openapi: 3.2.0 info: title: Azure Ad Directory.public Key Infrastructure Root API version: v1.0 description: 'Operations tagged directory.publicKeyInfrastructureRoot across 2 of this provider''s published API definitions: azure-ad-graph-directoryobjects-openapi.yml, azure-ad-graph-identity-directorymanagement-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: https://graph.microsoft.com/v1.0/ description: Core security: - azureaadv2: [] tags: - name: directory.publicKeyInfrastructureRoot paths: /directory/publicKeyInfrastructure: get: tags: - directory.publicKeyInfrastructureRoot summary: Get publicKeyInfrastructure from directory description: The collection of public key infrastructure instances for the certificate-based authentication feature for users in a Microsoft Entra tenant. operationId: directory_GetPublicKeyInfrastructure parameters: - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.publicKeyInfrastructureRoot' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - directory.publicKeyInfrastructureRoot summary: Update the navigation property publicKeyInfrastructure in directory operationId: directory_UpdatePublicKeyInfrastructure requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.publicKeyInfrastructureRoot' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.publicKeyInfrastructureRoot' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - directory.publicKeyInfrastructureRoot summary: Delete navigation property publicKeyInfrastructure for directory operationId: directory_DeletePublicKeyInfrastructure parameters: - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation servers: - url: https://graph.microsoft.com/v1.0/ description: Core /directory/publicKeyInfrastructure/certificateBasedAuthConfigurations: get: tags: - directory.publicKeyInfrastructureRoot summary: List certificateBasedAuthPki objects description: Get a list of the certificateBasedAuthPki objects and their properties. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/publickeyinfrastructureroot-list-certificatebasedauthconfigurations?view=graph-rest-1.0 operationId: directory.publicKeyInfrastructure_ListCertificateBasedAuthConfiguration parameters: - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.certificateBasedAuthPkiCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - directory.publicKeyInfrastructureRoot summary: Create certificateBasedAuthPki description: Create a new certificateBasedAuthPki object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/publickeyinfrastructureroot-post-certificatebasedauthconfigurations?view=graph-rest-1.0 operationId: directory.publicKeyInfrastructure_CreateCertificateBasedAuthConfiguration requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.certificateBasedAuthPki' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.certificateBasedAuthPki' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation servers: - url: https://graph.microsoft.com/v1.0/ description: Core /directory/publicKeyInfrastructure/certificateBasedAuthConfigurations/{certificateBasedAuthPki-id}: get: tags: - directory.publicKeyInfrastructureRoot summary: Get certificateBasedAuthPki description: Read the properties and relationships of a certificateBasedAuthPki object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/certificatebasedauthpki-get?view=graph-rest-1.0 operationId: directory.publicKeyInfrastructure_GetCertificateBasedAuthConfiguration parameters: - name: certificateBasedAuthPki-id in: path description: The unique identifier of certificateBasedAuthPki required: true style: simple schema: type: string x-ms-docs-key-type: certificateBasedAuthPki - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.certificateBasedAuthPki' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - directory.publicKeyInfrastructureRoot summary: Update certificateBasedAuthPki description: Update the properties of a certificateBasedAuthPki object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/certificatebasedauthpki-update?view=graph-rest-1.0 operationId: directory.publicKeyInfrastructure_UpdateCertificateBasedAuthConfiguration parameters: - name: certificateBasedAuthPki-id in: path description: The unique identifier of certificateBasedAuthPki required: true style: simple schema: type: string x-ms-docs-key-type: certificateBasedAuthPki requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.certificateBasedAuthPki' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.certificateBasedAuthPki' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - directory.publicKeyInfrastructureRoot summary: Delete certificateBasedAuthPki description: Delete a certificateBasedAuthPki object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/publickeyinfrastructureroot-delete-certificatebasedauthconfigurations?view=graph-rest-1.0 operationId: directory.publicKeyInfrastructure_DeleteCertificateBasedAuthConfiguration parameters: - name: certificateBasedAuthPki-id in: path description: The unique identifier of certificateBasedAuthPki required: true style: simple schema: type: string x-ms-docs-key-type: certificateBasedAuthPki - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation servers: - url: https://graph.microsoft.com/v1.0/ description: Core /directory/publicKeyInfrastructure/certificateBasedAuthConfigurations/{certificateBasedAuthPki-id}/certificateAuthorities: get: tags: - directory.publicKeyInfrastructureRoot summary: List certificateAuthorityDetail objects description: Get a list of the certificateAuthorityDetail objects and their properties. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/certificatebasedauthpki-list-certificateauthorities?view=graph-rest-1.0 operationId: directory.publicKeyInfrastructure.certificateBasedAuthConfiguration_ListCertificateAuthority parameters: - name: certificateBasedAuthPki-id in: path description: The unique identifier of certificateBasedAuthPki required: true style: simple schema: type: string x-ms-docs-key-type: certificateBasedAuthPki - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.certificateAuthorityDetailCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - directory.publicKeyInfrastructureRoot summary: Create certificateAuthorityDetail description: Create a new certificateAuthorityDetail object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/certificatebasedauthpki-post-certificateauthorities?view=graph-rest-1.0 operationId: directory.publicKeyInfrastructure.certificateBasedAuthConfiguration_CreateCertificateAuthority parameters: - name: certificateBasedAuthPki-id in: path description: The unique identifier of certificateBasedAuthPki required: true style: simple schema: type: string x-ms-docs-key-type: certificateBasedAuthPki requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.certificateAuthorityDetail' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.certificateAuthorityDetail' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation servers: - url: https://graph.microsoft.com/v1.0/ description: Core ? /directory/publicKeyInfrastructure/certificateBasedAuthConfigurations/{certificateBasedAuthPki-id}/certificateAuthorities/{certificateAuthorityDetail-id} : get: tags: - directory.publicKeyInfrastructureRoot summary: Get certificateAuthorities from directory description: The collection of certificate authorities contained in this public key infrastructure resource. operationId: directory.publicKeyInfrastructure.certificateBasedAuthConfiguration_GetCertificateAuthority parameters: - name: certificateBasedAuthPki-id in: path description: The unique identifier of certificateBasedAuthPki required: true style: simple schema: type: string x-ms-docs-key-type: certificateBasedAuthPki - name: certificateAuthorityDetail-id in: path description: The unique identifier of certificateAuthorityDetail required: true style: simple schema: type: string x-ms-docs-key-type: certificateAuthorityDetail - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.certificateAuthorityDetail' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - directory.publicKeyInfrastructureRoot summary: Update certificateAuthorityDetail externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/certificateauthoritydetail-update?view=graph-rest-1.0 operationId: directory.publicKeyInfrastructure.certificateBasedAuthConfiguration_UpdateCertificateAuthority parameters: - name: certificateBasedAuthPki-id in: path description: The unique identifier of certificateBasedAuthPki required: true style: simple schema: type: string x-ms-docs-key-type: certificateBasedAuthPki - name: certificateAuthorityDetail-id in: path description: The unique identifier of certificateAuthorityDetail required: true style: simple schema: type: string x-ms-docs-key-type: certificateAuthorityDetail requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.certificateAuthorityDetail' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.certificateAuthorityDetail' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - directory.publicKeyInfrastructureRoot summary: Delete certificateAuthorityDetail description: Delete a certificateAuthorityDetail object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/certificatebasedauthpki-delete-certificateauthorities?view=graph-rest-1.0 operationId: directory.publicKeyInfrastructure.certificateBasedAuthConfiguration_DeleteCertificateAuthority parameters: - name: certificateBasedAuthPki-id in: path description: The unique identifier of certificateBasedAuthPki required: true style: simple schema: type: string x-ms-docs-key-type: certificateBasedAuthPki - name: certificateAuthorityDetail-id in: path description: The unique identifier of certificateAuthorityDetail required: true style: simple schema: type: string x-ms-docs-key-type: certificateAuthorityDetail - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation servers: - url: https://graph.microsoft.com/v1.0/ description: Core ? /directory/publicKeyInfrastructure/certificateBasedAuthConfigurations/{certificateBasedAuthPki-id}/certificateAuthorities/$count : get: tags: - directory.publicKeyInfrastructureRoot summary: Get the number of the resource operationId: directory.publicKeyInfrastructure.certificateBasedAuthConfiguration.certificateAuthority_GetCount parameters: - name: certificateBasedAuthPki-id in: path description: The unique identifier of certificateBasedAuthPki required: true style: simple schema: type: string x-ms-docs-key-type: certificateBasedAuthPki - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' servers: - url: https://graph.microsoft.com/v1.0/ description: Core /directory/publicKeyInfrastructure/certificateBasedAuthConfigurations/{certificateBasedAuthPki-id}/microsoft.graph.upload: post: tags: - directory.publicKeyInfrastructureRoot summary: Invoke action upload description: Append additional certificate authority details to a certificateBasedAuthPki resource. Only one operation can run at a time and this operation can take up to 30 minutes to complete. To know whether another upload is in progress, call the Get certificateBasedAuthPki. The status property will have the value running. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/certificatebasedauthpki-upload?view=graph-rest-1.0 operationId: directory.publicKeyInfrastructure.certificateBasedAuthConfiguration_upload parameters: - name: certificateBasedAuthPki-id in: path description: The unique identifier of certificateBasedAuthPki required: true style: simple schema: type: string x-ms-docs-key-type: certificateBasedAuthPki requestBody: description: Action parameters content: application/json: schema: type: object properties: uploadUrl: type: string sha256FileHash: type: string additionalProperties: type: object required: true responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action servers: - url: https://graph.microsoft.com/v1.0/ description: Core /directory/publicKeyInfrastructure/certificateBasedAuthConfigurations/$count: get: tags: - directory.publicKeyInfrastructureRoot summary: Get the number of the resource operationId: directory.publicKeyInfrastructure.certificateBasedAuthConfiguration_GetCount parameters: - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' servers: - url: https://graph.microsoft.com/v1.0/ description: Core components: schemas: microsoft.graph.certificateBasedAuthPki: allOf: - $ref: '#/components/schemas/microsoft.graph.directoryObject' - title: certificateBasedAuthPki type: object properties: displayName: type: - string - 'null' description: The name of the object. Maximum length is 256 characters. lastModifiedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: string description: The date and time when the object was created or last modified. format: date-time status: type: - string - 'null' description: The status of any asynchronous jobs runs on the object which can be upload or delete. statusDetails: type: - string - 'null' description: The status details of the upload/deleted operation of PKI (Public Key Infrastructure). certificateAuthorities: type: array items: $ref: '#/components/schemas/microsoft.graph.certificateAuthorityDetail' description: The collection of certificate authorities contained in this public key infrastructure resource. x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.publicKeyInfrastructureRoot: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: publicKeyInfrastructureRoot type: object properties: certificateBasedAuthConfigurations: type: array items: $ref: '#/components/schemas/microsoft.graph.certificateBasedAuthPki' description: The collection of public key infrastructure instances for the certificate-based authentication feature for users. x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.ODataErrors.ODataError: required: - error type: object properties: error: $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError' additionalProperties: type: object microsoft.graph.certificateAuthorityDetail: allOf: - $ref: '#/components/schemas/microsoft.graph.directoryObject' - title: certificateAuthorityDetail type: object properties: certificate: type: string description: The public key of the certificate authority. format: base64url certificateAuthorityType: $ref: '#/components/schemas/microsoft.graph.certificateAuthorityType' certificateRevocationListUrl: type: - string - 'null' description: The URL to check if the certificate is revoked. createdDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The date and time when the certificate authority was created. format: date-time deltaCertificateRevocationListUrl: type: - string - 'null' displayName: type: - string - 'null' description: The display name of the certificate authority. expirationDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: string description: The date and time when the certificate authority expires. Supports $filter (eq) and $orderby. format: date-time isIssuerHintEnabled: type: - boolean - 'null' description: Indicates whether the certificate picker presents the certificate authority to the user to use for authentication. Default value is false. Optional. issuer: type: - string - 'null' description: The issuer of the certificate authority. issuerSubjectKeyIdentifier: type: - string - 'null' description: The subject key identifier of certificate authority. thumbprint: type: string description: The thumbprint of certificate authority certificate. Supports $filter (eq, startswith). additionalProperties: type: object microsoft.graph.ODataErrors.InnerError: type: object additionalProperties: type: object description: The structure of this object is service-specific microsoft.graph.directoryObject: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: directoryObject type: object properties: deletedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: Date and time when this object was deleted. Always null when the object hasn't been deleted. format: date-time additionalProperties: type: object microsoft.graph.certificateAuthorityType: title: certificateAuthorityType enum: - root - intermediate - unknownFutureValue type: string microsoft.graph.certificateBasedAuthPkiCollectionResponse: title: Collection of certificateBasedAuthPki type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.certificateBasedAuthPki' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.ODataErrors.ErrorDetails: required: - code - message type: object properties: code: type: string message: type: string target: type: - string - 'null' additionalProperties: type: object microsoft.graph.certificateAuthorityDetailCollectionResponse: title: Collection of certificateAuthorityDetail type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.certificateAuthorityDetail' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.ODataErrors.MainError: required: - code - message type: object properties: code: type: string message: type: string x-ms-primary-error-message: true target: type: - string - 'null' details: type: array items: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails' innerError: $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError' additionalProperties: type: object microsoft.graph.entity: title: entity type: object properties: id: type: string description: The unique identifier for an entity. Read-only. additionalProperties: type: object ODataCountResponse: type: integer format: int32 parameters: count: name: $count in: query description: Include count of items style: form explode: false schema: type: boolean filter: name: $filter in: query description: Filter items by property values style: form explode: false schema: type: string search: name: $search in: query description: Search items by search phrases style: form explode: false schema: type: string skip: name: $skip in: query description: Skip the first n items style: form explode: false schema: minimum: 0 type: integer top: name: $top in: query description: Show only the first n items style: form explode: false schema: minimum: 0 type: integer example: 50 responses: ODataCountResponse: description: The count of the resource content: text/plain: schema: $ref: '#/components/schemas/ODataCountResponse' microsoft.graph.certificateAuthorityDetailCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.certificateAuthorityDetailCollectionResponse' microsoft.graph.certificateBasedAuthPkiCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.certificateBasedAuthPkiCollectionResponse' error: description: error content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError' securitySchemes: azureaadv2: type: oauth2 flows: authorizationCode: authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token scopes: {} x-refined-from: - azure-ad-graph-directoryobjects-openapi.yml - azure-ad-graph-identity-directorymanagement-openapi.yml