# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Identity.SignIns Identity Protection.risky Service… version: 1.0.0 extends: openapi/azure-ad-identityprotection-riskyserviceprincipal-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 14 - target: $.paths['/identityProtection/riskyServicePrincipals'].get update: x-apievangelist-phrasing: intent: List risky service principals effect: read questions: - Which service principals has Identity Protection flagged as risky in my tenant? - Can I filter the risky workload identities list down to only high risk level ones? instructions: - text: List every risky service principal in the tenant. - text: Show me the risky service principals whose risk is still at risk, highest risk level first. method: generated generated: '2026-10-01' - target: $.paths['/identityProtection/riskyServicePrincipals'].post update: x-apievangelist-phrasing: intent: Add a risky service principal record effect: write questions: - Is it possible to create a new riskyServicePrincipal entry directly in Identity Protection? - What fields can I set when adding a risky service principal record, like risk level and risk state? instructions: - text: Create a risky service principal record for app {appId} named {displayName}. slots: appId: requestBody.appId displayName: requestBody.displayName - text: Add a risky service principal entry with risk level {riskLevel}. slots: riskLevel: requestBody.riskLevel method: generated generated: '2026-10-01' - target: $.paths['/identityProtection/riskyServicePrincipals/{riskyServicePrincipal-id}'].get update: x-apievangelist-phrasing: intent: Get a risky service principal effect: read questions: - What is the current risk level and risk detail for one specific risky service principal? - When was the risk on this flagged workload identity last updated? instructions: - text: Get risky service principal {riskyServicePrincipal}. slots: riskyServicePrincipal: path.riskyServicePrincipal-id - text: Show the risk state and risk detail of risky service principal {riskyServicePrincipal}. slots: riskyServicePrincipal: path.riskyServicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/identityProtection/riskyServicePrincipals/{riskyServicePrincipal-id}'].delete update: x-apievangelist-phrasing: intent: Delete a risky service principal record effect: destructive questions: - Can I remove a riskyServicePrincipal object from Identity Protection entirely? - How do I delete a single risky service principal entry by its id? instructions: - text: Delete risky service principal record {riskyServicePrincipal}. slots: riskyServicePrincipal: path.riskyServicePrincipal-id - text: Remove the risky service principal entry {riskyServicePrincipal} from Identity Protection. slots: riskyServicePrincipal: path.riskyServicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/identityProtection/riskyServicePrincipals/{riskyServicePrincipal-id}'].patch update: x-apievangelist-phrasing: intent: Update a risky service principal record effect: write questions: - Can I change the risk state or risk level stored on one risky service principal record? - How do I edit the display name on an existing risky service principal entry? instructions: - text: Set the risk state of risky service principal {riskyServicePrincipal} to {riskState}. slots: riskyServicePrincipal: path.riskyServicePrincipal-id riskState: requestBody.riskState - text: Update risky service principal {riskyServicePrincipal} with risk level {riskLevel}. slots: riskyServicePrincipal: path.riskyServicePrincipal-id riskLevel: requestBody.riskLevel method: generated generated: '2026-10-01' - target: $.paths['/identityProtection/riskyServicePrincipals/{riskyServicePrincipal-id}/history'].get update: x-apievangelist-phrasing: intent: List a risky service principal's risk history effect: read questions: - What is the risk history of a flagged service principal over time? - Which risk events and activities have been recorded for this risky workload identity? instructions: - text: List the risk history of risky service principal {riskyServicePrincipal}. slots: riskyServicePrincipal: path.riskyServicePrincipal-id - text: Show every risk history item recorded for service principal {riskyServicePrincipal}. slots: riskyServicePrincipal: path.riskyServicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/identityProtection/riskyServicePrincipals/{riskyServicePrincipal-id}/history'].post update: x-apievangelist-phrasing: intent: Add a risk history item to a service principal effect: write questions: - Can I append a new entry to a risky service principal's risk history? - What goes into a risk history item, such as the activity and who initiated it? instructions: - text: Add a risk history item to risky service principal {riskyServicePrincipal} initiated by {initiatedBy}. slots: riskyServicePrincipal: path.riskyServicePrincipal-id initiatedBy: requestBody.initiatedBy - text: Record activity {activity} in the risk history of service principal {riskyServicePrincipal}. slots: activity: requestBody.activity riskyServicePrincipal: path.riskyServicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/identityProtection/riskyServicePrincipals/{riskyServicePrincipal-id}/history/{riskyServicePrincipalHistoryItem-id}'].get update: x-apievangelist-phrasing: intent: Get one risk history item for a service principal effect: read questions: - How do I read a single entry from a risky service principal's risk history? - What activity is recorded in one specific risk history item? instructions: - text: Get risk history item {historyItem} for risky service principal {riskyServicePrincipal}. slots: historyItem: path.riskyServicePrincipalHistoryItem-id riskyServicePrincipal: path.riskyServicePrincipal-id - text: Show who initiated history entry {historyItem} on service principal {riskyServicePrincipal}. slots: historyItem: path.riskyServicePrincipalHistoryItem-id riskyServicePrincipal: path.riskyServicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/identityProtection/riskyServicePrincipals/{riskyServicePrincipal-id}/history/{riskyServicePrincipalHistoryItem-id}'].delete update: x-apievangelist-phrasing: intent: Delete a risk history item effect: destructive questions: - Can I delete one entry from a risky service principal's risk history? - Is there a way to remove a wrong risk history item from a workload identity? instructions: - text: Delete risk history item {historyItem} from risky service principal {riskyServicePrincipal}. slots: historyItem: path.riskyServicePrincipalHistoryItem-id riskyServicePrincipal: path.riskyServicePrincipal-id - text: Remove history entry {historyItem} of service principal {riskyServicePrincipal}. slots: historyItem: path.riskyServicePrincipalHistoryItem-id riskyServicePrincipal: path.riskyServicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/identityProtection/riskyServicePrincipals/{riskyServicePrincipal-id}/history/{riskyServicePrincipalHistoryItem-id}'].patch update: x-apievangelist-phrasing: intent: Update a risk history item effect: write questions: - Can I edit the activity recorded on an existing risk history item? - How do I change who is listed as initiating a service principal risk history entry? instructions: - text: Update risk history item {historyItem} of service principal {riskyServicePrincipal} to activity {activity}. slots: historyItem: path.riskyServicePrincipalHistoryItem-id riskyServicePrincipal: path.riskyServicePrincipal-id activity: requestBody.activity - text: Set initiatedBy to {initiatedBy} on history entry {historyItem} for {riskyServicePrincipal}. slots: initiatedBy: requestBody.initiatedBy historyItem: path.riskyServicePrincipalHistoryItem-id riskyServicePrincipal: path.riskyServicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/identityProtection/riskyServicePrincipals/{riskyServicePrincipal-id}/history/$count'].get update: x-apievangelist-phrasing: intent: Count a service principal's risk history items effect: read questions: - How many risk history entries does one risky service principal have? - Can I get just the number of history items without listing them? instructions: - text: Count the risk history items for risky service principal {riskyServicePrincipal}. slots: riskyServicePrincipal: path.riskyServicePrincipal-id - text: Tell me how many history entries service principal {riskyServicePrincipal} has. slots: riskyServicePrincipal: path.riskyServicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/identityProtection/riskyServicePrincipals/$count'].get update: x-apievangelist-phrasing: intent: Count risky service principals effect: read questions: - How many risky service principals are there in my tenant right now? - Can I get a total count of flagged workload identities? instructions: - text: Count all risky service principals in the tenant. - text: Give me the number of service principals Identity Protection has flagged as risky. method: generated generated: '2026-10-01' - target: $.paths['/identityProtection/riskyServicePrincipals/microsoft.graph.confirmCompromised'].post update: x-apievangelist-phrasing: intent: Confirm service principals as compromised effect: write questions: - How do I mark a service principal as compromised so its risk level goes to high? - Can I confirm several risky workload identities as compromised in one call? instructions: - text: Confirm service principals {servicePrincipalIds} as compromised. slots: servicePrincipalIds: requestBody.servicePrincipalIds - text: Mark service principal {servicePrincipalIds} as compromised and raise its risk to high. slots: servicePrincipalIds: requestBody.servicePrincipalIds method: generated generated: '2026-10-01' - target: $.paths['/identityProtection/riskyServicePrincipals/microsoft.graph.dismiss'].post update: x-apievangelist-phrasing: intent: Dismiss service principal risk effect: write questions: - How do I dismiss the risk on a service principal I've checked and found safe? - Can I set the risk level of several flagged service principals back to none at once? instructions: - text: Dismiss the risk for service principals {servicePrincipalIds}. slots: servicePrincipalIds: requestBody.servicePrincipalIds - text: Clear the risk on service principal {servicePrincipalIds} as a false positive. slots: servicePrincipalIds: requestBody.servicePrincipalIds method: generated generated: '2026-10-01'