# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Identity.SignIns Policies.cross Tenant Access Policy API version: 1.0.0 extends: openapi/azure-ad-policies-crosstenantaccesspolicy-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 30 - target: $.paths['/policies/crossTenantAccessPolicy'].get update: x-apievangelist-phrasing: intent: View the tenant's cross-tenant access policy effect: read questions: - How do I see my tenant's overall cross-tenant access policy in Microsoft Entra ID? - Which cloud endpoints are allowed in our cross-tenant access policy right now? instructions: - text: Show me the top-level cross-tenant access policy for our tenant. - text: Get the cross-tenant access policy and include only {fields}. slots: fields: query.$select method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy'].delete update: x-apievangelist-phrasing: intent: Delete the cross-tenant access policy object effect: destructive questions: - Can the whole cross-tenant access policy object be deleted from the policies root? - What happens if I remove the entire cross-tenant access policy rather than one partner? instructions: - text: Delete the entire cross-tenant access policy object from our tenant's policies. - text: Remove the whole cross-tenant access policy only if its ETag still matches {etag}. slots: etag: header.If-Match method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy'].patch update: x-apievangelist-phrasing: intent: Update the top-level cross-tenant access policy effect: write questions: - Can I change which cloud endpoints are allowed for cross-tenant collaboration? - How do I edit the overall cross-tenant access policy object itself? instructions: - text: Set the allowed cloud endpoints on our cross-tenant access policy to {endpoints}. slots: endpoints: requestBody.allowedCloudEndpoints - text: Patch the top-level cross-tenant access policy so collaboration with other clouds is limited to the ones I list. method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/default'].get update: x-apievangelist-phrasing: intent: View the default cross-tenant access settings effect: read questions: - What are the default inbound and outbound B2B settings that apply to tenants without a partner config? - Is our cross-tenant default still the service default or has it been customized? instructions: - text: Show the default cross-tenant access configuration for tenants that have no partner-specific settings. - text: Get the cross-tenant default configuration returning only {fields}. slots: fields: query.$select method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/default'].delete update: x-apievangelist-phrasing: intent: Delete the default cross-tenant configuration effect: destructive questions: - Can I delete the default configuration object under the cross-tenant access policy? - Is there a delete call for the cross-tenant default settings navigation property? instructions: - text: Delete the default configuration from our cross-tenant access policy. - text: Remove the cross-tenant default configuration if its ETag matches {etag}. slots: etag: header.If-Match method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/default'].patch update: x-apievangelist-phrasing: intent: Change default cross-tenant access settings effect: write questions: - How can I block outbound B2B collaboration by default for every external tenant? - Can I trust MFA claims from all external tenants by default? instructions: - text: Update the default B2B collaboration inbound settings to {settings}. slots: settings: requestBody.b2bCollaborationInbound - text: Change the default inbound trust for all external tenants to {trust}. slots: trust: requestBody.inboundTrust - text: Set the default tenant restrictions for cross-tenant access to {restrictions}. slots: restrictions: requestBody.tenantRestrictions method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/default/microsoft.graph.resetToSystemDefault'].post update: x-apievangelist-phrasing: intent: Reset default cross-tenant settings to system default effect: destructive questions: - How do I undo all my customizations to the default cross-tenant access settings? - Can I put the cross-tenant default configuration back to what Microsoft ships? instructions: - text: Reset our default cross-tenant access configuration back to the system default. - text: Discard every change to the cross-tenant default settings and restore the service default. method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/partners'].get update: x-apievangelist-phrasing: intent: List partner-specific cross-tenant configurations effect: read questions: - Which external tenants have their own partner configuration in our cross-tenant access policy? - Can I list partner configurations along with their user synchronization policies? instructions: - text: List every partner configuration in our cross-tenant access policy. - text: List cross-tenant partner configurations matching {filter}. slots: filter: query.$filter - text: List partner configurations and expand {relationship}. slots: relationship: query.$expand method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/partners'].post update: x-apievangelist-phrasing: intent: Add a partner tenant to cross-tenant access effect: write questions: - How do I set custom B2B settings for one specific external tenant? - Can I mark a partner tenant as a service provider when I add it? instructions: - text: Create a partner configuration for tenant {tenantId}. slots: tenantId: requestBody.tenantId - text: Add partner tenant {tenantId} with inbound trust set to {trust}. slots: tenantId: requestBody.tenantId trust: requestBody.inboundTrust method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}'].get update: x-apievangelist-phrasing: intent: Get one partner's cross-tenant configuration effect: read questions: - What cross-tenant settings have we configured for a particular partner tenant? - Does a specific partner tenant have inbound MFA trust enabled? instructions: - text: Show the partner configuration for tenant {tenantId}. slots: tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId - text: Get the inbound trust settings configured for partner tenant {tenantId}. slots: tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}'].delete update: x-apievangelist-phrasing: intent: Remove a partner's cross-tenant configuration effect: destructive questions: - How do I remove the custom settings for a partner tenant so it falls back to defaults? - Do I need to delete a partner's user sync policy before deleting the partner configuration? instructions: - text: Delete the partner configuration for tenant {tenantId}. slots: tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId - text: Remove partner tenant {tenantId} from our cross-tenant access policy. slots: tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}'].patch update: x-apievangelist-phrasing: intent: Update a partner's cross-tenant settings effect: write questions: - Can I change B2B direct connect settings for one partner tenant I already configured? - How would I turn on automatic user consent for an existing partner tenant? instructions: - text: Update B2B direct connect inbound for partner {tenantId} to {settings}. slots: tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId settings: requestBody.b2bDirectConnectInbound - text: Set automatic user consent settings for existing partner {tenantId} to {consent}. slots: tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId consent: requestBody.automaticUserConsentSettings method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/identitySynchronization'].get update: x-apievangelist-phrasing: intent: Get a partner's user synchronization policy effect: read questions: - Is user synchronization from a partner tenant into ours turned on? - What cross-tenant sync policy is set for a given partner? instructions: - text: Show the user synchronization policy for partner tenant {tenantId}. slots: tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId - text: Check whether inbound user sync is allowed from partner {tenantId}. slots: tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/identitySynchronization'].put update: x-apievangelist-phrasing: intent: Create a partner's user synchronization policy effect: write questions: - How do I allow users from a partner tenant to be synced into our directory? - Can I name the cross-tenant sync policy when I create it for a partner? instructions: - text: Create a user sync policy for partner {tenantId} with inbound sync set to {userSyncInbound}. slots: tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId userSyncInbound: requestBody.userSyncInbound - text: Set up cross-tenant user synchronization for partner {tenantId} named {name}. slots: tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId name: requestBody.displayName method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/identitySynchronization'].delete update: x-apievangelist-phrasing: intent: Delete a partner's user synchronization policy effect: destructive questions: - How do I stop syncing users in from a partner tenant? - Can I remove a partner's sync policy without deleting the partner configuration itself? instructions: - text: Delete the user synchronization policy for partner {tenantId}. slots: tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId - text: Turn off cross-tenant user sync from partner {tenantId} by removing its sync policy. slots: tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/serviceProviderConstraints'].get update: x-apievangelist-phrasing: intent: Get a partner's service provider constraints effect: read questions: - What service provider constraints apply to a partner tenant marked as a service provider? - Where can I read the service provider restrictions on a partner configuration? instructions: - text: Show the service provider constraints for partner tenant {tenantId}. slots: tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId - text: Get service provider constraints on partner {tenantId} returning only {fields}. slots: tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId fields: query.$select method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/serviceProviderConstraints'].delete update: x-apievangelist-phrasing: intent: Remove a partner's service provider constraints effect: destructive questions: - Can I clear the service provider constraints from a partner tenant configuration? - Is it possible to drop service provider restrictions for one partner? instructions: - text: Delete the service provider constraints for partner tenant {tenantId}. slots: tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId - text: Clear service provider restrictions on partner {tenantId}. slots: tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/partners/{crossTenantAccessPolicyConfigurationPartner-tenantId}/serviceProviderConstraints'].patch update: x-apievangelist-phrasing: intent: Update a partner's service provider constraints effect: write questions: - How do I modify the service provider constraints on an existing partner tenant? - Can service provider constraints be patched separately from the rest of the partner config? instructions: - text: Update the service provider constraints for partner tenant {tenantId}. slots: tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId - text: Patch the service provider constraint object on partner {tenantId}. slots: tenantId: path.crossTenantAccessPolicyConfigurationPartner-tenantId method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/partners/$count'].get update: x-apievangelist-phrasing: intent: Count partner cross-tenant configurations effect: read questions: - How many external tenants have partner-specific cross-tenant settings? - Can I count only the partner configurations matching a filter? instructions: - text: Count the partner configurations in our cross-tenant access policy. - text: Count cross-tenant partner configurations that match {filter}. slots: filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/templates'].get update: x-apievangelist-phrasing: intent: View multitenant organization policy templates effect: read questions: - What base policy templates exist for our multitenant organization settings? - Can I see both multitenant org templates in a single call? instructions: - text: Show the cross-tenant access policy templates container for our multitenant organization. - text: Get the multitenant organization templates and expand {relationship}. slots: relationship: query.$expand method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/templates'].delete update: x-apievangelist-phrasing: intent: Delete the multitenant organization templates effect: destructive questions: - Is there a way to delete the templates container under the cross-tenant access policy? - Can the multitenant organization base policy templates be removed? instructions: - text: Delete the templates container from our cross-tenant access policy. - text: Remove the multitenant organization templates container if its ETag matches {etag}. slots: etag: header.If-Match method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/templates'].patch update: x-apievangelist-phrasing: intent: Update the multitenant organization templates container effect: write questions: - Can I update both the identity sync and partner configuration templates together? - How do I patch the multitenant organization templates container as a whole? instructions: - text: Update the templates container with partner configuration template {template}. slots: template: requestBody.multiTenantOrganizationPartnerConfiguration - text: Patch the templates container setting the identity sync template to {template}. slots: template: requestBody.multiTenantOrganizationIdentitySynchronization method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationIdentitySynchronization'].get update: x-apievangelist-phrasing: intent: Get the multitenant org user sync template effect: read questions: - What user synchronization settings does our multitenant organization template apply? - Which tenants does the multitenant org identity sync template apply to? instructions: - text: Show the multitenant organization identity synchronization template. - text: Get the user sync template for our multitenant org with only {fields}. slots: fields: query.$select method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationIdentitySynchronization'].delete update: x-apievangelist-phrasing: intent: Delete the multitenant org user sync template effect: destructive questions: - Can I delete the identity synchronization template for our multitenant organization? - Is the multitenant org user sync template something I can remove outright? instructions: - text: Delete the multitenant organization identity synchronization template. - text: Remove the multitenant org user sync template if its ETag matches {etag}. slots: etag: header.If-Match method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationIdentitySynchronization'].patch update: x-apievangelist-phrasing: intent: Update the multitenant org user sync template effect: write questions: - How do I enable inbound user sync in the multitenant organization template? - Can I control which tenants the multitenant org sync template is applied to? instructions: - text: Set inbound user sync in the multitenant org identity sync template to {userSyncInbound}. slots: userSyncInbound: requestBody.userSyncInbound - text: Change the application level of the multitenant org user sync template to {level}. slots: level: requestBody.templateApplicationLevel method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationIdentitySynchronization/microsoft.graph.resetToDefaultSettings'].post update: x-apievangelist-phrasing: intent: Reset the multitenant org user sync template effect: destructive questions: - How do I restore the multitenant org identity sync template to its default values? - Can I undo my edits to the user synchronization template for our multitenant organization? instructions: - text: Reset the multitenant organization identity synchronization template to default settings. - text: Restore default values on our multitenant org user sync template. method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationPartnerConfiguration'].get update: x-apievangelist-phrasing: intent: Get the multitenant org partner config template effect: read questions: - What inbound and outbound partner settings does our multitenant organization template set? - Does the multitenant org partner template trust MFA from member tenants? instructions: - text: Show the multitenant organization partner configuration template. - text: Get the multitenant org partner configuration template returning {fields}. slots: fields: query.$select method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationPartnerConfiguration'].delete update: x-apievangelist-phrasing: intent: Delete the multitenant org partner config template effect: destructive questions: - Can the partner configuration template for our multitenant organization be deleted? - Is there a delete for the multitenant org inbound and outbound partner template? instructions: - text: Delete the multitenant organization partner configuration template. - text: Remove the multitenant org partner template if its ETag matches {etag}. slots: etag: header.If-Match method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationPartnerConfiguration'].patch update: x-apievangelist-phrasing: intent: Update the multitenant org partner config template effect: write questions: - How do I change B2B collaboration settings in the multitenant organization partner template? - Can I turn on automatic user consent across our multitenant organization via its template? instructions: - text: Set B2B collaboration outbound in the multitenant org partner template to {settings}. slots: settings: requestBody.b2bCollaborationOutbound - text: Update inbound trust in the multitenant org partner template to {trust}. slots: trust: requestBody.inboundTrust method: generated generated: '2026-10-01' - target: $.paths['/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationPartnerConfiguration/microsoft.graph.resetToDefaultSettings'].post update: x-apievangelist-phrasing: intent: Reset the multitenant org partner config template effect: destructive questions: - How can I put the multitenant org partner configuration template back to defaults? - Can I undo changes to the inbound and outbound template for our multitenant organization? instructions: - text: Reset the multitenant organization partner configuration template to default settings. - text: Restore default values on our multitenant org partner template. method: generated generated: '2026-10-01'