# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Palo Alto Networks Cloud Accounts (Azure) API version: 1.0.0 extends: openapi/palo-alto-networks-cloud-accounts-azure-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 6 - target: $.paths['/cas/v1/azure_account'].post update: x-apievangelist-phrasing: intent: Onboard an Azure account to Prisma Cloud effect: write questions: - How do I connect an Azure subscription or tenant to Prisma Cloud? - Can I enable flow log monitoring when onboarding Azure? instructions: - text: Onboard Azure account {cloudAccount} in tenant {tenantId} with client {clientId}, key {key}, environment {environmentType}. slots: cloudAccount: requestBody.cloudAccount tenantId: requestBody.tenantId clientId: requestBody.clientId key: requestBody.key environmentType: requestBody.environmentType - text: Add Azure tenant {tenantId} as a new cloud account with features {features}. slots: tenantId: requestBody.tenantId features: requestBody.features method: generated generated: '2026-09-26' - target: $.paths['/cas/v1/azure_account/{account_id}'].put update: x-apievangelist-phrasing: intent: Update an onboarded Azure account effect: write questions: - How do I rotate the client secret on an Azure account already in Prisma Cloud? - Can I change which features are enabled on an existing Azure account? instructions: - text: Update Azure account {account_id} with new key {key}. slots: account_id: path.account_id key: requestBody.key - text: Change the enabled features on Azure account {account_id} to {features}. slots: account_id: path.account_id features: requestBody.features method: generated generated: '2026-09-26' - target: $.paths['/cas/v1/cloud_account/status/azure'].post update: x-apievangelist-phrasing: intent: Check an Azure account's onboarding status effect: read questions: - Will my Azure credentials work before I actually onboard the account? - Which security capabilities are ready for an Azure account I'm about to add? instructions: - text: Check onboarding status for Azure account {cloudAccount} in tenant {tenantId} using client {clientId}, key {key}, environment {environmentType}. slots: cloudAccount: requestBody.cloudAccount tenantId: requestBody.tenantId clientId: requestBody.clientId key: requestBody.key environmentType: requestBody.environmentType - text: Dry-run the Azure onboarding checks for tenant {tenantId}. slots: tenantId: requestBody.tenantId method: generated generated: '2026-09-26' - target: $.paths['/cloud-accounts-manager/v1/cloudAccounts/azureAccounts/{account_id}/ancestors'].post update: x-apievangelist-phrasing: intent: List ancestors of Azure subscriptions effect: read questions: - Which management groups does an Azure subscription sit under? - Can I trace the ancestry of several Azure subscriptions at once? instructions: - text: Find the ancestors of Azure resources {resourceIds} in tenant account {account_id}. slots: resourceIds: requestBody.resourceIds account_id: path.account_id - text: Show the management group chain above subscriptions in Azure account {account_id}. slots: account_id: path.account_id method: generated generated: '2026-09-26' - target: $.paths['/cloud-accounts-manager/v1/cloudAccounts/azureAccounts/{parent_id}/children'].post update: x-apievangelist-phrasing: intent: List management groups and subscriptions under a parent effect: read questions: - What management groups and subscriptions are under my Azure tenant? - Can I browse the children of an Azure management group? instructions: - text: List the children of Azure parent {parent_id} for tenant {tenantId} using client {clientId}, key {key}, service principal {servicePrincipalId}. slots: parent_id: path.parent_id tenantId: requestBody.tenantId clientId: requestBody.clientId key: requestBody.key servicePrincipalId: requestBody.servicePrincipalId - text: Show subscriptions and management groups under Azure parent {parent_id}. slots: parent_id: path.parent_id method: generated generated: '2026-09-26' - target: $.paths['/cas/v1/azure_template'].post update: x-apievangelist-phrasing: intent: Generate the Azure onboarding Terraform template effect: write questions: - How do I get the Terraform template to grant Prisma Cloud access to Azure? - Does the Azure Terraform template include permissions for only the features I pick? instructions: - text: Generate an Azure Terraform template for tenant {tenantId} with account type {accountType}. slots: tenantId: requestBody.tenantId accountType: requestBody.accountType - text: Download Azure onboarding Terraform for subscription {subscriptionId} in tenant {tenantId}. slots: subscriptionId: requestBody.subscriptionId tenantId: requestBody.tenantId method: generated generated: '2026-09-26'