# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Identity.SignIns Users.authentication API version: 1.0.0 extends: openapi/azure-ad-users-authentication-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 68 - target: $.paths['/users/{user-id}/authentication'].get update: x-apievangelist-phrasing: intent: Get a user's authentication root effect: read questions: - Where do I see the authentication object that holds all of a user's sign-in method collections? - Can I pull a user's authentication container in Microsoft Entra ID and expand its method collections? instructions: - text: Get the authentication object for user {user_id}. slots: user_id: path.user-id - text: Fetch user {user_id}'s authentication root and expand {expand}. slots: user_id: path.user-id expand: query.$expand method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication'].delete update: x-apievangelist-phrasing: intent: Delete a user's authentication root effect: destructive questions: - Is it possible to delete the whole authentication navigation property on a user? - What happens if I remove a user's authentication container instead of one sign-in method? instructions: - text: Delete the authentication navigation property from user {user_id}. slots: user_id: path.user-id - text: Remove user {user_id}'s entire authentication object, matching ETag {etag}. slots: user_id: path.user-id etag: header.If-Match method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication'].patch update: x-apievangelist-phrasing: intent: Update a user's authentication root effect: write questions: - Can I patch the authentication object on a user to replace several method collections at once? - Which method collections can be set when updating a user's authentication container? instructions: - text: 'Update the authentication object on user {user_id} with these phone methods: {phone_methods}.' slots: user_id: path.user-id phone_methods: requestBody.phoneMethods - text: Patch user {user_id}'s authentication container to set email methods {email_methods}. slots: user_id: path.user-id email_methods: requestBody.emailMethods method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/emailMethods'].get update: x-apievangelist-phrasing: intent: List a user's email authentication methods effect: read questions: - Which email address has a user registered for self-service password reset? - How do I list the email authentication methods on a user's account? instructions: - text: List the email authentication methods registered to user {user_id}. slots: user_id: path.user-id - text: Show me the password-reset email addresses for {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/emailMethods'].post update: x-apievangelist-phrasing: intent: Register an email authentication method effect: write questions: - How do I add a password reset email address to a user in Entra ID? - Can a user have more than one email authentication method registered? instructions: - text: Register {email} as the authentication email for user {user_id}. slots: email: requestBody.emailAddress user_id: path.user-id - text: Add a new self-service password reset email {email} to {user_id}. slots: email: requestBody.emailAddress user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/emailMethods/{emailAuthenticationMethod-id}'].get update: x-apievangelist-phrasing: intent: Get one email authentication method effect: read questions: - What email address is stored on a specific email authentication method for a user? - Can I look up a single email method by its ID on a user? instructions: - text: Get email authentication method {method_id} for user {user_id}. slots: method_id: path.emailAuthenticationMethod-id user_id: path.user-id - text: Show the details of email method {method_id} on {user_id}. slots: method_id: path.emailAuthenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/emailMethods/{emailAuthenticationMethod-id}'].delete update: x-apievangelist-phrasing: intent: Remove a user's email authentication method effect: destructive questions: - How do I remove a user's password reset email address? - Can I delete an email authentication method so the user can't reset their password by email? instructions: - text: Delete email authentication method {method_id} from user {user_id}. slots: method_id: path.emailAuthenticationMethod-id user_id: path.user-id - text: Remove the reset email method {method_id} for {user_id}. slots: method_id: path.emailAuthenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/emailMethods/{emailAuthenticationMethod-id}'].patch update: x-apievangelist-phrasing: intent: Change a user's authentication email address effect: write questions: - Can I change the email address on an existing email authentication method for a user? - Is updating a user's reset email supported as a self-service operation? instructions: - text: Change email method {method_id} on user {user_id} to {email}. slots: method_id: path.emailAuthenticationMethod-id user_id: path.user-id email: requestBody.emailAddress - text: Update the existing reset email for {user_id} (method {method_id}) to {email}. slots: user_id: path.user-id method_id: path.emailAuthenticationMethod-id email: requestBody.emailAddress method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/emailMethods/$count'].get update: x-apievangelist-phrasing: intent: Count a user's email authentication methods effect: read questions: - How many email authentication methods does a user have registered? - Does this user have any reset email registered at all? instructions: - text: Count the email authentication methods on user {user_id}. slots: user_id: path.user-id - text: Return the number of reset emails registered for {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/externalAuthenticationMethods'].get update: x-apievangelist-phrasing: intent: List a user's external MFA methods effect: read questions: - Which external MFA providers has a user registered for sign-in? - Can I see the external authentication methods linked to a user through an outside identity provider? instructions: - text: List the external authentication methods registered to user {user_id}. slots: user_id: path.user-id - text: Show all external MFA registrations for {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/externalAuthenticationMethods'].post update: x-apievangelist-phrasing: intent: Register an external MFA method for a user effect: write questions: - How do I register an external MFA method for a user using an external authentication configuration? - Can users add their own external authentication method, or must an admin do it? instructions: - text: Register an external authentication method for user {user_id} using configuration {configuration_id}. slots: user_id: path.user-id configuration_id: requestBody.configurationId - text: Add external MFA {display_name} with configuration {configuration_id} to {user_id}. slots: display_name: requestBody.displayName configuration_id: requestBody.configurationId user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/externalAuthenticationMethods/{externalAuthenticationMethod-id}'].get update: x-apievangelist-phrasing: intent: Get one external MFA method effect: read questions: - What configuration is behind a specific external authentication method on a user? - Can I fetch a single external MFA registration by its ID? instructions: - text: Get external authentication method {method_id} for user {user_id}. slots: method_id: path.externalAuthenticationMethod-id user_id: path.user-id - text: Show details of external MFA {method_id} on {user_id}. slots: method_id: path.externalAuthenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/externalAuthenticationMethods/{externalAuthenticationMethod-id}'].delete update: x-apievangelist-phrasing: intent: Remove a user's external MFA method effect: destructive questions: - How do I remove an external MFA method from a user's account? - Can a user delete their own external authentication method? instructions: - text: Delete external authentication method {method_id} from user {user_id}. slots: method_id: path.externalAuthenticationMethod-id user_id: path.user-id - text: Remove external MFA {method_id} for {user_id}. slots: method_id: path.externalAuthenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/externalAuthenticationMethods/{externalAuthenticationMethod-id}'].patch update: x-apievangelist-phrasing: intent: Update a user's external MFA method effect: write questions: - Can I rename an external authentication method already registered to a user? - Is it possible to point an existing external MFA method at a different configuration? instructions: - text: Rename external authentication method {method_id} on user {user_id} to {display_name}. slots: method_id: path.externalAuthenticationMethod-id user_id: path.user-id display_name: requestBody.displayName - text: Update external MFA {method_id} for {user_id} to use configuration {configuration_id}. slots: method_id: path.externalAuthenticationMethod-id user_id: path.user-id configuration_id: requestBody.configurationId method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/externalAuthenticationMethods/$count'].get update: x-apievangelist-phrasing: intent: Count a user's external MFA methods effect: read questions: - How many external authentication methods does a user have? - Is there any external MFA registered for this user? instructions: - text: Count the external authentication methods on user {user_id}. slots: user_id: path.user-id - text: Return the number of external MFA registrations for {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/fido2Methods'].get update: x-apievangelist-phrasing: intent: List a user's FIDO2 security keys effect: read questions: - Which FIDO2 security keys or passkeys has a user registered? - Can I list every FIDO2 key on a user's account in Entra ID? instructions: - text: List the FIDO2 security keys registered to user {user_id}. slots: user_id: path.user-id - text: Show all passkeys and FIDO2 methods for {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/fido2Methods/{fido2AuthenticationMethod-id}'].get update: x-apievangelist-phrasing: intent: Get one FIDO2 security key effect: read questions: - What are the details of a specific FIDO2 key on a user? - Can I look up a single passkey registration by its ID? instructions: - text: Get FIDO2 method {method_id} for user {user_id}. slots: method_id: path.fido2AuthenticationMethod-id user_id: path.user-id - text: Show the security key {method_id} registered to {user_id}. slots: method_id: path.fido2AuthenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/fido2Methods/{fido2AuthenticationMethod-id}'].delete update: x-apievangelist-phrasing: intent: Remove a user's FIDO2 security key effect: destructive questions: - How do I remove a lost FIDO2 security key from a user? - Can I delete a passkey registration from someone's account? instructions: - text: Delete FIDO2 security key {method_id} from user {user_id}. slots: method_id: path.fido2AuthenticationMethod-id user_id: path.user-id - text: Remove the lost passkey {method_id} for {user_id}. slots: method_id: path.fido2AuthenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/fido2Methods/$count'].get update: x-apievangelist-phrasing: intent: Count a user's FIDO2 security keys effect: read questions: - How many FIDO2 security keys does a user have? - Does this user have any passkey registered yet? instructions: - text: Count the FIDO2 methods on user {user_id}. slots: user_id: path.user-id - text: Return how many security keys {user_id} has registered. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/fido2Methods/microsoft.graph.creationOptions()'].get update: x-apievangelist-phrasing: intent: Get passkey creation options for a user effect: read questions: - How do I get the WebAuthn creation options needed to register a passkey for a user? - What challenge and credential options does Entra ID return before provisioning a passkey? instructions: - text: Get the WebAuthn creation options for registering a passkey for user {user_id}. slots: user_id: path.user-id - text: Generate passkey registration options for {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/methods'].get update: x-apievangelist-phrasing: intent: List all of a user's authentication methods effect: read questions: - What sign-in methods of every type has a user registered? - Can I get one combined list of all authentication methods for a user? instructions: - text: List every authentication method registered to user {user_id}. slots: user_id: path.user-id - text: Show all registered sign-in methods of any type for {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/methods'].post update: x-apievangelist-phrasing: intent: Add a generic authentication method entry effect: write questions: - Can I create an entry directly in a user's generic authentication methods collection? - What fields does the base authentication method accept when created? instructions: - text: Create a new entry in the generic authentication methods collection for user {user_id}. slots: user_id: path.user-id - text: Add a base authentication method to {user_id} with created time {created}. slots: user_id: path.user-id created: requestBody.createdDateTime method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/methods/{authenticationMethod-id}'].get update: x-apievangelist-phrasing: intent: Get one authentication method of any type effect: read questions: - How can I read a single authentication method by ID without knowing its type? - Which type is a given authentication method on a user? instructions: - text: Get authentication method {method_id} for user {user_id}. slots: method_id: path.authenticationMethod-id user_id: path.user-id - text: Look up generic method {method_id} on {user_id}. slots: method_id: path.authenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/methods/{authenticationMethod-id}'].patch update: x-apievangelist-phrasing: intent: Update a generic authentication method entry effect: write questions: - Can I patch an entry in a user's generic authentication methods collection? - Which properties of a base authentication method are updatable? instructions: - text: Update generic authentication method {method_id} on user {user_id}. slots: method_id: path.authenticationMethod-id user_id: path.user-id - text: Patch method {method_id} for {user_id} with created time {created}. slots: method_id: path.authenticationMethod-id user_id: path.user-id created: requestBody.createdDateTime method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/methods/{authenticationMethod-id}/microsoft.graph.resetPassword'].post update: x-apievangelist-phrasing: intent: Reset a user's password as an admin effect: write questions: - How do I reset a user's password as an administrator through Microsoft Graph? - Can I supply the new password myself or let the system generate one? instructions: - text: Reset the password for user {user_id} using password method {method_id}. slots: user_id: path.user-id method_id: path.authenticationMethod-id - text: Set a new password {new_password} for {user_id} on method {method_id}. slots: new_password: requestBody.newPassword user_id: path.user-id method_id: path.authenticationMethod-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/methods/$count'].get update: x-apievangelist-phrasing: intent: Count all of a user's authentication methods effect: read questions: - How many authentication methods of all types does a user have in total? - Does a user have more than one sign-in method registered overall? instructions: - text: Count all authentication methods registered to user {user_id}. slots: user_id: path.user-id - text: Return the total number of sign-in methods for {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/microsoftAuthenticatorMethods'].get update: x-apievangelist-phrasing: intent: List a user's Microsoft Authenticator registrations effect: read questions: - Which phones has a user set up with the Microsoft Authenticator app? - Can I list all Microsoft Authenticator registrations for a user? instructions: - text: List the Microsoft Authenticator methods registered to user {user_id}. slots: user_id: path.user-id - text: Show every Authenticator app registration for {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/microsoftAuthenticatorMethods/{microsoftAuthenticatorAuthenticationMethod-id}'].get update: x-apievangelist-phrasing: intent: Get one Microsoft Authenticator registration effect: read questions: - What are the properties of a specific Microsoft Authenticator registration on a user? - Can I read one Authenticator app method by its ID? instructions: - text: Get Microsoft Authenticator method {method_id} for user {user_id}. slots: method_id: path.microsoftAuthenticatorAuthenticationMethod-id user_id: path.user-id - text: Show Authenticator registration {method_id} on {user_id}. slots: method_id: path.microsoftAuthenticatorAuthenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/microsoftAuthenticatorMethods/{microsoftAuthenticatorAuthenticationMethod-id}'].delete update: x-apievangelist-phrasing: intent: Remove a Microsoft Authenticator registration effect: destructive questions: - How do I remove the Authenticator app from a user who lost their phone? - Can I delete a user's Microsoft Authenticator registration? instructions: - text: Delete Microsoft Authenticator method {method_id} from user {user_id}. slots: method_id: path.microsoftAuthenticatorAuthenticationMethod-id user_id: path.user-id - text: Remove Authenticator app registration {method_id} for {user_id}. slots: method_id: path.microsoftAuthenticatorAuthenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/microsoftAuthenticatorMethods/{microsoftAuthenticatorAuthenticationMethod-id}/device'].get update: x-apievangelist-phrasing: intent: Get the device behind an Authenticator registration effect: read questions: - Which device is the Microsoft Authenticator app installed on for a user? - Why is the device empty for an Authenticator registration without passwordless phone sign-in? instructions: - text: Get the device for Microsoft Authenticator method {method_id} of user {user_id}. slots: method_id: path.microsoftAuthenticatorAuthenticationMethod-id user_id: path.user-id - text: Show which phone hosts Authenticator registration {method_id} for {user_id}. slots: method_id: path.microsoftAuthenticatorAuthenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/microsoftAuthenticatorMethods/$count'].get update: x-apievangelist-phrasing: intent: Count a user's Authenticator registrations effect: read questions: - How many Microsoft Authenticator registrations does a user have? - Has this user set up the Authenticator app on any phone? instructions: - text: Count the Microsoft Authenticator methods on user {user_id}. slots: user_id: path.user-id - text: Return how many Authenticator app registrations {user_id} has. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/operations'].get update: x-apievangelist-phrasing: intent: List a user's long-running authentication operations effect: read questions: - How do I check the status of pending authentication operations like a password reset for a user? - Can I list the long-running operations under a user's authentication? instructions: - text: List the long-running authentication operations for user {user_id}. slots: user_id: path.user-id - text: Show pending authentication operations for {user_id} filtered by {filter}. slots: user_id: path.user-id filter: query.$filter method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/operations'].post update: x-apievangelist-phrasing: intent: Create a long-running authentication operation effect: write questions: - Can I add a long-running operation record under a user's authentication? - What status fields does a new authentication operation record take? instructions: - text: Create a long-running authentication operation for user {user_id} with status {status}. slots: user_id: path.user-id status: requestBody.status - text: Add an operation record to {user_id} pointing at resource location {location}. slots: user_id: path.user-id location: requestBody.resourceLocation method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/operations/{longRunningOperation-id}'].get update: x-apievangelist-phrasing: intent: Get one long-running authentication operation effect: read questions: - Did a specific password reset operation for a user finish? - Can I read the status detail of one long-running authentication operation? instructions: - text: Get long-running operation {operation_id} for user {user_id}. slots: operation_id: path.longRunningOperation-id user_id: path.user-id - text: Check the status of authentication operation {operation_id} on {user_id}. slots: operation_id: path.longRunningOperation-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/operations/{longRunningOperation-id}'].delete update: x-apievangelist-phrasing: intent: Delete a long-running authentication operation effect: destructive questions: - Can I delete an old long-running operation record from a user's authentication? - How do I clear a finished authentication operation from a user? instructions: - text: Delete long-running operation {operation_id} from user {user_id}. slots: operation_id: path.longRunningOperation-id user_id: path.user-id - text: Remove authentication operation record {operation_id} for {user_id}. slots: operation_id: path.longRunningOperation-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/operations/{longRunningOperation-id}'].patch update: x-apievangelist-phrasing: intent: Update a long-running authentication operation effect: write questions: - Can I change the status of an existing long-running authentication operation? - Which fields of an authentication operation record are patchable? instructions: - text: Set the status of operation {operation_id} on user {user_id} to {status}. slots: operation_id: path.longRunningOperation-id user_id: path.user-id status: requestBody.status - text: Update status detail of authentication operation {operation_id} for {user_id} to {detail}. slots: operation_id: path.longRunningOperation-id user_id: path.user-id detail: requestBody.statusDetail method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/operations/$count'].get update: x-apievangelist-phrasing: intent: Count a user's authentication operations effect: read questions: - How many long-running authentication operations exist for a user? - Are there any outstanding authentication operations on this account? instructions: - text: Count the long-running authentication operations for user {user_id}. slots: user_id: path.user-id - text: Return the number of authentication operations on {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/passwordMethods'].get update: x-apievangelist-phrasing: intent: List a user's password authentication methods effect: read questions: - How do I find the ID of a user's password method so I can reset it? - Does the password method list ever return the actual password? instructions: - text: List the password authentication methods for user {user_id}. slots: user_id: path.user-id - text: Show the password method records registered to {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/passwordMethods'].post update: x-apievangelist-phrasing: intent: Add a password authentication method effect: write questions: - Can I create a password authentication method on a user with an initial password? - What does a new password method record accept in the request? instructions: - text: Create a password authentication method on user {user_id} with password {password}. slots: user_id: path.user-id password: requestBody.password - text: Add a password method to {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/passwordMethods/{passwordAuthenticationMethod-id}'].get update: x-apievangelist-phrasing: intent: Get one password authentication method effect: read questions: - When was a user's password method created? - Can I read a single password method by its ID? instructions: - text: Get password method {method_id} for user {user_id}. slots: method_id: path.passwordAuthenticationMethod-id user_id: path.user-id - text: Show password method record {method_id} on {user_id}. slots: method_id: path.passwordAuthenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/passwordMethods/$count'].get update: x-apievangelist-phrasing: intent: Count a user's password methods effect: read questions: - How many password methods does a user have registered? - Is there a password method on this user at all? instructions: - text: Count the password methods on user {user_id}. slots: user_id: path.user-id - text: Return the number of password records for {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/phoneMethods'].get update: x-apievangelist-phrasing: intent: List a user's phone authentication methods effect: read questions: - Which phone numbers has a user registered for MFA or SMS sign-in? - Can I see a user's mobile, alternate mobile and office phones used for authentication? instructions: - text: List the phone authentication methods registered to user {user_id}. slots: user_id: path.user-id - text: Show all authentication phone numbers for {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/phoneMethods'].post update: x-apievangelist-phrasing: intent: Add a phone authentication method effect: write questions: - How do I add a mobile number to a user for MFA in Entra ID? - Can a user have two phones of the same type registered? instructions: - text: Add phone number {phone} as a {phone_type} authentication method for user {user_id}. slots: phone: requestBody.phoneNumber phone_type: requestBody.phoneType user_id: path.user-id - text: Register mobile number {phone} for MFA on {user_id}. slots: phone: requestBody.phoneNumber user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/phoneMethods/{phoneAuthenticationMethod-id}'].get update: x-apievangelist-phrasing: intent: Get one phone authentication method effect: read questions: - Is SMS sign-in enabled on a particular phone method for a user? - Can I read one registered phone number by its method ID? instructions: - text: Get phone method {method_id} for user {user_id}. slots: method_id: path.phoneAuthenticationMethod-id user_id: path.user-id - text: Show the phone number and SMS sign-in state of method {method_id} on {user_id}. slots: method_id: path.phoneAuthenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/phoneMethods/{phoneAuthenticationMethod-id}'].delete update: x-apievangelist-phrasing: intent: Remove a phone authentication method effect: destructive questions: - How do I remove an old phone number from a user's MFA methods? - Can I delete a registered authentication phone for someone? instructions: - text: Delete phone method {method_id} from user {user_id}. slots: method_id: path.phoneAuthenticationMethod-id user_id: path.user-id - text: Remove the authentication phone number {method_id} for {user_id}. slots: method_id: path.phoneAuthenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/phoneMethods/{phoneAuthenticationMethod-id}'].patch update: x-apievangelist-phrasing: intent: Change a user's authentication phone number effect: write questions: - Can I change the number on an existing phone authentication method? - Why can't I switch a phone's type when updating it? instructions: - text: Change phone method {method_id} on user {user_id} to number {phone}. slots: method_id: path.phoneAuthenticationMethod-id user_id: path.user-id phone: requestBody.phoneNumber - text: Update the registered number for {user_id} method {method_id} to {phone}. slots: user_id: path.user-id method_id: path.phoneAuthenticationMethod-id phone: requestBody.phoneNumber method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/phoneMethods/{phoneAuthenticationMethod-id}/microsoft.graph.disableSmsSignIn'].post update: x-apievangelist-phrasing: intent: Turn off SMS sign-in for a phone effect: write questions: - How do I stop a user from signing in with a text message code on their mobile? - Can I disable SMS sign-in without deleting the phone number? instructions: - text: Disable SMS sign-in for phone method {method_id} on user {user_id}. slots: method_id: path.phoneAuthenticationMethod-id user_id: path.user-id - text: Turn off text-message sign-in on {user_id}'s phone {method_id}. slots: user_id: path.user-id method_id: path.phoneAuthenticationMethod-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/phoneMethods/{phoneAuthenticationMethod-id}/microsoft.graph.enableSmsSignIn'].post update: x-apievangelist-phrasing: intent: Turn on SMS sign-in for a phone effect: write questions: - How can I let a user sign in with just their mobile number and an SMS code? - What conditions must be met before SMS sign-in can be enabled on a phone? instructions: - text: Enable SMS sign-in for phone method {method_id} on user {user_id}. slots: method_id: path.phoneAuthenticationMethod-id user_id: path.user-id - text: Let {user_id} sign in with an SMS code sent to mobile method {method_id}. slots: user_id: path.user-id method_id: path.phoneAuthenticationMethod-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/phoneMethods/$count'].get update: x-apievangelist-phrasing: intent: Count a user's phone authentication methods effect: read questions: - How many phone numbers does a user have registered for authentication? - Has this user registered any authentication phone? instructions: - text: Count the phone methods on user {user_id}. slots: user_id: path.user-id - text: Return the number of authentication phones for {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/platformCredentialMethods'].get update: x-apievangelist-phrasing: intent: List a user's macOS platform credentials effect: read questions: - Which Mac platform credentials has a user registered? - Can I list Platform SSO credentials a user has on macOS? instructions: - text: List the platform credential methods registered to user {user_id}. slots: user_id: path.user-id - text: Show all macOS platform credentials for {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/platformCredentialMethods/{platformCredentialAuthenticationMethod-id}'].get update: x-apievangelist-phrasing: intent: Get one macOS platform credential effect: read questions: - What are the details of a specific Mac platform credential on a user? - Can I read one platform credential registration by its ID? instructions: - text: Get platform credential method {method_id} for user {user_id}. slots: method_id: path.platformCredentialAuthenticationMethod-id user_id: path.user-id - text: Show macOS credential {method_id} registered to {user_id}. slots: method_id: path.platformCredentialAuthenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/platformCredentialMethods/{platformCredentialAuthenticationMethod-id}'].delete update: x-apievangelist-phrasing: intent: Remove a macOS platform credential effect: destructive questions: - How do I remove a platform credential from a user's retired Mac? - Can I delete a user's macOS platform credential registration? instructions: - text: Delete platform credential method {method_id} from user {user_id}. slots: method_id: path.platformCredentialAuthenticationMethod-id user_id: path.user-id - text: Remove the Mac platform credential {method_id} for {user_id}. slots: method_id: path.platformCredentialAuthenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/platformCredentialMethods/{platformCredentialAuthenticationMethod-id}/device'].get update: x-apievangelist-phrasing: intent: Get the Mac behind a platform credential effect: read questions: - Which Mac device does a user's platform credential live on? - Can I see the registered device for a platform credential method? instructions: - text: Get the device for platform credential {method_id} of user {user_id}. slots: method_id: path.platformCredentialAuthenticationMethod-id user_id: path.user-id - text: Show which Mac holds platform credential {method_id} for {user_id}. slots: method_id: path.platformCredentialAuthenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/platformCredentialMethods/$count'].get update: x-apievangelist-phrasing: intent: Count a user's macOS platform credentials effect: read questions: - How many Mac platform credentials does a user have? - Does this user have any platform credential registered? instructions: - text: Count the platform credential methods on user {user_id}. slots: user_id: path.user-id - text: Return the number of macOS credentials for {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/softwareOathMethods'].get update: x-apievangelist-phrasing: intent: List a user's software OATH TOTP apps effect: read questions: - Which third-party authenticator apps generating TOTP codes has a user registered? - Can I list the software OATH tokens on a user's account? instructions: - text: List the software OATH methods registered to user {user_id}. slots: user_id: path.user-id - text: Show all TOTP authenticator apps for {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/softwareOathMethods/{softwareOathAuthenticationMethod-id}'].get update: x-apievangelist-phrasing: intent: Get one software OATH TOTP app effect: read questions: - What are the details of a specific TOTP app registration on a user? - Can I read one software OATH token by its ID? instructions: - text: Get software OATH method {method_id} for user {user_id}. slots: method_id: path.softwareOathAuthenticationMethod-id user_id: path.user-id - text: Show TOTP app registration {method_id} on {user_id}. slots: method_id: path.softwareOathAuthenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/softwareOathMethods/{softwareOathAuthenticationMethod-id}'].delete update: x-apievangelist-phrasing: intent: Remove a software OATH TOTP app effect: destructive questions: - How do I remove a TOTP authenticator app from a user? - Can I delete a user's software OATH token registration? instructions: - text: Delete software OATH method {method_id} from user {user_id}. slots: method_id: path.softwareOathAuthenticationMethod-id user_id: path.user-id - text: Remove TOTP app {method_id} for {user_id}. slots: method_id: path.softwareOathAuthenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/softwareOathMethods/$count'].get update: x-apievangelist-phrasing: intent: Count a user's software OATH TOTP apps effect: read questions: - How many software OATH tokens does a user have? - Has this user registered any TOTP app? instructions: - text: Count the software OATH methods on user {user_id}. slots: user_id: path.user-id - text: Return the number of TOTP apps for {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/temporaryAccessPassMethods'].get update: x-apievangelist-phrasing: intent: List a user's Temporary Access Passes effect: read questions: - Does a user currently have a Temporary Access Pass? - Why does the Temporary Access Pass list only ever return one item? instructions: - text: List the Temporary Access Pass methods for user {user_id}. slots: user_id: path.user-id - text: Show any Temporary Access Pass issued to {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/temporaryAccessPassMethods'].post update: x-apievangelist-phrasing: intent: Issue a Temporary Access Pass to a user effect: write questions: - How do I issue a Temporary Access Pass so a new employee can onboard passwordless? - Can I make a Temporary Access Pass single-use and set how many minutes it lasts? instructions: - text: Create a Temporary Access Pass for user {user_id} valid for {minutes} minutes. slots: user_id: path.user-id minutes: requestBody.lifetimeInMinutes - text: Issue a one-time Temporary Access Pass to {user_id} starting at {start}, single use {once}. slots: user_id: path.user-id start: requestBody.startDateTime once: requestBody.isUsableOnce method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/temporaryAccessPassMethods/{temporaryAccessPassAuthenticationMethod-id}'].get update: x-apievangelist-phrasing: intent: Get one Temporary Access Pass effect: read questions: - Is a specific Temporary Access Pass still usable and when does it start? - Can I read one Temporary Access Pass by its ID? instructions: - text: Get Temporary Access Pass {method_id} for user {user_id}. slots: method_id: path.temporaryAccessPassAuthenticationMethod-id user_id: path.user-id - text: Show the usability and lifetime of pass {method_id} on {user_id}. slots: method_id: path.temporaryAccessPassAuthenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/temporaryAccessPassMethods/{temporaryAccessPassAuthenticationMethod-id}'].delete update: x-apievangelist-phrasing: intent: Revoke a user's Temporary Access Pass effect: destructive questions: - How do I revoke a Temporary Access Pass before it expires? - Can I delete a user's Temporary Access Pass so I can issue a new one? instructions: - text: Delete Temporary Access Pass {method_id} from user {user_id}. slots: method_id: path.temporaryAccessPassAuthenticationMethod-id user_id: path.user-id - text: Revoke the Temporary Access Pass {method_id} for {user_id}. slots: method_id: path.temporaryAccessPassAuthenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/temporaryAccessPassMethods/$count'].get update: x-apievangelist-phrasing: intent: Count a user's Temporary Access Passes effect: read questions: - How many Temporary Access Pass methods does a user have? - Is there any Temporary Access Pass registered on this account? instructions: - text: Count the Temporary Access Pass methods on user {user_id}. slots: user_id: path.user-id - text: Return the number of Temporary Access Passes for {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/windowsHelloForBusinessMethods'].get update: x-apievangelist-phrasing: intent: List a user's Windows Hello for Business keys effect: read questions: - Which Windows Hello for Business keys has a user registered? - Can I list a user's Windows Hello sign-in registrations across devices? instructions: - text: List the Windows Hello for Business methods registered to user {user_id}. slots: user_id: path.user-id - text: Show all Windows Hello keys for {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/windowsHelloForBusinessMethods/{windowsHelloForBusinessAuthenticationMethod-id}'].get update: x-apievangelist-phrasing: intent: Get one Windows Hello for Business key effect: read questions: - What is the key strength of a specific Windows Hello for Business registration? - Can I read one Windows Hello key by its ID? instructions: - text: Get Windows Hello for Business method {method_id} for user {user_id}. slots: method_id: path.windowsHelloForBusinessAuthenticationMethod-id user_id: path.user-id - text: Show Windows Hello key {method_id} on {user_id}. slots: method_id: path.windowsHelloForBusinessAuthenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/windowsHelloForBusinessMethods/{windowsHelloForBusinessAuthenticationMethod-id}'].delete update: x-apievangelist-phrasing: intent: Remove a Windows Hello for Business key effect: destructive questions: - How do I remove a Windows Hello for Business key from a decommissioned PC? - Can I delete a user's Windows Hello registration? instructions: - text: Delete Windows Hello for Business method {method_id} from user {user_id}. slots: method_id: path.windowsHelloForBusinessAuthenticationMethod-id user_id: path.user-id - text: Remove Windows Hello key {method_id} for {user_id}. slots: method_id: path.windowsHelloForBusinessAuthenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/windowsHelloForBusinessMethods/{windowsHelloForBusinessAuthenticationMethod-id}/device'].get update: x-apievangelist-phrasing: intent: Get the PC behind a Windows Hello key effect: read questions: - Which Windows device holds a user's Windows Hello for Business key? - Can I see the registered device for a Windows Hello registration? instructions: - text: Get the device for Windows Hello method {method_id} of user {user_id}. slots: method_id: path.windowsHelloForBusinessAuthenticationMethod-id user_id: path.user-id - text: Show which PC holds Windows Hello key {method_id} for {user_id}. slots: method_id: path.windowsHelloForBusinessAuthenticationMethod-id user_id: path.user-id method: generated generated: '2026-10-01' - target: $.paths['/users/{user-id}/authentication/windowsHelloForBusinessMethods/$count'].get update: x-apievangelist-phrasing: intent: Count a user's Windows Hello for Business keys effect: read questions: - How many Windows Hello for Business keys does a user have? - Has this user enrolled Windows Hello on any device? instructions: - text: Count the Windows Hello for Business methods on user {user_id}. slots: user_id: path.user-id - text: Return the number of Windows Hello keys for {user_id}. slots: user_id: path.user-id method: generated generated: '2026-10-01'