openapi: 3.2.0 info: title: Identity.SignIns Policies.conditional Access Policy API version: v1.0 servers: - url: https://graph.microsoft.com/v1.0/ description: Core security: - azureaadv2: [] tags: - name: policies.conditionalAccessPolicy paths: /policies/conditionalAccessPolicies: get: tags: - policies.conditionalAccessPolicy summary: Get conditionalAccessPolicies from policies description: The custom rules that define an access scenario. operationId: policy_ListConditionalAccessPolicy parameters: - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.conditionalAccessPolicyCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - policies.conditionalAccessPolicy summary: Create new navigation property to conditionalAccessPolicies for policies operationId: policy_CreateConditionalAccessPolicy requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /policies/conditionalAccessPolicies/{conditionalAccessPolicy-id}: get: tags: - policies.conditionalAccessPolicy summary: Get conditionalAccessPolicies from policies description: The custom rules that define an access scenario. operationId: policy_GetConditionalAccessPolicy parameters: - name: conditionalAccessPolicy-id in: path description: The unique identifier of conditionalAccessPolicy required: true style: simple schema: type: string x-ms-docs-key-type: conditionalAccessPolicy - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - policies.conditionalAccessPolicy summary: Update the navigation property conditionalAccessPolicies in policies operationId: policy_UpdateConditionalAccessPolicy parameters: - name: conditionalAccessPolicy-id in: path description: The unique identifier of conditionalAccessPolicy required: true style: simple schema: type: string x-ms-docs-key-type: conditionalAccessPolicy requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - policies.conditionalAccessPolicy summary: Delete navigation property conditionalAccessPolicies for policies operationId: policy_DeleteConditionalAccessPolicy parameters: - name: conditionalAccessPolicy-id in: path description: The unique identifier of conditionalAccessPolicy required: true style: simple schema: type: string x-ms-docs-key-type: conditionalAccessPolicy - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /policies/conditionalAccessPolicies/{conditionalAccessPolicy-id}/microsoft.graph.restore: post: tags: - policies.conditionalAccessPolicy summary: Invoke action restore operationId: policy.conditionalAccessPolicy_restore parameters: - name: conditionalAccessPolicy-id in: path description: The unique identifier of conditionalAccessPolicy required: true style: simple schema: type: string x-ms-docs-key-type: conditionalAccessPolicy responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: action /policies/conditionalAccessPolicies/$count: get: tags: - policies.conditionalAccessPolicy summary: Get the number of the resource operationId: policy.conditionalAccessPolicy_GetCount parameters: - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' components: schemas: microsoft.graph.conditionalAccessApplications: title: conditionalAccessApplications type: object properties: applicationFilter: $ref: '#/components/schemas/microsoft.graph.conditionalAccessFilter' excludeApplications: type: array items: type: string description: 'Can be one of the following: The list of client IDs (appId) explicitly excluded from the policy. Office365 - For the list of apps included in Office365, see Apps included in Conditional Access Office 365 app suite MicrosoftAdminPortals - For more information, see Conditional Access Target resources: Microsoft Admin Portals' includeApplications: type: array items: type: string description: 'Can be one of the following: The list of client IDs (appId) the policy applies to, unless explicitly excluded (in excludeApplications) All Office365 - For the list of apps included in Office365, see Apps included in Conditional Access Office 365 app suite MicrosoftAdminPortals - For more information, see Conditional Access Target resources: Microsoft Admin Portals' includeAuthenticationContextClassReferences: type: array items: type: string includeUserActions: type: array items: type: string description: User actions to include. Supported values are urn:user:registersecurityinfo and urn:user:registerdevice additionalProperties: type: object microsoft.graph.applicationEnforcedRestrictionsSessionControl: allOf: - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl' - title: applicationEnforcedRestrictionsSessionControl type: object additionalProperties: type: object microsoft.graph.authenticationStrengthRequirements: title: authenticationStrengthRequirements enum: - none - mfa - unknownFutureValue type: string x-ms-enum-flags: isFlags: true microsoft.graph.conditionalAccessClientApp: title: conditionalAccessClientApp enum: - all - browser - mobileAppsAndDesktopClients - exchangeActiveSync - easSupported - other - unknownFutureValue type: string microsoft.graph.filterMode: title: filterMode enum: - include - exclude type: string microsoft.graph.authenticationStrengthPolicy: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: authenticationStrengthPolicy type: object properties: allowedCombinations: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModes' description: A collection of authentication method modes that are required be used to satify this authentication strength. createdDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: string description: The datetime when this policy was created. format: date-time description: type: - string - 'null' description: The human-readable description of this policy. displayName: type: string description: The human-readable display name of this policy. Supports $filter (eq, ne, not , and in). modifiedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: string description: The datetime when this policy was last modified. format: date-time policyType: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicyType' requirementsSatisfied: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthRequirements' combinationConfigurations: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationCombinationConfiguration' description: Settings that may be used to require specific types or instances of an authentication method to be used when authenticating with a specified combination of authentication methods. x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.authenticationCombinationConfiguration: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: authenticationCombinationConfiguration type: object properties: appliesToCombinations: type: array items: $ref: '#/components/schemas/microsoft.graph.authenticationMethodModes' description: Which authentication method combinations this configuration applies to. Must be an allowedCombinations object, part of the authenticationStrengthPolicy. The only possible value for fido2combinationConfigurations is 'fido2'. additionalProperties: type: object microsoft.graph.conditionalAccessSessionControls: title: conditionalAccessSessionControls type: object properties: applicationEnforcedRestrictions: $ref: '#/components/schemas/microsoft.graph.applicationEnforcedRestrictionsSessionControl' cloudAppSecurity: $ref: '#/components/schemas/microsoft.graph.cloudAppSecuritySessionControl' disableResilienceDefaults: type: - boolean - 'null' description: Session control that determines whether it is acceptable for Microsoft Entra ID to extend existing sessions based on information collected prior to an outage or not. persistentBrowser: $ref: '#/components/schemas/microsoft.graph.persistentBrowserSessionControl' secureSignInSession: $ref: '#/components/schemas/microsoft.graph.secureSignInSessionControl' signInFrequency: $ref: '#/components/schemas/microsoft.graph.signInFrequencySessionControl' additionalProperties: type: object microsoft.graph.persistentBrowserSessionControl: allOf: - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl' - title: persistentBrowserSessionControl type: object properties: mode: $ref: '#/components/schemas/microsoft.graph.persistentBrowserSessionMode' additionalProperties: type: object microsoft.graph.conditionalAccessDevices: title: conditionalAccessDevices type: object properties: deviceFilter: $ref: '#/components/schemas/microsoft.graph.conditionalAccessFilter' additionalProperties: type: object microsoft.graph.ODataErrors.ODataError: required: - error type: object properties: error: $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError' additionalProperties: type: object microsoft.graph.conditionalAccessSessionControl: title: conditionalAccessSessionControl type: object properties: isEnabled: type: - boolean - 'null' description: Specifies whether the session control is enabled. additionalProperties: type: object microsoft.graph.conditionalAccessFilter: title: conditionalAccessFilter type: object properties: mode: $ref: '#/components/schemas/microsoft.graph.filterMode' rule: type: string description: Rule syntax is similar to that used for membership rules for groups in Microsoft Entra ID. For details, see rules with multiple expressions additionalProperties: type: object microsoft.graph.authenticationMethodModes: title: authenticationMethodModes enum: - password - voice - hardwareOath - softwareOath - sms - fido2 - windowsHelloForBusiness - microsoftAuthenticatorPush - deviceBasedPush - temporaryAccessPassOneTime - temporaryAccessPassMultiUse - email - x509CertificateSingleFactor - x509CertificateMultiFactor - federatedSingleFactor - federatedMultiFactor - unknownFutureValue - qrCodePin type: string x-ms-enum-flags: isFlags: true microsoft.graph.conditionalAccessAuthenticationFlows: title: conditionalAccessAuthenticationFlows type: object properties: transferMethods: $ref: '#/components/schemas/microsoft.graph.conditionalAccessTransferMethods' additionalProperties: type: object microsoft.graph.conditionalAccessPolicyState: title: conditionalAccessPolicyState enum: - enabled - disabled - enabledForReportingButNotEnforced type: string microsoft.graph.ODataErrors.InnerError: type: object additionalProperties: type: object description: The structure of this object is service-specific microsoft.graph.signinFrequencyType: title: signinFrequencyType enum: - days - hours type: string microsoft.graph.conditionalAccessConditionSet: title: conditionalAccessConditionSet type: object properties: applications: $ref: '#/components/schemas/microsoft.graph.conditionalAccessApplications' authenticationFlows: $ref: '#/components/schemas/microsoft.graph.conditionalAccessAuthenticationFlows' clientApplications: $ref: '#/components/schemas/microsoft.graph.conditionalAccessClientApplications' clientAppTypes: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessClientApp' description: 'Client application types included in the policy. The possible values are: all, browser, mobileAppsAndDesktopClients, exchangeActiveSync, easSupported, other. Required. The easUnsupported enumeration member will be deprecated in favor of exchangeActiveSync, which includes EAS supported and unsupported platforms.' devices: $ref: '#/components/schemas/microsoft.graph.conditionalAccessDevices' insiderRiskLevels: $ref: '#/components/schemas/microsoft.graph.conditionalAccessInsiderRiskLevels' locations: $ref: '#/components/schemas/microsoft.graph.conditionalAccessLocations' platforms: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPlatforms' servicePrincipalRiskLevels: type: array items: $ref: '#/components/schemas/microsoft.graph.riskLevel' description: 'Service principal risk levels included in the policy. The possible values are: low, medium, high, none, unknownFutureValue.' signInRiskLevels: type: array items: $ref: '#/components/schemas/microsoft.graph.riskLevel' description: 'Sign-in risk levels included in the policy. The possible values are: low, medium, high, hidden, none, unknownFutureValue. Required.' userRiskLevels: type: array items: $ref: '#/components/schemas/microsoft.graph.riskLevel' description: 'User risk levels included in the policy. The possible values are: low, medium, high, hidden, none, unknownFutureValue. Required.' users: $ref: '#/components/schemas/microsoft.graph.conditionalAccessUsers' additionalProperties: type: object microsoft.graph.conditionalAccessPolicy: allOf: - $ref: '#/components/schemas/microsoft.graph.policyDeletableItem' - title: conditionalAccessPolicy type: object properties: conditions: $ref: '#/components/schemas/microsoft.graph.conditionalAccessConditionSet' createdDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. Read-only. format: date-time description: type: - string - 'null' displayName: type: string description: Specifies a display name for the conditionalAccessPolicy object. grantControls: $ref: '#/components/schemas/microsoft.graph.conditionalAccessGrantControls' id: type: string description: Specifies the identifier of a conditionalAccessPolicy object. Read-only. modifiedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. Read-only. format: date-time sessionControls: $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControls' state: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicyState' templateId: type: - string - 'null' description: Specifies the unique identifier of a Conditional Access template. Inherited from entity. additionalProperties: type: object microsoft.graph.conditionalAccessGrantControl: title: conditionalAccessGrantControl enum: - block - mfa - compliantDevice - domainJoinedDevice - approvedApplication - compliantApplication - passwordChange - unknownFutureValue - riskRemediation type: string microsoft.graph.conditionalAccessPolicyCollectionResponse: title: Collection of conditionalAccessPolicy type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicy' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.signInFrequencyInterval: title: signInFrequencyInterval enum: - timeBased - everyTime - unknownFutureValue type: string microsoft.graph.conditionalAccessPlatforms: title: conditionalAccessPlatforms type: object properties: excludePlatforms: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessDevicePlatform' description: 'The possible values are: android, iOS, windows, windowsPhone, macOS, linux, all, unknownFutureValue.' includePlatforms: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessDevicePlatform' description: 'The possible values are: android, iOS, windows, windowsPhone, macOS, linux, all, unknownFutureValue.' additionalProperties: type: object microsoft.graph.cloudAppSecuritySessionControlType: title: cloudAppSecuritySessionControlType enum: - mcasConfigured - monitorOnly - blockDownloads - unknownFutureValue type: string microsoft.graph.conditionalAccessUsers: title: conditionalAccessUsers type: object properties: excludeGroups: type: array items: type: string description: Group IDs excluded from scope of policy. excludeGuestsOrExternalUsers: $ref: '#/components/schemas/microsoft.graph.conditionalAccessGuestsOrExternalUsers' excludeRoles: type: array items: type: string description: Role IDs excluded from scope of policy. excludeUsers: type: array items: type: string description: User IDs excluded from scope of policy and/or GuestsOrExternalUsers. includeGroups: type: array items: type: string description: Group IDs in scope of policy unless explicitly excluded. includeGuestsOrExternalUsers: $ref: '#/components/schemas/microsoft.graph.conditionalAccessGuestsOrExternalUsers' includeRoles: type: array items: type: string description: Role IDs in scope of policy unless explicitly excluded. includeUsers: type: array items: type: string description: User IDs in scope of policy unless explicitly excluded, None, All, or GuestsOrExternalUsers. additionalProperties: type: object microsoft.graph.ODataErrors.ErrorDetails: required: - code - message type: object properties: code: type: string message: type: string target: type: - string - 'null' additionalProperties: type: object microsoft.graph.conditionalAccessClientApplications: title: conditionalAccessClientApplications type: object properties: excludeServicePrincipals: type: array items: type: string description: Service principal IDs excluded from the policy scope. includeServicePrincipals: type: array items: type: string description: Service principal IDs included in the policy scope, or ServicePrincipalsInMyTenant. servicePrincipalFilter: $ref: '#/components/schemas/microsoft.graph.conditionalAccessFilter' additionalProperties: type: object microsoft.graph.cloudAppSecuritySessionControl: allOf: - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl' - title: cloudAppSecuritySessionControl type: object properties: cloudAppSecurityType: $ref: '#/components/schemas/microsoft.graph.cloudAppSecuritySessionControlType' additionalProperties: type: object microsoft.graph.conditionalAccessLocations: title: conditionalAccessLocations type: object properties: excludeLocations: type: array items: type: string description: Location IDs excluded from scope of policy. includeLocations: type: array items: type: string description: Location IDs in scope of policy unless explicitly excluded, All, or AllTrusted. additionalProperties: type: object microsoft.graph.authenticationStrengthPolicyType: title: authenticationStrengthPolicyType enum: - builtIn - custom - unknownFutureValue type: string microsoft.graph.conditionalAccessExternalTenants: title: conditionalAccessExternalTenants type: object properties: membershipKind: $ref: '#/components/schemas/microsoft.graph.conditionalAccessExternalTenantsMembershipKind' additionalProperties: type: object microsoft.graph.conditionalAccessGuestsOrExternalUsers: title: conditionalAccessGuestsOrExternalUsers type: object properties: externalTenants: $ref: '#/components/schemas/microsoft.graph.conditionalAccessExternalTenants' guestOrExternalUserTypes: $ref: '#/components/schemas/microsoft.graph.conditionalAccessGuestOrExternalUserTypes' additionalProperties: type: object microsoft.graph.conditionalAccessExternalTenantsMembershipKind: title: conditionalAccessExternalTenantsMembershipKind enum: - all - enumerated - unknownFutureValue type: string microsoft.graph.persistentBrowserSessionMode: title: persistentBrowserSessionMode enum: - always - never type: string microsoft.graph.conditionalAccessGuestOrExternalUserTypes: title: conditionalAccessGuestOrExternalUserTypes enum: - none - internalGuest - b2bCollaborationGuest - b2bCollaborationMember - b2bDirectConnectUser - otherExternalUser - serviceProvider - unknownFutureValue type: string x-ms-enum-flags: isFlags: true microsoft.graph.conditionalAccessTransferMethods: title: conditionalAccessTransferMethods enum: - none - deviceCodeFlow - authenticationTransfer - unknownFutureValue type: string x-ms-enum-flags: isFlags: true microsoft.graph.conditionalAccessGrantControls: title: conditionalAccessGrantControls type: object properties: builtInControls: type: array items: $ref: '#/components/schemas/microsoft.graph.conditionalAccessGrantControl' description: 'List of values of built-in controls required by the policy. Possible values: block, mfa, compliantDevice, domainJoinedDevice, approvedApplication, compliantApplication, passwordChange, unknownFutureValue, riskRemediation. Use the Prefer: include-unknown-enum-members request header to get the following value in this evolvable enum: riskRemediation.' customAuthenticationFactors: type: array items: type: string description: List of custom controls IDs required by the policy. For more information, see Custom controls. operator: type: - string - 'null' description: 'Defines the relationship of the grant controls. Possible values: AND, OR.' termsOfUse: type: array items: type: string description: List of terms of use IDs required by the policy. authenticationStrength: $ref: '#/components/schemas/microsoft.graph.authenticationStrengthPolicy' additionalProperties: type: object microsoft.graph.conditionalAccessDevicePlatform: title: conditionalAccessDevicePlatform enum: - android - iOS - windows - windowsPhone - macOS - all - unknownFutureValue - linux type: string microsoft.graph.riskLevel: title: riskLevel enum: - low - medium - high - hidden - none - unknownFutureValue type: string microsoft.graph.signInFrequencyAuthenticationType: title: signInFrequencyAuthenticationType enum: - primaryAndSecondaryAuthentication - secondaryAuthentication - unknownFutureValue type: string microsoft.graph.ODataErrors.MainError: required: - code - message type: object properties: code: type: string message: type: string x-ms-primary-error-message: true target: type: - string - 'null' details: type: array items: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails' innerError: $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError' additionalProperties: type: object microsoft.graph.policyDeletableItem: title: policyDeletableItem type: object properties: deletedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' format: date-time additionalProperties: type: object microsoft.graph.entity: title: entity type: object properties: id: type: string description: The unique identifier for an entity. Read-only. additionalProperties: type: object ODataCountResponse: type: integer format: int32 microsoft.graph.secureSignInSessionControl: allOf: - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl' - title: secureSignInSessionControl type: object additionalProperties: type: object microsoft.graph.signInFrequencySessionControl: allOf: - $ref: '#/components/schemas/microsoft.graph.conditionalAccessSessionControl' - title: signInFrequencySessionControl type: object properties: authenticationType: $ref: '#/components/schemas/microsoft.graph.signInFrequencyAuthenticationType' frequencyInterval: $ref: '#/components/schemas/microsoft.graph.signInFrequencyInterval' type: $ref: '#/components/schemas/microsoft.graph.signinFrequencyType' value: maximum: 2147483647 minimum: -2147483648 type: - number - 'null' description: The number of days or hours. format: int32 additionalProperties: type: object microsoft.graph.conditionalAccessInsiderRiskLevels: title: conditionalAccessInsiderRiskLevels enum: - minor - moderate - elevated - unknownFutureValue type: string x-ms-enum-flags: isFlags: true parameters: count: name: $count in: query description: Include count of items style: form explode: false schema: type: boolean filter: name: $filter in: query description: Filter items by property values style: form explode: false schema: type: string search: name: $search in: query description: Search items by search phrases style: form explode: false schema: type: string skip: name: $skip in: query description: Skip the first n items style: form explode: false schema: minimum: 0 type: integer top: name: $top in: query description: Show only the first n items style: form explode: false schema: minimum: 0 type: integer example: 50 responses: microsoft.graph.conditionalAccessPolicyCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.conditionalAccessPolicyCollectionResponse' ODataCountResponse: description: The count of the resource content: text/plain: schema: $ref: '#/components/schemas/ODataCountResponse' error: description: error content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError' securitySchemes: azureaadv2: type: oauth2 flows: authorizationCode: authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token scopes: {}