openapi: 3.2.0 info: title: Identity.SignIns Identity.conditional Access Root API version: v1.0 servers: - url: https://graph.microsoft.com/v1.0/ description: Core security: - azureaadv2: [] tags: - name: identity.conditionalAccessRoot paths: /identity/conditionalAccess/authenticationContextClassReferences: get: tags: - identity.conditionalAccessRoot summary: List authenticationContextClassReferences description: Retrieve a list of authenticationContextClassReference objects. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/conditionalaccessroot-list-authenticationcontextclassreferences?view=graph-rest-1.0 operationId: identity.conditionalAccess_ListAuthenticationContextClassReference parameters: - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.authenticationContextClassReferenceCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - identity.conditionalAccessRoot summary: Create new navigation property to authenticationContextClassReferences for… operationId: identity.conditionalAccess_CreateAuthenticationContextClassReference requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationContextClassReference' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationContextClassReference' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identity/conditionalAccess/authenticationContextClassReferences/{authenticationContextClassReference-id}: get: tags: - identity.conditionalAccessRoot summary: Get authenticationContextClassReference description: Retrieve the properties and relationships of a authenticationContextClassReference object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/authenticationcontextclassreference-get?view=graph-rest-1.0 operationId: identity.conditionalAccess_GetAuthenticationContextClassReference parameters: - name: authenticationContextClassReference-id in: path description: The unique identifier of authenticationContextClassReference required: true style: simple schema: type: string x-ms-docs-key-type: authenticationContextClassReference - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationContextClassReference' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - identity.conditionalAccessRoot summary: Create or Update authenticationContextClassReference description: Create an authenticationContextClassReference object, if the ID has not been used. If ID has been used, this call updates the authenticationContextClassReference object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/authenticationcontextclassreference-update?view=graph-rest-1.0 operationId: identity.conditionalAccess_UpdateAuthenticationContextClassReference parameters: - name: authenticationContextClassReference-id in: path description: The unique identifier of authenticationContextClassReference required: true style: simple schema: type: string x-ms-docs-key-type: authenticationContextClassReference requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationContextClassReference' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationContextClassReference' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - identity.conditionalAccessRoot summary: Delete authenticationContextClassReference description: Delete an authenticationContextClassReference object that's not published or used by a conditional access policy. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/authenticationcontextclassreference-delete?view=graph-rest-1.0 operationId: identity.conditionalAccess_DeleteAuthenticationContextClassReference parameters: - name: authenticationContextClassReference-id in: path description: The unique identifier of authenticationContextClassReference required: true style: simple schema: type: string x-ms-docs-key-type: authenticationContextClassReference - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identity/conditionalAccess/authenticationContextClassReferences/$count: get: tags: - identity.conditionalAccessRoot summary: Get the number of the resource operationId: identity.conditionalAccess.authenticationContextClassReference_GetCount parameters: - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' /identity/conditionalAccess/authenticationStrength: get: tags: - identity.conditionalAccessRoot summary: Get authenticationStrength from identity operationId: identity.conditionalAccess_GetAuthenticationStrength parameters: - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthRoot' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - identity.conditionalAccessRoot summary: Update the navigation property authenticationStrength in identity operationId: identity.conditionalAccess_UpdateAuthenticationStrength requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthRoot' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthRoot' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - identity.conditionalAccessRoot summary: Delete navigation property authenticationStrength for identity operationId: identity.conditionalAccess_DeleteAuthenticationStrength parameters: - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identity/conditionalAccess/authenticationStrength/authenticationMethodModes: get: tags: - identity.conditionalAccessRoot summary: List authenticationMethodModes description: Get a list of all supported authentication methods, or all supported authentication method combinations as a list of authenticationMethodModes objects and their properties. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/authenticationstrengthroot-list-authenticationmethodmodes?view=graph-rest-1.0 operationId: identity.conditionalAccess.authenticationStrength_ListAuthenticationMethodMode parameters: - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.authenticationMethodModeDetailCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - identity.conditionalAccessRoot summary: Create new navigation property to authenticationMethodModes for identity operationId: identity.conditionalAccess.authenticationStrength_CreateAuthenticationMethodMode requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModeDetail' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModeDetail' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identity/conditionalAccess/authenticationStrength/authenticationMethodModes/{authenticationMethodModeDetail-id}: get: tags: - identity.conditionalAccessRoot summary: Get authenticationMethodModes from identity description: Names and descriptions of all valid authentication method modes in the system. operationId: identity.conditionalAccess.authenticationStrength_GetAuthenticationMethodMode parameters: - name: authenticationMethodModeDetail-id in: path description: The unique identifier of authenticationMethodModeDetail required: true style: simple schema: type: string x-ms-docs-key-type: authenticationMethodModeDetail - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModeDetail' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - identity.conditionalAccessRoot summary: Update the navigation property authenticationMethodModes in identity operationId: identity.conditionalAccess.authenticationStrength_UpdateAuthenticationMethodMode parameters: - name: authenticationMethodModeDetail-id in: path description: The unique identifier of authenticationMethodModeDetail required: true style: simple schema: type: string x-ms-docs-key-type: authenticationMethodModeDetail requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModeDetail' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModeDetail' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - identity.conditionalAccessRoot summary: Delete navigation property authenticationMethodModes for identity operationId: identity.conditionalAccess.authenticationStrength_DeleteAuthenticationMethodMode parameters: - name: authenticationMethodModeDetail-id in: path description: The unique identifier of authenticationMethodModeDetail required: true style: simple schema: type: string x-ms-docs-key-type: authenticationMethodModeDetail - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identity/conditionalAccess/authenticationStrength/authenticationMethodModes/$count: get: tags: - identity.conditionalAccessRoot summary: Get the number of the resource operationId: identity.conditionalAccess.authenticationStrength.authenticationMethodMode_GetCount parameters: - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' /identity/conditionalAccess/authenticationStrength/policies: get: tags: - identity.conditionalAccessRoot summary: Get policies from identity description: A collection of authentication strength policies that exist for this tenant, including both built-in and custom policies. operationId: identity.conditionalAccess.authenticationStrength_ListPolicy parameters: - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.authenticationStrengthPolicyCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - identity.conditionalAccessRoot summary: Create new navigation property to policies for identity operationId: identity.conditionalAccess.authenticationStrength_CreatePolicy requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicy' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicy' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}: get: tags: - identity.conditionalAccessRoot summary: Get policies from identity description: A collection of authentication strength policies that exist for this tenant, including both built-in and custom policies. operationId: identity.conditionalAccess.authenticationStrength_GetPolicy parameters: - name: authenticationStrengthPolicy-id in: path description: The unique identifier of authenticationStrengthPolicy required: true style: simple schema: type: string x-ms-docs-key-type: authenticationStrengthPolicy - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicy' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - identity.conditionalAccessRoot summary: Update the navigation property policies in identity operationId: identity.conditionalAccess.authenticationStrength_UpdatePolicy parameters: - name: authenticationStrengthPolicy-id in: path description: The unique identifier of authenticationStrengthPolicy required: true style: simple schema: type: string x-ms-docs-key-type: authenticationStrengthPolicy requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicy' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicy' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - identity.conditionalAccessRoot summary: Delete navigation property policies for identity operationId: identity.conditionalAccess.authenticationStrength_DeletePolicy parameters: - name: authenticationStrengthPolicy-id in: path description: The unique identifier of authenticationStrengthPolicy required: true style: simple schema: type: string x-ms-docs-key-type: authenticationStrengthPolicy - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}/combinationConfigurations: get: tags: - identity.conditionalAccessRoot summary: List combinationConfigurations description: 'Get the authenticationCombinationConfiguration objects for an authentication strength policy. The objects can be of one or more of the following derived types: * fido2combinationConfigurations * x509certificatecombinationconfiguration authenticationCombinationConfiguration objects are supported only for custom authentication strengths.' externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/authenticationstrengthpolicy-list-combinationconfigurations?view=graph-rest-1.0 operationId: identity.conditionalAccess.authenticationStrength.policy_ListCombinationConfiguration parameters: - name: authenticationStrengthPolicy-id in: path description: The unique identifier of authenticationStrengthPolicy required: true style: simple schema: type: string x-ms-docs-key-type: authenticationStrengthPolicy - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.authenticationCombinationConfigurationCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - identity.conditionalAccessRoot summary: Create authenticationCombinationConfiguration description: 'Create a new authenticationCombinationConfiguration object which can be of one of the following derived types: * fido2combinationConfiguration * x509certificatecombinationconfiguration' externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/authenticationstrengthpolicy-post-combinationconfigurations?view=graph-rest-1.0 operationId: identity.conditionalAccess.authenticationStrength.policy_CreateCombinationConfiguration parameters: - name: authenticationStrengthPolicy-id in: path description: The unique identifier of authenticationStrengthPolicy required: true style: simple schema: type: string x-ms-docs-key-type: authenticationStrengthPolicy requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationCombinationConfiguration' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationCombinationConfiguration' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation ? /identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}/combinationConfigurations/{authenticationCombinationConfiguration-id} : get: tags: - identity.conditionalAccessRoot summary: Get authenticationCombinationConfiguration description: Read the properties and relationships of an authenticationCombinationConfiguration object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/authenticationcombinationconfiguration-get?view=graph-rest-1.0 operationId: identity.conditionalAccess.authenticationStrength.policy_GetCombinationConfiguration parameters: - name: authenticationStrengthPolicy-id in: path description: The unique identifier of authenticationStrengthPolicy required: true style: simple schema: type: string x-ms-docs-key-type: authenticationStrengthPolicy - name: authenticationCombinationConfiguration-id in: path description: The unique identifier of authenticationCombinationConfiguration required: true style: simple schema: type: string x-ms-docs-key-type: authenticationCombinationConfiguration - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationCombinationConfiguration' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - identity.conditionalAccessRoot summary: Update authenticationCombinationConfiguration description: 'Update the properties of an authenticationCombinationConfiguration object. The properties can be for one of the following derived types: * fido2combinationConfigurations * x509certificatecombinationconfiguration' externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/authenticationcombinationconfiguration-update?view=graph-rest-1.0 operationId: identity.conditionalAccess.authenticationStrength.policy_UpdateCombinationConfiguration parameters: - name: authenticationStrengthPolicy-id in: path description: The unique identifier of authenticationStrengthPolicy required: true style: simple schema: type: string x-ms-docs-key-type: authenticationStrengthPolicy - name: authenticationCombinationConfiguration-id in: path description: The unique identifier of authenticationCombinationConfiguration required: true style: simple schema: type: string x-ms-docs-key-type: authenticationCombinationConfiguration requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationCombinationConfiguration' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationCombinationConfiguration' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - identity.conditionalAccessRoot summary: Delete authenticationCombinationConfiguration description: Delete an authenticationCombinationConfiguration for a custom authenticationStrengthPolicy object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/authenticationstrengthpolicy-delete-combinationconfigurations?view=graph-rest-1.0 operationId: identity.conditionalAccess.authenticationStrength.policy_DeleteCombinationConfiguration parameters: - name: authenticationStrengthPolicy-id in: path description: The unique identifier of authenticationStrengthPolicy required: true style: simple schema: type: string x-ms-docs-key-type: authenticationStrengthPolicy - name: authenticationCombinationConfiguration-id in: path description: The unique identifier of authenticationCombinationConfiguration required: true style: simple schema: type: string x-ms-docs-key-type: authenticationCombinationConfiguration - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation ? /identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}/combinationConfigurations/$count : get: tags: - identity.conditionalAccessRoot summary: Get the number of the resource operationId: identity.conditionalAccess.authenticationStrength.policy.combinationConfiguration_GetCount parameters: - name: authenticationStrengthPolicy-id in: path description: The unique identifier of authenticationStrengthPolicy required: true style: simple schema: type: string x-ms-docs-key-type: authenticationStrengthPolicy - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' ? /identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}/microsoft.graph.updateAllowedCombinations : post: tags: - identity.conditionalAccessRoot summary: Invoke action updateAllowedCombinations description: Update the allowedCombinations property of an authenticationStrengthPolicy object. To update other properties of an authenticationStrengthPolicy object, use the Update authenticationStrengthPolicy method. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/authenticationstrengthpolicy-updateallowedcombinations?view=graph-rest-1.0 operationId: identity.conditionalAccess.authenticationStrength.policy_updateAllowedCombination parameters: - name: authenticationStrengthPolicy-id in: path description: The unique identifier of authenticationStrengthPolicy required: true style: simple schema: type: string x-ms-docs-key-type: authenticationStrengthPolicy requestBody: description: Action parameters content: application/json: schema: type: object properties: allowedCombinations: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModes' additionalProperties: type: object required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.updateAllowedCombinationsResult' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action /identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}/microsoft.graph.usage(): get: tags: - identity.conditionalAccessRoot summary: Invoke function usage description: Allows the caller to see which Conditional Access policies reference a specified authentication strength policy. The policies are returned in two collections, one containing Conditional Access policies that require an MFA claim and the other containing Conditional Access policies that don't require such a claim. Policies in the former category are restricted in what kinds of changes may be made to them to prevent undermining the MFA requirement of those policies. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/authenticationstrengthpolicy-usage?view=graph-rest-1.0 operationId: identity.conditionalAccess.authenticationStrength.policy_usage parameters: - name: authenticationStrengthPolicy-id in: path description: The unique identifier of authenticationStrengthPolicy required: true style: simple schema: type: string x-ms-docs-key-type: authenticationStrengthPolicy responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthUsage' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: function /identity/conditionalAccess/authenticationStrength/policies/$count: get: tags: - identity.conditionalAccessRoot summary: Get the number of the resource operationId: identity.conditionalAccess.authenticationStrength.policy_GetCount parameters: - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' /identity/conditionalAccess/deletedItems: get: tags: - identity.conditionalAccessRoot summary: Get deletedItems from identity operationId: identity.conditionalAccess_GetDeletedItem parameters: - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.caPoliciesDeletableRoot' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - identity.conditionalAccessRoot summary: Update the navigation property deletedItems in identity operationId: identity.conditionalAccess_UpdateDeletedItem requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.caPoliciesDeletableRoot' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.caPoliciesDeletableRoot' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - identity.conditionalAccessRoot summary: Delete navigation property deletedItems for identity operationId: identity.conditionalAccess_DeleteDeletedItem parameters: - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identity/conditionalAccess/deletedItems/namedLocations: get: tags: - identity.conditionalAccessRoot summary: Get namedLocations from identity operationId: identity.conditionalAccess.deletedItem_ListNamedLocation parameters: - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.namedLocationCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - identity.conditionalAccessRoot summary: Create new navigation property to namedLocations for identity operationId: identity.conditionalAccess.deletedItem_CreateNamedLocation requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.namedLocation' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.namedLocation' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identity/conditionalAccess/deletedItems/namedLocations/{namedLocation-id}: get: tags: - identity.conditionalAccessRoot summary: Get namedLocations from identity operationId: identity.conditionalAccess.deletedItem_GetNamedLocation parameters: - name: namedLocation-id in: path description: The unique identifier of namedLocation required: true style: simple schema: type: string x-ms-docs-key-type: namedLocation - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.namedLocation' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - identity.conditionalAccessRoot summary: Update the navigation property namedLocations in identity operationId: identity.conditionalAccess.deletedItem_UpdateNamedLocation parameters: - name: namedLocation-id in: path description: The unique identifier of namedLocation required: true style: simple schema: type: string x-ms-docs-key-type: namedLocation requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.namedLocation' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.namedLocation' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - identity.conditionalAccessRoot summary: Delete navigation property namedLocations for identity operationId: identity.conditionalAccess.deletedItem_DeleteNamedLocation parameters: - name: namedLocation-id in: path description: The unique identifier of namedLocation required: true style: simple schema: type: string x-ms-docs-key-type: namedLocation - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identity/conditionalAccess/deletedItems/namedLocations/{namedLocation-id}/microsoft.graph.restore: post: tags: - identity.conditionalAccessRoot summary: Invoke action restore operationId: identity.conditionalAccess.deletedItem.namedLocation_restore parameters: - name: namedLocation-id in: path description: The unique identifier of namedLocation required: true style: simple schema: type: string x-ms-docs-key-type: namedLocation responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.namedLocation' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action /identity/conditionalAccess/deletedItems/namedLocations/$count: get: tags: - identity.conditionalAccessRoot summary: Get the number of the resource operationId: identity.conditionalAccess.deletedItem.namedLocation_GetCount parameters: - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' /identity/conditionalAccess/deletedItems/policies: get: tags: - identity.conditionalAccessRoot summary: Get policies from identity operationId: identity.conditionalAccess.deletedItem_ListPolicy parameters: - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.conditionalAccessPolicyCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - identity.conditionalAccessRoot summary: Create new navigation property to policies for identity operationId: identity.conditionalAccess.deletedItem_CreatePolicy requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identity/conditionalAccess/deletedItems/policies/{conditionalAccessPolicy-id}: get: tags: - identity.conditionalAccessRoot summary: Get policies from identity operationId: identity.conditionalAccess.deletedItem_GetPolicy parameters: - name: conditionalAccessPolicy-id in: path description: The unique identifier of conditionalAccessPolicy required: true style: simple schema: type: string x-ms-docs-key-type: conditionalAccessPolicy - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - identity.conditionalAccessRoot summary: Update the navigation property policies in identity operationId: identity.conditionalAccess.deletedItem_UpdatePolicy parameters: - name: conditionalAccessPolicy-id in: path description: The unique identifier of conditionalAccessPolicy required: true style: simple schema: type: string x-ms-docs-key-type: conditionalAccessPolicy requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - identity.conditionalAccessRoot summary: Delete navigation property policies for identity operationId: identity.conditionalAccess.deletedItem_DeletePolicy parameters: - name: conditionalAccessPolicy-id in: path description: The unique identifier of conditionalAccessPolicy required: true style: simple schema: type: string x-ms-docs-key-type: conditionalAccessPolicy - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identity/conditionalAccess/deletedItems/policies/{conditionalAccessPolicy-id}/microsoft.graph.restore: post: tags: - identity.conditionalAccessRoot summary: Invoke action restore operationId: identity.conditionalAccess.deletedItem.policy_restore parameters: - name: conditionalAccessPolicy-id in: path description: The unique identifier of conditionalAccessPolicy required: true style: simple schema: type: string x-ms-docs-key-type: conditionalAccessPolicy responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action /identity/conditionalAccess/deletedItems/policies/$count: get: tags: - identity.conditionalAccessRoot summary: Get the number of the resource operationId: identity.conditionalAccess.deletedItem.policy_GetCount parameters: - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' /identity/conditionalAccess/microsoft.graph.evaluate: post: tags: - identity.conditionalAccessRoot summary: Invoke action evaluate description: Evaluates the applicability of Conditional Access Policies in your tenant based on the provided sign-in properties. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/conditionalaccessroot-evaluate?view=graph-rest-1.0 operationId: identity.conditionalAccess_evaluate requestBody: description: Action parameters content: application/json: schema: type: object properties: signInIdentity: $ref: '#/components/schemas/microsoft.graph.signInIdentity' signInContext: $ref: '#/components/schemas/microsoft.graph.signInContext' signInConditions: $ref: '#/components/schemas/microsoft.graph.signInConditions' appliedPoliciesOnly: type: - boolean - 'null' default: false additionalProperties: type: object required: true responses: 2XX: description: Success content: application/json: schema: title: Collection of whatIfAnalysisResult type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.whatIfAnalysisResult' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore /identity/conditionalAccess/namedLocations: get: tags: - identity.conditionalAccessRoot summary: List namedLocations description: Get a list of namedLocation objects. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/conditionalaccessroot-list-namedlocations?view=graph-rest-1.0 operationId: identity.conditionalAccess_ListNamedLocation parameters: - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.namedLocationCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - identity.conditionalAccessRoot summary: Create namedLocation description: Create a new namedLocation object. Named locations can be either ipNamedLocation or countryNamedLocation objects. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/conditionalaccessroot-post-namedlocations?view=graph-rest-1.0 operationId: identity.conditionalAccess_CreateNamedLocation requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.namedLocation' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.namedLocation' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identity/conditionalAccess/namedLocations/{namedLocation-id}: get: tags: - identity.conditionalAccessRoot summary: Get countryNamedLocation description: Retrieve the properties and relationships of a countryNamedLocation object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/countrynamedlocation-get?view=graph-rest-1.0 operationId: identity.conditionalAccess_GetNamedLocation parameters: - name: namedLocation-id in: path description: The unique identifier of namedLocation required: true style: simple schema: type: string x-ms-docs-key-type: namedLocation - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.namedLocation' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - identity.conditionalAccessRoot summary: Update countryNamedLocation description: Update the properties of a countryNamedLocation object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/countrynamedlocation-update?view=graph-rest-1.0 operationId: identity.conditionalAccess_UpdateNamedLocation parameters: - name: namedLocation-id in: path description: The unique identifier of namedLocation required: true style: simple schema: type: string x-ms-docs-key-type: namedLocation requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.namedLocation' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.namedLocation' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - identity.conditionalAccessRoot summary: Delete countryNamedLocation description: Delete a countryNamedLocation object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/countrynamedlocation-delete?view=graph-rest-1.0 operationId: identity.conditionalAccess_DeleteNamedLocation parameters: - name: namedLocation-id in: path description: The unique identifier of namedLocation required: true style: simple schema: type: string x-ms-docs-key-type: namedLocation - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identity/conditionalAccess/namedLocations/{namedLocation-id}/microsoft.graph.restore: post: tags: - identity.conditionalAccessRoot summary: Invoke action restore operationId: identity.conditionalAccess.namedLocation_restore parameters: - name: namedLocation-id in: path description: The unique identifier of namedLocation required: true style: simple schema: type: string x-ms-docs-key-type: namedLocation responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.namedLocation' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action /identity/conditionalAccess/namedLocations/$count: get: tags: - identity.conditionalAccessRoot summary: Get the number of the resource operationId: identity.conditionalAccess.namedLocation_GetCount parameters: - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' /identity/conditionalAccess/policies: get: tags: - identity.conditionalAccessRoot summary: List policies description: Retrieve a list of conditionalAccessPolicy objects. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/conditionalaccessroot-list-policies?view=graph-rest-1.0 operationId: identity.conditionalAccess_ListPolicy parameters: - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.conditionalAccessPolicyCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - identity.conditionalAccessRoot summary: Create conditionalAccessPolicy description: Create a new conditionalAccessPolicy. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/conditionalaccessroot-post-policies?view=graph-rest-1.0 operationId: identity.conditionalAccess_CreatePolicy requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identity/conditionalAccess/policies/{conditionalAccessPolicy-id}: get: tags: - identity.conditionalAccessRoot summary: Get conditionalAccessPolicy description: Retrieve the properties and relationships of a conditionalAccessPolicy object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/conditionalaccesspolicy-get?view=graph-rest-1.0 operationId: identity.conditionalAccess_GetPolicy parameters: - name: conditionalAccessPolicy-id in: path description: The unique identifier of conditionalAccessPolicy required: true style: simple schema: type: string x-ms-docs-key-type: conditionalAccessPolicy - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - identity.conditionalAccessRoot summary: Update conditionalaccesspolicy description: Update the properties of a conditionalAccessPolicy object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/conditionalaccesspolicy-update?view=graph-rest-1.0 operationId: identity.conditionalAccess_UpdatePolicy parameters: - name: conditionalAccessPolicy-id in: path description: The unique identifier of conditionalAccessPolicy required: true style: simple schema: type: string x-ms-docs-key-type: conditionalAccessPolicy requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - identity.conditionalAccessRoot summary: Delete conditionalAccessPolicy description: Delete a conditionalAccessPolicy object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/conditionalaccesspolicy-delete?view=graph-rest-1.0 operationId: identity.conditionalAccess_DeletePolicy parameters: - name: conditionalAccessPolicy-id in: path description: The unique identifier of conditionalAccessPolicy required: true style: simple schema: type: string x-ms-docs-key-type: conditionalAccessPolicy - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identity/conditionalAccess/policies/{conditionalAccessPolicy-id}/microsoft.graph.restore: post: tags: - identity.conditionalAccessRoot summary: Invoke action restore operationId: identity.conditionalAccess.policy_restore parameters: - name: conditionalAccessPolicy-id in: path description: The unique identifier of conditionalAccessPolicy required: true style: simple schema: type: string x-ms-docs-key-type: conditionalAccessPolicy responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action /identity/conditionalAccess/policies/$count: get: tags: - identity.conditionalAccessRoot summary: Get the number of the resource operationId: identity.conditionalAccess.policy_GetCount parameters: - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' /identity/conditionalAccess/templates: get: tags: - identity.conditionalAccessRoot summary: List conditionalAccessTemplates description: Get a list of the conditionalAccessTemplate objects and their properties. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/conditionalaccessroot-list-templates?view=graph-rest-1.0 operationId: identity.conditionalAccess_ListTemplate parameters: - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.conditionalAccessTemplateCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation /identity/conditionalAccess/templates/{conditionalAccessTemplate-id}: get: tags: - identity.conditionalAccessRoot summary: Get conditionalAccessTemplate description: Read the properties and relationships of a conditionalAccessTemplate object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/conditionalaccesstemplate-get?view=graph-rest-1.0 operationId: identity.conditionalAccess_GetTemplate parameters: - name: conditionalAccessTemplate-id in: path description: The unique identifier of conditionalAccessTemplate required: true style: simple schema: type: string x-ms-docs-key-type: conditionalAccessTemplate - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.conditionalAccessTemplate' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identity/conditionalAccess/templates/$count: get: tags: - identity.conditionalAccessRoot summary: Get the number of the resource operationId: identity.conditionalAccess.template_GetCount parameters: - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' components: schemas: microsoft.graph.conditionalAccessApplications: title: conditionalAccessApplications type: object properties: applicationFilter: $ref: '#/components/schemas/microsoft.graph.conditionalAccessFilter' excludeApplications: type: array items: type: string description: 'Can be one of the following: The list of client IDs (appId) explicitly excluded from the policy. Office365 - For the list of apps included in Office365, see Apps included in Conditional Access Office 365 app suite MicrosoftAdminPortals - For more information, see Conditional Access Target resources: Microsoft Admin Portals' includeApplications: type: array items: type: string description: 'Can be one of the following: The list of client IDs (appId) the policy applies to, unless explicitly excluded (in excludeApplications) All Office365 - For the list of apps included in Office365, see Apps included in Conditional Access Office 365 app suite MicrosoftAdminPortals - For more information, see Conditional Access Target resources: Microsoft Admin Portals' includeAuthenticationContextClassReferences: type: array items: type: string includeUserActions: type: array items: type: string description: User actions to include. Supported values are urn:user:registersecurityinfo and urn:user:registerdevice additionalProperties: type: object microsoft.graph.authenticationStrengthPolicy: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: authenticationStrengthPolicy type: object properties: allowedCombinations: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModes' description: A collection of authentication method modes that are required be used to satify this authentication strength. createdDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: string description: The datetime when this policy was created. format: date-time description: type: - string - 'null' description: The human-readable description of this policy. displayName: type: string description: The human-readable display name of this policy. Supports $filter (eq, ne, not , and in). modifiedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: string description: The datetime when this policy was last modified. format: date-time policyType: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicyType' requirementsSatisfied: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthRequirements' combinationConfigurations: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationCombinationConfiguration' description: Settings that may be used to require specific types or instances of an authentication method to be used when authenticating with a specified combination of authentication methods. x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.authenticationCombinationConfiguration: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: authenticationCombinationConfiguration type: object properties: appliesToCombinations: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModes' description: Which authentication method combinations this configuration applies to. Must be an allowedCombinations object, part of the authenticationStrengthPolicy. The only possible value for fido2combinationConfigurations is 'fido2'. additionalProperties: type: object microsoft.graph.authenticationFlow: title: authenticationFlow type: object properties: transferMethod: $ref: '#/components/schemas/microsoft.graph.conditionalAccessTransferMethods' additionalProperties: type: object microsoft.graph.conditionalAccessGrantControl: title: conditionalAccessGrantControl enum: - block - mfa - compliantDevice - domainJoinedDevice - approvedApplication - compliantApplication - passwordChange - unknownFutureValue - riskRemediation type: string microsoft.graph.conditionalAccessPolicy: allOf: - $ref: '#/components/schemas/microsoft.graph.policyDeletableItem' - title: conditionalAccessPolicy type: object properties: conditions: $ref: '#/components/schemas/microsoft.graph.conditionalAccessConditionSet' createdDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. Read-only. format: date-time description: type: - string - 'null' displayName: type: string description: Specifies a display name for the conditionalAccessPolicy object. grantControls: $ref: '#/components/schemas/microsoft.graph.conditionalAccessGrantControls' id: type: string description: Specifies the identifier of a conditionalAccessPolicy object. Read-only. modifiedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. Read-only. format: date-time sessionControls: $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControls' state: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicyState' templateId: type: - string - 'null' description: Specifies the unique identifier of a Conditional Access template. Inherited from entity. additionalProperties: type: object microsoft.graph.conditionalAccessUsers: title: conditionalAccessUsers type: object properties: excludeGroups: type: array items: type: string description: Group IDs excluded from scope of policy. excludeGuestsOrExternalUsers: $ref: '#/components/schemas/microsoft.graph.conditionalAccessGuestsOrExternalUsers' excludeRoles: type: array items: type: string description: Role IDs excluded from scope of policy. excludeUsers: type: array items: type: string description: User IDs excluded from scope of policy and/or GuestsOrExternalUsers. includeGroups: type: array items: type: string description: Group IDs in scope of policy unless explicitly excluded. includeGuestsOrExternalUsers: $ref: '#/components/schemas/microsoft.graph.conditionalAccessGuestsOrExternalUsers' includeRoles: type: array items: type: string description: Role IDs in scope of policy unless explicitly excluded. includeUsers: type: array items: type: string description: User IDs in scope of policy unless explicitly excluded, None, All, or GuestsOrExternalUsers. additionalProperties: type: object microsoft.graph.authenticationMethodModeDetailCollectionResponse: title: Collection of authenticationMethodModeDetail type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModeDetail' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.conditionalAccessLocations: title: conditionalAccessLocations type: object properties: excludeLocations: type: array items: type: string description: Location IDs excluded from scope of policy. includeLocations: type: array items: type: string description: Location IDs in scope of policy unless explicitly excluded, All, or AllTrusted. additionalProperties: type: object microsoft.graph.updateAllowedCombinationsResult: title: updateAllowedCombinationsResult type: object properties: additionalInformation: type: - string - 'null' description: Information about why the updateAllowedCombinations action was successful or failed. conditionalAccessReferences: type: array items: type: - string - 'null' description: References to existing Conditional Access policies that use this authentication strength. currentCombinations: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModes' description: The list of current authentication method combinations allowed by the authentication strength. previousCombinations: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModes' description: The list of former authentication method combinations allowed by the authentication strength before they were updated through the updateAllowedCombinations action. additionalProperties: type: object microsoft.graph.riskLevel: title: riskLevel enum: - low - medium - high - hidden - none - unknownFutureValue type: string microsoft.graph.authenticationCombinationConfigurationCollectionResponse: title: Collection of authenticationCombinationConfiguration type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationCombinationConfiguration' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.signInIdentity: title: signInIdentity type: object additionalProperties: type: object microsoft.graph.applicationEnforcedRestrictionsSessionControl: allOf: - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl' - title: applicationEnforcedRestrictionsSessionControl type: object additionalProperties: type: object microsoft.graph.conditionalAccessFilter: title: conditionalAccessFilter type: object properties: mode: $ref: '#/components/schemas/microsoft.graph.filterMode' rule: type: string description: Rule syntax is similar to that used for membership rules for groups in Microsoft Entra ID. For details, see rules with multiple expressions additionalProperties: type: object microsoft.graph.conditionalAccessTemplateCollectionResponse: title: Collection of conditionalAccessTemplate type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessTemplate' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.ODataErrors.InnerError: type: object additionalProperties: type: object description: The structure of this object is service-specific microsoft.graph.conditionalAccessPolicyState: title: conditionalAccessPolicyState enum: - enabled - disabled - enabledForReportingButNotEnforced type: string microsoft.graph.signInFrequencyInterval: title: signInFrequencyInterval enum: - timeBased - everyTime - unknownFutureValue type: string microsoft.graph.conditionalAccessPlatforms: title: conditionalAccessPlatforms type: object properties: excludePlatforms: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessDevicePlatform' description: 'The possible values are: android, iOS, windows, windowsPhone, macOS, linux, all, unknownFutureValue.' includePlatforms: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessDevicePlatform' description: 'The possible values are: android, iOS, windows, windowsPhone, macOS, linux, all, unknownFutureValue.' additionalProperties: type: object microsoft.graph.baseAuthenticationMethod: title: baseAuthenticationMethod enum: - password - voice - hardwareOath - softwareOath - sms - fido2 - windowsHelloForBusiness - microsoftAuthenticator - temporaryAccessPass - email - x509Certificate - federation - unknownFutureValue - qrCodePin type: string microsoft.graph.authenticationStrengthPolicyCollectionResponse: title: Collection of authenticationStrengthPolicy type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicy' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.whatIfAnalysisReasons: title: whatIfAnalysisReasons enum: - notSet - notEnoughInformation - invalidCondition - users - workloadIdentities - application - userActions - authenticationContext - devicePlatform - devices - clientApps - location - signInRisk - emptyPolicy - invalidPolicy - policyNotEnabled - userRisk - time - insiderRisk - authenticationFlow - unknownFutureValue type: string x-ms-enum-flags: isFlags: true microsoft.graph.deviceInfo: title: deviceInfo type: object properties: deviceId: type: - string - 'null' description: Unique identifier set by Azure Device Registration Service at the time of registration. displayName: type: - string - 'null' description: The display name for the device. enrollmentProfileName: type: - string - 'null' description: Enrollment profile applied to the device. extensionAttribute1: type: - string - 'null' description: Extension attribute. extensionAttribute10: type: - string - 'null' description: Extension attribute. extensionAttribute11: type: - string - 'null' description: Extension attribute. extensionAttribute12: type: - string - 'null' description: Extension attribute. extensionAttribute13: type: - string - 'null' description: Extension attribute. extensionAttribute14: type: - string - 'null' description: Extension attribute. extensionAttribute15: type: - string - 'null' description: Extension attribute. extensionAttribute2: type: - string - 'null' description: Extension attribute. extensionAttribute3: type: - string - 'null' description: Extension attribute. extensionAttribute4: type: - string - 'null' description: Extension attribute. extensionAttribute5: type: - string - 'null' description: Extension attribute. extensionAttribute6: type: - string - 'null' description: Extension attribute. extensionAttribute7: type: - string - 'null' description: Extension attribute. extensionAttribute8: type: - string - 'null' description: Extension attribute. extensionAttribute9: type: - string - 'null' description: Extension attribute. isCompliant: type: - boolean - 'null' description: Indicates the device compliance status with Mobile Management Device (MDM) policies. Default is false. manufacturer: type: - string - 'null' description: Manufacturer of the device. mdmAppId: type: - string - 'null' description: Application identifier used to register device into MDM. model: type: - string - 'null' description: Model of the device. operatingSystem: type: - string - 'null' description: The type of operating system on the device. operatingSystemVersion: type: - string - 'null' description: The version of the operating system on the device. ownership: type: - string - 'null' description: Ownership of the device. This property is set by Intune. physicalIds: type: array items: type: - string - 'null' description: A collection of physical identifiers for the device. profileType: type: - string - 'null' description: The profile type of the device. systemLabels: type: array items: type: - string - 'null' description: List of labels applied to the device by the system. trustType: type: - string - 'null' description: Type of trust for the joined device. additionalProperties: type: object microsoft.graph.namedLocation: allOf: - $ref: '#/components/schemas/microsoft.graph.policyDeletableItem' - title: namedLocation type: object properties: createdDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The Timestamp type represents creation date and time of the location using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. Read-only. format: date-time displayName: type: string description: Human-readable name of the location. id: type: string description: Identifier of a namedLocation object. Read-only. modifiedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The Timestamp type represents last modified date and time of the location using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. Read-only. format: date-time additionalProperties: type: object microsoft.graph.conditionalAccessGrantControls: title: conditionalAccessGrantControls type: object properties: builtInControls: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessGrantControl' description: 'List of values of built-in controls required by the policy. Possible values: block, mfa, compliantDevice, domainJoinedDevice, approvedApplication, compliantApplication, passwordChange, unknownFutureValue, riskRemediation. Use the Prefer: include-unknown-enum-members request header to get the following value in this evolvable enum: riskRemediation.' customAuthenticationFactors: type: array items: type: string description: List of custom controls IDs required by the policy. For more information, see Custom controls. operator: type: - string - 'null' description: 'Defines the relationship of the grant controls. Possible values: AND, OR.' termsOfUse: type: array items: type: string description: List of terms of use IDs required by the policy. authenticationStrength: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicy' additionalProperties: type: object microsoft.graph.persistentBrowserSessionMode: title: persistentBrowserSessionMode enum: - always - never type: string microsoft.graph.signInFrequencyAuthenticationType: title: signInFrequencyAuthenticationType enum: - primaryAndSecondaryAuthentication - secondaryAuthentication - unknownFutureValue type: string microsoft.graph.authenticationMethodModeDetail: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: authenticationMethodModeDetail type: object properties: authenticationMethod: $ref: '#/components/schemas/microsoft.graph.baseAuthenticationMethod' displayName: type: string description: The display name of this mode additionalProperties: type: object microsoft.graph.policyDeletableItem: title: policyDeletableItem type: object properties: deletedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' format: date-time additionalProperties: type: object microsoft.graph.signInConditions: title: signInConditions type: object properties: authenticationFlow: $ref: '#/components/schemas/microsoft.graph.authenticationFlow' clientAppType: $ref: '#/components/schemas/microsoft.graph.conditionalAccessClientApp' country: type: - string - 'null' description: Country from where the identity is authenticating. deviceInfo: $ref: '#/components/schemas/microsoft.graph.deviceInfo' devicePlatform: $ref: '#/components/schemas/microsoft.graph.conditionalAccessDevicePlatform' insiderRiskLevel: $ref: '#/components/schemas/microsoft.graph.insiderRiskLevel' ipAddress: type: - string - 'null' description: Ip address of the authenticating identity. servicePrincipalRiskLevel: $ref: '#/components/schemas/microsoft.graph.riskLevel' signInRiskLevel: $ref: '#/components/schemas/microsoft.graph.riskLevel' userRiskLevel: $ref: '#/components/schemas/microsoft.graph.riskLevel' additionalProperties: type: object microsoft.graph.secureSignInSessionControl: allOf: - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl' - title: secureSignInSessionControl type: object additionalProperties: type: object microsoft.graph.authenticationStrengthRequirements: title: authenticationStrengthRequirements enum: - none - mfa - unknownFutureValue type: string x-ms-enum-flags: isFlags: true microsoft.graph.conditionalAccessClientApp: title: conditionalAccessClientApp enum: - all - browser - mobileAppsAndDesktopClients - exchangeActiveSync - easSupported - other - unknownFutureValue type: string microsoft.graph.caPoliciesDeletableRoot: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: caPoliciesDeletableRoot type: object properties: namedLocations: type: array items: $ref: '#/components/schemas/microsoft.graph.namedLocation' x-ms-navigationProperty: true policies: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.filterMode: title: filterMode enum: - include - exclude type: string microsoft.graph.conditionalAccessSessionControls: title: conditionalAccessSessionControls type: object properties: applicationEnforcedRestrictions: $ref: '#/components/schemas/microsoft.graph.applicationEnforcedRestrictionsSessionControl' cloudAppSecurity: $ref: '#/components/schemas/microsoft.graph.cloudAppSecuritySessionControl' disableResilienceDefaults: type: - boolean - 'null' description: Session control that determines whether it is acceptable for Microsoft Entra ID to extend existing sessions based on information collected prior to an outage or not. persistentBrowser: $ref: '#/components/schemas/microsoft.graph.persistentBrowserSessionControl' secureSignInSession: $ref: '#/components/schemas/microsoft.graph.secureSignInSessionControl' signInFrequency: $ref: '#/components/schemas/microsoft.graph.signInFrequencySessionControl' additionalProperties: type: object microsoft.graph.persistentBrowserSessionControl: allOf: - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl' - title: persistentBrowserSessionControl type: object properties: mode: $ref: '#/components/schemas/microsoft.graph.persistentBrowserSessionMode' additionalProperties: type: object microsoft.graph.authenticationStrengthRoot: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: authenticationStrengthRoot type: object properties: combinations: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModes' authenticationMethodModes: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModeDetail' description: Names and descriptions of all valid authentication method modes in the system. x-ms-navigationProperty: true policies: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicy' description: A collection of authentication strength policies that exist for this tenant, including both built-in and custom policies. x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.authenticationMethodModes: title: authenticationMethodModes enum: - password - voice - hardwareOath - softwareOath - sms - fido2 - windowsHelloForBusiness - microsoftAuthenticatorPush - deviceBasedPush - temporaryAccessPassOneTime - temporaryAccessPassMultiUse - email - x509CertificateSingleFactor - x509CertificateMultiFactor - federatedSingleFactor - federatedMultiFactor - unknownFutureValue - qrCodePin type: string x-ms-enum-flags: isFlags: true microsoft.graph.conditionalAccessAuthenticationFlows: title: conditionalAccessAuthenticationFlows type: object properties: transferMethods: $ref: '#/components/schemas/microsoft.graph.conditionalAccessTransferMethods' additionalProperties: type: object microsoft.graph.signinFrequencyType: title: signinFrequencyType enum: - days - hours type: string microsoft.graph.conditionalAccessConditionSet: title: conditionalAccessConditionSet type: object properties: applications: $ref: '#/components/schemas/microsoft.graph.conditionalAccessApplications' authenticationFlows: $ref: '#/components/schemas/microsoft.graph.conditionalAccessAuthenticationFlows' clientApplications: $ref: '#/components/schemas/microsoft.graph.conditionalAccessClientApplications' clientAppTypes: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessClientApp' description: 'Client application types included in the policy. The possible values are: all, browser, mobileAppsAndDesktopClients, exchangeActiveSync, easSupported, other. Required. The easUnsupported enumeration member will be deprecated in favor of exchangeActiveSync, which includes EAS supported and unsupported platforms.' devices: $ref: '#/components/schemas/microsoft.graph.conditionalAccessDevices' insiderRiskLevels: $ref: '#/components/schemas/microsoft.graph.conditionalAccessInsiderRiskLevels' locations: $ref: '#/components/schemas/microsoft.graph.conditionalAccessLocations' platforms: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPlatforms' servicePrincipalRiskLevels: type: array items: $ref: '#/components/schemas/microsoft.graph.riskLevel' description: 'Service principal risk levels included in the policy. The possible values are: low, medium, high, none, unknownFutureValue.' signInRiskLevels: type: array items: $ref: '#/components/schemas/microsoft.graph.riskLevel' description: 'Sign-in risk levels included in the policy. The possible values are: low, medium, high, hidden, none, unknownFutureValue. Required.' userRiskLevels: type: array items: $ref: '#/components/schemas/microsoft.graph.riskLevel' description: 'User risk levels included in the policy. The possible values are: low, medium, high, hidden, none, unknownFutureValue. Required.' users: $ref: '#/components/schemas/microsoft.graph.conditionalAccessUsers' additionalProperties: type: object microsoft.graph.authenticationStrengthUsage: title: authenticationStrengthUsage type: object properties: mfa: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' x-ms-navigationProperty: true none: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.conditionalAccessPolicyCollectionResponse: title: Collection of conditionalAccessPolicy type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.conditionalAccessPolicyDetail: title: conditionalAccessPolicyDetail type: object properties: conditions: $ref: '#/components/schemas/microsoft.graph.conditionalAccessConditionSet' grantControls: $ref: '#/components/schemas/microsoft.graph.conditionalAccessGrantControls' sessionControls: $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControls' additionalProperties: type: object microsoft.graph.ODataErrors.ErrorDetails: required: - code - message type: object properties: code: type: string message: type: string target: type: - string - 'null' additionalProperties: type: object microsoft.graph.conditionalAccessClientApplications: title: conditionalAccessClientApplications type: object properties: excludeServicePrincipals: type: array items: type: string description: Service principal IDs excluded from the policy scope. includeServicePrincipals: type: array items: type: string description: Service principal IDs included in the policy scope, or ServicePrincipalsInMyTenant. servicePrincipalFilter: $ref: '#/components/schemas/microsoft.graph.conditionalAccessFilter' additionalProperties: type: object microsoft.graph.cloudAppSecuritySessionControl: allOf: - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl' - title: cloudAppSecuritySessionControl type: object properties: cloudAppSecurityType: $ref: '#/components/schemas/microsoft.graph.cloudAppSecuritySessionControlType' additionalProperties: type: object microsoft.graph.authenticationContextClassReferenceCollectionResponse: title: Collection of authenticationContextClassReference type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationContextClassReference' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.namedLocationCollectionResponse: title: Collection of namedLocation type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.namedLocation' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.conditionalAccessGuestsOrExternalUsers: title: conditionalAccessGuestsOrExternalUsers type: object properties: externalTenants: $ref: '#/components/schemas/microsoft.graph.conditionalAccessExternalTenants' guestOrExternalUserTypes: $ref: '#/components/schemas/microsoft.graph.conditionalAccessGuestOrExternalUserTypes' additionalProperties: type: object microsoft.graph.conditionalAccessExternalTenantsMembershipKind: title: conditionalAccessExternalTenantsMembershipKind enum: - all - enumerated - unknownFutureValue type: string microsoft.graph.entity: title: entity type: object properties: id: type: string description: The unique identifier for an entity. Read-only. additionalProperties: type: object microsoft.graph.conditionalAccessTransferMethods: title: conditionalAccessTransferMethods enum: - none - deviceCodeFlow - authenticationTransfer - unknownFutureValue type: string x-ms-enum-flags: isFlags: true microsoft.graph.templateScenarios: title: templateScenarios enum: - new - secureFoundation - zeroTrust - remoteWork - protectAdmins - emergingThreats - unknownFutureValue type: string x-ms-enum-flags: isFlags: true microsoft.graph.ODataErrors.ODataError: required: - error type: object properties: error: $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError' additionalProperties: type: object microsoft.graph.conditionalAccessDevices: title: conditionalAccessDevices type: object properties: deviceFilter: $ref: '#/components/schemas/microsoft.graph.conditionalAccessFilter' additionalProperties: type: object microsoft.graph.authenticationContextClassReference: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: authenticationContextClassReference type: object properties: description: type: - string - 'null' description: A short explanation of the policies that are enforced by authenticationContextClassReference. This value should be used to provide secondary text to describe the authentication context class reference when building user-facing admin experiences. For example, a selection UX. displayName: type: - string - 'null' description: The display name is the friendly name of the authenticationContextClassReference object. This value should be used to identify the authentication context class reference when building user-facing admin experiences. For example, a selection UX. isAvailable: type: - boolean - 'null' description: Indicates whether the authenticationContextClassReference has been published by the security admin and is ready for use by apps. When it's set to false, it shouldn't be shown in authentication context selection UX, or used to protect app resources. It's shown and available for Conditional Access policy authoring. The default value is false. Supports $filter (eq). additionalProperties: type: object microsoft.graph.conditionalAccessSessionControl: title: conditionalAccessSessionControl type: object properties: isEnabled: type: - boolean - 'null' description: Specifies whether the session control is enabled. additionalProperties: type: object microsoft.graph.signInContext: title: signInContext type: object additionalProperties: type: object microsoft.graph.whatIfAnalysisResult: allOf: - $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' - title: whatIfAnalysisResult type: object properties: analysisReasons: $ref: '#/components/schemas/microsoft.graph.whatIfAnalysisReasons' policyApplies: type: boolean description: Specifies whether the policy applies to the sign-in properties provided in the request body. If policyApplies is true, the policy applies to the sign-in based on the sign-in properties provided. If policyApplies is false, the policy doesn't apply to the sign-in based on the sign-in properties provided and the analysisReasons property is populated to show the reason for the policy not applying. additionalProperties: type: object microsoft.graph.conditionalAccessTemplate: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: conditionalAccessTemplate type: object properties: description: type: string description: The user-friendly name of the template. details: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicyDetail' name: type: string description: The user-friendly name of the template. scenarios: $ref: '#/components/schemas/microsoft.graph.templateScenarios' additionalProperties: type: object microsoft.graph.cloudAppSecuritySessionControlType: title: cloudAppSecuritySessionControlType enum: - mcasConfigured - monitorOnly - blockDownloads - unknownFutureValue type: string microsoft.graph.authenticationStrengthPolicyType: title: authenticationStrengthPolicyType enum: - builtIn - custom - unknownFutureValue type: string microsoft.graph.conditionalAccessExternalTenants: title: conditionalAccessExternalTenants type: object properties: membershipKind: $ref: '#/components/schemas/microsoft.graph.conditionalAccessExternalTenantsMembershipKind' additionalProperties: type: object microsoft.graph.conditionalAccessGuestOrExternalUserTypes: title: conditionalAccessGuestOrExternalUserTypes enum: - none - internalGuest - b2bCollaborationGuest - b2bCollaborationMember - b2bDirectConnectUser - otherExternalUser - serviceProvider - unknownFutureValue type: string x-ms-enum-flags: isFlags: true microsoft.graph.insiderRiskLevel: title: insiderRiskLevel enum: - none - minor - moderate - elevated - unknownFutureValue type: string microsoft.graph.conditionalAccessDevicePlatform: title: conditionalAccessDevicePlatform enum: - android - iOS - windows - windowsPhone - macOS - all - unknownFutureValue - linux type: string microsoft.graph.ODataErrors.MainError: required: - code - message type: object properties: code: type: string message: type: string x-ms-primary-error-message: true target: type: - string - 'null' details: type: array items: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails' innerError: $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError' additionalProperties: type: object ODataCountResponse: type: integer format: int32 microsoft.graph.signInFrequencySessionControl: allOf: - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl' - title: signInFrequencySessionControl type: object properties: authenticationType: $ref: '#/components/schemas/microsoft.graph.signInFrequencyAuthenticationType' frequencyInterval: $ref: '#/components/schemas/microsoft.graph.signInFrequencyInterval' type: $ref: '#/components/schemas/microsoft.graph.signinFrequencyType' value: maximum: 2147483647 minimum: -2147483648 type: - number - 'null' description: The number of days or hours. format: int32 additionalProperties: type: object microsoft.graph.conditionalAccessInsiderRiskLevels: title: conditionalAccessInsiderRiskLevels enum: - minor - moderate - elevated - unknownFutureValue type: string x-ms-enum-flags: isFlags: true responses: ODataCountResponse: description: The count of the resource content: text/plain: schema: $ref: '#/components/schemas/ODataCountResponse' microsoft.graph.conditionalAccessTemplateCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.conditionalAccessTemplateCollectionResponse' microsoft.graph.authenticationMethodModeDetailCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModeDetailCollectionResponse' error: description: error content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError' microsoft.graph.namedLocationCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.namedLocationCollectionResponse' microsoft.graph.conditionalAccessPolicyCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicyCollectionResponse' microsoft.graph.authenticationStrengthPolicyCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicyCollectionResponse' microsoft.graph.authenticationCombinationConfigurationCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationCombinationConfigurationCollectionResponse' microsoft.graph.authenticationContextClassReferenceCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationContextClassReferenceCollectionResponse' parameters: search: name: $search in: query description: Search items by search phrases style: form explode: false schema: type: string filter: name: $filter in: query description: Filter items by property values style: form explode: false schema: type: string count: name: $count in: query description: Include count of items style: form explode: false schema: type: boolean skip: name: $skip in: query description: Skip the first n items style: form explode: false schema: minimum: 0 type: integer top: name: $top in: query description: Show only the first n items style: form explode: false schema: minimum: 0 type: integer example: 50 securitySchemes: azureaadv2: type: oauth2 flows: authorizationCode: authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token scopes: {}