openapi: 3.2.0 info: title: Identity.DirectoryManagement Directory Role… version: v1.0 servers: - url: https://graph.microsoft.com/v1.0/ description: Core security: - azureaadv2: [] tags: - name: directoryRoleTemplates.directoryRoleTemplate.Actions paths: /directoryRoleTemplates/{directoryRoleTemplate-id}/microsoft.graph.checkMemberGroups: post: tags: - directoryRoleTemplates.directoryRoleTemplate.Actions summary: Invoke action checkMemberGroups description: 'Check for membership in a specified list of group IDs, and return from that list the IDs of groups where a specified object is a member. The specified object can be of one of the following types: - user - group - service principal - organizational contact - device - directory object This function is transitive. You can check up to a maximum of 20 groups per request. This function supports all groups provisioned in Microsoft Entra ID. Because Microsoft 365 groups cannot contain other groups, membership in a Microsoft 365 group is always direct.' externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/directoryobject-checkmembergroups?view=graph-rest-1.0 operationId: directoryRoleTemplate_checkMemberGroup parameters: - name: directoryRoleTemplate-id in: path description: The unique identifier of directoryRoleTemplate required: true style: simple schema: type: string x-ms-docs-key-type: directoryRoleTemplate requestBody: description: Action parameters content: application/json: schema: type: object properties: groupIds: type: array items: type: string additionalProperties: type: object required: true responses: 2XX: description: Success content: application/json: schema: type: object properties: value: type: array items: type: string '@odata.nextLink': type: - string - 'null' additionalProperties: type: object default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore /directoryRoleTemplates/{directoryRoleTemplate-id}/microsoft.graph.checkMemberObjects: post: tags: - directoryRoleTemplates.directoryRoleTemplate.Actions summary: Invoke action checkMemberObjects operationId: directoryRoleTemplate_checkMemberObject parameters: - name: directoryRoleTemplate-id in: path description: The unique identifier of directoryRoleTemplate required: true style: simple schema: type: string x-ms-docs-key-type: directoryRoleTemplate requestBody: description: Action parameters content: application/json: schema: type: object properties: ids: type: array items: type: string additionalProperties: type: object required: true responses: 2XX: description: Success content: application/json: schema: type: object properties: value: type: array items: type: string '@odata.nextLink': type: - string - 'null' additionalProperties: type: object default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore /directoryRoleTemplates/{directoryRoleTemplate-id}/microsoft.graph.getMemberGroups: post: tags: - directoryRoleTemplates.directoryRoleTemplate.Actions summary: Invoke action getMemberGroups description: Return all the group IDs for the groups that the specified user, group, service principal, organizational contact, device, or directory object is a member of. This function is transitive. This API returns up to 11,000 group IDs. If more than 11,000 results are available, it returns a 400 Bad Request error with the DirectoryResultSizeLimitExceeded error code. If you get the DirectoryResultSizeLimitExceeded error code, use the List group transitive memberOf API instead. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/directoryobject-getmembergroups?view=graph-rest-1.0 operationId: directoryRoleTemplate_getMemberGroup parameters: - name: directoryRoleTemplate-id in: path description: The unique identifier of directoryRoleTemplate required: true style: simple schema: type: string x-ms-docs-key-type: directoryRoleTemplate requestBody: description: Action parameters content: application/json: schema: type: object properties: securityEnabledOnly: type: - boolean - 'null' default: false additionalProperties: type: object required: true responses: 2XX: description: Success content: application/json: schema: type: object properties: value: type: array items: type: string '@odata.nextLink': type: - string - 'null' additionalProperties: type: object default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore /directoryRoleTemplates/{directoryRoleTemplate-id}/microsoft.graph.getMemberObjects: post: tags: - directoryRoleTemplates.directoryRoleTemplate.Actions summary: Invoke action getMemberObjects description: 'Return all IDs for the groups, administrative units, and directory roles that an object of one of the following types is a member of: - user - group - service principal - organizational contact - device - directory object This function is transitive. Only users and role-enabled groups can be members of directory roles.' externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/directoryobject-getmemberobjects?view=graph-rest-1.0 operationId: directoryRoleTemplate_getMemberObject parameters: - name: directoryRoleTemplate-id in: path description: The unique identifier of directoryRoleTemplate required: true style: simple schema: type: string x-ms-docs-key-type: directoryRoleTemplate requestBody: description: Action parameters content: application/json: schema: type: object properties: securityEnabledOnly: type: - boolean - 'null' default: false additionalProperties: type: object required: true responses: 2XX: description: Success content: application/json: schema: type: object properties: value: type: array items: type: string '@odata.nextLink': type: - string - 'null' additionalProperties: type: object default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore /directoryRoleTemplates/{directoryRoleTemplate-id}/microsoft.graph.restore: post: tags: - directoryRoleTemplates.directoryRoleTemplate.Actions summary: Invoke action restore description: 'Restore a recently deleted directory object from deleted items. The following types are supported: - administrativeUnit - application - agentIdentityBlueprint - agentIdentity - agentIdentityBlueprintPrincipal - agentUser - certificateBasedAuthPki - certificateAuthorityDetail - group - servicePrincipal - user If an item is accidentally deleted, you can fully restore the item. Additionally, restoring an application doesn''t automatically restore the associated service principal automatically. You must call this API to explicitly restore the deleted service principal. A recently deleted item remains available for up to 30 days. After 30 days, the item is permanently deleted.' externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/directory-deleteditems-restore?view=graph-rest-1.0 operationId: directoryRoleTemplate_restore parameters: - name: directoryRoleTemplate-id in: path description: The unique identifier of directoryRoleTemplate required: true style: simple schema: type: string x-ms-docs-key-type: directoryRoleTemplate responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.directoryObject' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action /directoryRoleTemplates/microsoft.graph.getAvailableExtensionProperties: post: tags: - directoryRoleTemplates.directoryRoleTemplate.Actions summary: Invoke action getAvailableExtensionProperties description: 'Return all directory extension definitions that are registered in a directory, including through multitenant apps. The following entities support extension properties:' externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/directoryobject-getavailableextensionproperties?view=graph-rest-1.0 operationId: directoryRoleTemplate_getAvailableExtensionProperty requestBody: description: Action parameters content: application/json: schema: type: object properties: isSyncedFromOnPremises: type: - boolean - 'null' default: false additionalProperties: type: object required: true responses: 2XX: description: Success content: application/json: schema: title: Collection of extensionProperty type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.extensionProperty' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore /directoryRoleTemplates/microsoft.graph.getByIds: post: tags: - directoryRoleTemplates.directoryRoleTemplate.Actions summary: Invoke action getByIds description: 'Return the directory objects specified in a list of IDs. Only a subset of user properties are returned by default in v1.0. Some common uses for this function are to:' externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/directoryobject-getbyids?view=graph-rest-1.0 operationId: directoryRoleTemplate_getGraphBPreId requestBody: description: Action parameters content: application/json: schema: type: object properties: ids: type: array items: type: string types: type: array items: type: - string - 'null' additionalProperties: type: object required: true responses: 2XX: description: Success content: application/json: schema: title: Collection of directoryObject type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.directoryObject' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore /directoryRoleTemplates/microsoft.graph.validateProperties: post: tags: - directoryRoleTemplates.directoryRoleTemplate.Actions summary: Invoke action validateProperties description: 'Validate that a Microsoft 365 group''s display name or mail nickname complies with naming policies. Clients can use this API to determine whether a display name or mail nickname is valid before trying to create a Microsoft 365 group. To validate the properties of an existing group, use the group: validateProperties function. The following policy validations are performed for the display name and mail nickname properties: 1. Validate the prefix and suffix naming policy 2. Validate the custom banned words policy 3. Validate that the mail nickname is unique This API only returns the first validation failure that is encountered. If the properties fail multiple validations, only the first validation failure is returned. However, you can validate both the mail nickname and the display name and receive a collection of validation errors if you''re only validating the prefix and suffix naming policy. To learn more about configuring naming policies, see Configure naming policy.' externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/directoryobject-validateproperties?view=graph-rest-1.0 operationId: directoryRoleTemplate_validateProperty requestBody: description: Action parameters content: application/json: schema: type: object properties: entityType: type: - string - 'null' displayName: type: - string - 'null' mailNickname: type: - string - 'null' onBehalfOfUserId: pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$ type: - string - 'null' format: uuid additionalProperties: type: object required: true responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action components: schemas: microsoft.graph.ODataErrors.InnerError: type: object additionalProperties: type: object description: The structure of this object is service-specific microsoft.graph.directoryObject: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: directoryObject type: object properties: deletedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: Date and time when this object was deleted. Always null when the object hasn't been deleted. format: date-time additionalProperties: type: object microsoft.graph.ODataErrors.ErrorDetails: required: - code - message type: object properties: code: type: string message: type: string target: type: - string - 'null' additionalProperties: type: object microsoft.graph.ODataErrors.MainError: required: - code - message type: object properties: code: type: string message: type: string x-ms-primary-error-message: true target: type: - string - 'null' details: type: array items: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails' innerError: $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError' additionalProperties: type: object microsoft.graph.ODataErrors.ODataError: required: - error type: object properties: error: $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError' additionalProperties: type: object microsoft.graph.entity: title: entity type: object properties: id: type: string description: The unique identifier for an entity. Read-only. additionalProperties: type: object microsoft.graph.extensionProperty: allOf: - $ref: '#/components/schemas/microsoft.graph.directoryObject' - title: extensionProperty type: object properties: appDisplayName: type: - string - 'null' description: Display name of the application object on which this extension property is defined. Read-only. dataType: type: string description: Specifies the data type of the value the extension property can hold. Following values are supported. Binary - 256 bytes maximumBooleanDateTime - Must be specified in ISO 8601 format. Will be stored in UTC.Integer - 32-bit value.LargeInteger - 64-bit value.String - 256 characters maximumNot nullable. For multivalued directory extensions, these limits apply per value in the collection. isMultiValued: type: boolean description: 'Defines the directory extension as a multi-valued property. When true, the directory extension property can store a collection of objects of the dataType; for example, a collection of string types such as ''extensionb7b1c57b532f40b8b5ed4b7a7ba67401jobGroupTracker'': [''String 1'', ''String 2'']. The default value is false. Supports $filter (eq).' isSyncedFromOnPremises: type: - boolean - 'null' description: Indicates if this extension property was synced from on-premises active directory using Microsoft Entra Connect. Read-only. name: type: string description: Name of the extension property. Not nullable. Supports $filter (eq). targetObjects: type: array items: type: string description: Following values are supported. Not nullable. UserGroupAdministrativeUnitApplicationDeviceOrganization additionalProperties: type: object responses: error: description: error content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError' securitySchemes: azureaadv2: type: oauth2 flows: authorizationCode: authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token scopes: {}