openapi: 3.2.0 info: title: Applications Service Principals.app Role Assignment API version: v1.0 servers: - url: https://graph.microsoft.com/v1.0/ description: Core security: - azureaadv2: [] tags: - name: servicePrincipals.appRoleAssignment paths: /servicePrincipals/{servicePrincipal-id}/appRoleAssignedTo: get: tags: - servicePrincipals.appRoleAssignment summary: Get appRoleAssignment description: Read the properties and relationships of an appRoleAssignment object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/serviceprincipal-list-approleassignedto?view=graph-rest-1.0 operationId: servicePrincipal_ListAppRoleAssignedTo parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.appRoleAssignmentCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - servicePrincipals.appRoleAssignment summary: Grant an appRoleAssignment for a service principal description: 'Assign an app role for a resource service principal, to a user, group, or client service principal. App roles that are assigned to service principals are also known as application permissions. Application permissions can be granted directly with app role assignments, or through a consent experience. To grant an app role assignment, you need three identifiers:' externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/serviceprincipal-post-approleassignedto?view=graph-rest-1.0 operationId: servicePrincipal_CreateAppRoleAssignedTo parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.appRoleAssignment' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.appRoleAssignment' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /servicePrincipals/{servicePrincipal-id}/appRoleAssignedTo/{appRoleAssignment-id}: get: tags: - servicePrincipals.appRoleAssignment summary: Get appRoleAssignment description: Read the properties and relationships of an appRoleAssignment object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/approleassignment-get?view=graph-rest-1.0 operationId: servicePrincipal_GetAppRoleAssignedTo parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - name: appRoleAssignment-id in: path description: The unique identifier of appRoleAssignment required: true style: simple schema: type: string x-ms-docs-key-type: appRoleAssignment - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.appRoleAssignment' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - servicePrincipals.appRoleAssignment summary: Update the navigation property appRoleAssignedTo in servicePrincipals operationId: servicePrincipal_UpdateAppRoleAssignedTo parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - name: appRoleAssignment-id in: path description: The unique identifier of appRoleAssignment required: true style: simple schema: type: string x-ms-docs-key-type: appRoleAssignment requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.appRoleAssignment' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.appRoleAssignment' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - servicePrincipals.appRoleAssignment summary: Delete appRoleAssignedTo description: Deletes an appRoleAssignment that a user, group, or client service principal has been granted for a resource service principal. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/serviceprincipal-delete-approleassignedto?view=graph-rest-1.0 operationId: servicePrincipal_DeleteAppRoleAssignedTo parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - name: appRoleAssignment-id in: path description: The unique identifier of appRoleAssignment required: true style: simple schema: type: string x-ms-docs-key-type: appRoleAssignment - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /servicePrincipals/{servicePrincipal-id}/appRoleAssignedTo/$count: get: tags: - servicePrincipals.appRoleAssignment summary: Get the number of the resource operationId: servicePrincipal.appRoleAssignedTo_GetCount parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' /servicePrincipals/{servicePrincipal-id}/appRoleAssignments: get: tags: - servicePrincipals.appRoleAssignment summary: Get appRoleAssignment description: Read the properties and relationships of an appRoleAssignment object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/serviceprincipal-list-approleassignments?view=graph-rest-1.0 operationId: servicePrincipal_ListAppRoleAssignment parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - name: ConsistencyLevel in: header description: 'Indicates the requested consistency level. Documentation URL: https://docs.microsoft.com/graph/aad-advanced-queries' style: simple schema: type: string examples: example-1: description: $search and $count queries require the client to set the ConsistencyLevel HTTP header to 'eventual'. value: eventual - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.appRoleAssignmentCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - servicePrincipals.appRoleAssignment summary: Grant an appRoleAssignment to a service principal description: 'Assign an app role to a client service principal. App roles that are assigned to service principals are also known as application permissions. Application permissions can be granted directly with app role assignments, or through a consent experience. To grant an app role assignment to a client service principal, you need three identifiers:' externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/serviceprincipal-post-approleassignments?view=graph-rest-1.0 operationId: servicePrincipal_CreateAppRoleAssignment parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.appRoleAssignment' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.appRoleAssignment' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /servicePrincipals/{servicePrincipal-id}/appRoleAssignments/{appRoleAssignment-id}: get: tags: - servicePrincipals.appRoleAssignment summary: Get appRoleAssignment description: Read the properties and relationships of an appRoleAssignment object. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/approleassignment-get?view=graph-rest-1.0 operationId: servicePrincipal_GetAppRoleAssignment parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - name: appRoleAssignment-id in: path description: The unique identifier of appRoleAssignment required: true style: simple schema: type: string x-ms-docs-key-type: appRoleAssignment - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.appRoleAssignment' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - servicePrincipals.appRoleAssignment summary: Update the navigation property appRoleAssignments in servicePrincipals operationId: servicePrincipal_UpdateAppRoleAssignment parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - name: appRoleAssignment-id in: path description: The unique identifier of appRoleAssignment required: true style: simple schema: type: string x-ms-docs-key-type: appRoleAssignment requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.appRoleAssignment' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.appRoleAssignment' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - servicePrincipals.appRoleAssignment summary: Delete appRoleAssignment description: Deletes an appRoleAssignment that a service principal has been granted. App roles which are assigned to service principals are also known as application permissions. Deleting an app role assignment for a service principal is equivalent to revoking the app-only permission grant. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/serviceprincipal-delete-approleassignments?view=graph-rest-1.0 operationId: servicePrincipal_DeleteAppRoleAssignment parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - name: appRoleAssignment-id in: path description: The unique identifier of appRoleAssignment required: true style: simple schema: type: string x-ms-docs-key-type: appRoleAssignment - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /servicePrincipals/{servicePrincipal-id}/appRoleAssignments/$count: get: tags: - servicePrincipals.appRoleAssignment summary: Get the number of the resource operationId: servicePrincipal.appRoleAssignment_GetCount parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - name: ConsistencyLevel in: header description: 'Indicates the requested consistency level. Documentation URL: https://docs.microsoft.com/graph/aad-advanced-queries' style: simple schema: type: string examples: example-1: description: $search and $count queries require the client to set the ConsistencyLevel HTTP header to 'eventual'. value: eventual - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' components: responses: microsoft.graph.appRoleAssignmentCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.appRoleAssignmentCollectionResponse' error: description: error content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError' ODataCountResponse: description: The count of the resource content: text/plain: schema: $ref: '#/components/schemas/ODataCountResponse' parameters: top: name: $top in: query description: Show only the first n items style: form explode: false schema: minimum: 0 type: integer example: 50 count: name: $count in: query description: Include count of items style: form explode: false schema: type: boolean filter: name: $filter in: query description: Filter items by property values style: form explode: false schema: type: string search: name: $search in: query description: Search items by search phrases style: form explode: false schema: type: string skip: name: $skip in: query description: Skip the first n items style: form explode: false schema: minimum: 0 type: integer schemas: microsoft.graph.appRoleAssignment: allOf: - $ref: '#/components/schemas/microsoft.graph.directoryObject' - title: appRoleAssignment type: object properties: appRoleId: pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$ type: string description: The identifier (id) for the app role that's assigned to the principal. This app role must be exposed in the appRoles property on the resource application's service principal (resourceId). If the resource application hasn't declared any app roles, a default app role ID of 00000000-0000-0000-0000-000000000000 can be specified to signal that the principal is assigned to the resource app without any specific app roles. Required on create. format: uuid createdDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: The time when the app role assignment was created. The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. Read-only. format: date-time principalDisplayName: type: - string - 'null' description: The display name of the user, group, or service principal that was granted the app role assignment. Maximum length is 256 characters. Read-only. Supports $filter (eq and startswith). principalId: pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$ type: - string - 'null' description: The unique identifier (id) for the user, security group, or service principal being granted the app role. Security groups with dynamic memberships are supported. Required on create. format: uuid principalType: type: - string - 'null' description: The type of the assigned principal. This can either be User, Group, or ServicePrincipal. Read-only. resourceDisplayName: type: - string - 'null' description: The display name of the resource app's service principal to which the assignment is made. Maximum length is 256 characters. resourceId: pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$ type: - string - 'null' description: The unique identifier (id) for the resource service principal for which the assignment is made. Required on create. Supports $filter (eq only). format: uuid additionalProperties: type: object microsoft.graph.ODataErrors.InnerError: type: object additionalProperties: type: object description: The structure of this object is service-specific microsoft.graph.directoryObject: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: directoryObject type: object properties: deletedDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: - string - 'null' description: Date and time when this object was deleted. Always null when the object hasn't been deleted. format: date-time additionalProperties: type: object microsoft.graph.ODataErrors.ErrorDetails: required: - code - message type: object properties: code: type: string message: type: string target: type: - string - 'null' additionalProperties: type: object microsoft.graph.appRoleAssignmentCollectionResponse: title: Collection of appRoleAssignment type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.appRoleAssignment' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.ODataErrors.MainError: required: - code - message type: object properties: code: type: string message: type: string x-ms-primary-error-message: true target: type: - string - 'null' details: type: array items: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails' innerError: $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError' additionalProperties: type: object microsoft.graph.ODataErrors.ODataError: required: - error type: object properties: error: $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError' additionalProperties: type: object microsoft.graph.entity: title: entity type: object properties: id: type: string description: The unique identifier for an entity. Read-only. additionalProperties: type: object ODataCountResponse: type: integer format: int32 securitySchemes: azureaadv2: type: oauth2 flows: authorizationCode: authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token scopes: {}