# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Identity.SignIns Policies.authorization Policy API version: 1.0.0 extends: openapi/azure-ad-policies-authorizationpolicy-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 3 - target: $.paths['/policies/authorizationPolicy'].get update: x-apievangelist-phrasing: intent: Get the tenant authorization policy effect: read questions: - Who is allowed to invite guests into my Entra tenant? - Can users in my tenant use self-service password reset, according to the authorization policy? instructions: - text: Get the tenant's authorization policy. - text: Show the default user role permissions and guest invite settings. method: generated generated: '2026-10-01' - target: $.paths['/policies/authorizationPolicy'].delete update: x-apievangelist-phrasing: intent: Delete the authorization policy effect: destructive questions: - Is there a way to delete the authorization policy navigation property? - What happens when I remove the tenant authorization policy object? instructions: - text: Delete the tenant authorization policy. - text: Remove the authorization policy object from policies. method: generated generated: '2026-10-01' - target: $.paths['/policies/authorizationPolicy'].patch update: x-apievangelist-phrasing: intent: Update the tenant authorization policy effect: write questions: - How do I restrict guest invitations to admins only? - Can I block the MSOnline PowerShell module for my tenant? - Which setting lets email-verified users join my organization? instructions: - text: Set who can invite guests to {allowInvitesFrom}. slots: allowInvitesFrom: requestBody.allowInvitesFrom - text: Set blockMsolPowerShell to {block} in the authorization policy. slots: block: requestBody.blockMsolPowerShell - text: Change the guest user role to {roleId}. slots: roleId: requestBody.guestUserRoleId method: generated generated: '2026-10-01'