openapi: 3.2.0 info: title: Identity.SignIns Policies.tenant App Management Policy API version: v1.0 servers: - url: https://graph.microsoft.com/v1.0/ description: Core security: - azureaadv2: [] tags: - name: policies.tenantAppManagementPolicy paths: /policies/defaultAppManagementPolicy: get: tags: - policies.tenantAppManagementPolicy summary: Get tenantAppManagementPolicy description: Read the properties of a tenantAppManagementPolicy object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/tenantappmanagementpolicy-get?view=graph-rest-1.0 operationId: policy_GetDefaultAppManagementPolicy parameters: - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.tenantAppManagementPolicy' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - policies.tenantAppManagementPolicy summary: Update tenantAppManagementPolicy description: Update the properties of a tenantAppManagementPolicy object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/tenantappmanagementpolicy-update?view=graph-rest-1.0 operationId: policy_UpdateDefaultAppManagementPolicy requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.tenantAppManagementPolicy' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.tenantAppManagementPolicy' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - policies.tenantAppManagementPolicy summary: Delete navigation property defaultAppManagementPolicy for policies operationId: policy_DeleteDefaultAppManagementPolicy parameters: - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation components: schemas: microsoft.graph.ODataErrors.ODataError: required: - error type: object properties: error: $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError' additionalProperties: type: object microsoft.graph.identifierUriConfiguration: title: identifierUriConfiguration type: object properties: nonDefaultUriAddition: $ref: '#/components/schemas/microsoft.graph.identifierUriRestriction' uriAdditionWithoutUniqueTenantIdentifier: $ref: '#/components/schemas/microsoft.graph.identifierUriRestriction' additionalProperties: type: object microsoft.graph.appManagementServicePrincipalConfiguration: allOf: - $ref: '#/components/schemas/microsoft.graph.appManagementConfiguration' - title: appManagementServicePrincipalConfiguration type: object additionalProperties: type: object microsoft.graph.ODataErrors.InnerError: type: object additionalProperties: type: object description: The structure of this object is service-specific microsoft.graph.directoryObject: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: directoryObject type: object properties: deletedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: Date and time when this object was deleted. Always null when the object hasn't been deleted. format: date-time additionalProperties: type: object microsoft.graph.customSecurityAttributeExemption: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: customSecurityAttributeExemption type: object properties: id: type: string operator: $ref: '#/components/schemas/microsoft.graph.customSecurityAttributeComparisonOperator' additionalProperties: type: object microsoft.graph.keyCredentialConfiguration: title: keyCredentialConfiguration type: object properties: excludeActors: $ref: '#/components/schemas/microsoft.graph.appManagementPolicyActorExemptions' maxLifetime: pattern: ^-?P([0-9]+D)?(T([0-9]+H)?([0-9]+M)?([0-9]+([.][0-9]+)?S)?)?$ type: - string - 'null' description: String value that indicates the maximum lifetime for key expiration, defined as an ISO 8601 duration. For example, P4DT12H30M5S represents four days, 12 hours, 30 minutes, and five seconds. This property is required when restrictionType is set to asymmetricKeyLifetime. format: duration restrictForAppsCreatedAfterDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: Specifies the date from which the policy restriction applies to newly created applications. For existing applications, the enforcement date can be retroactively applied. format: date-time restrictionType: $ref: '#/components/schemas/microsoft.graph.appKeyCredentialRestrictionType' state: $ref: '#/components/schemas/microsoft.graph.appManagementRestrictionState' additionalProperties: type: object microsoft.graph.policyBase: allOf: - $ref: '#/components/schemas/microsoft.graph.directoryObject' - title: policyBase type: object properties: description: type: - string - 'null' description: Description for this policy. Required. displayName: type: - string - 'null' description: Display name for this policy. Required. additionalProperties: type: object microsoft.graph.appManagementApplicationConfiguration: allOf: - $ref: '#/components/schemas/microsoft.graph.appManagementConfiguration' - title: appManagementApplicationConfiguration type: object properties: identifierUris: $ref: '#/components/schemas/microsoft.graph.identifierUriConfiguration' additionalProperties: type: object microsoft.graph.ODataErrors.ErrorDetails: required: - code - message type: object properties: code: type: string message: type: string target: type: - string - 'null' additionalProperties: type: object microsoft.graph.appKeyCredentialRestrictionType: title: appKeyCredentialRestrictionType enum: - asymmetricKeyLifetime - unknownFutureValue type: string microsoft.graph.appManagementRestrictionState: title: appManagementRestrictionState enum: - enabled - disabled - unknownFutureValue type: string microsoft.graph.appManagementConfiguration: title: appManagementConfiguration type: object properties: keyCredentials: type: array items: $ref: '#/components/schemas/microsoft.graph.keyCredentialConfiguration' description: Collection of keyCredential restrictions settings to be applied to an application or service principal. passwordCredentials: type: array items: $ref: '#/components/schemas/microsoft.graph.passwordCredentialConfiguration' description: Collection of password restrictions settings to be applied to an application or service principal. additionalProperties: type: object microsoft.graph.appManagementPolicyActorExemptions: title: appManagementPolicyActorExemptions type: object properties: customSecurityAttributes: type: array items: $ref: '#/components/schemas/microsoft.graph.customSecurityAttributeExemption' description: The collection of customSecurityAttributeExemption to exempt from the policy enforcement. Limit of 5. additionalProperties: type: object microsoft.graph.appCredentialRestrictionType: title: appCredentialRestrictionType enum: - passwordAddition - passwordLifetime - symmetricKeyAddition - symmetricKeyLifetime - customPasswordAddition - unknownFutureValue type: string microsoft.graph.passwordCredentialConfiguration: title: passwordCredentialConfiguration type: object properties: excludeActors: $ref: '#/components/schemas/microsoft.graph.appManagementPolicyActorExemptions' maxLifetime: pattern: ^-?P([0-9]+D)?(T([0-9]+H)?([0-9]+M)?([0-9]+([.][0-9]+)?S)?)?$ type: - string - 'null' description: String value that indicates the maximum lifetime for password expiration, defined as an ISO 8601 duration. For example, P4DT12H30M5S represents four days, 12 hours, 30 minutes, and five seconds. This property is required when restrictionType is set to passwordLifetime. format: duration restrictForAppsCreatedAfterDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: Specifies the date from which the policy restriction applies to newly created applications. For existing applications, the enforcement date can be retroactively applied. format: date-time restrictionType: $ref: '#/components/schemas/microsoft.graph.appCredentialRestrictionType' state: $ref: '#/components/schemas/microsoft.graph.appManagementRestrictionState' additionalProperties: type: object microsoft.graph.customSecurityAttributeComparisonOperator: title: customSecurityAttributeComparisonOperator enum: - equals - unknownFutureValue type: string microsoft.graph.identifierUriRestriction: title: identifierUriRestriction type: object properties: excludeActors: $ref: '#/components/schemas/microsoft.graph.appManagementPolicyActorExemptions' excludeAppsReceivingV2Tokens: type: - boolean - 'null' description: If true, the restriction isn't enforced for applications that are configured to receive V2 tokens in Microsoft Entra ID; else, the restriction is enforced for those applications. excludeSaml: type: - boolean - 'null' description: If true, the restriction isn't enforced for SAML applications in Microsoft Entra ID; else, the restriction is enforced for those applications. isStateSetByMicrosoft: type: boolean description: If true, Microsoft sets the identifierUriRestriction state. If false, the tenant modifies the identifierUriRestriction state. Read-only. readOnly: true restrictForAppsCreatedAfterDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: Specifies the date from which the policy restriction applies to newly created applications. For existing applications, the enforcement date can be retroactively applied. format: date-time state: $ref: '#/components/schemas/microsoft.graph.appManagementRestrictionState' additionalProperties: type: object microsoft.graph.ODataErrors.MainError: required: - code - message type: object properties: code: type: string message: type: string x-ms-primary-error-message: true target: type: - string - 'null' details: type: array items: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails' innerError: $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError' additionalProperties: type: object microsoft.graph.tenantAppManagementPolicy: allOf: - $ref: '#/components/schemas/microsoft.graph.policyBase' - title: tenantAppManagementPolicy type: object properties: applicationRestrictions: $ref: '#/components/schemas/microsoft.graph.appManagementApplicationConfiguration' isEnabled: type: boolean description: Denotes whether the policy is enabled. Default value is false. servicePrincipalRestrictions: $ref: '#/components/schemas/microsoft.graph.appManagementServicePrincipalConfiguration' additionalProperties: type: object microsoft.graph.entity: title: entity type: object properties: id: type: string description: The unique identifier for an entity. Read-only. additionalProperties: type: object responses: error: description: error content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError' securitySchemes: azureaadv2: type: oauth2 flows: authorizationCode: authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token scopes: {}