openapi: 3.2.0 info: title: Identity.SignIns Identity Protection.risky Service… version: v1.0 servers: - url: https://graph.microsoft.com/v1.0/ description: Core security: - azureaadv2: [] tags: - name: identityProtection.riskyServicePrincipal paths: /identityProtection/riskyServicePrincipals: get: tags: - identityProtection.riskyServicePrincipal summary: List riskyServicePrincipals description: Retrieve the properties and relationships of riskyServicePrincipal objects. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/identityprotectionroot-list-riskyserviceprincipals?view=graph-rest-1.0 operationId: identityProtection_ListRiskyServicePrincipal parameters: - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.riskyServicePrincipalCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - identityProtection.riskyServicePrincipal summary: Create new navigation property to riskyServicePrincipals for identityProtection operationId: identityProtection_CreateRiskyServicePrincipal requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyServicePrincipal' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyServicePrincipal' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identityProtection/riskyServicePrincipals/{riskyServicePrincipal-id}: get: tags: - identityProtection.riskyServicePrincipal summary: Get riskyServicePrincipal description: Read the properties and relationships of a riskyServicePrincipal object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/riskyserviceprincipal-get?view=graph-rest-1.0 operationId: identityProtection_GetRiskyServicePrincipal parameters: - name: riskyServicePrincipal-id in: path description: The unique identifier of riskyServicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: riskyServicePrincipal - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyServicePrincipal' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - identityProtection.riskyServicePrincipal summary: Update the navigation property riskyServicePrincipals in identityProtection operationId: identityProtection_UpdateRiskyServicePrincipal parameters: - name: riskyServicePrincipal-id in: path description: The unique identifier of riskyServicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: riskyServicePrincipal requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyServicePrincipal' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyServicePrincipal' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - identityProtection.riskyServicePrincipal summary: Delete navigation property riskyServicePrincipals for identityProtection operationId: identityProtection_DeleteRiskyServicePrincipal parameters: - name: riskyServicePrincipal-id in: path description: The unique identifier of riskyServicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: riskyServicePrincipal - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identityProtection/riskyServicePrincipals/{riskyServicePrincipal-id}/history: get: tags: - identityProtection.riskyServicePrincipal summary: List history (risk history of riskyServicePrincipal) description: Get the risk history of a riskyServicePrincipal object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/riskyserviceprincipal-list-history?view=graph-rest-1.0 operationId: identityProtection.riskyServicePrincipal_ListHistory parameters: - name: riskyServicePrincipal-id in: path description: The unique identifier of riskyServicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: riskyServicePrincipal - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.riskyServicePrincipalHistoryItemCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - identityProtection.riskyServicePrincipal summary: Create new navigation property to history for identityProtection operationId: identityProtection.riskyServicePrincipal_CreateHistory parameters: - name: riskyServicePrincipal-id in: path description: The unique identifier of riskyServicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: riskyServicePrincipal requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyServicePrincipalHistoryItem' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyServicePrincipalHistoryItem' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identityProtection/riskyServicePrincipals/{riskyServicePrincipal-id}/history/{riskyServicePrincipalHistoryItem-id}: get: tags: - identityProtection.riskyServicePrincipal summary: Get history from identityProtection description: Represents the risk history of Microsoft Entra service principals. operationId: identityProtection.riskyServicePrincipal_GetHistory parameters: - name: riskyServicePrincipal-id in: path description: The unique identifier of riskyServicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: riskyServicePrincipal - name: riskyServicePrincipalHistoryItem-id in: path description: The unique identifier of riskyServicePrincipalHistoryItem required: true style: simple schema: type: string x-ms-docs-key-type: riskyServicePrincipalHistoryItem - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyServicePrincipalHistoryItem' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - identityProtection.riskyServicePrincipal summary: Update the navigation property history in identityProtection operationId: identityProtection.riskyServicePrincipal_UpdateHistory parameters: - name: riskyServicePrincipal-id in: path description: The unique identifier of riskyServicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: riskyServicePrincipal - name: riskyServicePrincipalHistoryItem-id in: path description: The unique identifier of riskyServicePrincipalHistoryItem required: true style: simple schema: type: string x-ms-docs-key-type: riskyServicePrincipalHistoryItem requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyServicePrincipalHistoryItem' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyServicePrincipalHistoryItem' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - identityProtection.riskyServicePrincipal summary: Delete navigation property history for identityProtection operationId: identityProtection.riskyServicePrincipal_DeleteHistory parameters: - name: riskyServicePrincipal-id in: path description: The unique identifier of riskyServicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: riskyServicePrincipal - name: riskyServicePrincipalHistoryItem-id in: path description: The unique identifier of riskyServicePrincipalHistoryItem required: true style: simple schema: type: string x-ms-docs-key-type: riskyServicePrincipalHistoryItem - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identityProtection/riskyServicePrincipals/{riskyServicePrincipal-id}/history/$count: get: tags: - identityProtection.riskyServicePrincipal summary: Get the number of the resource operationId: identityProtection.riskyServicePrincipal.history_GetCount parameters: - name: riskyServicePrincipal-id in: path description: The unique identifier of riskyServicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: riskyServicePrincipal - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' /identityProtection/riskyServicePrincipals/$count: get: tags: - identityProtection.riskyServicePrincipal summary: Get the number of the resource operationId: identityProtection.riskyServicePrincipal_GetCount parameters: - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' /identityProtection/riskyServicePrincipals/microsoft.graph.confirmCompromised: post: tags: - identityProtection.riskyServicePrincipal summary: Invoke action confirmCompromised description: Confirm one or more riskyServicePrincipal objects as compromised. This action sets the targeted service principal account's risk level to high. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/riskyserviceprincipal-confirmcompromised?view=graph-rest-1.0 operationId: identityProtection.riskyServicePrincipal_confirmCompromised requestBody: description: Action parameters content: application/json: schema: type: object properties: servicePrincipalIds: type: array items: type: - string - 'null' additionalProperties: type: object required: true responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action /identityProtection/riskyServicePrincipals/microsoft.graph.dismiss: post: tags: - identityProtection.riskyServicePrincipal summary: Invoke action dismiss description: Dismiss the risk of one or more riskyServicePrincipal objects. This action sets the targeted service principal account's risk level to none. You can dismiss up to 60 service principal accounts in one request. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/riskyserviceprincipal-dismiss?view=graph-rest-1.0 operationId: identityProtection.riskyServicePrincipal_dismiss requestBody: description: Action parameters content: application/json: schema: type: object properties: servicePrincipalIds: type: array items: type: - string - 'null' additionalProperties: type: object required: true responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action components: parameters: count: name: $count in: query description: Include count of items style: form explode: false schema: type: boolean filter: name: $filter in: query description: Filter items by property values style: form explode: false schema: type: string search: name: $search in: query description: Search items by search phrases style: form explode: false schema: type: string skip: name: $skip in: query description: Skip the first n items style: form explode: false schema: minimum: 0 type: integer top: name: $top in: query description: Show only the first n items style: form explode: false schema: minimum: 0 type: integer example: 50 responses: microsoft.graph.riskyServicePrincipalHistoryItemCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyServicePrincipalHistoryItemCollectionResponse' microsoft.graph.riskyServicePrincipalCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyServicePrincipalCollectionResponse' ODataCountResponse: description: The count of the resource content: text/plain: schema: $ref: '#/components/schemas/ODataCountResponse' error: description: error content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError' schemas: microsoft.graph.ODataErrors.ODataError: required: - error type: object properties: error: $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError' additionalProperties: type: object microsoft.graph.riskyServicePrincipalHistoryItemCollectionResponse: title: Collection of riskyServicePrincipalHistoryItem type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.riskyServicePrincipalHistoryItem' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.riskyServicePrincipalCollectionResponse: title: Collection of riskyServicePrincipal type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.riskyServicePrincipal' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.riskDetail: title: riskDetail enum: - none - adminGeneratedTemporaryPassword - userPerformedSecuredPasswordChange - userPerformedSecuredPasswordReset - adminConfirmedSigninSafe - aiConfirmedSigninSafe - userPassedMFADrivenByRiskBasedPolicy - adminDismissedAllRiskForUser - adminConfirmedSigninCompromised - hidden - adminConfirmedUserCompromised - unknownFutureValue - m365DAdminDismissedDetection - adminConfirmedServicePrincipalCompromised - adminDismissedAllRiskForServicePrincipal - userChangedPasswordOnPremises - adminDismissedRiskForSignIn - adminConfirmedAccountSafe - microsoftRevokedSessions type: string microsoft.graph.riskyServicePrincipal: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: riskyServicePrincipal type: object properties: appId: type: - string - 'null' description: The globally unique identifier for the associated application (its appId property), if any. displayName: type: - string - 'null' description: The display name for the service principal. isEnabled: type: - boolean - 'null' description: true if the service principal account is enabled; otherwise, false. isProcessing: type: - boolean - 'null' description: Indicates whether Microsoft Entra ID is currently processing the service principal's risky state. riskDetail: $ref: '#/components/schemas/microsoft.graph.riskDetail' riskLastUpdatedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The date and time that the risk state was last updated. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2021 is 2021-01-01T00:00:00Z. Supports $filter (eq). format: date-time riskLevel: $ref: '#/components/schemas/microsoft.graph.riskLevel' riskState: $ref: '#/components/schemas/microsoft.graph.riskState' servicePrincipalType: type: - string - 'null' description: Identifies whether the service principal represents an Application, a ManagedIdentity, or a legacy application (socialIdp). This is set by Microsoft Entra ID internally and is inherited from servicePrincipal. history: type: array items: $ref: '#/components/schemas/microsoft.graph.riskyServicePrincipalHistoryItem' description: Represents the risk history of Microsoft Entra service principals. x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.ODataErrors.InnerError: type: object additionalProperties: type: object description: The structure of this object is service-specific microsoft.graph.riskServicePrincipalActivity: title: riskServicePrincipalActivity type: object properties: detail: $ref: '#/components/schemas/microsoft.graph.riskDetail' riskEventTypes: type: array items: type: - string - 'null' description: 'The type of risk event detected. The possible values are: investigationsThreatIntelligence, generic, adminConfirmedServicePrincipalCompromised, suspiciousSignins, leakedCredentials, anomalousServicePrincipalActivity, maliciousApplication, suspiciousApplication.' additionalProperties: type: object microsoft.graph.ODataErrors.ErrorDetails: required: - code - message type: object properties: code: type: string message: type: string target: type: - string - 'null' additionalProperties: type: object microsoft.graph.riskLevel: title: riskLevel enum: - low - medium - high - hidden - none - unknownFutureValue type: string microsoft.graph.ODataErrors.MainError: required: - code - message type: object properties: code: type: string message: type: string x-ms-primary-error-message: true target: type: - string - 'null' details: type: array items: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails' innerError: $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError' additionalProperties: type: object microsoft.graph.riskState: title: riskState enum: - none - confirmedSafe - remediated - dismissed - atRisk - confirmedCompromised - unknownFutureValue type: string microsoft.graph.entity: title: entity type: object properties: id: type: string description: The unique identifier for an entity. Read-only. additionalProperties: type: object ODataCountResponse: type: integer format: int32 microsoft.graph.riskyServicePrincipalHistoryItem: allOf: - $ref: '#/components/schemas/microsoft.graph.riskyServicePrincipal' - title: riskyServicePrincipalHistoryItem type: object properties: activity: $ref: '#/components/schemas/microsoft.graph.riskServicePrincipalActivity' initiatedBy: type: - string - 'null' description: The identifier of the actor of the operation. additionalProperties: type: object securitySchemes: azureaadv2: type: oauth2 flows: authorizationCode: authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token scopes: {}