openapi: 3.2.0 info: title: Identity.SignIns Identity Protection.risky User API version: v1.0 servers: - url: https://graph.microsoft.com/v1.0/ description: Core security: - azureaadv2: [] tags: - name: identityProtection.riskyUser paths: /identityProtection/riskyUsers: get: tags: - identityProtection.riskyUser summary: List riskyUsers description: Get a list of the riskyUser objects and their properties. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/riskyuser-list?view=graph-rest-1.0 operationId: identityProtection_ListRiskyUser parameters: - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.riskyUserCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - identityProtection.riskyUser summary: Create new navigation property to riskyUsers for identityProtection operationId: identityProtection_CreateRiskyUser requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyUser' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyUser' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identityProtection/riskyUsers/{riskyUser-id}: get: tags: - identityProtection.riskyUser summary: Get riskyUser description: Read the properties and relationships of a riskyUser object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/riskyuser-get?view=graph-rest-1.0 operationId: identityProtection_GetRiskyUser parameters: - name: riskyUser-id in: path description: The unique identifier of riskyUser required: true style: simple schema: type: string x-ms-docs-key-type: riskyUser - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyUser' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - identityProtection.riskyUser summary: Update the navigation property riskyUsers in identityProtection operationId: identityProtection_UpdateRiskyUser parameters: - name: riskyUser-id in: path description: The unique identifier of riskyUser required: true style: simple schema: type: string x-ms-docs-key-type: riskyUser requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyUser' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyUser' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - identityProtection.riskyUser summary: Delete navigation property riskyUsers for identityProtection operationId: identityProtection_DeleteRiskyUser parameters: - name: riskyUser-id in: path description: The unique identifier of riskyUser required: true style: simple schema: type: string x-ms-docs-key-type: riskyUser - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identityProtection/riskyUsers/{riskyUser-id}/history: get: tags: - identityProtection.riskyUser summary: List history of riskyUser description: Get the riskyUserHistoryItems from the history navigation property. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/riskyuser-list-history?view=graph-rest-1.0 operationId: identityProtection.riskyUser_ListHistory parameters: - name: riskyUser-id in: path description: The unique identifier of riskyUser required: true style: simple schema: type: string x-ms-docs-key-type: riskyUser - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.riskyUserHistoryItemCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - identityProtection.riskyUser summary: Create new navigation property to history for identityProtection operationId: identityProtection.riskyUser_CreateHistory parameters: - name: riskyUser-id in: path description: The unique identifier of riskyUser required: true style: simple schema: type: string x-ms-docs-key-type: riskyUser requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identityProtection/riskyUsers/{riskyUser-id}/history/{riskyUserHistoryItem-id}: get: tags: - identityProtection.riskyUser summary: Get history from identityProtection description: The activity related to user risk level change operationId: identityProtection.riskyUser_GetHistory parameters: - name: riskyUser-id in: path description: The unique identifier of riskyUser required: true style: simple schema: type: string x-ms-docs-key-type: riskyUser - name: riskyUserHistoryItem-id in: path description: The unique identifier of riskyUserHistoryItem required: true style: simple schema: type: string x-ms-docs-key-type: riskyUserHistoryItem - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - identityProtection.riskyUser summary: Update the navigation property history in identityProtection operationId: identityProtection.riskyUser_UpdateHistory parameters: - name: riskyUser-id in: path description: The unique identifier of riskyUser required: true style: simple schema: type: string x-ms-docs-key-type: riskyUser - name: riskyUserHistoryItem-id in: path description: The unique identifier of riskyUserHistoryItem required: true style: simple schema: type: string x-ms-docs-key-type: riskyUserHistoryItem requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - identityProtection.riskyUser summary: Delete navigation property history for identityProtection operationId: identityProtection.riskyUser_DeleteHistory parameters: - name: riskyUser-id in: path description: The unique identifier of riskyUser required: true style: simple schema: type: string x-ms-docs-key-type: riskyUser - name: riskyUserHistoryItem-id in: path description: The unique identifier of riskyUserHistoryItem required: true style: simple schema: type: string x-ms-docs-key-type: riskyUserHistoryItem - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identityProtection/riskyUsers/{riskyUser-id}/history/$count: get: tags: - identityProtection.riskyUser summary: Get the number of the resource operationId: identityProtection.riskyUser.history_GetCount parameters: - name: riskyUser-id in: path description: The unique identifier of riskyUser required: true style: simple schema: type: string x-ms-docs-key-type: riskyUser - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' /identityProtection/riskyUsers/$count: get: tags: - identityProtection.riskyUser summary: Get the number of the resource operationId: identityProtection.riskyUser_GetCount parameters: - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' /identityProtection/riskyUsers/microsoft.graph.confirmCompromised: post: tags: - identityProtection.riskyUser summary: Invoke action confirmCompromised description: Confirm one or more riskyUser objects as compromised. This action sets the targeted user's risk level to high. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/riskyuser-confirmcompromised?view=graph-rest-1.0 operationId: identityProtection.riskyUser_confirmCompromised requestBody: description: Action parameters content: application/json: schema: type: object properties: userIds: type: array items: type: - string - 'null' additionalProperties: type: object required: true responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action /identityProtection/riskyUsers/microsoft.graph.confirmSafe: post: tags: - identityProtection.riskyUser summary: Invoke action confirmSafe description: Confirm one or more riskyUser objects as safe. This action sets the targeted user's risk level to none. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/riskyuser-confirmsafe?view=graph-rest-1.0 operationId: identityProtection.riskyUser_confirmSafe requestBody: description: Action parameters content: application/json: schema: type: object properties: userIds: type: array items: type: - string - 'null' additionalProperties: type: object required: true responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action /identityProtection/riskyUsers/microsoft.graph.dismiss: post: tags: - identityProtection.riskyUser summary: Invoke action dismiss description: Dismiss the risk of one or more riskyUser objects. This action sets the targeted user's risk level to none. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/riskyuser-dismiss?view=graph-rest-1.0 operationId: identityProtection.riskyUser_dismiss requestBody: description: Action parameters content: application/json: schema: type: object properties: userIds: type: array items: type: - string - 'null' additionalProperties: type: object required: true responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action components: parameters: count: name: $count in: query description: Include count of items style: form explode: false schema: type: boolean filter: name: $filter in: query description: Filter items by property values style: form explode: false schema: type: string search: name: $search in: query description: Search items by search phrases style: form explode: false schema: type: string skip: name: $skip in: query description: Skip the first n items style: form explode: false schema: minimum: 0 type: integer top: name: $top in: query description: Show only the first n items style: form explode: false schema: minimum: 0 type: integer example: 50 schemas: microsoft.graph.ODataErrors.ODataError: required: - error type: object properties: error: $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError' additionalProperties: type: object microsoft.graph.riskDetail: title: riskDetail enum: - none - adminGeneratedTemporaryPassword - userPerformedSecuredPasswordChange - userPerformedSecuredPasswordReset - adminConfirmedSigninSafe - aiConfirmedSigninSafe - userPassedMFADrivenByRiskBasedPolicy - adminDismissedAllRiskForUser - adminConfirmedSigninCompromised - hidden - adminConfirmedUserCompromised - unknownFutureValue - m365DAdminDismissedDetection - adminConfirmedServicePrincipalCompromised - adminDismissedAllRiskForServicePrincipal - userChangedPasswordOnPremises - adminDismissedRiskForSignIn - adminConfirmedAccountSafe - microsoftRevokedSessions type: string microsoft.graph.ODataErrors.InnerError: type: object additionalProperties: type: object description: The structure of this object is service-specific microsoft.graph.riskyUserHistoryItemCollectionResponse: title: Collection of riskyUserHistoryItem type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.riskyUserCollectionResponse: title: Collection of riskyUser type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.riskyUser' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.ODataErrors.ErrorDetails: required: - code - message type: object properties: code: type: string message: type: string target: type: - string - 'null' additionalProperties: type: object microsoft.graph.riskUserActivity: title: riskUserActivity type: object properties: detail: $ref: '#/components/schemas/microsoft.graph.riskDetail' riskEventTypes: type: array items: type: - string - 'null' description: The type of risk event detected. additionalProperties: type: object microsoft.graph.riskLevel: title: riskLevel enum: - low - medium - high - hidden - none - unknownFutureValue type: string microsoft.graph.riskyUser: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: riskyUser type: object properties: isDeleted: type: - boolean - 'null' description: 'Indicates whether the user is deleted. The possible values are: true, false.' isProcessing: type: - boolean - 'null' description: Indicates whether the backend is processing a user's risky state. riskDetail: $ref: '#/components/schemas/microsoft.graph.riskDetail' riskLastUpdatedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The date and time that the risky user was last updated. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. format: date-time riskLevel: $ref: '#/components/schemas/microsoft.graph.riskLevel' riskState: $ref: '#/components/schemas/microsoft.graph.riskState' userDisplayName: type: - string - 'null' description: Risky user display name. userPrincipalName: type: - string - 'null' description: Risky user principal name. history: type: array items: $ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem' description: The activity related to user risk level change x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.ODataErrors.MainError: required: - code - message type: object properties: code: type: string message: type: string x-ms-primary-error-message: true target: type: - string - 'null' details: type: array items: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails' innerError: $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError' additionalProperties: type: object microsoft.graph.riskState: title: riskState enum: - none - confirmedSafe - remediated - dismissed - atRisk - confirmedCompromised - unknownFutureValue type: string microsoft.graph.entity: title: entity type: object properties: id: type: string description: The unique identifier for an entity. Read-only. additionalProperties: type: object ODataCountResponse: type: integer format: int32 microsoft.graph.riskyUserHistoryItem: allOf: - $ref: '#/components/schemas/microsoft.graph.riskyUser' - title: riskyUserHistoryItem type: object properties: activity: $ref: '#/components/schemas/microsoft.graph.riskUserActivity' initiatedBy: type: - string - 'null' description: The ID of actor that does the operation. userId: type: - string - 'null' description: The ID of the user. additionalProperties: type: object responses: microsoft.graph.riskyUserCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyUserCollectionResponse' ODataCountResponse: description: The count of the resource content: text/plain: schema: $ref: '#/components/schemas/ODataCountResponse' error: description: error content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError' microsoft.graph.riskyUserHistoryItemCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItemCollectionResponse' securitySchemes: azureaadv2: type: oauth2 flows: authorizationCode: authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token scopes: {}