openapi: 3.2.0 info: title: Identity.SignIns Policies.authentication Strength Policy API version: v1.0 servers: - url: https://graph.microsoft.com/v1.0/ description: Core security: - azureaadv2: [] tags: - name: policies.authenticationStrengthPolicy paths: /policies/authenticationStrengthPolicies: get: tags: - policies.authenticationStrengthPolicy summary: List authenticationStrengthPolicies description: Get a list of the authenticationStrengthPolicy objects and their properties. This API returns both built-in and custom policies. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/authenticationstrengthroot-list-policies?view=graph-rest-1.0 operationId: policy_ListAuthenticationStrengthPolicy parameters: - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.authenticationStrengthPolicyCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - policies.authenticationStrengthPolicy summary: Create authenticationStrengthPolicy description: Create a new custom authenticationStrengthPolicy object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/authenticationstrengthroot-post-policies?view=graph-rest-1.0 operationId: policy_CreateAuthenticationStrengthPolicy requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicy' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicy' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /policies/authenticationStrengthPolicies/{authenticationStrengthPolicy-id}: get: tags: - policies.authenticationStrengthPolicy summary: Get authenticationStrengthPolicy description: Read the properties and relationships of an authenticationStrengthPolicy object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/authenticationstrengthpolicy-get?view=graph-rest-1.0 operationId: policy_GetAuthenticationStrengthPolicy parameters: - name: authenticationStrengthPolicy-id in: path description: The unique identifier of authenticationStrengthPolicy required: true style: simple schema: type: string x-ms-docs-key-type: authenticationStrengthPolicy - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicy' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - policies.authenticationStrengthPolicy summary: Update authenticationStrengthPolicy description: Update the properties of an authenticationStrengthPolicy object. You cannot update the allowed auth method combinations using this request. To do so, use the Update allowed combinations action. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/authenticationstrengthpolicy-update?view=graph-rest-1.0 operationId: policy_UpdateAuthenticationStrengthPolicy parameters: - name: authenticationStrengthPolicy-id in: path description: The unique identifier of authenticationStrengthPolicy required: true style: simple schema: type: string x-ms-docs-key-type: authenticationStrengthPolicy requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicy' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicy' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - policies.authenticationStrengthPolicy summary: Delete authenticationStrengthPolicy description: Delete a custom authenticationStrengthPolicy object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/authenticationstrengthroot-delete-policies?view=graph-rest-1.0 operationId: policy_DeleteAuthenticationStrengthPolicy parameters: - name: authenticationStrengthPolicy-id in: path description: The unique identifier of authenticationStrengthPolicy required: true style: simple schema: type: string x-ms-docs-key-type: authenticationStrengthPolicy - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /policies/authenticationStrengthPolicies/{authenticationStrengthPolicy-id}/combinationConfigurations: get: tags: - policies.authenticationStrengthPolicy summary: Get combinationConfigurations from policies description: Settings that may be used to require specific types or instances of an authentication method to be used when authenticating with a specified combination of authentication methods. operationId: policy.authenticationStrengthPolicy_ListCombinationConfiguration parameters: - name: authenticationStrengthPolicy-id in: path description: The unique identifier of authenticationStrengthPolicy required: true style: simple schema: type: string x-ms-docs-key-type: authenticationStrengthPolicy - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.authenticationCombinationConfigurationCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - policies.authenticationStrengthPolicy summary: Create new navigation property to combinationConfigurations for policies operationId: policy.authenticationStrengthPolicy_CreateCombinationConfiguration parameters: - name: authenticationStrengthPolicy-id in: path description: The unique identifier of authenticationStrengthPolicy required: true style: simple schema: type: string x-ms-docs-key-type: authenticationStrengthPolicy requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationCombinationConfiguration' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationCombinationConfiguration' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation ? /policies/authenticationStrengthPolicies/{authenticationStrengthPolicy-id}/combinationConfigurations/{authenticationCombinationConfiguration-id} : get: tags: - policies.authenticationStrengthPolicy summary: Get combinationConfigurations from policies description: Settings that may be used to require specific types or instances of an authentication method to be used when authenticating with a specified combination of authentication methods. operationId: policy.authenticationStrengthPolicy_GetCombinationConfiguration parameters: - name: authenticationStrengthPolicy-id in: path description: The unique identifier of authenticationStrengthPolicy required: true style: simple schema: type: string x-ms-docs-key-type: authenticationStrengthPolicy - name: authenticationCombinationConfiguration-id in: path description: The unique identifier of authenticationCombinationConfiguration required: true style: simple schema: type: string x-ms-docs-key-type: authenticationCombinationConfiguration - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationCombinationConfiguration' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - policies.authenticationStrengthPolicy summary: Update the navigation property combinationConfigurations in policies operationId: policy.authenticationStrengthPolicy_UpdateCombinationConfiguration parameters: - name: authenticationStrengthPolicy-id in: path description: The unique identifier of authenticationStrengthPolicy required: true style: simple schema: type: string x-ms-docs-key-type: authenticationStrengthPolicy - name: authenticationCombinationConfiguration-id in: path description: The unique identifier of authenticationCombinationConfiguration required: true style: simple schema: type: string x-ms-docs-key-type: authenticationCombinationConfiguration requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationCombinationConfiguration' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationCombinationConfiguration' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - policies.authenticationStrengthPolicy summary: Delete navigation property combinationConfigurations for policies operationId: policy.authenticationStrengthPolicy_DeleteCombinationConfiguration parameters: - name: authenticationStrengthPolicy-id in: path description: The unique identifier of authenticationStrengthPolicy required: true style: simple schema: type: string x-ms-docs-key-type: authenticationStrengthPolicy - name: authenticationCombinationConfiguration-id in: path description: The unique identifier of authenticationCombinationConfiguration required: true style: simple schema: type: string x-ms-docs-key-type: authenticationCombinationConfiguration - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /policies/authenticationStrengthPolicies/{authenticationStrengthPolicy-id}/combinationConfigurations/$count: get: tags: - policies.authenticationStrengthPolicy summary: Get the number of the resource operationId: policy.authenticationStrengthPolicy.combinationConfiguration_GetCount parameters: - name: authenticationStrengthPolicy-id in: path description: The unique identifier of authenticationStrengthPolicy required: true style: simple schema: type: string x-ms-docs-key-type: authenticationStrengthPolicy - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' /policies/authenticationStrengthPolicies/{authenticationStrengthPolicy-id}/microsoft.graph.updateAllowedCombinations: post: tags: - policies.authenticationStrengthPolicy summary: Invoke action updateAllowedCombinations description: Update the allowedCombinations property of an authenticationStrengthPolicy object. To update other properties of an authenticationStrengthPolicy object, use the Update authenticationStrengthPolicy method. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/authenticationstrengthpolicy-updateallowedcombinations?view=graph-rest-1.0 operationId: policy.authenticationStrengthPolicy_updateAllowedCombination parameters: - name: authenticationStrengthPolicy-id in: path description: The unique identifier of authenticationStrengthPolicy required: true style: simple schema: type: string x-ms-docs-key-type: authenticationStrengthPolicy requestBody: description: Action parameters content: application/json: schema: type: object properties: allowedCombinations: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModes' additionalProperties: type: object required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.updateAllowedCombinationsResult' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action /policies/authenticationStrengthPolicies/{authenticationStrengthPolicy-id}/microsoft.graph.usage(): get: tags: - policies.authenticationStrengthPolicy summary: Invoke function usage description: Allows the caller to see which Conditional Access policies reference a specified authentication strength policy. The policies are returned in two collections, one containing Conditional Access policies that require an MFA claim and the other containing Conditional Access policies that don't require such a claim. Policies in the former category are restricted in what kinds of changes may be made to them to prevent undermining the MFA requirement of those policies. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/authenticationstrengthpolicy-usage?view=graph-rest-1.0 operationId: policy.authenticationStrengthPolicy_usage parameters: - name: authenticationStrengthPolicy-id in: path description: The unique identifier of authenticationStrengthPolicy required: true style: simple schema: type: string x-ms-docs-key-type: authenticationStrengthPolicy responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthUsage' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: function /policies/authenticationStrengthPolicies/$count: get: tags: - policies.authenticationStrengthPolicy summary: Get the number of the resource operationId: policy.authenticationStrengthPolicy_GetCount parameters: - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' components: schemas: microsoft.graph.conditionalAccessApplications: title: conditionalAccessApplications type: object properties: applicationFilter: $ref: '#/components/schemas/microsoft.graph.conditionalAccessFilter' excludeApplications: type: array items: type: string description: 'Can be one of the following: The list of client IDs (appId) explicitly excluded from the policy. Office365 - For the list of apps included in Office365, see Apps included in Conditional Access Office 365 app suite MicrosoftAdminPortals - For more information, see Conditional Access Target resources: Microsoft Admin Portals' includeApplications: type: array items: type: string description: 'Can be one of the following: The list of client IDs (appId) the policy applies to, unless explicitly excluded (in excludeApplications) All Office365 - For the list of apps included in Office365, see Apps included in Conditional Access Office 365 app suite MicrosoftAdminPortals - For more information, see Conditional Access Target resources: Microsoft Admin Portals' includeAuthenticationContextClassReferences: type: array items: type: string includeUserActions: type: array items: type: string description: User actions to include. Supported values are urn:user:registersecurityinfo and urn:user:registerdevice additionalProperties: type: object microsoft.graph.applicationEnforcedRestrictionsSessionControl: allOf: - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl' - title: applicationEnforcedRestrictionsSessionControl type: object additionalProperties: type: object microsoft.graph.authenticationStrengthRequirements: title: authenticationStrengthRequirements enum: - none - mfa - unknownFutureValue type: string x-ms-enum-flags: isFlags: true microsoft.graph.conditionalAccessClientApp: title: conditionalAccessClientApp enum: - all - browser - mobileAppsAndDesktopClients - exchangeActiveSync - easSupported - other - unknownFutureValue type: string microsoft.graph.filterMode: title: filterMode enum: - include - exclude type: string microsoft.graph.authenticationStrengthPolicy: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: authenticationStrengthPolicy type: object properties: allowedCombinations: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModes' description: A collection of authentication method modes that are required be used to satify this authentication strength. createdDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: string description: The datetime when this policy was created. format: date-time description: type: - string - 'null' description: The human-readable description of this policy. displayName: type: string description: The human-readable display name of this policy. Supports $filter (eq, ne, not , and in). modifiedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: string description: The datetime when this policy was last modified. format: date-time policyType: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicyType' requirementsSatisfied: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthRequirements' combinationConfigurations: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationCombinationConfiguration' description: Settings that may be used to require specific types or instances of an authentication method to be used when authenticating with a specified combination of authentication methods. x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.authenticationCombinationConfiguration: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: authenticationCombinationConfiguration type: object properties: appliesToCombinations: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModes' description: Which authentication method combinations this configuration applies to. Must be an allowedCombinations object, part of the authenticationStrengthPolicy. The only possible value for fido2combinationConfigurations is 'fido2'. additionalProperties: type: object microsoft.graph.conditionalAccessSessionControls: title: conditionalAccessSessionControls type: object properties: applicationEnforcedRestrictions: $ref: '#/components/schemas/microsoft.graph.applicationEnforcedRestrictionsSessionControl' cloudAppSecurity: $ref: '#/components/schemas/microsoft.graph.cloudAppSecuritySessionControl' disableResilienceDefaults: type: - boolean - 'null' description: Session control that determines whether it is acceptable for Microsoft Entra ID to extend existing sessions based on information collected prior to an outage or not. persistentBrowser: $ref: '#/components/schemas/microsoft.graph.persistentBrowserSessionControl' secureSignInSession: $ref: '#/components/schemas/microsoft.graph.secureSignInSessionControl' signInFrequency: $ref: '#/components/schemas/microsoft.graph.signInFrequencySessionControl' additionalProperties: type: object microsoft.graph.persistentBrowserSessionControl: allOf: - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl' - title: persistentBrowserSessionControl type: object properties: mode: $ref: '#/components/schemas/microsoft.graph.persistentBrowserSessionMode' additionalProperties: type: object microsoft.graph.conditionalAccessDevices: title: conditionalAccessDevices type: object properties: deviceFilter: $ref: '#/components/schemas/microsoft.graph.conditionalAccessFilter' additionalProperties: type: object microsoft.graph.ODataErrors.ODataError: required: - error type: object properties: error: $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError' additionalProperties: type: object microsoft.graph.conditionalAccessSessionControl: title: conditionalAccessSessionControl type: object properties: isEnabled: type: - boolean - 'null' description: Specifies whether the session control is enabled. additionalProperties: type: object microsoft.graph.authenticationMethodModes: title: authenticationMethodModes enum: - password - voice - hardwareOath - softwareOath - sms - fido2 - windowsHelloForBusiness - microsoftAuthenticatorPush - deviceBasedPush - temporaryAccessPassOneTime - temporaryAccessPassMultiUse - email - x509CertificateSingleFactor - x509CertificateMultiFactor - federatedSingleFactor - federatedMultiFactor - unknownFutureValue - qrCodePin type: string x-ms-enum-flags: isFlags: true microsoft.graph.conditionalAccessFilter: title: conditionalAccessFilter type: object properties: mode: $ref: '#/components/schemas/microsoft.graph.filterMode' rule: type: string description: Rule syntax is similar to that used for membership rules for groups in Microsoft Entra ID. For details, see rules with multiple expressions additionalProperties: type: object microsoft.graph.conditionalAccessAuthenticationFlows: title: conditionalAccessAuthenticationFlows type: object properties: transferMethods: $ref: '#/components/schemas/microsoft.graph.conditionalAccessTransferMethods' additionalProperties: type: object microsoft.graph.conditionalAccessPolicyState: title: conditionalAccessPolicyState enum: - enabled - disabled - enabledForReportingButNotEnforced type: string microsoft.graph.ODataErrors.InnerError: type: object additionalProperties: type: object description: The structure of this object is service-specific microsoft.graph.signinFrequencyType: title: signinFrequencyType enum: - days - hours type: string microsoft.graph.conditionalAccessConditionSet: title: conditionalAccessConditionSet type: object properties: applications: $ref: '#/components/schemas/microsoft.graph.conditionalAccessApplications' authenticationFlows: $ref: '#/components/schemas/microsoft.graph.conditionalAccessAuthenticationFlows' clientApplications: $ref: '#/components/schemas/microsoft.graph.conditionalAccessClientApplications' clientAppTypes: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessClientApp' description: 'Client application types included in the policy. The possible values are: all, browser, mobileAppsAndDesktopClients, exchangeActiveSync, easSupported, other. Required. The easUnsupported enumeration member will be deprecated in favor of exchangeActiveSync, which includes EAS supported and unsupported platforms.' devices: $ref: '#/components/schemas/microsoft.graph.conditionalAccessDevices' insiderRiskLevels: $ref: '#/components/schemas/microsoft.graph.conditionalAccessInsiderRiskLevels' locations: $ref: '#/components/schemas/microsoft.graph.conditionalAccessLocations' platforms: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPlatforms' servicePrincipalRiskLevels: type: array items: $ref: '#/components/schemas/microsoft.graph.riskLevel' description: 'Service principal risk levels included in the policy. The possible values are: low, medium, high, none, unknownFutureValue.' signInRiskLevels: type: array items: $ref: '#/components/schemas/microsoft.graph.riskLevel' description: 'Sign-in risk levels included in the policy. The possible values are: low, medium, high, hidden, none, unknownFutureValue. Required.' userRiskLevels: type: array items: $ref: '#/components/schemas/microsoft.graph.riskLevel' description: 'User risk levels included in the policy. The possible values are: low, medium, high, hidden, none, unknownFutureValue. Required.' users: $ref: '#/components/schemas/microsoft.graph.conditionalAccessUsers' additionalProperties: type: object microsoft.graph.conditionalAccessPolicy: allOf: - $ref: '#/components/schemas/microsoft.graph.policyDeletableItem' - title: conditionalAccessPolicy type: object properties: conditions: $ref: '#/components/schemas/microsoft.graph.conditionalAccessConditionSet' createdDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. Read-only. format: date-time description: type: - string - 'null' displayName: type: string description: Specifies a display name for the conditionalAccessPolicy object. grantControls: $ref: '#/components/schemas/microsoft.graph.conditionalAccessGrantControls' id: type: string description: Specifies the identifier of a conditionalAccessPolicy object. Read-only. modifiedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. Read-only. format: date-time sessionControls: $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControls' state: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicyState' templateId: type: - string - 'null' description: Specifies the unique identifier of a Conditional Access template. Inherited from entity. additionalProperties: type: object microsoft.graph.conditionalAccessGrantControl: title: conditionalAccessGrantControl enum: - block - mfa - compliantDevice - domainJoinedDevice - approvedApplication - compliantApplication - passwordChange - unknownFutureValue - riskRemediation type: string microsoft.graph.authenticationStrengthUsage: title: authenticationStrengthUsage type: object properties: mfa: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' x-ms-navigationProperty: true none: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.signInFrequencyInterval: title: signInFrequencyInterval enum: - timeBased - everyTime - unknownFutureValue type: string microsoft.graph.conditionalAccessPlatforms: title: conditionalAccessPlatforms type: object properties: excludePlatforms: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessDevicePlatform' description: 'The possible values are: android, iOS, windows, windowsPhone, macOS, linux, all, unknownFutureValue.' includePlatforms: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessDevicePlatform' description: 'The possible values are: android, iOS, windows, windowsPhone, macOS, linux, all, unknownFutureValue.' additionalProperties: type: object microsoft.graph.authenticationStrengthPolicyCollectionResponse: title: Collection of authenticationStrengthPolicy type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicy' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.cloudAppSecuritySessionControlType: title: cloudAppSecuritySessionControlType enum: - mcasConfigured - monitorOnly - blockDownloads - unknownFutureValue type: string microsoft.graph.conditionalAccessUsers: title: conditionalAccessUsers type: object properties: excludeGroups: type: array items: type: string description: Group IDs excluded from scope of policy. excludeGuestsOrExternalUsers: $ref: '#/components/schemas/microsoft.graph.conditionalAccessGuestsOrExternalUsers' excludeRoles: type: array items: type: string description: Role IDs excluded from scope of policy. excludeUsers: type: array items: type: string description: User IDs excluded from scope of policy and/or GuestsOrExternalUsers. includeGroups: type: array items: type: string description: Group IDs in scope of policy unless explicitly excluded. includeGuestsOrExternalUsers: $ref: '#/components/schemas/microsoft.graph.conditionalAccessGuestsOrExternalUsers' includeRoles: type: array items: type: string description: Role IDs in scope of policy unless explicitly excluded. includeUsers: type: array items: type: string description: User IDs in scope of policy unless explicitly excluded, None, All, or GuestsOrExternalUsers. additionalProperties: type: object microsoft.graph.ODataErrors.ErrorDetails: required: - code - message type: object properties: code: type: string message: type: string target: type: - string - 'null' additionalProperties: type: object microsoft.graph.conditionalAccessClientApplications: title: conditionalAccessClientApplications type: object properties: excludeServicePrincipals: type: array items: type: string description: Service principal IDs excluded from the policy scope. includeServicePrincipals: type: array items: type: string description: Service principal IDs included in the policy scope, or ServicePrincipalsInMyTenant. servicePrincipalFilter: $ref: '#/components/schemas/microsoft.graph.conditionalAccessFilter' additionalProperties: type: object microsoft.graph.cloudAppSecuritySessionControl: allOf: - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl' - title: cloudAppSecuritySessionControl type: object properties: cloudAppSecurityType: $ref: '#/components/schemas/microsoft.graph.cloudAppSecuritySessionControlType' additionalProperties: type: object microsoft.graph.conditionalAccessLocations: title: conditionalAccessLocations type: object properties: excludeLocations: type: array items: type: string description: Location IDs excluded from scope of policy. includeLocations: type: array items: type: string description: Location IDs in scope of policy unless explicitly excluded, All, or AllTrusted. additionalProperties: type: object microsoft.graph.authenticationStrengthPolicyType: title: authenticationStrengthPolicyType enum: - builtIn - custom - unknownFutureValue type: string microsoft.graph.updateAllowedCombinationsResult: title: updateAllowedCombinationsResult type: object properties: additionalInformation: type: - string - 'null' description: Information about why the updateAllowedCombinations action was successful or failed. conditionalAccessReferences: type: array items: type: - string - 'null' description: References to existing Conditional Access policies that use this authentication strength. currentCombinations: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModes' description: The list of current authentication method combinations allowed by the authentication strength. previousCombinations: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModes' description: The list of former authentication method combinations allowed by the authentication strength before they were updated through the updateAllowedCombinations action. additionalProperties: type: object microsoft.graph.conditionalAccessExternalTenants: title: conditionalAccessExternalTenants type: object properties: membershipKind: $ref: '#/components/schemas/microsoft.graph.conditionalAccessExternalTenantsMembershipKind' additionalProperties: type: object microsoft.graph.conditionalAccessGuestsOrExternalUsers: title: conditionalAccessGuestsOrExternalUsers type: object properties: externalTenants: $ref: '#/components/schemas/microsoft.graph.conditionalAccessExternalTenants' guestOrExternalUserTypes: $ref: '#/components/schemas/microsoft.graph.conditionalAccessGuestOrExternalUserTypes' additionalProperties: type: object microsoft.graph.conditionalAccessExternalTenantsMembershipKind: title: conditionalAccessExternalTenantsMembershipKind enum: - all - enumerated - unknownFutureValue type: string microsoft.graph.persistentBrowserSessionMode: title: persistentBrowserSessionMode enum: - always - never type: string microsoft.graph.conditionalAccessGuestOrExternalUserTypes: title: conditionalAccessGuestOrExternalUserTypes enum: - none - internalGuest - b2bCollaborationGuest - b2bCollaborationMember - b2bDirectConnectUser - otherExternalUser - serviceProvider - unknownFutureValue type: string x-ms-enum-flags: isFlags: true microsoft.graph.conditionalAccessTransferMethods: title: conditionalAccessTransferMethods enum: - none - deviceCodeFlow - authenticationTransfer - unknownFutureValue type: string x-ms-enum-flags: isFlags: true microsoft.graph.conditionalAccessGrantControls: title: conditionalAccessGrantControls type: object properties: builtInControls: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessGrantControl' description: 'List of values of built-in controls required by the policy. Possible values: block, mfa, compliantDevice, domainJoinedDevice, approvedApplication, compliantApplication, passwordChange, unknownFutureValue, riskRemediation. Use the Prefer: include-unknown-enum-members request header to get the following value in this evolvable enum: riskRemediation.' customAuthenticationFactors: type: array items: type: string description: List of custom controls IDs required by the policy. For more information, see Custom controls. operator: type: - string - 'null' description: 'Defines the relationship of the grant controls. Possible values: AND, OR.' termsOfUse: type: array items: type: string description: List of terms of use IDs required by the policy. authenticationStrength: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicy' additionalProperties: type: object microsoft.graph.conditionalAccessDevicePlatform: title: conditionalAccessDevicePlatform enum: - android - iOS - windows - windowsPhone - macOS - all - unknownFutureValue - linux type: string microsoft.graph.riskLevel: title: riskLevel enum: - low - medium - high - hidden - none - unknownFutureValue type: string microsoft.graph.signInFrequencyAuthenticationType: title: signInFrequencyAuthenticationType enum: - primaryAndSecondaryAuthentication - secondaryAuthentication - unknownFutureValue type: string microsoft.graph.ODataErrors.MainError: required: - code - message type: object properties: code: type: string message: type: string x-ms-primary-error-message: true target: type: - string - 'null' details: type: array items: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails' innerError: $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError' additionalProperties: type: object microsoft.graph.policyDeletableItem: title: policyDeletableItem type: object properties: deletedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' format: date-time additionalProperties: type: object microsoft.graph.authenticationCombinationConfigurationCollectionResponse: title: Collection of authenticationCombinationConfiguration type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationCombinationConfiguration' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.entity: title: entity type: object properties: id: type: string description: The unique identifier for an entity. Read-only. additionalProperties: type: object ODataCountResponse: type: integer format: int32 microsoft.graph.secureSignInSessionControl: allOf: - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl' - title: secureSignInSessionControl type: object additionalProperties: type: object microsoft.graph.signInFrequencySessionControl: allOf: - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl' - title: signInFrequencySessionControl type: object properties: authenticationType: $ref: '#/components/schemas/microsoft.graph.signInFrequencyAuthenticationType' frequencyInterval: $ref: '#/components/schemas/microsoft.graph.signInFrequencyInterval' type: $ref: '#/components/schemas/microsoft.graph.signinFrequencyType' value: maximum: 2147483647 minimum: -2147483648 type: - number - 'null' description: The number of days or hours. format: int32 additionalProperties: type: object microsoft.graph.conditionalAccessInsiderRiskLevels: title: conditionalAccessInsiderRiskLevels enum: - minor - moderate - elevated - unknownFutureValue type: string x-ms-enum-flags: isFlags: true parameters: count: name: $count in: query description: Include count of items style: form explode: false schema: type: boolean filter: name: $filter in: query description: Filter items by property values style: form explode: false schema: type: string search: name: $search in: query description: Search items by search phrases style: form explode: false schema: type: string skip: name: $skip in: query description: Skip the first n items style: form explode: false schema: minimum: 0 type: integer top: name: $top in: query description: Show only the first n items style: form explode: false schema: minimum: 0 type: integer example: 50 responses: ODataCountResponse: description: The count of the resource content: text/plain: schema: $ref: '#/components/schemas/ODataCountResponse' microsoft.graph.authenticationStrengthPolicyCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicyCollectionResponse' microsoft.graph.authenticationCombinationConfigurationCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.authenticationCombinationConfigurationCollectionResponse' error: description: error content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError' securitySchemes: azureaadv2: type: oauth2 flows: authorizationCode: authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token scopes: {}