openapi: 3.2.0 info: title: Identity.DirectoryManagement Domains.internal Domain… version: v1.0 servers: - url: https://graph.microsoft.com/v1.0/ description: Core security: - azureaadv2: [] tags: - name: domains.internalDomainFederation paths: /domains/{domain-id}/federationConfiguration: get: tags: - domains.internalDomainFederation summary: List internalDomainFederations description: Read the properties of the internalDomainFederation objects for the domain. This API returns only one object in the collection. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/domain-list-federationconfiguration?view=graph-rest-1.0 operationId: domain_ListFederationConfiguration parameters: - name: domain-id in: path description: The unique identifier of domain required: true style: simple schema: type: string x-ms-docs-key-type: domain - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.internalDomainFederationCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - domains.internalDomainFederation summary: Create internalDomainFederation description: Create a new internalDomainFederation object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/domain-post-federationconfiguration?view=graph-rest-1.0 operationId: domain_CreateFederationConfiguration parameters: - name: domain-id in: path description: The unique identifier of domain required: true style: simple schema: type: string x-ms-docs-key-type: domain requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.internalDomainFederation' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.internalDomainFederation' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /domains/{domain-id}/federationConfiguration/{internalDomainFederation-id}: get: tags: - domains.internalDomainFederation summary: Get internalDomainFederation description: Read the properties and relationships of an internalDomainFederation object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/internaldomainfederation-get?view=graph-rest-1.0 operationId: domain_GetFederationConfiguration parameters: - name: domain-id in: path description: The unique identifier of domain required: true style: simple schema: type: string x-ms-docs-key-type: domain - name: internalDomainFederation-id in: path description: The unique identifier of internalDomainFederation required: true style: simple schema: type: string x-ms-docs-key-type: internalDomainFederation - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.internalDomainFederation' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - domains.internalDomainFederation summary: Update internalDomainFederation description: Update the properties of an internalDomainFederation object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/internaldomainfederation-update?view=graph-rest-1.0 operationId: domain_UpdateFederationConfiguration parameters: - name: domain-id in: path description: The unique identifier of domain required: true style: simple schema: type: string x-ms-docs-key-type: domain - name: internalDomainFederation-id in: path description: The unique identifier of internalDomainFederation required: true style: simple schema: type: string x-ms-docs-key-type: internalDomainFederation requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.internalDomainFederation' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.internalDomainFederation' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - domains.internalDomainFederation summary: Delete internalDomainFederation description: Delete an internalDomainFederation object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/internaldomainfederation-delete?view=graph-rest-1.0 operationId: domain_DeleteFederationConfiguration parameters: - name: domain-id in: path description: The unique identifier of domain required: true style: simple schema: type: string x-ms-docs-key-type: domain - name: internalDomainFederation-id in: path description: The unique identifier of internalDomainFederation required: true style: simple schema: type: string x-ms-docs-key-type: internalDomainFederation - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /domains/{domain-id}/federationConfiguration/$count: get: tags: - domains.internalDomainFederation summary: Get the number of the resource operationId: domain.federationConfiguration_GetCount parameters: - name: domain-id in: path description: The unique identifier of domain required: true style: simple schema: type: string x-ms-docs-key-type: domain - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' components: parameters: count: name: $count in: query description: Include count of items style: form explode: false schema: type: boolean filter: name: $filter in: query description: Filter items by property values style: form explode: false schema: type: string search: name: $search in: query description: Search items by search phrases style: form explode: false schema: type: string skip: name: $skip in: query description: Skip the first n items style: form explode: false schema: minimum: 0 type: integer top: name: $top in: query description: Show only the first n items style: form explode: false schema: minimum: 0 type: integer example: 50 schemas: microsoft.graph.ODataErrors.ODataError: required: - error type: object properties: error: $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError' additionalProperties: type: object microsoft.graph.internalDomainFederation: allOf: - $ref: '#/components/schemas/microsoft.graph.samlOrWsFedProvider' - title: internalDomainFederation type: object properties: activeSignInUri: type: - string - 'null' description: URL of the endpoint used by active clients when authenticating with federated domains set up for single sign-on in Microsoft Entra ID. Corresponds to the ActiveLogOnUri property of the Set-EntraDomainFederationSettings PowerShell cmdlet. federatedIdpMfaBehavior: $ref: '#/components/schemas/microsoft.graph.federatedIdpMfaBehavior' isSignedAuthenticationRequestRequired: type: - boolean - 'null' description: If true, when SAML authentication requests are sent to the federated SAML IdP, Microsoft Entra ID will sign those requests using the OrgID signing key. If false (default), the SAML authentication requests sent to the federated IdP aren't signed. nextSigningCertificate: type: - string - 'null' description: Fallback token signing certificate that can also be used to sign tokens, for example when the primary signing certificate expires. Formatted as Base64 encoded strings of the public portion of the federated IdP's token signing certificate. Needs to be compatible with the X509Certificate2 class. Much like the signingCertificate, the nextSigningCertificate property is used if a rollover is required outside of the auto-rollover update, a new federation service is being set up, or if the new token signing certificate isn't present in the federation properties after the federation service certificate has been updated. passwordResetUri: type: - string - 'null' promptLoginBehavior: $ref: '#/components/schemas/microsoft.graph.promptLoginBehavior' signingCertificateUpdateStatus: $ref: '#/components/schemas/microsoft.graph.signingCertificateUpdateStatus' signOutUri: type: - string - 'null' description: URI that clients are redirected to when they sign out of Microsoft Entra services. Corresponds to the LogOffUri property of the Set-EntraDomainFederationSettings PowerShell cmdlet. additionalProperties: type: object microsoft.graph.promptLoginBehavior: title: promptLoginBehavior enum: - translateToFreshPasswordAuthentication - nativeSupport - disabled - unknownFutureValue type: string microsoft.graph.internalDomainFederationCollectionResponse: title: Collection of internalDomainFederation type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.internalDomainFederation' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.ODataErrors.InnerError: type: object additionalProperties: type: object description: The structure of this object is service-specific microsoft.graph.federatedIdpMfaBehavior: title: federatedIdpMfaBehavior enum: - acceptIfMfaDoneByFederatedIdp - enforceMfaByFederatedIdp - rejectMfaByFederatedIdp - unknownFutureValue type: string microsoft.graph.authenticationProtocol: title: authenticationProtocol enum: - wsFed - saml - unknownFutureValue type: string microsoft.graph.signingCertificateUpdateStatus: title: signingCertificateUpdateStatus type: object properties: certificateUpdateResult: type: - string - 'null' description: Status of the last certificate update. Read-only. For a list of statuses, see certificateUpdateResult status. lastRunDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: Date and time in ISO 8601 format and in UTC time when the certificate was last updated. Read-only. format: date-time additionalProperties: type: object microsoft.graph.ODataErrors.ErrorDetails: required: - code - message type: object properties: code: type: string message: type: string target: type: - string - 'null' additionalProperties: type: object microsoft.graph.identityProviderBase: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: identityProviderBase type: object properties: displayName: type: - string - 'null' description: The display name of the identity provider. additionalProperties: type: object microsoft.graph.ODataErrors.MainError: required: - code - message type: object properties: code: type: string message: type: string x-ms-primary-error-message: true target: type: - string - 'null' details: type: array items: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails' innerError: $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError' additionalProperties: type: object microsoft.graph.samlOrWsFedProvider: allOf: - $ref: '#/components/schemas/microsoft.graph.identityProviderBase' - title: samlOrWsFedProvider type: object properties: issuerUri: type: - string - 'null' description: Issuer URI of the federation server. metadataExchangeUri: type: - string - 'null' description: URI of the metadata exchange endpoint used for authentication from rich client applications. passiveSignInUri: type: - string - 'null' description: URI that web-based clients are directed to when signing in to Microsoft Entra services. preferredAuthenticationProtocol: $ref: '#/components/schemas/microsoft.graph.authenticationProtocol' signingCertificate: type: - string - 'null' description: 'Current certificate used to sign tokens passed to the Microsoft identity platform. The certificate is formatted as a Base64 encoded string of the public portion of the federated IdP''s token signing certificate and must be compatible with the X509Certificate2 class. This property is used in the following scenarios: if a rollover is required outside of the autorollover update a new federation service is being set up if the new token signing certificate isn''t present in the federation properties after the federation service certificate has been updated. Microsoft Entra ID updates certificates via an autorollover process in which it attempts to retrieve a new certificate from the federation service metadata, 30 days before expiry of the current certificate. If a new certificate isn''t available, Microsoft Entra ID monitors the metadata daily and will update the federation settings for the domain when a new certificate is available.' additionalProperties: type: object microsoft.graph.entity: title: entity type: object properties: id: type: string description: The unique identifier for an entity. Read-only. additionalProperties: type: object ODataCountResponse: type: integer format: int32 responses: ODataCountResponse: description: The count of the resource content: text/plain: schema: $ref: '#/components/schemas/ODataCountResponse' error: description: error content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError' microsoft.graph.internalDomainFederationCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.internalDomainFederationCollectionResponse' securitySchemes: azureaadv2: type: oauth2 flows: authorizationCode: authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token scopes: {}