# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Applications Service Principals.directory Object API version: 1.0.0 extends: openapi/azure-ad-serviceprincipals-directoryobject-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 66 - target: $.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects'].get update: x-apievangelist-phrasing: intent: List objects a service principal created effect: read questions: - Which directory objects were created by a particular service principal? - Can I see everything an app's service principal has created in my tenant? instructions: - text: List all directory objects created by service principal {sp}. slots: sp: path.servicePrincipal-id - text: Show the first {top} objects that service principal {sp} created. slots: top: query.$top sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/{directoryObject-id}'].get update: x-apievangelist-phrasing: intent: Get one object a service principal created effect: read questions: - What are the details of a single object that a service principal created? - Can I look up one specific created object by its id under its creating service principal? instructions: - text: Get created object {object} from service principal {sp}. slots: object: path.directoryObject-id sp: path.servicePrincipal-id - text: Show me the directory object {object} that {sp} created. slots: object: path.directoryObject-id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/{directoryObject-id}/microsoft.graph.servicePrincipal'].get update: x-apievangelist-phrasing: intent: Get a created object typed as a service principal effect: read questions: - Can I read a created object with its service principal properties rather than generic directory fields? - Is the object a service principal created itself a service principal, and what are its app details? instructions: - text: Get created object {object} of service principal {sp}, cast as a service principal. slots: object: path.directoryObject-id sp: path.servicePrincipal-id - text: Return created item {object} under {sp} with its full service principal fields. slots: object: path.directoryObject-id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/$count'].get update: x-apievangelist-phrasing: intent: Count objects a service principal created effect: read questions: - How many directory objects has a given service principal created? - Is there a quick way to get just the total of created objects for an app without listing them? instructions: - text: Count the directory objects created by service principal {sp}. slots: sp: path.servicePrincipal-id - text: Give me the number of created objects for {sp}. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/microsoft.graph.servicePrincipal'].get update: x-apievangelist-phrasing: intent: List service principals a service principal created effect: read questions: - Which service principals were created by another service principal? - Can I filter a service principal's created objects down to only service principals? instructions: - text: List only the service principals that {sp} created. slots: sp: path.servicePrincipal-id - text: Show created objects of {sp} that are service principals, first {top}. slots: sp: path.servicePrincipal-id top: query.$top method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/createdObjects/microsoft.graph.servicePrincipal/$count'].get update: x-apievangelist-phrasing: intent: Count service principals a service principal created effect: read questions: - How many service principals has one service principal created? - What is the total of created objects that are themselves service principals? instructions: - text: Count the service principals created by {sp}. slots: sp: path.servicePrincipal-id - text: Tell me how many of the objects {sp} created are service principals. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf'].get update: x-apievangelist-phrasing: intent: List a service principal's direct memberships effect: read questions: - Which groups and directory roles is a service principal directly a member of? - Does the memberOf list for an app include nested group memberships? instructions: - text: List the groups and roles service principal {sp} directly belongs to. slots: sp: path.servicePrincipal-id - text: Show the direct, non-transitive memberships of {sp}. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/{directoryObject-id}'].get update: x-apievangelist-phrasing: intent: Get one direct membership of a service principal effect: read questions: - Can I fetch a single group or role that a service principal is directly a member of? - What does one direct membership entry for a service principal look like? instructions: - text: Get direct membership {object} of service principal {sp}. slots: object: path.directoryObject-id sp: path.servicePrincipal-id - text: Show the group or role {object} that {sp} is directly a member of. slots: object: path.directoryObject-id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/{directoryObject-id}/microsoft.graph.administrativeUnit'].get update: x-apievangelist-phrasing: intent: Get a direct membership as an administrative unit effect: read questions: - Can I read one of a service principal's direct memberships as an administrative unit? - What are the admin unit details for a unit a service principal directly belongs to? instructions: - text: Get direct membership {unit} of {sp} as an administrative unit. slots: unit: path.directoryObject-id sp: path.servicePrincipal-id - text: Show administrative unit {unit} that service principal {sp} is directly in. slots: unit: path.directoryObject-id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/{directoryObject-id}/microsoft.graph.directoryRole'].get update: x-apievangelist-phrasing: intent: Get a direct membership as a directory role effect: read questions: - Can I read one of a service principal's direct memberships as a directory role? - Which role details come back for a role a service principal holds directly? instructions: - text: Get direct membership {role} of {sp} as a directory role. slots: role: path.directoryObject-id sp: path.servicePrincipal-id - text: Show directory role {role} that service principal {sp} directly holds. slots: role: path.directoryObject-id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/{directoryObject-id}/microsoft.graph.group'].get update: x-apievangelist-phrasing: intent: Get a direct membership as a group effect: read questions: - Can I read one of a service principal's direct memberships with its group properties? - What are the group details for a group an app is directly a member of? instructions: - text: Get direct membership {group} of {sp} as a group. slots: group: path.directoryObject-id sp: path.servicePrincipal-id - text: Show group {group} that service principal {sp} is directly a member of. slots: group: path.directoryObject-id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/$count'].get update: x-apievangelist-phrasing: intent: Count a service principal's direct memberships effect: read questions: - How many groups and roles is a service principal directly a member of? - What is the total of direct memberships for one app? instructions: - text: Count the direct memberships of service principal {sp}. slots: sp: path.servicePrincipal-id - text: Give me the number of groups and roles {sp} directly belongs to. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.administrativeUnit'].get update: x-apievangelist-phrasing: intent: List admin units a service principal is directly in effect: read questions: - Which administrative units is a service principal directly a member of? - Can I narrow a service principal's direct memberships to administrative units only? instructions: - text: List the administrative units {sp} is directly a member of. slots: sp: path.servicePrincipal-id - text: Show only admin-unit memberships held directly by service principal {sp}. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.administrativeUnit/$count'].get update: x-apievangelist-phrasing: intent: Count admin units a service principal is directly in effect: read questions: - How many administrative units does a service principal directly belong to? - What is the count of direct admin-unit memberships for an app? instructions: - text: Count the administrative units {sp} is directly in. slots: sp: path.servicePrincipal-id - text: Tell me how many admin units service principal {sp} directly belongs to. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.directoryRole'].get update: x-apievangelist-phrasing: intent: List directory roles a service principal holds directly effect: read questions: - Which directory roles has a service principal been directly assigned? - Can I list only the roles, not groups, that an app is directly a member of? instructions: - text: List the directory roles service principal {sp} holds directly. slots: sp: path.servicePrincipal-id - text: Show only direct directory-role memberships for {sp}. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.directoryRole/$count'].get update: x-apievangelist-phrasing: intent: Count directory roles a service principal holds directly effect: read questions: - How many directory roles does a service principal directly hold? - What is the number of direct role memberships for an app? instructions: - text: Count the directory roles {sp} directly holds. slots: sp: path.servicePrincipal-id - text: Tell me how many roles service principal {sp} is directly assigned. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.group'].get update: x-apievangelist-phrasing: intent: List groups a service principal is directly in effect: read questions: - Which groups is a service principal directly a member of? - Can I see only the direct group memberships of an app, without roles? instructions: - text: List the groups service principal {sp} is directly a member of. slots: sp: path.servicePrincipal-id - text: Show only direct group memberships for {sp}. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/memberOf/microsoft.graph.group/$count'].get update: x-apievangelist-phrasing: intent: Count groups a service principal is directly in effect: read questions: - How many groups is a service principal directly a member of? - What is the direct group membership total for an app? instructions: - text: Count the groups {sp} is directly in. slots: sp: path.servicePrincipal-id - text: Tell me how many groups service principal {sp} directly belongs to. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects'].get update: x-apievangelist-phrasing: intent: List objects a service principal owns effect: read questions: - Which applications, groups or other objects does a service principal own? - Can I get every directory object owned by an app's service principal? instructions: - text: List all objects owned by service principal {sp}. slots: sp: path.servicePrincipal-id - text: Show the first {top} directory objects that {sp} owns. slots: top: query.$top sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/{directoryObject-id}'].get update: x-apievangelist-phrasing: intent: Get one object a service principal owns effect: read questions: - Can I fetch a single owned object by id for a service principal? - What are the generic directory details of one object an app owns? instructions: - text: Get owned object {object} of service principal {sp}. slots: object: path.directoryObject-id sp: path.servicePrincipal-id - text: Show the directory object {object} that {sp} owns. slots: object: path.directoryObject-id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/{directoryObject-id}/microsoft.graph.application'].get update: x-apievangelist-phrasing: intent: Get an owned object as an application effect: read questions: - Can I read an object a service principal owns with its application registration properties? - What app registration details come back for an application owned by a service principal? instructions: - text: Get owned object {app} of {sp} as an application. slots: app: path.directoryObject-id sp: path.servicePrincipal-id - text: Show application {app} that service principal {sp} owns. slots: app: path.directoryObject-id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/{directoryObject-id}/microsoft.graph.appRoleAssignment'].get update: x-apievangelist-phrasing: intent: Get an owned object as an app role assignment effect: read questions: - Can I read an owned object of a service principal as an app role assignment? - Which role and principal does an app role assignment owned by a service principal point to? instructions: - text: Get owned object {assignment} of {sp} as an app role assignment. slots: assignment: path.directoryObject-id sp: path.servicePrincipal-id - text: Show app role assignment {assignment} owned by service principal {sp}. slots: assignment: path.directoryObject-id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/{directoryObject-id}/microsoft.graph.endpoint'].get update: x-apievangelist-phrasing: intent: Get an owned object as an endpoint effect: read questions: - Can I read an owned object of a service principal as an endpoint? - What endpoint details are returned for one endpoint a service principal owns? instructions: - text: Get owned object {endpoint} of {sp} as an endpoint. slots: endpoint: path.directoryObject-id sp: path.servicePrincipal-id - text: Show endpoint {endpoint} owned by service principal {sp}. slots: endpoint: path.directoryObject-id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/{directoryObject-id}/microsoft.graph.group'].get update: x-apievangelist-phrasing: intent: Get an owned object as a group effect: read questions: - Can I read a group that a service principal owns with its group properties? - What group details come back for one group owned by an app? instructions: - text: Get owned object {group} of {sp} as a group. slots: group: path.directoryObject-id sp: path.servicePrincipal-id - text: Show group {group} that service principal {sp} owns. slots: group: path.directoryObject-id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/{directoryObject-id}/microsoft.graph.servicePrincipal'].get update: x-apievangelist-phrasing: intent: Get an owned object as a service principal effect: read questions: - Can I read another service principal that this service principal owns? - What app details come back for a service principal owned by a different one? instructions: - text: Get owned object {owned} of {sp} as a service principal. slots: owned: path.directoryObject-id sp: path.servicePrincipal-id - text: Show service principal {owned} that is owned by service principal {sp}. slots: owned: path.directoryObject-id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/$count'].get update: x-apievangelist-phrasing: intent: Count objects a service principal owns effect: read questions: - How many directory objects does a service principal own in total? - What is the owned-object count for one app? instructions: - text: Count all objects owned by service principal {sp}. slots: sp: path.servicePrincipal-id - text: Give me the total number of owned objects for {sp}. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.application'].get update: x-apievangelist-phrasing: intent: List applications a service principal owns effect: read questions: - Which application registrations does a service principal own? - Can I narrow a service principal's owned objects to applications only? instructions: - text: List the applications owned by service principal {sp}. slots: sp: path.servicePrincipal-id - text: Show only application registrations that {sp} owns. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.application/$count'].get update: x-apievangelist-phrasing: intent: Count applications a service principal owns effect: read questions: - How many application registrations does a service principal own? - What is the number of apps owned by one service principal? instructions: - text: Count the applications owned by {sp}. slots: sp: path.servicePrincipal-id - text: Tell me how many app registrations service principal {sp} owns. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.appRoleAssignment'].get update: x-apievangelist-phrasing: intent: List app role assignments a service principal owns effect: read questions: - Which app role assignments are owned by a service principal? - Can I filter a service principal's owned objects to app role assignments? instructions: - text: List the app role assignments owned by service principal {sp}. slots: sp: path.servicePrincipal-id - text: Show only owned app role assignments for {sp}. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.appRoleAssignment/$count'].get update: x-apievangelist-phrasing: intent: Count app role assignments a service principal owns effect: read questions: - How many app role assignments does a service principal own? - What is the owned app role assignment total for an app? instructions: - text: Count the app role assignments owned by {sp}. slots: sp: path.servicePrincipal-id - text: Tell me how many app role assignments service principal {sp} owns. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.endpoint'].get update: x-apievangelist-phrasing: intent: List endpoints a service principal owns effect: read questions: - Which endpoints does a service principal own? - Can I see just the endpoint objects owned by an app's service principal? instructions: - text: List the endpoints owned by service principal {sp}. slots: sp: path.servicePrincipal-id - text: Show only owned endpoint objects for {sp}. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.endpoint/$count'].get update: x-apievangelist-phrasing: intent: Count endpoints a service principal owns effect: read questions: - How many endpoints does a service principal own? - What is the owned endpoint total for one app? instructions: - text: Count the endpoints owned by {sp}. slots: sp: path.servicePrincipal-id - text: Tell me how many endpoint objects service principal {sp} owns. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.group'].get update: x-apievangelist-phrasing: intent: List groups a service principal owns effect: read questions: - Which groups are owned by a service principal? - Can I narrow an app's owned objects to groups only? instructions: - text: List the groups owned by service principal {sp}. slots: sp: path.servicePrincipal-id - text: Show only the groups that {sp} owns. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.group/$count'].get update: x-apievangelist-phrasing: intent: Count groups a service principal owns effect: read questions: - How many groups does a service principal own? - What is the number of groups owned by one app? instructions: - text: Count the groups owned by {sp}. slots: sp: path.servicePrincipal-id - text: Tell me how many groups service principal {sp} owns. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.servicePrincipal'].get update: x-apievangelist-phrasing: intent: List service principals a service principal owns effect: read questions: - Which other service principals does this service principal own? - Can I filter owned objects to only service principals? instructions: - text: List the service principals owned by service principal {sp}. slots: sp: path.servicePrincipal-id - text: Show only owned service principal objects for {sp}. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/ownedObjects/microsoft.graph.servicePrincipal/$count'].get update: x-apievangelist-phrasing: intent: Count service principals a service principal owns effect: read questions: - How many service principals are owned by one service principal? - What is the owned service principal total for an app? instructions: - text: Count the service principals owned by {sp}. slots: sp: path.servicePrincipal-id - text: Tell me how many other service principals {sp} owns. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners'].get update: x-apievangelist-phrasing: intent: List the owners of a service principal effect: read questions: - Who are the owners allowed to modify a service principal? - Which users and service principals own an enterprise app? instructions: - text: List the owners of service principal {sp}. slots: sp: path.servicePrincipal-id - text: Show who owns {sp}, with their full directory objects. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/{directoryObject-id}/$ref'].delete update: x-apievangelist-phrasing: intent: Remove an owner from a service principal by owner id effect: destructive questions: - Can I remove a specific owner from a service principal using the owner's object id? - What is the recommended minimum number of owners to keep on a service principal? instructions: - text: Remove owner {owner} from service principal {sp}. slots: owner: path.directoryObject-id sp: path.servicePrincipal-id - text: Take object {owner} off the owners of {sp} using its id in the path. slots: owner: path.directoryObject-id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/{directoryObject-id}/microsoft.graph.appRoleAssignment'].get update: x-apievangelist-phrasing: intent: Get a service principal owner as an app role assignment effect: read questions: - Can I read an owner of a service principal as an app role assignment? - Which app role assignment details come back for that type of owner? instructions: - text: Get owner {owner} of {sp} as an app role assignment. slots: owner: path.directoryObject-id sp: path.servicePrincipal-id - text: Show the app role assignment owner {owner} on service principal {sp}. slots: owner: path.directoryObject-id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/{directoryObject-id}/microsoft.graph.endpoint'].get update: x-apievangelist-phrasing: intent: Get a service principal owner as an endpoint effect: read questions: - Can I read an owner of a service principal cast as an endpoint? - What endpoint properties does an endpoint-type owner of an app have? instructions: - text: Get owner {owner} of {sp} as an endpoint. slots: owner: path.directoryObject-id sp: path.servicePrincipal-id - text: Show the endpoint owner {owner} on service principal {sp}. slots: owner: path.directoryObject-id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/{directoryObject-id}/microsoft.graph.servicePrincipal'].get update: x-apievangelist-phrasing: intent: Get a service principal owner as a service principal effect: read questions: - Can I read an owner that is itself a service principal with its app properties? - Which service principal owns this enterprise app, and what are its details? instructions: - text: Get owner {owner} of {sp} as a service principal. slots: owner: path.directoryObject-id sp: path.servicePrincipal-id - text: Fetch owner {owner} of {sp} with its app identity fields. slots: owner: path.directoryObject-id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/{directoryObject-id}/microsoft.graph.user'].get update: x-apievangelist-phrasing: intent: Get a service principal owner as a user effect: read questions: - Can I read a user owner of a service principal with their user profile fields? - What user details come back for a person who owns an enterprise app? instructions: - text: Get owner {owner} of {sp} as a user. slots: owner: path.directoryObject-id sp: path.servicePrincipal-id - text: Show the user profile of owner {owner} on service principal {sp}. slots: owner: path.directoryObject-id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/$count'].get update: x-apievangelist-phrasing: intent: Count the owners of a service principal effect: read questions: - How many owners does a service principal have? - Does an app have fewer than the two owners recommended as a best practice? instructions: - text: Count the owners of service principal {sp}. slots: sp: path.servicePrincipal-id - text: Tell me how many owners {sp} has. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/$ref'].get update: x-apievangelist-phrasing: intent: List owner references of a service principal effect: read questions: - Can I get just the reference links for a service principal's owners instead of full objects? - What are the @odata.id references of everyone who owns an app? instructions: - text: List owner references ($ref) for service principal {sp}. slots: sp: path.servicePrincipal-id - text: Return only the owner reference URLs of {sp}. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/$ref'].post update: x-apievangelist-phrasing: intent: Add an owner to a service principal effect: write questions: - How do I add an owner to a service principal? - Can a service principal be an owner of itself or of another service principal? instructions: - text: Add {owner} as an owner of service principal {sp}. slots: owner: requestBody.@odata.id sp: path.servicePrincipal-id - text: Make the directory object at reference {owner} an owner of {sp}. slots: owner: requestBody.@odata.id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/$ref'].delete update: x-apievangelist-phrasing: intent: Remove a service principal owner by reference URL effect: destructive questions: - Can I remove an owner from a service principal by passing the owner's reference URL as a query parameter? - Which reference form does the owner-removal call take when the owner id is not in the path? instructions: - text: Remove the owner referenced by {ref} from service principal {sp}. slots: ref: query.@id sp: path.servicePrincipal-id - text: Delete owner reference {ref} on {sp} using the @id query parameter. slots: ref: query.@id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/microsoft.graph.appRoleAssignment'].get update: x-apievangelist-phrasing: intent: List service principal owners that are app role assignments effect: read questions: - Which owners of a service principal are app role assignments? - Can I filter an app's owners to app role assignment objects? instructions: - text: List owners of {sp} that are app role assignments. slots: sp: path.servicePrincipal-id - text: Show only app role assignment owners on service principal {sp}. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/microsoft.graph.appRoleAssignment/$count'].get update: x-apievangelist-phrasing: intent: Count service principal owners that are app role assignments effect: read questions: - How many owners of a service principal are app role assignments? - What is the count of app-role-assignment owners on an app? instructions: - text: Count the app role assignment owners of {sp}. slots: sp: path.servicePrincipal-id - text: Tell me how many owners of service principal {sp} are app role assignments. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/microsoft.graph.endpoint'].get update: x-apievangelist-phrasing: intent: List service principal owners that are endpoints effect: read questions: - Which owners of a service principal are endpoint objects? - Can I narrow an app's owner list to endpoints? instructions: - text: List owners of {sp} that are endpoints. slots: sp: path.servicePrincipal-id - text: Show only endpoint-type owners on service principal {sp}. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/microsoft.graph.endpoint/$count'].get update: x-apievangelist-phrasing: intent: Count service principal owners that are endpoints effect: read questions: - How many owners of a service principal are endpoints? - What is the endpoint owner total on an app? instructions: - text: Count the endpoint owners of {sp}. slots: sp: path.servicePrincipal-id - text: Tell me how many owners of service principal {sp} are endpoints. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/microsoft.graph.servicePrincipal'].get update: x-apievangelist-phrasing: intent: List service principal owners that are service principals effect: read questions: - Which service principals are owners of this service principal? - Can I see only the app identities, not people, that own an enterprise app? instructions: - text: List owners of {sp} that are service principals. slots: sp: path.servicePrincipal-id - text: Show only service principal owners on {sp}. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/microsoft.graph.servicePrincipal/$count'].get update: x-apievangelist-phrasing: intent: Count service principal owners that are service principals effect: read questions: - How many owners of a service principal are other service principals? - What is the count of app identities that own this app? instructions: - text: Count only the app-identity owners, not users, of {sp}. slots: sp: path.servicePrincipal-id - text: Tell me how many owners of {sp} are service principals. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/microsoft.graph.user'].get update: x-apievangelist-phrasing: intent: List user owners of a service principal effect: read questions: - Which people own a given service principal? - Can I list only the user accounts among an enterprise app's owners? instructions: - text: List the users who own service principal {sp}. slots: sp: path.servicePrincipal-id - text: Show only user owners of {sp}. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/owners/microsoft.graph.user/$count'].get update: x-apievangelist-phrasing: intent: Count user owners of a service principal effect: read questions: - How many users own a service principal? - What is the number of people listed as owners of an app? instructions: - text: Count the user owners of {sp}. slots: sp: path.servicePrincipal-id - text: Tell me how many users own service principal {sp}. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/transitiveMemberOf'].get update: x-apievangelist-phrasing: intent: List all memberships of a service principal, nested too effect: read questions: - Which groups and roles does a service principal belong to, including through nested groups? - Can I get an app's full transitive membership rather than only direct ones? instructions: - text: List every group and role {sp} belongs to, including nested memberships. slots: sp: path.servicePrincipal-id - text: Show the transitive memberships of service principal {sp}. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/transitiveMemberOf/{directoryObject-id}'].get update: x-apievangelist-phrasing: intent: Get one transitive membership of a service principal effect: read questions: - Can I fetch a single group or role a service principal belongs to through nesting? - What does one transitive membership entry of an app contain? instructions: - text: Get transitive membership {object} of service principal {sp}. slots: object: path.directoryObject-id sp: path.servicePrincipal-id - text: Show the directly or indirectly joined group or role {object} for {sp}. slots: object: path.directoryObject-id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/transitiveMemberOf/{directoryObject-id}/microsoft.graph.administrativeUnit'].get update: x-apievangelist-phrasing: intent: Get a transitive membership as an administrative unit effect: read questions: - Can I read an administrative unit a service principal belongs to via nesting? - What admin unit details come back for an inherited membership of an app? instructions: - text: Get transitive membership {unit} of {sp} as an administrative unit. slots: unit: path.directoryObject-id sp: path.servicePrincipal-id - text: Show administrative unit {unit} that {sp} belongs to directly or through nesting. slots: unit: path.directoryObject-id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/transitiveMemberOf/{directoryObject-id}/microsoft.graph.directoryRole'].get update: x-apievangelist-phrasing: intent: Get a transitive membership as a directory role effect: read questions: - Can I read a directory role a service principal holds through group nesting? - What role details come back for an inherited role membership of an app? instructions: - text: Get transitive membership {role} of {sp} as a directory role. slots: role: path.directoryObject-id sp: path.servicePrincipal-id - text: Show directory role {role} that {sp} holds directly or through nesting. slots: role: path.directoryObject-id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/transitiveMemberOf/{directoryObject-id}/microsoft.graph.group'].get update: x-apievangelist-phrasing: intent: Get a transitive membership as a group effect: read questions: - Can I read a group a service principal belongs to through nested groups? - What group details come back for an inherited group membership of an app? instructions: - text: Get transitive membership {group} of {sp} as a group. slots: group: path.directoryObject-id sp: path.servicePrincipal-id - text: Show group {group} that {sp} is in directly or through nesting. slots: group: path.directoryObject-id sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/transitiveMemberOf/$count'].get update: x-apievangelist-phrasing: intent: Count all memberships of a service principal, nested too effect: read questions: - How many groups and roles does a service principal belong to once nested memberships are included? - What is an app's total transitive membership count? instructions: - text: Count the transitive memberships of service principal {sp}. slots: sp: path.servicePrincipal-id - text: Give me the number of groups and roles {sp} belongs to including nesting. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/transitiveMemberOf/microsoft.graph.administrativeUnit'].get update: x-apievangelist-phrasing: intent: List admin units a service principal is in, nested too effect: read questions: - Which administrative units does a service principal belong to, counting nested memberships? - Can I list an app's transitive admin-unit memberships only? instructions: - text: List administrative units {sp} belongs to, including through nesting. slots: sp: path.servicePrincipal-id - text: Show transitive admin-unit memberships for service principal {sp}. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/transitiveMemberOf/microsoft.graph.administrativeUnit/$count'].get update: x-apievangelist-phrasing: intent: Count admin units a service principal is in, nested too effect: read questions: - How many administrative units does a service principal belong to including nested ones? - What is the transitive admin-unit total for an app? instructions: - text: Count administrative units {sp} belongs to transitively. slots: sp: path.servicePrincipal-id - text: Tell me how many admin units service principal {sp} is in, nested included. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/transitiveMemberOf/microsoft.graph.directoryRole'].get update: x-apievangelist-phrasing: intent: List directory roles a service principal holds, nested too effect: read questions: - Which directory roles does a service principal effectively hold, including via group nesting? - Can I list an app's transitive directory-role memberships only? instructions: - text: List directory roles {sp} holds, including through nested groups. slots: sp: path.servicePrincipal-id - text: Show transitive directory-role memberships for service principal {sp}. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/transitiveMemberOf/microsoft.graph.directoryRole/$count'].get update: x-apievangelist-phrasing: intent: Count directory roles a service principal holds, nested too effect: read questions: - How many directory roles does a service principal hold once nesting is counted? - What is the transitive role total for an app? instructions: - text: Count directory roles {sp} holds transitively. slots: sp: path.servicePrincipal-id - text: Tell me how many roles service principal {sp} has, nested included. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/transitiveMemberOf/microsoft.graph.group'].get update: x-apievangelist-phrasing: intent: List groups a service principal is in, nested too effect: read questions: - Which groups does a service principal belong to, including groups inside groups? - Can I list an app's transitive group memberships without roles? instructions: - text: List groups {sp} belongs to, including through nested groups. slots: sp: path.servicePrincipal-id - text: Show transitive group memberships for service principal {sp}. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01' - target: $.paths['/servicePrincipals/{servicePrincipal-id}/transitiveMemberOf/microsoft.graph.group/$count'].get update: x-apievangelist-phrasing: intent: Count groups a service principal is in, nested too effect: read questions: - How many groups does a service principal belong to once nested groups are counted? - What is the transitive group total for an app? instructions: - text: Count groups {sp} belongs to transitively. slots: sp: path.servicePrincipal-id - text: Tell me how many groups service principal {sp} is in, nested included. slots: sp: path.servicePrincipal-id method: generated generated: '2026-10-01'