openapi: 3.2.0 info: title: Applications Service Principals.remote Desktop Security… version: v1.0 servers: - url: https://graph.microsoft.com/v1.0/ description: Core security: - azureaadv2: [] tags: - name: servicePrincipals.remoteDesktopSecurityConfiguration paths: /servicePrincipals/{servicePrincipal-id}/remoteDesktopSecurityConfiguration: get: tags: - servicePrincipals.remoteDesktopSecurityConfiguration summary: Get remoteDesktopSecurityConfiguration description: Read the properties and relationships of a remoteDesktopSecurityConfiguration object on a servicePrincipal. Use this configuration to view the Microsoft Entra ID Remote Desktop Services (RDS) authentication protocol to authenticate a user to Microsoft Entra joined or Microsoft Entra hybrid joined devices. Additionally you can view any targetDeviceGroups that have been configured for SSO. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/remotedesktopsecurityconfiguration-get?view=graph-rest-1.0 operationId: servicePrincipal_GetRemoteDesktopSecurityConfiguration parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.remoteDesktopSecurityConfiguration' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - servicePrincipals.remoteDesktopSecurityConfiguration summary: Update remoteDesktopSecurityConfiguration description: Update the properties of a remoteDesktopSecurityConfiguration object on the servicePrincipal. Use this configuration to enable or disable the Microsoft Entra ID Remote Desktop Services (RDS) authentication protocol to authenticate a user to Microsoft Entra joined or Microsoft Entra hybrid joined devices. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/remotedesktopsecurityconfiguration-update?view=graph-rest-1.0 operationId: servicePrincipal_UpdateRemoteDesktopSecurityConfiguration parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.remoteDesktopSecurityConfiguration' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.remoteDesktopSecurityConfiguration' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - servicePrincipals.remoteDesktopSecurityConfiguration summary: Delete remoteDesktopSecurityConfiguration description: Delete a remoteDesktopSecurityConfiguration object on a servicePrincipal. Removing remoteDesktopSecurityConfiguration object on the servicePrincipal disables the Microsoft Entra ID Remote Desktop Services (RDS) authentication protocol to authenticate a user to Microsoft Entra joined or Microsoft Entra hybrid joined devices, and removes any target device groups that you configured for SSO. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/serviceprincipal-delete-remotedesktopsecurityconfiguration?view=graph-rest-1.0 operationId: servicePrincipal_DeleteRemoteDesktopSecurityConfiguration parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /servicePrincipals/{servicePrincipal-id}/remoteDesktopSecurityConfiguration/approvedClientApps: get: tags: - servicePrincipals.remoteDesktopSecurityConfiguration summary: List approvedClientApp objects description: The collection of approved client apps that are associated with the RDS configuration. Supports $expand. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/remotedesktopsecurityconfiguration-list-approvedclientapps?view=graph-rest-1.0 operationId: servicePrincipal.remoteDesktopSecurityConfiguration_ListApprovedClientApp parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.approvedClientAppCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - servicePrincipals.remoteDesktopSecurityConfiguration summary: Create approvedClientApp description: Create a new approvedClientApp object for the remoteDesktopSecurityConfiguration object on a service principal. You can configure a maximum of 20 approved client apps. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/remotedesktopsecurityconfiguration-post-approvedclientapps?view=graph-rest-1.0 operationId: servicePrincipal.remoteDesktopSecurityConfiguration_CreateApprovedClientApp parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.approvedClientApp' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.approvedClientApp' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /servicePrincipals/{servicePrincipal-id}/remoteDesktopSecurityConfiguration/approvedClientApps/{approvedClientApp-id}: get: tags: - servicePrincipals.remoteDesktopSecurityConfiguration summary: Get approvedClientApp description: Read the properties and relationships of a approvedClientApp object for the remoteDesktopSecurityConfiguration object on a servicePrincipal. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/approvedclientapp-get?view=graph-rest-1.0 operationId: servicePrincipal.remoteDesktopSecurityConfiguration_GetApprovedClientApp parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - name: approvedClientApp-id in: path description: The unique identifier of approvedClientApp required: true style: simple schema: type: string x-ms-docs-key-type: approvedClientApp - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.approvedClientApp' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - servicePrincipals.remoteDesktopSecurityConfiguration summary: Update approvedClientApp description: Update the properties of an approvedClientApp object for a remotedesktopsecurityconfiguration. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/approvedclientapp-update?view=graph-rest-1.0 operationId: servicePrincipal.remoteDesktopSecurityConfiguration_UpdateApprovedClientApp parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - name: approvedClientApp-id in: path description: The unique identifier of approvedClientApp required: true style: simple schema: type: string x-ms-docs-key-type: approvedClientApp requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.approvedClientApp' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.approvedClientApp' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - servicePrincipals.remoteDesktopSecurityConfiguration summary: Delete approvedClientApp externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/remotedesktopsecurityconfiguration-delete-approvedclientapps?view=graph-rest-1.0 operationId: servicePrincipal.remoteDesktopSecurityConfiguration_DeleteApprovedClientApp parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - name: approvedClientApp-id in: path description: The unique identifier of approvedClientApp required: true style: simple schema: type: string x-ms-docs-key-type: approvedClientApp - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /servicePrincipals/{servicePrincipal-id}/remoteDesktopSecurityConfiguration/approvedClientApps/$count: get: tags: - servicePrincipals.remoteDesktopSecurityConfiguration summary: Get the number of the resource operationId: servicePrincipal.remoteDesktopSecurityConfiguration.approvedClientApp_GetCount parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' /servicePrincipals/{servicePrincipal-id}/remoteDesktopSecurityConfiguration/targetDeviceGroups: get: tags: - servicePrincipals.remoteDesktopSecurityConfiguration summary: List targetDeviceGroups description: Get a list of the targetDeviceGroup objects and their properties on the remoteDesktopSecurityConfiguration resource on the servicePrincipal. Any user authenticating using the Microsoft Entra ID Remote Desktop Services (RDS) authentication protocol to a Microsoft Entra joined or Microsoft Entra hybrid joined device that belongs to the targetDeviceGroup will get SSO. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/remotedesktopsecurityconfiguration-list-targetdevicegroups?view=graph-rest-1.0 operationId: servicePrincipal.remoteDesktopSecurityConfiguration_ListTargetDeviceGroup parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.targetDeviceGroupCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - servicePrincipals.remoteDesktopSecurityConfiguration summary: Create targetDeviceGroup description: Create a new targetDeviceGroup object for the remoteDesktopSecurityConfiguration object on the servicePrincipal. You can configure a maximum of 10 target device groups for the remoteDesktopSecurityConfiguration object on the servicePrincipal. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/remotedesktopsecurityconfiguration-post-targetdevicegroups?view=graph-rest-1.0 operationId: servicePrincipal.remoteDesktopSecurityConfiguration_CreateTargetDeviceGroup parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.targetDeviceGroup' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.targetDeviceGroup' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /servicePrincipals/{servicePrincipal-id}/remoteDesktopSecurityConfiguration/targetDeviceGroups/{targetDeviceGroup-id}: get: tags: - servicePrincipals.remoteDesktopSecurityConfiguration summary: Get targetDeviceGroup description: Read the properties and relationships of a targetDeviceGroup object for the remoteDesktopSecurityConfiguration object on the servicePrincipal. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/targetdevicegroup-get?view=graph-rest-1.0 operationId: servicePrincipal.remoteDesktopSecurityConfiguration_GetTargetDeviceGroup parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - name: targetDeviceGroup-id in: path description: The unique identifier of targetDeviceGroup required: true style: simple schema: type: string x-ms-docs-key-type: targetDeviceGroup - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.targetDeviceGroup' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - servicePrincipals.remoteDesktopSecurityConfiguration summary: Update targetDeviceGroup description: Update the properties of a targetDeviceGroup object for remoteDesktopSecurityConfiguration object on the servicePrincipal. You can configure a maximum of 10 target device groups for the remoteDesktopSecurityConfiguraiton object on the servicePrincipal. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/targetdevicegroup-update?view=graph-rest-1.0 operationId: servicePrincipal.remoteDesktopSecurityConfiguration_UpdateTargetDeviceGroup parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - name: targetDeviceGroup-id in: path description: The unique identifier of targetDeviceGroup required: true style: simple schema: type: string x-ms-docs-key-type: targetDeviceGroup requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.targetDeviceGroup' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.targetDeviceGroup' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - servicePrincipals.remoteDesktopSecurityConfiguration summary: Delete targetDeviceGroup description: Delete a targetDeviceGroup object for the remoteDesktopSecurityConfiguration object on the servicePrincipal. Any user authenticating using the Microsoft Entra ID Remote Desktop Services (RDS) authentication protocol to a Microsoft Entra joined or Microsoft Entra hybrid joined device that's in the removed targetDeviceGroup doesn't get SSO prompts. externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/remotedesktopsecurityconfiguration-delete-targetdevicegroups?view=graph-rest-1.0 operationId: servicePrincipal.remoteDesktopSecurityConfiguration_DeleteTargetDeviceGroup parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - name: targetDeviceGroup-id in: path description: The unique identifier of targetDeviceGroup required: true style: simple schema: type: string x-ms-docs-key-type: targetDeviceGroup - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /servicePrincipals/{servicePrincipal-id}/remoteDesktopSecurityConfiguration/targetDeviceGroups/$count: get: tags: - servicePrincipals.remoteDesktopSecurityConfiguration summary: Get the number of the resource operationId: servicePrincipal.remoteDesktopSecurityConfiguration.targetDeviceGroup_GetCount parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' components: schemas: microsoft.graph.approvedClientApp: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: approvedClientApp type: object properties: displayName: type: - string - 'null' description: The display name of the approved client application. additionalProperties: type: object microsoft.graph.remoteDesktopSecurityConfiguration: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: remoteDesktopSecurityConfiguration type: object properties: isRemoteDesktopProtocolEnabled: type: boolean description: Determines if Microsoft Entra ID RDS authentication protocol for RDP is enabled. approvedClientApps: type: array items: $ref: '#/components/schemas/microsoft.graph.approvedClientApp' description: The collection of approved client apps that are associated with the RDS configuration. Supports $expand. x-ms-navigationProperty: true targetDeviceGroups: type: array items: $ref: '#/components/schemas/microsoft.graph.targetDeviceGroup' description: The collection of target device groups that are associated with the RDS security configuration that will be enabled for SSO when a client connects to the target device over RDP using the new Microsoft Entra ID RDS authentication protocol. x-ms-navigationProperty: true additionalProperties: type: object microsoft.graph.ODataErrors.ODataError: required: - error type: object properties: error: $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError' additionalProperties: type: object microsoft.graph.ODataErrors.InnerError: type: object additionalProperties: type: object description: The structure of this object is service-specific microsoft.graph.targetDeviceGroup: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: targetDeviceGroup type: object properties: displayName: type: - string - 'null' description: Display name for the target device group. additionalProperties: type: object microsoft.graph.targetDeviceGroupCollectionResponse: title: Collection of targetDeviceGroup type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.targetDeviceGroup' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.ODataErrors.ErrorDetails: required: - code - message type: object properties: code: type: string message: type: string target: type: - string - 'null' additionalProperties: type: object microsoft.graph.ODataErrors.MainError: required: - code - message type: object properties: code: type: string message: type: string x-ms-primary-error-message: true target: type: - string - 'null' details: type: array items: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails' innerError: $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError' additionalProperties: type: object microsoft.graph.entity: title: entity type: object properties: id: type: string description: The unique identifier for an entity. Read-only. additionalProperties: type: object ODataCountResponse: type: integer format: int32 microsoft.graph.approvedClientAppCollectionResponse: title: Collection of approvedClientApp type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.approvedClientApp' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object parameters: count: name: $count in: query description: Include count of items style: form explode: false schema: type: boolean filter: name: $filter in: query description: Filter items by property values style: form explode: false schema: type: string search: name: $search in: query description: Search items by search phrases style: form explode: false schema: type: string skip: name: $skip in: query description: Skip the first n items style: form explode: false schema: minimum: 0 type: integer top: name: $top in: query description: Show only the first n items style: form explode: false schema: minimum: 0 type: integer example: 50 responses: microsoft.graph.approvedClientAppCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.approvedClientAppCollectionResponse' ODataCountResponse: description: The count of the resource content: text/plain: schema: $ref: '#/components/schemas/ODataCountResponse' error: description: error content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError' microsoft.graph.targetDeviceGroupCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.targetDeviceGroupCollectionResponse' securitySchemes: azureaadv2: type: oauth2 flows: authorizationCode: authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token scopes: {}