openapi: 3.2.0 info: title: Identity.SignIns Identity Protection.identity Protection… version: v1.0 servers: - url: https://graph.microsoft.com/v1.0/ description: Core security: - azureaadv2: [] tags: - name: identityProtection.identityProtectionRoot paths: /identityProtection: get: tags: - identityProtection.identityProtectionRoot summary: Get identityProtection operationId: identityProtection.identityProtectionRoot_GetIdentityProtectionRoot parameters: - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved entity content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.identityProtectionRoot' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - identityProtection.identityProtectionRoot summary: Update identityProtection operationId: identityProtection.identityProtectionRoot_UpdateIdentityProtectionRoot requestBody: description: New property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.identityProtectionRoot' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.identityProtectionRoot' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation components: schemas: microsoft.graph.geoCoordinates: title: geoCoordinates type: object properties: altitude: type: - number - 'null' description: Optional. The altitude (height), in feet, above sea level for the item. Read-only. format: double latitude: type: - number - 'null' description: Optional. The latitude, in decimal, for the item. Read-only. format: double longitude: type: - number - 'null' description: Optional. The longitude, in decimal, for the item. Read-only. format: double additionalProperties: type: object microsoft.graph.activityType: title: activityType enum: - signin - user - unknownFutureValue - servicePrincipal type: string microsoft.graph.ODataErrors.ODataError: required: - error type: object properties: error: $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError' additionalProperties: type: object microsoft.graph.riskDetection: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: riskDetection type: object properties: activity: $ref: '#/components/schemas/microsoft.graph.activityType' activityDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: 'Date and time that the risky activity occurred. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is look like this: 2014-01-01T00:00:00Z' format: date-time additionalInfo: type: - string - 'null' description: 'Additional information associated with the risk detection in JSON format. For example, ''[{/''Key/'':/''userAgent/'',/''Value/'':/''Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36/''}]''. Possible keys in the additionalInfo JSON string are: userAgent, alertUrl, relatedEventTimeInUtc, relatedUserAgent, deviceInformation, relatedLocation, requestId, correlationId, lastActivityTimeInUtc, malwareName, clientLocation, clientIp, riskReasons. For more information about riskReasons and possible values, see riskReasons values.' correlationId: type: - string - 'null' description: Correlation ID of the sign-in associated with the risk detection. This property is null if the risk detection is not associated with a sign-in. detectedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: 'Date and time that the risk was detected. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 looks like this: 2014-01-01T00:00:00Z' format: date-time detectionTimingType: $ref: '#/components/schemas/microsoft.graph.riskDetectionTimingType' ipAddress: type: - string - 'null' description: Provides the IP address of the client from where the risk occurred. lastUpdatedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: 'Date and time that the risk detection was last updated. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is look like this: 2014-01-01T00:00:00Z' format: date-time location: $ref: '#/components/schemas/microsoft.graph.signInLocation' requestId: type: - string - 'null' description: Request ID of the sign-in associated with the risk detection. This property is null if the risk detection is not associated with a sign-in. riskDetail: $ref: '#/components/schemas/microsoft.graph.riskDetail' riskEventType: type: - string - 'null' description: The type of risk event detected. The possible values are adminConfirmedUserCompromised, anomalousToken, anomalousUserActivity, anonymizedIPAddress, generic, impossibleTravel, investigationsThreatIntelligence, suspiciousSendingPatterns, leakedCredentials, maliciousIPAddress,malwareInfectedIPAddress, mcasSuspiciousInboxManipulationRules, newCountry, passwordSpray,riskyIPAddress, suspiciousAPITraffic, suspiciousBrowser,suspiciousInboxForwarding, suspiciousIPAddress, tokenIssuerAnomaly, unfamiliarFeatures, unlikelyTravel. If the risk detection is a premium detection, will show generic. For more information about each value, see Risk types and detection. riskLevel: $ref: '#/components/schemas/microsoft.graph.riskLevel' riskState: $ref: '#/components/schemas/microsoft.graph.riskState' source: type: - string - 'null' description: Source of the risk detection. For example, activeDirectory. tokenIssuerType: $ref: '#/components/schemas/microsoft.graph.tokenIssuerType' userDisplayName: type: - string - 'null' description: The user principal name (UPN) of the user. userId: type: - string - 'null' description: Unique ID of the user. userPrincipalName: type: - string - 'null' description: The user principal name (UPN) of the user. additionalProperties: type: object microsoft.graph.riskDetail: title: riskDetail enum: - none - adminGeneratedTemporaryPassword - userPerformedSecuredPasswordChange - userPerformedSecuredPasswordReset - adminConfirmedSigninSafe - aiConfirmedSigninSafe - userPassedMFADrivenByRiskBasedPolicy - adminDismissedAllRiskForUser - adminConfirmedSigninCompromised - hidden - adminConfirmedUserCompromised - unknownFutureValue - m365DAdminDismissedDetection - adminConfirmedServicePrincipalCompromised - adminDismissedAllRiskForServicePrincipal - userChangedPasswordOnPremises - adminDismissedRiskForSignIn - adminConfirmedAccountSafe - microsoftRevokedSessions type: string microsoft.graph.riskyServicePrincipal: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: riskyServicePrincipal type: object properties: appId: type: - string - 'null' description: The globally unique identifier for the associated application (its appId property), if any. displayName: type: - string - 'null' description: The display name for the service principal. isEnabled: type: - boolean - 'null' description: true if the service principal account is enabled; otherwise, false. isProcessing: type: - boolean - 'null' description: Indicates whether Microsoft Entra ID is currently processing the service principal's risky state. riskDetail: $ref: '#/components/schemas/microsoft.graph.riskDetail' riskLastUpdatedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The date and time that the risk state was last updated. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2021 is 2021-01-01T00:00:00Z. Supports $filter (eq). format: date-time riskLevel: $ref: '#/components/schemas/microsoft.graph.riskLevel' riskState: $ref: '#/components/schemas/microsoft.graph.riskState' servicePrincipalType: type: - string - 'null' description: Identifies whether the service principal represents an Application, a ManagedIdentity, or a legacy application (socialIdp). This is set by Microsoft Entra ID internally and is inherited from servicePrincipal. history: type: array items: $ref: '#/components/schemas/microsoft.graph.riskyServicePrincipalHistoryItem' description: Represents the risk history of Microsoft Entra service principals. x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.ODataErrors.InnerError: type: object additionalProperties: type: object description: The structure of this object is service-specific microsoft.graph.riskServicePrincipalActivity: title: riskServicePrincipalActivity type: object properties: detail: $ref: '#/components/schemas/microsoft.graph.riskDetail' riskEventTypes: type: array items: type: - string - 'null' description: 'The type of risk event detected. The possible values are: investigationsThreatIntelligence, generic, adminConfirmedServicePrincipalCompromised, suspiciousSignins, leakedCredentials, anomalousServicePrincipalActivity, maliciousApplication, suspiciousApplication.' additionalProperties: type: object microsoft.graph.signInLocation: title: signInLocation type: object properties: city: type: - string - 'null' description: Provides the city where the sign-in originated and is determined using latitude/longitude information from the sign-in activity. countryOrRegion: type: - string - 'null' description: Provides the country code info (two letter code) where the sign-in originated. This is calculated using latitude/longitude information from the sign-in activity. geoCoordinates: $ref: '#/components/schemas/microsoft.graph.geoCoordinates' state: type: - string - 'null' description: Provides the State where the sign-in originated. This is calculated using latitude/longitude information from the sign-in activity. additionalProperties: type: object microsoft.graph.ODataErrors.ErrorDetails: required: - code - message type: object properties: code: type: string message: type: string target: type: - string - 'null' additionalProperties: type: object microsoft.graph.tokenIssuerType: title: tokenIssuerType enum: - AzureAD - ADFederationServices - UnknownFutureValue - AzureADBackupAuth - ADFederationServicesMFAAdapter - NPSExtension type: string microsoft.graph.riskDetectionTimingType: title: riskDetectionTimingType enum: - notDefined - realtime - nearRealtime - offline - unknownFutureValue type: string microsoft.graph.riskUserActivity: title: riskUserActivity type: object properties: detail: $ref: '#/components/schemas/microsoft.graph.riskDetail' riskEventTypes: type: array items: type: - string - 'null' description: The type of risk event detected. additionalProperties: type: object microsoft.graph.riskLevel: title: riskLevel enum: - low - medium - high - hidden - none - unknownFutureValue type: string microsoft.graph.riskyUser: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: riskyUser type: object properties: isDeleted: type: - boolean - 'null' description: 'Indicates whether the user is deleted. The possible values are: true, false.' isProcessing: type: - boolean - 'null' description: Indicates whether the backend is processing a user's risky state. riskDetail: $ref: '#/components/schemas/microsoft.graph.riskDetail' riskLastUpdatedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The date and time that the risky user was last updated. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. format: date-time riskLevel: $ref: '#/components/schemas/microsoft.graph.riskLevel' riskState: $ref: '#/components/schemas/microsoft.graph.riskState' userDisplayName: type: - string - 'null' description: Risky user display name. userPrincipalName: type: - string - 'null' description: Risky user principal name. history: type: array items: $ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem' description: The activity related to user risk level change x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.servicePrincipalRiskDetection: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: servicePrincipalRiskDetection type: object properties: activity: $ref: '#/components/schemas/microsoft.graph.activityType' activityDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: Date and time when the risky activity occurred. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z format: date-time additionalInfo: type: - string - 'null' description: Additional information associated with the risk detection. This string value is represented as a JSON object with the quotations escaped. appId: type: - string - 'null' description: The unique identifier for the associated application. correlationId: type: - string - 'null' description: Correlation ID of the sign-in activity associated with the risk detection. This property is null if the risk detection is not associated with a sign-in activity. detectedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: Date and time when the risk was detected. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. format: date-time detectionTimingType: $ref: '#/components/schemas/microsoft.graph.riskDetectionTimingType' ipAddress: type: - string - 'null' description: Provides the IP address of the client from where the risk occurred. keyIds: type: array items: type: - string - 'null' description: The unique identifier for the key credential associated with the risk detection. lastUpdatedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: Date and time when the risk detection was last updated. format: date-time location: $ref: '#/components/schemas/microsoft.graph.signInLocation' requestId: type: - string - 'null' description: Request identifier of the sign-in activity associated with the risk detection. This property is null if the risk detection is not associated with a sign-in activity. Supports $filter (eq). riskDetail: $ref: '#/components/schemas/microsoft.graph.riskDetail' riskEventType: type: - string - 'null' description: 'The type of risk event detected. The possible values are: investigationsThreatIntelligence, generic, adminConfirmedServicePrincipalCompromised, suspiciousSignins, leakedCredentials, anomalousServicePrincipalActivity, maliciousApplication, suspiciousApplication.' riskLevel: $ref: '#/components/schemas/microsoft.graph.riskLevel' riskState: $ref: '#/components/schemas/microsoft.graph.riskState' servicePrincipalDisplayName: type: - string - 'null' description: The display name for the service principal. servicePrincipalId: type: - string - 'null' description: The unique identifier for the service principal. Supports $filter (eq). source: type: - string - 'null' description: Source of the risk detection. For example, identityProtection. tokenIssuerType: $ref: '#/components/schemas/microsoft.graph.tokenIssuerType' additionalProperties: type: object microsoft.graph.ODataErrors.MainError: required: - code - message type: object properties: code: type: string message: type: string x-ms-primary-error-message: true target: type: - string - 'null' details: type: array items: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails' innerError: $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError' additionalProperties: type: object microsoft.graph.riskState: title: riskState enum: - none - confirmedSafe - remediated - dismissed - atRisk - confirmedCompromised - unknownFutureValue type: string microsoft.graph.entity: title: entity type: object properties: id: type: string description: The unique identifier for an entity. Read-only. additionalProperties: type: object microsoft.graph.riskyUserHistoryItem: allOf: - $ref: '#/components/schemas/microsoft.graph.riskyUser' - title: riskyUserHistoryItem type: object properties: activity: $ref: '#/components/schemas/microsoft.graph.riskUserActivity' initiatedBy: type: - string - 'null' description: The ID of actor that does the operation. userId: type: - string - 'null' description: The ID of the user. additionalProperties: type: object microsoft.graph.identityProtectionRoot: title: identityProtectionRoot type: object properties: riskDetections: type: array items: $ref: '#/components/schemas/microsoft.graph.riskDetection' description: Risk detection in Microsoft Entra ID Protection and the associated information about the detection. x-ms-navigationProperty: true riskyServicePrincipals: type: array items: $ref: '#/components/schemas/microsoft.graph.riskyServicePrincipal' description: Microsoft Entra service principals that are at risk. x-ms-navigationProperty: true riskyUsers: type: array items: $ref: '#/components/schemas/microsoft.graph.riskyUser' description: Users that are flagged as at-risk by Microsoft Entra ID Protection. x-ms-navigationProperty: true servicePrincipalRiskDetections: type: array items: $ref: '#/components/schemas/microsoft.graph.servicePrincipalRiskDetection' description: Represents information about detected at-risk service principals in a Microsoft Entra tenant. x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.riskyServicePrincipalHistoryItem: allOf: - $ref: '#/components/schemas/microsoft.graph.riskyServicePrincipal' - title: riskyServicePrincipalHistoryItem type: object properties: activity: $ref: '#/components/schemas/microsoft.graph.riskServicePrincipalActivity' initiatedBy: type: - string - 'null' description: The identifier of the actor of the operation. additionalProperties: type: object responses: error: description: error content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError' securitySchemes: azureaadv2: type: oauth2 flows: authorizationCode: authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token scopes: {}