Microsoft Entra ID (formerly Azure AD) Directory Roles.directory Role.Actions API

The directoryRoles.directoryRole.Actions API from Microsoft Entra ID (formerly Azure AD) — 8 operation(s) for directoryroles.directoryrole.actions.

Operations 8

POST /directoryRoles/{directoryRole-id}/microsoft.graph.checkMemberGroups Invoke action checkMemberGroups #
POST /directoryRoles/{directoryRole-id}/microsoft.graph.checkMemberObjects Invoke action checkMemberObjects #
POST /directoryRoles/{directoryRole-id}/microsoft.graph.getMemberGroups Invoke action getMemberGroups #
POST /directoryRoles/{directoryRole-id}/microsoft.graph.getMemberObjects Invoke action getMemberObjects #
POST /directoryRoles/{directoryRole-id}/microsoft.graph.restore Invoke action restore #
POST /directoryRoles/microsoft.graph.getAvailableExtensionProperties Invoke action getAvailableExtensionProperties #
POST /directoryRoles/microsoft.graph.getByIds Invoke action getByIds #
POST /directoryRoles/microsoft.graph.validateProperties Invoke action validateProperties #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/azure-ad-directoryroles-directoryrole-actions-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

azure-ad-directoryroles-directoryrole-actions-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Identity.DirectoryManagement Directory Roles.directory…
  version: v1.0
servers:
- url: https://graph.microsoft.com/v1.0/
  description: Core
security:
- azureaadv2: []
tags:
- name: directoryRoles.directoryRole.Actions
paths:
  /directoryRoles/{directoryRole-id}/microsoft.graph.checkMemberGroups:
    post:
      tags:
      - directoryRoles.directoryRole.Actions
      summary: Invoke action checkMemberGroups
      description: 'Check for membership in a specified list of group IDs, and return from that list the IDs of groups where a specified object is a member. The specified object can be of one of the following types:

        - user

        - group

        - service principal

        - organizational contact

        - device

        - directory object This function is transitive. You can check up to a maximum of 20 groups per request. This function supports all groups provisioned in Microsoft Entra ID. Because Microsoft 365 groups cannot contain other groups, membership in a Microsoft 365 group is always direct.'
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/directoryobject-checkmembergroups?view=graph-rest-1.0
      operationId: directoryRole_checkMemberGroup
      parameters:
      - name: directoryRole-id
        in: path
        description: The unique identifier of directoryRole
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: directoryRole
      requestBody:
        description: Action parameters
        content:
          application/json:
            schema:
              type: object
              properties:
                groupIds:
                  type: array
                  items:
                    type: string
              additionalProperties:
                type: object
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  value:
                    type: array
                    items:
                      type: string
                  '@odata.nextLink':
                    type:
                    - string
                    - 'null'
                additionalProperties:
                  type: object
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
      x-ms-pageable:
        nextLinkName: '@odata.nextLink'
        operationName: listMore
  /directoryRoles/{directoryRole-id}/microsoft.graph.checkMemberObjects:
    post:
      tags:
      - directoryRoles.directoryRole.Actions
      summary: Invoke action checkMemberObjects
      operationId: directoryRole_checkMemberObject
      parameters:
      - name: directoryRole-id
        in: path
        description: The unique identifier of directoryRole
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: directoryRole
      requestBody:
        description: Action parameters
        content:
          application/json:
            schema:
              type: object
              properties:
                ids:
                  type: array
                  items:
                    type: string
              additionalProperties:
                type: object
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  value:
                    type: array
                    items:
                      type: string
                  '@odata.nextLink':
                    type:
                    - string
                    - 'null'
                additionalProperties:
                  type: object
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
      x-ms-pageable:
        nextLinkName: '@odata.nextLink'
        operationName: listMore
  /directoryRoles/{directoryRole-id}/microsoft.graph.getMemberGroups:
    post:
      tags:
      - directoryRoles.directoryRole.Actions
      summary: Invoke action getMemberGroups
      description: Return all the group IDs for the groups that the specified user, group, service principal, organizational contact, device, or directory object is a member of. This function is transitive. This API returns up to 11,000 group IDs. If more than 11,000 results are available, it returns a 400 Bad Request error with the DirectoryResultSizeLimitExceeded error code. If you get the DirectoryResultSizeLimitExceeded error code, use the List group transitive memberOf API instead.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/directoryobject-getmembergroups?view=graph-rest-1.0
      operationId: directoryRole_getMemberGroup
      parameters:
      - name: directoryRole-id
        in: path
        description: The unique identifier of directoryRole
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: directoryRole
      requestBody:
        description: Action parameters
        content:
          application/json:
            schema:
              type: object
              properties:
                securityEnabledOnly:
                  type:
                  - boolean
                  - 'null'
                  default: false
              additionalProperties:
                type: object
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  value:
                    type: array
                    items:
                      type: string
                  '@odata.nextLink':
                    type:
                    - string
                    - 'null'
                additionalProperties:
                  type: object
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
      x-ms-pageable:
        nextLinkName: '@odata.nextLink'
        operationName: listMore
  /directoryRoles/{directoryRole-id}/microsoft.graph.getMemberObjects:
    post:
      tags:
      - directoryRoles.directoryRole.Actions
      summary: Invoke action getMemberObjects
      description: 'Return all IDs for the groups, administrative units, and directory roles that an object of one of the following types is a member of:

        - user

        - group

        - service principal

        - organizational contact

        - device

        - directory object This function is transitive. Only users and role-enabled groups can be members of directory roles.'
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/directoryobject-getmemberobjects?view=graph-rest-1.0
      operationId: directoryRole_getMemberObject
      parameters:
      - name: directoryRole-id
        in: path
        description: The unique identifier of directoryRole
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: directoryRole
      requestBody:
        description: Action parameters
        content:
          application/json:
            schema:
              type: object
              properties:
                securityEnabledOnly:
                  type:
                  - boolean
                  - 'null'
                  default: false
              additionalProperties:
                type: object
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  value:
                    type: array
                    items:
                      type: string
                  '@odata.nextLink':
                    type:
                    - string
                    - 'null'
                additionalProperties:
                  type: object
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
      x-ms-pageable:
        nextLinkName: '@odata.nextLink'
        operationName: listMore
  /directoryRoles/{directoryRole-id}/microsoft.graph.restore:
    post:
      tags:
      - directoryRoles.directoryRole.Actions
      summary: Invoke action restore
      description: 'Restore a recently deleted directory object from deleted items. The following types are supported:

        - administrativeUnit

        - application

        - agentIdentityBlueprint

        - agentIdentity

        - agentIdentityBlueprintPrincipal

        - agentUser

        - certificateBasedAuthPki

        - certificateAuthorityDetail

        - group

        - servicePrincipal

        - user If an item is accidentally deleted, you can fully restore the item. Additionally, restoring an application doesn''t automatically restore the associated service principal automatically. You must call this API to explicitly restore the deleted service principal. A recently deleted item remains available for up to 30 days. After 30 days, the item is permanently deleted.'
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/directory-deleteditems-restore?view=graph-rest-1.0
      operationId: directoryRole_restore
      parameters:
      - name: directoryRole-id
        in: path
        description: The unique identifier of directoryRole
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: directoryRole
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.directoryObject'
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
  /directoryRoles/microsoft.graph.getAvailableExtensionProperties:
    post:
      tags:
      - directoryRoles.directoryRole.Actions
      summary: Invoke action getAvailableExtensionProperties
      description: 'Return all directory extension definitions that are registered in a directory, including through multitenant apps. The following entities support extension properties:'
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/directoryobject-getavailableextensionproperties?view=graph-rest-1.0
      operationId: directoryRole_getAvailableExtensionProperty
      requestBody:
        description: Action parameters
        content:
          application/json:
            schema:
              type: object
              properties:
                isSyncedFromOnPremises:
                  type:
                  - boolean
                  - 'null'
                  default: false
              additionalProperties:
                type: object
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                title: Collection of extensionProperty
                type: object
                properties:
                  value:
                    type: array
                    items:
                      $ref: '#/components/schemas/microsoft.graph.extensionProperty'
                  '@odata.nextLink':
                    type:
                    - string
                    - 'null'
                additionalProperties:
                  type: object
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
      x-ms-pageable:
        nextLinkName: '@odata.nextLink'
        operationName: listMore
  /directoryRoles/microsoft.graph.getByIds:
    post:
      tags:
      - directoryRoles.directoryRole.Actions
      summary: Invoke action getByIds
      description: 'Return the directory objects specified in a list of IDs. Only a subset of user properties are returned by default in v1.0. Some common uses for this function are to:'
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/directoryobject-getbyids?view=graph-rest-1.0
      operationId: directoryRole_getGraphBPreId
      requestBody:
        description: Action parameters
        content:
          application/json:
            schema:
              type: object
              properties:
                ids:
                  type: array
                  items:
                    type: string
                types:
                  type: array
                  items:
                    type:
                    - string
                    - 'null'
              additionalProperties:
                type: object
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                title: Collection of directoryObject
                type: object
                properties:
                  value:
                    type: array
                    items:
                      $ref: '#/components/schemas/microsoft.graph.directoryObject'
                  '@odata.nextLink':
                    type:
                    - string
                    - 'null'
                additionalProperties:
                  type: object
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
      x-ms-pageable:
        nextLinkName: '@odata.nextLink'
        operationName: listMore
  /directoryRoles/microsoft.graph.validateProperties:
    post:
      tags:
      - directoryRoles.directoryRole.Actions
      summary: Invoke action validateProperties
      description: 'Validate that a Microsoft 365 group''s display name or mail nickname complies with naming policies. Clients can use this API to determine whether a display name or mail nickname is valid before trying to create a Microsoft 365 group. To validate the properties of an existing group, use the group: validateProperties function. The following policy validations are performed for the display name and mail nickname properties:

        1. Validate the prefix and suffix naming policy

        2. Validate the custom banned words policy

        3. Validate that the mail nickname is unique This API only returns the first validation failure that is encountered. If the properties fail multiple validations, only the first validation failure is returned. However, you can validate both the mail nickname and the display name and receive a collection of validation errors if you''re only validating the prefix and suffix naming policy. To learn more about configuring naming policies, see Configure naming policy.'
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/directoryobject-validateproperties?view=graph-rest-1.0
      operationId: directoryRole_validateProperty
      requestBody:
        description: Action parameters
        content:
          application/json:
            schema:
              type: object
              properties:
                entityType:
                  type:
                  - string
                  - 'null'
                displayName:
                  type:
                  - string
                  - 'null'
                mailNickname:
                  type:
                  - string
                  - 'null'
                onBehalfOfUserId:
                  pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$
                  type:
                  - string
                  - 'null'
                  format: uuid
              additionalProperties:
                type: object
        required: true
      responses:
        2XX:
          description: Success
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
components:
  responses:
    error:
      description: error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError'
  schemas:
    microsoft.graph.extensionProperty:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.directoryObject'
      - title: extensionProperty
        type: object
        properties:
          appDisplayName:
            type:
            - string
            - 'null'
            description: Display name of the application object on which this extension property is defined. Read-only.
          dataType:
            type: string
            description: Specifies the data type of the value the extension property can hold. Following values are supported. Binary - 256 bytes maximumBooleanDateTime - Must be specified in ISO 8601 format. Will be stored in UTC.Integer - 32-bit value.LargeInteger - 64-bit value.String - 256 characters maximumNot nullable. For multivalued directory extensions, these limits apply per value in the collection.
          isMultiValued:
            type: boolean
            description: 'Defines the directory extension as a multi-valued property. When true, the directory extension property can store a collection of objects of the dataType; for example, a collection of string types such as ''extensionb7b1c57b532f40b8b5ed4b7a7ba67401jobGroupTracker'': [''String 1'', ''String 2'']. The default value is false. Supports $filter (eq).'
          isSyncedFromOnPremises:
            type:
            - boolean
            - 'null'
            description: Indicates if this extension property was synced from on-premises active directory using Microsoft Entra Connect. Read-only.
          name:
            type: string
            description: Name of the extension property. Not nullable. Supports $filter (eq).
          targetObjects:
            type: array
            items:
              type: string
            description: Following values are supported. Not nullable. UserGroupAdministrativeUnitApplicationDeviceOrganization
        additionalProperties:
          type: object
    microsoft.graph.ODataErrors.MainError:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
        message:
          type: string
          x-ms-primary-error-message: true
        target:
          type:
          - string
          - 'null'
        details:
          type: array
          items:
            $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails'
        innerError:
          $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError'
      additionalProperties:
        type: object
    microsoft.graph.ODataErrors.ODataError:
      required:
      - error
      type: object
      properties:
        error:
          $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError'
      additionalProperties:
        type: object
    microsoft.graph.entity:
      title: entity
      type: object
      properties:
        id:
          type: string
          description: The unique identifier for an entity. Read-only.
      additionalProperties:
        type: object
    microsoft.graph.ODataErrors.InnerError:
      type: object
      additionalProperties:
        type: object
      description: The structure of this object is service-specific
    microsoft.graph.ODataErrors.ErrorDetails:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
        message:
          type: string
        target:
          type:
          - string
          - 'null'
      additionalProperties:
        type: object
    microsoft.graph.directoryObject:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: directoryObject
        type: object
        properties:
          deletedDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type:
            - string
            - 'null'
            description: Date and time when this object was deleted. Always null when the object hasn't been deleted.
            format: date-time
        additionalProperties:
          type: object
  securitySchemes:
    azureaadv2:
      type: oauth2
      flows:
        authorizationCode:
          authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize
          tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token
          scopes: {}