Microsoft Graph API Identity & Access Management
This connector facilitates the management of identities and access within Azure Active Directory through the Microsoft Graph API, enabling automated workflows for security and IT operations.
Microsoft Graph API Identity & Access Management connector enables seamless integration with Microsoft's comprehensive identity and access management services. It allows Swimlane Turbine users to manage authentication methods, access controls, and identity protection mechanisms directly within their security workflows. By leveraging this connector, organizations can automate critical security tasks, enhance their identity governance, and respond rapidly to identity-related security events.
Configuration
Prerequisites
To utilize the Microsoft Graph API Identity & Access Management connector, the following prerequisites must be met:
- Client Credentials and Tenant ID authentication with the following parameters:
- URL: Endpoint URL for Microsoft Graph API.
- Client ID: Application ID registered in Azure AD.
- Client Secret: Secret generated for the application in Azure AD.
- Tenant ID: Directory ID of the Azure AD tenant.
- Scope: Permissions the app requires.
- OAuth 2.0 Client Credentials with the following parameters:
- URL: Endpoint URL for Microsoft Graph API.
- Client ID: Application ID registered in Azure AD.
- Client Secret: Secret generated for the application in Azure AD.
- Token URL: URL to retrieve the oauth2 token.
- Scope: Permissions the app requires.
- Delegated Flow Authentication with the following parameters:
- URL: Endpoint URL for Microsoft Graph API.
- Tenant ID: Directory ID of the Azure AD tenant. ... and so on
Authentication Methods
OAuth 2.0 client credentials authentication with these parameters:
- url: Endpoint for Microsoft Graph API.
- client_id: Application (client) ID registered in Azure AD.
- client_secret: Client secret (key) generated for the application in Azure AD.
- token_url: URL to retrieve the OAuth token.
- scope: Permissions the app requires.
Password Grant (Delegated Authentication) for acting on behalf of a user:
- url: Endpoint for Microsoft Graph API.
- tenant_id: Directory ID of the Azure AD tenant.
- oauth_un: User's username to authenticate.
- oauth_pwd: User's password to authenticate.
- oauth_cl_id: Application (client) ID registered in Azure AD.
- oauth_cl_secret: Client secret (key) generated for the application in Azure AD.
- login_url: Login URL. Default value is https://login.microsoftonline.com. (Optional).
- scope: Permissions the app requires. Optional field. (Optional).
Asset credentials specific to your organization (Microsoft Graph API Asset - Tenant ID):
- url: Endpoint for Microsoft Graph API.
- client_ID: Application (client) ID registered in Azure AD.
- client_Secret: Client secret (key) generated for the application in Azure AD.
- tenant_id: Directory ID of the Azure AD tenant.
- scope: Permissions the app requires.
Authentication for OAuth2 Refresh Token Grant credentials for Microsoft Graph API authentication
- url: Endpoint for Microsoft Graph API.
- client_ID: Application (client) ID registered in Azure AD.
- client_Secret: Client secret (key) generated for the application in Azure AD.
- refresh_token: Refresh Token.
- scope: Permissions the app requires.
Capabilities
The Microsoft Graph API connector gives the ability to get and update security alerts, and modify user licenses and sessions.
- Add Directory Administrative Unit Member
- Create Identity Directory Device
- Create Identity Directory Domain
- Create Identity Directory Role Management
- Create Identity Directory Role Member
- Delete Directory Administrative Unit Member
- Delete FIDO2 Authentication Method
- Delete Identity Directory Device
- Delete Identity Directory Device Registered User
- Delete Identity Directory Domain
- Delete Identity Directory Role Management
- Delete Identity Directory Role Member
- Delete Microsoft Authenticator Auth Method
- Delete Phone Authentication Method
- Delete Software OATH Authentication Method ... and so on
Asset Setup
Client Credential Flow Authentication
Authentication uses Azure application OAuth2. You will need an admin account in Azure to create the application.
Recommended Application Permissions (feel free use custom permissions if you only use certain actions):
- User.ReadWrite.All
- Calendars.ReadWrite
- Directory.ReadWrite.All
- Directory.AccessAsUser.All
- SecurityEvents.Read.All
- SecurityEvents.ReadWrite.All
- User.ManageIdentities.All,
- User.EnableDisableAccount.All,
- User.ReadWrite.All
- SecurityIncident.ReadWrite.All
- UserAuthenticationMethod.Read.All
- UserAuthenticationMethod.ReadWrite.All
- Group.ReadWrite.All
- IdentityRiskyUser.Read.All
In order to set up the asset, you need the following:
- Azure Application Client ID
- Azure Application Client Secret
- Azure Tenant ID
Steps to create the Azure app:
- Go to the App Registration page in the Azure portal.
- Click New Registration.
- Enter a name for your new application and choose Accounts in this organizational directory only, then click Register at the bottom.
- Navigate to the API permissions tab on the left navigation menu.
- Select Add a permission.
- Select Microsoft Graph.
- Select Application permissions, then mark all the permissions you need for the actions you are using (See suggested permissions at the top of the asset setup section).
- Click the Add permissions button at the bottom of the page.
- Select Grant admin consent for your organization, then your permissions should look as below.
- Navigate to the Certificates & secrets tab and select New client secret.
- Fill out the description and expiration, then click the Add button at the bottom.
- The Value of the secret you just created is the Client Secret needed for the Swimlane asset.
- Navigate to the Overview tab on the left menu.
- The Client ID and Tenant ID needed in the asset are shown on this page.
The Client ID, Tenant ID, and Client Secret described in the steps above are the credentials you need for the asset.
Password Flow (Delegated Auth)
- Use Delegated Permissions, instead of Application Permissions, and generate Client ID, Tenant ID, and Client Secret as described in the above Client Credential Flow Authentication.
- We also need an Username and a Password for this authentication.
Authentication flow for OAuth2 Refresh Token
- Oauth 2.0 refresh token grant, which requires a Refresh Token,Tenant ID, Client ID and Client Secret. Use this auth with accounts which have MFA enabled. To generate a refresh token please follow the instructions below.
- In step 3 of the above-mentioned setup instructions, please provide a Redirect URI and select the platform as 'Web', before clicking on Register at the the bottom.
- Proceed with the remaining steps to generate 'Client ID', Tenant ID and Client Secret.
- Add the permissions in Delegated Permissions.
- The Swimlane team will provide a Python script and instructions on how to use the script to generate the Refresh Token.
Limit Access to specific mailboxes
Administrators who want to limit app access to specific mailboxes can create an application access policy by using the New-ApplicationAccessPolicy PowerShell cmdlet. For more information please see the article Limiting application permissions to specific Exchange Online mailboxes.
Action Setup
OData filters
Information on the filter input formatting can be found here.
Keep in mind that not specifying a folder as an input will result in the query affecting all possible folders. Example: If we want to ingest only unread emails, and we don't set the input "folder", we will ingest all unread emails from all folders, including "Deleted Items", "Junk", etc.
Well Known Folders
Well known folders can be used instead of Folder IDs for email actions. All well known folder names can be found here.
Sites Get Site
All the Sites actions require the site ID to be executed. The site ID can be obtained using the action Sites Get Site, in order to run the action the site_hostname and site_name are needed. This two values can be found in a site URL:
https://{site_hostname}.sharepoint.com/sites/{site_name}For example if our site URL is https://swimlaneintegrations.sharepoint.com/sites/IntegrationsSite we should use:
- site_hostname: swimlaneintegrations
- site_name: IntegrationsSite
After the action execution you can find the Site ID on the ID output field.
Sites Create List
In order to create a list with its columns, use the input Columns. You can find all the possible values with its configuration on the following table.
Property name | Type | Description |
|---|---|---|
boolean | This column stores boolean values. | |
calculated | This column's data is calculated based on other columns. | |
choice | This column stores data from a list of choices. | |
currency | This column stores currency values. | |
dateTime | This column stores DateTime values. | |
geolocation | This column stores a geolocation. | |
lookup | This column's data is looked up from another source in the site. | |
number | This column stores number values. | |
personOrGroup | This column stores Person or Group values. | |
text | This column stores text values. | |
validation | This column stores validation formula and message for the column. | |
hyperlinkOrPicture | This column stores hyperlink or picture values. | |
term | This column stores taxonomy terms. | |
thumbnail | This column stores thumbnail values. | |
contentApprovalStatus | This column stores content approval status. |
For a complete version of this table please see the official column definition table.
Create List Column
Refer to the above table to get the Type properties and Column type input. The Type properties are documented within the links in the Type column.
Get list items
In order to use the filter input please refer to the OData filtersο»Ώ section.
The column used to filter the output must be indexed, see the Microsoft documentation to add an index to a list.
Limitations
When using $filter and $orderby in the same query to get messages, make sure to specify properties in the following ways:
- Properties that appear in $orderby must also appear in $filter.
- Properties that appear in $orderby are in the same order as in $filter.
- Properties that are present in $orderby appear in $filter before any properties that aren't.
Failing to do this results in the following error:
- Error code: InefficientFilter
- Error message: The restriction or sort order is too complex for this operation.
The Assign/Remove User License requires either the disabled plans and accompanying SKU IDs to assign licenses or the SKU ID of the license you want to remove.
The Get Security Alert has additional information it can return. There are a large number of fields that don't relate to many alerts, so they are not mapped; you can add them if desired.
Notes
- oauthlib Legacy Application client, this is sort of a hack to bypass manual login (typically required)
Configurations
Microsoft Graph API - Tenant ID
Authenticates using Client Credentials and Tenant ID
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
tenant_id | The Tenant ID. | string | Required |
client_ID | The client ID | string | Required |
client_Secret | The client secret. | string | Required |
scope | List of permission scopes for this action. | array | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Password Grant (Delegated Authentication)
Authenticates on behalf of a user using oauth 2.0 credentials
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
login_url | ο»Ώ | string | Optional |
tenant_id | ο»Ώ | string | Required |
oauth_un | The username for authentication | string | Required |
oauth_pwd | The password for authentication | string | Required |
oauth_cl_id | The client ID | string | Required |
oauth_cl_secret | The client secret. | string | Required |
scope | Permission scopes for this action. | array | Optional |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Oauth 2.0 Client Credentials
Authenticates using oauth 2.0 client credentials
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
token_url | Must start with https://login.microsoftonline.com/ and then continue with the tenant_id, and then be prepended with /oauth2/v2.0/token | string | Required |
client_id | The client ID | string | Required |
client_secret | The client secret. | string | Required |
scope | List of permission scopes for this action. | array | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
MS Graph OpenID Connect Refresh Token Grant
Authenticates using refresh token.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
cl_id | The client ID. | string | Required |
cl_secret | The client secret. | string | Required |
refresh_token | Refresh Token. | string | Optional |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Delete FIDO2 Authentication Method
Removes a user's FIDO2 Security Key Authentication Method in Microsoft Graph API by specifying their email address and method ID.
Endpoint
- URL: /v1.0/users/{{email_address}}/authentication/fido2Methods/{{id}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.email_address | string | Required | The account associated with the email. |
path_parameters.id | string | Required | The ID of the FIDO2 Security Key authentication method. |
Input Example
{"path_parameters":{"email_address":"[email protected]","id":"_jpuR-TGZtk6aQCLF3BQjA2"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"response_text":"string"}
Delete Microsoft Authenticator Auth Method
Removes a specific Microsoft Authenticator method for a user, identified by email address and authenticator ID.
Endpoint
- URL: /v1.0/users/{{email_address}}/authentication/microsoftAuthenticatorMethods/{{microsoftAuthenticatorAuthenticationMethodId}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.email_address | string | Required | The account associated with the email. |
path_parameters.microsoftAuthenticatorAuthenticationMethodId | string | Required | The ID of the Microsoft Authenticator authentication method. |
Input Example
{"path_parameters":{"email_address":"[email protected]","microsoftAuthenticatorAuthenticationMethodId":"_jpuR-TGZtk6aQCLF3BQjA2"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"response_text":"string"}
Delete Phone Authentication Method
Removes a user's phone authentication method in Microsoft Graph API using their email address and the specific phoneMethodId.
Endpoint
- URL: /v1.0/users/{{email_address}}/authentication/phoneMethods/{{phoneMethodId}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.email_address | string | Required | The account associated with the email. |
path_parameters.phoneMethodId | string | Required | The ID of the phone authentication method. The Phone Method ID values correspond to deleting specific phone types are b6332ec1-7057-4abe-9331-3d72feddfe41 for alternateMobile, e37fc753-ff3b-4958-9484-eaa9425c82bc for office, and 3179e48a-750b-4051-897c-87b9720928f7 for mobile. |
Input Example
{"path_parameters":{"email_address":"[email protected]","phoneMethodId":"3179e48a-750b-4051-897c-87b9720928f7"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"response_text":"string"}
Delete Software OATH Authentication Method
Removes a user's Software OATH token authentication method in Microsoft Graph API using their email address and ID.
Endpoint
- URL: /v1.0/users/{{email_address}}/authentication/softwareOathMethods/{{id}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.email_address | string | Required | The account associated with the email. |
path_parameters.id | string | Required | The ID of the Software OATH token authentication method. |
Input Example
{"path_parameters":{"email_address":"[email protected]","id":"b172893e-893e-b172-3e89-72b13e8972b1"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"response_text":"string"}
Delete Temporary Access Pass Auth Method
Removes a user's Temporary Access Pass Authentication Method in Microsoft Graph API using their email address and ID.
Endpoint
- URL: /v1.0/users/{{email_address}}/authentication/temporaryAccessPassMethods/{{id}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.email_address | string | Required | The account associated with the email. |
path_parameters.id | string | Required | The ID of the Temporary Access Pass authentication method. |
Input Example
{"path_parameters":{"email_address":"[email protected]","id":"05267842-25b2-4b21-8abd-8e4982796f7f"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"response_text":"string"}
Delete Windows Hello For Business Auth Method
Removes a Windows Hello For Business authentication method for a user by email address and method ID.
Endpoint
- URL: /v1.0/users/{{email_address}}/authentication/windowsHelloForBusinessMethods/{{windowsHelloForBusinessAuthenticationMethodId}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.email_address | string | Required | The account associated with the email. |
path_parameters.windowsHelloForBusinessAuthenticationMethodId | string | Required | The ID of the Windows Hello For Business authentication method. |
Input Example
{"path_parameters":{"email_address":"[email protected]","windowsHelloForBusinessAuthenticationMethodId":"_jpuR-TGZtk6aQCLF3BQjA2"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"response_text":"string"}
List riskyUsers
Retrieve a list of riskyUser objects from Microsoft Graph API to identify potential security risks.
Endpoint
- URL: /v1.0/identityProtection/riskyUsers
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.$filter | string | Optional | Filters results (rows). |
parameters.$select | string | Optional | Filters properties (columns). |
parameters.$top | number | Optional | Sets the page size of results. The maximum page size with top is 500 objects. |
Input Example
{"parameters":{"$filter":"riskLevel eq 'high' ","$select":"givenName,surname","$top":10}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
value | array | Value for the parameter |
string | Response data | |
value.id | string | Unique identifier |
value.isDeleted | boolean | Value for the parameter |
value.isProcessing | boolean | Value for the parameter |
value.riskLastUpdatedDateTime | string | Value for the parameter |
value.riskLevel | string | Value for the parameter |
value.riskState | string | Value for the parameter |
value.riskDetail | string | Value for the parameter |
value.userDisplayName | string | Name of the resource |
value.userPrincipalName | string | Name of the resource |
Output Example
{"value":[{"@odata.type":"#microsoft.graph.riskyUser","id":"d1d4a5d4-a5d4-d1d4-d4a5-d4d1d4a5d4d1","isDeleted":true,"isProcessing":true,"riskLastUpdatedDateTime":"2025-06-05T05:18:27Z","riskLevel":"High","riskState":"Active","riskDetail":"Suspicious activity detected","userDisplayName":"John Doe","userPrincipalName":"[email protected]"}]}
List Password Methods
Retrieve registered password authentication methods for a user in Microsoft Graph API by specifying the User ID.
Endpoint
- URL: /v1.0/users/{{id}}/authentication/passwordMethods
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | User ID |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
value | array | Value for the parameter |
value.id | string | Unique identifier |
value.password | object | Value for the parameter |
value.creationDateTime | object | Value for the parameter |
value.createdDateTime | object | Value for the parameter |
Output Example
{"@odata.context":"string","value":[{"id":"12345678-1234-1234-1234-123456789abc","password":{},"creationDateTime":{},"createdDateTime":{}}]}
Reset Password
Initiate a password reset for a specified user by providing their ID and methodId via the Microsoft Graph API.
Endpoint
- URL: /v1.0/users/{{id}}/authentication/methods/{{methodId}}/resetPassword
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | User ID |
path_parameters.methodId | string | Required | Password Method ID |
newPassword | string | Optional | The new password. Required for tenants with hybrid password scenarios. If omitted for a cloud-only password, the system returns a system-generated password. |
include_uppercase | boolean | Optional | Include Atleast One Uppercase Letter. |
include_lowercase | boolean | Optional | Include Atleast One Lowercase Letter. |
include_digit | boolean | Optional | Include Atleast One One Digit. |
include_special | boolean | Optional | Include Atleast One Special Character. |
length | number | Optional | Password length with minimum 20. |
auto_generate | boolean | Optional | Auto Generate Random password. |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc","methodId":"string"},"newPassword":"string","include_uppercase":true,"include_lowercase":true,"include_digit":true,"include_special":true,"length":20,"auto_generate":true}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
newPassword | string | Output field: newPassword |
Output Example
{"@odata.context":"https://graph.microsoft.com/v1.0/$metadata#microsoft.graph.passwordResetResponse","newPassword":"Cuyo5459"}
Get Identity Directory Device Registered User List
Retrieve a list of users registered to a specific device in Microsoft Graph API using the device's unique 'id'.
Endpoint
- URL: /v1.0/devices/{{id}}/registeredUsers
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Device ID |
parameters.filter | string | Optional | Use the filter query parameter to retrieve just a subset of a collection. For guidance on using filter, see https://learn.microsoft.com/en-us/graph/filter-query-parameter |
parameters.orderBy | string | Optional | Use the orderby query parameter to specify the sort order of the items returned from Microsoft Graph. |
parameters.top | number | Optional | Sets the page size of results. |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"},"parameters":{"filter":"string","orderBy":"string","top":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
value | array | Value for the parameter |
string | Response data | |
value.id | string | Unique identifier |
value.businessPhones | array | Value for the parameter |
value.displayName | string | Name of the resource |
value.givenName | string | Name of the resource |
value.jobTitle | object | Value for the parameter |
value.mail | object | Value for the parameter |
value.mobilePhone | object | Value for the parameter |
value.officeLocation | object | Value for the parameter |
value.preferredLanguage | string | Value for the parameter |
value.surname | string | Name of the resource |
value.userPrincipalName | string | Name of the resource |
Output Example
{"@odata.context":"string","value":[{"@odata.type":"string","id":"12345678-1234-1234-1234-123456789abc","businessPhones":[],"displayName":"Example Name","givenName":"Example Name","jobTitle":{},"mail":{},"mobilePhone":{},"officeLocation":{},"preferredLanguage":"string","surname":"Example Name","userPrincipalName":"Example Name"}]}
Get Identity Directory Objects by IDs List
Acquire specific users or groups by 'ids' and 'types' from Microsoft Graph API for targeted data retrieval.
Endpoint
- URL: /v1.0/directoryObjects/getByIds
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
ids | array | Optional | A collection of IDs for which to return objects. The IDs are GUIDs, represented as strings. You can specify up to 1000 IDs |
types | array | Optional | A collection of resource types that specifies the set of resource collections to search, for example user, group, and device objects |
Input Example
{"ids":["string"],"types":["string"]}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
value | array | Value for the parameter |
string | Response data | |
value.id | string | Unique identifier |
value.deletedDateTime | object | Value for the parameter |
value.classification | object | Value for the parameter |
value.createdDateTime | string | Value for the parameter |
value.creationOptions | array | Value for the parameter |
value.description | string | Value for the parameter |
value.displayName | string | Name of the resource |
value.expirationDateTime | object | Value for the parameter |
value.groupTypes | array | Type of the resource |
value.isAssignableToRole | object | Value for the parameter |
value.mail | string | Value for the parameter |
value.mailEnabled | boolean | Value for the parameter |
value.mailNickname | string | Name of the resource |
value.membershipRule | object | Value for the parameter |
value.membershipRuleProcessingState | object | Value for the parameter |
value.onPremisesDomainName | object | Name of the resource |
value.onPremisesLastSyncDateTime | object | Value for the parameter |
value.onPremisesNetBiosName | object | Name of the resource |
value.onPremisesSamAccountName | object | Name of the resource |
value.onPremisesSecurityIdentifier | object | Unique identifier |
Output Example
{"@odata.context":"string","value":[{"@odata.type":"string","id":"12345678-1234-1234-1234-123456789abc","deletedDateTime":{},"classification":{},"createdDateTime":"string","creationOptions":[],"description":"string","displayName":"Example Name","expirationDateTime":{},"groupTypes":[],"isAssignableToRole":{},"mail":"string","mailEnabled":true,"mailNickname":"Example Name","membershipRule":{}}]}
Delete Identity Directory Device Registered User
Remove a registered user from a device in the Microsoft Graph API directory by providing the 'id' and 'userId'.
Endpoint
- URL: /v1.0/devices/{{id}}/registeredUsers/{{userId}}/$ref
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Device ID |
path_parameters.userId | string | Required | User ID |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc","userId":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
error | object | Error message if any |
error.code | string | Error message if any |
error.message | string | Response message |
error.innerError | object | Error message if any |
error.innerError.date | string | Error message if any |
error.innerError.request-id | string | Unique identifier |
error.innerError.client-request-id | string | Unique identifier |
Output Example
{"error":{"code":"string","message":"string","innerError":{"date":"2024-01-01T00:00:00Z","request-id":"string","client-request-id":"string"}}}
Delete Identity Directory Device
Removes a specified device from the Microsoft Graph Identity Directory by using its unique ID.
Endpoint
- URL: /v1.0/devices/{{id}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Device ID |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
error | object | Error message if any |
error.code | string | Error message if any |
error.message | string | Response message |
error.innerError | object | Error message if any |
error.innerError.date | string | Error message if any |
error.innerError.request-id | string | Unique identifier |
error.innerError.client-request-id | string | Unique identifier |
Output Example
{"error":{"code":"string","message":"string","innerError":{"date":"2024-01-01T00:00:00Z","request-id":"string","client-request-id":"string"}}}
Get Identity Directory Device
Retrieve details for a specific device from the Microsoft Graph Identity Directory by providing the unique device ID.
Endpoint
- URL: /v1.0/devices/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.filter | string | Optional | Use the filter query parameter to retrieve just a subset of a collection. For guidance on using filter, see https://learn.microsoft.com/en-us/graph/filter-query-parameter |
parameters.orderBy | string | Optional | Use the orderby query parameter to specify the sort order of the items returned from Microsoft Graph. |
parameters.top | number | Optional | Sets the page size of results. |
path_parameters.id | string | Required | Device ID |
Input Example
{"parameters":{"filter":"string","orderBy":"string","top":123},"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
id | string | Unique identifier |
deletedDateTime | object | Time value |
accountEnabled | boolean | Output field: accountEnabled |
approximateLastSignInDateTime | string | Time value |
complianceExpirationDateTime | object | Time value |
createdDateTime | string | Time value |
deviceCategory | object | Output field: deviceCategory |
deviceId | string | Unique identifier |
deviceMetadata | object | Response data |
deviceOwnership | string | Output field: deviceOwnership |
deviceVersion | number | Output field: deviceVersion |
displayName | string | Name of the resource |
domainName | object | Name of the resource |
enrollmentProfileName | object | Name of the resource |
enrollmentType | string | Type of the resource |
externalSourceName | object | Name of the resource |
isCompliant | boolean | Output field: isCompliant |
isManaged | boolean | Output field: isManaged |
isRooted | boolean | Output field: isRooted |
managementType | string | Type of the resource |
manufacturer | string | Output field: manufacturer |
mdmAppId | string | Unique identifier |
Output Example
{"@odata.context":"string","id":"12345678-1234-1234-1234-123456789abc","deletedDateTime":{},"accountEnabled":true,"approximateLastSignInDateTime":"string","complianceExpirationDateTime":{},"createdDateTime":"string","deviceCategory":{},"deviceId":"string","deviceMetadata":{},"deviceOwnership":"string","deviceVersion":123,"displayName":"Example Name","domainName":{},"enrollmentProfileName":{}}
Create Identity Directory Device
Registers a new device with account status, display name, OS, and version in the Microsoft Graph API directory.
Endpoint
- URL: /v1.0/devices
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
accountEnabled | boolean | Optional | true if the account is enabled; otherwise, false. Required. Default is true |
alternativeSecurityIds | array | Optional | Alternative Security IDs |
alternativeSecurityIds.type | number | Optional | Unique identifier |
alternativeSecurityIds.identityProvider | string | Optional | Unique identifier |
alternativeSecurityIds.key | string | Optional | Unique identifier |
displayName | string | Optional | The display name for the device |
operatingSystem | string | Optional | The type of operating system on the device |
operatingSystemVersion | string | Optional | The version of the operating system on the device |
approximateLastSignInDateTime | string | Optional | The timestamp type represents date and time information using ISO 8601 format and is always in UTC time |
complianceExpirationDateTime | string | Optional | The timestamp type represents date and time information using ISO 8601 format and is always in UTC time |
deviceId | string | Optional | Unique identifier |
extensionAttributes | object | Optional | Contains extension attributes 1-15 for the device. The individual extension attributes are not selectable. These properties are mastered in cloud and can be set during creation or update of a device object in Azure AD |
extensionAttributes.extensionAttribute1 | string | Optional | Parameter for Create Identity Directory Device |
extensionAttributes.extensionAttribute2 | string | Optional | Parameter for Create Identity Directory Device |
extensionAttributes.extensionAttribute3 | string | Optional | Parameter for Create Identity Directory Device |
extensionAttributes.extensionAttribute4 | string | Optional | Parameter for Create Identity Directory Device |
extensionAttributes.extensionAttribute5 | string | Optional | Parameter for Create Identity Directory Device |
extensionAttributes.extensionAttribute6 | string | Optional | Parameter for Create Identity Directory Device |
extensionAttributes.extensionAttribute7 | string | Optional | Parameter for Create Identity Directory Device |
extensionAttributes.extensionAttribute8 | string | Optional | Parameter for Create Identity Directory Device |
extensionAttributes.extensionAttribute9 | string | Optional | Parameter for Create Identity Directory Device |
extensionAttributes.extensionAttribute10 | string | Optional | Parameter for Create Identity Directory Device |
extensionAttributes.extensionAttribute11 | string | Optional | Parameter for Create Identity Directory Device |
extensionAttributes.extensionAttribute12 | string | Optional | Parameter for Create Identity Directory Device |
extensionAttributes.extensionAttribute13 | string | Optional | Parameter for Create Identity Directory Device |
Input Example
{"accountEnabled":true,"alternativeSecurityIds":[{"type":123,"identityProvider":"string","key":"string"}],"displayName":"Example Name","operatingSystem":"string","operatingSystemVersion":"string","approximateLastSignInDateTime":"string","complianceExpirationDateTime":"string","deviceId":"string","extensionAttributes":{"extensionAttribute1":"string","extensionAttribute2":"string","extensionAttribute3":"string","extensionAttribute4":"string","extensionAttribute5":"string","extensionAttribute6":"string","extensionAttribute7":"string","extensionAttribute8":"string","extensionAttribute9":"string","extensionAttribute10":"string","extensionAttribute11":"string","extensionAttribute12":"string","extensionAttribute13":"string","extensionAttribute14":"string","extensionAttribute15":"string"},"isCompliant":true,"isManaged":true,"onPremisesLastSyncDateTime":"string","onPremisesSyncEnabled":true,"profileType":"RegisteredDevice","systemLabels":["string"]}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
error | object | Error message if any |
error.code | string | Error message if any |
error.message | string | Response message |
error.innerError | object | Error message if any |
error.innerError.date | string | Error message if any |
error.innerError.request-id | string | Unique identifier |
error.innerError.client-request-id | string | Unique identifier |
Output Example
{"error":{"code":"string","message":"string","innerError":{"date":"2024-01-01T00:00:00Z","request-id":"string","client-request-id":"string"}}}
Get Identity Directory Device Groups List
Retrieve groups associated with a specific device using its directory ID in Microsoft Graph API; requires the 'id' path parameter.
Endpoint
- URL: /v1.0/devices/{{id}}/memberOf
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Device ID |
parameters.filter | string | Optional | Use the filter query parameter to retrieve just a subset of a collection. For guidance on using filter, see https://learn.microsoft.com/en-us/graph/filter-query-parameter |
parameters.orderBy | string | Optional | Use the orderby query parameter to specify the sort order of the items returned from Microsoft Graph. |
parameters.top | number | Optional | Sets the page size of results. |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"},"parameters":{"filter":"string","orderBy":"string","top":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
value | array | Value for the parameter |
value.file_name | string | Name of the resource |
value.file | string | Value for the parameter |
Output Example
{"@odata.context":"string","value":[{"file_name":"Example Name","file":"string"}]}
Get Identity Directory Device List
Retrieve a list of registered devices with identifiers and display names from the Microsoft Graph Identity Directory.
Endpoint
- URL: /v1.0/devices
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.$filter | string | Optional | Use the filter query parameter to retrieve just a subset of a collection. For guidance on using filter, see https://learn.microsoft.com/en-us/graph/filter-query-parameter |
parameters.$orderBy | string | Optional | Use the orderby query parameter to specify the sort order of the items returned from Microsoft Graph. |
parameters.$top | number | Optional | Sets the page size of results. |
Input Example
{"parameters":{"$filter":"string","$orderBy":"string","$top":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
@odata.nextLink | string | Response data |
value | array | Value for the parameter |
value.id | string | Unique identifier |
value.deletedDateTime | object | Value for the parameter |
value.accountEnabled | boolean | Value for the parameter |
value.approximateLastSignInDateTime | string | Value for the parameter |
value.complianceExpirationDateTime | object | Value for the parameter |
value.createdDateTime | string | Value for the parameter |
value.deviceCategory | object | Value for the parameter |
value.deviceId | string | Unique identifier |
value.deviceMetadata | object | Response data |
value.deviceOwnership | string | Value for the parameter |
value.deviceVersion | number | Value for the parameter |
value.displayName | string | Name of the resource |
value.domainName | object | Name of the resource |
value.enrollmentProfileName | object | Name of the resource |
value.enrollmentType | string | Type of the resource |
value.externalSourceName | object | Name of the resource |
value.isCompliant | boolean | Value for the parameter |
value.isManaged | boolean | Value for the parameter |
value.isRooted | boolean | Value for the parameter |
value.managementType | string | Type of the resource |
Output Example
{"@odata.context":"string","@odata.nextLink":"string","value":[{"id":"12345678-1234-1234-1234-123456789abc","deletedDateTime":{},"accountEnabled":true,"approximateLastSignInDateTime":"string","complianceExpirationDateTime":{},"createdDateTime":"string","deviceCategory":{},"deviceId":"string","deviceMetadata":{},"deviceOwnership":"string","deviceVersion":123,"displayName":"Example Name","domainName":{},"enrollmentProfileName":{},"enrollmentType":"string"}]}
Create Identity Directory Role Member
Adds a new member to a directory role in Microsoft Graph API using the role's unique ID and requires member's @odata.id.
Endpoint
- URL: /v1.0/directoryRoles/{{id}}/members/$ref
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Directory Role ID |
@odata.id | string | Optional | OData ID Type User |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"},"@odata.id":"string"}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"response_text":"string"}
Create Identity Directory Role Management
Creates a new directory role in Microsoft Graph API with specified display name, status, and permissions.
Endpoint
- URL: /v1.0/roleManagement/directory/roleDefinitions
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
displayName | string | Optional | The display name for the role definition |
isEnabled | boolean | Optional | Flag indicating if the role is enabled for assignment. If false, the role is not available for assignment |
rolePermissions | array | Optional | List of permissions included in the role |
rolePermissions.allowedResourceActions | array | Optional | Set of tasks that can be performed on a resource |
rolePermissions.condition | string | Optional | Optional constraints that must be met for the permission to be effective |
rolePermissions.excludedResourceActions | array | Optional | Set of tasks that may not be performed on a resource |
description | string | Optional | The description for the unifiedRoleDefinition |
id | string | Optional | The unique identifier for the role definition. Key, not nullable, Read-only. Inherited from entity |
isBuiltIn | boolean | Optional | Flag indicating whether the role definition is part of the default set included in Azure Active Directory (Azure AD) or a custom definition |
resourceScopes | array | Optional | List of the scopes or permissions the role definition applies to |
templateId | string | Optional | Custom template identifier that can be set when isBuiltIn is false but is read-only when isBuiltIn is true. This identifier is typically used if one needs an identifier to be the same across different directories |
version | string | Optional | Indicates version of the role definition |
Input Example
{"displayName":"Example Name","isEnabled":true,"rolePermissions":[{"allowedResourceActions":["string"],"condition":"string","excludedResourceActions":["string"]}],"description":"string","id":"12345678-1234-1234-1234-123456789abc","isBuiltIn":true,"resourceScopes":["string"],"templateId":"string","version":"string"}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
error | object | Error message if any |
error.code | string | Error message if any |
error.message | string | Response message |
error.innerError | object | Error message if any |
error.innerError.date | string | Error message if any |
error.innerError.request-id | string | Unique identifier |
error.innerError.client-request-id | string | Unique identifier |
Output Example
{"error":{"code":"string","message":"string","innerError":{"date":"2024-01-01T00:00:00Z","request-id":"string","client-request-id":"string"}}}
Add Directory Administrative Unit Member
Adds a member to a specified Directory Administrative Unit in Microsoft Graph API using the unit ID and member's @odata.id.
Endpoint
- URL: /v1.0/directory/administrativeUnits/{{id}}/members/$ref
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Unit ID |
@odata.id | string | Optional | The OData id of the user, group or DirectoryObject to add |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"},"@odata.id":"string"}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"response_text":"string"}
Delete Directory Administrative Unit Member
Removes a member from a specified Directory Administrative Unit in Microsoft Graph API using 'id' and 'memberId'.
Endpoint
- URL: /v1.0/directory/administrativeUnits/{{id}}/members/{{memberId}}/$ref
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Unit ID |
path_parameters.memberId | string | Required | Member ID |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc","memberId":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"response_text":"string"}
Get Directory Administrative Unit List
Retrieve a list of administrative units for directory segmentation and management via the Microsoft Graph API.
Endpoint
- URL: /v1.0/directory/administrativeUnits
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.filter | string | Optional | Use the filter query parameter to retrieve just a subset of a collection. For guidance on using filter, see https://learn.microsoft.com/en-us/graph/filter-query-parameter |
parameters.orderBy | string | Optional | Use the orderby query parameter to specify the sort order of the items returned from Microsoft Graph. |
parameters.top | number | Optional | Sets the page size of results. |
Input Example
{"parameters":{"filter":"string","orderBy":"string","top":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
value | array | Value for the parameter |
value.id | string | Unique identifier |
value.deletedDateTime | object | Value for the parameter |
value.displayName | string | Name of the resource |
value.description | object | Value for the parameter |
value.membershipRule | object | Value for the parameter |
value.membershipType | object | Type of the resource |
value.membershipRuleProcessingState | object | Value for the parameter |
value.visibility | object | Value for the parameter |
Output Example
{"@odata.context":"string","value":[{"id":"12345678-1234-1234-1234-123456789abc","deletedDateTime":{},"displayName":"Example Name","description":{},"membershipRule":{},"membershipType":{},"membershipRuleProcessingState":{},"visibility":{}}]}
Get Directory Administrative Unit Member
Retrieve details for a member within a specific Directory Administrative Unit in Microsoft Graph API by using 'id' and 'memberId'.
Endpoint
- URL: /v1.0/directory/administrativeUnits/{{id}}/members/{{memberId}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | ID |
path_parameters.memberId | string | Required | Member ID |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc","memberId":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
@odata.type | string | Response data |
id | string | Unique identifier |
businessPhones | array | Output field: businessPhones |
businessPhones.file_name | string | Name of the resource |
businessPhones.file | string | Output field: businessPhones.file |
displayName | string | Name of the resource |
givenName | string | Name of the resource |
jobTitle | object | Output field: jobTitle |
string | Output field: mail | |
mobilePhone | object | Output field: mobilePhone |
officeLocation | object | Output field: officeLocation |
preferredLanguage | string | Output field: preferredLanguage |
surname | object | Name of the resource |
userPrincipalName | string | Name of the resource |
Output Example
{"@odata.context":"string","@odata.type":"string","id":"12345678-1234-1234-1234-123456789abc","businessPhones":[{"file_name":"Example Name","file":"string"}],"displayName":"Example Name","givenName":"Example Name","jobTitle":{},"mail":"string","mobilePhone":{},"officeLocation":{},"preferredLanguage":"string","surname":{},"userPrincipalName":"Example Name"}
Get Directory Administrative Unit
Retrieve details of a specified Directory Administrative Unit in Microsoft Graph API using its unique ID.
Endpoint
- URL: /v1.0/directory/administrativeUnits/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Unit ID |
parameters.filter | string | Optional | Use the filter query parameter to retrieve just a subset of a collection. For guidance on using filter, see https://learn.microsoft.com/en-us/graph/filter-query-parameter |
parameters.orderBy | string | Optional | Use the orderby query parameter to specify the sort order of the items returned from Microsoft Graph. |
parameters.top | number | Optional | Sets the page size of results. |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"},"parameters":{"filter":"string","orderBy":"string","top":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
id | string | Unique identifier |
deletedDateTime | object | Time value |
displayName | string | Name of the resource |
description | object | Output field: description |
isMemberManagementRestricted | boolean | Output field: isMemberManagementRestricted |
visibility | object | Output field: visibility |
membershipRule | object | Output field: membershipRule |
membershipType | object | Type of the resource |
membershipRuleProcessingState | object | Output field: membershipRuleProcessingState |
Output Example
{"@odata.context":"string","id":"12345678-1234-1234-1234-123456789abc","deletedDateTime":{},"displayName":"Example Name","description":{},"isMemberManagementRestricted":true,"visibility":{},"membershipRule":{},"membershipType":{},"membershipRuleProcessingState":{}}
Delete Identity Directory Role Member
Removes a user from a directory role in Microsoft Graph API using the specified 'id' and 'memberId'.
Endpoint
- URL: /v1.0/directoryRoles/{{id}}/members/{{memberId}}/$ref
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Role ID |
path_parameters.memberId | string | Required | Member ID |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc","memberId":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
error | object | Error message if any |
error.code | string | Error message if any |
error.message | string | Response message |
error.innerError | object | Error message if any |
error.innerError.date | string | Error message if any |
error.innerError.request-id | string | Unique identifier |
error.innerError.client-request-id | string | Unique identifier |
Output Example
{"error":{"code":"string","message":"string","innerError":{"date":"2024-01-01T00:00:00Z","request-id":"string","client-request-id":"string"}}}
Get Identity Directory Role
Retrieve details for a specific directory role in Microsoft Graph API using the provided unique ID.
Endpoint
- URL: /v1.0/directoryRoles/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Directory Role ID |
parameters.count | string | Optional | Include a count of the total number of items in a collection alongside the page of data values returned from Microsoft Graph |
parameters.filter | string | Optional | Use the $filter query parameter to retrieve just a subset of a collection. For guidance on using $filter, see https://learn.microsoft.com/en-us/graph/filter-query-parameter |
parameters.orderby | string | Optional | To sort the results in ascending or descending order, append either asc or desc to the field name, separated by a space. |
parameters.top | number | Optional | Sets the page size of results |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"},"parameters":{"count":"false","filter":"string","orderby":"string","top":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
id | string | Unique identifier |
deletedDateTime | object | Time value |
description | string | Output field: description |
displayName | string | Name of the resource |
roleTemplateId | string | Unique identifier |
Output Example
{"@odata.context":"string","id":"12345678-1234-1234-1234-123456789abc","deletedDateTime":{},"description":"string","displayName":"Example Name","roleTemplateId":"string"}
Get Identity Directory Role Assignment Member
Retrieve directory role assignment details for a specified identity in Microsoft Graph API using the unique identifier.
Endpoint
- URL: /v1.0/roleManagement/directory/roleAssignments/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Role Assignment ID |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
error | object | Error message if any |
error.code | string | Error message if any |
error.message | string | Response message |
error.innerError | object | Error message if any |
error.innerError.date | string | Error message if any |
error.innerError.request-id | string | Unique identifier |
error.innerError.client-request-id | string | Unique identifier |
Output Example
{"error":{"code":"string","message":"string","innerError":{"date":"2024-01-01T00:00:00Z","request-id":"string","client-request-id":"string"}}}
Delete Identity Directory Role Management
Removes a specified directory role in Microsoft Graph API using the provided unique identifier.
Endpoint
- URL: /v1.0/roleManagement/directory/roleDefinitions/{{id}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Role Management ID |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
error | object | Error message if any |
error.code | string | Error message if any |
error.message | string | Response message |
error.innerError | object | Error message if any |
error.innerError.date | string | Error message if any |
error.innerError.request-id | string | Unique identifier |
error.innerError.client-request-id | string | Unique identifier |
Output Example
{"error":{"code":"ResourceNotFound","message":"Invalid version: rolemanagement","innerError":{"date":"2022-12-20T20:37:28","request-id":"14c4462e-7088-48de-adf6-d6283055090d","client-request-id":"14c4462e-7088-48de-adf6-d6283055090d"}}}
Delete Identity Directory Domain
Removes a specified domain from a Microsoft tenant using the unique domain ID provided in path parameters.
Endpoint
- URL: v1.0/domains/{{id}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Delete Identity Directory Domain action |
Input Example
{"path_parameters":{"id":"myradom.test.directory"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"response_text":"string"}
Get Identity Directory Domain
Retrieve details for a specific domain in Microsoft Graph API using the provided domain ID.
Endpoint
- URL: v1.0/domains/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Get Identity Directory Domain action |
Input Example
{"path_parameters":{"id":"myradom.test.directory"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
authenticationType | string | Type of the resource |
availabilityStatus | object | Status value |
id | string | Unique identifier |
isAdminManaged | boolean | Output field: isAdminManaged |
isDefault | boolean | Output field: isDefault |
isInitial | boolean | Output field: isInitial |
isRoot | boolean | Output field: isRoot |
isVerified | boolean | Output field: isVerified |
supportedServices | array | Output field: supportedServices |
supportedServices.file_name | string | Name of the resource |
supportedServices.file | string | Output field: supportedServices.file |
passwordValidityPeriodInDays | object | Unique identifier |
passwordNotificationWindowInDays | object | Output field: passwordNotificationWindowInDays |
state | object | Output field: state |
Output Example
{"@odata.context":"https://graph.microsoft.com/v1.0/$metadata#domains/$entity","authenticationType":"Managed","availabilityStatus":null,"id":"myradom.test.directory","isAdminManaged":true,"isDefault":false,"isInitial":false,"isRoot":false,"isVerified":false,"supportedServices":[],"passwordValidityPeriodInDays":null,"passwordNotificationWindowInDays":null,"state":null}
Get Identity Directory Domain List
Retrieve all configured domains within the Microsoft Graph API for identity and access management.
Endpoint
- URL: v1.0/domains
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.count | string | Optional | Include a count of the total number of items in a collection alongside the page of data values returned from Microsoft Graph |
parameters.filter | string | Optional | Use the $filter query parameter to retrieve just a subset of a collection. For guidance on using $filter, see https://learn.microsoft.com/en-us/graph/filter-query-parameter |
parameters.orderby | string | Optional | To sort the results in ascending or descending order, append either asc or desc to the field name, separated by a space. |
parameters.top | number | Optional | Sets the page size of results |
Input Example
{"parameters":{"count":"false","filter":"string","orderby":"string","top":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
value | array | Value for the parameter |
value.authenticationType | string | Type of the resource |
value.availabilityStatus | object | Status value |
value.id | string | Unique identifier |
value.isAdminManaged | boolean | Value for the parameter |
value.isDefault | boolean | Value for the parameter |
value.isInitial | boolean | Value for the parameter |
value.isRoot | boolean | Value for the parameter |
value.isVerified | boolean | Value for the parameter |
value.supportedServices | array | Value for the parameter |
value.passwordValidityPeriodInDays | number | Unique identifier |
value.passwordNotificationWindowInDays | number | Value for the parameter |
value.state | object | Value for the parameter |
Output Example
{"@odata.context":"https://graph.microsoft.com/v1.0/$metadata#domains","value":[{"authenticationType":"Managed","availabilityStatus":null,"id":"bestcompanyever.com","isAdminManaged":true,"isDefault":false,"isInitial":false,"isRoot":false,"isVerified":false,"supportedServices":[],"passwordValidityPeriodInDays":null,"passwordNotificationWindowInDays":null,"state":null},{"authenticationType":"Managed","availabilityStatus":null,"id":"swimlaneintegrations.onmicrosoft.com","isAdminManaged":true,"isDef...
Create Identity Directory Domain
Adds a new domain to the Microsoft Graph API tenant using the specified 'id' in the JSON body input.
Endpoint
- URL: v1.0/domains
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
authenticationType | string | Optional | Type of the resource |
availabilityStatus | string | Optional | Status value |
id | string | Optional | Unique identifier |
isAdminManaged | boolean | Optional | Parameter for Create Identity Directory Domain |
isDefault | boolean | Optional | Parameter for Create Identity Directory Domain |
isInitial | boolean | Optional | Parameter for Create Identity Directory Domain |
isRoot | boolean | Optional | Parameter for Create Identity Directory Domain |
isVerified | boolean | Optional | Parameter for Create Identity Directory Domain |
passwordNotificationWindowInDays | number | Optional | Parameter for Create Identity Directory Domain |
passwordValidityPeriodInDays | number | Optional | Unique identifier |
state | object | Optional | Parameter for Create Identity Directory Domain |
string | Optional | Response data | |
supportedServices | array | Optional | Parameter for Create Identity Directory Domain |
Input Example
{"authenticationType":"string","availabilityStatus":"active","id":"12345678-1234-1234-1234-123456789abc","isAdminManaged":true,"isDefault":true,"isInitial":true,"isRoot":true,"isVerified":true,"passwordNotificationWindowInDays":123,"passwordValidityPeriodInDays":123,"state":{"@odata.type":"string"},"supportedServices":["string"]}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
authenticationType | string | Type of the resource |
availabilityStatus | object | Status value |
id | string | Unique identifier |
isAdminManaged | boolean | Output field: isAdminManaged |
isDefault | boolean | Output field: isDefault |
isInitial | boolean | Output field: isInitial |
isRoot | boolean | Output field: isRoot |
isVerified | boolean | Output field: isVerified |
supportedServices | array | Output field: supportedServices |
supportedServices.file_name | string | Name of the resource |
supportedServices.file | string | Output field: supportedServices.file |
passwordValidityPeriodInDays | object | Unique identifier |
passwordNotificationWindowInDays | object | Output field: passwordNotificationWindowInDays |
state | object | Output field: state |
Output Example
{"@odata.context":"https://graph.microsoft.com/v1.0/$metadata#domains/$entity","authenticationType":"Managed","availabilityStatus":null,"id":"myradom.test.directory","isAdminManaged":true,"isDefault":false,"isInitial":false,"isRoot":false,"isVerified":false,"supportedServices":[],"passwordValidityPeriodInDays":null,"passwordNotificationWindowInDays":null,"state":null}
Get Identity Directory Object
Retrieves a specific directory object from Microsoft Graph API using the provided unique identifier.
Endpoint
- URL: /v1.0/directoryObjects/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Directory Object ID |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
@odata.type | string | Response data |
id | string | Unique identifier |
deletedDateTime | object | Time value |
classification | object | Output field: classification |
createdDateTime | string | Time value |
creationOptions | array | Output field: creationOptions |
description | string | Output field: description |
displayName | string | Name of the resource |
expirationDateTime | object | Time value |
groupTypes | array | Type of the resource |
isAssignableToRole | object | Output field: isAssignableToRole |
string | Output field: mail | |
mailEnabled | boolean | Output field: mailEnabled |
mailNickname | string | Name of the resource |
membershipRule | object | Output field: membershipRule |
membershipRuleProcessingState | object | Output field: membershipRuleProcessingState |
onPremisesDomainName | object | Name of the resource |
onPremisesLastSyncDateTime | object | Time value |
onPremisesNetBiosName | object | Name of the resource |
onPremisesSamAccountName | object | Name of the resource |
onPremisesSecurityIdentifier | object | Unique identifier |
onPremisesSyncEnabled | object | Output field: onPremisesSyncEnabled |
Output Example
{"@odata.context":"string","@odata.type":"string","id":"12345678-1234-1234-1234-123456789abc","deletedDateTime":{},"classification":{},"createdDateTime":"string","creationOptions":["string"],"description":"string","displayName":"Example Name","expirationDateTime":{},"groupTypes":["string"],"isAssignableToRole":{},"mail":"string","mailEnabled":true,"mailNickname":"Example Name"}
Get Identity Directory Role Members List
Retrieve a list of members assigned to a specific directory role in Microsoft Graph API using the 'role-id'.
Endpoint
- URL: v1.0/directoryRoles/{{role-id}}/members
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.role-id | string | Required | Parameters for the Get Identity Directory Role Members List action |
Input Example
{"path_parameters":{"role-id":"b8d0b017-384c-40cb-b37b-99ee5d3f8a8f"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
value | array | Value for the parameter |
string | Response data | |
value.id | string | Unique identifier |
value.businessPhones | array | Value for the parameter |
value.businessPhones.file_name | string | Name of the resource |
value.businessPhones.file | string | Value for the parameter |
value.displayName | string | Name of the resource |
value.givenName | string | Name of the resource |
value.jobTitle | object | Value for the parameter |
value.mail | string | Value for the parameter |
value.mobilePhone | object | Value for the parameter |
value.officeLocation | object | Value for the parameter |
value.preferredLanguage | object | Value for the parameter |
value.surname | string | Name of the resource |
value.userPrincipalName | string | Name of the resource |
Output Example
{"@odata.context":"string","value":[{"@odata.type":"string","id":"12345678-1234-1234-1234-123456789abc","businessPhones":[],"displayName":"Example Name","givenName":"Example Name","jobTitle":{},"mail":"string","mobilePhone":{},"officeLocation":{},"preferredLanguage":{},"surname":"Example Name","userPrincipalName":"Example Name"}]}
Retrieve Authentication Methods
Retrieve a user's authentication methods in Microsoft Graph API using their mail ID.
Endpoint
- URL: /v1.0/users/{{mailid}}/authentication/methods
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.mailid | string | Required | The account associated with the email. |
Input Example
{"path_parameters":{"mailid":"[email protected]"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
@microsoft.graph.tips | string | Output field: @microsoft.graph.tips |
value | array | Value for the parameter |
string | Response data | |
value.id | string | Unique identifier |
value.password | object | Value for the parameter |
value.createdDateTime | string | Value for the parameter |
value.secretKey | object | Value for the parameter |
Output Example
{"@odata.context":"https://graph.microsoft.com/v1.0/$metadata#users('integrations%40swimlaneintegra...","@microsoft.graph.tips":"Use $select to choose only the properties your app needs, as this can lead to pe...","value":[{"@odata.type":"#microsoft.graph.passwordAuthenticationMethod","id":"28c10230-6103-485e-b985-444c60001490","password":null,"createdDateTime":"2021-12-15T01:31:09Z"},{"@odata.type":"#microsoft.graph.softwareOathAuthenticationMethod","id":"c03db085-34e7-47bc-b7d6-b54069b6042f","...
Revoke Signin Sessions
Invalidates all refresh tokens and browser session cookies for a user to ensure secure sign-out via Microsoft Graph API.
Endpoint
- URL: v1.0/users/{{id}}/revokeSignInSessions
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | User ID |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
value | boolean | Value for the parameter |
Output Example
{"@odata.context":"https://graph.microsoft.com/v1.0/$metadata#Edm.Boolean","value":true}
Response Headers
Header | Description | Example |
|---|---|---|
Cache-Control | Directives for caching mechanisms | no-cache |
client-request-id | HTTP response header: client-request-id | 30bcb75d-a62f-85ad-90e1-d7d1978e9ca3 |
Content-Encoding | HTTP response header: Content-Encoding | gzip |
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Tue, 20 Dec 2022 20:37:28 GMT |
Deprecation | HTTP response header: Deprecation | ο»Ώ |
Link | HTTP response header: Link | ο»Ώ |
Location | The URL to redirect a page to | |
OData-Version | HTTP response header: OData-Version | 4.0 |
request-id | HTTP response header: request-id | b15e85c5-d517-4e9e-a99e-d32ec5057dd7 |
Strict-Transport-Security | HTTP response header: Strict-Transport-Security | max-age=31536000 |
Sunset | HTTP response header: Sunset | ο»Ώ |
Transfer-Encoding | HTTP response header: Transfer-Encoding | chunked |
Vary | HTTP response header: Vary | Accept-Encoding |
x-ms-ags-diagnostic | HTTP response header: x-ms-ags-diagnostic | {"ServerInfo":{"DataCenter":"Central India","Slice":"E","Ring":"3","ScaleUnit":"001","RoleInstance":"PN3PEPF000002A8"}} |
x-ms-resource-unit | HTTP response header: x-ms-resource-unit | 2 |