# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Identity.DirectoryManagement Directory Roles.directory… version: 1.0.0 extends: openapi/azure-ad-directoryroles-directoryobject-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 24 - target: $.paths['/directoryRoles/{directoryRole-id}/members'].get update: x-apievangelist-phrasing: intent: List members of a directory role effect: read questions: - Who is assigned to the Global Administrator role in my Entra tenant? - Can I list a directory role's members using its template ID instead of its object ID? instructions: - text: List all members of directory role {role} with their full objects. slots: role: path.directoryRole-id - text: Show every principal assigned to role {role}. slots: role: path.directoryRole-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/{directoryObject-id}/$ref'].delete update: x-apievangelist-phrasing: intent: Remove a member from a directory role by id effect: destructive questions: - How do I take a user out of an admin role in Entra ID? - Can I unassign one principal from a directory role by addressing it in the URL path? instructions: - text: Remove member {member} from directory role {role}. slots: member: path.directoryObject-id role: path.directoryRole-id - text: Unassign principal {member} from role {role} using its path id. slots: member: path.directoryObject-id role: path.directoryRole-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/{directoryObject-id}/microsoft.graph.application'].get update: x-apievangelist-phrasing: intent: Get a directory role member as an application effect: read questions: - How do I read a role member cast as an application object? - Is a particular member of this directory role an app registration? instructions: - text: Get member {member} of role {role} as an application. slots: member: path.directoryObject-id role: path.directoryRole-id - text: Fetch the application details of role {role} member {member}. slots: role: path.directoryRole-id member: path.directoryObject-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/{directoryObject-id}/microsoft.graph.device'].get update: x-apievangelist-phrasing: intent: Get a directory role member as a device effect: read questions: - How do I read a directory role member cast as a device? - Is one of this role's members actually a device object? instructions: - text: Get member {member} of role {role} as a device. slots: member: path.directoryObject-id role: path.directoryRole-id - text: Fetch the device details of role {role} member {member}. slots: role: path.directoryRole-id member: path.directoryObject-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/{directoryObject-id}/microsoft.graph.group'].get update: x-apievangelist-phrasing: intent: Get a directory role member as a group effect: read questions: - How do I read a role member cast as a group, for a role-assignable group? - Is a given member of this admin role a group rather than a person? instructions: - text: Get member {member} of role {role} as a group. slots: member: path.directoryObject-id role: path.directoryRole-id - text: Fetch the group details of role {role} member {member}. slots: role: path.directoryRole-id member: path.directoryObject-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/{directoryObject-id}/microsoft.graph.orgContact'].get update: x-apievangelist-phrasing: intent: Get a directory role member as an org contact effect: read questions: - How do I read a role member cast as an organizational contact? - Is a particular member of this role an org contact? instructions: - text: Get member {member} of role {role} as an organizational contact. slots: member: path.directoryObject-id role: path.directoryRole-id - text: Fetch the org contact details of role {role} member {member}. slots: role: path.directoryRole-id member: path.directoryObject-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/{directoryObject-id}/microsoft.graph.servicePrincipal'].get update: x-apievangelist-phrasing: intent: Get a directory role member as a service principal effect: read questions: - How do I read a role member cast as a service principal? - Which enterprise app is this particular directory role member? instructions: - text: Get member {member} of role {role} as a service principal. slots: member: path.directoryObject-id role: path.directoryRole-id - text: Fetch the service principal details of role {role} member {member}. slots: role: path.directoryRole-id member: path.directoryObject-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/{directoryObject-id}/microsoft.graph.user'].get update: x-apievangelist-phrasing: intent: Get a directory role member as a user effect: read questions: - How do I read one role member's user profile directly? - Is a particular member of this admin role a user account? instructions: - text: Get member {member} of role {role} as a user. slots: member: path.directoryObject-id role: path.directoryRole-id - text: Fetch the user profile of role {role} member {member}. slots: role: path.directoryRole-id member: path.directoryObject-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/$count'].get update: x-apievangelist-phrasing: intent: Count all members of a directory role effect: read questions: - How many principals of any type hold a given directory role? - What's the total number of members across all types in an admin role? instructions: - text: Count all members of directory role {role}. slots: role: path.directoryRole-id - text: Tell me how many principals are assigned to role {role} in total. slots: role: path.directoryRole-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/$ref'].get update: x-apievangelist-phrasing: intent: List references to a directory role's members effect: read questions: - Can I get just the reference links for a role's members instead of the full objects? - Which member ids and @odata.id links does a directory role hold? instructions: - text: List the member references ($ref) of directory role {role}. slots: role: path.directoryRole-id - text: Return only the @odata.id links for members of role {role}. slots: role: path.directoryRole-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/$ref'].post update: x-apievangelist-phrasing: intent: Add a member to a directory role effect: write questions: - How do I assign a user to an Entra admin role through the Graph API? - Can I add a service principal to a directory role by its @odata.id reference? instructions: - text: Add {member_ref} as a member of directory role {role}. slots: member_ref: requestBody.@odata.id role: path.directoryRole-id - text: Assign the principal at {member_ref} to role {role}. slots: member_ref: requestBody.@odata.id role: path.directoryRole-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/$ref'].delete update: x-apievangelist-phrasing: intent: Remove a role member by reference query effect: destructive questions: - Can I remove a directory role member by passing its @id as a query parameter? - What is the collection-level way to unassign someone from a directory role? instructions: - text: Remove the member referenced by {member_ref} from role {role} via the @id query. slots: member_ref: query.@id role: path.directoryRole-id - text: Unassign {member_ref} from directory role {role} using the members $ref collection. slots: member_ref: query.@id role: path.directoryRole-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/microsoft.graph.application'].get update: x-apievangelist-phrasing: intent: List a directory role's application members effect: read questions: - Which applications hold a given directory role? - Can I filter a role's members down to app registrations only? instructions: - text: List only the application members of role {role}. slots: role: path.directoryRole-id - text: Show the apps assigned to directory role {role}. slots: role: path.directoryRole-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/microsoft.graph.application/$count'].get update: x-apievangelist-phrasing: intent: Count a directory role's application members effect: read questions: - How many applications are assigned to a directory role? - What's the number of app members in an admin role? instructions: - text: Count the application members of role {role}. slots: role: path.directoryRole-id - text: Tell me how many apps hold directory role {role}. slots: role: path.directoryRole-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/microsoft.graph.device'].get update: x-apievangelist-phrasing: intent: List a directory role's device members effect: read questions: - Which devices are members of a given directory role? - Can I narrow a role's member list to device objects? instructions: - text: List only the device members of role {role}. slots: role: path.directoryRole-id - text: Show the devices assigned to directory role {role}. slots: role: path.directoryRole-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/microsoft.graph.device/$count'].get update: x-apievangelist-phrasing: intent: Count a directory role's device members effect: read questions: - How many devices are members of a directory role? - What's the device member count for an admin role? instructions: - text: Count the device members of role {role}. slots: role: path.directoryRole-id - text: Tell me how many devices hold directory role {role}. slots: role: path.directoryRole-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/microsoft.graph.group'].get update: x-apievangelist-phrasing: intent: List a directory role's group members effect: read questions: - Which role-assignable groups are members of an admin role? - Can I see only the groups assigned to a directory role? instructions: - text: List only the group members of role {role}. slots: role: path.directoryRole-id - text: Show the groups assigned to directory role {role}. slots: role: path.directoryRole-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/microsoft.graph.group/$count'].get update: x-apievangelist-phrasing: intent: Count a directory role's group members effect: read questions: - How many groups are assigned to a directory role? - What's the group member count for an admin role? instructions: - text: Count the group members of role {role}. slots: role: path.directoryRole-id - text: Tell me how many groups hold directory role {role}. slots: role: path.directoryRole-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/microsoft.graph.orgContact'].get update: x-apievangelist-phrasing: intent: List a directory role's org contact members effect: read questions: - Which organizational contacts appear as members of a directory role? - Can I filter a role's members to org contacts only? instructions: - text: List only the org contact members of role {role}. slots: role: path.directoryRole-id - text: Show the organizational contacts in directory role {role}. slots: role: path.directoryRole-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/microsoft.graph.orgContact/$count'].get update: x-apievangelist-phrasing: intent: Count a directory role's org contact members effect: read questions: - How many org contacts are members of a directory role? - What's the organizational contact count for an admin role? instructions: - text: Count the org contact members of role {role}. slots: role: path.directoryRole-id - text: Tell me how many organizational contacts hold directory role {role}. slots: role: path.directoryRole-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/microsoft.graph.servicePrincipal'].get update: x-apievangelist-phrasing: intent: List a directory role's service principal members effect: read questions: - Which service principals have been granted a given admin role? - Can I see just the enterprise apps holding a directory role? instructions: - text: List only the service principal members of role {role}. slots: role: path.directoryRole-id - text: Show the service principals assigned to directory role {role}. slots: role: path.directoryRole-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/microsoft.graph.servicePrincipal/$count'].get update: x-apievangelist-phrasing: intent: Count a directory role's service principal members effect: read questions: - How many service principals hold a directory role? - What's the service principal member count for an admin role? instructions: - text: Count the service principal members of role {role}. slots: role: path.directoryRole-id - text: Tell me how many service principals hold directory role {role}. slots: role: path.directoryRole-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/microsoft.graph.user'].get update: x-apievangelist-phrasing: intent: List a directory role's user members effect: read questions: - Which people are Global Administrators in my tenant, excluding apps and groups? - Can I list just the user accounts assigned to a directory role? instructions: - text: List only the user members of role {role}. slots: role: path.directoryRole-id - text: Show the users assigned to directory role {role}. slots: role: path.directoryRole-id method: generated generated: '2026-10-01' - target: $.paths['/directoryRoles/{directoryRole-id}/members/microsoft.graph.user/$count'].get update: x-apievangelist-phrasing: intent: Count a directory role's user members effect: read questions: - How many users hold a particular admin role in Entra ID? - What's the user member count for a directory role? instructions: - text: Count the user members of role {role}. slots: role: path.directoryRole-id - text: Tell me how many users hold directory role {role}. slots: role: path.directoryRole-id method: generated generated: '2026-10-01'