openapi: 3.2.0 info: title: Identity.SignIns Identity.identity Container API version: v1.0 servers: - url: https://graph.microsoft.com/v1.0/ description: Core security: - azureaadv2: [] tags: - name: identity.identityContainer paths: /identity: get: tags: - identity.identityContainer summary: Get identity operationId: identity.identityContainer_GetIdentityContainer parameters: - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved entity content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.identityContainer' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - identity.identityContainer summary: Update identity operationId: identity.identityContainer_UpdateIdentityContainer requestBody: description: New property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.identityContainer' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.identityContainer' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation components: schemas: microsoft.graph.conditionalAccessApplications: title: conditionalAccessApplications type: object properties: applicationFilter: $ref: '#/components/schemas/microsoft.graph.conditionalAccessFilter' excludeApplications: type: array items: type: string description: 'Can be one of the following: The list of client IDs (appId) explicitly excluded from the policy. Office365 - For the list of apps included in Office365, see Apps included in Conditional Access Office 365 app suite MicrosoftAdminPortals - For more information, see Conditional Access Target resources: Microsoft Admin Portals' includeApplications: type: array items: type: string description: 'Can be one of the following: The list of client IDs (appId) the policy applies to, unless explicitly excluded (in excludeApplications) All Office365 - For the list of apps included in Office365, see Apps included in Conditional Access Office 365 app suite MicrosoftAdminPortals - For more information, see Conditional Access Target resources: Microsoft Admin Portals' includeAuthenticationContextClassReferences: type: array items: type: string includeUserActions: type: array items: type: string description: User actions to include. Supported values are urn:user:registersecurityinfo and urn:user:registerdevice additionalProperties: type: object microsoft.graph.faceCheckConfiguration: title: faceCheckConfiguration type: object properties: isEnabled: type: boolean description: Defines if Face Check is required. Currently must always be true. sourcePhotoClaimName: type: string description: Source of photo to validate Face Check against. Currently must always be portrait. additionalProperties: type: object microsoft.graph.authenticationStrengthPolicy: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: authenticationStrengthPolicy type: object properties: allowedCombinations: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModes' description: A collection of authentication method modes that are required be used to satify this authentication strength. createdDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: string description: The datetime when this policy was created. format: date-time description: type: - string - 'null' description: The human-readable description of this policy. displayName: type: string description: The human-readable display name of this policy. Supports $filter (eq, ne, not , and in). modifiedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: string description: The datetime when this policy was last modified. format: date-time policyType: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicyType' requirementsSatisfied: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthRequirements' combinationConfigurations: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationCombinationConfiguration' description: Settings that may be used to require specific types or instances of an authentication method to be used when authenticating with a specified combination of authentication methods. x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.authenticationCombinationConfiguration: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: authenticationCombinationConfiguration type: object properties: appliesToCombinations: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModes' description: Which authentication method combinations this configuration applies to. Must be an allowedCombinations object, part of the authenticationStrengthPolicy. The only possible value for fido2combinationConfigurations is 'fido2'. additionalProperties: type: object microsoft.graph.identityVerifiedIdRoot: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: identityVerifiedIdRoot type: object properties: profiles: type: array items: $ref: '#/components/schemas/microsoft.graph.verifiedIdProfile' description: Profile containing properties about a Verified ID provider and purpose x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.identityUserFlowAttributeDataType: title: identityUserFlowAttributeDataType enum: - string - boolean - int64 - stringCollection - dateTime - unknownFutureValue type: string microsoft.graph.conditionalAccessGrantControl: title: conditionalAccessGrantControl enum: - block - mfa - compliantDevice - domainJoinedDevice - approvedApplication - compliantApplication - passwordChange - unknownFutureValue - riskRemediation type: string microsoft.graph.conditionalAccessPolicy: allOf: - $ref: '#/components/schemas/microsoft.graph.policyDeletableItem' - title: conditionalAccessPolicy type: object properties: conditions: $ref: '#/components/schemas/microsoft.graph.conditionalAccessConditionSet' createdDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. Read-only. format: date-time description: type: - string - 'null' displayName: type: string description: Specifies a display name for the conditionalAccessPolicy object. grantControls: $ref: '#/components/schemas/microsoft.graph.conditionalAccessGrantControls' id: type: string description: Specifies the identifier of a conditionalAccessPolicy object. Read-only. modifiedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. Read-only. format: date-time sessionControls: $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControls' state: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicyState' templateId: type: - string - 'null' description: Specifies the unique identifier of a Conditional Access template. Inherited from entity. additionalProperties: type: object microsoft.graph.authenticationEventsFlow: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: authenticationEventsFlow type: object properties: conditions: $ref: '#/components/schemas/microsoft.graph.authenticationConditions' description: type: - string - 'null' description: The description of the events policy. displayName: type: string description: Required. The display name for the events policy. additionalProperties: type: object microsoft.graph.webApplicationFirewallVerifiedDetails: title: webApplicationFirewallVerifiedDetails type: object properties: dnsConfiguration: $ref: '#/components/schemas/microsoft.graph.webApplicationFirewallDnsConfiguration' additionalProperties: type: object microsoft.graph.verifiedIdUsageConfiguration: title: verifiedIdUsageConfiguration type: object properties: isEnabledForTestOnly: type: boolean description: Sets profile usage for evaluation (test-only) or production. purpose: $ref: '#/components/schemas/microsoft.graph.verifiedIdUsageConfigurationPurpose' additionalProperties: type: object microsoft.graph.conditionalAccessUsers: title: conditionalAccessUsers type: object properties: excludeGroups: type: array items: type: string description: Group IDs excluded from scope of policy. excludeGuestsOrExternalUsers: $ref: '#/components/schemas/microsoft.graph.conditionalAccessGuestsOrExternalUsers' excludeRoles: type: array items: type: string description: Role IDs excluded from scope of policy. excludeUsers: type: array items: type: string description: User IDs excluded from scope of policy and/or GuestsOrExternalUsers. includeGroups: type: array items: type: string description: Group IDs in scope of policy unless explicitly excluded. includeGuestsOrExternalUsers: $ref: '#/components/schemas/microsoft.graph.conditionalAccessGuestsOrExternalUsers' includeRoles: type: array items: type: string description: Role IDs in scope of policy unless explicitly excluded. includeUsers: type: array items: type: string description: User IDs in scope of policy unless explicitly excluded, None, All, or GuestsOrExternalUsers. additionalProperties: type: object microsoft.graph.identityProviderBase: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: identityProviderBase type: object properties: displayName: type: - string - 'null' description: The display name of the identity provider. additionalProperties: type: object microsoft.graph.conditionalAccessLocations: title: conditionalAccessLocations type: object properties: excludeLocations: type: array items: type: string description: Location IDs excluded from scope of policy. includeLocations: type: array items: type: string description: Location IDs in scope of policy unless explicitly excluded, All, or AllTrusted. additionalProperties: type: object microsoft.graph.userFlowType: title: userFlowType enum: - signUp - signIn - signUpOrSignIn - passwordReset - profileUpdate - resourceOwner - unknownFutureValue type: string microsoft.graph.identityUserFlowAttributeAssignment: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: identityUserFlowAttributeAssignment type: object properties: displayName: type: - string - 'null' description: The display name of the identityUserFlowAttribute within a user flow. isOptional: type: boolean description: Determines whether the identityUserFlowAttribute is optional. true means the user doesn't have to provide a value. false means the user can't complete sign-up without providing a value. requiresVerification: type: boolean description: Determines whether the identityUserFlowAttribute requires verification, and is only used for verifying the user's phone number or email address. userAttributeValues: type: array items: $ref: '#/components/schemas/microsoft.graph.userAttributeValuesItem' description: The input options for the user flow attribute. Only applicable when the userInputType is radioSingleSelect, dropdownSingleSelect, or checkboxMultiSelect. userInputType: $ref: '#/components/schemas/microsoft.graph.identityUserFlowAttributeInputType' userAttribute: $ref: '#/components/schemas/microsoft.graph.identityUserFlowAttribute' additionalProperties: type: object microsoft.graph.userFlowLanguageConfiguration: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: userFlowLanguageConfiguration type: object properties: displayName: type: - string - 'null' description: The language name to display. This property is read-only. isEnabled: type: boolean description: Indicates whether the language is enabled within the user flow. defaultPages: type: array items: $ref: '#/components/schemas/microsoft.graph.userFlowLanguagePage' description: Collection of pages with the default content to display in a user flow for a specified language. This collection doesn't allow any kind of modification. x-ms-navigationProperty: true overridesPages: type: array items: $ref: '#/components/schemas/microsoft.graph.userFlowLanguagePage' description: Collection of pages with the overrides messages to display in a user flow for a specified language. This collection only allows you to modify the content of the page, any other modification isn't allowed (creation or deletion of pages). x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.riskLevel: title: riskLevel enum: - low - medium - high - hidden - none - unknownFutureValue type: string microsoft.graph.webApplicationFirewallDnsRecordType: title: webApplicationFirewallDnsRecordType enum: - cname - unknownFutureValue type: string microsoft.graph.conditionalAccessRoot: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: conditionalAccessRoot type: object properties: authenticationContextClassReferences: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationContextClassReference' description: Read-only. Nullable. Returns a collection of the specified authentication context class references. x-ms-navigationProperty: true authenticationStrength: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthRoot' deletedItems: $ref: '#/components/schemas/microsoft.graph.caPoliciesDeletableRoot' namedLocations: type: array items: $ref: '#/components/schemas/microsoft.graph.namedLocation' description: Read-only. Nullable. Returns a collection of the specified named locations. x-ms-navigationProperty: true policies: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' description: Read-only. Nullable. Returns a collection of the specified Conditional Access (CA) policies. x-ms-navigationProperty: true templates: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessTemplate' description: Read-only. Nullable. Returns a collection of the specified Conditional Access templates. x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.webApplicationFirewallVerificationResult: title: webApplicationFirewallVerificationResult type: object properties: errors: type: array items: $ref: '#/components/schemas/microsoft.graph.genericError' description: List of errors encountered during the verification process. status: $ref: '#/components/schemas/microsoft.graph.webApplicationFirewallVerificationStatus' verifiedOnDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: string description: UTC timestamp when the verification was performed or last updated. This indicates when the verification result was produced. format: date-time warnings: type: array items: $ref: '#/components/schemas/microsoft.graph.genericError' description: List of warnings produced during verification. additionalProperties: type: object microsoft.graph.customExtensionClientConfiguration: title: customExtensionClientConfiguration type: object properties: maximumRetries: maximum: 2147483647 minimum: -2147483648 type: - number - 'null' description: The max number of retries that Microsoft Entra ID makes to the external API. Values of 0 or 1 are supported. If null, the default for the service applies. format: int32 timeoutInMilliseconds: maximum: 2147483647 minimum: -2147483648 type: - number - 'null' description: The max duration in milliseconds that Microsoft Entra ID waits for a response from the external app before it shuts down the connection. The valid range is between 200 and 2000 milliseconds. Default duration is 1000. format: int32 additionalProperties: type: object microsoft.graph.applicationEnforcedRestrictionsSessionControl: allOf: - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl' - title: applicationEnforcedRestrictionsSessionControl type: object additionalProperties: type: object microsoft.graph.webApplicationFirewallVerificationModel: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: webApplicationFirewallVerificationModel type: object properties: providerType: $ref: '#/components/schemas/microsoft.graph.webApplicationFirewallProviderType' verificationResult: $ref: '#/components/schemas/microsoft.graph.webApplicationFirewallVerificationResult' verifiedDetails: $ref: '#/components/schemas/microsoft.graph.webApplicationFirewallVerifiedDetails' verifiedHost: type: - string - 'null' description: The host (domain or subdomain) that was verified as part of this verification operation. provider: $ref: '#/components/schemas/microsoft.graph.webApplicationFirewallProvider' additionalProperties: type: object microsoft.graph.webApplicationFirewallProvider: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: webApplicationFirewallProvider type: object properties: displayName: type: string description: The display name of the WAF provider. additionalProperties: type: object microsoft.graph.webApplicationFirewallVerificationStatus: title: webApplicationFirewallVerificationStatus enum: - success - warning - failure - unknownFutureValue type: string microsoft.graph.identityApiConnector: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: identityApiConnector type: object properties: authenticationConfiguration: $ref: '#/components/schemas/microsoft.graph.apiAuthenticationConfigurationBase' displayName: type: - string - 'null' description: The name of the API connector. targetUrl: type: - string - 'null' description: The URL of the API endpoint to call. additionalProperties: type: object microsoft.graph.authenticationEventListener: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: authenticationEventListener type: object properties: authenticationEventsFlowId: type: - string - 'null' description: The identifier of the authenticationEventsFlow object. conditions: $ref: '#/components/schemas/microsoft.graph.authenticationConditions' displayName: type: - string - 'null' description: The display name of the listener. additionalProperties: type: object microsoft.graph.conditionalAccessFilter: title: conditionalAccessFilter type: object properties: mode: $ref: '#/components/schemas/microsoft.graph.filterMode' rule: type: string description: Rule syntax is similar to that used for membership rules for groups in Microsoft Entra ID. For details, see rules with multiple expressions additionalProperties: type: object microsoft.graph.ODataErrors.InnerError: type: object additionalProperties: type: object description: The structure of this object is service-specific microsoft.graph.conditionalAccessPolicyState: title: conditionalAccessPolicyState enum: - enabled - disabled - enabledForReportingButNotEnforced type: string microsoft.graph.customExtensionBehaviorOnError: title: customExtensionBehaviorOnError type: object additionalProperties: type: object microsoft.graph.signInFrequencyInterval: title: signInFrequencyInterval enum: - timeBased - everyTime - unknownFutureValue type: string microsoft.graph.conditionalAccessPlatforms: title: conditionalAccessPlatforms type: object properties: excludePlatforms: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessDevicePlatform' description: 'The possible values are: android, iOS, windows, windowsPhone, macOS, linux, all, unknownFutureValue.' includePlatforms: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessDevicePlatform' description: 'The possible values are: android, iOS, windows, windowsPhone, macOS, linux, all, unknownFutureValue.' additionalProperties: type: object microsoft.graph.baseAuthenticationMethod: title: baseAuthenticationMethod enum: - password - voice - hardwareOath - softwareOath - sms - fido2 - windowsHelloForBusiness - microsoftAuthenticator - temporaryAccessPass - email - x509Certificate - federation - unknownFutureValue - qrCodePin type: string microsoft.graph.apiAuthenticationConfigurationBase: title: apiAuthenticationConfigurationBase type: object additionalProperties: type: object microsoft.graph.namedLocation: allOf: - $ref: '#/components/schemas/microsoft.graph.policyDeletableItem' - title: namedLocation type: object properties: createdDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The Timestamp type represents creation date and time of the location using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. Read-only. format: date-time displayName: type: string description: Human-readable name of the location. id: type: string description: Identifier of a namedLocation object. Read-only. modifiedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The Timestamp type represents last modified date and time of the location using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. Read-only. format: date-time additionalProperties: type: object microsoft.graph.persistentBrowserSessionMode: title: persistentBrowserSessionMode enum: - always - never type: string microsoft.graph.conditionalAccessGrantControls: title: conditionalAccessGrantControls type: object properties: builtInControls: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessGrantControl' description: 'List of values of built-in controls required by the policy. Possible values: block, mfa, compliantDevice, domainJoinedDevice, approvedApplication, compliantApplication, passwordChange, unknownFutureValue, riskRemediation. Use the Prefer: include-unknown-enum-members request header to get the following value in this evolvable enum: riskRemediation.' customAuthenticationFactors: type: array items: type: string description: List of custom controls IDs required by the policy. For more information, see Custom controls. operator: type: - string - 'null' description: 'Defines the relationship of the grant controls. Possible values: AND, OR.' termsOfUse: type: array items: type: string description: List of terms of use IDs required by the policy. authenticationStrength: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicy' additionalProperties: type: object microsoft.graph.signInFrequencyAuthenticationType: title: signInFrequencyAuthenticationType enum: - primaryAndSecondaryAuthentication - secondaryAuthentication - unknownFutureValue type: string microsoft.graph.verifiedIdProfileConfiguration: title: verifiedIdProfileConfiguration type: object properties: acceptedIssuer: type: string description: Trusted Verified ID issuer. claimBindings: type: array items: $ref: '#/components/schemas/microsoft.graph.claimBinding' description: Claim bindings from Verified ID to source attributes. claimBindingSource: $ref: '#/components/schemas/microsoft.graph.claimBindingSource' claimValidation: $ref: '#/components/schemas/microsoft.graph.claimValidation' type: type: string description: Verified ID type. additionalProperties: type: object microsoft.graph.identityUserFlowAttribute: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: identityUserFlowAttribute type: object properties: dataType: $ref: '#/components/schemas/microsoft.graph.identityUserFlowAttributeDataType' description: type: - string - 'null' description: The description of the user flow attribute that's shown to the user at the time of sign up. displayName: type: - string - 'null' description: The display name of the user flow attribute. Supports $filter (eq, ne). userFlowAttributeType: $ref: '#/components/schemas/microsoft.graph.identityUserFlowAttributeType' additionalProperties: type: object microsoft.graph.authenticationMethodModeDetail: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: authenticationMethodModeDetail type: object properties: authenticationMethod: $ref: '#/components/schemas/microsoft.graph.baseAuthenticationMethod' displayName: type: string description: The display name of this mode additionalProperties: type: object microsoft.graph.policyDeletableItem: title: policyDeletableItem type: object properties: deletedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' format: date-time additionalProperties: type: object microsoft.graph.secureSignInSessionControl: allOf: - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl' - title: secureSignInSessionControl type: object additionalProperties: type: object microsoft.graph.verifiedIdProfile: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: verifiedIdProfile type: object properties: description: type: string description: Description for the verified ID profile. Required. faceCheckConfiguration: $ref: '#/components/schemas/microsoft.graph.faceCheckConfiguration' lastModifiedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: DateTime the profile was last modified. Optional. format: date-time name: type: string description: Display name for the verified ID profile. Required. priority: maximum: 2147483647 minimum: -2147483648 type: - number - 'null' description: Defines profile processing priority if multiple profiles are configured. Optional. format: int32 state: $ref: '#/components/schemas/microsoft.graph.verifiedIdProfileState' verifiedIdProfileConfiguration: $ref: '#/components/schemas/microsoft.graph.verifiedIdProfileConfiguration' verifiedIdUsageConfigurations: type: array items: $ref: '#/components/schemas/microsoft.graph.verifiedIdUsageConfiguration' description: Collection defining the usage purpose for the profile. Required. verifierDid: type: string description: Decentralized Identifier (DID) string that represents the verifier in the verifiable credential exchange. Required. additionalProperties: type: object microsoft.graph.userFlowLanguagePage: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: userFlowLanguagePage type: object additionalProperties: type: object microsoft.graph.authenticationStrengthRequirements: title: authenticationStrengthRequirements enum: - none - mfa - unknownFutureValue type: string x-ms-enum-flags: isFlags: true microsoft.graph.conditionalAccessClientApp: title: conditionalAccessClientApp enum: - all - browser - mobileAppsAndDesktopClients - exchangeActiveSync - easSupported - other - unknownFutureValue type: string microsoft.graph.caPoliciesDeletableRoot: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: caPoliciesDeletableRoot type: object properties: namedLocations: type: array items: $ref: '#/components/schemas/microsoft.graph.namedLocation' x-ms-navigationProperty: true policies: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.verifiedIdProfileState: title: verifiedIdProfileState enum: - enabled - disabled - unknownFutureValue type: string microsoft.graph.filterMode: title: filterMode enum: - include - exclude type: string microsoft.graph.conditionalAccessSessionControls: title: conditionalAccessSessionControls type: object properties: applicationEnforcedRestrictions: $ref: '#/components/schemas/microsoft.graph.applicationEnforcedRestrictionsSessionControl' cloudAppSecurity: $ref: '#/components/schemas/microsoft.graph.cloudAppSecuritySessionControl' disableResilienceDefaults: type: - boolean - 'null' description: Session control that determines whether it is acceptable for Microsoft Entra ID to extend existing sessions based on information collected prior to an outage or not. persistentBrowser: $ref: '#/components/schemas/microsoft.graph.persistentBrowserSessionControl' secureSignInSession: $ref: '#/components/schemas/microsoft.graph.secureSignInSessionControl' signInFrequency: $ref: '#/components/schemas/microsoft.graph.signInFrequencySessionControl' additionalProperties: type: object microsoft.graph.persistentBrowserSessionControl: allOf: - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl' - title: persistentBrowserSessionControl type: object properties: mode: $ref: '#/components/schemas/microsoft.graph.persistentBrowserSessionMode' additionalProperties: type: object microsoft.graph.authenticationStrengthRoot: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: authenticationStrengthRoot type: object properties: combinations: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModes' authenticationMethodModes: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModeDetail' description: Names and descriptions of all valid authentication method modes in the system. x-ms-navigationProperty: true policies: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicy' description: A collection of authentication strength policies that exist for this tenant, including both built-in and custom policies. x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.webApplicationFirewallProviderType: title: webApplicationFirewallProviderType enum: - akamai - cloudflare - unknownFutureValue type: string microsoft.graph.authenticationMethodModes: title: authenticationMethodModes enum: - password - voice - hardwareOath - softwareOath - sms - fido2 - windowsHelloForBusiness - microsoftAuthenticatorPush - deviceBasedPush - temporaryAccessPassOneTime - temporaryAccessPassMultiUse - email - x509CertificateSingleFactor - x509CertificateMultiFactor - federatedSingleFactor - federatedMultiFactor - unknownFutureValue - qrCodePin type: string x-ms-enum-flags: isFlags: true microsoft.graph.conditionalAccessAuthenticationFlows: title: conditionalAccessAuthenticationFlows type: object properties: transferMethods: $ref: '#/components/schemas/microsoft.graph.conditionalAccessTransferMethods' additionalProperties: type: object microsoft.graph.claimValidation: title: claimValidation type: object properties: customExtensionId: type: string description: The identifier of a custom extension for claim validation. isEnabled: type: boolean description: Indicates whether claim validation is enabled. additionalProperties: type: object microsoft.graph.fraudProtectionProvider: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: fraudProtectionProvider type: object properties: displayName: type: string description: The display name of the fraud protection provider configuration. additionalProperties: type: object microsoft.graph.signinFrequencyType: title: signinFrequencyType enum: - days - hours type: string microsoft.graph.conditionalAccessConditionSet: title: conditionalAccessConditionSet type: object properties: applications: $ref: '#/components/schemas/microsoft.graph.conditionalAccessApplications' authenticationFlows: $ref: '#/components/schemas/microsoft.graph.conditionalAccessAuthenticationFlows' clientApplications: $ref: '#/components/schemas/microsoft.graph.conditionalAccessClientApplications' clientAppTypes: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessClientApp' description: 'Client application types included in the policy. The possible values are: all, browser, mobileAppsAndDesktopClients, exchangeActiveSync, easSupported, other. Required. The easUnsupported enumeration member will be deprecated in favor of exchangeActiveSync, which includes EAS supported and unsupported platforms.' devices: $ref: '#/components/schemas/microsoft.graph.conditionalAccessDevices' insiderRiskLevels: $ref: '#/components/schemas/microsoft.graph.conditionalAccessInsiderRiskLevels' locations: $ref: '#/components/schemas/microsoft.graph.conditionalAccessLocations' platforms: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPlatforms' servicePrincipalRiskLevels: type: array items: $ref: '#/components/schemas/microsoft.graph.riskLevel' description: 'Service principal risk levels included in the policy. The possible values are: low, medium, high, none, unknownFutureValue.' signInRiskLevels: type: array items: $ref: '#/components/schemas/microsoft.graph.riskLevel' description: 'Sign-in risk levels included in the policy. The possible values are: low, medium, high, hidden, none, unknownFutureValue. Required.' userRiskLevels: type: array items: $ref: '#/components/schemas/microsoft.graph.riskLevel' description: 'User risk levels included in the policy. The possible values are: low, medium, high, hidden, none, unknownFutureValue. Required.' users: $ref: '#/components/schemas/microsoft.graph.conditionalAccessUsers' additionalProperties: type: object microsoft.graph.userAttributeValuesItem: title: userAttributeValuesItem type: object properties: isDefault: type: boolean description: Determines whether the value is set as the default. name: type: - string - 'null' description: The display name of the property displayed to the user in the user flow. value: type: - string - 'null' description: The value that is set when this item is selected. additionalProperties: type: object microsoft.graph.claimBinding: title: claimBinding type: object properties: matchConfidenceLevel: $ref: '#/components/schemas/microsoft.graph.matchConfidenceLevel' sourceAttribute: type: string description: Source attribute name from the source system, for example a directory attribute. verifiedIdClaim: type: string description: Verified ID claim name or path, for example vc.credentialSubject.firstName. additionalProperties: type: object microsoft.graph.conditionalAccessPolicyDetail: title: conditionalAccessPolicyDetail type: object properties: conditions: $ref: '#/components/schemas/microsoft.graph.conditionalAccessConditionSet' grantControls: $ref: '#/components/schemas/microsoft.graph.conditionalAccessGrantControls' sessionControls: $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControls' additionalProperties: type: object microsoft.graph.ODataErrors.ErrorDetails: required: - code - message type: object properties: code: type: string message: type: string target: type: - string - 'null' additionalProperties: type: object microsoft.graph.identityContainer: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: identityContainer type: object properties: apiConnectors: type: array items: $ref: '#/components/schemas/microsoft.graph.identityApiConnector' description: Represents entry point for API connectors. x-ms-navigationProperty: true authenticationEventListeners: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationEventListener' description: Represents listeners for custom authentication extension events in Azure AD for workforce and customers. x-ms-navigationProperty: true authenticationEventsFlows: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationEventsFlow' description: Represents the entry point for self-service sign-up and sign-in user flows in both Microsoft Entra workforce and external tenants. x-ms-navigationProperty: true b2xUserFlows: type: array items: $ref: '#/components/schemas/microsoft.graph.b2xIdentityUserFlow' description: Represents entry point for B2X/self-service sign-up identity userflows. x-ms-navigationProperty: true conditionalAccess: $ref: '#/components/schemas/microsoft.graph.conditionalAccessRoot' customAuthenticationExtensions: type: array items: $ref: '#/components/schemas/microsoft.graph.customAuthenticationExtension' description: Represents custom extensions to authentication flows in Azure AD for workforce and customers. x-ms-navigationProperty: true identityProviders: type: array items: $ref: '#/components/schemas/microsoft.graph.identityProviderBase' x-ms-navigationProperty: true riskPrevention: $ref: '#/components/schemas/microsoft.graph.riskPreventionContainer' userFlowAttributes: type: array items: $ref: '#/components/schemas/microsoft.graph.identityUserFlowAttribute' description: Represents entry point for identity userflow attributes. x-ms-navigationProperty: true verifiedId: $ref: '#/components/schemas/microsoft.graph.identityVerifiedIdRoot' additionalProperties: type: object microsoft.graph.conditionalAccessClientApplications: title: conditionalAccessClientApplications type: object properties: excludeServicePrincipals: type: array items: type: string description: Service principal IDs excluded from the policy scope. includeServicePrincipals: type: array items: type: string description: Service principal IDs included in the policy scope, or ServicePrincipalsInMyTenant. servicePrincipalFilter: $ref: '#/components/schemas/microsoft.graph.conditionalAccessFilter' additionalProperties: type: object microsoft.graph.identityProvider: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: identityProvider type: object properties: clientId: type: - string - 'null' description: The client ID for the application. This is the client ID obtained when registering the application with the identity provider. Required. Not nullable. clientSecret: type: - string - 'null' description: The client secret for the application. This is the client secret obtained when registering the application with the identity provider. This is write-only. A read operation will return . Required. Not nullable. name: type: - string - 'null' description: The display name of the identity provider. Not nullable. type: type: - string - 'null' description: 'The identity provider type is a required field. For B2B scenario: Google, Facebook. For B2C scenario: Microsoft, Google, Amazon, LinkedIn, Facebook, GitHub, Twitter, Weibo, QQ, WeChat, OpenIDConnect. Not nullable.' additionalProperties: type: object microsoft.graph.cloudAppSecuritySessionControl: allOf: - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl' - title: cloudAppSecuritySessionControl type: object properties: cloudAppSecurityType: $ref: '#/components/schemas/microsoft.graph.cloudAppSecuritySessionControlType' additionalProperties: type: object microsoft.graph.claimBindingSource: title: claimBindingSource enum: - directory - unknownFutureValue type: string microsoft.graph.identityUserFlowAttributeType: title: identityUserFlowAttributeType enum: - builtIn - custom - required - unknownFutureValue type: string microsoft.graph.identityUserFlow: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: identityUserFlow type: object properties: userFlowType: $ref: '#/components/schemas/microsoft.graph.userFlowType' userFlowTypeVersion: type: - number - 'null' format: float additionalProperties: type: object microsoft.graph.conditionalAccessGuestsOrExternalUsers: title: conditionalAccessGuestsOrExternalUsers type: object properties: externalTenants: $ref: '#/components/schemas/microsoft.graph.conditionalAccessExternalTenants' guestOrExternalUserTypes: $ref: '#/components/schemas/microsoft.graph.conditionalAccessGuestOrExternalUserTypes' additionalProperties: type: object microsoft.graph.conditionalAccessExternalTenantsMembershipKind: title: conditionalAccessExternalTenantsMembershipKind enum: - all - enumerated - unknownFutureValue type: string microsoft.graph.authenticationConditions: title: authenticationConditions type: object properties: applications: $ref: '#/components/schemas/microsoft.graph.authenticationConditionsApplications' additionalProperties: type: object microsoft.graph.webApplicationFirewallDnsConfiguration: title: webApplicationFirewallDnsConfiguration type: object properties: isDomainVerified: type: boolean description: Indicates whether the domain owning this DNS record has been verified by the WAF provider. isProxied: type: boolean description: Indicates whether traffic for this DNS record is proxied through the WAF provider's network (for example, using a CDN or reverse proxy). name: type: - string - 'null' description: The DNS record name (for example, www.contoso.com or contoso.com). This is the host or zone name to which the configuration applies. recordType: $ref: '#/components/schemas/microsoft.graph.webApplicationFirewallDnsRecordType' value: type: - string - 'null' description: The value of the DNS record. additionalProperties: type: object microsoft.graph.matchConfidenceLevel: title: matchConfidenceLevel enum: - exact - relaxed - unknownFutureValue type: string microsoft.graph.conditionalAccessTransferMethods: title: conditionalAccessTransferMethods enum: - none - deviceCodeFlow - authenticationTransfer - unknownFutureValue type: string x-ms-enum-flags: isFlags: true microsoft.graph.entity: title: entity type: object properties: id: type: string description: The unique identifier for an entity. Read-only. additionalProperties: type: object microsoft.graph.verifiedIdUsageConfigurationPurpose: title: verifiedIdUsageConfigurationPurpose enum: - recovery - onboarding - all - unknownFutureValue type: string microsoft.graph.templateScenarios: title: templateScenarios enum: - new - secureFoundation - zeroTrust - remoteWork - protectAdmins - emergingThreats - unknownFutureValue type: string x-ms-enum-flags: isFlags: true microsoft.graph.b2xIdentityUserFlow: allOf: - $ref: '#/components/schemas/microsoft.graph.identityUserFlow' - title: b2xIdentityUserFlow type: object properties: apiConnectorConfiguration: $ref: '#/components/schemas/microsoft.graph.userFlowApiConnectorConfiguration' identityProviders: type: array items: $ref: '#/components/schemas/microsoft.graph.identityProvider' description: The identity providers included in the user flow. x-ms-navigationProperty: true languages: type: array items: $ref: '#/components/schemas/microsoft.graph.userFlowLanguageConfiguration' description: The languages supported for customization within the user flow. Language customization is enabled by default in self-service sign-up user flow. You can't create custom languages in self-service sign-up user flows. x-ms-navigationProperty: true userAttributeAssignments: type: array items: $ref: '#/components/schemas/microsoft.graph.identityUserFlowAttributeAssignment' description: The user attribute assignments included in the user flow. x-ms-navigationProperty: true userFlowIdentityProviders: type: array items: $ref: '#/components/schemas/microsoft.graph.identityProviderBase' x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.customExtensionEndpointConfiguration: title: customExtensionEndpointConfiguration type: object additionalProperties: type: object microsoft.graph.customAuthenticationExtension: allOf: - $ref: '#/components/schemas/microsoft.graph.customCalloutExtension' - title: customAuthenticationExtension type: object properties: behaviorOnError: $ref: '#/components/schemas/microsoft.graph.customExtensionBehaviorOnError' additionalProperties: type: object microsoft.graph.identityUserFlowAttributeInputType: title: identityUserFlowAttributeInputType enum: - textBox - dateTimeDropdown - radioSingleSelect - dropdownSingleSelect - emailBox - checkboxMultiSelect type: string microsoft.graph.customExtensionAuthenticationConfiguration: title: customExtensionAuthenticationConfiguration type: object additionalProperties: type: object microsoft.graph.ODataErrors.ODataError: required: - error type: object properties: error: $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError' additionalProperties: type: object microsoft.graph.conditionalAccessDevices: title: conditionalAccessDevices type: object properties: deviceFilter: $ref: '#/components/schemas/microsoft.graph.conditionalAccessFilter' additionalProperties: type: object microsoft.graph.customCalloutExtension: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: customCalloutExtension type: object properties: authenticationConfiguration: $ref: '#/components/schemas/microsoft.graph.customExtensionAuthenticationConfiguration' clientConfiguration: $ref: '#/components/schemas/microsoft.graph.customExtensionClientConfiguration' description: type: - string - 'null' description: Description for the customCalloutExtension object. displayName: type: - string - 'null' description: Display name for the customCalloutExtension object. endpointConfiguration: $ref: '#/components/schemas/microsoft.graph.customExtensionEndpointConfiguration' additionalProperties: type: object microsoft.graph.authenticationContextClassReference: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: authenticationContextClassReference type: object properties: description: type: - string - 'null' description: A short explanation of the policies that are enforced by authenticationContextClassReference. This value should be used to provide secondary text to describe the authentication context class reference when building user-facing admin experiences. For example, a selection UX. displayName: type: - string - 'null' description: The display name is the friendly name of the authenticationContextClassReference object. This value should be used to identify the authentication context class reference when building user-facing admin experiences. For example, a selection UX. isAvailable: type: - boolean - 'null' description: Indicates whether the authenticationContextClassReference has been published by the security admin and is ready for use by apps. When it's set to false, it shouldn't be shown in authentication context selection UX, or used to protect app resources. It's shown and available for Conditional Access policy authoring. The default value is false. Supports $filter (eq). additionalProperties: type: object microsoft.graph.conditionalAccessSessionControl: title: conditionalAccessSessionControl type: object properties: isEnabled: type: - boolean - 'null' description: Specifies whether the session control is enabled. additionalProperties: type: object microsoft.graph.riskPreventionContainer: title: riskPreventionContainer type: object properties: fraudProtectionProviders: type: array items: $ref: '#/components/schemas/microsoft.graph.fraudProtectionProvider' description: Represents entry point for fraud protection provider configurations for Microsoft Entra External ID tenants. x-ms-navigationProperty: true webApplicationFirewallProviders: type: array items: $ref: '#/components/schemas/microsoft.graph.webApplicationFirewallProvider' description: Collection of WAF provider configurations registered in the External ID tenant. x-ms-navigationProperty: true webApplicationFirewallVerifications: type: array items: $ref: '#/components/schemas/microsoft.graph.webApplicationFirewallVerificationModel' description: Collection of verification operations performed for domains or hosts with WAF providers registered in the External ID tenant. x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.authenticationConditionApplication: title: authenticationConditionApplication type: object properties: appId: type: string description: The identifier for an application corresponding to a condition which will trigger an authenticationEventListener. additionalProperties: type: object microsoft.graph.cloudAppSecuritySessionControlType: title: cloudAppSecuritySessionControlType enum: - mcasConfigured - monitorOnly - blockDownloads - unknownFutureValue type: string microsoft.graph.conditionalAccessTemplate: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: conditionalAccessTemplate type: object properties: description: type: string description: The user-friendly name of the template. details: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicyDetail' name: type: string description: The user-friendly name of the template. scenarios: $ref: '#/components/schemas/microsoft.graph.templateScenarios' additionalProperties: type: object microsoft.graph.authenticationStrengthPolicyType: title: authenticationStrengthPolicyType enum: - builtIn - custom - unknownFutureValue type: string microsoft.graph.authenticationConditionsApplications: title: authenticationConditionsApplications type: object properties: includeApplications: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationConditionApplication' x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.conditionalAccessExternalTenants: title: conditionalAccessExternalTenants type: object properties: membershipKind: $ref: '#/components/schemas/microsoft.graph.conditionalAccessExternalTenantsMembershipKind' additionalProperties: type: object microsoft.graph.conditionalAccessGuestOrExternalUserTypes: title: conditionalAccessGuestOrExternalUserTypes enum: - none - internalGuest - b2bCollaborationGuest - b2bCollaborationMember - b2bDirectConnectUser - otherExternalUser - serviceProvider - unknownFutureValue type: string x-ms-enum-flags: isFlags: true microsoft.graph.userFlowApiConnectorConfiguration: title: userFlowApiConnectorConfiguration type: object properties: postAttributeCollection: $ref: '#/components/schemas/microsoft.graph.identityApiConnector' postFederationSignup: $ref: '#/components/schemas/microsoft.graph.identityApiConnector' additionalProperties: type: object microsoft.graph.conditionalAccessDevicePlatform: title: conditionalAccessDevicePlatform enum: - android - iOS - windows - windowsPhone - macOS - all - unknownFutureValue - linux type: string microsoft.graph.ODataErrors.MainError: required: - code - message type: object properties: code: type: string message: type: string x-ms-primary-error-message: true target: type: - string - 'null' details: type: array items: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails' innerError: $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError' additionalProperties: type: object microsoft.graph.genericError: title: genericError type: object properties: code: type: - string - 'null' description: The error code. message: type: - string - 'null' description: The error message. additionalProperties: type: object microsoft.graph.signInFrequencySessionControl: allOf: - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl' - title: signInFrequencySessionControl type: object properties: authenticationType: $ref: '#/components/schemas/microsoft.graph.signInFrequencyAuthenticationType' frequencyInterval: $ref: '#/components/schemas/microsoft.graph.signInFrequencyInterval' type: $ref: '#/components/schemas/microsoft.graph.signinFrequencyType' value: maximum: 2147483647 minimum: -2147483648 type: - number - 'null' description: The number of days or hours. format: int32 additionalProperties: type: object microsoft.graph.conditionalAccessInsiderRiskLevels: title: conditionalAccessInsiderRiskLevels enum: - minor - moderate - elevated - unknownFutureValue type: string x-ms-enum-flags: isFlags: true responses: error: description: error content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError' securitySchemes: azureaadv2: type: oauth2 flows: authorizationCode: authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token scopes: {}