openapi: 3.2.0 info: title: Identity.SignIns Policies.unified Role Management Policy… version: v1.0 servers: - url: https://graph.microsoft.com/v1.0/ description: Core security: - azureaadv2: [] tags: - name: policies.unifiedRoleManagementPolicyAssignment paths: /policies/roleManagementPolicyAssignments: get: tags: - policies.unifiedRoleManagementPolicyAssignment summary: List roleManagementPolicyAssignments description: Get the details of all role management policy assignments made in PIM for Microsoft Entra roles and PIM for Groups. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/policyroot-list-rolemanagementpolicyassignments?view=graph-rest-1.0 operationId: policy_ListRoleManagementPolicyAssignment parameters: - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.unifiedRoleManagementPolicyAssignmentCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - policies.unifiedRoleManagementPolicyAssignment summary: Create new navigation property to roleManagementPolicyAssignments for policies operationId: policy_CreateRoleManagementPolicyAssignment requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.unifiedRoleManagementPolicyAssignment' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.unifiedRoleManagementPolicyAssignment' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /policies/roleManagementPolicyAssignments/{unifiedRoleManagementPolicyAssignment-id}: get: tags: - policies.unifiedRoleManagementPolicyAssignment summary: Get unifiedRoleManagementPolicyAssignment description: Get the details of a policy assignment in PIM that's assigned to Microsoft Entra roles or group membership or ownership. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/unifiedrolemanagementpolicyassignment-get?view=graph-rest-1.0 operationId: policy_GetRoleManagementPolicyAssignment parameters: - name: unifiedRoleManagementPolicyAssignment-id in: path description: The unique identifier of unifiedRoleManagementPolicyAssignment required: true style: simple schema: type: string x-ms-docs-key-type: unifiedRoleManagementPolicyAssignment - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.unifiedRoleManagementPolicyAssignment' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - policies.unifiedRoleManagementPolicyAssignment summary: Update the navigation property roleManagementPolicyAssignments in policies operationId: policy_UpdateRoleManagementPolicyAssignment parameters: - name: unifiedRoleManagementPolicyAssignment-id in: path description: The unique identifier of unifiedRoleManagementPolicyAssignment required: true style: simple schema: type: string x-ms-docs-key-type: unifiedRoleManagementPolicyAssignment requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.unifiedRoleManagementPolicyAssignment' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.unifiedRoleManagementPolicyAssignment' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - policies.unifiedRoleManagementPolicyAssignment summary: Delete navigation property roleManagementPolicyAssignments for policies operationId: policy_DeleteRoleManagementPolicyAssignment parameters: - name: unifiedRoleManagementPolicyAssignment-id in: path description: The unique identifier of unifiedRoleManagementPolicyAssignment required: true style: simple schema: type: string x-ms-docs-key-type: unifiedRoleManagementPolicyAssignment - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /policies/roleManagementPolicyAssignments/{unifiedRoleManagementPolicyAssignment-id}/policy: get: tags: - policies.unifiedRoleManagementPolicyAssignment summary: Get policy from policies description: The policy that's associated with a policy assignment. Supports $expand and a nested $expand of the rules and effectiveRules relationships for the policy. operationId: policy.roleManagementPolicyAssignment_GetPolicy parameters: - name: unifiedRoleManagementPolicyAssignment-id in: path description: The unique identifier of unifiedRoleManagementPolicyAssignment required: true style: simple schema: type: string x-ms-docs-key-type: unifiedRoleManagementPolicyAssignment - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.unifiedRoleManagementPolicy' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /policies/roleManagementPolicyAssignments/$count: get: tags: - policies.unifiedRoleManagementPolicyAssignment summary: Get the number of the resource operationId: policy.roleManagementPolicyAssignment_GetCount parameters: - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' components: parameters: count: name: $count in: query description: Include count of items style: form explode: false schema: type: boolean filter: name: $filter in: query description: Filter items by property values style: form explode: false schema: type: string search: name: $search in: query description: Search items by search phrases style: form explode: false schema: type: string skip: name: $skip in: query description: Skip the first n items style: form explode: false schema: minimum: 0 type: integer top: name: $top in: query description: Show only the first n items style: form explode: false schema: minimum: 0 type: integer example: 50 schemas: microsoft.graph.ODataErrors.ODataError: required: - error type: object properties: error: $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError' additionalProperties: type: object microsoft.graph.unifiedRoleManagementPolicyRule: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: unifiedRoleManagementPolicyRule type: object properties: target: $ref: '#/components/schemas/microsoft.graph.unifiedRoleManagementPolicyRuleTarget' additionalProperties: type: object microsoft.graph.ODataErrors.InnerError: type: object additionalProperties: type: object description: The structure of this object is service-specific ODataCountResponse: type: integer format: int32 microsoft.graph.directoryObject: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: directoryObject type: object properties: deletedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: Date and time when this object was deleted. Always null when the object hasn't been deleted. format: date-time additionalProperties: type: object microsoft.graph.unifiedRoleManagementPolicy: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: unifiedRoleManagementPolicy type: object properties: description: type: string description: Description for the policy. displayName: type: string description: Display name for the policy. isOrganizationDefault: type: - boolean - 'null' description: This can only be set to true for a single tenant-wide policy which will apply to all scopes and roles. Set the scopeId to / and scopeType to Directory. Supports $filter (eq, ne). lastModifiedBy: $ref: '#/components/schemas/microsoft.graph.identity' lastModifiedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The time when the role setting was last modified. format: date-time scopeId: type: string description: The identifier of the scope where the policy is created. Can be / for the tenant or a group ID. Required. scopeType: type: string description: The type of the scope where the policy is created. One of Directory, DirectoryRole, Group. Required. effectiveRules: type: array items: $ref: '#/components/schemas/microsoft.graph.unifiedRoleManagementPolicyRule' description: The list of effective rules like approval rules and expiration rules evaluated based on inherited referenced rules. For example, if there is a tenant-wide policy to enforce enabling an approval rule, the effective rule will be to enable approval even if the policy has a rule to disable approval. Supports $expand. x-ms-navigationProperty: true rules: type: array items: $ref: '#/components/schemas/microsoft.graph.unifiedRoleManagementPolicyRule' description: The collection of rules like approval rules and expiration rules. Supports $expand. x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.identity: title: identity type: object properties: displayName: type: - string - 'null' description: The display name of the identity.For drive items, the display name might not always be available or up to date. For example, if a user changes their display name the API might show the new value in a future response, but the items associated with the user don't show up as changed when using delta. id: type: - string - 'null' description: Unique identifier for the identity or actor. For example, in the access reviews decisions API, this property might record the id of the principal, that is, the group, user, or application that's subject to review. additionalProperties: type: object microsoft.graph.ODataErrors.ErrorDetails: required: - code - message type: object properties: code: type: string message: type: string target: type: - string - 'null' additionalProperties: type: object microsoft.graph.unifiedRoleManagementPolicyAssignmentCollectionResponse: title: Collection of unifiedRoleManagementPolicyAssignment type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.unifiedRoleManagementPolicyAssignment' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.unifiedRoleManagementPolicyRuleTargetOperations: title: unifiedRoleManagementPolicyRuleTargetOperations enum: - all - activate - deactivate - assign - update - remove - extend - renew - unknownFutureValue type: string microsoft.graph.ODataErrors.MainError: required: - code - message type: object properties: code: type: string message: type: string x-ms-primary-error-message: true target: type: - string - 'null' details: type: array items: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails' innerError: $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError' additionalProperties: type: object microsoft.graph.unifiedRoleManagementPolicyRuleTarget: title: unifiedRoleManagementPolicyRuleTarget type: object properties: caller: type: - string - 'null' description: 'The type of caller that''s the target of the policy rule. Allowed values are: None, Admin, EndUser.' enforcedSettings: type: array items: type: - string - 'null' description: The list of role settings that are enforced and cannot be overridden by child scopes. Use All for all settings. inheritableSettings: type: array items: type: - string - 'null' description: The list of role settings that can be inherited by child scopes. Use All for all settings. level: type: - string - 'null' description: 'The role assignment type that''s the target of policy rule. Allowed values are: Eligibility, Assignment.' operations: type: array items: $ref: '#/components/schemas/microsoft.graph.unifiedRoleManagementPolicyRuleTargetOperations' description: 'The role management operations that are the target of the policy rule. Allowed values are: All, Activate, Deactivate, Assign, Update, Remove, Extend, Renew.' targetObjects: type: array items: $ref: '#/components/schemas/microsoft.graph.directoryObject' x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.entity: title: entity type: object properties: id: type: string description: The unique identifier for an entity. Read-only. additionalProperties: type: object microsoft.graph.unifiedRoleManagementPolicyAssignment: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: unifiedRoleManagementPolicyAssignment type: object properties: policyId: type: string description: The id of the policy. Inherited from entity. roleDefinitionId: type: - string - 'null' description: For Microsoft Entra roles policy, it's the identifier of the role definition object where the policy applies. For PIM for Groups membership and ownership, it's either member or owner. Supports $filter (eq). scopeId: type: string description: The identifier of the scope where the policy is assigned. Can be / for the tenant or a group ID. Required. scopeType: type: string description: The type of the scope where the policy is assigned. One of Directory, DirectoryRole, Group. Required. policy: $ref: '#/components/schemas/microsoft.graph.unifiedRoleManagementPolicy' additionalProperties: type: object responses: ODataCountResponse: description: The count of the resource content: text/plain: schema: $ref: '#/components/schemas/ODataCountResponse' microsoft.graph.unifiedRoleManagementPolicyAssignmentCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.unifiedRoleManagementPolicyAssignmentCollectionResponse' error: description: error content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError' securitySchemes: azureaadv2: type: oauth2 flows: authorizationCode: authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token scopes: {}