openapi: 3.1.0 info: title: Microsoft Graph Admin Admin.admin Audit Logs Directory Audits API description: 'Microsoft Graph API for managing administrative resources in Microsoft Entra ID. This API enables administrators to manage Microsoft Edge browser settings, Internet Explorer mode configurations, site lists, shared browser sites, Microsoft 365 Apps installation options, people insights, service announcements, SharePoint settings, Copilot administration, directory administrative units, and admin consent policies.' version: 1.0.0 contact: name: Microsoft Graph API Support url: https://developer.microsoft.com/graph servers: - url: https://graph.microsoft.com/v1.0 description: Microsoft Graph API v1.0 endpoint tags: - name: Audit Logs Directory Audits description: Operations for accessing audit log data paths: /auditLogs/directoryAudits: description: Provides operations to manage the directoryAudits property of the microsoft.graph.auditLogRoot entity. get: tags: - Audit Logs Directory Audits summary: Microsoft Graph List directoryAudits description: Get the list of audit logs generated by Microsoft Entra ID. This includes audit logs generated by various services within Microsoft Entra ID, including user, app, device and group Management, privileged identity management (PIM), access reviews, terms of use, identity protection, password management (self-service and admin password resets), and self- service group management, and so on. operationId: listAuditLogsDirectoryAudits externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/directoryaudit-list?view=graph-rest-1.0 parameters: - $ref: '#/components/parameters/Top' - $ref: '#/components/parameters/Skip' - $ref: '#/components/parameters/Search' - $ref: '#/components/parameters/Filter' - $ref: '#/components/parameters/Count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/DirectoryAuditCollectionResponse' 4XX: $ref: '#/components/responses/error' 5XX: $ref: '#/components/responses/error' x-microcks-operation: delay: 100 dispatcher: FALLBACK dispatcherRules: 2XX x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - Audit Logs Directory Audits summary: Microsoft Graph Create Directory Audits description: Performs POST operation on /auditLogs/directoryAudits operationId: createAuditLogsDirectoryAudits requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/DirectoryAudit' examples: DirectoryAuditRequestExample: $ref: '#/components/examples/DirectoryAuditRequestExample' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/DirectoryAudit' examples: DirectoryAuditExample: $ref: '#/components/examples/DirectoryAuditExample' 4XX: $ref: '#/components/responses/error' 5XX: $ref: '#/components/responses/error' x-microcks-operation: delay: 100 dispatcher: FALLBACK dispatcherRules: 2XX x-ms-docs-operation-type: operation /auditLogs/directoryAudits/{directoryAudit-id}: description: Provides operations to manage the directoryAudits property of the microsoft.graph.auditLogRoot entity. parameters: - name: directoryAudit-id in: path description: The unique identifier of directoryAudit required: true schema: type: string x-ms-docs-key-type: directoryAudit get: tags: - Audit Logs Directory Audits summary: Microsoft Graph Get directoryAudit description: Get a specific Microsoft Entra audit log item. This includes an audit log item generated by various services within Microsoft Entra ID like user, application, device and group management, privileged identity management (PIM), access reviews, terms of use, identity protection, password management (self-service and admin password resets), self-service group management, and so on. operationId: getAuditLogsDirectoryAudits externalDocs: description: Find more info here url: https://learn.microsoft.com/graph/api/directoryaudit-get?view=graph-rest-1.0 parameters: - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/DirectoryAudit' examples: DirectoryAuditExample: $ref: '#/components/examples/DirectoryAuditExample' 4XX: $ref: '#/components/responses/error' 5XX: $ref: '#/components/responses/error' x-microcks-operation: delay: 100 dispatcher: FALLBACK dispatcherRules: 2XX x-ms-docs-operation-type: operation patch: tags: - Audit Logs Directory Audits summary: Microsoft Graph Update Directory Audits description: Performs PATCH operation on /auditLogs/directoryAudits/{directoryAudit-id} operationId: updateAuditLogsDirectoryAudits requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/DirectoryAudit' examples: DirectoryAuditRequestExample: $ref: '#/components/examples/DirectoryAuditRequestExample' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/DirectoryAudit' examples: DirectoryAuditExample: $ref: '#/components/examples/DirectoryAuditExample' 4XX: $ref: '#/components/responses/error' 5XX: $ref: '#/components/responses/error' x-microcks-operation: delay: 100 dispatcher: FALLBACK dispatcherRules: 2XX x-ms-docs-operation-type: operation delete: tags: - Audit Logs Directory Audits summary: Microsoft Graph Delete Directory Audits description: Performs DELETE operation on /auditLogs/directoryAudits/{directoryAudit-id} operationId: deleteAuditLogsDirectoryAudits parameters: - name: If-Match in: header description: ETag schema: type: string responses: '204': description: Success 4XX: $ref: '#/components/responses/error' 5XX: $ref: '#/components/responses/error' x-microcks-operation: delay: 100 dispatcher: FALLBACK dispatcherRules: '204' x-ms-docs-operation-type: operation /auditLogs/directoryAudits/$count: description: Provides operations to count the resources in the collection. get: tags: - Audit Logs Directory Audits summary: Microsoft Graph Get the number of the resource description: Performs GET operation on /auditLogs/directoryAudits/$count operationId: countAuditLogsDirectoryAudits parameters: - $ref: '#/components/parameters/Search' - $ref: '#/components/parameters/Filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' 4XX: $ref: '#/components/responses/error' 5XX: $ref: '#/components/responses/error' x-microcks-operation: delay: 100 dispatcher: FALLBACK dispatcherRules: 2XX components: parameters: Top: name: $top in: query description: Show only the first n items style: form explode: false schema: minimum: 0 type: integer example: 50 Skip: name: $skip in: query description: Skip the first n items style: form explode: false schema: minimum: 0 type: integer Count: name: $count in: query description: Include count of items style: form explode: false schema: type: boolean Search: name: $search in: query description: Search items by search phrases style: form explode: false schema: type: string Filter: name: $filter in: query description: Filter items by property values style: form explode: false schema: type: string responses: ODataCountResponse: description: The count of the resource content: text/plain: schema: $ref: '#/components/schemas/ODataCountResponse' examples: ODataCountResponseExample: $ref: '#/components/examples/ODataCountResponseExample' error: description: error content: application/json: schema: $ref: '#/components/schemas/ODataError' examples: ODataErrorExample: $ref: '#/components/examples/ODataErrorExample' schemas: InnerError: title: InnerError type: object properties: request-id: type: string date: type: string format: date-time client-request-id: type: string Entity: title: Entity type: object properties: id: type: string description: The unique identifier for the entity. ODataCountResponse: title: ODataCountResponse type: integer format: int32 description: The count of entities DirectoryAudit: allOf: - $ref: '#/components/schemas/Entity' - title: directoryAudit required: - '@odata.type' type: object properties: activityDateTime: pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$ type: string description: Indicates the date and time the activity was performed. The Timestamp type is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. Supports $filter (eq, ge, le) and $orderby. format: date-time activityDisplayName: type: string description: 'Indicates the activity name or the operation name (examples: ''Create User'' and ''Add member to group''). For a list of activities logged, refer to Microsoft Entra audit log categories and activities. Supports $filter (eq, startswith).' additionalDetails: type: array items: $ref: '#/components/schemas/KeyValue' description: Indicates additional details on the activity. category: type: string description: 'Indicates which resource category that''s targeted by the activity. For example: UserManagement, GroupManagement, ApplicationManagement, RoleManagement. For a list of categories for activities logged, refer to Microsoft Entra audit log categories and activities.' correlationId: type: string description: Indicates a unique ID that helps correlate activities that span across various services. Can be used to trace logs across services. Supports $filter (eq). nullable: true initiatedBy: $ref: '#/components/schemas/AuditActivityInitiator' loggedByService: type: string description: 'Indicates information on which service initiated the activity (For example: Self-service Password Management, Core Directory, B2C, Invited Users, Microsoft Identity Manager, Privileged Identity Management. Supports $filter (eq).' nullable: true operationType: type: string description: 'Indicates the type of operation that was performed. The possible values include but are not limited to the following: Add, Assign, Update, Unassign, and Delete.' nullable: true result: anyOf: - $ref: '#/components/schemas/OperationResult' - type: object nullable: true description: 'Indicates the result of the activity. The possible values are: success, failure, timeout, unknownFutureValue.' resultReason: type: string description: Indicates the reason for failure if the result is failure or timeout. nullable: true targetResources: type: array items: $ref: '#/components/schemas/TargetResource' description: Indicates information on which resource was changed due to the activity. Target Resource Type can be User, Device, Directory, App, Role, Group, Policy or Other. Supports $filter (eq) for id and displayName; and $filter (startswith) for displayName. '@odata.type': type: string x-ms-discriminator-value: '#microsoft.graph.directoryAudit' ODataError: title: ODataError type: object required: - error properties: error: $ref: '#/components/schemas/MainError' ErrorDetail: title: ErrorDetail type: object required: - code - message properties: code: type: string message: type: string target: type: string nullable: true MainError: title: MainError type: object required: - code - message properties: code: type: string description: Error code message: type: string description: Error message target: type: string description: Target of the error nullable: true details: type: array items: $ref: '#/components/schemas/ErrorDetail' innerError: $ref: '#/components/schemas/InnerError' examples: ODataErrorExample: value: error: code: BadRequest message: The request is invalid. target: /resource details: - code: InvalidParameter message: Parameter value is invalid. target: parameterName innerError: request-id: 00000000-0000-0000-0000-000000000001 date: '2024-01-15T10:30:00Z' client-request-id: 00000000-0000-0000-0000-000000000002 DirectoryAuditRequestExample: value: id: 00000000-0000-0000-0000-000000000001 activityDateTime: '2024-01-15T10:30:00Z' activityDisplayName: Example Display Name additionalDetails: - {} category: string-value correlationId: 00000000-0000-0000-0000-000000000001 initiatedBy: {} '@odata.type': '#microsoft.graph.directoryaudit' DirectoryAuditExample: value: id: 00000000-0000-0000-0000-000000000001 activityDateTime: '2024-01-15T10:30:00Z' activityDisplayName: Example Display Name additionalDetails: - {} category: string-value correlationId: 00000000-0000-0000-0000-000000000001 initiatedBy: {} '@odata.type': '#microsoft.graph.directoryaudit' ODataCountResponseExample: value: 42