# Microsoft Entra ID (formerly Azure AD) Identity.conditional Access Root API

**Canonical:** https://apis.io/apis/azure-ad/azure-ad-identity-conditionalaccessroot-api/  
**Provider:** Microsoft Entra ID (formerly Azure AD) — https://apis.io/providers/azure-ad/  
**Base URL:** https://login.microsoftonline.com  
**Documentation:** https://learn.microsoft.com/en-us/azure/active-directory-b2c/

Microsoft Entra ID (formerly Azure AD) Identity.conditional Access Root API is one of 186 APIs that [Microsoft Entra ID (formerly Azure AD)](https://apis.io/providers/azure-ad/) publishes on the [APIs.io](https://apis.io/) network, described by a machine-readable OpenAPI specification. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, authentication docs, and a changelog.

The identity.conditionalAccessRoot API from Microsoft Entra ID (formerly Azure AD) — 36 operation(s) for identity.conditionalaccessroot.

## Operations (60 of 64)

| Method | Path | Summary |
|---|---|---|
| GET | `/identity/conditionalAccess/authenticationContextClassReferences` | List authenticationContextClassReferences |
| POST | `/identity/conditionalAccess/authenticationContextClassReferences` | Create new navigation property to authenticationContextClassReferences for… |
| GET | `/identity/conditionalAccess/authenticationContextClassReferences/{authenticationContextClassReference-id}` | Get authenticationContextClassReference |
| PATCH | `/identity/conditionalAccess/authenticationContextClassReferences/{authenticationContextClassReference-id}` | Create or Update authenticationContextClassReference |
| DELETE | `/identity/conditionalAccess/authenticationContextClassReferences/{authenticationContextClassReference-id}` | Delete authenticationContextClassReference |
| GET | `/identity/conditionalAccess/authenticationContextClassReferences/$count` | Get the number of the resource |
| GET | `/identity/conditionalAccess/authenticationStrength` | Get authenticationStrength from identity |
| PATCH | `/identity/conditionalAccess/authenticationStrength` | Update the navigation property authenticationStrength in identity |
| DELETE | `/identity/conditionalAccess/authenticationStrength` | Delete navigation property authenticationStrength for identity |
| GET | `/identity/conditionalAccess/authenticationStrength/authenticationMethodModes` | List authenticationMethodModes |
| POST | `/identity/conditionalAccess/authenticationStrength/authenticationMethodModes` | Create new navigation property to authenticationMethodModes for identity |
| GET | `/identity/conditionalAccess/authenticationStrength/authenticationMethodModes/{authenticationMethodModeDetail-id}` | Get authenticationMethodModes from identity |
| PATCH | `/identity/conditionalAccess/authenticationStrength/authenticationMethodModes/{authenticationMethodModeDetail-id}` | Update the navigation property authenticationMethodModes in identity |
| DELETE | `/identity/conditionalAccess/authenticationStrength/authenticationMethodModes/{authenticationMethodModeDetail-id}` | Delete navigation property authenticationMethodModes for identity |
| GET | `/identity/conditionalAccess/authenticationStrength/authenticationMethodModes/$count` | Get the number of the resource |
| GET | `/identity/conditionalAccess/authenticationStrength/policies` | Get policies from identity |
| POST | `/identity/conditionalAccess/authenticationStrength/policies` | Create new navigation property to policies for identity |
| GET | `/identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}` | Get policies from identity |
| PATCH | `/identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}` | Update the navigation property policies in identity |
| DELETE | `/identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}` | Delete navigation property policies for identity |
| GET | `/identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}/combinationConfigurations` | List combinationConfigurations |
| POST | `/identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}/combinationConfigurations` | Create authenticationCombinationConfiguration |
| GET | `/identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}/combinationConfigurations/{authenticationCombinationConfiguration-id}` | Get authenticationCombinationConfiguration |
| PATCH | `/identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}/combinationConfigurations/{authenticationCombinationConfiguration-id}` | Update authenticationCombinationConfiguration |
| DELETE | `/identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}/combinationConfigurations/{authenticationCombinationConfiguration-id}` | Delete authenticationCombinationConfiguration |
| GET | `/identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}/combinationConfigurations/$count` | Get the number of the resource |
| POST | `/identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}/microsoft.graph.updateAllowedCombinations` | Invoke action updateAllowedCombinations |
| GET | `/identity/conditionalAccess/authenticationStrength/policies/{authenticationStrengthPolicy-id}/microsoft.graph.usage()` | Invoke function usage |
| GET | `/identity/conditionalAccess/authenticationStrength/policies/$count` | Get the number of the resource |
| GET | `/identity/conditionalAccess/deletedItems` | Get deletedItems from identity |
| PATCH | `/identity/conditionalAccess/deletedItems` | Update the navigation property deletedItems in identity |
| DELETE | `/identity/conditionalAccess/deletedItems` | Delete navigation property deletedItems for identity |
| GET | `/identity/conditionalAccess/deletedItems/namedLocations` | Get namedLocations from identity |
| POST | `/identity/conditionalAccess/deletedItems/namedLocations` | Create new navigation property to namedLocations for identity |
| GET | `/identity/conditionalAccess/deletedItems/namedLocations/{namedLocation-id}` | Get namedLocations from identity |
| PATCH | `/identity/conditionalAccess/deletedItems/namedLocations/{namedLocation-id}` | Update the navigation property namedLocations in identity |
| DELETE | `/identity/conditionalAccess/deletedItems/namedLocations/{namedLocation-id}` | Delete navigation property namedLocations for identity |
| POST | `/identity/conditionalAccess/deletedItems/namedLocations/{namedLocation-id}/microsoft.graph.restore` | Invoke action restore |
| GET | `/identity/conditionalAccess/deletedItems/namedLocations/$count` | Get the number of the resource |
| GET | `/identity/conditionalAccess/deletedItems/policies` | Get policies from identity |
| POST | `/identity/conditionalAccess/deletedItems/policies` | Create new navigation property to policies for identity |
| GET | `/identity/conditionalAccess/deletedItems/policies/{conditionalAccessPolicy-id}` | Get policies from identity |
| PATCH | `/identity/conditionalAccess/deletedItems/policies/{conditionalAccessPolicy-id}` | Update the navigation property policies in identity |
| DELETE | `/identity/conditionalAccess/deletedItems/policies/{conditionalAccessPolicy-id}` | Delete navigation property policies for identity |
| POST | `/identity/conditionalAccess/deletedItems/policies/{conditionalAccessPolicy-id}/microsoft.graph.restore` | Invoke action restore |
| GET | `/identity/conditionalAccess/deletedItems/policies/$count` | Get the number of the resource |
| POST | `/identity/conditionalAccess/microsoft.graph.evaluate` | Invoke action evaluate |
| GET | `/identity/conditionalAccess/namedLocations` | List namedLocations |
| POST | `/identity/conditionalAccess/namedLocations` | Create namedLocation |
| GET | `/identity/conditionalAccess/namedLocations/{namedLocation-id}` | Get countryNamedLocation |
| PATCH | `/identity/conditionalAccess/namedLocations/{namedLocation-id}` | Update countryNamedLocation |
| DELETE | `/identity/conditionalAccess/namedLocations/{namedLocation-id}` | Delete countryNamedLocation |
| POST | `/identity/conditionalAccess/namedLocations/{namedLocation-id}/microsoft.graph.restore` | Invoke action restore |
| GET | `/identity/conditionalAccess/namedLocations/$count` | Get the number of the resource |
| GET | `/identity/conditionalAccess/policies` | List policies |
| POST | `/identity/conditionalAccess/policies` | Create conditionalAccessPolicy |
| GET | `/identity/conditionalAccess/policies/{conditionalAccessPolicy-id}` | Get conditionalAccessPolicy |
| PATCH | `/identity/conditionalAccess/policies/{conditionalAccessPolicy-id}` | Update conditionalaccesspolicy |
| DELETE | `/identity/conditionalAccess/policies/{conditionalAccessPolicy-id}` | Delete conditionalAccessPolicy |
| POST | `/identity/conditionalAccess/policies/{conditionalAccessPolicy-id}/microsoft.graph.restore` | Invoke action restore |

…and 4 more operations. They are listed in full on the page.

## Machine-readable artifacts (7)

- **OpenAPI** — https://raw.githubusercontent.com/api-evangelist/azure-ad/refs/heads/main/openapi/azure-ad-identity-conditionalaccessroot-api-openapi.yml
- **Documentation** — https://learn.microsoft.com/en-us/graph/api/overview
- **Authentication** — https://learn.microsoft.com/en-us/graph/auth/
- **SDKs** — https://learn.microsoft.com/en-us/graph/sdks/sdks-overview
- **ChangeLog** — https://developer.microsoft.com/en-us/graph/changelog
- **Webhooks** — https://raw.githubusercontent.com/api-evangelist/azure-ad/refs/heads/main/asyncapi/azure-ad-change-notifications-webhooks.yml
- **Documentation** — https://learn.microsoft.com/en-us/graph/change-notifications-overview

## Other Microsoft Entra ID (formerly Azure AD) APIs (12)

- [Azure AD B2C API](https://apis.io/apis/azure-ad/azure-ad-b2c-api/)
- [Microsoft Entra ID (formerly Azure AD) Admin.people Admin Settings API](https://apis.io/apis/azure-ad/azure-ad-admin-peopleadminsettings-api/)
- [Microsoft Entra ID (formerly Azure AD) Agreements.agreement API](https://apis.io/apis/azure-ad/azure-ad-agreements-agreement-api/)
- [Microsoft Entra ID (formerly Azure AD) Agreements.agreement Acceptance API](https://apis.io/apis/azure-ad/azure-ad-agreements-agreementacceptance-api/)
- [Microsoft Entra ID (formerly Azure AD) Agreements.agreement File API](https://apis.io/apis/azure-ad/azure-ad-agreements-agreementfile-api/)
- [Microsoft Entra ID (formerly Azure AD) Agreements.agreement File Localization API](https://apis.io/apis/azure-ad/azure-ad-agreements-agreementfilelocalization-api/)
- [Microsoft Entra ID (formerly Azure AD) Applications API](https://apis.io/apis/azure-ad/azure-ad-applications-api/)
- [Microsoft Entra ID (formerly Azure AD) Applications.application.Actions API](https://apis.io/apis/azure-ad/azure-ad-applications-application-actions-api/)
- [Microsoft Entra ID (formerly Azure AD) Applications.application API](https://apis.io/apis/azure-ad/azure-ad-applications-application-api/)
- [Microsoft Entra ID (formerly Azure AD) Applications.application.Functions API](https://apis.io/apis/azure-ad/azure-ad-applications-application-functions-api/)
- [Microsoft Entra ID (formerly Azure AD) Applications.app Management Policy API](https://apis.io/apis/azure-ad/azure-ad-applications-appmanagementpolicy-api/)
- [Microsoft Entra ID (formerly Azure AD) Applications.directory Object API](https://apis.io/apis/azure-ad/azure-ad-applications-directoryobject-api/)

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/azure-ad/azure-ad-identity-conditionalaccessroot-api/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/azure-ad/.
