openapi: 3.2.0 info: title: Identity.SignIns Identity Protection.service Principal Risk… version: v1.0 servers: - url: https://graph.microsoft.com/v1.0/ description: Core security: - azureaadv2: [] tags: - name: identityProtection.servicePrincipalRiskDetection paths: /identityProtection/servicePrincipalRiskDetections: get: tags: - identityProtection.servicePrincipalRiskDetection summary: List servicePrincipalRiskDetections description: Retrieve the properties of a collection of servicePrincipalRiskDetection objects. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/identityprotectionroot-list-serviceprincipalriskdetections?view=graph-rest-1.0 operationId: identityProtection_ListServicePrincipalRiskDetection parameters: - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.servicePrincipalRiskDetectionCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - identityProtection.servicePrincipalRiskDetection summary: Create new navigation property to servicePrincipalRiskDetections for… operationId: identityProtection_CreateServicePrincipalRiskDetection requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.servicePrincipalRiskDetection' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.servicePrincipalRiskDetection' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identityProtection/servicePrincipalRiskDetections/{servicePrincipalRiskDetection-id}: get: tags: - identityProtection.servicePrincipalRiskDetection summary: Get servicePrincipalRiskDetection description: Read the properties and relationships of a servicePrincipalRiskDetection object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/serviceprincipalriskdetection-get?view=graph-rest-1.0 operationId: identityProtection_GetServicePrincipalRiskDetection parameters: - name: servicePrincipalRiskDetection-id in: path description: The unique identifier of servicePrincipalRiskDetection required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipalRiskDetection - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.servicePrincipalRiskDetection' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - identityProtection.servicePrincipalRiskDetection summary: Update the navigation property servicePrincipalRiskDetections in… operationId: identityProtection_UpdateServicePrincipalRiskDetection parameters: - name: servicePrincipalRiskDetection-id in: path description: The unique identifier of servicePrincipalRiskDetection required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipalRiskDetection requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.servicePrincipalRiskDetection' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.servicePrincipalRiskDetection' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - identityProtection.servicePrincipalRiskDetection summary: Delete navigation property servicePrincipalRiskDetections for identityProtection operationId: identityProtection_DeleteServicePrincipalRiskDetection parameters: - name: servicePrincipalRiskDetection-id in: path description: The unique identifier of servicePrincipalRiskDetection required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipalRiskDetection - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /identityProtection/servicePrincipalRiskDetections/$count: get: tags: - identityProtection.servicePrincipalRiskDetection summary: Get the number of the resource operationId: identityProtection.servicePrincipalRiskDetection_GetCount parameters: - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' components: schemas: microsoft.graph.geoCoordinates: title: geoCoordinates type: object properties: altitude: type: - number - 'null' description: Optional. The altitude (height), in feet, above sea level for the item. Read-only. format: double latitude: type: - number - 'null' description: Optional. The latitude, in decimal, for the item. Read-only. format: double longitude: type: - number - 'null' description: Optional. The longitude, in decimal, for the item. Read-only. format: double additionalProperties: type: object microsoft.graph.activityType: title: activityType enum: - signin - user - unknownFutureValue - servicePrincipal type: string microsoft.graph.servicePrincipalRiskDetectionCollectionResponse: title: Collection of servicePrincipalRiskDetection type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.servicePrincipalRiskDetection' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.ODataErrors.ODataError: required: - error type: object properties: error: $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError' additionalProperties: type: object microsoft.graph.riskDetail: title: riskDetail enum: - none - adminGeneratedTemporaryPassword - userPerformedSecuredPasswordChange - userPerformedSecuredPasswordReset - adminConfirmedSigninSafe - aiConfirmedSigninSafe - userPassedMFADrivenByRiskBasedPolicy - adminDismissedAllRiskForUser - adminConfirmedSigninCompromised - hidden - adminConfirmedUserCompromised - unknownFutureValue - m365DAdminDismissedDetection - adminConfirmedServicePrincipalCompromised - adminDismissedAllRiskForServicePrincipal - userChangedPasswordOnPremises - adminDismissedRiskForSignIn - adminConfirmedAccountSafe - microsoftRevokedSessions type: string microsoft.graph.ODataErrors.InnerError: type: object additionalProperties: type: object description: The structure of this object is service-specific microsoft.graph.signInLocation: title: signInLocation type: object properties: city: type: - string - 'null' description: Provides the city where the sign-in originated and is determined using latitude/longitude information from the sign-in activity. countryOrRegion: type: - string - 'null' description: Provides the country code info (two letter code) where the sign-in originated. This is calculated using latitude/longitude information from the sign-in activity. geoCoordinates: $ref: '#/components/schemas/microsoft.graph.geoCoordinates' state: type: - string - 'null' description: Provides the State where the sign-in originated. This is calculated using latitude/longitude information from the sign-in activity. additionalProperties: type: object microsoft.graph.ODataErrors.ErrorDetails: required: - code - message type: object properties: code: type: string message: type: string target: type: - string - 'null' additionalProperties: type: object microsoft.graph.tokenIssuerType: title: tokenIssuerType enum: - AzureAD - ADFederationServices - UnknownFutureValue - AzureADBackupAuth - ADFederationServicesMFAAdapter - NPSExtension type: string microsoft.graph.riskDetectionTimingType: title: riskDetectionTimingType enum: - notDefined - realtime - nearRealtime - offline - unknownFutureValue type: string microsoft.graph.riskLevel: title: riskLevel enum: - low - medium - high - hidden - none - unknownFutureValue type: string microsoft.graph.servicePrincipalRiskDetection: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: servicePrincipalRiskDetection type: object properties: activity: $ref: '#/components/schemas/microsoft.graph.activityType' activityDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: Date and time when the risky activity occurred. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z format: date-time additionalInfo: type: - string - 'null' description: Additional information associated with the risk detection. This string value is represented as a JSON object with the quotations escaped. appId: type: - string - 'null' description: The unique identifier for the associated application. correlationId: type: - string - 'null' description: Correlation ID of the sign-in activity associated with the risk detection. This property is null if the risk detection is not associated with a sign-in activity. detectedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: Date and time when the risk was detected. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. format: date-time detectionTimingType: $ref: '#/components/schemas/microsoft.graph.riskDetectionTimingType' ipAddress: type: - string - 'null' description: Provides the IP address of the client from where the risk occurred. keyIds: type: array items: type: - string - 'null' description: The unique identifier for the key credential associated with the risk detection. lastUpdatedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: Date and time when the risk detection was last updated. format: date-time location: $ref: '#/components/schemas/microsoft.graph.signInLocation' requestId: type: - string - 'null' description: Request identifier of the sign-in activity associated with the risk detection. This property is null if the risk detection is not associated with a sign-in activity. Supports $filter (eq). riskDetail: $ref: '#/components/schemas/microsoft.graph.riskDetail' riskEventType: type: - string - 'null' description: 'The type of risk event detected. The possible values are: investigationsThreatIntelligence, generic, adminConfirmedServicePrincipalCompromised, suspiciousSignins, leakedCredentials, anomalousServicePrincipalActivity, maliciousApplication, suspiciousApplication.' riskLevel: $ref: '#/components/schemas/microsoft.graph.riskLevel' riskState: $ref: '#/components/schemas/microsoft.graph.riskState' servicePrincipalDisplayName: type: - string - 'null' description: The display name for the service principal. servicePrincipalId: type: - string - 'null' description: The unique identifier for the service principal. Supports $filter (eq). source: type: - string - 'null' description: Source of the risk detection. For example, identityProtection. tokenIssuerType: $ref: '#/components/schemas/microsoft.graph.tokenIssuerType' additionalProperties: type: object microsoft.graph.ODataErrors.MainError: required: - code - message type: object properties: code: type: string message: type: string x-ms-primary-error-message: true target: type: - string - 'null' details: type: array items: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails' innerError: $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError' additionalProperties: type: object microsoft.graph.riskState: title: riskState enum: - none - confirmedSafe - remediated - dismissed - atRisk - confirmedCompromised - unknownFutureValue type: string microsoft.graph.entity: title: entity type: object properties: id: type: string description: The unique identifier for an entity. Read-only. additionalProperties: type: object ODataCountResponse: type: integer format: int32 parameters: count: name: $count in: query description: Include count of items style: form explode: false schema: type: boolean filter: name: $filter in: query description: Filter items by property values style: form explode: false schema: type: string search: name: $search in: query description: Search items by search phrases style: form explode: false schema: type: string skip: name: $skip in: query description: Skip the first n items style: form explode: false schema: minimum: 0 type: integer top: name: $top in: query description: Show only the first n items style: form explode: false schema: minimum: 0 type: integer example: 50 responses: microsoft.graph.servicePrincipalRiskDetectionCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.servicePrincipalRiskDetectionCollectionResponse' ODataCountResponse: description: The count of the resource content: text/plain: schema: $ref: '#/components/schemas/ODataCountResponse' error: description: error content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError' securitySchemes: azureaadv2: type: oauth2 flows: authorizationCode: authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token scopes: {}