# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Identity.SignIns Identity.conditional Access Root API version: 1.0.0 extends: openapi/azure-ad-identity-conditionalaccessroot-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 64 - target: $.paths['/identity/conditionalAccess/authenticationContextClassReferences'].get update: x-apievangelist-phrasing: intent: List authentication contexts effect: read questions: - Which authentication contexts are defined for Conditional Access in my tenant? - Can I filter authentication context class references to only the ones available to apps? instructions: - text: List all authentication context class references. - text: Show authentication contexts matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationContextClassReferences'].post update: x-apievangelist-phrasing: intent: Add an authentication context effect: write questions: - How do I add a new authentication context like c5 for step-up Conditional Access? - Can I create an authentication context that is not yet available to apps? instructions: - text: Create authentication context {id} named {name}. slots: id: requestBody.id name: requestBody.displayName - text: Add authentication context {id} described as {description}, marked available. slots: id: requestBody.id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationContextClassReferences/{authenticationContextClassReference-id}'].get update: x-apievangelist-phrasing: intent: Get one authentication context effect: read questions: - What are the details of a specific authentication context class reference? - Is a given authentication context currently published to apps? instructions: - text: Show authentication context {context}. slots: context: path.authenticationContextClassReference-id - text: Get the display name and availability of authentication context {context}. slots: context: path.authenticationContextClassReference-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationContextClassReferences/{authenticationContextClassReference-id}'].delete update: x-apievangelist-phrasing: intent: Delete an authentication context effect: destructive questions: - How do I remove an authentication context that no policy uses anymore? - Why can't I delete an authentication context that a Conditional Access policy references? instructions: - text: Delete authentication context {context}. slots: context: path.authenticationContextClassReference-id - text: Remove unused authentication context {context} from Conditional Access. slots: context: path.authenticationContextClassReference-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationContextClassReferences/{authenticationContextClassReference-id}'].patch update: x-apievangelist-phrasing: intent: Create or update an authentication context effect: write questions: - Can I publish an existing authentication context so apps can start using it? - What happens if I PATCH an authentication context ID that hasn't been used yet? instructions: - text: Rename authentication context {context} to {name}. slots: context: path.authenticationContextClassReference-id name: requestBody.displayName - text: Make authentication context {context} available to apps with description {description}. slots: context: path.authenticationContextClassReference-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationContextClassReferences/$count'].get update: x-apievangelist-phrasing: intent: Count authentication contexts effect: read questions: - How many authentication context class references does my tenant have? - Can I get just the total number of authentication contexts without the list? instructions: - text: Count the authentication contexts in the tenant. - text: Count authentication contexts matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength'].get update: x-apievangelist-phrasing: intent: Get the authentication strength root effect: read questions: - What does the authentication strength container under Conditional Access hold? - Where do I start to browse authentication strength policies and method modes? instructions: - text: Show the Conditional Access authentication strength root object. - text: Get the authentication strength root with its policies expanded. method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength'].delete update: x-apievangelist-phrasing: intent: Delete the authentication strength root effect: destructive questions: - Can the whole authentication strength navigation property be deleted from Conditional Access? - What removes the authentication strength root object rather than a single policy? instructions: - text: Delete the authentication strength root from Conditional Access. - text: Remove the authentication strength container using ETag {etag}. slots: etag: header.If-Match method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength'].patch update: x-apievangelist-phrasing: intent: Update the authentication strength root effect: write questions: - How do I change the authentication strength root object as a whole? - Can I set the list of authentication combinations on the authentication strength root? instructions: - text: Update the authentication strength root combinations to {combinations}. slots: combinations: requestBody.combinations - text: Replace the method modes on the authentication strength root with {modes}. slots: modes: requestBody.authenticationMethodModes method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength/authenticationMethodModes'].get update: x-apievangelist-phrasing: intent: List supported authentication method modes effect: read questions: - Which authentication methods can be used in an authentication strength? - What method combinations like password plus SMS are supported for strengths? instructions: - text: List all supported authentication method modes. - text: Show authentication method modes matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength/authenticationMethodModes'].post update: x-apievangelist-phrasing: intent: Add an authentication method mode effect: write questions: - How do I add a new authentication method mode detail entry? - Can I register a method mode with its own display name? instructions: - text: Add authentication method mode {method} named {name}. slots: method: requestBody.authenticationMethod name: requestBody.displayName - text: Create a method mode detail for {method}. slots: method: requestBody.authenticationMethod method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength/authenticationMethodModes/{authenticationMethodModeDetail-id}'].get update: x-apievangelist-phrasing: intent: Get one authentication method mode effect: read questions: - What is the name and description of a specific authentication method mode? - Which authentication method does a particular method mode detail represent? instructions: - text: Show authentication method mode {mode}. slots: mode: path.authenticationMethodModeDetail-id - text: Get the display name of method mode {mode}. slots: mode: path.authenticationMethodModeDetail-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength/authenticationMethodModes/{authenticationMethodModeDetail-id}'].delete update: x-apievangelist-phrasing: intent: Delete an authentication method mode effect: destructive questions: - How do I remove an authentication method mode detail entry? - Can a method mode be deleted with an ETag check? instructions: - text: Delete authentication method mode {mode}. slots: mode: path.authenticationMethodModeDetail-id - text: Remove method mode {mode} only if its ETag is {etag}. slots: mode: path.authenticationMethodModeDetail-id etag: header.If-Match method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength/authenticationMethodModes/{authenticationMethodModeDetail-id}'].patch update: x-apievangelist-phrasing: intent: Update an authentication method mode effect: write questions: - How do I rename an authentication method mode detail? - Can I change which authentication method a method mode entry points to? instructions: - text: Rename authentication method mode {mode} to {name}. slots: mode: path.authenticationMethodModeDetail-id name: requestBody.displayName - text: Set method mode {mode} to authentication method {method}. slots: mode: path.authenticationMethodModeDetail-id method: requestBody.authenticationMethod method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength/authenticationMethodModes/$count'].get update: x-apievangelist-phrasing: intent: Count authentication method modes effect: read questions: - How many authentication method modes are supported in my tenant? - Can I just get the number of method modes available for strengths? instructions: - text: Count the supported authentication method modes. - text: Count method modes matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength/policies'].get update: x-apievangelist-phrasing: intent: List authentication strength policies effect: read questions: - Which authentication strength policies exist, both built-in and custom? - Can I list only the custom authentication strengths in my tenant? instructions: - text: List all authentication strength policies. - text: Show authentication strength policies matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength/policies'].post update: x-apievangelist-phrasing: intent: Create an authentication strength policy effect: write questions: - How do I create a custom authentication strength such as phishing-resistant only? - Can a new authentication strength list exactly which method combinations it allows? instructions: - text: Create authentication strength {name} allowing {combinations}. slots: name: requestBody.displayName combinations: requestBody.allowedCombinations - text: Create a custom authentication strength named {name} described as {description}. slots: name: requestBody.displayName description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}'].get update: x-apievangelist-phrasing: intent: Get one authentication strength policy effect: read questions: - What method combinations does a specific authentication strength allow? - Is a given authentication strength built-in or custom? instructions: - text: Show authentication strength policy {policy}. slots: policy: path.authenticationStrengthPolicy-id - text: Get the allowed combinations of authentication strength {policy}. slots: policy: path.authenticationStrengthPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}'].delete update: x-apievangelist-phrasing: intent: Delete an authentication strength policy effect: destructive questions: - How do I delete a custom authentication strength I no longer need? - Can I remove an authentication strength policy with an ETag precondition? instructions: - text: Delete authentication strength policy {policy}. slots: policy: path.authenticationStrengthPolicy-id - text: Remove custom authentication strength {policy} if its ETag is {etag}. slots: policy: path.authenticationStrengthPolicy-id etag: header.If-Match method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}'].patch update: x-apievangelist-phrasing: intent: Update an authentication strength policy effect: write questions: - How do I rename or re-describe a custom authentication strength? - Can I edit an authentication strength's name and description in one call? instructions: - text: Rename authentication strength {policy} to {name}. slots: policy: path.authenticationStrengthPolicy-id name: requestBody.displayName - text: Set the description of authentication strength {policy} to {description}. slots: policy: path.authenticationStrengthPolicy-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}/combinationConfigurations'].get update: x-apievangelist-phrasing: intent: List a strength's combination configurations effect: read questions: - Which FIDO2 or certificate restrictions are configured on an authentication strength? - What combination configurations apply to a specific authentication strength policy? instructions: - text: List combination configurations for authentication strength {policy}. slots: policy: path.authenticationStrengthPolicy-id - text: Show the first {top} combination configurations on strength {policy}. slots: policy: path.authenticationStrengthPolicy-id top: query.$top method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}/combinationConfigurations'].post update: x-apievangelist-phrasing: intent: Add a combination configuration to a strength effect: write questions: - How do I restrict which FIDO2 keys satisfy a custom authentication strength? - Can I add a combination configuration that applies only to certain method combinations? instructions: - text: Add a combination configuration to strength {policy} applying to {combinations}. slots: policy: path.authenticationStrengthPolicy-id combinations: requestBody.appliesToCombinations - text: Create a FIDO2 combination configuration on authentication strength {policy}. slots: policy: path.authenticationStrengthPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}/combinationConfigurations/{authenticationCombinationConfiguration-id}'].get update: x-apievangelist-phrasing: intent: Get one combination configuration effect: read questions: - What does a specific combination configuration on my authentication strength restrict? - Which method combinations does a given combination configuration apply to? instructions: - text: Show combination configuration {config} of strength {policy}. slots: config: path.authenticationCombinationConfiguration-id policy: path.authenticationStrengthPolicy-id - text: Get the combinations that configuration {config} on {policy} applies to. slots: config: path.authenticationCombinationConfiguration-id policy: path.authenticationStrengthPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}/combinationConfigurations/{authenticationCombinationConfiguration-id}'].delete update: x-apievangelist-phrasing: intent: Delete a combination configuration effect: destructive questions: - How do I remove a FIDO2 or certificate restriction from a custom authentication strength? - Can combination configurations be deleted from built-in strengths? instructions: - text: Delete combination configuration {config} from strength {policy}. slots: config: path.authenticationCombinationConfiguration-id policy: path.authenticationStrengthPolicy-id - text: Remove restriction {config} on authentication strength {policy}. slots: config: path.authenticationCombinationConfiguration-id policy: path.authenticationStrengthPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}/combinationConfigurations/{authenticationCombinationConfiguration-id}'].patch update: x-apievangelist-phrasing: intent: Update a combination configuration effect: write questions: - How do I change which combinations a strength's combination configuration covers? - Can I edit an existing FIDO2 restriction on an authentication strength? instructions: - text: Update configuration {config} on strength {policy} to apply to {combinations}. slots: config: path.authenticationCombinationConfiguration-id policy: path.authenticationStrengthPolicy-id combinations: requestBody.appliesToCombinations - text: Edit combination configuration {config} of authentication strength {policy}. slots: config: path.authenticationCombinationConfiguration-id policy: path.authenticationStrengthPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}/combinationConfigurations/$count'].get update: x-apievangelist-phrasing: intent: Count a strength's combination configurations effect: read questions: - How many combination configurations are set on a given authentication strength? - Does a particular authentication strength have any combination configurations at all? instructions: - text: Count combination configurations on authentication strength {policy}. slots: policy: path.authenticationStrengthPolicy-id - text: Tell me how many restrictions strength {policy} carries. slots: policy: path.authenticationStrengthPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}/microsoft.graph.updateAllowedCombinations'].post update: x-apievangelist-phrasing: intent: Change a strength's allowed method combinations effect: write questions: - How do I change only the allowed method combinations on an authentication strength? - Is there a dedicated action for updating allowedCombinations rather than a full policy update? instructions: - text: Set the allowed combinations of strength {policy} to {combinations}. slots: policy: path.authenticationStrengthPolicy-id combinations: requestBody.allowedCombinations - text: Replace the permitted MFA combinations on authentication strength {policy} with {combinations}. slots: policy: path.authenticationStrengthPolicy-id combinations: requestBody.allowedCombinations method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}/microsoft.graph.usage()'].get update: x-apievangelist-phrasing: intent: See which CA policies use an auth strength effect: read questions: - Which Conditional Access policies reference a given authentication strength? - Are any MFA-requiring policies using this authentication strength before I change it? instructions: - text: Show Conditional Access policies that use authentication strength {policy}. slots: policy: path.authenticationStrengthPolicy-id - text: Check the usage of strength {policy} split by MFA and non-MFA policies. slots: policy: path.authenticationStrengthPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/authenticationStrength/policies/$count'].get update: x-apievangelist-phrasing: intent: Count authentication strength policies effect: read questions: - How many authentication strength policies does my tenant have? - Can I count just the custom authentication strengths? instructions: - text: Count all authentication strength policies. - text: Count authentication strengths matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/deletedItems'].get update: x-apievangelist-phrasing: intent: Get the Conditional Access deleted items effect: read questions: - Where can I see Conditional Access policies and named locations that were deleted? - What is in the Conditional Access recycle bin container? instructions: - text: Show the Conditional Access deleted items container. - text: Get Conditional Access deleted items with deleted policies expanded. method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/deletedItems'].delete update: x-apievangelist-phrasing: intent: Delete the CA deleted items container effect: destructive questions: - Can I delete the whole Conditional Access deleted items container? - What removes the deletedItems navigation property from Conditional Access? instructions: - text: Delete the Conditional Access deleted items container. - text: Remove the CA deleted items object using ETag {etag}. slots: etag: header.If-Match method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/deletedItems'].patch update: x-apievangelist-phrasing: intent: Update the CA deleted items container effect: write questions: - Can I modify the Conditional Access deleted items container object directly? - How do I set the deleted policies collection on the deleted items container? instructions: - text: Update the Conditional Access deleted items container with policies {policies}. slots: policies: requestBody.policies - text: Set the deleted named locations on the CA deleted items container to {locations}. slots: locations: requestBody.namedLocations method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/deletedItems/namedLocations'].get update: x-apievangelist-phrasing: intent: List deleted named locations effect: read questions: - Which named locations have been deleted from Conditional Access recently? - Can I find a deleted IP range named location before restoring it? instructions: - text: List deleted named locations. - text: Show deleted named locations matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/deletedItems/namedLocations'].post update: x-apievangelist-phrasing: intent: Add a named location to deleted items effect: write questions: - Can I create an entry directly in the deleted named locations collection? - Is it possible to post a named location into Conditional Access deleted items? instructions: - text: Add named location {name} to the deleted named locations collection. slots: name: requestBody.displayName - text: Create a deleted named location record called {name}. slots: name: requestBody.displayName method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/deletedItems/namedLocations/{namedLocation-id}'].get update: x-apievangelist-phrasing: intent: Get one deleted named location effect: read questions: - When was a specific named location deleted? - What were the details of a named location that's now in deleted items? instructions: - text: Show deleted named location {location}. slots: location: path.namedLocation-id - text: Get the deletion time of named location {location} in deleted items. slots: location: path.namedLocation-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/deletedItems/namedLocations/{namedLocation-id}'].delete update: x-apievangelist-phrasing: intent: Permanently delete a deleted named location effect: destructive questions: - How do I permanently purge a named location from Conditional Access deleted items? - Can I hard-delete a soft-deleted named location so it can't be restored? instructions: - text: Permanently delete named location {location} from deleted items. slots: location: path.namedLocation-id - text: Purge deleted named location {location}. slots: location: path.namedLocation-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/deletedItems/namedLocations/{namedLocation-id}'].patch update: x-apievangelist-phrasing: intent: Update a deleted named location effect: write questions: - Can I edit a named location while it is still in deleted items? - How do I change the display name of a soft-deleted named location? instructions: - text: Rename deleted named location {location} to {name}. slots: location: path.namedLocation-id name: requestBody.displayName - text: Update the deleted named location record {location}. slots: location: path.namedLocation-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/deletedItems/namedLocations/{namedLocation-id}/microsoft.graph.restore'].post update: x-apievangelist-phrasing: intent: Restore a named location from deleted items effect: write questions: - How do I bring back a named location from the Conditional Access deleted items? - Can I undo the deletion of a country or IP named location? instructions: - text: Restore named location {location} from deleted items. slots: location: path.namedLocation-id - text: Recover soft-deleted named location {location} via the deleted items path. slots: location: path.namedLocation-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/deletedItems/namedLocations/$count'].get update: x-apievangelist-phrasing: intent: Count deleted named locations effect: read questions: - How many named locations are sitting in Conditional Access deleted items? - Are there any deleted named locations I could still restore? instructions: - text: Count deleted named locations. - text: Count deleted named locations matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/deletedItems/policies'].get update: x-apievangelist-phrasing: intent: List deleted Conditional Access policies effect: read questions: - Which Conditional Access policies were deleted and can still be recovered? - Can I search the deleted CA policies by display name? instructions: - text: List deleted Conditional Access policies. - text: Show deleted CA policies matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/deletedItems/policies'].post update: x-apievangelist-phrasing: intent: Add a policy to CA deleted items effect: write questions: - Can I post a Conditional Access policy directly into the deleted policies collection? - Is creating a record under deleted policies supported? instructions: - text: Add policy {name} to the deleted Conditional Access policies collection. slots: name: requestBody.displayName - text: Create a deleted CA policy record named {name} in state {state}. slots: name: requestBody.displayName state: requestBody.state method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/deletedItems/policies/{conditionalAccessPolicy-id}'].get update: x-apievangelist-phrasing: intent: Get one deleted Conditional Access policy effect: read questions: - What conditions and grant controls did a deleted Conditional Access policy have? - When was a particular CA policy deleted? instructions: - text: Show deleted Conditional Access policy {policy}. slots: policy: path.conditionalAccessPolicy-id - text: Get the conditions of deleted CA policy {policy}. slots: policy: path.conditionalAccessPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/deletedItems/policies/{conditionalAccessPolicy-id}'].delete update: x-apievangelist-phrasing: intent: Permanently delete a deleted CA policy effect: destructive questions: - How do I permanently purge a Conditional Access policy from deleted items? - Can I hard-delete a soft-deleted CA policy so nobody restores it? instructions: - text: Permanently delete CA policy {policy} from deleted items. slots: policy: path.conditionalAccessPolicy-id - text: Purge deleted Conditional Access policy {policy}. slots: policy: path.conditionalAccessPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/deletedItems/policies/{conditionalAccessPolicy-id}'].patch update: x-apievangelist-phrasing: intent: Update a deleted CA policy effect: write questions: - Can I edit a Conditional Access policy while it is still in deleted items? - How do I change the state of a soft-deleted CA policy record? instructions: - text: Rename deleted CA policy {policy} to {name}. slots: policy: path.conditionalAccessPolicy-id name: requestBody.displayName - text: Set the state of deleted Conditional Access policy {policy} to {state}. slots: policy: path.conditionalAccessPolicy-id state: requestBody.state method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/deletedItems/policies/{conditionalAccessPolicy-id}/microsoft.graph.restore'].post update: x-apievangelist-phrasing: intent: Restore a CA policy from deleted items effect: write questions: - How do I recover a Conditional Access policy someone deleted by mistake? - Can a deleted CA policy be restored through the deleted items collection? instructions: - text: Restore Conditional Access policy {policy} from deleted items. slots: policy: path.conditionalAccessPolicy-id - text: Undelete CA policy {policy} via the deleted items path. slots: policy: path.conditionalAccessPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/deletedItems/policies/$count'].get update: x-apievangelist-phrasing: intent: Count deleted CA policies effect: read questions: - How many Conditional Access policies are in deleted items right now? - Is anything in the deleted CA policies collection? instructions: - text: Count deleted Conditional Access policies. - text: Count deleted CA policies matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/microsoft.graph.evaluate'].post update: x-apievangelist-phrasing: intent: Evaluate which CA policies apply to a sign-in effect: read questions: - Which Conditional Access policies would apply if a given user signed in to an app? - Can I simulate a sign-in to test my Conditional Access setup, like the What If tool? - Can the evaluation return only the policies that would actually apply? instructions: - text: Evaluate Conditional Access for sign-in identity {identity} into {context}. slots: identity: requestBody.signInIdentity context: requestBody.signInContext - text: Simulate a sign-in for {identity} under conditions {conditions}, applied policies only. slots: identity: requestBody.signInIdentity conditions: requestBody.signInConditions method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/namedLocations'].get update: x-apievangelist-phrasing: intent: List named locations effect: read questions: - Which trusted IP ranges and countries are defined as named locations? - Can I filter named locations to just the IP-based ones? instructions: - text: List all Conditional Access named locations. - text: Show named locations matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/namedLocations'].post update: x-apievangelist-phrasing: intent: Create a named location effect: write questions: - How do I define a trusted office IP range for Conditional Access? - Can I create a country-based named location to block sign-ins from certain regions? instructions: - text: Create a named location called {name}. slots: name: requestBody.displayName - text: Add a new IP or country named location {name} for Conditional Access. slots: name: requestBody.displayName method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/namedLocations/{namedLocation-id}'].get update: x-apievangelist-phrasing: intent: Get a named location effect: read questions: - What countries or IP ranges does a specific named location cover? - When was a particular named location last modified? instructions: - text: Show named location {location}. slots: location: path.namedLocation-id - text: Get the countries included in named location {location}. slots: location: path.namedLocation-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/namedLocations/{namedLocation-id}'].delete update: x-apievangelist-phrasing: intent: Delete a named location effect: destructive questions: - How do I delete a named location that's no longer used by any policy? - What happens to a named location after I delete it from Conditional Access? instructions: - text: Delete named location {location}. slots: location: path.namedLocation-id - text: Remove Conditional Access named location {location} if its ETag is {etag}. slots: location: path.namedLocation-id etag: header.If-Match method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/namedLocations/{namedLocation-id}'].patch update: x-apievangelist-phrasing: intent: Update a named location effect: write questions: - How do I rename an existing active named location? - Can I update a country named location that policies already reference? instructions: - text: Rename named location {location} to {name}. slots: location: path.namedLocation-id name: requestBody.displayName - text: Update active named location {location}. slots: location: path.namedLocation-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/namedLocations/{namedLocation-id}/microsoft.graph.restore'].post update: x-apievangelist-phrasing: intent: Restore a named location effect: write questions: - Is there a restore action on the named locations collection itself? - Can I call restore directly on a named location by its ID? instructions: - text: Run the restore action on named location {location}. slots: location: path.namedLocation-id - text: Invoke restore for named location {location} through the named locations path. slots: location: path.namedLocation-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/namedLocations/$count'].get update: x-apievangelist-phrasing: intent: Count named locations effect: read questions: - How many named locations are configured in my tenant? - Can I get only the number of active named locations? instructions: - text: Count the active named locations. - text: Count named locations matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/policies'].get update: x-apievangelist-phrasing: intent: List Conditional Access policies effect: read questions: - Which Conditional Access policies are configured in my Entra ID tenant? - Can I list only the CA policies that are enabled or in report-only mode? instructions: - text: List all Conditional Access policies. - text: Show Conditional Access policies matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/policies'].post update: x-apievangelist-phrasing: intent: Create a Conditional Access policy effect: write questions: - How do I create a Conditional Access policy that requires MFA for admins? - Can I create a new CA policy in report-only state first? - What conditions and grant controls can a new Conditional Access policy set? instructions: - text: Create Conditional Access policy {name} with conditions {conditions} and grant controls {grant}. slots: name: requestBody.displayName conditions: requestBody.conditions grant: requestBody.grantControls - text: Create CA policy {name} in state {state}. slots: name: requestBody.displayName state: requestBody.state method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/policies/{conditionalAccessPolicy-id}'].get update: x-apievangelist-phrasing: intent: Get a Conditional Access policy effect: read questions: - What conditions, grant controls and session controls does a specific CA policy have? - Is a particular Conditional Access policy enabled right now? instructions: - text: Show Conditional Access policy {policy}. slots: policy: path.conditionalAccessPolicy-id - text: Get the grant controls of active CA policy {policy}. slots: policy: path.conditionalAccessPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/policies/{conditionalAccessPolicy-id}'].delete update: x-apievangelist-phrasing: intent: Delete a Conditional Access policy effect: destructive questions: - How do I delete a Conditional Access policy I no longer need? - Can a deleted CA policy be recovered later? instructions: - text: Delete Conditional Access policy {policy}. slots: policy: path.conditionalAccessPolicy-id - text: Remove active CA policy {policy} if its ETag is {etag}. slots: policy: path.conditionalAccessPolicy-id etag: header.If-Match method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/policies/{conditionalAccessPolicy-id}'].patch update: x-apievangelist-phrasing: intent: Update a Conditional Access policy effect: write questions: - How do I switch a Conditional Access policy from report-only to enabled? - Can I change the session controls on an existing CA policy? instructions: - text: Set the state of CA policy {policy} to {state}. slots: policy: path.conditionalAccessPolicy-id state: requestBody.state - text: Update conditions on Conditional Access policy {policy} to {conditions}. slots: policy: path.conditionalAccessPolicy-id conditions: requestBody.conditions method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/policies/{conditionalAccessPolicy-id}/microsoft.graph.restore'].post update: x-apievangelist-phrasing: intent: Restore a Conditional Access policy effect: write questions: - Is there a restore action on the active Conditional Access policies path? - Can I call restore on a CA policy directly by its ID? instructions: - text: Run the restore action on Conditional Access policy {policy}. slots: policy: path.conditionalAccessPolicy-id - text: Invoke restore for CA policy {policy} through the policies path. slots: policy: path.conditionalAccessPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/policies/$count'].get update: x-apievangelist-phrasing: intent: Count Conditional Access policies effect: read questions: - How many Conditional Access policies does my tenant have? - Can I count just the CA policies that are enabled? instructions: - text: Count the Conditional Access policies. - text: Count CA policies matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/templates'].get update: x-apievangelist-phrasing: intent: List Conditional Access templates effect: read questions: - What Conditional Access policy templates does Microsoft provide? - Can I browse CA templates by scenario, like securing admins or remote work? instructions: - text: List all Conditional Access templates. - text: Show CA templates matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/templates/{conditionalAccessTemplate-id}'].get update: x-apievangelist-phrasing: intent: Get a Conditional Access template effect: read questions: - What settings does a specific Conditional Access template contain? - Which scenarios is a given CA template meant for? instructions: - text: Show Conditional Access template {template}. slots: template: path.conditionalAccessTemplate-id - text: Get the policy details of CA template {template}. slots: template: path.conditionalAccessTemplate-id method: generated generated: '2026-10-01' - target: $.paths['/identity/conditionalAccess/templates/$count'].get update: x-apievangelist-phrasing: intent: Count Conditional Access templates effect: read questions: - How many Conditional Access templates are available? - Can I get just the number of CA templates? instructions: - text: Count the Conditional Access templates. - text: Count CA templates matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01'