# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Identity.SignIns Policies.authentication Strength Policy API version: 1.0.0 extends: openapi/azure-ad-policies-authenticationstrengthpolicy-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 14 - target: $.paths['/policies/authenticationStrengthPolicies'].get update: x-apievangelist-phrasing: intent: List authentication strength policies effect: read questions: - Which authentication strengths, built-in and custom, are available in my tenant? - How do I see all the MFA strength policies I can use in Conditional Access? - Can I filter authentication strength policies to only the custom ones? instructions: - text: List all authentication strength policies. - text: Show authentication strength policies matching {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/policies/authenticationStrengthPolicies'].post update: x-apievangelist-phrasing: intent: Create a custom authentication strength effect: write questions: - How do I define a custom authentication strength that only allows phishing-resistant methods? - What do I need to create my own authentication strength policy? instructions: - text: Create a custom authentication strength named {displayName} allowing {allowedCombinations}. slots: displayName: requestBody.displayName allowedCombinations: requestBody.allowedCombinations - text: Add a new authentication strength {displayName} described as {description}. slots: displayName: requestBody.displayName description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/policies/authenticationStrengthPolicies/{authenticationStrengthPolicy-id}'].get update: x-apievangelist-phrasing: intent: Get an authentication strength policy effect: read questions: - Which method combinations does a specific authentication strength allow? - How do I look up one authentication strength policy by ID? instructions: - text: Get authentication strength policy {policy}. slots: policy: path.authenticationStrengthPolicy-id - text: Show the allowed method combinations of strength {policy}. slots: policy: path.authenticationStrengthPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/policies/authenticationStrengthPolicies/{authenticationStrengthPolicy-id}'].delete update: x-apievangelist-phrasing: intent: Delete a custom authentication strength effect: destructive questions: - How do I delete a custom authentication strength I created? - Can I remove an authentication strength policy by ID? instructions: - text: Delete custom authentication strength {policy}. slots: policy: path.authenticationStrengthPolicy-id - text: Remove authentication strength policy {policy}. slots: policy: path.authenticationStrengthPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/policies/authenticationStrengthPolicies/{authenticationStrengthPolicy-id}'].patch update: x-apievangelist-phrasing: intent: Update an authentication strength's name or description effect: write questions: - How do I rename a custom authentication strength? - Can I change an authentication strength's description without touching its allowed combinations? instructions: - text: Rename authentication strength {policy} to {displayName}. slots: policy: path.authenticationStrengthPolicy-id displayName: requestBody.displayName - text: Change the description of authentication strength {policy} to {description}. slots: policy: path.authenticationStrengthPolicy-id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/policies/authenticationStrengthPolicies/{authenticationStrengthPolicy-id}/combinationConfigurations'].get update: x-apievangelist-phrasing: intent: List combination configurations of a strength effect: read questions: - What extra restrictions, like specific FIDO2 key models, are set on an authentication strength? - How do I list the combination configurations attached to a strength policy? instructions: - text: List combination configurations on authentication strength {policy}. slots: policy: path.authenticationStrengthPolicy-id - text: Show the method-specific restrictions set on strength {policy}. slots: policy: path.authenticationStrengthPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/policies/authenticationStrengthPolicies/{authenticationStrengthPolicy-id}/combinationConfigurations'].post update: x-apievangelist-phrasing: intent: Add a combination configuration to a strength effect: write questions: - How do I require a specific kind of authenticator for one combination in an authentication strength? - Can I add a combination configuration that applies to certain method combinations? instructions: - text: Add a combination configuration to strength {policy} that applies to {appliesToCombinations}. slots: policy: path.authenticationStrengthPolicy-id appliesToCombinations: requestBody.appliesToCombinations - text: Create a new method restriction on authentication strength {policy}. slots: policy: path.authenticationStrengthPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/policies/authenticationStrengthPolicies/{authenticationStrengthPolicy-id}/combinationConfigurations/{authenticationCombinationConfiguration-id}'].get update: x-apievangelist-phrasing: intent: Get one combination configuration of a strength effect: read questions: - How do I read a single combination configuration on an authentication strength? - Which combinations does a specific combination configuration apply to? instructions: - text: Get combination configuration {config} on strength {policy}. slots: config: path.authenticationCombinationConfiguration-id policy: path.authenticationStrengthPolicy-id - text: Show what restriction {config} of strength {policy} enforces. slots: config: path.authenticationCombinationConfiguration-id policy: path.authenticationStrengthPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/policies/authenticationStrengthPolicies/{authenticationStrengthPolicy-id}/combinationConfigurations/{authenticationCombinationConfiguration-id}'].delete update: x-apievangelist-phrasing: intent: Remove a combination configuration from a strength effect: destructive questions: - How do I drop a method restriction from an authentication strength? - Can I delete one combination configuration without deleting the whole strength? instructions: - text: Delete combination configuration {config} from strength {policy}. slots: config: path.authenticationCombinationConfiguration-id policy: path.authenticationStrengthPolicy-id - text: Remove restriction {config} on authentication strength {policy}. slots: config: path.authenticationCombinationConfiguration-id policy: path.authenticationStrengthPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/policies/authenticationStrengthPolicies/{authenticationStrengthPolicy-id}/combinationConfigurations/{authenticationCombinationConfiguration-id}'].patch update: x-apievangelist-phrasing: intent: Update a combination configuration on a strength effect: write questions: - How do I change which combinations an existing combination configuration applies to? - Can I edit a method restriction on an authentication strength after creating it? instructions: - text: Make combination configuration {config} on strength {policy} apply to {appliesToCombinations}. slots: config: path.authenticationCombinationConfiguration-id policy: path.authenticationStrengthPolicy-id appliesToCombinations: requestBody.appliesToCombinations - text: Update restriction {config} of authentication strength {policy}. slots: config: path.authenticationCombinationConfiguration-id policy: path.authenticationStrengthPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/policies/authenticationStrengthPolicies/{authenticationStrengthPolicy-id}/combinationConfigurations/$count'].get update: x-apievangelist-phrasing: intent: Count combination configurations on a strength effect: read questions: - How many combination configurations does an authentication strength have? - What's the number of method restrictions set on a strength policy? instructions: - text: Count combination configurations on strength {policy}. slots: policy: path.authenticationStrengthPolicy-id - text: Tell me how many method restrictions authentication strength {policy} has. slots: policy: path.authenticationStrengthPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/policies/authenticationStrengthPolicies/{authenticationStrengthPolicy-id}/microsoft.graph.updateAllowedCombinations'].post update: x-apievangelist-phrasing: intent: Change the allowed method combinations of a strength effect: write questions: - How do I change which MFA method combinations satisfy an authentication strength? - Why can't I update allowed combinations with a normal update, and what do I call instead? instructions: - text: Set the allowed combinations of authentication strength {policy} to {allowedCombinations}. slots: policy: path.authenticationStrengthPolicy-id allowedCombinations: requestBody.allowedCombinations - text: Allow only {allowedCombinations} to satisfy strength {policy}. slots: allowedCombinations: requestBody.allowedCombinations policy: path.authenticationStrengthPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/policies/authenticationStrengthPolicies/{authenticationStrengthPolicy-id}/microsoft.graph.usage()'].get update: x-apievangelist-phrasing: intent: See which Conditional Access policies use a strength effect: read questions: - Which Conditional Access policies reference a given authentication strength? - Is it safe to delete this authentication strength, or is a Conditional Access policy still using it? instructions: - text: Show the Conditional Access policies that use authentication strength {policy}. slots: policy: path.authenticationStrengthPolicy-id - text: Check where strength {policy} is referenced in Conditional Access. slots: policy: path.authenticationStrengthPolicy-id method: generated generated: '2026-10-01' - target: $.paths['/policies/authenticationStrengthPolicies/$count'].get update: x-apievangelist-phrasing: intent: Count authentication strength policies effect: read questions: - How many authentication strength policies exist in my tenant? - What's the total of built-in plus custom authentication strengths? instructions: - text: Count the authentication strength policies. - text: Tell me how many authentication strengths are defined. method: generated generated: '2026-10-01'