# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Azure Ad Directory.public Key Infrastructure Root API version: 1.0.0 extends: openapi/azure-ad-directory-publickeyinfrastructureroot-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 16 - target: $.paths['/directory/publicKeyInfrastructure'].get update: x-apievangelist-phrasing: intent: Get the tenant's public key infrastructure root effect: read questions: - Where does Entra ID keep the public key infrastructure used for certificate-based authentication? - Can I read the PKI container that holds my tenant's certificate-based auth configurations? instructions: - text: Get the directory's public key infrastructure root for certificate-based authentication. - text: Show the PKI container object for my tenant and its settings. method: generated generated: '2026-10-01' - target: $.paths['/directory/publicKeyInfrastructure'].delete update: x-apievangelist-phrasing: intent: Delete the tenant's public key infrastructure root effect: destructive questions: - Can I remove the entire public key infrastructure container from the directory? - What does deleting the PKI root do to certificate-based authentication in my tenant? instructions: - text: Delete the directory's public key infrastructure root object. - text: Remove the PKI container only if its ETag still matches {etag}. slots: etag: header.If-Match method: generated generated: '2026-10-01' - target: $.paths['/directory/publicKeyInfrastructure'].patch update: x-apievangelist-phrasing: intent: Update the tenant's public key infrastructure root effect: write questions: - Can I replace the set of certificate-based auth configurations on the PKI root in one update? - Which properties of the directory's PKI container can be patched? instructions: - text: Update the PKI root so its certificate-based auth configurations are {configurations}. slots: configurations: requestBody.certificateBasedAuthConfigurations - text: Patch the directory's public key infrastructure container with my changes. method: generated generated: '2026-10-01' - target: $.paths['/directory/publicKeyInfrastructure/certificateBasedAuthConfigurations'].get update: x-apievangelist-phrasing: intent: List certificate-based auth PKI configurations effect: read questions: - Which PKI configurations are set up for certificate-based authentication in my tenant? - How do I see every certificateBasedAuthPki object and its upload status? instructions: - text: List all certificate-based authentication PKI configurations in the directory. - text: Show every certificateBasedAuthPki with its display name and status. method: generated generated: '2026-10-01' - target: $.paths['/directory/publicKeyInfrastructure/certificateBasedAuthConfigurations'].post update: x-apievangelist-phrasing: intent: Create a certificate-based auth PKI configuration effect: write questions: - How do I create a new PKI object to hold certificate authorities for certificate-based sign-in? - Can I include certificate authorities when I first create a certificateBasedAuthPki? instructions: - text: Create a certificate-based auth PKI named {display_name}. slots: display_name: requestBody.displayName - text: Create PKI {display_name} with certificate authorities {authorities}. slots: display_name: requestBody.displayName authorities: requestBody.certificateAuthorities method: generated generated: '2026-10-01' - target: $.paths['/directory/publicKeyInfrastructure/certificateBasedAuthConfigurations/{certificateBasedAuthPki-id}'].get update: x-apievangelist-phrasing: intent: Get a certificate-based auth PKI configuration effect: read questions: - What status and details does one certificateBasedAuthPki object report? - Can I check whether a specific PKI configuration finished processing? instructions: - text: Get certificate-based auth PKI {pki_id} with its properties. slots: pki_id: path.certificateBasedAuthPki-id - text: Show the status and status details of PKI configuration {pki_id}. slots: pki_id: path.certificateBasedAuthPki-id method: generated generated: '2026-10-01' - target: $.paths['/directory/publicKeyInfrastructure/certificateBasedAuthConfigurations/{certificateBasedAuthPki-id}'].delete update: x-apievangelist-phrasing: intent: Delete a certificate-based auth PKI configuration effect: destructive questions: - Can I delete a PKI configuration I no longer use for certificate-based sign-in? - What happens to the certificate authorities inside a certificateBasedAuthPki when I delete it? instructions: - text: Delete certificate-based auth PKI {pki_id}. slots: pki_id: path.certificateBasedAuthPki-id - text: Remove PKI configuration {pki_id} only if its ETag is {etag}. slots: pki_id: path.certificateBasedAuthPki-id etag: header.If-Match method: generated generated: '2026-10-01' - target: $.paths['/directory/publicKeyInfrastructure/certificateBasedAuthConfigurations/{certificateBasedAuthPki-id}'].patch update: x-apievangelist-phrasing: intent: Update a certificate-based auth PKI configuration effect: write questions: - Can I rename an existing certificateBasedAuthPki object? - Which fields of a PKI configuration can I change after it is created? instructions: - text: Rename PKI configuration {pki_id} to {display_name}. slots: pki_id: path.certificateBasedAuthPki-id display_name: requestBody.displayName - text: Update the properties of certificate-based auth PKI {pki_id}. slots: pki_id: path.certificateBasedAuthPki-id method: generated generated: '2026-10-01' - target: $.paths['/directory/publicKeyInfrastructure/certificateBasedAuthConfigurations/{certificateBasedAuthPki-id}/certificateAuthorities'].get update: x-apievangelist-phrasing: intent: List certificate authorities in a PKI effect: read questions: - Which certificate authorities are trusted inside a given PKI configuration? - Can I see each CA's issuer, thumbprint and expiration date for one PKI? instructions: - text: List the certificate authorities in PKI {pki_id}. slots: pki_id: path.certificateBasedAuthPki-id - text: Show issuer, thumbprint and expiry for every CA under PKI {pki_id}. slots: pki_id: path.certificateBasedAuthPki-id method: generated generated: '2026-10-01' - target: $.paths['/directory/publicKeyInfrastructure/certificateBasedAuthConfigurations/{certificateBasedAuthPki-id}/certificateAuthorities'].post update: x-apievangelist-phrasing: intent: Add a certificate authority to a PKI effect: write questions: - How do I add a root or intermediate CA to a certificate-based auth PKI? - Can I set a certificate revocation list URL when adding a CA? instructions: - text: Add certificate authority {certificate} to PKI {pki_id}. slots: certificate: requestBody.certificate pki_id: path.certificateBasedAuthPki-id - text: Add a {ca_type} CA named {display_name} to PKI {pki_id} with CRL at {crl_url}. slots: ca_type: requestBody.certificateAuthorityType display_name: requestBody.displayName pki_id: path.certificateBasedAuthPki-id crl_url: requestBody.certificateRevocationListUrl method: generated generated: '2026-10-01' - target: $.paths['/directory/publicKeyInfrastructure/certificateBasedAuthConfigurations/{certificateBasedAuthPki-id}/certificateAuthorities/{certificateAuthorityDetail-id}'].get update: x-apievangelist-phrasing: intent: Get a certificate authority in a PKI effect: read questions: - What are the details of one certificate authority inside a PKI, such as its CRL URL? - When does a specific trusted CA in my certificate-based auth setup expire? instructions: - text: Get certificate authority {ca_id} from PKI {pki_id}. slots: ca_id: path.certificateAuthorityDetail-id pki_id: path.certificateBasedAuthPki-id - text: Show the expiration date and issuer of CA {ca_id} in PKI {pki_id}. slots: ca_id: path.certificateAuthorityDetail-id pki_id: path.certificateBasedAuthPki-id method: generated generated: '2026-10-01' - target: $.paths['/directory/publicKeyInfrastructure/certificateBasedAuthConfigurations/{certificateBasedAuthPki-id}/certificateAuthorities/{certificateAuthorityDetail-id}'].delete update: x-apievangelist-phrasing: intent: Remove a certificate authority from a PKI effect: destructive questions: - Can I stop trusting one CA by deleting it from a PKI configuration? - What happens to certificate sign-ins when I delete a certificate authority from the PKI? instructions: - text: Delete certificate authority {ca_id} from PKI {pki_id}. slots: ca_id: path.certificateAuthorityDetail-id pki_id: path.certificateBasedAuthPki-id - text: Remove CA {ca_id} from PKI {pki_id} only if its ETag is {etag}. slots: ca_id: path.certificateAuthorityDetail-id pki_id: path.certificateBasedAuthPki-id etag: header.If-Match method: generated generated: '2026-10-01' - target: $.paths['/directory/publicKeyInfrastructure/certificateBasedAuthConfigurations/{certificateBasedAuthPki-id}/certificateAuthorities/{certificateAuthorityDetail-id}'].patch update: x-apievangelist-phrasing: intent: Update a certificate authority in a PKI effect: write questions: - Can I change the revocation list URL of a CA that is already in my PKI? - Is it possible to turn issuer hints on or off for an existing certificate authority? instructions: - text: Set the CRL URL of CA {ca_id} in PKI {pki_id} to {crl_url}. slots: ca_id: path.certificateAuthorityDetail-id pki_id: path.certificateBasedAuthPki-id crl_url: requestBody.certificateRevocationListUrl - text: Set issuer hints to {hint_enabled} on CA {ca_id} in PKI {pki_id}. slots: hint_enabled: requestBody.isIssuerHintEnabled ca_id: path.certificateAuthorityDetail-id pki_id: path.certificateBasedAuthPki-id method: generated generated: '2026-10-01' - target: $.paths['/directory/publicKeyInfrastructure/certificateBasedAuthConfigurations/{certificateBasedAuthPki-id}/certificateAuthorities/$count'].get update: x-apievangelist-phrasing: intent: Count certificate authorities in a PKI effect: read questions: - How many certificate authorities does one PKI configuration contain? - Can I get just the number of CAs under a certificateBasedAuthPki? instructions: - text: Count the certificate authorities in PKI {pki_id}. slots: pki_id: path.certificateBasedAuthPki-id - text: Return only the CA total for PKI configuration {pki_id}. slots: pki_id: path.certificateBasedAuthPki-id method: generated generated: '2026-10-01' - target: $.paths['/directory/publicKeyInfrastructure/certificateBasedAuthConfigurations/{certificateBasedAuthPki-id}/microsoft.graph.upload'].post update: x-apievangelist-phrasing: intent: Upload more certificate authorities to a PKI effect: write questions: - How do I bulk-append certificate authorities to a PKI from a file I host? - Can I run two CA uploads against the same PKI at once? instructions: - text: Upload the CA file at {upload_url} with SHA-256 hash {file_hash} into PKI {pki_id}. slots: upload_url: requestBody.uploadUrl file_hash: requestBody.sha256FileHash pki_id: path.certificateBasedAuthPki-id - text: Append certificate authority details from {upload_url} to PKI {pki_id}. slots: upload_url: requestBody.uploadUrl pki_id: path.certificateBasedAuthPki-id method: generated generated: '2026-10-01' - target: $.paths['/directory/publicKeyInfrastructure/certificateBasedAuthConfigurations/$count'].get update: x-apievangelist-phrasing: intent: Count certificate-based auth PKI configurations effect: read questions: - How many PKI configurations exist for certificate-based authentication in my tenant? - Is there a quick total of certificateBasedAuthPki objects? instructions: - text: Count the certificate-based auth PKI configurations in the directory. - text: Return only the number of PKI objects under the public key infrastructure root. method: generated generated: '2026-10-01'