Microsoft Entra ID (formerly Azure AD) Identity Protection.risky User API

The identityProtection.riskyUser API from Microsoft Entra ID (formerly Azure AD) — 9 operation(s) for identityprotection.riskyuser.

Operations 15

GET /identityProtection/riskyUsers List riskyUsers #
POST /identityProtection/riskyUsers Create new navigation property to riskyUsers for identityProtection #
GET /identityProtection/riskyUsers/{riskyUser-id} Get riskyUser #
PATCH /identityProtection/riskyUsers/{riskyUser-id} Update the navigation property riskyUsers in identityProtection #
DELETE /identityProtection/riskyUsers/{riskyUser-id} Delete navigation property riskyUsers for identityProtection #
GET /identityProtection/riskyUsers/{riskyUser-id}/history List history of riskyUser #
POST /identityProtection/riskyUsers/{riskyUser-id}/history Create new navigation property to history for identityProtection #
GET /identityProtection/riskyUsers/{riskyUser-id}/history/{riskyUserHistoryItem-id} Get history from identityProtection #
PATCH /identityProtection/riskyUsers/{riskyUser-id}/history/{riskyUserHistoryItem-id} Update the navigation property history in identityProtection #
DELETE /identityProtection/riskyUsers/{riskyUser-id}/history/{riskyUserHistoryItem-id} Delete navigation property history for identityProtection #
GET /identityProtection/riskyUsers/{riskyUser-id}/history/$count Get the number of the resource #
GET /identityProtection/riskyUsers/$count Get the number of the resource #
POST /identityProtection/riskyUsers/microsoft.graph.confirmCompromised Invoke action confirmCompromised #
POST /identityProtection/riskyUsers/microsoft.graph.confirmSafe Invoke action confirmSafe #
POST /identityProtection/riskyUsers/microsoft.graph.dismiss Invoke action dismiss #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/azure-ad-identityprotection-riskyuser-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

azure-ad-identityprotection-riskyuser-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Identity.SignIns Identity Protection.risky User API
  version: v1.0
servers:
- url: https://graph.microsoft.com/v1.0/
  description: Core
security:
- azureaadv2: []
tags:
- name: identityProtection.riskyUser
paths:
  /identityProtection/riskyUsers:
    get:
      tags:
      - identityProtection.riskyUser
      summary: List riskyUsers
      description: Get a list of the riskyUser objects and their properties.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/riskyuser-list?view=graph-rest-1.0
      operationId: identityProtection_ListRiskyUser
      parameters:
      - $ref: '#/components/parameters/top'
      - $ref: '#/components/parameters/skip'
      - $ref: '#/components/parameters/search'
      - $ref: '#/components/parameters/filter'
      - $ref: '#/components/parameters/count'
      - name: $orderby
        in: query
        description: Order items by property values
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          $ref: '#/components/responses/microsoft.graph.riskyUserCollectionResponse'
        default:
          $ref: '#/components/responses/error'
      x-ms-pageable:
        nextLinkName: '@odata.nextLink'
        operationName: listMore
      x-ms-docs-operation-type: operation
    post:
      tags:
      - identityProtection.riskyUser
      summary: Create new navigation property to riskyUsers for identityProtection
      operationId: identityProtection_CreateRiskyUser
      requestBody:
        description: New navigation property
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.riskyUser'
        required: true
      responses:
        2XX:
          description: Created navigation property.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.riskyUser'
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
  /identityProtection/riskyUsers/{riskyUser-id}:
    get:
      tags:
      - identityProtection.riskyUser
      summary: Get riskyUser
      description: Read the properties and relationships of a riskyUser object.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/riskyuser-get?view=graph-rest-1.0
      operationId: identityProtection_GetRiskyUser
      parameters:
      - name: riskyUser-id
        in: path
        description: The unique identifier of riskyUser
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: riskyUser
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          description: Retrieved navigation property
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.riskyUser'
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    patch:
      tags:
      - identityProtection.riskyUser
      summary: Update the navigation property riskyUsers in identityProtection
      operationId: identityProtection_UpdateRiskyUser
      parameters:
      - name: riskyUser-id
        in: path
        description: The unique identifier of riskyUser
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: riskyUser
      requestBody:
        description: New navigation property values
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.riskyUser'
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.riskyUser'
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    delete:
      tags:
      - identityProtection.riskyUser
      summary: Delete navigation property riskyUsers for identityProtection
      operationId: identityProtection_DeleteRiskyUser
      parameters:
      - name: riskyUser-id
        in: path
        description: The unique identifier of riskyUser
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: riskyUser
      - name: If-Match
        in: header
        description: ETag
        style: simple
        schema:
          type: string
      responses:
        2XX:
          description: Success
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
  /identityProtection/riskyUsers/{riskyUser-id}/history:
    get:
      tags:
      - identityProtection.riskyUser
      summary: List history of riskyUser
      description: Get the riskyUserHistoryItems from the history navigation property.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/riskyuser-list-history?view=graph-rest-1.0
      operationId: identityProtection.riskyUser_ListHistory
      parameters:
      - name: riskyUser-id
        in: path
        description: The unique identifier of riskyUser
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: riskyUser
      - $ref: '#/components/parameters/top'
      - $ref: '#/components/parameters/skip'
      - $ref: '#/components/parameters/search'
      - $ref: '#/components/parameters/filter'
      - $ref: '#/components/parameters/count'
      - name: $orderby
        in: query
        description: Order items by property values
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          $ref: '#/components/responses/microsoft.graph.riskyUserHistoryItemCollectionResponse'
        default:
          $ref: '#/components/responses/error'
      x-ms-pageable:
        nextLinkName: '@odata.nextLink'
        operationName: listMore
      x-ms-docs-operation-type: operation
    post:
      tags:
      - identityProtection.riskyUser
      summary: Create new navigation property to history for identityProtection
      operationId: identityProtection.riskyUser_CreateHistory
      parameters:
      - name: riskyUser-id
        in: path
        description: The unique identifier of riskyUser
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: riskyUser
      requestBody:
        description: New navigation property
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem'
        required: true
      responses:
        2XX:
          description: Created navigation property.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem'
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
  /identityProtection/riskyUsers/{riskyUser-id}/history/{riskyUserHistoryItem-id}:
    get:
      tags:
      - identityProtection.riskyUser
      summary: Get history from identityProtection
      description: The activity related to user risk level change
      operationId: identityProtection.riskyUser_GetHistory
      parameters:
      - name: riskyUser-id
        in: path
        description: The unique identifier of riskyUser
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: riskyUser
      - name: riskyUserHistoryItem-id
        in: path
        description: The unique identifier of riskyUserHistoryItem
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: riskyUserHistoryItem
      - name: $select
        in: query
        description: Select properties to be returned
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      - name: $expand
        in: query
        description: Expand related entities
        style: form
        explode: false
        schema:
          uniqueItems: true
          type: array
          items:
            type: string
      responses:
        2XX:
          description: Retrieved navigation property
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem'
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    patch:
      tags:
      - identityProtection.riskyUser
      summary: Update the navigation property history in identityProtection
      operationId: identityProtection.riskyUser_UpdateHistory
      parameters:
      - name: riskyUser-id
        in: path
        description: The unique identifier of riskyUser
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: riskyUser
      - name: riskyUserHistoryItem-id
        in: path
        description: The unique identifier of riskyUserHistoryItem
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: riskyUserHistoryItem
      requestBody:
        description: New navigation property values
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem'
        required: true
      responses:
        2XX:
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem'
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
    delete:
      tags:
      - identityProtection.riskyUser
      summary: Delete navigation property history for identityProtection
      operationId: identityProtection.riskyUser_DeleteHistory
      parameters:
      - name: riskyUser-id
        in: path
        description: The unique identifier of riskyUser
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: riskyUser
      - name: riskyUserHistoryItem-id
        in: path
        description: The unique identifier of riskyUserHistoryItem
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: riskyUserHistoryItem
      - name: If-Match
        in: header
        description: ETag
        style: simple
        schema:
          type: string
      responses:
        2XX:
          description: Success
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: operation
  /identityProtection/riskyUsers/{riskyUser-id}/history/$count:
    get:
      tags:
      - identityProtection.riskyUser
      summary: Get the number of the resource
      operationId: identityProtection.riskyUser.history_GetCount
      parameters:
      - name: riskyUser-id
        in: path
        description: The unique identifier of riskyUser
        required: true
        style: simple
        schema:
          type: string
        x-ms-docs-key-type: riskyUser
      - $ref: '#/components/parameters/search'
      - $ref: '#/components/parameters/filter'
      responses:
        2XX:
          $ref: '#/components/responses/ODataCountResponse'
        default:
          $ref: '#/components/responses/error'
  /identityProtection/riskyUsers/$count:
    get:
      tags:
      - identityProtection.riskyUser
      summary: Get the number of the resource
      operationId: identityProtection.riskyUser_GetCount
      parameters:
      - $ref: '#/components/parameters/search'
      - $ref: '#/components/parameters/filter'
      responses:
        2XX:
          $ref: '#/components/responses/ODataCountResponse'
        default:
          $ref: '#/components/responses/error'
  /identityProtection/riskyUsers/microsoft.graph.confirmCompromised:
    post:
      tags:
      - identityProtection.riskyUser
      summary: Invoke action confirmCompromised
      description: Confirm one or more riskyUser objects as compromised. This action sets the targeted user's risk level to high.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/riskyuser-confirmcompromised?view=graph-rest-1.0
      operationId: identityProtection.riskyUser_confirmCompromised
      requestBody:
        description: Action parameters
        content:
          application/json:
            schema:
              type: object
              properties:
                userIds:
                  type: array
                  items:
                    type:
                    - string
                    - 'null'
              additionalProperties:
                type: object
        required: true
      responses:
        2XX:
          description: Success
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
  /identityProtection/riskyUsers/microsoft.graph.confirmSafe:
    post:
      tags:
      - identityProtection.riskyUser
      summary: Invoke action confirmSafe
      description: Confirm one or more riskyUser objects as safe. This action sets the targeted user's risk level to none.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/riskyuser-confirmsafe?view=graph-rest-1.0
      operationId: identityProtection.riskyUser_confirmSafe
      requestBody:
        description: Action parameters
        content:
          application/json:
            schema:
              type: object
              properties:
                userIds:
                  type: array
                  items:
                    type:
                    - string
                    - 'null'
              additionalProperties:
                type: object
        required: true
      responses:
        2XX:
          description: Success
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
  /identityProtection/riskyUsers/microsoft.graph.dismiss:
    post:
      tags:
      - identityProtection.riskyUser
      summary: Invoke action dismiss
      description: Dismiss the risk of one or more riskyUser objects. This action sets the targeted user's risk level to none.
      externalDocs:
        description: Find more info here
        url: https://learn.microsoft.com/graph/api/riskyuser-dismiss?view=graph-rest-1.0
      operationId: identityProtection.riskyUser_dismiss
      requestBody:
        description: Action parameters
        content:
          application/json:
            schema:
              type: object
              properties:
                userIds:
                  type: array
                  items:
                    type:
                    - string
                    - 'null'
              additionalProperties:
                type: object
        required: true
      responses:
        2XX:
          description: Success
        default:
          $ref: '#/components/responses/error'
      x-ms-docs-operation-type: action
components:
  responses:
    error:
      description: error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError'
    microsoft.graph.riskyUserHistoryItemCollectionResponse:
      description: Retrieved collection
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItemCollectionResponse'
    microsoft.graph.riskyUserCollectionResponse:
      description: Retrieved collection
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/microsoft.graph.riskyUserCollectionResponse'
    ODataCountResponse:
      description: The count of the resource
      content:
        text/plain:
          schema:
            $ref: '#/components/schemas/ODataCountResponse'
  schemas:
    microsoft.graph.riskState:
      title: riskState
      enum:
      - none
      - confirmedSafe
      - remediated
      - dismissed
      - atRisk
      - confirmedCompromised
      - unknownFutureValue
      type: string
    microsoft.graph.ODataErrors.MainError:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
        message:
          type: string
          x-ms-primary-error-message: true
        target:
          type:
          - string
          - 'null'
        details:
          type: array
          items:
            $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails'
        innerError:
          $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError'
      additionalProperties:
        type: object
    ODataCountResponse:
      type: integer
      format: int32
    microsoft.graph.riskyUserHistoryItemCollectionResponse:
      title: Collection of riskyUserHistoryItem
      type: object
      properties:
        value:
          type: array
          items:
            $ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem'
        '@odata.nextLink':
          type:
          - string
          - 'null'
      additionalProperties:
        type: object
    microsoft.graph.ODataErrors.InnerError:
      type: object
      additionalProperties:
        type: object
      description: The structure of this object is service-specific
    microsoft.graph.ODataErrors.ODataError:
      required:
      - error
      type: object
      properties:
        error:
          $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError'
      additionalProperties:
        type: object
    microsoft.graph.riskLevel:
      title: riskLevel
      enum:
      - low
      - medium
      - high
      - hidden
      - none
      - unknownFutureValue
      type: string
    microsoft.graph.ODataErrors.ErrorDetails:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
        message:
          type: string
        target:
          type:
          - string
          - 'null'
      additionalProperties:
        type: object
    microsoft.graph.entity:
      title: entity
      type: object
      properties:
        id:
          type: string
          description: The unique identifier for an entity. Read-only.
      additionalProperties:
        type: object
    microsoft.graph.riskyUser:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.entity'
      - title: riskyUser
        type: object
        properties:
          isDeleted:
            type:
            - boolean
            - 'null'
            description: 'Indicates whether the user is deleted. The possible values are: true, false.'
          isProcessing:
            type:
            - boolean
            - 'null'
            description: Indicates whether the backend is processing a user's risky state.
          riskDetail:
            $ref: '#/components/schemas/microsoft.graph.riskDetail'
          riskLastUpdatedDateTime:
            pattern: ^[0-9]{4,}-(0[1-9]|1[012])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]([.][0-9]{1,12})?(Z|[+-][0-9][0-9]:[0-9][0-9])$
            type:
            - string
            - 'null'
            description: The date and time that the risky user was last updated. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
            format: date-time
          riskLevel:
            $ref: '#/components/schemas/microsoft.graph.riskLevel'
          riskState:
            $ref: '#/components/schemas/microsoft.graph.riskState'
          userDisplayName:
            type:
            - string
            - 'null'
            description: Risky user display name.
          userPrincipalName:
            type:
            - string
            - 'null'
            description: Risky user principal name.
          history:
            type: array
            items:
              $ref: '#/components/schemas/microsoft.graph.riskyUserHistoryItem'
            description: The activity related to user risk level change
            x-ms-navigationProperty: true
        additionalProperties:
          type: object
    microsoft.graph.riskUserActivity:
      title: riskUserActivity
      type: object
      properties:
        detail:
          $ref: '#/components/schemas/microsoft.graph.riskDetail'
        riskEventTypes:
          type: array
          items:
            type:
            - string
            - 'null'
          description: The type of risk event detected.
      additionalProperties:
        type: object
    microsoft.graph.riskDetail:
      title: riskDetail
      enum:
      - none
      - adminGeneratedTemporaryPassword
      - userPerformedSecuredPasswordChange
      - userPerformedSecuredPasswordReset
      - adminConfirmedSigninSafe
      - aiConfirmedSigninSafe
      - userPassedMFADrivenByRiskBasedPolicy
      - adminDismissedAllRiskForUser
      - adminConfirmedSigninCompromised
      - hidden
      - adminConfirmedUserCompromised
      - unknownFutureValue
      - m365DAdminDismissedDetection
      - adminConfirmedServicePrincipalCompromised
      - adminDismissedAllRiskForServicePrincipal
      - userChangedPasswordOnPremises
      - adminDismissedRiskForSignIn
      - adminConfirmedAccountSafe
      - microsoftRevokedSessions
      type: string
    microsoft.graph.riskyUserCollectionResponse:
      title: Collection of riskyUser
      type: object
      properties:
        value:
          type: array
          items:
            $ref: '#/components/schemas/microsoft.graph.riskyUser'
        '@odata.nextLink':
          type:
          - string
          - 'null'
      additionalProperties:
        type: object
    microsoft.graph.riskyUserHistoryItem:
      allOf:
      - $ref: '#/components/schemas/microsoft.graph.riskyUser'
      - title: riskyUserHistoryItem
        type: object
        properties:
          activity:
            $ref: '#/components/schemas/microsoft.graph.riskUserActivity'
          initiatedBy:
            type:
            - string
            - 'null'
            description: The ID of actor that does the operation.
          userId:
            type:
            - string
            - 'null'
            description: The ID of the user.
        additionalProperties:
          type: object
  parameters:
    filter:
      name: $filter
      in: query
      description: Filter items by property values
      style: form
      explode: false
      schema:
        type: string
    search:
      name: $search
      in: query
      description: Search items by search phrases
      style: form
      explode: false
      schema:
        type: string
    count:
      name: $count
      in: query
      description: Include count of items
      style: form
      explode: false
      schema:
        type: boolean
    skip:
      name: $skip
      in: query
      description: Skip the first n items
      style: form
      explode: false
      schema:
        minimum: 0
        type: integer
    top:
      name: $top
      in: query
      description: Show only the first n items
      style: form
      explode: false
      schema:
        minimum: 0
        type: integer
      example: 50
  securitySchemes:
    azureaadv2:
      type: oauth2
      flows:
        authorizationCode:
          authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize
          tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token
          scopes: {}