openapi: 3.2.0 info: title: Identity.SignIns Information Protection.threat Assessment… version: v1.0 servers: - url: https://graph.microsoft.com/v1.0/ description: Core security: - azureaadv2: [] tags: - name: informationProtection.threatAssessmentRequest paths: /informationProtection/threatAssessmentRequests: get: tags: - informationProtection.threatAssessmentRequest summary: List threatAssessmentRequests description: 'Retrieve a list of threatAssessmentRequest objects. A threat assessment request can be one of the following types:' externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/informationprotection-list-threatassessmentrequests?view=graph-rest-1.0 operationId: informationProtection_ListThreatAssessmentRequest parameters: - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.threatAssessmentRequestCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - informationProtection.threatAssessmentRequest summary: Create threatAssessmentRequest description: 'Create a new threat assessment request. A threat assessment request can be one of the following types:' externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/informationprotection-post-threatassessmentrequests?view=graph-rest-1.0 operationId: informationProtection_CreateThreatAssessmentRequest requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.threatAssessmentRequest' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.threatAssessmentRequest' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /informationProtection/threatAssessmentRequests/{threatAssessmentRequest-id}: get: tags: - informationProtection.threatAssessmentRequest summary: Get threatAssessmentRequest description: 'Retrieve the properties and relationships of a specified threatAssessmentRequest object. A threat assessment request can be one of the following types:' externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/threatassessmentrequest-get?view=graph-rest-1.0 operationId: informationProtection_GetThreatAssessmentRequest parameters: - name: threatAssessmentRequest-id in: path description: The unique identifier of threatAssessmentRequest required: true style: simple schema: type: string x-ms-docs-key-type: threatAssessmentRequest - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.threatAssessmentRequest' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - informationProtection.threatAssessmentRequest summary: Update the navigation property threatAssessmentRequests in informationProtection operationId: informationProtection_UpdateThreatAssessmentRequest parameters: - name: threatAssessmentRequest-id in: path description: The unique identifier of threatAssessmentRequest required: true style: simple schema: type: string x-ms-docs-key-type: threatAssessmentRequest requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.threatAssessmentRequest' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.threatAssessmentRequest' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - informationProtection.threatAssessmentRequest summary: Delete navigation property threatAssessmentRequests for informationProtection operationId: informationProtection_DeleteThreatAssessmentRequest parameters: - name: threatAssessmentRequest-id in: path description: The unique identifier of threatAssessmentRequest required: true style: simple schema: type: string x-ms-docs-key-type: threatAssessmentRequest - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /informationProtection/threatAssessmentRequests/{threatAssessmentRequest-id}/results: get: tags: - informationProtection.threatAssessmentRequest summary: Get results from informationProtection description: A collection of threat assessment results. Read-only. By default, a GET /threatAssessmentRequests/{id} does not return this property unless you apply $expand on it. operationId: informationProtection.threatAssessmentRequest_ListResult parameters: - name: threatAssessmentRequest-id in: path description: The unique identifier of threatAssessmentRequest required: true style: simple schema: type: string x-ms-docs-key-type: threatAssessmentRequest - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.threatAssessmentResultCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - informationProtection.threatAssessmentRequest summary: Create new navigation property to results for informationProtection operationId: informationProtection.threatAssessmentRequest_CreateResult parameters: - name: threatAssessmentRequest-id in: path description: The unique identifier of threatAssessmentRequest required: true style: simple schema: type: string x-ms-docs-key-type: threatAssessmentRequest requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.threatAssessmentResult' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.threatAssessmentResult' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /informationProtection/threatAssessmentRequests/{threatAssessmentRequest-id}/results/{threatAssessmentResult-id}: get: tags: - informationProtection.threatAssessmentRequest summary: Get results from informationProtection description: A collection of threat assessment results. Read-only. By default, a GET /threatAssessmentRequests/{id} does not return this property unless you apply $expand on it. operationId: informationProtection.threatAssessmentRequest_GetResult parameters: - name: threatAssessmentRequest-id in: path description: The unique identifier of threatAssessmentRequest required: true style: simple schema: type: string x-ms-docs-key-type: threatAssessmentRequest - name: threatAssessmentResult-id in: path description: The unique identifier of threatAssessmentResult required: true style: simple schema: type: string x-ms-docs-key-type: threatAssessmentResult - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.threatAssessmentResult' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - informationProtection.threatAssessmentRequest summary: Update the navigation property results in informationProtection operationId: informationProtection.threatAssessmentRequest_UpdateResult parameters: - name: threatAssessmentRequest-id in: path description: The unique identifier of threatAssessmentRequest required: true style: simple schema: type: string x-ms-docs-key-type: threatAssessmentRequest - name: threatAssessmentResult-id in: path description: The unique identifier of threatAssessmentResult required: true style: simple schema: type: string x-ms-docs-key-type: threatAssessmentResult requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.threatAssessmentResult' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.threatAssessmentResult' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - informationProtection.threatAssessmentRequest summary: Delete navigation property results for informationProtection operationId: informationProtection.threatAssessmentRequest_DeleteResult parameters: - name: threatAssessmentRequest-id in: path description: The unique identifier of threatAssessmentRequest required: true style: simple schema: type: string x-ms-docs-key-type: threatAssessmentRequest - name: threatAssessmentResult-id in: path description: The unique identifier of threatAssessmentResult required: true style: simple schema: type: string x-ms-docs-key-type: threatAssessmentResult - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /informationProtection/threatAssessmentRequests/{threatAssessmentRequest-id}/results/$count: get: tags: - informationProtection.threatAssessmentRequest summary: Get the number of the resource operationId: informationProtection.threatAssessmentRequest.result_GetCount parameters: - name: threatAssessmentRequest-id in: path description: The unique identifier of threatAssessmentRequest required: true style: simple schema: type: string x-ms-docs-key-type: threatAssessmentRequest - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' /informationProtection/threatAssessmentRequests/$count: get: tags: - informationProtection.threatAssessmentRequest summary: Get the number of the resource operationId: informationProtection.threatAssessmentRequest_GetCount parameters: - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' components: schemas: microsoft.graph.threatAssessmentRequestCollectionResponse: title: Collection of threatAssessmentRequest type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.threatAssessmentRequest' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.ODataErrors.ODataError: required: - error type: object properties: error: $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError' additionalProperties: type: object microsoft.graph.threatAssessmentRequest: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: threatAssessmentRequest type: object properties: category: $ref: '#/components/schemas/microsoft.graph.threatCategory' contentType: $ref: '#/components/schemas/microsoft.graph.threatAssessmentContentType' createdBy: $ref: '#/components/schemas/microsoft.graph.identitySet' createdDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. format: date-time expectedAssessment: $ref: '#/components/schemas/microsoft.graph.threatExpectedAssessment' requestSource: $ref: '#/components/schemas/microsoft.graph.threatAssessmentRequestSource' status: $ref: '#/components/schemas/microsoft.graph.threatAssessmentStatus' results: type: array items: $ref: '#/components/schemas/microsoft.graph.threatAssessmentResult' description: A collection of threat assessment results. Read-only. By default, a GET /threatAssessmentRequests/{id} does not return this property unless you apply $expand on it. x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.identitySet: title: identitySet type: object properties: application: $ref: '#/components/schemas/microsoft.graph.identity' device: $ref: '#/components/schemas/microsoft.graph.identity' user: $ref: '#/components/schemas/microsoft.graph.identity' additionalProperties: type: object microsoft.graph.ODataErrors.InnerError: type: object additionalProperties: type: object description: The structure of this object is service-specific microsoft.graph.threatAssessmentResult: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: threatAssessmentResult type: object properties: createdDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. format: date-time message: type: - string - 'null' description: The result message for each threat assessment. resultType: $ref: '#/components/schemas/microsoft.graph.threatAssessmentResultType' additionalProperties: type: object microsoft.graph.identity: title: identity type: object properties: displayName: type: - string - 'null' description: The display name of the identity.For drive items, the display name might not always be available or up to date. For example, if a user changes their display name the API might show the new value in a future response, but the items associated with the user don't show up as changed when using delta. id: type: - string - 'null' description: Unique identifier for the identity or actor. For example, in the access reviews decisions API, this property might record the id of the principal, that is, the group, user, or application that's subject to review. additionalProperties: type: object microsoft.graph.threatAssessmentResultCollectionResponse: title: Collection of threatAssessmentResult type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.threatAssessmentResult' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.ODataErrors.ErrorDetails: required: - code - message type: object properties: code: type: string message: type: string target: type: - string - 'null' additionalProperties: type: object microsoft.graph.threatExpectedAssessment: title: threatExpectedAssessment enum: - block - unblock type: string microsoft.graph.threatAssessmentStatus: title: threatAssessmentStatus enum: - pending - completed type: string microsoft.graph.threatAssessmentRequestSource: title: threatAssessmentRequestSource enum: - undefined - user - administrator type: string microsoft.graph.threatAssessmentResultType: title: threatAssessmentResultType enum: - checkPolicy - rescan - unknownFutureValue type: string microsoft.graph.threatCategory: title: threatCategory enum: - undefined - spam - phishing - malware - unknownFutureValue type: string microsoft.graph.ODataErrors.MainError: required: - code - message type: object properties: code: type: string message: type: string x-ms-primary-error-message: true target: type: - string - 'null' details: type: array items: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails' innerError: $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError' additionalProperties: type: object microsoft.graph.entity: title: entity type: object properties: id: type: string description: The unique identifier for an entity. Read-only. additionalProperties: type: object ODataCountResponse: type: integer format: int32 microsoft.graph.threatAssessmentContentType: title: threatAssessmentContentType enum: - mail - url - file type: string parameters: count: name: $count in: query description: Include count of items style: form explode: false schema: type: boolean filter: name: $filter in: query description: Filter items by property values style: form explode: false schema: type: string search: name: $search in: query description: Search items by search phrases style: form explode: false schema: type: string skip: name: $skip in: query description: Skip the first n items style: form explode: false schema: minimum: 0 type: integer top: name: $top in: query description: Show only the first n items style: form explode: false schema: minimum: 0 type: integer example: 50 responses: microsoft.graph.threatAssessmentRequestCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.threatAssessmentRequestCollectionResponse' ODataCountResponse: description: The count of the resource content: text/plain: schema: $ref: '#/components/schemas/ODataCountResponse' microsoft.graph.threatAssessmentResultCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.threatAssessmentResultCollectionResponse' error: description: error content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError' securitySchemes: azureaadv2: type: oauth2 flows: authorizationCode: authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token scopes: {}