Microsoft Entra ID (formerly Azure AD) Groups.app Role Assignment API

The groups.appRoleAssignment API from Microsoft Entra ID (formerly Azure AD) — 3 operation(s) for groups.approleassignment.

Operations 6

GET /groups/{group-id}/appRoleAssignments List appRoleAssignments granted to a group #
POST /groups/{group-id}/appRoleAssignments Grant an appRoleAssignment to a group #
GET /groups/{group-id}/appRoleAssignments/{appRoleAssignment-id} Get appRoleAssignments from groups #
PATCH /groups/{group-id}/appRoleAssignments/{appRoleAssignment-id} Update the navigation property appRoleAssignments in groups #
DELETE /groups/{group-id}/appRoleAssignments/{appRoleAssignment-id} Delete appRoleAssignment #
GET /groups/{group-id}/appRoleAssignments/$count Get the number of the resource #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/azure-ad-groups-approleassignment-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

azure-ad-groups-approleassignment-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Applications Groups.app Role Assignment API
  version: v1.0
servers:
- url: https://graph.microsoft.com/v1.0/
  description: Core
security:
- azureaadv2: []
tags:
- name: groups.appRoleAssignment
paths:
  /groups/{group-id}/appRoleAssignments:
    get:
      tags:
      - groups.appRoleAssignment
      summary: List appRoleAssignments granted to a group
      description: Retrieve the list of appRoleAssignment that have been granted to a group.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/group-list-approleassignments?view=graph-rest-1.0
      operationId: group_ListAppRoleAssignment
      parameters:
      - name: group-id
        in: path
        description: The unique identifier of group
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: group
      - name: ConsistencyLevel
        in: header
        description: 'Indicates the requested consistency level. Documentation URL: https://docs.microsoft.com/graph/aad-advanced-queries'
        style: simple
        schema:
          type: string
        examples:
          example-1:
            description: $search and $count queries require the client to set the ConsistencyLevel HTTP header to 'eventual'.
            value: eventual
      - $ref: '#/components/parameters/top'
      - $ref: '#/components/parameters/skip'
      - $ref: '#/components/parameters/search'
      - $ref: '#/components/parameters/filter'
      - $ref: '#/components/parameters/count'
      - name: $orderby
        in: query
        description: Order items by property values
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          $ref: '#/components/responses/microsoft.graph.appRoleAssignmentCollectionResponse'
        default:
          $ref: '#/components/responses/error'
      x-ms-pageable:
        nextLinkName: '@odata.nextLink'
        operationName: listMore
      x-ms-docs-operation-type: operation
    post:
      tags:
      - groups.appRoleAssignment
      summary: Grant an appRoleAssignment to a group
      description: 'Use this API to assign an app role to a security group. All direct members of the group will be considered assigned. Security groups with dynamic memberships are supported. To grant an app role assignment to a group, you need three identifiers: Additional licenses might be required to use a group to manage access to applications.'
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/group-post-approleassignments?view=graph-rest-1.0
      operationId: group_CreateAppRoleAssignment
      parameters:
      - name: group-id
        in: path
        description: The unique identifier of group
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: group
      requestBody:
        description: New navigation property
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.appRoleAssignment'
        required: true
      responses:
        2XX:
          description: Created navigation property.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.appRoleAssignment'
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
  /groups/{group-id}/appRoleAssignments/{appRoleAssignment-id}:
    get:
      tags:
      - groups.appRoleAssignment
      summary: Get appRoleAssignments from groups
      description: Represents the app roles granted to a group for an application. Supports $expand.
      operationId: group_GetAppRoleAssignment
      parameters:
      - name: group-id
        in: path
        description: The unique identifier of group
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: group
      - name: appRoleAssignment-id
        in: path
        description: The unique identifier of appRoleAssignment
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: appRoleAssignment
      - name: ConsistencyLevel
        in: header
        description: 'Indicates the requested consistency level. Documentation URL: https://docs.microsoft.com/graph/aad-advanced-queries'
        style: simple
        schema:
          type: string
        examples:
          example-1:
            description: $search and $count queries require the client to set the ConsistencyLevel HTTP header to 'eventual'.
            value: eventual
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          description: Retrieved navigation property
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.appRoleAssignment'
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    patch:
      tags:
      - groups.appRoleAssignment
      summary: Update the navigation property appRoleAssignments in groups
      operationId: group_UpdateAppRoleAssignment
      parameters:
      - name: group-id
        in: path
        description: The unique identifier of group
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: group
      - name: appRoleAssignment-id
        in: path
        description: The unique identifier of appRoleAssignment
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: appRoleAssignment
      requestBody:
        description: New navigation property values
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.appRoleAssignment'
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.appRoleAssignment'
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    delete:
      tags:
      - groups.appRoleAssignment
      summary: Delete appRoleAssignment
      description: Deletes an appRoleAssignment that a group has been granted.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/group-delete-approleassignments?view=graph-rest-1.0
      operationId: group_DeleteAppRoleAssignment
      parameters:
      - name: group-id
        in: path
        description: The unique identifier of group
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: group
      - name: appRoleAssignment-id
        in: path
        description: The unique identifier of appRoleAssignment
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: appRoleAssignment
      - name: If-Match
        in: header
        description: ETag
        style: simple
        schema:
          type: string
      responses:
        2XX:
          description: Success
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
  /groups/{group-id}/appRoleAssignments/$count:
    get:
      tags:
      - groups.appRoleAssignment
      summary: Get the number of the resource
      operationId: group.appRoleAssignment_GetCount
      parameters:
      - name: group-id
        in: path
        description: The unique identifier of group
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: group
      - name: ConsistencyLevel
        in: header
        description: 'Indicates the requested consistency level. Documentation URL: https://docs.microsoft.com/graph/aad-advanced-queries'
        style: simple
        schema:
          type: string
        examples:
          example-1:
            description: $search and $count queries require the client to set the ConsistencyLevel HTTP header to 'eventual'.
            value: eventual
      - $ref: '#/components/parameters/search'
      - $ref: '#/components/parameters/filter'
      responses:
        2XX:
          $ref: '#/components/responses/ODataCountResponse'
        default:
          $ref: '#/components/responses/error'
components:
  responses:
    error:
      description: error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError'
    microsoft.graph.appRoleAssignmentCollectionResponse:
      description: Retrieved collection
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/microsoft.graph.appRoleAssignmentCollectionResponse'
    ODataCountResponse:
      description: The count of the resource
      content:
        text/plain:
          schema:
            $ref: '#/components/schemas/ODataCountResponse'
  schemas:
    microsoft.graph.ODataErrors.MainError:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
        message:
          type: string
          x-ms-primary-error-message: true
        target:
          type:
          - string
          - 'null'
        details:
          type: array
          items:
            $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails'
        innerError:
          $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError'
      additionalProperties:
        type: object
    microsoft.graph.directoryObject:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: directoryObject
        type: object
        properties:
          deletedDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type:
            - string
            - 'null'
            description: Date and time when this object was deleted. Always null when the object hasn't been deleted.
            format: date-time
        additionalProperties:
          type: object
    ODataCountResponse:
      type: integer
      format: int32
    microsoft.graph.ODataErrors.ODataError:
      required:
      - error
      type: object
      properties:
        error:
          $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError'
      additionalProperties:
        type: object
    microsoft.graph.entity:
      title: entity
      type: object
      properties:
        id:
          type: string
          description: The unique identifier for an entity. Read-only.
      additionalProperties:
        type: object
    microsoft.graph.appRoleAssignmentCollectionResponse:
      title: Collection of appRoleAssignment
      type: object
      properties:
        value:
          type: array
          items:
            $ref: '#/components/schemas/microsoft.graph.appRoleAssignment'
        '@odata.nextLink':
          type:
          - string
          - 'null'
      additionalProperties:
        type: object
    microsoft.graph.ODataErrors.InnerError:
      type: object
      additionalProperties:
        type: object
      description: The structure of this object is service-specific
    microsoft.graph.ODataErrors.ErrorDetails:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
        message:
          type: string
        target:
          type:
          - string
          - 'null'
      additionalProperties:
        type: object
    microsoft.graph.appRoleAssignment:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.directoryObject'
      - title: appRoleAssignment
        type: object
        properties:
          appRoleId:
            pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$
            type: string
            description: The identifier (id) for the app role that's assigned to the principal. This app role must be exposed in the appRoles property on the resource application's service principal (resourceId). If the resource application hasn't declared any app roles, a default app role ID of 00000000-0000-0000-0000-000000000000 can be specified to signal that the principal is assigned to the resource app without any specific app roles. Required on create.
            format: uuid
          createdDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type:
            - string
            - 'null'
            description: The time when the app role assignment was created. The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. Read-only.
            format: date-time
          principalDisplayName:
            type:
            - string
            - 'null'
            description: The display name of the user, group, or service principal that was granted the app role assignment. Maximum length is 256 characters. Read-only. Supports $filter (eq and startswith).
          principalId:
            pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$
            type:
            - string
            - 'null'
            description: The unique identifier (id) for the user, security group, or service principal being granted the app role. Security groups with dynamic memberships are supported. Required on create.
            format: uuid
          principalType:
            type:
            - string
            - 'null'
            description: The type of the assigned principal. This can either be User, Group, or ServicePrincipal. Read-only.
          resourceDisplayName:
            type:
            - string
            - 'null'
            description: The display name of the resource app's service principal to which the assignment is made. Maximum length is 256 characters.
          resourceId:
            pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$
            type:
            - string
            - 'null'
            description: The unique identifier (id) for the resource service principal for which the assignment is made. Required on create. Supports $filter (eq only).
            format: uuid
        additionalProperties:
          type: object
  parameters:
    count:
      name: $count
      in: query
      description: Include count of items
      style: form
      explode: false
      schema:
        type: boolean
    filter:
      name: $filter
      in: query
      description: Filter items by property values
      style: form
      explode: false
      schema:
        type: string
    search:
      name: $search
      in: query
      description: Search items by search phrases
      style: form
      explode: false
      schema:
        type: string
    top:
      name: $top
      in: query
      description: Show only the first n items
      style: form
      explode: false
      schema:
        minimum: 0
        type: integer
      example: 50
    skip:
      name: $skip
      in: query
      description: Skip the first n items
      style: form
      explode: false
      schema:
        minimum: 0
        type: integer
  securitySchemes:
    azureaadv2:
      type: oauth2
      flows:
        authorizationCode:
          authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize
          tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token
          scopes: {}