Microsoft Entra ID (formerly Azure AD) Domains.internal Domain Federation API
The domains.internalDomainFederation API from Microsoft Entra ID (formerly Azure AD) — 3 operation(s) for domains.internaldomainfederation.
The domains.internalDomainFederation API from Microsoft Entra ID (formerly Azure AD) — 3 operation(s) for domains.internaldomainfederation.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/azure-ad-domains-internaldomainfederation-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: Identity.DirectoryManagement Domains.internal Domain…
version: v1.0
servers:
- url: https://graph.microsoft.com/v1.0/
description: Core
security:
- azureaadv2: []
tags:
- name: domains.internalDomainFederation
paths:
/domains/{domain-id}/federationConfiguration:
get:
tags:
- domains.internalDomainFederation
summary: List internalDomainFederations
description: Read the properties of the internalDomainFederation objects for the domain. This API returns only one object in the collection.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/domain-list-federationconfiguration?view=graph-rest-1.0
operationId: domain_ListFederationConfiguration
parameters:
- name: domain-id
in: path
description: The unique identifier of domain
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: domain
- $ref: '#/components/parameters/top'
- $ref: '#/components/parameters/skip'
- $ref: '#/components/parameters/search'
- $ref: '#/components/parameters/filter'
- $ref: '#/components/parameters/count'
- name: $orderby
in: query
description: Order items by property values
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
- name: $select
in: query
description: Select properties to be returned
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
- name: $expand
in: query
description: Expand related entities
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
responses:
2XX:
$ref: '#/components/responses/microsoft.graph.internalDomainFederationCollectionResponse'
default:
$ref: '#/components/responses/error'
x-ms-pageable:
nextLinkName: '@odata.nextLink'
operationName: listMore
x-ms-docs-operation-type: operation
post:
tags:
- domains.internalDomainFederation
summary: Create internalDomainFederation
description: Create a new internalDomainFederation object.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/domain-post-federationconfiguration?view=graph-rest-1.0
operationId: domain_CreateFederationConfiguration
parameters:
- name: domain-id
in: path
description: The unique identifier of domain
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: domain
requestBody:
description: New navigation property
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.internalDomainFederation'
required: true
responses:
2XX:
description: Created navigation property.
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.internalDomainFederation'
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
/domains/{domain-id}/federationConfiguration/{internalDomainFederation-id}:
get:
tags:
- domains.internalDomainFederation
summary: Get internalDomainFederation
description: Read the properties and relationships of an internalDomainFederation object.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/internaldomainfederation-get?view=graph-rest-1.0
operationId: domain_GetFederationConfiguration
parameters:
- name: domain-id
in: path
description: The unique identifier of domain
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: domain
- name: internalDomainFederation-id
in: path
description: The unique identifier of internalDomainFederation
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: internalDomainFederation
- name: $select
in: query
description: Select properties to be returned
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
- name: $expand
in: query
description: Expand related entities
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
responses:
2XX:
description: Retrieved navigation property
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.internalDomainFederation'
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
patch:
tags:
- domains.internalDomainFederation
summary: Update internalDomainFederation
description: Update the properties of an internalDomainFederation object.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/internaldomainfederation-update?view=graph-rest-1.0
operationId: domain_UpdateFederationConfiguration
parameters:
- name: domain-id
in: path
description: The unique identifier of domain
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: domain
- name: internalDomainFederation-id
in: path
description: The unique identifier of internalDomainFederation
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: internalDomainFederation
requestBody:
description: New navigation property values
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.internalDomainFederation'
required: true
responses:
2XX:
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.internalDomainFederation'
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
delete:
tags:
- domains.internalDomainFederation
summary: Delete internalDomainFederation
description: Delete an internalDomainFederation object.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/internaldomainfederation-delete?view=graph-rest-1.0
operationId: domain_DeleteFederationConfiguration
parameters:
- name: domain-id
in: path
description: The unique identifier of domain
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: domain
- name: internalDomainFederation-id
in: path
description: The unique identifier of internalDomainFederation
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: internalDomainFederation
- name: If-Match
in: header
description: ETag
style: simple
schema:
type: string
responses:
2XX:
description: Success
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
/domains/{domain-id}/federationConfiguration/$count:
get:
tags:
- domains.internalDomainFederation
summary: Get the number of the resource
operationId: domain.federationConfiguration_GetCount
parameters:
- name: domain-id
in: path
description: The unique identifier of domain
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: domain
- $ref: '#/components/parameters/search'
- $ref: '#/components/parameters/filter'
responses:
2XX:
$ref: '#/components/responses/ODataCountResponse'
default:
$ref: '#/components/responses/error'
components:
responses:
error:
description: error
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError'
microsoft.graph.internalDomainFederationCollectionResponse:
description: Retrieved collection
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.internalDomainFederationCollectionResponse'
ODataCountResponse:
description: The count of the resource
content:
text/plain:
schema:
$ref: '#/components/schemas/ODataCountResponse'
schemas:
microsoft.graph.internalDomainFederation:
allOf:
- $ref: '#/components/schemas/microsoft.graph.samlOrWsFedProvider'
- title: internalDomainFederation
type: object
properties:
activeSignInUri:
type:
- string
- 'null'
description: URL of the endpoint used by active clients when authenticating with federated domains set up for single sign-on in Microsoft Entra ID. Corresponds to the ActiveLogOnUri property of the Set-EntraDomainFederationSettings PowerShell cmdlet.
federatedIdpMfaBehavior:
$ref: '#/components/schemas/microsoft.graph.federatedIdpMfaBehavior'
isSignedAuthenticationRequestRequired:
type:
- boolean
- 'null'
description: If true, when SAML authentication requests are sent to the federated SAML IdP, Microsoft Entra ID will sign those requests using the OrgID signing key. If false (default), the SAML authentication requests sent to the federated IdP aren't signed.
nextSigningCertificate:
type:
- string
- 'null'
description: Fallback token signing certificate that can also be used to sign tokens, for example when the primary signing certificate expires. Formatted as Base64 encoded strings of the public portion of the federated IdP's token signing certificate. Needs to be compatible with the X509Certificate2 class. Much like the signingCertificate, the nextSigningCertificate property is used if a rollover is required outside of the auto-rollover update, a new federation service is being set up, or if the new token signing certificate isn't present in the federation properties after the federation service certificate has been updated.
passwordResetUri:
type:
- string
- 'null'
promptLoginBehavior:
$ref: '#/components/schemas/microsoft.graph.promptLoginBehavior'
signingCertificateUpdateStatus:
$ref: '#/components/schemas/microsoft.graph.signingCertificateUpdateStatus'
signOutUri:
type:
- string
- 'null'
description: URI that clients are redirected to when they sign out of Microsoft Entra services. Corresponds to the LogOffUri property of the Set-EntraDomainFederationSettings PowerShell cmdlet.
additionalProperties:
type: object
microsoft.graph.ODataErrors.MainError:
required:
- code
- message
type: object
properties:
code:
type: string
message:
type: string
x-ms-primary-error-message: true
target:
type:
- string
- 'null'
details:
type: array
items:
$ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails'
innerError:
$ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError'
additionalProperties:
type: object
ODataCountResponse:
type: integer
format: int32
microsoft.graph.ODataErrors.InnerError:
type: object
additionalProperties:
type: object
description: The structure of this object is service-specific
microsoft.graph.identityProviderBase:
allOf:
- $ref: '#/components/schemas/microsoft.graph.entity'
- title: identityProviderBase
type: object
properties:
displayName:
type:
- string
- 'null'
description: The display name of the identity provider.
additionalProperties:
type: object
microsoft.graph.ODataErrors.ODataError:
required:
- error
type: object
properties:
error:
$ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError'
additionalProperties:
type: object
microsoft.graph.samlOrWsFedProvider:
allOf:
- $ref: '#/components/schemas/microsoft.graph.identityProviderBase'
- title: samlOrWsFedProvider
type: object
properties:
issuerUri:
type:
- string
- 'null'
description: Issuer URI of the federation server.
metadataExchangeUri:
type:
- string
- 'null'
description: URI of the metadata exchange endpoint used for authentication from rich client applications.
passiveSignInUri:
type:
- string
- 'null'
description: URI that web-based clients are directed to when signing in to Microsoft Entra services.
preferredAuthenticationProtocol:
$ref: '#/components/schemas/microsoft.graph.authenticationProtocol'
signingCertificate:
type:
- string
- 'null'
description: 'Current certificate used to sign tokens passed to the Microsoft identity platform. The certificate is formatted as a Base64 encoded string of the public portion of the federated IdP''s token signing certificate and must be compatible with the X509Certificate2 class. This property is used in the following scenarios: if a rollover is required outside of the autorollover update a new federation service is being set up if the new token signing certificate isn''t present in the federation properties after the federation service certificate has been updated. Microsoft Entra ID updates certificates via an autorollover process in which it attempts to retrieve a new certificate from the federation service metadata, 30 days before expiry of the current certificate. If a new certificate isn''t available, Microsoft Entra ID monitors the metadata daily and will update the federation settings for the domain when a new certificate is available.'
additionalProperties:
type: object
microsoft.graph.ODataErrors.ErrorDetails:
required:
- code
- message
type: object
properties:
code:
type: string
message:
type: string
target:
type:
- string
- 'null'
additionalProperties:
type: object
microsoft.graph.promptLoginBehavior:
title: promptLoginBehavior
enum:
- translateToFreshPasswordAuthentication
- nativeSupport
- disabled
- unknownFutureValue
type: string
microsoft.graph.internalDomainFederationCollectionResponse:
title: Collection of internalDomainFederation
type: object
properties:
value:
type: array
items:
$ref: '#/components/schemas/microsoft.graph.internalDomainFederation'
'@odata.nextLink':
type:
- string
- 'null'
additionalProperties:
type: object
microsoft.graph.entity:
title: entity
type: object
properties:
id:
type: string
description: The unique identifier for an entity. Read-only.
additionalProperties:
type: object
microsoft.graph.authenticationProtocol:
title: authenticationProtocol
enum:
- wsFed
- saml
- unknownFutureValue
type: string
microsoft.graph.signingCertificateUpdateStatus:
title: signingCertificateUpdateStatus
type: object
properties:
certificateUpdateResult:
type:
- string
- 'null'
description: Status of the last certificate update. Read-only. For a list of statuses, see certificateUpdateResult status.
lastRunDateTime:
pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
type:
- string
- 'null'
description: Date and time in ISO 8601 format and in UTC time when the certificate was last updated. Read-only.
format: date-time
additionalProperties:
type: object
microsoft.graph.federatedIdpMfaBehavior:
title: federatedIdpMfaBehavior
enum:
- acceptIfMfaDoneByFederatedIdp
- enforceMfaByFederatedIdp
- rejectMfaByFederatedIdp
- unknownFutureValue
type: string
parameters:
filter:
name: $filter
in: query
description: Filter items by property values
style: form
explode: false
schema:
type: string
search:
name: $search
in: query
description: Search items by search phrases
style: form
explode: false
schema:
type: string
count:
name: $count
in: query
description: Include count of items
style: form
explode: false
schema:
type: boolean
skip:
name: $skip
in: query
description: Skip the first n items
style: form
explode: false
schema:
minimum: 0
type: integer
top:
name: $top
in: query
description: Show only the first n items
style: form
explode: false
schema:
minimum: 0
type: integer
example: 50
securitySchemes:
azureaadv2:
type: oauth2
flows:
authorizationCode:
authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize
tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token
scopes: {}