerSet: maximum: 2147483647 minimum: -2147483648 type: - number - 'null' description: Maximum number of custom security attributes that can be defined in this attribute set. Default value is null. If not specified, the administrator can add up to the maximum of 500 active attributes per tenant. Can be changed later. format: int32 additionalProperties: type: object microsoft.graph.directoryObject: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: directoryObject type: object properties: deletedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: Date and time when this object was deleted. Always null when the object hasn't been deleted. format: date-time additionalProperties: type: object microsoft.graph.customSecurityAttributeDefinition: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: customSecurityAttributeDefinition type: object properties: attributeSet: type: string description: Name of the attribute set. Case insensitive. description: type: - string - 'null' description: Description of the custom security attribute. Can be up to 128 characters long and include Unicode characters. Can be changed later. isCollection: type: boolean description: Indicates whether multiple values can be assigned to the custom security attribute. Cannot be changed later. If type is set to Boolean, isCollection cannot be set to true. isSearchable: type: - boolean - 'null' description: Indicates whether custom security attribute values are indexed for searching on objects that are assigned attribute values. Cannot be changed later. name: type: string description: Name of the custom security attribute. Must be unique within an attribute set. Can be up to 32 characters long and include Unicode characters. Cannot contain spaces or special characters. Cannot be changed later. Case insensitive. status: type: string description: 'Specifies whether the custom security attribute is active or deactivated. Acceptable values are: Available and Deprecated. Can be changed later.' type: type: string description: 'Data type for the custom security attribute values. Supported types are: Boolean, Integer, and String. Cannot be changed later.' usePreDefinedValuesOnly: type: - boolean - 'null' description: Indicates whether only predefined values can be assigned to the custom security attribute. If set to false, free-form values are allowed. Can later be changed from true to false, but cannot be changed from false to true. If type is set to Boolean, usePreDefinedValuesOnly cannot be set to true. allowedValues: type: array items: $ref: '#/components/schemas/microsoft.graph.allowedValue' description: Values that are predefined for this custom security attribute. This navigation property is not returned by default and must be specified in an $expand query. For example, /directory/customSecurityAttributeDefinitions?$expand=allowedValues. x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.entraRecoveryServices.recovery: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: recovery type: object properties: jobs: type: array items: $ref: '#/components/schemas/microsoft.graph.entraRecoveryServices.recoveryJobBase' x-ms-navigationProperty: true snapshots: type: array items: $ref: '#/components/schemas/microsoft.graph.entraRecoveryServices.snapshot' x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.administrativeUnit: allOf: - $ref: '#/components/schemas/microsoft.graph.directoryObject' - title: administrativeUnit type: object properties: description: type: - string - 'null' description: An optional description for the administrative unit. Supports $filter (eq, ne, in, startsWith), $search. displayName: type: - string - 'null' description: Display name for the administrative unit. Maximum length is 256 characters. Supports $filter (eq, ne, not, ge, le, in, startsWith, and eq on null values), $search, and $orderby. isMemberManagementRestricted: type: - boolean - 'null' description: true if members of this administrative unit should be treated as sensitive, which requires specific permissions to manage. If not set, the default value is null and the default behavior is false. Use this property to define administrative units with roles that don't inherit from tenant-level administrators, and where the management of individual member objects is limited to administrators scoped to a restricted management administrative unit. This property is immutable and can't be changed later. For more information on how to work with restricted management administrative units, see Restricted management administrative units in Microsoft Entra ID. membershipRule: type: - string - 'null' description: The dynamic membership rule for the administrative unit. For more information about the rules you can use for dynamic administrative units and dynamic groups, see Manage rules for dynamic membership groups in Microsoft Entra ID. membershipRuleProcessingState: type: - string - 'null' description: Controls whether the dynamic membership rule is actively processed. Set to On to activate the dynamic membership rule, or Paused to stop updating membership dynamically. membershipType: type: - string - 'null' description: 'Indicates the membership type for the administrative unit. The possible values are: dynamic, assigned. If not set, the default value is null and the default behavior is assigned.' visibility: type: - string - 'null' description: Controls whether the administrative unit and its members are hidden or public. Can be set to HiddenMembership. If not set, the default value is null and the default behavior is public. When set to HiddenMembership, only members of the administrative unit can list other members of the administrative unit. extensions: type: array items: $ref: '#/components/schemas/microsoft.graph.extension' description: The collection of open extensions defined for this administrative unit. Nullable. x-ms-navigationProperty: true members: type: array items: $ref: '#/components/schemas/microsoft.graph.directoryObject' description: Users and groups that are members of this administrative unit. Supports $expand. x-ms-navigationProperty: true scopedRoleMembers: type: array items: $ref: '#/components/schemas/microsoft.graph.scopedRoleMembership' description: Scoped-role members of this administrative unit. x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.identity: title: identity type: object properties: displayName: type: - string - 'null' description: The display name of the identity.For drive items, the display name might not always be available or up to date. For example, if a user changes their display name the API might show the new value in a future response, but the items associated with the user don't show up as changed when using delta. id: type: - string - 'null' description: Unique identifier for the identity or actor. For example, in the access reviews decisions API, this property might record the id of the principal, that is, the group, user, or application that's subject to review. additionalProperties: type: object microsoft.graph.companySubscription: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: companySubscription type: object properties: commerceSubscriptionId: type: - string - 'null' description: The ID of this subscription in the commerce system. Alternate key. createdDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The date and time when this subscription was created. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. format: date-time isTrial: type: - boolean - 'null' description: Whether the subscription is a free trial or purchased. nextLifecycleDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The date and time when the subscription will move to the next state (as defined by the status property) if not renewed by the tenant. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. format: date-time ownerId: type: - string - 'null' description: The object ID of the account admin. ownerTenantId: type: - string - 'null' description: The unique identifier for the Microsoft partner tenant that created the subscription on a customer tenant. ownerType: type: - string - 'null' description: Indicates the entity that ownerId belongs to, for example, 'User'. serviceStatus: type: array items: $ref: '#/components/schemas/microsoft.graph.servicePlanInfo' description: The provisioning status of each service included in this subscription. skuId: type: - string - 'null' description: The object ID of the SKU associated with this subscription. skuPartNumber: type: - string - 'null' description: The SKU associated with this subscription. status: type: - string - 'null' description: 'The status of this subscription. The possible values are: Enabled, Deleted, Suspended, Warning, LockedOut.' totalLicenses: maximum: 2147483647 minimum: -2147483648 type: - number - 'null' description: The number of licenses included in this subscription. format: int32 additionalProperties: type: object microsoft.graph.onPremisesAccidentalDeletionPrevention: title: onPremisesAccidentalDeletionPrevention type: object properties: alertThreshold: maximum: 2147483647 minimum: -2147483648 type: - number - 'null' description: Threshold value which triggers accidental deletion prevention. The threshold is either an absolute number of objects or a percentage number of objects. format: int32 synchronizationPreventionType: $ref: '#/components/schemas/microsoft.graph.onPremisesDirectorySynchronizationDeletionPreventionType' additionalProperties: type: object microsoft.graph.certificateAuthorityType: title: certificateAuthorityType enum: - root - intermediate - unknownFutureValue type: string microsoft.graph.entraRecoveryServices.snapshot: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: snapshot type: object properties: createdDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: string format: date-time totalChangedObjects: maximum: 2147483647 minimum: -2147483648 type: - number - 'null' format: int32 recoveryJobs: type: array items: $ref: '#/components/schemas/microsoft.graph.entraRecoveryServices.recoveryJob' x-ms-navigationProperty: true recoveryPreviewJobs: type: array items: $ref: '#/components/schemas/microsoft.graph.entraRecoveryServices.recoveryPreviewJob' x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.deviceLocalCredential: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: deviceLocalCredential type: object properties: accountName: type: string description: The name of the local admin account for which LAPS is enabled. accountSid: type: string description: The SID of the local admin account for which LAPS is enabled. backupDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: string description: When the local administrator account credential for the device object was backed up to Azure Active Directory. format: date-time passwordBase64: type: string description: The password for the local administrator account that is backed up to Azure Active Directory and returned as a Base64 encoded value. additionalProperties: type: object microsoft.graph.ODataErrors.ErrorDetails: required: - code - message type: object properties: code: type: string message: type: string target: type: - string - 'null' additionalProperties: type: object microsoft.graph.identityProviderBase: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: identityProviderBase type: object properties: displayName: type: - string - 'null' description: The display name of the identity provider. additionalProperties: type: object microsoft.graph.deviceLocalCredentialInfo: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: deviceLocalCredentialInfo type: object properties: credentials: type: array items: $ref: '#/components/schemas/microsoft.graph.deviceLocalCredential' description: The credentials of the device's local administrator account backed up to Azure Active Directory. deviceName: type: string description: Display name of the device that the local credentials are associated with. lastBackupDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: string description: When the local administrator account credential was backed up to Azure Active Directory. format: date-time refreshDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: string description: When the local administrator account credential will be refreshed and backed up to Azure Active Directory. format: date-time additionalProperties: type: object microsoft.graph.servicePlanInfo: title: servicePlanInfo type: object properties: appliesTo: type: - string - 'null' description: The object the service plan can be assigned to. The possible values are:User - service plan can be assigned to individual users.Company - service plan can be assigned to the entire tenant. provisioningStatus: type: - string - 'null' description: The provisioning status of the service plan. The possible values are:Success - Service is fully provisioned.Disabled - Service is disabled.Error - The service plan isn't provisioned and is in an error state.PendingInput - The service isn't provisioned and is awaiting service confirmation.PendingActivation - The service is provisioned but requires explicit activation by an administrator (for example, Intune_O365 service plan)PendingProvisioning - Microsoft has added a new service to the product SKU and it isn't activated in the tenant. servicePlanId: pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$ type: - string - 'null' description: The unique identifier of the service plan. format: uuid servicePlanName: type: - string - 'null' description: The name of the service plan. additionalProperties: type: object microsoft.graph.onPremisesDirectorySynchronizationFeature: title: onPremisesDirectorySynchronizationFeature type: object properties: allowOnPremUpdateOfOnPremisesObjectIdentifierEnabled: type: - boolean - 'null' description: When true, allows on-premises directory sync clients to update the onPremisesObjectIdentifier property. blockCloudObjectTakeoverThroughHardMatchEnabled: type: - boolean - 'null' description: Used to block cloud object takeover via source anchor hard match if enabled. blockSoftMatchEnabled: type: - boolean - 'null' description: Use to block soft match for all objects if enabled for the tenant. Customers are encouraged to enable this feature and keep it enabled until soft matching is required again for their tenancy. This flag should be enabled again after any soft matching has been completed and is no longer needed. bypassDirSyncOverridesEnabled: type: - boolean - 'null' description: When true, persists the values of Mobile and OtherMobile in on-premises AD during sync cycles instead of values of MobilePhone or AlternateMobilePhones in Microsoft Entra ID. cloudPasswordPolicyForPasswordSyncedUsersEnabled: type: - boolean - 'null' description: Used to indicate that cloud password policy applies to users whose passwords are synchronized from on-premises. concurrentCredentialUpdateEnabled: type: - boolean - 'null' description: Used to enable concurrent user credentials update in OrgId. concurrentOrgIdProvisioningEnabled: type: - boolean - 'null' description: Used to enable concurrent user creation in OrgId. deviceWritebackEnabled: type: - boolean - 'null' description: Used to indicate that device write-back is enabled. directoryExtensionsEnabled: type: - boolean - 'null' description: Used to indicate that directory extensions are being synced from on-premises AD to Microsoft Entra ID. fopeConflictResolutionEnabled: type: - boolean - 'null' description: Used to indicate that for a Microsoft Forefront Online Protection for Exchange (FOPE) migrated tenant, the conflicting proxy address should be migrated over. groupWriteBackEnabled: type: - boolean - 'null' description: Used to enable object-level group writeback feature for additional group types. passwordSyncEnabled: type: - boolean - 'null' description: Used to indicate on-premise password synchronization is enabled. passwordWritebackEnabled: type: - boolean - 'null' description: Used to indicate that writeback of password resets from Microsoft Entra ID to on-premises AD is enabled. This property isn't in use and updating it isn't supported. quarantineUponProxyAddressesConflictEnabled: type: - boolean - 'null' description: Used to indicate that we should quarantine objects with conflicting proxy address. quarantineUponUpnConflictEnabled: type: - boolean - 'null' description: Used to indicate that we should quarantine objects conflicting with duplicate userPrincipalName. softMatchOnUpnEnabled: type: - boolean - 'null' description: Used to indicate that we should soft match objects based on userPrincipalName. synchronizeUpnForManagedUsersEnabled: type: - boolean - 'null' description: Used to indicate that we should synchronize userPrincipalName objects for managed users with licenses. unifiedGroupWritebackEnabled: type: - boolean - 'null' description: Used to indicate that Microsoft 365 Group write-back is enabled. userForcePasswordChangeOnLogonEnabled: type: - boolean - 'null' description: Used to indicate that feature to force password change for a user on logon is enabled while synchronizing on-premise credentials. userWritebackEnabled: type: - boolean - 'null' description: Used to indicate that user writeback is enabled. additionalProperties: type: object microsoft.graph.onPremisesDirectorySynchronizationDeletionPreventionType: title: onPremisesDirectorySynchronizationDeletionPreventionType enum: - disabled - enabledForCount - enabledForPercentage - unknownFutureValue type: string microsoft.graph.onPremisesDirectorySynchronizationConfiguration: title: onPremisesDirectorySynchronizationConfiguration type: object properties: accidentalDeletionPrevention: $ref: '#/components/schemas/microsoft.graph.onPremisesAccidentalDeletionPrevention' additionalProperties: type: object microsoft.graph.entraRecoveryServices.recoveryStatus: title: recoveryStatus enum: - initialized - running - successful - failed - abandoned - unknownFutureValue - calculating - loadingData type: string x-ms-enum: name: recoveryStatus modelAsString: false values: - value: initialized description: Represents a job that has been initialized but has not been started yet name: initialized - value: running description: Represents a job that is in progress name: running - value: successful description: Represents a job that ran successfully and is now complete name: successful - value: failed description: Represents a job that we were not able to run successfully name: failed - value: abandoned description: Represents a job that was abandoned by the user name: abandoned - value: unknownFutureValue description: This will help in making this enum evolable and adding more values in the future- name: unknownFutureValue - value: calculating description: Represents a job for which we have started calculating the diff/preview. name: calculating - value: loadingData description: Represents a job for which we have started loading data of the snapshot. name: loadingData microsoft.graph.entraRecoveryServices.recoveryJob: allOf: - $ref: '#/components/schemas/microsoft.graph.entraRecoveryServices.recoveryJobBase' - title: recoveryJob type: object properties: totalFailedChanges: maximum: 2147483647 minimum: -2147483648 type: - number - 'null' format: int32 totalLinksModified: maximum: 2147483647 minimum: -2147483648 type: - number - 'null' format: int32 totalObjectsModified: maximum: 2147483647 minimum: -2147483648 type: - number - 'null' format: int32 additionalProperties: type: object microsoft.graph.allowedValue: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: allowedValue type: object properties: isActive: type: - boolean - 'null' description: Indicates whether the predefined value is active or deactivated. If set to false, this predefined value can't be assigned to any other supported directory objects. additionalProperties: type: object microsoft.graph.extension: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: extension type: object additionalProperties: type: object microsoft.graph.ODataErrors.MainError: required: - code - message type: object properties: code: type: string message: type: string x-ms-primary-error-message: true target: type: - string - 'null' details: type: array items: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails' innerError: $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError' additionalProperties: type: object microsoft.graph.entity: title: entity type: object properties: id: type: string description: The unique identifier for an entity. Read-only. additionalProperties: type: object microsoft.graph.onPremisesDirectorySynchronization: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: onPremisesDirectorySynchronization type: object properties: configuration: $ref: '#/components/schemas/microsoft.graph.onPremisesDirectorySynchronizationConfiguration' features: $ref: '#/components/schemas/microsoft.graph.onPremisesDirectorySynchronizationFeature' additionalProperties: type: object responses: error: description: error content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError' securitySchemes: azureaadv2: type: oauth2 flows: authorizationCode: authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token scopes: {}