Microsoft Entra ID (formerly Azure AD) Identity Protection.identity Protection Root API

The identityProtection.identityProtectionRoot API from Microsoft Entra ID (formerly Azure AD) — 1 operation(s) for identityprotection.identityprotectionroot.

Operations 2

GET /identityProtection Get identityProtection #
PATCH /identityProtection Update identityProtection #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/azure-ad-identityprotection-identityprotectionroot-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

azure-ad-identityprotection-identityprotectionroot-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Identity.SignIns Identity Protection.identity Protection…
  version: v1.0
servers:
- url: https://graph.microsoft.com/v1.0/
  description: Core
security:
- azureaadv2: []
tags:
- name: identityProtection.identityProtectionRoot
paths:
  /identityProtection:
    get:
      tags:
      - identityProtection.identityProtectionRoot
      summary: Get identityProtection
      operationId: identityProtection.identityProtectionRoot_GetIdentityProtectionRoot
      parameters:
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          description: Retrieved entity
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.identityProtectionRoot'
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    patch:
      tags:
      - identityProtection.identityProtectionRoot
      summary: Update identityProtection
      operationId: identityProtection.identityProtectionRoot_UpdateIdentityProtectionRoot
      requestBody:
        description: New property values
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.identityProtectionRoot'
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.identityProtectionRoot'
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
components:
  schemas:
    microsoft.graph.riskyServicePrincipalHistoryItem:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.riskyServicePrincipal'
      - title: riskyServicePrincipalHistoryItem
        type: object
        properties:
          activity:
            $ref: '#/components/schemas/microsoft.graph.riskServicePrincipalActivity'
          initiatedBy:
            type:
            - string
            - 'null'
            description: The identifier of the actor of the operation.
        additionalProperties:
          type: object
    microsoft.graph.riskState:
      title: riskState
      enum:
      - none
      - confirmedSafe
      - remediated
      - dismissed
      - atRisk
      - confirmedCompromised
      - unknownFutureValue
      type: string
    microsoft.graph.ODataErrors.MainError:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
        message:
          type: string
          x-ms-primary-error-message: true
        target:
          type:
          - string
          - 'null'
        details:
          type: array
          items:
            $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails'
        innerError:
          $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError'
      additionalProperties:
        type: object
    microsoft.graph.riskDetectionTimingType:
      title: riskDetectionTimingType
      enum:
      - notDefined
      - realtime
      - nearRealtime
      - offline
      - unknownFutureValue
      type: string
    microsoft.graph.servicePrincipalRiskDetection:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: servicePrincipalRiskDetection
        type: object
        properties:
          activity:
            $ref: '#/components/schemas/microsoft.graph.activityType'
          activityDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type:
            - string
            - 'null'
            description: Date and time when the risky activity occurred. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z
            format: date-time
          additionalInfo:
            type:
            - string
            - 'null'
            description: Additional information associated with the risk detection. This string value is represented as a JSON object with the quotations escaped.
          appId:
            type:
            - string
            - 'null'
            description: The unique identifier for the associated application.
          correlationId:
            type:
            - string
            - 'null'
            description: Correlation ID of the sign-in activity associated with the risk detection. This property is null if the risk detection is not associated with a sign-in activity.
          detectedDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type:
            - string
            - 'null'
            description: Date and time when the risk was detected. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
            format: date-time
          detectionTimingType:
            $ref: '#/components/schemas/microsoft.graph.riskDetectionTimingType'
          ipAddress:
            type:
            - string
            - 'null'
            description: Provides the IP address of the client from where the risk occurred.
          keyIds:
            type: array
            items:
              type:
              - string
              - 'null'
            description: The unique identifier for the key credential associated with the risk detection.
          lastUpdatedDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type:
            - string
            - 'null'
            description: Date and time when the risk detection was last updated.
            format: date-time
          location:
            $ref: '#/components/schemas/microsoft.graph.signInLocation'
          requestId:
            type:
            - string
            - 'null'
            description: Request identifier of the sign-in activity associated with the risk detection. This property is null if the risk detection is not associated with a sign-in activity. Supports $filter (eq).
          riskDetail:
            $ref: '#/components/schemas/microsoft.graph.riskDetail'
          riskEventType:
            type:
            - string
            - 'null'
            description: 'The type of risk event detected. The possible values are: investigationsThreatIntelligence, generic, adminConfirmedServicePrincipalCompromised, suspiciousSignins, leakedCredentials, anomalousServicePrincipalActivity, maliciousApplication, suspiciousApplication.'
          riskLevel:
            $ref: '#/components/schemas/microsoft.graph.riskLevel'
          riskState:
            $ref: '#/components/schemas/microsoft.graph.riskState'
          servicePrincipalDisplayName:
            type:
            - string
            - 'null'
            description: The display name for the service principal.
          servicePrincipalId:
            type:
            - string
            - 'null'
            description: The unique identifier for the service principal. Supports $filter (eq).
          source:
            type:
            - string
            - 'null'
            description: Source of the risk detection. For example, identityProtection.
          tokenIssuerType:
            $ref: '#/components/schemas/microsoft.graph.tokenIssuerType'
        additionalProperties:
          type: object
    microsoft.graph.riskDetection:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: riskDetection
        type: object
        properties:
          activity:
            $ref: '#/components/schemas/microsoft.graph.activityType'
          activityDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type:
            - string
            - 'null'
            description: 'Date and time that the risky activity occurred. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is look like this: 2014-01-01T00:00:00Z'
            format: date-time
          additionalInfo:
            type:
            - string
            - 'null'
            description: 'Additional information associated with the risk detection in JSON format. For example, ''[{/''Key/'':/''userAgent/'',/''Value/'':/''Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36/''}]''. Possible keys in the additionalInfo JSON string are: userAgent, alertUrl, relatedEventTimeInUtc, relatedUserAgent, deviceInformation, relatedLocation, requestId, correlationId, lastActivityTimeInUtc, malwareName, clientLocation, clientIp, riskReasons. For more information about riskReasons and possible values, see riskReasons values.'
          correlationId:
            type:
            - string
            - 'null'
            description: Correlation ID of the sign-in associated with the risk detection. This property is null if the risk detection is not associated with a sign-in.
          detectedDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type:
            - string
            - 'null'
            description: 'Date and time that the risk was detected. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 looks like this: 2014-01-01T00:00:00Z'
            format: date-time
          detectionTimingType:
            $ref: '#/components/schemas/microsoft.graph.riskDetectionTimingType'
          ipAddress:
            type:
            - string
            - 'null'
            description: Provides the IP address of the client from where the risk occurred.
          lastUpdatedDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type:
            - string
            - 'null'
            description: 'Date and time that the risk detection was last updated. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is look like this: 2014-01-01T00:00:00Z'
            format: date-time
          location:
            $ref: '#/components/schemas/microsoft.graph.signInLocation'
          requestId:
            type:
            - string
            - 'null'
            description: Request ID of the sign-in associated with the risk detection. This property is null if the risk detection is not associated with a sign-in.
          riskDetail:
            $ref: '#/components/schemas/microsoft.graph.riskDetail'
          riskEventType:
            type:
            - string
            - 'null'
            description: The type of risk event detected. The possible values are adminConfirmedUserCompromised, anomalousToken, anomalousUserActivity, anonymizedIPAddress, generic, impossibleTravel, investigationsThreatIntelligence, suspiciousSendingPatterns, leakedCredentials, maliciousIPAddress,malwareInfectedIPAddress, mcasSuspiciousInboxManipulationRules, newCountry, passwordSpray,riskyIPAddress, suspiciousAPITraffic, suspiciousBrowser,suspiciousInboxForwarding, suspiciousIPAddress, tokenIssuerAnomaly, unfamiliarFeatures, unlikelyTravel. If the risk detection is a premium detection, will show generic. For more information about each value, see Risk types and detection.
          riskLevel:
            $ref: '#/components/schemas/microsoft.graph.riskLevel'
          riskState:
            $ref: '#/components/schemas/microsoft.graph.riskState'
          source:
            type:
            - string
            - 'null'
            description: Source of the risk detection. For example, activeDirectory.
          tokenIssuerType:
            $ref: '#/components/schemas/microsoft.graph.tokenIssuerType'
          userDisplayName:
            type:
            - string
            - 'null'
            description: The user principal name (UPN) of the user.
          userId:
            type:
            - string
            - 'null'
            description: Unique ID of the user.
          userPrincipalName:
            type:
            - string
            - 'null'
            description: The user principal name (UPN) of the user.
        additionalProperties:
          type: object
    microsoft.graph.ODataErrors.InnerError:
      type: object
      additionalProperties:
        type: object
      description: The structure of this object is service-specific
    microsoft.graph.signInLocation:
      title: signInLocation
      type: object
      properties:
        city:
          type:
          - string
          - 'null'
          description: Provides the city where the sign-in originated and is determined using latitude/longitude information from the sign-in activity.
        countryOrRegion:
          type:
          - string
          - 'null'
          description: Provides the country code info (two letter code) where the sign-in originated.  This is calculated using latitude/longitude information from the sign-in activity.
        geoCoordinates:
          $ref: '#/components/schemas/microsoft.graph.geoCoordinates'
        state:
          type:
          - string
          - 'null'
          description: Provides the State where the sign-in originated. This is calculated using latitude/longitude information from the sign-in activity.
      additionalProperties:
        type: object
    microsoft.graph.activityType:
      title: activityType
      enum:
      - signin
      - user
      - unknownFutureValue
      - servicePrincipal
      type: string
    microsoft.graph.geoCoordinates:
      title: geoCoordinates
      type: object
      properties:
        altitude:
          type:
          - number
          - 'null'
          description: Optional. The altitude (height), in feet,  above sea level for the item. Read-only.
          format: double
        latitude:
          type:
          - number
          - 'null'
          description: Optional. The latitude, in decimal, for the item. Read-only.
          format: double
        longitude:
          type:
          - number
          - 'null'
          description: Optional. The longitude, in decimal, for the item. Read-only.
          format: double
      additionalProperties:
        type: object
    microsoft.graph.ODataErrors.ODataError:
      required:
      - error
      type: object
      properties:
        error:
          $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError'
      additionalProperties:
        type: object
    microsoft.graph.riskLevel:
      title: riskLevel
      enum:
      - low
      - medium
      - high
      - hidden
      - none
      - unknownFutureValue
      type: string
    microsoft.graph.tokenIssuerType:
      title: tokenIssuerType
      enum:
      - AzureAD
      - ADFederationServices
      - UnknownFutureValue
      - AzureADBackupAuth
      - ADFederationServicesMFAAdapter
      - NPSExtension
      type: string
    microsoft.graph.ODataErrors.ErrorDetails:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
        message:
          type: string
        target:
          type:
          - string
          - 'null'
      additionalProperties:
        type: object
    microsoft.graph.entity:
      title: entity
      type: object
      properties:
        id:
          type: string
          description: The unique identifier for an entity. Read-only.
      additionalProperties:
        type: object
    microsoft.graph.riskyServicePrincipal:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: riskyServicePrincipal
        type: object
        properties:
          appId:
            type:
            - string
            - 'null'
            description: The globally unique identifier for the associated application (its appId property), if any.
          displayName:
            type:
            - string
            - 'null'
            description: The display name for the service principal.
          isEnabled:
            type:
            - boolean
            - 'null'
            description: true if the service principal account is enabled; otherwise, false.
          isProcessing:
            type:
            - boolean
            - 'null'
            description: Indicates whether Microsoft Entra ID is currently processing the service principal's risky state.
          riskDetail:
            $ref: '#/components/schemas/microsoft.graph.riskDetail'
          riskLastUpdatedDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type:
            - string
            - 'null'
            description: The date and time that the risk state was last updated. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2021 is 2021-01-01T00:00:00Z. Supports $filter (eq).
            format: date-time
          riskLevel:
            $ref: '#/components/schemas/microsoft.graph.riskLevel'
          riskState:
            $ref: '#/components/schemas/microsoft.graph.riskState'
          servicePrincipalType:
            type:
            - string
            - 'null'
            description: Identifies whether the service principal represents an Application, a ManagedIdentity, or a legacy application (socialIdp). This is set by Microsoft Entra ID internally and is inherited from servicePrincipal.
          history:
            type: array
            items:
              $ref: '#/components/schemas/microsoft.graph.riskyServicePrincipalHistoryItem'
            description: Represents the risk history of Microsoft Entra service principals.
            x-ms-navigationProperty: true
        additionalProperties:
          type: object
    microsoft.graph.riskyUser:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: riskyUser
        type: object
        properties:
          isDeleted:
            type:
            - boolean
            - 'null'
            description: 'Indicates whether the user is deleted. The possible values are: true, false.'
          isProcessing:
            type:
            - boolean
            - 'null'
            description: Indicates whether the backend is processing a user's risky state.
          riskDetail:
            $ref: '#/components/schemas/microsoft.graph.riskDetail'
          riskLastUpdatedDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type:
            - string
            - 'null'
            description: The date and time that the risky user was last updated. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
            format: date-time
          riskLevel:
            $ref: '#/components/schemas/microsoft.graph.riskLevel'
          riskState:
            $ref: '#/components/schemas/microsoft.graph.riskState'
          userDisplayName:
            type:
            - string
            - 'null'
            description: Risky user display name.
          userPrincipalName:
            type:
            - string
            - 'null'
            description: Risky user principal name.
          history:
            type: array
            items:
              $ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem'
            description: The activity related to user risk level change
            x-ms-navigationProperty: true
        additionalProperties:
          type: object
    microsoft.graph.riskUserActivity:
      title: riskUserActivity
      type: object
      properties:
        detail:
          $ref: '#/components/schemas/microsoft.graph.riskDetail'
        riskEventTypes:
          type: array
          items:
            type:
            - string
            - 'null'
          description: The type of risk event detected.
      additionalProperties:
        type: object
    microsoft.graph.riskServicePrincipalActivity:
      title: riskServicePrincipalActivity
      type: object
      properties:
        detail:
          $ref: '#/components/schemas/microsoft.graph.riskDetail'
        riskEventTypes:
          type: array
          items:
            type:
            - string
            - 'null'
          description: 'The type of risk event detected. The possible values are: investigationsThreatIntelligence, generic, adminConfirmedServicePrincipalCompromised, suspiciousSignins, leakedCredentials, anomalousServicePrincipalActivity, maliciousApplication, suspiciousApplication.'
      additionalProperties:
        type: object
    microsoft.graph.riskDetail:
      title: riskDetail
      enum:
      - none
      - adminGeneratedTemporaryPassword
      - userPerformedSecuredPasswordChange
      - userPerformedSecuredPasswordReset
      - adminConfirmedSigninSafe
      - aiConfirmedSigninSafe
      - userPassedMFADrivenByRiskBasedPolicy
      - adminDismissedAllRiskForUser
      - adminConfirmedSigninCompromised
      - hidden
      - adminConfirmedUserCompromised
      - unknownFutureValue
      - m365DAdminDismissedDetection
      - adminConfirmedServicePrincipalCompromised
      - adminDismissedAllRiskForServicePrincipal
      - userChangedPasswordOnPremises
      - adminDismissedRiskForSignIn
      - adminConfirmedAccountSafe
      - microsoftRevokedSessions
      type: string
    microsoft.graph.riskyUserHistoryItem:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.riskyUser'
      - title: riskyUserHistoryItem
        type: object
        properties:
          activity:
            $ref: '#/components/schemas/microsoft.graph.riskUserActivity'
          initiatedBy:
            type:
            - string
            - 'null'
            description: The ID of actor that does the operation.
          userId:
            type:
            - string
            - 'null'
            description: The ID of the user.
        additionalProperties:
          type: object
    microsoft.graph.identityProtectionRoot:
      title: identityProtectionRoot
      type: object
      properties:
        riskDetections:
          type: array
          items:
            $ref: '#/components/schemas/microsoft.graph.riskDetection'
          description: Risk detection in Microsoft Entra ID Protection and the associated information about the detection.
          x-ms-navigationProperty: true
        riskyServicePrincipals:
          type: array
          items:
            $ref: '#/components/schemas/microsoft.graph.riskyServicePrincipal'
          description: Microsoft Entra service principals that are at risk.
          x-ms-navigationProperty: true
        riskyUsers:
          type: array
          items:
            $ref: '#/components/schemas/microsoft.graph.riskyUser'
          description: Users that are flagged as at-risk by Microsoft Entra ID Protection.
          x-ms-navigationProperty: true
        servicePrincipalRiskDetections:
          type: array
          items:
            $ref: '#/components/schemas/microsoft.graph.servicePrincipalRiskDetection'
          description: Represents information about detected at-risk service principals in a Microsoft Entra tenant.
          x-ms-navigationProperty: true
      additionalProperties:
        type: object
  responses:
    error:
      description: error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError'
  securitySchemes:
    azureaadv2:
      type: oauth2
      flows:
        authorizationCode:
          authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize
          tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token
          scopes: {}