# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Identity.SignIns Policies.tenant App Management Policy API version: 1.0.0 extends: openapi/azure-ad-policies-tenantappmanagementpolicy-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 3 - target: $.paths['/policies/defaultAppManagementPolicy'].get update: x-apievangelist-phrasing: intent: Get the tenant default app management policy effect: read questions: - What credential restrictions does my tenant enforce on apps by default? - Is the tenant-wide app management policy currently enabled? instructions: - text: Get the tenant's default app management policy. - text: Show the application and service principal restrictions in the default policy. method: generated generated: '2026-10-01' - target: $.paths['/policies/defaultAppManagementPolicy'].delete update: x-apievangelist-phrasing: intent: Delete the tenant default app management policy effect: destructive questions: - Can I delete the tenant-wide default app management policy? - What happens to app credential restrictions if the default policy is removed? instructions: - text: Delete the tenant default app management policy. - text: Remove the default app management policy only if its ETag is {etag}. slots: etag: header.If-Match method: generated generated: '2026-10-01' - target: $.paths['/policies/defaultAppManagementPolicy'].patch update: x-apievangelist-phrasing: intent: Update the tenant default app management policy effect: write questions: - How do I turn on tenant-wide restrictions for app secrets and certificates? - Can I set different credential restrictions for applications and for service principals? instructions: - text: Set the default app management policy enabled flag to {enabled}. slots: enabled: requestBody.isEnabled - text: Apply application restrictions {app_rules} to the tenant default policy. slots: app_rules: requestBody.applicationRestrictions - text: Apply service principal restrictions {sp_rules} to the tenant default policy. slots: sp_rules: requestBody.servicePrincipalRestrictions method: generated generated: '2026-10-01'